Connect Flutter phone auth and Android platform
This commit is contained in:
+28
-23
@@ -9,7 +9,7 @@
|
||||
|
||||
header('Content-Type: application/json');
|
||||
header('Access-Control-Allow-Methods: POST, OPTIONS');
|
||||
header('Access-Control-Allow-Headers: Content-Type, X-API-Key, X-Signature, X-Timestamp');
|
||||
header('Access-Control-Allow-Headers: Content-Type, Authorization, X-API-Key, X-Signature, X-Timestamp');
|
||||
|
||||
// Handle CORS preflight
|
||||
if ($_SERVER['REQUEST_METHOD'] === 'OPTIONS') {
|
||||
@@ -23,39 +23,44 @@ if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
|
||||
die(json_encode(['error' => 'Method not allowed']));
|
||||
}
|
||||
|
||||
require_once 'Database.php';
|
||||
require_once 'AuthenticationHandler.php';
|
||||
require_once 'PolylineUtility.php';
|
||||
require_once 'WorkoutValidator.php';
|
||||
require_once __DIR__ . '/Database.php';
|
||||
require_once __DIR__ . '/Config.php';
|
||||
require_once __DIR__ . '/AuthenticationHandler.php';
|
||||
require_once __DIR__ . '/JwtToken.php';
|
||||
require_once __DIR__ . '/ApiAuth.php';
|
||||
require_once __DIR__ . '/PolylineUtility.php';
|
||||
require_once __DIR__ . '/WorkoutValidator.php';
|
||||
require_once dirname(__DIR__) . '/public/api/v1/_bootstrap.php';
|
||||
|
||||
try {
|
||||
// Get request headers
|
||||
$api_key = getHeader('X-API-Key');
|
||||
$signature = getHeader('X-Signature');
|
||||
$timestamp = getHeader('X-Timestamp');
|
||||
|
||||
if (!$api_key || !$signature || !$timestamp) {
|
||||
throw new Exception('Missing required authentication headers', 400);
|
||||
}
|
||||
|
||||
// Get raw request body for signature verification
|
||||
$rawBody = file_get_contents('php://input');
|
||||
if (empty($rawBody)) {
|
||||
throw new Exception('Empty request body', 400);
|
||||
}
|
||||
|
||||
// Initialize handlers
|
||||
$auth = new AuthenticationHandler();
|
||||
$db = Database::getInstance();
|
||||
|
||||
// Validate HMAC signature
|
||||
$authResult = $auth->validateHmacSignature($api_key, $signature, $rawBody, $timestamp);
|
||||
if (!$authResult['valid']) {
|
||||
throw new Exception($authResult['error'], 401);
|
||||
if (isset($_SERVER['HTTP_AUTHORIZATION']) && preg_match('/^Bearer\s+/i', $_SERVER['HTTP_AUTHORIZATION'])) {
|
||||
$user_id = ApiAuth::bearerClaims()['user_id'];
|
||||
} else {
|
||||
AppConfig::loadEnvironment();
|
||||
if (getenv('LEGACY_HMAC_ENABLED') !== 'true') {
|
||||
throw new Exception('Bearer authentication required', 401);
|
||||
}
|
||||
$api_key = getHeader('X-API-Key');
|
||||
$signature = getHeader('X-Signature');
|
||||
$timestamp = getHeader('X-Timestamp');
|
||||
if (!$api_key || !$signature || !$timestamp) {
|
||||
throw new Exception('Missing required authentication headers', 401);
|
||||
}
|
||||
$auth = new AuthenticationHandler();
|
||||
$authResult = $auth->validateHmacSignature($api_key, $signature, $rawBody, $timestamp);
|
||||
if (!$authResult['valid']) {
|
||||
throw new Exception($authResult['error'], 401);
|
||||
}
|
||||
$user_id = $authResult['user_id'];
|
||||
}
|
||||
|
||||
$user_id = $authResult['user_id'];
|
||||
|
||||
// Parse and validate JSON payload
|
||||
$payload = json_decode($rawBody, true);
|
||||
if (!is_array($payload)) {
|
||||
|
||||
Reference in New Issue
Block a user