UserController.php 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288
  1. <?php
  2. /*
  3. * This file is part of Packagist.
  4. *
  5. * (c) Jordi Boggiano <j.boggiano@seld.be>
  6. * Nils Adermann <naderman@naderman.de>
  7. *
  8. * For the full copyright and license information, please view the LICENSE
  9. * file that was distributed with this source code.
  10. */
  11. namespace Packagist\WebBundle\Controller;
  12. use Doctrine\ORM\NoResultException;
  13. use FOS\UserBundle\Model\UserInterface;
  14. use Packagist\WebBundle\Entity\Job;
  15. use Packagist\WebBundle\Entity\Package;
  16. use Packagist\WebBundle\Entity\User;
  17. use Packagist\WebBundle\Model\RedisAdapter;
  18. use Pagerfanta\Adapter\DoctrineORMAdapter;
  19. use Pagerfanta\Pagerfanta;
  20. use Sensio\Bundle\FrameworkExtraBundle\Configuration\ParamConverter;
  21. use Sensio\Bundle\FrameworkExtraBundle\Configuration\Template;
  22. use Symfony\Component\HttpFoundation\Request;
  23. use Symfony\Component\HttpFoundation\Response;
  24. use Symfony\Component\HttpKernel\Exception\NotFoundHttpException;
  25. use Symfony\Component\Routing\Annotation\Route;
  26. use Symfony\Component\Security\Core\Exception\AccessDeniedException;
  27. /**
  28. * @author Jordi Boggiano <j.boggiano@seld.be>
  29. */
  30. class UserController extends Controller
  31. {
  32. /**
  33. * @Template()
  34. * @Route("/users/{name}/packages/", name="user_packages")
  35. * @ParamConverter("user", options={"mapping": {"name": "username"}})
  36. */
  37. public function packagesAction(Request $req, User $user)
  38. {
  39. $packages = $this->getUserPackages($req, $user);
  40. return array(
  41. 'packages' => $packages,
  42. 'meta' => $this->getPackagesMetadata($packages),
  43. 'user' => $user,
  44. );
  45. }
  46. /**
  47. * @Route("/trigger-github-sync/", name="user_github_sync")
  48. */
  49. public function triggerGitHubSyncAction(Request $req)
  50. {
  51. $user = $this->getUser();
  52. if (!$user) {
  53. throw new \AccessDeniedException();
  54. }
  55. if (!$user->getGithubToken()) {
  56. $this->get('session')->getFlashBag()->set('error', 'You must connect your user account to github to sync packages.');
  57. return $this->redirectToRoute('fos_user_profile_show');
  58. }
  59. if (!$user->getGithubScope()) {
  60. $this->get('session')->getFlashBag()->set('error', 'Please log out and log in with GitHub again to make sure the correct GitHub permissions are granted.');
  61. return $this->redirectToRoute('fos_user_profile_show');
  62. }
  63. $this->get('scheduler')->scheduleUserScopeMigration($user->getId(), '', $user->getGithubScope());
  64. sleep(5);
  65. $this->get('session')->getFlashBag()->set('success', 'User sync scheduled. It might take a few seconds to run through, make sure you refresh then to check if any packages still need sync.');
  66. return $this->redirectToRoute('fos_user_profile_show');
  67. }
  68. /**
  69. * @Route("/spammers/{name}/", name="mark_spammer", methods={"POST"})
  70. * @ParamConverter("user", options={"mapping": {"name": "username"}})
  71. */
  72. public function markSpammerAction(Request $req, User $user)
  73. {
  74. if (!$this->isGranted('ROLE_ANTISPAM')) {
  75. throw new AccessDeniedException('This user can not mark others as spammers');
  76. }
  77. $form = $this->createFormBuilder(array())->getForm();
  78. $form->submit($req->request->get('form'));
  79. if ($form->isValid()) {
  80. $user->addRole('ROLE_SPAMMER');
  81. $user->setEnabled(false);
  82. $this->get('fos_user.user_manager')->updateUser($user);
  83. $doctrine = $this->getDoctrine();
  84. $doctrine->getConnection()->executeUpdate(
  85. 'UPDATE package p JOIN maintainers_packages mp ON mp.package_id = p.id
  86. SET abandoned = 1, replacementPackage = "spam/spam", description = "", readme = "", indexedAt = NULL, dumpedAt = "2100-01-01 00:00:00"
  87. WHERE mp.user_id = :userId',
  88. ['userId' => $user->getId()]
  89. );
  90. /** @var VersionRepository $versionRepo */
  91. $versionRepo = $doctrine->getRepository('PackagistWebBundle:Version');
  92. $packages = $doctrine
  93. ->getRepository('PackagistWebBundle:Package')
  94. ->getFilteredQueryBuilder(array('maintainer' => $user->getId()), true)
  95. ->getQuery()->getResult();
  96. $providerManager = $this->get('packagist.provider_manager');
  97. foreach ($packages as $package) {
  98. foreach ($package->getVersions() as $version) {
  99. $versionRepo->remove($version);
  100. }
  101. $providerManager->deletePackage($package);
  102. }
  103. $this->getDoctrine()->getManager()->flush();
  104. $this->get('session')->getFlashBag()->set('success', $user->getUsername().' has been marked as a spammer');
  105. }
  106. return $this->redirect(
  107. $this->generateUrl("user_profile", array("name" => $user->getUsername()))
  108. );
  109. }
  110. /**
  111. * @param Request $req
  112. * @return Response
  113. */
  114. public function viewProfileAction(Request $req)
  115. {
  116. $user = $this->container->get('security.token_storage')->getToken()->getUser();
  117. if (!is_object($user) || !$user instanceof UserInterface) {
  118. throw new AccessDeniedException('This user does not have access to this section.');
  119. }
  120. $packages = $this->getUserPackages($req, $user);
  121. $lastGithubSync = $this->getDoctrine()->getRepository(Job::class)->getLastGitHubSyncJob($user->getId());
  122. return $this->container->get('templating')->renderResponse(
  123. 'FOSUserBundle:Profile:show.html.twig',
  124. array(
  125. 'packages' => $packages,
  126. 'meta' => $this->getPackagesMetadata($packages),
  127. 'user' => $user,
  128. 'githubSync' => $lastGithubSync,
  129. )
  130. );
  131. }
  132. /**
  133. * @Template()
  134. * @Route("/users/{name}/", name="user_profile")
  135. * @ParamConverter("user", options={"mapping": {"name": "username"}})
  136. */
  137. public function profileAction(Request $req, User $user)
  138. {
  139. $packages = $this->getUserPackages($req, $user);
  140. $data = array(
  141. 'packages' => $packages,
  142. 'meta' => $this->getPackagesMetadata($packages),
  143. 'user' => $user,
  144. );
  145. if ($this->isGranted('ROLE_ANTISPAM')) {
  146. $data['spammerForm'] = $this->createFormBuilder(array())->getForm()->createView();
  147. }
  148. return $data;
  149. }
  150. /**
  151. * @Route("/oauth/github/disconnect", name="user_github_disconnect")
  152. */
  153. public function disconnectGitHubAction(Request $req)
  154. {
  155. $user = $this->getUser();
  156. $token = $this->get('security.csrf.token_manager')->getToken('unlink_github')->getValue();
  157. if (!hash_equals($token, $req->query->get('token', '')) || !$user) {
  158. throw new AccessDeniedException('Invalid CSRF token');
  159. }
  160. if ($user->getGithubId()) {
  161. $user->setGithubId(null);
  162. $user->setGithubToken(null);
  163. $user->setGithubScope(null);
  164. $this->getDoctrine()->getEntityManager()->flush();
  165. }
  166. return $this->redirectToRoute('fos_user_profile_edit');
  167. }
  168. /**
  169. * @Template()
  170. * @Route("/users/{name}/favorites/", name="user_favorites", methods={"GET"})
  171. * @ParamConverter("user", options={"mapping": {"name": "username"}})
  172. */
  173. public function favoritesAction(Request $req, User $user)
  174. {
  175. try {
  176. if (!$this->get('snc_redis.default')->isConnected()) {
  177. $this->get('snc_redis.default')->connect();
  178. }
  179. } catch (\Exception $e) {
  180. $this->get('session')->getFlashBag()->set('error', 'Could not connect to the Redis database.');
  181. $this->get('logger')->notice($e->getMessage(), array('exception' => $e));
  182. return array('user' => $user, 'packages' => array());
  183. }
  184. $paginator = new Pagerfanta(
  185. new RedisAdapter($this->get('packagist.favorite_manager'), $user, 'getFavorites', 'getFavoriteCount')
  186. );
  187. $paginator->setMaxPerPage(15);
  188. $paginator->setCurrentPage($req->query->get('page', 1), false, true);
  189. return array('packages' => $paginator, 'user' => $user);
  190. }
  191. /**
  192. * @Route("/users/{name}/favorites/", name="user_add_fav", defaults={"_format" = "json"}, methods={"POST"})
  193. * @ParamConverter("user", options={"mapping": {"name": "username"}})
  194. */
  195. public function postFavoriteAction(Request $req, User $user)
  196. {
  197. if ($user->getId() !== $this->getUser()->getId()) {
  198. throw new AccessDeniedException('You can only change your own favorites');
  199. }
  200. $package = $req->request->get('package');
  201. try {
  202. $package = $this->getDoctrine()
  203. ->getRepository('PackagistWebBundle:Package')
  204. ->findOneByName($package);
  205. } catch (NoResultException $e) {
  206. throw new NotFoundHttpException('The given package "'.$package.'" was not found.');
  207. }
  208. $this->get('packagist.favorite_manager')->markFavorite($user, $package);
  209. return new Response('{"status": "success"}', 201);
  210. }
  211. /**
  212. * @Route("/users/{name}/favorites/{package}", name="user_remove_fav", defaults={"_format" = "json"}, requirements={"package"="[A-Za-z0-9_.-]+/[A-Za-z0-9_.-]+?"}, methods={"DELETE"})
  213. * @ParamConverter("user", options={"mapping": {"name": "username"}})
  214. * @ParamConverter("package", options={"mapping": {"package": "name"}})
  215. */
  216. public function deleteFavoriteAction(User $user, Package $package)
  217. {
  218. if ($user->getId() !== $this->getUser()->getId()) {
  219. throw new AccessDeniedException('You can only change your own favorites');
  220. }
  221. $this->get('packagist.favorite_manager')->removeFavorite($user, $package);
  222. return new Response('{"status": "success"}', 204);
  223. }
  224. /**
  225. * @param Request $req
  226. * @param User $user
  227. * @return Pagerfanta
  228. */
  229. protected function getUserPackages($req, $user)
  230. {
  231. $packages = $this->getDoctrine()
  232. ->getRepository('PackagistWebBundle:Package')
  233. ->getFilteredQueryBuilder(array('maintainer' => $user->getId()), true);
  234. $paginator = new Pagerfanta(new DoctrineORMAdapter($packages, true));
  235. $paginator->setMaxPerPage(15);
  236. $paginator->setCurrentPage($req->query->get('page', 1), false, true);
  237. return $paginator;
  238. }
  239. }