Files
tripz-llc/backend/encrypt_decrypt.php
2026-08-09 16:56:13 +03:00

183 lines
6.5 KiB
PHP
Raw Permalink Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<?php
//encrypt_decrypt.php
// ⚠️ هذا الملف للتوافقية فقط. استخدم core/Security/EncryptionHelper.php للتشفير الجديد
// vendor يقع داخل backend/ لا فوقه. المسار السابق '/../vendor/autoload.php'
// يشير إلى /var/www/vendor غير الموجود، و realpath() تُعيد false عندئذٍ،
// فيصبح الاستدعاء require_once('') ويسقط بخطأ قاتل يُحلّ من مجلد العمل
// الحالي — وهو ما ظهر في السجل كـ "Failed opening required ''".
$autoloadPath = __DIR__ . '/vendor/autoload.php';
if (!file_exists($autoloadPath)) {
$autoloadPath = __DIR__ . '/../vendor/autoload.php';
}
if (file_exists($autoloadPath)) {
require_once $autoloadPath;
}
require_once 'load_env.php';
$siteUser = get_current_user();
$homeDir = "/home/$siteUser";
if (!is_dir($homeDir)) {
$homeDir = realpath(__DIR__ . '/../../../'); // Fallback
}
$env_file = getenv('ENV_FILE_PATH') ?: ($homeDir . '/.env');
if (!file_exists($env_file)) {
$env_file = __DIR__ . '/../.env';
}
loadEnvironment($env_file);
if (!getenv('ENCRYPTION_KEY_PATH')) {
$encKeyDefault = "$homeDir/.enckey";
putenv("ENCRYPTION_KEY_PATH=$encKeyDefault");
$_ENV['ENCRYPTION_KEY_PATH'] = $encKeyDefault;
}
// ✅ FIX C-02: استخدام getenv بدلاً من file_get_contents الثابت
$keyPath = getenv('ENCRYPTION_KEY_PATH');
$key = '';
if ($keyPath && file_exists($keyPath)) {
$key = trim(file_get_contents($keyPath));
}
if (!$key) {
$key = getenv('ENC_KEY') ?: '';
}
$iv = getenv('initializationVector'); // 16 bytes
// ‏الصنف نفسه معرَّف أيضاً في core/Security/EncryptionHelper.php، وأي ملف
// ‏يحمّل bootstrap.php ثم يصل إلى هنا كان ينهار بـ "Cannot declare class
// ‏EncryptionHelper, because the name is already in use" — وهو ما أسقط
// ‏blacklist_manager.php. نُبقي أول تعريف محمَّل (النسخة الحديثة في core)
// ‏ونتخطّى هذه النسخة القديمة المتروكة للتوافقية.
if (!class_exists('EncryptionHelper', false)) {
class EncryptionHelper {
private $key;
private $iv;
public function __construct($key, $iv) {
if (strlen($key) !== 32) {
throw new Exception("❌ المفتاح (Key) لازم يكون 32 بايت.");
}
if (strlen($iv) !== 16) {
throw new Exception("❌ الـ IV لازم يكون 16 بايت.");
}
$this->key = $key;
$this->iv = $iv;
}
// --------- النصوص ----------
private function addPadding($data, $blockSize = 16) {
$pad = $blockSize - (strlen($data) % $blockSize);
return $data . str_repeat(chr($pad), $pad);
}
private function removePadding($data) {
$pad = ord($data[strlen($data) - 1]);
return substr($data, 0, -$pad);
}
public function encryptData($plainText) {
$plainText = mb_convert_encoding($plainText, 'UTF-8');
$paddedText = $this->addPadding($plainText);
$iv = random_bytes(16);
$encrypted = openssl_encrypt($paddedText, 'AES-256-CBC', $this->key, OPENSSL_RAW_DATA, $iv);
return base64_encode($iv . $encrypted);
}
public function decryptData($encryptedText) {
$decoded = base64_decode($encryptedText, true);
if ($decoded === false) {
error_log("[ERROR] base64_decode failed for input: $encryptedText");
return false;
}
// محاولة أولى: استخراج IV عشوائي من أول 16 بايت
if (strlen($decoded) >= 16) {
$iv = substr($decoded, 0, 16);
$payload = substr($decoded, 16);
$decrypted = openssl_decrypt($payload, 'AES-256-CBC', $this->key, OPENSSL_RAW_DATA, $iv);
if ($decrypted !== false) {
$pad = ord($decrypted[strlen($decrypted) - 1]);
if ($pad >= 1 && $pad <= 16) {
return substr($decrypted, 0, -$pad);
}
}
}
// محاولة ثانية: IV ثابت (للبيانات القديمة)
$decrypted = openssl_decrypt($decoded, 'AES-256-CBC', $this->key, OPENSSL_RAW_DATA, $this->iv);
if ($decrypted === false) {
error_log("[ERROR] openssl_decrypt failed for input: $encryptedText");
return false;
}
$pad = ord($decrypted[strlen($decrypted) - 1]);
if ($pad < 1 || $pad > 16) {
error_log("[ERROR] Invalid padding value ($pad) for decrypted input: $encryptedText");
return false;
}
return substr($decrypted, 0, -$pad);
}
public function decryptFile($encryptedFilePath, $destinationPath) {
if (!file_exists($encryptedFilePath)) {
throw new Exception("❌ الملف المشفر غير موجود: $encryptedFilePath");
}
$encryptedData = file_get_contents($encryptedFilePath);
$decryptedData = openssl_decrypt($encryptedData, 'AES-256-CBC', $this->key, OPENSSL_RAW_DATA, $this->iv);
if ($decryptedData === false) {
error_log("[ERROR] openssl_decrypt failed for file: $encryptedFilePath");
throw new Exception("❌ فشل فك تشفير الملف: $encryptedFilePath");
}
file_put_contents($destinationPath, $decryptedData);
return true;
}
public function encryptBinary($data) {
$iv = random_bytes(16);
$encrypted = openssl_encrypt($data, 'AES-256-CBC', $this->key, OPENSSL_RAW_DATA, $iv);
return $iv . $encrypted;
}
public function decryptBinary($data) {
if (strlen($data) >= 16) {
$iv = substr($data, 0, 16);
$payload = substr($data, 16);
$decrypted = openssl_decrypt($payload, 'AES-256-CBC', $this->key, OPENSSL_RAW_DATA, $iv);
if ($decrypted !== false) {
return $decrypted;
}
}
// للبيانات القديمة ذات IV الثابت
$decrypted = openssl_decrypt($data, 'AES-256-CBC', $this->key, OPENSSL_RAW_DATA, $this->iv);
if ($decrypted === false) {
error_log('[CRIT-07] openssl_decrypt failed in decryptBinary');
throw new Exception('Decryption failed');
}
return $decrypted;
}
}
} // نهاية حارس class_exists
// ✅ Load the key and IV from .env or use default values
// ✅ Ensure the lengths are correct
//echo "Key Length: " . $key . PHP_EOL;
//echo "IV Length: " . $iv . PHP_EOL;
try {
$encryptionHelper = new EncryptionHelper($key, $iv);
} catch (Exception $e) {
error_log("[encrypt_decrypt] Initialization error: " . $e->getMessage());
}
?>