AdminInviteController.php 6.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191
  1. <?php
  2. namespace App\Http\Controllers;
  3. use Illuminate\Http\Request;
  4. use App\Models\AdminInvite;
  5. use App\Profile;
  6. use App\User;
  7. use App\Util\Lexer\RestrictedNames;
  8. use Illuminate\Foundation\Auth\RegistersUsers;
  9. use Illuminate\Support\Facades\Auth;
  10. use Illuminate\Support\Facades\Hash;
  11. use Illuminate\Support\Facades\Validator;
  12. use Illuminate\Auth\Events\Registered;
  13. use App\Services\EmailService;
  14. use App\Http\Controllers\Auth\RegisterController;
  15. class AdminInviteController extends Controller
  16. {
  17. public function __construct()
  18. {
  19. abort_if(!config('instance.admin_invites.enabled'), 404);
  20. }
  21. public function index(Request $request, $code)
  22. {
  23. if($request->user()) {
  24. return redirect('/');
  25. }
  26. return view('invite.admin_invite', compact('code'));
  27. }
  28. public function apiVerifyCheck(Request $request)
  29. {
  30. $this->validate($request, [
  31. 'token' => 'required',
  32. ]);
  33. $invite = AdminInvite::whereInviteCode($request->input('token'))->first();
  34. abort_if(!$invite, 404);
  35. abort_if($invite->expires_at && $invite->expires_at->lt(now()), 400, 'Invite has expired.');
  36. abort_if($invite->max_uses && $invite->uses >= $invite->max_uses, 400, 'Maximum invites reached.');
  37. $res = [
  38. 'message' => $invite->message,
  39. 'max_uses' => $invite->max_uses,
  40. 'sev' => $invite->skip_email_verification
  41. ];
  42. return response()->json($res);
  43. }
  44. public function apiUsernameCheck(Request $request)
  45. {
  46. $this->validate($request, [
  47. 'token' => 'required',
  48. 'username' => 'required'
  49. ]);
  50. $invite = AdminInvite::whereInviteCode($request->input('token'))->first();
  51. abort_if(!$invite, 404);
  52. abort_if($invite->expires_at && $invite->expires_at->lt(now()), 400, 'Invite has expired.');
  53. abort_if($invite->max_uses && $invite->uses >= $invite->max_uses, 400, 'Maximum invites reached.');
  54. $usernameRules = [
  55. 'required',
  56. 'min:2',
  57. 'max:15',
  58. 'unique:users',
  59. function ($attribute, $value, $fail) {
  60. $dash = substr_count($value, '-');
  61. $underscore = substr_count($value, '_');
  62. $period = substr_count($value, '.');
  63. if(ends_with($value, ['.php', '.js', '.css'])) {
  64. return $fail('Username is invalid.');
  65. }
  66. if(($dash + $underscore + $period) > 1) {
  67. return $fail('Username is invalid. Can only contain one dash (-), period (.) or underscore (_).');
  68. }
  69. if (!ctype_alnum($value[0])) {
  70. return $fail('Username is invalid. Must start with a letter or number.');
  71. }
  72. if (!ctype_alnum($value[strlen($value) - 1])) {
  73. return $fail('Username is invalid. Must end with a letter or number.');
  74. }
  75. $val = str_replace(['_', '.', '-'], '', $value);
  76. if(!ctype_alnum($val)) {
  77. return $fail('Username is invalid. Username must be alpha-numeric and may contain dashes (-), periods (.) and underscores (_).');
  78. }
  79. $restricted = RestrictedNames::get();
  80. if (in_array(strtolower($value), array_map('strtolower', $restricted))) {
  81. return $fail('Username cannot be used.');
  82. }
  83. },
  84. ];
  85. $rules = ['username' => $usernameRules];
  86. $validator = Validator::make($request->all(), $rules);
  87. if($validator->fails()) {
  88. return response()->json($validator->errors(), 400);
  89. }
  90. return response()->json([]);
  91. }
  92. public function apiEmailCheck(Request $request)
  93. {
  94. $this->validate($request, [
  95. 'token' => 'required',
  96. 'email' => 'required'
  97. ]);
  98. $invite = AdminInvite::whereInviteCode($request->input('token'))->first();
  99. abort_if(!$invite, 404);
  100. abort_if($invite->expires_at && $invite->expires_at->lt(now()), 400, 'Invite has expired.');
  101. abort_if($invite->max_uses && $invite->uses >= $invite->max_uses, 400, 'Maximum invites reached.');
  102. $emailRules = [
  103. 'required',
  104. 'string',
  105. 'email',
  106. 'max:255',
  107. 'unique:users',
  108. function ($attribute, $value, $fail) {
  109. $banned = EmailService::isBanned($value);
  110. if($banned) {
  111. return $fail('Email is invalid.');
  112. }
  113. },
  114. ];
  115. $rules = ['email' => $emailRules];
  116. $validator = Validator::make($request->all(), $rules);
  117. if($validator->fails()) {
  118. return response()->json($validator->errors(), 400);
  119. }
  120. return response()->json([]);
  121. }
  122. public function apiRegister(Request $request)
  123. {
  124. $this->validate($request, [
  125. 'token' => 'required',
  126. 'username' => 'required',
  127. 'name' => 'nullable',
  128. 'email' => 'required|email',
  129. 'password' => 'required',
  130. 'password_confirm' => 'required'
  131. ]);
  132. $invite = AdminInvite::whereInviteCode($request->input('token'))->firstOrFail();
  133. abort_if($invite->expires_at && $invite->expires_at->lt(now()), 400, 'Invite expired');
  134. abort_if($invite->max_uses && $invite->uses >= $invite->max_uses, 400, 'Maximum invites reached.');
  135. $invite->uses = $invite->uses + 1;
  136. event(new Registered($user = User::create([
  137. 'name' => $request->input('name') ?? $request->input('username'),
  138. 'username' => $request->input('username'),
  139. 'email' => $request->input('email'),
  140. 'password' => Hash::make($request->input('password')),
  141. ])));
  142. $invite->used_by = array_merge($invite->used_by ?? [], [[
  143. 'user_id' => $user->id,
  144. 'username' => $user->username
  145. ]]);
  146. $invite->save();
  147. if($invite->skip_email_verification) {
  148. $user->email_verified_at = now();
  149. $user->save();
  150. }
  151. if(Auth::attempt([
  152. 'email' => $request->input('email'),
  153. 'password' => $request->input('password')
  154. ])) {
  155. $request->session()->regenerate();
  156. return redirect()->intended('/');
  157. } else {
  158. return response()->json([], 400);
  159. }
  160. }
  161. }