KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I am building a RESTful api with laravel using the RESTful controller property. So far i've been able to get most of it working. The issue am having now is authenication, am trying to use Amazon approach using a "user_id" and "signature". Am creating the signature using php's 'hash_hmac()'. this an example api controller class Api_Tasks_Controller extends Api_Controller { public $restful = true; public function get_index($id = null) { $this->verfiy_request(); if(!is_null($id)) { return Response::json(array("tasks"=>"just one"),200); } else { return Response::json(array("tasks"=>"everthing"),200); } } } and this the api controller class class Api_Controller extends Controller { public function verify_request() { //user id $user_id = (int) Input::get('user_id'); //signature $sig = Input::get('sig'); //Lookup user $user = Sentry::user($user_id); if($user) { //user email $email = $user->email; //user api key $api_key = $user->metadata['api_key']; //recreate signature $_sig = hash_hmac("sha256",$email.$user_id,$api_key); if($_sig === $sig) { return Response::json(array("message"=>"Request Ok"),200); } else { return Response::json(array("message"=>"Request Bad"),400); } } else { return Response::json(array("message"=>"Request not authorized"),401); } } Making a get request http://api.xyz.com/v1/tasks/1?user_id=1&sig=41295da38eadfa56189b041a022c6ae0fdcbcd5e65c83f0e9aa0e6fbae666cd8 always returns a successful message even when i alter the value of the user_id parameter which should void the signature an make
Tags (comma-separated)
Save Edits
Cancel