' . $name . '
-' . $text . '
-diff --git a/api/api.php b/api/api.php index 2247c32..6a18155 100755 --- a/api/api.php +++ b/api/api.php @@ -28,7 +28,7 @@ class gbAPI { return parse_ini_file(APP_PATH . ".env"); } - function generateToken($username) { + function generateCookieToken($username) { $config = $this->getConfig(); // Generate Token @@ -37,7 +37,21 @@ class gbAPI { "auth" => true ]; $string = json_encode($payload); - $secret = $config["TOKEN_SIGNATURE"]; + $secret = $config["COOKIE_TOKEN_SIGNATURE"]; + + return hash_hmac("sha256", $string, $secret); + } + + function generateAPIToken($username) { + $config = $this->getConfig(); + + // Generate Token + $payload = [ + "user" => $username, + "auth" => true + ]; + $string = json_encode($payload); + $secret = $config["API_TOKEN_SIGNATURE"]; return hash_hmac("sha256", $string, $secret); } @@ -83,9 +97,11 @@ class gbAPI { } function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) { - $db_path = APP_PATH . "database.db"; + $config = $this->getConfig(); + $db_name = $config["DB_NAME"]; + $db_path = APP_PATH . $db_name; - $db = new PDO("sqlite: " . $db_path); + $db = new PDO("sqlite:" . $db_path); $db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); $stmt = $db->prepare($command); @@ -97,4 +113,8 @@ class gbAPI { return $result; } } + + function getSetting() { + + } } diff --git a/api/entrys/add.php b/api/entrys/add.php new file mode 100644 index 0000000..fe3ec00 --- /dev/null +++ b/api/entrys/add.php @@ -0,0 +1,23 @@ +answer(400, [ + "error" => "false_request_method", + "error_text" => "Only POST allowed" + ]); +} + +$input = json_decode(file_get_contents("php://input"), true); + +if (!isset($input["name"]) || !isset($input["text"])) { + $api->answer(400, [ + "error" => "missing_fields", + "error_text" => "Some fields are missing" + ]); +} + +$api->getSetting(""); \ No newline at end of file diff --git a/api/entrys/get.php b/api/entrys/get.php new file mode 100644 index 0000000..5b9e5c5 --- /dev/null +++ b/api/entrys/get.php @@ -0,0 +1,37 @@ +dbCommand($command, true, true, [":status" => 1]); + +$entrys = []; + +if (!$result) { + $api->answer(200, [ + "entrys" => [], + "empty" => true + ]); +} + +foreach($result as $row) { + $entry_name = $row["name"]; + $entry_text = $row["text"]; + + $entry = [ + "name" => $entry_name, + "text" => $entry_text + ]; + + $entrys[] = $entry; +} + +$json = json_encode($entrys); + +$api->answer(200, [ + "entrys" => $entrys, + "empty" => false +]); \ No newline at end of file diff --git a/api/setup/save.php b/api/setup/save.php index 930af76..e755dea 100755 --- a/api/setup/save.php +++ b/api/setup/save.php @@ -21,6 +21,14 @@ if (!isset($input["username"]) || !isset($input["password"]) || !isset($input["p ]); } +// Check if application already configurated +if (is_file(APP_PATH . "database.db")) { + $api->answer(503, [ + "error" => "already_configurated", + "error_text" => "The application is already configurated." + ]); +} + $username = $input["username"]; $password = $input["password"]; $password_repeat = $input["password_repeat"]; @@ -56,5 +64,35 @@ $command = "INSERT INTO users (username, password, owner) VALUES (:username, :pa $stmt = $db->prepare($command); $stmt->execute([":username" => $username, ":password" => $hash, ":owner" => 1]); -$api->answer(200); +// INSERT SETTINGS +$command = "INSERT INTO settings (name, value) VALUES (:name, :value)"; + +$settings = [ + ":application_name" => "", + ":allow_html" => "false", + ":approve_entrys" => "true", + ":allow_new_entrys" => "true" +]; + +foreach ($settings as $key => $value) { + $stmt = $db->prepare($command); + $stmt->execute([$key => $value]); +} + +// WRITE .env AND GENERATE SECRETS +$env = ""; + +$cookie_token = bin2hex(random_bytes(32)); +$env .= "COOKIE_TOKEN_SIGNATURE=" . $cookie_token; + +$api_token = bin2hex(random_bytes(32)); +$env .= "API_TOKEN_SIGNATURE=" . $api_token; + +$env .= "DB_FILE=database.db"; + +file_put_contents(APP_PATH . ".env", $env); + + +// RETURN SUCCESS MESSAGE +$api->answer(200); \ No newline at end of file diff --git a/database.db b/database.db index 56156f7..fd48bc5 100644 Binary files a/database.db and b/database.db differ diff --git a/db_structure.sql b/db_structure.sql index deb7921..9ce29ea 100755 --- a/db_structure.sql +++ b/db_structure.sql @@ -12,3 +12,8 @@ CREATE TABLE IF NOT EXISTS "entrys" ( "status" INTEGER NOT NULL DEFAULT 0 ); +CREATE TABLE IF NOT EXISTS "settings" ( + "id" INTEGER PRIMARY KEY AUTOINCREMENT, + "name" TEXT NOT NULL, + "value" TEXT NOT NULL +); \ No newline at end of file diff --git a/public/index.php b/public/index.php index c930b11..f7f65ca 100755 --- a/public/index.php +++ b/public/index.php @@ -18,20 +18,26 @@ $htmlLoader->setTemplate("entrys_frontend"); $url = "http://" . APP_DOMAIN . "/api/entrys/get.php"; $response = file_get_contents($url); -$entrys = json_decode($response, true); -$entrys = $entrys["entrys"]; +$response = json_decode($response, true); +if ($response["data"]["empty"]) { + $html_block = "
There aren'n any entrys yet. Be the first one!
"; +}else{ + $entrys = $response["data"]["entrys"]; -$html_block = ""; -foreach($entrys as $entry) { - $name = $entry["name"]; - $text = $entry["text"]; + $html_block = ""; + foreach($entrys as $entry) { + $name = $entry["name"]; + $text = $entry["text"]; + $date = $entry["date"]; - $html_block .= ' -' . $text . '
-' . $date . '
+' . $text . '
+