Hardening pass over the API surface. No route's auth requirements change.
Resilience:
- Add recover middleware. There was none, so an unhandled panic in any
handler propagated out of the process instead of becoming a 500.
- Add a centralized ErrorHandler so errors and recovered panics return the
same {success,message} envelope as the utils helpers, not Fiber's default
plain-text body. 5xx responses are logged with method and path.
Rate limiting:
- Global 300/min per IP as an abuse backstop, exempting health/readiness
probes and websocket upgrades.
- 10/min shared across every credential endpoint (customer/miler/admin/hub
login, verify-pin, reset-pin, email OTP). PINs are 4 digits, so the whole
keyspace was previously walkable in seconds. One shared limiter instance
means rotating between endpoints doesn't reset the budget.
- Add TRUSTED_PROXIES config. Limits key on c.IP(), which behind a TLS
terminator is the proxy, collapsing every client into one bucket. When set,
X-Forwarded-For is honoured only from those proxies so the header can't be
spoofed to dodge the limit. Logs a warning when unset.
Transactions:
- Check the error on all 51 previously-unchecked tx.Save/Create/Delete/
Model(...).Update/Commit calls across 6 controllers. A failed write inside
a transaction was silently ignored and the request still reported success;
an unchecked Commit could fail with the caller told everything worked.
Each site now rolls back and returns a specific message.
Pagination:
- Add utils.ParsePage/Paginated, reusing the pageno/pagesize convention
GetAdminBookings already established. Default 500, hard cap 1000.
- Apply to the previously unbounded consignments, tripsheets, exceptions,
app-users and clients endpoints. Defaults are high so existing consoles
that don't paginate keep working; the cap only stops a growing table from
being loaded wholesale. total is now a real COUNT, not len(data).
- GetClients also loaded the entire auth table to join in memory; it now
fetches only the current page's rows.
Tests (first in the repo):
- Extract the hyperlocal pincode rule out of BookingPickupComplete into
isHyperlocal so it is testable, covering the short/empty pincode fallback.
- Cover calculateVolumetricWeight and the ParsePage clamping rules.
Repo hygiene:
- Tag scratch/*.go with //go:build ignore. Each declared its own main(), so
`go build ./...` failed on redeclaration; it now passes repo-wide.
- Untrack scratch/node_modules (216 files) and ignore node_modules, test
artifacts, and the `doormile` binary `go build .` emits.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
42 lines
1.2 KiB
Plaintext
42 lines
1.2 KiB
Plaintext
# App Config
|
|
APP_PORT=8081
|
|
ENV=development
|
|
JWT_SECRET_KEY=DoormileSuperSecretJWTKey2026!
|
|
INTERNAL_API_KEY=doormile-internal-2024
|
|
|
|
# Reverse proxy — comma-separated IPs/CIDRs allowed to set X-Forwarded-For.
|
|
# Rate limiting keys on the client IP, so if this service sits behind nginx or
|
|
# any TLS terminator this MUST list that proxy; otherwise every request looks
|
|
# like it came from the proxy and all clients share one rate-limit bucket.
|
|
# Leave empty only when the app is exposed directly.
|
|
# TRUSTED_PROXIES=127.0.0.1,10.0.0.0/8
|
|
|
|
# PostgreSQL Database Configuration
|
|
DB_HOST=31.97.228.132
|
|
DB_PORT=5433
|
|
DB_NAME=logistics
|
|
DB_USER=admin
|
|
DB_PASSWORD=Package@321#
|
|
|
|
# Redis Configuration
|
|
REDIS_HOST=31.97.228.132
|
|
REDIS_PORT=6379
|
|
REDIS_USER=admin
|
|
REDIS_PASSWORD=Package@321#
|
|
|
|
# SMTP Configuration (email OTP verification)
|
|
SMTP_HOST=smtp.gmail.com
|
|
SMTP_PORT=465
|
|
SMTP_USER=your-email@gmail.com
|
|
SMTP_PASSWORD=your-16-char-app-password
|
|
SMTP_FROM=your-email@gmail.com
|
|
|
|
|
|
$env:PATH += ";C:\Program Files\Docker\Docker\resources\bin"
|
|
>>
|
|
>> docker build -t doormile/doormile-backend:latest .
|
|
>> docker push doormile/doormile-backend:latest
|
|
>>
|
|
|
|
|