Add blind-index search layer; fix captain detail 200-with-empty-body

Searching encrypted columns currently works only because encryptData() is
AES-CBC with a fixed IV, i.e. deterministic. That determinism is what leaks
equality and shared prefixes, and it is why moving storage to AES-GCM would
break every lookup. This separates the two concerns.

- core/Security/BlindIndex.php: HMAC-SHA256 over a normalised value, keyed by
  a secret pepper. Phone numbers have a small keyspace, so a bare SHA-256
  would be reversible by enumeration; the pepper lives in the environment, not
  the database. The scope string includes table and field so the same number
  does not produce a matching index across tables.
  Normalisation unifies local/international phone forms, lowercases emails and
  folds Arabic alef/ya/ta-marbuta and diacritics for names.
- migrations/: nullable *_bidx columns plus indexes, and the missing
  adminUser.status/approved_by/approved_at columns that admin approvals need.
- scripts/backfill_blind_index.php: restartable, batched, --dry-run capable,
  touches only index columns.
- Admin lookups by phone/email now match the index, keeping the old ciphertext
  comparison in the same query so search keeps working until the backfill runs.
  bootstrap exposes $blindIndex as null when no pepper is configured.

Also: AdminCaptain/getCaptainDetailsById.php selected driver.education, a
column absent from this schema. The PDOException was uncaught, so the client
received an empty body with HTTP 200 — the "non-JSON response" seen when
opening a captain. It now omits the column, catches the error, reports it as
JSON, and requires an admin role.

Console: opening any sidebar section refetches its data instead of showing
what was loaded when the console started.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Hamza-Ayed
2026-07-25 15:16:09 +03:00
co-authored by Claude Opus 5
parent 81ee2acefd
commit 6802026dbd
10 changed files with 406 additions and 24 deletions
+33 -4
View File
@@ -11,7 +11,7 @@
// Bump together with the ?v= query in index.html. Shown in the UI and in the
// diagnostics report so "the deploy did nothing" can be answered with a fact
// rather than a guess about caching.
const BUILD = '2026-07-25-6';
const BUILD = '2026-07-25-7';
// ── Localisation ─────────────────────────────────────────────────────────
// Arabic is the operators' language; English is kept because several screens
@@ -2815,15 +2815,44 @@
if (window.innerWidth <= 992) el.sidebar.classList.remove('open');
redrawCharts();
const mod = MODULES.find((m) => m.id === item.dataset.module);
if (mod && session) loadModule(mod);
// Opening a section always refetches it: an operator switching to a
// list expects what the database holds now, not what it held when the
// console was first opened.
if (session) refreshView(item.dataset.view, item.dataset.module);
});
});
el.toggleSidebar?.addEventListener('click', () => el.sidebar.classList.toggle('open'));
}
// Maps a sidebar entry to the loader that owns its data.
const VIEW_LOADERS = {
dashboardView: () => { loadStats().catch(() => {}); loadRidesTrend().catch(() => {}); },
ridesView: () => loadRides().catch(() => {}),
driversView: () => loadDrivers().catch(() => {}),
passengersView: () => loadPassengers().catch(() => {}),
financialsView: () => loadStats().catch(() => {}),
complaintsView: () => loadStats().catch(() => {}),
approvalsView: () => loadApprovals().catch(() => {}),
systemView: () => renderSessionInfo(),
};
function refreshView(viewId, moduleId) {
const mod = MODULES.find((m) => m.id === moduleId);
if (mod) {
loadModule(mod, true); // force: bypass the loaded-once cache
return;
}
VIEW_LOADERS[viewId]?.();
}
function setupDataEvents() {
el.refreshBtn?.addEventListener('click', () => { if (session) loadEverything(); });
el.refreshBtn?.addEventListener('click', () => {
if (!session) return;
const active = document.querySelector('.nav-item.active');
if (active) refreshView(active.dataset.view, active.dataset.module);
else loadEverything();
});
$('langToggle')?.addEventListener('click', () => setLanguage(lang === 'ar' ? 'en' : 'ar'));
el.rideStatusFilter?.addEventListener('change', () => loadRides().catch(() => {}));