pos login with the ph number and pin
This commit is contained in:
@@ -529,14 +529,19 @@ func (r *posRepository) DeactivatePosUser(tenantID, locationID, userID int) erro
|
||||
// supervisor has opened the terminal with a real password first and the guesses
|
||||
// are confined to one outlet's own staff.
|
||||
func (r *posRepository) PosLoginByPin(tenantID, locationID int, pin string) (*models.PosSession, error) {
|
||||
value, err := validatePosPin(pin)
|
||||
// posLoginPin, not validatePosPin: the latter also refuses the PINs nobody
|
||||
// should be *given*, and applying a creation rule on the way in would lock
|
||||
// out every account issued before it existed. Live data has 1234 on eleven
|
||||
// accounts and 1111 on nine.
|
||||
value, err := posLoginPin(pin)
|
||||
if err != nil {
|
||||
return nil, errPosLoginRejected
|
||||
}
|
||||
|
||||
var rows []posLoginRow
|
||||
err = r.db.Raw(`
|
||||
SELECT userid, COALESCE(password,'') AS password, COALESCE(status,'') AS status,
|
||||
SELECT userid, COALESCE(password,'') AS password, COALESCE(pin,0) AS pin,
|
||||
COALESCE(status,'') AS status,
|
||||
COALESCE(roleid,0) AS roleid, COALESCE(configid,0) AS configid,
|
||||
COALESCE(tenantid,0) AS tenantid, COALESCE(locationid,0) AS locationid,
|
||||
COALESCE(firstname,'') AS firstname, COALESCE(lastname,'') AS lastname,
|
||||
@@ -635,12 +640,16 @@ func posPhoneTaken(tx *gorm.DB, tenantID int, phone string, exceptUser int) (boo
|
||||
return count > 0, err
|
||||
}
|
||||
|
||||
// validatePosPin checks a PIN is one this schema can store faithfully.
|
||||
func validatePosPin(raw string) (int64, error) {
|
||||
// posLoginPin reads a PIN somebody has just typed at a terminal.
|
||||
//
|
||||
// Format only — four digits the column can hold, and nothing about whether the
|
||||
// PIN was a wise one to issue. That distinction is the whole reason this is
|
||||
// separate from [validatePosPin]: a rule about what may be *created* must never
|
||||
// run on the way *in*. Applied at sign-in, the guessable-PIN list below would
|
||||
// permanently lock out the eleven live accounts holding 1234 and the nine
|
||||
// holding 1111 — accounts this system itself issued before the rule existed.
|
||||
func posLoginPin(raw string) (int64, error) {
|
||||
pin := strings.TrimSpace(raw)
|
||||
if pin == "" {
|
||||
return 0, nil
|
||||
}
|
||||
|
||||
if len(pin) != 4 {
|
||||
return 0, fmt.Errorf("a PIN is exactly 4 digits")
|
||||
@@ -654,9 +663,24 @@ func validatePosPin(raw string) (int64, error) {
|
||||
// is 4 digits" would be baffling to somebody who just typed four.
|
||||
return 0, fmt.Errorf("a PIN cannot start with 0")
|
||||
}
|
||||
return value, nil
|
||||
}
|
||||
|
||||
// validatePosPin checks a PIN is one this schema can store faithfully, and one
|
||||
// worth issuing.
|
||||
func validatePosPin(raw string) (int64, error) {
|
||||
pin := strings.TrimSpace(raw)
|
||||
if pin == "" {
|
||||
return 0, nil
|
||||
}
|
||||
|
||||
value, err := posLoginPin(pin)
|
||||
if err != nil {
|
||||
return 0, err
|
||||
}
|
||||
|
||||
// The first thing anyone tries, and live data already has 1234 on eleven
|
||||
// accounts and 1111 on nine.
|
||||
// accounts and 1111 on nine. Refused at creation only — see posLoginPin.
|
||||
switch pin {
|
||||
case "1234", "1111", "0000", "2345", "3456", "4321", "9999", "2222":
|
||||
return 0, fmt.Errorf("that PIN is too easy to guess; choose another")
|
||||
|
||||
Reference in New Issue
Block a user