api for health score toggle

This commit is contained in:
2026-10-05 12:07:49 +05:30
parent 97f277f424
commit fc2caffcd1
7 changed files with 358 additions and 1 deletions

View File

@@ -1008,3 +1008,44 @@ func (ctl *ProductController) RelinkCatalogue(c *fiber.Ctx) error {
}
return c.JSON(fiber.Map{"code": 200, "message": "Success", "status": true, "details": report})
}
// SetShowHealthScore turns one product's health score on or off for one shop.
//
// Scoped twice over: `middleware.WebAuth` refuses a request naming a tenant the
// session does not own — it reads `tenantid` from the body as well as the query
// — and the repository's UPDATE carries the tenant in its WHERE clause. A write
// that changes what a shopper sees should not rest on one guard being mounted
// correctly.
func (ctl *ProductController) SetShowHealthScore(c *fiber.Ctx) error {
var req struct {
Tenantid int `json:"tenantid"`
Productid int `json:"productid"`
// A POINTER so a body that forgot the field is refused rather than read
// as "turn it off". The whole point of this endpoint is the difference
// between the two.
Showhealthscore *bool `json:"showhealthscore"`
}
if err := c.BodyParser(&req); err != nil {
return c.Status(http.StatusBadRequest).JSON(fiber.Map{
"code": http.StatusBadRequest, "status": false, "message": "Invalid request body",
})
}
if req.Showhealthscore == nil {
return c.Status(http.StatusBadRequest).JSON(fiber.Map{
"code": http.StatusBadRequest, "status": false,
"message": "showhealthscore is required: send true or false.",
})
}
if err := ctl.productService.SetShowHealthScore(req.Tenantid, req.Productid, *req.Showhealthscore); err != nil {
// 409, not 500. "No such product for this business" is a fact the
// caller can act on, not a fault in the server.
return c.Status(http.StatusConflict).JSON(fiber.Map{
"code": http.StatusConflict, "status": false, "message": err.Error(),
})
}
return c.JSON(fiber.Map{
"code": http.StatusOK, "status": true, "message": "Successfully Updated",
})
}