CODE merge : GWM

This commit is contained in:
Gowtham M 2025-08-08 10:48:10 +05:30
parent 43b58b02e6
commit 698012ee85
5 changed files with 47 additions and 6 deletions

View File

@ -14,6 +14,7 @@ use CodeIgniter\Filters\PerformanceMetrics;
use CodeIgniter\Filters\SecureHeaders;
use App\Filters\JwtAuthFilter;
use App\Filters\SignedUrlFilter;
use App\Filters\VerifyAppSignature;
class Filters extends BaseFilters
{
/**
@ -35,8 +36,9 @@ class Filters extends BaseFilters
'forcehttps' => ForceHTTPS::class,
'pagecache' => PageCache::class,
'performance' => PerformanceMetrics::class,
'jwtAuth' => JwtAuthFilter::class,
'signedUrl' => SignedUrlFilter::class,
'jwtAuth' => JwtAuthFilter::class,
'signedUrl' => SignedUrlFilter::class,
'appSignature' => VerifyAppSignature::class,
];

View File

@ -18,10 +18,12 @@ $routes->get('metadata', 'SamlController::metadata');
//login api
$routes->group('api', ['filter' => 'appSignature'], function ($routes) {
$routes->post('auth/login', 'AuthController::login');
$routes->get('auth/oauthClient', 'AuthController::oauthClient');
$routes->post('auth/oauthlogin', 'AuthController::oauthlogin');
$routes->get('auth/msRedirectionHandler', 'AuthController::msRedirectionHandler');
});
//forgot password
@ -30,7 +32,7 @@ $routes->post('forgotPassword/changePassword', 'UserController::forgotChangePass
//api's with token
$routes->group('api', ['filter' => 'jwtAuth'], function ($routes) {
$routes->group('api', ['filter' => 'jwtAuth|appSignature'], function ($routes) {
//Organization
@ -189,3 +191,5 @@ $routes->get('logout', 'AuthController::logout');

View File

@ -0,0 +1,36 @@
<?php
namespace App\Filters;
use CodeIgniter\HTTP\RequestInterface;
use CodeIgniter\HTTP\ResponseInterface;
use CodeIgniter\Filters\FilterInterface;
class VerifyAppSignature implements FilterInterface
{
public function before(RequestInterface $request, $arguments = null)
{
// Get the header sent by the Flutter app
$clientSignature = $request->getHeaderLine('App-Signature');
// Load the server's expected signature from the .env
$validSignature = getenv('APP_SIGNATURE');
// Check if signature is valid
if ($clientSignature !== $validSignature) {
return service('response')
->setStatusCode(403)
->setJSON([
'status' => false,
'message' => 'Forbidden: Invalid App Signature',
]);
}
// allow request to proceed
}
public function after(RequestInterface $request, ResponseInterface $response, $arguments = null)
{
// nothing to do after response
}
}

View File

@ -821,8 +821,8 @@ if (!function_exists('send_email_agent')) {
"to" => [
["email_address" => ["address" => $value['email']]]
],
"subject" => $templateData['subject'],
"htmlbody" => $templateData['body_html'],
"subject" => $subject,
"htmlbody" => $html,
];
if (!empty($attachments)) {

View File

@ -1 +0,0 @@
,smart,smart-Vostro-15-3568,07.08.2025 10:57,file:///home/smart/.config/libreoffice/4;