Milers now choose their own PIN the first time they log in, instead of the
console assigning a shared default:
- CreateMiler always creates a rider with an empty Password (PIN field removed
from MilerCreateRequest); any client-supplied PIN is ignored, making
"riders set their own PIN" a backend invariant, not a console convention.
- LoginMiler returns `pin_set` so the app routes to enter-PIN vs set-PIN.
- New POST /miler/set-pin (SetMilerPin): self-service first PIN, allowed ONLY
when the account has none yet (409 otherwise, so it can't overwrite/take over
an active account), then logs the rider in. Self-service and throttle-only is
safe because of that guard; OTP-gate it once the SMS gateway is live.
- verify-pin and set-pin share issueMilerSession so the two success responses
can't drift.
Also switches BookingPickupComplete's timestamp to DBNow() (IST) so the
compatibility-flow inwardedat matches the reconciliation windows.
Existing riders keep their PIN and are unaffected; blanking their password to
move them onto self-set is a separate, deliberate DB step.
go build, go vet and go test ./... all pass.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WRaFH5hMRqmUQvVPQsyjZD