pos gap fix
This commit is contained in:
@@ -55,6 +55,12 @@ func PosAuth(pos services.PosService) fiber.Handler {
|
||||
token := bearerToken(c)
|
||||
|
||||
if token == "" {
|
||||
// Counted before anything else happens to it. This is the number
|
||||
// that decides when POS_AUTH_REQUIRED can be switched on, and
|
||||
// nothing else in the system was recording it — the request was
|
||||
// simply waved through in silence. See posauthadoption.go.
|
||||
recordPosUntokened(requestedLocation(c), c.Path())
|
||||
|
||||
if posAuthRequired() {
|
||||
return posUnauthorized(c, "a session token is required; sign in at /pos/login")
|
||||
}
|
||||
@@ -96,6 +102,12 @@ func PosAuth(pos services.PosService) fiber.Handler {
|
||||
}
|
||||
}
|
||||
|
||||
// A till that has adopted the new sign-in. Counted only once the token
|
||||
// has verified AND the outlet check has passed, so the figure means
|
||||
// "requests this guard would still serve with enforcement on" rather
|
||||
// than "requests that carried something token-shaped".
|
||||
recordPosToken()
|
||||
|
||||
c.Locals(PosLocalsKey, claims)
|
||||
return c.Next()
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user