<?php
namespace App\Controller;
use App\Entity\User;
use App\Form\RegistrationFormType;
use App\Repository\CurrencyRepository;
use App\Repository\ThemeRepository;
use App\Repository\UserRepository;
use App\Security\EmailVerifier;
use App\Service\MailerService;
use Doctrine\ORM\EntityManagerInterface;
use Symfony\Bridge\Twig\Mime\TemplatedEmail;
use Symfony\Bundle\FrameworkBundle\Controller\AbstractController;
use Symfony\Component\HttpFoundation\Request;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\Mime\Address;
use Symfony\Component\PasswordHasher\Hasher\UserPasswordHasherInterface;
use Symfony\Component\Routing\Annotation\Route;
use Symfony\Contracts\Translation\TranslatorInterface;
use SymfonyCasts\Bundle\VerifyEmail\Exception\VerifyEmailExceptionInterface;
class RegistrationController extends AbstractController
{
public const PREVENTED_PASSWORDS = ['1234', 'Qwert', 'qwert', '2345', '3456', '4567', '5678', '6789', '7890', '0987', '9876', '8765', '7654', '6543', '5432', '4321', '3210', '1111', '2222', '3333', '4444', '5555', '6666',
'7777', '8888', '9999', '0000', 'password', 'Password', '123123', '98765', 'uiop', 'mynoob', '123321', '18atcskd2v', '1g2w3e4r', '3ris1la7ge', 'google', 'Google', '1g2w3e', 'g2w3e4', '2w3e4r', 'w3e4r5', '123qwe', 'zxcvbnm', 'abc123', 'loveyou', 'Loveyou', 'LoveYou', 'Monkey', 'monkey', 'Dragon', 'dragon', 'master', 'Master'];
public function __construct(private readonly EmailVerifier $emailVerifier, private readonly MailerService $mailerService)
{
}
#[Route('/user/register', name: 'app_register')]
public function clientRegistration(Request $request, UserPasswordHasherInterface $userPasswordHasher, EntityManagerInterface $entityManager, ThemeRepository $themeRepository, CurrencyRepository $currencyRepository): Response
{
$preventedPasswords = array_merge(self::PREVENTED_PASSWORDS, range(1900, 2050));
if ($this->getUser()) {
return $this->redirectToRoute('home');
}
$logoUrl = $request->getScheme().'://'.$request->getHttpHost().$request->getBasePath().'/assets/img/Consort/Consort1-email.png';
$user = new User();
$form = $this->createForm(RegistrationFormType::class, $user);
$form->handleRequest($request);
// Prevent a list of passwords patterns
if ($form->isSubmitted() && $form->isValid()) {
foreach ($preventedPasswords as $pattern) {
if (str_contains($form->get('password')->getData(), $pattern)) {
$this->addFlash(
'password_error', 'Your password contains unsecure characteristics (dates, patterns, or popular phrases), please choose another password.'
);
return $this->render('registration/register.html.twig', [
'registrationForm' => $form->createView(),
]);
}
}
// encode the plain password
$user->setPassword(
$userPasswordHasher->hashPassword(
$user,
$form->get('password')->getData()
)
);
$user->setRoles(['ROLE_TRADER']);
$defaultTheme = $themeRepository->findOneBy(['name' => 'Night Trader']);
$defaultCurrency = $currencyRepository->findOneBy(['value' => 'GBP']);
$user->setAssociatedTheme($defaultTheme);
$user->setSelectedCurrency($defaultCurrency);
$entityManager->persist($user);
$entityManager->flush();
// Send email notification to admin
$this->mailerService->sendRegistrationMailToAdmin('justin.clapham@consort1.com', 'New User Registration');
// generate a signed url and email it to the user
$this->emailVerifier->sendEmailConfirmation('app_verify_email', $user,
(new TemplatedEmail())
->from(new Address('trading@sdsrepo.io', 'Consort1 - SDSrepo.io'))
->to($user->getEmail())
->subject('Please Confirm your Email')
->htmlTemplate('registration/confirmation_email.html.twig')
->context([
'imgUrl' => $logoUrl,
])
);
// do anything else you need here, like send an email
return $this->redirectToRoute('app_verify_email_request', [
'userId' => $user->getId(),
]);
}
return $this->render('registration/register.html.twig', [
'registrationForm' => $form->createView(),
]);
}
#[Route('/counterparty/register', name: 'counterparty_register')]
public function counterpartyRegistration(Request $request, UserPasswordHasherInterface $userPasswordHasher, EntityManagerInterface $entityManager, ThemeRepository $themeRepository, CurrencyRepository $currencyRepository): Response
{
$preventedPasswords = array_merge(self::PREVENTED_PASSWORDS, range(1900, 2050));
if ($this->getUser()) {
return $this->redirectToRoute('counterparty_login');
}
$logoUrl = $request->getScheme().'://'.$request->getHttpHost().$request->getBasePath().'/assets/img/Consort/Consort1-email.png';
$user = new User();
$form = $this->createForm(RegistrationFormType::class, $user);
$form->handleRequest($request);
// Prevent a list of passwords patterns
if ($form->isSubmitted() && $form->isValid()) {
foreach ($preventedPasswords as $pattern) {
if (str_contains($form->get('password')->getData(), $pattern)) {
$this->addFlash(
'password_error', 'Your password contains unsecure characteristics (dates, patterns, or popular phrases), please choose another password.'
);
return $this->render('registration/register.html.twig', [
'registrationForm' => $form->createView(),
]);
}
}
// encode the plain password
$user->setPassword(
$userPasswordHasher->hashPassword(
$user,
$form->get('password')->getData()
)
);
$user->setRoles(['ROLE_COUNTERPARTY']);
$defaultTheme = $themeRepository->findOneBy(['name' => 'Night Trader']);
$defaultCurrency = $currencyRepository->findOneBy(['value' => 'GBP']);
$user->setAssociatedTheme($defaultTheme);
$user->setSelectedCurrency($defaultCurrency);
$entityManager->persist($user);
$entityManager->flush();
// Send email notification to admin
$this->mailerService->sendRegistrationMailToAdmin('justin.clapham@consort1.com', 'New Counterparty Registration');
// generate a signed url and email it to the user
$this->emailVerifier->sendEmailConfirmation('counterparty_verify_email', $user,
(new TemplatedEmail())
->from(new Address('trading@sdsrepo.io', 'Consort1 - SDSrepo.io'))
->to($user->getEmail())
->subject('Please Confirm your Email')
->htmlTemplate('registration/confirmation_email.html.twig')
->context([
'imgUrl' => $logoUrl,
])
);
// do anything else you need here, like send an email
return $this->redirectToRoute('counterparty_verify_email_request', [
'userId' => $user->getId(),
]);
}
return $this->render('registration/register.html.twig', [
'registrationForm' => $form->createView(),
]);
}
#[Route('/user/verify/email', name: 'app_verify_email')]
public function verifyUserEmail(Request $request, TranslatorInterface $translator, UserRepository $userRepository): Response
{
$id = $request->get('id');
if (null === $id) {
return $this->redirectToRoute('app_register');
}
$user = $userRepository->find($id);
if (null === $user) {
return $this->redirectToRoute('app_register');
}
// validate email confirmation link, sets User::isVerified=true and persists
try {
$this->emailVerifier->handleEmailConfirmation($request, $user);
} catch (VerifyEmailExceptionInterface $exception) {
$this->addFlash('verify_email_error', $translator->trans($exception->getReason(), [], 'VerifyEmailBundle'));
return $this->redirectToRoute('app_register');
}
// @TODO Change the redirect on success and handle or remove the flash message in your templates
$this->addFlash('success', 'Congratulations! Your email address has just been verified.');
return $this->redirectToRoute('app_login');
}
#[Route('/counterparty/verify/email', name: 'counterparty_verify_email')]
public function verifyCounterpartyEmail(Request $request, TranslatorInterface $translator, UserRepository $userRepository): Response
{
$id = $request->get('id');
if (null === $id) {
return $this->redirectToRoute('counterparty_register');
}
$user = $userRepository->find($id);
if (null === $user) {
return $this->redirectToRoute('counterparty_register');
}
// validate email confirmation link, sets User::isVerified=true and persists
try {
$this->emailVerifier->handleEmailConfirmation($request, $user);
} catch (VerifyEmailExceptionInterface $exception) {
$this->addFlash('verify_email_error', $translator->trans($exception->getReason(), [], 'VerifyEmailBundle'));
return $this->redirectToRoute('counterparty_register');
}
// @TODO Change the redirect on success and handle or remove the flash message in your templates
$this->addFlash('success', 'Congratulations! Your email address has just been verified.');
return $this->redirectToRoute('app_login');
}
#[Route('/user/verify/email/{userId}/request', name: 'app_verify_email_request')]
public function verifyUserEmailRequest(int $userId, UserRepository $userRepository): Response
{
return $this->render('email_verification/check_email.html.twig', [
'user_email' => $userRepository->find($userId)->getEmail(),
]);
}
#[Route('/counterparty/verify/email/{userId}/request', name: 'counterparty_verify_email_request')]
public function verifyCounterpartyEmailRequest(int $userId, UserRepository $userRepository): Response
{
return $this->render('email_verification/check_email.html.twig', [
'user_email' => $userRepository->find($userId)->getEmail(),
]);
}
}