Skip to main content

Overview

Finanzapp supports two authentication methods: traditional email/password authentication and Google OAuth integration. All authenticated requests use PHP session-based authentication.

Authentication Methods

Email/Password

Traditional authentication with email and password

Google OAuth

Single sign-on using Google accounts

Email/Password Authentication

Login Endpoint

Request Parameters

string
required
User’s email address (must be a valid email format)
string
required
User’s password (minimum 8 characters, at least one uppercase letter and one number)
string
reCAPTCHA token for bot protection (optional but recommended)

Response

boolean
required
Indicates if the login was successful
string
Human-readable message about the operation
object
User information object (only included on success)

Example Response

Success
Error - Invalid Credentials
Error - Forbidden Access

Registration Endpoint

Request Parameters

string
required
User’s full name
string
required
User’s email address (must be unique and valid)
string
required
User’s password (minimum 8 characters, one uppercase, one number)
string
required
Password confirmation (must match password)
string
required
Terms and conditions acceptance (must be “on”)
string
Newsletter subscription preference (“on” or empty)

Response

boolean
required
Indicates if the registration was successful
string
required
Human-readable message about the operation

Example Response

Success
Error - Email Already Exists

Google OAuth Authentication

Login with Google

Finanzapp integrates with Google Sign-In for seamless authentication.

Request Parameters

string
required
Google JWT credential token received from Google Sign-In

Response

string
required
Status of the operation: "exists" (existing user) or "inserted" (new user)
object
User information extracted from Google profile

Register with Google

Similar to login, but uses a redirect mode:

Session Management

Once authenticated, Finanzapp creates a PHP session that persists across requests.

Session Data Structure

The server stores the following information in $_SESSION['user']:

Checking Authentication Status

Protected pages verify authentication using:

Logout

Logout Endpoint

Endpoint Details

URL: POST /app/auth/logout.php Headers Required:
  • X-Requested-With: XMLHttpRequest

Response

boolean
required
Indicates if logout was successful
string
required
Human-readable message

Implementation

The logout endpoint (source: /home/daytona/workspace/source/app/auth/logout.php:18-21):

Example Response

Success
Error - Invalid Request

Security Considerations

Important Security Notes:
  1. All authentication endpoints require the X-Requested-With: XMLHttpRequest header
  2. Direct browser access to API endpoints will return a 403 Forbidden error
  3. Passwords must meet complexity requirements (8+ chars, uppercase, number)
  4. reCAPTCHA integration prevents automated attacks
  5. Sessions are managed server-side with PHP’s built-in session handling

Password Requirements

Passwords must meet the following criteria (validated client-side and server-side):
  • Minimum 8 characters
  • At least one uppercase letter
  • At least one number
  • No maximum length limit

Error Handling

All authentication endpoints return consistent error responses:
Error messages are returned in Spanish by default. The frontend uses the translation system for internationalization.

Next Steps

API Endpoints

Explore all available API endpoints

User Management

Learn about user profile and account management