# 📖 Users API (PHP + SQLite)

Questa API REST gestisce gli **utenti autorizzati** per il bot Telegram (o altre applicazioni). È scritta in **PHP** con **SQLite** come database.

---

## 🚀 Funzionalità principali
- Autenticazione via **Bearer Token** nell'header `Authorization`
- Supporto a metodi **GET**, **POST**, **DELETE**
- Risposte sempre in formato **JSON**
- Gestione tabella `users` in `user.db`

---

## 🔑 Autenticazione
Tutte le richieste devono includere l'header:
```http
Authorization: Bearer TOKEN123
```
*(cambia `TOKEN123` con un valore sicuro)*

Se l'header non è presente o non è valido → `401 Unauthorized`.

---

## 🔹 Endpoint disponibili

### 1. GET `/users`
**Descrizione:** Ritorna la lista completa degli utenti.

```bash
curl -X GET "https://tuodominio.it/users.php" \
  -H "Authorization: Bearer TOKEN123"
```

📌 **Risposta esempio:**
```json
{
  "status": "success",
  "message": "Lista utenti",
  "data": [
    {"telegram_id":"12345","nome":"Mario","cognome":"Rossi"},
    {"telegram_id":"67890","nome":"Luca","cognome":"Bianchi"}
  ]
}
```

---

### 2. GET `/users?telegram_id=12345`
**Descrizione:** Ritorna i dettagli di un utente specifico.

```bash
curl -X GET "https://tuodominio.it/users.php?telegram_id=12345" \
  -H "Authorization: Bearer TOKEN123"
```

📌 **Risposta esempio (utente trovato):**
```json
{
  "status": "success",
  "message": "Utente trovato",
  "data": {"telegram_id":"12345","nome":"Mario","cognome":"Rossi"}
}
```

📌 **Risposta esempio (utente non trovato):**
```json
{
  "status": "error",
  "message": "Utente non trovato"
}
```

---

### 3. POST `/users`
**Descrizione:** Crea un nuovo utente.

```bash
curl -X POST "https://tuodominio.it/users.php" \
  -H "Authorization: Bearer TOKEN123" \
  -H "Content-Type: application/json" \
  -d '{"telegram_id":"12345","nome":"Mario","cognome":"Rossi"}'
```

📌 **Risposta esempio (successo):**
```json
{
  "status": "success",
  "message": "Utente aggiunto"
}
```

📌 **Risposta esempio (utente già esistente):**
```json
{
  "status": "error",
  "message": "Utente già esistente con questo telegram_id"
}
```

---

### 4. DELETE `/users`
**Descrizione:** Cancella un utente specifico.

```bash
curl -X DELETE "https://tuodominio.it/users.php" \
  -H "Authorization: Bearer TOKEN123" \
  -d "telegram_id=12345"
```

📌 **Risposta esempio (successo):**
```json
{
  "status": "success",
  "message": "Utente eliminato"
}
```

📌 **Risposta esempio (utente non trovato):**
```json
{
  "status": "error",
  "message": "Utente non trovato"
}
```

---

## 📂 Struttura progetto
```
.
├── users.php     # Script principale API REST
├── user.db       # Database SQLite con tabella utenti
└── README.md     # Questo file
```

---

## ⚠️ Note di sicurezza
- Cambia sempre il valore di `$API_TOKEN` con un token sicuro.
- Proteggi l'endpoint con HTTPS.
- Non committare `user.db` se contiene dati reali.

---

✍️ Autore: *[Il tuo nome qui]*

