Connect Flutter phone auth and Android platform

This commit is contained in:
Hamza-Ayed
2026-10-04 01:44:07 +03:00
parent 5b90da6b18
commit 98490a17e6
44 changed files with 1271 additions and 168 deletions
+28 -23
View File
@@ -9,7 +9,7 @@
header('Content-Type: application/json');
header('Access-Control-Allow-Methods: POST, OPTIONS');
header('Access-Control-Allow-Headers: Content-Type, X-API-Key, X-Signature, X-Timestamp');
header('Access-Control-Allow-Headers: Content-Type, Authorization, X-API-Key, X-Signature, X-Timestamp');
// Handle CORS preflight
if ($_SERVER['REQUEST_METHOD'] === 'OPTIONS') {
@@ -23,39 +23,44 @@ if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
die(json_encode(['error' => 'Method not allowed']));
}
require_once 'Database.php';
require_once 'AuthenticationHandler.php';
require_once 'PolylineUtility.php';
require_once 'WorkoutValidator.php';
require_once __DIR__ . '/Database.php';
require_once __DIR__ . '/Config.php';
require_once __DIR__ . '/AuthenticationHandler.php';
require_once __DIR__ . '/JwtToken.php';
require_once __DIR__ . '/ApiAuth.php';
require_once __DIR__ . '/PolylineUtility.php';
require_once __DIR__ . '/WorkoutValidator.php';
require_once dirname(__DIR__) . '/public/api/v1/_bootstrap.php';
try {
// Get request headers
$api_key = getHeader('X-API-Key');
$signature = getHeader('X-Signature');
$timestamp = getHeader('X-Timestamp');
if (!$api_key || !$signature || !$timestamp) {
throw new Exception('Missing required authentication headers', 400);
}
// Get raw request body for signature verification
$rawBody = file_get_contents('php://input');
if (empty($rawBody)) {
throw new Exception('Empty request body', 400);
}
// Initialize handlers
$auth = new AuthenticationHandler();
$db = Database::getInstance();
// Validate HMAC signature
$authResult = $auth->validateHmacSignature($api_key, $signature, $rawBody, $timestamp);
if (!$authResult['valid']) {
throw new Exception($authResult['error'], 401);
if (isset($_SERVER['HTTP_AUTHORIZATION']) && preg_match('/^Bearer\s+/i', $_SERVER['HTTP_AUTHORIZATION'])) {
$user_id = ApiAuth::bearerClaims()['user_id'];
} else {
AppConfig::loadEnvironment();
if (getenv('LEGACY_HMAC_ENABLED') !== 'true') {
throw new Exception('Bearer authentication required', 401);
}
$api_key = getHeader('X-API-Key');
$signature = getHeader('X-Signature');
$timestamp = getHeader('X-Timestamp');
if (!$api_key || !$signature || !$timestamp) {
throw new Exception('Missing required authentication headers', 401);
}
$auth = new AuthenticationHandler();
$authResult = $auth->validateHmacSignature($api_key, $signature, $rawBody, $timestamp);
if (!$authResult['valid']) {
throw new Exception($authResult['error'], 401);
}
$user_id = $authResult['user_id'];
}
$user_id = $authResult['user_id'];
// Parse and validate JSON payload
$payload = json_decode($rawBody, true);
if (!is_array($payload)) {