ParentalControlsController.php 7.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231
  1. <?php
  2. namespace App\Http\Controllers;
  3. use Illuminate\Http\Request;
  4. use App\Models\ParentalControls;
  5. use App\Models\UserRoles;
  6. use App\Profile;
  7. use App\User;
  8. use App\Http\Controllers\Auth\RegisterController;
  9. use Illuminate\Auth\Events\Registered;
  10. use Illuminate\Support\Facades\Auth;
  11. use App\Services\UserRoleService;
  12. use App\Jobs\ParentalControlsPipeline\DispatchChildInvitePipeline;
  13. class ParentalControlsController extends Controller
  14. {
  15. public function authPreflight($request, $maxUserCheck = false, $authCheck = true)
  16. {
  17. if($authCheck) {
  18. abort_unless($request->user(), 404);
  19. abort_unless($request->user()->has_roles === 0, 404);
  20. }
  21. abort_unless(config('instance.parental_controls.enabled'), 404);
  22. if(config_cache('pixelfed.open_registration') == false) {
  23. abort_if(config('instance.parental_controls.limits.respect_open_registration'), 404);
  24. }
  25. if($maxUserCheck == true) {
  26. $hasLimit = config('pixelfed.enforce_max_users');
  27. if($hasLimit) {
  28. $count = User::where(function($q){ return $q->whereNull('status')->orWhereNotIn('status', ['deleted','delete']); })->count();
  29. $limit = (int) config('pixelfed.max_users');
  30. abort_if($limit && $limit <= $count, 404);
  31. }
  32. }
  33. }
  34. public function index(Request $request)
  35. {
  36. $this->authPreflight($request);
  37. $children = ParentalControls::whereParentId($request->user()->id)->latest()->paginate(5);
  38. return view('settings.parental-controls.index', compact('children'));
  39. }
  40. public function add(Request $request)
  41. {
  42. $this->authPreflight($request, true);
  43. return view('settings.parental-controls.add');
  44. }
  45. public function view(Request $request, $id)
  46. {
  47. $this->authPreflight($request);
  48. $uid = $request->user()->id;
  49. $pc = ParentalControls::whereParentId($uid)->findOrFail($id);
  50. return view('settings.parental-controls.manage', compact('pc'));
  51. }
  52. public function update(Request $request, $id)
  53. {
  54. $this->authPreflight($request);
  55. $uid = $request->user()->id;
  56. $ff = $this->requestFormFields($request);
  57. $pc = ParentalControls::whereParentId($uid)->findOrFail($id);
  58. $pc->permissions = $ff;
  59. $pc->save();
  60. $roles = UserRoleService::mapActions($pc->child_id, $ff);
  61. if(isset($roles['account-force-private'])) {
  62. $c = Profile::whereUserId($pc->child_id)->first();
  63. $c->is_private = $roles['account-force-private'];
  64. $c->save();
  65. }
  66. UserRoles::whereUserId($pc->child_id)->update(['roles' => $roles]);
  67. return redirect($pc->manageUrl() . '?permissions');
  68. }
  69. public function store(Request $request)
  70. {
  71. $this->authPreflight($request, true);
  72. $this->validate($request, [
  73. 'email' => 'required|email|unique:parental_controls,email|unique:users,email',
  74. ]);
  75. $state = $this->requestFormFields($request);
  76. $pc = new ParentalControls;
  77. $pc->parent_id = $request->user()->id;
  78. $pc->email = $request->input('email');
  79. $pc->verify_code = str_random(32);
  80. $pc->permissions = $state;
  81. $pc->save();
  82. DispatchChildInvitePipeline::dispatch($pc);
  83. return redirect($pc->manageUrl());
  84. }
  85. public function inviteRegister(Request $request, $id, $code)
  86. {
  87. if($request->user()) {
  88. $title = 'You cannot complete this action on this device.';
  89. $body = 'Please log out or use a different device or browser to complete the invitation registration.';
  90. return view('errors.custom', compact('title', 'body'));
  91. }
  92. $this->authPreflight($request, true, false);
  93. $pc = ParentalControls::whereRaw('verify_code = BINARY ?', $code)->whereNull(['email_verified_at', 'child_id'])->findOrFail($id);
  94. abort_unless(User::whereId($pc->parent_id)->exists(), 404);
  95. return view('settings.parental-controls.invite-register-form', compact('pc'));
  96. }
  97. public function inviteRegisterStore(Request $request, $id, $code)
  98. {
  99. if($request->user()) {
  100. $title = 'You cannot complete this action on this device.';
  101. $body = 'Please log out or use a different device or browser to complete the invitation registration.';
  102. return view('errors.custom', compact('title', 'body'));
  103. }
  104. $this->authPreflight($request, true, false);
  105. $pc = ParentalControls::whereRaw('verify_code = BINARY ?', $code)->whereNull('email_verified_at')->findOrFail($id);
  106. $fields = $request->all();
  107. $fields['email'] = $pc->email;
  108. $defaults = UserRoleService::defaultRoles();
  109. $validator = (new RegisterController)->validator($fields);
  110. $valid = $validator->validate();
  111. abort_if(!$valid, 404);
  112. event(new Registered($user = (new RegisterController)->create($fields)));
  113. sleep(5);
  114. $user->has_roles = true;
  115. $user->parent_id = $pc->parent_id;
  116. if(config('instance.parental_controls.limits.auto_verify_email')) {
  117. $user->email_verified_at = now();
  118. $user->save();
  119. sleep(3);
  120. } else {
  121. $user->save();
  122. sleep(3);
  123. }
  124. $ur = UserRoles::updateOrCreate([
  125. 'user_id' => $user->id,
  126. ],[
  127. 'roles' => UserRoleService::mapInvite($user->id, $pc->permissions)
  128. ]);
  129. $pc->email_verified_at = now();
  130. $pc->child_id = $user->id;
  131. $pc->save();
  132. sleep(2);
  133. Auth::guard()->login($user);
  134. return redirect('/i/web');
  135. }
  136. public function cancelInvite(Request $request, $id)
  137. {
  138. $this->authPreflight($request);
  139. $pc = ParentalControls::whereParentId($request->user()->id)
  140. ->whereNull(['email_verified_at', 'child_id'])
  141. ->findOrFail($id);
  142. return view('settings.parental-controls.delete-invite', compact('pc'));
  143. }
  144. public function cancelInviteHandle(Request $request, $id)
  145. {
  146. $this->authPreflight($request);
  147. $pc = ParentalControls::whereParentId($request->user()->id)
  148. ->whereNull(['email_verified_at', 'child_id'])
  149. ->findOrFail($id);
  150. $pc->delete();
  151. return redirect('/settings/parental-controls');
  152. }
  153. public function stopManaging(Request $request, $id)
  154. {
  155. $this->authPreflight($request);
  156. $pc = ParentalControls::whereParentId($request->user()->id)
  157. ->whereNotNull(['email_verified_at', 'child_id'])
  158. ->findOrFail($id);
  159. return view('settings.parental-controls.stop-managing', compact('pc'));
  160. }
  161. public function stopManagingHandle(Request $request, $id)
  162. {
  163. $this->authPreflight($request);
  164. $pc = ParentalControls::whereParentId($request->user()->id)
  165. ->whereNotNull(['email_verified_at', 'child_id'])
  166. ->findOrFail($id);
  167. $pc->child()->update([
  168. 'has_roles' => false,
  169. 'parent_id' => null,
  170. ]);
  171. $pc->delete();
  172. return redirect('/settings/parental-controls');
  173. }
  174. protected function requestFormFields($request)
  175. {
  176. $state = [];
  177. $fields = [
  178. 'post',
  179. 'comment',
  180. 'like',
  181. 'share',
  182. 'follow',
  183. 'bookmark',
  184. 'story',
  185. 'collection',
  186. 'discovery_feeds',
  187. 'dms',
  188. 'federation',
  189. 'hide_network',
  190. 'private',
  191. 'hide_cw'
  192. ];
  193. foreach ($fields as $field) {
  194. $state[$field] = $request->input($field) == 'on';
  195. }
  196. return $state;
  197. }
  198. }