UserController.php 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422
  1. <?php
  2. namespace App\Http\Controllers\Admin;
  3. use App\Events\UserUpdateCreditsEvent;
  4. use App\Http\Controllers\Controller;
  5. use App\Models\User;
  6. use App\Notifications\DynamicNotification;
  7. use App\Settings\LocaleSettings;
  8. use App\Settings\PterodactylSettings;
  9. use App\Classes\PterodactylClient;
  10. use App\Settings\GeneralSettings;
  11. use Exception;
  12. use Illuminate\Contracts\Foundation\Application;
  13. use Illuminate\Contracts\View\Factory;
  14. use Illuminate\Contracts\View\View;
  15. use Illuminate\Http\RedirectResponse;
  16. use Illuminate\Http\Request;
  17. use Illuminate\Http\Response;
  18. use Illuminate\Notifications\Messages\MailMessage;
  19. use Illuminate\Support\Facades\Auth;
  20. use Illuminate\Support\Facades\DB;
  21. use Illuminate\Support\Facades\Hash;
  22. use Illuminate\Support\Facades\Notification;
  23. use Illuminate\Support\HtmlString;
  24. use Illuminate\Validation\Rule;
  25. use Illuminate\Validation\ValidationException;
  26. use Spatie\QueryBuilder\QueryBuilder;
  27. use App\Models\Role;
  28. class UserController extends Controller
  29. {
  30. const READ_PERMISSION = "admin.users.read";
  31. const WRITE_PERMISSION = "admin.users.write";
  32. const SUSPEND_PERMISSION = "admin.users.suspend";
  33. const CHANGE_EMAIL_PERMISSION = "admin.users.write.email";
  34. const CHANGE_CREDITS_PERMISSION = "admin.users.write.credits";
  35. const CHANGE_USERNAME_PERMISSION = "admin.users.write.username";
  36. const CHANGE_PASSWORD_PERMISSION = "admin.users.write.password";
  37. const CHANGE_ROLE_PERMISSION ="admin.users.write.role";
  38. const CHANGE_REFERAL_PERMISSION ="admin.users.write.referral";
  39. const CHANGE_PTERO_PERMISSION = "admin.users.write.pterodactyl";
  40. const DELETE_PERMISSION = "admin.users.delete";
  41. const NOTIFY_PERMISSION = "admin.users.notify";
  42. const LOGIN_PERMISSION = "admin.users.login_as";
  43. private $pterodactyl;
  44. public function __construct(PterodactylSettings $ptero_settings)
  45. {
  46. $this->pterodactyl = new PterodactylClient($ptero_settings);
  47. }
  48. /**
  49. * Display a listing of the resource.
  50. *
  51. * @param Request $request
  52. * @return Application|Factory|View|Response
  53. */
  54. public function index(LocaleSettings $locale_settings, GeneralSettings $general_settings)
  55. {
  56. $this->checkPermission(self::READ_PERMISSION);
  57. return view('admin.users.index', [
  58. 'locale_datatables' => $locale_settings->datatables,
  59. 'credits_display_name' => $general_settings->credits_display_name
  60. ]);
  61. }
  62. /**
  63. * Display the specified resource.
  64. *
  65. * @param User $user
  66. * @return Application|Factory|View|Response
  67. */
  68. public function show(User $user, LocaleSettings $locale_settings, GeneralSettings $general_settings)
  69. {
  70. $this->checkPermission(self::READ_PERMISSION);
  71. //QUERY ALL REFERRALS A USER HAS
  72. //i am not proud of this at all.
  73. $allReferals = [];
  74. $referrals = DB::table('user_referrals')->where('referral_id', '=', $user->id)->get();
  75. foreach ($referrals as $referral) {
  76. array_push($allReferals, $allReferals['id'] = User::query()->findOrFail($referral->registered_user_id));
  77. }
  78. array_pop($allReferals);
  79. return view('admin.users.show')->with([
  80. 'user' => $user,
  81. 'referrals' => $allReferals,
  82. 'locale_datatables' => $locale_settings->datatables,
  83. 'credits_display_name' => $general_settings->credits_display_name
  84. ]);
  85. }
  86. /**
  87. * Get a JSON response of users.
  88. *
  89. * @return \Illuminate\Support\Collection|\App\models\User
  90. */
  91. public function json(Request $request)
  92. {
  93. $users = QueryBuilder::for(User::query())
  94. ->allowedFilters(['id', 'name', 'pterodactyl_id', 'email'])
  95. ->paginate(25);
  96. if ($request->query('user_id')) {
  97. $user = User::query()->findOrFail($request->input('user_id'));
  98. $user->avatarUrl = $user->getAvatar();
  99. return $user;
  100. }
  101. return $users->map(function ($item) {
  102. $item->avatarUrl = $item->getAvatar();
  103. return $item;
  104. });
  105. }
  106. /**
  107. * Show the form for editing the specified resource.
  108. *
  109. * @param User $user
  110. * @return Application|Factory|View|Response
  111. */
  112. public function edit(User $user, GeneralSettings $general_settings)
  113. {
  114. $this->checkPermission(self::WRITE_PERMISSION);
  115. $roles = Role::all();
  116. return view('admin.users.edit')->with([
  117. 'user' => $user,
  118. 'credits_display_name' => $general_settings->credits_display_name,
  119. 'roles' => $roles
  120. ]);
  121. }
  122. /**
  123. * Update the specified resource in storage.
  124. *
  125. * @param Request $request
  126. * @param User $user
  127. * @return RedirectResponse
  128. *
  129. * @throws Exception
  130. */
  131. public function update(Request $request, User $user)
  132. {
  133. $data = $request->validate([
  134. 'name' => 'required|string|min:4|max:30',
  135. 'pterodactyl_id' => "required|numeric|unique:users,pterodactyl_id,{$user->id}",
  136. 'email' => 'required|string|email',
  137. 'credits' => 'required|numeric|min:0|max:99999999',
  138. 'server_limit' => 'required|numeric|min:0|max:1000000',
  139. 'referral_code' => "required|string|min:2|max:32|unique:users,referral_code,{$user->id}",
  140. ]);
  141. //update roles
  142. if ($request->roles && $this->can(self::CHANGE_ROLE_PERMISSION)) {
  143. $user->syncRoles($request->roles);
  144. }
  145. if (isset($this->pterodactyl->getUser($request->input('pterodactyl_id'))['errors'])) {
  146. throw ValidationException::withMessages([
  147. 'pterodactyl_id' => [__("User does not exists on pterodactyl's panel")],
  148. ]);
  149. }
  150. if (!is_null($request->input('new_password')) && $this->can(self::CHANGE_PASSWORD_PERMISSION)) {
  151. $request->validate([
  152. 'new_password' => 'required|string|min:8',
  153. 'new_password_confirmation' => 'required|same:new_password',
  154. ]);
  155. $user->update([
  156. 'password' => Hash::make($request->input('new_password')),
  157. ]);
  158. }
  159. // if($this->can(self::CHANGE_USERNAME_PERMISSION)){
  160. // $user->name = $request->name;
  161. // }
  162. // if($this->can(self::CHANGE_CREDITS_PERMISSION)){
  163. // $user->credits = $request->credits;
  164. // }
  165. // if($this->can(self::CHANGE_PTERO_PERMISSION)){
  166. // $user->pterodactyl_id = $request->pterodactyl_id;
  167. // }
  168. // if($this->can(self::CHANGE_REFERAL_PERMISSION)){
  169. // $user->referral_code = $request->referral_code;
  170. // }
  171. // if($this->can(self::CHANGE_EMAIL_PERMISSION)){
  172. // $user->email = $request->email;
  173. // }
  174. $user->update($data);
  175. event(new UserUpdateCreditsEvent($user));
  176. return redirect()->route('admin.users.index')->with('success', 'User updated!');
  177. }
  178. /**
  179. * Remove the specified resource from storage.
  180. *
  181. * @param User $user
  182. * @return RedirectResponse
  183. */
  184. public function destroy(User $user)
  185. {
  186. $this->checkPermission(self::DELETE_PERMISSION);
  187. if ($user->hasRole(1) && User::role(1)->count() === 1) {
  188. return redirect()->back()->with('error', __('You can not delete the last admin!'));
  189. }
  190. $user->delete();
  191. return redirect()->back()->with('success', __('user has been removed!'));
  192. }
  193. /**
  194. * Verifys the users email
  195. *
  196. * @param User $user
  197. * @return RedirectResponse
  198. */
  199. public function verifyEmail(User $user)
  200. {
  201. $user->verifyEmail();
  202. return redirect()->back()->with('success', __('Email has been verified!'));
  203. }
  204. /**
  205. * @param Request $request
  206. * @param User $user
  207. * @return RedirectResponse
  208. */
  209. public function loginAs(Request $request, User $user)
  210. {
  211. $this->checkPermission(self::LOGIN_PERMISSION);
  212. $request->session()->put('previousUser', Auth::user()->id);
  213. Auth::login($user);
  214. return redirect()->route('home');
  215. }
  216. /**
  217. * @param Request $request
  218. * @return RedirectResponse
  219. */
  220. public function logBackIn(Request $request)
  221. {
  222. Auth::loginUsingId($request->session()->get('previousUser'), true);
  223. $request->session()->remove('previousUser');
  224. return redirect()->route('admin.users.index');
  225. }
  226. /**
  227. * Show the form for seding notifications to the specified resource.
  228. *
  229. * @param User $user
  230. * @return Application|Factory|View|Response
  231. */
  232. public function notifications()
  233. {
  234. $this->checkPermission(self::NOTIFY_PERMISSION);
  235. $roles = Role::all();
  236. return view('admin.users.notifications')->with(["roles" => $roles]);
  237. }
  238. /**
  239. * Notify the specified resource.
  240. *
  241. * @param Request $request
  242. * @param User $user
  243. * @return RedirectResponse
  244. *
  245. * @throws Exception
  246. */
  247. public function notify(Request $request)
  248. {
  249. $this->checkPermission(self::NOTIFY_PERMISSION);
  250. //TODO: reimplement the required validation on all,users and roles . didnt work -- required_without:users,roles
  251. $data = $request->validate([
  252. 'via' => 'required|min:1|array',
  253. 'via.*' => 'required|string|in:mail,database',
  254. 'all' => 'boolean',
  255. 'users' => 'min:1|array',
  256. 'roles' => 'min:1|array',
  257. 'roles.*' => 'required_without:all,users|exists:roles,id',
  258. 'title' => 'required|string|min:1',
  259. 'content' => 'required|string|min:1',
  260. ]);
  261. $mail = null;
  262. $database = null;
  263. if (in_array('database', $data['via'])) {
  264. $database = [
  265. 'title' => $data['title'],
  266. 'content' => $data['content'],
  267. ];
  268. }
  269. if (in_array('mail', $data['via'])) {
  270. $mail = (new MailMessage)
  271. ->subject($data['title'])
  272. ->line(new HtmlString($data['content']));
  273. }
  274. $all = $data['all'] ?? false;
  275. $roles = $data['roles'] ?? false;
  276. if(!$roles){
  277. $users = $all ? User::all() : User::whereIn('id', $data['users'])->get();
  278. } else{
  279. $users = User::role($data["roles"])->get();
  280. }
  281. try {
  282. Notification::send($users, new DynamicNotification($data['via'], $database, $mail));
  283. } catch (Exception $e) {
  284. return redirect()->route('admin.users.notifications')->with('error', __('The attempt to send the email failed with the error: ' . $e->getMessage()));
  285. }
  286. return redirect()->route('admin.users.notifications')->with('success', __('Notification sent!'));
  287. }
  288. /**
  289. * @param User $user
  290. * @return RedirectResponse
  291. */
  292. public function toggleSuspended(User $user)
  293. {
  294. $this->checkPermission(self::SUSPEND_PERMISSION);
  295. if (Auth::user()->id === $user->id) {
  296. return redirect()->back()->with('error', __('You can not suspend yourself!'));
  297. }
  298. try {
  299. !$user->isSuspended() ? $user->suspend() : $user->unSuspend();
  300. } catch (Exception $exception) {
  301. return redirect()->back()->with('error', $exception->getMessage());
  302. }
  303. return redirect()->back()->with('success', __('User has been updated!'));
  304. }
  305. /**
  306. * @throws Exception
  307. */
  308. public function dataTable(Request $request)
  309. {
  310. $query = User::query()
  311. ->withCount('servers')
  312. ->leftJoin('model_has_roles', 'users.id', '=', 'model_has_roles.model_id')
  313. ->leftJoin('roles', 'model_has_roles.role_id', '=', 'roles.id')
  314. ->selectRaw('users.*, roles.name as role_name, (SELECT COUNT(*) FROM user_referrals WHERE user_referrals.referral_id = users.id) as referrals_count')
  315. ->where('model_has_roles.model_type', User::class);
  316. return datatables($query)
  317. ->addColumn('avatar', function (User $user) {
  318. return '<img width="28px" height="28px" class="ml-1 rounded-circle" src="' . $user->getAvatar() . '">';
  319. })
  320. ->addColumn('credits', function (User $user) {
  321. return '<i class="mr-2 fas fa-coins"></i> ' . $user->credits();
  322. })
  323. ->addColumn('verified', function (User $user) {
  324. return $user->getVerifiedStatus();
  325. })
  326. ->addColumn('discordId', function (User $user) {
  327. return $user->discordUser ? $user->discordUser->id : '';
  328. })
  329. ->addColumn('actions', function (User $user) {
  330. $suspendColor = $user->isSuspended() ? 'btn-success' : 'btn-warning';
  331. $suspendIcon = $user->isSuspended() ? 'fa-play-circle' : 'fa-pause-circle';
  332. $suspendText = $user->isSuspended() ? __('Unsuspend') : __('Suspend');
  333. return '
  334. <a data-content="' . __('Login as User') . '" data-toggle="popover" data-trigger="hover" data-placement="top" href="' . route('admin.users.loginas', $user->id) . '" class="mr-1 btn btn-sm btn-primary"><i class="fas fa-sign-in-alt"></i></a>
  335. <a data-content="' . __('Verify') . '" data-toggle="popover" data-trigger="hover" data-placement="top" href="' . route('admin.users.verifyEmail', $user->id) . '" class="mr-1 btn btn-sm btn-secondary"><i class="fas fa-envelope"></i></a>
  336. <a data-content="' . __('Show') . '" data-toggle="popover" data-trigger="hover" data-placement="top" href="' . route('admin.users.show', $user->id) . '" class="mr-1 text-white btn btn-sm btn-warning"><i class="fas fa-eye"></i></a>
  337. <a data-content="' . __('Edit') . '" data-toggle="popover" data-trigger="hover" data-placement="top" href="' . route('admin.users.edit', $user->id) . '" class="mr-1 btn btn-sm btn-info"><i class="fas fa-pen"></i></a>
  338. <form class="d-inline" method="post" action="' . route('admin.users.togglesuspend', $user->id) . '">
  339. ' . csrf_field() . '
  340. <button data-content="' . $suspendText . '" data-toggle="popover" data-trigger="hover" data-placement="top" class="btn btn-sm ' . $suspendColor . ' text-white mr-1"><i class="far ' . $suspendIcon . '"></i></button>
  341. </form>
  342. <form class="d-inline" onsubmit="return submitResult();" method="post" action="' . route('admin.users.destroy', $user->id) . '">
  343. ' . csrf_field() . '
  344. ' . method_field('DELETE') . '
  345. <button data-content="' . __('Delete') . '" data-toggle="popover" data-trigger="hover" data-placement="top" class="mr-1 btn btn-sm btn-danger"><i class="fas fa-trash"></i></button>
  346. </form>
  347. ';
  348. })
  349. ->editColumn('role', function (User $user) {
  350. $html = '';
  351. foreach ($user->roles as $role) {
  352. $html .= "<span style='background-color: $role->color' class='badge'>$role->name</span>";
  353. }
  354. return $html;
  355. })
  356. ->editColumn('last_seen', function (User $user) {
  357. return $user->last_seen ? $user->last_seen->diffForHumans() : __('Never');
  358. })
  359. ->editColumn('name', function (User $user, PterodactylSettings $ptero_settings) {
  360. return '<a class="text-info" target="_blank" href="' . $ptero_settings->panel_url . '/admin/users/view/' . $user->pterodactyl_id . '">' . strip_tags($user->name) . '</a>';
  361. })
  362. ->orderColumn('role', 'role_name $1')
  363. ->rawColumns(['avatar', 'name', 'credits', 'role', 'usage', 'actions'])
  364. ->make();
  365. }
  366. }