CuratedRegisterController.php 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Jobs\CuratedOnboarding\CuratedOnboardingNotifyAdminNewApplicationPipeline;
  4. use App\Mail\CuratedRegisterConfirmEmail;
  5. use App\Models\CuratedRegister;
  6. use App\Models\CuratedRegisterActivity;
  7. use App\Services\EmailService;
  8. use App\Util\Lexer\RestrictedNames;
  9. use Illuminate\Http\Request;
  10. use Illuminate\Support\Facades\Mail;
  11. use Illuminate\Support\Str;
  12. class CuratedRegisterController extends Controller
  13. {
  14. public function preCheck($allowWhenDisabled = false)
  15. {
  16. if (! $allowWhenDisabled) {
  17. abort_unless((bool) config_cache('instance.curated_registration.enabled'), 404);
  18. if ((bool) config_cache('pixelfed.open_registration')) {
  19. abort_if(config('instance.curated_registration.state.only_enabled_on_closed_reg'), 404);
  20. } else {
  21. abort_unless(config('instance.curated_registration.state.fallback_on_closed_reg'), 404);
  22. }
  23. } else {
  24. abort_unless(config('instance.curated_registration.state.fallback_on_closed_reg'), 404);
  25. }
  26. }
  27. public function index(Request $request)
  28. {
  29. abort_if($request->user(), 404);
  30. return view('auth.curated-register.index', ['step' => 1]);
  31. }
  32. public function concierge(Request $request)
  33. {
  34. abort_if($request->user(), 404);
  35. $this->preCheck(true);
  36. $emailConfirmed = $request->session()->has('cur-reg-con.email-confirmed') &&
  37. $request->has('next') &&
  38. $request->session()->has('cur-reg-con.cr-id');
  39. return view('auth.curated-register.concierge', compact('emailConfirmed'));
  40. }
  41. public function conciergeResponseSent(Request $request)
  42. {
  43. $this->preCheck(true);
  44. return view('auth.curated-register.user_response_sent');
  45. }
  46. public function conciergeFormShow(Request $request)
  47. {
  48. abort_if($request->user(), 404);
  49. $this->preCheck(true);
  50. abort_unless(
  51. $request->session()->has('cur-reg-con.email-confirmed') &&
  52. $request->session()->has('cur-reg-con.cr-id') &&
  53. $request->session()->has('cur-reg-con.ac-id'), 404);
  54. $crid = $request->session()->get('cur-reg-con.cr-id');
  55. $arid = $request->session()->get('cur-reg-con.ac-id');
  56. $showCaptcha = config('instance.curated_registration.captcha_enabled');
  57. if ($attempts = $request->session()->get('cur-reg-con-attempt')) {
  58. $showCaptcha = $attempts && $attempts >= 2;
  59. } else {
  60. $showCaptcha = false;
  61. }
  62. $activity = CuratedRegisterActivity::whereRegisterId($crid)->whereFromAdmin(true)->findOrFail($arid);
  63. return view('auth.curated-register.concierge_form', compact('activity', 'showCaptcha'));
  64. }
  65. public function conciergeFormStore(Request $request)
  66. {
  67. abort_if($request->user(), 404);
  68. $this->preCheck(true);
  69. $request->session()->increment('cur-reg-con-attempt');
  70. abort_unless(
  71. $request->session()->has('cur-reg-con.email-confirmed') &&
  72. $request->session()->has('cur-reg-con.cr-id') &&
  73. $request->session()->has('cur-reg-con.ac-id'), 404);
  74. $attempts = $request->session()->get('cur-reg-con-attempt');
  75. $messages = [];
  76. $rules = [
  77. 'response' => 'required|string|min:5|max:1000',
  78. 'crid' => 'required|integer|min:1',
  79. 'acid' => 'required|integer|min:1',
  80. ];
  81. if (config('instance.curated_registration.captcha_enabled') && $attempts >= 3) {
  82. $rules['h-captcha-response'] = 'required|captcha';
  83. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  84. }
  85. $this->validate($request, $rules, $messages);
  86. $crid = $request->session()->get('cur-reg-con.cr-id');
  87. $acid = $request->session()->get('cur-reg-con.ac-id');
  88. abort_if((string) $crid !== $request->input('crid'), 404);
  89. abort_if((string) $acid !== $request->input('acid'), 404);
  90. if (CuratedRegisterActivity::whereRegisterId($crid)->whereReplyToId($acid)->exists()) {
  91. return redirect()->back()->withErrors(['code' => 'You already replied to this request.']);
  92. }
  93. $act = CuratedRegisterActivity::create([
  94. 'register_id' => $crid,
  95. 'reply_to_id' => $acid,
  96. 'type' => 'user_response',
  97. 'message' => $request->input('response'),
  98. 'from_user' => true,
  99. 'action_required' => true,
  100. ]);
  101. CuratedRegister::findOrFail($crid)->update(['user_has_responded' => true]);
  102. $request->session()->pull('cur-reg-con');
  103. $request->session()->pull('cur-reg-con-attempt');
  104. return view('auth.curated-register.user_response_sent');
  105. }
  106. public function conciergeStore(Request $request)
  107. {
  108. abort_if($request->user(), 404);
  109. $this->preCheck(true);
  110. $rules = [
  111. 'sid' => 'required_if:action,email|integer|min:1|max:20000000',
  112. 'id' => 'required_if:action,email|integer|min:1|max:20000000',
  113. 'code' => 'required_if:action,email',
  114. 'action' => 'required|string|in:email,message',
  115. 'email' => 'required_if:action,email|email',
  116. 'response' => 'required_if:action,message|string|min:20|max:1000',
  117. ];
  118. $messages = [];
  119. if (config('instance.curated_registration.captcha_enabled')) {
  120. $rules['h-captcha-response'] = 'required|captcha';
  121. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  122. }
  123. $this->validate($request, $rules, $messages);
  124. $action = $request->input('action');
  125. $sid = $request->input('sid');
  126. $id = $request->input('id');
  127. $code = $request->input('code');
  128. $email = $request->input('email');
  129. $cr = CuratedRegister::whereIsClosed(false)->findOrFail($sid);
  130. $ac = CuratedRegisterActivity::whereRegisterId($cr->id)->whereFromAdmin(true)->findOrFail($id);
  131. if (! hash_equals($ac->secret_code, $code)) {
  132. return redirect()->back()->withErrors(['code' => 'Invalid code']);
  133. }
  134. if (! hash_equals($cr->email, $email)) {
  135. return redirect()->back()->withErrors(['email' => 'Invalid email']);
  136. }
  137. $request->session()->put('cur-reg-con.email-confirmed', true);
  138. $request->session()->put('cur-reg-con.cr-id', $cr->id);
  139. $request->session()->put('cur-reg-con.ac-id', $ac->id);
  140. $emailConfirmed = true;
  141. return redirect('/auth/sign_up/concierge/form');
  142. }
  143. public function confirmEmail(Request $request)
  144. {
  145. if ($request->user()) {
  146. return redirect(route('help.email-confirmation-issues'));
  147. }
  148. $this->preCheck(true);
  149. return view('auth.curated-register.confirm_email');
  150. }
  151. public function emailConfirmed(Request $request)
  152. {
  153. if ($request->user()) {
  154. return redirect(route('help.email-confirmation-issues'));
  155. }
  156. $this->preCheck(true);
  157. return view('auth.curated-register.email_confirmed');
  158. }
  159. public function resendConfirmation(Request $request)
  160. {
  161. if ($request->user()) {
  162. return redirect(route('help.email-confirmation-issues'));
  163. }
  164. $this->preCheck(true);
  165. return view('auth.curated-register.resend-confirmation');
  166. }
  167. public function resendConfirmationProcess(Request $request)
  168. {
  169. if ($request->user()) {
  170. return redirect(route('help.email-confirmation-issues'));
  171. }
  172. $this->preCheck(true);
  173. $rules = [
  174. 'email' => [
  175. 'required',
  176. 'string',
  177. app()->environment() === 'production' ? 'email:rfc,dns,spoof' : 'email',
  178. 'exists:curated_registers',
  179. ],
  180. ];
  181. $messages = [];
  182. if (config('instance.curated_registration.captcha_enabled')) {
  183. $rules['h-captcha-response'] = 'required|captcha';
  184. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  185. }
  186. $this->validate($request, $rules, $messages);
  187. $cur = CuratedRegister::whereEmail($request->input('email'))->whereIsClosed(false)->first();
  188. if (! $cur) {
  189. return redirect()->back()->withErrors(['email' => 'The selected email is invalid.']);
  190. }
  191. $totalCount = CuratedRegisterActivity::whereRegisterId($cur->id)
  192. ->whereType('user_resend_email_confirmation')
  193. ->count();
  194. if ($totalCount && $totalCount >= config('instance.curated_registration.resend_confirmation_limit')) {
  195. return redirect()->back()->withErrors(['email' => 'You have re-attempted too many times. To proceed with your application, please <a href="/site/contact" class="text-white" style="text-decoration: underline;">contact the admin team</a>.']);
  196. }
  197. $count = CuratedRegisterActivity::whereRegisterId($cur->id)
  198. ->whereType('user_resend_email_confirmation')
  199. ->where('created_at', '>', now()->subHours(12))
  200. ->count();
  201. if ($count) {
  202. return redirect()->back()->withErrors(['email' => 'You can only re-send the confirmation email once per 12 hours. Try again later.']);
  203. }
  204. DB::transaction(function () use ($cur) {
  205. $cur->verify_code = Str::random(40);
  206. $cur->created_at = now();
  207. $cur->save();
  208. CuratedRegisterActivity::create([
  209. 'register_id' => $cur->id,
  210. 'type' => 'user_resend_email_confirmation',
  211. 'admin_only_view' => true,
  212. 'from_admin' => false,
  213. 'from_user' => false,
  214. 'action_required' => false,
  215. ]);
  216. Mail::to($cur->email)->send(new CuratedRegisterConfirmEmail($cur));
  217. });
  218. return view('auth.curated-register.resent-confirmation');
  219. }
  220. public function confirmEmailHandle(Request $request)
  221. {
  222. if ($request->user()) {
  223. return redirect(route('help.email-confirmation-issues'));
  224. }
  225. $this->preCheck(true);
  226. $rules = [
  227. 'sid' => 'required',
  228. 'code' => 'required',
  229. ];
  230. $messages = [];
  231. if (config('instance.curated_registration.captcha_enabled')) {
  232. $rules['h-captcha-response'] = 'required|captcha';
  233. $messages['h-captcha-response.required'] = 'The captcha must be filled';
  234. }
  235. $this->validate($request, $rules, $messages);
  236. $cr = CuratedRegister::whereNull('email_verified_at')
  237. ->where('created_at', '>', now()->subDays(7))
  238. ->find($request->input('sid'));
  239. if (! $cr) {
  240. return redirect(route('help.email-confirmation-issues'));
  241. }
  242. if (! hash_equals($cr->verify_code, $request->input('code'))) {
  243. return redirect(route('help.email-confirmation-issues'));
  244. }
  245. $cr->email_verified_at = now();
  246. $cr->save();
  247. if (config('instance.curated_registration.notify.admin.on_verify_email.enabled')) {
  248. CuratedOnboardingNotifyAdminNewApplicationPipeline::dispatch($cr);
  249. }
  250. return view('auth.curated-register.email_confirmed');
  251. }
  252. public function proceed(Request $request)
  253. {
  254. if ($request->user()) {
  255. return redirect(route('help.email-confirmation-issues'));
  256. }
  257. $this->preCheck(false);
  258. $this->validate($request, [
  259. 'step' => 'required|integer|in:1,2,3,4',
  260. ]);
  261. $step = $request->input('step');
  262. switch ($step) {
  263. case 1:
  264. $step = 2;
  265. $request->session()->put('cur-step', 1);
  266. return view('auth.curated-register.index', compact('step'));
  267. break;
  268. case 2:
  269. $this->stepTwo($request);
  270. $step = 3;
  271. $request->session()->put('cur-step', 2);
  272. return view('auth.curated-register.index', compact('step'));
  273. break;
  274. case 3:
  275. $this->stepThree($request);
  276. $step = 3;
  277. $request->session()->put('cur-step', 3);
  278. $verifiedEmail = true;
  279. $request->session()->pull('cur-reg');
  280. return view('auth.curated-register.index', compact('step', 'verifiedEmail'));
  281. break;
  282. }
  283. }
  284. protected function stepTwo($request)
  285. {
  286. if ($request->filled('reason')) {
  287. $request->session()->put('cur-reg.form-reason', $request->input('reason'));
  288. }
  289. if ($request->filled('username')) {
  290. $request->session()->put('cur-reg.form-username', $request->input('username'));
  291. }
  292. if ($request->filled('email')) {
  293. $request->session()->put('cur-reg.form-email', $request->input('email'));
  294. }
  295. $this->validate($request, [
  296. 'username' => [
  297. 'required',
  298. 'min:2',
  299. 'max:30',
  300. 'unique:curated_registers',
  301. 'unique:users',
  302. function ($attribute, $value, $fail) {
  303. $dash = substr_count($value, '-');
  304. $underscore = substr_count($value, '_');
  305. $period = substr_count($value, '.');
  306. if (ends_with($value, ['.php', '.js', '.css'])) {
  307. return $fail('Username is invalid.');
  308. }
  309. if (($dash + $underscore + $period) > 1) {
  310. return $fail('Username is invalid. Can only contain one dash (-), period (.) or underscore (_).');
  311. }
  312. if (! ctype_alnum($value[0])) {
  313. return $fail('Username is invalid. Must start with a letter or number.');
  314. }
  315. if (! ctype_alnum($value[strlen($value) - 1])) {
  316. return $fail('Username is invalid. Must end with a letter or number.');
  317. }
  318. $val = str_replace(['_', '.', '-'], '', $value);
  319. if (! ctype_alnum($val)) {
  320. return $fail('Username is invalid. Username must be alpha-numeric and may contain dashes (-), periods (.) and underscores (_).');
  321. }
  322. $restricted = RestrictedNames::get();
  323. if (in_array(strtolower($value), array_map('strtolower', $restricted))) {
  324. return $fail('Username cannot be used.');
  325. }
  326. },
  327. ],
  328. 'email' => [
  329. 'required',
  330. 'string',
  331. app()->environment() === 'production' ? 'email:rfc,dns,spoof' : 'email',
  332. 'max:255',
  333. 'unique:users',
  334. 'unique:curated_registers',
  335. function ($attribute, $value, $fail) {
  336. $banned = EmailService::isBanned($value);
  337. if ($banned) {
  338. return $fail('Email is invalid.');
  339. }
  340. },
  341. ],
  342. 'password' => 'required|min:8',
  343. 'password_confirmation' => 'required|same:password',
  344. 'reason' => 'required|min:20|max:1000',
  345. 'agree' => 'required|accepted',
  346. ]);
  347. $request->session()->put('cur-reg.form-email', $request->input('email'));
  348. $request->session()->put('cur-reg.form-password', $request->input('password'));
  349. }
  350. protected function stepThree($request)
  351. {
  352. $this->validate($request, [
  353. 'email' => [
  354. 'required',
  355. 'string',
  356. app()->environment() === 'production' ? 'email:rfc,dns,spoof' : 'email',
  357. 'max:255',
  358. 'unique:users',
  359. 'unique:curated_registers',
  360. function ($attribute, $value, $fail) {
  361. $banned = EmailService::isBanned($value);
  362. if ($banned) {
  363. return $fail('Email is invalid.');
  364. }
  365. },
  366. ],
  367. ]);
  368. $cr = new CuratedRegister;
  369. $cr->email = $request->email;
  370. $cr->username = $request->session()->get('cur-reg.form-username');
  371. $cr->password = bcrypt($request->session()->get('cur-reg.form-password'));
  372. $cr->ip_address = $request->ip();
  373. $cr->reason_to_join = $request->session()->get('cur-reg.form-reason');
  374. $cr->verify_code = Str::random(40);
  375. $cr->save();
  376. Mail::to($cr->email)->send(new CuratedRegisterConfirmEmail($cr));
  377. }
  378. }