Enhance token generation: include expiration in cookie token and improve authentication checks
This commit is contained in:
1 parent
fd1b8d9a0b
commit
bf552e87cc
4 files changed
+58
-24
No files matched your search
+42
-11
@@ -36,12 +36,14 @@ class gbAPI {
|
||||
// Generate Token
|
||||
$payload = [
|
||||
"user" => $username,
|
||||
"auth" => true
|
||||
"auth" => true,
|
||||
"exp" => $config["COOKIE_TOKEN_LIFETIME"]
|
||||
];
|
||||
$string = json_encode($payload);
|
||||
$string = base64_encode(json_encode($payload));
|
||||
$secret = $config["COOKIE_TOKEN_SIGNATURE"];
|
||||
|
||||
return hash_hmac("sha256", $string, $secret);
|
||||
$sig = hash_hmac("sha256", $string, $secret);
|
||||
return base64_encode(json_encode($payload)) . "." . $sig;
|
||||
}
|
||||
|
||||
function generateAPIToken($username) {
|
||||
@@ -52,10 +54,11 @@ class gbAPI {
|
||||
"user" => $username,
|
||||
"auth" => true
|
||||
];
|
||||
$string = json_encode($payload);
|
||||
$string = base64_encode(json_encode($payload));
|
||||
$secret = $config["API_TOKEN_SIGNATURE"];
|
||||
|
||||
return hash_hmac("sha256", $string, $secret);
|
||||
$sig = hash_hmac("sha256", $string, $secret);
|
||||
return base
|
||||
}
|
||||
|
||||
function checkAuth() {
|
||||
@@ -69,7 +72,14 @@ class gbAPI {
|
||||
|
||||
$result = hash_equals($expected, $given);
|
||||
if ($result) {
|
||||
return true;
|
||||
$given_string = explode(".", $given);
|
||||
$body = json_decode(base64_decode($given_string[0]));
|
||||
|
||||
if ($body["exp"] > time()) {
|
||||
return true;
|
||||
}else{
|
||||
return false;
|
||||
}
|
||||
}
|
||||
}elseif (isset($_SERVER["HTTP_X_API_KEY"])) {
|
||||
// Decode Token
|
||||
@@ -88,14 +98,28 @@ class gbAPI {
|
||||
return false;
|
||||
}
|
||||
|
||||
function answer($status, $data = []) {
|
||||
function answer($status, $data = [], $error = false) {
|
||||
http_response_code($status);
|
||||
Header ("Content-Type: application/json; charset=UTF-8");
|
||||
header("Content-Type: application/json; charset=UTF-8");
|
||||
|
||||
$data = json_encode($data);
|
||||
|
||||
$json = '{"status":' . $status . ',"data":' . $data . '}';
|
||||
die($json);
|
||||
if ($error) {
|
||||
$json = [];
|
||||
|
||||
$json["status"] = $status;
|
||||
|
||||
foreach ($data as $key => $value) {
|
||||
$json[$key] = $value;
|
||||
}
|
||||
}else{
|
||||
$json = [
|
||||
"status" => $status,
|
||||
"data" => $data
|
||||
];
|
||||
}
|
||||
|
||||
$return = json_encode($json);
|
||||
die($return);
|
||||
}
|
||||
|
||||
function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) {
|
||||
@@ -106,6 +130,13 @@ class gbAPI {
|
||||
$db_name = $config["DB_FILE"];
|
||||
$db_path = APP_PATH . $db_name;
|
||||
|
||||
if (!is_file($db_path)) {
|
||||
$api->answer(500, [
|
||||
"error" => "database_not_found",
|
||||
"error_display" => "The Database was not found."
|
||||
], true);
|
||||
}
|
||||
|
||||
$db = new PDO("sqlite:" . $db_path);
|
||||
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user