Update api.php

1. Improved input handling using `filter_input` with `FILTER_SANITIZE_STRING`.
2. Enhanced error handling for invalid parameters and cURL errors.
This commit is contained in:
Danii Saahir 2024-05-17 00:11:11 +08:00 committed by GitHub
parent 087003b134
commit 3a0f6e24fb
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

132
api.php
View file

@ -1,115 +1,81 @@
<?php
$query = $_GET['q'];
$bookmark = null;
if (array_key_exists("bookmark", $_GET)) {
$bookmark = urldecode($_GET["bookmark"]);
require "misc/tools.php";
$query = filter_input(INPUT_GET, 'q', FILTER_SANITIZE_STRING);
if (!$query) {
http_response_code(400);
echo json_encode(["error" => "Invalid query parameter."]);
exit;
}
$csrftoken = null;
if (array_key_exists("csrftoken", $_GET)) {
$csrftoken = $_GET["csrftoken"];
}
$bookmark = isset($_GET["bookmark"]) ? urldecode($_GET["bookmark"]) : null;
$csrftoken = $_GET["csrftoken"]??null;
$url = "https://www.pinterest.com/resource/BaseSearchResource/get/";
class SearchResult
{
public $images;
public $bookmark;
class SearchResult {
public $images = [];
public $bookmark = null;
}
$header_function = function($ch, $rawheader)
{
global $csrftoken;
$header_function = function ($ch, $rawheader) use (&$csrftoken) {
$len = strlen($rawheader);
$header = explode(":", $rawheader, 2);
if (count($header) != 2)
if (count($header) != 2) {
return $len;
// we are only interested in set-cookie header
if (trim($header[0]) != "set-cookie")
}
if (trim($header[0]) != "set-cookie") {
return $len;
}
$cookie = explode(";", trim($header[1]), 2);
$cookie = explode("=", $cookie[0], 2);
switch ($cookie[0])
{
case "csrftoken":
$csrftoken = $cookie[1];
if ($cookie[0] === "csrftoken") {
$csrftoken = $cookie[1];
}
return $len;
};
$prepare_search_curl_obj = function($query, $bookmark) use ($url, $header_function, $csrftoken)
{
$data_param_obj = array(
"options"=>array(
"query"=>$query
)
);
if ($bookmark != null)
$data_param_obj["options"]["bookmarks"] = array($bookmark);
$data_param = urlencode(json_encode($data_param_obj));
$headers = array();
if ($csrftoken != null)
{
$prepare_search_curl_obj = function ($query, $bookmark) use ($url, $header_function, $csrftoken) {
$data_param_obj = ["options" => ["query" => $query]];
if ($bookmark !== null) {
$data_param_obj["options"]["bookmarks"] = [$bookmark];
}
$data_param = json_encode($data_param_obj);
$headers = [];
if ($csrftoken !== null) {
$headers[] = "x-csrftoken: $csrftoken";
$headers[] = "cookie: csrftoken=$csrftoken";
}
$finalurl = $url;
if ($bookmark == null)
$finalurl = "$url?data=$data_param";
$finalurl = "$url?data=" . urlencode($data_param);
$ch = curl_init($finalurl);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_HEADERFUNCTION, $header_function);
curl_setopt($ch, CURLOPT_HTTPHEADER, $headers);
if ($bookmark != null)
{
if ($bookmark !== null) {
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, "data=$data_param");
curl_setopt($ch, CURLOPT_POSTFIELDS, "data=" . urlencode($data_param));
}
return $ch;
};
$search = function($query, $bookmark) use($prepare_search_curl_obj)
{
$search = function ($query, $bookmark) use ($prepare_search_curl_obj) {
$ch = $prepare_search_curl_obj($query, $bookmark);
$response = curl_exec($ch);
if (curl_errno($ch)) {
http_response_code(500);
echo json_encode(["error" => curl_error($ch) ]);
curl_close($ch);
exit;
}
$data = json_decode($response);
$images = array();
foreach ($data->{"resource_response"}->{"data"}->{"results"} as $result)
{
$image = $result->{"images"}->{"orig"};
$url = $image->{"url"};
array_push($images, $url);
}
echo json_encode($images);
curl_close($ch);
$result = new SearchResult();
$result->images = $images;
if (property_exists($data->{"resource_response"}, "bookmark"))
$result->bookmark = $data->{"resource_response"}->{"bookmark"};
if (isset($data->resource_response->data->results)) {
foreach ($data->resource_response->data->results as $item) {
if (isset($item->images->orig->url)) {
$result->images[] = $item->images->orig->url;
}
}
}
if (isset($data->resource_response->bookmark)) {
$result->bookmark = $data->resource_response->bookmark;
}
return $result;
};
$result = $search($query, $bookmark);
if ($result->bookmark != null)
{
$query_encoded = urlencode($query);
$bookmark_encoded = urlencode($result->bookmark);
$csrftoken_encoded = urlencode($csrftoken);
// echo "<h2 style=\"text-align: center;\"><a href=\"/search.php?q=$query_encoded&bookmark=$bookmark_encoded&csrftoken=$csrftoken_encoded\">Next page</a></h2><br><br><br>";
}
header("Content-Type: application/json");
header("Content-Type: application/json");
echo json_encode($result);
?>