updates on the onboardings and hubs patches as well
This commit is contained in:
@@ -37,6 +37,22 @@ func consoleTenantID(c *fiber.Ctx) int {
|
||||
return tenantID
|
||||
}
|
||||
|
||||
// clientCityID is a client login's operating city: the applocationid of the
|
||||
// token's appusers row. isClient is false for Doormile staff. A client whose
|
||||
// user row has no city gets city 0, and callers show them nothing rather than
|
||||
// everything.
|
||||
func clientCityID(c *fiber.Ctx) (city int, isClient bool) {
|
||||
if isDoormileConsoleStaff(c) {
|
||||
return 0, false
|
||||
}
|
||||
uid, _ := c.Locals("userid").(int)
|
||||
var u models.AppUser
|
||||
if uid == 0 || db.DB.Select("applocationid").Where("userid = ?", uid).First(&u).Error != nil {
|
||||
return 0, true
|
||||
}
|
||||
return u.Applocationid, true
|
||||
}
|
||||
|
||||
// isDoormileConsoleStaff reports whether the caller sees every tenant's data.
|
||||
func isDoormileConsoleStaff(c *fiber.Ctx) bool {
|
||||
return consoleTenantID(c) == 0
|
||||
@@ -263,6 +279,9 @@ func LoginAdmin(cfg *config.Config) fiber.Handler {
|
||||
"email": auth.Email,
|
||||
"role": auth.Role,
|
||||
"tenantid": auth.Tenantid,
|
||||
// The login's operating city, so the console can offer a client
|
||||
// the Doormile hubs of their own city as zones.
|
||||
"applocationid": appUser.Applocationid,
|
||||
},
|
||||
})
|
||||
}
|
||||
@@ -1610,6 +1629,16 @@ func GetHubs(c *fiber.Ctx) error {
|
||||
var hubs []models.Hub
|
||||
query := db.DB.Where("deletedat IS NULL")
|
||||
|
||||
// A client login sees only the hubs of its own city. Every page that
|
||||
// lists hubs (zones, order form, Fleet Ops) reads this endpoint, and it
|
||||
// used to hand clients every hub in every city.
|
||||
if city, isClient := clientCityID(c); isClient {
|
||||
if city == 0 {
|
||||
return utils.List(c, []models.Hub{}, 0)
|
||||
}
|
||||
query = query.Where("applocationid = ?", city)
|
||||
}
|
||||
|
||||
if appLocationID := c.Query("applocationid"); appLocationID != "" {
|
||||
query = query.Where("applocationid = ?", appLocationID)
|
||||
}
|
||||
@@ -1707,6 +1736,10 @@ func GetHubDetails(c *fiber.Ctx) error {
|
||||
if err := db.DB.Where("hubid = ? AND deletedat IS NULL", id).First(&hub).Error; err != nil {
|
||||
return utils.NotFound(c, "hub not found")
|
||||
}
|
||||
// Same city rule as GetHubs; another city's hub reads as not found.
|
||||
if city, isClient := clientCityID(c); isClient && hub.Applocationid != city {
|
||||
return utils.NotFound(c, "hub not found")
|
||||
}
|
||||
// A one-element slice, because attachHubCities writes THROUGH the slice —
|
||||
// handing it `[]models.Hub{hub}` would fill a copy and return the original
|
||||
// with City still empty.
|
||||
@@ -3678,7 +3711,10 @@ func CreateException(c *fiber.Ctx) error {
|
||||
func GetExceptionDetails(c *fiber.Ctx) error {
|
||||
id, _ := strconv.Atoi(c.Params("id"))
|
||||
var exception models.ConsignmentException
|
||||
if err := db.DB.Where("exceptionid = ? AND deletedat IS NULL", id).First(&exception).Error; err != nil {
|
||||
// Scoped like GetExceptions: a client could otherwise read any other
|
||||
// client's exception by guessing its id.
|
||||
if err := scopeViaConsignments(c, db.DB, "consignmentid").
|
||||
Where("exceptionid = ? AND deletedat IS NULL", id).First(&exception).Error; err != nil {
|
||||
return utils.NotFound(c, "exception not found")
|
||||
}
|
||||
return utils.OK(c, exception)
|
||||
|
||||
Reference in New Issue
Block a user