Implement user authentication and registration; enhance error handling and database interaction in API

This commit is contained in:
marc-go committed 2026-10-04 19:21:38 +02:00
1 parent 2ac799d0a4
commit c50c1bd122
6 files changed
+163 -16

No files matched your search

+1
View File
@@ -0,0 +1 @@
TOKEN_SIGNATURE=281361f952279bd9530734c67ed04aed2756f0fe00cb998cd6c28324f491484c
+64 -11
View File
@@ -1,13 +1,19 @@
<?php <?php
// API Main Library // API Main Library
class gbAPI { class gbAPI {
public $authRequired; function __construct($authRequired) {
function __construct() {
define("APP_PATH", __DIR__ . "/../"); define("APP_PATH", __DIR__ . "/../");
if ($this->authRequited) { if ($authRequired) {
$this->checkAuth(); if (!$this->checkAuth()) {
$status = 401;
$data = [
"error" => "unauthorized",
"error_text" => "Authentication failed."
];
$this->answer($status, $data);
}
} }
} }
@@ -15,26 +21,73 @@ class gbAPI {
return parse_ini_file(APP_PATH . ".env"); return parse_ini_file(APP_PATH . ".env");
} }
function generateToken() { function generateToken($username) {
$config = $this->getConfig(); $config = $this->getConfig();
// Generate Token // Generate Token
$token = bin2hex(random_bytes(32)); $payload = [
$secret = $config["COOKIE_SIGNATURE"]; "user" => $username,
"auth" => true
];
$string = json_encode($payload);
$secret = $config["TOKEN_SIGNATURE"];
return hash_hmac('sha256', $token, SECRET, true); return hash_hmac("sha256", $string, $secret);
} }
function checkAuth() { function checkAuth() {
if (isset($_SERVER)) if (!isset($_SERVER["HTTP_X_API_KEY"]) && !isset($_COOKIE["auth_token"])) {
return false;
}elseif (isset($_COOKIE["auth_token"]) && isset($_COOKIE["username"])) {
// Check Token
$username = $_COOKIE["username"];
$expected = $this->generateToken($username);
$given = $_COOKIE["auth_token"];
$result = hash_equals($expected, $give);
if ($result) {
return true;
}
}elseif (isset($_SERVER["HTTP_X_API_KEY"])) {
// Decode Token
$payload = json_decode(base64_decode($_SERVER["HTTP_X_API_KEY"]), true);
$username = $payload["username"];
$given = $payload["auth_token"];
$expected = $this->generateToken($username);
$result = hash_equals($expected, $given);
if ($result) {
return true;
}
}
return false;
} }
function answer($status, $data) { function answer($status, $data) {
http_response_code($status); http_response_code($status);
Header ("Content-Type: application/json; charset=UTF-8");
$data = json_encode($data); $data = json_encode($data);
$json = '{"status":' . $status . ',"data":' $data . '}'; $json = '{"status":' . $status . ',"data":' . $data . '}';
die($json); die($json);
} }
function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) {
$db_path = APP_PATH . "database.db";
$db = new PDO("sqlite:" . $db_path);
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
$stmt = $db->prepare($command);
$stmt->execute($stmtArgs);
if ($expectResult) {
$result = $stmt->fetch(PDO::FETCH_ASSOC);
return $result;
}
}
} }
+50
View File
@@ -0,0 +1,50 @@
<?php
// Load API Library
require "../api.php";
$api = new gbAPI(false);
// Check Request Body
if ($_SERVER["REQUEST_METHOD"] !== "POST") {
$api->answer(400, [
"error" => "false_request_method",
"error_text" => "Only POST allowed"
]);
}
if (!isset($_POST["username"]) || !isset($_POST["password"])) {
$api->answer(400, [
"error" => "missing_fields",
"error_text" => "Some fields are missing"
]);
}
$username = $_POST["username"];
$password = $_POST["password"];
// Prepare SQL Command
$hash = hash("sha256", $password);
$command = "SELECT username, password FROM users WHERE username = :username AND password = :password";
$args = [
":username" => $username,
":password" => $password
];
// Execute SQL Command
$result = $api->dbCommand($command, true, true, $args);
// Check Result
if ($result) {
// Login successful. Generate Auth Token
$token = $api->generateToken($username);
// Set cookies
setcookie("auth_token", $token, time() + 86400, "/");
setcookie("username", $username, time() + 86400, "/");
}else{
$api->answer(401, [
"error" => "unauthorized",
"error_text" => "A user with this password does not exists."
]);
}
+36 -1
View File
@@ -2,4 +2,39 @@
// Load Main Libary // Load Main Libary
require "../api.php"; require "../api.php";
bin2hex(random_bytes(32)) $api = new gbAPI(true);
// Check Request body
if ($_SERVER["REQUEST_METHOD"] !== "POST") {
$api->answer(400, [
"error" => "false_request_method",
"error_text" => "Only POST allowed"
]);
}
if (!isset($_POST["username"]) || !isset($_POST["password"]) || !isset($_POST["password_repeat"])) {
$api->answer(400, [
"error" => "missing_fields",
"error_text" => "Some fields are missing"
]);
}
$username = $_POST["username"];
$password = $_POST["password"];
$password_repeat = $_POST["password_repeat"];
// Check Passwords
if ($password !== $password_repeat) {
$api->answer(400, [
"error" => "passwords_dont_match",
"error_text" => "The passwords does not match."
]);
}
// Hash Password
$hash = hash("sha256", $password);
// CREATE DATABASE STRUCTURE
file_get_contents(APP_PATH . "db_structure.sql");
+2 -1
View File
@@ -100,7 +100,8 @@
method: "POST", method: "POST",
body: JSON.stringify({ body: JSON.stringify({
username: username, username: username,
password: password password: password,
password_repeat: password_repeat
}), }),
headers: { headers: {
"Content-type": "application/json; charset=UTF-8" "Content-type": "application/json; charset=UTF-8"
+10 -3
View File
@@ -1,7 +1,14 @@
<?php <?php
foreach($_SERVER as $key => $value) { /*foreach($_SERVER as $key => $value) {
echo $key . " === " . $value . "<br>"; echo $key . " === " . $value . "<br>";
} }*/
//echo $_SERVER["HTTP_X_API_KEY"]; //echo $_SERVER["HTTP_X_API_KEY"];
$string = '{"user":"marc", "auth":true}';
$secret = "281361f952279bd9530734c67ed04aed2756f0fe00cb998cd6c28324f491484c";
echo "Hash: " . hash_hmac("sha256", $string, $secret);
echo "Decode: " . hash_equals($string, $secret);