diff options
Diffstat (limited to 'classes/Request.php')
| -rw-r--r-- | classes/Request.php | 94 |
1 files changed, 0 insertions, 94 deletions
diff --git a/classes/Request.php b/classes/Request.php deleted file mode 100644 index 20b82c7..0000000 --- a/classes/Request.php +++ /dev/null @@ -1,94 +0,0 @@ -<?php - -class Request -{ - - public $URL; // full request url - - public $PATH; // Path (decoded) - - public $QUERY; // Query string (decoded) - - public $HOST; - - public $PORT; - - public $METHOD; // request method - - public $TIME; // request timestamp - - public $IP; // Client's IP address - - public $AGENT; // Client's User Agent - - public $GET = []; - - public $POST = []; - - public $SIGNATURE; // user/client's device signature - - - - public function __construct($errors = false) - { - $parsed = parse_url($_SERVER['REQUEST_URI']); - $this->URL = $_SERVER['REQUEST_URI']; - $this->PATH = (!empty($parsed['path'])) ? urldecode($parsed['path']) : ''; - $this->QUERY = (!empty($parsed['query'])) ? urldecode($parsed['query']) : false; - $this->HOST = $_SERVER['HTTP_HOST']; - $this->PORT = $_SERVER['SERVER_PORT']; - $this->TIME = $_SERVER['REQUEST_TIME']; - $this->CLI_IP = $_SERVER['REMOTE_ADDR']; - - $this->METHOD = strtolower($_SERVER['REQUEST_METHOD']); - - $this->GET = $_GET; // $_GET should only used - // to request data or specify options (never to perform - // system-changes) thus should not need any validation; - // * If (for any reason) you requide $_GET sanitization - // enable it later on the method's code - - // $this->INTERFACE = php_sapi_name(); - - $this->AGENT = $_SERVER['HTTP_USER_AGENT'] ?? 'unknown'; - $this->SIGNATURE = sha1( - $_SERVER['HTTP_USER_AGENT'] ?? 'unknown' - . $_SERVER['HTTP_ACCEPT'] ?? '' - . $_SERVER['HTTP_ACCEPT_LANGUAGE'] ?? '' - . $_SERVER['HTTP_ACCEPT_ENCODING'] ?? '' - ); - - // sanitize user input - // if (isset($_GET)) { $this->GET = $this->sanitize($_GET); } - $this->GET = $this->sanitize($_GET); - if (isset($_POST)) { $this->POST = $this->sanitize($_POST); } - if (isset($_COOKIE)) { $this->COOKIE = $this->sanitize($_COOKIE); } - - // check anti-CSRF token if needed - // (again, GET requests should not need CSRF cheking) - if (in_array($this->METHOD, ['post', 'put', 'patch', 'delete'])) { - // TODO: only if CSRF protection enabled... - $this->checkCsrfToken(); - } - - } - - - private function sanitize($array) - { - // TODO: - // ... - return $array; - } - - - public function checkCsrfToken() - { - // TODO: - // ... - // if SCRF-token is not valideted, serve 403 - return $array; - } - -} - |
