Scriptlog Docs

Scriptlog Documentation

Code reference for the Scriptlog codebase

User Tools

Site Tools


scriptlog:lib:core:apiauth

This is an old revision of the document!


ApiAuth

Layer: Core · Source: lib/core/ApiAuth.php:21 (lines 21–590)


class ApiAuth

API Authentication

Handles token-based authentication for the RESTful API Supports API Key and Bearer Token authentication

Docblock Metadata

^ Tag ^ Value ^
| ''@category'' | Core Class |
| ''@author'' | Blogware Team |
| ''@license'' | MIT |
| ''@version'' | 1.0 |
| ''@since'' | Since Release 1.0 |

Inheritance

No parent, interface or trait. This is a root type.

Constants (6)

^ Visibility ^ Name ^ Value ^ Line ^
| ''-'' | ''AUTH_API_KEY'' | '''api_key';'' | 26 |
| ''-'' | ''AUTH_BEARER'' | '''bearer';'' | 27 |
| ''-'' | ''AUTH_NONE'' | '''none';'' | 28 |
| ''-'' | ''TOKEN_EXPIRY'' | ''86400;'' | 34 |
| ''-'' | ''MAX_LOGIN_ATTEMPTS'' | ''5;'' | 39 |
| ''-'' | ''LOCKOUT_DURATION'' | ''900;'' | 44 |

Properties (3)

^ Visibility ^ Type ^ Name ^ Default ^ Line ^
| ''private static'' | ''static'' | ''$user'' | ''null;'' | 49 |
| ''private static'' | ''static'' | ''$authType'' | ''self::AUTH_NONE;'' | 54 |
| ''private static'' | ''static'' | ''$isAuthenticated'' | ''false;'' | 59 |

Methods (22)

^ Visibility ^ Method ^ Summary ^ Line ^
| public static | ''authenticate()'' | Initialize and authenticate the request | 66 |
| private static | ''authenticateWithApiKey()'' | Authenticate using API Key | 95 |
| private static | ''authenticateWithToken()'' | Authenticate using Bearer Token | 170 |
| private static | ''getApiKey()'' | Get API Key from request headers | 226 |
| private static | ''getBearerToken()'' | Get Bearer Token from request headers | 238 |
| public static | ''isAuthenticated()'' | Check if user is authenticated | 254 |
| public static | ''getUser()'' | Get authenticated user data | 264 |
| public static | ''getUserId()'' | Get authenticated user ID | 274 |
| public static | ''getUserLevel()'' | Get authenticated user level | 284 |
| public static | ''getAuthType()'' | Get authentication type used | 294 |
| public static | ''hasPermission()'' | Check if user has required permission level | 305 |
| private static | ''isAccountLocked()'' | Check if account is locked | 326 |
| private static | ''logAccess()'' | Log API access attempt | 343 |
| private static | ''hasApiOrBearerAuth()'' | Check whether the current request carries API-key or Bearer auth headers. | 396 |
| public static | ''validateCsrfForWrite()'' | (undocumented) | 408 |
| public static | ''generateCsrfToken()'' | Generate a CSRF token for API write operations and store it in session. | 463 |
| private static | ''getClientIp()'' | Get client IP address | 484 |
| public static | ''setSessionUser()'' | Set authenticated user from session-based authentication | 501 |
| public static | ''getUserLogin()'' | Get authenticated user login name | 513 |
| public static | ''generateApiKey()'' | Generate API key for a user | 528 |
| public static | ''revokeApiKey()'' | Revoke all API keys for a user | 559 |
| public static | ''revokeApiKeyById()'' | Revoke a specific API key by ID | 578 |

authenticate()

public static function authenticate()

lines 66–83 (18)

Initialize and authenticate the request

Takes no parameters.

Returns: (none declared) — bool Whether authentication was successful

authenticateWithApiKey()

private static function authenticateWithApiKey($apiKey)

lines 95–162 (68)

Authenticate using API Key

Looks up the key in the dedicated tbl_api_keys table and verifies it against the stored password_hash(). Falls back to direct comparison for legacy plaintext keys that may exist in tbl_settings.

^ Parameter ^ Type ^ Default ^ Description ^
| ''$apiKey'' | ''(untyped)'' | //required// | The API key |

Returns: (none declared) — bool Authentication success

authenticateWithToken()

private static function authenticateWithToken($token)

lines 170–216 (47)

Authenticate using Bearer Token

^ Parameter ^ Type ^ Default ^ Description ^
| ''$token'' | ''(untyped)'' | //required// | The bearer token |

Returns: (none declared) — bool Authentication success

getApiKey()

private static function getApiKey()

lines 226–231 (6)

Get API Key from request headers

Only the X-API-Key header is accepted. Query-string keys were removed: they leak into access logs and defeat the point of a secret header.

Takes no parameters.

Returns: (none declared) — string|null

getBearerToken()

private static function getBearerToken()

lines 238–247 (10)

Get Bearer Token from request headers

Takes no parameters.

Returns: (none declared) — string|null

isAuthenticated()

public static function isAuthenticated()

lines 254–257 (4)

Check if user is authenticated

Takes no parameters.

Returns: (none declared) — bool

getUser()

public static function getUser()

lines 264–267 (4)

Get authenticated user data

Takes no parameters.

Returns: (none declared) — array|null

getUserId()

public static function getUserId()

lines 274–277 (4)

Get authenticated user ID

Takes no parameters.

Returns: (none declared) — int|null

getUserLevel()

public static function getUserLevel()

lines 284–287 (4)

Get authenticated user level

Takes no parameters.

Returns: (none declared) — string|null

getAuthType()

public static function getAuthType()

lines 294–297 (4)

Get authentication type used

Takes no parameters.

Returns: (none declared) — string

hasPermission()

public static function hasPermission($requiredLevels)

lines 305–318 (14)

Check if user has required permission level

^ Parameter ^ Type ^ Default ^ Description ^
| ''$requiredLevels'' | ''(untyped)'' | //required// | Required user level(s) |

Returns: (none declared) — bool

isAccountLocked()

private static function isAccountLocked($user)

lines 326–335 (10)

Check if account is locked

^ Parameter ^ Type ^ Default ^ Description ^
| ''$user'' | ''(untyped)'' | //required// | User data |

Returns: (none declared) — bool

logAccess()

private static function logAccess($userId, $success)

lines 343–378 (36)

Log API access attempt

^ Parameter ^ Type ^ Default ^ Description ^
| ''$userId'' | ''(untyped)'' | //required// | User ID (0 if failed) |
| ''$success'' | ''(untyped)'' | //required// | Whether authentication was successful |

Returns: (none declared)

hasApiOrBearerAuth()

private static function hasApiOrBearerAuth()

lines 396–406 (11)

Check whether the current request carries API-key or Bearer auth headers.

Takes no parameters.

Returns: (none declared) — bool

validateCsrfForWrite()

public static function validateCsrfForWrite()

lines 408–456 (49)

Takes no parameters.

Returns: (none declared)

generateCsrfToken()

public static function generateCsrfToken()

lines 463–471 (9)

Generate a CSRF token for API write operations and store it in session.

Takes no parameters.

Returns: (none declared) — string The generated token

getClientIp()

private static function getClientIp()

lines 484–489 (6)

Get client IP address

Delegates to the application-wide get_ip_address() helper, which trusts only REMOTE_ADDR (or a Cloudflare CF-Connecting-IP header). Client-supplied forwarding headers (X-Forwarded-For etc.) are never trusted, so the login-attempt and rate-limit accounting cannot be bypassed by spoofing. Falls back to the “0.0.0.0” sentinel when no REMOTE_ADDR is present.

Takes no parameters.

Returns: (none declared) — string

setSessionUser()

public static function setSessionUser(array $userData, $authType = 'session')

lines 501–506 (6)

Set authenticated user from session-based authentication

Used by MediaApiController and other admin panel entry points that authenticate via session/cookie rather than API key/token.

^ Parameter ^ Type ^ Default ^ Description ^
| ''$userData'' | ''array'' | //required// | Must contain 'user_login' and optionally 'user_level' |
| ''$authType'' | ''(untyped)'' | '''session''' | The authentication type (default: 'session') |

Returns: (none declared) — void

getUserLogin()

public static function getUserLogin()

lines 513–516 (4)

Get authenticated user login name

Takes no parameters.

Returns: (none declared) — string|null

generateApiKey()

public static function generateApiKey($userId, $description = '')

lines 528–549 (22)

Generate API key for a user

Stores the key hash (bcrypt) in the dedicated tbl_api_keys table and returns the raw key to the caller for one-time display.

^ Parameter ^ Type ^ Default ^ Description ^
| ''$userId'' | ''(untyped)'' | //required// | User ID |
| ''$description'' | ''(untyped)'' | '''''' | Optional description for the key |

Returns: (none declared) — string Generated API key (plaintext, show once)

revokeApiKey()

public static function revokeApiKey($userId)

lines 559–570 (12)

Revoke all API keys for a user

Sets is_revoked = 1 on all active keys for the given user.

^ Parameter ^ Type ^ Default ^ Description ^
| ''$userId'' | ''(untyped)'' | //required// | User ID |

Returns: (none declared) — bool Success

revokeApiKeyById()

public static function revokeApiKeyById($keyId)

lines 578–589 (12)

Revoke a specific API key by ID

^ Parameter ^ Type ^ Default ^ Description ^
| ''$keyId'' | ''(untyped)'' | //required// | The API key ID |

Returns: (none declared) — bool Success


This page is generated from source by 'tools/gendoc'. Edits will be overwritten.

scriptlog/lib/core/apiauth.1790413761.txt.gz · Last modified: by admin