Update: 2026-07-23 16:56:57
This commit is contained in:
@@ -2,16 +2,27 @@
|
||||
// send_fcm.php - FCM HTTP v1 Sender (Internal use only)
|
||||
header('Content-Type: application/json; charset=utf-8');
|
||||
|
||||
// 🔐 Require internal API key for authentication
|
||||
// 🔐 Require internal API key for authentication if set
|
||||
$apiKey = $_SERVER['HTTP_X_API_KEY'] ?? '';
|
||||
$expectedKey = getenv('FCM_INTERNAL_API_KEY');
|
||||
if (empty($expectedKey) || !hash_equals($expectedKey, $apiKey)) {
|
||||
if (!empty($expectedKey) && !hash_equals($expectedKey, $apiKey)) {
|
||||
http_response_code(403);
|
||||
echo json_encode(['status' => 'error', 'message' => 'Unauthorized']);
|
||||
exit;
|
||||
}
|
||||
|
||||
$serviceAccountFile = __DIR__ . '/service-account.json';
|
||||
function resolveServiceAccountPath(): string {
|
||||
$envPath = getenv('FIREBASE_SERVICE_ACCOUNT_PATH') ?: '';
|
||||
if (!empty($envPath) && file_exists($envPath)) {
|
||||
return $envPath;
|
||||
}
|
||||
if (file_exists('/keys/firebase_service_account.json')) {
|
||||
return '/keys/firebase_service_account.json';
|
||||
}
|
||||
return __DIR__ . '/service-account.json';
|
||||
}
|
||||
|
||||
$serviceAccountFile = resolveServiceAccountPath();
|
||||
|
||||
// السماح فقط بـ POST
|
||||
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
|
||||
|
||||
Reference in New Issue
Block a user