Compare commits
5
Commits
master
...
3ad5f5bdd6
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3ad5f5bdd6 | ||
|
|
f5f42b73ee | ||
|
|
c50c1bd122 | ||
|
|
2ac799d0a4 | ||
|
|
06a4f9a6c0 |
No files matched your search
@@ -0,0 +1 @@
|
|||||||
|
TOKEN_SIGNATURE=281361f952279bd9530734c67ed04aed2756f0fe00cb998cd6c28324f491484c
|
||||||
Executable
+93
@@ -0,0 +1,93 @@
|
|||||||
|
<?php
|
||||||
|
// API Main Library
|
||||||
|
class gbAPI {
|
||||||
|
function __construct($authRequired) {
|
||||||
|
define("APP_PATH", __DIR__ . "/../");
|
||||||
|
|
||||||
|
if ($authRequired) {
|
||||||
|
if (!$this->checkAuth()) {
|
||||||
|
$status = 401;
|
||||||
|
$data = [
|
||||||
|
"error" => "unauthorized",
|
||||||
|
"error_text" => "Authentication failed."
|
||||||
|
];
|
||||||
|
|
||||||
|
$this->answer($status, $data);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function getConfig() {
|
||||||
|
return parse_ini_file(APP_PATH . ".env");
|
||||||
|
}
|
||||||
|
|
||||||
|
function generateToken($username) {
|
||||||
|
$config = $this->getConfig();
|
||||||
|
|
||||||
|
// Generate Token
|
||||||
|
$payload = [
|
||||||
|
"user" => $username,
|
||||||
|
"auth" => true
|
||||||
|
];
|
||||||
|
$string = json_encode($payload);
|
||||||
|
$secret = $config["TOKEN_SIGNATURE"];
|
||||||
|
|
||||||
|
return hash_hmac("sha256", $string, $secret);
|
||||||
|
}
|
||||||
|
|
||||||
|
function checkAuth() {
|
||||||
|
if (!isset($_SERVER["HTTP_X_API_KEY"]) && !isset($_COOKIE["auth_token"])) {
|
||||||
|
return false;
|
||||||
|
}elseif (isset($_COOKIE["auth_token"]) && isset($_COOKIE["username"])) {
|
||||||
|
// Check Token
|
||||||
|
$username = $_COOKIE["username"];
|
||||||
|
$expected = $this->generateToken($username);
|
||||||
|
$given = $_COOKIE["auth_token"];
|
||||||
|
|
||||||
|
$result = hash_equals($expected, $given);
|
||||||
|
if ($result) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}elseif (isset($_SERVER["HTTP_X_API_KEY"])) {
|
||||||
|
// Decode Token
|
||||||
|
$payload = json_decode(base64_decode($_SERVER["HTTP_X_API_KEY"]), true);
|
||||||
|
$username = $payload["username"];
|
||||||
|
|
||||||
|
$given = $payload["auth_token"];
|
||||||
|
$expected = $this->generateToken($username);
|
||||||
|
|
||||||
|
$result = hash_equals($expected, $given);
|
||||||
|
if ($result) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
function answer($status, $data) {
|
||||||
|
http_response_code($status);
|
||||||
|
Header ("Content-Type: application/json; charset=UTF-8");
|
||||||
|
|
||||||
|
$data = json_encode($data);
|
||||||
|
|
||||||
|
$json = '{"status":' . $status . ',"data":' . $data . '}';
|
||||||
|
die($json);
|
||||||
|
}
|
||||||
|
|
||||||
|
function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) {
|
||||||
|
$db_path = APP_PATH . "database.db";
|
||||||
|
|
||||||
|
$db = new PDO("sqlite:" . $db_path);
|
||||||
|
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
|
||||||
|
|
||||||
|
$stmt = $db->prepare($command);
|
||||||
|
$stmt->execute($stmtArgs);
|
||||||
|
|
||||||
|
if ($expectResult) {
|
||||||
|
$result = $stmt->fetch(PDO::FETCH_ASSOC);
|
||||||
|
|
||||||
|
return $result;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
Executable
+50
@@ -0,0 +1,50 @@
|
|||||||
|
<?php
|
||||||
|
// Load API Library
|
||||||
|
require "../api.php";
|
||||||
|
|
||||||
|
$api = new gbAPI(false);
|
||||||
|
|
||||||
|
// Check Request Body
|
||||||
|
if ($_SERVER["REQUEST_METHOD"] !== "POST") {
|
||||||
|
$api->answer(400, [
|
||||||
|
"error" => "false_request_method",
|
||||||
|
"error_text" => "Only POST allowed"
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!isset($_POST["username"]) || !isset($_POST["password"])) {
|
||||||
|
$api->answer(400, [
|
||||||
|
"error" => "missing_fields",
|
||||||
|
"error_text" => "Some fields are missing"
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
$username = $_POST["username"];
|
||||||
|
$password = $_POST["password"];
|
||||||
|
|
||||||
|
// Prepare SQL Command
|
||||||
|
$hash = hash("sha256", $password);
|
||||||
|
|
||||||
|
$command = "SELECT username, password FROM users WHERE username = :username AND password = :password";
|
||||||
|
$args = [
|
||||||
|
":username" => $username,
|
||||||
|
":password" => $hash
|
||||||
|
];
|
||||||
|
|
||||||
|
// Execute SQL Command
|
||||||
|
$result = $api->dbCommand($command, true, true, $args);
|
||||||
|
|
||||||
|
// Check Result
|
||||||
|
if ($result && password_verify($password, $result["password"])) {
|
||||||
|
// Login successful. Generate Auth Token
|
||||||
|
$token = $api->generateToken($username);
|
||||||
|
|
||||||
|
// Set cookies
|
||||||
|
setcookie("auth_token", $token, time() + 86400, "/");
|
||||||
|
setcookie("username", $username, time() + 86400, "/");
|
||||||
|
}else{
|
||||||
|
$api->answer(401, [
|
||||||
|
"error" => "unauthorized",
|
||||||
|
"error_text" => "A user with this password does not exists."
|
||||||
|
]);
|
||||||
|
}
|
||||||
Executable
+40
@@ -0,0 +1,40 @@
|
|||||||
|
<?php
|
||||||
|
// Load Main Libary
|
||||||
|
require "../api.php";
|
||||||
|
|
||||||
|
$api = new gbAPI(false);
|
||||||
|
|
||||||
|
// Check Request body
|
||||||
|
if ($_SERVER["REQUEST_METHOD"] !== "POST") {
|
||||||
|
$api->answer(400, [
|
||||||
|
"error" => "false_request_method",
|
||||||
|
"error_text" => "Only POST allowed"
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!isset($_POST["username"]) || !isset($_POST["password"]) || !isset($_POST["password_repeat"])) {
|
||||||
|
$api->answer(400, [
|
||||||
|
"error" => "missing_fields",
|
||||||
|
"error_text" => "Some fields are missing"
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
$username = $_POST["username"];
|
||||||
|
$password = $_POST["password"];
|
||||||
|
$password_repeat = $_POST["password_repeat"];
|
||||||
|
|
||||||
|
// Check Passwords
|
||||||
|
if ($password !== $password_repeat) {
|
||||||
|
$api->answer(400, [
|
||||||
|
"error" => "passwords_dont_match",
|
||||||
|
"error_text" => "The passwords does not match."
|
||||||
|
]);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Hash Password
|
||||||
|
$hash = password_hash($password);
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
// CREATE DATABASE STRUCTURE
|
||||||
|
file_get_contents(APP_PATH . "db_structure.sql");
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
CREATE TABLE IF NOT EXISTS "users" (
|
||||||
|
"id" INTEGER NOT NULL,
|
||||||
|
"username" VARCHAR NOT NULL,
|
||||||
|
"password" VARCHAR NOT NULL,
|
||||||
|
"owner" INTEGER NOT NULL,
|
||||||
|
PRIMARY KEY("id", "username", "owner")
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS "entrys" (
|
||||||
|
"id" INTEGER NOT NULL,
|
||||||
|
"name" VARCHAR NOT NULL,
|
||||||
|
"text" VARCHAR NOT NULL,
|
||||||
|
"status" INTEGER,
|
||||||
|
PRIMARY KEY("id")
|
||||||
|
);
|
||||||
Regular → Executable
-38
@@ -1,38 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
<head>
|
|
||||||
<link href="https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap" rel="stylesheet">
|
|
||||||
<script type="importmap">
|
|
||||||
{
|
|
||||||
"imports": {
|
|
||||||
"@material/web/": "https://esm.run/@material/web/"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</script>
|
|
||||||
<script type="module">
|
|
||||||
import '@material/web/all.js';
|
|
||||||
import {styles as typescaleStyles} from '@material/web/typography/md-typescale-styles.js';
|
|
||||||
|
|
||||||
document.adoptedStyleSheets.push(typescaleStyles.styleSheet);
|
|
||||||
</script>
|
|
||||||
|
|
||||||
<style>
|
|
||||||
body {
|
|
||||||
display: flex;
|
|
||||||
justify-content: center;
|
|
||||||
align-items: center;
|
|
||||||
text-align: center;
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
</head>
|
|
||||||
<body>
|
|
||||||
<div class="content">
|
|
||||||
<h1 class="md-typescale-display-medium">Hello!</h1>
|
|
||||||
<p>Welcome to your Guestbook! Enter here your prefered username and password.</p>
|
|
||||||
<md-filled-text-field label="Username" type="text"></md-filled-text-field><br><br>
|
|
||||||
<md-filled-text-field label="Password" type="password"></md-filled-text-field><br><br>
|
|
||||||
<md-filled-text-field label="Repeat Password" type="password"></md-filled-text-field><br><br>
|
|
||||||
<md-filled-button disabled>Save</md-filled-button>
|
|
||||||
</div>
|
|
||||||
</body>
|
|
||||||
</html>
|
|
||||||
Regular → Executable
File mode changed.
@@ -1,11 +1,122 @@
|
|||||||
<!DOCTYPE html>
|
<!DOCTYPE html>
|
||||||
<html lang="en">
|
<html lang="en">
|
||||||
<head>
|
<head>
|
||||||
<meta charset="UTF-8">
|
<link href="https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap" rel="stylesheet">
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
<script type="importmap">
|
||||||
<title>Setup</title>
|
{
|
||||||
|
"imports": {
|
||||||
|
"@material/web/": "https://esm.run/@material/web/"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
</script>
|
||||||
|
<script type="module">
|
||||||
|
import '@material/web/all.js';
|
||||||
|
import {styles as typescaleStyles} from '@material/web/typography/md-typescale-styles.js';
|
||||||
|
|
||||||
|
document.adoptedStyleSheets.push(typescaleStyles.styleSheet);
|
||||||
|
</script>
|
||||||
|
|
||||||
|
<title>Setup</title>
|
||||||
|
|
||||||
|
<style>
|
||||||
|
:root {
|
||||||
|
--md-sys-color-primary: rgb(58, 58, 255);
|
||||||
|
}
|
||||||
|
|
||||||
|
body {
|
||||||
|
display: flex;
|
||||||
|
justify-content: center;
|
||||||
|
align-items: center;
|
||||||
|
text-align: center;
|
||||||
|
}
|
||||||
|
|
||||||
|
p {
|
||||||
|
font-family: Verdana, Geneva, Tahoma, sans-serif;
|
||||||
|
}
|
||||||
|
</style>
|
||||||
</head>
|
</head>
|
||||||
<body>
|
<body>
|
||||||
<h1>La setup</h1>
|
<div class="content">
|
||||||
|
<h1 class="md-typescale-display-medium">Hello!</h1>
|
||||||
|
<p>Welcome to your Guestbook! Enter here your prefered username and password.</p>
|
||||||
|
<md-filled-text-field label="Username" type="text" id="setup-username"></md-filled-text-field><br><br>
|
||||||
|
<md-filled-text-field label="Password" type="password" id="setup-password"></md-filled-text-field><br><br>
|
||||||
|
<md-filled-text-field label="Repeat Password" type="password" id="setup-password-repeat"></md-filled-text-field><br><br>
|
||||||
|
<md-filled-button id="submit-button">Save</md-filled-button>
|
||||||
|
</div>
|
||||||
|
<md-dialog id="http-dialog">
|
||||||
|
<div slot="headline">
|
||||||
|
Warning
|
||||||
|
</div>
|
||||||
|
<form slot="content" method="dialog">
|
||||||
|
Your browser is using http instead of https. That means your connection is not encrypted and everyone in your network can read your credentials.
|
||||||
|
</form>
|
||||||
|
<div slot="actions">
|
||||||
|
<md-text-button id="http-dialog-close-button">I know what i'm doing!</md-text-button>
|
||||||
|
</div>
|
||||||
|
</md-dialog>
|
||||||
|
<md-dialog id="error-dialog">
|
||||||
|
<div slot="headline">
|
||||||
|
Error
|
||||||
|
</div>
|
||||||
|
<form slot="content" method="dialog" id="error-dialog-text">
|
||||||
|
|
||||||
|
</form>
|
||||||
|
<div slot="actions">
|
||||||
|
<md-filled-button id="close-button">Close</md-filled-button>
|
||||||
|
</div>
|
||||||
|
</md-dialog>
|
||||||
|
<script>
|
||||||
|
if (window.location.protocol == "http:") {
|
||||||
|
document.getElementById("http-dialog").setAttribute("open", "");
|
||||||
|
document.getElementById("http-dialog-close-button").addEventListener("click", function() {
|
||||||
|
document.getElementById("http-dialog").removeAttribute("open");
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
document.getElementById("submit-button").addEventListener("click", function() {
|
||||||
|
checkSetup();
|
||||||
|
});
|
||||||
|
|
||||||
|
document.getElementById("close-button").addEventListener("click", function() {
|
||||||
|
document.getElementById("error-dialog").removeAttribute("open");
|
||||||
|
})
|
||||||
|
|
||||||
|
function checkSetup() {
|
||||||
|
const username = document.getElementById("setup-username").value;
|
||||||
|
const password = document.getElementById("setup-password").value;
|
||||||
|
const password_repeat = document.getElementById("setup-password-repeat").value;
|
||||||
|
|
||||||
|
// Check if Passwords match
|
||||||
|
if (password !== password_repeat) {
|
||||||
|
console.error("Passwords does not match");
|
||||||
|
|
||||||
|
document.getElementById("error-dialog-text").innerHTML = "Passwords does not match";
|
||||||
|
document.getElementById("error-dialog").setAttribute("open", "");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Send data
|
||||||
|
fetch("/api/setup/save.php", {
|
||||||
|
method: "POST",
|
||||||
|
body: JSON.stringify({
|
||||||
|
username: username,
|
||||||
|
password: password,
|
||||||
|
password_repeat: password_repeat
|
||||||
|
}),
|
||||||
|
headers: {
|
||||||
|
"Content-type": "application/json; charset=UTF-8"
|
||||||
|
}
|
||||||
|
})
|
||||||
|
.then(response => response.json())
|
||||||
|
.then(data => function() {
|
||||||
|
if (data.status !== 200) {
|
||||||
|
console.error("Server returned following message: " + data.error);
|
||||||
|
|
||||||
|
document.getElementById("error-dialog-text").innerHTML = data.display_error;
|
||||||
|
document.getElementById("error-dialog").setAttribute("open", "");
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
</script>
|
||||||
</body>
|
</body>
|
||||||
</html>
|
</html>
|
||||||
+11
-2
@@ -1,5 +1,14 @@
|
|||||||
<?php
|
<?php
|
||||||
|
|
||||||
foreach($_SERVER as $key => $value) {
|
/*foreach($_SERVER as $key => $value) {
|
||||||
echo $key . " === " . $value . "<br>";
|
echo $key . " === " . $value . "<br>";
|
||||||
}
|
}*/
|
||||||
|
|
||||||
|
//echo $_SERVER["HTTP_X_API_KEY"];
|
||||||
|
|
||||||
|
$string = '{"user":"marc", "auth":true}';
|
||||||
|
$secret = "281361f952279bd9530734c67ed04aed2756f0fe00cb998cd6c28324f491484c";
|
||||||
|
|
||||||
|
echo "Hash: " . hash_hmac("sha256", $string, $secret);
|
||||||
|
|
||||||
|
echo "Decode: " . hash_equals($string, $secret);
|
||||||
Reference in new issue
Block a user