Files
doormile_backend/dto/auth.go
Suriyakumarvijayanayagam dd0fa75e7b feat: miler self-set PIN on first login; no console-set default PIN
Milers now choose their own PIN the first time they log in, instead of the
console assigning a shared default:

- CreateMiler always creates a rider with an empty Password (PIN field removed
  from MilerCreateRequest); any client-supplied PIN is ignored, making
  "riders set their own PIN" a backend invariant, not a console convention.
- LoginMiler returns `pin_set` so the app routes to enter-PIN vs set-PIN.
- New POST /miler/set-pin (SetMilerPin): self-service first PIN, allowed ONLY
  when the account has none yet (409 otherwise, so it can't overwrite/take over
  an active account), then logs the rider in. Self-service and throttle-only is
  safe because of that guard; OTP-gate it once the SMS gateway is live.
- verify-pin and set-pin share issueMilerSession so the two success responses
  can't drift.

Also switches BookingPickupComplete's timestamp to DBNow() (IST) so the
compatibility-flow inwardedat matches the reconciliation windows.

Existing riders keep their PIN and are unaffected; blanking their password to
move them onto self-set is a separate, deliberate DB step.

go build, go vet and go test ./... all pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WRaFH5hMRqmUQvVPQsyjZD
2026-09-16 12:17:00 +05:30

46 lines
1.6 KiB
Go

package dto
// The customer app has no password and no PIN: it authenticates on a 4-digit
// code sent to a phone or an email address, and its request shapes are declared
// inline in controllers/cxAuthController.go alongside the handlers that read
// them. The PIN register/login/verify/reset request types that used to live
// here went with that flow.
type MilerLoginRequest struct {
Phone string `json:"phone" xml:"phone" form:"phone"`
Configid int `json:"configid"`
}
type MilerPinVerifyRequest struct {
Phone string `json:"phone" xml:"phone" form:"phone"`
Pin string `json:"pin" xml:"pin" form:"pin"`
Configid int `json:"configid"`
DeviceToken string `json:"device_token"`
}
type MilerResetPinRequest struct {
Phone string `json:"phone" xml:"phone" form:"phone"`
NewPin string `json:"new_pin" xml:"new_pin" form:"new_pin"`
Configid int `json:"configid"`
}
// MilerSetPinRequest is the self-service first-login PIN creation payload
// (SetMilerPin). DeviceToken is accepted so the rider is fully logged in the
// moment they set their PIN, without a second verify-pin round trip.
type MilerSetPinRequest struct {
Phone string `json:"phone" xml:"phone" form:"phone"`
NewPin string `json:"new_pin" xml:"new_pin" form:"new_pin"`
Configid int `json:"configid"`
DeviceToken string `json:"device_token"`
}
type AdminLoginRequest struct {
Email string `json:"email" xml:"email" form:"email"`
Password string `json:"password" xml:"password" form:"password"`
}
type LoginResponse struct {
Token string `json:"token"`
User interface{} `json:"user"`
}