Searching encrypted columns currently works only because encryptData() is AES-CBC with a fixed IV, i.e. deterministic. That determinism is what leaks equality and shared prefixes, and it is why moving storage to AES-GCM would break every lookup. This separates the two concerns. - core/Security/BlindIndex.php: HMAC-SHA256 over a normalised value, keyed by a secret pepper. Phone numbers have a small keyspace, so a bare SHA-256 would be reversible by enumeration; the pepper lives in the environment, not the database. The scope string includes table and field so the same number does not produce a matching index across tables. Normalisation unifies local/international phone forms, lowercases emails and folds Arabic alef/ya/ta-marbuta and diacritics for names. - migrations/: nullable *_bidx columns plus indexes, and the missing adminUser.status/approved_by/approved_at columns that admin approvals need. - scripts/backfill_blind_index.php: restartable, batched, --dry-run capable, touches only index columns. - Admin lookups by phone/email now match the index, keeping the old ciphertext comparison in the same query so search keeps working until the backfill runs. bootstrap exposes $blindIndex as null when no pepper is configured. Also: AdminCaptain/getCaptainDetailsById.php selected driver.education, a column absent from this schema. The PDOException was uncaught, so the client received an empty body with HTTP 200 — the "non-JSON response" seen when opening a captain. It now omits the column, catches the error, reports it as JSON, and requires an admin role. Console: opening any sidebar section refetches its data instead of showing what was loaded when the console started. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
104 lines
3.4 KiB
PHP
104 lines
3.4 KiB
PHP
<?php
|
|
require_once __DIR__ . '/../connect.php';
|
|
|
|
$passengerEmail = $encryptionHelper->encryptData(filterRequest("passengerEmail"));
|
|
$passengerId = filterRequest("passengerId");
|
|
$passengerphone = $encryptionHelper->encryptData(filterRequest("passengerphone"));
|
|
|
|
|
|
/**
|
|
* الفهرس الأعمى: يسمح بالبحث بعد نقل التخزين إلى AES-GCM العشوائي.
|
|
* تُبقى المقارنة القديمة في نفس الاستعلام كاحتياط حتى تنتهي تعبئة الفهارس.
|
|
*/
|
|
global $blindIndex;
|
|
$emailBidx = $blindIndex ? $blindIndex->index('passengers.email', filterRequest("passengerEmail")) : null;
|
|
$phoneBidx = $blindIndex ? $blindIndex->index('passengers.phone', filterRequest("passengerphone")) : null;
|
|
|
|
$sql = "SELECT
|
|
`passengers`.`id`,
|
|
`passengers`.`phone`,
|
|
`passengers`.`email`,
|
|
`passengers`.`gender`,
|
|
`passengers`.`status`,
|
|
`passengers`.`birthdate`,
|
|
`passengers`.`site`,
|
|
`passengers`.`first_name`,
|
|
`passengers`.`last_name`,
|
|
`passengers`.`sosPhone`,
|
|
`passengers`.`education`,
|
|
`passengers`.`employmentType`,
|
|
`passengers`.`maritalStatus`,
|
|
`passengers`.`created_at`,
|
|
`passengers`.`updated_at`,
|
|
(
|
|
SELECT COUNT(`id`) FROM `passengers`
|
|
) AS countPassenger,
|
|
(
|
|
SELECT COUNT(`id`) FROM `feedBack`
|
|
) AS countFeedback,
|
|
(
|
|
SELECT CAST(AVG(`rating`) AS DECIMAL(10, 2)) FROM `ratingPassenger`
|
|
WHERE `passenger_id` = `passengers`.`id`
|
|
) AS ratingPassenger,
|
|
(
|
|
SELECT COUNT(`driverID`) FROM `ratingPassenger`
|
|
WHERE `passenger_id` = `passengers`.`id`
|
|
) AS countDriverRate,
|
|
(
|
|
SELECT COUNT(`passengerID`) FROM `canecl`
|
|
WHERE `passengerID` = `passengers`.`id`
|
|
) AS countPassengerCancel,
|
|
(
|
|
SELECT CAST(AVG(`rating`) AS DECIMAL(10, 2)) FROM `ratingDriver`
|
|
WHERE `passenger_iD` = `passengers`.`id`
|
|
) AS passengerAverageRating,
|
|
(
|
|
SELECT COUNT(`driver_id`) FROM `ratingDriver`
|
|
WHERE `passenger_id` = `passengers`.`id`
|
|
) AS countPassengerRate,
|
|
(
|
|
SELECT COUNT(`passenger_id`) FROM `ride`
|
|
WHERE `passenger_id` = `passengers`.`id`
|
|
) AS countPassengerRide,
|
|
(
|
|
SELECT `token` FROM `tokens`
|
|
WHERE `passengerID` = `passengers`.`id`
|
|
) AS passengerToken
|
|
FROM
|
|
`passengers`
|
|
WHERE
|
|
passengers.email = :email OR passengers.phone = :phone OR passengers.id = :id
|
|
OR (:email_bidx IS NOT NULL AND passengers.email_bidx = :email_bidx)
|
|
OR (:phone_bidx IS NOT NULL AND passengers.phone_bidx = :phone_bidx)
|
|
";
|
|
|
|
$stmt = $con->prepare($sql);
|
|
$stmt->bindParam(":email", $passengerEmail);
|
|
$stmt->bindParam(":phone", $passengerphone);
|
|
$stmt->bindParam(":id", $passengerId);
|
|
$stmt->bindParam(":email_bidx", $emailBidx);
|
|
$stmt->bindParam(":phone_bidx", $phoneBidx);
|
|
$stmt->execute();
|
|
$result = $stmt->fetchAll(PDO::FETCH_ASSOC);
|
|
|
|
// فك التشفير للحقول الحساسة
|
|
foreach ($result as &$row) {
|
|
$fieldsToDecrypt = [
|
|
"phone", "email", "gender", "birthdate", "site",
|
|
"first_name", "last_name", "sosPhone",
|
|
"education", "employmentType", "maritalStatus"
|
|
];
|
|
|
|
foreach ($fieldsToDecrypt as $field) {
|
|
if (isset($row[$field])) {
|
|
$row[$field] = $encryptionHelper->decryptData($row[$field]);
|
|
}
|
|
}
|
|
}
|
|
|
|
if ($stmt->rowCount() > 0) {
|
|
jsonSuccess($data = $result);
|
|
} else {
|
|
jsonError("No records found");
|
|
}
|
|
?>
|