updates on the customercontroller and the booking.go updates

This commit is contained in:
2026-09-02 17:52:36 +05:30
parent d12629a1e4
commit 35675d8a9b
4 changed files with 196 additions and 6 deletions

58
main.go
View File

@@ -2,6 +2,7 @@ package main
import (
"errors"
"net/url"
"os"
"os/signal"
"strings"
@@ -31,6 +32,30 @@ import (
// turned into an error by the recover middleware — into the same
// {success, message} envelope the utils helpers emit, so clients never receive
// Fiber's default plain-text error body.
// isLoopbackOrigin reports whether an Origin header names this machine, on any
// port. It exists for Flutter Web, whose dev server picks a fresh random port
// on every launch — no fixed allowlist can name it in advance.
//
// Deliberately strict about what counts as loopback: the host must be exactly
// localhost, 127.0.0.1 or [::1]. A prefix match would admit
// http://localhost.attacker.com, which is a different machine entirely and is
// precisely the mistake this kind of check usually makes.
func isLoopbackOrigin(origin string) bool {
u, err := url.Parse(origin)
if err != nil {
return false
}
if u.Scheme != "http" && u.Scheme != "https" {
return false
}
switch u.Hostname() {
case "localhost", "127.0.0.1", "::1":
return true
default:
return false
}
}
func errorHandler(c *fiber.Ctx, err error) error {
code := fiber.StatusInternalServerError
msg := "internal server error"
@@ -107,10 +132,37 @@ func main() {
// nil-pointer dereference in any handler takes the whole process down.
app.Use(recover.New(recover.Config{EnableStackTrace: true}))
// CORS policy
// CORS policy.
//
// The named list is production and the well-known dev-server ports. It cannot
// cover local development on its own: `flutter run -d chrome` binds a RANDOM
// high port on every launch (65256 one run, something else the next), so a
// fixed allowlist misses it every time and the browser rejects the request
// with PreflightMissingAllowOriginHeader before the handler is ever reached.
//
// AllowOriginsFunc is consulted only when the static list has already missed,
// so it widens nothing in production — it just admits loopback origins on any
// port while developing. It is NOT enabled when ENV=production: a live API
// that accepts credentialed requests from any localhost page is a real, if
// modest, hole — a developer visiting a hostile page served from their own
// machine would have that page able to call this API as them.
//
// A wildcard is not an option regardless: AllowCredentials with
// AllowOrigins "*" is rejected by the CORS spec, and Fiber panics on it.
allowLoopbackOrigins := !strings.EqualFold(cfg.Env, "production")
if allowLoopbackOrigins {
utils.Info("CORS: loopback origins on any port are allowed (non-production)", "env", cfg.Env)
}
app.Use(cors.New(cors.Config{
AllowHeaders: "Origin,Content-Type,Accept,Authorization",
AllowOrigins: "http://localhost:5173,http://localhost:5174,http://localhost:3000,http://localhost:3001,http://localhost:3002,http://localhost:8080,http://localhost:8081,https://doormile.com,https://www.doormile.com,https://admin.doormile.com,https://api.doormile.com,https://crm.doormile.com,https://console.doormile.com,https://app.doormile.com,https://hub.doormile.com",
// Idempotency-Key is sent by the rider app on pickup-complete, payment
// and the base handover. A browser client that could not send it would
// lose retry safety on exactly the calls that most need it.
AllowHeaders: "Origin,Content-Type,Accept,Authorization,Idempotency-Key",
AllowOrigins: "http://localhost:5173,http://localhost:5174,http://localhost:3000,http://localhost:3001,http://localhost:3002,http://localhost:8080,http://localhost:8081,https://doormile.com,https://www.doormile.com,https://admin.doormile.com,https://api.doormile.com,https://crm.doormile.com,https://console.doormile.com,https://app.doormile.com,https://hub.doormile.com",
AllowOriginsFunc: func(origin string) bool {
return allowLoopbackOrigins && isLoopbackOrigin(origin)
},
AllowCredentials: true,
AllowMethods: "GET,POST,PUT,DELETE,PATCH,OPTIONS",
}))