v3.0.0.2
FlatlyPage
- <?php
- require_once __DIR__ . '/../config.php';
-
- header('Content-Type: application/json; charset=utf-8');
- header('Cache-Control: no-store');
- header('X-Content-Type-Options: nosniff');
-
- function analytics_respond(int $status, array $payload): void
- {
- http_response_code($status);
- echo json_encode($payload, JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES | JSON_INVALID_UTF8_SUBSTITUTE);
- exit;
- }
-
- if (($_SERVER['REQUEST_METHOD'] ?? '') !== 'POST') {
- header('Allow: POST');
- analytics_respond(405, ['ok' => false, 'error' => 'Method not allowed.']);
- }
-
- if (!is_logged_in()) {
- analytics_respond(401, ['ok' => false, 'error' => 'Your session expired. Reload the page and sign in again.']);
- }
- check_ip_ban();
-
- if (!verify_csrf_token((string) ($_SERVER['HTTP_X_CSRF_TOKEN'] ?? ''))) {
- analytics_respond(403, ['ok' => false, 'error' => 'Your session timed out. Reload the page and try again.']);
- }
-
- $maxBody = 4194304;
- if ((int) ($_SERVER['CONTENT_LENGTH'] ?? 0) > $maxBody) {
- analytics_respond(413, ['ok' => false, 'error' => 'Your scripts are too large to save.']);
- }
-
- $input = json_decode((string) file_get_contents('php://input', false, null, 0, $maxBody + 1), true);
- $decoded = is_array($input) && is_string($input['payload'] ?? null) ? base64_decode($input['payload'], true) : false;
- $data = $decoded !== false ? json_decode($decoded, true) : null;
- if (!is_array($data)) {
- analytics_respond(400, ['ok' => false, 'error' => 'Something went wrong. Reload the page and try again.']);
- }
-
- $system = get_system_settings();
- $system['analytics'] = flatly_clean_analytics($data);
- if (!save_page('system', $system)) {
- analytics_respond(500, ['ok' => false, 'error' => "Couldn't save. Check the folder permissions on your server."]);
- }
-
- analytics_respond(200, ['ok' => true, 'analytics' => $system['analytics']]);
-