UserController.php 3.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108
  1. <?php
  2. namespace App\Http\Controllers\Auth;
  3. use App\Models\User;
  4. use App\Services\TwoFAccountService;
  5. use App\Http\Requests\UserUpdateRequest;
  6. use App\Http\Requests\UserDeleteRequest;
  7. use App\Api\v1\Resources\UserResource;
  8. use App\Http\Controllers\Controller;
  9. use Illuminate\Support\Facades\Auth;
  10. use Illuminate\Support\Facades\Hash;
  11. use Illuminate\Support\Facades\DB;
  12. use Illuminate\Support\Facades\Artisan;
  13. use App\Exceptions\UnsupportedWithReverseProxyException;
  14. use Exception;
  15. class UserController extends Controller
  16. {
  17. /**
  18. * The TwoFAccount Service instance.
  19. */
  20. protected $twofaccountService;
  21. /**
  22. * Create a new controller instance.
  23. *
  24. * @param \App\Services\TwoFAccountService $twofaccountService
  25. * @return void
  26. */
  27. public function __construct(TwoFAccountService $twofaccountService)
  28. {
  29. $this->twofaccountService = $twofaccountService;
  30. $authGuard = config('auth.defaults.guard');
  31. if ($authGuard === 'reverse-proxy-guard') {
  32. throw new UnsupportedWithReverseProxyException();
  33. }
  34. }
  35. /**
  36. * Update the user's profile information.
  37. *
  38. * @param \App\Http\Requests\UserUpdateRequest $request
  39. * @return \App\Api\v1\Resources\UserResource
  40. */
  41. public function update(UserUpdateRequest $request)
  42. {
  43. $user = $request->user();
  44. $validated = $request->validated();
  45. if (!Hash::check( $request->password, Auth::user()->password) ) {
  46. return response()->json(['message' => __('errors.wrong_current_password')], 400);
  47. }
  48. if (!config('2fauth.config.isDemoApp') ) {
  49. tap($user)->update([
  50. 'name' => $validated['name'],
  51. 'email' => $validated['email'],
  52. ]);
  53. }
  54. return new UserResource($user);
  55. }
  56. /**
  57. * Delete the user's account.
  58. *
  59. * @param \App\Http\Requests\UserDeleteRequest $request
  60. * @return \Illuminate\Http\JsonResponse
  61. */
  62. public function delete(UserDeleteRequest $request)
  63. {
  64. $validated = $request->validated();
  65. if (!Hash::check( $validated['password'], Auth::user()->password) ) {
  66. return response()->json(['message' => __('errors.wrong_current_password')], 400);
  67. }
  68. try {
  69. DB::transaction(function () {
  70. DB::table('twofaccounts')->delete();
  71. DB::table('groups')->delete();
  72. DB::table('options')->delete();
  73. DB::table('web_authn_credentials')->delete();
  74. DB::table('web_authn_recoveries')->delete();
  75. DB::table('oauth_access_tokens')->delete();
  76. DB::table('oauth_auth_codes')->delete();
  77. DB::table('oauth_clients')->delete();
  78. DB::table('oauth_personal_access_clients')->delete();
  79. DB::table('oauth_refresh_tokens')->delete();
  80. DB::table('password_resets')->delete();
  81. DB::table('users')->delete();
  82. });
  83. Artisan::call('passport:install --force');
  84. Artisan::call('config:clear');
  85. }
  86. catch (\Throwable $e) {
  87. return response()->json(['message' => __('errors.user_deletion_failed')], 400);
  88. }
  89. return response()->json(null, 204);
  90. }
  91. }