Update: 2026-08-08 13:33:53
This commit is contained in:
@@ -78,15 +78,28 @@ try {
|
||||
unauthorizedDriver();
|
||||
}
|
||||
|
||||
$fpPepper = getenv('FP_PEPPER') ?: '';
|
||||
$expectedFp = !empty($fpPepper) ? hash('sha256', $fingerprint . $fpPepper) : $fingerprint;
|
||||
// driverToken.fingerPrint مكتوب بصيغتين حسب آخر endpoint لمسه:
|
||||
// • خام — من verify.php و ride/firebase/addDriver.php
|
||||
// • hash مملّح — من loginJwtWalletDriver.php ومن هنا
|
||||
// القبول على صيغة واحدة فقط كان يرفض كل سائق OTP لم يفتح المحفظة
|
||||
// بعد (401 دائم ⇒ يستحيل ترقية توكن التسجيل). نقبل الاثنتين ثم
|
||||
// نُوحّد الصف على الصيغة المُهشّمة.
|
||||
$fpPepper = getenv('FP_PEPPER') ?: '';
|
||||
$storedFp = $fpRow['fingerPrint'];
|
||||
$hashedFp = !empty($fpPepper) ? hash('sha256', $fingerprint . $fpPepper) : $fingerprint;
|
||||
|
||||
if (!hash_equals($fpRow['fingerPrint'], $expectedFp)) {
|
||||
if (!hash_equals($storedFp, $hashedFp) && !hash_equals($storedFp, $fingerprint)) {
|
||||
securityLog("LoginDriver(OTP): fingerprint mismatch", [
|
||||
'driver_id' => $driver['id'],
|
||||
]);
|
||||
unauthorizedDriver();
|
||||
}
|
||||
|
||||
// توحيد التخزين على الصيغة المُهشّمة (لا نحفظ البصمة الخام).
|
||||
if (!hash_equals($storedFp, $hashedFp)) {
|
||||
$con->prepare('UPDATE driverToken SET fingerPrint = :fp WHERE captain_id = :cid')
|
||||
->execute([':fp' => $hashedFp, ':cid' => $driver['id']]);
|
||||
}
|
||||
// ✅ تم التحقق عبر fingerprint — نتابع لتوليد JWT
|
||||
} else {
|
||||
// ── المسار التقليدي: التحقق عبر password + HMAC ──────────
|
||||
|
||||
Reference in New Issue
Block a user