f1dbf7edc9e4d3c4f03bfe909002f1c850bde10c
No SMS/OTP gateway is live yet, so customers sign in with a self-set PIN like
milers do. The OTP endpoints stay in place — the app switches back once a
gateway is plugged in.
- POST /customer/auth/login {phone} -> {registered, pin_set, name}: routes the
app to register / set-PIN / enter-PIN.
- POST /customer/auth/set-pin {phone, new_pin, name?}: first-time PIN. Creates
the account (name required) or sets the first PIN on an account with none;
refuses to overwrite an existing PIN (409); logs in on success.
- POST /customer/auth/verify-pin {phone, pin}: returning login; same generic
message for unknown phone and wrong PIN so it can't enumerate accounts.
All three reuse issueCxSession (access + refresh + customer) and the /customer
Cx* response envelope. Build + vet clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WRaFH5hMRqmUQvVPQsyjZD
Description
No description provided
Languages
Go
97.9%
PLpgSQL
1.6%
Python
0.4%