View Source

Preview the code here, or download the complete usable site as one ZIP. It contains the same unminified, untranspiled PHP, CSS, images, and configuration that run the site.

↓ Download complete site source
router.php 72 lines
<?php
/**
* PHP built-in server router.
* Strips the BASE_PATH prefix and dispatches to the correct file in public/.
*/
$configuredBase = getenv('BASE_PATH');
$base = $configuredBase !== false ? rtrim($configuredBase, '/') : '';
$uri = parse_url($_SERVER['REQUEST_URI'], PHP_URL_PATH);
if (!is_string($uri) || str_contains($uri, "\0")) {
http_response_code(400);
exit('Bad Request');
}
// Strip base prefix
if ($base !== '' && ($uri === $base || str_starts_with($uri, $base . '/'))) {
$path = substr($uri, strlen($base));
} else {
$path = $uri;
}
if ($path === '' || $path === '/') {
$path = '/index.php';
}
$publicRoot = realpath(__DIR__ . '/public');
$decodedPath = rawurldecode($path);
$segments = explode('/', trim($decodedPath, '/'));
$hasPrivateSegment = false;
foreach ($segments as $segment) {
if ($segment === '..' || $segment === 'includes' || str_starts_with($segment, '.')) {
$hasPrivateSegment = true;
break;
}
}
if (!$hasPrivateSegment && $publicRoot !== false) {
$candidate = $publicRoot . '/' . ltrim($decodedPath, '/');
$file = realpath($candidate);
} else {
$file = false;
}
if ($file !== false
&& str_starts_with($file, $publicRoot . DIRECTORY_SEPARATOR)
&& is_file($file)) {
$ext = pathinfo($file, PATHINFO_EXTENSION);
if ($ext === 'php') {
include $file;
} else {
// Serve static assets (CSS, images, etc.)
$mimes = [
'css' => 'text/css',
'js' => 'application/javascript',
'png' => 'image/png',
'jpg' => 'image/jpeg',
'jpeg' => 'image/jpeg',
'gif' => 'image/gif',
'svg' => 'image/svg+xml',
'ico' => 'image/x-icon',
'woff2'=> 'font/woff2',
];
header('Content-Type: ' . ($mimes[$ext] ?? 'application/octet-stream'));
readfile($file);
}
exit;
}
http_response_code(404);
echo '<!DOCTYPE html><html><body><h1>404 Not Found</h1></body></html>';