UserController.php 3.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104
  1. <?php
  2. namespace App\Http\Controllers\Auth;
  3. use App\Models\User;
  4. use App\Services\TwoFAccountService;
  5. use App\Http\Requests\UserUpdateRequest;
  6. use App\Http\Requests\UserDeleteRequest;
  7. use App\Api\v1\Resources\UserResource;
  8. use App\Http\Controllers\Controller;
  9. use Illuminate\Support\Facades\Auth;
  10. use Illuminate\Support\Facades\Hash;
  11. use Illuminate\Support\Facades\DB;
  12. use Illuminate\Support\Facades\Artisan;
  13. use Exception;
  14. class UserController extends Controller
  15. {
  16. /**
  17. * The TwoFAccount Service instance.
  18. */
  19. protected $twofaccountService;
  20. /**
  21. * Create a new controller instance.
  22. *
  23. * @param \App\Services\TwoFAccountService $twofaccountService
  24. * @return void
  25. */
  26. public function __construct(TwoFAccountService $twofaccountService)
  27. {
  28. $this->twofaccountService = $twofaccountService;
  29. }
  30. /**
  31. * Update the user's profile information.
  32. *
  33. * @param \App\Http\Requests\UserUpdateRequest $request
  34. * @return \App\Api\v1\Resources\UserResource
  35. */
  36. public function update(UserUpdateRequest $request)
  37. {
  38. $user = $request->user();
  39. $validated = $request->validated();
  40. if (!Hash::check( $request->password, Auth::user()->password) ) {
  41. return response()->json(['message' => __('errors.wrong_current_password')], 400);
  42. }
  43. if (!config('2fauth.config.isDemoApp') ) {
  44. tap($user)->update([
  45. 'name' => $validated['name'],
  46. 'email' => $validated['email'],
  47. ]);
  48. }
  49. return new UserResource($user);
  50. }
  51. /**
  52. * Delete the user's account.
  53. *
  54. * @param \App\Http\Requests\UserDeleteRequest $request
  55. * @return \Illuminate\Http\JsonResponse
  56. */
  57. public function delete(UserDeleteRequest $request)
  58. {
  59. $validated = $request->validated();
  60. if (!Hash::check( $validated['password'], Auth::user()->password) ) {
  61. return response()->json(['message' => __('errors.wrong_current_password')], 400);
  62. }
  63. try {
  64. DB::transaction(function () {
  65. DB::table('twofaccounts')->delete();
  66. DB::table('groups')->delete();
  67. DB::table('options')->delete();
  68. DB::table('web_authn_credentials')->delete();
  69. DB::table('web_authn_recoveries')->delete();
  70. DB::table('oauth_access_tokens')->delete();
  71. DB::table('oauth_auth_codes')->delete();
  72. DB::table('oauth_clients')->delete();
  73. DB::table('oauth_personal_access_clients')->delete();
  74. DB::table('oauth_refresh_tokens')->delete();
  75. DB::table('password_resets')->delete();
  76. DB::table('users')->delete();
  77. });
  78. Artisan::call('passport:install --force');
  79. Artisan::call('config:clear');
  80. }
  81. // @codeCoverageIgnoreStart
  82. catch (\Throwable $e) {
  83. return response()->json(['message' => __('errors.user_deletion_failed')], 400);
  84. }
  85. // @codeCoverageIgnoreEnd
  86. return response()->json(null, 204);
  87. }
  88. }