fix: console tenant scoping, miler identity spoofing, delivery proof, timezone

Security
- Express console had no tenant scoping at all: LoginAdmin hardcoded tenantid 0
  into every JWT and none of the 85 admin handlers filtered by tenant, so any
  client given a console login would read every other client's bookings,
  customers, pricing and reports. Adds DoormileAuth.Tenantid (nil = Doormile
  staff, unrestricted; set = client, scoped), emits it in the token, and scopes
  reads, guards writes and pins tenantid on create.
- Miler telemetry (/miler/logs, /miler/status, /miler/consignments/logs) took
  userid from the request body, letting any authenticated rider write another
  rider's status and GPS trail — data the dispatch layer reasons over. Identity
  now comes from the token.
- POST /miler/reset-pin was unauthenticated and overwrote a PIN given only a
  phone number, so reset-pin + verify-pin took over any rider account. Now
  requires admin/manager/executive auth.

Correctness
- Date ranges compared the container's UTC clock against timestamps the DB
  writes as IST wall-clock (DSN sets TimeZone=Asia/Kolkata), so "today so far"
  ended 5h30m in the past and silently dropped everything created after noon
  IST from every report. Sets TZ in the image and adds utils.DBNow/DBToday,
  which stay correct regardless of container timezone.
- CreateMiler never set Configid, so console-created riders got the column
  default of 1 while LoginMiler looks up configid 1001 — every such rider was
  unable to log in, reported as "no miler account found".
- Delivery wrote no consignment history row, so a tracking timeline never
  showed the parcel arriving.

Features
- Delivery OTP is now real (crypto/rand, issued to the receiver, verified and
  cleared on delivery) but opt-in per client via Tenant.Requiredeliveryotp,
  defaulting off — friction worth it for a courier parcel, not a food order.
- Express bookings accept pickuplocationid, so the console can name a client
  site (a DailyGrubs kitchen) instead of retyping its address; validated
  against the tenant and carried through to the consignment.
- TenantLocation.Locationname, miler tenantid/hubid, Nagercoil (629) opened.
- PUT /miler/availability accepts both "status" and "availabilitystatus", and
  /miler/location no longer drops speed/heading — both were contract
  mismatches against the doc the Flutter dev was given.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Suriya
2026-08-05 18:16:56 +05:30
parent e1fd4dc5d0
commit fd7cf3e35e
14 changed files with 614 additions and 184 deletions

View File

@@ -18,11 +18,11 @@ type DoormileClient struct {
Phone string `gorm:"uniqueIndex;size:20;not null" json:"phone"`
// Location
Address string `gorm:"type:text" json:"address"`
City string `gorm:"size:100" json:"city"`
State string `gorm:"size:100" json:"state"`
Neighbourhood string `gorm:"size:100" json:"neighbourhood"`
Pincode string `gorm:"size:20" json:"pincode"`
Address string `gorm:"type:text" json:"address"`
City string `gorm:"size:100" json:"city"`
State string `gorm:"size:100" json:"state"`
Neighbourhood string `gorm:"size:100" json:"neighbourhood"`
Pincode string `gorm:"size:20" json:"pincode"`
// GPS survey data
SurveyLat float64 `gorm:"column:surveylat" json:"survey_lat"`
@@ -41,10 +41,10 @@ type DoormileClient struct {
// Full-consent-only fields (zeroed for basicOnly)
ParcelVolume float64 `json:"parcel_volume"`
ActiveContracts int `json:"active_contracts"`
LogisticsProvider string `gorm:"size:100" json:"logistics_provider"`
ProviderEfficiency string `gorm:"size:100" json:"provider_efficiency"`
Notes string `gorm:"type:text" json:"notes"`
ActiveContracts int `json:"active_contracts"`
LogisticsProvider string `gorm:"size:100" json:"logistics_provider"`
ProviderEfficiency string `gorm:"size:100" json:"provider_efficiency"`
Notes string `gorm:"type:text" json:"notes"`
// Consent & registration tracking
DataConsent string `gorm:"size:20;default:'full'" json:"data_consent"`
@@ -63,8 +63,13 @@ type DoormileAuth struct {
Email string `gorm:"uniqueIndex;size:255;not null" json:"email"`
PasswordHash string `gorm:"not null" json:"-"`
Role string `gorm:"default:'user'" json:"role"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
// Tenantid scopes an express-console login to one client, using the same
// convention as HubStaffAccount.Tenantid: null = Doormile's own staff, who
// see every tenant's data; set = a client's own login, restricted to their
// tenant. Without this every console login sees all tenants.
Tenantid *int `gorm:"column:tenantid;index" json:"tenantid"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
}
func (DoormileAuth) TableName() string {