pos gap fix
This commit is contained in:
@@ -77,6 +77,28 @@ func RegisterPosRoutes(api fiber.Router, f *facade.Facade) {
|
||||
registerPosStaffConsoleRoutes(api, f)
|
||||
registerPosReadConsoleRoutes(api, f)
|
||||
registerLiveRoutes(api, f)
|
||||
registerPosAdoptionRoute(api, f)
|
||||
}
|
||||
|
||||
// How much of the till fleet has adopted the session token.
|
||||
//
|
||||
// The number that decides when `POS_AUTH_REQUIRED` can be switched on. Nothing
|
||||
// was recording it — an untokened request was waved through in silence — so the
|
||||
// only way to judge the risk of flipping the flag was to flip it and watch.
|
||||
//
|
||||
// ── Why it is on /v1/web and only /v1/web ───────────────────────────────────
|
||||
//
|
||||
// It names the outlets still calling without a token, which is a list of the
|
||||
// shops that would stop trading if enforcement went on today. That is exactly
|
||||
// the list an attacker would want, so it sits behind `middleware.WebAuth` and
|
||||
// NOT on the unauthenticated health endpoint, where the rest of "is this
|
||||
// deployment wired up" lives.
|
||||
//
|
||||
// Registered on its own rather than inside registerPosReadConsoleRoutes,
|
||||
// because that function deliberately mirrors every route onto `/v1/mob/pos`
|
||||
// as well — which has no guard at all.
|
||||
func registerPosAdoptionRoute(api fiber.Router, f *facade.Facade) {
|
||||
api.Group("/v1/web/pos").Get("/authadoption", f.PosController.AuthAdoption)
|
||||
}
|
||||
|
||||
// The same counter-sales reads, for callers that are not a terminal.
|
||||
|
||||
Reference in New Issue
Block a user