Files
fitness/backend/api_history.php
T
2026-10-04 00:19:45 +03:00

51 lines
1.3 KiB
PHP

<?php
/**
* Workout History API
* GET /api/v1/history.php
*/
header('Content-Type: application/json');
require_once 'Database.php';
require_once 'AuthenticationHandler.php';
try {
$api_key = $_SERVER['HTTP_X_API_KEY'] ?? null;
$signature = $_SERVER['HTTP_X_SIGNATURE'] ?? null;
$timestamp = $_SERVER['HTTP_X_TIMESTAMP'] ?? null;
if (!$api_key || !$signature || !$timestamp) {
throw new Exception('Unauthorized', 401);
}
$auth = new AuthenticationHandler();
$db = Database::getInstance();
// Verification (Using empty body for GET request signature)
$authResult = $auth->validateHmacSignature($api_key, $signature, '', $timestamp);
if (!$authResult['valid']) {
throw new Exception($authResult['error'], 401);
}
$user_id = $authResult['user_id'];
// Fetch workouts
$stmt = $db->prepare('SELECT * FROM workouts WHERE user_id = ? ORDER BY created_at DESC LIMIT 50');
$stmt->bind_param('i', $user_id);
$stmt->execute();
$result = $stmt->get_result();
$workouts = [];
while ($row = $result->fetch_assoc()) {
$workouts[] = $row;
}
echo json_encode([
'status' => 'success',
'data' => $workouts
]);
} catch (Exception $e) {
http_response_code($e->getCode() ?: 500);
echo json_encode(['status' => 'error', 'error' => $e->getMessage()]);
}