CuratedRegisterController.php 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Jobs\CuratedOnboarding\CuratedOnboardingNotifyAdminNewApplicationPipeline;
  4. use App\Mail\CuratedRegisterConfirmEmail;
  5. use App\Models\CuratedRegister;
  6. use App\Models\CuratedRegisterActivity;
  7. use App\Services\EmailService;
  8. use App\Util\Lexer\RestrictedNames;
  9. use Illuminate\Http\Request;
  10. use Illuminate\Support\Facades\DB;
  11. use Illuminate\Support\Facades\Mail;
  12. use Illuminate\Support\Str;
  13. class CuratedRegisterController extends Controller
  14. {
  15. public function preCheck($allowWhenDisabled = false)
  16. {
  17. if (! $allowWhenDisabled) {
  18. abort_unless((bool) config_cache('instance.curated_registration.enabled'), 404);
  19. if ((bool) config_cache('pixelfed.open_registration')) {
  20. abort_if(config('instance.curated_registration.state.only_enabled_on_closed_reg'), 404);
  21. } else {
  22. abort_unless(config('instance.curated_registration.state.fallback_on_closed_reg'), 404);
  23. }
  24. } else {
  25. abort_unless(config('instance.curated_registration.state.fallback_on_closed_reg'), 404);
  26. }
  27. }
  28. public function index(Request $request)
  29. {
  30. abort_if($request->user(), 404);
  31. return view('auth.curated-register.index', ['step' => 1]);
  32. }
  33. public function concierge(Request $request)
  34. {
  35. abort_if($request->user(), 404);
  36. $this->preCheck(true);
  37. $emailConfirmed = $request->session()->has('cur-reg-con.email-confirmed') &&
  38. $request->has('next') &&
  39. $request->session()->has('cur-reg-con.cr-id');
  40. return view('auth.curated-register.concierge', compact('emailConfirmed'));
  41. }
  42. public function conciergeResponseSent(Request $request)
  43. {
  44. $this->preCheck(true);
  45. return view('auth.curated-register.user_response_sent');
  46. }
  47. public function conciergeFormShow(Request $request)
  48. {
  49. abort_if($request->user(), 404);
  50. $this->preCheck(true);
  51. abort_unless(
  52. $request->session()->has('cur-reg-con.email-confirmed') &&
  53. $request->session()->has('cur-reg-con.cr-id') &&
  54. $request->session()->has('cur-reg-con.ac-id'), 404);
  55. $crid = $request->session()->get('cur-reg-con.cr-id');
  56. $arid = $request->session()->get('cur-reg-con.ac-id');
  57. $showCaptcha = config('instance.curated_registration.captcha_enabled');
  58. if ($attempts = $request->session()->get('cur-reg-con-attempt')) {
  59. $showCaptcha = $attempts && $attempts >= 2;
  60. } else {
  61. $showCaptcha = false;
  62. }
  63. $activity = CuratedRegisterActivity::whereRegisterId($crid)->whereFromAdmin(true)->findOrFail($arid);
  64. return view('auth.curated-register.concierge_form', compact('activity', 'showCaptcha'));
  65. }
  66. public function conciergeFormStore(Request $request)
  67. {
  68. abort_if($request->user(), 404);
  69. $this->preCheck(true);
  70. $request->session()->increment('cur-reg-con-attempt');
  71. abort_unless(
  72. $request->session()->has('cur-reg-con.email-confirmed') &&
  73. $request->session()->has('cur-reg-con.cr-id') &&
  74. $request->session()->has('cur-reg-con.ac-id'), 404);
  75. $attempts = $request->session()->get('cur-reg-con-attempt');
  76. $messages = [];
  77. $rules = [
  78. 'response' => 'required|string|min:5|max:1000',
  79. 'crid' => 'required|integer|min:1',
  80. 'acid' => 'required|integer|min:1',
  81. ];
  82. if (config('instance.curated_registration.captcha_enabled') && $attempts >= 3) {
  83. $rules['h-captcha-response'] = 'required|captcha';
  84. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  85. }
  86. $this->validate($request, $rules, $messages);
  87. $crid = $request->session()->get('cur-reg-con.cr-id');
  88. $acid = $request->session()->get('cur-reg-con.ac-id');
  89. abort_if((string) $crid !== $request->input('crid'), 404);
  90. abort_if((string) $acid !== $request->input('acid'), 404);
  91. if (CuratedRegisterActivity::whereRegisterId($crid)->whereReplyToId($acid)->exists()) {
  92. return redirect()->back()->withErrors(['code' => 'You already replied to this request.']);
  93. }
  94. $act = CuratedRegisterActivity::create([
  95. 'register_id' => $crid,
  96. 'reply_to_id' => $acid,
  97. 'type' => 'user_response',
  98. 'message' => $request->input('response'),
  99. 'from_user' => true,
  100. 'action_required' => true,
  101. ]);
  102. CuratedRegister::findOrFail($crid)->update(['user_has_responded' => true]);
  103. $request->session()->pull('cur-reg-con');
  104. $request->session()->pull('cur-reg-con-attempt');
  105. return view('auth.curated-register.user_response_sent');
  106. }
  107. public function conciergeStore(Request $request)
  108. {
  109. abort_if($request->user(), 404);
  110. $this->preCheck(true);
  111. $rules = [
  112. 'sid' => 'required_if:action,email|integer|min:1|max:20000000',
  113. 'id' => 'required_if:action,email|integer|min:1|max:20000000',
  114. 'code' => 'required_if:action,email',
  115. 'action' => 'required|string|in:email,message',
  116. 'email' => 'required_if:action,email|email',
  117. 'response' => 'required_if:action,message|string|min:20|max:1000',
  118. ];
  119. $messages = [];
  120. if (config('instance.curated_registration.captcha_enabled')) {
  121. $rules['h-captcha-response'] = 'required|captcha';
  122. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  123. }
  124. $this->validate($request, $rules, $messages);
  125. $action = $request->input('action');
  126. $sid = $request->input('sid');
  127. $id = $request->input('id');
  128. $code = $request->input('code');
  129. $email = $request->input('email');
  130. $cr = CuratedRegister::whereIsClosed(false)->findOrFail($sid);
  131. $ac = CuratedRegisterActivity::whereRegisterId($cr->id)->whereFromAdmin(true)->findOrFail($id);
  132. if (! hash_equals($ac->secret_code, $code)) {
  133. return redirect()->back()->withErrors(['code' => 'Invalid code']);
  134. }
  135. if (! hash_equals($cr->email, $email)) {
  136. return redirect()->back()->withErrors(['email' => 'Invalid email']);
  137. }
  138. $request->session()->put('cur-reg-con.email-confirmed', true);
  139. $request->session()->put('cur-reg-con.cr-id', $cr->id);
  140. $request->session()->put('cur-reg-con.ac-id', $ac->id);
  141. $emailConfirmed = true;
  142. return redirect('/auth/sign_up/concierge/form');
  143. }
  144. public function confirmEmail(Request $request)
  145. {
  146. if ($request->user()) {
  147. return redirect(route('help.email-confirmation-issues'));
  148. }
  149. $this->preCheck(true);
  150. return view('auth.curated-register.confirm_email');
  151. }
  152. public function emailConfirmed(Request $request)
  153. {
  154. if ($request->user()) {
  155. return redirect(route('help.email-confirmation-issues'));
  156. }
  157. $this->preCheck(true);
  158. return view('auth.curated-register.email_confirmed');
  159. }
  160. public function resendConfirmation(Request $request)
  161. {
  162. if ($request->user()) {
  163. return redirect(route('help.email-confirmation-issues'));
  164. }
  165. $this->preCheck(true);
  166. return view('auth.curated-register.resend-confirmation');
  167. }
  168. public function resendConfirmationProcess(Request $request)
  169. {
  170. if ($request->user()) {
  171. return redirect(route('help.email-confirmation-issues'));
  172. }
  173. $this->preCheck(true);
  174. $rules = [
  175. 'email' => [
  176. 'required',
  177. 'string',
  178. app()->environment() === 'production' ? 'email:rfc,dns,spoof' : 'email',
  179. 'exists:curated_registers',
  180. ],
  181. ];
  182. $messages = [];
  183. if (config('instance.curated_registration.captcha_enabled')) {
  184. $rules['h-captcha-response'] = 'required|captcha';
  185. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  186. }
  187. $this->validate($request, $rules, $messages);
  188. $cur = CuratedRegister::whereEmail($request->input('email'))->whereIsClosed(false)->first();
  189. if (! $cur) {
  190. return redirect()->back()->withErrors(['email' => 'The selected email is invalid.']);
  191. }
  192. $totalCount = CuratedRegisterActivity::whereRegisterId($cur->id)
  193. ->whereType('user_resend_email_confirmation')
  194. ->count();
  195. if ($totalCount && $totalCount >= config('instance.curated_registration.resend_confirmation_limit')) {
  196. return redirect()->back()->withErrors(['email' => 'You have re-attempted too many times. To proceed with your application, please <a href="/site/contact" class="text-white" style="text-decoration: underline;">contact the admin team</a>.']);
  197. }
  198. $count = CuratedRegisterActivity::whereRegisterId($cur->id)
  199. ->whereType('user_resend_email_confirmation')
  200. ->where('created_at', '>', now()->subHours(12))
  201. ->count();
  202. if ($count) {
  203. return redirect()->back()->withErrors(['email' => 'You can only re-send the confirmation email once per 12 hours. Try again later.']);
  204. }
  205. DB::transaction(function () use ($cur) {
  206. $cur->verify_code = Str::random(40);
  207. $cur->created_at = now();
  208. $cur->save();
  209. CuratedRegisterActivity::create([
  210. 'register_id' => $cur->id,
  211. 'type' => 'user_resend_email_confirmation',
  212. 'admin_only_view' => true,
  213. 'from_admin' => false,
  214. 'from_user' => false,
  215. 'action_required' => false,
  216. ]);
  217. Mail::to($cur->email)->send(new CuratedRegisterConfirmEmail($cur));
  218. });
  219. return view('auth.curated-register.resent-confirmation');
  220. }
  221. public function confirmEmailHandle(Request $request)
  222. {
  223. if ($request->user()) {
  224. return redirect(route('help.email-confirmation-issues'));
  225. }
  226. $this->preCheck(true);
  227. $rules = [
  228. 'sid' => 'required',
  229. 'code' => 'required',
  230. ];
  231. $messages = [];
  232. if (config('instance.curated_registration.captcha_enabled')) {
  233. $rules['h-captcha-response'] = 'required|captcha';
  234. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  235. }
  236. $this->validate($request, $rules, $messages);
  237. $cr = CuratedRegister::whereNull('email_verified_at')
  238. ->where('created_at', '>', now()->subDays(7))
  239. ->find($request->input('sid'));
  240. if (! $cr) {
  241. return redirect(route('help.email-confirmation-issues'));
  242. }
  243. if (! hash_equals($cr->verify_code, $request->input('code'))) {
  244. return redirect(route('help.email-confirmation-issues'));
  245. }
  246. $cr->email_verified_at = now();
  247. $cr->save();
  248. if (config('instance.curated_registration.notify.admin.on_verify_email.enabled')) {
  249. CuratedOnboardingNotifyAdminNewApplicationPipeline::dispatch($cr);
  250. }
  251. return view('auth.curated-register.email_confirmed');
  252. }
  253. public function proceed(Request $request)
  254. {
  255. if ($request->user()) {
  256. return redirect(route('help.email-confirmation-issues'));
  257. }
  258. $this->preCheck(false);
  259. $this->validate($request, [
  260. 'step' => 'required|integer|in:1,2,3,4',
  261. ]);
  262. $step = $request->input('step');
  263. switch ($step) {
  264. case 1:
  265. $step = 2;
  266. $request->session()->put('cur-step', 1);
  267. return view('auth.curated-register.index', compact('step'));
  268. break;
  269. case 2:
  270. $this->stepTwo($request);
  271. $step = 3;
  272. $request->session()->put('cur-step', 2);
  273. return view('auth.curated-register.index', compact('step'));
  274. break;
  275. case 3:
  276. $this->stepThree($request);
  277. $step = 3;
  278. $request->session()->put('cur-step', 3);
  279. $verifiedEmail = true;
  280. $request->session()->pull('cur-reg');
  281. return view('auth.curated-register.index', compact('step', 'verifiedEmail'));
  282. break;
  283. }
  284. }
  285. protected function stepTwo($request)
  286. {
  287. if ($request->filled('reason')) {
  288. $request->session()->put('cur-reg.form-reason', $request->input('reason'));
  289. }
  290. if ($request->filled('username')) {
  291. $request->session()->put('cur-reg.form-username', $request->input('username'));
  292. }
  293. if ($request->filled('email')) {
  294. $request->session()->put('cur-reg.form-email', $request->input('email'));
  295. }
  296. $this->validate($request, [
  297. 'username' => [
  298. 'required',
  299. 'min:2',
  300. 'max:30',
  301. 'unique:curated_registers',
  302. 'unique:users',
  303. function ($attribute, $value, $fail) {
  304. $dash = substr_count($value, '-');
  305. $underscore = substr_count($value, '_');
  306. $period = substr_count($value, '.');
  307. if (ends_with($value, ['.php', '.js', '.css'])) {
  308. return $fail('Username is invalid.');
  309. }
  310. if (($dash + $underscore + $period) > 1) {
  311. return $fail('Username is invalid. Can only contain one dash (-), period (.) or underscore (_).');
  312. }
  313. if (! ctype_alnum($value[0])) {
  314. return $fail('Username is invalid. Must start with a letter or number.');
  315. }
  316. if (! ctype_alnum($value[strlen($value) - 1])) {
  317. return $fail('Username is invalid. Must end with a letter or number.');
  318. }
  319. $val = str_replace(['_', '.', '-'], '', $value);
  320. if (! ctype_alnum($val)) {
  321. return $fail('Username is invalid. Username must be alpha-numeric and may contain dashes (-), periods (.) and underscores (_).');
  322. }
  323. $restricted = RestrictedNames::get();
  324. if (in_array(strtolower($value), array_map('strtolower', $restricted))) {
  325. return $fail('Username cannot be used.');
  326. }
  327. },
  328. ],
  329. 'email' => [
  330. 'required',
  331. 'string',
  332. app()->environment() === 'production' ? 'email:rfc,dns,spoof' : 'email',
  333. 'max:255',
  334. 'unique:users',
  335. 'unique:curated_registers',
  336. function ($attribute, $value, $fail) {
  337. $banned = EmailService::isBanned($value);
  338. if ($banned) {
  339. return $fail('Email is invalid.');
  340. }
  341. },
  342. ],
  343. 'password' => 'required|min:8',
  344. 'password_confirmation' => 'required|same:password',
  345. 'reason' => 'required|min:20|max:1000',
  346. 'agree' => 'required|accepted',
  347. ]);
  348. $request->session()->put('cur-reg.form-email', $request->input('email'));
  349. $request->session()->put('cur-reg.form-password', $request->input('password'));
  350. }
  351. protected function stepThree($request)
  352. {
  353. $this->validate($request, [
  354. 'email' => [
  355. 'required',
  356. 'string',
  357. app()->environment() === 'production' ? 'email:rfc,dns,spoof' : 'email',
  358. 'max:255',
  359. 'unique:users',
  360. 'unique:curated_registers',
  361. function ($attribute, $value, $fail) {
  362. $banned = EmailService::isBanned($value);
  363. if ($banned) {
  364. return $fail('Email is invalid.');
  365. }
  366. },
  367. ],
  368. ]);
  369. $cr = new CuratedRegister;
  370. $cr->email = $request->email;
  371. $cr->username = $request->session()->get('cur-reg.form-username');
  372. $cr->password = bcrypt($request->session()->get('cur-reg.form-password'));
  373. $cr->ip_address = $request->ip();
  374. $cr->reason_to_join = $request->session()->get('cur-reg.form-reason');
  375. $cr->verify_code = Str::random(40);
  376. $cr->save();
  377. Mail::to($cr->email)->send(new CuratedRegisterConfirmEmail($cr));
  378. }
  379. }