PasswordController.php 4.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143
  1. <?php
  2. declare(strict_types=1);
  3. namespace App\Controllers;
  4. use App\Models\Config;
  5. use App\Models\User;
  6. use App\Services\Cache;
  7. use App\Services\Captcha;
  8. use App\Services\Password;
  9. use App\Services\RateLimit;
  10. use App\Utils\Hash;
  11. use App\Utils\ResponseHelper;
  12. use Exception;
  13. use Psr\Http\Client\ClientExceptionInterface;
  14. use Psr\Http\Message\ResponseInterface;
  15. use RedisException;
  16. use Slim\Http\Response;
  17. use Slim\Http\ServerRequest;
  18. use function strlen;
  19. final class PasswordController extends BaseController
  20. {
  21. /**
  22. * @throws Exception
  23. */
  24. public function reset(ServerRequest $request, Response $response, array $args): ResponseInterface
  25. {
  26. $captcha = [];
  27. if (Config::obtain('enable_reset_password_captcha')) {
  28. $captcha = Captcha::generate();
  29. }
  30. return $response->write(
  31. $this->view()
  32. ->assign('captcha', $captcha)
  33. ->fetch('password/reset.tpl')
  34. );
  35. }
  36. public function handleReset(ServerRequest $request, Response $response, array $args): ResponseInterface
  37. {
  38. if (Config::obtain('enable_reset_password_captcha')) {
  39. $ret = Captcha::verify($request->getParams());
  40. if (! $ret) {
  41. return ResponseHelper::error($response, '系统无法接受你的验证结果,请刷新页面后重试');
  42. }
  43. }
  44. $email = strtolower($this->antiXss->xss_clean($request->getParam('email')));
  45. if ($email === '') {
  46. return ResponseHelper::error($response, '未填写邮箱');
  47. }
  48. if (! (new RateLimit())->checkRateLimit('email_request_ip', $request->getServerParam('REMOTE_ADDR')) ||
  49. ! (new RateLimit())->checkRateLimit('email_request_address', $email)
  50. ) {
  51. return ResponseHelper::error($response, '你的请求过于频繁,请稍后再试');
  52. }
  53. $user = (new User())->where('email', $email)->first();
  54. $msg = '如果你的账户存在于我们的数据库中,那么重置密码的链接将会发送到你账户所对应的邮箱';
  55. if ($user !== null) {
  56. try {
  57. Password::sendResetEmail($email);
  58. } catch (ClientExceptionInterface|RedisException) {
  59. $msg = '邮件发送失败';
  60. }
  61. }
  62. return ResponseHelper::success($response, $msg);
  63. }
  64. /**
  65. * @throws Exception
  66. */
  67. public function token(ServerRequest $request, Response $response, array $args)
  68. {
  69. $token = $this->antiXss->xss_clean($args['token']);
  70. $redis = (new Cache())->initRedis();
  71. $email = $redis->get('password_reset:' . $token);
  72. if (! $email) {
  73. return $response->withStatus(302)->withHeader('Location', '/password/reset');
  74. }
  75. return $response->write(
  76. $this->view()->fetch('password/token.tpl')
  77. );
  78. }
  79. /**
  80. * @throws RedisException
  81. */
  82. public function handleToken(ServerRequest $request, Response $response, array $args): ResponseInterface
  83. {
  84. $token = $this->antiXss->xss_clean($args['token']);
  85. $password = $request->getParam('password');
  86. $confirm_password = $request->getParam('confirm_password');
  87. if ($password !== $confirm_password) {
  88. return ResponseHelper::error($response, '两次输入不符合');
  89. }
  90. if (strlen($password) < 8) {
  91. return ResponseHelper::error($response, '密码过短');
  92. }
  93. $redis = (new Cache())->initRedis();
  94. $email = $redis->get('password_reset:' . $token);
  95. if (! $email) {
  96. return ResponseHelper::error($response, '链接无效');
  97. }
  98. $user = (new User())->where('email', $email)->first();
  99. if ($user === null) {
  100. return ResponseHelper::error($response, '链接无效');
  101. }
  102. // reset password
  103. $hashPassword = Hash::passwordHash($password);
  104. $user->pass = $hashPassword;
  105. if (! $user->save()) {
  106. return ResponseHelper::error($response, '重置失败,请重试');
  107. }
  108. if (Config::obtain('enable_forced_replacement')) {
  109. $user->removeLink();
  110. }
  111. $redis->del('password_reset:' . $token);
  112. return ResponseHelper::success($response, '重置成功');
  113. }
  114. }