fix: console tenant scoping, miler identity spoofing, delivery proof, timezone

Security
- Express console had no tenant scoping at all: LoginAdmin hardcoded tenantid 0
  into every JWT and none of the 85 admin handlers filtered by tenant, so any
  client given a console login would read every other client's bookings,
  customers, pricing and reports. Adds DoormileAuth.Tenantid (nil = Doormile
  staff, unrestricted; set = client, scoped), emits it in the token, and scopes
  reads, guards writes and pins tenantid on create.
- Miler telemetry (/miler/logs, /miler/status, /miler/consignments/logs) took
  userid from the request body, letting any authenticated rider write another
  rider's status and GPS trail — data the dispatch layer reasons over. Identity
  now comes from the token.
- POST /miler/reset-pin was unauthenticated and overwrote a PIN given only a
  phone number, so reset-pin + verify-pin took over any rider account. Now
  requires admin/manager/executive auth.

Correctness
- Date ranges compared the container's UTC clock against timestamps the DB
  writes as IST wall-clock (DSN sets TimeZone=Asia/Kolkata), so "today so far"
  ended 5h30m in the past and silently dropped everything created after noon
  IST from every report. Sets TZ in the image and adds utils.DBNow/DBToday,
  which stay correct regardless of container timezone.
- CreateMiler never set Configid, so console-created riders got the column
  default of 1 while LoginMiler looks up configid 1001 — every such rider was
  unable to log in, reported as "no miler account found".
- Delivery wrote no consignment history row, so a tracking timeline never
  showed the parcel arriving.

Features
- Delivery OTP is now real (crypto/rand, issued to the receiver, verified and
  cleared on delivery) but opt-in per client via Tenant.Requiredeliveryotp,
  defaulting off — friction worth it for a courier parcel, not a food order.
- Express bookings accept pickuplocationid, so the console can name a client
  site (a DailyGrubs kitchen) instead of retyping its address; validated
  against the tenant and carried through to the consignment.
- TenantLocation.Locationname, miler tenantid/hubid, Nagercoil (629) opened.
- PUT /miler/availability accepts both "status" and "availabilitystatus", and
  /miler/location no longer drops speed/heading — both were contract
  mismatches against the doc the Flutter dev was given.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Suriya
2026-08-05 18:16:56 +05:30
parent e1fd4dc5d0
commit fd7cf3e35e
14 changed files with 614 additions and 184 deletions

View File

@@ -7,17 +7,23 @@ type TenantCreateRequest struct {
Primaryemail string `json:"primaryemail"`
Primarycontact string `json:"primarycontact"`
Status string `json:"status"`
// Requiredeliveryotp is a pointer so an update that omits it leaves the
// existing setting alone rather than silently switching OTPs off.
Requiredeliveryotp *bool `json:"requiredeliveryotp"`
}
type TenantLocationCreateRequest struct {
Address string `json:"address"`
City string `json:"city"`
State string `json:"state"`
Pincode string `json:"pincode"`
Latitude float64 `json:"latitude"`
Longitude float64 `json:"longitude"`
Isprimary bool `json:"isprimary"`
Status string `json:"status"`
// Locationname is the client's own label for the site — "DailyGrubs
// Peelamedu Kitchen" — since an address alone doesn't identify a branch.
Locationname string `json:"locationname"`
Address string `json:"address"`
City string `json:"city"`
State string `json:"state"`
Pincode string `json:"pincode"`
Latitude float64 `json:"latitude"`
Longitude float64 `json:"longitude"`
Isprimary bool `json:"isprimary"`
Status string `json:"status"`
}
type TenantCustomerCreateRequest struct {
@@ -57,13 +63,23 @@ type VehicleCreateRequest struct {
}
type MilerCreateRequest struct {
Authname string `json:"authname"`
Email string `json:"email"`
Contactno string `json:"contactno"`
Password string `json:"password"`
Displayname string `json:"displayname"`
Authname string `json:"authname"`
Email string `json:"email"`
Contactno string `json:"contactno"`
Password string `json:"password"`
Displayname string `json:"displayname"`
// Tenantid attaches a rider to the client they deliver for — riders migrated
// from jupiter belong to a specific client (DailyGrubs, Bawa Medicals)
// rather than to Doormile's general pool. Zero leaves them unattached.
Tenantid int `json:"tenantid"`
Defaultvehicletype string `json:"defaultvehicletype"`
Applocationid int `json:"applocationid"`
// Configid partitions logins; defaults to 1001, which is what the miler app
// authenticates against. Only set this if you know why you're changing it.
Configid int `json:"configid"`
// Hubid is optional: a rider with no hub is still assignable from the
// express console, but is invisible to the hub console's miler list.
Hubid *int `json:"hubid"`
}
type PricingCreateRequest struct {

View File

@@ -20,10 +20,10 @@ type ParcelRequest struct {
Itemcategory string `json:"itemcategory"`
Itemdescription string `json:"itemdescription"`
Declaredvalue float64 `json:"declaredvalue"`
Weight float64 `json:"weight"` // optional — miler weighs at pickup
Length float64 `json:"length"` // optional
Width float64 `json:"width"` // optional
Height float64 `json:"height"` // optional
Weight float64 `json:"weight"` // optional — miler weighs at pickup
Length float64 `json:"length"` // optional
Width float64 `json:"width"` // optional
Height float64 `json:"height"` // optional
Isfragile bool `json:"isfragile"`
Needsinsurance bool `json:"needsinsurance"`
Requireslargevehicle bool `json:"requireslargevehicle"`
@@ -31,8 +31,8 @@ type ParcelRequest struct {
type PickupBookingRequest struct {
Pickuplocationid *int `json:"pickuplocationid"`
Pickupaddress string `json:"pickupaddress"` // required
Pickuppincode string `json:"pickuppincode"` // required
Pickupaddress string `json:"pickupaddress"` // required
Pickuppincode string `json:"pickuppincode"` // required
Pickuplatitude float64 `json:"pickuplatitude"`
Pickuplongitude float64 `json:"pickuplongitude"`
Deliveryaddress string `json:"deliveryaddress"` // optional — can be filled later
@@ -55,18 +55,36 @@ type MilerLocationUpdateRequest struct {
Latitude float64 `json:"latitude"`
Longitude float64 `json:"longitude"`
Pincode string `json:"pincode"`
// Speed and Heading are sent by the rider app and were previously dropped on
// the floor, since unknown JSON fields parse silently. Accepted here so the
// values at least reach the periodic-log telemetry rather than vanishing.
Speed float64 `json:"speed"`
Heading float64 `json:"heading"`
}
type MilerAvailabilityRequest struct {
Status string `json:"status"` // Offline, Available, Break, etc.
// Availabilitystatus is the field name the published Miler App API Contract
// v1.0 told the Flutter dev to send, while the code only ever read "status"
// — so the documented request 400s. Both are accepted rather than picking a
// winner, because either side may already be built against either name.
Availabilitystatus string `json:"availabilitystatus"`
}
// ResolvedStatus returns whichever of the two accepted field names was sent.
func (r MilerAvailabilityRequest) ResolvedStatus() string {
if r.Status != "" {
return r.Status
}
return r.Availabilitystatus
}
type PricingQuoteRequest struct {
Pickuppincode string `json:"pickuppincode"`
Deliverypincode string `json:"deliverypincode"`
Pickuplatitude float64 `json:"pickuplatitude"`
Pickuplongitude float64 `json:"pickuplongitude"`
Deliverylatitude float64 `json:"deliverylatitude"`
Pickuppincode string `json:"pickuppincode"`
Deliverypincode string `json:"deliverypincode"`
Pickuplatitude float64 `json:"pickuplatitude"`
Pickuplongitude float64 `json:"pickuplongitude"`
Deliverylatitude float64 `json:"deliverylatitude"`
Deliverylongitude float64 `json:"deliverylongitude"`
Parcels []ParcelRequest `json:"parcels"`
Parcels []ParcelRequest `json:"parcels"`
}