AuthController.php 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276
  1. <?php
  2. namespace App\Http\Controllers\Passport;
  3. use App\Http\Controllers\Controller;
  4. use App\Http\Requests\Passport\AuthRegister;
  5. use App\Http\Requests\Passport\AuthForget;
  6. use App\Http\Requests\Passport\AuthLogin;
  7. use Illuminate\Http\Request;
  8. use Illuminate\Support\Facades\Cache;
  9. use App\Models\Plan;
  10. use App\Models\User;
  11. use App\Models\InviteCode;
  12. use App\Utils\Helper;
  13. use App\Utils\Dict;
  14. use App\Utils\CacheKey;
  15. use ReCaptcha\ReCaptcha;
  16. class AuthController extends Controller
  17. {
  18. public function register(AuthRegister $request)
  19. {
  20. $registerCountByIP = CacheKey::get('REGISTER_IP_RATE_LIMIT', $request->ip()) || 0;
  21. if ($registerCountByIP >= 3) {
  22. abort(500, __('Register frequently, please try again after 1 hour'));
  23. }
  24. if ((int)config('v2board.recaptcha_enable', 0)) {
  25. $recaptcha = new ReCaptcha(config('v2board.recaptcha_key'));
  26. $recaptchaResp = $recaptcha->verify($request->input('recaptcha_data'));
  27. if (!$recaptchaResp->isSuccess()) {
  28. abort(500, __('Invalid code is incorrect'));
  29. }
  30. }
  31. if ((int)config('v2board.email_whitelist_enable', 0)) {
  32. if (!Helper::emailSuffixVerify(
  33. $request->input('email'),
  34. config('v2board.email_whitelist_suffix', Dict::EMAIL_WHITELIST_SUFFIX_DEFAULT))
  35. ) {
  36. abort(500, __('Email suffix is not in the Whitelist'));
  37. }
  38. }
  39. if ((int)config('v2board.email_gmail_limit_enable', 0)) {
  40. $prefix = explode('@', $request->input('email'))[0];
  41. if (strpos($prefix, '.') !== false || strpos($prefix, '+') !== false) {
  42. abort(500, __('Gmail alias is not supported'));
  43. }
  44. }
  45. if ((int)config('v2board.stop_register', 0)) {
  46. abort(500, __('Registration has closed'));
  47. }
  48. if ((int)config('v2board.invite_force', 0)) {
  49. if (empty($request->input('invite_code'))) {
  50. abort(500, __('You must use the invitation code to register'));
  51. }
  52. }
  53. if ((int)config('v2board.email_verify', 0)) {
  54. if (empty($request->input('email_code'))) {
  55. abort(500, __('Email verification code cannot be empty'));
  56. }
  57. if (Cache::get(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email'))) !== $request->input('email_code')) {
  58. abort(500, __('Incorrect email verification code'));
  59. }
  60. }
  61. $email = $request->input('email');
  62. $password = $request->input('password');
  63. $exist = User::where('email', $email)->first();
  64. if ($exist) {
  65. abort(500, __('Email already exists'));
  66. }
  67. $user = new User();
  68. $user->email = $email;
  69. $user->password = password_hash($password, PASSWORD_DEFAULT);
  70. $user->uuid = Helper::guid(true);
  71. $user->token = Helper::guid();
  72. if ($request->input('invite_code')) {
  73. $inviteCode = InviteCode::where('code', $request->input('invite_code'))
  74. ->where('status', 0)
  75. ->first();
  76. if (!$inviteCode) {
  77. if ((int)config('v2board.invite_force', 0)) {
  78. abort(500, __('Invalid invitation code'));
  79. }
  80. } else {
  81. $user->invite_user_id = $inviteCode->user_id ? $inviteCode->user_id : null;
  82. if (!(int)config('v2board.invite_never_expire', 0)) {
  83. $inviteCode->status = 1;
  84. $inviteCode->save();
  85. }
  86. }
  87. }
  88. // try out
  89. if ((int)config('v2board.try_out_plan_id', 0)) {
  90. $plan = Plan::find(config('v2board.try_out_plan_id'));
  91. if ($plan) {
  92. $user->transfer_enable = $plan->transfer_enable * 1073741824;
  93. $user->plan_id = $plan->id;
  94. $user->group_id = $plan->group_id;
  95. $user->expired_at = time() + (config('v2board.try_out_hour', 1) * 3600);
  96. }
  97. }
  98. if (!$user->save()) {
  99. abort(500, __('Register failed'));
  100. }
  101. if ((int)config('v2board.email_verify', 0)) {
  102. Cache::forget(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email')));
  103. }
  104. $data = [
  105. 'token' => $user->token,
  106. 'auth_data' => base64_encode("{$user->email}:{$user->password}")
  107. ];
  108. $request->session()->put('email', $user->email);
  109. $request->session()->put('id', $user->id);
  110. $user->last_login_at = time();
  111. $user->save();
  112. Cache::put(CacheKey::get('REGISTER_IP_RATE_LIMIT', $request->ip()), $registerCountByIP + 1, 3600);
  113. return response()->json([
  114. 'data' => $data
  115. ]);
  116. }
  117. public function login(AuthLogin $request)
  118. {
  119. $email = $request->input('email');
  120. $password = $request->input('password');
  121. $user = User::where('email', $email)->first();
  122. if (!$user) {
  123. abort(500, __('Incorrect email or password'));
  124. }
  125. if (!Helper::multiPasswordVerify(
  126. $user->password_algo,
  127. $user->password_salt,
  128. $password,
  129. $user->password)
  130. ) {
  131. abort(500, __('Incorrect email or password'));
  132. }
  133. if ($user->banned) {
  134. abort(500, __('Your account has been suspended'));
  135. }
  136. $data = [
  137. 'token' => $user->token,
  138. 'auth_data' => base64_encode("{$user->email}:{$user->password}")
  139. ];
  140. $request->session()->put('email', $user->email);
  141. $request->session()->put('id', $user->id);
  142. if ($user->is_admin) {
  143. $request->session()->put('is_admin', true);
  144. $data['is_admin'] = true;
  145. }
  146. if ($user->is_staff) {
  147. $request->session()->put('is_staff', true);
  148. $data['is_staff'] = true;
  149. }
  150. return response([
  151. 'data' => $data
  152. ]);
  153. }
  154. public function token2Login(Request $request)
  155. {
  156. if ($request->input('token')) {
  157. $redirect = '/#/login?verify=' . $request->input('token') . '&redirect=' . ($request->input('redirect') ? $request->input('redirect') : 'dashboard');
  158. if (config('v2board.app_url')) {
  159. $location = config('v2board.app_url') . $redirect;
  160. } else {
  161. $location = url($redirect);
  162. }
  163. return redirect()->to($location)->send();
  164. }
  165. if ($request->input('verify')) {
  166. $key = CacheKey::get('TEMP_TOKEN', $request->input('verify'));
  167. $userId = Cache::get($key);
  168. if (!$userId) {
  169. abort(500, __('Token error'));
  170. }
  171. $user = User::find($userId);
  172. if (!$user) {
  173. abort(500, __('The user does not '));
  174. }
  175. if ($user->banned) {
  176. abort(500, __('Your account has been suspended'));
  177. }
  178. $request->session()->put('email', $user->email);
  179. $request->session()->put('id', $user->id);
  180. if ($user->is_admin) {
  181. $request->session()->put('is_admin', true);
  182. }
  183. Cache::forget($key);
  184. return response([
  185. 'data' => true
  186. ]);
  187. }
  188. }
  189. public function getTempToken(Request $request)
  190. {
  191. $user = User::where('token', $request->input('token'))->first();
  192. if (!$user) {
  193. abort(500, __('Token error'));
  194. }
  195. $code = Helper::guid();
  196. $key = CacheKey::get('TEMP_TOKEN', $code);
  197. Cache::put($key, $user->id, 60);
  198. return response([
  199. 'data' => $code
  200. ]);
  201. }
  202. public function getQuickLoginUrl(Request $request)
  203. {
  204. $authData = explode(':', base64_decode($request->input('auth_data')));
  205. if (!isset($authData[0])) abort(403, __('Token error'));
  206. $user = User::where('email', $authData[0])
  207. ->where('password', $authData[1])
  208. ->first();
  209. if (!$user) {
  210. abort(500, __('Token error'));
  211. }
  212. $code = Helper::guid();
  213. $key = CacheKey::get('TEMP_TOKEN', $code);
  214. Cache::put($key, $user->id, 60);
  215. $redirect = '/#/login?verify=' . $code . '&redirect=' . ($request->input('redirect') ? $request->input('redirect') : 'dashboard');
  216. if (config('v2board.app_url')) {
  217. $url = config('v2board.app_url') . $redirect;
  218. } else {
  219. $url = url($redirect);
  220. }
  221. return response([
  222. 'data' => $url
  223. ]);
  224. }
  225. public function check(Request $request)
  226. {
  227. $data = [
  228. 'is_login' => $request->session()->get('id') ? true : false
  229. ];
  230. if ($request->session()->get('is_admin')) {
  231. $data['is_admin'] = true;
  232. }
  233. return response([
  234. 'data' => $data
  235. ]);
  236. }
  237. public function forget(AuthForget $request)
  238. {
  239. if (Cache::get(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email'))) !== $request->input('email_code')) {
  240. abort(500, __('Incorrect email verification code'));
  241. }
  242. $user = User::where('email', $request->input('email'))->first();
  243. if (!$user) {
  244. abort(500, __('This email is not registered in the system'));
  245. }
  246. $user->password = password_hash($request->input('password'), PASSWORD_DEFAULT);
  247. $user->password_algo = NULL;
  248. $user->password_salt = NULL;
  249. if (!$user->save()) {
  250. abort(500, __('Reset failed'));
  251. }
  252. Cache::forget(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email')));
  253. return response([
  254. 'data' => true
  255. ]);
  256. }
  257. }