RegisterController.php 5.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184
  1. <?php
  2. namespace App\Http\Controllers\Auth;
  3. use App\Http\Controllers\Controller;
  4. use App\User;
  5. use App\Util\Lexer\RestrictedNames;
  6. use Illuminate\Foundation\Auth\RegistersUsers;
  7. use Illuminate\Support\Facades\Hash;
  8. use Illuminate\Support\Facades\Validator;
  9. use Illuminate\Auth\Events\Registered;
  10. use Illuminate\Http\Request;
  11. use App\Services\EmailService;
  12. class RegisterController extends Controller
  13. {
  14. /*
  15. |--------------------------------------------------------------------------
  16. | Register Controller
  17. |--------------------------------------------------------------------------
  18. |
  19. | This controller handles the registration of new users as well as their
  20. | validation and creation. By default this controller uses a trait to
  21. | provide this functionality without requiring any additional code.
  22. |
  23. */
  24. use RegistersUsers;
  25. /**
  26. * Where to redirect users after registration.
  27. *
  28. * @var string
  29. */
  30. protected $redirectTo = '/';
  31. /**
  32. * Create a new controller instance.
  33. *
  34. * @return void
  35. */
  36. public function __construct()
  37. {
  38. $this->middleware('guest');
  39. }
  40. /**
  41. * Get a validator for an incoming registration request.
  42. *
  43. * @param array $data
  44. *
  45. * @return \Illuminate\Contracts\Validation\Validator
  46. */
  47. protected function validator(array $data)
  48. {
  49. if(config('database.default') == 'pgsql') {
  50. $data['username'] = strtolower($data['username']);
  51. $data['email'] = strtolower($data['email']);
  52. }
  53. $this->validateEmail($data['email']);
  54. $usernameRules = [
  55. 'required',
  56. 'min:2',
  57. 'max:15',
  58. 'unique:users',
  59. function ($attribute, $value, $fail) {
  60. $dash = substr_count($value, '-');
  61. $underscore = substr_count($value, '_');
  62. $period = substr_count($value, '.');
  63. if(($dash + $underscore + $period) > 1) {
  64. return $fail('Username is invalid. Can only contain one dash (-), period (.) or underscore (_).');
  65. }
  66. if (!ctype_alpha($value[0])) {
  67. return $fail('Username is invalid. Must start with a letter or number.');
  68. }
  69. if (!ctype_alnum($value[strlen($value) - 1])) {
  70. return $fail('Username is invalid. Must end with a letter or number.');
  71. }
  72. $val = str_replace(['_', '.', '-'], '', $value);
  73. if(!ctype_alnum($val)) {
  74. return $fail('Username is invalid. Username must be alpha-numeric and may contain dashes (-), periods (.) and underscores (_).');
  75. }
  76. $restricted = RestrictedNames::get();
  77. if (in_array($value, $restricted)) {
  78. return $fail('Username cannot be used.');
  79. }
  80. },
  81. ];
  82. $rules = [
  83. 'agecheck' => 'required|accepted',
  84. 'name' => 'nullable|string|max:'.config('pixelfed.max_name_length'),
  85. 'username' => $usernameRules,
  86. 'email' => 'required|string|email|max:255|unique:users',
  87. 'password' => 'required|string|min:12|confirmed',
  88. ];
  89. return Validator::make($data, $rules);
  90. }
  91. /**
  92. * Create a new user instance after a valid registration.
  93. *
  94. * @param array $data
  95. *
  96. * @return \App\User
  97. */
  98. protected function create(array $data)
  99. {
  100. if(config('database.default') == 'pgsql') {
  101. $data['username'] = strtolower($data['username']);
  102. $data['email'] = strtolower($data['email']);
  103. }
  104. return User::create([
  105. 'name' => $data['name'],
  106. 'username' => $data['username'],
  107. 'email' => $data['email'],
  108. 'password' => Hash::make($data['password']),
  109. ]);
  110. }
  111. public function validateEmail($email)
  112. {
  113. $banned = EmailService::isBanned($email);
  114. if($banned) {
  115. return abort(403, 'Invalid email.');
  116. }
  117. }
  118. /**
  119. * Show the application registration form.
  120. *
  121. * @return \Illuminate\Http\Response
  122. */
  123. public function showRegistrationForm()
  124. {
  125. if(config('pixelfed.open_registration')) {
  126. $limit = config('pixelfed.max_users');
  127. if($limit) {
  128. abort_if($limit <= User::count(), 404);
  129. return view('auth.register');
  130. } else {
  131. return view('auth.register');
  132. }
  133. } else {
  134. abort(404);
  135. }
  136. }
  137. /**
  138. * Handle a registration request for the application.
  139. *
  140. * @param \Illuminate\Http\Request $request
  141. * @return \Illuminate\Http\Response
  142. */
  143. public function register(Request $request)
  144. {
  145. abort_if(config('pixelfed.open_registration') == false, 400);
  146. $count = User::count();
  147. $limit = config('pixelfed.max_users');
  148. if(false == config('pixelfed.open_registration') || $limit && $limit <= $count) {
  149. return abort(403);
  150. }
  151. $this->validator($request->all())->validate();
  152. event(new Registered($user = $this->create($request->all())));
  153. $this->guard()->login($user);
  154. return $this->registered($request, $user)
  155. ?: redirect($this->redirectPath());
  156. }
  157. }