LoginController.php 6.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Http\Middleware\RedirectAuthenticatedPro;
  4. use App\Lib\Backend;
  5. use App\Models\Pro;
  6. use Illuminate\Http\Request;
  7. use Illuminate\Support\Facades\Cookie;
  8. use Exception;
  9. use Illuminate\Support\Facades\Http;
  10. class LoginController extends Controller
  11. {
  12. public function __construct()
  13. {
  14. $this->middleware('pro.auth.redirect')->except('logout');
  15. }
  16. public function showLoginForm(Request $request)
  17. {
  18. return view('app/login');
  19. }
  20. public function showRequestPasswordReset(Request $request)
  21. {
  22. return view('app/request_password_reset');
  23. }
  24. public function processRequestPasswordReset(Request $request)
  25. {
  26. try {
  27. $url = config('stag.backendUrl') . '/pro/requestPasswordReset';
  28. $data = [
  29. 'cellNumber' => $request->input('cellNumber'),
  30. ];
  31. $response = Http::asForm()
  32. ->post($url, $data)
  33. ->json();
  34. if(!isset($response['success']) || !$response['success']){
  35. $message = 'API error';
  36. if(isset($response['error'])) {
  37. $message = $response['error'];
  38. if(isset($response['path'])) $message .= ': ' . $response['path'];
  39. }
  40. else if(isset($response['message'])) $message = $response['message'];
  41. return redirect('/request_password_reset')
  42. ->withInput()
  43. ->with('message', $message);
  44. }
  45. // load pro and set security questions in the session
  46. $guestPro = Pro::where('cell_number', $request->input('cellNumber'))->first();
  47. $request->session()->put('sq1', $guestPro->security_question_1);
  48. $request->session()->put('sq2', $guestPro->security_question_2);
  49. return redirect('/self_reset_password');
  50. } catch (\Exception $e) {
  51. return redirect()->back()
  52. ->with('message', 'Unable to process your request at the moment. Please try again later.')
  53. ->withInput($request->input());
  54. }
  55. }
  56. public function showSelfResetPassword(Request $request)
  57. {
  58. return view('app/self_reset_password');
  59. }
  60. public function processSelfResetPassword(Request $request)
  61. {
  62. try {
  63. $url = config('stag.backendUrl') . '/pro/selfResetPassword';
  64. $data = [
  65. 'cellNumber' => $request->input('cellNumber'),
  66. 'passwordResetToken' => $request->input('passwordResetToken'),
  67. 'securityQuestionAnswer1' => $request->input('securityQuestionAnswer1'),
  68. 'securityQuestionAnswer2' => $request->input('securityQuestionAnswer2'),
  69. 'password' => $request->input('password'),
  70. 'passwordConfirmation' => $request->input('passwordConfirmation'),
  71. ];
  72. $response = Http::asForm()
  73. ->post($url, $data)
  74. ->json();
  75. if(!isset($response['success']) || !$response['success']){
  76. $message = 'API error';
  77. if(isset($response['error'])) {
  78. $message = $response['error'];
  79. if(isset($response['path'])) $message .= ': ' . $response['path'];
  80. }
  81. else if(isset($response['message'])) $message = $response['message'];
  82. return redirect('/self_reset_password')
  83. ->withInput()
  84. ->with('message', $message);
  85. }
  86. $request->session()->remove('sq1');
  87. $request->session()->remove('sq2');
  88. return redirect('/login');
  89. } catch (\Exception $e) {
  90. return redirect()->back()
  91. ->with('message', 'Unable to process your request at the moment. Please try again later.')
  92. ->withInput($request->input());
  93. }
  94. }
  95. public function login(Request $request)
  96. {
  97. $this->validate($request, [
  98. 'cell-number' => 'required',
  99. 'password' => 'required'
  100. ]);
  101. $api = new Backend();
  102. try {
  103. $apiResponse = $api->post('session/proLogInWithPassword', [
  104. 'cellNumber' => $request->post('cell-number'),
  105. 'password' => $request->post('password')
  106. ]);
  107. $data = json_decode($apiResponse->getContents());
  108. if (!property_exists($data, 'success') || !$data->success) {
  109. return back()->with('message', 'Invalid login credentials.')
  110. ->withInput($request->input());
  111. }
  112. Cookie::queue('sessionKey', $data->data->sessionKey);
  113. return redirect('/mc');
  114. } catch (\Exception $e) {
  115. return redirect()->back()
  116. ->with('message', 'Unable to process your request at the moment. Please try again later.')
  117. ->withInput($request->input());
  118. }
  119. }
  120. public function logout(Request $request)
  121. {
  122. $api = new Backend();
  123. try {
  124. //$apiResponse = $api->get('session/logOut?sessionKey=' . $request->cookie('sessionKey'));
  125. $apiResponse = $api->sendRequest(
  126. 'session/logOut',
  127. 'GET',
  128. [
  129. 'headers' => [
  130. 'sessionKey' => $request->cookie('sessionKey')
  131. ]
  132. ]
  133. );
  134. $data = json_decode($apiResponse->getContents());
  135. if (!property_exists($data, 'success') || !$data->success) {
  136. //TODO: throw message to log
  137. throw new Exception('Failed to log out of backend');
  138. }
  139. } catch (Exception $e) {
  140. // TODO: Log message
  141. // TODO: Never fail on logout. Just delete cookie.
  142. } finally {
  143. Cookie::queue(Cookie::forget('sessionKey'));
  144. }
  145. return redirect()->to(config('stag.authUrl'));
  146. }
  147. public function loginWithSessionKey($sessionKey, Request $request){
  148. $url = "/session/pro_log_in_with_session_key/${sessionKey}";
  149. $api = new Backend();
  150. try {
  151. $apiResponse = $api->post($url, []);
  152. $data = json_decode($apiResponse->getContents());
  153. if (!property_exists($data, 'success') || !$data->success) {
  154. return redirect('/mc');
  155. }
  156. Cookie::queue('sessionKey', $data->data->sessionKey);
  157. return redirect('/mc');
  158. } catch (\Exception $e) {
  159. return redirect('/mc');
  160. }
  161. }
  162. }