UserController.php 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Http\Models\Article;
  4. use App\Http\Models\Config;
  5. use App\Http\Models\Invite;
  6. use App\Http\Models\SsNode;
  7. use App\Http\Models\SsNodeInfo;
  8. use App\Http\Models\SsNodeOnlineLog;
  9. use App\Http\Models\User;
  10. use App\Http\Models\UserTrafficLog;
  11. use App\Http\Models\Verify;
  12. use App\Mail\activeUser;
  13. use App\Mail\resetPassword;
  14. use Illuminate\Http\Request;
  15. use Redirect;
  16. use Response;
  17. use Cache;
  18. use Mail;
  19. class UserController extends BaseController
  20. {
  21. protected static $config;
  22. function __construct()
  23. {
  24. self::$config = $this->systemConfig();
  25. }
  26. public function index(Request $request)
  27. {
  28. if (!$request->session()->has('user')) {
  29. return Redirect::to('login');
  30. }
  31. $view['articleList'] = Article::orderBy('sort', 'desc')->orderBy('id', 'desc')->paginate(5);
  32. $view['info'] = $request->session()->get('user');
  33. return Response::view('user/index', $view);
  34. }
  35. // 公告详情
  36. public function article(Request $request)
  37. {
  38. $id = $request->get('id');
  39. $view['info'] = Article::where('id', $id)->first();
  40. return Response::view('user/article', $view);
  41. }
  42. // 修改个人资料
  43. public function profile(Request $request)
  44. {
  45. if (!$request->session()->has('user')) {
  46. return Redirect::to('login');
  47. }
  48. $user = $request->session()->get('user');
  49. if ($request->method() == 'POST') {
  50. $old_password = $request->get('old_password');
  51. $new_password = $request->get('new_password');
  52. $port = trim($request->get('port'));
  53. $passwd = trim($request->get('passwd'));
  54. $method = $request->get('method');
  55. $protocol = $request->get('protocol');
  56. $obfs = $request->get('obfs');
  57. // 修改密码
  58. if (!empty($old_password) && !empty($new_password)) {
  59. $old_password = md5(trim($old_password));
  60. $new_password = md5(trim($new_password));
  61. $user = User::where('id', $user['id'])->first();
  62. if ($user->password != $old_password) {
  63. $request->session()->flash('errorMsg', '旧密码错误,请重新输入');
  64. return Redirect::to('user/profile#tab_1');
  65. } else if ($user->password == $new_password) {
  66. $request->session()->flash('errorMsg', '新密码不可与旧密码一样,请重新输入');
  67. return Redirect::to('user/profile#tab_1');
  68. }
  69. $ret = User::where('id', $user['id'])->update(['password' => $new_password]);
  70. if (!$ret) {
  71. $request->session()->flash('errorMsg', '修改失败');
  72. return Redirect::to('user/profile#tab_1');
  73. } else {
  74. $request->session()->flash('successMsg', '修改成功');
  75. return Redirect::to('user/profile#tab_1');
  76. }
  77. }
  78. // 修改SS信息
  79. if (empty($port)) {
  80. $request->session()->flash('errorMsg', '端口不能为空');
  81. return Redirect::to('user/profile#tab_2');
  82. }
  83. if (empty($passwd)) {
  84. $request->session()->flash('errorMsg', '密码不能为空');
  85. return Redirect::to('user/profile#tab_2');
  86. }
  87. $data = [
  88. //'port' => $port,
  89. 'passwd' => $passwd,
  90. 'method' => $method,
  91. 'protocol' => $protocol,
  92. 'obfs' => $obfs
  93. ];
  94. $ret = User::where('id', $user['id'])->update($data);
  95. if (!$ret) {
  96. $request->session()->flash('errorMsg', '修改失败');
  97. return Redirect::to('user/profile#tab_2');
  98. } else {
  99. // 更新session
  100. $user = User::where('id', $user['id'])->first()->toArray();
  101. $request->session()->remove('user');
  102. $request->session()->put('user', $user);
  103. $request->session()->flash('successMsg', '修改成功');
  104. return Redirect::to('user/profile#tab_2');
  105. }
  106. } else {
  107. // 加密方式、协议、混淆
  108. $view['method_list'] = $this->methodList();
  109. $view['protocol_list'] = $this->protocolList();
  110. $view['obfs_list'] = $this->obfsList();
  111. $view['info'] = User::where('id', $user['id'])->first();
  112. return Response::view('user/profile', $view);
  113. }
  114. }
  115. // 节点列表
  116. public function nodeList(Request $request)
  117. {
  118. if (!$request->session()->has('user')) {
  119. return Redirect::to('login');
  120. }
  121. $user = $request->session()->get('user');
  122. $nodeList = SsNode::paginate(10);
  123. foreach ($nodeList as &$node) {
  124. // 在线人数
  125. $online_log = SsNodeOnlineLog::where('node_id', $node->id)->orderBy('id', 'desc')->first();
  126. $node->online_users = empty($online_log) ? 0 : $online_log->online_user;
  127. // 已产生流量
  128. $u = UserTrafficLog::where('node_id', $node->id)->sum('u');
  129. $d = UserTrafficLog::where('node_id', $node->id)->sum('d');
  130. $node->transfer = $this->flowAutoShow($u + $d);
  131. // 负载
  132. $node_info = SsNodeInfo::where('node_id', $node->id)->orderBy('id', 'desc')->first();
  133. $node->load = empty($node_info->load) ? 0 : $node_info->load;
  134. // 生成ssr scheme
  135. $ssr_str = '';
  136. $ssr_str .= $node->server . ':' . $user['port'];
  137. $ssr_str .= ':' . $user['protocol'] . ':' . $user['method'];
  138. $ssr_str .= ':' . $user['obfs'] . ':' . base64_encode($user['passwd']);
  139. $ssr_str .= '/?obfsparam=' . $user['obfs_param'];
  140. $ssr_str .= '&=protoparam' . $user['protocol_param'];
  141. $ssr_str .= '&remarks=' . base64_encode('VPN');
  142. $ssr_str = $this->base64url_encode($ssr_str);
  143. $ssr_scheme = 'ssr://' . $ssr_str;
  144. // 生成ss scheme
  145. $ss_str = '';
  146. $ss_str .= $user['method'] . ':' . $user['passwd'] . '@';
  147. $ss_str .= $node->server . ':' . $user['port'];
  148. $ss_str = $this->base64url_encode($ss_str) . '#' . 'VPN';
  149. $ss_scheme = 'ss://' . $ss_str;
  150. // 生成文本配置信息
  151. $txt = <<<TXT
  152. 服务器:{$node->server}
  153. 远程端口:{$user['port']}
  154. 本地端口:1080
  155. 密码:{$user['passwd']}
  156. 加密方法:{$user['method']}
  157. 协议:{$user['protocol']}
  158. 协议参数:{$user['protocol_param']}
  159. 混淆方式:{$user['obfs']}
  160. 混淆参数:{$user['obfs_param']}
  161. 路由:绕过局域网及中国大陆地址
  162. TXT;
  163. $node->txt = $txt;
  164. $node->ssr_scheme = $ssr_scheme;
  165. $node->ss_scheme = $ss_scheme;
  166. }
  167. $view['nodeList'] = $nodeList;
  168. return Response::view('user/nodeList', $view);
  169. }
  170. // 流量日志
  171. public function trafficLog(Request $request)
  172. {
  173. if (!$request->session()->has('user')) {
  174. return Redirect::to('login');
  175. }
  176. $user = $request->session()->get('user');
  177. // 30天内的流量
  178. $trafficList = \DB::select("SELECT date(from_unixtime(log_time)) AS dd, SUM(u) AS u, SUM(d) AS d FROM `user_traffic_log` WHERE `user_id` = {$user['id']} GROUP BY `dd`");
  179. foreach ($trafficList as $key => &$val) {
  180. $val->total = ($val->u + $val->d) / (1024 * 1024); // 以M为单位
  181. }
  182. $view['trafficList'] = $trafficList;
  183. return Response::view('user/trafficLog', $view);
  184. }
  185. // 邀请码
  186. public function invite(Request $request)
  187. {
  188. if (!$request->session()->has('user')) {
  189. return Redirect::to('login');
  190. }
  191. $user = $request->session()->get('user');
  192. // 已生成的邀请码数量
  193. $num = Invite::where('uid', $user['id'])->count();
  194. $view['num'] = self::$config['invite_num'] - $num <= 0 ? 0 : self::$config['invite_num'] - $num; // 还可以生成的邀请码数量
  195. $view['inviteList'] = Invite::where('uid', $user['id'])->with(['generator', 'user'])->paginate(10); // 邀请码列表
  196. return Response::view('user/invite', $view);
  197. }
  198. // 生成邀请码
  199. public function makeInvite(Request $request)
  200. {
  201. if (!$request->session()->has('user')) {
  202. return Redirect::to('login');
  203. }
  204. $user = $request->session()->get('user');
  205. // 已生成的邀请码数量
  206. $num = Invite::where('uid', $user['id'])->count();
  207. if ($num >= self::$config['invite_num']) {
  208. return Response::json(['status' => 'fail', 'data' => '', 'message' => '生成失败:最多只能生成' . self::$config['invite_num'] . '个邀请码']);
  209. }
  210. $obj = new Invite();
  211. $obj->uid = $user['id'];
  212. $obj->fuid = 0;
  213. $obj->code = strtoupper(mb_substr(md5(microtime() . $this->makeRandStr(6)), 8, 16));
  214. $obj->status = 0;
  215. $obj->dateline = date('Y-m-d H:i:s', strtotime("+7 days"));
  216. $obj->save();
  217. return Response::json(['status' => 'success', 'data' => '', 'message' => '生成成功']);
  218. }
  219. // 激活账号页
  220. public function activeUser(Request $request)
  221. {
  222. if ($request->method() == 'POST') {
  223. $username = trim($request->get('username'));
  224. // 是否开启账号激活
  225. if (!self::$config['is_active_register']) {
  226. $request->session()->flash('errorMsg', '系统未开启账号激活功能,请联系管理员');
  227. return Redirect::back()->withInput();
  228. }
  229. // 查找账号
  230. $user = User::where('username', $username)->first();
  231. if (!$user) {
  232. $request->session()->flash('errorMsg', '账号不存在,请重试');
  233. return Redirect::back();
  234. } else if ($user->status < 0) {
  235. $request->session()->flash('errorMsg', '账号已禁止登陆,无需激活');
  236. return Redirect::back();
  237. } else if ($user->status > 0) {
  238. $request->session()->flash('errorMsg', '账号无需激活');
  239. return Redirect::back();
  240. }
  241. // 24小时内激活次数限制
  242. $activeTimes = 0;
  243. if (Cache::has('activeUser_' . md5($username))) {
  244. $activeTimes = Cache::get('activeUser_' . md5($username));
  245. if ($activeTimes >= self::$config['active_times']) {
  246. $request->session()->flash('errorMsg', '同一个账号24小时内只能请求激活' . self::$config['active_times'] . '次,请勿频繁操作');
  247. return Redirect::back();
  248. }
  249. }
  250. // 生成激活账号的地址
  251. $token = md5(self::$config['website_name'] . $username . microtime());
  252. $verify = new Verify();
  253. $verify->user_id = $user->id;
  254. $verify->username = $username;
  255. $verify->token = $token;
  256. $verify->status = 0;
  257. $verify->save();
  258. // 发送邮件
  259. $activeUserUrl = self::$config['website_url'] . '/active/' . $token;
  260. Mail::to($user->username)->send(new activeUser(self::$config['website_name'], $activeUserUrl));
  261. Cache::put('activeUser_' . md5($username), $activeTimes + 1, 1440);
  262. $request->session()->flash('successMsg', '邮件已发送,请查看邮箱');
  263. return Redirect::back();
  264. } else {
  265. $view['is_active_register'] = self::$config['is_active_register'];
  266. return Response::view('user/activeUser', $view);
  267. }
  268. }
  269. // 激活账号
  270. public function active(Request $request, $token)
  271. {
  272. if (empty($token)) {
  273. return Redirect::to('login');
  274. }
  275. $verify = Verify::where('token', $token)->with('user')->first();
  276. if (empty($verify)) {
  277. return Redirect::to('login');
  278. } else if ($verify->status == 1) {
  279. $request->session()->flash('errorMsg', '该链接已失效');
  280. return Response::view('user/active');
  281. } else if ($verify->user->status != 0) {
  282. $request->session()->flash('errorMsg', '该账号无需激活.');
  283. return Response::view('user/active');
  284. } else if (time() - strtotime($verify->created_at) >= 1800) {
  285. $request->session()->flash('errorMsg', '该链接已过期');
  286. // 置为已失效
  287. $verify->status = 2;
  288. $verify->save();
  289. return Response::view('user/active');
  290. }
  291. // 更新账号状态
  292. $ret = User::where('id', $verify->user_id)->update(['status' => 1]);
  293. if (!$ret) {
  294. $request->session()->flash('errorMsg', '账号激活失败');
  295. return Redirect::back();
  296. }
  297. // 置为已使用
  298. $verify->status = 1;
  299. $verify->save();
  300. $request->session()->flash('successMsg', '账号激活成功');
  301. return Response::view('user/active');
  302. }
  303. // 重设密码页
  304. public function resetPassword(Request $request)
  305. {
  306. if ($request->method() == 'POST') {
  307. $username = trim($request->get('username'));
  308. // 是否开启重设密码
  309. if (!self::$config['is_reset_password']) {
  310. $request->session()->flash('errorMsg', '系统未开启重置密码功能,请联系管理员');
  311. return Redirect::back()->withInput();
  312. }
  313. // 查找账号
  314. $user = User::where('username', $username)->first();
  315. if (!$user) {
  316. $request->session()->flash('errorMsg', '账号不存在,请重试');
  317. return Redirect::back();
  318. }
  319. // 24小时内重设密码次数限制
  320. $resetTimes = 0;
  321. if (Cache::has('resetPassword_' . md5($username))) {
  322. $resetTimes = Cache::get('resetPassword_' . md5($username));
  323. if ($resetTimes >= self::$config['reset_password_times']) {
  324. $request->session()->flash('errorMsg', '同一个账号24小时内只能重设密码' . self::$config['reset_password_times'] . '次,请勿频繁操作');
  325. return Redirect::back();
  326. }
  327. }
  328. // 生成取回密码的地址
  329. $token = md5(self::$config['website_name'] . $username . microtime());
  330. $verify = new Verify();
  331. $verify->user_id = $user->id;
  332. $verify->username = $username;
  333. $verify->token = $token;
  334. $verify->status = 0;
  335. $verify->save();
  336. // 发送邮件
  337. $resetPasswordUrl = self::$config['website_url'] . '/reset/' . $token;
  338. Mail::to($user->username)->send(new resetPassword(self::$config['website_name'], $resetPasswordUrl));
  339. Cache::put('resetPassword_' . md5($username), $resetTimes + 1, 1440);
  340. $request->session()->flash('successMsg', '重置成功,请查看邮箱');
  341. return Redirect::back();
  342. } else {
  343. $view['is_reset_password'] = self::$config['is_reset_password'];
  344. return Response::view('user/resetPassword', $view);
  345. }
  346. }
  347. // 重设密码
  348. public function reset(Request $request, $token)
  349. {
  350. if ($request->method() == 'POST') {
  351. $password = trim($request->get('password'));
  352. $repassword = trim($request->get('repassword'));
  353. if (empty($token)) {
  354. return Redirect::to('login');
  355. } else if (empty($password) || empty($repassword)) {
  356. $request->session()->flash('errorMsg', '密码不能为空');
  357. return Redirect::back();
  358. } else if (md5($password) != md5($repassword)) {
  359. $request->session()->flash('errorMsg', '两次输入密码不一致,请重新输入');
  360. return Redirect::back();
  361. }
  362. // 校验账号
  363. $verify = Verify::where('token', $token)->with('User')->first();
  364. if (empty($verify)) {
  365. return Redirect::to('login');
  366. } else if ($verify->status == 1) {
  367. $request->session()->flash('errorMsg', '该链接已失效');
  368. return Redirect::back();
  369. } else if ($verify->user->status < 0) {
  370. $request->session()->flash('errorMsg', '账号已被禁用');
  371. return Redirect::back();
  372. } else if (md5($password) == $verify->user->password) {
  373. $request->session()->flash('errorMsg', '新旧密码一样,请重新输入');
  374. return Redirect::back();
  375. }
  376. // 更新密码
  377. $ret = User::where('id', $verify->user_id)->update(['password' => md5($password)]);
  378. if (!$ret) {
  379. $request->session()->flash('errorMsg', '重设密码失败');
  380. return Redirect::back();
  381. }
  382. // 置为已使用
  383. $verify->status = 1;
  384. $verify->save();
  385. $request->session()->flash('successMsg', '新密码设置成功,请自行登录');
  386. return Redirect::back();
  387. } else {
  388. if (empty($token)) {
  389. return Redirect::to('login');
  390. }
  391. $verify = Verify::where('token', $token)->with('user')->first();
  392. if (empty($verify)) {
  393. return Redirect::to('login');
  394. } else if (time() - strtotime($verify->created_at) >= 1800) {
  395. $request->session()->flash('errorMsg', '该链接已过期');
  396. // 置为已失效
  397. $verify->status = 2;
  398. $verify->save();
  399. return Response::view('user/reset');
  400. }
  401. $view['verify'] = $verify;
  402. return Response::view('user/reset', $view);
  403. }
  404. }
  405. }