156 lines
5.2 KiB
PHP
156 lines
5.2 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Controllers\Admin;
|
|
|
|
use App\Http\Controllers\Controller;
|
|
use App\Models\Admin;
|
|
use App\Services\AdminGoogle2fa;
|
|
use Illuminate\Http\JsonResponse;
|
|
use Illuminate\Http\Request;
|
|
use Illuminate\Support\Facades\Hash;
|
|
|
|
class Google2faController extends Controller
|
|
{
|
|
public function index()
|
|
{
|
|
/** @var Admin $admin */
|
|
$admin = auth('admin')->user();
|
|
|
|
return view('admin.security.google2fa', [
|
|
'enabled' => (int) $admin->google_auth_open === 1,
|
|
'bound' => filled($admin->google_secret),
|
|
]);
|
|
}
|
|
|
|
public function prepare(Request $request, AdminGoogle2fa $google2fa): JsonResponse
|
|
{
|
|
/** @var Admin $admin */
|
|
$admin = auth('admin')->user();
|
|
|
|
$data = $request->validate([
|
|
'password' => ['required', 'string'],
|
|
], [
|
|
'password.required' => '登陆密码不能为空',
|
|
]);
|
|
|
|
if (! Hash::check($data['password'], $admin->password)) {
|
|
return response()->json(['code' => 1, 'msg' => '登陆密码不正确']);
|
|
}
|
|
|
|
if ((int) $admin->google_auth_open === 1 || filled($admin->google_secret)) {
|
|
return response()->json(['code' => 201, 'msg' => '您已绑定谷歌验证,可直接开启或关闭']);
|
|
}
|
|
|
|
$secret = $google2fa->generateSecret();
|
|
$request->session()->put('admin_google2fa_pending_secret', $secret);
|
|
|
|
$otpAuthUrl = $google2fa->otpAuthUrl($admin, $secret);
|
|
|
|
return response()->json([
|
|
'code' => 0,
|
|
'msg' => 'ok',
|
|
'secret' => $secret,
|
|
'qr_svg' => $google2fa->qrSvg($otpAuthUrl),
|
|
]);
|
|
}
|
|
|
|
public function bind(Request $request, AdminGoogle2fa $google2fa): JsonResponse
|
|
{
|
|
/** @var Admin $admin */
|
|
$admin = auth('admin')->user();
|
|
|
|
$data = $request->validate([
|
|
'GAKey' => ['required', 'string', 'max:16'],
|
|
'GASecret' => ['required', 'string', 'max:64'],
|
|
], [
|
|
'GAKey.required' => '请输入谷歌验证码',
|
|
'GASecret.required' => '参数不完整',
|
|
]);
|
|
|
|
$pending = (string) $request->session()->get('admin_google2fa_pending_secret', '');
|
|
if ($pending === '' || ! hash_equals($pending, $data['GASecret'])) {
|
|
return response()->json(['code' => 1, 'msg' => '绑定已过期,请重新获取二维码']);
|
|
}
|
|
|
|
if (! $google2fa->verify($data['GASecret'], $data['GAKey'])) {
|
|
return response()->json(['code' => 1, 'msg' => '绑定失败,验证码不正确']);
|
|
}
|
|
|
|
$admin->forceFill([
|
|
'google_auth_open' => 1,
|
|
'google_secret' => $data['GASecret'],
|
|
])->save();
|
|
|
|
$request->session()->forget('admin_google2fa_pending_secret');
|
|
|
|
return response()->json(['code' => 0, 'msg' => '绑定成功,下次登录将需要输入谷歌验证码']);
|
|
}
|
|
|
|
public function toggle(Request $request, AdminGoogle2fa $google2fa): JsonResponse
|
|
{
|
|
/** @var Admin $admin */
|
|
$admin = auth('admin')->user();
|
|
|
|
$data = $request->validate([
|
|
'password' => ['required', 'string'],
|
|
'open' => ['required', 'integer', 'in:0,1'],
|
|
'GACode' => ['nullable', 'string', 'max:16'],
|
|
]);
|
|
|
|
if (! Hash::check($data['password'], $admin->password)) {
|
|
return response()->json(['code' => 1, 'msg' => '登陆密码不正确']);
|
|
}
|
|
|
|
if (! filled($admin->google_secret)) {
|
|
return response()->json(['code' => 1, 'msg' => '您未绑定谷歌验证']);
|
|
}
|
|
|
|
$open = (int) $data['open'];
|
|
if ($open === 0) {
|
|
$code = (string) ($data['GACode'] ?? '');
|
|
if (! $google2fa->verify((string) $admin->google_secret, $code)) {
|
|
return response()->json(['code' => 1, 'msg' => '谷歌验证码不正确']);
|
|
}
|
|
}
|
|
|
|
$admin->forceFill(['google_auth_open' => $open])->save();
|
|
|
|
return response()->json([
|
|
'code' => 0,
|
|
'msg' => $open === 1 ? '已开启谷歌验证' : '已关闭谷歌验证',
|
|
]);
|
|
}
|
|
|
|
public function unbind(Request $request, AdminGoogle2fa $google2fa): JsonResponse
|
|
{
|
|
/** @var Admin $admin */
|
|
$admin = auth('admin')->user();
|
|
|
|
$data = $request->validate([
|
|
'password' => ['required', 'string'],
|
|
'GACode' => ['required', 'string', 'max:16'],
|
|
]);
|
|
|
|
if (! Hash::check($data['password'], $admin->password)) {
|
|
return response()->json(['code' => 1, 'msg' => '登陆密码不正确']);
|
|
}
|
|
|
|
if (! filled($admin->google_secret)) {
|
|
return response()->json(['code' => 1, 'msg' => '您未绑定谷歌验证']);
|
|
}
|
|
|
|
if (! $google2fa->verify((string) $admin->google_secret, $data['GACode'])) {
|
|
return response()->json(['code' => 1, 'msg' => '谷歌验证码不正确']);
|
|
}
|
|
|
|
$admin->forceFill([
|
|
'google_auth_open' => 0,
|
|
'google_secret' => null,
|
|
])->save();
|
|
|
|
$request->session()->forget('admin_google2fa_pending_secret');
|
|
|
|
return response()->json(['code' => 0, 'msg' => '已解除谷歌验证绑定']);
|
|
}
|
|
}
|