🔒️ Improved and fixed security issues by adding .env file for DB connection and loading class.

This commit is contained in:
Florian Sylvain
2021-09-24 22:37:00 +02:00
parent a05438ab76
commit f56ba7e3c8
3 changed files with 51 additions and 6 deletions
+1
View File
@@ -0,0 +1 @@
/ProjetProgWeb/env.php
+4 -6
View File
@@ -1,15 +1,13 @@
<?php <?php
require_once('dotEnv.php');
(new DotEnv(__DIR__ . '/../.env'))->load();
class conf class conf
{ {
private pdo $pdo; private pdo $pdo;
public function __construct()
{
$this->pdo = new PDO('mysql:host=localhost;dbname=projet_prog_web', 'root', 'root');
}
public function getPDO() : pdo { public function getPDO() : pdo {
return $this->pdo; return new PDO('mysql:host=localhost;dbname=' . getenv('DBNAME'), getenv('USERNAME'), getenv('PASSWORD'));
} }
} }
+46
View File
@@ -0,0 +1,46 @@
<?php
// Since I don't know atm if I am allowed to use external libs like dotenv, I used this piece of code to load .env file.
// Link : https://dev.to/fadymr/php-create-your-own-php-dotenv-3k2i
// Author : F.R Michel
class dotEnv
{
/**
* The directory where the .env file can be located.
* @var string
*/
protected string $path;
public function __construct(string $path)
{
if(!file_exists($path)) {
throw new \InvalidArgumentException(sprintf('%s does not exist', $path));
}
$this->path = $path;
}
public function load() :void
{
if (!is_readable($this->path)) {
throw new \RuntimeException(sprintf('%s file is not readable', $this->path));
}
$lines = file($this->path, FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES);
foreach ($lines as $line) {
if (strpos(trim($line), '#') === 0) {
continue;
}
list($name, $value) = explode('=', $line, 2);
$name = trim($name);
$value = trim($value);
if (!array_key_exists($name, $_SERVER) && !array_key_exists($name, $_ENV)) {
putenv(sprintf('%s=%s', $name, $value));
$_ENV[$name] = $value;
$_SERVER[$name] = $value;
}
}
}
}