AuthController.php 8.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258
  1. <?php
  2. namespace App\Http\Controllers\Passport;
  3. use App\Http\Controllers\Controller;
  4. use App\Http\Requests\Passport\AuthRegister;
  5. use App\Http\Requests\Passport\AuthForget;
  6. use App\Http\Requests\Passport\AuthLogin;
  7. use Illuminate\Http\Request;
  8. use Illuminate\Support\Facades\Cache;
  9. use App\Models\Plan;
  10. use App\Models\User;
  11. use App\Models\InviteCode;
  12. use App\Utils\Helper;
  13. use App\Utils\Dict;
  14. use App\Utils\CacheKey;
  15. use ReCaptcha\ReCaptcha;
  16. class AuthController extends Controller
  17. {
  18. public function register(AuthRegister $request)
  19. {
  20. abort(500, __('passport.auth.register.verify_incorrect'));
  21. if ((int)config('v2board.recaptcha_enable', 0)) {
  22. $recaptcha = new ReCaptcha(config('v2board.recaptcha_key'));
  23. $recaptchaResp = $recaptcha->verify($request->input('recaptcha_data'));
  24. if (!$recaptchaResp->isSuccess()) {
  25. abort(500, '验证码有误');
  26. }
  27. }
  28. if ((int)config('v2board.email_whitelist_enable', 0)) {
  29. if (!Helper::emailSuffixVerify(
  30. $request->input('email'),
  31. config('v2board.email_whitelist_suffix', Dict::EMAIL_WHITELIST_SUFFIX_DEFAULT))
  32. ) {
  33. abort(500, '邮箱后缀不处于白名单中');
  34. }
  35. }
  36. if ((int)config('v2board.email_gmail_limit_enable', 0)) {
  37. $prefix = explode('@', $request->input('email'))[0];
  38. if (strpos($prefix, '.') !== false || strpos($prefix, '+') !== false) {
  39. abort(500, '不支持Gmail别名邮箱');
  40. }
  41. }
  42. if ((int)config('v2board.stop_register', 0)) {
  43. abort(500, '本站已关闭注册');
  44. }
  45. if ((int)config('v2board.invite_force', 0)) {
  46. if (empty($request->input('invite_code'))) {
  47. abort(500, '必须使用邀请码才可以注册');
  48. }
  49. }
  50. if ((int)config('v2board.email_verify', 0)) {
  51. if (empty($request->input('email_code'))) {
  52. abort(500, '邮箱验证码不能为空');
  53. }
  54. if (Cache::get(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email'))) !== $request->input('email_code')) {
  55. abort(500, '邮箱验证码有误');
  56. }
  57. }
  58. $email = $request->input('email');
  59. $password = $request->input('password');
  60. $exist = User::where('email', $email)->first();
  61. if ($exist) {
  62. abort(500, '邮箱已存在系统中');
  63. }
  64. $user = new User();
  65. $user->email = $email;
  66. $user->password = password_hash($password, PASSWORD_DEFAULT);
  67. $user->uuid = Helper::guid(true);
  68. $user->token = Helper::guid();
  69. if ($request->input('invite_code')) {
  70. $inviteCode = InviteCode::where('code', $request->input('invite_code'))
  71. ->where('status', 0)
  72. ->first();
  73. if (!$inviteCode) {
  74. if ((int)config('v2board.invite_force', 0)) {
  75. abort(500, '邀请码无效');
  76. }
  77. } else {
  78. $user->invite_user_id = $inviteCode->user_id ? $inviteCode->user_id : null;
  79. if (!(int)config('v2board.invite_never_expire', 0)) {
  80. $inviteCode->status = 1;
  81. $inviteCode->save();
  82. }
  83. }
  84. }
  85. // try out
  86. if ((int)config('v2board.try_out_plan_id', 0)) {
  87. $plan = Plan::find(config('v2board.try_out_plan_id'));
  88. if ($plan) {
  89. $user->transfer_enable = $plan->transfer_enable * 1073741824;
  90. $user->plan_id = $plan->id;
  91. $user->group_id = $plan->group_id;
  92. $user->expired_at = time() + (config('v2board.try_out_hour', 1) * 3600);
  93. }
  94. }
  95. if (!$user->save()) {
  96. abort(500, '注册失败');
  97. }
  98. if ((int)config('v2board.email_verify', 0)) {
  99. Cache::forget(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email')));
  100. }
  101. $request->session()->put('email', $user->email);
  102. $request->session()->put('id', $user->id);
  103. return response()->json([
  104. 'data' => true
  105. ]);
  106. }
  107. public function login(AuthLogin $request)
  108. {
  109. $email = $request->input('email');
  110. $password = $request->input('password');
  111. $user = User::where('email', $email)->first();
  112. if (!$user) {
  113. abort(500, '用户名或密码错误');
  114. }
  115. if (!Helper::multiPasswordVerify(
  116. $user->password_algo,
  117. $password,
  118. $user->password)
  119. ) {
  120. abort(500, '用户名或密码错误');
  121. }
  122. if ($user->banned) {
  123. abort(500, '该账户已被停止使用');
  124. }
  125. $data = [
  126. 'token' => $user->token
  127. ];
  128. $request->session()->put('email', $user->email);
  129. $request->session()->put('id', $user->id);
  130. if ($user->is_admin) {
  131. $request->session()->put('is_admin', true);
  132. $data['is_admin'] = true;
  133. }
  134. if ($user->is_staff) {
  135. $request->session()->put('is_staff', true);
  136. $data['is_staff'] = true;
  137. }
  138. return response([
  139. 'data' => $data
  140. ]);
  141. }
  142. public function token2Login(Request $request)
  143. {
  144. if ($request->input('token')) {
  145. $redirect = '/#/login?verify=' . $request->input('token') . '&redirect=' . ($request->input('redirect') ? $request->input('redirect') : 'dashboard');
  146. if (config('v2board.app_url')) {
  147. $location = config('v2board.app_url') . $redirect;
  148. } else {
  149. $location = url($redirect);
  150. }
  151. return redirect()->to($location)->send();
  152. }
  153. if ($request->input('verify')) {
  154. $key = CacheKey::get('TEMP_TOKEN', $request->input('verify'));
  155. $userId = Cache::get($key);
  156. if (!$userId) {
  157. abort(500, '令牌有误');
  158. }
  159. $user = User::find($userId);
  160. if (!$user) {
  161. abort(500, '用户不存在');
  162. }
  163. if ($user->banned) {
  164. abort(500, '该账户已被停止使用');
  165. }
  166. $request->session()->put('email', $user->email);
  167. $request->session()->put('id', $user->id);
  168. if ($user->is_admin) {
  169. $request->session()->put('is_admin', true);
  170. }
  171. Cache::forget($key);
  172. return response([
  173. 'data' => true
  174. ]);
  175. }
  176. }
  177. public function getTempToken(Request $request)
  178. {
  179. $user = User::where('token', $request->input('token'))->first();
  180. if (!$user) {
  181. abort(500, '令牌有误');
  182. }
  183. $code = Helper::guid();
  184. $key = CacheKey::get('TEMP_TOKEN', $code);
  185. Cache::put($key, $user->id, 60);
  186. return response([
  187. 'data' => $code
  188. ]);
  189. }
  190. public function getQuickLoginUrl(Request $request)
  191. {
  192. $user = User::where('token', $request->input('token'))->first();
  193. if (!$user) {
  194. abort(500, '令牌有误');
  195. }
  196. $code = Helper::guid();
  197. $key = CacheKey::get('TEMP_TOKEN', $code);
  198. Cache::put($key, $user->id, 60);
  199. $redirect = '/#/login?verify=' . $code . '&redirect=' . ($request->input('redirect') ? $request->input('redirect') : 'dashboard');
  200. if (config('v2board.app_url')) {
  201. $url = config('v2board.app_url') . $redirect;
  202. } else {
  203. $url = url($redirect);
  204. }
  205. return response([
  206. 'data' => $url
  207. ]);
  208. }
  209. public function check(Request $request)
  210. {
  211. $data = [
  212. 'is_login' => $request->session()->get('id') ? true : false
  213. ];
  214. if ($request->session()->get('is_admin')) {
  215. $data['is_admin'] = true;
  216. }
  217. return response([
  218. 'data' => $data
  219. ]);
  220. }
  221. public function forget(AuthForget $request)
  222. {
  223. if (Cache::get(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email'))) !== $request->input('email_code')) {
  224. abort(500, '邮箱验证码有误');
  225. }
  226. $user = User::where('email', $request->input('email'))->first();
  227. if (!$user) {
  228. abort(500, '该邮箱不存在系统中');
  229. }
  230. $user->password = password_hash($request->input('password'), PASSWORD_DEFAULT);
  231. $user->password_algo = NULL;
  232. if (!$user->save()) {
  233. abort(500, '重置失败');
  234. }
  235. Cache::forget(CacheKey::get('EMAIL_VERIFY_CODE', $request->input('email')));
  236. return response([
  237. 'data' => true
  238. ]);
  239. }
  240. }