This repository has been archived on 2024-06-26. You can view files and clone it, but cannot push or open issues or pull requests.
sakura/app/Controllers/Settings/AdvancedController.php

90 lines
2.6 KiB
PHP

<?php
/**
* Holds the advanced section controller.
* @package Sakura
*/
namespace Sakura\Controllers\Settings;
use Phroute\Phroute\Exception\HttpMethodNotAllowedException;
use Sakura\CurrentSession;
use Sakura\Session;
/**
* Advanced settings.
* @package Sakura
* @author Julian van de Groep <me@flash.moe>
*/
class AdvancedController extends Controller
{
/**
* Renders the session management page.
* @return string
*/
public function sessions(): string
{
$id = $_POST['id'] ?? null;
$all = isset($_POST['all']);
if (session_check() && ($id || $all)) {
$redirect = route('settings.advanced.sessions');
// End all sessions
if ($all) {
CurrentSession::$user->purgeSessions();
$message = "Deleted all active session associated with your account!";
return view('global/information', compact('message', 'redirect'));
}
// Create the session statement
$session = new Session($id);
// Check if the session exists
if ($session->id < 1 || $session->user !== CurrentSession::$user->id) {
$message = "This session doesn't exist!";
return view('global/information', compact('message', 'redirect'));
}
$session->delete();
return redirect($redirect);
}
$sessions = CurrentSession::$user->sessions();
$active = CurrentSession::$session->id;
return view('settings/advanced/sessions', compact('sessions', 'active'));
}
/**
* Renders the deactivation page.
* @return string
*/
public function deactivate(): string
{
if (!CurrentSession::$user->perms->deactivateAccount) {
throw new HttpMethodNotAllowedException;
}
$password = $_POST['password'] ?? null;
if (session_check()) {
if (!$password || strlen($password) < 1 || !CurrentSession::$user->verifyPassword($password)) {
return $this->json(['error' => 'Incorrect password!']);
}
// Deactivate account
DB::table('users')
->where('user_id', CurrentSession::$user->id)
->update(['user_activated' => 0]);
// Destroy all active sessions
CurrentSession::$user->purgeSessions();
// should probably not use the error var for the farewell msg but w/e
return $this->json(['error' => 'Farewell!', 'go' => route('main.index')]);
}
return view('settings/advanced/deactivate');
}
}