── What was actually broken ── The SMS gateway was switched off, and `POST /auth/otp/request` does not fail when that happens: it still answers `sent: true`, still issues a valid 4-digit code, and writes it to the **server log**. So the phone path walked customers to a code screen for a code that could not arrive, and every digit they eventually typed was wrong. The failure read to them as "I entered it wrong". Phone sign-in is now a PIN, which needs no gateway. ── Email still sends codes, so email is untouched ── Email OTP goes over SMTP and works. Deleting a working way in to tidy up a broken one is a net loss for anyone with an email on their account, so "Use email instead" and the code screen stay exactly as they were. `login_otp_guard_test` moves to that path — the `sent: false` guard still matters there, and that is now the only place it can fire. ── One screen, three entrances ── `POST /auth/login` says which of them a number is before anything is asked, so the app never guesses. Guessing is not cosmetic: offer "create a PIN" to a returning customer and the server answers `pin_already_set` on a screen that cannot succeed; offer "enter your PIN" to somebody who has never set one and every attempt is wrong. The separate sign-up screen is deleted rather than hidden. It asked for a name and then sent an SMS code — a second entrance asking the same questions and posting a letter that never lands. A new number now gives its name and PIN on the same screen. ── A second sign-in path found a latent bug ── `AppState.signIn` only started `refreshOrders`, and the OTP screen called `detectPickupLocation` itself afterwards to make up the difference. That held exactly as long as there was one sign-in screen. PIN sign-in did not know about the extra call, so Home opened with no pickup and no serviceable cities. The work belongs to signing in, not to whichever screen happened to be last, so it moved into `signIn` and the OTP screen's copy is gone. ── What the screen deliberately does not do ── It does not greet by name. `POST /auth/login` returns the account holder's name, which tells anybody who types a number who owns it; the field is read but never displayed, so it disappears quietly when the backend drops it. It does not say whether the number or the PIN was wrong — the server answers identically for both on purpose, and narrowing it here would turn sign-in into a way of testing whether a number has an account. "Forgot your PIN?" renders only when a support contact is configured. There is no reset endpoint, so it can only point at a human — and telling somebody locked out that help exists without saying where is worse than silence. ── The handover note does not reach the Miler ── The app said "we pass this to your Miler as a note". It does not: `remarks` reaches the admin console and stops, because the rider app reads a `notes` field per stop that the backend never sends. A customer could hand their parcel to a neighbour believing the Miler had been told. Both screens now say it is recorded on the booking, and that the Miler still calls the account's number. ── Also ── DmTextField gains `obscure`, and PinScreen carries a back button — without one the only correction for a mistyped digit was killing the app.
107 lines
3.9 KiB
Dart
107 lines
3.9 KiB
Dart
import 'package:doormile_cx/data/dev_doormile_api.dart';
|
|
import 'package:doormile_cx/data/models.dart';
|
|
import 'package:doormile_cx/main.dart';
|
|
import 'package:doormile_cx/state/app_state.dart';
|
|
import 'package:flutter/material.dart';
|
|
import 'package:flutter_test/flutter_test.dart';
|
|
|
|
/// The login screen must not walk a customer to the code screen when no code
|
|
/// was sent.
|
|
///
|
|
/// ── Why this is an email test now ──
|
|
///
|
|
/// Phone sign-in no longer sends a code at all: the SMS gateway was switched
|
|
/// off, `otp/request` still answers `sent: true` and writes the code to the
|
|
/// server log, and the phone path therefore moved to a PIN. Email OTP goes
|
|
/// over SMTP, is unaffected, and is still offered — so the guard still matters
|
|
/// and this is the path that exercises it.
|
|
///
|
|
/// `sent: false` is the server saying it accepted the request and delivered
|
|
/// nothing — the SMS gateway or the mail relay refused it. Advancing anyway
|
|
/// puts four empty boxes in front of someone for a code that does not exist,
|
|
/// and every digit they try is wrong. The failure then reads as "I typed it
|
|
/// wrong" instead of "nothing arrived", which is the wrong problem to hand
|
|
/// somebody.
|
|
///
|
|
/// The resend control on the code screen has always honoured this flag. The
|
|
/// login screen did not, which is the asymmetry these tests pin down.
|
|
|
|
/// The app runs continuous animations, so `pumpAndSettle` never returns.
|
|
Future<void> settle(WidgetTester tester, [int ms = 800]) async {
|
|
await tester.pump();
|
|
await tester.pump(Duration(milliseconds: ms));
|
|
await tester.pump(const Duration(milliseconds: 400));
|
|
}
|
|
|
|
class _SendFails extends DevDoormileApi {
|
|
@override
|
|
Future<OtpChallenge> sendOtp(String identifier) async =>
|
|
const OtpChallenge(sent: false);
|
|
}
|
|
|
|
class _SendSucceeds extends DevDoormileApi {
|
|
var calls = 0;
|
|
|
|
@override
|
|
Future<OtpChallenge> sendOtp(String identifier) async {
|
|
calls++;
|
|
return const OtpChallenge(sent: true);
|
|
}
|
|
}
|
|
|
|
Future<void> _tapContinue(WidgetTester tester, AppState state) async {
|
|
tester.view.physicalSize = const Size(1230, 9000);
|
|
tester.view.devicePixelRatio = 3.0;
|
|
addTearDown(tester.view.reset);
|
|
|
|
await tester.pumpWidget(DoormileApp(initialState: state));
|
|
// The splash holds for its own minimum — and the waits in front of it — before handing over, so
|
|
// the entrance is waited out once, here, rather than by lengthening every
|
|
// settle in the suite.
|
|
await settle(tester, 4400);
|
|
|
|
// Email, because that is the only identifier that still gets a code.
|
|
await tester.tap(find.text('Use email instead'));
|
|
await settle(tester, 200);
|
|
await tester.enterText(find.byType(TextField).first, 'joe@example.com');
|
|
await settle(tester, 200);
|
|
await tester.tap(find.text('Continue'));
|
|
await settle(tester);
|
|
}
|
|
|
|
void main() {
|
|
testWidgets('a code that was never sent does not open the code screen',
|
|
(tester) async {
|
|
await _tapContinue(tester, AppState(api: _SendFails()));
|
|
|
|
expect(
|
|
find.text('Verify your number'),
|
|
findsNothing,
|
|
reason: 'no code was delivered, so there is nothing to verify',
|
|
);
|
|
expect(
|
|
// The entry screen's heading. It used to be the promise on the crimson
|
|
// ("Book a pickup from your door."); the screen was cut back to an
|
|
// instruction, a field and a button, so the heading is now the
|
|
// instruction. What this asserts is unchanged: the customer is still on
|
|
// the sign-in screen and can try again.
|
|
find.text('Enter your email address'),
|
|
findsOneWidget,
|
|
reason: 'the customer stays where they can try again',
|
|
);
|
|
|
|
// Drain the toast timer so the test ends with nothing pending.
|
|
await tester.pump(const Duration(seconds: 4));
|
|
});
|
|
|
|
testWidgets('a delivered code does open the code screen', (tester) async {
|
|
final api = _SendSucceeds();
|
|
await _tapContinue(tester, AppState(api: api));
|
|
|
|
expect(find.text('Verify your number'), findsOneWidget);
|
|
expect(api.calls, 1);
|
|
|
|
await tester.pump(const Duration(seconds: 4));
|
|
});
|
|
}
|