check
This commit is contained in:
@@ -1,10 +1,6 @@
|
||||
import 'package:flutter_riverpod/flutter_riverpod.dart';
|
||||
|
||||
import '../../../app/providers.dart';
|
||||
import '../../../core/config/api_config.dart';
|
||||
import '../../../data/local/app_database.dart';
|
||||
import '../../../data/local/staff_dao.dart';
|
||||
import '../../../data/remote/auth_api.dart';
|
||||
import '../../../domain/entities/store_account.dart';
|
||||
|
||||
/// Sign-in state for the terminal.
|
||||
@@ -27,7 +23,6 @@ class Authenticated extends AuthState {
|
||||
required this.store,
|
||||
required this.user,
|
||||
required this.login,
|
||||
this.session,
|
||||
});
|
||||
|
||||
final StoreAccount store;
|
||||
@@ -37,25 +32,10 @@ class Authenticated extends AuthState {
|
||||
/// is allowed to show — not [user], which can be swapped at the till.
|
||||
final TerminalLogin login;
|
||||
|
||||
/// What the back office answered with. Null only on the offline demo path,
|
||||
/// where there was no back office to answer.
|
||||
///
|
||||
/// Everything downstream reads from here rather than from a constant: the
|
||||
/// bearer token for the catalogue pull and the order push, the location id
|
||||
/// they are scoped to, and the tenant name shown beside the logo.
|
||||
final LoginSession? session;
|
||||
|
||||
StaffRole get role => login.role;
|
||||
|
||||
bool get isAdmin => login == TerminalLogin.admin;
|
||||
bool get isCashier => login == TerminalLogin.cashier;
|
||||
|
||||
/// The name beside the logo: the tenant, then the outlet, then whatever the
|
||||
/// store record on this terminal says.
|
||||
String get storeName {
|
||||
final fromApi = session?.displayStoreName ?? '';
|
||||
return fromApi.isNotEmpty ? fromApi : store.name;
|
||||
}
|
||||
}
|
||||
|
||||
class AuthFailure extends AuthState {
|
||||
@@ -64,19 +44,19 @@ class AuthFailure extends AuthState {
|
||||
final String message;
|
||||
}
|
||||
|
||||
/// What this terminal is allowed to open.
|
||||
/// The two ways into this terminal.
|
||||
///
|
||||
/// No longer a credential — the back office decides the role now, and
|
||||
/// [AuthController.signIn] maps its answer onto one of these. The two values
|
||||
/// remain because the whole shell keys off them:
|
||||
/// Store-level credentials, not a person's: they are replaced wholesale when
|
||||
/// the terminal is registered against a real back office. Staff PINs — the
|
||||
/// credential that actually opens a till drawer — are not here. They live
|
||||
/// hashed in the database.
|
||||
///
|
||||
/// * [admin] runs the full shell and is the only login that can pull the
|
||||
/// The split is what the two roles are *for*, not decoration:
|
||||
///
|
||||
/// * [admin] runs the whole shell and is the only login that can pull the
|
||||
/// catalogue. Signing out leaves the products on the terminal.
|
||||
/// * [cashier] gets the billing screen and nothing else, and every way out of
|
||||
/// the session takes the catalogue with it.
|
||||
///
|
||||
/// The email and password fields are the built-in demo accounts, used only by
|
||||
/// the offline path — see [ApiConfig.allowOfflineDemoLogin].
|
||||
/// * [cashier] gets the billing screen and nothing else, and signing out
|
||||
/// takes the catalogue with it.
|
||||
enum TerminalLogin {
|
||||
admin(
|
||||
label: 'Admin',
|
||||
@@ -121,7 +101,7 @@ enum TerminalLogin {
|
||||
}
|
||||
}
|
||||
|
||||
/// The built-in accounts, used only by the offline path.
|
||||
/// Kept for the store record, which is keyed on the outlet's own address.
|
||||
class DemoCredentials {
|
||||
const DemoCredentials._();
|
||||
|
||||
@@ -132,7 +112,7 @@ class DemoCredentials {
|
||||
static const String cashierPassword = 'cashier123';
|
||||
}
|
||||
|
||||
/// Signs the terminal in against the back office and holds the session.
|
||||
/// Validates store credentials and holds the signed-in session.
|
||||
class AuthController extends StateNotifier<AuthState> {
|
||||
AuthController(this._ref) : super(const Unauthenticated());
|
||||
|
||||
@@ -147,152 +127,44 @@ class AuthController extends StateNotifier<AuthState> {
|
||||
return current is Authenticated && current.login.clearsCatalogueOnSignOut;
|
||||
}
|
||||
|
||||
/// Signs in against `POST /login`.
|
||||
///
|
||||
/// The back office decides everything the terminal then does: the role that
|
||||
/// picks admin shell or billing screen, the location the catalogue is pulled
|
||||
/// for, and the token every later call carries. Nothing here is chosen at
|
||||
/// the login screen any more.
|
||||
Future<bool> signIn({
|
||||
required String email,
|
||||
required String password,
|
||||
}) async {
|
||||
state = const Authenticating();
|
||||
|
||||
final store = _ref.read(localStoreProvider);
|
||||
// This till's own minted identity, not a fresh uuid — the back office can
|
||||
// recognise a terminal across restarts and refuse one it has not
|
||||
// registered.
|
||||
final deviceId = store.isReady ? store.terminal.deviceId : 'unopened';
|
||||
// Stand-in for the network round trip.
|
||||
await Future<void>.delayed(const Duration(milliseconds: 600));
|
||||
|
||||
LoginSession session;
|
||||
try {
|
||||
session = await _ref.read(authApiProvider).login(
|
||||
authname: email,
|
||||
password: password,
|
||||
deviceId: deviceId,
|
||||
);
|
||||
} on ApiException catch (e) {
|
||||
// A refusal is final. Only a shop with no line at all may fall through,
|
||||
// and only onto the built-in accounts — a wrong password must never
|
||||
// quietly become a local sign-in.
|
||||
if (ApiConfig.allowOfflineDemoLogin && e.isNetworkFault) {
|
||||
final offline = await _signInOffline(email, password);
|
||||
if (offline) return true;
|
||||
}
|
||||
state = AuthFailure(e.message);
|
||||
return false;
|
||||
}
|
||||
|
||||
try {
|
||||
await _applySession(session);
|
||||
} on Object catch (e) {
|
||||
state = AuthFailure(
|
||||
'Signed in, but this terminal could not store the store details: $e',
|
||||
);
|
||||
return false;
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
/// Writes everything the session decided into the terminal, then opens it.
|
||||
///
|
||||
/// Order matters. The store id and terminal identity are written first,
|
||||
/// because `syncConfigProvider` is derived from them and from the session —
|
||||
/// setting the session last means the catalogue and order transports are
|
||||
/// rebuilt once, already pointing at the right location with the right
|
||||
/// token.
|
||||
Future<void> _applySession(LoginSession session) async {
|
||||
final store = _ref.read(localStoreProvider);
|
||||
final catalogue = store.catalogue;
|
||||
|
||||
// 1. The outlet, as the back office describes it. These are printed on
|
||||
// every GST invoice, so they come from the server rather than from the
|
||||
// build's constants.
|
||||
await catalogue.setMeta(MetaKeys.storeId, session.storeId);
|
||||
if (session.displayStoreName.isNotEmpty) {
|
||||
await catalogue.setMeta(MetaKeys.storeName, session.displayStoreName);
|
||||
}
|
||||
if (session.address.isNotEmpty) {
|
||||
await catalogue.setMeta(MetaKeys.storeAddress, session.address);
|
||||
}
|
||||
if (session.phone.isNotEmpty) {
|
||||
await catalogue.setMeta(MetaKeys.storePhone, session.phone);
|
||||
}
|
||||
|
||||
// 2. This till now belongs to that outlet. Reloaded rather than left to a
|
||||
// restart: the cached identity is what every bill and topic reads.
|
||||
await store.identityStore.rename(storeId: session.storeId);
|
||||
await store.reloadTerminal();
|
||||
_ref.invalidate(terminalIdentityProvider);
|
||||
|
||||
// 3. The staff list, so PIN switching at the counter works against the
|
||||
// people head office actually employs.
|
||||
final me = await _syncStaff(session);
|
||||
|
||||
// 4. Open the session. syncConfigProvider watches this, so the catalogue
|
||||
// pull and the order push pick up the token and location id from here.
|
||||
final account = await _ref.read(storeRepositoryProvider).load(
|
||||
email: session.email.isEmpty ? DemoCredentials.email : session.email,
|
||||
);
|
||||
|
||||
state = Authenticated(
|
||||
store: account,
|
||||
user: me,
|
||||
login: session.isAdmin ? TerminalLogin.admin : TerminalLogin.cashier,
|
||||
session: session,
|
||||
);
|
||||
|
||||
_ref.invalidate(storeAccountProvider);
|
||||
}
|
||||
|
||||
/// Mirrors the back office's staff list onto this terminal, and returns the
|
||||
/// row for whoever just signed in.
|
||||
///
|
||||
/// Additive on purpose. Deactivating everyone the server did not mention
|
||||
/// would lock a shop out of its own till the first time the endpoint answers
|
||||
/// with an empty array — which is exactly what the sample response does.
|
||||
Future<StaffUser> _syncStaff(LoginSession session) async {
|
||||
final dao = _ref.read(localStoreProvider).staff;
|
||||
|
||||
for (final member in session.staff) {
|
||||
if (member.userId == 0) continue;
|
||||
await dao.upsertFromServer(
|
||||
id: StaffDao.serverId(member.userId),
|
||||
name: member.fullName,
|
||||
role: member.staffRole,
|
||||
pin: member.pin,
|
||||
isActive: member.isActive,
|
||||
);
|
||||
}
|
||||
|
||||
// The person who signed in may not appear in that list — `staff` comes
|
||||
// back empty for a single-operator shop. They still need a row, because
|
||||
// every bill is stamped with a staff id.
|
||||
return dao.upsertFromServer(
|
||||
id: StaffDao.serverId(session.userId),
|
||||
name: session.displayUserName,
|
||||
role: session.staffRole,
|
||||
pin: session.whoAmI?.pin,
|
||||
);
|
||||
}
|
||||
|
||||
/// The built-in accounts, for a terminal with no line to the back office.
|
||||
///
|
||||
/// Development only — see [ApiConfig.allowOfflineDemoLogin]. It reaches no
|
||||
/// server, so it sets no token: the catalogue cannot be pulled and bills
|
||||
/// cannot be pushed until a real sign-in happens.
|
||||
Future<bool> _signInOffline(String email, String password) async {
|
||||
final login = TerminalLogin.byEmail(email);
|
||||
if (login == null || password != login.password) return false;
|
||||
|
||||
final store = await _ref.read(storeRepositoryProvider).load(email: email);
|
||||
if (store.staff.isEmpty) return false;
|
||||
if (login == null) {
|
||||
state = const AuthFailure('No account is registered against that email.');
|
||||
return false;
|
||||
}
|
||||
|
||||
final opener = store.staff.firstWhere(
|
||||
if (password != login.password) {
|
||||
state = const AuthFailure('Incorrect password. Please try again.');
|
||||
return false;
|
||||
}
|
||||
|
||||
final store = await _ref.read(storeAccountProvider.future);
|
||||
final staff = store.staff;
|
||||
|
||||
if (staff.isEmpty) {
|
||||
state = const AuthFailure(
|
||||
'This terminal has no staff accounts. Reinstall to seed them.',
|
||||
);
|
||||
return false;
|
||||
}
|
||||
|
||||
// Whoever on this terminal matches the role that just signed in. Falls
|
||||
// back rather than failing: the session's permissions come from [login],
|
||||
// so a shop with no cashier row still gets a usable till — the bills are
|
||||
// just stamped with the account that is there.
|
||||
final opener = staff.firstWhere(
|
||||
(s) => s.role == login.role,
|
||||
orElse: () => store.staff.first,
|
||||
orElse: () => staff.first,
|
||||
);
|
||||
|
||||
state = Authenticated(store: store, user: opener, login: login);
|
||||
@@ -318,7 +190,6 @@ class AuthController extends StateNotifier<AuthState> {
|
||||
store: current.store,
|
||||
user: user,
|
||||
login: current.login,
|
||||
session: current.session,
|
||||
);
|
||||
return true;
|
||||
}
|
||||
@@ -338,24 +209,19 @@ class AuthController extends StateNotifier<AuthState> {
|
||||
// would keep stamping bills with an account the shop has revoked.
|
||||
user: me.isEmpty ? store.staff.first : me.first,
|
||||
login: current.login,
|
||||
session: current.session,
|
||||
);
|
||||
}
|
||||
|
||||
/// Ends the session, and — for a cashier only — the catalogue with it.
|
||||
///
|
||||
/// Every way out of a cashier session clears the products: ending a shift,
|
||||
/// and a temporary logout alike. There is no exception for stepping away for
|
||||
/// ten minutes, because the terminal is left unattended either way and the
|
||||
/// next session should bill against what the back office answers with rather
|
||||
/// than a catalogue carried over.
|
||||
/// Every cashier sign-out drops the products, whatever the reason for it.
|
||||
/// The next shift should bill against what the back office answers with,
|
||||
/// never a catalogue carried over, and a terminal left at a login screen
|
||||
/// must not be sitting on a shop's prices and stock.
|
||||
///
|
||||
/// An admin signing out is the opposite case. They have just pulled the
|
||||
/// products *so that* a cashier can pick the terminal up, so dropping the
|
||||
/// table here would make the import pointless.
|
||||
///
|
||||
/// The bearer token needs no clearing: it lives on the session, so it goes
|
||||
/// when the state does, and `syncConfigProvider` is derived from it.
|
||||
Future<void> signOut() async {
|
||||
if (clearsCatalogueOnSignOut) {
|
||||
await _ref.read(localStoreProvider).clearCatalogue();
|
||||
@@ -384,31 +250,6 @@ final currentUserProvider = Provider<StaffUser?>((ref) {
|
||||
return s is Authenticated ? s.user : null;
|
||||
});
|
||||
|
||||
/// What the back office answered with, or null before sign-in.
|
||||
///
|
||||
/// `select` rather than a plain watch: the whole sync configuration is derived
|
||||
/// from this, and rebuilding the transports on every intermediate auth state
|
||||
/// would tear down a connection mid-request.
|
||||
final apiSessionProvider = Provider<LoginSession?>((ref) {
|
||||
return ref.watch(
|
||||
authControllerProvider.select(
|
||||
(s) => s is Authenticated ? s.session : null,
|
||||
),
|
||||
);
|
||||
});
|
||||
|
||||
/// The name shown beside the logo — tenant first, then the outlet, then the
|
||||
/// store record on this terminal.
|
||||
final storeDisplayNameProvider = Provider<String>((ref) {
|
||||
final s = ref.watch(authControllerProvider);
|
||||
return s is Authenticated ? s.storeName : '';
|
||||
});
|
||||
|
||||
/// The outlet, for the line under the store name.
|
||||
final locationDisplayNameProvider = Provider<String>((ref) {
|
||||
return ref.watch(apiSessionProvider)?.locationName.trim() ?? '';
|
||||
});
|
||||
|
||||
/// Which credential is holding this session open, or null before sign-in.
|
||||
final terminalLoginProvider = Provider<TerminalLogin?>((ref) {
|
||||
final s = ref.watch(authControllerProvider);
|
||||
|
||||
Reference in New Issue
Block a user