Files
geograsim/App/php/templates/_scripts.php
T
Adminator 32ed869f23 Simplify: PHP page dedup, secure UUID, input validation, remove redundant headers
- pages/*.php: 11 files reduced to 1-liners via shared renderPage() helper
- Session: UUID generation uses random_bytes() instead of mt_rand()
- Session: logout cookie uses same security options as create
- API saves: size limits on key (100) and data (500KB)
- API sessions: displayName capped at 64 chars
- API: removed redundant Content-Type headers (Response::json handles it)
- API dashboard: replaced SELECT * with explicit columns

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-13 16:54:43 +02:00

56 lines
2.0 KiB
PHP

<?php
/**
* Vite Manifest Reader
* Liest dist/.vite/manifest.json und gibt die korrekten Script-Tags aus.
* Im Dev-Modus (kein manifest vorhanden) wird direkt auf die TS-Quellen verwiesen.
*/
function viteAssets(string $entry): void {
$manifestPath = APP_ROOT . '/dist/.vite/manifest.json';
// Production: Lese Manifest
if (file_exists($manifestPath)) {
$manifest = json_decode(file_get_contents($manifestPath), true);
$chunk = $manifest[$entry] ?? null;
if (!$chunk) return;
// CSS
foreach ($chunk['css'] ?? [] as $css) {
echo '<link rel="stylesheet" href="' . BASE_PATH . '/dist/' . $css . '">' . "\n";
}
// Preload imports
foreach ($chunk['imports'] ?? [] as $importKey) {
$imp = $manifest[$importKey] ?? null;
if ($imp) {
echo '<link rel="modulepreload" crossorigin href="' . BASE_PATH . '/dist/' . $imp['file'] . '">' . "\n";
}
}
// Main entry
echo '<script type="module" crossorigin src="' . BASE_PATH . '/dist/' . $chunk['file'] . '"></script>' . "\n";
}
// Dev fallback: keine Manifest-Datei → direkte TS-Referenz (Vite Dev Server)
}
/** Session-Kontext als JS-Variable injizieren */
function injectSessionContext(): void {
$ctx = [
'sessionId' => Session::studentId(),
'teacherId' => Session::teacherId(),
'baseUrl' => BASE_URL,
'basePath' => BASE_PATH,
];
echo '<script>window.__GGS__ = ' . json_encode($ctx, JSON_UNESCAPED_UNICODE) . ';</script>' . "\n";
}
/** Seite rendern: HTML laden, Session-Kontext injizieren, ausgeben */
function renderPage(string $htmlFile): void {
$html = file_get_contents(APP_ROOT . '/' . $htmlFile);
$ctx = '<script>window.__GGS__ = ' . json_encode([
'sessionId' => Session::studentId(),
'teacherId' => Session::teacherId(),
'baseUrl' => BASE_URL,
'basePath' => BASE_PATH,
], JSON_UNESCAPED_UNICODE) . ';</script>';
echo str_replace('</body>', $ctx . "\n</body>", $html);
}