Refactor(Auth): Complete auth folder restructuring, security patches, and Flutter endpoint updates

This commit is contained in:
Hamza-Ayed
2026-07-09 05:22:05 +03:00
parent 45859883a5
commit 87dc925ea7
37 changed files with 40 additions and 31 deletions
+2 -2
View File
@@ -25,7 +25,7 @@ class JwtService
// Endpoints مسموح لها بتوكن نوع registration // Endpoints مسموح لها بتوكن نوع registration
private const REGISTRATION_ENDPOINTS = [ private const REGISTRATION_ENDPOINTS = [
'loginFirstTime', 'loginFirstTimeDriver', 'loginFirstTime', 'loginFirstTimeDriver',
'checkPhoneNumberISVerfiedDriver', 'checkPhoneNumberISVerfiedPassenger', 'checkPhoneNumberISVerfied', 'checkPhoneNumberISVerfiedDriver', 'checkPhoneNumberISVerfiedPassenger',
'otpmessage', 'signup', 'verifyEmail', 'verifyOtpMessage', 'otpmessage', 'signup', 'verifyEmail', 'verifyOtpMessage',
'sendVerifyEmail', 'sendWhatsAppDriver', 'register_passenger', 'sendVerifyEmail', 'sendWhatsAppDriver', 'register_passenger',
'sendWhatsOpt', 'verifyOtp', 'auth_proxy', 'addToken', 'sendWhatsOpt', 'verifyOtp', 'auth_proxy', 'addToken',
@@ -33,7 +33,7 @@ class JwtService
'loginFromGooglePassenger', 'loginUsingCredentialsWithoutGooglePassenger', 'loginFromGooglePassenger', 'loginUsingCredentialsWithoutGooglePassenger',
'register', 'sendOtpMessageDriver', 'getTokensPassenger', 'register', 'sendOtpMessageDriver', 'getTokensPassenger',
'send_otp', 'verify_otp', 'errorApp', 'register_driver', 'send_otp', 'verify_otp', 'errorApp', 'register_driver',
'uploadImage', 'register_driver_and_car', 'uploadImage', 'uploadDriverDocs', 'register_driver_and_car',
]; ];
public function __construct(?Redis $redis = null) public function __construct(?Redis $redis = null)
+8 -8
View File
@@ -387,7 +387,7 @@ class AppLink {
static String get getApiKey => "$ride/apiKey/get.php"; static String get getApiKey => "$ride/apiKey/get.php";
static String get getCnMap => "$server/auth/cnMap.php"; static String get getCnMap => "$server/auth/cnMap.php";
static String get getPromptDriverDocumentsEgypt => static String get getPromptDriverDocumentsEgypt =>
"$server/auth/captin/getPromptDriverDocumentsEgypt.php"; "$server/auth/driver/getPromptDriverDocumentsEgypt.php";
static String get saveDriverDestination => static String get saveDriverDestination =>
"$ride/location/save_driver_destination.php"; "$ride/location/save_driver_destination.php";
@@ -408,7 +408,7 @@ class AppLink {
static String get updateApiKey => "$ride/apiKey/update.php"; static String get updateApiKey => "$ride/apiKey/update.php";
static String get deleteApiKey => "$ride/apiKey/delete.php"; static String get deleteApiKey => "$ride/apiKey/delete.php";
static String get checkPhoneNumberISVerfiedDriver => static String get checkPhoneNumberISVerfiedDriver =>
"$auth/checkPhoneNumberISVerfiedDriver.php"; "$auth/driver/checkPhoneNumberISVerfied.php";
static String get getTesterApp => "$auth/Tester/getTesterApp.php"; static String get getTesterApp => "$auth/Tester/getTesterApp.php";
static String get updateTesterApp => "$auth/Tester/updateTesterApp.php"; static String get updateTesterApp => "$auth/Tester/updateTesterApp.php";
@@ -476,7 +476,7 @@ class AppLink {
static String get uploadImage1 => "$server/uploadImage1.php"; static String get uploadImage1 => "$server/uploadImage1.php";
static String get uploadImagePortrate => "$server/uploadImagePortrate.php"; static String get uploadImagePortrate => "$server/uploadImagePortrate.php";
static String get uploadSyrianDocs => static String get uploadSyrianDocs =>
"$syria/auth/syria/uploadSyrianDocs.php"; "$syria/auth/driver/uploadDriverDocs.php";
static String get uploadImageType => "$server/uploadImageType.php"; static String get uploadImageType => "$server/uploadImageType.php";
//=============egypt documents ============== //=============egypt documents ==============
static String get uploadEgyptidFront => static String get uploadEgyptidFront =>
@@ -556,7 +556,7 @@ class AppLink {
static String get updateInvitationCodeFromRegister => static String get updateInvitationCodeFromRegister =>
"$ride/invitor/updateInvitationCodeFromRegister.php"; "$ride/invitor/updateInvitationCodeFromRegister.php";
static String get register_driver_and_car => static String get register_driver_and_car =>
"$auth/syria/driver/register_driver_and_car.php"; "$auth/driver/register.php";
static String get updateDriverInvitationDirectly => static String get updateDriverInvitationDirectly =>
"$ride/invitor/updateDriverInvitationDirectly.php"; "$ride/invitor/updateDriverInvitationDirectly.php";
static String get updatePassengersInvitation => static String get updatePassengersInvitation =>
@@ -567,12 +567,12 @@ class AppLink {
static String get auth => '$server/auth'; static String get auth => '$server/auth';
static String get login => "$auth/login.php"; static String get login => "$auth/login.php";
static String get signUp => "$auth/signup.php"; static String get signUp => "$auth/signup.php";
static String get updateDriverClaim => "$auth/captin/updateDriverClaim.php"; static String get updateDriverClaim => "$auth/driver/updateDriverClaim.php";
static String get updateShamCashDriver => static String get updateShamCashDriver =>
"$auth/captin/updateShamCashDriver.php"; "$auth/driver/updateShamCashDriver.php";
static String get sendVerifyEmail => "$auth/sendVerifyEmail.php"; static String get sendVerifyEmail => "$auth/sendVerifyEmail.php";
static String get passengerRemovedAccountEmail => static String get passengerRemovedAccountEmail =>
"$auth/passengerRemovedAccountEmail.php"; "$auth/passenger/remove_account.php";
static String get verifyEmail => "$auth/verifyEmail.php"; static String get verifyEmail => "$auth/verifyEmail.php";
//===================Auth Captin============ //===================Auth Captin============
static String get authCaptin => '$server/auth/captin'; static String get authCaptin => '$server/auth/captin';
@@ -595,7 +595,7 @@ class AppLink {
static String get updateAccountBank => "$authCaptin/updateAccountBank.php"; static String get updateAccountBank => "$authCaptin/updateAccountBank.php";
static String get getAccount => "$authCaptin/getAccount.php"; static String get getAccount => "$authCaptin/getAccount.php";
static String get uploadImageToAi => "$auth/document_syria/ai_document.php"; static String get uploadImageToAi => "$auth/document_syria/ai_document.php";
static String get isPhoneVerified => "$auth/syria/driver/isPhoneVerified.php"; static String get isPhoneVerified => "$auth/driver/isPhoneVerified.php";
//===================Admin Captin============ //===================Admin Captin============
@@ -97,7 +97,7 @@ class OtpVerificationController extends GetxController {
// توجه إلى الصفحة التالية // توجه إلى الصفحة التالية
await CRUD().post( await CRUD().post(
link: '${AppLink.paymentServer}/auth/token/update_driver_auth.php', link: AppLink.addTokensDriver,
payload: { payload: {
'token': box.read(BoxName.tokenDriver).toString(), 'token': box.read(BoxName.tokenDriver).toString(),
'fingerPrint': finger.toString(), 'fingerPrint': finger.toString(),
@@ -764,7 +764,7 @@ class RegistrationController extends GetxController {
// isLoading.value = true; // isLoading.value = true;
// final uri = Uri.parse( // final uri = Uri.parse(
// 'https://intaleq.xyz/siro/auth/syria/driver/register_driver_and_car.php', // 'https://intaleq.xyz/siro/auth/driver/register.php',
// ); // );
// final client = http.Client(); // final client = http.Client();
@@ -48,10 +48,10 @@ void main() async {
print(' Request: { phone_number: "$phone", code: "123456", device_token: "fp_abc123" }'); print(' Request: { phone_number: "$phone", code: "123456", device_token: "fp_abc123" }');
print(' ✅ Phone verified, driver_id returned'); print(' ✅ Phone verified, driver_id returned');
// Check: GET /auth/syria/driver/isPhoneVerified.php // Check: GET /auth/driver/isPhoneVerified.php
// Query: phone_number // Query: phone_number
// Returns: success if is_verified = 1 // Returns: success if is_verified = 1
print(' → GET /auth/syria/driver/isPhoneVerified.php?phone_number=$phone'); print(' → GET /auth/driver/isPhoneVerified.php?phone_number=$phone');
print(' ✅ Phone is verified, proceeding to registration'); print(' ✅ Phone is verified, proceeding to registration');
// ================================================================ // ================================================================
@@ -157,7 +157,7 @@ void main() async {
for (final docType in uploadDocTypes) { for (final docType in uploadDocTypes) {
print(' 📤 Uploading: $docType'); print(' 📤 Uploading: $docType');
print(' → POST /auth/syria/uploadSyrianDocs.php'); print(' → POST /auth/driver/uploadDriverDocs.php');
print(' Fields: driver_id=$driverId, doc_type=$docType, file (multipart)'); print(' Fields: driver_id=$driverId, doc_type=$docType, file (multipart)');
print(' File stored: private_uploads/<hash>/<driverId>__${docType}.jpg'); print(' File stored: private_uploads/<hash>/<driverId>__${docType}.jpg');
print(' MIME validation: image/jpeg, image/png, image/webp'); print(' MIME validation: image/jpeg, image/png, image/webp');
@@ -179,7 +179,7 @@ void main() async {
// STEP 6: Final Registration Submission // STEP 6: Final Registration Submission
// ================================================================ // ================================================================
print('\n─── STEP 6: Final Registration (register_driver_and_car.php) ───'); print('\n─── STEP 6: Final Registration (register_driver_and_car.php) ───');
print(' → POST /auth/syria/driver/register_driver_and_car.php'); print(' → POST /auth/driver/register.php');
print(' This is the MAIN orchestrator. It does:'); print(' This is the MAIN orchestrator. It does:');
print(' 1. Phone number normalization (Syria/Jordan/Egypt logic)'); print(' 1. Phone number normalization (Syria/Jordan/Egypt logic)');
print(' 2. Encrypt sensitive fields (phone, email, name, address, etc.)'); print(' 2. Encrypt sensitive fields (phone, email, name, address, etc.)');
@@ -256,14 +256,14 @@ void main() async {
// Admin fetches pending drivers // Admin fetches pending drivers
print(' 🔍 Admin fetches pending drivers:'); print(' 🔍 Admin fetches pending drivers:');
print(' → GET /auth/syria/driver/drivers_pending_list.php'); print(' → GET /auth/driver/drivers_pending_list.php');
print(' Decrypts: phone, first_name, last_name'); print(' Decrypts: phone, first_name, last_name');
print(' Returns: [{ id: "$driverId", first_name: "أحمد", last_name: "الأسد", phone: "$phone" }]'); print(' Returns: [{ id: "$driverId", first_name: "أحمد", last_name: "الأسد", phone: "$phone" }]');
print(' ✅ Driver appears in pending list (status != "active")'); print(' ✅ Driver appears in pending list (status != "active")');
// Admin views details // Admin views details
print('\n 📋 Admin views driver details:'); print('\n 📋 Admin views driver details:');
print(' → GET /auth/syria/driver/driver_details.php?driver_id=$driverId'); print(' → GET /auth/driver/driver_details.php?driver_id=$driverId');
print(' Returns: driver row + car registration + document links'); print(' Returns: driver row + car registration + document links');
print(' ✅ Admin reviews all documents'); print(' ✅ Admin reviews all documents');
@@ -301,12 +301,12 @@ void main() async {
print(' - ml_google_doc.dart (phone OCR scanner)'); print(' - ml_google_doc.dart (phone OCR scanner)');
print(' Backend (PHP):'); print(' Backend (PHP):');
print(' - /auth/otp/request.php + verify.php'); print(' - /auth/otp/request.php + verify.php');
print(' - /auth/syria/driver/isPhoneVerified.php'); print(' - /auth/driver/isPhoneVerified.php');
print(' - /auth/document_syria/ai_document.php'); print(' - /auth/document_syria/ai_document.php');
print(' - /auth/syria/uploadSyrianDocs.php'); print(' - /auth/driver/uploadDriverDocs.php');
print(' - /auth/syria/driver/register_driver_and_car.php'); print(' - /auth/driver/register.php');
print(' - /auth/syria/driver/drivers_pending_list.php'); print(' - /auth/driver/drivers_pending_list.php');
print(' - /auth/syria/driver/driver_details.php'); print(' - /auth/driver/driver_details.php');
print(' - /serviceapp/getDriversWaitingActive.php'); print(' - /serviceapp/getDriversWaitingActive.php');
print(' - /Admin/Staff/activate.php'); print(' - /Admin/Staff/activate.php');
print(' Schema:'); print(' Schema:');
@@ -381,7 +381,7 @@ class RegistrationView extends StatelessWidget {
// STEP 3 // STEP 3
Widget _buildDocumentUploadStep(BuildContext ctx, RegistrationController c) { Widget _buildDocumentUploadStep(BuildContext ctx, RegistrationController c) {
final String primaryLink = final String primaryLink =
'${AppLink.server}/auth/syria/uploadImage.php'; '${AppLink.server}/auth/driver/uploadImage.php';
return GetBuilder<RegistrationController>( return GetBuilder<RegistrationController>(
builder: (ctrl) => SingleChildScrollView( builder: (ctrl) => SingleChildScrollView(
+4 -4
View File
@@ -470,17 +470,17 @@ class AppLink {
static String get updateTesterApp => "$auth/Tester/updateTesterApp.php"; static String get updateTesterApp => "$auth/Tester/updateTesterApp.php";
static String get signUp => "$auth/signup.php"; static String get signUp => "$auth/signup.php";
static String get savePassengerLocation => static String get savePassengerLocation =>
"$auth/save_passenger_location.php"; "$auth/passenger/save_location.php";
static String get sendVerifyEmail => "$auth/sendVerifyEmail.php"; static String get sendVerifyEmail => "$auth/sendVerifyEmail.php";
static String get loginFromGooglePassenger => static String get loginFromGooglePassenger =>
"$auth/loginFromGooglePassenger.php"; "$auth/passenger/loginFromGoogle.php";
static String get loginUsingCredentialsWithoutGooglePassenger => static String get loginUsingCredentialsWithoutGooglePassenger =>
"$auth/loginUsingCredentialsWithoutGooglePassenger.php"; "$auth/passenger/loginUsingCredentialsWithoutGoogle.php";
static String get checkPhoneNumberISVerfiedPassenger => static String get checkPhoneNumberISVerfiedPassenger =>
"$auth/checkPhoneNumberISVerfiedPassenger.php"; "$auth/checkPhoneNumberISVerfiedPassenger.php";
static String get passengerRemovedAccountEmail => static String get passengerRemovedAccountEmail =>
"$auth/passengerRemovedAccountEmail.php"; "$auth/passenger/remove_account.php";
static String get verifyEmail => "$auth/verifyEmail.php"; static String get verifyEmail => "$auth/verifyEmail.php";
//===================Auth Captin============ //===================Auth Captin============
static String get authCaptin => '$server/auth/captin'; static String get authCaptin => '$server/auth/captin';
@@ -16,7 +16,7 @@ class PhoneAuthHelper {
// Define your server URLs // Define your server URLs
static final String _sendOtpUrl = '${AppLink.server}/auth/otp/request.php'; static final String _sendOtpUrl = '${AppLink.server}/auth/otp/request.php';
static final String _verifyOtpUrl = '${AppLink.server}/auth/otp/verify.php'; static final String _verifyOtpUrl = '${AppLink.server}/auth/otp/verify.php';
static final String _registerUrl = '${AppLink.server}/auth/syria/register_passenger.php'; static final String _registerUrl = '${AppLink.server}/auth/passenger/register.php';
// removed formatSyrianPhone // removed formatSyrianPhone
@@ -96,6 +96,15 @@ class OtpVerificationController extends GetxController {
); );
if (response != 'failure' && response['status'] == 'success') { if (response != 'failure' && response['status'] == 'success') {
// تحديث التوكن والبصمة الجديدة في الباك إند
await CRUD().post(
link: "${AppLink.server}/ride/firebase/addToken.php",
payload: {
'token': box.read(BoxName.tokenFCM).toString(),
'fingerPrint': fingerPrint.toString(),
'passengerID': box.read(BoxName.passengerID).toString(),
});
await NotificationService.sendNotification( await NotificationService.sendNotification(
category: 'token change', category: 'token change',
target: ptoken.toString(), target: ptoken.toString(),
+2 -2
View File
@@ -131,10 +131,10 @@ class AppLink {
static String signUp = "$auth/signup.php"; static String signUp = "$auth/signup.php";
static String sendVerifyEmail = "$auth/sendVerifyEmail.php"; static String sendVerifyEmail = "$auth/sendVerifyEmail.php";
static String passengerRemovedAccountEmail = static String passengerRemovedAccountEmail =
"$auth/passengerRemovedAccountEmail.php"; "$auth/passenger/remove_account.php";
static String verifyEmail = "$auth/verifyEmail.php"; static String verifyEmail = "$auth/verifyEmail.php";
static String getPromptDriverDocumentsEgypt = static String getPromptDriverDocumentsEgypt =
"$server/auth/captin/getPromptDriverDocumentsEgypt.php"; "$server/auth/driver/getPromptDriverDocumentsEgypt.php";
//===================Auth Captin============ //===================Auth Captin============
static String authCaptin = '$server/auth/captin'; static String authCaptin = '$server/auth/captin';