blessing-skin-server/app/Http/Controllers/AuthController.php

247 lines
7.8 KiB
PHP
Raw Normal View History

2016-07-21 22:01:57 +08:00
<?php
2016-08-28 10:05:21 +08:00
namespace App\Http\Controllers;
2016-07-21 22:01:57 +08:00
use Mail;
use View;
2016-08-06 19:38:37 +08:00
use Utils;
2016-07-21 22:01:57 +08:00
use Option;
2016-08-28 10:05:21 +08:00
use Session;
use App\Models\User;
use App\Models\UserModel;
use Illuminate\Http\Request;
use App\Exceptions\PrettyPageException;
2016-07-21 22:01:57 +08:00
2016-09-03 23:50:55 +08:00
class AuthController extends Controller
2016-07-21 22:01:57 +08:00
{
public function login()
{
2016-08-28 10:05:21 +08:00
return view('auth.login');
2016-07-21 22:01:57 +08:00
}
2016-09-03 23:50:55 +08:00
public function handleLogin(Request $request)
2016-07-21 22:01:57 +08:00
{
2016-09-03 23:50:55 +08:00
$this->validate($request, [
'email' => 'sometimes|required|email',
'username' => 'sometimes|required|username',
'password' => 'required|min:8|max:16'
]);
if ($request->has('email')) {
$auth_type = "email";
} elseif ($request->has('username')) {
$auth_type = "username";
} else {
View::json('邮箱或角色名格式错误', 3);
}
2016-08-16 13:27:06 +08:00
// instantiate user
2016-09-03 23:50:55 +08:00
$user = ($auth_type == 'email') ?
new User(null, ['email' => $request->input('email')]) :
new User(null, ['username' => $request->input('username')]);
2016-07-21 22:01:57 +08:00
2016-08-28 10:05:21 +08:00
if (session('login_fails', 0) > 3) {
2016-09-03 23:50:55 +08:00
if (strtolower($request->input('captcha')) != strtolower(session('phrase')))
2016-07-21 22:01:57 +08:00
View::json('验证码填写错误', 1);
}
if (!$user->is_registered) {
View::json('用户不存在哦', 2);
} else {
2016-09-03 23:50:55 +08:00
if ($user->checkPasswd($request->input('password'))) {
Session::forget('login_fails');
2016-07-21 22:01:57 +08:00
2016-08-28 10:05:21 +08:00
Session::put('uid' , $user->uid);
Session::put('token', $user->getToken());
2016-07-21 22:01:57 +08:00
2016-09-03 23:50:55 +08:00
$time = $request->input('keep') == true ? 86400 : 3600;
setcookie('uid', $user->uid, time()+$time, '/');
setcookie('token', $user->getToken(), time()+$time, '/');
2016-07-21 22:01:57 +08:00
2016-08-16 13:27:06 +08:00
View::json([
2016-07-21 22:01:57 +08:00
'errno' => 0,
'msg' => '登录成功,欢迎回来~',
'token' => $user->getToken()
]);
} else {
2016-09-03 23:50:55 +08:00
$fails = session('login_fails', 0);
Session::put('login_fails', $fails + 1);
2016-08-16 13:27:06 +08:00
2016-07-21 22:01:57 +08:00
View::json([
'errno' => 1,
'msg' => '邮箱或密码不对哦~',
2016-08-28 10:05:21 +08:00
'login_fails' => session('login_fails')
2016-07-21 22:01:57 +08:00
]);
}
}
}
public function logout()
{
2016-08-28 10:05:21 +08:00
if (Session::has('token')) {
setcookie('uid', '', time() - 3600, '/');
setcookie('token', '', time() - 3600, '/');
2016-08-16 13:27:06 +08:00
2016-08-28 10:05:21 +08:00
Session::flush();
2016-07-21 22:01:57 +08:00
View::json('登出成功~', 0);
} else {
View::json('并没有有效的 session', 1);
2016-07-21 22:01:57 +08:00
}
}
public function register()
{
if (Option::get('user_can_register') == 1) {
2016-08-28 10:05:21 +08:00
return view('auth.register');
} else {
throw new PrettyPageException('残念。。本皮肤站已经关闭注册咯 QAQ', 7);
}
2016-07-21 22:01:57 +08:00
}
2016-09-03 23:50:55 +08:00
public function handleRegister(Request $request)
2016-07-21 22:01:57 +08:00
{
2016-09-03 23:50:55 +08:00
if (strtolower($request->input('captcha')) != strtolower(session('phrase')))
2016-07-21 22:01:57 +08:00
View::json('验证码填写错误', 1);
2016-09-03 23:50:55 +08:00
$this->validate($request, [
'email' => 'required|email',
'password' => 'required|min:8|max:16',
'nickname' => 'required|nickname|max:255'
]);
$user = new User(null, ['email' => $request->input('email')]);
2016-07-21 22:01:57 +08:00
if (!$user->is_registered) {
if (Option::get('user_can_register') == 1) {
2016-09-03 23:50:55 +08:00
$ip = get_real_ip();
// If amount of registered accounts of IP is more than allowed amounts,
// then reject the register.
if (UserModel::where('ip', $ip)->count() < Option::get('regs_per_ip'))
{
// register new user
$user = $user->register($request->input('password'), $ip);
$user->setNickName($request->input('nickname'));
// set cookies
setcookie('uid', $user->uid, time() + 3600, '/');
setcookie('token', $user->getToken(), time() + 3600, '/');
View::json([
'errno' => 0,
'msg' => '注册成功,正在跳转~',
'token' => $user->getToken()
]);
} else {
View::json('你最多只能注册 '.Option::get('regs_per_ip').' 个账户哦', 7);
2016-07-21 22:01:57 +08:00
}
} else {
View::json('残念。。本皮肤站已经关闭注册咯 QAQ', 7);
}
} else {
View::json('这个邮箱已经注册过啦,换一个吧', 5);
}
}
public function forgot()
{
2016-09-03 23:50:55 +08:00
if (config('mail.host') != "") {
2016-08-28 10:05:21 +08:00
return view('auth.forgot');
} else {
throw new PrettyPageException('本站已关闭重置密码功能', 8);
}
2016-07-21 22:01:57 +08:00
}
2016-09-03 23:50:55 +08:00
public function handleForgot(Request $request)
2016-07-21 22:01:57 +08:00
{
2016-09-03 23:50:55 +08:00
if (strtolower($request->input('captcha')) != strtolower(session('phrase')))
2016-07-21 22:01:57 +08:00
View::json('验证码填写错误', 1);
2016-09-03 23:50:55 +08:00
if (config('mail.host') == "")
View::json('本站已关闭重置密码功能', 1);
2016-09-04 16:15:11 +08:00
if (Session::has('last_mail_time') && (time() - session('last_mail_time')) < 60)
2016-07-21 22:01:57 +08:00
View::json('你邮件发送得太频繁啦,过 60 秒后再点发送吧', 1);
2016-09-03 23:50:55 +08:00
$user = new User(null, ['email' => $request->input('email')]);
2016-07-21 22:01:57 +08:00
if (!$user->is_registered)
View::json('该邮箱尚未注册', 1);
2016-08-16 13:27:06 +08:00
$uid = $user->uid;
2016-08-06 19:38:37 +08:00
$token = base64_encode($user->getToken().substr(time(), 4, 6).Utils::generateRndString(16));
2016-07-21 22:01:57 +08:00
2016-08-16 13:27:06 +08:00
$url = Option::get('site_url')."/auth/reset?uid=$uid&token=$token";
2016-09-04 16:15:11 +08:00
try {
Mail::send('auth.mail', ['reset_url' => $url], function ($m) use ($request) {
$site_name = Option::get('site_name');
2016-07-21 22:01:57 +08:00
2016-09-04 16:15:11 +08:00
$m->from(config('mail.username'), $site_name);
$m->to($request->input('email'))->subject("重置您在 $site_name 上的账户密码");
});
} catch(\Exception $e) {
View::json('邮件发送失败,详细信息:'.$e->getMessage(), 2);
2016-07-21 22:01:57 +08:00
}
2016-09-04 16:15:11 +08:00
Session::put('last_mail_time', time());
View::json('邮件已发送,一小时内有效,请注意查收.', 0);
2016-07-21 22:01:57 +08:00
}
public function reset()
{
if (isset($_GET['uid']) && isset($_GET['token'])) {
2016-08-16 13:27:06 +08:00
$user = new User($_GET['uid']);
2016-07-21 22:01:57 +08:00
if (!$user->is_registered)
2016-08-29 23:08:09 +08:00
return redirect('auth/forgot')->with('msg', '无效的链接');
2016-07-21 22:01:57 +08:00
$token = substr(base64_decode($_GET['token']), 0, -22);
if ($user->getToken() != $token) {
2016-08-29 23:08:09 +08:00
return redirect('auth/forgot')->with('msg', '无效的链接');
2016-07-21 22:01:57 +08:00
}
$timestamp = substr(base64_decode($_GET['token']), strlen($token), 6);
// more than 1 hour
if ((substr(time(), 4, 6) - $timestamp) > 3600) {
2016-08-29 23:08:09 +08:00
return redirect('auth/forgot')->with('msg', '链接已过期');
2016-07-21 22:01:57 +08:00
}
2016-09-04 16:15:11 +08:00
return view('auth.reset')->with('user', $user);
2016-07-21 22:01:57 +08:00
} else {
2016-08-29 23:08:09 +08:00
return redirect('auth/login')->with('msg', '非法访问');
2016-07-21 22:01:57 +08:00
}
}
2016-09-03 23:50:55 +08:00
public function handleReset(Request $request)
2016-07-21 22:01:57 +08:00
{
2016-09-03 23:50:55 +08:00
$this->validate($request, [
'uid' => 'required|integer',
'password' => 'required|min:8|max:16',
]);
2016-07-21 22:01:57 +08:00
2016-09-03 23:50:55 +08:00
$user = new User($request->input('uid'));
2016-07-21 22:01:57 +08:00
2016-09-03 23:50:55 +08:00
$user->changePasswd($request->input('password'));
2016-07-21 22:01:57 +08:00
2016-09-03 23:50:55 +08:00
View::json('密码重置成功', 0);
2016-07-21 22:01:57 +08:00
}
public function captcha()
{
$builder = new \Gregwar\Captcha\CaptchaBuilder;
$builder->build($width = 100, $height = 34);
2016-08-28 10:05:21 +08:00
Session::put('phrase', $builder->getPhrase());
2016-07-21 22:01:57 +08:00
$builder->output();
2016-08-29 23:08:09 +08:00
return \Response::png();
2016-07-21 22:01:57 +08:00
}
}