T.ME/BIBIL_0DAY
CasperSecurity


Server : Apache/2
System : Linux server-15-235-50-60 5.15.0-164-generic #174-Ubuntu SMP Fri Nov 14 20:25:16 UTC 2025 x86_64
User : gositeme ( 1004)
PHP Version : 8.2.29
Disable Function : exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
Directory :  /home/gositeme/domains/soundstudiopro.com/private_html/api/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : /home/gositeme/domains/soundstudiopro.com/private_html/api/toggle_like.php
<?php
// Ensure no output before headers
if (ob_get_level() > 0) {
    ob_clean();
} else {
    ob_start();
}

// Start session first
if (session_status() === PHP_SESSION_NONE) {
    session_start();
}

require_once '../config/database.php';

// Clear any output that might have been generated
ob_clean();

header('Content-Type: application/json');
header('Cache-Control: no-cache, must-revalidate');

// Only allow POST requests
if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
    http_response_code(405);
    echo json_encode(['success' => false, 'error' => 'Method not allowed']);
    exit;
}

// Check if user is logged in
if (!isset($_SESSION['user_id'])) {
    http_response_code(401);
    echo json_encode(['success' => false, 'error' => 'User must be logged in']);
    exit;
}

// Get JSON input
$raw_input = file_get_contents('php://input');
$input = json_decode($raw_input, true);

// Handle JSON decode errors
if (json_last_error() !== JSON_ERROR_NONE) {
    error_log("JSON decode error in toggle_like.php: " . json_last_error_msg() . " - Input: " . substr($raw_input, 0, 100));
    http_response_code(400);
    echo json_encode(['success' => false, 'error' => 'Invalid JSON input']);
    exit;
}

$track_id = $input['track_id'] ?? null;

// Validate track_id
if (!$track_id) {
    http_response_code(400);
    echo json_encode(['success' => false, 'error' => 'Track ID is required']);
    exit;
}

// Validate track_id is numeric
if (!is_numeric($track_id) || (int)$track_id <= 0) {
    http_response_code(400);
    echo json_encode(['success' => false, 'error' => 'Invalid track ID']);
    exit;
}

$track_id = (int)$track_id;

try {
    $pdo = getDBConnection();
    
    if (!$pdo) {
        throw new Exception('Database connection failed');
    }
    
    // Verify track exists
    $stmt = $pdo->prepare("SELECT id FROM music_tracks WHERE id = ?");
    $stmt->execute([$track_id]);
    $track = $stmt->fetch();
    
    if (!$track) {
        http_response_code(404);
        echo json_encode(['success' => false, 'error' => 'Track not found']);
        exit;
    }
    
    // Check if user already liked the track
    $stmt = $pdo->prepare("SELECT id FROM track_likes WHERE track_id = ? AND user_id = ?");
    $stmt->execute([$track_id, $_SESSION['user_id']]);
    $existing_like = $stmt->fetch();
    
    if ($existing_like) {
        // Unlike the track
        $stmt = $pdo->prepare("DELETE FROM track_likes WHERE track_id = ? AND user_id = ?");
        $stmt->execute([$track_id, $_SESSION['user_id']]);
        $liked = false;
    } else {
        // Like the track
        $stmt = $pdo->prepare("INSERT INTO track_likes (track_id, user_id, created_at) VALUES (?, ?, NOW())");
        $stmt->execute([$track_id, $_SESSION['user_id']]);
        $liked = true;
    }
    
    // Get updated like count
    $stmt = $pdo->prepare("SELECT COUNT(*) as like_count FROM track_likes WHERE track_id = ?");
    $stmt->execute([$track_id]);
    $result = $stmt->fetch(PDO::FETCH_ASSOC);
    $like_count = (int)($result['like_count'] ?? 0);
    
    $response = json_encode([
        'success' => true,
        'liked' => $liked,
        'like_count' => $like_count
    ], JSON_UNESCAPED_UNICODE);
    
    // Ensure no trailing whitespace
    echo trim($response);
    
} catch (PDOException $e) {
    error_log("Database error in toggle_like.php: " . $e->getMessage() . " | Track ID: " . ($track_id ?? 'N/A') . " | User ID: " . ($_SESSION['user_id'] ?? 'N/A'));
    http_response_code(500);
    echo json_encode(['success' => false, 'error' => 'Database error occurred']);
} catch (Exception $e) {
    error_log("Error in toggle_like.php: " . $e->getMessage() . " | Track ID: " . ($track_id ?? 'N/A') . " | User ID: " . ($_SESSION['user_id'] ?? 'N/A'));
    http_response_code(500);
    echo json_encode(['success' => false, 'error' => 'Internal server error']);
} finally {
    // Ensure no extra output
    if (ob_get_level() > 0) {
        ob_end_flush();
    }
}
?> 

CasperSecurity Mini