feat: miler self-set PIN on first login; no console-set default PIN

Milers now choose their own PIN the first time they log in, instead of the
console assigning a shared default:

- CreateMiler always creates a rider with an empty Password (PIN field removed
  from MilerCreateRequest); any client-supplied PIN is ignored, making
  "riders set their own PIN" a backend invariant, not a console convention.
- LoginMiler returns `pin_set` so the app routes to enter-PIN vs set-PIN.
- New POST /miler/set-pin (SetMilerPin): self-service first PIN, allowed ONLY
  when the account has none yet (409 otherwise, so it can't overwrite/take over
  an active account), then logs the rider in. Self-service and throttle-only is
  safe because of that guard; OTP-gate it once the SMS gateway is live.
- verify-pin and set-pin share issueMilerSession so the two success responses
  can't drift.

Also switches BookingPickupComplete's timestamp to DBNow() (IST) so the
compatibility-flow inwardedat matches the reconciliation windows.

Existing riders keep their PIN and are unaffected; blanking their password to
move them onto self-set is a separate, deliberate DB step.

go build, go vet and go test ./... all pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WRaFH5hMRqmUQvVPQsyjZD
This commit is contained in:
2026-09-16 12:17:00 +05:30
parent ba2cd2299c
commit dd0fa75e7b
5 changed files with 133 additions and 49 deletions

View File

@@ -1859,8 +1859,6 @@ func CreateMiler(c *fiber.Ctx) error {
return utils.BadRequest(c, "invalid request body")
}
passHash, _ := utils.HashPassword(req.Password)
tx := db.DB.Begin()
appLocID := req.Applocationid
@@ -1884,10 +1882,12 @@ func CreateMiler(c *fiber.Ctx) error {
}
user := models.AppUser{
Authname: req.Authname,
Email: req.Email,
Contactno: req.Contactno,
Password: passHash,
Authname: req.Authname,
Email: req.Email,
Contactno: req.Contactno,
// Empty PIN by design: the rider self-sets it on first login via
// /miler/set-pin. See MilerCreateRequest — no console-set PIN.
Password: "",
Roleid: 5, // Miler
Status: "Active",
Applocationid: appLocID,