From bf552e87ccafa72b604484cf21d90f4de602d163 Mon Sep 17 00:00:00 2001 From: marc-go Date: Thu, 8 Oct 2026 14:50:59 +0200 Subject: [PATCH] Enhance token generation: include expiration in cookie token and improve authentication checks --- api/api.php | 53 +++++++++++++++++++++++++++++++++++---------- api/auth/login.php | 25 +++++++++++---------- database.db | Bin 24576 -> 24576 bytes public/test.php | 4 +++- 4 files changed, 58 insertions(+), 24 deletions(-) diff --git a/api/api.php b/api/api.php index 562bdc1..0cd0f67 100755 --- a/api/api.php +++ b/api/api.php @@ -36,12 +36,14 @@ class gbAPI { // Generate Token $payload = [ "user" => $username, - "auth" => true + "auth" => true, + "exp" => $config["COOKIE_TOKEN_LIFETIME"] ]; - $string = json_encode($payload); + $string = base64_encode(json_encode($payload)); $secret = $config["COOKIE_TOKEN_SIGNATURE"]; - return hash_hmac("sha256", $string, $secret); + $sig = hash_hmac("sha256", $string, $secret); + return base64_encode(json_encode($payload)) . "." . $sig; } function generateAPIToken($username) { @@ -52,10 +54,11 @@ class gbAPI { "user" => $username, "auth" => true ]; - $string = json_encode($payload); + $string = base64_encode(json_encode($payload)); $secret = $config["API_TOKEN_SIGNATURE"]; - return hash_hmac("sha256", $string, $secret); + $sig = hash_hmac("sha256", $string, $secret); + return base } function checkAuth() { @@ -69,7 +72,14 @@ class gbAPI { $result = hash_equals($expected, $given); if ($result) { - return true; + $given_string = explode(".", $given); + $body = json_decode(base64_decode($given_string[0])); + + if ($body["exp"] > time()) { + return true; + }else{ + return false; + } } }elseif (isset($_SERVER["HTTP_X_API_KEY"])) { // Decode Token @@ -88,14 +98,28 @@ class gbAPI { return false; } - function answer($status, $data = []) { + function answer($status, $data = [], $error = false) { http_response_code($status); - Header ("Content-Type: application/json; charset=UTF-8"); + header("Content-Type: application/json; charset=UTF-8"); - $data = json_encode($data); - $json = '{"status":' . $status . ',"data":' . $data . '}'; - die($json); + if ($error) { + $json = []; + + $json["status"] = $status; + + foreach ($data as $key => $value) { + $json[$key] = $value; + } + }else{ + $json = [ + "status" => $status, + "data" => $data + ]; + } + + $return = json_encode($json); + die($return); } function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) { @@ -106,6 +130,13 @@ class gbAPI { $db_name = $config["DB_FILE"]; $db_path = APP_PATH . $db_name; + if (!is_file($db_path)) { + $api->answer(500, [ + "error" => "database_not_found", + "error_display" => "The Database was not found." + ], true); + } + $db = new PDO("sqlite:" . $db_path); $db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); } diff --git a/api/auth/login.php b/api/auth/login.php index 3a9f176..910d3a0 100755 --- a/api/auth/login.php +++ b/api/auth/login.php @@ -9,42 +9,43 @@ if ($_SERVER["REQUEST_METHOD"] !== "POST") { $api->answer(400, [ "error" => "false_request_method", "error_text" => "Only POST allowed" - ]); + ], true); } -if (!isset($_POST["username"]) || !isset($_POST["password"])) { +$input = json_decode(file_get_contents("php://input"), true); + +if (!isset($input["username"]) || !isset($input["password"])) { $api->answer(400, [ "error" => "missing_fields", "error_text" => "Some fields are missing" - ]); + ], true); } -$username = $_POST["username"]; -$password = $_POST["password"]; +$username = $input["username"]; +$password = $input["password"]; // Prepare SQL Command -$hash = password_hash($password, PASSWORD_DEFAULT); - -$command = "SELECT username, password FROM users WHERE username = :username AND password = :password"; +$command = "SELECT username, password FROM users WHERE username = :username"; $args = [ - ":username" => $username, - ":password" => $hash + ":username" => $username ]; // Execute SQL Command $result = $api->dbCommand($command, true, true, $args); // Check Result -if ($result && password_verify($password, $result["password"])) { +if ($result && password_verify($password, $result[0]["password"])) { // Login successful. Generate Auth Token $token = $api->generateCookieToken($username); // Set cookies setcookie("auth_token", $token, time() + 86400, "/"); setcookie("username", $username, time() + 86400, "/"); + + $api->answer(200); }else{ $api->answer(401, [ "error" => "unauthorized", "error_text" => "A user with this password does not exists." - ]); + ], true); } \ No newline at end of file diff --git a/database.db b/database.db index 68f1cac33196670b83fe24a1eeb9b0ad6d567f41..cd77c7b8040f71d29412e6f77924e4b4417963c0 100755 GIT binary patch delta 112 zcmZoTz}Rqrae_3Xz(g5mMuCk9?e>hUlV8}&vF&8wzstXKv!KFSes?8SHU?2~V@}`1 tqU4g);u0ex10yqCLjzp{3k5?%D^o)&6LUotpc+vmHRwu=O&0|S007IY9Fzb6 delta 94 zcmZoTz}Rqrae_1>&qNt#MxKoc?e>h!lV8}&v7Kh%f5v}$v!KF$ep5+iHU?2~MNZ$u hqU4g);u0eRb3H=?JtG4nGYKZ3lqf<9A+snz008vv81w)D diff --git a/public/test.php b/public/test.php index 74c5f6e..c85de7b 100755 --- a/public/test.php +++ b/public/test.php @@ -15,4 +15,6 @@ //print_r(PDO::getAvailableDrivers()); -print_r(json_decode('{"entrys":[{"name":"marc"}]}', true)); \ No newline at end of file +//print_r(json_decode('{"entrys":[{"name":"marc"}]}', true)); + +print_r(explode(".", "jakob.stinkt")); \ No newline at end of file