Storing the verification phone as a keyed HMAC fixed OTP lookups but broke every query that joined those tables back to the account, because phone_verification*.phone_number no longer holds the same value as driver.phone / passengers.phone. Six joins were affected, and four of them feed the `verified` flag that the rider and driver apps check at sign-in — so this was already failing under the current CBC mode, not only after a switch to GCM. Accounts now carry phone_key, computed exactly as otpPhoneKey() does, and the joins match on it. It is written at registration for both apps and populated for existing rows by the backfill. The backfill also covers the columns added for the remaining lookups: users.email_bidx/phone_bidx and driver.national_bidx, which were migrated but never populated, and honours a per-field prefix so phone_key reproduces otpPhoneKey's exact output. Insert column/value counts verified with a paren-aware parser after editing. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
108 lines
3.5 KiB
PHP
108 lines
3.5 KiB
PHP
<?php
|
|
|
|
require_once __DIR__ . '/../../connect.php';
|
|
|
|
// لا نستقبل id أو email من التطبيق بل نأخذهم من التوكن (JWT) لزيادة الأمان
|
|
$platform = filterRequest("platform") ?: 'unknown';
|
|
$appName = filterRequest("appName") ?: 'unknown';
|
|
|
|
// الاعتماد كلياً على الـ ID المستخرج من JWT داخل connect.php
|
|
$id = $user_id;
|
|
if ($id === 'new') {
|
|
if (isset($decoded->sub) && $decoded->sub !== 'new') {
|
|
$id = $decoded->sub;
|
|
} else {
|
|
$id = filterRequest("passengerID") ?: filterRequest("passengerId");
|
|
}
|
|
}
|
|
|
|
// تجهيز الاستعلام
|
|
$sql = "SELECT
|
|
p.`id`,
|
|
p.`phone`,
|
|
p.`email`,
|
|
p.`gender`,
|
|
p.`status`,
|
|
p.`birthdate`,
|
|
p.`site`,
|
|
p.`first_name`,
|
|
p.`last_name`,
|
|
p.`sosPhone`,
|
|
p.`education`,
|
|
p.`employmentType`,
|
|
p.`maritalStatus`,
|
|
p.`created_at`,
|
|
p.`updated_at`,
|
|
phone_verification_passenger.verified,
|
|
invitesToPassengers.isInstall,
|
|
invitesToPassengers.inviteCode,
|
|
invitesToPassengers.isGiftToken,
|
|
(SELECT `version` FROM `packageInfo` WHERE platform = :platform AND appName = :appName) AS package,
|
|
promos.promo_code AS promo,
|
|
promos.amount AS discount,
|
|
promos.validity_end_date AS validity,
|
|
t.token AS fcm_token,
|
|
t.fingerPrint AS fcm_fingerprint
|
|
FROM passengers p
|
|
LEFT JOIN phone_verification_passenger
|
|
ON phone_verification_passenger.phone_number = p.phone_key
|
|
LEFT JOIN invitesToPassengers
|
|
ON invitesToPassengers.inviterPassengerPhone = p.phone
|
|
LEFT JOIN promos
|
|
ON promos.passengerID = p.id
|
|
LEFT JOIN tokens t
|
|
ON t.passengerID = p.id
|
|
WHERE p.id = :id
|
|
LIMIT 1";
|
|
|
|
// تنفيذ الاستعلام
|
|
$stmt = $con->prepare($sql);
|
|
$stmt->bindParam(':id', $id);
|
|
$stmt->bindParam(':appName', $appName);
|
|
$stmt->bindParam(':platform', $platform);
|
|
$stmt->execute();
|
|
|
|
$data = $stmt->fetchAll(PDO::FETCH_ASSOC);
|
|
$count = $stmt->rowCount();
|
|
|
|
// تجهيز الرد
|
|
header('Content-Type: application/json');
|
|
|
|
if ($count > 0) {
|
|
foreach ($data as &$row) {
|
|
// فك تشفير الحقول الحساسة
|
|
$row['phone'] = $encryptionHelper->decryptData($row['phone']);
|
|
$row['email'] = $encryptionHelper->decryptData($row['email']);
|
|
$row['gender'] = $encryptionHelper->decryptData($row['gender']);
|
|
$row['birthdate'] = $encryptionHelper->decryptData($row['birthdate']);
|
|
$row['site'] = $encryptionHelper->decryptData($row['site']);
|
|
$row['first_name'] = $encryptionHelper->decryptData($row['first_name']);
|
|
$row['last_name'] = $encryptionHelper->decryptData($row['last_name']);
|
|
$row['sosPhone'] = $encryptionHelper->decryptData($row['sosPhone']);
|
|
$row['education'] = $encryptionHelper->decryptData($row['education']);
|
|
$row['employmentType'] = $encryptionHelper->decryptData($row['employmentType']);
|
|
$row['maritalStatus'] = $encryptionHelper->decryptData($row['maritalStatus']);
|
|
|
|
// فك تشفير توكن FCM إذا وجد
|
|
if (!empty($row['fcm_token'])) {
|
|
$row['fcm_token'] = $encryptionHelper->decryptData($row['fcm_token']);
|
|
}
|
|
}
|
|
|
|
echo json_encode([
|
|
"status" => "success",
|
|
"count" => $count,
|
|
"data" => $data
|
|
]);
|
|
} else {
|
|
error_log("User does not exist: " . $email);
|
|
echo json_encode([
|
|
"status" => "Failure",
|
|
"data" => "User does not exist."
|
|
]);
|
|
}
|
|
|
|
// تنظيف الموارد
|
|
$stmt = null;
|
|
$con = null;
|
|
exit(); |