feat: implement secure OTP-based payout workflow with dynamic fee calculation and improved authentication checks
This commit is contained in:
@@ -67,9 +67,25 @@ if (!function_exists('finalizePayout')) {
|
||||
}
|
||||
|
||||
$driverId = $payout['driver_id'];
|
||||
$payoutFee = 3500;
|
||||
$netAmount = (float)$payout['amount']-$payoutFee; // المبلغ الصافي الذي طلبه السائق
|
||||
$totalDeducted = $netAmount; // المبلغ الإجمالي الذي سيتم خصمه
|
||||
// Fetch driver site to calculate dynamic fee
|
||||
$stmtDriver = $con->prepare("SELECT site FROM driver WHERE id = :id");
|
||||
$stmtDriver->execute([':id' => $driverId]);
|
||||
$driverInfo = $stmtDriver->fetch(PDO::FETCH_ASSOC);
|
||||
$site = $encryptionHelper->decryptData($driverInfo['site'] ?? '');
|
||||
|
||||
$payoutFee = 0.0;
|
||||
if (strtolower($site) === 'syria') {
|
||||
$payoutFee = 35.00;
|
||||
} elseif (strtolower($site) === 'egypt') {
|
||||
$payoutFee = 10.00;
|
||||
} elseif (strtolower($site) === 'jordan') {
|
||||
$payoutFee = 0.00;
|
||||
} else {
|
||||
$payoutFee = 35.00;
|
||||
}
|
||||
|
||||
$netAmount = (float)$payout['amount']; // The amount requested
|
||||
$totalDeducted = $netAmount + $payoutFee; // Total deducted
|
||||
|
||||
// 2. إنشاء معرف دفع رئيسي لهذه المعاملة
|
||||
// نسجل المبلغ الإجمالي المخصوم بالسالب
|
||||
@@ -83,17 +99,16 @@ if (!function_exists('finalizePayout')) {
|
||||
if (!$tokenDriver || !$tokenSiro) throw new Exception('Failed to generate required tokens');
|
||||
logPayoutError("GEN_TOKENS", "Driver and Siro tokens generated successfully.");
|
||||
|
||||
// 4. تسجيل معاملة الخصم في محفظة السائق (driverWallet)
|
||||
$insertDriver = $con->prepare("INSERT INTO driverWallet (driverID, paymentID, amount, paymentMethod) VALUES (:driverID, :paymentID, :amount, :paymentMethod)");
|
||||
$insertDriver->execute([
|
||||
// 4. Update the reserved deduction in driverWallet with the real paymentID
|
||||
$updateDriver = $con->prepare("UPDATE driverWallet SET paymentID = :paymentID, paymentMethod = 'payout' WHERE driverID = :driverID AND paymentMethod = 'payout_reserved' AND amount = :amount LIMIT 1");
|
||||
$updateDriver->execute([
|
||||
':driverID' => $driverId,
|
||||
':paymentID' => $paymentID,
|
||||
':amount' => -$totalDeducted, // تسجيل المبلغ بالسالب
|
||||
':paymentMethod' => 'payout'
|
||||
':amount' => -$totalDeducted
|
||||
]);
|
||||
if ($insertDriver->rowCount() === 0) throw new Exception('Insert to driverWallet failed');
|
||||
|
||||
$con->prepare("UPDATE payment_tokens SET isUsed = TRUE WHERE token = :token")->execute([':token' => $tokenDriver]);
|
||||
logPayoutError("DRIVER_WALLET", "Negative transaction of {$totalDeducted} recorded in driverWallet.");
|
||||
logPayoutError("DRIVER_WALLET", "Updated reserved transaction of {$totalDeducted} in driverWallet.");
|
||||
|
||||
// 5. تسجيل معاملة الربح (العمولة) في محفظة الشركة (siroWallet)
|
||||
$insertSiro = $con->prepare("INSERT INTO siroWallet (driverId, passengerId, amount, paymentMethod, token) VALUES (:driverId, :passengerId, :amount, :paymentMethod, :token)");
|
||||
|
||||
Reference in New Issue
Block a user