AuthController.php 23 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Components\Helpers;
  4. use App\Components\IPIP;
  5. use App\Components\QQWry;
  6. use App\Http\Models\Invite;
  7. use App\Http\Models\SensitiveWords;
  8. use App\Http\Models\User;
  9. use App\Http\Models\UserLabel;
  10. use App\Http\Models\UserLoginLog;
  11. use App\Http\Models\UserSubscribe;
  12. use App\Http\Models\Verify;
  13. use App\Http\Models\VerifyCode;
  14. use App\Mail\activeUser;
  15. use App\Mail\resetPassword;
  16. use App\Mail\sendVerifyCode;
  17. use Auth;
  18. use Cache;
  19. use Captcha;
  20. use Cookie;
  21. use Hash;
  22. use Illuminate\Http\Request;
  23. use Log;
  24. use Mail;
  25. use Redirect;
  26. use Response;
  27. use Session;
  28. use Validator;
  29. /**
  30. * 认证控制器
  31. *
  32. * Class AuthController
  33. *
  34. * @package App\Http\Controllers
  35. */
  36. class AuthController extends Controller
  37. {
  38. protected static $systemConfig;
  39. function __construct()
  40. {
  41. self::$systemConfig = Helpers::systemConfig();
  42. }
  43. // 登录
  44. public function login(Request $request)
  45. {
  46. if($request->isMethod('POST')){
  47. $this->validate($request, [
  48. 'email' => 'required',
  49. 'password' => 'required'
  50. ], [
  51. 'email.required' => trans('auth.email_null'),
  52. 'password.required' => trans('auth.password_null')
  53. ]);
  54. $email = $request->input('email');
  55. $password = $request->input('password');
  56. $remember = $request->input('remember');
  57. // 是否校验验证码
  58. $captcha = $this->check_captcha($request);
  59. if($captcha != FALSE){
  60. return $captcha;
  61. }
  62. // 验证账号并创建会话
  63. if(!Auth::attempt(['email' => $email, 'password' => $password], $remember)){
  64. return Redirect::back()->withInput()->withErrors(trans('auth.login_error'));
  65. }
  66. // 校验普通用户账号状态
  67. if(!Auth::user()->is_admin){
  68. if(Auth::user()->status < 0){
  69. Auth::logout(); // 强制销毁会话,因为Auth::attempt的时候会产生会话
  70. return Redirect::back()->withInput()->withErrors(trans('auth.login_ban', ['email' => self::$systemConfig['webmaster_email']]));
  71. }elseif(Auth::user()->status == 0 && self::$systemConfig['is_activate_account']){
  72. Auth::logout(); // 强制销毁会话,因为Auth::attempt的时候会产生会话
  73. return Redirect::back()->withInput()->withErrors(trans('auth.active_tip').'<a href="/activeUser?email='.$email.'" target="_blank"><span style="color:#000">【'.trans('auth.active_account').'】</span></a>');
  74. }
  75. }
  76. // 写入登录日志
  77. $this->addUserLoginLog(Auth::user()->id, getClientIp());
  78. // 更新登录信息
  79. User::uid()->update(['last_login' => time()]);
  80. // 根据权限跳转
  81. if(Auth::user()->is_admin){
  82. return Redirect::to('admin');
  83. }
  84. return Redirect::to('/');
  85. }else{
  86. if(Auth::check()){
  87. if(Auth::user()->is_admin){
  88. return Redirect::to('admin');
  89. }
  90. return Redirect::to('/');
  91. }
  92. return Response::view('auth.login');
  93. }
  94. }
  95. /**
  96. * 添加用户登录日志
  97. *
  98. * @param string $userId 用户ID
  99. * @param string $ip IP地址
  100. */
  101. private function addUserLoginLog($userId, $ip)
  102. {
  103. if(filter_var($ip, FILTER_VALIDATE_IP, FILTER_FLAG_IPV6)){
  104. Log::info('识别到IPv6,尝试解析:'.$ip);
  105. $ipInfo = getIPv6($ip);
  106. }else{
  107. $ipInfo = QQWry::ip($ip); // 通过纯真IP库解析IPv4信息
  108. if(isset($ipInfo['error'])){
  109. Log::info('无法识别IPv4,尝试使用IPIP的IP库解析:'.$ip);
  110. $ipip = IPIP::ip($ip);
  111. $ipInfo = [
  112. 'country' => $ipip['country_name'],
  113. 'province' => $ipip['region_name'],
  114. 'city' => $ipip['city_name']
  115. ];
  116. }else{
  117. // 判断纯真IP库获取的国家信息是否与IPIP的IP库获取的信息一致,不一致则用IPIP的(因为纯真IP库的非大陆IP准确率较低)
  118. $ipip = IPIP::ip($ip);
  119. if($ipInfo['country'] != $ipip['country_name']){
  120. $ipInfo['country'] = $ipip['country_name'];
  121. $ipInfo['province'] = $ipip['region_name'];
  122. $ipInfo['city'] = $ipip['city_name'];
  123. }
  124. }
  125. }
  126. if(empty($ipInfo) || empty($ipInfo['country'])){
  127. Log::warning("获取IP信息异常:".$ip);
  128. }
  129. $log = new UserLoginLog();
  130. $log->user_id = $userId;
  131. $log->ip = $ip;
  132. $log->country = $ipInfo['country'] ?? '';
  133. $log->province = $ipInfo['province'] ?? '';
  134. $log->city = $ipInfo['city'] ?? '';
  135. $log->county = $ipInfo['county'] ?? '';
  136. $log->isp = $ipInfo['isp'] ?? ($ipInfo['organization'] ?? '');
  137. $log->area = $ipInfo['area'] ?? '';
  138. $log->save();
  139. }
  140. // 校验验证码
  141. private function check_captcha($request)
  142. {
  143. switch(self::$systemConfig['is_captcha']){
  144. case 1: // 默认图形验证码
  145. if(!Captcha::check($request->input('captcha'))){
  146. return Redirect::back()->withInput()->withErrors(trans('auth.captcha_error'));
  147. }
  148. break;
  149. case 2: // Geetest
  150. $result = $this->validate($request, [
  151. 'geetest_challenge' => 'required|geetest'
  152. ], [
  153. 'geetest' => trans('auth.captcha_fail')
  154. ]);
  155. if(!$result){
  156. return Redirect::back()->withInput()->withErrors(trans('auth.fail_captcha'));
  157. }
  158. break;
  159. case 3: // Google reCAPTCHA
  160. $result = $this->validate($request, [
  161. 'g-recaptcha-response' => 'required|NoCaptcha'
  162. ]);
  163. if(!$result){
  164. return Redirect::back()->withInput()->withErrors(trans('auth.fail_captcha'));
  165. }
  166. break;
  167. case 4: // hCaptcha
  168. $result = $this->validate($request, [
  169. 'h-captcha-response' => 'required|HCaptcha'
  170. ]);
  171. if(!$result){
  172. return Redirect::back()->withInput()->withErrors(trans('auth.fail_captcha'));
  173. }
  174. break;
  175. default: // 不启用验证码
  176. break;
  177. }
  178. }
  179. // 退出
  180. public function logout()
  181. {
  182. Auth::logout();
  183. return Redirect::to('login');
  184. }
  185. // 注册
  186. public function register(Request $request)
  187. {
  188. $cacheKey = 'register_times_'.md5(getClientIp()); // 注册限制缓存key
  189. if($request->isMethod('POST')){
  190. $this->validate($request, [
  191. 'username' => 'required',
  192. 'email' => 'required|email|unique:user',
  193. 'password' => 'required|min:6',
  194. 'confirmPassword' => 'required|same:password',
  195. 'term' => 'accepted'
  196. ], [
  197. 'username.required' => trans('auth.email_null'),
  198. 'email.required' => trans('auth.email_null'),
  199. 'email.email' => trans('auth.email_legitimate'),
  200. 'email.unique' => trans('auth.email_exist'),
  201. 'password.required' => trans('auth.password_null'),
  202. 'password.min' => trans('auth.password_limit'),
  203. 'confirmPassword.required' => trans('auth.confirm_password'),
  204. 'confirmPassword.same' => trans('auth.password_same'),
  205. 'term.accepted' => trans('auth.unaccepted')
  206. ]);
  207. $username = $request->input('username');
  208. $email = $request->input('email');
  209. $password = $request->input('password');
  210. $register_token = $request->input('register_token');
  211. $code = $request->input('code');
  212. $verify_code = $request->input('verify_code');
  213. $aff = intval($request->input('aff'));
  214. // 防止重复提交
  215. if($register_token != Session::get('register_token')){
  216. return Redirect::back()->withInput()->withErrors(trans('auth.repeat_request'));
  217. }else{
  218. Session::forget('register_token');
  219. }
  220. // 是否开启注册
  221. if(!self::$systemConfig['is_register']){
  222. return Redirect::back()->withErrors(trans('auth.register_close'));
  223. }
  224. // 校验域名邮箱黑白名单
  225. if(self::$systemConfig['is_email_filtering']){
  226. $result = $this->emailChecker($email);
  227. if($result != FALSE){
  228. return $result;
  229. }
  230. }
  231. // 如果需要邀请注册
  232. if(self::$systemConfig['is_invite_register']){
  233. // 必须使用邀请码
  234. if(self::$systemConfig['is_invite_register'] == 2 && !$code){
  235. return Redirect::back()->withInput()->withErrors(trans('auth.code_null'));
  236. }
  237. // 校验邀请码合法性
  238. if($code){
  239. $codeEnable = Invite::query()->whereCode($code)->whereStatus(0)->doesntExist();
  240. if($codeEnable){
  241. return Redirect::back()->withInput($request->except(['code']))->withErrors(trans('auth.code_error'));
  242. }
  243. }
  244. }
  245. // 注册前发送激活码
  246. if(self::$systemConfig['is_activate_account'] == 1){
  247. if(!$verify_code){
  248. return Redirect::back()->withInput($request->except(['verify_code']))->withErrors(trans('auth.captcha_null'));
  249. }else{
  250. $verifyCode = VerifyCode::query()->whereAddress($email)->whereCode($verify_code)->whereStatus(0)->firstOrFail();
  251. if(!$verifyCode){
  252. return Redirect::back()->withInput($request->except(['verify_code']))->withErrors(trans('auth.captcha_overtime'));
  253. }
  254. $verifyCode->status = 1;
  255. $verifyCode->save();
  256. }
  257. }
  258. // 是否校验验证码
  259. $captcha = $this->check_captcha($request);
  260. if($captcha != FALSE){
  261. return $captcha;
  262. }
  263. // 24小时内同IP注册限制
  264. if(self::$systemConfig['register_ip_limit']){
  265. if(Cache::has($cacheKey)){
  266. $registerTimes = Cache::get($cacheKey);
  267. if($registerTimes >= self::$systemConfig['register_ip_limit']){
  268. return Redirect::back()->withInput($request->except(['code']))->withErrors(trans('auth.register_anti'));
  269. }
  270. }
  271. }
  272. // 获取可用端口
  273. $port = self::$systemConfig['is_rand_port']? Helpers::getRandPort() : Helpers::getOnlyPort();
  274. if($port > self::$systemConfig['max_port']){
  275. return Redirect::back()->withInput()->withErrors(trans('auth.register_close'));
  276. }
  277. // 获取aff
  278. $affArr = $this->getAff($code, $aff);
  279. $referral_uid = $affArr['referral_uid'];
  280. $transfer_enable = 1048576*(self::$systemConfig['default_traffic']+($referral_uid? self::$systemConfig['referral_traffic'] : 0));
  281. // 创建新用户
  282. $uid = Helpers::addUser($email, Hash::make($password), $transfer_enable, self::$systemConfig['default_days'], $referral_uid);
  283. // 注册失败,抛出异常
  284. if(!$uid){
  285. return Redirect::back()->withInput()->withErrors(trans('auth.register_fail'));
  286. }
  287. // 更新昵称
  288. User::query()->whereKey($uid)->update(['username' => $username]);
  289. // 生成订阅码
  290. $subscribe = new UserSubscribe();
  291. $subscribe->user_id = $uid;
  292. $subscribe->code = Helpers::makeSubscribeCode();
  293. $subscribe->times = 0;
  294. $subscribe->save();
  295. // 注册次数+1
  296. if(Cache::has($cacheKey)){
  297. Cache::increment($cacheKey);
  298. }else{
  299. Cache::put($cacheKey, 1, 86400); // 24小时
  300. }
  301. // 初始化默认标签
  302. if(strlen(self::$systemConfig['initial_labels_for_user'])){
  303. $labels = explode(',', self::$systemConfig['initial_labels_for_user']);
  304. foreach($labels as $label){
  305. $userLabel = new UserLabel();
  306. $userLabel->user_id = $uid;
  307. $userLabel->label_id = $label;
  308. $userLabel->save();
  309. }
  310. }
  311. // 更新邀请码
  312. if(self::$systemConfig['is_invite_register'] && $affArr['code_id']){
  313. Invite::query()->whereId($affArr['code_id'])->update(['fuid' => $uid, 'status' => 1]);
  314. }
  315. // 清除邀请人Cookie
  316. Cookie::unqueue('register_aff');
  317. // 注册后发送激活码
  318. if(self::$systemConfig['is_activate_account'] == 2){
  319. // 生成激活账号的地址
  320. $token = $this->addVerifyUrl($uid, $email);
  321. $activeUserUrl = self::$systemConfig['website_url'].'/active/'.$token;
  322. $logId = Helpers::addNotificationLog('注册激活', '请求地址:'.$activeUserUrl, 1, $email);
  323. Mail::to($email)->send(new activeUser($logId, $activeUserUrl));
  324. Session::flash('regSuccessMsg', trans('auth.register_active_tip'));
  325. }else{
  326. // 则直接给推荐人加流量
  327. if($referral_uid){
  328. $referralUser = User::query()->whereId($referral_uid)->first();
  329. if($referralUser){
  330. if($referralUser->expire_time >= date('Y-m-d')){
  331. User::query()->whereId($referral_uid)->increment('transfer_enable', self::$systemConfig['referral_traffic']*1048576);
  332. }
  333. }
  334. }
  335. if(self::$systemConfig['is_activate_account'] == 1){
  336. User::query()->whereId($uid)->update(['status' => 1]);
  337. }
  338. Session::flash('regSuccessMsg', trans('auth.register_success'));
  339. }
  340. return Redirect::to('login')->withInput();
  341. }else{
  342. $view['emailList'] = self::$systemConfig['is_email_filtering'] != 2? FALSE : SensitiveWords::query()->whereType(2)->get();
  343. Session::put('register_token', makeRandStr(16));
  344. return Response::view('auth.register', $view);
  345. }
  346. }
  347. //邮箱检查
  348. private function emailChecker($email)
  349. {
  350. $sensitiveWords = $this->sensitiveWords(self::$systemConfig['is_email_filtering']);
  351. $emailSuffix = explode('@', $email); // 提取邮箱后缀
  352. switch(self::$systemConfig['is_email_filtering']){
  353. // 黑名单
  354. case 1:
  355. if(in_array(strtolower($emailSuffix[1]), $sensitiveWords)){
  356. return Response::json(['status' => 'fail', 'message' => trans('auth.email_banned')]);
  357. }
  358. break;
  359. //白名单
  360. case 2:
  361. if(!in_array(strtolower($emailSuffix[1]), $sensitiveWords)){
  362. return Response::json(['status' => 'fail', 'message' => trans('auth.email_invalid')]);
  363. }
  364. break;
  365. default:
  366. return Response::json(['status' => 'fail', 'message' => trans('auth.email_invalid')]);
  367. }
  368. return FALSE;
  369. }
  370. /**
  371. * 获取AFF
  372. *
  373. * @param string $code 邀请码
  374. * @param int $aff URL中的aff参数
  375. *
  376. * @return array
  377. */
  378. private function getAff($code = '', $aff = NULL)
  379. {
  380. // 邀请人ID
  381. $referral_uid = 0;
  382. // 邀请码ID
  383. $code_id = 0;
  384. // 有邀请码先用邀请码,用谁的邀请码就给谁返利
  385. if($code){
  386. $inviteCode = Invite::query()->whereCode($code)->whereStatus(0)->first();
  387. if($inviteCode){
  388. $referral_uid = $inviteCode->uid;
  389. $code_id = $inviteCode->id;
  390. }
  391. }
  392. // 没有用邀请码或者邀请码是管理员生成的,则检查cookie或者url链接
  393. if(!$referral_uid){
  394. // 检查一下cookie里有没有aff
  395. $cookieAff = \Request::hasCookie('register_aff')? \Request::cookie('register_aff') : 0;
  396. if($cookieAff){
  397. $affUser = User::query()->whereId($cookieAff)->exists();
  398. $referral_uid = $affUser? $cookieAff : 0;
  399. }elseif($aff){ // 如果cookie里没有aff,就再检查一下请求的url里有没有aff,因为有些人的浏览器会禁用了cookie,比如chrome开了隐私模式
  400. $affUser = User::query()->whereId($aff)->exists();
  401. $referral_uid = $affUser? $aff : 0;
  402. }
  403. }
  404. return [
  405. 'referral_uid' => $referral_uid,
  406. 'code_id' => $code_id
  407. ];
  408. }
  409. // 生成申请的请求地址
  410. private function addVerifyUrl($uid, $email)
  411. {
  412. $token = md5(self::$systemConfig['website_name'].$email.microtime());
  413. $verify = new Verify();
  414. $verify->type = 1;
  415. $verify->user_id = $uid;
  416. $verify->token = $token;
  417. $verify->status = 0;
  418. $verify->save();
  419. return $token;
  420. }
  421. // 重设密码页
  422. public function resetPassword(Request $request)
  423. {
  424. if($request->isMethod('POST')){
  425. // 校验请求
  426. $this->validate($request, [
  427. 'email' => 'required|email'
  428. ], [
  429. 'email.required' => trans('auth.email_null'),
  430. 'email.email' => trans('auth.email_legitimate')
  431. ]);
  432. $email = $request->input('email');
  433. // 是否开启重设密码
  434. if(!self::$systemConfig['is_reset_password']){
  435. return Redirect::back()->withErrors(trans('auth.reset_password_close', ['email' => self::$systemConfig['webmaster_email']]));
  436. }
  437. // 查找账号
  438. $user = User::query()->whereEmail($email)->first();
  439. if(!$user){
  440. return Redirect::back()->withErrors(trans('auth.email_notExist'));
  441. }
  442. // 24小时内重设密码次数限制
  443. $resetTimes = 0;
  444. if(Cache::has('resetPassword_'.md5($email))){
  445. $resetTimes = Cache::get('resetPassword_'.md5($email));
  446. if($resetTimes >= self::$systemConfig['reset_password_times']){
  447. return Redirect::back()->withErrors(trans('auth.reset_password_limit', ['time' => self::$systemConfig['reset_password_times']]));
  448. }
  449. }
  450. // 生成取回密码的地址
  451. $token = $this->addVerifyUrl($user->id, $email);
  452. // 发送邮件
  453. $resetPasswordUrl = self::$systemConfig['website_url'].'/reset/'.$token;
  454. $logId = Helpers::addNotificationLog('重置密码', '请求地址:'.$resetPasswordUrl, 1, $email);
  455. Mail::to($email)->send(new resetPassword($logId, $resetPasswordUrl));
  456. Cache::put('resetPassword_'.md5($email), $resetTimes+1, 86400);
  457. return Redirect::back()->with('successMsg', trans('auth.reset_password_success_tip'));
  458. }else{
  459. return Response::view('auth.resetPassword');
  460. }
  461. }
  462. // 重设密码
  463. public function reset(Request $request, $token)
  464. {
  465. if(!$token){
  466. return Redirect::to('login');
  467. }
  468. if($request->isMethod('POST')){
  469. $this->validate($request, [
  470. 'password' => 'required|min:6',
  471. 'confirmPassword' => 'required|same:password'
  472. ], [
  473. 'password.required' => trans('auth.password_null'),
  474. 'password.min' => trans('auth.password_limit'),
  475. 'confirmPassword.required' => trans('auth.password_null'),
  476. 'confirmPassword.min' => trans('auth.password_limit'),
  477. 'confirmPassword.same' => trans('auth.password_same'),
  478. ]);
  479. $password = $request->input('password');
  480. // 校验账号
  481. $verify = Verify::type(1)->with('user')->whereToken($token)->first();
  482. if(!$verify){
  483. return Redirect::to('login');
  484. }elseif($verify->status == 1){
  485. return Redirect::back()->withErrors(trans('auth.overtime'));
  486. }elseif($verify->user->status < 0){
  487. return Redirect::back()->withErrors(trans('auth.email_banned'));
  488. }elseif(Hash::check($password, $verify->user->password)){
  489. return Redirect::back()->withErrors(trans('auth.reset_password_same_fail'));
  490. }
  491. // 更新密码
  492. $ret = User::query()->whereId($verify->user_id)->update(['password' => Hash::make($password)]);
  493. if(!$ret){
  494. return Redirect::back()->withErrors(trans('auth.reset_password_fail'));
  495. }
  496. // 置为已使用
  497. $verify->status = 1;
  498. $verify->save();
  499. return Redirect::back()->with('successMsg', trans('auth.reset_password_new'));
  500. }else{
  501. $verify = Verify::type(1)->whereToken($token)->first();
  502. if(!$verify){
  503. return Redirect::to('login');
  504. }elseif(time()-strtotime($verify->created_at) >= 1800){
  505. // 置为已失效
  506. $verify->status = 2;
  507. $verify->save();
  508. }
  509. // 重新获取一遍verify
  510. $view['verify'] = Verify::type(1)->whereToken($token)->first();
  511. return Response::view('auth.reset', $view);
  512. }
  513. }
  514. // 激活账号页
  515. public function activeUser(Request $request)
  516. {
  517. if($request->isMethod('POST')){
  518. $this->validate($request, [
  519. 'email' => 'required|email|exists:user,email'
  520. ], [
  521. 'email.required' => trans('auth.email_null'),
  522. 'email.email' => trans('auth.email_legitimate'),
  523. 'email.exists' => trans('auth.email_notExist')
  524. ]);
  525. $email = $request->input('email');
  526. // 是否开启账号激活
  527. if(self::$systemConfig['is_activate_account'] != 2){
  528. return Redirect::back()->withInput()->withErrors(trans('auth.active_close', ['email' => self::$systemConfig['webmaster_email']]));
  529. }
  530. // 查找账号
  531. $user = User::query()->whereEmail($email)->first();
  532. if($user->status < 0){
  533. return Redirect::back()->withErrors(trans('auth.login_ban', ['email' => self::$systemConfig['webmaster_email']]));
  534. }elseif($user->status > 0){
  535. return Redirect::back()->withErrors(trans('auth.email_normal'));
  536. }
  537. // 24小时内激活次数限制
  538. $activeTimes = 0;
  539. if(Cache::has('activeUser_'.md5($email))){
  540. $activeTimes = Cache::get('activeUser_'.md5($email));
  541. if($activeTimes >= self::$systemConfig['active_times']){
  542. return Redirect::back()->withErrors(trans('auth.active_limit', ['time' => self::$systemConfig['webmaster_email']]));
  543. }
  544. }
  545. // 生成激活账号的地址
  546. $token = $this->addVerifyUrl($user->id, $email);
  547. // 发送邮件
  548. $activeUserUrl = self::$systemConfig['website_url'].'/active/'.$token;
  549. $logId = Helpers::addNotificationLog('激活账号', '请求地址:'.$activeUserUrl, 1, $email);
  550. Mail::to($email)->send(new activeUser($logId, $activeUserUrl));
  551. Cache::put('activeUser_'.md5($email), $activeTimes+1, 86400);
  552. return Redirect::back()->with('successMsg', trans('auth.register_active_tip'));
  553. }else{
  554. return Response::view('auth.activeUser');
  555. }
  556. }
  557. // 激活账号
  558. public function active($token)
  559. {
  560. if(!$token){
  561. return Redirect::to('login');
  562. }
  563. $verify = Verify::type(1)->with('user')->whereToken($token)->first();
  564. if(!$verify){
  565. return Redirect::to('login');
  566. }elseif(empty($verify->user)){
  567. Session::flash('errorMsg', trans('auth.overtime'));
  568. return Response::view('auth.active');
  569. }elseif($verify->status > 0){
  570. Session::flash('errorMsg', trans('auth.overtime'));
  571. return Response::view('auth.active');
  572. }elseif($verify->user->status != 0){
  573. Session::flash('errorMsg', trans('auth.email_normal'));
  574. return Response::view('auth.active');
  575. }elseif(time()-strtotime($verify->created_at) >= 1800){
  576. Session::flash('errorMsg', trans('auth.overtime'));
  577. // 置为已失效
  578. $verify->status = 2;
  579. $verify->save();
  580. return Response::view('auth.active');
  581. }
  582. // 更新账号状态
  583. $ret = User::query()->whereId($verify->user_id)->update(['status' => 1]);
  584. if(!$ret){
  585. Session::flash('errorMsg', trans('auth.active_fail'));
  586. return Redirect::back();
  587. }
  588. // 置为已使用
  589. $verify->status = 1;
  590. $verify->save();
  591. // 账号激活后给邀请人送流量
  592. if($verify->user->referral_uid){
  593. $transfer_enable = self::$systemConfig['referral_traffic']*1048576;
  594. User::query()->whereId($verify->user->referral_uid)->increment('transfer_enable', $transfer_enable, ['enable' => 1]);
  595. }
  596. Session::flash('successMsg', trans('auth.active_success'));
  597. return Response::view('auth.active');
  598. }
  599. // 发送注册验证码
  600. public function sendCode(Request $request)
  601. {
  602. $validator = Validator::make($request->all(), [
  603. 'email' => 'required|email|unique:user'
  604. ], [
  605. 'email.required' => trans('auth.email_null'),
  606. 'email.email' => trans('auth.email_legitimate'),
  607. 'email.unique' => trans('auth.email_exist')
  608. ]);
  609. $email = $request->input('email');
  610. if($validator->fails()){
  611. return Response::json(['status' => 'fail', 'message' => $validator->getMessageBag()->first()]);
  612. }
  613. // 校验域名邮箱黑白名单
  614. if(self::$systemConfig['is_email_filtering']){
  615. $result = $this->emailChecker($email);
  616. if($result != FALSE){
  617. return $result;
  618. }
  619. }
  620. // 是否开启注册发送验证码
  621. if(self::$systemConfig['is_activate_account'] != 1){
  622. return Response::json(['status' => 'fail', 'message' => trans('auth.captcha_close')]);
  623. }
  624. // 防刷机制
  625. if(Cache::has('send_verify_code_'.md5(getClientIP()))){
  626. return Response::json(['status' => 'fail', 'message' => trans('auth.register_anti')]);
  627. }
  628. // 发送邮件
  629. $code = makeRandStr(6, TRUE);
  630. $logId = Helpers::addNotificationLog('发送注册验证码', '验证码:'.$code, 1, $email);
  631. Mail::to($email)->send(new sendVerifyCode($logId, $code));
  632. $this->addVerifyCode($email, $code);
  633. Cache::put('send_verify_code_'.md5(getClientIP()), getClientIP(), 60);
  634. return Response::json(['status' => 'success', 'message' => trans('auth.captcha_send')]);
  635. }
  636. // 生成注册验证码
  637. private function addVerifyCode($email, $code)
  638. {
  639. $verify = new VerifyCode();
  640. $verify->address = $email;
  641. $verify->code = $code;
  642. $verify->status = 0;
  643. $verify->save();
  644. }
  645. // 公开的邀请码列表
  646. public function free()
  647. {
  648. $view['inviteList'] = Invite::query()->whereUid(0)->whereStatus(0)->paginate();
  649. return Response::view('auth.free', $view);
  650. }
  651. // 切换语言
  652. public function switchLang($locale)
  653. {
  654. Session::put("locale", $locale);
  655. return Redirect::back();
  656. }
  657. }