X-Git-Url: http://source.bookstackapp.com/bookstack/blobdiff_plain/88049476fe496de3a3b767a4305d985f78a96db8..refs/pull/5280/head:/app/Http/Kernel.php diff --git a/app/Http/Kernel.php b/app/Http/Kernel.php index a1f2a581f..30714e2ac 100644 --- a/app/Http/Kernel.php +++ b/app/Http/Kernel.php @@ -8,27 +8,53 @@ class Kernel extends HttpKernel { /** * The application's global HTTP middleware stack. + * These middleware are run during every request to your application. + */ + protected $middleware = [ + \BookStack\Http\Middleware\PreventRequestsDuringMaintenance::class, + \Illuminate\Foundation\Http\Middleware\ValidatePostSize::class, + \BookStack\Http\Middleware\TrimStrings::class, + \BookStack\Http\Middleware\TrustProxies::class, + \BookStack\Http\Middleware\PreventResponseCaching::class, + ]; + + /** + * The application's route middleware groups. * * @var array */ - protected $middleware = [ - \Illuminate\Foundation\Http\Middleware\CheckForMaintenanceMode::class, - \BookStack\Http\Middleware\EncryptCookies::class, - \Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class, - \Illuminate\Session\Middleware\StartSession::class, - \Illuminate\View\Middleware\ShareErrorsFromSession::class, - \BookStack\Http\Middleware\VerifyCsrfToken::class, + protected $middlewareGroups = [ + 'web' => [ + \BookStack\Http\Middleware\ApplyCspRules::class, + \BookStack\Http\Middleware\EncryptCookies::class, + \Illuminate\Cookie\Middleware\AddQueuedCookiesToResponse::class, + \BookStack\Http\Middleware\StartSessionExtended::class, + \Illuminate\View\Middleware\ShareErrorsFromSession::class, + \BookStack\Http\Middleware\VerifyCsrfToken::class, + \BookStack\Http\Middleware\CheckEmailConfirmed::class, + \BookStack\Http\Middleware\RunThemeActions::class, + \BookStack\Http\Middleware\Localization::class, + ], + 'api' => [ + \BookStack\Http\Middleware\ThrottleApiRequests::class, + \BookStack\Http\Middleware\EncryptCookies::class, + \BookStack\Http\Middleware\StartSessionIfCookieExists::class, + \BookStack\Http\Middleware\ApiAuthenticate::class, + \BookStack\Http\Middleware\CheckEmailConfirmed::class, + ], ]; /** - * The application's route middleware. + * The application's middleware aliases. * * @var array */ - protected $routeMiddleware = [ + protected $middlewareAliases = [ 'auth' => \BookStack\Http\Middleware\Authenticate::class, - 'auth.basic' => \Illuminate\Auth\Middleware\AuthenticateWithBasicAuth::class, + 'can' => \BookStack\Http\Middleware\CheckUserHasPermission::class, 'guest' => \BookStack\Http\Middleware\RedirectIfAuthenticated::class, - 'perm' => \BookStack\Http\Middleware\PermissionMiddleware::class + 'throttle' => \Illuminate\Routing\Middleware\ThrottleRequests::class, + 'guard' => \BookStack\Http\Middleware\CheckGuard::class, + 'mfa-setup' => \BookStack\Http\Middleware\AuthenticatedOrPendingMfa::class, ]; }