Files
doormile_customer_app/design/screens
Thiru-tenext 8757b16cf5 PIN sign-in, because the code could never arrive
── What was actually broken ──

The SMS gateway was switched off, and `POST /auth/otp/request` does not fail
when that happens: it still answers `sent: true`, still issues a valid 4-digit
code, and writes it to the **server log**. So the phone path walked customers
to a code screen for a code that could not arrive, and every digit they
eventually typed was wrong. The failure read to them as "I entered it wrong".

Phone sign-in is now a PIN, which needs no gateway.

── Email still sends codes, so email is untouched ──

Email OTP goes over SMTP and works. Deleting a working way in to tidy up a
broken one is a net loss for anyone with an email on their account, so "Use
email instead" and the code screen stay exactly as they were.
`login_otp_guard_test` moves to that path — the `sent: false` guard still
matters there, and that is now the only place it can fire.

── One screen, three entrances ──

`POST /auth/login` says which of them a number is before anything is asked, so
the app never guesses. Guessing is not cosmetic: offer "create a PIN" to a
returning customer and the server answers `pin_already_set` on a screen that
cannot succeed; offer "enter your PIN" to somebody who has never set one and
every attempt is wrong.

The separate sign-up screen is deleted rather than hidden. It asked for a name
and then sent an SMS code — a second entrance asking the same questions and
posting a letter that never lands. A new number now gives its name and PIN on
the same screen.

── A second sign-in path found a latent bug ──

`AppState.signIn` only started `refreshOrders`, and the OTP screen called
`detectPickupLocation` itself afterwards to make up the difference. That held
exactly as long as there was one sign-in screen. PIN sign-in did not know about
the extra call, so Home opened with no pickup and no serviceable cities.

The work belongs to signing in, not to whichever screen happened to be last, so
it moved into `signIn` and the OTP screen's copy is gone.

── What the screen deliberately does not do ──

It does not greet by name. `POST /auth/login` returns the account holder's
name, which tells anybody who types a number who owns it; the field is read but
never displayed, so it disappears quietly when the backend drops it.

It does not say whether the number or the PIN was wrong — the server answers
identically for both on purpose, and narrowing it here would turn sign-in into
a way of testing whether a number has an account.

"Forgot your PIN?" renders only when a support contact is configured. There is
no reset endpoint, so it can only point at a human — and telling somebody
locked out that help exists without saying where is worse than silence.

── The handover note does not reach the Miler ──

The app said "we pass this to your Miler as a note". It does not: `remarks`
reaches the admin console and stops, because the rider app reads a `notes`
field per stop that the backend never sends. A customer could hand their parcel
to a neighbour believing the Miler had been told. Both screens now say it is
recorded on the booking, and that the Miler still calls the account's number.

── Also ──

DmTextField gains `obscure`, and PinScreen carries a back button — without one
the only correction for a mistyped digit was killing the app.
2026-09-30 10:44:22 +05:30
..

Screens

Every screen in the app, at 390×844 @3x, with the real fonts.

These are the golden files from test/snapshots/, copied here under readable names so the set can be browsed, shared or dropped into a deck without anyone having to know what a golden is. test/snapshots/ is the source of truth — this folder is a copy, and a stale copy is worse than none, so refresh it whenever the design moves:

flutter test test/design_snapshot_test.dart --run-skipped --update-goldens
tool/screens.sh

They are rendered by the test harness rather than captured from a handset, so they are identical on any machine and need no device attached. Two consequences worth knowing: map tiles are blank, because the harness has no network and CARTO is fetched live; and the data is DevDoormileApi's, so the names, addresses and references are invented.

File Screen
00-splash-truck.png Splash · first beat What the app does, in white on the brand crimson the launcher icon opens from.
00b-splash-invert.png Splash · second beat The invert, caught halfway: the ground lightening as the truck darkens, both on one curve.
00c-splash-mark.png Splash · third beat Whose app it is. The same mark the launcher icon is cut from.
01-sign-in.png Sign in One question, one field, one button.
02-sign-up.png Create account The same shell, three fields.
03-verify-code.png Verify the code One field behind four boxes that only draw.
04-home.png Home Welcome, the pickup address, BOOK, and the live booking.
05-pickup-search.png Collect from Changing the pickup address from the Home header.
06-orders-active.png Orders · Active State, date, route, packages, reference.
07-orders-completed.png Orders · Completed Delivered orders and what they cost.
08-account.png Account Grouped rows, and the build this handset is running.
09-tracking.png Live tracking The live card, the map, the Miler, the journey rail.
10-cancel-pickup.png Cancel this pickup The one destructive action, behind a reason.
11-pickup-where.png Pickup · where Every city Doormile serves, headed by state. One list, no level to open — and the answer to "where do you deliver?".
12-pickup-when.png Pickup · when The same sheet's second question. It never leaves and never changes height.
14-send-a-parcel.png Send a parcel The route, the packages, the two commitments.
15-pickup-map.png Pickup point The map editor, and who the Miler asks for.
16-pickup-booked.png Pickup booked White tick on green. The reference and the live search.
17-receipt.png Order details What was collected, weighed, photographed and paid.

Not here yet

First-run Home — the sphere's caption and the "How it works" rail only appear for a customer with no orders, and the dev backend seeds three. It needs a flag on DevFlags to capture, which is not worth adding for a picture.