Scriptlog Docs

Scriptlog Documentation

Code reference for the Scriptlog codebase

User Tools

Site Tools


scriptlog:lib:core:apiauth

This is an old revision of the document!


ApiAuth

Layer: Core · Source: lib/core/ApiAuth.php:21 (lines 21–590)


class ApiAuth

API Authentication

Handles token-based authentication for the RESTful API Supports API Key and Bearer Token authentication

Docblock Metadata

Tag Value
@category Core Class
@author Blogware Team
@license MIT
@version 1.0
@since Since Release 1.0

Inheritance

No parent, interface or trait. This is a root type.

Constants (6)

Visibility Name Value Line
- AUTH_API_KEY 'api_key'; 26
- AUTH_BEARER 'bearer'; 27
- AUTH_NONE 'none'; 28
- TOKEN_EXPIRY 86400; 34
- MAX_LOGIN_ATTEMPTS 5; 39
- LOCKOUT_DURATION 900; 44

Properties (3)

Visibility Type Name Default Line
private static static $user null; 49
private static static $authType self::AUTH_NONE; 54
private static static $isAuthenticated false; 59

Methods (22)

Visibility Method Summary Line
public static authenticate() Initialize and authenticate the request 66
private static authenticateWithApiKey() Authenticate using API Key 95
private static authenticateWithToken() Authenticate using Bearer Token 170
private static getApiKey() Get API Key from request headers 226
private static getBearerToken() Get Bearer Token from request headers 238
public static isAuthenticated() Check if user is authenticated 254
public static getUser() Get authenticated user data 264
public static getUserId() Get authenticated user ID 274
public static getUserLevel() Get authenticated user level 284
public static getAuthType() Get authentication type used 294
public static hasPermission() Check if user has required permission level 305
private static isAccountLocked() Check if account is locked 326
private static logAccess() Log API access attempt 343
private static hasApiOrBearerAuth() Check whether the current request carries API-key or Bearer auth headers. 396
public static validateCsrfForWrite() (undocumented) 408
public static generateCsrfToken() Generate a CSRF token for API write operations and store it in session. 463
private static getClientIp() Get client IP address 484
public static setSessionUser() Set authenticated user from session-based authentication 501
public static getUserLogin() Get authenticated user login name 513
public static generateApiKey() Generate API key for a user 528
public static revokeApiKey() Revoke all API keys for a user 559
public static revokeApiKeyById() Revoke a specific API key by ID 578

authenticate()

public static function authenticate()

lines 66–83 (18)

Initialize and authenticate the request

Takes no parameters.

Returns: (none declared) — bool Whether authentication was successful

authenticateWithApiKey()

private static function authenticateWithApiKey($apiKey)

lines 95–162 (68)

Authenticate using API Key

Looks up the key in the dedicated tbl_api_keys table and verifies it against the stored password_hash(). Falls back to direct comparison for legacy plaintext keys that may exist in tbl_settings.

Parameter Type Default Description
$apiKey (untyped) required The API key

Returns: (none declared) — bool Authentication success

authenticateWithToken()

private static function authenticateWithToken($token)

lines 170–216 (47)

Authenticate using Bearer Token

Parameter Type Default Description
$token (untyped) required The bearer token

Returns: (none declared) — bool Authentication success

getApiKey()

private static function getApiKey()

lines 226–231 (6)

Get API Key from request headers

Only the X-API-Key header is accepted. Query-string keys were removed: they leak into access logs and defeat the point of a secret header.

Takes no parameters.

Returns: (none declared) — string|null

getBearerToken()

private static function getBearerToken()

lines 238–247 (10)

Get Bearer Token from request headers

Takes no parameters.

Returns: (none declared) — string|null

isAuthenticated()

public static function isAuthenticated()

lines 254–257 (4)

Check if user is authenticated

Takes no parameters.

Returns: (none declared) — bool

getUser()

public static function getUser()

lines 264–267 (4)

Get authenticated user data

Takes no parameters.

Returns: (none declared) — array|null

getUserId()

public static function getUserId()

lines 274–277 (4)

Get authenticated user ID

Takes no parameters.

Returns: (none declared) — int|null

getUserLevel()

public static function getUserLevel()

lines 284–287 (4)

Get authenticated user level

Takes no parameters.

Returns: (none declared) — string|null

getAuthType()

public static function getAuthType()

lines 294–297 (4)

Get authentication type used

Takes no parameters.

Returns: (none declared) — string

hasPermission()

public static function hasPermission($requiredLevels)

lines 305–318 (14)

Check if user has required permission level

Parameter Type Default Description
$requiredLevels (untyped) required Required user level(s)

Returns: (none declared) — bool

isAccountLocked()

private static function isAccountLocked($user)

lines 326–335 (10)

Check if account is locked

Parameter Type Default Description
$user (untyped) required User data

Returns: (none declared) — bool

logAccess()

private static function logAccess($userId, $success)

lines 343–378 (36)

Log API access attempt

Parameter Type Default Description
$userId (untyped) required User ID (0 if failed)
$success (untyped) required Whether authentication was successful

Returns: (none declared)

hasApiOrBearerAuth()

private static function hasApiOrBearerAuth()

lines 396–406 (11)

Check whether the current request carries API-key or Bearer auth headers.

Takes no parameters.

Returns: (none declared) — bool

validateCsrfForWrite()

public static function validateCsrfForWrite()

lines 408–456 (49)

Takes no parameters.

Returns: (none declared)

generateCsrfToken()

public static function generateCsrfToken()

lines 463–471 (9)

Generate a CSRF token for API write operations and store it in session.

Takes no parameters.

Returns: (none declared) — string The generated token

getClientIp()

private static function getClientIp()

lines 484–489 (6)

Get client IP address

Delegates to the application-wide get_ip_address() helper, which trusts only REMOTE_ADDR (or a Cloudflare CF-Connecting-IP header). Client-supplied forwarding headers (X-Forwarded-For etc.) are never trusted, so the login-attempt and rate-limit accounting cannot be bypassed by spoofing. Falls back to the “0.0.0.0” sentinel when no REMOTE_ADDR is present.

Takes no parameters.

Returns: (none declared) — string

setSessionUser()

public static function setSessionUser(array $userData, $authType = 'session')

lines 501–506 (6)

Set authenticated user from session-based authentication

Used by MediaApiController and other admin panel entry points that authenticate via session/cookie rather than API key/token.

Parameter Type Default Description
$userData array required Must contain 'user_login' and optionally 'user_level'
$authType (untyped) 'session' The authentication type (default: 'session')

Returns: (none declared) — void

getUserLogin()

public static function getUserLogin()

lines 513–516 (4)

Get authenticated user login name

Takes no parameters.

Returns: (none declared) — string|null

generateApiKey()

public static function generateApiKey($userId, $description = '')

lines 528–549 (22)

Generate API key for a user

Stores the key hash (bcrypt) in the dedicated tbl_api_keys table and returns the raw key to the caller for one-time display.

Parameter Type Default Description
$userId (untyped) required User ID
$description (untyped) '''''' Optional description for the key

Returns: (none declared) — string Generated API key (plaintext, show once)

revokeApiKey()

public static function revokeApiKey($userId)

lines 559–570 (12)

Revoke all API keys for a user

Sets is_revoked = 1 on all active keys for the given user.

Parameter Type Default Description
$userId (untyped) required User ID

Returns: (none declared) — bool Success

revokeApiKeyById()

public static function revokeApiKeyById($keyId)

lines 578–589 (12)

Revoke a specific API key by ID

Parameter Type Default Description
$keyId (untyped) required The API key ID

Returns: (none declared) — bool Success


This page is generated from source by 'tools/gendoc'. Edits will be overwritten.

scriptlog/lib/core/apiauth.1790414216.txt.gz · Last modified: by admin