UserController.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400
  1. <?php
  2. namespace App\Http\Controllers;
  3. use App\Http\Requests\User\DeleteUser;
  4. use App\Http\Requests\User\StoreProfile;
  5. use App\Http\Requests\User\StoreUser;
  6. use App\Models\Order;
  7. use App\Models\Permission;
  8. use App\Models\Reclamation;
  9. use App\Models\ReclamationStatus;
  10. use App\Models\Role;
  11. use App\Models\User;
  12. use App\Models\UserNotificationSetting;
  13. use App\Services\Access\AccessService;
  14. use Illuminate\Http\Request;
  15. use Illuminate\Support\Facades\Auth;
  16. use Illuminate\Support\Facades\DB;
  17. use Illuminate\Support\Facades\Hash;
  18. class UserController extends Controller
  19. {
  20. protected array $data = [
  21. 'active' => 'users',
  22. 'title' => 'Пользователи',
  23. 'id' => 'users',
  24. 'header' => [
  25. 'id' => 'ID',
  26. 'email' => 'Логин/email',
  27. 'name' => 'ФИО',
  28. 'phone' => 'Телефон',
  29. 'role' => 'Роль',
  30. 'app_installed' => 'Приложение',
  31. 'created_at' => 'Дата создания',
  32. 'deleted_at' => 'Дата Удаления',
  33. ],
  34. 'searchFields' => [
  35. 'name',
  36. 'phone',
  37. 'email',
  38. ],
  39. 'ranges' => [],
  40. 'filters' => [],
  41. ];
  42. /**
  43. * Display a listing of the resource.
  44. */
  45. public function index(Request $request)
  46. {
  47. session(['gp_users' => $request->query()]);
  48. $nav = $this->startNavigationContext($request);
  49. $model = new User;
  50. $this->createFilters($model, 'role');
  51. $this->createDateFilters($model, 'created_at');
  52. if (isset($this->data['filters']['role']['values'])) {
  53. foreach ($this->data['filters']['role']['values'] as $key => $value) {
  54. $this->data['filters']['role']['values'][$key] = \App\Models\Role::NAMES[$key] ?? $value;
  55. }
  56. }
  57. $q = $model::query();
  58. $this->acceptFilters($q, $request);
  59. $this->acceptSearch($q, $request);
  60. $this->setSortAndOrderBy($model, $request);
  61. // $q->withTrashed();
  62. $this->applyStableSorting($q);
  63. $this->data['users'] = $q->paginate($this->data['per_page'])->withQueryString();
  64. $this->data['nav'] = $nav;
  65. return view('users.index', $this->data);
  66. }
  67. /**
  68. * Show the form for creating a new resource.
  69. */
  70. public function create(Request $request)
  71. {
  72. $nav = $this->resolveNavToken($request);
  73. $this->rememberNavigation($request, $nav);
  74. $this->data['nav'] = $nav;
  75. $this->data['back_url'] = $this->navigationBackUrl(
  76. $request,
  77. $nav,
  78. route('user.index', session('gp_users', []))
  79. );
  80. $this->data['user'] = null;
  81. $this->prepareNotificationSettingsData(null);
  82. $this->preparePermissionSettingsData(null);
  83. return view('users.edit', $this->data);
  84. }
  85. /**
  86. * Store a newly or update existing created resource in storage.
  87. */
  88. public function store(StoreUser $request)
  89. {
  90. $validated = $request->validated();
  91. $settingsData = $this->extractNotificationSettings($request);
  92. $permissionEffects = $validated['permission_effects'] ?? [];
  93. unset($validated['notification_settings']);
  94. unset($validated['permission_effects']);
  95. if (!empty($validated['role_id'])) {
  96. $role = Role::query()->find($validated['role_id']);
  97. $validated['role'] = $role?->slug ?? $validated['role'] ?? Role::MANAGER;
  98. } elseif (!empty($validated['role'])) {
  99. $role = Role::query()->where('slug', $validated['role'])->first();
  100. $validated['role_id'] = $role?->id;
  101. }
  102. if(!empty($validated['password'])) {
  103. $validated['password'] = Hash::make($validated['password']);
  104. } else {
  105. unset($validated['password']);
  106. }
  107. $user = null;
  108. DB::transaction(function () use ($validated, $settingsData, $permissionEffects, &$user) {
  109. if(isset($validated['id'])) {
  110. User::query()
  111. ->where('id', $validated['id'])
  112. ->update($validated);
  113. $user = User::query()->find($validated['id']);
  114. } else {
  115. $user = User::query()->create($validated);
  116. }
  117. if ($user) {
  118. UserNotificationSetting::query()->updateOrCreate(
  119. ['user_id' => $user->id],
  120. $settingsData,
  121. );
  122. $this->syncUserPermissionOverrides($user, $permissionEffects);
  123. }
  124. });
  125. app(AccessService::class)->bumpCacheVersion();
  126. return redirect()->route('user.index')->with(['success' => 'Пользователь ' . $validated['name'] . ' сохранён!']);
  127. }
  128. /**
  129. * Display the specified resource.
  130. */
  131. public function show(Request $request, int $userId)
  132. {
  133. $nav = $this->resolveNavToken($request);
  134. $this->rememberNavigation($request, $nav);
  135. $this->data['nav'] = $nav;
  136. $this->data['back_url'] = $this->navigationBackUrl(
  137. $request,
  138. $nav,
  139. route('user.index', session('gp_users', []))
  140. );
  141. $this->data['user'] = User::query()
  142. ->where('id', $userId)
  143. ->withTrashed()
  144. ->first();
  145. $this->prepareNotificationSettingsData($this->data['user']);
  146. $this->preparePermissionSettingsData($this->data['user']);
  147. return view('users.edit', $this->data);
  148. }
  149. /**
  150. * Remove the specified resource from storage.
  151. */
  152. public function destroy(User $user, DeleteUser $request)
  153. {
  154. if($user->is($request->user())) {
  155. return redirect()->route('user.index')->with(['danger' => 'Нельзя удалить самого себя!']);
  156. } else {
  157. $user->delete();
  158. return redirect()->route('user.index')->with(['success' => 'Пользователь ' . $user->name . ' удалён!']);
  159. }
  160. }
  161. public function profile(Request $request)
  162. {
  163. $this->data['current_menu'] = 'profile';
  164. $this->data['user'] = $request->user();
  165. return view('users.profile', $this->data);
  166. }
  167. public function storeProfile(StoreProfile $request)
  168. {
  169. $data = $request->validated();
  170. unset($data['current_password'], $data['password']);
  171. if(
  172. isset($request->current_password)
  173. && isset($request->password)
  174. && (Hash::check($request->current_password, $request->user()->password))) {
  175. $data['password'] = Hash::make($request->password);
  176. }
  177. User::query()->where('id', '=', $request->user()->id)->update($data);
  178. return redirect()->route('user.profile')->with(['success' => 'Профиль обновлён!']);
  179. }
  180. public function deleteProfile(Request $request)
  181. {
  182. User::query()->where('id', '=', $request->user()->id)->delete();
  183. User::clearFcmToken((int)$request->user()->id);
  184. Auth::logout();
  185. return redirect()->route('login')->with(['success' => 'Профиль удалён!']);
  186. }
  187. public function undelete(int $userId)
  188. {
  189. User::query()->where('id', '=', $userId)->restore();
  190. return redirect()->route('user.show', $userId)->with(['success' => 'Пользователь восстановлен!']);
  191. }
  192. public function impersonate(Request $request, User $user)
  193. {
  194. $currentUser = $request->user();
  195. if ($currentUser->id === $user->id) {
  196. return redirect()->back()->with(['danger' => 'Нельзя войти от имени самого себя!']);
  197. }
  198. if ($user->trashed()) {
  199. return redirect()->back()->with(['danger' => 'Нельзя войти от имени удалённого пользователя!']);
  200. }
  201. if (session()->has('impersonator_id')) {
  202. return redirect()->back()->with(['danger' => 'Вы уже вошли от имени другого пользователя.']);
  203. }
  204. $impersonatorId = $currentUser->id;
  205. Auth::login($user);
  206. $request->session()->put('impersonator_id', $impersonatorId);
  207. $request->session()->regenerate();
  208. return redirect()->route('home')->with(['success' => 'Вы вошли от имени пользователя ' . $user->name . '.']);
  209. }
  210. public function leaveImpersonation(Request $request)
  211. {
  212. $impersonatorId = (int) session('impersonator_id');
  213. if (!$impersonatorId) {
  214. return redirect()->back()->with(['danger' => 'Режим impersonate не активен.']);
  215. }
  216. $impersonator = User::query()->find($impersonatorId);
  217. if (!$impersonator) {
  218. if ($request->user()) {
  219. User::clearFcmToken((int)$request->user()->id);
  220. }
  221. Auth::logout();
  222. $request->session()->invalidate();
  223. $request->session()->regenerateToken();
  224. return redirect()->route('login')->with(['danger' => 'Не удалось вернуться к исходному пользователю.']);
  225. }
  226. Auth::login($impersonator);
  227. $request->session()->forget('impersonator_id');
  228. $request->session()->regenerate();
  229. return redirect()->route('user.index')->with(['success' => 'Вы вернулись в аккаунт администратора.']);
  230. }
  231. private function prepareNotificationSettingsData(?User $user): void
  232. {
  233. $this->data['orderStatusOptions'] = Order::STATUS_NAMES;
  234. $this->data['orderStatusColors'] = Order::STATUS_COLOR;
  235. $this->data['reclamationStatusOptions'] = Reclamation::STATUS_NAMES;
  236. $this->data['reclamationStatusColors'] = ReclamationStatus::STATUS_COLOR;
  237. $this->data['scheduleSourceOptions'] = ['platform' => 'Площадки', 'reclamation' => 'Рекламации'];
  238. $this->data['chatSourceOptions'] = ['platform' => 'Площадки', 'reclamation' => 'Рекламации'];
  239. $this->data['notificationChannels'] = ['browser' => 'Браузер', 'push' => 'Push', 'email' => 'Email'];
  240. $this->data['disabledChannels'] = [
  241. 'browser' => false,
  242. 'push' => !$user || !$user->token_fcm,
  243. 'email' => !$user || !$user->notification_email || !filter_var($user->notification_email, FILTER_VALIDATE_EMAIL),
  244. ];
  245. if (!$user) {
  246. $this->data['notificationSettings'] = UserNotificationSetting::defaultsForUser(0);
  247. return;
  248. }
  249. $settings = UserNotificationSetting::query()->firstOrCreate(
  250. ['user_id' => $user->id],
  251. UserNotificationSetting::defaultsForUser($user->id),
  252. );
  253. $this->data['notificationSettings'] = $settings->toArray();
  254. }
  255. private function preparePermissionSettingsData(?User $user): void
  256. {
  257. $this->data['roles'] = Role::query()
  258. ->where('is_active', true)
  259. ->orderBy('sort')
  260. ->orderBy('name')
  261. ->pluck('name', 'id')
  262. ->all();
  263. $this->data['permissionGroups'] = Permission::getGroupedForUi();
  264. $this->data['permissionEffects'] = [];
  265. $this->data['rolePermissionEffects'] = [];
  266. if (!$user) {
  267. return;
  268. }
  269. $this->data['permissionEffects'] = $user->permissions()
  270. ->pluck('user_permissions.effect', 'permissions.id')
  271. ->all();
  272. if ($user->roleModel) {
  273. $this->data['rolePermissionEffects'] = $user->roleModel
  274. ->permissions()
  275. ->pluck('role_permissions.effect', 'permissions.id')
  276. ->all();
  277. }
  278. }
  279. private function syncUserPermissionOverrides(User $user, array $effects): void
  280. {
  281. if ($user->resolvedRoleSlug() === Role::ADMIN) {
  282. $user->permissions()->detach();
  283. return;
  284. }
  285. $permissions = Permission::query()
  286. ->whereIn('id', array_filter(array_keys($effects), 'is_numeric'))
  287. ->get();
  288. $sync = [];
  289. foreach ($permissions as $permission) {
  290. $effect = $effects[$permission->id] ?? null;
  291. if (in_array($effect, ['allow', 'deny'], true)) {
  292. $sync[$permission->id] = ['effect' => $effect];
  293. }
  294. }
  295. $user->permissions()->sync($sync);
  296. }
  297. private function extractNotificationSettings(Request $request): array
  298. {
  299. $input = $request->input('notification_settings', []);
  300. $settings = [
  301. 'order_settings' => [],
  302. 'reclamation_settings' => [],
  303. 'schedule_settings' => [],
  304. 'chat_settings' => [],
  305. ];
  306. $orderStatuses = array_keys(Order::STATUS_NAMES);
  307. $reclamationStatuses = array_keys(Reclamation::STATUS_NAMES);
  308. $scheduleSources = ['platform', 'reclamation'];
  309. $chatSources = ['platform', 'reclamation'];
  310. $channels = ['browser', 'push', 'email'];
  311. foreach ($orderStatuses as $statusId) {
  312. foreach ($channels as $channel) {
  313. $settings['order_settings'][$statusId][$channel] = isset($input['orders'][$statusId][$channel]);
  314. }
  315. }
  316. foreach ($reclamationStatuses as $statusId) {
  317. foreach ($channels as $channel) {
  318. $settings['reclamation_settings'][$statusId][$channel] = isset($input['reclamations'][$statusId][$channel]);
  319. }
  320. }
  321. foreach ($scheduleSources as $source) {
  322. foreach ($channels as $channel) {
  323. $settings['schedule_settings'][$source][$channel] = isset($input['schedule'][$source][$channel]);
  324. }
  325. }
  326. foreach ($chatSources as $source) {
  327. foreach ($channels as $channel) {
  328. $settings['chat_settings'][$source][$channel] = isset($input['chat'][$source][$channel]);
  329. }
  330. }
  331. return $settings;
  332. }
  333. }