简体   繁体   English

PHP:在CURL GET Call中使用API​​密钥

[英]PHP: Using API key in CURL GET Call

I have seen the post for using api key for authenticating post calls in curl. 我看过使用api密钥验证curl中的post调用的帖子。 I have a GET call that requires apikey for authorization ie the request must have an authorization header cantaining the apiKey. 我有一个GET调用,需要apikey进行授权,即请求必须有一个授权标头来保存apiKey。 I have obtained the api key and try to use it for a GET call : 我已经获得了api密钥并尝试将其用于GET调用:

<?php

$service_url = 'http://localhost/finals/task_manager/v1/tasks/Authorization:'.$apiKey;
$curl = curl_init($service_url);
curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
$curl_response = curl_exec($curl);
if ($curl_response === false) {
    $info = curl_getinfo($curl);
    curl_close($curl);
    die('error occured during curl exec. Additioanl info: ' . var_export($info));
}

curl_close($curl);
$decoded1 = json_decode($curl_response,true);
if (isset($decoded1->response->status) && $decoded1->response->status == 'ERROR') {
    die('error occured: ' . $decoded1->response->errormessage);
}
echo 'response ok!';
var_export($decoded1->response);
?>

I am getting error in json response: 我在json响应中收到错误:

{"error":true,"message":"Api key is misssing"}

I have tried a few other ways like passing a header array but i keep getting the error. 我尝试了一些其他的方式,如传递一个标题数组,但我不断收到错误。 How to correctly get the curl_response ? 如何正确获取curl_response? How should I pass the Authorization header which uses the api key ? 我应该如何传递使用api密钥的Authorization标头?

The api for the get call I am making is (created using Slim Library) : 我正在进行的get调用的api是(使用Slim Library创建的):

index.php
/**
 * Listing all tasks of particual user
 * method GET
 * url /tasks          
 */
$app->get('/tasks', 'authenticate', function() {
            global $user_id;
            $response = array();
            $db = new DbHandler();

            // fetching all user tasks
            $result = $db->getAllUserTasks($user_id);

            $response["error"] = false;
            $response["tasks"] = array();

            // looping through result and preparing tasks array
            while ($task = $result->fetch_assoc()) {
                $tmp = array();
                $tmp["id"] = $task["id"];
                $tmp["task"] = $task["task"];
                $tmp["status"] = $task["status"];
                $tmp["createdAt"] = $task["created_at"];
                array_push($response["tasks"], $tmp);
            }

            echoRespnse(200, $response);
        });

The authenticate function is : 验证功能是:

in the same index.php file
/**
 * Adding Middle Layer to authenticate every request
 * Checking if the request has valid api key in the 'Authorization' header
 */
function authenticate(\Slim\Route $route) {
    // Getting request headers
    $headers = apache_request_headers();
    $response = array();
    $app = \Slim\Slim::getInstance();

    // Verifying Authorization Header
    if (isset($headers['Authorization'])) {
        $db = new DbHandler();

        // get the api key
        $api_key = $headers['Authorization'];
        // validating api key
        if (!$db->isValidApiKey($api_key)) {
            // api key is not present in users table
            $response["error"] = true;
            $response["message"] = "Access Denied. Invalid Api key";
            echoRespnse(401, $response);
            $app->stop();
        } else {
            global $user_id;
            // get user primary key id
            $user = $db->getUserId($api_key);
            if ($user != NULL)
                $user_id = $user["id"];
        }
    } else {
        // api key is missing in header
        $response["error"] = true;
        $response["message"] = "Api key is misssing";
        echoRespnse(400, $response);
        $app->stop();
    }
}

ok so it should be pretty straightforward... Could you try and add: 好吧所以它应该非常简单...你能尝试添加:

curl_setopt($curl, CURLOPT_HTTPHEADER, array(
'Authorization: ' . $apiKey
));

to your curl? 你的卷曲? After that, do a print_r($headers) in your authenticate() function to see if you receive it ok. 之后,在authenticate()函数中执行print_r($ headers)以查看是否收到它。

Access web service using custom Authorization key. 使用自定义授权密钥访问Web服务。

PHP Client,client.php PHP客户端,client.php

$name = 'Book name';
//Server url
$url = "http://localhost/php-rest/book/$name";
$apiKey = '32Xhsdf7asd5'; // should match with Server key
$headers = array(
     'Authorization: '.$apiKey
);
// Send request to Server
$ch = curl_init($url);
// To save response in a variable from server, set headers;
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_HTTPHEADER, $headers);
// Get response
$response = curl_exec($ch);
// Decode
$result = json_decode($response);

PHP Server, index.php PHP服务器,index.php

header("Content-Type:application/json");
$seceretKey = '32Xhsdf7asd';
$headers = apache_request_headers();
    if(isset($headers['Authorization'])){
        $api_key = $headers['Authorization'];
        if($api_key != $seceretKey) 
        {
            //403,'Authorization faild'; your logic
            exit;
        }
    }

to overcome this problem when passing Api key from Advance rest client use Authorization rather than authorization in header parameter. 从Advance rest客户端传递Api密钥时使用Authorization而不是header参数中的授权来解决此问题。 then it will work. 然后它会工作。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM