Sign the terminal in against the back office instead of against two constants

Sign-in compared `admin@nearle.in` / `nearle123` — a compile-time const — after
a 600ms delay standing in for a network call that was never made. Two things
followed, and the second was the serious one.

Every install of a build shared one password, and changing it meant a rebuild.
Worse: because nothing was checked with the back office, the *outlet* could not
come from the sign-in. It came from a store id typed into Settings, so the till
asserted which shop it belonged to and the server took its word. One field on
one screen moved a terminal into another tenant's books.

Now a person signs in with their own back-office account and the outlet arrives
as a consequence — sealed in a signed token, checked server-side on every
request, and not editable from this device. `DemoCredentials` is gone, along
with the prefilled fields and the "Demo account" hint that printed the password
on the login screen.

The pieces:

- `PosSession` — what the back office answers with. The token is opaque on
  purpose: the till must not parse it or reason about what it appears to say.
- `SessionStore` — the whole session to the platform keystore, not SQLite. The
  token is a bearer credential and SQLite here is a file behind a shop counter.
  An expired session reads back as absent, so no caller has to remember to
  check.
- `SyncConfig.bearerToken` — one accessor rather than the same `??` at each
  call site, because the request that forgot it would be the one silently
  sending no credentials. The session beats a static API key: the key says the
  request came from our fleet, the session says which outlet it came from, and
  only the second can stop a till reaching another tenant's books.
- Restore runs in `syncBootstrapProvider` *before* the engine starts. A drain
  that began first would upload the day's bills unauthenticated. A till trades
  all day; a reboot mid-shift must not put a login screen in front of a queue.
- An outlet picker, shown only when the account genuinely reaches several. Not
  dismissable — defaulting silently to the first outlet is how a day's takings
  end up filed against the wrong shop.

Store name, address, GSTIN and phone now come down with the session and are
written on sign-in. They were compile-time constants, and on a GST invoice
those fields are a legal requirement rather than decoration.

The smoke test signs in through a fake client and inside `runAsync`: sign-in
reaches SQLite now, and real disk I/O cannot complete on a widget test's fake
clock — pumping alone leaves it suspended for ever.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Suriya
2026-08-06 15:46:59 +05:30
parent 908058038a
commit b5b2047bcd
12 changed files with 1097 additions and 93 deletions

View File

@@ -5,10 +5,11 @@ import 'package:google_fonts/google_fonts.dart';
import 'package:nearle_pos/app/app.dart';
import 'package:nearle_pos/data/datasources/local_store.dart';
import 'package:nearle_pos/data/datasources/seed_data.dart';
import 'package:nearle_pos/data/remote/pos_auth_api.dart';
import 'package:nearle_pos/domain/entities/pos_session.dart';
import 'package:nearle_pos/app/providers.dart';
import 'package:nearle_pos/domain/entities/shift_report.dart';
import 'package:nearle_pos/domain/entities/store_account.dart';
import 'package:nearle_pos/presentation/auth/providers/auth_controller.dart';
import 'package:nearle_pos/presentation/pos/providers/cart_controller.dart';
import 'package:nearle_pos/presentation/pos/screens/pos_dashboard_screen.dart';
import 'package:nearle_pos/presentation/sync/providers/sync_controller.dart';
@@ -35,7 +36,7 @@ void main() {
const testStore = StoreAccount(
id: 'store-001',
name: 'Nearle Daily',
email: DemoCredentials.email,
email: 'manager@ragulstores.test',
address: '1 Test Street',
gstin: '33AABCU9603R1ZM',
phone: '9840000000',
@@ -65,6 +66,12 @@ void main() {
// fail on a screen that never arrived.
storeAccountProvider.overrideWith((ref) async => testStore),
// Sign-in is a network call now — a person's own back-office account
// rather than two constants compiled into the build. A widget test
// must not depend on a live endpoint, so the client is swapped for
// one that answers with a fixed session.
posAuthApiProvider.overrideWithValue(_FakePosAuthApi()),
// Catalogue reads come from the in-memory cache and resolve on the
// spot, but these four go to SQLite. Real disk I/O cannot be driven
// by the fake clock a widget test runs on: sqflite's own lock-warning
@@ -96,11 +103,20 @@ void main() {
Future<void> signIn(WidgetTester tester) async {
final fields = find.byType(TextFormField);
await tester.enterText(fields.first, DemoCredentials.email);
await tester.enterText(fields.at(1), DemoCredentials.password);
await tester.enterText(fields.first, _testEmail);
await tester.enterText(fields.at(1), _testPassword);
await tester.pump();
await tester.tap(find.text('Sign in').last);
// Sign-in reaches SQLite now: it writes the outlet the back office named
// and the store details a receipt is legally required to carry, before the
// shell opens. Real disk I/O cannot complete on a widget test's fake clock,
// so the tap runs inside runAsync — pumping alone leaves the sign-in
// suspended for ever and every later assertion fails on a screen that never
// arrived.
await tester.runAsync(() async {
await tester.tap(find.text('Sign in').last);
await Future<void>.delayed(const Duration(milliseconds: 200));
});
await settle(tester);
}
@@ -191,3 +207,52 @@ void main() {
expect(tester.takeException(), isNull);
});
}
const _testEmail = 'manager@ragulstores.test';
const _testPassword = 'correct-horse';
/// A back office that accepts one account and refuses everything else.
///
/// Subclasses rather than reimplements an interface because the real client is
/// concrete — and answering a wrong password correctly matters here: the login
/// screen's failure path is part of what these tests cover.
class _FakePosAuthApi extends PosAuthApi {
_FakePosAuthApi() : super(baseUrl: 'https://example.invalid/pos');
@override
Future<PosSession> login({
required String authname,
required String password,
String? terminalId,
String? deviceId,
int? locationId,
int? configId,
}) async {
if (authname.trim() != _testEmail || password != _testPassword) {
throw const PosAuthException(
'those sign-in details were not recognised',
isCredentialFailure: true,
);
}
return PosSession(
token: 'test-session-token',
expiresAt: DateTime.now().add(const Duration(days: 30)),
userId: 1229,
fullName: 'Test Manager',
email: _testEmail,
roleId: 0,
tenantId: 1087,
tenantName: 'Ragul Stores',
storeId: '1135',
locationId: 1135,
locationName: 'Ragul stores Selvapuram',
outlets: const [
PosOutlet(locationId: 1135, locationName: 'Ragul stores Selvapuram'),
],
);
}
@override
void dispose() {}
}