ParentalControlsController.php 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207
  1. <?php
  2. namespace App\Http\Controllers;
  3. use Illuminate\Http\Request;
  4. use App\Models\ParentalControls;
  5. use App\Models\UserRoles;
  6. use App\User;
  7. use App\Http\Controllers\Auth\RegisterController;
  8. use Illuminate\Auth\Events\Registered;
  9. use Illuminate\Support\Facades\Auth;
  10. use App\Services\UserRoleService;
  11. use App\Jobs\ParentalControlsPipeline\DispatchChildInvitePipeline;
  12. class ParentalControlsController extends Controller
  13. {
  14. public function authPreflight($request, $maxUserCheck = false, $authCheck = true)
  15. {
  16. if($authCheck) {
  17. abort_unless($request->user(), 404);
  18. }
  19. abort_unless(config('instance.parental_controls.enabled'), 404);
  20. if(config_cache('pixelfed.open_registration') == false) {
  21. abort_if(config('instance.parental_controls.limits.respect_open_registration'), 404);
  22. }
  23. if($maxUserCheck == true) {
  24. $hasLimit = config('pixelfed.enforce_max_users');
  25. if($hasLimit) {
  26. $count = User::where(function($q){ return $q->whereNull('status')->orWhereNotIn('status', ['deleted','delete']); })->count();
  27. $limit = (int) config('pixelfed.max_users');
  28. abort_if($limit && $limit <= $count, 404);
  29. }
  30. }
  31. }
  32. public function index(Request $request)
  33. {
  34. $this->authPreflight($request);
  35. $children = ParentalControls::whereParentId($request->user()->id)->latest()->paginate(5);
  36. return view('settings.parental-controls.index', compact('children'));
  37. }
  38. public function add(Request $request)
  39. {
  40. $this->authPreflight($request, true);
  41. return view('settings.parental-controls.add');
  42. }
  43. public function view(Request $request, $id)
  44. {
  45. $this->authPreflight($request);
  46. $uid = $request->user()->id;
  47. $pc = ParentalControls::whereParentId($uid)->findOrFail($id);
  48. return view('settings.parental-controls.manage', compact('pc'));
  49. }
  50. public function update(Request $request, $id)
  51. {
  52. $this->authPreflight($request);
  53. $uid = $request->user()->id;
  54. $pc = ParentalControls::whereParentId($uid)->findOrFail($id);
  55. $pc->permissions = $this->requestFormFields($request);
  56. $pc->save();
  57. return redirect($pc->manageUrl() . '?permissions');
  58. }
  59. public function store(Request $request)
  60. {
  61. $this->authPreflight($request, true);
  62. $this->validate($request, [
  63. 'email' => 'required|email|unique:parental_controls,email|unique:users,email',
  64. ]);
  65. $state = $this->requestFormFields($request);
  66. $pc = new ParentalControls;
  67. $pc->parent_id = $request->user()->id;
  68. $pc->email = $request->input('email');
  69. $pc->verify_code = str_random(32);
  70. $pc->permissions = $state;
  71. $pc->save();
  72. DispatchChildInvitePipeline::dispatch($pc);
  73. return redirect($pc->manageUrl());
  74. }
  75. public function inviteRegister(Request $request, $id, $code)
  76. {
  77. $this->authPreflight($request, true, false);
  78. $pc = ParentalControls::whereRaw('verify_code = BINARY ?', $code)->whereNull(['email_verified_at', 'child_id'])->findOrFail($id);
  79. abort_unless(User::whereId($pc->parent_id)->exists(), 404);
  80. return view('settings.parental-controls.invite-register-form', compact('pc'));
  81. }
  82. public function inviteRegisterStore(Request $request, $id, $code)
  83. {
  84. $this->authPreflight($request, true, false);
  85. $pc = ParentalControls::whereRaw('verify_code = BINARY ?', $code)->whereNull('email_verified_at')->findOrFail($id);
  86. $fields = $request->all();
  87. $fields['email'] = $pc->email;
  88. $defaults = UserRoleService::defaultRoles();
  89. $validator = (new RegisterController)->validator($fields);
  90. $valid = $validator->validate();
  91. abort_if(!$valid, 404);
  92. event(new Registered($user = (new RegisterController)->create($fields)));
  93. sleep(5);
  94. $user->has_roles = true;
  95. $user->parent_id = $pc->parent_id;
  96. if(config('instance.parental_controls.limits.auto_verify_email')) {
  97. $user->email_verified_at = now();
  98. $user->save();
  99. sleep(3);
  100. } else {
  101. $user->save();
  102. sleep(3);
  103. }
  104. $ur = UserRoles::updateOrCreate([
  105. 'user_id' => $user->id,
  106. ],[
  107. 'roles' => UserRoleService::mapInvite($user->id, $pc->permissions)
  108. ]);
  109. $pc->email_verified_at = now();
  110. $pc->child_id = $user->id;
  111. $pc->save();
  112. sleep(2);
  113. Auth::guard()->login($user);
  114. return redirect('/i/web');
  115. }
  116. public function cancelInvite(Request $request, $id)
  117. {
  118. $this->authPreflight($request);
  119. $pc = ParentalControls::whereParentId($request->user()->id)
  120. ->whereNull(['email_verified_at', 'child_id'])
  121. ->findOrFail($id);
  122. return view('settings.parental-controls.delete-invite', compact('pc'));
  123. }
  124. public function cancelInviteHandle(Request $request, $id)
  125. {
  126. $this->authPreflight($request);
  127. $pc = ParentalControls::whereParentId($request->user()->id)
  128. ->whereNull(['email_verified_at', 'child_id'])
  129. ->findOrFail($id);
  130. $pc->delete();
  131. return redirect('/settings/parental-controls');
  132. }
  133. public function stopManaging(Request $request, $id)
  134. {
  135. $this->authPreflight($request);
  136. $pc = ParentalControls::whereParentId($request->user()->id)
  137. ->whereNotNull(['email_verified_at', 'child_id'])
  138. ->findOrFail($id);
  139. return view('settings.parental-controls.stop-managing', compact('pc'));
  140. }
  141. public function stopManagingHandle(Request $request, $id)
  142. {
  143. $this->authPreflight($request);
  144. $pc = ParentalControls::whereParentId($request->user()->id)
  145. ->whereNotNull(['email_verified_at', 'child_id'])
  146. ->findOrFail($id);
  147. $pc->child()->update([
  148. 'has_roles' => false,
  149. 'parent_id' => null,
  150. ]);
  151. $pc->delete();
  152. return redirect('/settings/parental-controls');
  153. }
  154. protected function requestFormFields($request)
  155. {
  156. $state = [];
  157. $fields = [
  158. 'post',
  159. 'comment',
  160. 'like',
  161. 'share',
  162. 'follow',
  163. 'bookmark',
  164. 'story',
  165. 'collection',
  166. 'discovery_feeds',
  167. 'dms',
  168. 'federation',
  169. 'hide_network',
  170. 'private',
  171. 'hide_cw'
  172. ];
  173. foreach ($fields as $field) {
  174. $state[$field] = $request->input($field) == 'on';
  175. }
  176. return $state;
  177. }
  178. }