Simplify: PHP page dedup, secure UUID, input validation, remove redundant headers

- pages/*.php: 11 files reduced to 1-liners via shared renderPage() helper
- Session: UUID generation uses random_bytes() instead of mt_rand()
- Session: logout cookie uses same security options as create
- API saves: size limits on key (100) and data (500KB)
- API sessions: displayName capped at 64 chars
- API: removed redundant Content-Type headers (Response::json handles it)
- API dashboard: replaced SELECT * with explicit columns

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-04-13 16:54:43 +02:00
parent f22c5ebbfe
commit 32ed869f23
17 changed files with 47 additions and 121 deletions
+8 -8
View File
@@ -1,22 +1,19 @@
<?php
/**
* API: Spielstaende speichern/laden
* GET /api/saves?key=klimawaechter-save → Spielstand laden
* POST /api/saves {key, data, version} → Spielstand speichern
* GET /api/saves?key=klimawaechter-save
* POST /api/saves {key, data, version}
*/
header('Content-Type: application/json; charset=utf-8');
$method = $_SERVER['REQUEST_METHOD'];
$db = Database::get();
if ($method === 'GET') {
$sessionId = Session::studentId();
if (!$sessionId) {
Response::json(['data' => null]);
}
if (!$sessionId) Response::json(['data' => null]);
$key = $_GET['key'] ?? '';
if (!$key) Response::error('key fehlt');
if (!$key || strlen($key) > 100) Response::error('key fehlt oder zu lang');
$row = $db->fetchOne(
'SELECT save_data, save_version FROM game_saves WHERE session_id = ? AND save_key = ?',
@@ -31,6 +28,9 @@ if ($method === 'POST') {
if (!$body || !isset($body['key']) || !isset($body['data'])) {
Response::error('key und data erforderlich');
}
if (strlen($body['key']) > 100 || strlen($body['data']) > 500000) {
Response::error('Payload zu gross', 413);
}
$db->execute(
'INSERT INTO game_saves (session_id, save_key, save_data, save_version)