Connect Flutter phone auth and Android platform
This commit is contained in:
+26
-18
@@ -5,29 +5,37 @@
|
||||
*/
|
||||
|
||||
header('Content-Type: application/json');
|
||||
require_once 'Database.php';
|
||||
require_once 'AuthenticationHandler.php';
|
||||
header('Access-Control-Allow-Headers: Content-Type, Authorization, X-API-Key, X-Signature, X-Timestamp');
|
||||
require_once __DIR__ . '/Database.php';
|
||||
require_once __DIR__ . '/Config.php';
|
||||
require_once __DIR__ . '/AuthenticationHandler.php';
|
||||
require_once __DIR__ . '/JwtToken.php';
|
||||
require_once __DIR__ . '/ApiAuth.php';
|
||||
require_once dirname(__DIR__) . '/public/api/v1/_bootstrap.php';
|
||||
|
||||
try {
|
||||
$api_key = $_SERVER['HTTP_X_API_KEY'] ?? null;
|
||||
$signature = $_SERVER['HTTP_X_SIGNATURE'] ?? null;
|
||||
$timestamp = $_SERVER['HTTP_X_TIMESTAMP'] ?? null;
|
||||
|
||||
if (!$api_key || !$signature || !$timestamp) {
|
||||
throw new Exception('Unauthorized', 401);
|
||||
}
|
||||
|
||||
$auth = new AuthenticationHandler();
|
||||
$db = Database::getInstance();
|
||||
|
||||
// Verification (Using empty body for GET request signature)
|
||||
$authResult = $auth->validateHmacSignature($api_key, $signature, '', $timestamp);
|
||||
if (!$authResult['valid']) {
|
||||
throw new Exception($authResult['error'], 401);
|
||||
if (isset($_SERVER['HTTP_AUTHORIZATION']) && preg_match('/^Bearer\s+/i', $_SERVER['HTTP_AUTHORIZATION'])) {
|
||||
$user_id = ApiAuth::bearerClaims()['user_id'];
|
||||
} else {
|
||||
AppConfig::loadEnvironment();
|
||||
if (getenv('LEGACY_HMAC_ENABLED') !== 'true') {
|
||||
throw new Exception('Bearer authentication required', 401);
|
||||
}
|
||||
$api_key = $_SERVER['HTTP_X_API_KEY'] ?? null;
|
||||
$signature = $_SERVER['HTTP_X_SIGNATURE'] ?? null;
|
||||
$timestamp = $_SERVER['HTTP_X_TIMESTAMP'] ?? null;
|
||||
if (!$api_key || !$signature || !$timestamp) {
|
||||
throw new Exception('Unauthorized', 401);
|
||||
}
|
||||
$auth = new AuthenticationHandler();
|
||||
$authResult = $auth->validateHmacSignature($api_key, $signature, '', $timestamp);
|
||||
if (!$authResult['valid']) {
|
||||
throw new Exception($authResult['error'], 401);
|
||||
}
|
||||
$user_id = $authResult['user_id'];
|
||||
}
|
||||
|
||||
$user_id = $authResult['user_id'];
|
||||
|
||||
// Fetch workouts
|
||||
$stmt = $db->prepare('SELECT * FROM workouts WHERE user_id = ? ORDER BY created_at DESC LIMIT 50');
|
||||
$stmt->bind_param('i', $user_id);
|
||||
|
||||
Reference in New Issue
Block a user