fix in the catlogue

This commit is contained in:
2026-08-10 15:36:39 +05:30
parent 5c04d40f0e
commit 3531c656d4
2 changed files with 72 additions and 2 deletions

View File

@@ -75,6 +75,48 @@ func RegisterPosRoutes(api fiber.Router, f *facade.Facade) {
pos.Get("/health/location", f.PosController.LocationHealth)
registerPosStaffConsoleRoutes(api, f)
registerPosReadConsoleRoutes(api, f)
}
// The same counter-sales reads, for callers that are not a terminal.
//
// `PosAuth` pins a request to the outlet inside a terminal's token. The web
// console has no such token and cannot obtain one — `/pos/login` refuses an
// account that is not a till account, which is the separation working as
// intended. So the moment `POS_AUTH_REQUIRED=true` is set, every POS screen in
// the back office goes dark: the two were mutually exclusive.
//
// Rather than weaken the terminal guard or hand the console a terminal
// identity, the reads are offered again outside the group. A browser and a till
// are different callers and belong on different doors.
//
// Only the five the console actually reads, and only reads. Specifically NOT
// `/health/terminal`: it takes a terminal code and no outlet, so it resolves
// the shop from the heartbeat and checks that against the caller's token. Off
// this group there is no token to check, and mirroring it would undo that.
// Nothing in the console calls it — `/health/location` answers the same
// question with an outlet to scope by.
//
// These inherit the `/web` surface's authentication, which is none. That is not
// a new hole opened here — `getposusers` on the neighbouring group already
// answers unauthenticated and returns PINs — but it is the reason this whole
// surface wants a session guard, which is tracked separately.
func registerPosReadConsoleRoutes(api fiber.Router, f *facade.Facade) {
for _, group := range []string{"/v1/web/pos", "/v1/mob/pos"} {
g := api.Group(group)
g.Get("/sales", f.PosController.GetSales)
g.Get("/sales/detail", f.PosController.GetSaleDetail)
g.Get("/sales/summary", f.PosController.GetSalesSummary)
// The fleet board. Scoped by the outlet named in the query, exactly as
// on the terminal group — the handler reads nothing from a session.
g.Get("/health/location", f.PosController.LocationHealth)
// What a till at this shop can sell. Read-only and already scoped by
// store id; the console shows it to explain why a product will not ring.
g.Get("/catalogue", f.PosController.Catalogue)
}
}
// Till staff, managed from the web console rather than from a counter.