From 1a2ee0c176f3d7cd1fda16cb0b14720968f46b97 Mon Sep 17 00:00:00 2001 From: marc-go Date: Tue, 6 Oct 2026 19:23:15 +0200 Subject: [PATCH] Refactor API and database interactions: enhance token management, improve entry handling, and add application name retrieval --- .env | 4 +++- api/api.php | 25 +++++++++++++++++-------- api/auth/login.php | 2 +- api/entrys/add.php | 31 ++++++++++++++++++++++++++++++- api/entrys/get.php | 2 +- api/settings/appname.php | 13 +++++++++++++ api/setup/save.php | 14 +++++++------- database.db | Bin 24576 -> 24576 bytes db_structure.sql | 1 + public/html_loader.php | 6 ++++++ 10 files changed, 79 insertions(+), 19 deletions(-) mode change 100755 => 100644 .env create mode 100644 api/settings/appname.php diff --git a/.env b/.env old mode 100755 new mode 100644 index dfaec6d..dfff617 --- a/.env +++ b/.env @@ -1 +1,3 @@ -TOKEN_SIGNATURE=281361f952279bd9530734c67ed04aed2756f0fe00cb998cd6c28324f491484c \ No newline at end of file +COOKIE_TOKEN_SIGNATURE=628ef1d351018f7bb15dd5b5bc17fbc478fa6e7c7b993d136d5c03a4c2593c98 +API_TOKEN_SIGNATURE=2740fbb0a179e0e9fd801798e21515cd8a20ae964e3ef0abdeaf92830eaeefb4 +DB_FILE=database.db \ No newline at end of file diff --git a/api/api.php b/api/api.php index 6a18155..075e5e5 100755 --- a/api/api.php +++ b/api/api.php @@ -8,6 +8,8 @@ if ($debug) { } // API Main Library class gbAPI { + private $db; + function __construct($authRequired) { define("APP_PATH", __DIR__ . "/../"); @@ -62,7 +64,7 @@ class gbAPI { }elseif (isset($_COOKIE["auth_token"]) && isset($_COOKIE["username"])) { // Check Token $username = $_COOKIE["username"]; - $expected = $this->generateToken($username); + $expected = $this->generateCookieToken($username); $given = $_COOKIE["auth_token"]; $result = hash_equals($expected, $given); @@ -75,7 +77,7 @@ class gbAPI { $username = $payload["username"]; $given = $payload["auth_token"]; - $expected = $this->generateToken($username); + $expected = $this->generateAPIToken($username); $result = hash_equals($expected, $given); if ($result) { @@ -97,12 +99,16 @@ class gbAPI { } function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) { - $config = $this->getConfig(); - $db_name = $config["DB_NAME"]; - $db_path = APP_PATH . $db_name; + if (isset($this->db)) { + $db = $this->db; + }else{ + $config = $this->getConfig(); + $db_name = $config["DB_FILE"]; + $db_path = APP_PATH . $db_name; - $db = new PDO("sqlite:" . $db_path); - $db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); + $db = new PDO("sqlite:" . $db_path); + $db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); + } $stmt = $db->prepare($command); $stmt->execute($stmtArgs); @@ -114,7 +120,10 @@ class gbAPI { } } - function getSetting() { + function getSetting($key) { + $command = "SELECT name, value FROM settings WHERE name = :name"; + $value = $this->dbCommand($command, true, true, [":name" => $key]); + return $value; } } diff --git a/api/auth/login.php b/api/auth/login.php index de50f76..c758473 100755 --- a/api/auth/login.php +++ b/api/auth/login.php @@ -23,7 +23,7 @@ $username = $_POST["username"]; $password = $_POST["password"]; // Prepare SQL Command -$hash = hash("sha256", $password); +$hash = password_hash($password, PASSWORD_DEFAULT); $command = "SELECT username, password FROM users WHERE username = :username AND password = :password"; $args = [ diff --git a/api/entrys/add.php b/api/entrys/add.php index fe3ec00..ae22129 100644 --- a/api/entrys/add.php +++ b/api/entrys/add.php @@ -20,4 +20,33 @@ if (!isset($input["name"]) || !isset($input["text"])) { ]); } -$api->getSetting(""); \ No newline at end of file +$html_allowed = $api->getSetting("allow_html"); + +if ($html_allowed == "true") { + $name = $input["name"]; + $text = $input["text"]; +}else{ + $name = htmlspecialchars($input["name"]); + $text = htmlspecialchars($input["text"]); +} + +$date = date("d.m.Y"); +$approve = $api->getSetting("approve_entrys") == "true" ? true : false; + +if ($approve) { + $status = 0; +}else{ + $status = 1; +} + + +// Insert Into Database +$command = "INSERT INTO entrys (name, text, date, status) VALUES (:name, :text, :date, :status)"; +$api->dbCommand($command, false, true, [ + ":name" => $name, + ":text" => $text, + ":date" => $date, + ":status" => $status +]); + +$api->answer(200); \ No newline at end of file diff --git a/api/entrys/get.php b/api/entrys/get.php index 5b9e5c5..4d77df6 100644 --- a/api/entrys/get.php +++ b/api/entrys/get.php @@ -32,6 +32,6 @@ foreach($result as $row) { $json = json_encode($entrys); $api->answer(200, [ - "entrys" => $entrys, + "entrys" => $json, "empty" => false ]); \ No newline at end of file diff --git a/api/settings/appname.php b/api/settings/appname.php new file mode 100644 index 0000000..edefd54 --- /dev/null +++ b/api/settings/appname.php @@ -0,0 +1,13 @@ +dbCommand($command, true, true, [":name" => "application_name"]); + +$api->answer(200, [ + "application_name" => $result["value"] +]); \ No newline at end of file diff --git a/api/setup/save.php b/api/setup/save.php index e755dea..5dcda59 100755 --- a/api/setup/save.php +++ b/api/setup/save.php @@ -69,25 +69,25 @@ $stmt->execute([":username" => $username, ":password" => $hash, ":owner" => 1]); $command = "INSERT INTO settings (name, value) VALUES (:name, :value)"; $settings = [ - ":application_name" => "", - ":allow_html" => "false", - ":approve_entrys" => "true", - ":allow_new_entrys" => "true" + "application_name" => "Guestbook", + "allow_html" => "false", + "approve_entrys" => "true", + "allow_new_entrys" => "true" ]; foreach ($settings as $key => $value) { $stmt = $db->prepare($command); - $stmt->execute([$key => $value]); + $stmt->execute([":name" => $key, ":value" => $value]); } // WRITE .env AND GENERATE SECRETS $env = ""; $cookie_token = bin2hex(random_bytes(32)); -$env .= "COOKIE_TOKEN_SIGNATURE=" . $cookie_token; +$env .= "COOKIE_TOKEN_SIGNATURE=" . $cookie_token . "\n"; $api_token = bin2hex(random_bytes(32)); -$env .= "API_TOKEN_SIGNATURE=" . $api_token; +$env .= "API_TOKEN_SIGNATURE=" . $api_token . "\n"; $env .= "DB_FILE=database.db"; diff --git a/database.db b/database.db index fd48bc51e0b28281a04d8ca952707ee0b73d66cf..7f374d78bbd62d9f15aa79b7496b970ff1ca5d0a 100644 GIT binary patch delta 413 zcmZoTz}Rqrae_1>=R_H2aZU!kszP4=9}KL#>I{5;_|NjK;yuZ$zOiv5&tzxb#hh_0 z?BbG=jLqVc-}6pqPDw189LOiRxsA_N&@|6K+%(ms!Z10?+p{V>IW3~d*dSBSBP7Yg zF*((+ETT+5*~8eesJOhUz$YxP#4(^aC@OK20*e3_Gyh!%{%`y*`0s8OR5;JC%gM|v z$(fp0QdC*Y!^AAhSe#l?l9`uY%)-IQEY4Y4oLW@O%fP_E$iI|_vIjKb@8ft~5`6bptsToiR;cHrR zfi&qObQzfG85-yr85o&?tYYDx#lZiN{|x^Y{#if^yZF;2SXdZzMH6#!^2_7%Qp@8Z z&Mhe_O%-EiVbBy!EGQ_-FH1!d7iMB%P!xyg$SBFpNlVNrPL*W@8Y2%>oRgWHSdy8a T7oV4yo9bSgT3nKppPvl?h8}-B delta 178 zcmZoTz}Rqrae_1>%S0JxaTW%>szP4=9}KL#&J28i_|NjK;(f~Nyjf7-EYD0w zEbQWvl8jC9lP~j5-`vLMDrlNnVVsoiT47$E8s+4XRuY(Gp6=>fn&Rf;Rcc`xkZI