Enhance token generation: include expiration in cookie token and improve authentication checks
This commit is contained in:
1 parent
fd1b8d9a0b
commit
bf552e87cc
4 files changed
+57
-23
No files matched your search
+41
-10
@@ -36,12 +36,14 @@ class gbAPI {
|
|||||||
// Generate Token
|
// Generate Token
|
||||||
$payload = [
|
$payload = [
|
||||||
"user" => $username,
|
"user" => $username,
|
||||||
"auth" => true
|
"auth" => true,
|
||||||
|
"exp" => $config["COOKIE_TOKEN_LIFETIME"]
|
||||||
];
|
];
|
||||||
$string = json_encode($payload);
|
$string = base64_encode(json_encode($payload));
|
||||||
$secret = $config["COOKIE_TOKEN_SIGNATURE"];
|
$secret = $config["COOKIE_TOKEN_SIGNATURE"];
|
||||||
|
|
||||||
return hash_hmac("sha256", $string, $secret);
|
$sig = hash_hmac("sha256", $string, $secret);
|
||||||
|
return base64_encode(json_encode($payload)) . "." . $sig;
|
||||||
}
|
}
|
||||||
|
|
||||||
function generateAPIToken($username) {
|
function generateAPIToken($username) {
|
||||||
@@ -52,10 +54,11 @@ class gbAPI {
|
|||||||
"user" => $username,
|
"user" => $username,
|
||||||
"auth" => true
|
"auth" => true
|
||||||
];
|
];
|
||||||
$string = json_encode($payload);
|
$string = base64_encode(json_encode($payload));
|
||||||
$secret = $config["API_TOKEN_SIGNATURE"];
|
$secret = $config["API_TOKEN_SIGNATURE"];
|
||||||
|
|
||||||
return hash_hmac("sha256", $string, $secret);
|
$sig = hash_hmac("sha256", $string, $secret);
|
||||||
|
return base
|
||||||
}
|
}
|
||||||
|
|
||||||
function checkAuth() {
|
function checkAuth() {
|
||||||
@@ -69,7 +72,14 @@ class gbAPI {
|
|||||||
|
|
||||||
$result = hash_equals($expected, $given);
|
$result = hash_equals($expected, $given);
|
||||||
if ($result) {
|
if ($result) {
|
||||||
|
$given_string = explode(".", $given);
|
||||||
|
$body = json_decode(base64_decode($given_string[0]));
|
||||||
|
|
||||||
|
if ($body["exp"] > time()) {
|
||||||
return true;
|
return true;
|
||||||
|
}else{
|
||||||
|
return false;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}elseif (isset($_SERVER["HTTP_X_API_KEY"])) {
|
}elseif (isset($_SERVER["HTTP_X_API_KEY"])) {
|
||||||
// Decode Token
|
// Decode Token
|
||||||
@@ -88,14 +98,28 @@ class gbAPI {
|
|||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
function answer($status, $data = []) {
|
function answer($status, $data = [], $error = false) {
|
||||||
http_response_code($status);
|
http_response_code($status);
|
||||||
Header ("Content-Type: application/json; charset=UTF-8");
|
header("Content-Type: application/json; charset=UTF-8");
|
||||||
|
|
||||||
$data = json_encode($data);
|
|
||||||
|
|
||||||
$json = '{"status":' . $status . ',"data":' . $data . '}';
|
if ($error) {
|
||||||
die($json);
|
$json = [];
|
||||||
|
|
||||||
|
$json["status"] = $status;
|
||||||
|
|
||||||
|
foreach ($data as $key => $value) {
|
||||||
|
$json[$key] = $value;
|
||||||
|
}
|
||||||
|
}else{
|
||||||
|
$json = [
|
||||||
|
"status" => $status,
|
||||||
|
"data" => $data
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
$return = json_encode($json);
|
||||||
|
die($return);
|
||||||
}
|
}
|
||||||
|
|
||||||
function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) {
|
function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) {
|
||||||
@@ -106,6 +130,13 @@ class gbAPI {
|
|||||||
$db_name = $config["DB_FILE"];
|
$db_name = $config["DB_FILE"];
|
||||||
$db_path = APP_PATH . $db_name;
|
$db_path = APP_PATH . $db_name;
|
||||||
|
|
||||||
|
if (!is_file($db_path)) {
|
||||||
|
$api->answer(500, [
|
||||||
|
"error" => "database_not_found",
|
||||||
|
"error_display" => "The Database was not found."
|
||||||
|
], true);
|
||||||
|
}
|
||||||
|
|
||||||
$db = new PDO("sqlite:" . $db_path);
|
$db = new PDO("sqlite:" . $db_path);
|
||||||
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
|
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
|
||||||
}
|
}
|
||||||
|
|||||||
+13
-12
@@ -9,42 +9,43 @@ if ($_SERVER["REQUEST_METHOD"] !== "POST") {
|
|||||||
$api->answer(400, [
|
$api->answer(400, [
|
||||||
"error" => "false_request_method",
|
"error" => "false_request_method",
|
||||||
"error_text" => "Only POST allowed"
|
"error_text" => "Only POST allowed"
|
||||||
]);
|
], true);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!isset($_POST["username"]) || !isset($_POST["password"])) {
|
$input = json_decode(file_get_contents("php://input"), true);
|
||||||
|
|
||||||
|
if (!isset($input["username"]) || !isset($input["password"])) {
|
||||||
$api->answer(400, [
|
$api->answer(400, [
|
||||||
"error" => "missing_fields",
|
"error" => "missing_fields",
|
||||||
"error_text" => "Some fields are missing"
|
"error_text" => "Some fields are missing"
|
||||||
]);
|
], true);
|
||||||
}
|
}
|
||||||
|
|
||||||
$username = $_POST["username"];
|
$username = $input["username"];
|
||||||
$password = $_POST["password"];
|
$password = $input["password"];
|
||||||
|
|
||||||
// Prepare SQL Command
|
// Prepare SQL Command
|
||||||
$hash = password_hash($password, PASSWORD_DEFAULT);
|
$command = "SELECT username, password FROM users WHERE username = :username";
|
||||||
|
|
||||||
$command = "SELECT username, password FROM users WHERE username = :username AND password = :password";
|
|
||||||
$args = [
|
$args = [
|
||||||
":username" => $username,
|
":username" => $username
|
||||||
":password" => $hash
|
|
||||||
];
|
];
|
||||||
|
|
||||||
// Execute SQL Command
|
// Execute SQL Command
|
||||||
$result = $api->dbCommand($command, true, true, $args);
|
$result = $api->dbCommand($command, true, true, $args);
|
||||||
|
|
||||||
// Check Result
|
// Check Result
|
||||||
if ($result && password_verify($password, $result["password"])) {
|
if ($result && password_verify($password, $result[0]["password"])) {
|
||||||
// Login successful. Generate Auth Token
|
// Login successful. Generate Auth Token
|
||||||
$token = $api->generateCookieToken($username);
|
$token = $api->generateCookieToken($username);
|
||||||
|
|
||||||
// Set cookies
|
// Set cookies
|
||||||
setcookie("auth_token", $token, time() + 86400, "/");
|
setcookie("auth_token", $token, time() + 86400, "/");
|
||||||
setcookie("username", $username, time() + 86400, "/");
|
setcookie("username", $username, time() + 86400, "/");
|
||||||
|
|
||||||
|
$api->answer(200);
|
||||||
}else{
|
}else{
|
||||||
$api->answer(401, [
|
$api->answer(401, [
|
||||||
"error" => "unauthorized",
|
"error" => "unauthorized",
|
||||||
"error_text" => "A user with this password does not exists."
|
"error_text" => "A user with this password does not exists."
|
||||||
]);
|
], true);
|
||||||
}
|
}
|
||||||
BIN
Binary file not shown.
+3
-1
@@ -15,4 +15,6 @@
|
|||||||
|
|
||||||
//print_r(PDO::getAvailableDrivers());
|
//print_r(PDO::getAvailableDrivers());
|
||||||
|
|
||||||
print_r(json_decode('{"entrys":[{"name":"marc"}]}', true));
|
//print_r(json_decode('{"entrys":[{"name":"marc"}]}', true));
|
||||||
|
|
||||||
|
print_r(explode(".", "jakob.stinkt"));
|
||||||
Reference in new issue
Block a user