"error", "message" => "PIN tidak boleh kosong!"]); exit; } // Pastikan user sudah login if (!isset($_SESSION['user_id'])) { echo json_encode(["status" => "error", "message" => "Sesi login tidak ditemukan. Silakan login ulang."]); exit; } $userId = $_SESSION['user_id']; try { // Verifikasi PIN hanya untuk akun yang sedang login $stmt = $pdo->prepare("SELECT id_account, name, pin FROM account WHERE id_account = ? AND status = 'approved'"); $stmt->execute([$userId]); $account = $stmt->fetch(PDO::FETCH_ASSOC); if ($account && $account['pin'] === $pin) { echo json_encode(["status" => "success", "id_account" => $account['id_account'], "name" => $account['name']]); } else { echo json_encode(["status" => "error", "message" => "PIN salah!"]); } } catch (Exception $e) { echo json_encode(["status" => "error", "message" => "Server error: " . $e->getMessage()]); } ?>