AdminUserController.php 7.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284
  1. <?php
  2. namespace App\Http\Controllers\Admin;
  3. use Cache, DB;
  4. use Illuminate\Http\Request;
  5. use App\ModLog;
  6. use App\Profile;
  7. use App\User;
  8. use App\Mail\AdminMessage;
  9. use Illuminate\Support\Facades\Mail;
  10. use App\Services\ModLogService;
  11. use App\Jobs\DeletePipeline\DeleteAccountPipeline;
  12. trait AdminUserController
  13. {
  14. public function users(Request $request)
  15. {
  16. $col = $request->query('col') ?? 'id';
  17. $dir = $request->query('dir') ?? 'desc';
  18. $users = User::select('id', 'username', 'status')
  19. ->withCount('statuses')
  20. ->orderBy($col, $dir)
  21. ->simplePaginate(10);
  22. return view('admin.users.home', compact('users'));
  23. }
  24. public function userShow(Request $request, $id)
  25. {
  26. $user = User::findOrFail($id);
  27. $profile = $user->profile;
  28. return view('admin.users.show', compact('user', 'profile'));
  29. }
  30. public function userEdit(Request $request, $id)
  31. {
  32. $user = User::findOrFail($id);
  33. $profile = $user->profile;
  34. return view('admin.users.edit', compact('user', 'profile'));
  35. }
  36. public function userEditSubmit(Request $request, $id)
  37. {
  38. $user = User::findOrFail($id);
  39. $profile = $user->profile;
  40. $changed = false;
  41. $fields = [];
  42. if($request->filled('name') && $request->input('name') != $user->name) {
  43. $fields['name'] = ['old' => $user->name, 'new' => $request->input('name')];
  44. $user->name = $profile->name = $request->input('name');
  45. $changed = true;
  46. }
  47. if($request->filled('username') && $request->input('username') != $user->username) {
  48. $fields['username'] = ['old' => $user->username, 'new' => $request->input('username')];
  49. $user->username = $profile->username = $request->input('username');
  50. $changed = true;
  51. }
  52. if($request->filled('email') && $request->input('email') != $user->email) {
  53. if(filter_var($request->input('email'), FILTER_VALIDATE_EMAIL) == false) {
  54. abort(500, 'Invalid email address');
  55. }
  56. $fields['email'] = ['old' => $user->email, 'new' => $request->input('email')];
  57. $user->email = $request->input('email');
  58. $changed = true;
  59. }
  60. if($request->input('bio') != $profile->bio) {
  61. $fields['bio'] = ['old' => $user->bio, 'new' => $request->input('bio')];
  62. $profile->bio = $request->input('bio');
  63. $changed = true;
  64. }
  65. if($request->input('website') != $profile->website) {
  66. $fields['website'] = ['old' => $user->website, 'new' => $request->input('website')];
  67. $profile->website = $request->input('website');
  68. $changed = true;
  69. }
  70. if($changed == true) {
  71. ModLogService::boot()
  72. ->objectUid($user->id)
  73. ->objectId($user->id)
  74. ->objectType('App\User::class')
  75. ->user($request->user())
  76. ->action('admin.user.edit')
  77. ->metadata([
  78. 'fields' => $fields
  79. ])
  80. ->accessLevel('admin')
  81. ->save();
  82. $profile->save();
  83. $user->save();
  84. }
  85. return redirect('/i/admin/users/show/' . $user->id);
  86. }
  87. public function userActivity(Request $request, $id)
  88. {
  89. $user = User::findOrFail($id);
  90. $profile = $user->profile;
  91. $logs = $user->accountLog()->orderByDesc('created_at')->paginate(10);
  92. return view('admin.users.activity', compact('user', 'profile', 'logs'));
  93. }
  94. public function userMessage(Request $request, $id)
  95. {
  96. $user = User::findOrFail($id);
  97. $profile = $user->profile;
  98. return view('admin.users.message', compact('user', 'profile'));
  99. }
  100. public function userMessageSend(Request $request, $id)
  101. {
  102. $this->validate($request, [
  103. 'message' => 'required|string|min:5|max:500'
  104. ]);
  105. $user = User::findOrFail($id);
  106. $profile = $user->profile;
  107. $message = $request->input('message');
  108. Mail::to($user->email)->send(new AdminMessage($message));
  109. ModLogService::boot()
  110. ->objectUid($user->id)
  111. ->objectId($user->id)
  112. ->objectType('App\User::class')
  113. ->user($request->user())
  114. ->action('admin.user.mail')
  115. ->metadata([
  116. 'message' => $message
  117. ])
  118. ->accessLevel('admin')
  119. ->save();
  120. return redirect('/i/admin/users/show/' . $user->id);
  121. }
  122. public function userModTools(Request $request, $id)
  123. {
  124. $user = User::findOrFail($id);
  125. $profile = $user->profile;
  126. return view('admin.users.modtools', compact('user', 'profile'));
  127. }
  128. public function userModLogs(Request $request, $id)
  129. {
  130. $user = User::findOrFail($id);
  131. $profile = $user->profile;
  132. $logs = ModLog::whereObjectUid($user->id)
  133. ->orderByDesc('created_at')
  134. ->simplePaginate(10);
  135. return view('admin.users.modlogs', compact('user', 'profile', 'logs'));
  136. }
  137. public function userModLogsMessage(Request $request, $id)
  138. {
  139. $this->validate($request, [
  140. 'message' => 'required|string|min:5|max:500'
  141. ]);
  142. $user = User::findOrFail($id);
  143. $profile = $user->profile;
  144. $msg = $request->input('message');
  145. ModLogService::boot()
  146. ->objectUid($user->id)
  147. ->objectId($user->id)
  148. ->objectType('App\User::class')
  149. ->user($request->user())
  150. ->message($msg)
  151. ->accessLevel('admin')
  152. ->save();
  153. return redirect('/i/admin/users/modlogs/' . $user->id);
  154. }
  155. public function userDelete(Request $request, $id)
  156. {
  157. $user = User::findOrFail($id);
  158. $profile = $user->profile;
  159. return view('admin.users.delete', compact('user', 'profile'));
  160. }
  161. public function userDeleteProcess(Request $request, $id)
  162. {
  163. $user = User::findOrFail($id);
  164. $profile = $user->profile;
  165. if(config('pixelfed.account_deletion') == false) {
  166. abort(404);
  167. }
  168. if($user->is_admin == true) {
  169. $mid = $request->user()->id;
  170. abort_if($user->id < $mid, 403);
  171. }
  172. $ts = now()->addMonth();
  173. $user->status = 'delete';
  174. $profile->status = 'delete';
  175. $user->delete_after = $ts;
  176. $profile->delete_after = $ts;
  177. $user->save();
  178. $profile->save();
  179. ModLogService::boot()
  180. ->objectUid($user->id)
  181. ->objectId($user->id)
  182. ->objectType('App\User::class')
  183. ->user($request->user())
  184. ->action('admin.user.delete')
  185. ->accessLevel('admin')
  186. ->save();
  187. Cache::forget('profiles:private');
  188. DeleteAccountPipeline::dispatch($user)->onQueue('high');
  189. $msg = "Successfully deleted {$user->username}!";
  190. $request->session()->flash('status', $msg);
  191. return redirect('/i/admin/users/list');
  192. }
  193. public function userModerate(Request $request)
  194. {
  195. $this->validate($request, [
  196. 'profile_id' => 'required|exists:profiles,id',
  197. 'action' => 'required|in:cw,no_autolink,unlisted'
  198. ]);
  199. $pid = $request->input('profile_id');
  200. $action = $request->input('action');
  201. $profile = Profile::findOrFail($pid);
  202. if($profile->user->is_admin == true) {
  203. $mid = $request->user()->id;
  204. abort_if($profile->user_id < $mid, 403);
  205. }
  206. switch ($action) {
  207. case 'cw':
  208. $profile->cw = !$profile->cw;
  209. $msg = "Success!";
  210. break;
  211. case 'no_autolink':
  212. $profile->no_autolink = !$profile->no_autolink;
  213. $msg = "Success!";
  214. break;
  215. case 'unlisted':
  216. $profile->unlisted = !$profile->unlisted;
  217. $msg = "Success!";
  218. break;
  219. }
  220. $profile->save();
  221. ModLogService::boot()
  222. ->objectUid($profile->user_id)
  223. ->objectId($profile->user_id)
  224. ->objectType('App\User::class')
  225. ->user($request->user())
  226. ->action('admin.user.moderate')
  227. ->metadata([
  228. 'action' => $action,
  229. 'message' => $msg
  230. ])
  231. ->accessLevel('admin')
  232. ->save();
  233. $request->session()->flash('status', $msg);
  234. return redirect('/i/admin/users/modtools/' . $profile->user_id);
  235. }
  236. public function userModLogDelete(Request $request, $id)
  237. {
  238. $this->validate($request, [
  239. 'mid' => 'required|integer|exists:mod_logs,id'
  240. ]);
  241. $user = User::findOrFail($id);
  242. $uid = $request->user()->id;
  243. $mid = $request->input('mid');
  244. $ml = ModLog::whereUserId($uid)->findOrFail($mid)->delete();
  245. $msg = "Successfully deleted modlog comment!";
  246. $request->session()->flash('status', $msg);
  247. return redirect('/i/admin/users/modlogs/' . $user->id);
  248. }
  249. }