summaryrefslogtreecommitdiff
path: root/classes/Request.php
diff options
context:
space:
mode:
Diffstat (limited to 'classes/Request.php')
-rw-r--r--classes/Request.php94
1 files changed, 0 insertions, 94 deletions
diff --git a/classes/Request.php b/classes/Request.php
deleted file mode 100644
index 20b82c7..0000000
--- a/classes/Request.php
+++ /dev/null
@@ -1,94 +0,0 @@
-<?php
-
-class Request
-{
-
- public $URL; // full request url
-
- public $PATH; // Path (decoded)
-
- public $QUERY; // Query string (decoded)
-
- public $HOST;
-
- public $PORT;
-
- public $METHOD; // request method
-
- public $TIME; // request timestamp
-
- public $IP; // Client's IP address
-
- public $AGENT; // Client's User Agent
-
- public $GET = [];
-
- public $POST = [];
-
- public $SIGNATURE; // user/client's device signature
-
-
-
- public function __construct($errors = false)
- {
- $parsed = parse_url($_SERVER['REQUEST_URI']);
- $this->URL = $_SERVER['REQUEST_URI'];
- $this->PATH = (!empty($parsed['path'])) ? urldecode($parsed['path']) : '';
- $this->QUERY = (!empty($parsed['query'])) ? urldecode($parsed['query']) : false;
- $this->HOST = $_SERVER['HTTP_HOST'];
- $this->PORT = $_SERVER['SERVER_PORT'];
- $this->TIME = $_SERVER['REQUEST_TIME'];
- $this->CLI_IP = $_SERVER['REMOTE_ADDR'];
-
- $this->METHOD = strtolower($_SERVER['REQUEST_METHOD']);
-
- $this->GET = $_GET; // $_GET should only used
- // to request data or specify options (never to perform
- // system-changes) thus should not need any validation;
- // * If (for any reason) you requide $_GET sanitization
- // enable it later on the method's code
-
- // $this->INTERFACE = php_sapi_name();
-
- $this->AGENT = $_SERVER['HTTP_USER_AGENT'] ?? 'unknown';
- $this->SIGNATURE = sha1(
- $_SERVER['HTTP_USER_AGENT'] ?? 'unknown'
- . $_SERVER['HTTP_ACCEPT'] ?? ''
- . $_SERVER['HTTP_ACCEPT_LANGUAGE'] ?? ''
- . $_SERVER['HTTP_ACCEPT_ENCODING'] ?? ''
- );
-
- // sanitize user input
- // if (isset($_GET)) { $this->GET = $this->sanitize($_GET); }
- $this->GET = $this->sanitize($_GET);
- if (isset($_POST)) { $this->POST = $this->sanitize($_POST); }
- if (isset($_COOKIE)) { $this->COOKIE = $this->sanitize($_COOKIE); }
-
- // check anti-CSRF token if needed
- // (again, GET requests should not need CSRF cheking)
- if (in_array($this->METHOD, ['post', 'put', 'patch', 'delete'])) {
- // TODO: only if CSRF protection enabled...
- $this->checkCsrfToken();
- }
-
- }
-
-
- private function sanitize($array)
- {
- // TODO:
- // ...
- return $array;
- }
-
-
- public function checkCsrfToken()
- {
- // TODO:
- // ...
- // if SCRF-token is not valideted, serve 403
- return $array;
- }
-
-}
-