Files
sam-api/app/Http/Controllers/Api/V1/ApiController.php

133 lines
3.7 KiB
PHP
Raw Normal View History

2025-07-17 10:05:47 +09:00
<?php
namespace App\Http\Controllers\Api\V1;
2025-07-17 10:05:47 +09:00
2025-07-29 13:00:25 +09:00
use App\Http\Controllers\Controller;
use App\Models\User;
2025-07-17 10:05:47 +09:00
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Str;
class ApiController extends Controller
{
/**
* @OA\Get(
* path="/api/v1/debug-apikey",
2025-07-17 10:05:47 +09:00
* tags={"API Key 인증"},
* summary="API Key 인증 확인",
* security={
* {"ApiKeyAuth": {}},
* {"BearerAuth": {}}
* },
2025-07-17 10:05:47 +09:00
* @OA\Response(
* response=200,
* description="API Key 인증 성공"
* ),
* @OA\Response(
* response=401,
* description="인증 실패"
* )
* )
*/
public function debugApikey()
{
$message = 'API Key 인증 성공';
return response()->json(['message' => $message]);
2025-07-17 10:05:47 +09:00
}
/**
* @OA\Post(
* path="/api/v1/login",
2025-07-17 10:05:47 +09:00
* summary="회원 토큰 정보확인",
* tags={"Auth"},
* security={{"ApiKeyAuth": {}},},
2025-07-17 10:05:47 +09:00
* @OA\RequestBody(
* required=true,
* @OA\JsonContent(
* required={"user_id", "user_pwd"},
* @OA\Property(property="user_id", type="string", example="test"),
* @OA\Property(property="user_pwd", type="string", example="testpass")
2025-07-17 10:05:47 +09:00
* )
* ),
* @OA\Response(
* response=200,
* description="로그인 성공",
* @OA\JsonContent(
* @OA\Property(property="message", type="string"),
* @OA\Property(property="user_token", type="string")
2025-07-17 10:05:47 +09:00
* )
* ),
* @OA\Response(response=401, description="로그인 실패")
* )
*/
public function login(Request $request)
{
$userId = $request->input('user_id');
$userPwd = $request->input('user_pwd');
if (!$userId || !$userPwd) {
return response()->json(['error' => '아이디 또는 비밀번호 누락'], 400);
}
$user = User::where('user_id', $userId)->first();
2025-07-17 10:05:47 +09:00
if (!$user) {
return response()->json(['error' => '사용자를 찾을 수 없습니다.'], 404);
}
$isValid = false;
if (Str::startsWith($user->password, '$2y$')) {
2025-07-17 10:05:47 +09:00
// bcrypt로 해싱된 경우
$isValid = Hash::check($userPwd, $user->password);
2025-07-17 10:05:47 +09:00
} else {
// sha256으로 해싱된 경우
$isValid = strtoupper(hash('sha256', $userPwd)) === strtoupper($user->password);
2025-07-17 10:05:47 +09:00
}
if (!$isValid) {
return response()->json(['error' => '아이디 또는 비밀번호가 올바르지 않습니다.'], 401);
}
//인증토큰 생성
$token = $user->createToken('front-app')->plainTextToken;
2025-07-17 10:05:47 +09:00
// 선택: DB에 신규 token 저장
$USER_TOKEN = hash('sha256', $user->mb_id.date('YmdHis'));
$user->remember_token = $USER_TOKEN;
$user->save();
return response()->json([
'message' => '로그인 성공',
'user_token' => $token,
2025-07-17 10:05:47 +09:00
]);
}
/**
* @OA\Post(
* path="/api/v1/logout",
2025-07-17 10:05:47 +09:00
* summary="로그아웃 (Access 및 Token 무효화)",
* tags={"Auth"},
* security={
* {"ApiKeyAuth": {}},
* {"BearerAuth": {}}
* },
2025-07-17 10:05:47 +09:00
* @OA\Response(response=200, description="로그아웃 성공"),
* @OA\Response(response=401, description="인증 실패")
* )
*/
public function logout(Request $request)
{
2025-07-28 11:44:07 +09:00
//인증토큰 삭제
$request->user()->currentAccessToken()->delete();
2025-07-17 10:05:47 +09:00
return response()->json(['message' => '로그아웃 완료']);
}
}