AuthController.php 6.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184
  1. <?php
  2. namespace App\Http\Controllers\Passport;
  3. use App\Http\Controllers\Controller;
  4. use App\Http\Requests\Passport\AuthRegister;
  5. use App\Http\Requests\Passport\AuthForget;
  6. use App\Http\Requests\Passport\AuthLogin;
  7. use Illuminate\Http\Request;
  8. use Illuminate\Support\Facades\Mail;
  9. use Illuminate\Support\Facades\Cache;
  10. use App\Models\User;
  11. use App\Models\InviteCode;
  12. use App\Utils\Helper;
  13. class AuthController extends Controller
  14. {
  15. public function register(AuthRegister $request)
  16. {
  17. if ((int)config('v2board.stop_register', 0)) {
  18. abort(500, '本站已关闭注册');
  19. }
  20. if ((int)config('v2board.invite_force', 0)) {
  21. if (empty($request->input('invite_code'))) {
  22. abort(500, '必须使用邀请码才可以注册');
  23. }
  24. }
  25. if ((int)config('v2board.email_verify', 0)) {
  26. $redisKey = 'sendEmailVerify:' . $request->input('email');
  27. if (empty($request->input('email_code'))) {
  28. abort(500, '邮箱验证码不能为空');
  29. }
  30. if (Cache::get($redisKey) !== $request->input('email_code')) {
  31. abort(500, '邮箱验证码有误');
  32. }
  33. }
  34. $email = $request->input('email');
  35. $password = $request->input('password');
  36. $exist = User::where('email', $email)->first();
  37. if ($exist) {
  38. abort(500, '邮箱已存在系统中');
  39. }
  40. $user = new User();
  41. $user->email = $email;
  42. $user->password = password_hash($password, PASSWORD_DEFAULT);
  43. $user->v2ray_uuid = Helper::guid(true);
  44. $user->token = Helper::guid();
  45. if ($request->input('invite_code')) {
  46. $inviteCode = InviteCode::where('code', $request->input('invite_code'))
  47. ->where('status', 0)
  48. ->first();
  49. if (!$inviteCode) {
  50. if ((int)config('v2board.invite_force', 0)) {
  51. abort(500, '邀请码无效');
  52. }
  53. } else {
  54. $user->invite_user_id = $inviteCode->user_id ? $inviteCode->user_id : null;
  55. if (!(int)config('v2board.invite_never_expire', env('V2BOARD_INVITE_NEVER_EXPIRE'))) {
  56. $inviteCode->status = 1;
  57. $inviteCode->save();
  58. }
  59. }
  60. }
  61. // try out
  62. if ((int)config('v2board.try_out_enable', 0)) {
  63. $plan = Plan::find(config('v2board.try_out_plan_id'));
  64. if ($plan) {
  65. $user->transfer_enable = $plan->transfer_enable * 1073741824;
  66. $user->plan_id = $plan->id;
  67. $user->group_id = $plan->group_id;
  68. $user->expired_at = time() + (config('v2board.try_out_hour', 1) * 3600);
  69. }
  70. }
  71. if (!$user->save()) {
  72. abort(500, '注册失败');
  73. }
  74. if ((int)config('v2board.email_verify', 0)) {
  75. Cache::forget($redisKey);
  76. }
  77. return response()->json([
  78. 'data' => true
  79. ]);
  80. }
  81. public function login(AuthLogin $request)
  82. {
  83. $email = $request->input('email');
  84. $password = $request->input('password');
  85. $user = User::where('email', $email)->first();
  86. if (!$user) {
  87. abort(500, '用户名或密码错误');
  88. }
  89. if (!password_verify($password, $user->password)) {
  90. abort(500, '用户名或密码错误');
  91. }
  92. if ($user->banned) {
  93. abort(500, '该账户已被停止使用');
  94. }
  95. $request->session()->put('email', $user->email);
  96. $request->session()->put('id', $user->id);
  97. if ($user->is_admin) {
  98. $request->session()->put('is_admin', true);
  99. }
  100. return response([
  101. 'data' => [
  102. 'is_admin' => $user->is_admin ? 2 : 1,
  103. 'token' => $user->token
  104. ]
  105. ]);
  106. }
  107. public function token2Login(Request $request)
  108. {
  109. if ($request->input('token')) {
  110. $user = User::where('token', $request->input('token'))->first();
  111. if (!$user) {
  112. return header('Location:' . config('v2board.app_url'));
  113. }
  114. $code = Helper::guid();
  115. $key = 'token2Login_' . $code;
  116. Cache::put($key, $user->id, 600);
  117. $redirect = '/#/login?verify=' . $code . '&redirect=' . ($request->input('redirect') ? $request->input('redirect') : 'dashboard');
  118. if (config('v2board.app_url')) {
  119. $location = config('v2board.app_url') . $redirect;
  120. } else {
  121. $location = url($redirect);
  122. }
  123. return header('Location:' . $location);
  124. }
  125. if ($request->input('verify')) {
  126. $key = 'token2Login_' . $request->input('verify');
  127. $userId = Cache::get($key);
  128. if (!$userId) {
  129. abort(500, '令牌有误');
  130. }
  131. $user = User::find($userId);
  132. if (!$user) {
  133. abort(500, '用户不存在');
  134. }
  135. if ($user->banned) {
  136. abort(500, '该账户已被停止使用');
  137. }
  138. $request->session()->put('email', $user->email);
  139. $request->session()->put('id', $user->id);
  140. if ($user->is_admin) {
  141. $request->session()->put('is_admin', true);
  142. }
  143. Cache::forget($key);
  144. return response([
  145. 'data' => true
  146. ]);
  147. }
  148. }
  149. public function check(Request $request)
  150. {
  151. return response([
  152. 'data' => $request->session()->get('id') ? true : false
  153. ]);
  154. }
  155. public function forget(AuthForget $request)
  156. {
  157. $redisKey = 'sendEmailVerify:' . $request->input('email');
  158. if (Cache::get($redisKey) !== $request->input('email_code')) {
  159. abort(500, '邮箱验证码有误');
  160. }
  161. $user = User::where('email', $request->input('email'))->first();
  162. $user->password = password_hash($request->input('password'), PASSWORD_DEFAULT);
  163. if (!$user->save()) {
  164. abort(500, '重置失败');
  165. }
  166. Cache::forget($redisKey);
  167. return response([
  168. 'data' => true
  169. ]);
  170. }
  171. }