login fix

This commit is contained in:
2026-09-25 10:36:38 +05:30
parent db84a9a752
commit 276e12beb9
7 changed files with 366 additions and 0 deletions

View File

@@ -2,6 +2,7 @@ package services
import (
"errors"
"fmt"
"log"
"nearle/models"
"nearle/repositories"
@@ -58,6 +59,9 @@ type UserService interface {
Login(user models.User) (models.UserInfo, error)
TenantLogin(user models.User) (models.TenantUserInfo, error)
UpdateStaff(user models.User) error
// SetInitialPassword is the one write reachable without a session — see
// the repository for what makes that safe.
SetInitialPassword(userid int, password string) error
AppLogin(user models.User) (models.TenantUserInfo, fiber.Map, error)
CreateUser(user models.User) (models.UserInfo, error)
TenantWebLogin(user models.User) (models.TenantUserInfo, map[string]interface{})
@@ -355,3 +359,25 @@ func (s *userService) TenantWebLogin(user models.User) (models.TenantUserInfo, m
func (s *userService) DeleteUser(userid int) error {
return s.repo.DeleteUser(userid)
}
// SetInitialPassword gives a never-used account its first password.
//
// The minimum length is enforced here as well as at the edge: this is the only
// write in the product reachable without a session, so the rule cannot live
// only in a handler that a second caller might not go through.
func (s *userService) SetInitialPassword(userid int, password string) error {
if userid <= 0 {
return errors.New("which account?")
}
password = strings.TrimSpace(password)
if len(password) < MinPasswordLength {
return fmt.Errorf("the password must be at least %d characters", MinPasswordLength)
}
return s.repo.SetInitialPassword(userid, password)
}
// MinPasswordLength is the floor for a console password.
//
// Six, matching the check `UpdateStaff` already applied at the controller — not
// a new rule, the same one stated where both callers can reach it.
const MinPasswordLength = 6