Security - Express console had no tenant scoping at all: LoginAdmin hardcoded tenantid 0 into every JWT and none of the 85 admin handlers filtered by tenant, so any client given a console login would read every other client's bookings, customers, pricing and reports. Adds DoormileAuth.Tenantid (nil = Doormile staff, unrestricted; set = client, scoped), emits it in the token, and scopes reads, guards writes and pins tenantid on create. - Miler telemetry (/miler/logs, /miler/status, /miler/consignments/logs) took userid from the request body, letting any authenticated rider write another rider's status and GPS trail — data the dispatch layer reasons over. Identity now comes from the token. - POST /miler/reset-pin was unauthenticated and overwrote a PIN given only a phone number, so reset-pin + verify-pin took over any rider account. Now requires admin/manager/executive auth. Correctness - Date ranges compared the container's UTC clock against timestamps the DB writes as IST wall-clock (DSN sets TimeZone=Asia/Kolkata), so "today so far" ended 5h30m in the past and silently dropped everything created after noon IST from every report. Sets TZ in the image and adds utils.DBNow/DBToday, which stay correct regardless of container timezone. - CreateMiler never set Configid, so console-created riders got the column default of 1 while LoginMiler looks up configid 1001 — every such rider was unable to log in, reported as "no miler account found". - Delivery wrote no consignment history row, so a tracking timeline never showed the parcel arriving. Features - Delivery OTP is now real (crypto/rand, issued to the receiver, verified and cleared on delivery) but opt-in per client via Tenant.Requiredeliveryotp, defaulting off — friction worth it for a courier parcel, not a food order. - Express bookings accept pickuplocationid, so the console can name a client site (a DailyGrubs kitchen) instead of retyping its address; validated against the tenant and carried through to the consignment. - TenantLocation.Locationname, miler tenantid/hubid, Nagercoil (629) opened. - PUT /miler/availability accepts both "status" and "availabilitystatus", and /miler/location no longer drops speed/heading — both were contract mismatches against the doc the Flutter dev was given. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
42 lines
1.1 KiB
Go
42 lines
1.1 KiB
Go
package middlewares
|
|
|
|
import (
|
|
"encoding/json"
|
|
"strings"
|
|
|
|
"github.com/gofiber/fiber/v2"
|
|
)
|
|
|
|
// operatingCityPrefixes maps supported 3-digit pincode prefixes to city names.
|
|
var operatingCityPrefixes = map[string]string{
|
|
"641": "Coimbatore",
|
|
"600": "Chennai",
|
|
"560": "Bengaluru",
|
|
"500": "Hyderabad",
|
|
"629": "Nagercoil",
|
|
}
|
|
|
|
// CityGateMiddleware rejects bookings from pincodes outside Doormile's operating cities.
|
|
// It reads pickuppincode from the JSON body without consuming it, so the downstream
|
|
// controller can still call c.BodyParser() as usual.
|
|
func CityGateMiddleware(c *fiber.Ctx) error {
|
|
var body struct {
|
|
Pickuppincode string `json:"pickuppincode"`
|
|
}
|
|
if err := json.Unmarshal(c.Body(), &body); err != nil || body.Pickuppincode == "" {
|
|
return c.Next()
|
|
}
|
|
|
|
pincode := strings.TrimSpace(body.Pickuppincode)
|
|
if len(pincode) >= 3 {
|
|
if _, ok := operatingCityPrefixes[pincode[:3]]; ok {
|
|
return c.Next()
|
|
}
|
|
}
|
|
|
|
return c.Status(fiber.StatusBadRequest).JSON(fiber.Map{
|
|
"error": "We are not yet operating in your city. Stay tuned!",
|
|
"code": "CITY_NOT_SUPPORTED",
|
|
})
|
|
}
|