Enhance token generation: include expiration in cookie token and improve authentication checks
This commit is contained in:
1 parent
fd1b8d9a0b
commit
bf552e87cc
4 files changed
+58
-24
No files matched your search
+13
-12
@@ -9,42 +9,43 @@ if ($_SERVER["REQUEST_METHOD"] !== "POST") {
|
||||
$api->answer(400, [
|
||||
"error" => "false_request_method",
|
||||
"error_text" => "Only POST allowed"
|
||||
]);
|
||||
], true);
|
||||
}
|
||||
|
||||
if (!isset($_POST["username"]) || !isset($_POST["password"])) {
|
||||
$input = json_decode(file_get_contents("php://input"), true);
|
||||
|
||||
if (!isset($input["username"]) || !isset($input["password"])) {
|
||||
$api->answer(400, [
|
||||
"error" => "missing_fields",
|
||||
"error_text" => "Some fields are missing"
|
||||
]);
|
||||
], true);
|
||||
}
|
||||
|
||||
$username = $_POST["username"];
|
||||
$password = $_POST["password"];
|
||||
$username = $input["username"];
|
||||
$password = $input["password"];
|
||||
|
||||
// Prepare SQL Command
|
||||
$hash = password_hash($password, PASSWORD_DEFAULT);
|
||||
|
||||
$command = "SELECT username, password FROM users WHERE username = :username AND password = :password";
|
||||
$command = "SELECT username, password FROM users WHERE username = :username";
|
||||
$args = [
|
||||
":username" => $username,
|
||||
":password" => $hash
|
||||
":username" => $username
|
||||
];
|
||||
|
||||
// Execute SQL Command
|
||||
$result = $api->dbCommand($command, true, true, $args);
|
||||
|
||||
// Check Result
|
||||
if ($result && password_verify($password, $result["password"])) {
|
||||
if ($result && password_verify($password, $result[0]["password"])) {
|
||||
// Login successful. Generate Auth Token
|
||||
$token = $api->generateCookieToken($username);
|
||||
|
||||
// Set cookies
|
||||
setcookie("auth_token", $token, time() + 86400, "/");
|
||||
setcookie("username", $username, time() + 86400, "/");
|
||||
|
||||
$api->answer(200);
|
||||
}else{
|
||||
$api->answer(401, [
|
||||
"error" => "unauthorized",
|
||||
"error_text" => "A user with this password does not exists."
|
||||
]);
|
||||
], true);
|
||||
}
|
||||
Reference in new issue
Block a user