|
3 | 3 | namespace App\Http\Controllers\Auth; |
4 | 4 |
|
5 | 5 | use App\Http\Controllers\Controller; |
| 6 | +use App\Models\User; |
6 | 7 | use Illuminate\Auth\Events\Verified; |
7 | | -use Illuminate\Foundation\Auth\EmailVerificationRequest; |
| 8 | +use Illuminate\Http\Request; |
8 | 9 | use Illuminate\Http\RedirectResponse; |
| 10 | +use Illuminate\Support\Facades\Auth; |
9 | 11 |
|
10 | 12 | class VerifyEmailController extends Controller |
11 | 13 | { |
12 | 14 | /** |
13 | 15 | * Mark the authenticated user's email address as verified. |
14 | 16 | */ |
15 | | - public function __invoke(EmailVerificationRequest $request): RedirectResponse |
| 17 | + public function __invoke(Request $request, int $id, string $hash): RedirectResponse |
16 | 18 | { |
17 | | - if ($request->user()->hasVerifiedEmail()) { |
18 | | - return redirect()->intended(route('dashboard', absolute: false).'?verified=1'); |
| 19 | + if (! $request->hasValidSignature()) { |
| 20 | + abort(403, 'Invalid or expired verification link.'); |
19 | 21 | } |
20 | | - |
21 | | - if ($request->user()->markEmailAsVerified()) { |
22 | | - /** @var \Illuminate\Contracts\Auth\MustVerifyEmail $user */ |
23 | | - $user = $request->user(); |
| 22 | + |
| 23 | + $user = User::findOrFail($id); |
| 24 | + |
| 25 | + if (! hash_equals($hash, sha1($user->getEmailForVerification()))) { |
| 26 | + abort(403, 'Invalid verification hash.'); |
| 27 | + } |
| 28 | + |
| 29 | + // Now you can verify the email |
| 30 | + if (! $user->hasVerifiedEmail()) { |
| 31 | + $user->markEmailAsVerified(); |
| 32 | + |
| 33 | + // Fire event when email is verified |
24 | 34 | event(new Verified($user)); |
25 | 35 | } |
| 36 | + |
| 37 | + // Always log the user in, regardless of verification status |
| 38 | + Auth::login($user); |
26 | 39 |
|
27 | 40 | return redirect()->intended(route('dashboard', absolute: false).'?verified=1'); |
28 | 41 | } |
|
0 commit comments