diff --git a/services/tenantProfile.go b/services/tenantProfile.go index bcf4128..ec5c786 100644 --- a/services/tenantProfile.go +++ b/services/tenantProfile.go @@ -26,6 +26,12 @@ var editableTenantFields = map[string]bool{ "tenantname": true, "tenantimage": true, "tenantinfo": true, + // The kind of shop it is. Omitting it was a silent data loss: store setup + // marks Store type REQUIRED, sends it on save, and the merchant is shown a + // successful step while the answer is dropped here. It describes the + // business rather than its standing on the platform, so it belongs to the + // merchant in the way "approved" and "partnerid" do not. + "tenanttype": true, // How to reach the business. "primaryemail": true, diff --git a/services/tenantProfile_test.go b/services/tenantProfile_test.go index 65787d3..31074a8 100644 --- a/services/tenantProfile_test.go +++ b/services/tenantProfile_test.go @@ -98,3 +98,35 @@ func TestFieldNamesAreMatchedLeniently(t *testing.T) { t.Errorf("want the field normalised onto its column, got %+v", clean) } } + +// Store setup marks Store type REQUIRED and sends it on save. It was missing +// from the allowlist, so the merchant answered a required question, saw the +// step succeed, and the answer was dropped on the floor — measured on local +// tenant 9002, which reached the end of setup with `tenanttype` still empty. +func TestTheKindOfShopIsTheMerchantsToSet(t *testing.T) { + clean, err := TenantProfileUpdate(map[string]any{"tenanttype": "grocery"}) + if err != nil { + t.Fatalf("TenantProfileUpdate: %v", err) + } + if clean["tenanttype"] != "grocery" { + t.Errorf("tenanttype did not survive the allowlist: %#v", clean) + } +} + +// Letting the shop describe itself must not have opened a door next to it. +func TestAllowingTheShopTypeDidNotAllowItsStanding(t *testing.T) { + clean, err := TenantProfileUpdate(map[string]any{ + "tenanttype": "pharmacy", + "tenanttoken": "stolen", + "partnerid": 99, + "configid": 7, + }) + if err != nil { + t.Fatalf("TenantProfileUpdate: %v", err) + } + for _, forbidden := range []string{"tenanttoken", "partnerid", "configid"} { + if _, present := clean[forbidden]; present { + t.Errorf("%q survived the allowlist", forbidden) + } + } +}