Code review to prevent misuse of API Endport PHP

Viewed 35

I am having trouble with people misuse my API Endpoint which has been developed using PHP Flat, so to prevent others to access the API I have created a method on my own thoughts to prevent people to submit any request or to handle it by our serverside if it was not originated from our domain.

the code is written in PHP.

every time that I make an AJAX request from the page a token will be generated using this code

$token = sha1(date("Y-m-d H:i:s").session_id()."ITcanBEanyRANDOMstring");
$_SESSION['token'] = $token;
$_SESSION['is_used'] = FALSE;

then on the API End port website, it will check for the token using the code below

if(($_POST['token'] === $_SESSION['token']) && !$_SESSION['is_used']){
 $_SESSION['is_used'] = true;
}

any other suggestion ? is this method secure !!

0 Answers
Related