ParentalControlsController.php 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220
  1. <?php
  2. namespace App\Http\Controllers;
  3. use Illuminate\Http\Request;
  4. use App\Models\ParentalControls;
  5. use App\Models\UserRoles;
  6. use App\User;
  7. use App\Http\Controllers\Auth\RegisterController;
  8. use Illuminate\Auth\Events\Registered;
  9. use Illuminate\Support\Facades\Auth;
  10. use App\Services\UserRoleService;
  11. use App\Jobs\ParentalControlsPipeline\DispatchChildInvitePipeline;
  12. class ParentalControlsController extends Controller
  13. {
  14. public function authPreflight($request, $maxUserCheck = false, $authCheck = true)
  15. {
  16. if($authCheck) {
  17. abort_unless($request->user(), 404);
  18. }
  19. abort_unless(config('instance.parental_controls.enabled'), 404);
  20. if(config_cache('pixelfed.open_registration') == false) {
  21. abort_if(config('instance.parental_controls.limits.respect_open_registration'), 404);
  22. }
  23. if($maxUserCheck == true) {
  24. $hasLimit = config('pixelfed.enforce_max_users');
  25. if($hasLimit) {
  26. $count = User::where(function($q){ return $q->whereNull('status')->orWhereNotIn('status', ['deleted','delete']); })->count();
  27. $limit = (int) config('pixelfed.max_users');
  28. abort_if($limit && $limit <= $count, 404);
  29. }
  30. }
  31. }
  32. public function index(Request $request)
  33. {
  34. $this->authPreflight($request);
  35. $children = ParentalControls::whereParentId($request->user()->id)->latest()->paginate(5);
  36. return view('settings.parental-controls.index', compact('children'));
  37. }
  38. public function add(Request $request)
  39. {
  40. $this->authPreflight($request, true);
  41. return view('settings.parental-controls.add');
  42. }
  43. public function view(Request $request, $id)
  44. {
  45. $this->authPreflight($request);
  46. $uid = $request->user()->id;
  47. $pc = ParentalControls::whereParentId($uid)->findOrFail($id);
  48. return view('settings.parental-controls.manage', compact('pc'));
  49. }
  50. public function update(Request $request, $id)
  51. {
  52. $this->authPreflight($request);
  53. $uid = $request->user()->id;
  54. $pc = ParentalControls::whereParentId($uid)->findOrFail($id);
  55. $pc->permissions = $this->requestFormFields($request);
  56. $pc->save();
  57. return redirect($pc->manageUrl() . '?permissions');
  58. }
  59. public function store(Request $request)
  60. {
  61. $this->authPreflight($request, true);
  62. $this->validate($request, [
  63. 'email' => 'required|email|unique:parental_controls,email|unique:users,email',
  64. ]);
  65. $state = $this->requestFormFields($request);
  66. $pc = new ParentalControls;
  67. $pc->parent_id = $request->user()->id;
  68. $pc->email = $request->input('email');
  69. $pc->verify_code = str_random(32);
  70. $pc->permissions = $state;
  71. $pc->save();
  72. DispatchChildInvitePipeline::dispatch($pc);
  73. return redirect($pc->manageUrl());
  74. }
  75. public function inviteRegister(Request $request, $id, $code)
  76. {
  77. if($request->user()) {
  78. $title = 'You cannot complete this action on this device.';
  79. $body = 'Please log out or use a different device or browser to complete the invitation registration.';
  80. return view('errors.custom', compact('title', 'body'));
  81. }
  82. $this->authPreflight($request, true, false);
  83. $pc = ParentalControls::whereRaw('verify_code = BINARY ?', $code)->whereNull(['email_verified_at', 'child_id'])->findOrFail($id);
  84. abort_unless(User::whereId($pc->parent_id)->exists(), 404);
  85. return view('settings.parental-controls.invite-register-form', compact('pc'));
  86. }
  87. public function inviteRegisterStore(Request $request, $id, $code)
  88. {
  89. if($request->user()) {
  90. $title = 'You cannot complete this action on this device.';
  91. $body = 'Please log out or use a different device or browser to complete the invitation registration.';
  92. return view('errors.custom', compact('title', 'body'));
  93. }
  94. $this->authPreflight($request, true, false);
  95. $pc = ParentalControls::whereRaw('verify_code = BINARY ?', $code)->whereNull('email_verified_at')->findOrFail($id);
  96. $fields = $request->all();
  97. $fields['email'] = $pc->email;
  98. $defaults = UserRoleService::defaultRoles();
  99. $validator = (new RegisterController)->validator($fields);
  100. $valid = $validator->validate();
  101. abort_if(!$valid, 404);
  102. event(new Registered($user = (new RegisterController)->create($fields)));
  103. sleep(5);
  104. $user->has_roles = true;
  105. $user->parent_id = $pc->parent_id;
  106. if(config('instance.parental_controls.limits.auto_verify_email')) {
  107. $user->email_verified_at = now();
  108. $user->save();
  109. sleep(3);
  110. } else {
  111. $user->save();
  112. sleep(3);
  113. }
  114. $ur = UserRoles::updateOrCreate([
  115. 'user_id' => $user->id,
  116. ],[
  117. 'roles' => UserRoleService::mapInvite($user->id, $pc->permissions)
  118. ]);
  119. $pc->email_verified_at = now();
  120. $pc->child_id = $user->id;
  121. $pc->save();
  122. sleep(2);
  123. Auth::guard()->login($user);
  124. return redirect('/i/web');
  125. }
  126. public function cancelInvite(Request $request, $id)
  127. {
  128. $this->authPreflight($request);
  129. $pc = ParentalControls::whereParentId($request->user()->id)
  130. ->whereNull(['email_verified_at', 'child_id'])
  131. ->findOrFail($id);
  132. return view('settings.parental-controls.delete-invite', compact('pc'));
  133. }
  134. public function cancelInviteHandle(Request $request, $id)
  135. {
  136. $this->authPreflight($request);
  137. $pc = ParentalControls::whereParentId($request->user()->id)
  138. ->whereNull(['email_verified_at', 'child_id'])
  139. ->findOrFail($id);
  140. $pc->delete();
  141. return redirect('/settings/parental-controls');
  142. }
  143. public function stopManaging(Request $request, $id)
  144. {
  145. $this->authPreflight($request);
  146. $pc = ParentalControls::whereParentId($request->user()->id)
  147. ->whereNotNull(['email_verified_at', 'child_id'])
  148. ->findOrFail($id);
  149. return view('settings.parental-controls.stop-managing', compact('pc'));
  150. }
  151. public function stopManagingHandle(Request $request, $id)
  152. {
  153. $this->authPreflight($request);
  154. $pc = ParentalControls::whereParentId($request->user()->id)
  155. ->whereNotNull(['email_verified_at', 'child_id'])
  156. ->findOrFail($id);
  157. $pc->child()->update([
  158. 'has_roles' => false,
  159. 'parent_id' => null,
  160. ]);
  161. $pc->delete();
  162. return redirect('/settings/parental-controls');
  163. }
  164. protected function requestFormFields($request)
  165. {
  166. $state = [];
  167. $fields = [
  168. 'post',
  169. 'comment',
  170. 'like',
  171. 'share',
  172. 'follow',
  173. 'bookmark',
  174. 'story',
  175. 'collection',
  176. 'discovery_feeds',
  177. 'dms',
  178. 'federation',
  179. 'hide_network',
  180. 'private',
  181. 'hide_cw'
  182. ];
  183. foreach ($fields as $field) {
  184. $state[$field] = $request->input($field) == 'on';
  185. }
  186. return $state;
  187. }
  188. }