fix: close price-tamper, premature rider-free, and IST/txn gaps in merged cx/handover work

Reviewed the 10 merged customer-app/base-handover commits and fixed the
defects found:

- HIGH (money): CreateCxBooking let the request body's `estimate` set the
  billed price with no server-side check; it flows into Estimatedprice →
  ridercharges (miler pay + tenant bill) with no weight re-price, so
  {min:1,max:1} settled a delivery at ₹1. Now the client estimate is honoured
  only when it matches the server quote within 15%, else the server quote
  stands.
- MED: base handover freed the rider and closed the booking-level assignment
  after the FIRST parcel of a multi-destination pickup, dropping the remaining
  stops and crediting one leg. Now finalized only when no consignment of the
  booking is still in the rider's hands.
- MED: inwardedat/completedat were written with time.Now() (UTC) instead of
  DBNow() (IST), skewing them ~5h30 vs createdat and the earnings/reconcile
  windows. Fixed in the handover, inbound-scan, reconcile and pickup-complete
  paths.
- MED: B2C customers got two "miler assigned" pushes on auto-assign (two token
  stores) and none on manual assign. Reconciled to one cxstage.Notify on both
  paths.
- LOW: ReconcileHubInbound now runs in a transaction and checks its audit
  inserts (was returning 200 with a silently-missing history row); CxLogout no
  longer reports signedOut when the token revoke fails; a rider-named handover
  base far from their reported position is rejected instead of silently
  rerouting the parcel to another city.

go build, go vet and go test ./... all pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WRaFH5hMRqmUQvVPQsyjZD
This commit is contained in:
2026-09-16 12:16:50 +05:30
parent 049bb85359
commit ba2cd2299c
7 changed files with 185 additions and 58 deletions

View File

@@ -4,7 +4,6 @@ import (
"fmt"
"strconv"
"strings"
"time"
"doormile/constants"
"doormile/db"
@@ -204,7 +203,11 @@ func ReconcileHubInbound(c *fiber.Ctx) error {
return utils.NotFound(c, "consignment not found")
}
now := time.Now()
// IST wall-clock (DBNow) to match the other consignment timestamps. A single
// transaction so a failed audit insert can't leave a state change with no
// history row and still answer 200.
now := utils.DBNow()
tx := db.DB.Begin()
if !*req.Received {
description := strings.TrimSpace(req.Remarks)
@@ -224,16 +227,23 @@ func ReconcileHubInbound(c *fiber.Ctx) error {
Status: constants.ExceptionOpen,
Createdby: staffAccountID,
}
if err := db.DB.Create(&exception).Error; err != nil {
if err := tx.Create(&exception).Error; err != nil {
tx.Rollback()
return utils.Internal(c, "failed to raise handover exception")
}
db.DB.Create(&models.ConsignmentHistory{
if err := tx.Create(&models.ConsignmentHistory{
Consignmentid: consignment.Consignmentid,
Hubid: &hubID,
Eventstatus: consignment.Status,
Remarks: fmt.Sprintf("Handover disputed at base by hub staff account %d: %s",
staffAccountID, description),
})
}).Error; err != nil {
tx.Rollback()
return utils.Internal(c, "failed to record dispute history")
}
if err := tx.Commit().Error; err != nil {
return utils.Internal(c, "failed to record the dispute")
}
return utils.OK(c, fiber.Map{
"consignmentid": consignment.Consignmentid,
@@ -258,7 +268,8 @@ func ReconcileHubInbound(c *fiber.Ctx) error {
if consignment.Inwardedat == nil {
consignment.Inwardedat = &now
}
if err := db.DB.Save(&consignment).Error; err != nil {
if err := tx.Save(&consignment).Error; err != nil {
tx.Rollback()
return utils.Internal(c, "failed to record receipt")
}
@@ -267,12 +278,19 @@ func ReconcileHubInbound(c *fiber.Ctx) error {
if remarks == "" {
remarks = "Physical receipt confirmed at base"
}
db.DB.Create(&models.ConsignmentHistory{
if err := tx.Create(&models.ConsignmentHistory{
Consignmentid: consignment.Consignmentid,
Hubid: &hubID,
Eventstatus: constants.ConsignmentInwardedAtHub,
Remarks: fmt.Sprintf("%s (hub staff account %d)", remarks, staffAccountID),
})
}).Error; err != nil {
tx.Rollback()
return utils.Internal(c, "failed to record receipt history")
}
}
if err := tx.Commit().Error; err != nil {
return utils.Internal(c, "failed to record the receipt")
}
return utils.OK(c, fiber.Map{