Security - Express console had no tenant scoping at all: LoginAdmin hardcoded tenantid 0 into every JWT and none of the 85 admin handlers filtered by tenant, so any client given a console login would read every other client's bookings, customers, pricing and reports. Adds DoormileAuth.Tenantid (nil = Doormile staff, unrestricted; set = client, scoped), emits it in the token, and scopes reads, guards writes and pins tenantid on create. - Miler telemetry (/miler/logs, /miler/status, /miler/consignments/logs) took userid from the request body, letting any authenticated rider write another rider's status and GPS trail — data the dispatch layer reasons over. Identity now comes from the token. - POST /miler/reset-pin was unauthenticated and overwrote a PIN given only a phone number, so reset-pin + verify-pin took over any rider account. Now requires admin/manager/executive auth. Correctness - Date ranges compared the container's UTC clock against timestamps the DB writes as IST wall-clock (DSN sets TimeZone=Asia/Kolkata), so "today so far" ended 5h30m in the past and silently dropped everything created after noon IST from every report. Sets TZ in the image and adds utils.DBNow/DBToday, which stay correct regardless of container timezone. - CreateMiler never set Configid, so console-created riders got the column default of 1 while LoginMiler looks up configid 1001 — every such rider was unable to log in, reported as "no miler account found". - Delivery wrote no consignment history row, so a tracking timeline never showed the parcel arriving. Features - Delivery OTP is now real (crypto/rand, issued to the receiver, verified and cleared on delivery) but opt-in per client via Tenant.Requiredeliveryotp, defaulting off — friction worth it for a courier parcel, not a food order. - Express bookings accept pickuplocationid, so the console can name a client site (a DailyGrubs kitchen) instead of retyping its address; validated against the tenant and carried through to the consignment. - TenantLocation.Locationname, miler tenantid/hubid, Nagercoil (629) opened. - PUT /miler/availability accepts both "status" and "availabilitystatus", and /miler/location no longer drops speed/heading — both were contract mismatches against the doc the Flutter dev was given. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
126 lines
4.6 KiB
Go
126 lines
4.6 KiB
Go
package dto
|
|
|
|
import "time"
|
|
|
|
type TenantCreateRequest struct {
|
|
Tenantname string `json:"tenantname"`
|
|
Primaryemail string `json:"primaryemail"`
|
|
Primarycontact string `json:"primarycontact"`
|
|
Status string `json:"status"`
|
|
// Requiredeliveryotp is a pointer so an update that omits it leaves the
|
|
// existing setting alone rather than silently switching OTPs off.
|
|
Requiredeliveryotp *bool `json:"requiredeliveryotp"`
|
|
}
|
|
|
|
type TenantLocationCreateRequest struct {
|
|
// Locationname is the client's own label for the site — "DailyGrubs
|
|
// Peelamedu Kitchen" — since an address alone doesn't identify a branch.
|
|
Locationname string `json:"locationname"`
|
|
Address string `json:"address"`
|
|
City string `json:"city"`
|
|
State string `json:"state"`
|
|
Pincode string `json:"pincode"`
|
|
Latitude float64 `json:"latitude"`
|
|
Longitude float64 `json:"longitude"`
|
|
Isprimary bool `json:"isprimary"`
|
|
Status string `json:"status"`
|
|
}
|
|
|
|
type TenantCustomerCreateRequest struct {
|
|
Firstname string `json:"firstname"`
|
|
Lastname string `json:"lastname"`
|
|
Phone string `json:"phone"`
|
|
Email string `json:"email"`
|
|
}
|
|
|
|
type PartnerCreateRequest struct {
|
|
Partnername string `json:"partnername"`
|
|
Partnertypeid int `json:"partnertypeid"`
|
|
Contactno string `json:"contactno"`
|
|
Status string `json:"status"`
|
|
}
|
|
|
|
type HubCreateRequest struct {
|
|
Hubname string `json:"hubname"`
|
|
Hubtype string `json:"hubtype"` // sorting_center, delivery_hub
|
|
Applocationid int `json:"applocationid"`
|
|
Contactno string `json:"contactno"`
|
|
Address string `json:"address"`
|
|
Latitude float64 `json:"latitude"`
|
|
Longitude float64 `json:"longitude"`
|
|
Pincode string `json:"pincode"`
|
|
Status string `json:"status"`
|
|
}
|
|
|
|
type VehicleCreateRequest struct {
|
|
Vehicleno string `json:"vehicleno"`
|
|
Vehicletype string `json:"vehicletype"`
|
|
Maxweight float64 `json:"maxweight"`
|
|
Maxvolume float64 `json:"maxvolume"`
|
|
Partnerid *int `json:"partnerid"`
|
|
Batterypercentage int `json:"batterypercentage"`
|
|
Status string `json:"status"`
|
|
}
|
|
|
|
type MilerCreateRequest struct {
|
|
Authname string `json:"authname"`
|
|
Email string `json:"email"`
|
|
Contactno string `json:"contactno"`
|
|
Password string `json:"password"`
|
|
Displayname string `json:"displayname"`
|
|
// Tenantid attaches a rider to the client they deliver for — riders migrated
|
|
// from jupiter belong to a specific client (DailyGrubs, Bawa Medicals)
|
|
// rather than to Doormile's general pool. Zero leaves them unattached.
|
|
Tenantid int `json:"tenantid"`
|
|
Defaultvehicletype string `json:"defaultvehicletype"`
|
|
Applocationid int `json:"applocationid"`
|
|
// Configid partitions logins; defaults to 1001, which is what the miler app
|
|
// authenticates against. Only set this if you know why you're changing it.
|
|
Configid int `json:"configid"`
|
|
// Hubid is optional: a rider with no hub is still assignable from the
|
|
// express console, but is invisible to the hub console's miler list.
|
|
Hubid *int `json:"hubid"`
|
|
}
|
|
|
|
type PricingCreateRequest struct {
|
|
Tenantid int `json:"tenantid"`
|
|
Applocationid int `json:"applocationid"`
|
|
Vehicletype string `json:"vehicletype"`
|
|
Baseprice float64 `json:"baseprice"`
|
|
Baseweight float64 `json:"baseweight"`
|
|
Priceperkg float64 `json:"priceperkg"`
|
|
Basedistance float64 `json:"basedistance"`
|
|
Priceperkm float64 `json:"priceperkm"`
|
|
Handlingcharges float64 `json:"handlingcharges"`
|
|
Effectivefrom time.Time `json:"effectivefrom"`
|
|
Effectiveto time.Time `json:"effectiveto"`
|
|
Currency string `json:"currency"`
|
|
Priority int `json:"priority"`
|
|
Status string `json:"status"`
|
|
}
|
|
|
|
type TripsheetCreateRequest struct {
|
|
Sourcehubid int `json:"sourcehubid"`
|
|
Destinationhubid int `json:"destinationhubid"`
|
|
Vehicleid *int `json:"vehicleid"`
|
|
Driveruserid *int `json:"driveruserid"`
|
|
}
|
|
|
|
type TripsheetItemAddRequest struct {
|
|
Consignmentid int `json:"consignmentid"`
|
|
}
|
|
|
|
type ExceptionCreateRequest struct {
|
|
Consignmentid int `json:"consignmentid"`
|
|
Tripsheetid *int `json:"tripsheetid"`
|
|
Hubid *int `json:"hubid"`
|
|
Exceptiontype string `json:"exceptiontype"` // Lost, Damaged, Misrouted, Receiver_Refused, Missing_Contents, Undeliverable
|
|
Severity string `json:"severity"` // Low, Medium, High, Critical
|
|
Description string `json:"description"`
|
|
}
|
|
|
|
type ExceptionResolveRequest struct {
|
|
Resolution string `json:"resolution"`
|
|
Status string `json:"status"` // Resolved, Closed
|
|
}
|