Compare commits

7 Commits
9 changed files with 164 additions and 16 deletions
+2 -1
View File
@@ -120,9 +120,10 @@ NABEH_API_KEY=<CHANGE_ME_SHARED_SECRET>
SECRET_KEY_HMAC=<CHANGE_ME_HMAC_SECRET_FOR_SIGNED_URLS>
# =============================================================================
# Security Configuration - Fingerprint
# Security Configuration - Fingerprint & Testers
# =============================================================================
FP_PEPPER=<CHANGE_ME_FINGERPRINT_PEPPER>
ALLOWED_TESTER_EMAILS=driver_tester@siromove.com,passenger_tester@siromove.com
# =============================================================================
# Gemini AI Configuration
@@ -11,6 +11,31 @@ $password = filterRequest('password');
$audience = filterRequest('aud') ?? 'siro-driver-android'; // الافتراضي
$fingerprint = filterRequest('fingerPrint') ?? filterRequest('fingerprint');
// 1. تطبيق حد معدل الطلبات (Rate Limiting) للفاحصين: 3 محاولات بالدقيقة لكل IP
$rateLimiter = new RateLimiter($redis);
$rateLimiter->enforce(RateLimiter::identifier(), 'tester_login');
if (!$email || !$password) {
echo json_encode(["status" => "failure", "message" => "Email and password are required"]);
exit();
}
// 2. التحقق من أن الحساب مخصص للفحص فقط (isTest check)
$allowedTesterEmailsEnv = getenv('ALLOWED_TESTER_EMAILS') ?: '';
$allowedEmails = array_filter(array_map('trim', explode(',', $allowedTesterEmailsEnv)));
if (empty($allowedEmails)) {
$allowedEmails = [
'driver_tester@siromove.com',
'passenger_tester@siromove.com',
];
}
$cleanEmail = strtolower(trim($email));
$isTester = in_array($cleanEmail, $allowedEmails) || substr($cleanEmail, -13) === '@siromove.com';
if (!$isTester) {
echo json_encode(["status" => "failure", "message" => "Access denied. Only tester accounts are allowed."]);
exit();
}
// تشفير الإيميل لاستخدامه في الاستعلام
$encryptedEmail = $encryptionHelper->encryptData($email);
@@ -9,11 +9,27 @@ $password = filterRequest("password");
$fingerprint = filterRequest('fingerPrint') ?? filterRequest('fingerprint');
$audience = filterRequest('aud') ?: 'siro_passenger';
// 1. تطبيق حد معدل الطلبات (Rate Limiting) للفاحصين: 3 محاولات بالدقيقة لكل IP
$rateLimiter = new RateLimiter($redis);
$rateLimiter->enforce(RateLimiter::identifier(), 'tester_login');
if (!$email || !$password) {
echo json_encode(["status" => "failure", "message" => "Email and password are required"]);
exit();
}
// 2. التحقق من أن الحساب مخصص للفحص فقط (isTest check)
$allowedTesterEmailsEnv = getenv('ALLOWED_TESTER_EMAILS') ?: '';
$allowedEmails = array_filter(array_map('trim', explode(',', $allowedTesterEmailsEnv)));
$cleanEmail = strtolower(trim($email));
$isTester = in_array($cleanEmail, $allowedEmails) || substr($cleanEmail, -13) === '@siromove.com';
if (!$isTester) {
echo json_encode(["status" => "failure", "message" => "Access denied. Only tester accounts are allowed."]);
exit();
}
try {
$con = Database::get('main');
+7 -6
View File
@@ -10,12 +10,13 @@ class RateLimiter
// حدود مختلفة لكل نوع endpoint
private const LIMITS = [
'login' => ['requests' => 5, 'window' => 60], // 5 محاولات / دقيقة
'otp' => ['requests' => 3, 'window' => 300], // 3 محاولات / 5 دقائق
'register' => ['requests' => 3, 'window' => 3600], // 3 محاولات / ساعة
'api' => ['requests' => 120, 'window' => 60], // 120 طلب / دقيقة
'ride' => ['requests' => 30, 'window' => 60], // 30 طلب / دقيقة
'upload' => ['requests' => 10, 'window' => 300], // 10 رفع / 5 دقائق
'login' => ['requests' => 5, 'window' => 60], // 5 محاولات / دقيقة
'tester_login' => ['requests' => 3, 'window' => 60], // 3 محاولات / دقيقة
'otp' => ['requests' => 3, 'window' => 300], // 3 محاولات / 5 دقائق
'register' => ['requests' => 3, 'window' => 3600], // 3 محاولات / ساعة
'api' => ['requests' => 120, 'window' => 60], // 120 طلب / دقيقة
'ride' => ['requests' => 30, 'window' => 60], // 30 طلب / دقيقة
'upload' => ['requests' => 10, 'window' => 300], // 10 رفع / 5 دقائق
];
public function __construct(?Redis $redis)
+1
View File
@@ -61,6 +61,7 @@ CREATE TABLE `adminUser` (
`email` varchar(500) CHARACTER SET utf8mb4 COLLATE utf8mb4_general_ci DEFAULT NULL COMMENT 'البريد مشفر (AES-GCM)',
`password` varchar(255) CHARACTER SET utf8mb4 COLLATE utf8mb4_general_ci NOT NULL COMMENT 'bcrypt',
`role` varchar(30) CHARACTER SET utf8mb4 COLLATE utf8mb4_general_ci NOT NULL DEFAULT 'admin' COMMENT 'admin | super_admin | service',
`country` varchar(100) CHARACTER SET utf8mb4 COLLATE utf8mb4_general_ci DEFAULT 'Jordan' COMMENT 'اسم الدولة: Syria, Egypt, Jordan, Iraq, ...',
`created_at` timestamp NOT NULL DEFAULT CURRENT_TIMESTAMP,
`updated_at` timestamp NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
PRIMARY KEY (`id`),
@@ -23,6 +23,14 @@ class OtpHelper extends GetxController {
static final String _checkAdminLogin =
'${AppLink.server}/Admin/auth/login.php';
var selectedCountry = 'Jordan'.obs;
bool isFirstRun = box.read(BoxName.countryCode) == null;
void changeCountry(String country) {
selectedCountry.value = country;
box.write(BoxName.countryCode, country);
}
/// إرسال OTP
static Future<bool> sendOtp(String phoneNumber) async {
try {
@@ -163,6 +171,10 @@ class OtpHelper extends GetxController {
String role = data['role'].toString().trim();
await box.write('admin_role', role);
Log.print('Admin role saved: $role');
if (role != 'super_admin' && data['country'] != null) {
await box.write(BoxName.countryCode, data['country']);
}
}
if (data['phone'] != null) {
await box.write(BoxName.adminPhone, data['phone']);
@@ -277,6 +289,10 @@ class OtpHelper extends GetxController {
@override
void onInit() {
if (box.read(BoxName.countryCode) == null) {
box.write(BoxName.countryCode, 'Jordan');
}
selectedCountry.value = box.read(BoxName.countryCode) ?? 'Jordan';
super.onInit();
DeviceHelper.getDeviceFingerprint().then((deviceFingerprint) {
box.write(BoxName.fingerPrint, deviceFingerprint);
+54 -1
View File
@@ -297,7 +297,60 @@ class _AdminLoginPageState extends State<AdminLoginPage>
return null;
},
),
const SizedBox(height: 28),
if (Get.find<OtpHelper>().isFirstRun) ...[
const SizedBox(height: 20),
// ── Country Dropdown ───────────────────────────
const Row(
children: [
Icon(Icons.public_rounded,
color: _C.accent, size: 16),
SizedBox(width: 8),
Text(
'الدولة',
style: TextStyle(
color: _C.textSec,
fontSize: 13,
fontWeight: FontWeight.w600,
letterSpacing: 0.3,
),
),
],
),
const SizedBox(height: 10),
Obx(() {
final otpHelper = Get.find<OtpHelper>();
return Container(
padding: const EdgeInsets.symmetric(horizontal: 16, vertical: 4),
decoration: BoxDecoration(
color: _C.inputBg,
borderRadius: BorderRadius.circular(14),
border: Border.all(color: _C.border, width: 1),
),
child: DropdownButtonHideUnderline(
child: DropdownButton<String>(
value: otpHelper.selectedCountry.value,
icon: const Icon(Icons.arrow_drop_down, color: _C.accent),
isExpanded: true,
dropdownColor: _C.card,
style: const TextStyle(color: _C.textPrimary, fontSize: 16),
items: ['Jordan', 'Egypt', 'Syria'].map((String country) {
return DropdownMenuItem<String>(
value: country,
child: Text(country.tr),
);
}).toList(),
onChanged: (String? val) {
if (val != null) {
otpHelper.changeCountry(val);
}
},
),
),
);
}),
const SizedBox(height: 28),
],
// ── Submit button ────────────────────────────
_isLoading
@@ -21,13 +21,15 @@ class LoginController extends GetxController {
final FlutterSecureStorage storage = const FlutterSecureStorage();
void login() async {
final emailStr = email.text.trim();
final detectedCountry = AppLink.detectCountryFromPhone(emailStr);
if (detectedCountry.isNotEmpty) {
await box.write(BoxName.countryCode, detectedCountry);
}
var selectedCountry = 'Jordan'.obs;
bool isFirstRun = box.read(BoxName.countryCode) == null;
void changeCountry(String country) {
selectedCountry.value = country;
box.write(BoxName.countryCode, country);
}
void login() async {
// Ensure fingerprint is ready
String fingerprint = box.read(BoxName.fingerPrint) ?? '';
if (fingerprint.isEmpty) {
@@ -183,6 +185,10 @@ class LoginController extends GetxController {
@override
void onInit() async {
if (box.read(BoxName.countryCode) == null) {
await box.write(BoxName.countryCode, 'Jordan');
}
selectedCountry.value = box.read(BoxName.countryCode) ?? 'Jordan';
await EncryptionHelper.initialize();
await DeviceHelper.getDeviceFingerprint();
+31 -2
View File
@@ -100,8 +100,37 @@ class LoginPage extends StatelessWidget {
hint: 'أدخل كلمة المرور',
type: TextInputType.visiblePassword,
),
const SizedBox(height: 40),
if (controller.isFirstRun) ...[
Obx(() => Container(
padding: const EdgeInsets.symmetric(horizontal: 16, vertical: 4),
decoration: BoxDecoration(
color: Colors.grey.withOpacity(0.08),
borderRadius: BorderRadius.circular(16),
border: Border.all(color: Colors.grey.withOpacity(0.2)),
),
child: DropdownButtonHideUnderline(
child: DropdownButton<String>(
value: controller.selectedCountry.value,
icon: const Icon(Icons.arrow_drop_down, color: AppColor.blueColor),
isExpanded: true,
dropdownColor: Colors.white,
style: const TextStyle(color: Colors.black87, fontSize: 16),
items: ['Jordan', 'Egypt', 'Syria'].map((String country) {
return DropdownMenuItem<String>(
value: country,
child: Text(country.tr),
);
}).toList(),
onChanged: (String? val) {
if (val != null) {
controller.changeCountry(val);
}
},
),
),
)),
const SizedBox(height: 40),
],
// Login Button
Container(