fix: console tenant scoping, miler identity spoofing, delivery proof, timezone
Security - Express console had no tenant scoping at all: LoginAdmin hardcoded tenantid 0 into every JWT and none of the 85 admin handlers filtered by tenant, so any client given a console login would read every other client's bookings, customers, pricing and reports. Adds DoormileAuth.Tenantid (nil = Doormile staff, unrestricted; set = client, scoped), emits it in the token, and scopes reads, guards writes and pins tenantid on create. - Miler telemetry (/miler/logs, /miler/status, /miler/consignments/logs) took userid from the request body, letting any authenticated rider write another rider's status and GPS trail — data the dispatch layer reasons over. Identity now comes from the token. - POST /miler/reset-pin was unauthenticated and overwrote a PIN given only a phone number, so reset-pin + verify-pin took over any rider account. Now requires admin/manager/executive auth. Correctness - Date ranges compared the container's UTC clock against timestamps the DB writes as IST wall-clock (DSN sets TimeZone=Asia/Kolkata), so "today so far" ended 5h30m in the past and silently dropped everything created after noon IST from every report. Sets TZ in the image and adds utils.DBNow/DBToday, which stay correct regardless of container timezone. - CreateMiler never set Configid, so console-created riders got the column default of 1 while LoginMiler looks up configid 1001 — every such rider was unable to log in, reported as "no miler account found". - Delivery wrote no consignment history row, so a tracking timeline never showed the parcel arriving. Features - Delivery OTP is now real (crypto/rand, issued to the receiver, verified and cleared on delivery) but opt-in per client via Tenant.Requiredeliveryotp, defaulting off — friction worth it for a courier parcel, not a food order. - Express bookings accept pickuplocationid, so the console can name a client site (a DailyGrubs kitchen) instead of retyping its address; validated against the tenant and carried through to the consignment. - TenantLocation.Locationname, miler tenantid/hubid, Nagercoil (629) opened. - PUT /miler/availability accepts both "status" and "availabilitystatus", and /miler/location no longer drops speed/heading — both were contract mismatches against the doc the Flutter dev was given. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -96,9 +96,11 @@ func humanizeRelativeTime(t time.Time) string {
|
||||
|
||||
// todayMidnight returns the start of the current day in server local time,
|
||||
// used to scope "today" counters on the hub dashboard.
|
||||
// todayMidnight is the start of the current day as the database records it —
|
||||
// see utils.DBNow. Using the container's own clock here dropped every row
|
||||
// created after noon IST out of "today so far".
|
||||
func todayMidnight() time.Time {
|
||||
now := time.Now()
|
||||
return time.Date(now.Year(), now.Month(), now.Day(), 0, 0, 0, 0, now.Location())
|
||||
return utils.DBToday()
|
||||
}
|
||||
|
||||
// parseHubDateRange parses optional from/to (YYYY-MM-DD) query params shared
|
||||
@@ -110,17 +112,20 @@ func parseHubDateRange(c *fiber.Ctx) (time.Time, time.Time, error) {
|
||||
toStr := c.Query("to")
|
||||
|
||||
if fromStr == "" && toStr == "" {
|
||||
return todayMidnight(), time.Now(), nil
|
||||
return todayMidnight(), utils.DBNow(), nil
|
||||
}
|
||||
if fromStr == "" || toStr == "" {
|
||||
return time.Time{}, time.Time{}, fmt.Errorf("both from and to query params are required (YYYY-MM-DD)")
|
||||
}
|
||||
|
||||
from, err := time.ParseInLocation("2006-01-02", fromStr, time.Local)
|
||||
// Parsed as UTC, not time.Local: stored timestamps are bare wall-clock
|
||||
// digits, so the bounds must be too — otherwise the window silently shifts
|
||||
// with whatever timezone the container happens to run in.
|
||||
from, err := time.ParseInLocation("2006-01-02", fromStr, time.UTC)
|
||||
if err != nil {
|
||||
return time.Time{}, time.Time{}, fmt.Errorf("invalid from date, expected YYYY-MM-DD")
|
||||
}
|
||||
toDate, err := time.ParseInLocation("2006-01-02", toStr, time.Local)
|
||||
toDate, err := time.ParseInLocation("2006-01-02", toStr, time.UTC)
|
||||
if err != nil {
|
||||
return time.Time{}, time.Time{}, fmt.Errorf("invalid to date, expected YYYY-MM-DD")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user