Sign the terminal in against the back office instead of against two constants

Sign-in compared `admin@nearle.in` / `nearle123` — a compile-time const — after
a 600ms delay standing in for a network call that was never made. Two things
followed, and the second was the serious one.

Every install of a build shared one password, and changing it meant a rebuild.
Worse: because nothing was checked with the back office, the *outlet* could not
come from the sign-in. It came from a store id typed into Settings, so the till
asserted which shop it belonged to and the server took its word. One field on
one screen moved a terminal into another tenant's books.

Now a person signs in with their own back-office account and the outlet arrives
as a consequence — sealed in a signed token, checked server-side on every
request, and not editable from this device. `DemoCredentials` is gone, along
with the prefilled fields and the "Demo account" hint that printed the password
on the login screen.

The pieces:

- `PosSession` — what the back office answers with. The token is opaque on
  purpose: the till must not parse it or reason about what it appears to say.
- `SessionStore` — the whole session to the platform keystore, not SQLite. The
  token is a bearer credential and SQLite here is a file behind a shop counter.
  An expired session reads back as absent, so no caller has to remember to
  check.
- `SyncConfig.bearerToken` — one accessor rather than the same `??` at each
  call site, because the request that forgot it would be the one silently
  sending no credentials. The session beats a static API key: the key says the
  request came from our fleet, the session says which outlet it came from, and
  only the second can stop a till reaching another tenant's books.
- Restore runs in `syncBootstrapProvider` *before* the engine starts. A drain
  that began first would upload the day's bills unauthenticated. A till trades
  all day; a reboot mid-shift must not put a login screen in front of a queue.
- An outlet picker, shown only when the account genuinely reaches several. Not
  dismissable — defaulting silently to the first outlet is how a day's takings
  end up filed against the wrong shop.

Store name, address, GSTIN and phone now come down with the session and are
written on sign-in. They were compile-time constants, and on a GST invoice
those fields are a legal requirement rather than decoration.

The smoke test signs in through a fake client and inside `runAsync`: sign-in
reaches SQLite now, and real disk I/O cannot complete on a widget test's fake
clock — pumping alone leaves it suspended for ever.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Suriya
2026-08-06 15:46:59 +05:30
parent 908058038a
commit b5b2047bcd
12 changed files with 1097 additions and 93 deletions

View File

@@ -0,0 +1,81 @@
import 'dart:convert';
import 'package:flutter/foundation.dart';
import 'package:flutter_secure_storage/flutter_secure_storage.dart';
import '../../domain/entities/pos_session.dart';
/// Keeps a terminal signed in across restarts.
///
/// A till is not a browser. It signs in when a shop opens and bills for the
/// whole trading day, often on a connection that comes and goes, and it must
/// survive being rebooted mid-shift without a queue of customers waiting while
/// somebody finds the manager's password.
///
/// The whole session goes to the platform keystore rather than to SQLite. The
/// token is a bearer credential — anything holding it can bill as this shop —
/// and SQLite here is a file on a machine behind a shop counter, readable by
/// anything that can open it. The rest of the session travels with the token
/// because splitting them invites the two halves to disagree about which outlet
/// this terminal is.
class SessionStore {
SessionStore({FlutterSecureStorage? secureStorage})
: _secure = secureStorage ?? const FlutterSecureStorage();
final FlutterSecureStorage _secure;
static const _key = 'pos.session';
/// Reads the saved session, or null when there is none worth using.
///
/// An expired session is treated as absent rather than returned for the
/// caller to check. Every caller would have to make the same check, and the
/// one that forgot would send a dead token all day and read the resulting
/// 401s as a server fault.
Future<PosSession?> read({DateTime? now}) async {
final String? raw;
try {
raw = await _secure.read(key: _key);
} on Object catch (e) {
// No keystore — a headless test host, or a Linux box with no secret
// service. Signing in again is the safe way to fail.
debugPrint('Secure storage unavailable, session not loaded: $e');
return null;
}
if (raw == null || raw.isEmpty) return null;
try {
final session =
PosSession.fromJson(jsonDecode(raw) as Map<String, Object?>);
if (!session.isValidAt(now ?? DateTime.now())) return null;
if (session.token.isEmpty || session.locationId <= 0) return null;
return session;
} on Object catch (e) {
// A stored session this build cannot parse — most likely written by an
// older one. Dropped rather than repaired: a half-understood session is
// worse than none, and re-authenticating costs one screen.
debugPrint('Stored session could not be read, discarding: $e');
return null;
}
}
Future<void> write(PosSession session) async {
try {
await _secure.write(key: _key, value: jsonEncode(session.toJson()));
} on Object catch (e) {
// The terminal keeps working on the session it holds in memory; it just
// will not survive a restart. Failing the sign-in over this would close a
// shop for a keystore problem.
debugPrint('Could not persist the session: $e');
}
}
Future<void> clear() async {
try {
await _secure.delete(key: _key);
} on Object catch (e) {
debugPrint('Could not clear the session: $e');
}
}
}