feat: harden backend security with HMAC verification, SSL validation, and documentation updates while removing legacy scripts.

This commit is contained in:
Hamza-Ayed
2026-07-08 22:10:01 +03:00
parent 628e169552
commit 21877153eb
20 changed files with 6267 additions and 17 deletions
+2 -2
View File
@@ -14,7 +14,7 @@ if (empty($secretKey)) {
// --- 1. التحقق من صحة الطلب ---
$authHeader = $_SERVER['HTTP_AUTHORIZATION'] ?? '';
if ($authHeader !== 'Bearer ' . $secretKey) {
if (empty($secretKey) || !hash_equals('Bearer ' . $secretKey, $authHeader)) {
http_response_code(403);
echo json_encode(['status' => 'error', 'message' => 'Unauthorized Access']);
exit();
@@ -74,7 +74,7 @@ if (preg_match($pattern_orangemoney_jo, $message_body, $matches)) {
// كتابة كل شيء في ملف السجل (بالمسار المطلق)
$logDir = __DIR__ . '/../../logs';
if (!is_dir($logDir)) @mkdir($logDir, 0777, true);
if (!is_dir($logDir)) @mkdir($logDir, 0750, true);
file_put_contents($logDir . '/sms_webhook_log.txt', $log_entry, FILE_APPEND);