pos login with the ph number and pin
This commit is contained in:
@@ -443,6 +443,11 @@ func posIngestError(c *fiber.Ctx, op string, err error) error {
|
||||
// The one POS route that is deliberately left unauthenticated — it is where a
|
||||
// token comes from. Everything else on the group sits behind the session this
|
||||
// issues.
|
||||
//
|
||||
// A mobile number and a PIN. Because it is unauthenticated and the PIN is four
|
||||
// digits, this is the one route on the group that needs a rate limit in front
|
||||
// of it — the pair is only strong while an attacker cannot try ten thousand
|
||||
// times. That belongs at the edge, not here.
|
||||
func (ctl *PosController) Login(c *fiber.Ctx) error {
|
||||
var req models.PosLoginRequest
|
||||
if err := c.BodyParser(&req); err != nil {
|
||||
@@ -452,10 +457,23 @@ func (ctl *PosController) Login(c *fiber.Ctx) error {
|
||||
})
|
||||
}
|
||||
|
||||
if strings.TrimSpace(req.Authname) == "" && strings.TrimSpace(req.Contactno) == "" {
|
||||
// Which account, and which of the two credentials was offered. Both are
|
||||
// checked here so an empty field is answered as the malformed request it is,
|
||||
// rather than spending a database round trip to say the same thing.
|
||||
identity := strings.TrimSpace(req.Contactno)
|
||||
if identity == "" {
|
||||
identity = strings.TrimSpace(req.Authname)
|
||||
}
|
||||
if identity == "" {
|
||||
return c.Status(http.StatusBadRequest).JSON(fiber.Map{
|
||||
"code": http.StatusBadRequest, "status": false,
|
||||
"message": "an email or mobile number is required",
|
||||
"message": "a mobile number is required",
|
||||
})
|
||||
}
|
||||
if strings.TrimSpace(req.Pin) == "" && strings.TrimSpace(req.Password) == "" {
|
||||
return c.Status(http.StatusBadRequest).JSON(fiber.Map{
|
||||
"code": http.StatusBadRequest, "status": false,
|
||||
"message": "a PIN is required",
|
||||
})
|
||||
}
|
||||
|
||||
@@ -471,7 +489,7 @@ func (ctl *PosController) Login(c *fiber.Ctx) error {
|
||||
})
|
||||
}
|
||||
|
||||
log.Printf("pos login (%s): %v", req.Authname, err)
|
||||
log.Printf("pos login (%s): %v", identity, err)
|
||||
return c.Status(http.StatusForbidden).JSON(fiber.Map{
|
||||
"code": http.StatusForbidden, "status": false, "message": err.Error(),
|
||||
})
|
||||
@@ -693,7 +711,7 @@ func (ctl *PosController) PinLogin(c *fiber.Ctx) error {
|
||||
if !ok {
|
||||
return c.Status(http.StatusUnauthorized).JSON(fiber.Map{
|
||||
"code": http.StatusUnauthorized, "status": false,
|
||||
"message": "sign the terminal in with an email and password before using PIN sign-in",
|
||||
"message": "sign the terminal in with a mobile number and PIN before switching operator",
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user