diff --git a/app/Http/Controllers/Api/AuthSmsController.php b/app/Http/Controllers/Api/AuthSmsController.php index bdec1e0..4139459 100644 --- a/app/Http/Controllers/Api/AuthSmsController.php +++ b/app/Http/Controllers/Api/AuthSmsController.php @@ -42,7 +42,7 @@ class AuthSmsController extends Controller ]); $resendSec = (int) config('sms.resend_interval_seconds', 60); - $rateKey = 'sms-send:'.$mobile; + $rateKey = 'sms-send:'.hash('sha256', $mobile); if (RateLimiter::tooManyAttempts($rateKey, 1)) { Log::warning('sms.send rate_limited', [ 'mobile_mask' => $this->maskMobile($mobile), diff --git a/app/Http/Controllers/Api/PublicCompetitionController.php b/app/Http/Controllers/Api/PublicCompetitionController.php index f5c6086..9d87aa7 100644 --- a/app/Http/Controllers/Api/PublicCompetitionController.php +++ b/app/Http/Controllers/Api/PublicCompetitionController.php @@ -5,17 +5,24 @@ namespace App\Http\Controllers\Api; use App\Http\Controllers\Controller; use App\Models\Competition; use Illuminate\Http\JsonResponse; +use Illuminate\Support\Facades\Schema; class PublicCompetitionController extends Controller { public function active(): JsonResponse { - $competition = Competition::query() - ->where('published', true) - ->whereIn('status', ['published', 'signup_open']) - ->orderByDesc('signup_open_at') - ->orderByDesc('id') - ->firstOrFail(); + $query = Competition::query(); + if (Schema::hasColumn('competitions', 'published')) { + $query->where('published', true); + } + if (Schema::hasColumn('competitions', 'status')) { + $query->whereIn('status', ['published', 'signup_open']); + } + if (Schema::hasColumn('competitions', 'signup_open_at')) { + $query->orderByDesc('signup_open_at'); + } + + $competition = $query->orderByDesc('id')->firstOrFail(); return response()->json([ 'id' => $competition->id, diff --git a/routes/web.php b/routes/web.php index b0f151e..af508bd 100644 --- a/routes/web.php +++ b/routes/web.php @@ -2,8 +2,10 @@ use App\Http\Controllers\Api\ApplicationFileController; use App\Http\Controllers\ChannelEntryController; +use App\Models\Competition; use Illuminate\Support\Facades\File; use Illuminate\Support\Facades\Route; +use Illuminate\Support\Facades\Schema; /* |-------------------------------------------------------------------------- @@ -17,7 +19,24 @@ use Illuminate\Support\Facades\Route; */ Route::get('/', function () { - return view('welcome'); + $query = Competition::query(); + if (Schema::hasColumn('competitions', 'published')) { + $query->where('published', true); + } + if (Schema::hasColumn('competitions', 'status')) { + $query->whereIn('status', ['published', 'signup_open']); + } + if (Schema::hasColumn('competitions', 'signup_open_at')) { + $query->orderByDesc('signup_open_at'); + } + + $competition = $query->orderByDesc('id')->first(); + + if ($competition === null) { + return redirect('/admin/'); + } + + return redirect('/admin/c/'.rawurlencode($competition->slug).'/login'); }); Route::get('/channel-entry', ChannelEntryController::class)->name('channel.entry'); diff --git a/tests/Feature/AuthSmsControllerTest.php b/tests/Feature/AuthSmsControllerTest.php index 00547a5..0e94a23 100644 --- a/tests/Feature/AuthSmsControllerTest.php +++ b/tests/Feature/AuthSmsControllerTest.php @@ -260,6 +260,18 @@ class AuthSmsControllerTest extends TestCase 'created_at' => now()->subMinutes(2), 'updated_at' => now()->subMinutes(2), ])->save(); + $oldPending = SmsVerification::query()->create([ + 'scene' => SmsVerification::SCENE_PARTICIPANT_LOGIN, + 'mobile' => '13800138007', + 'code' => '444444', + 'provider' => SmsVerification::PROVIDER_TENCENTCLOUD, + 'status' => SmsVerification::STATUS_PENDING, + 'expires_at' => now()->addMinutes(5), + ]); + $oldPending->forceFill([ + 'created_at' => now()->subMinutes(2), + 'updated_at' => now()->subMinutes(2), + ])->save(); $this->enableTencentCloudConfig(); Http::fake([ @@ -282,6 +294,10 @@ class AuthSmsControllerTest extends TestCase 'id' => $old->id, 'status' => SmsVerification::STATUS_EXPIRED, ]); + $this->assertDatabaseHas('sms_verifications', [ + 'id' => $oldPending->id, + 'status' => SmsVerification::STATUS_EXPIRED, + ]); $this->postJson('/api/auth/sms/login', [ 'mobile' => '13800138007',