service add APP_SIGNATURE_SERVICE 1
This commit is contained in:
@@ -267,6 +267,8 @@ class JwtService
|
||||
error_log("[SECURITY] HMAC mismatch | user: $userId | IP: " . ($_SERVER['REMOTE_ADDR'] ?? '?'));
|
||||
self::abort(403, 'Invalid HMAC signature');
|
||||
}
|
||||
|
||||
|
||||
}
|
||||
|
||||
return $decoded;
|
||||
|
||||
@@ -78,13 +78,18 @@ try {
|
||||
$expires_in = $ttl;
|
||||
}
|
||||
|
||||
// توليد مفتاح HMAC فريد للمستخدم (للتوافق مع CRUD الجديد)
|
||||
$hmacKey = hash_hmac('sha256', (string)$user['id'], getenv('SECRET_KEY_HMAC'));
|
||||
|
||||
printSuccess([
|
||||
"message" => "Login successful",
|
||||
"data" => $user,
|
||||
"jwt" => $jwt,
|
||||
"hmac" => $hmacKey,
|
||||
"expires_in" => $expires_in
|
||||
]);
|
||||
|
||||
|
||||
} else {
|
||||
jsonError("Incorrect password");
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user