prepare("SELECT name_ar FROM fuel_stations WHERE id = ? LIMIT 1"); $st->execute([$stationId]); $name = $st->fetchColumn(); if ($name === false) { jsonError('المحطة غير موجودة', 404); } $plainKey = bin2hex(random_bytes(24)); $con->prepare("UPDATE fuel_stations SET api_key_hash = ? WHERE id = ?") ->execute([hash('sha256', $plainKey), $stationId]); error_log("[admin/fuel] دُوِّر مفتاح المحطة #$stationId بواسطة $user_id"); jsonSuccess([ 'station_id' => $stationId, 'station' => $name, 'api_key' => $plainKey, ], 'المفتاح القديم توقّف. انسخ الجديد الآن — لن يظهر مرة أخرى.'); } catch (PDOException $e) { error_log('[admin/fuel/rotate_key] ' . $e->getMessage()); jsonError('Server error', 500); }