From c95daba5206cb4bd55b5685e8141311f23606e1a Mon Sep 17 00:00:00 2001 From: George Halkiadakis Date: Fri, 31 Mar 2023 05:49:40 +0300 Subject: added advances and secure confifuratin parametres --- core/auth/env.example | 36 ++++++++++++++++++++++++++++++++++++ core/config/anom_settings.php | 16 +++++++--------- html/app/config/app_constants.php | 39 ++++++++++++++++++++++++++++++++++----- html/app/controllers/Auth.php | 26 +++++++++++++++++++++++--- 4 files changed, 100 insertions(+), 17 deletions(-) create mode 100644 core/auth/env.example diff --git a/core/auth/env.example b/core/auth/env.example new file mode 100644 index 0000000..fd47dd8 --- /dev/null +++ b/core/auth/env.example @@ -0,0 +1,36 @@ +ENVIRONMENT='development' + +# MySQL connection +# --- -- -- - - - +DB_NAME= +DB_USER= +DB_PASS= +PDO_HOST= + +# mailhog +# == testting/fake email service +# --- -- -- - - - +# MAIL_HOST=mailhog_server +# MAIL_PORT=1025 +# MAIL_USERNAME= +# MAIL_PASSWORD= +# MAIL_ENCRYPTION= + +# SMTP setup +# == read mail server +# --- -- -- - - - +MAIL_MAILER=smtp +MAIL_HOST= +MAIL_PORT=465 +MAIL_USERNAME= +MAIL_PASSWORD= +MAIL_ENCRYPTION=ssl +NO_REPLY_EMAIL=noreply@... +REPLY_TO_EMAIL=webmaster@r... +MAIL_FROM_NAME=Classroom + +# redis cache server +# --- -- -- - - - +# REDIS_HOST=redis +# REDIS_PASSWORD= +# REDIS_PORT=6379 \ No newline at end of file diff --git a/core/config/anom_settings.php b/core/config/anom_settings.php index 76c7c62..399c180 100644 --- a/core/config/anom_settings.php +++ b/core/config/anom_settings.php @@ -12,7 +12,7 @@ */ if (file_exists("../core/auth/.env")) { - $ini_array = parse_ini_file("../core/auth/.env"); + $ini = parse_ini_file("../core/auth/.env"); } // DEFINE WHETTHER THE APP RUNS ON PRODUCTION @@ -30,7 +30,7 @@ if (file_exists("../core/auth/.env")) { # } # define by .env file -define('PRODUCTION', ($ini_array['ENVIRONMENT'] == 'production') ); +define('PRODUCTION', ($ini['ENVIRONMENT'] == 'production') ); @@ -243,15 +243,13 @@ define('CSRF_EXCLUDE_URIS', array()); // Array of URIs which ignore CSRF check * ----------------------------------------------------------------------------- */ - $ini_array = parse_ini_file("../core/auth/.env"); - - define('DB_NAME', $ini_array['DB_NAME']); +define('DB_NAME', $ini['DB_NAME']); - define('DB_USER', $ini_array['DB_USER']); +define('DB_USER', $ini['DB_USER']); - define('DB_PASS', $ini_array['DB_PASS']); +define('DB_PASS', $ini['DB_PASS']); - define('PDO_HOST', $ini_array['PDO_HOST']); +define('PDO_HOST', $ini['PDO_HOST']); /** This is just good enough @@ -286,7 +284,7 @@ define('CSRF_EXCLUDE_URIS', array()); // Array of URIs which ignore CSRF check # # } - define('DB_TIMEZONE', "SET time_zone = 'Europe/Athens'"); +define('DB_TIMEZONE', "SET time_zone = 'Europe/Athens'"); /** NOTE: * Both Redis and Memcached configurations are given as a template to work on; diff --git a/html/app/config/app_constants.php b/html/app/config/app_constants.php index a89cc6a..4ddf7ac 100644 --- a/html/app/config/app_constants.php +++ b/html/app/config/app_constants.php @@ -1,11 +1,40 @@ SMTPDebug = 2; + $mail->IsSMTP(); + $mail->Host = MAIL_HOST; + $mail->SMPTAuth = true; + $mail->SMTPSecure = MAIL_ENCRYPTION; + $mail->Protocol = 'mail'; + + $mail->Mailer = MAIL_MAILER; + $mail->Port = MAIL_PORT; + $mail->Username = MAIL_USERNAME; + $mail->Password = MAIL_PASSWORD; + + // setup format $mail->CharSet = 'utf-8'; $mail->IsHTML(true); - //It's important not to use the submitter's address as the from address as it's forgery, - //which will cause your messages to fail SPF checks. - //Use an address in your own domain as the from address, put the submitter's address in a reply-to + + // setup THE mail + // --- -- -- - - - + // It's important not to use the submitter's address as the from address as it's forgery, + // which will cause your messages to fail SPF checks. + // Use an address in your own domain as the from address, put the submitter's address in a reply-to $mail->setFrom(NO_REPLY_EMAIL, SITE_TITLE); $mail->addAddress($letter['email'], $letter['name']); $mail->addReplyTo(REPLY_TO_EMAIL, SITE_TITLE); @@ -277,3 +295,5 @@ class Auth { } +// NOTE: +// check: https://netcorecloud.com/tutorials/send-an-email-via-gmail-smtp-server-using-php/ \ No newline at end of file -- cgit v1.2.3