fix: console tenant scoping, miler identity spoofing, delivery proof, timezone
Security - Express console had no tenant scoping at all: LoginAdmin hardcoded tenantid 0 into every JWT and none of the 85 admin handlers filtered by tenant, so any client given a console login would read every other client's bookings, customers, pricing and reports. Adds DoormileAuth.Tenantid (nil = Doormile staff, unrestricted; set = client, scoped), emits it in the token, and scopes reads, guards writes and pins tenantid on create. - Miler telemetry (/miler/logs, /miler/status, /miler/consignments/logs) took userid from the request body, letting any authenticated rider write another rider's status and GPS trail — data the dispatch layer reasons over. Identity now comes from the token. - POST /miler/reset-pin was unauthenticated and overwrote a PIN given only a phone number, so reset-pin + verify-pin took over any rider account. Now requires admin/manager/executive auth. Correctness - Date ranges compared the container's UTC clock against timestamps the DB writes as IST wall-clock (DSN sets TimeZone=Asia/Kolkata), so "today so far" ended 5h30m in the past and silently dropped everything created after noon IST from every report. Sets TZ in the image and adds utils.DBNow/DBToday, which stay correct regardless of container timezone. - CreateMiler never set Configid, so console-created riders got the column default of 1 while LoginMiler looks up configid 1001 — every such rider was unable to log in, reported as "no miler account found". - Delivery wrote no consignment history row, so a tracking timeline never showed the parcel arriving. Features - Delivery OTP is now real (crypto/rand, issued to the receiver, verified and cleared on delivery) but opt-in per client via Tenant.Requiredeliveryotp, defaulting off — friction worth it for a courier parcel, not a food order. - Express bookings accept pickuplocationid, so the console can name a client site (a DailyGrubs kitchen) instead of retyping its address; validated against the tenant and carried through to the consignment. - TenantLocation.Locationname, miler tenantid/hubid, Nagercoil (629) opened. - PUT /miler/availability accepts both "status" and "availabilitystatus", and /miler/location no longer drops speed/heading — both were contract mismatches against the doc the Flutter dev was given. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -84,26 +84,26 @@ func (AppUser) TableName() string {
|
||||
}
|
||||
|
||||
type MilerProfile struct {
|
||||
Milerprofileid int `json:"milerprofileid" gorm:"primaryKey;column:milerprofileid"`
|
||||
Userid int `json:"userid" gorm:"column:userid;unique;not null"`
|
||||
Applocationid int `json:"applocationid" gorm:"column:applocationid;default:1"`
|
||||
Displayname string `json:"displayname" gorm:"column:displayname;not null"`
|
||||
Phone string `json:"phone" gorm:"column:phone;not null"`
|
||||
Profilephotourl string `json:"profilephotourl" gorm:"column:profilephotourl"`
|
||||
Vehicleid *int `json:"vehicleid" gorm:"column:vehicleid"`
|
||||
Hubid *int `json:"hubid" gorm:"column:hubid"`
|
||||
Defaultvehicletype string `json:"defaultvehicletype" gorm:"column:defaultvehicletype"`
|
||||
Currentlatitude float64 `json:"currentlatitude" gorm:"column:currentlatitude"`
|
||||
Currentlongitude float64 `json:"currentlongitude" gorm:"column:currentlongitude"`
|
||||
Currentpincode string `json:"currentpincode" gorm:"column:currentpincode"`
|
||||
Availabilitystatus string `json:"availabilitystatus" gorm:"column:availabilitystatus;default:Offline"` // Offline, Available, Assigned, On_Pickup, At_Customer, Picked_Up, On_Delivery, Break, Blocked
|
||||
Rating float64 `json:"rating" gorm:"column:rating;default:5.00"`
|
||||
Totalcompletedpickups int `json:"totalcompletedpickups" gorm:"column:totalcompletedpickups;default:0"`
|
||||
Totalcancelledpickups int `json:"totalcancelledpickups" gorm:"column:totalcancelledpickups;default:0"`
|
||||
Devicetoken string `json:"device_token,omitempty" gorm:"column:device_token"`
|
||||
Lastlocationupdatedat *time.Time `json:"lastlocationupdatedat" gorm:"column:lastlocationupdatedat"`
|
||||
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
||||
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
||||
Milerprofileid int `json:"milerprofileid" gorm:"primaryKey;column:milerprofileid"`
|
||||
Userid int `json:"userid" gorm:"column:userid;unique;not null"`
|
||||
Applocationid int `json:"applocationid" gorm:"column:applocationid;default:1"`
|
||||
Displayname string `json:"displayname" gorm:"column:displayname;not null"`
|
||||
Phone string `json:"phone" gorm:"column:phone;not null"`
|
||||
Profilephotourl string `json:"profilephotourl" gorm:"column:profilephotourl"`
|
||||
Vehicleid *int `json:"vehicleid" gorm:"column:vehicleid"`
|
||||
Hubid *int `json:"hubid" gorm:"column:hubid"`
|
||||
Defaultvehicletype string `json:"defaultvehicletype" gorm:"column:defaultvehicletype"`
|
||||
Currentlatitude float64 `json:"currentlatitude" gorm:"column:currentlatitude"`
|
||||
Currentlongitude float64 `json:"currentlongitude" gorm:"column:currentlongitude"`
|
||||
Currentpincode string `json:"currentpincode" gorm:"column:currentpincode"`
|
||||
Availabilitystatus string `json:"availabilitystatus" gorm:"column:availabilitystatus;default:Offline"` // Offline, Available, Assigned, On_Pickup, At_Customer, Picked_Up, On_Delivery, Break, Blocked
|
||||
Rating float64 `json:"rating" gorm:"column:rating;default:5.00"`
|
||||
Totalcompletedpickups int `json:"totalcompletedpickups" gorm:"column:totalcompletedpickups;default:0"`
|
||||
Totalcancelledpickups int `json:"totalcancelledpickups" gorm:"column:totalcancelledpickups;default:0"`
|
||||
Devicetoken string `json:"device_token,omitempty" gorm:"column:device_token"`
|
||||
Lastlocationupdatedat *time.Time `json:"lastlocationupdatedat" gorm:"column:lastlocationupdatedat"`
|
||||
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
||||
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
||||
}
|
||||
|
||||
func (MilerProfile) TableName() string {
|
||||
@@ -158,6 +158,7 @@ func (AppCustomerLocation) TableName() string {
|
||||
type TenantLocation struct {
|
||||
Tenantlocationid int `json:"tenantlocationid" gorm:"primaryKey;column:tenantlocationid"`
|
||||
Tenantid int `json:"tenantid" gorm:"column:tenantid;not null"`
|
||||
Locationname string `json:"locationname" gorm:"column:locationname"`
|
||||
Address string `json:"address" gorm:"column:address;not null"`
|
||||
City string `json:"city" gorm:"column:city;not null"`
|
||||
State string `json:"state" gorm:"column:state;not null"`
|
||||
|
||||
Reference in New Issue
Block a user