UserController.php 3.1 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889
  1. <?php
  2. namespace App\Http\Controllers\Auth;
  3. use App\Api\v1\Resources\UserResource;
  4. use App\Http\Controllers\Controller;
  5. use App\Http\Requests\UserDeleteRequest;
  6. use App\Http\Requests\UserUpdateRequest;
  7. use App\Models\User;
  8. use Illuminate\Support\Facades\Auth;
  9. use Illuminate\Support\Facades\DB;
  10. use Illuminate\Support\Facades\Hash;
  11. use Illuminate\Support\Facades\Log;
  12. class UserController extends Controller
  13. {
  14. /**
  15. * Update the user's profile information.
  16. *
  17. * @param \App\Http\Requests\UserUpdateRequest $request
  18. * @return \App\Api\v1\Resources\UserResource|\Illuminate\Http\JsonResponse
  19. */
  20. public function update(UserUpdateRequest $request)
  21. {
  22. $user = $request->user();
  23. $validated = $request->validated();
  24. if (! Hash::check($request->password, Auth::user()->password)) {
  25. Log::notice('Account update failed: wrong password provided');
  26. return response()->json(['message' => __('errors.wrong_current_password')], 400);
  27. }
  28. if (! config('2fauth.config.isDemoApp')) {
  29. $user->update([
  30. 'name' => $validated['name'],
  31. 'email' => $validated['email'],
  32. ]);
  33. }
  34. Log::info(sprintf('Account of user ID #%s updated', $user->id));
  35. return new UserResource($user);
  36. }
  37. /**
  38. * Delete the user's account.
  39. *
  40. * @param \App\Http\Requests\UserDeleteRequest $request
  41. * @return \Illuminate\Http\JsonResponse
  42. */
  43. public function delete(UserDeleteRequest $request)
  44. {
  45. $validated = $request->validated();
  46. $user = Auth::user();
  47. Log::info(sprintf('Deletion of user ID #%s requested', $user->id));
  48. if ($user->is_admin && User::admins()->count() == 1) {
  49. return response()->json(['message' => __('errors.cannot_delete_the_only_admin')], 400);
  50. }
  51. if (! Hash::check($validated['password'], Auth::user()->password)) {
  52. return response()->json(['message' => __('errors.wrong_current_password')], 400);
  53. }
  54. try {
  55. DB::transaction(function () use ($user) {
  56. DB::table('twofaccounts')->where('user_id', $user->id)->delete();
  57. DB::table('groups')->where('user_id', $user->id)->delete();
  58. DB::table('webauthn_credentials')->where('authenticatable_id', $user->id)->delete();
  59. DB::table('webauthn_recoveries')->where('email', $user->email)->delete();
  60. DB::table('oauth_access_tokens')->where('user_id', $user->id)->delete();
  61. DB::table('password_resets')->where('email', $user->email)->delete();
  62. DB::table('users')->where('id', $user->id)->delete();
  63. });
  64. }
  65. // @codeCoverageIgnoreStart
  66. catch (\Throwable $e) {
  67. Log::error(sprintf('Deletion of user ID #%s failed, transaction has been rolled-back', $user->id));
  68. return response()->json(['message' => __('errors.user_deletion_failed')], 400);
  69. }
  70. // @codeCoverageIgnoreEnd
  71. Log::info(sprintf('User ID #%s deleted', $user->id));
  72. return response()->json(null, 204);
  73. }
  74. }