| Next revision | Previous revision |
| scriptlog:lib:core:apiauth [2026/09/26 09:09] – admin admin | scriptlog:lib:core:apiauth [2026/09/26 09:34] (current) – admin admin |
|---|
| ======= Docblock Metadata ======= | ======= Docblock Metadata ======= |
| |
| ^ Tag ^ Value ^ | ^ Tag ^ Value ^ |
| | ''@category'' | Core Class | | | ''@category'' | Core Class | |
| | ''@author'' | Blogware Team | | | ''@author'' | Blogware Team | |
| | ''@license'' | MIT | | | ''@license'' | MIT | |
| | ''@version'' | 1.0 | | | ''@version'' | 1.0 | |
| | ''@since'' | Since Release 1.0 | | | ''@since'' | Since Release 1.0 | |
| |
| ======= Inheritance ======= | ======= Inheritance ======= |
| ======= Constants (6) ======= | ======= Constants (6) ======= |
| |
| ^ Visibility ^ Name ^ Value ^ Line ^ | ^ Visibility ^ Name ^ Value ^ Line ^ |
| | ''-'' | ''AUTH_API_KEY'' | '''api_key';'' | 26 | | | ''-'' | ''AUTH_API_KEY'' | '''api_key';'' | 26 | |
| | ''-'' | ''AUTH_BEARER'' | '''bearer';'' | 27 | | | ''-'' | ''AUTH_BEARER'' | '''bearer';'' | 27 | |
| | ''-'' | ''AUTH_NONE'' | '''none';'' | 28 | | | ''-'' | ''AUTH_NONE'' | '''none';'' | 28 | |
| | ''-'' | ''TOKEN_EXPIRY'' | ''86400;'' | 34 | | | ''-'' | ''TOKEN_EXPIRY'' | ''86400;'' | 34 | |
| | ''-'' | ''MAX_LOGIN_ATTEMPTS'' | ''5;'' | 39 | | | ''-'' | ''MAX_LOGIN_ATTEMPTS'' | ''5;'' | 39 | |
| | ''-'' | ''LOCKOUT_DURATION'' | ''900;'' | 44 | | | ''-'' | ''LOCKOUT_DURATION'' | ''900;'' | 44 | |
| |
| ======= Properties (3) ======= | ======= Properties (3) ======= |
| |
| ^ Visibility ^ Type ^ Name ^ Default ^ Line ^ | ^ Visibility ^ Type ^ Name ^ Default ^ Line ^ |
| | ''private static'' | ''static'' | ''$user'' | ''null;'' | 49 | | | ''private static'' | ''static'' | ''$user'' | ''null'' | 49 | |
| | ''private static'' | ''static'' | ''$authType'' | ''self::AUTH_NONE;'' | 54 | | | ''private static'' | ''static'' | ''$authType'' | ''self::AUTH_NONE'' | 54 | |
| | ''private static'' | ''static'' | ''$isAuthenticated'' | ''false;'' | 59 | | | ''private static'' | ''static'' | ''$isAuthenticated'' | ''false'' | 59 | |
| |
| ======= Methods (22) ======= | ======= Methods (22) ======= |
| |
| ^ Visibility ^ Method ^ Summary ^ Line ^ | ^ Visibility ^ Method ^ Summary ^ Line ^ |
| | public static | ''authenticate()'' | Initialize and authenticate the request | 66 | | | public static | ''authenticate()'' | Initialize and authenticate the request | 66 | |
| | private static | ''authenticateWithApiKey()'' | Authenticate using API Key | 95 | | | private static | ''authenticateWithApiKey()'' | Authenticate using API Key | 95 | |
| | private static | ''authenticateWithToken()'' | Authenticate using Bearer Token | 170 | | | private static | ''authenticateWithToken()'' | Authenticate using Bearer Token | 170 | |
| | private static | ''getApiKey()'' | Get API Key from request headers | 226 | | | private static | ''getApiKey()'' | Get API Key from request headers | 226 | |
| | private static | ''getBearerToken()'' | Get Bearer Token from request headers | 238 | | | private static | ''getBearerToken()'' | Get Bearer Token from request headers | 238 | |
| | public static | ''isAuthenticated()'' | Check if user is authenticated | 254 | | | public static | ''isAuthenticated()'' | Check if user is authenticated | 254 | |
| | public static | ''getUser()'' | Get authenticated user data | 264 | | | public static | ''getUser()'' | Get authenticated user data | 264 | |
| | public static | ''getUserId()'' | Get authenticated user ID | 274 | | | public static | ''getUserId()'' | Get authenticated user ID | 274 | |
| | public static | ''getUserLevel()'' | Get authenticated user level | 284 | | | public static | ''getUserLevel()'' | Get authenticated user level | 284 | |
| | public static | ''getAuthType()'' | Get authentication type used | 294 | | | public static | ''getAuthType()'' | Get authentication type used | 294 | |
| | public static | ''hasPermission()'' | Check if user has required permission level | 305 | | | public static | ''hasPermission()'' | Check if user has required permission level | 305 | |
| | private static | ''isAccountLocked()'' | Check if account is locked | 326 | | | private static | ''isAccountLocked()'' | Check if account is locked | 326 | |
| | private static | ''logAccess()'' | Log API access attempt | 343 | | | private static | ''logAccess()'' | Log API access attempt | 343 | |
| | private static | ''hasApiOrBearerAuth()'' | Check whether the current request carries API-key or Bearer auth headers. | 396 | | | private static | ''hasApiOrBearerAuth()'' | Check whether the current request carries API-key or Bearer auth headers. | 396 | |
| | public static | ''validateCsrfForWrite()'' | (undocumented) | 408 | | | public static | ''validateCsrfForWrite()'' | (undocumented) | 408 | |
| | public static | ''generateCsrfToken()'' | Generate a CSRF token for API write operations and store it in session. | 463 | | | public static | ''generateCsrfToken()'' | Generate a CSRF token for API write operations and store it in session. | 463 | |
| | private static | ''getClientIp()'' | Get client IP address | 484 | | | private static | ''getClientIp()'' | Get client IP address | 484 | |
| | public static | ''setSessionUser()'' | Set authenticated user from session-based authentication | 501 | | | public static | ''setSessionUser()'' | Set authenticated user from session-based authentication | 501 | |
| | public static | ''getUserLogin()'' | Get authenticated user login name | 513 | | | public static | ''getUserLogin()'' | Get authenticated user login name | 513 | |
| | public static | ''generateApiKey()'' | Generate API key for a user | 528 | | | public static | ''generateApiKey()'' | Generate API key for a user | 528 | |
| | public static | ''revokeApiKey()'' | Revoke all API keys for a user | 559 | | | public static | ''revokeApiKey()'' | Revoke all API keys for a user | 559 | |
| | public static | ''revokeApiKeyById()'' | Revoke a specific API key by ID | 578 | | | public static | ''revokeApiKeyById()'' | Revoke a specific API key by ID | 578 | |
| |
| |
| for legacy plaintext keys that may exist in tbl_settings. | for legacy plaintext keys that may exist in tbl_settings. |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$apiKey'' | ''(untyped)'' | //required// | The API key | | | ''$apiKey'' | ''(untyped)'' | //required// | The API key | |
| |
| **Returns:** ''(none declared)'' — bool Authentication success | **Returns:** ''(none declared)'' — bool Authentication success |
| Authenticate using Bearer Token | Authenticate using Bearer Token |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$token'' | ''(untyped)'' | //required// | The bearer token | | | ''$token'' | ''(untyped)'' | //required// | The bearer token | |
| |
| **Returns:** ''(none declared)'' — bool Authentication success | **Returns:** ''(none declared)'' — bool Authentication success |
| Check if user has required permission level | Check if user has required permission level |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$requiredLevels'' | ''(untyped)'' | //required// | Required user level(s) | | | ''$requiredLevels'' | ''(untyped)'' | //required// | Required user level(s) | |
| |
| **Returns:** ''(none declared)'' — bool | **Returns:** ''(none declared)'' — bool |
| Check if account is locked | Check if account is locked |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$user'' | ''(untyped)'' | //required// | User data | | | ''$user'' | ''(untyped)'' | //required// | User data | |
| |
| **Returns:** ''(none declared)'' — bool | **Returns:** ''(none declared)'' — bool |
| Log API access attempt | Log API access attempt |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$userId'' | ''(untyped)'' | //required// | User ID (0 if failed) | | | ''$userId'' | ''(untyped)'' | //required// | User ID (0 if failed) | |
| | ''$success'' | ''(untyped)'' | //required// | Whether authentication was successful | | | ''$success'' | ''(untyped)'' | //required// | Whether authentication was successful | |
| |
| **Returns:** ''(none declared)'' | **Returns:** ''(none declared)'' |
| that authenticate via session/cookie rather than API key/token. | that authenticate via session/cookie rather than API key/token. |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$userData'' | ''array'' | //required// | Must contain 'user_login' and optionally 'user_level' | | | ''$userData'' | ''array'' | //required// | Must contain 'user_login' and optionally 'user_level' | |
| | ''$authType'' | ''(untyped)'' | '''session''' | The authentication type (default: 'session') | | | ''$authType'' | ''(untyped)'' | '''session''' | The authentication type (default: 'session') | |
| |
| **Returns:** ''(none declared)'' — void | **Returns:** ''(none declared)'' — void |
| and returns the raw key to the caller for one-time display. | and returns the raw key to the caller for one-time display. |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$userId'' | ''(untyped)'' | //required// | User ID | | | ''$userId'' | ''(untyped)'' | //required// | User ID | |
| | ''$description'' | ''(untyped)'' | '''''' | Optional description for the key | | | ''$description'' | ''(untyped)'' | '''''' | Optional description for the key | |
| |
| **Returns:** ''(none declared)'' — string Generated API key (plaintext, show once) | **Returns:** ''(none declared)'' — string Generated API key (plaintext, show once) |
| Sets is_revoked = 1 on all active keys for the given user. | Sets is_revoked = 1 on all active keys for the given user. |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$userId'' | ''(untyped)'' | //required// | User ID | | | ''$userId'' | ''(untyped)'' | //required// | User ID | |
| |
| **Returns:** ''(none declared)'' — bool Success | **Returns:** ''(none declared)'' — bool Success |
| Revoke a specific API key by ID | Revoke a specific API key by ID |
| |
| ^ Parameter ^ Type ^ Default ^ Description ^ | ^ Parameter ^ Type ^ Default ^ Description ^ |
| | ''$keyId'' | ''(untyped)'' | //required// | The API key ID | | | ''$keyId'' | ''(untyped)'' | //required// | The API key ID | |
| |
| **Returns:** ''(none declared)'' — bool Success | **Returns:** ''(none declared)'' — bool Success |