feat: implement secure OTP-based payout workflow with dynamic fee calculation and improved authentication checks

This commit is contained in:
Hamza-Ayed
2026-07-19 01:51:39 +03:00
parent 5e80c886a0
commit 085b180bdb
11 changed files with 252 additions and 193 deletions
+3 -3
View File
@@ -119,8 +119,8 @@ switch (strtolower($country)) {
// 6. DB Storage on Success
if ($sentSuccessfully) {
$encryptedPhone = $encryptionHelper->encryptData($receiver);
$encryptedOtp = $encryptionHelper->encryptData($otp);
$encryptedPhone = $encryptionHelper->encryptData($receiver); // Deterministic CBC
$encryptedOtp = $encryptionHelper->encryptDataGCM($otp); // Random GCM
$encryptedEmail = !empty($email) ? $encryptionHelper->encryptData($email) : '';
try {
@@ -143,7 +143,7 @@ if ($sentSuccessfully) {
$encryptedOtp
]);
} elseif ($user_type === 'driver') {
if ($context === 'token_change') {
if ($context === 'token_change' || $context === 'payout') {
// Delete old verification attempts
$stmtDel = $con->prepare("DELETE FROM `token_verification_driver` WHERE `phone_number` = ?");
$stmtDel->execute([$encryptedPhone]);