checkAuth()) { $status = 401; $data = [ "error" => "unauthorized", "error_text" => "Authentication failed." ]; $this->answer($status, $data); } } } function getConfig() { if (isset($this->config)) { return $config; }else{ return parse_ini_file(APP_PATH . ".env"); } } function generateCookieToken($username) { $config = $this->getConfig(); // Generate Token $payload = [ "user" => $username, "auth" => true, "exp" => time() + $config["COOKIE_TOKEN_LIFETIME"] ]; $string = $this->b64url_encode(json_encode($payload)); $secret = $config["COOKIE_TOKEN_SIGNATURE"]; $sig = hash_hmac("sha256", $string, $secret); return $string . "." . $sig; } function generateAPIToken($username) { $config = $this->getConfig(); // Generate Token $payload = [ "user" => $username, "auth" => true ]; $string = $this->b64url_encode(json_encode($payload)); $secret = $config["API_TOKEN_SIGNATURE"]; $sig = hash_hmac("sha256", $string, $secret); return $string . "." . $sig; } function checkAuth() { if (isset($_COOKIE["auth_token"])) { // Get Config $config = $this->getConfig(); // Check Token $given = $_COOKIE["auth_token"]; if (!is_string($given)) { return false; } $given_string = explode(".", $given); if (count($given_string) !== 2) { return false; } $sig_expected = hash_hmac("sha256", $given_string[0], $config["COOKIE_TOKEN_SIGNATURE"]); @$result = hash_equals($sig_expected, $given_string[1]); if ($result) { $body = json_decode($this->b64url_decode($given_string[0]), true); if ($body["exp"] > time()) { $this->username = $body["user"]; return true; }else{ return false; } }else{ return false; } }elseif (isset($_SERVER["HTTP_X_API_KEY"])) { // Get config $config = $this->getConfig(); // Decode Token $given = $_SERVER["HTTP_X_API_KEY"]; if (!is_string($given)) { return false; } $given_string = explode(".", $given); if (count($given_string) !== 2) { return false; } $sig_expected = hash_hmac("sha256", $given_string[0], $config["API_TOKEN_SIGNATURE"]); @$result = hash_equals($sig_expected, $given_string[1]); } return false; } function answer($status, $data = [], $error = false) { http_response_code($status); header("Content-Type: application/json; charset=UTF-8"); if ($error) { $json = []; $json["status"] = $status; foreach ($data as $key => $value) { $json[$key] = $value; } }else{ $json = [ "status" => $status, "data" => $data ]; } $return = json_encode($json); die($return); } function dbCommand($command, $expectResult, $stmtArgsRequired = false, $stmtArgs = []) { if (isset($this->db)) { $db = $this->db; }else{ $config = $this->getConfig(); $db_name = $config["DB_FILE"]; $db_path = APP_PATH . $db_name; if (!is_file($db_path)) { $api->answer(500, [ "error" => "database_not_found", "error_display" => "The Database was not found." ], true); } $db = new PDO("sqlite:" . $db_path); $db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); } $stmt = $db->prepare($command); $stmt->execute($stmtArgs); if ($expectResult) { $result = $stmt->fetchAll(PDO::FETCH_ASSOC); return $result; } } function getSetting($key) { $command = "SELECT name, value FROM settings WHERE name = :name"; $value = $this->dbCommand($command, true, true, [":name" => $key]); return $value; } }