fix: console tenant scoping, miler identity spoofing, delivery proof, timezone
Security - Express console had no tenant scoping at all: LoginAdmin hardcoded tenantid 0 into every JWT and none of the 85 admin handlers filtered by tenant, so any client given a console login would read every other client's bookings, customers, pricing and reports. Adds DoormileAuth.Tenantid (nil = Doormile staff, unrestricted; set = client, scoped), emits it in the token, and scopes reads, guards writes and pins tenantid on create. - Miler telemetry (/miler/logs, /miler/status, /miler/consignments/logs) took userid from the request body, letting any authenticated rider write another rider's status and GPS trail — data the dispatch layer reasons over. Identity now comes from the token. - POST /miler/reset-pin was unauthenticated and overwrote a PIN given only a phone number, so reset-pin + verify-pin took over any rider account. Now requires admin/manager/executive auth. Correctness - Date ranges compared the container's UTC clock against timestamps the DB writes as IST wall-clock (DSN sets TimeZone=Asia/Kolkata), so "today so far" ended 5h30m in the past and silently dropped everything created after noon IST from every report. Sets TZ in the image and adds utils.DBNow/DBToday, which stay correct regardless of container timezone. - CreateMiler never set Configid, so console-created riders got the column default of 1 while LoginMiler looks up configid 1001 — every such rider was unable to log in, reported as "no miler account found". - Delivery wrote no consignment history row, so a tracking timeline never showed the parcel arriving. Features - Delivery OTP is now real (crypto/rand, issued to the receiver, verified and cleared on delivery) but opt-in per client via Tenant.Requiredeliveryotp, defaulting off — friction worth it for a courier parcel, not a food order. - Express bookings accept pickuplocationid, so the console can name a client site (a DailyGrubs kitchen) instead of retyping its address; validated against the tenant and carried through to the consignment. - TenantLocation.Locationname, miler tenantid/hubid, Nagercoil (629) opened. - PUT /miler/availability accepts both "status" and "availabilitystatus", and /miler/location no longer drops speed/heading — both were contract mismatches against the doc the Flutter dev was given. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -20,10 +20,10 @@ type ParcelRequest struct {
|
||||
Itemcategory string `json:"itemcategory"`
|
||||
Itemdescription string `json:"itemdescription"`
|
||||
Declaredvalue float64 `json:"declaredvalue"`
|
||||
Weight float64 `json:"weight"` // optional — miler weighs at pickup
|
||||
Length float64 `json:"length"` // optional
|
||||
Width float64 `json:"width"` // optional
|
||||
Height float64 `json:"height"` // optional
|
||||
Weight float64 `json:"weight"` // optional — miler weighs at pickup
|
||||
Length float64 `json:"length"` // optional
|
||||
Width float64 `json:"width"` // optional
|
||||
Height float64 `json:"height"` // optional
|
||||
Isfragile bool `json:"isfragile"`
|
||||
Needsinsurance bool `json:"needsinsurance"`
|
||||
Requireslargevehicle bool `json:"requireslargevehicle"`
|
||||
@@ -31,8 +31,8 @@ type ParcelRequest struct {
|
||||
|
||||
type PickupBookingRequest struct {
|
||||
Pickuplocationid *int `json:"pickuplocationid"`
|
||||
Pickupaddress string `json:"pickupaddress"` // required
|
||||
Pickuppincode string `json:"pickuppincode"` // required
|
||||
Pickupaddress string `json:"pickupaddress"` // required
|
||||
Pickuppincode string `json:"pickuppincode"` // required
|
||||
Pickuplatitude float64 `json:"pickuplatitude"`
|
||||
Pickuplongitude float64 `json:"pickuplongitude"`
|
||||
Deliveryaddress string `json:"deliveryaddress"` // optional — can be filled later
|
||||
@@ -55,18 +55,36 @@ type MilerLocationUpdateRequest struct {
|
||||
Latitude float64 `json:"latitude"`
|
||||
Longitude float64 `json:"longitude"`
|
||||
Pincode string `json:"pincode"`
|
||||
// Speed and Heading are sent by the rider app and were previously dropped on
|
||||
// the floor, since unknown JSON fields parse silently. Accepted here so the
|
||||
// values at least reach the periodic-log telemetry rather than vanishing.
|
||||
Speed float64 `json:"speed"`
|
||||
Heading float64 `json:"heading"`
|
||||
}
|
||||
|
||||
type MilerAvailabilityRequest struct {
|
||||
Status string `json:"status"` // Offline, Available, Break, etc.
|
||||
// Availabilitystatus is the field name the published Miler App API Contract
|
||||
// v1.0 told the Flutter dev to send, while the code only ever read "status"
|
||||
// — so the documented request 400s. Both are accepted rather than picking a
|
||||
// winner, because either side may already be built against either name.
|
||||
Availabilitystatus string `json:"availabilitystatus"`
|
||||
}
|
||||
|
||||
// ResolvedStatus returns whichever of the two accepted field names was sent.
|
||||
func (r MilerAvailabilityRequest) ResolvedStatus() string {
|
||||
if r.Status != "" {
|
||||
return r.Status
|
||||
}
|
||||
return r.Availabilitystatus
|
||||
}
|
||||
|
||||
type PricingQuoteRequest struct {
|
||||
Pickuppincode string `json:"pickuppincode"`
|
||||
Deliverypincode string `json:"deliverypincode"`
|
||||
Pickuplatitude float64 `json:"pickuplatitude"`
|
||||
Pickuplongitude float64 `json:"pickuplongitude"`
|
||||
Deliverylatitude float64 `json:"deliverylatitude"`
|
||||
Pickuppincode string `json:"pickuppincode"`
|
||||
Deliverypincode string `json:"deliverypincode"`
|
||||
Pickuplatitude float64 `json:"pickuplatitude"`
|
||||
Pickuplongitude float64 `json:"pickuplongitude"`
|
||||
Deliverylatitude float64 `json:"deliverylatitude"`
|
||||
Deliverylongitude float64 `json:"deliverylongitude"`
|
||||
Parcels []ParcelRequest `json:"parcels"`
|
||||
Parcels []ParcelRequest `json:"parcels"`
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user