|
|
|
|
@ -135,62 +135,4 @@ class LoginController extends Controller
|
|
|
|
|
$this->username() => [trans('auth.failed')],
|
|
|
|
|
]);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Handle a login request to the application.
|
|
|
|
|
*
|
|
|
|
|
* @return \Illuminate\Http\RedirectResponse|\Illuminate\Http\Response|\Illuminate\Http\JsonResponse
|
|
|
|
|
*
|
|
|
|
|
* @throws \Illuminate\Validation\ValidationException
|
|
|
|
|
*/
|
|
|
|
|
public function login(Request $request)
|
|
|
|
|
{
|
|
|
|
|
$this->validateLogin($request);
|
|
|
|
|
|
|
|
|
|
// If the class is using the ThrottlesLogins trait, we can automatically throttle
|
|
|
|
|
// the login attempts for this application. We'll key this by the username and
|
|
|
|
|
// the IP address of the client making these requests into this application.
|
|
|
|
|
if (method_exists($this, 'hasTooManyLoginAttempts') &&
|
|
|
|
|
$this->hasTooManyLoginAttempts($request)) {
|
|
|
|
|
$this->fireLockoutEvent($request);
|
|
|
|
|
|
|
|
|
|
return $this->sendLockoutResponse($request);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if ($this->attemptLogin($request)) {
|
|
|
|
|
$user = $this->guard()->user();
|
|
|
|
|
|
|
|
|
|
// Check for 2FA and email verification
|
|
|
|
|
if ($user->two_factor_enabled && ! $user->two_factor_verified) {
|
|
|
|
|
// Store necessary data in session
|
|
|
|
|
session(['login_credentials' => $request->only('email', 'password')]);
|
|
|
|
|
session(['two_factor_required' => true]);
|
|
|
|
|
|
|
|
|
|
// Redirect to 2FA verification
|
|
|
|
|
return redirect()->route('two_factor.verify');
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if (! $user->email_verified_at) {
|
|
|
|
|
$request->session()->invalidate();
|
|
|
|
|
session(['login_uid' => $user->id]);
|
|
|
|
|
session(['login_credentials' => $request->only('email', 'password')]);
|
|
|
|
|
session(['verify_email' => true]);
|
|
|
|
|
|
|
|
|
|
return redirect()->route('custom-auth:verify-email');
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if ($request->hasSession()) {
|
|
|
|
|
$request->session()->put('auth.password_confirmed_at', time());
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return $this->sendLoginResponse($request);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// If the login attempt was unsuccessful we will increment the number of attempts
|
|
|
|
|
// to login and redirect the user back to the login form. Of course, when this
|
|
|
|
|
// user surpasses their maximum number of attempts they will get locked out.
|
|
|
|
|
$this->incrementLoginAttempts($request);
|
|
|
|
|
|
|
|
|
|
return $this->sendFailedLoginResponse($request);
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|