Sign the terminal in against the back office instead of against two constants
Sign-in compared `admin@nearle.in` / `nearle123` — a compile-time const — after a 600ms delay standing in for a network call that was never made. Two things followed, and the second was the serious one. Every install of a build shared one password, and changing it meant a rebuild. Worse: because nothing was checked with the back office, the *outlet* could not come from the sign-in. It came from a store id typed into Settings, so the till asserted which shop it belonged to and the server took its word. One field on one screen moved a terminal into another tenant's books. Now a person signs in with their own back-office account and the outlet arrives as a consequence — sealed in a signed token, checked server-side on every request, and not editable from this device. `DemoCredentials` is gone, along with the prefilled fields and the "Demo account" hint that printed the password on the login screen. The pieces: - `PosSession` — what the back office answers with. The token is opaque on purpose: the till must not parse it or reason about what it appears to say. - `SessionStore` — the whole session to the platform keystore, not SQLite. The token is a bearer credential and SQLite here is a file behind a shop counter. An expired session reads back as absent, so no caller has to remember to check. - `SyncConfig.bearerToken` — one accessor rather than the same `??` at each call site, because the request that forgot it would be the one silently sending no credentials. The session beats a static API key: the key says the request came from our fleet, the session says which outlet it came from, and only the second can stop a till reaching another tenant's books. - Restore runs in `syncBootstrapProvider` *before* the engine starts. A drain that began first would upload the day's bills unauthenticated. A till trades all day; a reboot mid-shift must not put a login screen in front of a queue. - An outlet picker, shown only when the account genuinely reaches several. Not dismissable — defaulting silently to the first outlet is how a day's takings end up filed against the wrong shop. Store name, address, GSTIN and phone now come down with the session and are written on sign-in. They were compile-time constants, and on a GST invoice those fields are a legal requirement rather than decoration. The smoke test signs in through a fake client and inside `runAsync`: sign-in reaches SQLite now, and real disk I/O cannot complete on a widget test's fake clock — pumping alone leaves it suspended for ever. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -35,6 +35,7 @@ class SyncConfig {
|
||||
this.password,
|
||||
this.httpBaseUrl = '',
|
||||
this.apiKey,
|
||||
this.sessionToken,
|
||||
this.ackTimeout = const Duration(seconds: 20),
|
||||
this.batchSize = 50,
|
||||
});
|
||||
@@ -52,8 +53,38 @@ class SyncConfig {
|
||||
final String? password;
|
||||
|
||||
final String httpBaseUrl;
|
||||
|
||||
/// A static key shared by every terminal at a deployment, if one is set.
|
||||
///
|
||||
/// Predates sign-in and says nothing about *who* is at the till, so it cannot
|
||||
/// scope a request to an outlet. Kept for deployments that put one in front
|
||||
/// of the endpoint.
|
||||
final String? apiKey;
|
||||
|
||||
/// The signed session from `POST /login`, held for the trading day.
|
||||
///
|
||||
/// Distinct from [apiKey] because the two answer different questions. The key
|
||||
/// says "this request came from our fleet"; the session says "this request
|
||||
/// came from Selvapuram, signed in as Ragul, and may touch that outlet and no
|
||||
/// other". Only the second can stop a till reaching another tenant's books,
|
||||
/// which is why it takes precedence when both are present.
|
||||
final String? sessionToken;
|
||||
|
||||
/// What goes in the Authorization header.
|
||||
///
|
||||
/// One accessor rather than the same `??` repeated at each call site, because
|
||||
/// the request that forgot it would be the one silently sending no
|
||||
/// credentials at all.
|
||||
String? get bearerToken {
|
||||
final session = sessionToken?.trim();
|
||||
if (session != null && session.isNotEmpty) return session;
|
||||
|
||||
final key = apiKey?.trim();
|
||||
if (key != null && key.isNotEmpty) return key;
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
/// How long to wait for the back office to confirm a batch before treating
|
||||
/// the outcome as unknown and leaving every row pending.
|
||||
///
|
||||
@@ -148,6 +179,7 @@ class SyncConfig {
|
||||
String? password,
|
||||
String? httpBaseUrl,
|
||||
String? apiKey,
|
||||
String? sessionToken,
|
||||
Duration? ackTimeout,
|
||||
int? batchSize,
|
||||
}) =>
|
||||
@@ -162,6 +194,7 @@ class SyncConfig {
|
||||
password: password ?? this.password,
|
||||
httpBaseUrl: httpBaseUrl ?? this.httpBaseUrl,
|
||||
apiKey: apiKey ?? this.apiKey,
|
||||
sessionToken: sessionToken ?? this.sessionToken,
|
||||
ackTimeout: ackTimeout ?? this.ackTimeout,
|
||||
batchSize: batchSize ?? this.batchSize,
|
||||
);
|
||||
|
||||
Reference in New Issue
Block a user