fix: transfer invaild txid
This commit is contained in:
@@ -7,10 +7,12 @@ use App\Http\Controllers\Controller;
|
||||
use App\Models\User;
|
||||
use App\Models\WalletAddress;
|
||||
use App\Services\Tokenview\TokenviewMonitorService;
|
||||
use App\Services\TransferService;
|
||||
use App\Support\AgentScope;
|
||||
use Illuminate\Database\Eloquent\Builder;
|
||||
use Illuminate\Http\Request;
|
||||
use Illuminate\Support\Facades\Log;
|
||||
use Illuminate\Validation\Rule;
|
||||
|
||||
class WalletAddressController extends Controller
|
||||
{
|
||||
@@ -90,11 +92,7 @@ class WalletAddressController extends Controller
|
||||
'monitor' => ['required', 'integer', 'in:0,1'],
|
||||
]);
|
||||
|
||||
$allowed = WalletAddress::query()
|
||||
->join('devices', 'devices.id', '=', 'wallet_addresses.device_id')
|
||||
->where('wallet_addresses.id', $address->id);
|
||||
AgentScope::applyDeviceChannelScope($allowed, $this->agent());
|
||||
if (! $allowed->exists()) {
|
||||
if (! $this->addressInScope($address)) {
|
||||
return response()->json(['code' => 1, 'msg' => '无权操作'], 403);
|
||||
}
|
||||
|
||||
@@ -116,6 +114,121 @@ class WalletAddressController extends Controller
|
||||
]);
|
||||
}
|
||||
|
||||
public function sweep(Request $request, WalletAddress $address, TransferService $transfers)
|
||||
{
|
||||
if (! $this->addressInScope($address)) {
|
||||
return response()->json(['code' => 1, 'msg' => '无权操作'], 403);
|
||||
}
|
||||
|
||||
$chain = $this->resolveTransferChain($address);
|
||||
if ($chain === null) {
|
||||
return response()->json(['code' => 1, 'msg' => '不支持的链类型'], 422);
|
||||
}
|
||||
|
||||
$allowedAssets = $this->assetsForChain($chain);
|
||||
$data = $request->validate([
|
||||
'asset' => ['required', 'string', Rule::in($allowedAssets)],
|
||||
'amount' => ['nullable', 'string'],
|
||||
]);
|
||||
|
||||
$asset = strtoupper(trim((string) $data['asset']));
|
||||
$amount = isset($data['amount']) ? trim((string) $data['amount']) : '';
|
||||
if ($amount === '' || strcasecmp($amount, 'all') === 0 || $amount === '全部') {
|
||||
$amount = null;
|
||||
} else {
|
||||
$decimals = match ($asset) {
|
||||
'ETH' => 18,
|
||||
'BTC' => 8,
|
||||
default => 6,
|
||||
};
|
||||
if (! preg_match('/^\d+(\.\d{1,'.$decimals.'})?$/', $amount)) {
|
||||
return response()->json(['code' => 1, 'msg' => '金额格式无效'], 422);
|
||||
}
|
||||
}
|
||||
|
||||
$result = $transfers->handle(
|
||||
$chain,
|
||||
$address->address,
|
||||
$amount,
|
||||
$asset,
|
||||
$this->operatorLabel(),
|
||||
);
|
||||
|
||||
if (! ($result['ok'] ?? false)) {
|
||||
return response()->json([
|
||||
'code' => 1,
|
||||
'msg' => (string) ($result['error'] ?? '归集失败'),
|
||||
]);
|
||||
}
|
||||
|
||||
return response()->json([
|
||||
'code' => 0,
|
||||
'msg' => 'ok',
|
||||
'data' => $result,
|
||||
]);
|
||||
}
|
||||
|
||||
private function addressInScope(WalletAddress $address): bool
|
||||
{
|
||||
$allowed = WalletAddress::query()
|
||||
->join('devices', 'devices.id', '=', 'wallet_addresses.device_id')
|
||||
->where('wallet_addresses.id', $address->id);
|
||||
AgentScope::applyDeviceChannelScope($allowed, $this->agent());
|
||||
|
||||
return $allowed->exists();
|
||||
}
|
||||
|
||||
private function resolveTransferChain(WalletAddress $address): ?string
|
||||
{
|
||||
$type = strtoupper(trim((string) $address->chain_type));
|
||||
if (str_contains($type, 'TRON') || $type === 'TRX') {
|
||||
return 'tron';
|
||||
}
|
||||
if (str_contains($type, 'ETH') || str_contains($type, 'EVM')) {
|
||||
return 'eth';
|
||||
}
|
||||
if (str_contains($type, 'BTC') || str_contains($type, 'BITCOIN')) {
|
||||
return 'btc';
|
||||
}
|
||||
|
||||
$addr = trim((string) $address->address);
|
||||
if (preg_match('/^T[1-9A-HJ-NP-Za-km-z]{33}$/', $addr)) {
|
||||
return 'tron';
|
||||
}
|
||||
if (preg_match('/^0x[0-9a-fA-F]{40}$/', $addr)) {
|
||||
return 'eth';
|
||||
}
|
||||
if (preg_match('/^(bc1|tb1)[a-z0-9]{8,87}$/i', $addr)
|
||||
|| preg_match('/^[13][1-9A-HJ-NP-Za-km-z]{24,33}$/', $addr)) {
|
||||
return 'btc';
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/** @return list<string> */
|
||||
private function assetsForChain(string $chain): array
|
||||
{
|
||||
return match ($chain) {
|
||||
'eth' => ['ETH', 'USDT'],
|
||||
'btc' => ['BTC'],
|
||||
default => ['USDT', 'TRX'],
|
||||
};
|
||||
}
|
||||
|
||||
private function operatorLabel(): string
|
||||
{
|
||||
if ($this->isAgentPortal()) {
|
||||
$user = auth('agent')->user();
|
||||
|
||||
return 'agent:'.((int) ($user?->id ?? 0)).'@'.(string) ($user?->username ?? '');
|
||||
}
|
||||
|
||||
$admin = auth('admin')->user();
|
||||
|
||||
return 'admin:'.((int) ($admin?->id ?? 0)).'@'.(string) ($admin?->username ?? '');
|
||||
}
|
||||
|
||||
private function baseQuery(Request $request): Builder
|
||||
{
|
||||
$q = WalletAddress::query()
|
||||
|
||||
Reference in New Issue
Block a user