Hamza-AyedandClaude Opus 5 a1c19b052d Make OTP verification independent of the encryption mode
The verification tables (token_verification*, phone_verification*) use the
phone number as a lookup key: written when the code is sent, read when it is
checked. Storing it encrypted worked only because encryptData() is
deterministic — under AES-GCM the two sides would produce different
ciphertexts and no code would ever verify, locking every user out of
registration and OTP sign-in.

otpPhoneKey() stores a keyed HMAC of the normalised number instead. No schema
change is needed since the column is textual, local and international formats
now resolve to the same key, and the value cannot be reversed without the
pepper. It falls back to the previous behaviour when no pepper is configured.

Applied to both sides of every affected flow — request/verify, and the driver
and passenger send/verify pairs — including the OTP value itself where it is
compared by equality rather than decrypted. auth/otp/verify.php already
decrypts the token before comparing, so it needed no change there.

Also adds ENCRYPTION_MODE to EncryptionHelper: encryptData() writes GCM when
set to 'gcm', CBC otherwise. Verified in both directions — rows written under
CBC stay readable after switching, and rows written under GCM stay readable
after rolling back — so the switch is reversible by an environment variable.

The admin console's own OTP is unaffected: it keys the table by the stored
ciphertext read from adminUser, identical on both sides.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-25 16:18:16 +03:00
2026-07-25 01:02:02 +03:00
2026-06-21 18:58:13 +03:00
2026-06-21 18:58:13 +03:00
2026-06-21 03:02:56 +03:00
2026-06-30 14:19:01 +03:00
2026-07-23 02:19:01 +03:00
2026-07-05 22:40:18 +03:00
2026-07-23 21:02:51 +03:00
2026-07-23 22:14:10 +03:00
2026-07-23 20:43:21 +03:00
2026-07-14 19:10:36 +03:00
2026-07-06 00:44:01 +03:00
2026-07-22 01:07:41 +03:00
2026-06-23 15:21:45 +03:00
2026-06-09 08:40:31 +03:00

📚 مركز توثيق منصة Siro — الفهرس الموحّد

هذا المجلد هو المصدر الوحيد لكل توثيق المشروع. تم دمج المجلدات الثلاثة السابقة (docs + documents + knowledge) هنا، مقسّمة حسب الموضوع.

أين أبدأ؟ التقرير التفاعلي الشامل: 09_reports/siro_digital_legacy_report.html


01_overview — نظرة عامة ومعمارية النظام

فهم البنية الكاملة: 4 تطبيقات Flutter + باك اند PHP + خوادم Socket + Redis.

الملف المحتوى
PROJECT_OVERVIEW.md تعريف المشروع ومكوناته الرئيسية
SYSTEM_ARCHITECTURE.md المعمارية التقنية الكاملة
siro_comprehensive_report.md التقرير الشامل الأحدث (فحص 8 مسارات للكود)
tel.comprehensive_report.md نسخة التقرير الشامل المعدّة للإرسال
Siro_Platform_Report.md تقرير المنصة العام
PLATFORM_CURRENT_STATE_AR.md الحالة الراهنة للمنصة
API_DEPENDENCY_MATRIX.md مصفوفة اعتماديات الـ API
DATABASE_DEPENDENCY_MATRIX.md مصفوفة جداول قاعدة البيانات
server_architecture_feedback.md مراجعة معمارية الخوادم المتعددة
AI_CONTEXT.md سياق موجز لأدوات الذكاء الاصطناعي

02_journeys_and_tutorials — رحلات المستخدم والتوتوريال

سير الرحلة خطوة بخطوة (راكب وسائق) + خطة التوتوريال داخل الموقع.

الملف المحتوى
TUTORIAL_PLAN_AR.md ⭐ خطة التوتوريال الكاملة مع قائمة لقطات الشاشة المطلوبة
PASSENGER_JOURNEY.md دورة حياة الراكب كاملة (شاشات + APIs + حالات)
DRIVER_JOURNEY.md دورة حياة السائق كاملة
ride_simulation_report.md تقرير محاكاة رحلة الراكب
driver_ride_simulation_report.md تقرير محاكاة رحلة السائق
syria_driver_registration_report.md تسجيل سائق سوريا
ملفات *_simulation.html محاكاة تفاعلية بالمتصفح (راكب/سائق/تسجيل/إدارة/نظام كامل)

03_pricing — محرك التسعير

الملف المحتوى
PRICING_ENGINE_ARCHITECTURE.md معمارية محرك التسعير كاملة
pricing_system_report.md تقرير نظام التسعير
دراسة_نظام_أتمتة_السوق_الذكي.md أتمتة مراقبة المنافسين وإعادة التسعير
redis_state_plan.md خطة حالة الرحلة في Redis

04_features — الميزات الفنية والتنافسية

الملف المحتوى
COMPETITIVE_FEATURES.md الميزات التنافسية مقابل كريم/أوبر/يلا-جو
TECHNICAL_ADVANTAGES_AR.md المزايا التقنية المبنية داخلياً
NEW_FEATURES_PROPOSAL_AR.md مقترحات ميزات جديدة
AUDIO_MUSIC_FEATURES_AR.md ميزات الصوت والموسيقى
BATTERY_PERFORMANCE_AR.md أداء البطارية والتحسينات
auto_carplay_checklist_arabic.md Android Auto / CarPlay (عربي + إنجليزي)
ai_document_extraction_prompt.md برومبت استخراج الوثائق بالذكاء الاصطناعي

05_transit_mawasalati — نظام «مواصلاتي» (باصات الجامعات)

الملف المحتوى
transit_comprehensive_workflow_report.md ⭐ سير العمليات الكامل (الأحدث — 2026-07-14)
mawasalati_full_system_review.md المراجعة الفنية الكاملة والفجوات المعروفة
mowasalaty_strategy_report.md التقرير الاستراتيجي (نموذج SaaS المجاني)
mawasalati_plan.md خطة التنفيذ الأصلية

06_investors — وثائق المستثمرين ودراسات الجدوى

الملف المحتوى
rebuild_cost_estimate_egypt_2026.md ⭐ دراسة كلفة إعادة البناء في مصر (فريق + AI، 2026)
SIRO_INVESTOR_REPORT_AR.md تقرير المستثمر الرئيسي
تقرير_المستثمر_الشامل_Siro.md التقرير الشامل للمستثمر
Siro_Investors_Report_AR.md تقرير مستثمرين (نسخة سابقة)
SIRO_INVESTOR_DECK.html عرض المستثمرين التفاعلي
Siro_Feasibility_Study_v4.pdf دراسة الجدوى v4
Siro_Egypt_Competitive_Study_AR.md دراسة سوق مصر التنافسية
تقرير_سيرو_الكامل.docx نسخة Word للمشاركة

⚠️ تنبيه حوكمة: يوجد سرديتان تمويليتان مختلفتان (180K$ سوريا مقابل 200K$/22% عامة) — يجب توحيدهما قبل أي عرض رسمي.

07_marketing — التسويق والنمو

الملف المحتوى
SIRO_MARKETING_REPORT_AR.md تقرير التسويق الرئيسي
marketing_and_growth_strategy.md استراتيجية التسويق والنمو
marketing_integration_plan_ar.md خطة التكامل التسويقي
damascus_zones_map.html خريطة مناطق دمشق

08_security — الأمن ومراجعات الكود

الملف المحتوى
التقرير_الأمني_Backend_Siro.md التدقيق الأمني للباك اند (بنود مفتوحة!)
CODE_REVIEW_REPORT_AR.md مراجعة الكود الشاملة

09_reports — التقارير التفاعلية النهائية

الملف المحتوى
siro_digital_legacy_report.html ⭐ تقرير الإرث الرقمي الشامل (يشمل مواصلاتي وسير الرحلة والتوتوريال)

99_archive — أرشيف

الملف المحتوى
intaleq_v1_secure_latest.md نسخة كود V1 المؤرشفة (1.2MB — مرجع تاريخي فقط)
S
Description
No description provided
Readme
184 MiB
Languages
Dart 56.5%
JavaScript 21.5%
PHP 12.8%
C++ 2.1%
HTML 2%
Other 4.9%