Implement user authentication and registration; enhance error handling and database interaction in API
This commit is contained in:
1 parent
2ac799d0a4
commit
c50c1bd122
6 files changed
+162
-15
No files matched your search
@@ -0,0 +1 @@
|
||||
TOKEN_SIGNATURE=281361f952279bd9530734c67ed04aed2756f0fe00cb998cd6c28324f491484c
|
||||
+64
-11
@@ -1,13 +1,19 @@
|
||||
<?php
|
||||
// API Main Library
|
||||
class gbAPI {
|
||||
public $authRequired;
|
||||
|
||||
function __construct() {
|
||||
function __construct($authRequired) {
|
||||
define("APP_PATH", __DIR__ . "/../");
|
||||
|
||||
if ($this->authRequited) {
|
||||
$this->checkAuth();
|
||||
if ($authRequired) {
|
||||
if (!$this->checkAuth()) {
|
||||
$status = 401;
|
||||
$data = [
|
||||
"error" => "unauthorized",
|
||||
"error_text" => "Authentication failed."
|
||||
];
|
||||
|
||||
$this->answer($status, $data);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -15,26 +21,73 @@ class gbAPI {
|
||||
return parse_ini_file(APP_PATH . ".env");
|
||||
}
|
||||
|
||||
function generateToken() {
|
||||
function generateToken($username) {
|
||||
$config = $this->getConfig();
|
||||
|
||||
// Generate Token
|
||||
$token = bin2hex(random_bytes(32));
|
||||
$secret = $config["COOKIE_SIGNATURE"];
|
||||
$payload = [
|
||||
"user" => $username,
|
||||
"auth" => true
|
||||
];
|
||||
$string = json_encode($payload);
|
||||
$secret = $config["TOKEN_SIGNATURE"];
|
||||
|
||||
return hash_hmac('sha256', $token, SECRET, true);
|
||||
return hash_hmac("sha256", $string, $secret);
|
||||
}
|
||||
|
||||
function checkAuth() {
|
||||
if (isset($_SERVER))
|
||||
if (!isset($_SERVER["HTTP_X_API_KEY"]) && !isset($_COOKIE["auth_token"])) {
|
||||
return false;
|
||||
}elseif (isset($_COOKIE["auth_token"]) && isset($_COOKIE["username"])) {
|
||||
// Check Token
|
||||
$username = $_COOKIE["username"];
|
||||
$expected = $this->generateToken($username);
|
||||
$given = $_COOKIE["auth_token"];
|
||||
|
||||
$result = hash_equals($expected, $give);
|
||||
if ($result) {
|
||||
return true;
|
||||
}
|
||||
}elseif (isset($_SERVER["HTTP_X_API_KEY"])) {
|
||||
// Decode Token
|
||||
$payload = json_decode(base64_decode($_SERVER["HTTP_X_API_KEY"]), true);
|
||||
$username = $payload["username"];
|
||||
|
||||
$given = $payload["auth_token"];
|
||||
$expected = $this->generateToken($username);
|
||||
|
||||
$result = hash_equals($expected, $given);
|
||||
if ($result) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
function answer($status, $data) {
|
||||
http_response_code($status);
|
||||
Header ("Content-Type: application/json; charset=UTF-8");
|
||||
|
||||
$data = json_encode($data);
|
||||
|
||||
$json = '{"status":' . $status . ',"data":' $data . '}';
|
||||
$json = '{"status":' . $status . ',"data":' . $data . '}';
|
||||
die($json);
|
||||
}
|
||||
|
||||
function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) {
|
||||
$db_path = APP_PATH . "database.db";
|
||||
|
||||
$db = new PDO("sqlite:" . $db_path);
|
||||
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
|
||||
|
||||
$stmt = $db->prepare($command);
|
||||
$stmt->execute($stmtArgs);
|
||||
|
||||
if ($expectResult) {
|
||||
$result = $stmt->fetch(PDO::FETCH_ASSOC);
|
||||
|
||||
return $result;
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,50 @@
|
||||
<?php
|
||||
// Load API Library
|
||||
require "../api.php";
|
||||
|
||||
$api = new gbAPI(false);
|
||||
|
||||
// Check Request Body
|
||||
if ($_SERVER["REQUEST_METHOD"] !== "POST") {
|
||||
$api->answer(400, [
|
||||
"error" => "false_request_method",
|
||||
"error_text" => "Only POST allowed"
|
||||
]);
|
||||
}
|
||||
|
||||
if (!isset($_POST["username"]) || !isset($_POST["password"])) {
|
||||
$api->answer(400, [
|
||||
"error" => "missing_fields",
|
||||
"error_text" => "Some fields are missing"
|
||||
]);
|
||||
}
|
||||
|
||||
$username = $_POST["username"];
|
||||
$password = $_POST["password"];
|
||||
|
||||
// Prepare SQL Command
|
||||
$hash = hash("sha256", $password);
|
||||
|
||||
$command = "SELECT username, password FROM users WHERE username = :username AND password = :password";
|
||||
$args = [
|
||||
":username" => $username,
|
||||
":password" => $password
|
||||
];
|
||||
|
||||
// Execute SQL Command
|
||||
$result = $api->dbCommand($command, true, true, $args);
|
||||
|
||||
// Check Result
|
||||
if ($result) {
|
||||
// Login successful. Generate Auth Token
|
||||
$token = $api->generateToken($username);
|
||||
|
||||
// Set cookies
|
||||
setcookie("auth_token", $token, time() + 86400, "/");
|
||||
setcookie("username", $username, time() + 86400, "/");
|
||||
}else{
|
||||
$api->answer(401, [
|
||||
"error" => "unauthorized",
|
||||
"error_text" => "A user with this password does not exists."
|
||||
]);
|
||||
}
|
||||
+36
-1
@@ -2,4 +2,39 @@
|
||||
// Load Main Libary
|
||||
require "../api.php";
|
||||
|
||||
bin2hex(random_bytes(32))
|
||||
$api = new gbAPI(true);
|
||||
|
||||
// Check Request body
|
||||
if ($_SERVER["REQUEST_METHOD"] !== "POST") {
|
||||
$api->answer(400, [
|
||||
"error" => "false_request_method",
|
||||
"error_text" => "Only POST allowed"
|
||||
]);
|
||||
}
|
||||
|
||||
if (!isset($_POST["username"]) || !isset($_POST["password"]) || !isset($_POST["password_repeat"])) {
|
||||
$api->answer(400, [
|
||||
"error" => "missing_fields",
|
||||
"error_text" => "Some fields are missing"
|
||||
]);
|
||||
}
|
||||
|
||||
$username = $_POST["username"];
|
||||
$password = $_POST["password"];
|
||||
$password_repeat = $_POST["password_repeat"];
|
||||
|
||||
// Check Passwords
|
||||
if ($password !== $password_repeat) {
|
||||
$api->answer(400, [
|
||||
"error" => "passwords_dont_match",
|
||||
"error_text" => "The passwords does not match."
|
||||
]);
|
||||
}
|
||||
|
||||
// Hash Password
|
||||
$hash = hash("sha256", $password);
|
||||
|
||||
|
||||
|
||||
// CREATE DATABASE STRUCTURE
|
||||
file_get_contents(APP_PATH . "db_structure.sql");
|
||||
@@ -100,7 +100,8 @@
|
||||
method: "POST",
|
||||
body: JSON.stringify({
|
||||
username: username,
|
||||
password: password
|
||||
password: password,
|
||||
password_repeat: password_repeat
|
||||
}),
|
||||
headers: {
|
||||
"Content-type": "application/json; charset=UTF-8"
|
||||
|
||||
+9
-2
@@ -1,7 +1,14 @@
|
||||
<?php
|
||||
|
||||
foreach($_SERVER as $key => $value) {
|
||||
/*foreach($_SERVER as $key => $value) {
|
||||
echo $key . " === " . $value . "<br>";
|
||||
}
|
||||
}*/
|
||||
|
||||
//echo $_SERVER["HTTP_X_API_KEY"];
|
||||
|
||||
$string = '{"user":"marc", "auth":true}';
|
||||
$secret = "281361f952279bd9530734c67ed04aed2756f0fe00cb998cd6c28324f491484c";
|
||||
|
||||
echo "Hash: " . hash_hmac("sha256", $string, $secret);
|
||||
|
||||
echo "Decode: " . hash_equals($string, $secret);
|
||||
Reference in new issue
Block a user