Sign the terminal in against the back office instead of against two constants
Sign-in compared `admin@nearle.in` / `nearle123` — a compile-time const — after a 600ms delay standing in for a network call that was never made. Two things followed, and the second was the serious one. Every install of a build shared one password, and changing it meant a rebuild. Worse: because nothing was checked with the back office, the *outlet* could not come from the sign-in. It came from a store id typed into Settings, so the till asserted which shop it belonged to and the server took its word. One field on one screen moved a terminal into another tenant's books. Now a person signs in with their own back-office account and the outlet arrives as a consequence — sealed in a signed token, checked server-side on every request, and not editable from this device. `DemoCredentials` is gone, along with the prefilled fields and the "Demo account" hint that printed the password on the login screen. The pieces: - `PosSession` — what the back office answers with. The token is opaque on purpose: the till must not parse it or reason about what it appears to say. - `SessionStore` — the whole session to the platform keystore, not SQLite. The token is a bearer credential and SQLite here is a file behind a shop counter. An expired session reads back as absent, so no caller has to remember to check. - `SyncConfig.bearerToken` — one accessor rather than the same `??` at each call site, because the request that forgot it would be the one silently sending no credentials. The session beats a static API key: the key says the request came from our fleet, the session says which outlet it came from, and only the second can stop a till reaching another tenant's books. - Restore runs in `syncBootstrapProvider` *before* the engine starts. A drain that began first would upload the day's bills unauthenticated. A till trades all day; a reboot mid-shift must not put a login screen in front of a queue. - An outlet picker, shown only when the account genuinely reaches several. Not dismissable — defaulting silently to the first outlet is how a day's takings end up filed against the wrong shop. Store name, address, GSTIN and phone now come down with the session and are written on sign-in. They were compile-time constants, and on a GST invoice those fields are a legal requirement rather than decoration. The smoke test signs in through a fake client and inside `runAsync`: sign-in reaches SQLite now, and real disk I/O cannot complete on a widget test's fake clock — pumping alone leaves it suspended for ever. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
288
test/unit/pos_session_test.dart
Normal file
288
test/unit/pos_session_test.dart
Normal file
@@ -0,0 +1,288 @@
|
||||
import 'dart:convert';
|
||||
|
||||
import 'package:flutter_test/flutter_test.dart';
|
||||
import 'package:http/http.dart' as http;
|
||||
import 'package:nearle_pos/core/config/sync_config.dart';
|
||||
import 'package:nearle_pos/data/remote/pos_auth_api.dart';
|
||||
import 'package:nearle_pos/domain/entities/pos_session.dart';
|
||||
|
||||
/// Sign-in used to be two constants compiled into the app, compared after a
|
||||
/// fake 600ms delay. The store id came from a field in Settings, so a till
|
||||
/// named its own outlet and was believed — one number changed on one screen
|
||||
/// moved a terminal into another tenant's books.
|
||||
///
|
||||
/// These cover the replacement: the outlet arrives *from* the back office, and
|
||||
/// everything the till does with that answer.
|
||||
|
||||
void main() {
|
||||
group('a session read off the wire', () {
|
||||
test('takes its outlet from the back office, not from the till', () {
|
||||
final session = PosSession.fromJson({
|
||||
'token': 'abc.def',
|
||||
'expires_at': '2026-09-05T10:00:00Z',
|
||||
'user_id': 1229,
|
||||
'full_name': 'Selvapuram',
|
||||
'tenant_id': 1087,
|
||||
'tenant_name': 'Ragul Stores',
|
||||
'store_id': '1135',
|
||||
'location_id': 1135,
|
||||
'location_name': 'Ragul stores Selvapuram',
|
||||
});
|
||||
|
||||
expect(session.storeId, '1135');
|
||||
expect(session.locationId, 1135);
|
||||
expect(session.tenantId, 1087);
|
||||
});
|
||||
|
||||
test('reads an id whether it arrives quoted or bare', () {
|
||||
// The backend sends `location_id` as a number and `store_id` as a string
|
||||
// for the same value. A till that accepted only one shape would read zero
|
||||
// for the other — which looks like "no outlet" rather than like a bug.
|
||||
final quoted = PosSession.fromJson({
|
||||
'location_id': '1135',
|
||||
'token': 't',
|
||||
'expires_at': '2026-09-05T10:00:00Z',
|
||||
});
|
||||
final bare = PosSession.fromJson({
|
||||
'location_id': 1135,
|
||||
'token': 't',
|
||||
'expires_at': '2026-09-05T10:00:00Z',
|
||||
});
|
||||
|
||||
expect(quoted.locationId, 1135);
|
||||
expect(bare.locationId, 1135);
|
||||
});
|
||||
|
||||
test('falls back to the location id when no store id is sent', () {
|
||||
final session = PosSession.fromJson({
|
||||
'token': 't',
|
||||
'expires_at': '2026-09-05T10:00:00Z',
|
||||
'location_id': 1135,
|
||||
});
|
||||
|
||||
expect(session.storeId, '1135');
|
||||
});
|
||||
|
||||
test('an unreadable expiry counts as already finished', () {
|
||||
// Guessing "valid" here would keep a till sending a token the server
|
||||
// stopped honouring hours ago, and reading the resulting refusals as a
|
||||
// server fault.
|
||||
final session = PosSession.fromJson({
|
||||
'token': 't',
|
||||
'location_id': 1135,
|
||||
'expires_at': 'not a date',
|
||||
});
|
||||
|
||||
expect(session.isValidAt(DateTime.now()), isFalse);
|
||||
});
|
||||
|
||||
test('survives a round trip through storage', () {
|
||||
final original = PosSession.fromJson({
|
||||
'token': 'abc.def',
|
||||
'expires_at': '2026-09-05T10:00:00Z',
|
||||
'user_id': 1305,
|
||||
'full_name': 'Gokul R',
|
||||
'email': 'raguladmin@example.test',
|
||||
'tenant_id': 1087,
|
||||
'tenant_name': 'Ragul Stores',
|
||||
'store_id': '1097',
|
||||
'location_id': 1097,
|
||||
'location_name': 'Ragul stores',
|
||||
'gstin': '33AABCU9603R1ZM',
|
||||
'locations': [
|
||||
{'location_id': 1097, 'location_name': 'Ragul stores'},
|
||||
{'location_id': 1135, 'location_name': 'Ragul stores Selvapuram'},
|
||||
],
|
||||
});
|
||||
|
||||
final restored = PosSession.fromJson(
|
||||
jsonDecode(jsonEncode(original.toJson())) as Map<String, Object?>,
|
||||
);
|
||||
|
||||
expect(restored.token, original.token);
|
||||
expect(restored.locationId, original.locationId);
|
||||
expect(restored.gstin, original.gstin);
|
||||
expect(restored.outlets.length, 2);
|
||||
expect(restored.expiresAt.toUtc(), original.expiresAt.toUtc());
|
||||
});
|
||||
|
||||
test('offers a choice only when there is one', () {
|
||||
final single = PosSession.fromJson({
|
||||
'token': 't',
|
||||
'expires_at': '2026-09-05T10:00:00Z',
|
||||
'location_id': 1135,
|
||||
'locations': [
|
||||
{'location_id': 1135, 'location_name': 'Selvapuram'},
|
||||
],
|
||||
});
|
||||
final several = PosSession.fromJson({
|
||||
'token': 't',
|
||||
'expires_at': '2026-09-05T10:00:00Z',
|
||||
'location_id': 1097,
|
||||
'locations': [
|
||||
{'location_id': 1097, 'location_name': 'Ragul stores'},
|
||||
{'location_id': 1135, 'location_name': 'Selvapuram'},
|
||||
],
|
||||
});
|
||||
|
||||
expect(single.hasChoiceOfOutlet, isFalse);
|
||||
expect(several.hasChoiceOfOutlet, isTrue);
|
||||
});
|
||||
});
|
||||
|
||||
group('the session is what authenticates a request', () {
|
||||
test('takes precedence over a static api key', () {
|
||||
// The key says "this came from our fleet". The session says which outlet
|
||||
// it came from — and only the second can stop a till reaching another
|
||||
// tenant's books.
|
||||
const config = SyncConfig(
|
||||
apiKey: 'fleet-wide-key',
|
||||
sessionToken: 'per-user-session',
|
||||
);
|
||||
|
||||
expect(config.bearerToken, 'per-user-session');
|
||||
});
|
||||
|
||||
test('falls back to the api key before a terminal has signed in', () {
|
||||
const config = SyncConfig(apiKey: 'fleet-wide-key');
|
||||
|
||||
expect(config.bearerToken, 'fleet-wide-key');
|
||||
});
|
||||
|
||||
test('an emptied session does not authenticate as itself', () {
|
||||
// Sign-out clears the token by writing an empty string rather than by
|
||||
// rebuilding the config. If that read as a credential, a signed-out till
|
||||
// would keep uploading as the shop that signed in this morning.
|
||||
const config = SyncConfig(sessionToken: '', apiKey: '');
|
||||
|
||||
expect(config.bearerToken, isNull);
|
||||
});
|
||||
});
|
||||
|
||||
group('signing in against the back office', () {
|
||||
PosAuthApi apiReturning(int status, Object body) => PosAuthApi(
|
||||
baseUrl: 'https://example.invalid/pos',
|
||||
client: MockClient(
|
||||
(_) async => http.Response(jsonEncode(body), status,
|
||||
headers: {'content-type': 'application/json'}),
|
||||
),
|
||||
);
|
||||
|
||||
test('returns the outlet the back office named', () async {
|
||||
final api = apiReturning(200, {
|
||||
'code': 200,
|
||||
'status': true,
|
||||
'details': {
|
||||
'token': 'abc.def',
|
||||
'expires_at': '2026-09-05T10:00:00Z',
|
||||
'location_id': 1135,
|
||||
'store_id': '1135',
|
||||
'location_name': 'Ragul stores Selvapuram',
|
||||
},
|
||||
});
|
||||
|
||||
final session = await api.login(authname: 'a@b.test', password: 'pw');
|
||||
|
||||
expect(session.storeId, '1135');
|
||||
expect(session.token, 'abc.def');
|
||||
});
|
||||
|
||||
test('a wrong password is reported as one worth re-typing', () async {
|
||||
final api = apiReturning(401, {
|
||||
'code': 401,
|
||||
'status': false,
|
||||
'message': 'those sign-in details were not recognised',
|
||||
});
|
||||
|
||||
await expectLater(
|
||||
api.login(authname: 'a@b.test', password: 'wrong'),
|
||||
throwsA(
|
||||
isA<PosAuthException>()
|
||||
.having((e) => e.isCredentialFailure, 'credential failure', true),
|
||||
),
|
||||
);
|
||||
});
|
||||
|
||||
test('a refused outlet is not reported as a wrong password', () async {
|
||||
// 403 is a real account that may not open this till. Telling someone to
|
||||
// re-type a password that was correct sends them round a loop.
|
||||
final api = apiReturning(403, {
|
||||
'code': 403,
|
||||
'status': false,
|
||||
'message': 'this account cannot open a till at outlet 1185',
|
||||
});
|
||||
|
||||
await expectLater(
|
||||
api.login(authname: 'a@b.test', password: 'pw'),
|
||||
throwsA(
|
||||
isA<PosAuthException>()
|
||||
.having((e) => e.isCredentialFailure, 'credential failure', false),
|
||||
),
|
||||
);
|
||||
});
|
||||
|
||||
test('a session with no token is refused rather than saved', () async {
|
||||
// Saving it would fail against every later request instead of here, which
|
||||
// is much harder to diagnose from a shop floor.
|
||||
final api = apiReturning(200, {
|
||||
'code': 200,
|
||||
'status': true,
|
||||
'details': {'location_id': 1135, 'expires_at': '2026-09-05T10:00:00Z'},
|
||||
});
|
||||
|
||||
await expectLater(
|
||||
api.login(authname: 'a@b.test', password: 'pw'),
|
||||
throwsA(isA<PosAuthException>()),
|
||||
);
|
||||
});
|
||||
|
||||
test('a session naming no outlet is refused', () async {
|
||||
final api = apiReturning(200, {
|
||||
'code': 200,
|
||||
'status': true,
|
||||
'details': {'token': 'abc.def', 'expires_at': '2026-09-05T10:00:00Z'},
|
||||
});
|
||||
|
||||
await expectLater(
|
||||
api.login(authname: 'a@b.test', password: 'pw'),
|
||||
throwsA(isA<PosAuthException>()),
|
||||
);
|
||||
});
|
||||
|
||||
test('an unconfigured terminal says so instead of failing obscurely',
|
||||
() async {
|
||||
final api = PosAuthApi(baseUrl: '');
|
||||
|
||||
await expectLater(
|
||||
api.login(authname: 'a@b.test', password: 'pw'),
|
||||
throwsA(
|
||||
isA<PosAuthException>().having(
|
||||
(e) => e.message,
|
||||
'message',
|
||||
contains('no back office configured'),
|
||||
),
|
||||
),
|
||||
);
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
/// A client answering with one canned response.
|
||||
///
|
||||
/// Hand-rolled rather than pulled from `http/testing.dart` so the test suite
|
||||
/// does not gain a dependency for four lines.
|
||||
class MockClient extends http.BaseClient {
|
||||
MockClient(this._handler);
|
||||
|
||||
final Future<http.Response> Function(http.BaseRequest) _handler;
|
||||
|
||||
@override
|
||||
Future<http.StreamedResponse> send(http.BaseRequest request) async {
|
||||
final response = await _handler(request);
|
||||
return http.StreamedResponse(
|
||||
Stream.value(response.bodyBytes),
|
||||
response.statusCode,
|
||||
headers: response.headers,
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -5,10 +5,11 @@ import 'package:google_fonts/google_fonts.dart';
|
||||
import 'package:nearle_pos/app/app.dart';
|
||||
import 'package:nearle_pos/data/datasources/local_store.dart';
|
||||
import 'package:nearle_pos/data/datasources/seed_data.dart';
|
||||
import 'package:nearle_pos/data/remote/pos_auth_api.dart';
|
||||
import 'package:nearle_pos/domain/entities/pos_session.dart';
|
||||
import 'package:nearle_pos/app/providers.dart';
|
||||
import 'package:nearle_pos/domain/entities/shift_report.dart';
|
||||
import 'package:nearle_pos/domain/entities/store_account.dart';
|
||||
import 'package:nearle_pos/presentation/auth/providers/auth_controller.dart';
|
||||
import 'package:nearle_pos/presentation/pos/providers/cart_controller.dart';
|
||||
import 'package:nearle_pos/presentation/pos/screens/pos_dashboard_screen.dart';
|
||||
import 'package:nearle_pos/presentation/sync/providers/sync_controller.dart';
|
||||
@@ -35,7 +36,7 @@ void main() {
|
||||
const testStore = StoreAccount(
|
||||
id: 'store-001',
|
||||
name: 'Nearle Daily',
|
||||
email: DemoCredentials.email,
|
||||
email: 'manager@ragulstores.test',
|
||||
address: '1 Test Street',
|
||||
gstin: '33AABCU9603R1ZM',
|
||||
phone: '9840000000',
|
||||
@@ -65,6 +66,12 @@ void main() {
|
||||
// fail on a screen that never arrived.
|
||||
storeAccountProvider.overrideWith((ref) async => testStore),
|
||||
|
||||
// Sign-in is a network call now — a person's own back-office account
|
||||
// rather than two constants compiled into the build. A widget test
|
||||
// must not depend on a live endpoint, so the client is swapped for
|
||||
// one that answers with a fixed session.
|
||||
posAuthApiProvider.overrideWithValue(_FakePosAuthApi()),
|
||||
|
||||
// Catalogue reads come from the in-memory cache and resolve on the
|
||||
// spot, but these four go to SQLite. Real disk I/O cannot be driven
|
||||
// by the fake clock a widget test runs on: sqflite's own lock-warning
|
||||
@@ -96,11 +103,20 @@ void main() {
|
||||
|
||||
Future<void> signIn(WidgetTester tester) async {
|
||||
final fields = find.byType(TextFormField);
|
||||
await tester.enterText(fields.first, DemoCredentials.email);
|
||||
await tester.enterText(fields.at(1), DemoCredentials.password);
|
||||
await tester.enterText(fields.first, _testEmail);
|
||||
await tester.enterText(fields.at(1), _testPassword);
|
||||
await tester.pump();
|
||||
|
||||
await tester.tap(find.text('Sign in').last);
|
||||
// Sign-in reaches SQLite now: it writes the outlet the back office named
|
||||
// and the store details a receipt is legally required to carry, before the
|
||||
// shell opens. Real disk I/O cannot complete on a widget test's fake clock,
|
||||
// so the tap runs inside runAsync — pumping alone leaves the sign-in
|
||||
// suspended for ever and every later assertion fails on a screen that never
|
||||
// arrived.
|
||||
await tester.runAsync(() async {
|
||||
await tester.tap(find.text('Sign in').last);
|
||||
await Future<void>.delayed(const Duration(milliseconds: 200));
|
||||
});
|
||||
await settle(tester);
|
||||
}
|
||||
|
||||
@@ -191,3 +207,52 @@ void main() {
|
||||
expect(tester.takeException(), isNull);
|
||||
});
|
||||
}
|
||||
|
||||
const _testEmail = 'manager@ragulstores.test';
|
||||
const _testPassword = 'correct-horse';
|
||||
|
||||
/// A back office that accepts one account and refuses everything else.
|
||||
///
|
||||
/// Subclasses rather than reimplements an interface because the real client is
|
||||
/// concrete — and answering a wrong password correctly matters here: the login
|
||||
/// screen's failure path is part of what these tests cover.
|
||||
class _FakePosAuthApi extends PosAuthApi {
|
||||
_FakePosAuthApi() : super(baseUrl: 'https://example.invalid/pos');
|
||||
|
||||
@override
|
||||
Future<PosSession> login({
|
||||
required String authname,
|
||||
required String password,
|
||||
String? terminalId,
|
||||
String? deviceId,
|
||||
int? locationId,
|
||||
int? configId,
|
||||
}) async {
|
||||
if (authname.trim() != _testEmail || password != _testPassword) {
|
||||
throw const PosAuthException(
|
||||
'those sign-in details were not recognised',
|
||||
isCredentialFailure: true,
|
||||
);
|
||||
}
|
||||
|
||||
return PosSession(
|
||||
token: 'test-session-token',
|
||||
expiresAt: DateTime.now().add(const Duration(days: 30)),
|
||||
userId: 1229,
|
||||
fullName: 'Test Manager',
|
||||
email: _testEmail,
|
||||
roleId: 0,
|
||||
tenantId: 1087,
|
||||
tenantName: 'Ragul Stores',
|
||||
storeId: '1135',
|
||||
locationId: 1135,
|
||||
locationName: 'Ragul stores Selvapuram',
|
||||
outlets: const [
|
||||
PosOutlet(locationId: 1135, locationName: 'Ragul stores Selvapuram'),
|
||||
],
|
||||
);
|
||||
}
|
||||
|
||||
@override
|
||||
void dispose() {}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user