UserController.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318
  1. <?php
  2. namespace App\Controllers;
  3. use Psr\Http\Message\ResponseInterface as Response;
  4. use Psr\Http\Message\ServerRequestInterface as Request;
  5. use Slim\Exception\HttpNotFoundException;
  6. use Slim\Exception\HttpUnauthorizedException;
  7. class UserController extends Controller
  8. {
  9. const PER_PAGE = 15;
  10. /**
  11. * @param Response $response
  12. * @param int|null $page
  13. * @return Response
  14. * @throws \Twig\Error\LoaderError
  15. * @throws \Twig\Error\RuntimeError
  16. * @throws \Twig\Error\SyntaxError
  17. */
  18. public function index(Response $response, int $page = 0): Response
  19. {
  20. $page = max(0, --$page);
  21. $users = $this->database->query('SELECT * FROM `users` LIMIT ? OFFSET ?', [self::PER_PAGE, $page * self::PER_PAGE])->fetchAll();
  22. $pages = $this->database->query('SELECT COUNT(*) AS `count` FROM `users`')->fetch()->count / self::PER_PAGE;
  23. return view()->render($response,
  24. 'user/index.twig',
  25. [
  26. 'users' => $users,
  27. 'next' => $page < floor($pages),
  28. 'previous' => $page >= 1,
  29. 'current_page' => ++$page,
  30. ]
  31. );
  32. }
  33. /**
  34. * @param Response $response
  35. * @return Response
  36. * @throws \Twig\Error\LoaderError
  37. * @throws \Twig\Error\RuntimeError
  38. * @throws \Twig\Error\SyntaxError
  39. */
  40. public function create(Response $response): Response
  41. {
  42. return view()->render($response, 'user/create.twig');
  43. }
  44. /**
  45. * @param Request $request
  46. * @param Response $response
  47. * @return Response
  48. */
  49. public function store(Request $request, Response $response): Response
  50. {
  51. if (param($request, 'email') === null) {
  52. $this->session->alert(lang('email_required'), 'danger');
  53. return redirect($response, route('user.create'));
  54. }
  55. if ($this->database->query('SELECT COUNT(*) AS `count` FROM `users` WHERE `email` = ?', param($request, 'email'))->fetch()->count > 0) {
  56. $this->session->alert(lang('email_taken'), 'danger');
  57. return redirect($response, route('user.create'));
  58. }
  59. if (param($request, 'username') === null) {
  60. $this->session->alert(lang('username_required'), 'danger');
  61. return redirect($response, route('user.create'));
  62. }
  63. if (param($request, 'password') === null) {
  64. $this->session->alert(lang('password_required'), 'danger');
  65. return redirect($response, route('user.create'));
  66. }
  67. if ($this->database->query('SELECT COUNT(*) AS `count` FROM `users` WHERE `username` = ?', param($request, 'username'))->fetch()->count > 0) {
  68. $this->session->alert(lang('username_taken'), 'danger');
  69. return redirect($response, route('user.create'));
  70. }
  71. do {
  72. $userCode = humanRandomString(5);
  73. } while ($this->database->query('SELECT COUNT(*) AS `count` FROM `users` WHERE `user_code` = ?', $userCode)->fetch()->count > 0);
  74. $token = $this->generateNewToken();
  75. $this->database->query('INSERT INTO `users`(`email`, `username`, `password`, `is_admin`, `active`, `user_code`, `token`) VALUES (?, ?, ?, ?, ?, ?, ?)', [
  76. param($request, 'email'),
  77. param($request, 'username'),
  78. password_hash(param($request, 'password'), PASSWORD_DEFAULT),
  79. param($request, 'is_admin') !== null ? 1 : 0,
  80. param($request, 'is_active') !== null ? 1 : 0,
  81. $userCode,
  82. $token,
  83. ]);
  84. $this->session->alert(lang('user_created', [param($request, 'username')]), 'success');
  85. $this->logger->info('User '.$this->session->get('username').' created a new user.', [array_diff_key($request->getParsedBody(), array_flip(['password']))]);
  86. return redirect($response, route('user.index'));
  87. }
  88. /**
  89. * @param Request $request
  90. * @param Response $response
  91. * @param $id
  92. * @return Response
  93. * @throws HttpNotFoundException
  94. * @throws \Twig\Error\LoaderError
  95. * @throws \Twig\Error\RuntimeError
  96. * @throws \Twig\Error\SyntaxError
  97. * @throws HttpUnauthorizedException
  98. */
  99. public function edit(Request $request, Response $response, int $id): Response
  100. {
  101. $user = $this->getUser($request, $id, false);
  102. return view()->render($response, 'user/edit.twig', [
  103. 'profile' => false,
  104. 'user' => $user,
  105. ]);
  106. }
  107. /**
  108. * @param Request $request
  109. * @param Response $response
  110. * @param int $id
  111. * @return Response
  112. * @throws HttpNotFoundException
  113. * @throws HttpUnauthorizedException
  114. */
  115. public function update(Request $request, Response $response, int $id): Response
  116. {
  117. $user = $this->getUser($request, $id, false);
  118. if (param($request, 'email') === null) {
  119. $this->session->alert(lang('email_required'), 'danger');
  120. return redirect($response, route('user.edit', ['id' => $id]));
  121. }
  122. if ($this->database->query('SELECT COUNT(*) AS `count` FROM `users` WHERE `email` = ? AND `email` <> ?', [param($request, 'email'), $user->email])->fetch()->count > 0) {
  123. $this->session->alert(lang('email_taken'), 'danger');
  124. return redirect($response, route('user.edit', ['id' => $id]));
  125. }
  126. if (param($request, 'username') === null) {
  127. $this->session->alert(lang('username_required'), 'danger');
  128. return redirect($response, route('user.edit', ['id' => $id]));
  129. }
  130. if ($this->database->query('SELECT COUNT(*) AS `count` FROM `users` WHERE `username` = ? AND `username` <> ?', [param($request, 'username'), $user->username])->fetch()->count > 0) {
  131. $this->session->alert(lang('username_taken'), 'danger');
  132. return redirect($response, route('user.edit', ['id' => $id]));
  133. }
  134. if ($user->id === $this->session->get('user_id') && param($request, 'is_admin') === null) {
  135. $this->session->alert(lang('cannot_demote'), 'danger');
  136. return redirect($response, route('user.edit', ['id' => $id]));
  137. }
  138. if (param($request, 'password') !== null && !empty(param($request, 'password'))) {
  139. $this->database->query('UPDATE `users` SET `email`=?, `username`=?, `password`=?, `is_admin`=?, `active`=? WHERE `id` = ?', [
  140. param($request, 'email'),
  141. param($request, 'username'),
  142. password_hash(param($request, 'password'), PASSWORD_DEFAULT),
  143. param($request, 'is_admin') !== null ? 1 : 0,
  144. param($request, 'is_active') !== null ? 1 : 0,
  145. $user->id,
  146. ]);
  147. } else {
  148. $this->database->query('UPDATE `users` SET `email`=?, `username`=?, `is_admin`=?, `active`=? WHERE `id` = ?', [
  149. param($request, 'email'),
  150. param($request, 'username'),
  151. param($request, 'is_admin') !== null ? 1 : 0,
  152. param($request, 'is_active') !== null ? 1 : 0,
  153. $user->id,
  154. ]);
  155. }
  156. $this->session->alert(lang('user_updated', [param($request, 'username')]), 'success');
  157. $this->logger->info('User '.$this->session->get('username')." updated $user->id.", [
  158. array_diff_key((array)$user, array_flip(['password'])),
  159. array_diff_key($request->getParsedBody(), array_flip(['password'])),
  160. ]);
  161. return redirect($response, route('user.index'));
  162. }
  163. /**
  164. * @param Request $request
  165. * @param Response $response
  166. * @param int $id
  167. * @return Response
  168. * @throws HttpNotFoundException
  169. * @throws HttpUnauthorizedException
  170. */
  171. public function delete(Request $request, Response $response, int $id): Response
  172. {
  173. $user = $this->getUser($request, $id, false);
  174. if ($user->id === $this->session->get('user_id')) {
  175. $this->session->alert(lang('cannot_delete'), 'danger');
  176. return redirect($response, route('user.index'));
  177. }
  178. $this->database->query('DELETE FROM `users` WHERE `id` = ?', $user->id);
  179. $this->session->alert(lang('user_deleted'), 'success');
  180. $this->logger->info('User '.$this->session->get('username')." deleted $user->id.");
  181. return redirect($response, route('user.index'));
  182. }
  183. /**
  184. * @param Request $request
  185. * @param Response $response
  186. * @return Response
  187. * @throws HttpNotFoundException
  188. * @throws HttpUnauthorizedException
  189. * @throws \Twig\Error\LoaderError
  190. * @throws \Twig\Error\RuntimeError
  191. * @throws \Twig\Error\SyntaxError
  192. */
  193. public function profile(Request $request, Response $response): Response
  194. {
  195. $user = $this->getUser($request, $this->session->get('user_id'), true);
  196. return view()->render($response, 'user/edit.twig', [
  197. 'profile' => true,
  198. 'user' => $user,
  199. ]);
  200. }
  201. /**
  202. * @param Request $request
  203. * @param Response $response
  204. * @param int $id
  205. * @return Response
  206. * @throws HttpNotFoundException
  207. * @throws HttpUnauthorizedException
  208. */
  209. public function profileEdit(Request $request, Response $response, int $id): Response
  210. {
  211. if (param($request, 'email') === null) {
  212. $this->session->alert(lang('email_required'), 'danger');
  213. return redirect($response, route('profile'));
  214. }
  215. $user = $this->getUser($request, $id, true);
  216. if ($this->database->query('SELECT COUNT(*) AS `count` FROM `users` WHERE `email` = ? AND `email` <> ?', [param($request, 'email'), $user->email])->fetch()->count > 0) {
  217. $this->session->alert(lang('email_taken'), 'danger');
  218. return redirect($response, route('profile'));
  219. }
  220. if (param($request, 'password') !== null && !empty(param($request, 'password'))) {
  221. $this->database->query('UPDATE `users` SET `email`=?, `password`=? WHERE `id` = ?', [
  222. param($request, 'email'),
  223. password_hash(param($request, 'password'), PASSWORD_DEFAULT),
  224. $user->id,
  225. ]);
  226. } else {
  227. $this->database->query('UPDATE `users` SET `email`=? WHERE `id` = ?', [
  228. param($request, 'email'),
  229. $user->id,
  230. ]);
  231. }
  232. $this->session->alert(lang('profile_updated'), 'success');
  233. $this->logger->info('User '.$this->session->get('username')." updated profile of $user->id.");
  234. return redirect($response, route('profile'));
  235. }
  236. /**
  237. * @param Request $request
  238. * @param Response $response
  239. * @param int $id
  240. * @return Response
  241. * @throws HttpNotFoundException
  242. * @throws HttpUnauthorizedException
  243. */
  244. public function refreshToken(Request $request, Response $response, int $id): Response
  245. {
  246. $user = $this->getUser($request, $id, true);
  247. $token = $this->generateNewToken();
  248. $this->database->query('UPDATE `users` SET `token`=? WHERE `id` = ?', [
  249. $token,
  250. $user->id,
  251. ]);
  252. $this->logger->info('User '.$this->session->get('username')." refreshed token of user $user->id.");
  253. $response->getBody()->write($token);
  254. return $response;
  255. }
  256. /**
  257. * @return string
  258. */
  259. protected function generateNewToken(): string
  260. {
  261. do {
  262. $token = 'token_'.md5(uniqid('', true));
  263. } while ($this->database->query('SELECT COUNT(*) AS `count` FROM `users` WHERE `token` = ?', $token)->fetch()->count > 0);
  264. return $token;
  265. }
  266. }