This commit is contained in:
Mekan1206
2026-05-19 21:22:36 +05:00
parent b1a6c12a00
commit e66ce8fdcd
21 changed files with 677 additions and 150 deletions

View File

@@ -0,0 +1,10 @@
<?php
namespace App\Enums;
enum OtpVerificationResult
{
case Verified;
case Invalid;
case Expired;
}

View File

@@ -12,6 +12,7 @@ class CouponInfolist
return $schema
->components([
TextEntry::make('phone')
->formatStateUsing(fn (string $state): string => format_phone($state))
->copyable(),
TextEntry::make('code')
->copyable(),

View File

@@ -4,7 +4,6 @@ namespace App\Filament\Resources\Coupons\Tables;
use App\Filament\Tables\Filters\CreatedAtDateFilter;
use Filament\Actions\ViewAction;
use Filament\Actions\DeleteAction;
use Filament\Tables\Columns\TextColumn;
use Filament\Tables\Table;
@@ -18,6 +17,7 @@ class CouponsTable
TextColumn::make('id')
->sortable(),
TextColumn::make('phone')
->formatStateUsing(fn (string $state): string => format_phone($state))
->searchable()
->sortable()
->copyable(),
@@ -37,7 +37,6 @@ class CouponsTable
])
->recordActions([
ViewAction::make(),
DeleteAction::make(),
]);
}
}

View File

@@ -13,9 +13,7 @@ class PhoneVerificationInfolist
return $schema
->components([
TextEntry::make('phone')
->copyable(),
TextEntry::make('otp')
->label('OTP')
->formatStateUsing(fn (string $state): string => format_phone($state))
->copyable(),
TextEntry::make('expires_at')
->dateTime(),

View File

@@ -4,7 +4,6 @@ namespace App\Filament\Resources\PhoneVerifications\Tables;
use App\Filament\Tables\Filters\CreatedAtDateFilter;
use Filament\Actions\ViewAction;
use Filament\Actions\DeleteAction;
use Filament\Tables\Columns\IconColumn;
use Filament\Tables\Columns\TextColumn;
use Filament\Tables\Table;
@@ -19,12 +18,10 @@ class PhoneVerificationsTable
TextColumn::make('id')
->sortable(),
TextColumn::make('phone')
->formatStateUsing(fn (string $state): string => format_phone($state))
->searchable()
->sortable()
->copyable(),
TextColumn::make('otp')
->label('OTP')
->copyable(),
TextColumn::make('expires_at')
->dateTime()
->sortable(),
@@ -44,7 +41,6 @@ class PhoneVerificationsTable
])
->recordActions([
ViewAction::make(),
DeleteAction::make(),
]);
}
}

View File

@@ -1,6 +1,8 @@
<?php
use Illuminate\Http\Client\ConnectionException;
use Illuminate\Http\Client\PendingRequest;
use Illuminate\Http\Client\RequestException;
use Illuminate\Support\Facades\Http;
use Illuminate\Support\Facades\Log;
@@ -8,27 +10,49 @@ if (! function_exists('sendSMS')) {
/**
* Send a sms
*/
function sendSMS(string|int $phone, string|int $message): mixed
function sendSMS(string|int $phone, string|int $message): bool
{
$response = Http::retry(
times: 3,
sleepMilliseconds: 50,
throw: false,
when: function (Exception $exception, PendingRequest $request) {
Log::error('Exception: ', [
'message' => $exception->getMessage(),
'line' => $exception->getLine(),
]);
try {
$response = Http::timeout(config('services.sms.timeout'))
->connectTimeout(config('services.sms.connect_timeout'))
->retry(
times: 3,
sleepMilliseconds: 50,
throw: false,
when: function (Throwable $exception, PendingRequest $request): bool {
if ($exception instanceof ConnectionException) {
return true;
}
return true;
if ($exception instanceof RequestException) {
return $exception->response->serverError();
}
return false;
}
)
->post(config('services.sms.url'), [
'phone' => '+993'.$phone,
'code' => $message,
]);
if (! $response->successful()) {
Log::error('SMS API request failed', [
'status' => $response->status(),
'body' => $response->body(),
]);
return false;
}
)
->post('http://216.250.14.144:3000/api/data', [
'phone' => '+993' . $phone,
'code' => $message,
return true;
} catch (Throwable $exception) {
Log::error('SMS API exception', [
'message' => $exception->getMessage(),
]);
return $response->body();
return false;
}
}
}
@@ -38,19 +62,36 @@ if (! function_exists('unmask_phone')) {
*/
function unmask_phone(string $phone): string
{
// Keep digits only
$digits = preg_replace('/\D+/', '', $phone);
// Remove Turkmenistan country code if present
if (str_starts_with($digits, '993')) {
$digits = substr($digits, 3);
}
// Return only valid 8-digit TM mobile number
if (preg_match('/^6\d{7}$/', $digits)) {
return $digits;
}
return '';
}
}
}
if (! function_exists('format_phone')) {
/**
* Format an 8-digit TM mobile number for display (+993 6X XX XX XX).
*/
function format_phone(string $phone): string
{
if (! preg_match('/^6\d{7}$/', $phone)) {
return $phone;
}
return sprintf(
'+993 %s %s %s %s',
substr($phone, 0, 2),
substr($phone, 2, 2),
substr($phone, 4, 2),
substr($phone, 6, 2),
);
}
}

View File

@@ -2,75 +2,61 @@
namespace App\Http\Controllers;
use Illuminate\Http\Request;
use App\Models\PhoneVerification;
use App\Enums\OtpVerificationResult;
use App\Http\Requests\SendOtpRequest;
use App\Http\Requests\VerifyOtpRequest;
use App\Models\Coupon;
use Illuminate\Support\Str;
use Illuminate\Support\Facades\Log;
use App\Services\CouponService;
use App\Services\OtpService;
use Illuminate\Contracts\View\View;
use Illuminate\Http\RedirectResponse;
use Illuminate\Http\Request;
use Symfony\Component\HttpFoundation\Cookie;
class VerificationController extends Controller
{
public function index()
{
if (request()->cookie('device_registered')) {
return redirect()->route('verification.congratulations');
}
private const DEVICE_COOKIE_NAME = 'device_registered';
if (session()->has('coupon_code')) {
return redirect()->route('verification.congratulations');
public function __construct(
private OtpService $otpService,
private CouponService $couponService,
) {}
public function index(): View|RedirectResponse
{
if ($redirect = $this->redirectIfAlreadyRegistered()) {
return $redirect;
}
return view('verification.index');
}
public function sendOtp(Request $request)
public function sendOtp(SendOtpRequest $request): RedirectResponse
{
if ($request->cookie('device_registered')) {
if ($request->cookie(self::DEVICE_COOKIE_NAME)) {
return back()->withErrors(['phone' => 'Siz eýýäm agza bolduňyz.']);
}
$request->validate([
'phone' => ['required', 'regex:/^\+993 [67]\d \d{2} \d{2} \d{2}$/']
], [
'phone.regex' => 'Telefon belgiňiz şu formatda bolmaly: +993 KX XX XX XX (bu ýerde K 6 ýa-da 7).'
]);
$phone = unmask_phone($request->phone);
$phone = $request->unmaskedPhone();
$existingCoupon = Coupon::query()->where('phone', $phone)->first();
if ($existingCoupon) {
return back()->withErrors(['phone' => 'Bu telefon belgisi eýýäm ulanyldy.'])->withInput();
}
// Generate a 4-digit OTP
$otp = (string) rand(1000, 9999);
// Store in DB
PhoneVerification::updateOrCreate(
['phone' => $phone],
[
'otp' => $otp,
'expires_at' => now()->addMinutes(10),
'verified' => false
]
);
sendSMS($phone, 'Tassyklaýyş belgi: ' . $otp);
if (! $this->otpService->issue($phone)) {
return back()->withErrors(['phone' => 'SMS iberilmedi. Soňrak synanyşyň.'])->withInput();
}
// Store phone in session for the next step
session()->put('verify_phone', $phone);
return redirect()->route('verification.verify.form');
}
public function verifyForm()
public function verifyForm(): View|RedirectResponse
{
if (request()->cookie('device_registered')) {
return redirect()->route('verification.congratulations');
}
if (session()->has('coupon_code')) {
return redirect()->route('verification.congratulations');
if ($redirect = $this->redirectIfAlreadyRegistered()) {
return $redirect;
}
if (! session()->has('verify_phone')) {
@@ -78,105 +64,137 @@ class VerificationController extends Controller
}
return view('verification.verify', [
'phone' => session()->get('verify_phone')
'phone' => session()->get('verify_phone'),
]);
}
public function resendOtp()
public function resendOtp(Request $request): RedirectResponse
{
if ($request->cookie(self::DEVICE_COOKIE_NAME)) {
return redirect()->route('verification.congratulations');
}
$phone = session()->get('verify_phone');
if (!$phone) {
if (! $phone) {
return redirect()->route('verification.index');
}
// Generate a 4-digit OTP
$otp = (string) rand(1000, 9999);
// Store in DB
PhoneVerification::updateOrCreate(
['phone' => $phone],
[
'otp' => $otp,
'expires_at' => now()->addMinutes(10),
'verified' => false
]
);
if (Coupon::query()->where('phone', $phone)->exists()) {
return redirect()->route('verification.congratulations');
}
sendSMS($phone, $otp);
if (! $this->otpService->issue($phone)) {
return back()->withErrors(['otp' => 'SMS iberilmedi. Soňrak synanyşyň.']);
}
return back()->with('status', 'Täze kod iberildi!');
}
public function verifyOtp(Request $request)
public function verifyOtp(VerifyOtpRequest $request): RedirectResponse
{
$request->validate([
'phone' => 'required',
'otp' => 'required|digits:4'
]);
$phone = session()->get('verify_phone');
$verification = PhoneVerification::query()->where('phone', $request->phone)->first();
if (!$verification || $verification->otp !== $request->otp) {
return back()->withErrors(['otp' => 'Nädogry kod.']);
if (! $phone) {
return redirect()->route('verification.index');
}
if ($verification->expires_at < now()) {
$result = $this->otpService->verify($phone, $request->string('otp')->toString());
if ($result === OtpVerificationResult::Expired) {
return back()->withErrors(['otp' => 'Kodyň möhleti gutardy.']);
}
// Mark as verified
$verification->update(['verified' => true]);
if ($result === OtpVerificationResult::Invalid) {
return back()->withErrors(['otp' => 'Nädogry kod.']);
}
// Generate or get Coupon
$coupon = Coupon::firstOrCreate(
['phone' => $request->phone],
['code' => $this->generateCouponCode()]
);
$coupon = $this->couponService->findOrCreateForPhone($phone);
// Put coupon code in session for the congratulations page
session()->put('coupon_code', $coupon->code);
// We set a long-lived cookie to mark this device as registered (e.g. 5 years)
return redirect()->route('verification.congratulations')
->cookie('device_registered', 'true', 60 * 24 * 365 * 5);
return redirect()
->route('verification.congratulations')
->withCookie($this->makeDeviceCookie($phone));
}
public function congratulations()
public function congratulations(): View|RedirectResponse
{
// If they have the cookie but lost the session, we don't know their code unless we query
// But for simplicity based on the flow, we'll try to find it by phone if available
if (!session()->has('coupon_code') && !request()->cookie('device_registered')) {
if (! session()->has('coupon_code') && ! request()->cookie(self::DEVICE_COOKIE_NAME)) {
return redirect()->route('verification.index');
}
$code = session()->get('coupon_code');
if (!$code && session()->has('verify_phone')) {
$coupon = Coupon::query()->where('phone', session()->get('verify_phone'))->first();
if ($coupon) {
$code = $coupon->code;
session()->put('coupon_code', $code);
}
if (! $code) {
$phone = $this->phoneFromDeviceCookie();
if ($phone) {
$coupon = Coupon::query()->where('phone', $phone)->first();
if ($coupon) {
$code = $coupon->code;
session()->put('coupon_code', $code);
}
}
}
// If for some reason code is completely lost (e.g. cookie exists but session cleared and no phone),
// we can't show a specific code. In this specific scenario, we'll default to redirecting back.
if (!$code) {
return redirect()->route('verification.index')->withoutCookie('device_registered');
if (! $code && session()->has('verify_phone')) {
$coupon = Coupon::query()->where('phone', session()->get('verify_phone'))->first();
if ($coupon) {
$code = $coupon->code;
session()->put('coupon_code', $code);
}
}
if (! $code) {
return redirect()
->route('verification.index')
->withoutCookie(self::DEVICE_COOKIE_NAME);
}
return view('verification.congratulations', [
'code' => $code
'code' => $code,
]);
}
private function generateCouponCode()
private function redirectIfAlreadyRegistered(): ?RedirectResponse
{
// Format X_YYYY (X is integer, Y is capital char)
$x = rand(1, 9);
$yyyy = substr(str_shuffle("ABCDEFGHIJKLMNOPQRSTUVWXYZ"), 0, 4);
if (request()->cookie(self::DEVICE_COOKIE_NAME) || session()->has('coupon_code')) {
return redirect()->route('verification.congratulations');
}
return "{$x}_{$yyyy}";
return null;
}
private function makeDeviceCookie(string $phone): Cookie
{
return cookie(
self::DEVICE_COOKIE_NAME,
encrypt($phone),
60 * 24 * 365 * 5,
'/',
null,
null,
true,
false,
'lax',
);
}
private function phoneFromDeviceCookie(): ?string
{
$value = request()->cookie(self::DEVICE_COOKIE_NAME);
if (! $value) {
return null;
}
try {
$phone = decrypt($value);
return is_string($phone) && preg_match('/^6\d{7}$/', $phone) ? $phone : null;
} catch (\Throwable) {
return null;
}
}
}

View File

@@ -0,0 +1,52 @@
<?php
namespace App\Http\Requests;
use Illuminate\Foundation\Http\FormRequest;
use Illuminate\Validation\Validator;
class SendOtpRequest extends FormRequest
{
public function authorize(): bool
{
return true;
}
/**
* @return array<string, array<int, string>>
*/
public function rules(): array
{
return [
'phone' => ['required', 'regex:/^\+993 [67]\d \d{2} \d{2} \d{2}$/'],
];
}
/**
* @return array<string, string>
*/
public function messages(): array
{
return [
'phone.regex' => 'Telefon belgiňiz şu formatda bolmaly: +993 KX XX XX XX (bu ýerde K 6 ýa-da 7).',
];
}
public function withValidator(Validator $validator): void
{
$validator->after(function (Validator $validator): void {
if ($validator->errors()->isNotEmpty()) {
return;
}
if (unmask_phone($this->string('phone')->toString()) === '') {
$validator->errors()->add('phone', 'Telefon belgiňiz şu formatda bolmaly: +993 KX XX XX XX (bu ýerde K 6 ýa-da 7).');
}
});
}
public function unmaskedPhone(): string
{
return unmask_phone($this->string('phone')->toString());
}
}

View File

@@ -0,0 +1,23 @@
<?php
namespace App\Http\Requests;
use Illuminate\Foundation\Http\FormRequest;
class VerifyOtpRequest extends FormRequest
{
public function authorize(): bool
{
return true;
}
/**
* @return array<string, array<int, string>>
*/
public function rules(): array
{
return [
'otp' => ['required', 'digits:4'],
];
}
}

View File

@@ -2,9 +2,20 @@
namespace App\Models;
use Database\Factories\CouponFactory;
use Illuminate\Database\Eloquent\Factories\HasFactory;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\HasOne;
class Coupon extends Model
{
/** @use HasFactory<CouponFactory> */
use HasFactory;
protected $fillable = ['phone', 'code'];
public function phoneVerification(): HasOne
{
return $this->hasOne(PhoneVerification::class, 'phone', 'phone');
}
}

View File

@@ -2,13 +2,28 @@
namespace App\Models;
use Database\Factories\PhoneVerificationFactory;
use Illuminate\Database\Eloquent\Factories\HasFactory;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Database\Eloquent\Relations\HasOne;
class PhoneVerification extends Model
{
/** @use HasFactory<PhoneVerificationFactory> */
use HasFactory;
protected $fillable = ['phone', 'otp', 'expires_at', 'verified'];
protected $casts = [
'expires_at' => 'datetime',
'verified' => 'boolean'
];
protected function casts(): array
{
return [
'expires_at' => 'datetime',
'verified' => 'boolean',
];
}
public function coupon(): HasOne
{
return $this->hasOne(Coupon::class, 'phone', 'phone');
}
}

View File

@@ -0,0 +1,45 @@
<?php
namespace App\Services;
use App\Models\Coupon;
use Illuminate\Database\UniqueConstraintViolationException;
use Illuminate\Support\Str;
class CouponService
{
public function findOrCreateForPhone(string $phone): Coupon
{
$existing = Coupon::query()->where('phone', $phone)->first();
if ($existing) {
return $existing;
}
return $this->createWithUniqueCode($phone);
}
private function createWithUniqueCode(string $phone): Coupon
{
for ($attempt = 0; $attempt < 10; $attempt++) {
try {
return Coupon::query()->create([
'phone' => $phone,
'code' => $this->generateCouponCode(),
]);
} catch (UniqueConstraintViolationException) {
continue;
}
}
throw new \RuntimeException('Unable to generate a unique coupon code.');
}
private function generateCouponCode(): string
{
$x = random_int(1, 9);
$yyyy = Str::upper(Str::random(4));
return "{$x}_{$yyyy}";
}
}

View File

@@ -0,0 +1,54 @@
<?php
namespace App\Services;
use App\Enums\OtpVerificationResult;
use App\Models\PhoneVerification;
use Illuminate\Support\Facades\Hash;
class OtpService
{
public const OTP_EXPIRY_MINUTES = 10;
public function issue(string $phone): bool
{
$otp = $this->generateOtp();
PhoneVerification::query()->updateOrCreate(
['phone' => $phone],
[
'otp' => Hash::make($otp),
'expires_at' => now()->addMinutes(self::OTP_EXPIRY_MINUTES),
'verified' => false,
],
);
return sendSMS($phone, 'Tassyklaýyş belgi: '.$otp);
}
public function verify(string $phone, string $otp): OtpVerificationResult
{
$verification = PhoneVerification::query()->where('phone', $phone)->first();
if (! $verification) {
return OtpVerificationResult::Invalid;
}
if ($verification->expires_at->isPast()) {
return OtpVerificationResult::Expired;
}
if (! Hash::check($otp, $verification->otp)) {
return OtpVerificationResult::Invalid;
}
$verification->update(['verified' => true]);
return OtpVerificationResult::Verified;
}
private function generateOtp(): string
{
return (string) random_int(1000, 9999);
}
}