answer(400, [ "error" => "false_request_method", "error_text" => "Only POST allowed" ]); } if (!isset($_POST["username"]) || !isset($_POST["password"])) { $api->answer(400, [ "error" => "missing_fields", "error_text" => "Some fields are missing" ]); } $username = $_POST["username"]; $password = $_POST["password"]; // Prepare SQL Command $hash = hash("sha256", $password); $command = "SELECT username, password FROM users WHERE username = :username AND password = :password"; $args = [ ":username" => $username, ":password" => $hash ]; // Execute SQL Command $result = $api->dbCommand($command, true, true, $args); // Check Result if ($result && password_verify($password, $result["password"])) { // Login successful. Generate Auth Token $token = $api->generateToken($username); // Set cookies setcookie("auth_token", $token, time() + 86400, "/"); setcookie("username", $username, time() + 86400, "/"); }else{ $api->answer(401, [ "error" => "unauthorized", "error_text" => "A user with this password does not exists." ]); }