The outlet check could not go in the middleware with the others: it scopes a request by the location it names, and this route names only a terminal code — free text minted at the till. The outlet is not known until after the lookup, so the check happens in the handler, reading the outlet off the heartbeat itself rather than off the request. Guessing "T4A9" now answers 403 instead of another shop's pending bills, takings so far today, and app version. Silent when no token is presented, in step with middleware.PosAuth: while POS_AUTH_REQUIRED is off, real tills are still calling this unauthenticated and refusing them would blank the fleet board for exactly the terminals it watches. scratch/termbackfill repairs the rows left behind by the posTerminalFor bug. The code was never lost — it is the third segment of the invoice number the till printed in the same transaction — so this derives rather than guesses, and refuses to write a code that outlet has never filed a bill under. 39 of 40 recovered; the holdout is a synthetic proof bill whose only sibling is itself, and unverifiable codes stay blank rather than becoming plausible. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
65 lines
2.1 KiB
Go
65 lines
2.1 KiB
Go
// Read-only audit of terminalid coverage on pos_orders.
|
|
//
|
|
// Answers one question: are blank terminal codes still arriving, or do they all
|
|
// predate the posTerminalFor fix? Touches nothing.
|
|
//
|
|
// go run ./scratch/termaudit
|
|
package main
|
|
|
|
import (
|
|
"fmt"
|
|
"log"
|
|
"os"
|
|
|
|
"github.com/joho/godotenv"
|
|
"gorm.io/driver/postgres"
|
|
"gorm.io/gorm"
|
|
"gorm.io/gorm/logger"
|
|
)
|
|
|
|
func main() {
|
|
_ = godotenv.Load()
|
|
dsn := fmt.Sprintf("host=%s port=%s user=%s password=%s dbname=%s sslmode=disable",
|
|
os.Getenv("DB_HOST"), os.Getenv("DB_PORT"), os.Getenv("DB_USER"),
|
|
os.Getenv("DB_PASSWORD"), os.Getenv("DB_NAME"))
|
|
db, err := gorm.Open(postgres.Open(dsn), &gorm.Config{Logger: logger.Default.LogMode(logger.Silent)})
|
|
if err != nil {
|
|
log.Fatal(err)
|
|
}
|
|
|
|
var rows []struct {
|
|
Day string
|
|
Blank int
|
|
Named int
|
|
Invoice string
|
|
}
|
|
db.Raw(`SELECT to_char(receivedat,'YYYY-MM-DD') AS day,
|
|
COUNT(*) FILTER (WHERE COALESCE(terminalid,'') = '') AS blank,
|
|
COUNT(*) FILTER (WHERE COALESCE(terminalid,'') <> '') AS named,
|
|
MIN(invoicenumber) AS invoice
|
|
FROM pos_orders GROUP BY 1 ORDER BY 1`).Scan(&rows)
|
|
|
|
fmt.Printf("%-12s %7s %7s %s\n", "received", "blank", "named", "sample invoice")
|
|
for _, r := range rows {
|
|
fmt.Printf("%-12s %7d %7d %s\n", r.Day, r.Blank, r.Named, r.Invoice)
|
|
}
|
|
|
|
var last struct {
|
|
Invoicenumber string
|
|
Terminalid string
|
|
Receivedat string
|
|
}
|
|
db.Raw(`SELECT invoicenumber, COALESCE(terminalid,'') AS terminalid,
|
|
to_char(receivedat,'YYYY-MM-DD HH24:MI') AS receivedat
|
|
FROM pos_orders WHERE COALESCE(terminalid,'') = ''
|
|
ORDER BY receivedat DESC LIMIT 1`).Scan(&last)
|
|
fmt.Printf("\nnewest blank bill: %s received %s\n", last.Invoicenumber, last.Receivedat)
|
|
|
|
// Does the invoice number itself carry the terminal code? INV-2608-T5EDD-00116
|
|
var recoverable int
|
|
db.Raw(`SELECT COUNT(*) FROM pos_orders
|
|
WHERE COALESCE(terminalid,'') = ''
|
|
AND invoicenumber ~ '^INV-[0-9]+-[A-Z0-9]+-[0-9]+$'`).Scan(&recoverable)
|
|
fmt.Printf("blank bills whose invoice number encodes a terminal: %d\n", recoverable)
|
|
}
|