ParentalControlsController.php 7.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224
  1. <?php
  2. namespace App\Http\Controllers;
  3. use Illuminate\Http\Request;
  4. use App\Models\ParentalControls;
  5. use App\Models\UserRoles;
  6. use App\User;
  7. use App\Http\Controllers\Auth\RegisterController;
  8. use Illuminate\Auth\Events\Registered;
  9. use Illuminate\Support\Facades\Auth;
  10. use App\Services\UserRoleService;
  11. use App\Jobs\ParentalControlsPipeline\DispatchChildInvitePipeline;
  12. class ParentalControlsController extends Controller
  13. {
  14. public function authPreflight($request, $maxUserCheck = false, $authCheck = true)
  15. {
  16. if($authCheck) {
  17. abort_unless($request->user(), 404);
  18. }
  19. abort_unless(config('instance.parental_controls.enabled'), 404);
  20. if(config_cache('pixelfed.open_registration') == false) {
  21. abort_if(config('instance.parental_controls.limits.respect_open_registration'), 404);
  22. }
  23. if($maxUserCheck == true) {
  24. $hasLimit = config('pixelfed.enforce_max_users');
  25. if($hasLimit) {
  26. $count = User::where(function($q){ return $q->whereNull('status')->orWhereNotIn('status', ['deleted','delete']); })->count();
  27. $limit = (int) config('pixelfed.max_users');
  28. abort_if($limit && $limit <= $count, 404);
  29. }
  30. }
  31. }
  32. public function index(Request $request)
  33. {
  34. $this->authPreflight($request);
  35. $children = ParentalControls::whereParentId($request->user()->id)->latest()->paginate(5);
  36. return view('settings.parental-controls.index', compact('children'));
  37. }
  38. public function add(Request $request)
  39. {
  40. $this->authPreflight($request, true);
  41. return view('settings.parental-controls.add');
  42. }
  43. public function view(Request $request, $id)
  44. {
  45. $this->authPreflight($request);
  46. $uid = $request->user()->id;
  47. $pc = ParentalControls::whereParentId($uid)->findOrFail($id);
  48. return view('settings.parental-controls.manage', compact('pc'));
  49. }
  50. public function update(Request $request, $id)
  51. {
  52. $this->authPreflight($request);
  53. $uid = $request->user()->id;
  54. $ff = $this->requestFormFields($request);
  55. $pc = ParentalControls::whereParentId($uid)->findOrFail($id);
  56. $pc->permissions = $ff;
  57. $pc->save();
  58. $roles = UserRoleService::mapActions($pc->child_id, $ff);
  59. UserRoles::whereUserId($pc->child_id)->update(['roles' => $roles]);
  60. return redirect($pc->manageUrl() . '?permissions');
  61. }
  62. public function store(Request $request)
  63. {
  64. $this->authPreflight($request, true);
  65. $this->validate($request, [
  66. 'email' => 'required|email|unique:parental_controls,email|unique:users,email',
  67. ]);
  68. $state = $this->requestFormFields($request);
  69. $pc = new ParentalControls;
  70. $pc->parent_id = $request->user()->id;
  71. $pc->email = $request->input('email');
  72. $pc->verify_code = str_random(32);
  73. $pc->permissions = $state;
  74. $pc->save();
  75. DispatchChildInvitePipeline::dispatch($pc);
  76. return redirect($pc->manageUrl());
  77. }
  78. public function inviteRegister(Request $request, $id, $code)
  79. {
  80. if($request->user()) {
  81. $title = 'You cannot complete this action on this device.';
  82. $body = 'Please log out or use a different device or browser to complete the invitation registration.';
  83. return view('errors.custom', compact('title', 'body'));
  84. }
  85. $this->authPreflight($request, true, false);
  86. $pc = ParentalControls::whereRaw('verify_code = BINARY ?', $code)->whereNull(['email_verified_at', 'child_id'])->findOrFail($id);
  87. abort_unless(User::whereId($pc->parent_id)->exists(), 404);
  88. return view('settings.parental-controls.invite-register-form', compact('pc'));
  89. }
  90. public function inviteRegisterStore(Request $request, $id, $code)
  91. {
  92. if($request->user()) {
  93. $title = 'You cannot complete this action on this device.';
  94. $body = 'Please log out or use a different device or browser to complete the invitation registration.';
  95. return view('errors.custom', compact('title', 'body'));
  96. }
  97. $this->authPreflight($request, true, false);
  98. $pc = ParentalControls::whereRaw('verify_code = BINARY ?', $code)->whereNull('email_verified_at')->findOrFail($id);
  99. $fields = $request->all();
  100. $fields['email'] = $pc->email;
  101. $defaults = UserRoleService::defaultRoles();
  102. $validator = (new RegisterController)->validator($fields);
  103. $valid = $validator->validate();
  104. abort_if(!$valid, 404);
  105. event(new Registered($user = (new RegisterController)->create($fields)));
  106. sleep(5);
  107. $user->has_roles = true;
  108. $user->parent_id = $pc->parent_id;
  109. if(config('instance.parental_controls.limits.auto_verify_email')) {
  110. $user->email_verified_at = now();
  111. $user->save();
  112. sleep(3);
  113. } else {
  114. $user->save();
  115. sleep(3);
  116. }
  117. $ur = UserRoles::updateOrCreate([
  118. 'user_id' => $user->id,
  119. ],[
  120. 'roles' => UserRoleService::mapInvite($user->id, $pc->permissions)
  121. ]);
  122. $pc->email_verified_at = now();
  123. $pc->child_id = $user->id;
  124. $pc->save();
  125. sleep(2);
  126. Auth::guard()->login($user);
  127. return redirect('/i/web');
  128. }
  129. public function cancelInvite(Request $request, $id)
  130. {
  131. $this->authPreflight($request);
  132. $pc = ParentalControls::whereParentId($request->user()->id)
  133. ->whereNull(['email_verified_at', 'child_id'])
  134. ->findOrFail($id);
  135. return view('settings.parental-controls.delete-invite', compact('pc'));
  136. }
  137. public function cancelInviteHandle(Request $request, $id)
  138. {
  139. $this->authPreflight($request);
  140. $pc = ParentalControls::whereParentId($request->user()->id)
  141. ->whereNull(['email_verified_at', 'child_id'])
  142. ->findOrFail($id);
  143. $pc->delete();
  144. return redirect('/settings/parental-controls');
  145. }
  146. public function stopManaging(Request $request, $id)
  147. {
  148. $this->authPreflight($request);
  149. $pc = ParentalControls::whereParentId($request->user()->id)
  150. ->whereNotNull(['email_verified_at', 'child_id'])
  151. ->findOrFail($id);
  152. return view('settings.parental-controls.stop-managing', compact('pc'));
  153. }
  154. public function stopManagingHandle(Request $request, $id)
  155. {
  156. $this->authPreflight($request);
  157. $pc = ParentalControls::whereParentId($request->user()->id)
  158. ->whereNotNull(['email_verified_at', 'child_id'])
  159. ->findOrFail($id);
  160. $pc->child()->update([
  161. 'has_roles' => false,
  162. 'parent_id' => null,
  163. ]);
  164. $pc->delete();
  165. return redirect('/settings/parental-controls');
  166. }
  167. protected function requestFormFields($request)
  168. {
  169. $state = [];
  170. $fields = [
  171. 'post',
  172. 'comment',
  173. 'like',
  174. 'share',
  175. 'follow',
  176. 'bookmark',
  177. 'story',
  178. 'collection',
  179. 'discovery_feeds',
  180. 'dms',
  181. 'federation',
  182. 'hide_network',
  183. 'private',
  184. 'hide_cw'
  185. ];
  186. foreach ($fields as $field) {
  187. $state[$field] = $request->input($field) == 'on';
  188. }
  189. return $state;
  190. }
  191. }