<?php
/*
 * Offerwall.GG postback for VieFaucet.
 *
 * Paste the method below into application/controllers/Wh.php, just before
 * the last closing bracket "}" of the class. Then set your postback URL on
 * offerwall.gg to:
 *
 *     https://YOUR-SITE/wh/offerwallgg
 *
 * Offerwall.GG adds userId, transactionId, currencyAmount, status, test and
 * signature to it on every reward.
 */

    public function offerwallgg()
    {
        // Your placement's secret key from offerwall.gg.
        $secretKey = 'YOUR_SECRET_KEY';

        $userId    = isset($_REQUEST['userId']) ? trim((string) $_REQUEST['userId']) : '';
        $txId      = isset($_REQUEST['transactionId']) ? trim((string) $_REQUEST['transactionId']) : '';
        $amount    = isset($_REQUEST['currencyAmount']) ? trim((string) $_REQUEST['currencyAmount']) : '';
        $status    = isset($_REQUEST['status']) ? (string) $_REQUEST['status'] : 'credited';
        $test      = isset($_REQUEST['test']) ? (string) $_REQUEST['test'] : '0';
        $offerName = isset($_REQUEST['offerName']) ? (string) $_REQUEST['offerName'] : '';
        $signature = isset($_REQUEST['signature']) ? strtolower((string) $_REQUEST['signature']) : '';

        // The signature covers the three values exactly as they arrived.
        $expected = hash_hmac('sha256', $userId . ':' . $txId . ':' . $amount, $secretKey);
        if ($secretKey === '' || $secretKey === 'YOUR_SECRET_KEY' || !hash_equals($expected, $signature)) {
            $this->output->set_status_header(403);
            echo "ERROR: Signature doesn't match";
            return;
        }

        // "Send test postback" on offerwall.gg: answer, credit nobody.
        if ($test === '1') {
            echo 'OK';
            return;
        }

        if (!ctype_digit($userId) || !preg_match('/^[A-Za-z0-9_-]{1,64}$/', $txId) || !is_numeric($amount)) {
            $this->output->set_status_header(400);
            echo 'ERROR: Bad request';
            return;
        }

        $user = $this->m_core->get_user_from_id($userId);
        if (!$user) {
            $this->output->set_status_header(400);
            echo 'ERROR: Unknown user';
            return;
        }

        $reward = abs((float) $amount);
        $ip     = '0.0.0.0';

        // A reversal reuses the transaction id of the reward it cancels.
        // Take back what that reward paid, once.
        if ($status === 'reversed' || (float) $amount < 0) {
            $original = $this->m_offerwall->getTransaction($txId, 'OfferwallGG');
            $reversed = $this->m_offerwall->getTransaction('R-' . $txId, 'OfferwallGG');

            if ($original && !$reversed) {
                $this->m_offerwall->reduceUserBalance($userId, $reward);
                $this->m_offerwall->insertTransaction($userId, 'OfferwallGG', $ip, $reward, 'R-' . $txId, 1, time());
                $this->m_core->addNotification($userId, format_money($reward) . ' USD from an Offerwall.GG offer was reversed.', 0);
            } elseif (!$original && !$reversed) {
                // Never credited here: remember it so a late credit cannot land.
                $this->m_offerwall->insertTransaction($userId, 'OfferwallGG', $ip, 0, 'R-' . $txId, 1, time());
                $this->m_offerwall->insertTransaction($userId, 'OfferwallGG', $ip, 0, $txId, 1, time());
            }

            echo 'OK';
            return;
        }

        if ($this->m_offerwall->getTransaction($txId, 'OfferwallGG')) {
            echo 'DUP';
            return;
        }

        $offerId = $this->m_offerwall->insertTransaction($userId, 'OfferwallGG', $ip, $reward, $txId, 2, time());
        $this->m_offerwall->updateUserBalance($userId, $reward);

        $label = $offerName !== '' ? ' (' . htmlspecialchars(mb_substr($offerName, 0, 60), ENT_QUOTES, 'UTF-8') . ')' : '';
        $this->m_core->addNotification($userId, format_money($reward) . ' USD from Offerwall.GG offer #' . $offerId . $label . ' was credited to your balance.', 1);

        $this->m_core->addExp($user['id'], $this->data['settings']['offerwall_exp_reward']);
        if (($user['exp'] + $this->data['settings']['offerwall_exp_reward']) >= ($user['level'] + 1) * 100) {
            $this->m_core->levelUp($user['id']);
        }

        echo 'OK';
    }
