Update: 2026-08-07 05:03:39
This commit is contained in:
+14
-10
@@ -53,23 +53,28 @@ $role = $decoded->role ?? 'passenger';
|
||||
// update_complaint — أي أن أي حامل JWT صالح (راكب عادي) يقرأ بيانات
|
||||
// السائقين والركّاب ويغلق الشكاوى. تحققنا أن siro_rider و siro_driver لا
|
||||
// يستدعيان أي نقطة تحت serviceapp/، فالإغلاق لا يكسر تطبيقات الجوال.
|
||||
//
|
||||
// ⚠️ لكل مجلد أدواره: تسجيل دخول تطبيق الخدمة (Admin/jwtService.php:51)
|
||||
// يصدر الدور 'service' لا 'admin'. فرضُ admin على serviceapp/ كان
|
||||
// سيمنع كل موظفي خدمة العملاء من كل نقاطهم.
|
||||
$gatedDirs = array_filter([
|
||||
realpath(__DIR__ . '/Admin'),
|
||||
realpath(__DIR__ . '/serviceapp'),
|
||||
]);
|
||||
$script = realpath($_SERVER['SCRIPT_FILENAME'] ?? '');
|
||||
realpath(__DIR__ . '/Admin') => ['admin', 'super_admin'],
|
||||
realpath(__DIR__ . '/serviceapp') => ['service', 'admin', 'super_admin'],
|
||||
], fn($k) => $k !== false, ARRAY_FILTER_USE_KEY);
|
||||
|
||||
$inGatedDir = false;
|
||||
$script = realpath($_SERVER['SCRIPT_FILENAME'] ?? '');
|
||||
|
||||
$gateRoles = null;
|
||||
if ($script) {
|
||||
foreach ($gatedDirs as $dir) {
|
||||
foreach ($gatedDirs as $dir => $roles) {
|
||||
if (str_starts_with($script, $dir . DIRECTORY_SEPARATOR)) {
|
||||
$inGatedDir = true;
|
||||
$gateRoles = $roles;
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if ($inGatedDir) {
|
||||
if ($gateRoles !== null) {
|
||||
// نقاط تحت Admin/ تستدعيها تطبيقات الجوال بأدوار غير إدارية.
|
||||
// تم التحقق من مواضع الاستدعاء الفعلية في siro_rider و siro_driver:
|
||||
// errorApp.php → التطبيقان يبلّغان عن الأخطاء
|
||||
@@ -81,8 +86,7 @@ if ($inGatedDir) {
|
||||
];
|
||||
|
||||
if (!in_array(basename($script), $adminGateExempt, true)
|
||||
&& $role !== 'admin'
|
||||
&& $role !== 'super_admin'
|
||||
&& !in_array($role, $gateRoles, true)
|
||||
) {
|
||||
securityLog('Admin gate blocked non-admin request', [
|
||||
'script' => basename($script),
|
||||
|
||||
Reference in New Issue
Block a user