This is an old revision of the document!
Table of Contents
ApiAuth
Layer: Core · Source: lib/core/ApiAuth.php:21 (lines 21–590)
class ApiAuth
API Authentication
Handles token-based authentication for the RESTful API Supports API Key and Bearer Token authentication
Docblock Metadata
^ Tag ^ Value ^ | ''@category'' | Core Class | | ''@author'' | Blogware Team | | ''@license'' | MIT | | ''@version'' | 1.0 | | ''@since'' | Since Release 1.0 |
Inheritance
No parent, interface or trait. This is a root type.
Constants (6)
^ Visibility ^ Name ^ Value ^ Line ^ | ''-'' | ''AUTH_API_KEY'' | '''api_key';'' | 26 | | ''-'' | ''AUTH_BEARER'' | '''bearer';'' | 27 | | ''-'' | ''AUTH_NONE'' | '''none';'' | 28 | | ''-'' | ''TOKEN_EXPIRY'' | ''86400;'' | 34 | | ''-'' | ''MAX_LOGIN_ATTEMPTS'' | ''5;'' | 39 | | ''-'' | ''LOCKOUT_DURATION'' | ''900;'' | 44 |
Properties (3)
^ Visibility ^ Type ^ Name ^ Default ^ Line ^ | ''private static'' | ''static'' | ''$user'' | ''null;'' | 49 | | ''private static'' | ''static'' | ''$authType'' | ''self::AUTH_NONE;'' | 54 | | ''private static'' | ''static'' | ''$isAuthenticated'' | ''false;'' | 59 |
Methods (22)
^ Visibility ^ Method ^ Summary ^ Line ^ | public static | ''authenticate()'' | Initialize and authenticate the request | 66 | | private static | ''authenticateWithApiKey()'' | Authenticate using API Key | 95 | | private static | ''authenticateWithToken()'' | Authenticate using Bearer Token | 170 | | private static | ''getApiKey()'' | Get API Key from request headers | 226 | | private static | ''getBearerToken()'' | Get Bearer Token from request headers | 238 | | public static | ''isAuthenticated()'' | Check if user is authenticated | 254 | | public static | ''getUser()'' | Get authenticated user data | 264 | | public static | ''getUserId()'' | Get authenticated user ID | 274 | | public static | ''getUserLevel()'' | Get authenticated user level | 284 | | public static | ''getAuthType()'' | Get authentication type used | 294 | | public static | ''hasPermission()'' | Check if user has required permission level | 305 | | private static | ''isAccountLocked()'' | Check if account is locked | 326 | | private static | ''logAccess()'' | Log API access attempt | 343 | | private static | ''hasApiOrBearerAuth()'' | Check whether the current request carries API-key or Bearer auth headers. | 396 | | public static | ''validateCsrfForWrite()'' | (undocumented) | 408 | | public static | ''generateCsrfToken()'' | Generate a CSRF token for API write operations and store it in session. | 463 | | private static | ''getClientIp()'' | Get client IP address | 484 | | public static | ''setSessionUser()'' | Set authenticated user from session-based authentication | 501 | | public static | ''getUserLogin()'' | Get authenticated user login name | 513 | | public static | ''generateApiKey()'' | Generate API key for a user | 528 | | public static | ''revokeApiKey()'' | Revoke all API keys for a user | 559 | | public static | ''revokeApiKeyById()'' | Revoke a specific API key by ID | 578 |
authenticate()
public static function authenticate()
lines 66–83 (18)
Initialize and authenticate the request
Takes no parameters.
Returns: (none declared) — bool Whether authentication was successful
authenticateWithApiKey()
private static function authenticateWithApiKey($apiKey)
lines 95–162 (68)
Authenticate using API Key
Looks up the key in the dedicated tbl_api_keys table and verifies it against the stored password_hash(). Falls back to direct comparison for legacy plaintext keys that may exist in tbl_settings.
^ Parameter ^ Type ^ Default ^ Description ^ | ''$apiKey'' | ''(untyped)'' | //required// | The API key |
Returns: (none declared) — bool Authentication success
authenticateWithToken()
private static function authenticateWithToken($token)
lines 170–216 (47)
Authenticate using Bearer Token
^ Parameter ^ Type ^ Default ^ Description ^ | ''$token'' | ''(untyped)'' | //required// | The bearer token |
Returns: (none declared) — bool Authentication success
getApiKey()
private static function getApiKey()
lines 226–231 (6)
Get API Key from request headers
Only the X-API-Key header is accepted. Query-string keys were removed: they leak into access logs and defeat the point of a secret header.
Takes no parameters.
Returns: (none declared) — string|null
getBearerToken()
private static function getBearerToken()
lines 238–247 (10)
Get Bearer Token from request headers
Takes no parameters.
Returns: (none declared) — string|null
isAuthenticated()
public static function isAuthenticated()
lines 254–257 (4)
Check if user is authenticated
Takes no parameters.
Returns: (none declared) — bool
getUser()
public static function getUser()
lines 264–267 (4)
Get authenticated user data
Takes no parameters.
Returns: (none declared) — array|null
getUserId()
public static function getUserId()
lines 274–277 (4)
Get authenticated user ID
Takes no parameters.
Returns: (none declared) — int|null
getUserLevel()
public static function getUserLevel()
lines 284–287 (4)
Get authenticated user level
Takes no parameters.
Returns: (none declared) — string|null
getAuthType()
public static function getAuthType()
lines 294–297 (4)
Get authentication type used
Takes no parameters.
Returns: (none declared) — string
hasPermission()
public static function hasPermission($requiredLevels)
lines 305–318 (14)
Check if user has required permission level
^ Parameter ^ Type ^ Default ^ Description ^ | ''$requiredLevels'' | ''(untyped)'' | //required// | Required user level(s) |
Returns: (none declared) — bool
isAccountLocked()
private static function isAccountLocked($user)
lines 326–335 (10)
Check if account is locked
^ Parameter ^ Type ^ Default ^ Description ^ | ''$user'' | ''(untyped)'' | //required// | User data |
Returns: (none declared) — bool
logAccess()
private static function logAccess($userId, $success)
lines 343–378 (36)
Log API access attempt
^ Parameter ^ Type ^ Default ^ Description ^ | ''$userId'' | ''(untyped)'' | //required// | User ID (0 if failed) | | ''$success'' | ''(untyped)'' | //required// | Whether authentication was successful |
Returns: (none declared)
hasApiOrBearerAuth()
private static function hasApiOrBearerAuth()
lines 396–406 (11)
Check whether the current request carries API-key or Bearer auth headers.
Takes no parameters.
Returns: (none declared) — bool
validateCsrfForWrite()
public static function validateCsrfForWrite()
lines 408–456 (49)
Takes no parameters.
Returns: (none declared)
generateCsrfToken()
public static function generateCsrfToken()
lines 463–471 (9)
Generate a CSRF token for API write operations and store it in session.
Takes no parameters.
Returns: (none declared) — string The generated token
getClientIp()
private static function getClientIp()
lines 484–489 (6)
Get client IP address
Delegates to the application-wide get_ip_address() helper, which trusts only REMOTE_ADDR (or a Cloudflare CF-Connecting-IP header). Client-supplied forwarding headers (X-Forwarded-For etc.) are never trusted, so the login-attempt and rate-limit accounting cannot be bypassed by spoofing. Falls back to the “0.0.0.0” sentinel when no REMOTE_ADDR is present.
Takes no parameters.
Returns: (none declared) — string
setSessionUser()
public static function setSessionUser(array $userData, $authType = 'session')
lines 501–506 (6)
Set authenticated user from session-based authentication
Used by MediaApiController and other admin panel entry points that authenticate via session/cookie rather than API key/token.
^ Parameter ^ Type ^ Default ^ Description ^ | ''$userData'' | ''array'' | //required// | Must contain 'user_login' and optionally 'user_level' | | ''$authType'' | ''(untyped)'' | '''session''' | The authentication type (default: 'session') |
Returns: (none declared) — void
getUserLogin()
public static function getUserLogin()
lines 513–516 (4)
Get authenticated user login name
Takes no parameters.
Returns: (none declared) — string|null
generateApiKey()
public static function generateApiKey($userId, $description = '')
lines 528–549 (22)
Generate API key for a user
Stores the key hash (bcrypt) in the dedicated tbl_api_keys table and returns the raw key to the caller for one-time display.
^ Parameter ^ Type ^ Default ^ Description ^ | ''$userId'' | ''(untyped)'' | //required// | User ID | | ''$description'' | ''(untyped)'' | '''''' | Optional description for the key |
Returns: (none declared) — string Generated API key (plaintext, show once)
revokeApiKey()
public static function revokeApiKey($userId)
lines 559–570 (12)
Revoke all API keys for a user
Sets is_revoked = 1 on all active keys for the given user.
^ Parameter ^ Type ^ Default ^ Description ^ | ''$userId'' | ''(untyped)'' | //required// | User ID |
Returns: (none declared) — bool Success
revokeApiKeyById()
public static function revokeApiKeyById($keyId)
lines 578–589 (12)
Revoke a specific API key by ID
^ Parameter ^ Type ^ Default ^ Description ^ | ''$keyId'' | ''(untyped)'' | //required// | The API key ID |
Returns: (none declared) — bool Success
This page is generated from source by 'tools/gendoc'. Edits will be overwritten.
