AuthController.php 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211
  1. <?php
  2. namespace App\Http\Controllers\Passport;
  3. use App\Http\Controllers\Controller;
  4. use App\Http\Requests\Passport\AuthRegister;
  5. use App\Http\Requests\Passport\AuthForget;
  6. use App\Http\Requests\Passport\AuthLogin;
  7. use Illuminate\Http\Request;
  8. use Illuminate\Support\Facades\Cache;
  9. use App\Models\Plan;
  10. use App\Models\User;
  11. use App\Models\InviteCode;
  12. use App\Utils\Helper;
  13. use App\Utils\Dict;
  14. class AuthController extends Controller
  15. {
  16. public function register(AuthRegister $request)
  17. {
  18. if ((int)config('v2board.email_whitelist_enable', 0)) {
  19. if (!Helper::emailSuffixVerify(
  20. $request->input('email'),
  21. config('v2board.email_whitelist_suffix', Dict::EMAIL_WHITELIST_SUFFIX_DEFAULT))
  22. ) {
  23. abort(500, '邮箱后缀不处于白名单中');
  24. }
  25. }
  26. if ((int)config('v2board.stop_register', 0)) {
  27. abort(500, '本站已关闭注册');
  28. }
  29. if ((int)config('v2board.invite_force', 0)) {
  30. if (empty($request->input('invite_code'))) {
  31. abort(500, '必须使用邀请码才可以注册');
  32. }
  33. }
  34. if ((int)config('v2board.email_verify', 0)) {
  35. $redisKey = 'sendEmailVerify:' . $request->input('email');
  36. if (empty($request->input('email_code'))) {
  37. abort(500, '邮箱验证码不能为空');
  38. }
  39. if (Cache::get($redisKey) !== $request->input('email_code')) {
  40. abort(500, '邮箱验证码有误');
  41. }
  42. }
  43. $email = $request->input('email');
  44. $password = $request->input('password');
  45. $exist = User::where('email', $email)->first();
  46. if ($exist) {
  47. abort(500, '邮箱已存在系统中');
  48. }
  49. $user = new User();
  50. $user->email = $email;
  51. $user->password = password_hash($password, PASSWORD_DEFAULT);
  52. $user->v2ray_uuid = Helper::guid(true);
  53. $user->token = Helper::guid();
  54. if ($request->input('invite_code')) {
  55. $inviteCode = InviteCode::where('code', $request->input('invite_code'))
  56. ->where('status', 0)
  57. ->first();
  58. if (!$inviteCode) {
  59. if ((int)config('v2board.invite_force', 0)) {
  60. abort(500, '邀请码无效');
  61. }
  62. } else {
  63. $user->invite_user_id = $inviteCode->user_id ? $inviteCode->user_id : null;
  64. if (!(int)config('v2board.invite_never_expire', env('V2BOARD_INVITE_NEVER_EXPIRE'))) {
  65. $inviteCode->status = 1;
  66. $inviteCode->save();
  67. }
  68. }
  69. }
  70. // try out
  71. if ((int)config('v2board.try_out_plan_id', 0)) {
  72. $plan = Plan::find(config('v2board.try_out_plan_id'));
  73. if ($plan) {
  74. $user->transfer_enable = $plan->transfer_enable * 1073741824;
  75. $user->plan_id = $plan->id;
  76. $user->group_id = $plan->group_id;
  77. $user->expired_at = time() + (config('v2board.try_out_hour', 1) * 3600);
  78. }
  79. }
  80. if (!$user->save()) {
  81. abort(500, '注册失败');
  82. }
  83. if ((int)config('v2board.email_verify', 0)) {
  84. Cache::forget($redisKey);
  85. }
  86. $request->session()->put('email', $user->email);
  87. $request->session()->put('id', $user->id);
  88. return response()->json([
  89. 'data' => true
  90. ]);
  91. }
  92. public function login(AuthLogin $request)
  93. {
  94. $email = $request->input('email');
  95. $password = $request->input('password');
  96. $user = User::where('email', $email)->first();
  97. if (!$user) {
  98. abort(500, '用户名或密码错误');
  99. }
  100. if (!Helper::multiPasswordVerify(
  101. $user->password_algo,
  102. $password,
  103. $user->password)
  104. ) {
  105. abort(500, '用户名或密码错误');
  106. }
  107. if ($user->banned) {
  108. abort(500, '该账户已被停止使用');
  109. }
  110. $data = [
  111. 'token' => $user->token
  112. ];
  113. $request->session()->put('email', $user->email);
  114. $request->session()->put('id', $user->id);
  115. if ($user->is_admin) {
  116. $request->session()->put('is_admin', true);
  117. $data['is_admin'] = true;
  118. }
  119. return response([
  120. 'data' => $data
  121. ]);
  122. }
  123. public function token2Login(Request $request)
  124. {
  125. if ($request->input('token')) {
  126. $user = User::where('token', $request->input('token'))->first();
  127. if (!$user) {
  128. return header('Location:' . config('v2board.app_url'));
  129. }
  130. $code = Helper::guid();
  131. $key = 'token2Login_' . $code;
  132. Cache::put($key, $user->id, 600);
  133. $redirect = '/#/login?verify=' . $code . '&redirect=' . ($request->input('redirect') ? $request->input('redirect') : 'dashboard');
  134. if (config('v2board.app_url')) {
  135. $location = config('v2board.app_url') . $redirect;
  136. } else {
  137. $location = url($redirect);
  138. }
  139. return header('Location:' . $location);
  140. }
  141. if ($request->input('verify')) {
  142. $key = 'token2Login_' . $request->input('verify');
  143. $userId = Cache::get($key);
  144. if (!$userId) {
  145. abort(500, '令牌有误');
  146. }
  147. $user = User::find($userId);
  148. if (!$user) {
  149. abort(500, '用户不存在');
  150. }
  151. if ($user->banned) {
  152. abort(500, '该账户已被停止使用');
  153. }
  154. $request->session()->put('email', $user->email);
  155. $request->session()->put('id', $user->id);
  156. if ($user->is_admin) {
  157. $request->session()->put('is_admin', true);
  158. }
  159. Cache::forget($key);
  160. return response([
  161. 'data' => true
  162. ]);
  163. }
  164. }
  165. public function check(Request $request)
  166. {
  167. $data = [
  168. 'is_login' => $request->session()->get('id') ? true : false
  169. ];
  170. if ($request->session()->get('is_admin')) {
  171. $data['is_admin'] = true;
  172. }
  173. return response([
  174. 'data' => $data
  175. ]);
  176. }
  177. public function forget(AuthForget $request)
  178. {
  179. $redisKey = 'sendEmailVerify:' . $request->input('email');
  180. if (Cache::get($redisKey) !== $request->input('email_code')) {
  181. abort(500, '邮箱验证码有误');
  182. }
  183. $user = User::where('email', $request->input('email'))->first();
  184. if (!$user) {
  185. abort(500, '该邮箱不存在系统中');
  186. }
  187. $user->password = password_hash($request->input('password'), PASSWORD_DEFAULT);
  188. $user->password_algo = NULL;
  189. if (!$user->save()) {
  190. abort(500, '重置失败');
  191. }
  192. Cache::forget($redisKey);
  193. return response([
  194. 'data' => true
  195. ]);
  196. }
  197. }