Refactor authentication: streamline cookie handling and enhance username retrieval in responses

This commit is contained in:
marc-go committed 2026-10-09 19:20:53 +02:00
1 parent a1bbae383a
commit 6b5a299079
3 files changed
+45 -18

No files matched your search

+43 -16
View File
@@ -8,7 +8,10 @@ if ($debug) {
} }
// API Main Library // API Main Library
class gbAPI { class gbAPI {
public $username;
private $db; private $db;
private $config;
private function b64url_encode($data) { private function b64url_encode($data) {
return rtrim(strtr(base64_encode($data), "+/", "-_"), "="); return rtrim(strtr(base64_encode($data), "+/", "-_"), "=");
} }
@@ -34,7 +37,11 @@ class gbAPI {
} }
function getConfig() { function getConfig() {
return parse_ini_file(APP_PATH . ".env"); if (isset($this->config)) {
return $config;
}else{
return parse_ini_file(APP_PATH . ".env");
}
} }
function generateCookieToken($username) { function generateCookieToken($username) {
@@ -69,37 +76,57 @@ class gbAPI {
} }
function checkAuth() { function checkAuth() {
if (!isset($_SERVER["HTTP_X_API_KEY"]) && !isset($_COOKIE["auth_token"])) { if (isset($_COOKIE["auth_token"])) {
return false; // Get Config
}elseif (isset($_COOKIE["auth_token"]) && isset($_COOKIE["username"])) { $config = $this->getConfig();
// Check Token // Check Token
$username = $_COOKIE["username"];
$expected = $this->generateCookieToken($username);
$given = $_COOKIE["auth_token"]; $given = $_COOKIE["auth_token"];
if (!is_string($given)) {
return false;
}
$result = hash_equals($expected, $given); $given_string = explode(".", $given);
if (count($parts) !== 2) {
return false;
}
$sig_expected = hash_hmac("sha256", $given_string[0], $config["COOKIE_TOKEN_SIGNATURE"]);
@$result = hash_equals($sig_expected, $given_string[1]);
if ($result) { if ($result) {
$given_string = explode(".", $given);
$body = json_decode($this->b64url_decode($given_string[0]), true); $body = json_decode($this->b64url_decode($given_string[0]), true);
if ($body["exp"] > time()) { if ($body["exp"] > time()) {
$this->username = $body["user"];
return true; return true;
}else{ }else{
return false; return false;
} }
}else{
return false;
} }
}elseif (isset($_SERVER["HTTP_X_API_KEY"])) { }elseif (isset($_SERVER["HTTP_X_API_KEY"])) {
// Get config
$config = $this->getConfig();
// Decode Token // Decode Token
$payload = json_decode($this->b64url_decode($_SERVER["HTTP_X_API_KEY"]), true); $given = $_SERVER["HTTP_X_API_KEY"];
$username = $payload["username"];
$given = $payload["auth_token"]; if (!is_string($given)) {
$expected = $this->generateAPIToken($username); return false;
$result = hash_equals($expected, $given);
if ($result) {
return true;
} }
$given_string = explode(".", $given);
if (count($parts) !== 2) {
return false;
}
$sig_expected = hash_hmac("sha256", $given_string[0], $config["API_TOKEN_SIGNATURE"]);
@$result = hash_equals($sig_expected, $given_string[1]);
} }
return false; return false;
+2 -1
View File
@@ -4,5 +4,6 @@ require "../api.php";
$api = new gbAPI(true); $api = new gbAPI(true);
$api->answer(200, [ $api->answer(200, [
"login" => true "login" => true,
"username" => $api->username
]); ]);
-1
View File
@@ -40,7 +40,6 @@ if ($result && password_verify($password, $result[0]["password"])) {
// Set cookies // Set cookies
setcookie("auth_token", $token, time() + 86400, "/"); setcookie("auth_token", $token, time() + 86400, "/");
setcookie("username", $username, time() + 86400, "/");
$api->answer(200); $api->answer(200);
}else{ }else{