UserController.php 8.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337
  1. <?php
  2. namespace App\Controllers;
  3. use App\Database\DB;
  4. use App\Exceptions\NotFoundException;
  5. use App\Exceptions\UnauthorizedException;
  6. use App\Traits\SingletonController;
  7. use App\Web\Log;
  8. use App\Web\Session;
  9. use Flight;
  10. class UserController extends Controller
  11. {
  12. use SingletonController;
  13. const PER_PAGE = 15;
  14. public function index($page = 1): void
  15. {
  16. $this->checkAdmin();
  17. $page = max(0, --$page);
  18. $users = DB::query('SELECT * FROM `users` LIMIT ? OFFSET ?', [self::PER_PAGE, $page * self::PER_PAGE])->fetchAll();
  19. $pages = DB::query('SELECT COUNT(*) AS `count` FROM `users`')->fetch()->count / self::PER_PAGE;
  20. Flight::render('user/index.twig', [
  21. 'users' => $users,
  22. 'next' => $page < floor($pages),
  23. 'previous' => $page >= 1,
  24. 'current_page' => ++$page,
  25. ]);
  26. }
  27. public function create(): void
  28. {
  29. $this->checkAdmin();
  30. Flight::render('user/create.twig');
  31. }
  32. public function store(): void
  33. {
  34. $this->checkAdmin();
  35. $form = Flight::request()->data;
  36. if (!isset($form->email) || empty($form->email)) {
  37. Session::alert('The email is required.', 'danger');
  38. Flight::redirectBack();
  39. return;
  40. }
  41. if (!isset($form->username) || empty($form->username)) {
  42. Session::alert('The username is required.', 'danger');
  43. Flight::redirectBack();
  44. return;
  45. }
  46. if (DB::query('SELECT COUNT(*) AS `count` FROM `users` WHERE `username` = ?', $form->username)->fetch()->count > 0) {
  47. Session::alert('The username already taken.', 'danger');
  48. Flight::redirectBack();
  49. return;
  50. }
  51. if (!isset($form->password) || empty($form->password)) {
  52. Session::alert('The password is required.', 'danger');
  53. Flight::redirectBack();
  54. return;
  55. }
  56. do {
  57. $userCode = substr(md5(microtime()), rand(0, 26), 5);
  58. } while (DB::query('SELECT COUNT(*) AS `count` FROM `users` WHERE `user_code` = ?', $userCode)->fetch()->count > 0);
  59. $token = $this->generateNewToken();
  60. DB::query('INSERT INTO `users`(`email`, `username`, `password`, `is_admin`, `active`, `user_code`, `token`) VALUES (?, ?, ?, ?, ?, ?, ?)', [
  61. $form->email,
  62. $form->username,
  63. password_hash($form->password, PASSWORD_DEFAULT),
  64. isset($form->is_admin),
  65. isset($form->is_active),
  66. $userCode,
  67. $token
  68. ]);
  69. Session::alert("User '$form->username' created!", 'success');
  70. Log::info('User ' . Session::get('username') . ' created a new user.', [array_diff($form->getData(), ['password'])]);
  71. Flight::redirect('/users');
  72. }
  73. public function edit($id): void
  74. {
  75. $this->checkAdmin();
  76. $user = DB::query('SELECT * FROM `users` WHERE `id` = ? LIMIT 1', $id)->fetch();
  77. if (!$user) {
  78. Flight::error(new NotFoundException());
  79. return;
  80. }
  81. Flight::render('user/edit.twig', [
  82. 'user' => $user
  83. ]);
  84. }
  85. public function update($id): void
  86. {
  87. $this->checkAdmin();
  88. $form = Flight::request()->data;
  89. $user = DB::query('SELECT * FROM `users` WHERE `id` = ? LIMIT 1', $id)->fetch();
  90. if (!$user) {
  91. Flight::error(new NotFoundException());
  92. return;
  93. }
  94. if (!isset($form->email) || empty($form->email)) {
  95. Session::alert('The email is required.', 'danger');
  96. Flight::redirectBack();
  97. return;
  98. }
  99. if (!isset($form->username) || empty($form->username)) {
  100. Session::alert('The username is required.', 'danger');
  101. Flight::redirectBack();
  102. return;
  103. }
  104. if (DB::query('SELECT COUNT(*) AS `count` FROM `users` WHERE `username` = ? AND `username` <> ?', [$form->username, $user->username])->fetch()->count > 0) {
  105. Session::alert('The username already taken.', 'danger');
  106. Flight::redirectBack();
  107. return;
  108. }
  109. if ($user->id === Session::get('user_id') && !isset($form->is_admin)) {
  110. Session::alert('You cannot demote yourself.', 'danger');
  111. Flight::redirectBack();
  112. return;
  113. }
  114. if (isset($form->password) && !empty($form->password)) {
  115. DB::query('UPDATE `users` SET `email`=?, `username`=?, `password`=?, `is_admin`=?, `active`=? WHERE `id` = ?', [
  116. $form->email,
  117. $form->username,
  118. password_hash($form->password, PASSWORD_DEFAULT),
  119. isset($form->is_admin),
  120. isset($form->is_active),
  121. $user->id
  122. ]);
  123. } else {
  124. DB::query('UPDATE `users` SET `email`=?, `username`=?, `is_admin`=?, `active`=? WHERE `id` = ?', [
  125. $form->email,
  126. $form->username,
  127. isset($form->is_admin),
  128. isset($form->is_active),
  129. $user->id
  130. ]);
  131. }
  132. Session::alert("User '$form->username' updated!", 'success');
  133. Log::info('User ' . Session::get('username') . " updated $user->id.", [$user, array_diff($form->getData(), ['password'])]);
  134. Flight::redirect('/users');
  135. }
  136. public function delete($id): void
  137. {
  138. $this->checkAdmin();
  139. $user = DB::query('SELECT * FROM `users` WHERE `id` = ? LIMIT 1', $id)->fetch();
  140. if (!$user) {
  141. Flight::error(new NotFoundException());
  142. return;
  143. }
  144. if ($user->id === Session::get('user_id')) {
  145. Session::alert('You cannot delete yourself.', 'danger');
  146. Flight::redirectBack();
  147. return;
  148. }
  149. DB::query('DELETE FROM `users` WHERE `id` = ?', $user->id);
  150. Session::alert('User deleted.', 'success');
  151. Log::info('User ' . Session::get('username') . " deleted $user->id.");
  152. Flight::redirect('/users');
  153. }
  154. public function profile(): void
  155. {
  156. $this->checkLogin();
  157. $user = DB::query('SELECT * FROM `users` WHERE `id` = ? LIMIT 1', Session::get('user_id'))->fetch();
  158. if (!$user) {
  159. Flight::error(new NotFoundException());
  160. return;
  161. }
  162. if ($user->id !== Session::get('user_id') && !Session::get('admin', false)) {
  163. Flight::error(new UnauthorizedException());
  164. return;
  165. }
  166. Flight::render('user/profile.twig', [
  167. 'user' => $user
  168. ]);
  169. }
  170. public function profileEdit($id): void
  171. {
  172. $this->checkLogin();
  173. $form = Flight::request()->data;
  174. $user = DB::query('SELECT * FROM `users` WHERE `id` = ? LIMIT 1', $id)->fetch();
  175. if (!$user) {
  176. Flight::error(new NotFoundException());
  177. return;
  178. }
  179. if ($user->id !== Session::get('user_id') && !Session::get('admin', false)) {
  180. Flight::error(new UnauthorizedException());
  181. return;
  182. }
  183. if (!isset($form->email) || empty($form->email)) {
  184. Session::alert('The email is required.', 'danger');
  185. Flight::redirectBack();
  186. return;
  187. }
  188. if (isset($form->password) && !empty($form->password)) {
  189. DB::query('UPDATE `users` SET `email`=?, `password`=? WHERE `id` = ?', [
  190. $form->email,
  191. password_hash($form->password, PASSWORD_DEFAULT),
  192. $user->id
  193. ]);
  194. } else {
  195. DB::query('UPDATE `users` SET `email`=? WHERE `id` = ?', [
  196. $form->email,
  197. $user->id
  198. ]);
  199. }
  200. Session::alert('Profile updated successfully!', 'success');
  201. Log::info('User ' . Session::get('username') . " updated profile of $user->id.");
  202. Flight::redirectBack();
  203. }
  204. public function refreshToken($id): void
  205. {
  206. $this->checkLogin();
  207. $user = DB::query('SELECT * FROM `users` WHERE `id` = ? LIMIT 1', $id)->fetch();
  208. if (!$user) {
  209. Flight::halt(404);
  210. return;
  211. }
  212. if ($user->id !== Session::get('user_id') && !Session::get('admin', false)) {
  213. Flight::halt(403);
  214. return;
  215. }
  216. $token = $this->generateNewToken();
  217. DB::query('UPDATE `users` SET `token`=? WHERE `id` = ?', [
  218. $token,
  219. $user->id
  220. ]);
  221. Log::info('User ' . Session::get('username') . " refreshed token of user $user->id.");
  222. echo $token;
  223. }
  224. public function getShareXconfigFile($id): void
  225. {
  226. $this->checkLogin();
  227. $user = DB::query('SELECT * FROM `users` WHERE `id` = ? LIMIT 1', $id)->fetch();
  228. if (!$user) {
  229. Flight::halt(404);
  230. return;
  231. }
  232. if ($user->id !== Session::get('user_id') && !Session::get('admin', false)) {
  233. Flight::halt(403);
  234. return;
  235. }
  236. $base_url = Flight::get('config')['base_url'];
  237. $json = [
  238. 'DestinationType' => 'ImageUploader, TextUploader, FileUploader',
  239. 'RequestURL' => "$base_url/upload",
  240. 'FileFormName' => 'upload',
  241. 'Arguments' => [
  242. 'file' => '$filename$',
  243. 'text' => '$input$',
  244. 'token' => $user->token,
  245. ],
  246. 'URL' => '$json:url$',
  247. 'ThumbnailURL' => '$json:url$/raw',
  248. ];
  249. Flight::response()->header('Content-Type', 'application/json');
  250. Flight::response()->header('Content-Disposition', 'attachment;filename="' . $user->username . '-ShareX.sxcu"');
  251. Flight::response()->sendHeaders();
  252. echo json_encode($json, JSON_UNESCAPED_SLASHES | JSON_PRETTY_PRINT);
  253. }
  254. protected function generateNewToken(): string
  255. {
  256. do {
  257. $token = 'token_' . md5(uniqid('', true));
  258. } while (DB::query('SELECT COUNT(*) AS `count` FROM `users` WHERE `token` = ?', $token)->fetch()->count > 0);
  259. return $token;
  260. }
  261. }