2016-07-21 22:01:57 +08:00
|
|
|
<?php
|
|
|
|
|
2016-08-28 10:05:21 +08:00
|
|
|
namespace App\Http\Controllers;
|
2016-07-21 22:01:57 +08:00
|
|
|
|
2016-11-17 17:32:12 +08:00
|
|
|
use App\Events;
|
2019-12-14 11:10:37 +08:00
|
|
|
use App\Exceptions\PrettyPageException;
|
|
|
|
use App\Mail\ForgotPassword;
|
2018-08-17 17:03:38 +08:00
|
|
|
use App\Models\Player;
|
2019-12-14 11:10:37 +08:00
|
|
|
use App\Models\User;
|
2019-03-24 09:58:37 +08:00
|
|
|
use App\Rules\Captcha;
|
2019-12-14 11:10:37 +08:00
|
|
|
use Auth;
|
|
|
|
use Cache;
|
2016-09-04 15:35:12 +08:00
|
|
|
use Illuminate\Http\Request;
|
2019-12-15 11:19:10 +08:00
|
|
|
use Laravel\Socialite\Facades\Socialite;
|
2019-12-14 11:10:37 +08:00
|
|
|
use Mail;
|
|
|
|
use Session;
|
|
|
|
use URL;
|
|
|
|
use View;
|
2016-07-21 22:01:57 +08:00
|
|
|
|
2016-09-03 23:50:55 +08:00
|
|
|
class AuthController extends Controller
|
2016-07-21 22:01:57 +08:00
|
|
|
{
|
2019-09-18 23:06:48 +08:00
|
|
|
public function login()
|
|
|
|
{
|
|
|
|
return view('auth.login', [
|
|
|
|
'extra' => [
|
|
|
|
'tooManyFails' => cache(sha1('login_fails_'.get_client_ip())) > 3,
|
|
|
|
'recaptcha' => option('recaptcha_sitekey'),
|
|
|
|
'invisible' => (bool) option('recaptcha_invisible'),
|
|
|
|
],
|
|
|
|
]);
|
|
|
|
}
|
|
|
|
|
2019-09-07 11:15:23 +08:00
|
|
|
public function handleLogin(Request $request, Captcha $captcha)
|
2016-07-21 22:01:57 +08:00
|
|
|
{
|
2016-09-03 23:50:55 +08:00
|
|
|
$this->validate($request, [
|
2016-10-02 20:30:27 +08:00
|
|
|
'identification' => 'required',
|
2019-12-14 11:10:37 +08:00
|
|
|
'password' => 'required|min:6|max:32',
|
2016-09-03 23:50:55 +08:00
|
|
|
]);
|
|
|
|
|
2016-10-02 20:30:27 +08:00
|
|
|
$identification = $request->input('identification');
|
|
|
|
|
2018-02-16 17:31:04 +08:00
|
|
|
// Guess type of identification
|
2019-03-23 11:06:36 +08:00
|
|
|
$authType = filter_var($identification, FILTER_VALIDATE_EMAIL) ? 'email' : 'username';
|
2016-09-03 23:50:55 +08:00
|
|
|
|
2018-02-16 17:31:04 +08:00
|
|
|
event(new Events\UserTryToLogin($identification, $authType));
|
2016-10-17 17:51:51 +08:00
|
|
|
|
2019-03-23 11:06:36 +08:00
|
|
|
if ($authType == 'email') {
|
2019-08-24 10:22:26 +08:00
|
|
|
$user = User::where('email', $identification)->first();
|
2019-03-23 11:06:36 +08:00
|
|
|
} else {
|
|
|
|
$player = Player::where('name', $identification)->first();
|
|
|
|
$user = $player ? $player->user : null;
|
|
|
|
}
|
2016-07-21 22:01:57 +08:00
|
|
|
|
2018-08-16 17:57:24 +08:00
|
|
|
// Require CAPTCHA if user fails to login more than 3 times
|
2018-08-17 22:54:26 +08:00
|
|
|
$loginFailsCacheKey = sha1('login_fails_'.get_client_ip());
|
2018-08-16 17:57:24 +08:00
|
|
|
$loginFails = (int) Cache::get($loginFailsCacheKey, 0);
|
|
|
|
|
|
|
|
if ($loginFails > 3) {
|
2019-04-04 11:04:13 +08:00
|
|
|
$this->validate($request, ['captcha' => ['required', $captcha]]);
|
2016-07-21 22:01:57 +08:00
|
|
|
}
|
|
|
|
|
2019-12-14 11:10:37 +08:00
|
|
|
if (!$user) {
|
2016-09-15 09:20:02 +08:00
|
|
|
return json(trans('auth.validation.user'), 2);
|
2016-07-21 22:01:57 +08:00
|
|
|
} else {
|
2017-01-08 12:49:32 +08:00
|
|
|
if ($user->verifyPassword($request->input('password'))) {
|
2016-09-03 23:50:55 +08:00
|
|
|
Session::forget('login_fails');
|
2016-07-21 22:01:57 +08:00
|
|
|
|
2019-06-04 22:22:49 +08:00
|
|
|
Auth::login($user, $request->input('keep'));
|
2016-07-21 22:01:57 +08:00
|
|
|
|
2016-11-17 17:32:12 +08:00
|
|
|
event(new Events\UserLoggedIn($user));
|
2016-10-17 17:51:51 +08:00
|
|
|
|
2018-08-16 17:57:24 +08:00
|
|
|
Cache::forget($loginFailsCacheKey);
|
2017-06-28 20:42:51 +08:00
|
|
|
|
2019-07-12 15:53:49 +08:00
|
|
|
return json(trans('auth.login.success'), 0, [
|
|
|
|
'redirectTo' => $request->session()->pull('last_requested_path', url('/user')),
|
|
|
|
]);
|
2016-07-21 22:01:57 +08:00
|
|
|
} else {
|
2018-08-16 17:57:24 +08:00
|
|
|
// Increase the counter
|
2019-02-27 23:44:50 +08:00
|
|
|
Cache::put($loginFailsCacheKey, ++$loginFails, 3600);
|
2016-08-16 13:27:06 +08:00
|
|
|
|
2016-10-02 20:30:27 +08:00
|
|
|
return json(trans('auth.validation.password'), 1, [
|
2019-03-02 22:58:37 +08:00
|
|
|
'login_fails' => $loginFails,
|
2016-07-21 22:01:57 +08:00
|
|
|
]);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-07-20 14:42:43 +08:00
|
|
|
public function logout()
|
2016-07-21 22:01:57 +08:00
|
|
|
{
|
2018-07-20 14:42:43 +08:00
|
|
|
if (Auth::check()) {
|
|
|
|
Auth::logout();
|
2019-04-19 19:36:36 +08:00
|
|
|
|
2018-07-20 14:42:43 +08:00
|
|
|
return json(trans('auth.logout.success'), 0);
|
2016-07-21 22:01:57 +08:00
|
|
|
} else {
|
2016-10-06 17:57:07 +08:00
|
|
|
return json(trans('auth.logout.fail'), 1);
|
2016-07-21 22:01:57 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public function register()
|
|
|
|
{
|
2016-10-23 11:41:52 +08:00
|
|
|
if (option('user_can_register')) {
|
2019-03-24 09:58:37 +08:00
|
|
|
return view('auth.register', [
|
2019-09-18 23:06:48 +08:00
|
|
|
'site_name' => option_localized('site_name'),
|
2019-03-24 09:58:37 +08:00
|
|
|
'extra' => [
|
2019-03-31 16:07:36 +08:00
|
|
|
'player' => (bool) option('register_with_player_name'),
|
2019-03-24 09:58:37 +08:00
|
|
|
'recaptcha' => option('recaptcha_sitekey'),
|
2019-03-24 15:45:50 +08:00
|
|
|
'invisible' => (bool) option('recaptcha_invisible'),
|
2019-04-19 19:36:36 +08:00
|
|
|
],
|
2019-03-24 09:58:37 +08:00
|
|
|
]);
|
2016-07-27 18:31:59 +08:00
|
|
|
} else {
|
2016-09-15 09:20:02 +08:00
|
|
|
throw new PrettyPageException(trans('auth.register.close'), 7);
|
2016-07-27 18:31:59 +08:00
|
|
|
}
|
2016-07-21 22:01:57 +08:00
|
|
|
}
|
|
|
|
|
2019-09-07 11:15:23 +08:00
|
|
|
public function handleRegister(Request $request, Captcha $captcha)
|
2016-07-21 22:01:57 +08:00
|
|
|
{
|
2019-12-14 11:10:37 +08:00
|
|
|
if (!option('user_can_register')) {
|
2018-08-17 17:03:38 +08:00
|
|
|
return json(trans('auth.register.close'), 7);
|
|
|
|
}
|
|
|
|
|
|
|
|
$rule = option('register_with_player_name') ?
|
|
|
|
['player_name' => 'required|player_name|min:'.option('player_name_length_min').'|max:'.option('player_name_length_max')] :
|
|
|
|
['nickname' => 'required|no_special_chars|max:255'];
|
|
|
|
$data = $this->validate($request, array_merge([
|
2019-12-14 11:10:37 +08:00
|
|
|
'email' => 'required|email|unique:users',
|
2018-02-24 16:05:07 +08:00
|
|
|
'password' => 'required|min:8|max:32',
|
2019-12-14 11:10:37 +08:00
|
|
|
'captcha' => ['required', $captcha],
|
2018-08-17 17:03:38 +08:00
|
|
|
], $rule));
|
2016-09-03 23:50:55 +08:00
|
|
|
|
2018-08-17 17:03:38 +08:00
|
|
|
if (option('register_with_player_name')) {
|
|
|
|
event(new Events\CheckPlayerExists($request->get('player_name')));
|
|
|
|
|
2019-03-13 13:16:51 +08:00
|
|
|
if (Player::where('name', $request->get('player_name'))->first()) {
|
2018-08-17 17:03:38 +08:00
|
|
|
return json(trans('user.player.add.repeated'), 2);
|
|
|
|
}
|
2016-10-23 11:41:52 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
// If amount of registered accounts of IP is more than allowed amounts,
|
2018-08-17 22:54:26 +08:00
|
|
|
// then reject the register.
|
2019-08-24 10:22:26 +08:00
|
|
|
if (User::where('ip', get_client_ip())->count() >= option('regs_per_ip')) {
|
2018-08-17 22:54:26 +08:00
|
|
|
return json(trans('auth.register.max', ['regs' => option('regs_per_ip')]), 7);
|
|
|
|
}
|
2018-08-17 17:03:38 +08:00
|
|
|
|
2019-12-14 11:10:37 +08:00
|
|
|
$user = new User();
|
2018-08-17 22:54:26 +08:00
|
|
|
$user->email = $data['email'];
|
|
|
|
$user->nickname = $data[option('register_with_player_name') ? 'player_name' : 'nickname'];
|
|
|
|
$user->score = option('user_initial_score');
|
|
|
|
$user->avatar = 0;
|
2019-07-30 15:12:31 +08:00
|
|
|
$user->password = $user->getEncryptedPwdFromEvent($data['password'])
|
2018-08-17 22:54:26 +08:00
|
|
|
?: app('cipher')->hash($data['password'], config('secure.salt'));
|
|
|
|
$user->ip = get_client_ip();
|
|
|
|
$user->permission = User::NORMAL;
|
|
|
|
$user->register_at = get_datetime_string();
|
|
|
|
$user->last_sign_at = get_datetime_string(time() - 86400);
|
2018-07-20 14:42:43 +08:00
|
|
|
|
2018-08-17 22:54:26 +08:00
|
|
|
$user->save();
|
2016-10-23 11:41:52 +08:00
|
|
|
|
2018-08-17 22:54:26 +08:00
|
|
|
event(new Events\UserRegistered($user));
|
|
|
|
|
|
|
|
if (option('register_with_player_name')) {
|
2019-12-14 11:10:37 +08:00
|
|
|
$player = new Player();
|
2019-03-02 22:58:37 +08:00
|
|
|
$player->uid = $user->uid;
|
2019-03-13 13:16:51 +08:00
|
|
|
$player->name = $request->get('player_name');
|
2019-03-02 22:58:37 +08:00
|
|
|
$player->tid_skin = 0;
|
2018-08-17 22:54:26 +08:00
|
|
|
$player->save();
|
|
|
|
|
|
|
|
event(new Events\PlayerWasAdded($player));
|
2016-07-21 22:01:57 +08:00
|
|
|
}
|
2018-08-17 22:54:26 +08:00
|
|
|
|
|
|
|
Auth::login($user);
|
|
|
|
|
2019-04-23 19:14:41 +08:00
|
|
|
return json(trans('auth.register.success'), 0);
|
2016-07-21 22:01:57 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
public function forgot()
|
|
|
|
{
|
2019-03-02 22:58:37 +08:00
|
|
|
if (config('mail.driver') != '') {
|
2019-03-27 11:07:04 +08:00
|
|
|
return view('auth.forgot', [
|
|
|
|
'extra' => [
|
|
|
|
'recaptcha' => option('recaptcha_sitekey'),
|
|
|
|
'invisible' => (bool) option('recaptcha_invisible'),
|
2019-04-19 19:36:36 +08:00
|
|
|
],
|
2019-03-27 11:07:04 +08:00
|
|
|
]);
|
2016-08-06 19:12:39 +08:00
|
|
|
} else {
|
2018-08-17 12:32:44 +08:00
|
|
|
throw new PrettyPageException(trans('auth.forgot.disabled'), 8);
|
2016-08-06 19:12:39 +08:00
|
|
|
}
|
2016-07-21 22:01:57 +08:00
|
|
|
}
|
|
|
|
|
2019-09-07 11:15:23 +08:00
|
|
|
public function handleForgot(Request $request, Captcha $captcha)
|
2016-07-21 22:01:57 +08:00
|
|
|
{
|
2018-08-12 16:00:21 +08:00
|
|
|
$this->validate($request, [
|
2019-04-04 11:04:13 +08:00
|
|
|
'captcha' => ['required', $captcha],
|
2018-08-12 16:00:21 +08:00
|
|
|
]);
|
2016-07-21 22:01:57 +08:00
|
|
|
|
2019-12-14 11:10:37 +08:00
|
|
|
if (!config('mail.driver')) {
|
2018-08-17 12:32:44 +08:00
|
|
|
return json(trans('auth.forgot.disabled'), 1);
|
|
|
|
}
|
2016-08-06 19:12:39 +08:00
|
|
|
|
2018-08-17 16:07:24 +08:00
|
|
|
$rateLimit = 180;
|
2018-08-17 22:54:26 +08:00
|
|
|
$lastMailCacheKey = sha1('last_mail_'.get_client_ip());
|
2018-08-17 16:07:24 +08:00
|
|
|
$remain = $rateLimit + Cache::get($lastMailCacheKey, 0) - time();
|
|
|
|
|
|
|
|
// Rate limit
|
|
|
|
if ($remain > 0) {
|
2019-04-23 19:14:41 +08:00
|
|
|
return json(trans('auth.forgot.frequent-mail'), 2);
|
2018-08-17 16:07:24 +08:00
|
|
|
}
|
2016-07-21 22:01:57 +08:00
|
|
|
|
2019-08-24 10:22:26 +08:00
|
|
|
$user = User::where('email', $request->email)->first();
|
2016-07-21 22:01:57 +08:00
|
|
|
|
2019-12-14 11:10:37 +08:00
|
|
|
if (!$user) {
|
2016-09-15 09:20:02 +08:00
|
|
|
return json(trans('auth.forgot.unregistered'), 1);
|
2019-03-02 22:58:37 +08:00
|
|
|
}
|
2016-07-21 22:01:57 +08:00
|
|
|
|
2018-07-18 11:04:34 +08:00
|
|
|
$url = URL::temporarySignedRoute('auth.reset', now()->addHour(), ['uid' => $user->uid]);
|
2016-07-21 22:01:57 +08:00
|
|
|
|
2016-09-04 16:15:11 +08:00
|
|
|
try {
|
2018-07-18 11:04:34 +08:00
|
|
|
Mail::to($request->input('email'))->send(new ForgotPassword($url));
|
2018-07-15 18:15:55 +08:00
|
|
|
} catch (\Exception $e) {
|
2018-07-22 11:36:00 +08:00
|
|
|
report($e);
|
2018-07-15 18:15:55 +08:00
|
|
|
|
2018-08-16 18:10:09 +08:00
|
|
|
return json(trans('auth.forgot.failed', ['msg' => $e->getMessage()]), 2);
|
2016-07-21 22:01:57 +08:00
|
|
|
}
|
|
|
|
|
2019-02-27 23:44:50 +08:00
|
|
|
Cache::put($lastMailCacheKey, time(), 3600);
|
2016-09-04 16:15:11 +08:00
|
|
|
|
2018-08-16 18:10:09 +08:00
|
|
|
return json(trans('auth.forgot.success'), 0);
|
2016-07-21 22:01:57 +08:00
|
|
|
}
|
|
|
|
|
2019-09-07 11:15:23 +08:00
|
|
|
public function reset($uid)
|
2016-07-21 22:01:57 +08:00
|
|
|
{
|
2019-08-24 10:22:26 +08:00
|
|
|
return view('auth.reset')->with('user', User::find($uid));
|
2016-07-21 22:01:57 +08:00
|
|
|
}
|
|
|
|
|
2019-09-07 11:15:23 +08:00
|
|
|
public function handleReset(Request $request, $uid)
|
2016-07-21 22:01:57 +08:00
|
|
|
{
|
2018-07-18 11:04:34 +08:00
|
|
|
$validated = $this->validate($request, [
|
2018-02-24 16:05:07 +08:00
|
|
|
'password' => 'required|min:8|max:32',
|
2016-09-03 23:50:55 +08:00
|
|
|
]);
|
2016-07-21 22:01:57 +08:00
|
|
|
|
2019-08-24 10:22:26 +08:00
|
|
|
User::find($uid)->changePassword($validated['password']);
|
2016-11-07 22:34:34 +08:00
|
|
|
|
2016-09-15 09:20:02 +08:00
|
|
|
return json(trans('auth.reset.success'), 0);
|
2016-07-21 22:01:57 +08:00
|
|
|
}
|
|
|
|
|
2019-09-05 12:23:46 +08:00
|
|
|
public function captcha(\Gregwar\Captcha\CaptchaBuilder $builder)
|
|
|
|
{
|
|
|
|
$builder->build(100, 34);
|
|
|
|
session(['captcha' => $builder->getPhrase()]);
|
2019-09-07 11:00:35 +08:00
|
|
|
|
2019-09-05 12:23:46 +08:00
|
|
|
return response($builder->output(), 200, [
|
|
|
|
'Content-Type' => 'image/jpeg',
|
|
|
|
'Cache-Control' => 'no-store',
|
|
|
|
]);
|
|
|
|
}
|
|
|
|
|
2019-04-25 13:01:39 +08:00
|
|
|
public function fillEmail(Request $request)
|
|
|
|
{
|
|
|
|
$email = $this->validate($request, ['email' => 'required|email|unique:users'])['email'];
|
|
|
|
$user = $request->user();
|
|
|
|
$user->email = $email;
|
|
|
|
$user->save();
|
2019-05-19 13:49:44 +08:00
|
|
|
|
2019-04-25 13:01:39 +08:00
|
|
|
return redirect('/user');
|
|
|
|
}
|
|
|
|
|
2019-09-07 11:15:23 +08:00
|
|
|
public function verify($uid)
|
2016-10-23 11:41:52 +08:00
|
|
|
{
|
2019-12-14 11:10:37 +08:00
|
|
|
if (!option('require_verification')) {
|
2018-08-17 12:32:44 +08:00
|
|
|
throw new PrettyPageException(trans('user.verification.disabled'), 1);
|
|
|
|
}
|
|
|
|
|
2019-08-24 10:22:26 +08:00
|
|
|
$user = User::find($uid);
|
2018-08-17 12:32:44 +08:00
|
|
|
|
2019-12-14 11:10:37 +08:00
|
|
|
if (!$user || $user->verified) {
|
2018-08-17 12:32:44 +08:00
|
|
|
throw new PrettyPageException(trans('auth.verify.invalid'), 1);
|
|
|
|
}
|
|
|
|
|
|
|
|
$user->verified = true;
|
|
|
|
$user->save();
|
|
|
|
|
2019-09-18 23:06:48 +08:00
|
|
|
return view('auth.verify', ['site_name' => option_localized('site_name')]);
|
2016-10-23 11:41:52 +08:00
|
|
|
}
|
2019-04-23 10:05:58 +08:00
|
|
|
|
2019-04-25 13:29:43 +08:00
|
|
|
public function jwtLogin(Request $request)
|
2019-04-23 10:05:58 +08:00
|
|
|
{
|
2019-04-25 13:29:43 +08:00
|
|
|
$token = Auth::guard('jwt')->attempt([
|
2019-04-23 10:05:58 +08:00
|
|
|
'email' => $request->email,
|
2019-05-19 13:49:44 +08:00
|
|
|
'password' => $request->password,
|
2019-04-26 18:58:12 +08:00
|
|
|
]) ?: '';
|
2019-04-23 10:05:58 +08:00
|
|
|
|
|
|
|
return json(compact('token'));
|
|
|
|
}
|
|
|
|
|
2019-04-25 13:29:43 +08:00
|
|
|
public function jwtLogout()
|
2019-04-23 10:05:58 +08:00
|
|
|
{
|
2019-04-25 13:29:43 +08:00
|
|
|
Auth::guard('jwt')->logout();
|
2019-05-19 13:49:44 +08:00
|
|
|
|
2019-04-23 10:05:58 +08:00
|
|
|
return response('', 204);
|
|
|
|
}
|
2019-04-23 12:45:06 +08:00
|
|
|
|
2019-04-25 13:29:43 +08:00
|
|
|
public function jwtRefresh()
|
2019-04-23 12:45:06 +08:00
|
|
|
{
|
2019-04-25 13:29:43 +08:00
|
|
|
return json(['token' => Auth::guard('jwt')->refresh()]);
|
2019-04-23 12:45:06 +08:00
|
|
|
}
|
2019-12-15 11:19:10 +08:00
|
|
|
|
|
|
|
public function oauthLogin($driver)
|
|
|
|
{
|
|
|
|
return Socialite::driver($driver)->redirect();
|
|
|
|
}
|
|
|
|
|
|
|
|
public function oauthCallback($driver)
|
|
|
|
{
|
|
|
|
$remoteUser = Socialite::driver($driver)->user();
|
|
|
|
|
|
|
|
$email = $remoteUser->email;
|
|
|
|
if (empty($email)) {
|
|
|
|
abort(500, 'Unsupported OAuth Server which does not provide email.');
|
|
|
|
}
|
|
|
|
|
|
|
|
$user = User::where('email', $email)->first();
|
|
|
|
if ($user) {
|
|
|
|
event(new Events\UserLoggedIn($user));
|
|
|
|
|
|
|
|
Auth::login($user);
|
|
|
|
} else {
|
|
|
|
$user = new User();
|
|
|
|
$user->email = $email;
|
|
|
|
$user->nickname = $remoteUser->nickname ?? $remoteUser->name ?? $email;
|
|
|
|
$user->score = option('user_initial_score');
|
|
|
|
$user->avatar = 0;
|
|
|
|
$user->password = '';
|
|
|
|
$user->ip = get_client_ip();
|
|
|
|
$user->permission = User::NORMAL;
|
|
|
|
$user->register_at = get_datetime_string();
|
|
|
|
$user->last_sign_at = get_datetime_string(time() - 86400);
|
2019-12-15 17:58:38 +08:00
|
|
|
$user->verified = true;
|
2019-12-15 11:19:10 +08:00
|
|
|
|
|
|
|
$user->save();
|
|
|
|
event(new Events\UserRegistered($user));
|
|
|
|
|
|
|
|
Auth::login($user);
|
|
|
|
}
|
|
|
|
|
|
|
|
return redirect('/user');
|
|
|
|
}
|
2016-07-21 22:01:57 +08:00
|
|
|
}
|