Update: 2026-08-08 13:33:53

This commit is contained in:
Hamza-Ayed
2026-08-08 13:33:54 +03:00
parent fae0e4a38a
commit c8e8e481a6
7 changed files with 362 additions and 141 deletions
+16 -3
View File
@@ -78,15 +78,28 @@ try {
unauthorizedDriver();
}
$fpPepper = getenv('FP_PEPPER') ?: '';
$expectedFp = !empty($fpPepper) ? hash('sha256', $fingerprint . $fpPepper) : $fingerprint;
// driverToken.fingerPrint مكتوب بصيغتين حسب آخر endpoint لمسه:
// • خام — من verify.php و ride/firebase/addDriver.php
// • hash مملّح — من loginJwtWalletDriver.php ومن هنا
// القبول على صيغة واحدة فقط كان يرفض كل سائق OTP لم يفتح المحفظة
// بعد (401 دائم ⇒ يستحيل ترقية توكن التسجيل). نقبل الاثنتين ثم
// نُوحّد الصف على الصيغة المُهشّمة.
$fpPepper = getenv('FP_PEPPER') ?: '';
$storedFp = $fpRow['fingerPrint'];
$hashedFp = !empty($fpPepper) ? hash('sha256', $fingerprint . $fpPepper) : $fingerprint;
if (!hash_equals($fpRow['fingerPrint'], $expectedFp)) {
if (!hash_equals($storedFp, $hashedFp) && !hash_equals($storedFp, $fingerprint)) {
securityLog("LoginDriver(OTP): fingerprint mismatch", [
'driver_id' => $driver['id'],
]);
unauthorizedDriver();
}
// توحيد التخزين على الصيغة المُهشّمة (لا نحفظ البصمة الخام).
if (!hash_equals($storedFp, $hashedFp)) {
$con->prepare('UPDATE driverToken SET fingerPrint = :fp WHERE captain_id = :cid')
->execute([':fp' => $hashedFp, ':cid' => $driver['id']]);
}
// ✅ تم التحقق عبر fingerprint — نتابع لتوليد JWT
} else {
// ── المسار التقليدي: التحقق عبر password + HMAC ──────────