Files
doormile_backend/dto/admin.go
Suriyakumarvijayanayagam dd0fa75e7b feat: miler self-set PIN on first login; no console-set default PIN
Milers now choose their own PIN the first time they log in, instead of the
console assigning a shared default:

- CreateMiler always creates a rider with an empty Password (PIN field removed
  from MilerCreateRequest); any client-supplied PIN is ignored, making
  "riders set their own PIN" a backend invariant, not a console convention.
- LoginMiler returns `pin_set` so the app routes to enter-PIN vs set-PIN.
- New POST /miler/set-pin (SetMilerPin): self-service first PIN, allowed ONLY
  when the account has none yet (409 otherwise, so it can't overwrite/take over
  an active account), then logs the rider in. Self-service and throttle-only is
  safe because of that guard; OTP-gate it once the SMS gateway is live.
- verify-pin and set-pin share issueMilerSession so the two success responses
  can't drift.

Also switches BookingPickupComplete's timestamp to DBNow() (IST) so the
compatibility-flow inwardedat matches the reconciliation windows.

Existing riders keep their PIN and are unaffected; blanking their password to
move them onto self-set is a separate, deliberate DB step.

go build, go vet and go test ./... all pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WRaFH5hMRqmUQvVPQsyjZD
2026-09-16 12:17:00 +05:30

130 lines
4.9 KiB
Go

package dto
import "time"
type TenantCreateRequest struct {
Tenantname string `json:"tenantname"`
Primaryemail string `json:"primaryemail"`
Primarycontact string `json:"primarycontact"`
Status string `json:"status"`
// Requiredeliveryotp is a pointer so an update that omits it leaves the
// existing setting alone rather than silently switching OTPs off.
Requiredeliveryotp *bool `json:"requiredeliveryotp"`
}
type TenantLocationCreateRequest struct {
// Locationname is the client's own label for the site — "DailyGrubs
// Peelamedu Kitchen" — since an address alone doesn't identify a branch.
Locationname string `json:"locationname"`
Address string `json:"address"`
City string `json:"city"`
State string `json:"state"`
Pincode string `json:"pincode"`
Latitude float64 `json:"latitude"`
Longitude float64 `json:"longitude"`
Isprimary bool `json:"isprimary"`
Status string `json:"status"`
}
type TenantCustomerCreateRequest struct {
Firstname string `json:"firstname"`
Lastname string `json:"lastname"`
Phone string `json:"phone"`
Email string `json:"email"`
}
type PartnerCreateRequest struct {
Partnername string `json:"partnername"`
Partnertypeid int `json:"partnertypeid"`
Contactno string `json:"contactno"`
Status string `json:"status"`
}
type HubCreateRequest struct {
Hubname string `json:"hubname"`
Hubtype string `json:"hubtype"` // sorting_center, delivery_hub
Applocationid int `json:"applocationid"`
Contactno string `json:"contactno"`
Address string `json:"address"`
Latitude float64 `json:"latitude"`
Longitude float64 `json:"longitude"`
Pincode string `json:"pincode"`
Status string `json:"status"`
}
type VehicleCreateRequest struct {
Vehicleno string `json:"vehicleno"`
Vehicletype string `json:"vehicletype"`
Maxweight float64 `json:"maxweight"`
Maxvolume float64 `json:"maxvolume"`
Partnerid *int `json:"partnerid"`
Batterypercentage int `json:"batterypercentage"`
Status string `json:"status"`
}
type MilerCreateRequest struct {
Authname string `json:"authname"`
Email string `json:"email"`
Contactno string `json:"contactno"`
// No PIN field: riders never receive a console-set PIN. A rider is created
// with an empty Password and sets their own PIN on first login via
// /miler/set-pin (LoginMiler reports pin_set:false). Any "password" the
// console sends is ignored. This makes "riders choose their own PIN" a
// backend invariant instead of trusting the console not to send a default.
Displayname string `json:"displayname"`
// Tenantid attaches a rider to the client they deliver for — riders migrated
// from jupiter belong to a specific client (DailyGrubs, Bawa Medicals)
// rather than to Doormile's general pool. Zero leaves them unattached.
Tenantid int `json:"tenantid"`
Defaultvehicletype string `json:"defaultvehicletype"`
Applocationid int `json:"applocationid"`
// Configid partitions logins; defaults to 1001, which is what the miler app
// authenticates against. Only set this if you know why you're changing it.
Configid int `json:"configid"`
// Hubid is optional: a rider with no hub is still assignable from the
// express console, but is invisible to the hub console's miler list.
Hubid *int `json:"hubid"`
}
type PricingCreateRequest struct {
Tenantid int `json:"tenantid"`
Applocationid int `json:"applocationid"`
Vehicletype string `json:"vehicletype"`
Baseprice float64 `json:"baseprice"`
Baseweight float64 `json:"baseweight"`
Priceperkg float64 `json:"priceperkg"`
Basedistance float64 `json:"basedistance"`
Priceperkm float64 `json:"priceperkm"`
Handlingcharges float64 `json:"handlingcharges"`
Effectivefrom time.Time `json:"effectivefrom"`
Effectiveto time.Time `json:"effectiveto"`
Currency string `json:"currency"`
Priority int `json:"priority"`
Status string `json:"status"`
}
type TripsheetCreateRequest struct {
Sourcehubid int `json:"sourcehubid"`
Destinationhubid int `json:"destinationhubid"`
Vehicleid *int `json:"vehicleid"`
Driveruserid *int `json:"driveruserid"`
}
type TripsheetItemAddRequest struct {
Consignmentid int `json:"consignmentid"`
}
type ExceptionCreateRequest struct {
Consignmentid int `json:"consignmentid"`
Tripsheetid *int `json:"tripsheetid"`
Hubid *int `json:"hubid"`
Exceptiontype string `json:"exceptiontype"` // Lost, Damaged, Misrouted, Receiver_Refused, Missing_Contents, Undeliverable
Severity string `json:"severity"` // Low, Medium, High, Critical
Description string `json:"description"`
}
type ExceptionResolveRequest struct {
Resolution string `json:"resolution"`
Status string `json:"status"` // Resolved, Closed
}