Fix SQL injection and stale status matching in the wallet endpoints

The three endpoints the driver app calls for its wallet built their queries by
interpolating the driver id straight into SQL. Anything the app sent went into
the statement, and these run against the payments database.

They also matched only status = 'Finished'. The current ride pipeline writes
'completed', so a driver's completed rides, pending payouts and weekly
earnings all read as zero regardless of how much they had driven — which is
what the wallet errors in the admin error log are sitting next to.

getAllPayment.php, driverStatistic.php and getCountRide.php now bind the id
and match either spelling. Verified no interpolated identifier remains and
every rewritten condition is balanced.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Hamza-Ayed
2026-07-25 17:57:52 +03:00
co-authored by Claude Opus 5
parent 3fb7bc5190
commit 61d6380861
3 changed files with 90 additions and 80 deletions
@@ -9,9 +9,9 @@ $sql = "SELECT
FROM
`ride`
WHERE
`ride`.`status` = 'Finished'
LOWER(`ride`.`status`) IN ('finished','completed')
AND `ride`.`created_at` BETWEEN CURRENT_DATE() + INTERVAL 7 HOUR AND CURRENT_DATE() + INTERVAL 10 HOUR
AND `ride`.`driver_id` = '$driverID'
AND `ride`.`driver_id` = :driverID
) AS morning_count,
(
SELECT
@@ -19,9 +19,9 @@ $sql = "SELECT
FROM
`ride`
WHERE
`ride`.`status` = 'Finished'
LOWER(`ride`.`status`) IN ('finished','completed')
AND `ride`.`created_at` BETWEEN CURRENT_DATE() + INTERVAL 15 HOUR AND CURRENT_DATE() + INTERVAL 18 HOUR
AND `ride`.`driver_id` = '$driverID'
AND `ride`.`driver_id` = :driverID
) AS afternoon_count,
(
SELECT
@@ -29,7 +29,7 @@ $sql = "SELECT
FROM
payments
WHERE
isGiven = 'waiting' AND `driverID` = '$driverID'
isGiven = 'waiting' AND `driverID` = :driverID
) AS total_amount,
(
SELECT
@@ -37,8 +37,8 @@ $sql = "SELECT
FROM
ride
WHERE
`driver_id` = '$driverID'
AND `ride`.`status` = 'Finished'
`driver_id` = :driverID
AND LOWER(`ride`.`status`) IN ('finished','completed')
AND `ride`.`created_at` > CURRENT_DATE() - INTERVAL 1 WEEK
) AS total_amount_last_week
FROM
@@ -47,7 +47,13 @@ LIMIT 1;
";
/**
* كان معرّف السائق يُدمج في نص الاستعلام مباشرةً (حقن SQL)، وكانت الحالة
* تُطابق 'Finished' فقط بينما خط الرحلات الحالي يكتب 'completed' — فتظهر
* أرباح السائق ورحلاته أصفاراً.
*/
$stmt = $con->prepare($sql);
$stmt->bindValue(':driverID', $driverID);
$stmt->execute();
if ($stmt->rowCount() > 0) {