fix in the catlogue
This commit is contained in:
@@ -75,6 +75,48 @@ func RegisterPosRoutes(api fiber.Router, f *facade.Facade) {
|
||||
pos.Get("/health/location", f.PosController.LocationHealth)
|
||||
|
||||
registerPosStaffConsoleRoutes(api, f)
|
||||
registerPosReadConsoleRoutes(api, f)
|
||||
}
|
||||
|
||||
// The same counter-sales reads, for callers that are not a terminal.
|
||||
//
|
||||
// `PosAuth` pins a request to the outlet inside a terminal's token. The web
|
||||
// console has no such token and cannot obtain one — `/pos/login` refuses an
|
||||
// account that is not a till account, which is the separation working as
|
||||
// intended. So the moment `POS_AUTH_REQUIRED=true` is set, every POS screen in
|
||||
// the back office goes dark: the two were mutually exclusive.
|
||||
//
|
||||
// Rather than weaken the terminal guard or hand the console a terminal
|
||||
// identity, the reads are offered again outside the group. A browser and a till
|
||||
// are different callers and belong on different doors.
|
||||
//
|
||||
// Only the five the console actually reads, and only reads. Specifically NOT
|
||||
// `/health/terminal`: it takes a terminal code and no outlet, so it resolves
|
||||
// the shop from the heartbeat and checks that against the caller's token. Off
|
||||
// this group there is no token to check, and mirroring it would undo that.
|
||||
// Nothing in the console calls it — `/health/location` answers the same
|
||||
// question with an outlet to scope by.
|
||||
//
|
||||
// These inherit the `/web` surface's authentication, which is none. That is not
|
||||
// a new hole opened here — `getposusers` on the neighbouring group already
|
||||
// answers unauthenticated and returns PINs — but it is the reason this whole
|
||||
// surface wants a session guard, which is tracked separately.
|
||||
func registerPosReadConsoleRoutes(api fiber.Router, f *facade.Facade) {
|
||||
for _, group := range []string{"/v1/web/pos", "/v1/mob/pos"} {
|
||||
g := api.Group(group)
|
||||
|
||||
g.Get("/sales", f.PosController.GetSales)
|
||||
g.Get("/sales/detail", f.PosController.GetSaleDetail)
|
||||
g.Get("/sales/summary", f.PosController.GetSalesSummary)
|
||||
|
||||
// The fleet board. Scoped by the outlet named in the query, exactly as
|
||||
// on the terminal group — the handler reads nothing from a session.
|
||||
g.Get("/health/location", f.PosController.LocationHealth)
|
||||
|
||||
// What a till at this shop can sell. Read-only and already scoped by
|
||||
// store id; the console shows it to explain why a product will not ring.
|
||||
g.Get("/catalogue", f.PosController.Catalogue)
|
||||
}
|
||||
}
|
||||
|
||||
// Till staff, managed from the web console rather than from a counter.
|
||||
|
||||
Reference in New Issue
Block a user