mirror of
https://github.com/NamelessMC/Nameless
synced 2026-08-18 06:29:04 -04:00
* Create StyleCI config file * Disable `phpdoc_separation` * Apply fixes from StyleCI (#3476) Co-authored-by: StyleCI Bot <bot@styleci.io> * style: styleci fixes --------- Co-authored-by: StyleCI Bot <bot@styleci.io> Co-authored-by: Sam <samerton@users.noreply.github.com>
62 lines
1.9 KiB
PHP
62 lines
1.9 KiB
PHP
<?php
|
|
|
|
use Symfony\Component\HttpFoundation\Response;
|
|
|
|
/**
|
|
* Allows an endpoint to require an API key to be present (and valid) in the request.
|
|
*
|
|
* @package NamelessMC\Endpoints
|
|
* @author Aberdeener
|
|
* @version 2.0.0-pr13
|
|
* @license MIT
|
|
*/
|
|
class KeyAuthEndpoint extends EndpointBase
|
|
{
|
|
/**
|
|
* Determine if the passed API key (in Authorization header) is valid.
|
|
*
|
|
* @param Nameless2API $api Instance of the Nameless2API class
|
|
* @return bool Whether the API key is valid
|
|
*/
|
|
final public function isAuthorised(Nameless2API $api): bool
|
|
{
|
|
$auth_header = HttpUtils::getHeader('Authorization');
|
|
|
|
if ($auth_header !== null) {
|
|
$exploded = explode(' ', trim($auth_header));
|
|
|
|
if (count($exploded) !== 2 ||
|
|
strcasecmp($exploded[0], 'Bearer') !== 0) {
|
|
$api->throwError(Nameless2API::ERROR_MISSING_API_KEY, 'Authorization header not in expected format');
|
|
}
|
|
|
|
$api_key = $exploded[1];
|
|
} else {
|
|
// Some hosting providers remove the Authorization header, fall back to non-standard X-API-Key heeader
|
|
$api_key_header = HttpUtils::getHeader('X-API-Key');
|
|
if ($api_key_header === null) {
|
|
$api->throwError(Nameless2API::ERROR_MISSING_API_KEY, 'Missing authorization header', Response::HTTP_UNAUTHORIZED);
|
|
}
|
|
|
|
$api_key = $api_key_header;
|
|
}
|
|
|
|
return $this->validateKey($api_key);
|
|
}
|
|
|
|
/**
|
|
* Validate provided API key to make sure it matches.
|
|
*
|
|
* @param string $api_key API key to check.
|
|
* @return bool Whether it matches or not.
|
|
*/
|
|
private function validateKey(string $api_key): bool
|
|
{
|
|
$correct_key = Settings::get('mc_api_key');
|
|
if ($correct_key === null) {
|
|
die('API key is null');
|
|
}
|
|
|
|
return hash_equals($api_key, $correct_key);
|
|
}
|
|
}
|