BookStack/app/Http/Controllers/Auth/UserInviteController.php

107 lines
3 KiB
PHP
Raw Normal View History

2019-08-18 14:11:30 +02:00
<?php
namespace BookStack\Http\Controllers\Auth;
2021-03-19 22:54:50 +01:00
use BookStack\Actions\ActivityType;
use BookStack\Auth\Access\LoginService;
2019-08-18 14:11:30 +02:00
use BookStack\Auth\Access\UserInviteService;
use BookStack\Auth\UserRepo;
use BookStack\Exceptions\UserTokenExpiredException;
use BookStack\Exceptions\UserTokenNotFoundException;
2021-03-19 22:54:50 +01:00
use BookStack\Facades\Theme;
2019-08-18 14:11:30 +02:00
use BookStack\Http\Controllers\Controller;
2021-03-19 22:54:50 +01:00
use BookStack\Theming\ThemeEvents;
2019-08-18 14:11:30 +02:00
use Exception;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Illuminate\Routing\Redirector;
class UserInviteController extends Controller
{
protected $inviteService;
protected $loginService;
2019-08-18 14:11:30 +02:00
protected $userRepo;
/**
* Create a new controller instance.
*/
public function __construct(UserInviteService $inviteService, LoginService $loginService, UserRepo $userRepo)
2019-08-18 14:11:30 +02:00
{
$this->middleware('guest');
$this->middleware('guard:standard');
2019-08-18 14:11:30 +02:00
$this->inviteService = $inviteService;
$this->loginService = $loginService;
2019-08-18 14:11:30 +02:00
$this->userRepo = $userRepo;
}
/**
* Show the page for the user to set the password for their account.
2021-06-26 17:23:15 +02:00
*
2019-08-18 14:11:30 +02:00
* @throws Exception
*/
public function showSetPassword(string $token)
{
try {
$this->inviteService->checkTokenAndGetUserId($token);
} catch (Exception $exception) {
return $this->handleTokenException($exception);
}
return view('auth.invite-set-password', [
'token' => $token,
]);
}
/**
* Sets the password for an invited user and then grants them access.
2021-06-26 17:23:15 +02:00
*
2019-08-18 14:11:30 +02:00
* @throws Exception
*/
public function setPassword(Request $request, string $token)
2019-08-18 14:11:30 +02:00
{
$this->validate($request, [
2021-06-26 17:23:15 +02:00
'password' => 'required|min:8',
2019-08-18 14:11:30 +02:00
]);
try {
$userId = $this->inviteService->checkTokenAndGetUserId($token);
} catch (Exception $exception) {
return $this->handleTokenException($exception);
}
$user = $this->userRepo->getById($userId);
$user->password = bcrypt($request->get('password'));
$user->email_confirmed = true;
$user->save();
$this->loginService->login($user, auth()->getDefaultDriver());
$this->showSuccessNotification(trans('auth.user_invite_success', ['appName' => setting('app-name')]));
2019-08-18 14:11:30 +02:00
$this->inviteService->deleteByUser($user);
return redirect('/');
}
/**
* Check and validate the exception thrown when checking an invite token.
2021-06-26 17:23:15 +02:00
*
2019-08-18 14:11:30 +02:00
* @throws Exception
2021-06-26 17:23:15 +02:00
*
* @return RedirectResponse|Redirector
2019-08-18 14:11:30 +02:00
*/
protected function handleTokenException(Exception $exception)
{
if ($exception instanceof UserTokenNotFoundException) {
return redirect('/');
}
if ($exception instanceof UserTokenExpiredException) {
$this->showErrorNotification(trans('errors.invite_token_expired'));
2021-06-26 17:23:15 +02:00
2019-08-18 14:11:30 +02:00
return redirect('/password/email');
}
throw $exception;
}
}