Update: 2026-07-12 18:53:59

This commit is contained in:
Hamza-Ayed
2026-07-12 18:53:59 +03:00
parent 8cd4a4b57e
commit 653d73422f
54 changed files with 2078 additions and 436 deletions
+10 -3
View File
@@ -5,6 +5,10 @@
require_once __DIR__ . '/../../core/bootstrap.php';
require_once __DIR__ . '/../functions.php';
// Rate limiting — حد صارم على طلبات OTP
$limiter = new RateLimiter($redis);
$limiter->enforce(RateLimiter::identifier(), 'api');
try { $transit_con = Database::get('transit'); }
catch (Exception $e) { jsonError('Transit service unavailable', 503); }
@@ -13,7 +17,8 @@ if (!$rawPhone) jsonError('Phone is required');
$phone = normalizePhone($rawPhone);
if (transitIsOtpLocked($phone)) {
jsonError('Too many attempts. Try again in 30 minutes.', 429);
// نفس رسالة النجاح — لا نكشف أن الحساب مقفل
jsonSuccess(null, 'OTP sent successfully');
}
$phoneEnc = $encryptionHelper->encryptData($phone);
@@ -26,8 +31,10 @@ $st = $transit_con->prepare(
$st->execute([$phoneEnc]);
$admin = $st->fetch();
if (!$admin) jsonError('Invalid credentials', 401);
if ($admin['contract_status'] === 'terminated') jsonError('Account suspended', 403);
// لا نكشف إن كان الهاتف موجوداً أم لا — نفس الرد دائماً
if (!$admin || $admin['contract_status'] === 'terminated') {
jsonSuccess(null, 'OTP sent successfully');
}
transitSendAdminOtp($phone);
+4
View File
@@ -5,6 +5,10 @@
require_once __DIR__ . '/../../core/bootstrap.php';
require_once __DIR__ . '/../functions.php';
// Rate limiting
$limiter = new RateLimiter($redis);
$limiter->enforce(RateLimiter::identifier(), 'api');
try { $transit_con = Database::get('transit'); }
catch (Exception $e) { jsonError('Transit service unavailable', 503); }
+34
View File
@@ -0,0 +1,34 @@
<?php
// transit/admin/logout.php — تسجيل خروج مشرف المؤسسة (حذف الجلسة)
// POST: — (التوكن في الهيدر Authorization: Bearer)
require_once __DIR__ . '/../../core/bootstrap.php';
require_once __DIR__ . '/../functions.php';
try { $transit_con = Database::get('transit'); }
catch (Exception $e) { jsonError('Transit service unavailable', 503); }
// استخرج التوكن من الهيدر
$authHeader = $_SERVER['HTTP_AUTHORIZATION'] ?? '';
$token = '';
if (preg_match('/Bearer\s+(\S+)/i', $authHeader, $m)) {
$token = $m[1];
} else {
$token = filterRequest('token') ?? '';
}
if (!$token) jsonError('No session token provided', 400);
$hash = hash('sha256', $token);
// حذف من Redis
if ($redis) $redis->del("siro:transit:session:{$hash}");
// حذف من MySQL
try {
$transit_con->prepare("DELETE FROM transit_sessions WHERE token_hash=?")->execute([$hash]);
} catch (Throwable $e) {
// لا بأس — الجلسة انتهت بالـ Redis
}
jsonSuccess(null, 'Logged out successfully');