PIN sign-in, because the code could never arrive
── What was actually broken ── The SMS gateway was switched off, and `POST /auth/otp/request` does not fail when that happens: it still answers `sent: true`, still issues a valid 4-digit code, and writes it to the **server log**. So the phone path walked customers to a code screen for a code that could not arrive, and every digit they eventually typed was wrong. The failure read to them as "I entered it wrong". Phone sign-in is now a PIN, which needs no gateway. ── Email still sends codes, so email is untouched ── Email OTP goes over SMTP and works. Deleting a working way in to tidy up a broken one is a net loss for anyone with an email on their account, so "Use email instead" and the code screen stay exactly as they were. `login_otp_guard_test` moves to that path — the `sent: false` guard still matters there, and that is now the only place it can fire. ── One screen, three entrances ── `POST /auth/login` says which of them a number is before anything is asked, so the app never guesses. Guessing is not cosmetic: offer "create a PIN" to a returning customer and the server answers `pin_already_set` on a screen that cannot succeed; offer "enter your PIN" to somebody who has never set one and every attempt is wrong. The separate sign-up screen is deleted rather than hidden. It asked for a name and then sent an SMS code — a second entrance asking the same questions and posting a letter that never lands. A new number now gives its name and PIN on the same screen. ── A second sign-in path found a latent bug ── `AppState.signIn` only started `refreshOrders`, and the OTP screen called `detectPickupLocation` itself afterwards to make up the difference. That held exactly as long as there was one sign-in screen. PIN sign-in did not know about the extra call, so Home opened with no pickup and no serviceable cities. The work belongs to signing in, not to whichever screen happened to be last, so it moved into `signIn` and the OTP screen's copy is gone. ── What the screen deliberately does not do ── It does not greet by name. `POST /auth/login` returns the account holder's name, which tells anybody who types a number who owns it; the field is read but never displayed, so it disappears quietly when the backend drops it. It does not say whether the number or the PIN was wrong — the server answers identically for both on purpose, and narrowing it here would turn sign-in into a way of testing whether a number has an account. "Forgot your PIN?" renders only when a support contact is configured. There is no reset endpoint, so it can only point at a human — and telling somebody locked out that help exists without saying where is worse than silence. ── The handover note does not reach the Miler ── The app said "we pass this to your Miler as a note". It does not: `remarks` reaches the admin console and stops, because the rider app reads a `notes` field per stop that the backend never sends. A customer could hand their parcel to a neighbour believing the Miler had been told. Both screens now say it is recorded on the booking, and that the Miler still calls the account's number. ── Also ── DmTextField gains `obscure`, and PinScreen carries a back button — without one the only correction for a mistyped digit was killing the app.
This commit is contained in:
@@ -49,6 +49,28 @@ class ApiException implements Exception {
|
||||
/// The Miler has already arrived, so the cancel window has closed.
|
||||
static const String notCancellable = 'not_cancellable';
|
||||
|
||||
// ── PIN sign-in ──
|
||||
//
|
||||
// Three codes, three different next screens, which is why none of them can
|
||||
// be folded into [invalid]. The server uses the same message for a wrong PIN
|
||||
// and an unknown number on purpose — so the app must not guess which, and
|
||||
// says "That number or PIN is incorrect" rather than naming one.
|
||||
|
||||
/// Wrong PIN, **or** a phone with no account. Deliberately ambiguous.
|
||||
static const String invalidPin = 'invalid_pin';
|
||||
|
||||
/// The account exists and has no PIN yet — send them to create one.
|
||||
static const String pinNotSet = 'pin_not_set';
|
||||
|
||||
/// The account already has a PIN — send them to enter it.
|
||||
static const String pinAlreadySet = 'pin_already_set';
|
||||
|
||||
/// Too many wrong PINs on this account. Not in the contract yet: the backend
|
||||
/// is adding a per-account lockout, and the app reads it the moment it lands
|
||||
/// rather than needing a release to catch up. Until then the server answers
|
||||
/// [invalidPin] and this simply never fires.
|
||||
static const String pinLocked = 'pin_locked';
|
||||
|
||||
/// Translates the contract's `error.code` into the vocabulary above.
|
||||
///
|
||||
/// The wire spells its codes in capitals; the client's are lowercase, and
|
||||
@@ -64,6 +86,10 @@ class ApiException implements Exception {
|
||||
if (trimmed.isEmpty) return fromStatus();
|
||||
if (trimmed != trimmed.toUpperCase()) return trimmed;
|
||||
return switch (trimmed) {
|
||||
'INVALID_PIN' => invalidPin,
|
||||
'PIN_NOT_SET' => pinNotSet,
|
||||
'PIN_ALREADY_SET' => pinAlreadySet,
|
||||
'PIN_LOCKED' || 'ACCOUNT_LOCKED' => pinLocked,
|
||||
'UNAUTHORIZED' || 'TOKEN_EXPIRED' => unauthorized,
|
||||
'FORBIDDEN' => forbidden,
|
||||
'NOT_FOUND' => notFound,
|
||||
|
||||
@@ -216,6 +216,95 @@ class DevDoormileApi extends DoormileApi {
|
||||
);
|
||||
});
|
||||
|
||||
// ── PIN sign-in ──
|
||||
//
|
||||
// Modelled on the real server's three answers rather than always succeeding,
|
||||
// so the screens can be driven through every branch without a backend:
|
||||
//
|
||||
// 9876543210 an account with a PIN -> enterPin
|
||||
// 9000000000 an account with no PIN -> createPin
|
||||
// anything else -> createAccount
|
||||
//
|
||||
// The PIN itself is 1234 everywhere. Any other value is refused, so the
|
||||
// wrong-PIN path is reachable too.
|
||||
|
||||
/// Numbers the fake backend already knows about, and whether they have a PIN.
|
||||
static const _knownPins = {'9876543210': true, '9000000000': false};
|
||||
|
||||
static String _digits(String phone) => phone.replaceAll(RegExp(r'\D'), '');
|
||||
|
||||
static String _last10(String phone) {
|
||||
final d = _digits(phone);
|
||||
return d.length <= 10 ? d : d.substring(d.length - 10);
|
||||
}
|
||||
|
||||
@override
|
||||
Future<PhoneCheck> checkPhone(String phone) => _respond(() {
|
||||
final key = _last10(phone);
|
||||
final known = _knownPins[key];
|
||||
return PhoneCheck(
|
||||
phone: '+91 $key',
|
||||
registered: known != null,
|
||||
pinSet: known ?? false,
|
||||
name: known == null ? null : 'Joe Oommen',
|
||||
);
|
||||
});
|
||||
|
||||
@override
|
||||
Future<Customer> setPin({
|
||||
required String phone,
|
||||
required String pin,
|
||||
String? name,
|
||||
}) => _respond(() {
|
||||
if (pin.length != 4 || int.tryParse(pin) == null) {
|
||||
throw ApiException(ApiException.invalid, 'Enter a valid PIN');
|
||||
}
|
||||
final key = _last10(phone);
|
||||
if (_knownPins[key] == true) {
|
||||
throw ApiException(
|
||||
ApiException.pinAlreadySet,
|
||||
'That number already has a PIN',
|
||||
);
|
||||
}
|
||||
if (_knownPins[key] == null && (name == null || name.trim().length < 2)) {
|
||||
throw ApiException(ApiException.invalidName, 'Enter your full name');
|
||||
}
|
||||
return Customer(
|
||||
id: 'cust_10241',
|
||||
name: name?.trim().isNotEmpty == true ? name!.trim() : 'Joe Oommen',
|
||||
phone: '+91 $key',
|
||||
email: 'joe@example.com',
|
||||
);
|
||||
});
|
||||
|
||||
@override
|
||||
Future<Customer> verifyPin({
|
||||
required String phone,
|
||||
required String pin,
|
||||
}) => _respond(() {
|
||||
final key = _last10(phone);
|
||||
if (_knownPins[key] != true) {
|
||||
throw ApiException(
|
||||
ApiException.pinNotSet,
|
||||
'Create a PIN for this number',
|
||||
);
|
||||
}
|
||||
if (pin != '1234') {
|
||||
// The server answers the same way for a wrong PIN and an unknown number,
|
||||
// and so does this — the screen must not be able to tell them apart.
|
||||
throw ApiException(
|
||||
ApiException.invalidPin,
|
||||
'That phone number or PIN is incorrect',
|
||||
);
|
||||
}
|
||||
return const Customer(
|
||||
id: 'cust_10241',
|
||||
name: 'Joe Oommen',
|
||||
phone: '+91 9876543210',
|
||||
email: 'joe@example.com',
|
||||
);
|
||||
});
|
||||
|
||||
// ----------------------------------------------------------- serviceability
|
||||
|
||||
@override
|
||||
|
||||
@@ -69,6 +69,33 @@ abstract class DoormileApi {
|
||||
/// [name] is set when verifying a freshly created account.
|
||||
Future<Customer> verifyOtp(String identifier, String code, {String? name});
|
||||
|
||||
// ── PIN sign-in ──
|
||||
//
|
||||
// The paid SMS gateway was switched off, so phone OTP issues codes that
|
||||
// reach only the server log. These three replace it for phone numbers. Email
|
||||
// OTP still works and is still offered — see `LoginScreen`.
|
||||
//
|
||||
// `setPin` and `verifyPin` return the same session `verifyOtp` does, so
|
||||
// everything after sign-in — token refresh, restore, logout — is untouched.
|
||||
|
||||
/// Which of the three PIN screens this number leads to.
|
||||
Future<PhoneCheck> checkPhone(String phone);
|
||||
|
||||
/// Sets the **first** PIN on a number, creating the account when it is new.
|
||||
///
|
||||
/// [name] is required only for a number with no account. Throws
|
||||
/// [ApiException.pinAlreadySet] when there is already a PIN.
|
||||
Future<Customer> setPin({
|
||||
required String phone,
|
||||
required String pin,
|
||||
String? name,
|
||||
});
|
||||
|
||||
/// Signs in with an existing PIN. Throws [ApiException.invalidPin] for a
|
||||
/// wrong PIN *or* an unknown number, and [ApiException.pinNotSet] when the
|
||||
/// account has none yet.
|
||||
Future<Customer> verifyPin({required String phone, required String pin});
|
||||
|
||||
/// Restores a persisted session at launch, or null when there is none.
|
||||
Future<Customer?> restoreSession() async => null;
|
||||
|
||||
|
||||
@@ -120,6 +120,90 @@ class LiveDoormileApi extends DoormileApi {
|
||||
return customer;
|
||||
}
|
||||
|
||||
// ── PIN sign-in ──
|
||||
|
||||
@override
|
||||
Future<PhoneCheck> checkPhone(String phone) async {
|
||||
final normalised = _normalisePhone(phone);
|
||||
final response = await client.post(
|
||||
'/auth/login',
|
||||
body: {'phone': normalised},
|
||||
authenticated: false,
|
||||
);
|
||||
return PhoneCheck.fromJson(response.map, normalised);
|
||||
}
|
||||
|
||||
@override
|
||||
Future<Customer> setPin({
|
||||
required String phone,
|
||||
required String pin,
|
||||
String? name,
|
||||
}) async {
|
||||
final response = await client.post(
|
||||
'/auth/set-pin',
|
||||
// `new_pin`, snake_case, unlike every other field on the customer
|
||||
// surface. The PIN routes were added on their own and spell it that way;
|
||||
// sending `newPin` is a 400 "Enter a valid PIN" on every attempt.
|
||||
body: {
|
||||
'phone': _normalisePhone(phone),
|
||||
'new_pin': pin,
|
||||
if (name != null && name.trim().isNotEmpty) 'name': name.trim(),
|
||||
},
|
||||
authenticated: false,
|
||||
idempotencyKey: client.newIdempotencyKey(),
|
||||
);
|
||||
return _adoptSessionFrom(response, 'set-pin');
|
||||
}
|
||||
|
||||
@override
|
||||
Future<Customer> verifyPin({
|
||||
required String phone,
|
||||
required String pin,
|
||||
}) async {
|
||||
final response = await client.post(
|
||||
'/auth/verify-pin',
|
||||
body: {'phone': _normalisePhone(phone), 'pin': pin},
|
||||
authenticated: false,
|
||||
idempotencyKey: client.newIdempotencyKey(),
|
||||
);
|
||||
return _adoptSessionFrom(response, 'verify-pin');
|
||||
}
|
||||
|
||||
/// Reads a session out of an auth response and adopts it.
|
||||
///
|
||||
/// Extracted so the three sign-in paths cannot drift: `verifyOtp` had this
|
||||
/// inline, and a second copy written by hand is a second place for the
|
||||
/// `expiresIn` default or the null check to be subtly different.
|
||||
Future<Customer> _adoptSessionFrom(ApiResponse response, String where) async {
|
||||
final data = response.map;
|
||||
final access = data['accessToken'] as String?;
|
||||
final refresh = data['refreshToken'] as String?;
|
||||
if (access == null || refresh == null) {
|
||||
debugPrint('[AUTH] $where answered without a session');
|
||||
throw ApiException(
|
||||
ApiException.serverError,
|
||||
'Something went wrong',
|
||||
200,
|
||||
response.requestId,
|
||||
);
|
||||
}
|
||||
|
||||
final customer = Customer.fromJson(
|
||||
(data['customer'] as Map<String, dynamic>?) ?? const {},
|
||||
);
|
||||
await client.adoptSession(
|
||||
Session(
|
||||
accessToken: access,
|
||||
refreshToken: refresh,
|
||||
expiresAt: DateTime.now().add(
|
||||
Duration(seconds: (data['expiresIn'] as num?)?.toInt() ?? 3600),
|
||||
),
|
||||
customer: customer,
|
||||
),
|
||||
);
|
||||
return customer;
|
||||
}
|
||||
|
||||
@override
|
||||
Future<Customer?> restoreSession() async {
|
||||
await _adoptDevTokenIfGiven();
|
||||
|
||||
@@ -258,6 +258,74 @@ double? coordinate(Map<String, dynamic> json, String key) {
|
||||
/// The server owns both numbers, and the OTP screen is built from them rather
|
||||
/// than from constants: a backend that moves to a six-digit code, or lengthens
|
||||
/// the resend window, must not need an app release to be usable.
|
||||
/// What `POST /customer/auth/login` answers about a phone number.
|
||||
///
|
||||
/// ── Why the app asks before it shows a field ──
|
||||
///
|
||||
/// PIN sign-in has three entrances and they look identical to a customer: an
|
||||
/// unknown number, a known number with no PIN yet, and a known number with
|
||||
/// one. Guessing wrong means asking somebody to "enter your PIN" when they
|
||||
/// have never set one, or asking a returning customer to invent a new one over
|
||||
/// the top of theirs (which the server refuses with `pin_already_set`, leaving
|
||||
/// them stuck on a screen that cannot succeed).
|
||||
///
|
||||
/// One call up front removes the guess. The screen that follows is the right
|
||||
/// one every time.
|
||||
class PhoneCheck {
|
||||
const PhoneCheck({
|
||||
required this.phone,
|
||||
required this.registered,
|
||||
required this.pinSet,
|
||||
this.name,
|
||||
});
|
||||
|
||||
/// The number as the server normalised it — E.164. Sent back on the next
|
||||
/// call rather than re-normalised here, so both requests agree.
|
||||
final String phone;
|
||||
|
||||
final bool registered;
|
||||
final bool pinSet;
|
||||
|
||||
/// The account holder's first name, when there is an account.
|
||||
///
|
||||
/// The server returns it and the backend has been asked to stop, because it
|
||||
/// discloses who owns a number to anybody who types it. The app therefore
|
||||
/// **does not display it** — it is read only so that it disappears quietly
|
||||
/// when the backend drops the field, rather than becoming a missing greeting
|
||||
/// somebody has to go and diagnose.
|
||||
final String? name;
|
||||
|
||||
/// Which screen comes next.
|
||||
PhoneStep get step => !registered
|
||||
? PhoneStep.createAccount
|
||||
: (pinSet ? PhoneStep.enterPin : PhoneStep.createPin);
|
||||
|
||||
factory PhoneCheck.fromJson(Map<String, dynamic> json, String fallback) =>
|
||||
PhoneCheck(
|
||||
phone: (json['phone'] as String?)?.trim().isNotEmpty == true
|
||||
? (json['phone'] as String).trim()
|
||||
: fallback,
|
||||
// snake_case here and nowhere else on the customer surface — the PIN
|
||||
// routes were added separately and spell it `pin_set`. Both are read
|
||||
// so a later tidy-up on the server does not break sign-in.
|
||||
registered: (json['registered'] ?? json['isRegistered']) == true,
|
||||
pinSet: (json['pin_set'] ?? json['pinSet']) == true,
|
||||
name: (json['name'] as String?)?.trim(),
|
||||
);
|
||||
}
|
||||
|
||||
/// The screen a phone number leads to.
|
||||
enum PhoneStep {
|
||||
/// No account: ask for a name and a new PIN.
|
||||
createAccount,
|
||||
|
||||
/// Account exists, no PIN: ask for a new PIN only.
|
||||
createPin,
|
||||
|
||||
/// Account with a PIN: ask for it.
|
||||
enterPin,
|
||||
}
|
||||
|
||||
class OtpChallenge {
|
||||
const OtpChallenge({
|
||||
this.codeLength = 4,
|
||||
|
||||
Reference in New Issue
Block a user