Enhance API functionality: add token generation methods, implement entry management, and improve setup process with settings storage
This commit is contained in:
1 parent
8ef5f7a941
commit
9316818753
9 files changed
+248
-25
No files matched your search
+24
-4
@@ -28,7 +28,7 @@ class gbAPI {
|
||||
return parse_ini_file(APP_PATH . ".env");
|
||||
}
|
||||
|
||||
function generateToken($username) {
|
||||
function generateCookieToken($username) {
|
||||
$config = $this->getConfig();
|
||||
|
||||
// Generate Token
|
||||
@@ -37,7 +37,21 @@ class gbAPI {
|
||||
"auth" => true
|
||||
];
|
||||
$string = json_encode($payload);
|
||||
$secret = $config["TOKEN_SIGNATURE"];
|
||||
$secret = $config["COOKIE_TOKEN_SIGNATURE"];
|
||||
|
||||
return hash_hmac("sha256", $string, $secret);
|
||||
}
|
||||
|
||||
function generateAPIToken($username) {
|
||||
$config = $this->getConfig();
|
||||
|
||||
// Generate Token
|
||||
$payload = [
|
||||
"user" => $username,
|
||||
"auth" => true
|
||||
];
|
||||
$string = json_encode($payload);
|
||||
$secret = $config["API_TOKEN_SIGNATURE"];
|
||||
|
||||
return hash_hmac("sha256", $string, $secret);
|
||||
}
|
||||
@@ -83,9 +97,11 @@ class gbAPI {
|
||||
}
|
||||
|
||||
function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) {
|
||||
$db_path = APP_PATH . "database.db";
|
||||
$config = $this->getConfig();
|
||||
$db_name = $config["DB_NAME"];
|
||||
$db_path = APP_PATH . $db_name;
|
||||
|
||||
$db = new PDO("sqlite: " . $db_path);
|
||||
$db = new PDO("sqlite:" . $db_path);
|
||||
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
|
||||
|
||||
$stmt = $db->prepare($command);
|
||||
@@ -97,4 +113,8 @@ class gbAPI {
|
||||
return $result;
|
||||
}
|
||||
}
|
||||
|
||||
function getSetting() {
|
||||
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,23 @@
|
||||
<?php
|
||||
// Load Main Library
|
||||
require "../api.php";
|
||||
|
||||
$api = new gbAPI(false);
|
||||
|
||||
if ($_SERVER["REQUEST_METHOD"] !== "POST") {
|
||||
$api->answer(400, [
|
||||
"error" => "false_request_method",
|
||||
"error_text" => "Only POST allowed"
|
||||
]);
|
||||
}
|
||||
|
||||
$input = json_decode(file_get_contents("php://input"), true);
|
||||
|
||||
if (!isset($input["name"]) || !isset($input["text"])) {
|
||||
$api->answer(400, [
|
||||
"error" => "missing_fields",
|
||||
"error_text" => "Some fields are missing"
|
||||
]);
|
||||
}
|
||||
|
||||
$api->getSetting("");
|
||||
@@ -0,0 +1,37 @@
|
||||
<?php
|
||||
// Load Main Library
|
||||
require "../api.php";
|
||||
|
||||
$api = new gbAPI(false);
|
||||
|
||||
// Get Entrys
|
||||
$command = "SELECT * FROM entrys WHERE status = :status";
|
||||
$result = $api->dbCommand($command, true, true, [":status" => 1]);
|
||||
|
||||
$entrys = [];
|
||||
|
||||
if (!$result) {
|
||||
$api->answer(200, [
|
||||
"entrys" => [],
|
||||
"empty" => true
|
||||
]);
|
||||
}
|
||||
|
||||
foreach($result as $row) {
|
||||
$entry_name = $row["name"];
|
||||
$entry_text = $row["text"];
|
||||
|
||||
$entry = [
|
||||
"name" => $entry_name,
|
||||
"text" => $entry_text
|
||||
];
|
||||
|
||||
$entrys[] = $entry;
|
||||
}
|
||||
|
||||
$json = json_encode($entrys);
|
||||
|
||||
$api->answer(200, [
|
||||
"entrys" => $entrys,
|
||||
"empty" => false
|
||||
]);
|
||||
+39
-1
@@ -21,6 +21,14 @@ if (!isset($input["username"]) || !isset($input["password"]) || !isset($input["p
|
||||
]);
|
||||
}
|
||||
|
||||
// Check if application already configurated
|
||||
if (is_file(APP_PATH . "database.db")) {
|
||||
$api->answer(503, [
|
||||
"error" => "already_configurated",
|
||||
"error_text" => "The application is already configurated."
|
||||
]);
|
||||
}
|
||||
|
||||
$username = $input["username"];
|
||||
$password = $input["password"];
|
||||
$password_repeat = $input["password_repeat"];
|
||||
@@ -56,5 +64,35 @@ $command = "INSERT INTO users (username, password, owner) VALUES (:username, :pa
|
||||
$stmt = $db->prepare($command);
|
||||
$stmt->execute([":username" => $username, ":password" => $hash, ":owner" => 1]);
|
||||
|
||||
$api->answer(200);
|
||||
|
||||
// INSERT SETTINGS
|
||||
$command = "INSERT INTO settings (name, value) VALUES (:name, :value)";
|
||||
|
||||
$settings = [
|
||||
":application_name" => "",
|
||||
":allow_html" => "false",
|
||||
":approve_entrys" => "true",
|
||||
":allow_new_entrys" => "true"
|
||||
];
|
||||
|
||||
foreach ($settings as $key => $value) {
|
||||
$stmt = $db->prepare($command);
|
||||
$stmt->execute([$key => $value]);
|
||||
}
|
||||
|
||||
// WRITE .env AND GENERATE SECRETS
|
||||
$env = "";
|
||||
|
||||
$cookie_token = bin2hex(random_bytes(32));
|
||||
$env .= "COOKIE_TOKEN_SIGNATURE=" . $cookie_token;
|
||||
|
||||
$api_token = bin2hex(random_bytes(32));
|
||||
$env .= "API_TOKEN_SIGNATURE=" . $api_token;
|
||||
|
||||
$env .= "DB_FILE=database.db";
|
||||
|
||||
file_put_contents(APP_PATH . ".env", $env);
|
||||
|
||||
|
||||
// RETURN SUCCESS MESSAGE
|
||||
$api->answer(200);
|
||||
Reference in new issue
Block a user