fix: console tenant scoping, miler identity spoofing, delivery proof, timezone
Security - Express console had no tenant scoping at all: LoginAdmin hardcoded tenantid 0 into every JWT and none of the 85 admin handlers filtered by tenant, so any client given a console login would read every other client's bookings, customers, pricing and reports. Adds DoormileAuth.Tenantid (nil = Doormile staff, unrestricted; set = client, scoped), emits it in the token, and scopes reads, guards writes and pins tenantid on create. - Miler telemetry (/miler/logs, /miler/status, /miler/consignments/logs) took userid from the request body, letting any authenticated rider write another rider's status and GPS trail — data the dispatch layer reasons over. Identity now comes from the token. - POST /miler/reset-pin was unauthenticated and overwrote a PIN given only a phone number, so reset-pin + verify-pin took over any rider account. Now requires admin/manager/executive auth. Correctness - Date ranges compared the container's UTC clock against timestamps the DB writes as IST wall-clock (DSN sets TimeZone=Asia/Kolkata), so "today so far" ended 5h30m in the past and silently dropped everything created after noon IST from every report. Sets TZ in the image and adds utils.DBNow/DBToday, which stay correct regardless of container timezone. - CreateMiler never set Configid, so console-created riders got the column default of 1 while LoginMiler looks up configid 1001 — every such rider was unable to log in, reported as "no miler account found". - Delivery wrote no consignment history row, so a tracking timeline never showed the parcel arriving. Features - Delivery OTP is now real (crypto/rand, issued to the receiver, verified and cleared on delivery) but opt-in per client via Tenant.Requiredeliveryotp, defaulting off — friction worth it for a courier parcel, not a food order. - Express bookings accept pickuplocationid, so the console can name a client site (a DailyGrubs kitchen) instead of retyping its address; validated against the tenant and carried through to the consignment. - TenantLocation.Locationname, miler tenantid/hubid, Nagercoil (629) opened. - PUT /miler/availability accepts both "status" and "availabilitystatus", and /miler/location no longer drops speed/heading — both were contract mismatches against the doc the Flutter dev was given. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -274,9 +274,6 @@ func MilerDeliverConsignment(c *fiber.Ctx) error {
|
||||
if err := c.BodyParser(&req); err != nil {
|
||||
return utils.BadRequest(c, "invalid request body")
|
||||
}
|
||||
if req.Otp == "" {
|
||||
return utils.BadRequest(c, "otp is required")
|
||||
}
|
||||
if req.Deliveredtoname == "" {
|
||||
return utils.BadRequest(c, "deliveredtoname is required")
|
||||
}
|
||||
@@ -296,17 +293,28 @@ func MilerDeliverConsignment(c *fiber.Ctx) error {
|
||||
return utils.BadRequest(c, "consignment is not out for delivery")
|
||||
}
|
||||
|
||||
// An OTP is only present when the client asked for one (Tenant.Requiredeliveryotp),
|
||||
// so an empty one means this delivery was never meant to need a code — that
|
||||
// covers food clients like DailyGrubs as well as parcels already in the
|
||||
// network from before OTPs existed, which would otherwise be unclosable.
|
||||
if consignment.Deliveryotp != "" {
|
||||
if req.Otp == "" {
|
||||
return utils.BadRequest(c, "otp is required for this delivery")
|
||||
}
|
||||
if req.Otp != consignment.Deliveryotp {
|
||||
return utils.BadRequest(c, "incorrect delivery OTP")
|
||||
}
|
||||
}
|
||||
|
||||
tx := db.DB.Begin()
|
||||
|
||||
// OTP generation/storage is Phase 2 — no delivery_otp field exists yet on
|
||||
// consignments, so acceptance of a non-empty OTP is treated as verified.
|
||||
proof := models.DeliveryProof{
|
||||
Consignmentid: consignment.Consignmentid,
|
||||
Deliveredat: time.Now(),
|
||||
Deliveredtoname: req.Deliveredtoname,
|
||||
Receiversignatureurl: req.Receiversignatureurl,
|
||||
Photourl: req.Photourl,
|
||||
Otpverified: true,
|
||||
Otpverified: consignment.Deliveryotp != "",
|
||||
Geolatitude: req.Lat,
|
||||
Geolongitude: req.Lon,
|
||||
Createdby: milerUserID,
|
||||
@@ -317,12 +325,30 @@ func MilerDeliverConsignment(c *fiber.Ctx) error {
|
||||
}
|
||||
|
||||
consignment.Status = constants.ConsignmentDelivered
|
||||
// Cleared once redeemed so the same code can't close out a second attempt.
|
||||
consignment.Deliveryotp = ""
|
||||
consignment.Updatedat = time.Now()
|
||||
if err := tx.Save(&consignment).Error; err != nil {
|
||||
tx.Rollback()
|
||||
return utils.Internal(c, "failed to mark consignment delivered")
|
||||
}
|
||||
|
||||
// Every other state change on a consignment writes a history row; delivery
|
||||
// did not, so a customer following the tracking timeline never saw the
|
||||
// parcel arrive — it just stopped at Out_for_Delivery.
|
||||
deliveredEvent := models.ConsignmentHistory{
|
||||
Consignmentid: consignment.Consignmentid,
|
||||
Hubid: consignment.Currenthubid,
|
||||
Userid: &milerUserID,
|
||||
Eventstatus: constants.ConsignmentDelivered,
|
||||
Remarks: fmt.Sprintf("Delivered to %s at (%.5f, %.5f)",
|
||||
req.Deliveredtoname, req.Lat, req.Lon),
|
||||
}
|
||||
if err := tx.Create(&deliveredEvent).Error; err != nil {
|
||||
tx.Rollback()
|
||||
return utils.Internal(c, "failed to record delivery history")
|
||||
}
|
||||
|
||||
if err := tx.Model(&models.BookingAssignment{}).
|
||||
Where("bookingid = ? AND mileruserid = ?", booking.Bookingid, milerUserID).
|
||||
Updates(map[string]interface{}{
|
||||
|
||||
Reference in New Issue
Block a user