fix: console tenant scoping, miler identity spoofing, delivery proof, timezone

Security
- Express console had no tenant scoping at all: LoginAdmin hardcoded tenantid 0
  into every JWT and none of the 85 admin handlers filtered by tenant, so any
  client given a console login would read every other client's bookings,
  customers, pricing and reports. Adds DoormileAuth.Tenantid (nil = Doormile
  staff, unrestricted; set = client, scoped), emits it in the token, and scopes
  reads, guards writes and pins tenantid on create.
- Miler telemetry (/miler/logs, /miler/status, /miler/consignments/logs) took
  userid from the request body, letting any authenticated rider write another
  rider's status and GPS trail — data the dispatch layer reasons over. Identity
  now comes from the token.
- POST /miler/reset-pin was unauthenticated and overwrote a PIN given only a
  phone number, so reset-pin + verify-pin took over any rider account. Now
  requires admin/manager/executive auth.

Correctness
- Date ranges compared the container's UTC clock against timestamps the DB
  writes as IST wall-clock (DSN sets TimeZone=Asia/Kolkata), so "today so far"
  ended 5h30m in the past and silently dropped everything created after noon
  IST from every report. Sets TZ in the image and adds utils.DBNow/DBToday,
  which stay correct regardless of container timezone.
- CreateMiler never set Configid, so console-created riders got the column
  default of 1 while LoginMiler looks up configid 1001 — every such rider was
  unable to log in, reported as "no miler account found".
- Delivery wrote no consignment history row, so a tracking timeline never
  showed the parcel arriving.

Features
- Delivery OTP is now real (crypto/rand, issued to the receiver, verified and
  cleared on delivery) but opt-in per client via Tenant.Requiredeliveryotp,
  defaulting off — friction worth it for a courier parcel, not a food order.
- Express bookings accept pickuplocationid, so the console can name a client
  site (a DailyGrubs kitchen) instead of retyping its address; validated
  against the tenant and carried through to the consignment.
- TenantLocation.Locationname, miler tenantid/hubid, Nagercoil (629) opened.
- PUT /miler/availability accepts both "status" and "availabilitystatus", and
  /miler/location no longer drops speed/heading — both were contract
  mismatches against the doc the Flutter dev was given.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Suriya
2026-08-05 18:16:56 +05:30
parent e1fd4dc5d0
commit fd7cf3e35e
14 changed files with 614 additions and 184 deletions

View File

@@ -57,9 +57,9 @@ type Consignment struct {
Chargeableweight float64 `json:"chargeableweight" gorm:"column:chargeableweight;not null"`
Codamount float64 `json:"codamount" gorm:"column:codamount;default:0.00"`
Codcollected float64 `json:"codcollected" gorm:"column:codcollected;default:0.00"`
Paymentmode string `json:"paymentmode" gorm:"column:paymentmode"` // Prepaid, COD, To_Pay
Paymentmode string `json:"paymentmode" gorm:"column:paymentmode"` // Prepaid, COD, To_Pay
Billingstatus string `json:"billingstatus" gorm:"column:billingstatus;default:Unbilled"` // Unbilled, Billed, Paid, Settled
Status string `json:"status" gorm:"column:status;default:Created"` // Created, Inwarded_at_Hub, Tripsheet_Loaded, In_Transit, Out_for_Delivery, Delivered, RTO_Initiated, Returned_to_Sender, Missing, Damaged
Status string `json:"status" gorm:"column:status;default:Created"` // Created, Inwarded_at_Hub, Tripsheet_Loaded, In_Transit, Out_for_Delivery, Delivered, RTO_Initiated, Returned_to_Sender, Missing, Damaged
Attemptcount int `json:"attemptcount" gorm:"column:attemptcount;default:0"`
Estimateddeliveryat *time.Time `json:"estimateddeliveryat" gorm:"column:estimateddeliveryat"`
Sladueat *time.Time `json:"sladueat" gorm:"column:sladueat"`
@@ -69,11 +69,16 @@ type Consignment struct {
Parentconsignmentid *int `json:"parentconsignmentid" gorm:"column:parentconsignmentid"`
Condition string `json:"condition" gorm:"column:condition;size:50"` // recorded at hub inbound scan: Good, Damaged, etc.
Shelf string `json:"shelf" gorm:"column:shelf;size:50"` // hub storage location assigned at inbound scan
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
Createdby int `json:"createdby" gorm:"column:createdby"`
Updatedby int `json:"updatedby" gorm:"column:updatedby"`
Deletedat *time.Time `json:"deletedat,omitempty" gorm:"column:deletedat"`
// Deliveryotp is issued when the consignment goes out for delivery and is
// given to the receiver, not the rider — it is the only proof the parcel
// reached the right person. Never serialised outward: returning it in an API
// response would hand the rider the code they are supposed to be told.
Deliveryotp string `json:"-" gorm:"column:deliveryotp;size:6"`
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
Createdby int `json:"createdby" gorm:"column:createdby"`
Updatedby int `json:"updatedby" gorm:"column:updatedby"`
Deletedat *time.Time `json:"deletedat,omitempty" gorm:"column:deletedat"`
}
func (Consignment) TableName() string {
@@ -121,12 +126,12 @@ func (ConsignmentException) TableName() string {
// at that hub. One conversation per (hubid, mileruserid) pair.
type HubConversation struct {
Hubconversationid int `json:"hubconversationid" gorm:"primaryKey;column:hubconversationid"`
Hubid int `json:"hubid" gorm:"column:hubid;index;not null"`
Mileruserid *int `json:"mileruserid" gorm:"column:mileruserid;index"`
Participantname string `json:"participantname" gorm:"column:participantname;not null"`
Participantrole string `json:"participantrole" gorm:"column:participantrole"`
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
Hubid int `json:"hubid" gorm:"column:hubid;index;not null"`
Mileruserid *int `json:"mileruserid" gorm:"column:mileruserid;index"`
Participantname string `json:"participantname" gorm:"column:participantname;not null"`
Participantrole string `json:"participantrole" gorm:"column:participantrole"`
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
}
func (HubConversation) TableName() string {
@@ -137,13 +142,13 @@ func (HubConversation) TableName() string {
// requesting hub staff) or "them" (the other party), matching the hub
// console frontend's bubble-side convention.
type HubMessage struct {
Hubmessageid int `json:"hubmessageid" gorm:"primaryKey;column:hubmessageid"`
Hubconversationid int `json:"hubconversationid" gorm:"column:hubconversationid;index;not null"`
Sender string `json:"sender" gorm:"column:sender;not null"` // me, them
Senderstaffid *int `json:"senderstaffid" gorm:"column:senderstaffid"`
Messagetext string `json:"messagetext" gorm:"column:messagetext;not null"`
Isread bool `json:"isread" gorm:"column:isread;default:false"`
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
Hubmessageid int `json:"hubmessageid" gorm:"primaryKey;column:hubmessageid"`
Hubconversationid int `json:"hubconversationid" gorm:"column:hubconversationid;index;not null"`
Sender string `json:"sender" gorm:"column:sender;not null"` // me, them
Senderstaffid *int `json:"senderstaffid" gorm:"column:senderstaffid"`
Messagetext string `json:"messagetext" gorm:"column:messagetext;not null"`
Isread bool `json:"isread" gorm:"column:isread;default:false"`
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
}
func (HubMessage) TableName() string {

View File

@@ -18,11 +18,11 @@ type DoormileClient struct {
Phone string `gorm:"uniqueIndex;size:20;not null" json:"phone"`
// Location
Address string `gorm:"type:text" json:"address"`
City string `gorm:"size:100" json:"city"`
State string `gorm:"size:100" json:"state"`
Neighbourhood string `gorm:"size:100" json:"neighbourhood"`
Pincode string `gorm:"size:20" json:"pincode"`
Address string `gorm:"type:text" json:"address"`
City string `gorm:"size:100" json:"city"`
State string `gorm:"size:100" json:"state"`
Neighbourhood string `gorm:"size:100" json:"neighbourhood"`
Pincode string `gorm:"size:20" json:"pincode"`
// GPS survey data
SurveyLat float64 `gorm:"column:surveylat" json:"survey_lat"`
@@ -41,10 +41,10 @@ type DoormileClient struct {
// Full-consent-only fields (zeroed for basicOnly)
ParcelVolume float64 `json:"parcel_volume"`
ActiveContracts int `json:"active_contracts"`
LogisticsProvider string `gorm:"size:100" json:"logistics_provider"`
ProviderEfficiency string `gorm:"size:100" json:"provider_efficiency"`
Notes string `gorm:"type:text" json:"notes"`
ActiveContracts int `json:"active_contracts"`
LogisticsProvider string `gorm:"size:100" json:"logistics_provider"`
ProviderEfficiency string `gorm:"size:100" json:"provider_efficiency"`
Notes string `gorm:"type:text" json:"notes"`
// Consent & registration tracking
DataConsent string `gorm:"size:20;default:'full'" json:"data_consent"`
@@ -63,8 +63,13 @@ type DoormileAuth struct {
Email string `gorm:"uniqueIndex;size:255;not null" json:"email"`
PasswordHash string `gorm:"not null" json:"-"`
Role string `gorm:"default:'user'" json:"role"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
// Tenantid scopes an express-console login to one client, using the same
// convention as HubStaffAccount.Tenantid: null = Doormile's own staff, who
// see every tenant's data; set = a client's own login, restricted to their
// tenant. Without this every console login sees all tenants.
Tenantid *int `gorm:"column:tenantid;index" json:"tenantid"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
}
func (DoormileAuth) TableName() string {

View File

@@ -4,13 +4,19 @@ import "time"
// Tenant represents the pre-existing 'tenants' table
type Tenant struct {
Tenantid int `json:"tenantid" gorm:"primaryKey;column:tenantid"`
Tenantname string `json:"tenantname" gorm:"column:tenantname"`
Primaryemail string `json:"primaryemail" gorm:"column:primaryemail"`
Primarycontact string `json:"primarycontact" gorm:"column:primarycontact"`
Status string `json:"status" gorm:"column:status;default:Active"`
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
Tenantid int `json:"tenantid" gorm:"primaryKey;column:tenantid"`
Tenantname string `json:"tenantname" gorm:"column:tenantname"`
Primaryemail string `json:"primaryemail" gorm:"column:primaryemail"`
Primarycontact string `json:"primarycontact" gorm:"column:primarycontact"`
Status string `json:"status" gorm:"column:status;default:Active"`
// Requiredeliveryotp decides whether the receiver must read a code back to
// the rider. Worth the friction for a courier handing over a valuable
// parcel; not for a food order, where it just slows every drop down.
// Defaults off: turning it on platform-wide would block deliveries for
// clients whose customer app has no way to show the code yet.
Requiredeliveryotp bool `json:"requiredeliveryotp" gorm:"column:requiredeliveryotp;default:false"`
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
}
func (Tenant) TableName() string {
@@ -19,14 +25,14 @@ func (Tenant) TableName() string {
// Customer represents the pre-existing 'customers' table
type Customer struct {
Customerid int `json:"customerid" gorm:"primaryKey;column:customerid"`
Firstname string `json:"firstname" gorm:"column:firstname"`
Lastname string `json:"lastname" gorm:"column:lastname"`
Contactno string `json:"contactno" gorm:"column:contactno"`
Email string `json:"email" gorm:"column:email"`
Status int `json:"status" gorm:"column:status"`
Createdat time.Time `json:"createdat" gorm:"column:createdat"`
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat"`
Customerid int `json:"customerid" gorm:"primaryKey;column:customerid"`
Firstname string `json:"firstname" gorm:"column:firstname"`
Lastname string `json:"lastname" gorm:"column:lastname"`
Contactno string `json:"contactno" gorm:"column:contactno"`
Email string `json:"email" gorm:"column:email"`
Status int `json:"status" gorm:"column:status"`
Createdat time.Time `json:"createdat" gorm:"column:createdat"`
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat"`
}
func (Customer) TableName() string {
@@ -35,15 +41,15 @@ func (Customer) TableName() string {
// CustomerLocation represents the pre-existing 'customerlocations' table
type CustomerLocation struct {
Locationid int `json:"locationid" gorm:"primaryKey;column:locationid"`
Customerid int `json:"customerid" gorm:"column:customerid"`
Address string `json:"address" gorm:"column:address"`
City string `json:"city" gorm:"column:city"`
State string `json:"state" gorm:"column:state"`
Postcode string `json:"postcode" gorm:"column:postcode"`
Latitude string `json:"latitude" gorm:"column:latitude"`
Longitude string `json:"longitude" gorm:"column:longitude"`
Status int `json:"status" gorm:"column:status"`
Locationid int `json:"locationid" gorm:"primaryKey;column:locationid"`
Customerid int `json:"customerid" gorm:"column:customerid"`
Address string `json:"address" gorm:"column:address"`
City string `json:"city" gorm:"column:city"`
State string `json:"state" gorm:"column:state"`
Postcode string `json:"postcode" gorm:"column:postcode"`
Latitude string `json:"latitude" gorm:"column:latitude"`
Longitude string `json:"longitude" gorm:"column:longitude"`
Status int `json:"status" gorm:"column:status"`
}
func (CustomerLocation) TableName() string {

View File

@@ -84,26 +84,26 @@ func (AppUser) TableName() string {
}
type MilerProfile struct {
Milerprofileid int `json:"milerprofileid" gorm:"primaryKey;column:milerprofileid"`
Userid int `json:"userid" gorm:"column:userid;unique;not null"`
Applocationid int `json:"applocationid" gorm:"column:applocationid;default:1"`
Displayname string `json:"displayname" gorm:"column:displayname;not null"`
Phone string `json:"phone" gorm:"column:phone;not null"`
Profilephotourl string `json:"profilephotourl" gorm:"column:profilephotourl"`
Vehicleid *int `json:"vehicleid" gorm:"column:vehicleid"`
Hubid *int `json:"hubid" gorm:"column:hubid"`
Defaultvehicletype string `json:"defaultvehicletype" gorm:"column:defaultvehicletype"`
Currentlatitude float64 `json:"currentlatitude" gorm:"column:currentlatitude"`
Currentlongitude float64 `json:"currentlongitude" gorm:"column:currentlongitude"`
Currentpincode string `json:"currentpincode" gorm:"column:currentpincode"`
Availabilitystatus string `json:"availabilitystatus" gorm:"column:availabilitystatus;default:Offline"` // Offline, Available, Assigned, On_Pickup, At_Customer, Picked_Up, On_Delivery, Break, Blocked
Rating float64 `json:"rating" gorm:"column:rating;default:5.00"`
Totalcompletedpickups int `json:"totalcompletedpickups" gorm:"column:totalcompletedpickups;default:0"`
Totalcancelledpickups int `json:"totalcancelledpickups" gorm:"column:totalcancelledpickups;default:0"`
Devicetoken string `json:"device_token,omitempty" gorm:"column:device_token"`
Lastlocationupdatedat *time.Time `json:"lastlocationupdatedat" gorm:"column:lastlocationupdatedat"`
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
Milerprofileid int `json:"milerprofileid" gorm:"primaryKey;column:milerprofileid"`
Userid int `json:"userid" gorm:"column:userid;unique;not null"`
Applocationid int `json:"applocationid" gorm:"column:applocationid;default:1"`
Displayname string `json:"displayname" gorm:"column:displayname;not null"`
Phone string `json:"phone" gorm:"column:phone;not null"`
Profilephotourl string `json:"profilephotourl" gorm:"column:profilephotourl"`
Vehicleid *int `json:"vehicleid" gorm:"column:vehicleid"`
Hubid *int `json:"hubid" gorm:"column:hubid"`
Defaultvehicletype string `json:"defaultvehicletype" gorm:"column:defaultvehicletype"`
Currentlatitude float64 `json:"currentlatitude" gorm:"column:currentlatitude"`
Currentlongitude float64 `json:"currentlongitude" gorm:"column:currentlongitude"`
Currentpincode string `json:"currentpincode" gorm:"column:currentpincode"`
Availabilitystatus string `json:"availabilitystatus" gorm:"column:availabilitystatus;default:Offline"` // Offline, Available, Assigned, On_Pickup, At_Customer, Picked_Up, On_Delivery, Break, Blocked
Rating float64 `json:"rating" gorm:"column:rating;default:5.00"`
Totalcompletedpickups int `json:"totalcompletedpickups" gorm:"column:totalcompletedpickups;default:0"`
Totalcancelledpickups int `json:"totalcancelledpickups" gorm:"column:totalcancelledpickups;default:0"`
Devicetoken string `json:"device_token,omitempty" gorm:"column:device_token"`
Lastlocationupdatedat *time.Time `json:"lastlocationupdatedat" gorm:"column:lastlocationupdatedat"`
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
}
func (MilerProfile) TableName() string {
@@ -158,6 +158,7 @@ func (AppCustomerLocation) TableName() string {
type TenantLocation struct {
Tenantlocationid int `json:"tenantlocationid" gorm:"primaryKey;column:tenantlocationid"`
Tenantid int `json:"tenantid" gorm:"column:tenantid;not null"`
Locationname string `json:"locationname" gorm:"column:locationname"`
Address string `json:"address" gorm:"column:address;not null"`
City string `json:"city" gorm:"column:city;not null"`
State string `json:"state" gorm:"column:state;not null"`