encryptData($phone); $st = $transit_con->prepare( "SELECT a.id, o.contract_status FROM transit_org_admins a JOIN transit_orgs o ON o.id = a.org_id WHERE a.phone = ? AND a.is_active = 1 LIMIT 1" ); $st->execute([$phoneEnc]); $admin = $st->fetch(); if (!$admin) jsonError('Invalid credentials', 401); if ($admin['contract_status'] === 'terminated') jsonError('Account suspended', 403); transitSendAdminOtp($phone); jsonSuccess(null, 'OTP sent successfully');