diff --git a/.env b/.env old mode 100755 new mode 100644 index dfaec6d..dfff617 --- a/.env +++ b/.env @@ -1 +1,3 @@ -TOKEN_SIGNATURE=281361f952279bd9530734c67ed04aed2756f0fe00cb998cd6c28324f491484c \ No newline at end of file +COOKIE_TOKEN_SIGNATURE=628ef1d351018f7bb15dd5b5bc17fbc478fa6e7c7b993d136d5c03a4c2593c98 +API_TOKEN_SIGNATURE=2740fbb0a179e0e9fd801798e21515cd8a20ae964e3ef0abdeaf92830eaeefb4 +DB_FILE=database.db \ No newline at end of file diff --git a/api/api.php b/api/api.php index 6a18155..075e5e5 100755 --- a/api/api.php +++ b/api/api.php @@ -8,6 +8,8 @@ if ($debug) { } // API Main Library class gbAPI { + private $db; + function __construct($authRequired) { define("APP_PATH", __DIR__ . "/../"); @@ -62,7 +64,7 @@ class gbAPI { }elseif (isset($_COOKIE["auth_token"]) && isset($_COOKIE["username"])) { // Check Token $username = $_COOKIE["username"]; - $expected = $this->generateToken($username); + $expected = $this->generateCookieToken($username); $given = $_COOKIE["auth_token"]; $result = hash_equals($expected, $given); @@ -75,7 +77,7 @@ class gbAPI { $username = $payload["username"]; $given = $payload["auth_token"]; - $expected = $this->generateToken($username); + $expected = $this->generateAPIToken($username); $result = hash_equals($expected, $given); if ($result) { @@ -97,12 +99,16 @@ class gbAPI { } function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) { - $config = $this->getConfig(); - $db_name = $config["DB_NAME"]; - $db_path = APP_PATH . $db_name; + if (isset($this->db)) { + $db = $this->db; + }else{ + $config = $this->getConfig(); + $db_name = $config["DB_FILE"]; + $db_path = APP_PATH . $db_name; - $db = new PDO("sqlite:" . $db_path); - $db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); + $db = new PDO("sqlite:" . $db_path); + $db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); + } $stmt = $db->prepare($command); $stmt->execute($stmtArgs); @@ -114,7 +120,10 @@ class gbAPI { } } - function getSetting() { + function getSetting($key) { + $command = "SELECT name, value FROM settings WHERE name = :name"; + $value = $this->dbCommand($command, true, true, [":name" => $key]); + return $value; } } diff --git a/api/auth/login.php b/api/auth/login.php index de50f76..c758473 100755 --- a/api/auth/login.php +++ b/api/auth/login.php @@ -23,7 +23,7 @@ $username = $_POST["username"]; $password = $_POST["password"]; // Prepare SQL Command -$hash = hash("sha256", $password); +$hash = password_hash($password, PASSWORD_DEFAULT); $command = "SELECT username, password FROM users WHERE username = :username AND password = :password"; $args = [ diff --git a/api/entrys/add.php b/api/entrys/add.php index fe3ec00..ae22129 100644 --- a/api/entrys/add.php +++ b/api/entrys/add.php @@ -20,4 +20,33 @@ if (!isset($input["name"]) || !isset($input["text"])) { ]); } -$api->getSetting(""); \ No newline at end of file +$html_allowed = $api->getSetting("allow_html"); + +if ($html_allowed == "true") { + $name = $input["name"]; + $text = $input["text"]; +}else{ + $name = htmlspecialchars($input["name"]); + $text = htmlspecialchars($input["text"]); +} + +$date = date("d.m.Y"); +$approve = $api->getSetting("approve_entrys") == "true" ? true : false; + +if ($approve) { + $status = 0; +}else{ + $status = 1; +} + + +// Insert Into Database +$command = "INSERT INTO entrys (name, text, date, status) VALUES (:name, :text, :date, :status)"; +$api->dbCommand($command, false, true, [ + ":name" => $name, + ":text" => $text, + ":date" => $date, + ":status" => $status +]); + +$api->answer(200); \ No newline at end of file diff --git a/api/entrys/get.php b/api/entrys/get.php index 5b9e5c5..4d77df6 100644 --- a/api/entrys/get.php +++ b/api/entrys/get.php @@ -32,6 +32,6 @@ foreach($result as $row) { $json = json_encode($entrys); $api->answer(200, [ - "entrys" => $entrys, + "entrys" => $json, "empty" => false ]); \ No newline at end of file diff --git a/api/settings/appname.php b/api/settings/appname.php new file mode 100644 index 0000000..edefd54 --- /dev/null +++ b/api/settings/appname.php @@ -0,0 +1,13 @@ +dbCommand($command, true, true, [":name" => "application_name"]); + +$api->answer(200, [ + "application_name" => $result["value"] +]); \ No newline at end of file diff --git a/api/setup/save.php b/api/setup/save.php index e755dea..5dcda59 100755 --- a/api/setup/save.php +++ b/api/setup/save.php @@ -69,25 +69,25 @@ $stmt->execute([":username" => $username, ":password" => $hash, ":owner" => 1]); $command = "INSERT INTO settings (name, value) VALUES (:name, :value)"; $settings = [ - ":application_name" => "", - ":allow_html" => "false", - ":approve_entrys" => "true", - ":allow_new_entrys" => "true" + "application_name" => "Guestbook", + "allow_html" => "false", + "approve_entrys" => "true", + "allow_new_entrys" => "true" ]; foreach ($settings as $key => $value) { $stmt = $db->prepare($command); - $stmt->execute([$key => $value]); + $stmt->execute([":name" => $key, ":value" => $value]); } // WRITE .env AND GENERATE SECRETS $env = ""; $cookie_token = bin2hex(random_bytes(32)); -$env .= "COOKIE_TOKEN_SIGNATURE=" . $cookie_token; +$env .= "COOKIE_TOKEN_SIGNATURE=" . $cookie_token . "\n"; $api_token = bin2hex(random_bytes(32)); -$env .= "API_TOKEN_SIGNATURE=" . $api_token; +$env .= "API_TOKEN_SIGNATURE=" . $api_token . "\n"; $env .= "DB_FILE=database.db"; diff --git a/database.db b/database.db index fd48bc5..7f374d7 100644 Binary files a/database.db and b/database.db differ diff --git a/db_structure.sql b/db_structure.sql index 9ce29ea..2f67bc8 100755 --- a/db_structure.sql +++ b/db_structure.sql @@ -9,6 +9,7 @@ CREATE TABLE IF NOT EXISTS "entrys" ( "id" INTEGER PRIMARY KEY AUTOINCREMENT, "name" TEXT NOT NULL, "text" TEXT NOT NULL, + "date" TEXT NOT NULL, "status" INTEGER NOT NULL DEFAULT 0 ); diff --git a/public/html_loader.php b/public/html_loader.php index cc8c834..c7efa3f 100755 --- a/public/html_loader.php +++ b/public/html_loader.php @@ -60,6 +60,12 @@ class HTMLLoader { $page = $json[$template]; $html = file_get_contents(TEMPLATE_PATH . $page["dir_name"] . "/" . $page["html_file"]); + $app_name = file_get_contents("http://" . APP_DOMAIN . "/api/settings/appname.php"); + $app_name = json_decode($app_name, true); + $app_name = $app_name["data"]["application_name"]; + + $html = str_replace("%appname%", $app_name, $html); + // Get CSS $css = "";