feat: miler self-set PIN on first login; no console-set default PIN
Milers now choose their own PIN the first time they log in, instead of the console assigning a shared default: - CreateMiler always creates a rider with an empty Password (PIN field removed from MilerCreateRequest); any client-supplied PIN is ignored, making "riders set their own PIN" a backend invariant, not a console convention. - LoginMiler returns `pin_set` so the app routes to enter-PIN vs set-PIN. - New POST /miler/set-pin (SetMilerPin): self-service first PIN, allowed ONLY when the account has none yet (409 otherwise, so it can't overwrite/take over an active account), then logs the rider in. Self-service and throttle-only is safe because of that guard; OTP-gate it once the SMS gateway is live. - verify-pin and set-pin share issueMilerSession so the two success responses can't drift. Also switches BookingPickupComplete's timestamp to DBNow() (IST) so the compatibility-flow inwardedat matches the reconciliation windows. Existing riders keep their PIN and are unaffected; blanking their password to move them onto self-set is a separate, deliberate DB step. go build, go vet and go test ./... all pass. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WRaFH5hMRqmUQvVPQsyjZD
This commit is contained in:
@@ -175,6 +175,11 @@ func RegisterRoutes(app *fiber.App, cfg *config.Config) {
|
||||
miler := api.Group("/miler")
|
||||
miler.Post("/login", authThrottle, controllers.LoginMiler(cfg))
|
||||
miler.Post("/verify-pin", authThrottle, controllers.VerifyMilerPin(cfg))
|
||||
// First-login PIN creation is self-service (unlike reset-pin below), and safe
|
||||
// to leave unauthenticated because SetMilerPin refuses to overwrite an
|
||||
// existing PIN — it only works on an account that has none yet. authThrottle
|
||||
// still caps abuse of the phone-number probe.
|
||||
miler.Post("/set-pin", authThrottle, controllers.SetMilerPin(cfg))
|
||||
// PIN reset is console-operated, NOT self-service: ResetMilerPin overwrites
|
||||
// the PIN given only a phone number, and phone numbers are the miler login
|
||||
// identifier rather than a secret. Left unauthenticated, two calls
|
||||
|
||||
Reference in New Issue
Block a user