From 9cb50d7d2815e1795c41ff49cd4a0e4e05f9709a Mon Sep 17 00:00:00 2001 From: marc-go Date: Sat, 10 Oct 2026 15:05:24 +0200 Subject: [PATCH] Refactor API structure: update internal handling, enhance input retrieval, and improve template loading --- .env | 7 +--- api/api.php | 77 +++++++++++++++++++++++++++++------ api/auth/isauth.php | 5 ++- api/auth/login.php | 14 ++----- api/entrys/add.php | 14 ++----- api/entrys/get.php | 5 ++- api/settings/appname.php | 5 ++- api/setup/save.php | 25 ++++++------ api/template/get.php | 16 ++++++++ database.db | Bin 24576 -> 24576 bytes public/html_loader.php | 84 +++++++++++++++++++++++++++------------ public/index.php | 9 ++--- public/main.php | 15 +++---- 13 files changed, 181 insertions(+), 95 deletions(-) create mode 100644 api/template/get.php mode change 100755 => 100644 database.db diff --git a/.env b/.env index 00755bb..924585d 100644 --- a/.env +++ b/.env @@ -1,7 +1,4 @@ -COOKIE_TOKEN_SIGNATURE=628ef1d351018f7bb15dd5b5bc17fbc478fa6e7c7b993d136d5c03a4c2593c98 +COOKIE_TOKEN_SIGNATURE=a11a9ea5fd839e616bd08ebc432f641a24ef1f4d74ca478f904e7a3122fc7a05 COOKIE_TOKEN_LIFETIME=86400 - -API_TOKEN_SIGNATURE=2740fbb0a179e0e9fd801798e21515cd8a20ae964e3ef0abdeaf92830eaeefb4 - - +API_TOKEN_SIGNATURE=38bcd8a8e9ac3be83ddfcf4c12c19ccb3be70df00e48d43d4f63f54f014d1946 DB_FILE=database.db \ No newline at end of file diff --git a/api/api.php b/api/api.php index 3656df5..d9b8ac4 100755 --- a/api/api.php +++ b/api/api.php @@ -6,13 +6,17 @@ if ($debug) { ini_set("display_startup_errors", 1); error_reporting(E_ALL); } + +debug_print_backtrace(); // API Main Library class gbAPI { public $username; + public $input; private $db; private $config; private $internal; + private $response; private function b64url_encode($data) { return rtrim(strtr(base64_encode($data), "+/", "-_"), "="); @@ -23,10 +27,13 @@ class gbAPI { } function __construct($authRequired, $internal) { - define("APP_PATH", __DIR__ . "/../"); + if (!defined("APP_PATH")) { + define("APP_PATH", __DIR__ . "/../"); + } + $this->internal = $internal; - if ($authRequired) { + if ($authRequired && !$internal) { if (!$this->checkAuth()) { $status = 401; $data = [ @@ -39,6 +46,27 @@ class gbAPI { } } + function getInput() { + if (isset($this->input)) { + return $this->input; + }elseif ($_SERVER["REQUEST_METHOD"] == "POST") { + try { + $input = json_decode(file_get_contents("php://input"), true); + } catch (JsonException $error) { + $this->answer(400, [ + "error" => "invalid_body", + "error_text" => "Can not read request body: " . $error + ]); + } + return $input; + }else{ + $this->answer(400, [ + "error" => "false_request_method", + "error_text" => "Only POST allowed" + ], true); + } + } + function getConfig() { if (isset($this->config)) { return $config; @@ -136,27 +164,49 @@ class gbAPI { } function answer($status, $data = [], $error = false) { - http_response_code($status); - header("Content-Type: application/json; charset=UTF-8"); - - if ($error) { - $json = []; + $return = []; - $json["status"] = $status; + $return["status"] = $status; foreach ($data as $key => $value) { - $json[$key] = $value; + $return[$key] = $value; } }else{ - $json = [ + $return = [ "status" => $status, "data" => $data ]; } + + // Check if request is internal or external + if ($this->internal) { + $this->response = $return; + }else{ + http_response_code($status); + header("Content-Type: application/json; charset=UTF-8"); - $return = json_encode($json); - die($return); + $return = json_encode($return); + die($return); + } + } + + function getAnswer() { + if (!isset($this->response)) { + $error = [ + "status" => 500, + "error" => "empty_return", + "error_text" => "API Returned nothing." + ]; + + return $error; + } + + return $this->response; + } + + function getResponse() { + return $this->response; } function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) { @@ -192,6 +242,7 @@ class gbAPI { $command = "SELECT name, value FROM settings WHERE name = :name"; $value = $this->dbCommand($command, true, true, [":name" => $key]); - return $value; + + return $value[0]["value"]; } } diff --git a/api/auth/isauth.php b/api/auth/isauth.php index 7fee7d1..55504ed 100755 --- a/api/auth/isauth.php +++ b/api/auth/isauth.php @@ -2,11 +2,12 @@ // Set internal to false so that the answer goes to the client if (!isset($internal)) { $internal = false; + define("API_DIR", "../"); } // Load Main Library -require "../api.php"; -$api = new gbAPI(true); +require API_DIR . "api.php"; +$api = new gbAPI(true, $internal); $api->answer(200, [ "login" => true, diff --git a/api/auth/login.php b/api/auth/login.php index 1076934..16d6346 100755 --- a/api/auth/login.php +++ b/api/auth/login.php @@ -2,22 +2,16 @@ // Set internal to false so that the answer goes to the client if (!isset($internal)) { $internal = false; + define("API_DIR", "../"); } // Load API Library -require "../api.php"; +require API_DIR . "api.php"; -$api = new gbAPI(false); +$api = new gbAPI(false, $internal); // Check Request Body -if ($_SERVER["REQUEST_METHOD"] !== "POST") { - $api->answer(400, [ - "error" => "false_request_method", - "error_text" => "Only POST allowed" - ], true); -} - -$input = json_decode(file_get_contents("php://input"), true); +$input = $api->getInput(); if (!isset($input["username"]) || !isset($input["password"])) { $api->answer(400, [ diff --git a/api/entrys/add.php b/api/entrys/add.php index 8e9ed8b..ede645f 100755 --- a/api/entrys/add.php +++ b/api/entrys/add.php @@ -2,21 +2,15 @@ // Set internal to false so that the answer goes to the client if (!isset($internal)) { $internal = false; + define("API_DIR", "../"); } // Load Main Library -require "../api.php"; +require API_DIR . "api.php"; -$api = new gbAPI(false); +$api = new gbAPI(false, $internal); -if ($_SERVER["REQUEST_METHOD"] !== "POST") { - $api->answer(400, [ - "error" => "false_request_method", - "error_text" => "Only POST allowed" - ]); -} - -$input = json_decode(file_get_contents("php://input"), true); +$input = $api->getInput(); if (!isset($input["name"]) || !isset($input["text"])) { $api->answer(400, [ diff --git a/api/entrys/get.php b/api/entrys/get.php index 03c2401..a794a23 100755 --- a/api/entrys/get.php +++ b/api/entrys/get.php @@ -2,12 +2,13 @@ // Set internal to false so that the answer goes to the client if (!isset($internal)) { $internal = false; + define("API_DIR", "../"); } // Load Main Library -require "../api.php"; +require API_DIR . "api.php"; -$api = new gbAPI(false); +$api = new gbAPI(false, $internal); // Get Entrys $command = "SELECT * FROM entrys WHERE status = :status ORDER BY date DESC"; diff --git a/api/settings/appname.php b/api/settings/appname.php index 5d4661c..9eecac9 100755 --- a/api/settings/appname.php +++ b/api/settings/appname.php @@ -2,12 +2,13 @@ // Set internal to false so that the answer goes to the client if (!isset($internal)) { $internal = false; + define("API_DIR", "../"); } // Load Main Library -require "../api.php"; +require API_DIR . "api.php"; -$api = new gbAPI(false); +$api = new gbAPI(false, $internal); // Get App Name $command = "SELECT name, value FROM settings WHERE name = :name"; diff --git a/api/setup/save.php b/api/setup/save.php index c972667..7f77919 100755 --- a/api/setup/save.php +++ b/api/setup/save.php @@ -1,18 +1,17 @@ answer(400, [ - "error" => "false_request_method", - "error_text" => "Only POST allowed" - ]); +// Set internal to false so that the answer goes to the client +if (!isset($internal)) { + $internal = false; + define("API_DIR", "../"); } -$input = json_decode(file_get_contents("php://input"), true); +// Load Main Libary +require API_DIR . "api.php"; + +$api = new gbAPI(false, $internal); + +// Check Request body +$input = $api->getInput(); if (!isset($input["username"]) || !isset($input["password"]) || !isset($input["password_repeat"])) { $api->answer(400, [ @@ -94,12 +93,12 @@ $env = ""; $cookie_token = bin2hex(random_bytes(32)); $env .= "COOKIE_TOKEN_SIGNATURE=" . $cookie_token . "\n"; +$env .= "COOKIE_TOKEN_LIFETIME=86400\n"; $api_token = bin2hex(random_bytes(32)); $env .= "API_TOKEN_SIGNATURE=" . $api_token . "\n"; $env .= "DB_FILE=database.db"; -$env .= "COOKIE_TOKEN_LIFETIME=86400"; file_put_contents(APP_PATH . ".env", $env); diff --git a/api/template/get.php b/api/template/get.php new file mode 100644 index 0000000..bd22c6e --- /dev/null +++ b/api/template/get.php @@ -0,0 +1,16 @@ +getSetting("template"); + +$api->answer(200, [ + "template_name" => $template +]); \ No newline at end of file diff --git a/database.db b/database.db old mode 100755 new mode 100644 index cd77c7b8040f71d29412e6f77924e4b4417963c0..4870db2a1abc84f1b150d641576221e7b0500ff2 GIT binary patch delta 181 zcmZoTz}Rqrae_1>=R_H2M$U~1+482Qg_hpI0XYF)jz!toCYi>5Cca@VrKtr)rNPc2 z!Ie${`kv0ghH0gaffmLYX{7<)Ibnv*n-o|CIGFffFz|olf3aCm;SRqX4->O2V{vLp zNoHPpF)Ifnvp8pIacWU9F9Q$=0M$I_pEyBS2*hROZ(-nn$bW`^3;!(smd%0!Mf_qS etSk(&vL&gx1v!Z&sl_FUc`1oSDU)Z#rvU&Inl&2$ delta 244 zcmZoTz}Rqrae_3Xz(g5mMuCk9+481&{^6#nCKZOsQQn?a;mK(cMaBl1dLAK39*)VW zhGh|D`pF)~jzz`gRRum_c_oek#X(Vtn-o|CxS09xFz|olf5Crev!KE`egiIMW=Y1> zypp2IVpbj|W?9DK)RL0Sy!2ug4n}5i&eG!4qGDbK1_mbnoecbU`F8?!t>q6_Vr63x z6*uPeO)N?-Ni8lhGBPkS(={~EHLy@HG_*1`v@$VQWC5xXMN)&V#Ml&MFbn@I2L6Zq TXZW}9&)O^~(8WJ_R(u)&`Zhw? diff --git a/public/html_loader.php b/public/html_loader.php index 03728ce..abbf8ce 100755 --- a/public/html_loader.php +++ b/public/html_loader.php @@ -1,33 +1,55 @@ templates = json_decode(file_get_contents(TEMPLATE_CONF), true); } function setTemplate($template) { // Check if template exists - $file = file_get_contents(TEMPLATE_CONF); - $json = json_decode($file, true); - - if (!array_key_exists($template, $json) && array_key_exists("error", $json)) { - $this->showError('Template "' . $template . '" was not found.'); - exit; - }elseif (!array_key_exists("error", $json)){ - die("Error Template was not found."); + if (!array_key_exists($template, $this->templates)) { + die("Template " . $template . " not found."); } - $this->page = $template; + + if (!is_dir(TEMPLATE_PATH . $this->templates[$template]["dir_name"])) { + die("Template " . $template . " not found."); + } + + $this->template = $template; + } + + function getTemplate() { + // Call API + $call = new APICall("template/get.php"); + $response = $call->response; + + if ($response["status"] !== 200) { + $this->setTemplate("standard"); + $this->showError("Template API Returned an error: " . $response["error_text"]); + } + + $this->template = $response["data"]["template_name"]; + } + + function setPage($page) { + $this->page = $page; } function showError($error) { - $file = file_get_contents(TEMPLATE_CONF); - $json = json_decode($file, true); + $template_dir = $this->templates[$this->template]["dir_name"]; + $template_conf = json_decode(file_get_contents(TEMPLATE_DIR . $template_dir)); - $page = $json["error"]; + $page = $tempalte_conf["error"]; $html = file_get_contents(TEMPLATE_PATH . $page["dir_name"] . "/" . $page["html_file"]); $css = ""; @@ -35,12 +57,12 @@ class HTMLLoader { // Get CSS foreach ($page["css_files"] as $file) { // Check if File exists - if (!is_file(TEMPLATE_PATH . $page["dir_name"] . "/" . $file)) { - $this->showError('CSS File ' . $file . ' for Template error in ' . __FILE__ . " not found."); + if (!is_file(TEMPLATE_PATH . $template_dir . "/" . $page["dir_name"] . "/" . $file)) { + die("CSS File " . $file . " not found."); } // Add CSS Files to HTML - $css .= ''; + $css .= ''; } $html = str_replace("%css%", $css, $html); @@ -51,32 +73,42 @@ class HTMLLoader { die($replace); } - function show($args = []) { + function show($args = [], $showAppName = true) { + if (!isset($this->template)) { + $this->getTemplate(); + } + $template = $this->template; - $file = file_get_contents(TEMPLATE_CONF); - $json = json_decode($file, true); + $template_dir = $this->templates[$template]["dir_name"]; + $template_conf = TEMPLATE_PATH . $template_dir . "/template.json"; - $page = $json[$template]; - $html = file_get_contents(TEMPLATE_PATH . $page["dir_name"] . "/" . $page["html_file"]); + $file = file_get_contents($template_conf); + $tempalte_conf = json_decode($file, true); - $app_name = file_get_contents("http://" . APP_DOMAIN . "/api/settings/appname.php"); - $app_name = json_decode($app_name, true); - $app_name = $app_name["data"]["application_name"]; + $page = $tempalte_conf[$this->page]; - $html = str_replace("%appname%", $app_name, $html); + $html = file_get_contents(TEMPLATE_PATH . $template_dir . "/" . $page["dir_name"] . "/" . $page["html_file"]); + + if ($showAppName) { + $app_name = file_get_contents("http://" . APP_DOMAIN . "/api/settings/appname.php"); + $app_name = json_decode($app_name, true); + $app_name = $app_name["data"]["application_name"]; + + $html = str_replace("%appname%", $app_name, $html); + } // Get CSS $css = ""; foreach ($page["css_files"] as $file) { // Check if File exists - if (!is_file(TEMPLATE_PATH . $page["dir_name"] . "/" . $file)) { + if (!is_file(TEMPLATE_PATH . $template_dir . "/" . $page["dir_name"] . "/" . $file)) { $this->showError('CSS File ' . $file . ' for Template ' . $this->template . ' in ' . __FILE__ . " not found."); } // Add CSS Files to HTML - $css .= ''; + $css .= ''; } $html = str_replace("%css%", $css, $html); diff --git a/public/index.php b/public/index.php index 18b703e..3814bc7 100755 --- a/public/index.php +++ b/public/index.php @@ -13,12 +13,11 @@ require FRONTEND_PATH . "html_loader.php"; $htmlLoader = new HTMLLoader(); // Build Entry Page -$htmlLoader->setTemplate("entrys_frontend"); +$htmlLoader->setPage("entrys_frontend"); -$url = "http://" . APP_DOMAIN . "/api/entrys/get.php"; -$response = file_get_contents($url); - -$response = json_decode($response, true); +// Get entrys +$call = new APICall("entrys/get.php"); +$response = $call->response; if ($response["data"]["empty"]) { $html_block = "

There aren'n any entrys yet. Be the first one!

"; diff --git a/public/main.php b/public/main.php index bd99aaf..0352dc9 100755 --- a/public/main.php +++ b/public/main.php @@ -12,7 +12,7 @@ class gb { define("APP_DOMAIN", $_SERVER["SERVER_NAME"]); define("APP_PATH", __DIR__ . "/../"); define("FRONTEND_PATH", __DIR__ . "/"); - define("API_PATH", __DIR__ . "/../api/"); + define("API_DIR", __DIR__ . "/../api/"); define("TEMPLATE_PATH", FRONTEND_PATH . "templates/"); define("TEMPLATE_CONF", TEMPLATE_PATH . "templates.json"); @@ -28,29 +28,30 @@ class gb { $html = new HTMLLoader(); // Set template to Setup an show it - $html->setTemplate("setup"); - $html->show(); + $html->setTemplate("standard"); + $html->setPage("setup"); + $html->show([], false); } } // Internal API Call Library class APICall { - private $response; + public $response; private $error; - function __construct($path, $data) { + function __construct($path, $data = []) { // Set $internal to true so the api return does not go to the browser $internal = true; // Check Path - if (!is_file(API_PATH . $path)) { + if (!is_file(API_DIR . $path)) { $this->error("API Path invalid."); return false; } // Call API - require API_PATH . $path; + require API_DIR . $path; // Get return from the API Library $response = $api->getAnswer();