CuratedRegisterController.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398
  1. <?php
  2. namespace App\Http\Controllers;
  3. use Illuminate\Http\Request;
  4. use Illuminate\Support\Str;
  5. use App\User;
  6. use App\Models\CuratedRegister;
  7. use App\Models\CuratedRegisterActivity;
  8. use App\Services\EmailService;
  9. use App\Services\BouncerService;
  10. use App\Util\Lexer\RestrictedNames;
  11. use App\Mail\CuratedRegisterConfirmEmail;
  12. use App\Mail\CuratedRegisterNotifyAdmin;
  13. use Illuminate\Support\Facades\Mail;
  14. use App\Jobs\CuratedOnboarding\CuratedOnboardingNotifyAdminNewApplicationPipeline;
  15. class CuratedRegisterController extends Controller
  16. {
  17. public function __construct()
  18. {
  19. abort_unless((bool) config_cache('instance.curated_registration.enabled'), 404);
  20. if((bool) config_cache('pixelfed.open_registration')) {
  21. abort_if(config('instance.curated_registration.state.only_enabled_on_closed_reg'), 404);
  22. } else {
  23. abort_unless(config('instance.curated_registration.state.fallback_on_closed_reg'), 404);
  24. }
  25. }
  26. public function index(Request $request)
  27. {
  28. abort_if($request->user(), 404);
  29. return view('auth.curated-register.index', ['step' => 1]);
  30. }
  31. public function concierge(Request $request)
  32. {
  33. abort_if($request->user(), 404);
  34. $emailConfirmed = $request->session()->has('cur-reg-con.email-confirmed') &&
  35. $request->has('next') &&
  36. $request->session()->has('cur-reg-con.cr-id');
  37. return view('auth.curated-register.concierge', compact('emailConfirmed'));
  38. }
  39. public function conciergeResponseSent(Request $request)
  40. {
  41. return view('auth.curated-register.user_response_sent');
  42. }
  43. public function conciergeFormShow(Request $request)
  44. {
  45. abort_if($request->user(), 404);
  46. abort_unless(
  47. $request->session()->has('cur-reg-con.email-confirmed') &&
  48. $request->session()->has('cur-reg-con.cr-id') &&
  49. $request->session()->has('cur-reg-con.ac-id'), 404);
  50. $crid = $request->session()->get('cur-reg-con.cr-id');
  51. $arid = $request->session()->get('cur-reg-con.ac-id');
  52. $showCaptcha = config('instance.curated_registration.captcha_enabled');
  53. if($attempts = $request->session()->get('cur-reg-con-attempt')) {
  54. $showCaptcha = $attempts && $attempts >= 2;
  55. } else {
  56. $showCaptcha = false;
  57. }
  58. $activity = CuratedRegisterActivity::whereRegisterId($crid)->whereFromAdmin(true)->findOrFail($arid);
  59. return view('auth.curated-register.concierge_form', compact('activity', 'showCaptcha'));
  60. }
  61. public function conciergeFormStore(Request $request)
  62. {
  63. abort_if($request->user(), 404);
  64. $request->session()->increment('cur-reg-con-attempt');
  65. abort_unless(
  66. $request->session()->has('cur-reg-con.email-confirmed') &&
  67. $request->session()->has('cur-reg-con.cr-id') &&
  68. $request->session()->has('cur-reg-con.ac-id'), 404);
  69. $attempts = $request->session()->get('cur-reg-con-attempt');
  70. $messages = [];
  71. $rules = [
  72. 'response' => 'required|string|min:5|max:1000',
  73. 'crid' => 'required|integer|min:1',
  74. 'acid' => 'required|integer|min:1'
  75. ];
  76. if(config('instance.curated_registration.captcha_enabled') && $attempts >= 3) {
  77. $rules['h-captcha-response'] = 'required|captcha';
  78. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  79. }
  80. $this->validate($request, $rules, $messages);
  81. $crid = $request->session()->get('cur-reg-con.cr-id');
  82. $acid = $request->session()->get('cur-reg-con.ac-id');
  83. abort_if((string) $crid !== $request->input('crid'), 404);
  84. abort_if((string) $acid !== $request->input('acid'), 404);
  85. if(CuratedRegisterActivity::whereRegisterId($crid)->whereReplyToId($acid)->exists()) {
  86. return redirect()->back()->withErrors(['code' => 'You already replied to this request.']);
  87. }
  88. $act = CuratedRegisterActivity::create([
  89. 'register_id' => $crid,
  90. 'reply_to_id' => $acid,
  91. 'type' => 'user_response',
  92. 'message' => $request->input('response'),
  93. 'from_user' => true,
  94. 'action_required' => true,
  95. ]);
  96. $request->session()->pull('cur-reg-con');
  97. $request->session()->pull('cur-reg-con-attempt');
  98. return view('auth.curated-register.user_response_sent');
  99. }
  100. public function conciergeStore(Request $request)
  101. {
  102. abort_if($request->user(), 404);
  103. $rules = [
  104. 'sid' => 'required_if:action,email|integer|min:1|max:20000000',
  105. 'id' => 'required_if:action,email|integer|min:1|max:20000000',
  106. 'code' => 'required_if:action,email',
  107. 'action' => 'required|string|in:email,message',
  108. 'email' => 'required_if:action,email|email',
  109. 'response' => 'required_if:action,message|string|min:20|max:1000',
  110. ];
  111. $messages = [];
  112. if(config('instance.curated_registration.captcha_enabled')) {
  113. $rules['h-captcha-response'] = 'required|captcha';
  114. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  115. }
  116. $this->validate($request, $rules, $messages);
  117. $action = $request->input('action');
  118. $sid = $request->input('sid');
  119. $id = $request->input('id');
  120. $code = $request->input('code');
  121. $email = $request->input('email');
  122. $cr = CuratedRegister::whereIsClosed(false)->findOrFail($sid);
  123. $ac = CuratedRegisterActivity::whereRegisterId($cr->id)->whereFromAdmin(true)->findOrFail($id);
  124. if(!hash_equals($ac->secret_code, $code)) {
  125. return redirect()->back()->withErrors(['code' => 'Invalid code']);
  126. }
  127. if(!hash_equals($cr->email, $email)) {
  128. return redirect()->back()->withErrors(['email' => 'Invalid email']);
  129. }
  130. $request->session()->put('cur-reg-con.email-confirmed', true);
  131. $request->session()->put('cur-reg-con.cr-id', $cr->id);
  132. $request->session()->put('cur-reg-con.ac-id', $ac->id);
  133. $emailConfirmed = true;
  134. return redirect('/auth/sign_up/concierge/form');
  135. }
  136. public function confirmEmail(Request $request)
  137. {
  138. if($request->user()) {
  139. return redirect(route('help.email-confirmation-issues'));
  140. }
  141. return view('auth.curated-register.confirm_email');
  142. }
  143. public function emailConfirmed(Request $request)
  144. {
  145. if($request->user()) {
  146. return redirect(route('help.email-confirmation-issues'));
  147. }
  148. return view('auth.curated-register.email_confirmed');
  149. }
  150. public function resendConfirmation(Request $request)
  151. {
  152. return view('auth.curated-register.resend-confirmation');
  153. }
  154. public function resendConfirmationProcess(Request $request)
  155. {
  156. $rules = [
  157. 'email' => [
  158. 'required',
  159. 'string',
  160. app()->environment() === 'production' ? 'email:rfc,dns,spoof' : 'email',
  161. 'exists:curated_registers',
  162. ]
  163. ];
  164. $messages = [];
  165. if(config('instance.curated_registration.captcha_enabled')) {
  166. $rules['h-captcha-response'] = 'required|captcha';
  167. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  168. }
  169. $this->validate($request, $rules, $messages);
  170. $cur = CuratedRegister::whereEmail($request->input('email'))->whereIsClosed(false)->first();
  171. if(!$cur) {
  172. return redirect()->back()->withErrors(['email' => 'The selected email is invalid.']);
  173. }
  174. $totalCount = CuratedRegisterActivity::whereRegisterId($cur->id)
  175. ->whereType('user_resend_email_confirmation')
  176. ->count();
  177. if($totalCount && $totalCount >= config('instance.curated_registration.resend_confirmation_limit')) {
  178. return redirect()->back()->withErrors(['email' => 'You have re-attempted too many times. To proceed with your application, please <a href="/site/contact" class="text-white" style="text-decoration: underline;">contact the admin team</a>.']);
  179. }
  180. $count = CuratedRegisterActivity::whereRegisterId($cur->id)
  181. ->whereType('user_resend_email_confirmation')
  182. ->where('created_at', '>', now()->subHours(12))
  183. ->count();
  184. if($count) {
  185. return redirect()->back()->withErrors(['email' => 'You can only re-send the confirmation email once per 12 hours. Try again later.']);
  186. }
  187. CuratedRegisterActivity::create([
  188. 'register_id' => $cur->id,
  189. 'type' => 'user_resend_email_confirmation',
  190. 'admin_only_view' => true,
  191. 'from_admin' => false,
  192. 'from_user' => false,
  193. 'action_required' => false,
  194. ]);
  195. Mail::to($cur->email)->send(new CuratedRegisterConfirmEmail($cur));
  196. return view('auth.curated-register.resent-confirmation');
  197. return $request->all();
  198. }
  199. public function confirmEmailHandle(Request $request)
  200. {
  201. $rules = [
  202. 'sid' => 'required',
  203. 'code' => 'required'
  204. ];
  205. $messages = [];
  206. if(config('instance.curated_registration.captcha_enabled')) {
  207. $rules['h-captcha-response'] = 'required|captcha';
  208. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  209. }
  210. $this->validate($request, $rules, $messages);
  211. $cr = CuratedRegister::whereNull('email_verified_at')
  212. ->where('created_at', '>', now()->subHours(24))
  213. ->find($request->input('sid'));
  214. if(!$cr) {
  215. return redirect(route('help.email-confirmation-issues'));
  216. }
  217. if(!hash_equals($cr->verify_code, $request->input('code'))) {
  218. return redirect(route('help.email-confirmation-issues'));
  219. }
  220. $cr->email_verified_at = now();
  221. $cr->save();
  222. if(config('instance.curated_registration.notify.admin.on_verify_email.enabled')) {
  223. CuratedOnboardingNotifyAdminNewApplicationPipeline::dispatch($cr);
  224. }
  225. return view('auth.curated-register.email_confirmed');
  226. }
  227. public function proceed(Request $request)
  228. {
  229. $this->validate($request, [
  230. 'step' => 'required|integer|in:1,2,3,4'
  231. ]);
  232. $step = $request->input('step');
  233. switch($step) {
  234. case 1:
  235. $step = 2;
  236. $request->session()->put('cur-step', 1);
  237. return view('auth.curated-register.index', compact('step'));
  238. break;
  239. case 2:
  240. $this->stepTwo($request);
  241. $step = 3;
  242. $request->session()->put('cur-step', 2);
  243. return view('auth.curated-register.index', compact('step'));
  244. break;
  245. case 3:
  246. $this->stepThree($request);
  247. $step = 3;
  248. $request->session()->put('cur-step', 3);
  249. $verifiedEmail = true;
  250. $request->session()->pull('cur-reg');
  251. return view('auth.curated-register.index', compact('step', 'verifiedEmail'));
  252. break;
  253. }
  254. }
  255. protected function stepTwo($request)
  256. {
  257. if($request->filled('reason')) {
  258. $request->session()->put('cur-reg.form-reason', $request->input('reason'));
  259. }
  260. if($request->filled('username')) {
  261. $request->session()->put('cur-reg.form-username', $request->input('username'));
  262. }
  263. if($request->filled('email')) {
  264. $request->session()->put('cur-reg.form-email', $request->input('email'));
  265. }
  266. $this->validate($request, [
  267. 'username' => [
  268. 'required',
  269. 'min:2',
  270. 'max:15',
  271. 'unique:curated_registers',
  272. 'unique:users',
  273. function ($attribute, $value, $fail) {
  274. $dash = substr_count($value, '-');
  275. $underscore = substr_count($value, '_');
  276. $period = substr_count($value, '.');
  277. if(ends_with($value, ['.php', '.js', '.css'])) {
  278. return $fail('Username is invalid.');
  279. }
  280. if(($dash + $underscore + $period) > 1) {
  281. return $fail('Username is invalid. Can only contain one dash (-), period (.) or underscore (_).');
  282. }
  283. if (!ctype_alnum($value[0])) {
  284. return $fail('Username is invalid. Must start with a letter or number.');
  285. }
  286. if (!ctype_alnum($value[strlen($value) - 1])) {
  287. return $fail('Username is invalid. Must end with a letter or number.');
  288. }
  289. $val = str_replace(['_', '.', '-'], '', $value);
  290. if(!ctype_alnum($val)) {
  291. return $fail('Username is invalid. Username must be alpha-numeric and may contain dashes (-), periods (.) and underscores (_).');
  292. }
  293. $restricted = RestrictedNames::get();
  294. if (in_array(strtolower($value), array_map('strtolower', $restricted))) {
  295. return $fail('Username cannot be used.');
  296. }
  297. },
  298. ],
  299. 'email' => [
  300. 'required',
  301. 'string',
  302. app()->environment() === 'production' ? 'email:rfc,dns,spoof' : 'email',
  303. 'max:255',
  304. 'unique:users',
  305. 'unique:curated_registers',
  306. function ($attribute, $value, $fail) {
  307. $banned = EmailService::isBanned($value);
  308. if($banned) {
  309. return $fail('Email is invalid.');
  310. }
  311. },
  312. ],
  313. 'password' => 'required|min:8',
  314. 'password_confirmation' => 'required|same:password',
  315. 'reason' => 'required|min:20|max:1000',
  316. 'agree' => 'required|accepted'
  317. ]);
  318. $request->session()->put('cur-reg.form-email', $request->input('email'));
  319. $request->session()->put('cur-reg.form-password', $request->input('password'));
  320. }
  321. protected function stepThree($request)
  322. {
  323. $this->validate($request, [
  324. 'email' => [
  325. 'required',
  326. 'string',
  327. app()->environment() === 'production' ? 'email:rfc,dns,spoof' : 'email',
  328. 'max:255',
  329. 'unique:users',
  330. 'unique:curated_registers',
  331. function ($attribute, $value, $fail) {
  332. $banned = EmailService::isBanned($value);
  333. if($banned) {
  334. return $fail('Email is invalid.');
  335. }
  336. },
  337. ]
  338. ]);
  339. $cr = new CuratedRegister;
  340. $cr->email = $request->email;
  341. $cr->username = $request->session()->get('cur-reg.form-username');
  342. $cr->password = bcrypt($request->session()->get('cur-reg.form-password'));
  343. $cr->ip_address = $request->ip();
  344. $cr->reason_to_join = $request->session()->get('cur-reg.form-reason');
  345. $cr->verify_code = Str::random(40);
  346. $cr->save();
  347. Mail::to($cr->email)->send(new CuratedRegisterConfirmEmail($cr));
  348. }
  349. }