profile name change
This commit is contained in:
@@ -57,6 +57,13 @@ type Tenantinfo struct {
|
|||||||
Approved int `json:"approved"`
|
Approved int `json:"approved"`
|
||||||
Moduleid int `json:"moduleid"`
|
Moduleid int `json:"moduleid"`
|
||||||
Subcategoryname string `json:"subcategoryname"`
|
Subcategoryname string `json:"subcategoryname"`
|
||||||
|
// The app category this store trades under, by name.
|
||||||
|
//
|
||||||
|
// `GetTenantByID` has always joined `app_category b` and selected
|
||||||
|
// `b.categoryname`, and the struct had nowhere to put it — so the value was
|
||||||
|
// computed on every read and discarded, leaving the console to print
|
||||||
|
// "Category 2" at a merchant who trades under Daily Needs.
|
||||||
|
Categoryname string `json:"categoryname"`
|
||||||
Firstname string `json:"firstname"`
|
Firstname string `json:"firstname"`
|
||||||
Lastname string `json:"lastname"`
|
Lastname string `json:"lastname"`
|
||||||
Accountname string `json:"Accountname"`
|
Accountname string `json:"Accountname"`
|
||||||
|
|||||||
@@ -37,6 +37,15 @@ var editableTenantFields = map[string]bool{
|
|||||||
"primaryemail": true,
|
"primaryemail": true,
|
||||||
"primarycontact": true,
|
"primarycontact": true,
|
||||||
"companyname": true,
|
"companyname": true,
|
||||||
|
// The person who administers the shop — the Store admin.
|
||||||
|
//
|
||||||
|
// `tenants.firstname` — there is no lastname column, so this is the whole
|
||||||
|
// name. It was collected nowhere and writable nowhere, which is why every
|
||||||
|
// merchant read so far comes back with it empty and the store profile shows
|
||||||
|
// "—" for Store admin. It describes the business's own contact person, in
|
||||||
|
// the same way `companyname` does, and belongs to the merchant rather than
|
||||||
|
// to the platform.
|
||||||
|
"firstname": true,
|
||||||
|
|
||||||
// Where it is.
|
// Where it is.
|
||||||
"address": true,
|
"address": true,
|
||||||
|
|||||||
@@ -130,3 +130,39 @@ func TestAllowingTheShopTypeDidNotAllowItsStanding(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The person who runs the shop.
|
||||||
|
//
|
||||||
|
// `tenants.firstname` was collected by no form and permitted by no allowlist,
|
||||||
|
// so every merchant read came back with it empty and the store profile printed
|
||||||
|
// "—" for Store admin. It is the business's own contact person, not its
|
||||||
|
// standing on the platform.
|
||||||
|
func TestTenantProfileUpdateAllowsStoreAdmin(t *testing.T) {
|
||||||
|
clean, err := TenantProfileUpdate(map[string]any{
|
||||||
|
"tenantid": 1147,
|
||||||
|
"firstname": "Ravi Kumar",
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("TenantProfileUpdate: %v", err)
|
||||||
|
}
|
||||||
|
if clean["firstname"] != "Ravi Kumar" {
|
||||||
|
t.Fatalf("firstname should survive the allowlist, got %v", clean["firstname"])
|
||||||
|
}
|
||||||
|
if _, ok := clean["tenantid"]; ok {
|
||||||
|
t.Fatal("tenantid names the row and is never a value to write")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// The guard that makes the allowlist worth having: a merchant must not be able
|
||||||
|
// to approve themselves or move under another partner by sending the field.
|
||||||
|
func TestTenantProfileUpdateStillRefusesPlatformFields(t *testing.T) {
|
||||||
|
_, err := TenantProfileUpdate(map[string]any{
|
||||||
|
"tenantid": 1147,
|
||||||
|
"approved": 1,
|
||||||
|
"partnerid": 9,
|
||||||
|
"status": "Active",
|
||||||
|
})
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("nothing in that request is editable, so it must not report success")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user