Security - Express console had no tenant scoping at all: LoginAdmin hardcoded tenantid 0 into every JWT and none of the 85 admin handlers filtered by tenant, so any client given a console login would read every other client's bookings, customers, pricing and reports. Adds DoormileAuth.Tenantid (nil = Doormile staff, unrestricted; set = client, scoped), emits it in the token, and scopes reads, guards writes and pins tenantid on create. - Miler telemetry (/miler/logs, /miler/status, /miler/consignments/logs) took userid from the request body, letting any authenticated rider write another rider's status and GPS trail — data the dispatch layer reasons over. Identity now comes from the token. - POST /miler/reset-pin was unauthenticated and overwrote a PIN given only a phone number, so reset-pin + verify-pin took over any rider account. Now requires admin/manager/executive auth. Correctness - Date ranges compared the container's UTC clock against timestamps the DB writes as IST wall-clock (DSN sets TimeZone=Asia/Kolkata), so "today so far" ended 5h30m in the past and silently dropped everything created after noon IST from every report. Sets TZ in the image and adds utils.DBNow/DBToday, which stay correct regardless of container timezone. - CreateMiler never set Configid, so console-created riders got the column default of 1 while LoginMiler looks up configid 1001 — every such rider was unable to log in, reported as "no miler account found". - Delivery wrote no consignment history row, so a tracking timeline never showed the parcel arriving. Features - Delivery OTP is now real (crypto/rand, issued to the receiver, verified and cleared on delivery) but opt-in per client via Tenant.Requiredeliveryotp, defaulting off — friction worth it for a courier parcel, not a food order. - Express bookings accept pickuplocationid, so the console can name a client site (a DailyGrubs kitchen) instead of retyping its address; validated against the tenant and carried through to the consignment. - TenantLocation.Locationname, miler tenantid/hubid, Nagercoil (629) opened. - PUT /miler/availability accepts both "status" and "availabilitystatus", and /miler/location no longer drops speed/heading — both were contract mismatches against the doc the Flutter dev was given. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
240 lines
13 KiB
Go
240 lines
13 KiB
Go
package models
|
|
|
|
import (
|
|
"time"
|
|
)
|
|
|
|
type PartnerInfo struct {
|
|
Partnerid int `json:"partnerid" gorm:"primaryKey;column:partnerid"`
|
|
Partnername string `json:"partnername" gorm:"column:partnername;not null"`
|
|
Partnertypeid int `json:"partnertypeid" gorm:"column:partnertypeid"`
|
|
Contactno string `json:"contactno" gorm:"column:contactno"`
|
|
Status string `json:"status" gorm:"column:status;default:Active"`
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
|
}
|
|
|
|
func (PartnerInfo) TableName() string {
|
|
return "partnerinfo"
|
|
}
|
|
|
|
type Hub struct {
|
|
Hubid int `json:"hubid" gorm:"primaryKey;column:hubid"`
|
|
Hubname string `json:"hubname" gorm:"column:hubname;not null"`
|
|
Hubtype string `json:"hubtype" gorm:"column:hubtype;not null"` // sorting_center, delivery_hub
|
|
Applocationid int `json:"applocationid" gorm:"column:applocationid"`
|
|
Contactno string `json:"contactno" gorm:"column:contactno"`
|
|
Address string `json:"address" gorm:"column:address"`
|
|
Latitude float64 `json:"latitude" gorm:"column:latitude"`
|
|
Longitude float64 `json:"longitude" gorm:"column:longitude"`
|
|
Pincode string `json:"pincode" gorm:"column:pincode"`
|
|
Capacity int `json:"capacity" gorm:"column:capacity;default:50"`
|
|
Status string `json:"status" gorm:"column:status;default:Active"` // Active, InActive
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
|
Createdby int `json:"createdby" gorm:"column:createdby"`
|
|
Updatedby int `json:"updatedby" gorm:"column:updatedby"`
|
|
Deletedat *time.Time `json:"deletedat,omitempty" gorm:"column:deletedat"`
|
|
}
|
|
|
|
func (Hub) TableName() string {
|
|
return "hubs"
|
|
}
|
|
|
|
type Vehicle struct {
|
|
Vehicleid int `json:"vehicleid" gorm:"primaryKey;column:vehicleid"`
|
|
Vehicleno string `json:"vehicleno" gorm:"primaryKey;column:vehicleno;unique;not null"`
|
|
Vehicletype string `json:"vehicletype" gorm:"column:vehicletype;not null"`
|
|
Maxweight float64 `json:"maxweight" gorm:"column:maxweight;not null"`
|
|
Maxvolume float64 `json:"maxvolume" gorm:"column:maxvolume;not null"`
|
|
Partnerid *int `json:"partnerid" gorm:"column:partnerid"`
|
|
Batterypercentage int `json:"batterypercentage" gorm:"column:batterypercentage"`
|
|
Status string `json:"status" gorm:"column:status;default:Available"` // Available, In_Transit, Maintenance, InActive
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
|
Createdby int `json:"createdby" gorm:"column:createdby"`
|
|
Updatedby int `json:"updatedby" gorm:"column:updatedby"`
|
|
Deletedat *time.Time `json:"deletedat,omitempty" gorm:"column:deletedat"`
|
|
}
|
|
|
|
func (Vehicle) TableName() string {
|
|
return "vehicles"
|
|
}
|
|
|
|
type AppUser struct {
|
|
Userid int `json:"userid" gorm:"primaryKey;column:userid"`
|
|
Authname string `json:"authname" gorm:"column:authname;not null"`
|
|
Email string `json:"email" gorm:"column:email;unique;not null"`
|
|
Contactno string `json:"contactno" gorm:"column:contactno;not null"`
|
|
Password string `json:"-" gorm:"column:password;not null"`
|
|
Roleid int `json:"roleid" gorm:"column:roleid;not null"`
|
|
Hubid *int `json:"hubid" gorm:"column:hubid"`
|
|
Applocationid int `json:"applocationid" gorm:"column:applocationid"`
|
|
Partnerid *int `json:"partnerid" gorm:"column:partnerid"`
|
|
Tenantid int `json:"tenantid" gorm:"column:tenantid"`
|
|
Configid int `json:"configid" gorm:"column:configid;default:1"`
|
|
Onduty int `json:"onduty" gorm:"column:onduty;default:0"`
|
|
Status string `json:"status" gorm:"column:status;default:Active"`
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
|
}
|
|
|
|
func (AppUser) TableName() string {
|
|
return "appusers"
|
|
}
|
|
|
|
type MilerProfile struct {
|
|
Milerprofileid int `json:"milerprofileid" gorm:"primaryKey;column:milerprofileid"`
|
|
Userid int `json:"userid" gorm:"column:userid;unique;not null"`
|
|
Applocationid int `json:"applocationid" gorm:"column:applocationid;default:1"`
|
|
Displayname string `json:"displayname" gorm:"column:displayname;not null"`
|
|
Phone string `json:"phone" gorm:"column:phone;not null"`
|
|
Profilephotourl string `json:"profilephotourl" gorm:"column:profilephotourl"`
|
|
Vehicleid *int `json:"vehicleid" gorm:"column:vehicleid"`
|
|
Hubid *int `json:"hubid" gorm:"column:hubid"`
|
|
Defaultvehicletype string `json:"defaultvehicletype" gorm:"column:defaultvehicletype"`
|
|
Currentlatitude float64 `json:"currentlatitude" gorm:"column:currentlatitude"`
|
|
Currentlongitude float64 `json:"currentlongitude" gorm:"column:currentlongitude"`
|
|
Currentpincode string `json:"currentpincode" gorm:"column:currentpincode"`
|
|
Availabilitystatus string `json:"availabilitystatus" gorm:"column:availabilitystatus;default:Offline"` // Offline, Available, Assigned, On_Pickup, At_Customer, Picked_Up, On_Delivery, Break, Blocked
|
|
Rating float64 `json:"rating" gorm:"column:rating;default:5.00"`
|
|
Totalcompletedpickups int `json:"totalcompletedpickups" gorm:"column:totalcompletedpickups;default:0"`
|
|
Totalcancelledpickups int `json:"totalcancelledpickups" gorm:"column:totalcancelledpickups;default:0"`
|
|
Devicetoken string `json:"device_token,omitempty" gorm:"column:device_token"`
|
|
Lastlocationupdatedat *time.Time `json:"lastlocationupdatedat" gorm:"column:lastlocationupdatedat"`
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
|
}
|
|
|
|
func (MilerProfile) TableName() string {
|
|
return "milerprofiles"
|
|
}
|
|
|
|
type AppCustomer struct {
|
|
Appcustomerid int `json:"appcustomerid" gorm:"primaryKey;column:appcustomerid"`
|
|
Firstname string `json:"firstname" gorm:"column:firstname;not null"`
|
|
Lastname string `json:"lastname" gorm:"column:lastname"`
|
|
Phone string `json:"phone" gorm:"column:phone;unique;not null"`
|
|
Email string `json:"email" gorm:"column:email"`
|
|
Loginpinhash string `json:"-" gorm:"column:loginpinhash"`
|
|
Defaultlatitude float64 `json:"defaultlatitude" gorm:"column:defaultlatitude"`
|
|
Defaultlongitude float64 `json:"defaultlongitude" gorm:"column:defaultlongitude"`
|
|
Defaultpincode string `json:"defaultpincode" gorm:"column:defaultpincode"`
|
|
Devicetoken string `json:"device_token,omitempty" gorm:"column:device_token"`
|
|
Status string `json:"status" gorm:"column:status;default:Active"` // Active, Blocked, Deleted
|
|
Configid int `json:"configid" gorm:"column:configid;default:1"`
|
|
Lastloginat *time.Time `json:"lastloginat" gorm:"column:lastloginat"`
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
|
}
|
|
|
|
func (AppCustomer) TableName() string {
|
|
return "appcustomers"
|
|
}
|
|
|
|
type AppCustomerLocation struct {
|
|
Appcustomerlocationid int `json:"appcustomerlocationid" gorm:"primaryKey;column:appcustomerlocationid"`
|
|
Appcustomerid int `json:"appcustomerid" gorm:"column:appcustomerid"`
|
|
Label string `json:"label" gorm:"column:label;default:Home"`
|
|
Receivername string `json:"receivername" gorm:"column:receivername"`
|
|
Receiverphone string `json:"receiverphone" gorm:"column:receiverphone"`
|
|
Address string `json:"address" gorm:"column:address;not null"`
|
|
Landmark string `json:"landmark" gorm:"column:landmark"`
|
|
City string `json:"city" gorm:"column:city"`
|
|
State string `json:"state" gorm:"column:state"`
|
|
Pincode string `json:"pincode" gorm:"column:pincode;not null"`
|
|
Latitude float64 `json:"latitude" gorm:"column:latitude;not null"`
|
|
Longitude float64 `json:"longitude" gorm:"column:longitude;not null"`
|
|
Isdefault bool `json:"isdefault" gorm:"column:isdefault;default:false"`
|
|
Status string `json:"status" gorm:"column:status;default:Active"`
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
|
}
|
|
|
|
func (AppCustomerLocation) TableName() string {
|
|
return "appcustomerlocations"
|
|
}
|
|
|
|
type TenantLocation struct {
|
|
Tenantlocationid int `json:"tenantlocationid" gorm:"primaryKey;column:tenantlocationid"`
|
|
Tenantid int `json:"tenantid" gorm:"column:tenantid;not null"`
|
|
Locationname string `json:"locationname" gorm:"column:locationname"`
|
|
Address string `json:"address" gorm:"column:address;not null"`
|
|
City string `json:"city" gorm:"column:city;not null"`
|
|
State string `json:"state" gorm:"column:state;not null"`
|
|
Pincode string `json:"pincode" gorm:"column:pincode;not null"`
|
|
Latitude float64 `json:"latitude" gorm:"column:latitude;not null"`
|
|
Longitude float64 `json:"longitude" gorm:"column:longitude;not null"`
|
|
Isprimary bool `json:"isprimary" gorm:"column:isprimary;default:false"`
|
|
Status string `json:"status" gorm:"column:status;default:Active"`
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
|
}
|
|
|
|
func (TenantLocation) TableName() string {
|
|
return "tenantlocations"
|
|
}
|
|
|
|
type HubStaffAccount struct {
|
|
Hubstaffaccountid int `json:"hubstaffaccountid" gorm:"primaryKey;column:hubstaffaccountid"`
|
|
Hubid int `json:"hubid" gorm:"column:hubid;index;not null"`
|
|
Email string `json:"email" gorm:"column:email;unique;not null"`
|
|
Passwordhash string `json:"-" gorm:"column:passwordhash;not null"`
|
|
Displayname string `json:"displayname" gorm:"column:displayname"`
|
|
Roleid int `json:"roleid" gorm:"column:roleid;default:6"`
|
|
Isactive bool `json:"isactive" gorm:"column:isactive;default:true"`
|
|
Tenantid *int `json:"tenantid" gorm:"column:tenantid;index"` // null = Doormile staff (can manage any hub in their city); set = partner staff scoped to their own hub
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
|
}
|
|
|
|
func (HubStaffAccount) TableName() string {
|
|
return "hubstaffaccounts"
|
|
}
|
|
|
|
type MilerDutyLog struct {
|
|
Dutylogid int `json:"dutylogid" gorm:"primaryKey;column:dutylogid"`
|
|
Userid int `json:"userid" gorm:"column:userid;index;not null"`
|
|
Loginat time.Time `json:"loginat" gorm:"column:loginat;not null"`
|
|
Logoutat *time.Time `json:"logoutat" gorm:"column:logoutat"`
|
|
Onduty bool `json:"onduty" gorm:"column:onduty;default:true"`
|
|
Startlat float64 `json:"startlat" gorm:"column:startlat"`
|
|
Startlon float64 `json:"startlon" gorm:"column:startlon"`
|
|
Lastlat float64 `json:"lastlat" gorm:"column:lastlat"`
|
|
Lastlon float64 `json:"lastlon" gorm:"column:lastlon"`
|
|
Totalkms float64 `json:"totalkms" gorm:"column:totalkms;default:0"`
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
}
|
|
|
|
func (MilerDutyLog) TableName() string {
|
|
return "milerdutylogs"
|
|
}
|
|
|
|
type MilerBreakLog struct {
|
|
Breaklogid int `json:"breaklogid" gorm:"primaryKey;column:breaklogid"`
|
|
Userid int `json:"userid" gorm:"column:userid;index;not null"`
|
|
Dutylogid int `json:"dutylogid" gorm:"column:dutylogid;not null"`
|
|
Breaktype string `json:"breaktype" gorm:"column:breaktype;default:Personal"`
|
|
Startat time.Time `json:"startat" gorm:"column:startat;not null"`
|
|
Endat *time.Time `json:"endat" gorm:"column:endat"`
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
}
|
|
|
|
func (MilerBreakLog) TableName() string {
|
|
return "milerbreaklogs"
|
|
}
|
|
|
|
type MilerSupportTicket struct {
|
|
Ticketid int `json:"ticketid" gorm:"primaryKey;column:ticketid"`
|
|
Userid int `json:"userid" gorm:"column:userid;index;not null"`
|
|
Subject string `json:"subject" gorm:"column:subject;size:200;not null"`
|
|
Description string `json:"description" gorm:"column:description;type:text;not null"`
|
|
Status string `json:"status" gorm:"column:status;default:Open"`
|
|
Createdat time.Time `json:"createdat" gorm:"column:createdat;default:CURRENT_TIMESTAMP"`
|
|
Updatedat time.Time `json:"updatedat" gorm:"column:updatedat;default:CURRENT_TIMESTAMP"`
|
|
}
|
|
|
|
func (MilerSupportTicket) TableName() string {
|
|
return "milersupporttickets"
|
|
}
|