UserController.php 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322
  1. <?php
  2. namespace App\Controllers;
  3. use App\Database\Queries\UserQuery;
  4. use App\Web\Mail;
  5. use App\Web\ValidationChecker;
  6. use League\Flysystem\FileNotFoundException;
  7. use Psr\Http\Message\ResponseInterface as Response;
  8. use Psr\Http\Message\ServerRequestInterface as Request;
  9. class UserController extends Controller
  10. {
  11. const PER_PAGE = 15;
  12. /**
  13. * @param Response $response
  14. * @param int|null $page
  15. *
  16. * @return Response
  17. * @throws \Twig\Error\RuntimeError
  18. * @throws \Twig\Error\SyntaxError
  19. *
  20. * @throws \Twig\Error\LoaderError
  21. */
  22. public function index(Response $response, int $page = 0): Response
  23. {
  24. $page = max(0, --$page);
  25. $users = $this->database->query('SELECT * FROM `users` LIMIT ? OFFSET ?', [self::PER_PAGE, $page * self::PER_PAGE])->fetchAll();
  26. $pages = $this->database->query('SELECT COUNT(*) AS `count` FROM `users`')->fetch()->count / self::PER_PAGE;
  27. return view()->render($response,
  28. 'user/index.twig',
  29. [
  30. 'users' => $users,
  31. 'next' => $page < floor($pages),
  32. 'previous' => $page >= 1,
  33. 'current_page' => ++$page,
  34. 'quota_enabled' => $this->getSetting('quota_enabled'),
  35. ]
  36. );
  37. }
  38. /**
  39. * @param Response $response
  40. *
  41. * @return Response
  42. * @throws \Twig\Error\RuntimeError
  43. * @throws \Twig\Error\SyntaxError
  44. *
  45. * @throws \Twig\Error\LoaderError
  46. */
  47. public function create(Response $response): Response
  48. {
  49. return view()->render($response, 'user/create.twig', [
  50. 'default_user_quota' => humanFileSize($this->getSetting('default_user_quota'), 0, true),
  51. 'quota_enabled' => $this->getSetting('quota_enabled', 'off'),
  52. ]);
  53. }
  54. /**
  55. * @param Request $request
  56. * @param Response $response
  57. *
  58. * @return Response
  59. * @throws \Exception
  60. */
  61. public function store(Request $request, Response $response): Response
  62. {
  63. $validator = $this->getUserCreateValidator($request);
  64. $hasPassword = $validator->removeRule('password.required');
  65. if ($validator->fails()) {
  66. return redirect($response, route('user.create'));
  67. }
  68. $maxUserQuota = -1;
  69. if ($this->getSetting('quota_enabled') === 'on') {
  70. $maxUserQuotaStr = param($request, 'max_user_quota', humanFileSize($this->getSetting('default_user_quota', -1), 0, true));
  71. if (!preg_match('/([0-9]+[K|M|G|T])|(\-1)/i', $maxUserQuotaStr)) {
  72. $this->session->alert(lang('invalid_quota', 'danger'));
  73. return redirect($response, route('user.create'));
  74. }
  75. if ($maxUserQuotaStr !== '-1') {
  76. $maxUserQuota = stringToBytes($maxUserQuotaStr);
  77. }
  78. }
  79. make(UserQuery::class)->create(
  80. param($request, 'email'),
  81. param($request, 'username'),
  82. param($request, 'password'),
  83. param($request, 'is_admin') !== null ? 1 : 0,
  84. param($request, 'is_active') !== null ? 1 : 0,
  85. $maxUserQuota,
  86. false,
  87. param($request, 'hide_uploads') !== null ? 1 : 0,
  88. param($request, 'copy_raw') !== null ? 1 : 0
  89. );
  90. if (param($request, 'send_notification') !== null) {
  91. $this->sendCreateNotification($hasPassword, $request);
  92. }
  93. $this->session->alert(lang('user_created', [param($request, 'username')]), 'success');
  94. $this->logger->info('User '.$this->session->get('username').' created a new user.', [array_diff_key($request->getParsedBody(), array_flip(['password']))]);
  95. return redirect($response, route('user.index'));
  96. }
  97. /**
  98. * @param Request $request
  99. * @param Response $response
  100. * @param int $id
  101. *
  102. * @return Response
  103. * @throws \Twig\Error\LoaderError
  104. * @throws \Twig\Error\RuntimeError
  105. * @throws \Twig\Error\SyntaxError
  106. */
  107. public function edit(Request $request, Response $response, int $id): Response
  108. {
  109. $user = make(UserQuery::class)->get($request, $id);
  110. return view()->render($response, 'user/edit.twig', [
  111. 'profile' => false,
  112. 'user' => $user,
  113. 'quota_enabled' => $this->getSetting('quota_enabled', 'off'),
  114. 'max_disk_quota' => $user->max_disk_quota > 0 ? humanFileSize($user->max_disk_quota, 0, true) : -1,
  115. ]);
  116. }
  117. /**
  118. * @param Request $request
  119. * @param Response $response
  120. * @param int $id
  121. *
  122. * @return Response
  123. */
  124. public function update(Request $request, Response $response, int $id): Response
  125. {
  126. $user = make(UserQuery::class)->get($request, $id);
  127. $validator = ValidationChecker::make()
  128. ->rules([
  129. 'email.required' => filter_var(param($request, 'email'), FILTER_VALIDATE_EMAIL),
  130. 'username.required' => !empty(param($request, 'username')),
  131. 'email.unique' => $this->database->query('SELECT COUNT(*) AS `count` FROM `users` WHERE `email` = ? AND `email` <> ?', [param($request, 'email'), $user->email])->fetch()->count == 0,
  132. 'username.unique' => $this->database->query('SELECT COUNT(*) AS `count` FROM `users` WHERE `username` = ? AND `username` <> ?', [param($request, 'username'), $user->username])->fetch()->count == 0,
  133. 'demote' => !($user->id === $this->session->get('user_id') && param($request, 'is_admin') === null),
  134. ])
  135. ->onFail(function ($rule) {
  136. $alerts = [
  137. 'email.required' => lang('email_required'),
  138. 'username.required' => lang('username_required'),
  139. 'email.unique' => lang('email_taken'),
  140. 'username.unique' => lang('username_taken'),
  141. 'demote' => lang('cannot_demote'),
  142. ];
  143. $this->session->alert($alerts[$rule], 'danger');
  144. });
  145. if ($validator->fails()) {
  146. return redirect($response, route('user.edit', ['id' => $id]));
  147. }
  148. $user->max_disk_quota = -1;
  149. if ($this->getSetting('quota_enabled') === 'on') {
  150. $maxUserQuota = param($request, 'max_user_quota', humanFileSize($this->getSetting('default_user_quota'), 0, true));
  151. if (!preg_match('/([0-9]+[K|M|G|T])|(\-1)/i', $maxUserQuota)) {
  152. $this->session->alert(lang('invalid_quota', 'danger'));
  153. return redirect($response, route('user.create'));
  154. }
  155. if ($maxUserQuota !== '-1') {
  156. $user->max_disk_quota = stringToBytes($maxUserQuota);
  157. }
  158. }
  159. make(UserQuery::class)->update(
  160. $user->id,
  161. param($request, 'email'),
  162. param($request, 'username'),
  163. param($request, 'password'),
  164. param($request, 'is_admin') !== null ? 1 : 0,
  165. param($request, 'is_active') !== null ? 1 : 0,
  166. $user->max_disk_quota,
  167. param($request, 'ldap') !== null ? 1 : 0,
  168. param($request, 'hide_uploads') !== null ? 1 : 0,
  169. param($request, 'copy_raw') !== null ? 1 : 0
  170. );
  171. if ($user->id === $this->session->get('user_id')) {
  172. $this->setSessionQuotaInfo($user->current_disk_quota, $user->max_disk_quota);
  173. }
  174. $this->session->alert(lang('user_updated', [param($request, 'username')]), 'success');
  175. $this->logger->info('User '.$this->session->get('username')." updated $user->id.", [
  176. array_diff_key((array) $user, array_flip(['password'])),
  177. array_diff_key($request->getParsedBody(), array_flip(['password'])),
  178. ]);
  179. return redirect($response, route('user.index'));
  180. }
  181. /**
  182. * @param Request $request
  183. * @param Response $response
  184. * @param int $id
  185. *
  186. * @return Response
  187. */
  188. public function delete(Request $request, Response $response, int $id): Response
  189. {
  190. $user = make(UserQuery::class)->get($request, $id);
  191. if ($user->id === $this->session->get('user_id')) {
  192. $this->session->alert(lang('cannot_delete'), 'danger');
  193. return redirect($response, route('user.index'));
  194. }
  195. $this->database->query('DELETE FROM `users` WHERE `id` = ?', $user->id);
  196. $this->session->alert(lang('user_deleted'), 'success');
  197. $this->logger->info('User '.$this->session->get('username')." deleted $user->id.");
  198. return redirect($response, route('user.index'));
  199. }
  200. /**
  201. * @param Request $request
  202. * @param Response $response
  203. * @param int $id
  204. * @return Response
  205. */
  206. public function clearUserMedia(Request $request, Response $response, int $id): Response
  207. {
  208. $user = make(UserQuery::class)->get($request, $id, true);
  209. $medias = $this->database->query('SELECT * FROM `uploads` WHERE `user_id` = ?', $user->id);
  210. foreach ($medias as $media) {
  211. try {
  212. $this->storage->delete($media->storage_path);
  213. } catch (FileNotFoundException $e) {
  214. }
  215. }
  216. $this->database->query('DELETE FROM `uploads` WHERE `user_id` = ?', $user->id);
  217. $this->database->query('UPDATE `users` SET `current_disk_quota`=? WHERE `id` = ?', [
  218. 0,
  219. $user->id,
  220. ]);
  221. $this->session->alert(lang('account_media_deleted'), 'success');
  222. return redirect($response, route('user.edit', ['id' => $id]));
  223. }
  224. /**
  225. * @param Request $request
  226. * @param Response $response
  227. * @param int $id
  228. *
  229. * @return Response
  230. */
  231. public function refreshToken(Request $request, Response $response, int $id): Response
  232. {
  233. $query = make(UserQuery::class);
  234. $user = $query->get($request, $id, true);
  235. $this->logger->info('User '.$this->session->get('username')." refreshed token of user $user->id.");
  236. $response->getBody()->write($query->refreshToken($user->id));
  237. return $response;
  238. }
  239. /**
  240. * @param $hasPassword
  241. * @param $request
  242. * @throws \Exception
  243. */
  244. private function sendCreateNotification($hasPassword, $request)
  245. {
  246. if ($hasPassword) {
  247. $message = lang('mail.new_account_text_with_pw', [
  248. param($request, 'username'),
  249. $this->config['app_name'],
  250. $this->config['base_url'],
  251. param($request, 'username'),
  252. param($request, 'password'),
  253. route('login.show'),
  254. ]);
  255. } else {
  256. $resetToken = bin2hex(random_bytes(16));
  257. $this->database->query('UPDATE `users` SET `reset_token`=? WHERE `id` = ?', [
  258. $resetToken,
  259. $this->database->getPdo()->lastInsertId(),
  260. ]);
  261. $message = lang('mail.new_account_text_with_reset', [
  262. param($request, 'username'),
  263. $this->config['app_name'],
  264. $this->config['base_url'],
  265. route('recover.password', ['resetToken' => $resetToken]),
  266. ]);
  267. }
  268. Mail::make()
  269. ->from(platform_mail(), $this->config['app_name'])
  270. ->to(param($request, 'email'))
  271. ->subject(lang('mail.new_account', [$this->config['app_name']]))
  272. ->message($message)
  273. ->send();
  274. }
  275. }