feat: delete
This commit is contained in:
@@ -4,11 +4,19 @@ namespace App\Http\Controllers\Agent;
|
||||
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Models\User;
|
||||
use Illuminate\Http\JsonResponse;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Support\Facades\Auth;
|
||||
use Illuminate\Support\Facades\RateLimiter;
|
||||
use Illuminate\Support\Str;
|
||||
use Illuminate\Validation\ValidationException;
|
||||
|
||||
class AuthController extends Controller
|
||||
{
|
||||
private const MAX_ATTEMPTS = 5;
|
||||
|
||||
private const DECAY_SECONDS = 60;
|
||||
|
||||
public function showLogin()
|
||||
{
|
||||
if (Auth::guard('agent')->check()) {
|
||||
@@ -23,29 +31,58 @@ class AuthController extends Controller
|
||||
return view('user.shell');
|
||||
}
|
||||
|
||||
public function login(Request $request)
|
||||
public function login(Request $request): JsonResponse
|
||||
{
|
||||
$credentials = $request->validate([
|
||||
'username' => 'required|string',
|
||||
'password' => 'required|string',
|
||||
]);
|
||||
try {
|
||||
$credentials = $request->validate([
|
||||
'username' => 'required|string|min:2|max:64',
|
||||
'password' => 'required|string|max:128',
|
||||
], [
|
||||
'username.required' => '请输入用户名',
|
||||
'password.required' => '请输入密码',
|
||||
]);
|
||||
} catch (ValidationException $e) {
|
||||
return response()->json([
|
||||
'code' => 1,
|
||||
'msg' => collect($e->errors())->flatten()->implode('<br>'),
|
||||
]);
|
||||
}
|
||||
|
||||
$throttleKey = $this->throttleKey($request);
|
||||
if (RateLimiter::tooManyAttempts($throttleKey, self::MAX_ATTEMPTS)) {
|
||||
$seconds = RateLimiter::availableIn($throttleKey);
|
||||
|
||||
return response()->json([
|
||||
'code' => 1,
|
||||
'msg' => '登陆失败次数过多,请'.$seconds.'秒后再重试',
|
||||
]);
|
||||
}
|
||||
|
||||
/** @var User|null $user */
|
||||
$user = User::query()->where('username', $credentials['username'])->first();
|
||||
if ($user && ! $user->isEnabled()) {
|
||||
return back()->withErrors(['username' => '账号已禁用'])->onlyInput('username');
|
||||
RateLimiter::hit($throttleKey, self::DECAY_SECONDS);
|
||||
|
||||
return response()->json(['code' => 1, 'msg' => '账号已禁用']);
|
||||
}
|
||||
|
||||
if (Auth::guard('agent')->attempt(
|
||||
if (! Auth::guard('agent')->attempt(
|
||||
['username' => $credentials['username'], 'password' => $credentials['password']],
|
||||
$request->boolean('remember')
|
||||
)) {
|
||||
$request->session()->regenerate();
|
||||
RateLimiter::hit($throttleKey, self::DECAY_SECONDS);
|
||||
|
||||
return redirect()->intended(route('user.home'));
|
||||
return response()->json(['code' => 1, 'msg' => '用户名或密码错误']);
|
||||
}
|
||||
|
||||
return back()->withErrors(['username' => '用户名或密码错误'])->onlyInput('username');
|
||||
RateLimiter::clear($throttleKey);
|
||||
$request->session()->regenerate();
|
||||
|
||||
return response()->json([
|
||||
'code' => 0,
|
||||
'msg' => '登录成功',
|
||||
'data' => route('user.home'),
|
||||
]);
|
||||
}
|
||||
|
||||
public function logout(Request $request)
|
||||
@@ -56,4 +93,9 @@ class AuthController extends Controller
|
||||
|
||||
return redirect()->route('user.login');
|
||||
}
|
||||
|
||||
private function throttleKey(Request $request): string
|
||||
{
|
||||
return Str::transliterate(Str::lower((string) $request->input('username')).'|'.$request->ip());
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user