Don't allow guests into the admin area

This commit is contained in:
Toby Zerner 2015-03-30 12:43:55 +10:30
parent 1286a52e1d
commit a43957e1e2

View File

@ -16,12 +16,11 @@ class LoginWithCookieAndCheckAdmin
public function handle($request, Closure $next)
{
if (($token = $request->cookie('flarum_remember')) &&
($accessToken = AccessToken::where('id', $token)->first())) {
$user = $accessToken->user;
if (! $user->isAdmin()) {
die('ur not an admin');
}
$this->actor->setUser($user);
($accessToken = AccessToken::where('id', $token)->first()) &&
$accessToken->user->isAdmin()) {
$this->actor->setUser($accessToken->user);
} else {
die('ur not an admin');
}
return $next($request);