feat: harden backend security with HMAC verification, SSL validation, and documentation updates while removing legacy scripts.
This commit is contained in:
@@ -14,7 +14,7 @@ if (empty($secretKey)) {
|
||||
|
||||
// --- 1. التحقق من صحة الطلب ---
|
||||
$authHeader = $_SERVER['HTTP_AUTHORIZATION'] ?? '';
|
||||
if ($authHeader !== 'Bearer ' . $secretKey) {
|
||||
if (empty($secretKey) || !hash_equals('Bearer ' . $secretKey, $authHeader)) {
|
||||
http_response_code(403);
|
||||
echo json_encode(['status' => 'error', 'message' => 'Unauthorized Access']);
|
||||
exit();
|
||||
@@ -74,7 +74,7 @@ if (preg_match($pattern_orangemoney_jo, $message_body, $matches)) {
|
||||
|
||||
// كتابة كل شيء في ملف السجل (بالمسار المطلق)
|
||||
$logDir = __DIR__ . '/../../logs';
|
||||
if (!is_dir($logDir)) @mkdir($logDir, 0777, true);
|
||||
if (!is_dir($logDir)) @mkdir($logDir, 0750, true);
|
||||
file_put_contents($logDir . '/sms_webhook_log.txt', $log_entry, FILE_APPEND);
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user