AuthController.php 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285
  1. <?php
  2. namespace App\Http\Controllers\Passport;
  3. use App\Http\Controllers\Controller;
  4. use App\Http\Requests\Passport\AuthRegister;
  5. use App\Http\Requests\Passport\AuthForget;
  6. use App\Http\Requests\Passport\AuthLogin;
  7. use Illuminate\Http\Request;
  8. use Illuminate\Support\Facades\Cache;
  9. use App\Models\Plan;
  10. use App\Models\User;
  11. use App\Models\InviteCode;
  12. use App\Utils\Helper;
  13. use App\Utils\Dict;
  14. use App\Utils\CacheKey;
  15. use ReCaptcha\ReCaptcha;
  16. class AuthController extends Controller
  17. {
  18. public function register(AuthRegister $request)
  19. {
  20. if ((int)config('v2board.register_limit_by_ip_enable', 0)) {
  21. $registerCountByIP = Cache::get(CacheKey::get('REGISTER_IP_RATE_LIMIT', $request->ip())) ?? 0;
  22. if ((int)$registerCountByIP >= (int)config('v2board.register_limit_count', 3)) {
  23. abort(500, __('Register frequently, please try again after 1 hour'));
  24. }
  25. }
  26. if ((int)config('v2board.recaptcha_enable', 0)) {
  27. $recaptcha = new ReCaptcha(config('v2board.recaptcha_key'));
  28. $recaptchaResp = $recaptcha->verify($request->input('recaptcha_data'));
  29. if (!$recaptchaResp->isSuccess()) {
  30. abort(500, __('Invalid code is incorrect'));
  31. }
  32. }
  33. if ((int)config('v2board.email_whitelist_enable', 0)) {
  34. if (!Helper::emailSuffixVerify(
  35. $request->input('email'),
  36. config('v2board.email_whitelist_suffix', Dict::EMAIL_WHITELIST_SUFFIX_DEFAULT))
  37. ) {
  38. abort(500, __('Email suffix is not in the Whitelist'));
  39. }
  40. }
  41. if ((int)config('v2board.email_gmail_limit_enable', 0)) {
  42. $prefix = explode('@', $request->input('email'))[0];
  43. if (strpos($prefix, '.') !== false || strpos($prefix, '+') !== false) {
  44. abort(500, __('Gmail alias is not supported'));
  45. }
  46. }
  47. if ((int)config('v2board.stop_register', 0)) {
  48. abort(500, __('Registration has closed'));
  49. }
  50. if ((int)config('v2board.invite_force', 0)) {
  51. if (empty($request->input('invite_code'))) {
  52. abort(500, __('You must use the invitation code to register'));
  53. }
  54. }
  55. if ((int)config('v2board.email_verify', 0)) {
  56. if (empty($request->input('email_code'))) {
  57. abort(500, __('Email verification code cannot be empty'));
  58. }
  59. if (Cache::get(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email'))) !== $request->input('email_code')) {
  60. abort(500, __('Incorrect email verification code'));
  61. }
  62. }
  63. $email = $request->input('email');
  64. $password = $request->input('password');
  65. $exist = User::where('email', $email)->first();
  66. if ($exist) {
  67. abort(500, __('Email already exists'));
  68. }
  69. $user = new User();
  70. $user->email = $email;
  71. $user->password = password_hash($password, PASSWORD_DEFAULT);
  72. $user->uuid = Helper::guid(true);
  73. $user->token = Helper::guid();
  74. if ($request->input('invite_code')) {
  75. $inviteCode = InviteCode::where('code', $request->input('invite_code'))
  76. ->where('status', 0)
  77. ->first();
  78. if (!$inviteCode) {
  79. if ((int)config('v2board.invite_force', 0)) {
  80. abort(500, __('Invalid invitation code'));
  81. }
  82. } else {
  83. $user->invite_user_id = $inviteCode->user_id ? $inviteCode->user_id : null;
  84. if (!(int)config('v2board.invite_never_expire', 0)) {
  85. $inviteCode->status = 1;
  86. $inviteCode->save();
  87. }
  88. }
  89. }
  90. // try out
  91. if ((int)config('v2board.try_out_plan_id', 0)) {
  92. $plan = Plan::find(config('v2board.try_out_plan_id'));
  93. if ($plan) {
  94. $user->transfer_enable = $plan->transfer_enable * 1073741824;
  95. $user->plan_id = $plan->id;
  96. $user->group_id = $plan->group_id;
  97. $user->expired_at = time() + (config('v2board.try_out_hour', 1) * 3600);
  98. }
  99. }
  100. if (!$user->save()) {
  101. abort(500, __('Register failed'));
  102. }
  103. if ((int)config('v2board.email_verify', 0)) {
  104. Cache::forget(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email')));
  105. }
  106. $data = [
  107. 'token' => $user->token,
  108. 'auth_data' => base64_encode("{$user->email}:{$user->password}")
  109. ];
  110. $request->session()->put('email', $user->email);
  111. $request->session()->put('id', $user->id);
  112. $user->last_login_at = time();
  113. $user->save();
  114. if ((int)config('v2board.register_limit_by_ip_enable', 0)) {
  115. Cache::put(
  116. CacheKey::get('REGISTER_IP_RATE_LIMIT', $request->ip()),
  117. (int)$registerCountByIP + 1,
  118. (int)config('v2board.register_limit_expire', 60) * 60
  119. );
  120. }
  121. return response()->json([
  122. 'data' => $data
  123. ]);
  124. }
  125. public function login(AuthLogin $request)
  126. {
  127. $email = $request->input('email');
  128. $password = $request->input('password');
  129. $user = User::where('email', $email)->first();
  130. if (!$user) {
  131. abort(500, __('Incorrect email or password'));
  132. }
  133. if (!Helper::multiPasswordVerify(
  134. $user->password_algo,
  135. $user->password_salt,
  136. $password,
  137. $user->password)
  138. ) {
  139. abort(500, __('Incorrect email or password'));
  140. }
  141. if ($user->banned) {
  142. abort(500, __('Your account has been suspended'));
  143. }
  144. $data = [
  145. 'token' => $user->token,
  146. 'auth_data' => base64_encode("{$user->email}:{$user->password}")
  147. ];
  148. $request->session()->put('email', $user->email);
  149. $request->session()->put('id', $user->id);
  150. if ($user->is_admin) {
  151. $request->session()->put('is_admin', true);
  152. $data['is_admin'] = true;
  153. }
  154. if ($user->is_staff) {
  155. $request->session()->put('is_staff', true);
  156. $data['is_staff'] = true;
  157. }
  158. return response([
  159. 'data' => $data
  160. ]);
  161. }
  162. public function token2Login(Request $request)
  163. {
  164. if ($request->input('token')) {
  165. $redirect = '/#/login?verify=' . $request->input('token') . '&redirect=' . ($request->input('redirect') ? $request->input('redirect') : 'dashboard');
  166. if (config('v2board.app_url')) {
  167. $location = config('v2board.app_url') . $redirect;
  168. } else {
  169. $location = url($redirect);
  170. }
  171. return redirect()->to($location)->send();
  172. }
  173. if ($request->input('verify')) {
  174. $key = CacheKey::get('TEMP_TOKEN', $request->input('verify'));
  175. $userId = Cache::get($key);
  176. if (!$userId) {
  177. abort(500, __('Token error'));
  178. }
  179. $user = User::find($userId);
  180. if (!$user) {
  181. abort(500, __('The user does not '));
  182. }
  183. if ($user->banned) {
  184. abort(500, __('Your account has been suspended'));
  185. }
  186. $request->session()->put('email', $user->email);
  187. $request->session()->put('id', $user->id);
  188. if ($user->is_admin) {
  189. $request->session()->put('is_admin', true);
  190. }
  191. Cache::forget($key);
  192. return response([
  193. 'data' => true
  194. ]);
  195. }
  196. }
  197. public function getTempToken(Request $request)
  198. {
  199. $user = User::where('token', $request->input('token'))->first();
  200. if (!$user) {
  201. abort(500, __('Token error'));
  202. }
  203. $code = Helper::guid();
  204. $key = CacheKey::get('TEMP_TOKEN', $code);
  205. Cache::put($key, $user->id, 60);
  206. return response([
  207. 'data' => $code
  208. ]);
  209. }
  210. public function getQuickLoginUrl(Request $request)
  211. {
  212. $authData = explode(':', base64_decode($request->input('auth_data')));
  213. if (!isset($authData[0])) abort(403, __('Token error'));
  214. $user = User::where('email', $authData[0])
  215. ->where('password', $authData[1])
  216. ->first();
  217. if (!$user) {
  218. abort(500, __('Token error'));
  219. }
  220. $code = Helper::guid();
  221. $key = CacheKey::get('TEMP_TOKEN', $code);
  222. Cache::put($key, $user->id, 60);
  223. $redirect = '/#/login?verify=' . $code . '&redirect=' . ($request->input('redirect') ? $request->input('redirect') : 'dashboard');
  224. if (config('v2board.app_url')) {
  225. $url = config('v2board.app_url') . $redirect;
  226. } else {
  227. $url = url($redirect);
  228. }
  229. return response([
  230. 'data' => $url
  231. ]);
  232. }
  233. public function check(Request $request)
  234. {
  235. $data = [
  236. 'is_login' => $request->session()->get('id') ? true : false
  237. ];
  238. if ($request->session()->get('is_admin')) {
  239. $data['is_admin'] = true;
  240. }
  241. return response([
  242. 'data' => $data
  243. ]);
  244. }
  245. public function forget(AuthForget $request)
  246. {
  247. if (Cache::get(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email'))) !== $request->input('email_code')) {
  248. abort(500, __('Incorrect email verification code'));
  249. }
  250. $user = User::where('email', $request->input('email'))->first();
  251. if (!$user) {
  252. abort(500, __('This email is not registered in the system'));
  253. }
  254. $user->password = password_hash($request->input('password'), PASSWORD_DEFAULT);
  255. $user->password_algo = NULL;
  256. $user->password_salt = NULL;
  257. if (!$user->save()) {
  258. abort(500, __('Reset failed'));
  259. }
  260. Cache::forget(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email')));
  261. return response([
  262. 'data' => true
  263. ]);
  264. }
  265. }