Hamza-Ayed
|
264e005a7b
|
fix: PHP syntax errors in upload files and composer config
- Fix PHP 8.x string interpolation syntax in upload log calls
- Fix const getenv() -> runtime variable in uploadSyrianDocs.php
- Add composer security advisory ignore for firebase/php-jwt
- Run composer update to sync lock file
|
2026-06-17 08:41:16 +03:00 |
|
Hamza-Ayed
|
a8748cf4c9
|
Fix #22: Medium-severity fixes (M-01 through M-07)
M-01: Host header injection - replaced HTTP_HOST with APP_DOMAIN
M-02: Unauthenticated CRUD - ownership checks on carDrivers add/delete
M-03: MD5 tracking token - replaced md5() with hash_hmac sha256
M-04: Webhook SMS - absolute log path instead of relative
M-05: Weak 3-digit OTP - already noted as requirement (Fix #5)
M-06: Redis without auth - added password + prefix to cancel_ride_by_driver
M-07: SSRF bypass - str_ends_with -> strict equality in allowlist
|
2026-06-17 07:58:21 +03:00 |
|
Hamza-Ayed
|
fc58529b09
|
Update: 2026-06-16 01:17:28
|
2026-06-16 01:17:29 +03:00 |
|
Hamza-Ayed
|
f907212c57
|
Update: 2026-06-12 20:40:40
|
2026-06-12 20:40:40 +03:00 |
|
Hamza-Ayed
|
ef6b52d2e3
|
Update: 2026-06-12 01:23:54
|
2026-06-12 01:23:54 +03:00 |
|
Hamza-Ayed
|
c5170a88d2
|
Update: 2026-06-11 13:47:39
|
2026-06-11 13:47:40 +03:00 |
|
Hamza-Ayed
|
d8901e1a87
|
first commit
|
2026-06-09 08:40:31 +03:00 |
|