admin
This commit is contained in:
@@ -22,7 +22,7 @@ class AdminUserController extends Controller
|
||||
$q->where('username', 'like', '%'.$username.'%');
|
||||
}
|
||||
|
||||
$sortable = ['id', 'username', 'is_super', 'created_at', 'updated_at'];
|
||||
$sortable = ['id', 'username', 'is_super', 'status', 'created_at', 'updated_at'];
|
||||
$field = (string) $request->query('field', 'id');
|
||||
$order = strtolower((string) $request->query('order', 'desc')) === 'asc' ? 'asc' : 'desc';
|
||||
if (! in_array($field, $sortable, true)) {
|
||||
@@ -40,6 +40,9 @@ class AdminUserController extends Controller
|
||||
'id' => $a->id,
|
||||
'username' => $a->username,
|
||||
'is_super' => (int) $a->is_super,
|
||||
'status' => (int) $a->status,
|
||||
'google_auth_open' => (int) $a->google_auth_open,
|
||||
'last_ip' => $a->last_ip,
|
||||
'created_at' => optional($a->created_at)->format('Y-m-d H:i:s'),
|
||||
'updated_at' => optional($a->updated_at)->format('Y-m-d H:i:s'),
|
||||
'is_self' => $a->id === $selfId,
|
||||
@@ -60,12 +63,14 @@ class AdminUserController extends Controller
|
||||
'username' => ['required', 'string', 'max:64', 'alpha_dash', Rule::unique('admins', 'username')],
|
||||
'password' => ['required', 'string', 'min:6', 'max:128'],
|
||||
'is_super' => ['nullable', 'integer', Rule::in([0, 1])],
|
||||
'status' => ['nullable', 'integer', Rule::in([0, 1])],
|
||||
]);
|
||||
|
||||
$admin = Admin::query()->create([
|
||||
'username' => $data['username'],
|
||||
'password' => $data['password'],
|
||||
'is_super' => (int) ($data['is_super'] ?? 0),
|
||||
'status' => (int) ($data['status'] ?? 1),
|
||||
]);
|
||||
|
||||
return response()->json(['code' => 0, 'msg' => 'ok', 'data' => ['id' => $admin->id]]);
|
||||
@@ -76,6 +81,7 @@ class AdminUserController extends Controller
|
||||
$data = $request->validate([
|
||||
'password' => ['nullable', 'string', 'min:6', 'max:128'],
|
||||
'is_super' => ['nullable', 'integer', Rule::in([0, 1])],
|
||||
'status' => ['nullable', 'integer', Rule::in([0, 1])],
|
||||
]);
|
||||
|
||||
if (array_key_exists('is_super', $data) && $data['is_super'] !== null) {
|
||||
@@ -86,6 +92,13 @@ class AdminUserController extends Controller
|
||||
$adminUser->is_super = $newSuper;
|
||||
}
|
||||
|
||||
if (array_key_exists('status', $data) && $data['status'] !== null) {
|
||||
if ((int) $adminUser->id === (int) auth('admin')->id() && (int) $data['status'] === 0) {
|
||||
return response()->json(['code' => 1, 'msg' => '不能禁用当前登录账号'], 422);
|
||||
}
|
||||
$adminUser->status = (int) $data['status'];
|
||||
}
|
||||
|
||||
if (! empty($data['password'])) {
|
||||
$adminUser->password = $data['password'];
|
||||
}
|
||||
|
||||
@@ -3,11 +3,21 @@
|
||||
namespace App\Http\Controllers\Admin;
|
||||
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Models\Admin;
|
||||
use App\Services\AdminGoogle2fa;
|
||||
use Illuminate\Http\JsonResponse;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Support\Facades\Auth;
|
||||
use Illuminate\Support\Facades\RateLimiter;
|
||||
use Illuminate\Support\Str;
|
||||
use Illuminate\Validation\ValidationException;
|
||||
|
||||
class AuthController extends Controller
|
||||
{
|
||||
private const MAX_ATTEMPTS = 5;
|
||||
|
||||
private const DECAY_SECONDS = 60;
|
||||
|
||||
public function showLogin()
|
||||
{
|
||||
if (Auth::guard('admin')->check()) {
|
||||
@@ -22,23 +32,78 @@ class AuthController extends Controller
|
||||
return view('admin.shell');
|
||||
}
|
||||
|
||||
public function login(Request $request)
|
||||
public function login(Request $request, AdminGoogle2fa $google2fa): JsonResponse
|
||||
{
|
||||
$credentials = $request->validate([
|
||||
'username' => 'required|string',
|
||||
'password' => 'required|string',
|
||||
]);
|
||||
|
||||
if (Auth::guard('admin')->attempt(
|
||||
['username' => $credentials['username'], 'password' => $credentials['password']],
|
||||
$request->boolean('remember')
|
||||
)) {
|
||||
$request->session()->regenerate();
|
||||
|
||||
return redirect()->intended(route('admin.home'));
|
||||
try {
|
||||
$credentials = $request->validate([
|
||||
'username' => 'required|string|min:2|max:64',
|
||||
'password' => 'required|string|min:6|max:128',
|
||||
'GACode' => 'nullable|string|max:16',
|
||||
], [
|
||||
'username.required' => '请输入用户名',
|
||||
'password.required' => '请输入密码',
|
||||
]);
|
||||
} catch (ValidationException $e) {
|
||||
return response()->json([
|
||||
'code' => 1,
|
||||
'msg' => collect($e->errors())->flatten()->implode('<br>'),
|
||||
]);
|
||||
}
|
||||
|
||||
return back()->withErrors(['username' => '用户名或密码错误'])->onlyInput('username');
|
||||
$throttleKey = $this->throttleKey($request);
|
||||
if (RateLimiter::tooManyAttempts($throttleKey, self::MAX_ATTEMPTS)) {
|
||||
$seconds = RateLimiter::availableIn($throttleKey);
|
||||
|
||||
return response()->json([
|
||||
'code' => 1,
|
||||
'msg' => '登陆失败次数过多,请'.$seconds.'秒后再重试',
|
||||
]);
|
||||
}
|
||||
|
||||
if (! Auth::guard('admin')->attempt(
|
||||
['username' => $credentials['username'], 'password' => $credentials['password']],
|
||||
false
|
||||
)) {
|
||||
RateLimiter::hit($throttleKey, self::DECAY_SECONDS);
|
||||
|
||||
return response()->json(['code' => 1, 'msg' => '用户名或密码错误']);
|
||||
}
|
||||
|
||||
/** @var Admin $user */
|
||||
$user = Auth::guard('admin')->user();
|
||||
|
||||
if ((int) $user->status !== 1) {
|
||||
Auth::guard('admin')->logout();
|
||||
RateLimiter::hit($throttleKey, self::DECAY_SECONDS);
|
||||
|
||||
return response()->json(['code' => 1, 'msg' => '用户已被禁用']);
|
||||
}
|
||||
|
||||
if ((int) $user->google_auth_open === 1) {
|
||||
$code = (string) ($credentials['GACode'] ?? '');
|
||||
if ($code === '') {
|
||||
Auth::guard('admin')->logout();
|
||||
|
||||
return response()->json(['code' => 1, 'msg' => '请输入谷歌验证码!']);
|
||||
}
|
||||
if (! $google2fa->verify((string) $user->google_secret, $code)) {
|
||||
Auth::guard('admin')->logout();
|
||||
RateLimiter::hit($throttleKey, self::DECAY_SECONDS);
|
||||
|
||||
return response()->json(['code' => 1, 'msg' => '谷歌验证码不正确!']);
|
||||
}
|
||||
}
|
||||
|
||||
RateLimiter::clear($throttleKey);
|
||||
$request->session()->regenerate();
|
||||
|
||||
$user->forceFill(['last_ip' => $request->ip()])->save();
|
||||
|
||||
return response()->json([
|
||||
'code' => 0,
|
||||
'msg' => '登录成功',
|
||||
'data' => route('admin.home'),
|
||||
]);
|
||||
}
|
||||
|
||||
public function logout(Request $request)
|
||||
@@ -49,4 +114,9 @@ class AuthController extends Controller
|
||||
|
||||
return redirect()->route('admin.login');
|
||||
}
|
||||
|
||||
private function throttleKey(Request $request): string
|
||||
{
|
||||
return Str::transliterate(Str::lower((string) $request->input('username')).'|'.$request->ip());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,155 @@
|
||||
<?php
|
||||
|
||||
namespace App\Http\Controllers\Admin;
|
||||
|
||||
use App\Http\Controllers\Controller;
|
||||
use App\Models\Admin;
|
||||
use App\Services\AdminGoogle2fa;
|
||||
use Illuminate\Http\JsonResponse;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Support\Facades\Hash;
|
||||
|
||||
class Google2faController extends Controller
|
||||
{
|
||||
public function index()
|
||||
{
|
||||
/** @var Admin $admin */
|
||||
$admin = auth('admin')->user();
|
||||
|
||||
return view('admin.security.google2fa', [
|
||||
'enabled' => (int) $admin->google_auth_open === 1,
|
||||
'bound' => filled($admin->google_secret),
|
||||
]);
|
||||
}
|
||||
|
||||
public function prepare(Request $request, AdminGoogle2fa $google2fa): JsonResponse
|
||||
{
|
||||
/** @var Admin $admin */
|
||||
$admin = auth('admin')->user();
|
||||
|
||||
$data = $request->validate([
|
||||
'password' => ['required', 'string'],
|
||||
], [
|
||||
'password.required' => '登陆密码不能为空',
|
||||
]);
|
||||
|
||||
if (! Hash::check($data['password'], $admin->password)) {
|
||||
return response()->json(['code' => 1, 'msg' => '登陆密码不正确']);
|
||||
}
|
||||
|
||||
if ((int) $admin->google_auth_open === 1 || filled($admin->google_secret)) {
|
||||
return response()->json(['code' => 201, 'msg' => '您已绑定谷歌验证,可直接开启或关闭']);
|
||||
}
|
||||
|
||||
$secret = $google2fa->generateSecret();
|
||||
$request->session()->put('admin_google2fa_pending_secret', $secret);
|
||||
|
||||
$otpAuthUrl = $google2fa->otpAuthUrl($admin, $secret);
|
||||
|
||||
return response()->json([
|
||||
'code' => 0,
|
||||
'msg' => 'ok',
|
||||
'secret' => $secret,
|
||||
'qr_svg' => $google2fa->qrSvg($otpAuthUrl),
|
||||
]);
|
||||
}
|
||||
|
||||
public function bind(Request $request, AdminGoogle2fa $google2fa): JsonResponse
|
||||
{
|
||||
/** @var Admin $admin */
|
||||
$admin = auth('admin')->user();
|
||||
|
||||
$data = $request->validate([
|
||||
'GAKey' => ['required', 'string', 'max:16'],
|
||||
'GASecret' => ['required', 'string', 'max:64'],
|
||||
], [
|
||||
'GAKey.required' => '请输入谷歌验证码',
|
||||
'GASecret.required' => '参数不完整',
|
||||
]);
|
||||
|
||||
$pending = (string) $request->session()->get('admin_google2fa_pending_secret', '');
|
||||
if ($pending === '' || ! hash_equals($pending, $data['GASecret'])) {
|
||||
return response()->json(['code' => 1, 'msg' => '绑定已过期,请重新获取二维码']);
|
||||
}
|
||||
|
||||
if (! $google2fa->verify($data['GASecret'], $data['GAKey'])) {
|
||||
return response()->json(['code' => 1, 'msg' => '绑定失败,验证码不正确']);
|
||||
}
|
||||
|
||||
$admin->forceFill([
|
||||
'google_auth_open' => 1,
|
||||
'google_secret' => $data['GASecret'],
|
||||
])->save();
|
||||
|
||||
$request->session()->forget('admin_google2fa_pending_secret');
|
||||
|
||||
return response()->json(['code' => 0, 'msg' => '绑定成功,下次登录将需要输入谷歌验证码']);
|
||||
}
|
||||
|
||||
public function toggle(Request $request, AdminGoogle2fa $google2fa): JsonResponse
|
||||
{
|
||||
/** @var Admin $admin */
|
||||
$admin = auth('admin')->user();
|
||||
|
||||
$data = $request->validate([
|
||||
'password' => ['required', 'string'],
|
||||
'open' => ['required', 'integer', 'in:0,1'],
|
||||
'GACode' => ['nullable', 'string', 'max:16'],
|
||||
]);
|
||||
|
||||
if (! Hash::check($data['password'], $admin->password)) {
|
||||
return response()->json(['code' => 1, 'msg' => '登陆密码不正确']);
|
||||
}
|
||||
|
||||
if (! filled($admin->google_secret)) {
|
||||
return response()->json(['code' => 1, 'msg' => '您未绑定谷歌验证']);
|
||||
}
|
||||
|
||||
$open = (int) $data['open'];
|
||||
if ($open === 0) {
|
||||
$code = (string) ($data['GACode'] ?? '');
|
||||
if (! $google2fa->verify((string) $admin->google_secret, $code)) {
|
||||
return response()->json(['code' => 1, 'msg' => '谷歌验证码不正确']);
|
||||
}
|
||||
}
|
||||
|
||||
$admin->forceFill(['google_auth_open' => $open])->save();
|
||||
|
||||
return response()->json([
|
||||
'code' => 0,
|
||||
'msg' => $open === 1 ? '已开启谷歌验证' : '已关闭谷歌验证',
|
||||
]);
|
||||
}
|
||||
|
||||
public function unbind(Request $request, AdminGoogle2fa $google2fa): JsonResponse
|
||||
{
|
||||
/** @var Admin $admin */
|
||||
$admin = auth('admin')->user();
|
||||
|
||||
$data = $request->validate([
|
||||
'password' => ['required', 'string'],
|
||||
'GACode' => ['required', 'string', 'max:16'],
|
||||
]);
|
||||
|
||||
if (! Hash::check($data['password'], $admin->password)) {
|
||||
return response()->json(['code' => 1, 'msg' => '登陆密码不正确']);
|
||||
}
|
||||
|
||||
if (! filled($admin->google_secret)) {
|
||||
return response()->json(['code' => 1, 'msg' => '您未绑定谷歌验证']);
|
||||
}
|
||||
|
||||
if (! $google2fa->verify((string) $admin->google_secret, $data['GACode'])) {
|
||||
return response()->json(['code' => 1, 'msg' => '谷歌验证码不正确']);
|
||||
}
|
||||
|
||||
$admin->forceFill([
|
||||
'google_auth_open' => 0,
|
||||
'google_secret' => null,
|
||||
])->save();
|
||||
|
||||
$request->session()->forget('admin_google2fa_pending_secret');
|
||||
|
||||
return response()->json(['code' => 0, 'msg' => '已解除谷歌验证绑定']);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user