Files
better_guestbook/api/setup/save.php
T

107 lines
2.6 KiB
PHP
Executable File

<?php
// Load Main Libary
require "../api.php";
$api = new gbAPI(false);
// Check Request body
if ($_SERVER["REQUEST_METHOD"] !== "POST") {
$api->answer(400, [
"error" => "false_request_method",
"error_text" => "Only POST allowed"
]);
}
$input = json_decode(file_get_contents("php://input"), true);
if (!isset($input["username"]) || !isset($input["password"]) || !isset($input["password_repeat"])) {
$api->answer(400, [
"error" => "missing_fields",
"error_text" => "Some fields are missing"
]);
}
// Check if application already configurated
if (is_file(APP_PATH . "database.db")) {
$api->answer(503, [
"error" => "already_configurated",
"error_text" => "The application is already configurated."
]);
}
// Check PDO drivers
if (!extension_loaded("pdo_sqlite") || !extension_loaded("sqlite3")) {
$api->answer(500, [
"error" => "missing_drives",
"error_text" => "Please install the extensions pdo_sqlite and sqlite3."
]);
}
$username = $input["username"];
$password = $input["password"];
$password_repeat = $input["password_repeat"];
// Check Passwords
if ($password !== $password_repeat) {
$api->answer(400, [
"error" => "passwords_dont_match",
"error_text" => "The passwords does not match."
]);
}
// Hash Password
$hash = password_hash($password, PASSWORD_DEFAULT);
// CREATE DATABASE STRUCTURE
$sql_file = file_get_contents(APP_PATH . "db_structure.sql");
$db_path = APP_PATH . "database.db";
$db = new PDO("sqlite:" . $db_path);
$db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
$db->exec($sql_file);
// INSERT USER
$command = "INSERT INTO users (username, password, owner) VALUES (:username, :password, :owner)";
$stmt = $db->prepare($command);
$stmt->execute([":username" => $username, ":password" => $hash, ":owner" => 1]);
// INSERT SETTINGS
$command = "INSERT INTO settings (name, value) VALUES (:name, :value)";
$settings = [
"application_name" => "Guestbook",
"allow_html" => "false",
"approve_entrys" => "true",
"allow_new_entrys" => "true"
];
foreach ($settings as $key => $value) {
$stmt = $db->prepare($command);
$stmt->execute([":name" => $key, ":value" => $value]);
}
// WRITE .env AND GENERATE SECRETS
$env = "";
$cookie_token = bin2hex(random_bytes(32));
$env .= "COOKIE_TOKEN_SIGNATURE=" . $cookie_token . "\n";
$api_token = bin2hex(random_bytes(32));
$env .= "API_TOKEN_SIGNATURE=" . $api_token . "\n";
$env .= "DB_FILE=database.db";
$env .= "COOKIE_TOKEN_LIFETIME=86400";
file_put_contents(APP_PATH . ".env", $env);
// RETURN SUCCESS MESSAGE
$api->answer(200);