Refactor API and database interactions: enhance token management, improve entry handling, and add application name retrieval

This commit is contained in:
marc-go committed 2026-10-06 19:23:15 +02:00
1 parent 9316818753
commit 1a2ee0c176
10 files changed
+79 -19

No files matched your search

+17 -8
View File
@@ -8,6 +8,8 @@ if ($debug) {
}
// API Main Library
class gbAPI {
private $db;
function __construct($authRequired) {
define("APP_PATH", __DIR__ . "/../");
@@ -62,7 +64,7 @@ class gbAPI {
}elseif (isset($_COOKIE["auth_token"]) && isset($_COOKIE["username"])) {
// Check Token
$username = $_COOKIE["username"];
$expected = $this->generateToken($username);
$expected = $this->generateCookieToken($username);
$given = $_COOKIE["auth_token"];
$result = hash_equals($expected, $given);
@@ -75,7 +77,7 @@ class gbAPI {
$username = $payload["username"];
$given = $payload["auth_token"];
$expected = $this->generateToken($username);
$expected = $this->generateAPIToken($username);
$result = hash_equals($expected, $given);
if ($result) {
@@ -97,12 +99,16 @@ class gbAPI {
}
function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) {
$config = $this->getConfig();
$db_name = $config["DB_NAME"];
$db_path = APP_PATH . $db_name;
if (isset($this->db)) {
$db = $this->db;
}else{
$config = $this->getConfig();
$db_name = $config["DB_FILE"];
$db_path = APP_PATH . $db_name;
$db = new PDO("sqlite:" . $db_path);
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
$db = new PDO("sqlite:" . $db_path);
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
}
$stmt = $db->prepare($command);
$stmt->execute($stmtArgs);
@@ -114,7 +120,10 @@ class gbAPI {
}
}
function getSetting() {
function getSetting($key) {
$command = "SELECT name, value FROM settings WHERE name = :name";
$value = $this->dbCommand($command, true, true, [":name" => $key]);
return $value;
}
}
+1 -1
View File
@@ -23,7 +23,7 @@ $username = $_POST["username"];
$password = $_POST["password"];
// Prepare SQL Command
$hash = hash("sha256", $password);
$hash = password_hash($password, PASSWORD_DEFAULT);
$command = "SELECT username, password FROM users WHERE username = :username AND password = :password";
$args = [
+30 -1
View File
@@ -20,4 +20,33 @@ if (!isset($input["name"]) || !isset($input["text"])) {
]);
}
$api->getSetting("");
$html_allowed = $api->getSetting("allow_html");
if ($html_allowed == "true") {
$name = $input["name"];
$text = $input["text"];
}else{
$name = htmlspecialchars($input["name"]);
$text = htmlspecialchars($input["text"]);
}
$date = date("d.m.Y");
$approve = $api->getSetting("approve_entrys") == "true" ? true : false;
if ($approve) {
$status = 0;
}else{
$status = 1;
}
// Insert Into Database
$command = "INSERT INTO entrys (name, text, date, status) VALUES (:name, :text, :date, :status)";
$api->dbCommand($command, false, true, [
":name" => $name,
":text" => $text,
":date" => $date,
":status" => $status
]);
$api->answer(200);
+1 -1
View File
@@ -32,6 +32,6 @@ foreach($result as $row) {
$json = json_encode($entrys);
$api->answer(200, [
"entrys" => $entrys,
"entrys" => $json,
"empty" => false
]);
+13
View File
@@ -0,0 +1,13 @@
<?php
// Load Main Library
require "../api.php";
$api = new gbAPI(false);
// Get App Name
$command = "SELECT name, value FROM settings WHERE name = :name";
$result = $api->dbCommand($command, true, true, [":name" => "application_name"]);
$api->answer(200, [
"application_name" => $result["value"]
]);
+7 -7
View File
@@ -69,25 +69,25 @@ $stmt->execute([":username" => $username, ":password" => $hash, ":owner" => 1]);
$command = "INSERT INTO settings (name, value) VALUES (:name, :value)";
$settings = [
":application_name" => "",
":allow_html" => "false",
":approve_entrys" => "true",
":allow_new_entrys" => "true"
"application_name" => "Guestbook",
"allow_html" => "false",
"approve_entrys" => "true",
"allow_new_entrys" => "true"
];
foreach ($settings as $key => $value) {
$stmt = $db->prepare($command);
$stmt->execute([$key => $value]);
$stmt->execute([":name" => $key, ":value" => $value]);
}
// WRITE .env AND GENERATE SECRETS
$env = "";
$cookie_token = bin2hex(random_bytes(32));
$env .= "COOKIE_TOKEN_SIGNATURE=" . $cookie_token;
$env .= "COOKIE_TOKEN_SIGNATURE=" . $cookie_token . "\n";
$api_token = bin2hex(random_bytes(32));
$env .= "API_TOKEN_SIGNATURE=" . $api_token;
$env .= "API_TOKEN_SIGNATURE=" . $api_token . "\n";
$env .= "DB_FILE=database.db";