'Order ID not specified']); exit; } $status = null; try { $pdo = db(); if ($user_id) { $stmt = $pdo->prepare("SELECT status FROM orders WHERE id = ? AND user_id = ?"); $stmt->execute([$order_id, $user_id]); $result = $stmt->fetch(PDO::FETCH_ASSOC); if ($result) { $status = $result['status']; } } elseif ($token) { $stmt = $pdo->prepare("SELECT status FROM orders WHERE id = ? AND guest_token = ?"); $stmt->execute([$order_id, $token]); $result = $stmt->fetch(PDO::FETCH_ASSOC); if ($result) { $status = $result['status']; } } if ($status) { echo json_encode(['status' => ucwords($status)]); } else { echo json_encode(['error' => 'Order not found or permission denied']); } } catch (PDOException $e) { http_response_code(500); echo json_encode(['error' => 'Database connection error']); }