'Method not allowed']); exit; } $username = trim($_GET['username'] ?? ''); $filepath = trim($_GET['filepath'] ?? ''); // Validate username if (!preg_match('/^[a-z0-9]{3,32}$/', $username)) { http_response_code(400); echo json_encode(['error' => 'Invalid username']); exit; } // Sanitise filepath — no directory traversal $filepath = basename($filepath); if (empty($filepath)) { http_response_code(400); echo json_encode(['error' => 'Invalid filepath']); exit; } // Check user exists $db = new PDO('sqlite:/data/db/platform.sqlite'); $db->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); $stmt = $db->prepare('SELECT id FROM users WHERE username = ?'); $stmt->execute([$username]); if (!$stmt->fetch()) { http_response_code(404); echo json_encode(['error' => 'User not found']); exit; } $dest = "/data/sites/{$username}/htdocs/{$filepath}"; if (!file_exists($dest)) { http_response_code(404); echo json_encode(['error' => 'File not found']); exit; } $content = file_get_contents($dest); echo json_encode([ 'success' => true, 'username' => $username, 'filepath' => $filepath, 'content' => $content ]);