path correction

This commit is contained in:
sandhiya-hepl
2026-07-16 10:07:30 +05:30
parent abb35c0e03
commit 78749c860d
9 changed files with 59 additions and 412 deletions
+8 -11
View File
@@ -1,25 +1,22 @@
# Deployed under /citpl_website/ on Apache.
# Requires: mod_rewrite, mod_headers, PHP curl
# API: PHP proxy to Node on 127.0.0.1:3001 (start with: npm run server / pm2)
# Deployed under /citpl_website/ Apache must proxy API to the Node server.
# Requires: mod_rewrite, mod_proxy, mod_proxy_http, mod_headers
# Start Node on the host: npm run server (or pm2 start server/index.js)
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /citpl_website/
# API -> PHP proxy (works without mod_proxy)
RewriteRule ^api(?:/.*)?$ api/index.php [QSA,L]
# Uploads -> PHP proxy
RewriteRule ^uploads/(.*)$ uploads-proxy.php?file=$1 [QSA,L]
# Proxy API + uploads to Express (Node) on port 3001
RewriteRule ^api/(.*)$ http://127.0.0.1:3001/api/$1 [P,L]
RewriteRule ^uploads/(.*)$ http://127.0.0.1:3001/uploads/$1 [P,L]
</IfModule>
# Host security headers use frame-ancestors 'none' + X-Frame-Options DENY.
# Edit them so admin can embed preview.html (same origin).
# Allow admin login preview iframe (same origin)
<IfModule mod_headers.c>
Header always edit Content-Security-Policy "frame-ancestors 'none'" "frame-ancestors 'self'"
Header always edit X-Frame-Options "DENY" "SAMEORIGIN"
<FilesMatch "^(preview\.html|preview\.php|index\.html)$">
<FilesMatch "^(preview\.html|index\.html)$">
Header unset X-Frame-Options
Header always unset X-Frame-Options
Header unset Content-Security-Policy
-119
View File
@@ -1,119 +0,0 @@
<?php
/**
* Forward /citpl_website/api/* → Node (Express) without requiring Apache mod_proxy.
* Start the API on the server: cd /path/to/app && npm run server
* Or: pm2 start server/index.js --name citpl-api
*/
declare(strict_types=1);
$apiOrigin = getenv('CITPL_API_ORIGIN') ?: 'http://127.0.0.1:3001';
$requestUri = $_SERVER['REQUEST_URI'] ?? '/api';
$path = parse_url($requestUri, PHP_URL_PATH) ?: '/api';
// Keep everything from "/api" onward (works under /citpl_website/api/...)
if (preg_match('#(/api(?:/.*)?)$#', $path, $m)) {
$forwardPath = $m[1];
} else {
$forwardPath = '/api';
}
$query = $_SERVER['QUERY_STRING'] ?? '';
$url = rtrim($apiOrigin, '/') . $forwardPath . ($query !== '' ? '?' . $query : '');
$method = $_SERVER['REQUEST_METHOD'] ?? 'GET';
$body = file_get_contents('php://input');
if ($body === false) {
$body = '';
}
$headers = [];
if (function_exists('getallheaders')) {
foreach (getallheaders() as $name => $value) {
$lower = strtolower((string) $name);
if ($lower === 'host' || $lower === 'content-length') {
continue;
}
$headers[] = $name . ': ' . $value;
}
} else {
foreach ($_SERVER as $key => $value) {
if (strpos($key, 'HTTP_') !== 0) {
continue;
}
$name = str_replace(' ', '-', ucwords(strtolower(str_replace('_', ' ', substr($key, 5)))));
if (strtolower($name) === 'host') {
continue;
}
$headers[] = $name . ': ' . $value;
}
if (!empty($_SERVER['CONTENT_TYPE'])) {
$headers[] = 'Content-Type: ' . $_SERVER['CONTENT_TYPE'];
}
}
if (!function_exists('curl_init')) {
http_response_code(500);
header('Content-Type: application/json');
echo json_encode([
'error' => 'PHP curl extension is required for the API proxy',
'code' => 'PROXY_MISCONFIGURED',
]);
exit;
}
$ch = curl_init($url);
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => $method,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HEADER => true,
CURLOPT_FOLLOWLOCATION => false,
CURLOPT_CONNECTTIMEOUT => 5,
CURLOPT_TIMEOUT => 60,
CURLOPT_HTTPHEADER => $headers,
]);
if ($method !== 'GET' && $method !== 'HEAD') {
curl_setopt($ch, CURLOPT_POSTFIELDS, $body);
}
$response = curl_exec($ch);
if ($response === false) {
$err = curl_error($ch);
curl_close($ch);
http_response_code(502);
header('Content-Type: application/json');
echo json_encode([
'error' => 'API server unreachable. On the host run: npm run server (port 3001)',
'detail' => $err,
'code' => 'BAD_GATEWAY',
]);
exit;
}
$status = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
$headerSize = (int) curl_getinfo($ch, CURLINFO_HEADER_SIZE);
curl_close($ch);
$rawHeaders = substr($response, 0, $headerSize);
$responseBody = substr($response, $headerSize);
http_response_code($status > 0 ? $status : 502);
$skip = ['transfer-encoding', 'connection', 'keep-alive', 'content-length'];
foreach (explode("\r\n", $rawHeaders) as $line) {
if ($line === '' || stripos($line, 'HTTP/') === 0) {
continue;
}
$parts = explode(':', $line, 2);
if (count($parts) < 2) {
continue;
}
$name = trim($parts[0]);
if (in_array(strtolower($name), $skip, true)) {
continue;
}
header($name . ':' . $parts[1], false);
}
echo $responseBody;
-66
View File
@@ -1,66 +0,0 @@
<?php
/**
* Forward /citpl_website/uploads/* → Node static uploads (no mod_proxy required).
*/
declare(strict_types=1);
$apiOrigin = getenv('CITPL_API_ORIGIN') ?: 'http://127.0.0.1:3001';
$file = $_GET['file'] ?? '';
$file = str_replace(['..', '\\'], '', $file);
$file = ltrim($file, '/');
if ($file === '') {
http_response_code(400);
header('Content-Type: application/json');
echo json_encode(['error' => 'Missing file', 'code' => 'VALIDATION']);
exit;
}
$url = rtrim($apiOrigin, '/') . '/uploads/' . str_replace(' ', '%20', $file);
if (!function_exists('curl_init')) {
http_response_code(500);
exit('curl required');
}
$ch = curl_init($url);
curl_setopt_array($ch, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HEADER => true,
CURLOPT_FOLLOWLOCATION => false,
CURLOPT_CONNECTTIMEOUT => 5,
CURLOPT_TIMEOUT => 60,
]);
$response = curl_exec($ch);
if ($response === false) {
curl_close($ch);
http_response_code(502);
exit('Upload server unreachable');
}
$status = (int) curl_getinfo($ch, CURLINFO_HTTP_CODE);
$headerSize = (int) curl_getinfo($ch, CURLINFO_HEADER_SIZE);
curl_close($ch);
http_response_code($status > 0 ? $status : 502);
$rawHeaders = substr($response, 0, $headerSize);
$body = substr($response, $headerSize);
$skip = ['transfer-encoding', 'connection', 'keep-alive'];
foreach (explode("\r\n", $rawHeaders) as $line) {
if ($line === '' || stripos($line, 'HTTP/') === 0) {
continue;
}
$parts = explode(':', $line, 2);
if (count($parts) < 2) {
continue;
}
$name = trim($parts[0]);
if (in_array(strtolower($name), $skip, true)) {
continue;
}
header($name . ':' . $parts[1], false);
}
echo $body;