UserController.php 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269
  1. <?php
  2. namespace App\Controllers;
  3. use App\Database\Queries\UserQuery;
  4. use App\Web\ValidationChecker;
  5. use League\Flysystem\FileNotFoundException;
  6. use Psr\Http\Message\ResponseInterface as Response;
  7. use Psr\Http\Message\ServerRequestInterface as Request;
  8. class UserController extends Controller
  9. {
  10. const PER_PAGE = 15;
  11. /**
  12. * @param Response $response
  13. * @param int|null $page
  14. *
  15. * @return Response
  16. * @throws \Twig\Error\RuntimeError
  17. * @throws \Twig\Error\SyntaxError
  18. *
  19. * @throws \Twig\Error\LoaderError
  20. */
  21. public function index(Response $response, int $page = 0): Response
  22. {
  23. $page = max(0, --$page);
  24. $users = $this->database->query('SELECT * FROM `users` LIMIT ? OFFSET ?', [self::PER_PAGE, $page * self::PER_PAGE])->fetchAll();
  25. $pages = $this->database->query('SELECT COUNT(*) AS `count` FROM `users`')->fetch()->count / self::PER_PAGE;
  26. return view()->render($response,
  27. 'user/index.twig',
  28. [
  29. 'users' => $users,
  30. 'next' => $page < floor($pages),
  31. 'previous' => $page >= 1,
  32. 'current_page' => ++$page,
  33. 'quota_enabled' => $this->getSetting('quota_enabled'),
  34. ]
  35. );
  36. }
  37. /**
  38. * @param Response $response
  39. *
  40. * @return Response
  41. * @throws \Twig\Error\RuntimeError
  42. * @throws \Twig\Error\SyntaxError
  43. *
  44. * @throws \Twig\Error\LoaderError
  45. */
  46. public function create(Response $response): Response
  47. {
  48. return view()->render($response, 'user/create.twig', [
  49. 'default_user_quota' => humanFileSize($this->getSetting('default_user_quota'), 0, true),
  50. 'quota_enabled' => $this->getSetting('quota_enabled', 'off'),
  51. ]);
  52. }
  53. /**
  54. * @param Request $request
  55. * @param Response $response
  56. *
  57. * @return Response
  58. */
  59. public function store(Request $request, Response $response): Response
  60. {
  61. $validator = $this->getUserCreateValidator($request);
  62. if ($validator->fails()) {
  63. return redirect($response, route('user.create'));
  64. }
  65. $maxUserQuota = -1;
  66. if ($this->getSetting('quota_enabled') === 'on') {
  67. $maxUserQuotaStr = param($request, 'max_user_quota', humanFileSize($this->getSetting('default_user_quota', -1), 0, true));
  68. if (!preg_match('/([0-9]+[K|M|G|T])|(\-1)/i', $maxUserQuotaStr)) {
  69. $this->session->alert(lang('invalid_quota', 'danger'));
  70. return redirect($response, route('user.create'));
  71. }
  72. if ($maxUserQuotaStr !== '-1') {
  73. $maxUserQuota = stringToBytes($maxUserQuotaStr);
  74. }
  75. }
  76. make(UserQuery::class)->create(
  77. param($request, 'email'),
  78. param($request, 'username'),
  79. param($request, 'password'),
  80. param($request, 'is_admin') !== null ? 1 : 0,
  81. param($request, 'is_active') !== null ? 1 : 0,
  82. $maxUserQuota
  83. );
  84. $this->session->alert(lang('user_created', [param($request, 'username')]), 'success');
  85. $this->logger->info('User '.$this->session->get('username').' created a new user.', [array_diff_key($request->getParsedBody(), array_flip(['password']))]);
  86. return redirect($response, route('user.index'));
  87. }
  88. /**
  89. * @param Request $request
  90. * @param Response $response
  91. * @param int $id
  92. *
  93. * @return Response
  94. * @throws \Twig\Error\LoaderError
  95. * @throws \Twig\Error\RuntimeError
  96. * @throws \Twig\Error\SyntaxError
  97. */
  98. public function edit(Request $request, Response $response, int $id): Response
  99. {
  100. $user = make(UserQuery::class)->get($request, $id);
  101. return view()->render($response, 'user/edit.twig', [
  102. 'profile' => false,
  103. 'user' => $user,
  104. 'quota_enabled' => $this->getSetting('quota_enabled', 'off'),
  105. 'max_disk_quota' => $user->max_disk_quota > 0 ? humanFileSize($user->max_disk_quota, 0, true) : -1,
  106. ]);
  107. }
  108. /**
  109. * @param Request $request
  110. * @param Response $response
  111. * @param int $id
  112. *
  113. * @return Response
  114. */
  115. public function update(Request $request, Response $response, int $id): Response
  116. {
  117. $user = make(UserQuery::class)->get($request, $id);
  118. $validator = ValidationChecker::make()
  119. ->rules([
  120. 'email.required' => filter_var(param($request, 'email'), FILTER_VALIDATE_EMAIL),
  121. 'username.required' => !empty(param($request, 'username')),
  122. 'email.unique' => $this->database->query('SELECT COUNT(*) AS `count` FROM `users` WHERE `email` = ? AND `email` <> ?', [param($request, 'email'), $user->email])->fetch()->count == 0,
  123. 'username.unique' => $this->database->query('SELECT COUNT(*) AS `count` FROM `users` WHERE `username` = ? AND `username` <> ?', [param($request, 'username'), $user->username])->fetch()->count == 0,
  124. 'demote' => !($user->id === $this->session->get('user_id') && param($request, 'is_admin') === null),
  125. ])
  126. ->onFail(function ($rule) {
  127. $alerts = [
  128. 'email.required' => lang('email_required'),
  129. 'username.required' => lang('username_required'),
  130. 'email.unique' => lang('email_taken'),
  131. 'username.unique' => lang('username_taken'),
  132. 'demote' => lang('cannot_demote'),
  133. ];
  134. $this->session->alert($alerts[$rule], 'danger');
  135. });
  136. if ($validator->fails()) {
  137. return redirect($response, route('user.edit', ['id' => $id]));
  138. }
  139. $user->max_disk_quota = -1;
  140. if ($this->getSetting('quota_enabled') === 'on') {
  141. $maxUserQuota = param($request, 'max_user_quota', humanFileSize($this->getSetting('default_user_quota'), 0, true));
  142. if (!preg_match('/([0-9]+[K|M|G|T])|(\-1)/i', $maxUserQuota)) {
  143. $this->session->alert(lang('invalid_quota', 'danger'));
  144. return redirect($response, route('user.create'));
  145. }
  146. if ($maxUserQuota !== '-1') {
  147. $user->max_disk_quota = stringToBytes($maxUserQuota);
  148. }
  149. }
  150. make(UserQuery::class)->update(
  151. $user->id,
  152. param($request, 'email'),
  153. param($request, 'username'),
  154. param($request, 'password'),
  155. param($request, 'is_admin') !== null ? 1 : 0,
  156. param($request, 'is_active') !== null ? 1 : 0,
  157. $user->max_disk_quota
  158. );
  159. if ($user->id === $this->session->get('user_id')) {
  160. $this->setSessionQuotaInfo($user->current_disk_quota, $user->max_disk_quota);
  161. }
  162. $this->session->alert(lang('user_updated', [param($request, 'username')]), 'success');
  163. $this->logger->info('User '.$this->session->get('username')." updated $user->id.", [
  164. array_diff_key((array) $user, array_flip(['password'])),
  165. array_diff_key($request->getParsedBody(), array_flip(['password'])),
  166. ]);
  167. return redirect($response, route('user.index'));
  168. }
  169. /**
  170. * @param Request $request
  171. * @param Response $response
  172. * @param int $id
  173. *
  174. * @return Response
  175. */
  176. public function delete(Request $request, Response $response, int $id): Response
  177. {
  178. $user = make(UserQuery::class)->get($request, $id);
  179. if ($user->id === $this->session->get('user_id')) {
  180. $this->session->alert(lang('cannot_delete'), 'danger');
  181. return redirect($response, route('user.index'));
  182. }
  183. $this->database->query('DELETE FROM `users` WHERE `id` = ?', $user->id);
  184. $this->session->alert(lang('user_deleted'), 'success');
  185. $this->logger->info('User '.$this->session->get('username')." deleted $user->id.");
  186. return redirect($response, route('user.index'));
  187. }
  188. /**
  189. * @param Request $request
  190. * @param Response $response
  191. * @param int $id
  192. * @return Response
  193. */
  194. public function clearUserMedia(Request $request, Response $response, int $id): Response
  195. {
  196. $user = make(UserQuery::class)->get($request, $id, true);
  197. $medias = $this->database->query('SELECT * FROM `uploads` WHERE `user_id` = ?', $user->id);
  198. foreach ($medias as $media) {
  199. try {
  200. $this->storage->delete($media->storage_path);
  201. } catch (FileNotFoundException $e) {
  202. }
  203. }
  204. $this->database->query('DELETE FROM `uploads` WHERE `user_id` = ?', $user->id);
  205. $this->database->query('UPDATE `users` SET `current_disk_quota`=? WHERE `id` = ?', [
  206. 0,
  207. $user->id,
  208. ]);
  209. $this->session->alert(lang('account_media_deleted'), 'success');
  210. return redirect($response, route('user.edit', ['id' => $id]));
  211. }
  212. /**
  213. * @param Request $request
  214. * @param Response $response
  215. * @param int $id
  216. *
  217. * @return Response
  218. */
  219. public function refreshToken(Request $request, Response $response, int $id): Response
  220. {
  221. $query = make(UserQuery::class);
  222. $user = $query->get($request, $id, true);
  223. $this->logger->info('User '.$this->session->get('username')." refreshed token of user $user->id.");
  224. $response->getBody()->write($query->refreshToken($user->id));
  225. return $response;
  226. }
  227. }