Implement user authentication and registration; enhance error handling and database interaction in API

This commit is contained in:
marc-go committed 2026-10-04 19:21:38 +02:00
1 parent 2ac799d0a4
commit c50c1bd122
6 files changed
+163 -16

No files matched your search

+50
View File
@@ -0,0 +1,50 @@
<?php
// Load API Library
require "../api.php";
$api = new gbAPI(false);
// Check Request Body
if ($_SERVER["REQUEST_METHOD"] !== "POST") {
$api->answer(400, [
"error" => "false_request_method",
"error_text" => "Only POST allowed"
]);
}
if (!isset($_POST["username"]) || !isset($_POST["password"])) {
$api->answer(400, [
"error" => "missing_fields",
"error_text" => "Some fields are missing"
]);
}
$username = $_POST["username"];
$password = $_POST["password"];
// Prepare SQL Command
$hash = hash("sha256", $password);
$command = "SELECT username, password FROM users WHERE username = :username AND password = :password";
$args = [
":username" => $username,
":password" => $password
];
// Execute SQL Command
$result = $api->dbCommand($command, true, true, $args);
// Check Result
if ($result) {
// Login successful. Generate Auth Token
$token = $api->generateToken($username);
// Set cookies
setcookie("auth_token", $token, time() + 86400, "/");
setcookie("username", $username, time() + 86400, "/");
}else{
$api->answer(401, [
"error" => "unauthorized",
"error_text" => "A user with this password does not exists."
]);
}