Sign-in compared `admin@nearle.in` / `nearle123` — a compile-time const — after a 600ms delay standing in for a network call that was never made. Two things followed, and the second was the serious one. Every install of a build shared one password, and changing it meant a rebuild. Worse: because nothing was checked with the back office, the *outlet* could not come from the sign-in. It came from a store id typed into Settings, so the till asserted which shop it belonged to and the server took its word. One field on one screen moved a terminal into another tenant's books. Now a person signs in with their own back-office account and the outlet arrives as a consequence — sealed in a signed token, checked server-side on every request, and not editable from this device. `DemoCredentials` is gone, along with the prefilled fields and the "Demo account" hint that printed the password on the login screen. The pieces: - `PosSession` — what the back office answers with. The token is opaque on purpose: the till must not parse it or reason about what it appears to say. - `SessionStore` — the whole session to the platform keystore, not SQLite. The token is a bearer credential and SQLite here is a file behind a shop counter. An expired session reads back as absent, so no caller has to remember to check. - `SyncConfig.bearerToken` — one accessor rather than the same `??` at each call site, because the request that forgot it would be the one silently sending no credentials. The session beats a static API key: the key says the request came from our fleet, the session says which outlet it came from, and only the second can stop a till reaching another tenant's books. - Restore runs in `syncBootstrapProvider` *before* the engine starts. A drain that began first would upload the day's bills unauthenticated. A till trades all day; a reboot mid-shift must not put a login screen in front of a queue. - An outlet picker, shown only when the account genuinely reaches several. Not dismissable — defaulting silently to the first outlet is how a day's takings end up filed against the wrong shop. Store name, address, GSTIN and phone now come down with the session and are written on sign-in. They were compile-time constants, and on a GST invoice those fields are a legal requirement rather than decoration. The smoke test signs in through a fake client and inside `runAsync`: sign-in reaches SQLite now, and real disk I/O cannot complete on a widget test's fake clock — pumping alone leaves it suspended for ever. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
262 lines
9.6 KiB
Dart
262 lines
9.6 KiB
Dart
import 'package:flutter_riverpod/flutter_riverpod.dart';
|
|
|
|
import '../core/config/sync_config.dart';
|
|
import '../core/services/connectivity_service.dart';
|
|
import '../core/services/receipt_service.dart';
|
|
import '../core/services/sound_service.dart';
|
|
import '../data/datasources/local_store.dart';
|
|
import '../data/repositories/customer_repository_impl.dart';
|
|
import '../data/repositories/product_repository_impl.dart';
|
|
import '../data/remote/catalogue_source.dart';
|
|
import '../data/remote/http_catalogue_source.dart';
|
|
import '../data/remote/simulated_catalogue_source.dart';
|
|
import '../data/remote/http_order_transport.dart';
|
|
import '../data/remote/mqtt_order_transport.dart';
|
|
import '../data/remote/order_transport.dart';
|
|
import '../data/remote/simulated_order_transport.dart';
|
|
import '../data/repositories/store_repository_impl.dart';
|
|
import '../data/repositories/sync_repository_impl.dart';
|
|
import '../data/repositories/transaction_repository_impl.dart';
|
|
import '../data/local/session_store.dart';
|
|
import '../data/local/terminal_identity.dart';
|
|
import '../data/remote/pos_auth_api.dart';
|
|
import '../data/sync/sync_engine.dart';
|
|
import '../domain/repositories/customer_repository.dart';
|
|
import '../domain/repositories/product_repository.dart';
|
|
import '../domain/repositories/sync_repository.dart';
|
|
import '../domain/repositories/transaction_repository.dart';
|
|
import '../domain/entities/promo.dart';
|
|
import '../domain/entities/store_account.dart';
|
|
import '../domain/usecases/checkout_sale.dart';
|
|
import '../presentation/auth/providers/auth_controller.dart';
|
|
|
|
/// Root data source. Overridden in tests with an in-memory double.
|
|
final localStoreProvider = Provider<LocalStore>((ref) => LocalStore.instance);
|
|
|
|
// ---------------------------------------------------------- Repositories
|
|
final productRepositoryProvider = Provider<ProductRepository>(
|
|
(ref) => ProductRepositoryImpl(ref.watch(localStoreProvider)),
|
|
);
|
|
|
|
final customerRepositoryProvider = Provider<CustomerRepository>(
|
|
(ref) => CustomerRepositoryImpl(ref.watch(localStoreProvider)),
|
|
);
|
|
|
|
final transactionRepositoryProvider = Provider<TransactionRepository>(
|
|
(ref) => TransactionRepositoryImpl(ref.watch(localStoreProvider)),
|
|
);
|
|
|
|
/// Mirrors the Settings "Simulate offline" switch so the header can show it.
|
|
///
|
|
/// Without this the terminal claims LIVE while every call is being failed on
|
|
/// purpose, which reads as a real network fault.
|
|
final simulateOfflineProvider = StateProvider<bool>((ref) => false);
|
|
|
|
/// Where products and customers come from.
|
|
///
|
|
/// Rebuilt when the route changes, and the old one closed, so a re-pointed
|
|
/// terminal does not keep a stale client alive.
|
|
final catalogueSourceProvider = Provider<CatalogueSource>((ref) {
|
|
final config = ref.watch(syncConfigProvider);
|
|
|
|
final source = switch (config.transport) {
|
|
// MQTT carries the *notification* that the catalogue moved; the catalogue
|
|
// itself is a bulk pull, which is an HTTP job. A broker is the wrong shape
|
|
// for tens of thousands of rows.
|
|
TransportKind.http || TransportKind.mqtt =>
|
|
config.httpBaseUrl.isEmpty
|
|
? SimulatedCatalogueSource(
|
|
isOffline: () => ref.read(simulateOfflineProvider),
|
|
)
|
|
: HttpCatalogueSource(config: config),
|
|
TransportKind.simulated => SimulatedCatalogueSource(
|
|
isOffline: () => ref.read(simulateOfflineProvider),
|
|
),
|
|
};
|
|
|
|
ref.onDispose(source.dispose);
|
|
return source;
|
|
});
|
|
|
|
// ------------------------------------------------------------------- Sync
|
|
/// How this terminal reaches the back office.
|
|
///
|
|
/// Defaults to this store's live HTTP endpoint, so importing works out of the
|
|
/// box against real products rather than the offline demo catalogue.
|
|
/// Settings → Connectivity & sync → Configure re-points it to a different
|
|
/// store, endpoint, or transport without a rebuild.
|
|
///
|
|
/// Terminal id always comes from this device's own identity, never from a
|
|
/// literal — two terminals publishing on the same topic is the failure this
|
|
/// exists to prevent.
|
|
final syncConfigProvider = StateProvider<SyncConfig>((ref) {
|
|
final terminal = ref.watch(terminalIdentityProvider);
|
|
return SyncConfig(
|
|
transport: TransportKind.http,
|
|
httpBaseUrl: 'https://fiesta.nearle.app/live/api/v1/pos',
|
|
storeId: terminal.storeId,
|
|
terminalId: terminal.code,
|
|
);
|
|
});
|
|
|
|
/// Real network state, folded with the Settings offline switch.
|
|
final connectivityServiceProvider = Provider<ConnectivityService>((ref) {
|
|
final service = ConnectivityService(
|
|
isSimulatedOffline: () => ref.read(simulateOfflineProvider),
|
|
);
|
|
ref.onDispose(service.dispose);
|
|
return service;
|
|
});
|
|
|
|
/// The wire itself. Rebuilt when the configuration changes, and the old one is
|
|
/// closed so a re-pointed terminal does not keep a stale broker session open.
|
|
final orderTransportProvider = Provider<OrderTransport>((ref) {
|
|
final config = ref.watch(syncConfigProvider);
|
|
|
|
final transport = switch (config.transport) {
|
|
TransportKind.mqtt => MqttOrderTransport(config: config),
|
|
TransportKind.http => HttpOrderTransport(config: config),
|
|
TransportKind.simulated => SimulatedOrderTransport(
|
|
isOffline: () => ref.read(simulateOfflineProvider),
|
|
),
|
|
};
|
|
|
|
ref.onDispose(transport.dispose);
|
|
return transport;
|
|
});
|
|
|
|
final syncRepositoryProvider = Provider<SyncRepository>(
|
|
(ref) => SyncRepositoryImpl(
|
|
ref.watch(localStoreProvider),
|
|
ref.watch(catalogueSourceProvider),
|
|
ref.watch(orderTransportProvider),
|
|
batchSize: ref.watch(syncConfigProvider).batchSize,
|
|
),
|
|
);
|
|
|
|
/// Decides when bills are uploaded. Started once, by the app shell.
|
|
final syncEngineProvider = Provider<SyncEngine>((ref) {
|
|
final transport = ref.watch(orderTransportProvider);
|
|
|
|
final engine = SyncEngine(
|
|
repository: ref.watch(syncRepositoryProvider),
|
|
connectivity: ref.watch(connectivityServiceProvider).onlineChanges,
|
|
downlink: transport.downlink,
|
|
onCatalogueChanged: () async {
|
|
await ref.read(syncRepositoryProvider).importCatalogue();
|
|
ref.invalidate(localStoreProvider);
|
|
},
|
|
);
|
|
|
|
ref.onDispose(engine.dispose);
|
|
return engine;
|
|
});
|
|
|
|
/// Live engine state for the header pill and the events screen.
|
|
final syncEngineStateProvider = StreamProvider<SyncEngineState>((ref) {
|
|
final engine = ref.watch(syncEngineProvider);
|
|
return engine.states.map((s) => s);
|
|
});
|
|
|
|
/// Store details and staff, read from this terminal's database.
|
|
final storeRepositoryProvider = Provider<StoreRepositoryImpl>(
|
|
(ref) => StoreRepositoryImpl(ref.watch(localStoreProvider)),
|
|
);
|
|
|
|
/// Signs a terminal in against the back office.
|
|
///
|
|
/// Points at the same base URL the uplinks use, so re-pointing a terminal in
|
|
/// Settings moves its sign-in with it rather than leaving it authenticating
|
|
/// against the endpoint it used to belong to.
|
|
final posAuthApiProvider = Provider<PosAuthApi>((ref) {
|
|
final api = PosAuthApi(baseUrl: ref.watch(syncConfigProvider).httpBaseUrl);
|
|
ref.onDispose(api.dispose);
|
|
return api;
|
|
});
|
|
|
|
/// Where the signed session survives a restart.
|
|
final sessionStoreProvider = Provider<SessionStore>((ref) => SessionStore());
|
|
|
|
/// The outlet, refreshed whenever staff or details change.
|
|
///
|
|
/// The email is the signed-in account's, not a constant. It used to be
|
|
/// `DemoCredentials.email` — the same address on every install of a build,
|
|
/// which is what made the store login decorative.
|
|
final storeAccountProvider = FutureProvider<StoreAccount>(
|
|
(ref) => ref.watch(storeRepositoryProvider).load(
|
|
email: ref.watch(authControllerProvider.notifier).session?.email ?? '',
|
|
),
|
|
);
|
|
|
|
/// Campaigns stored on this terminal.
|
|
final promosProvider = FutureProvider<List<Promo>>(
|
|
(ref) => ref.watch(localStoreProvider).promos.all(),
|
|
);
|
|
|
|
/// Only the campaigns the till should be applying right now.
|
|
final activePromosProvider = FutureProvider<List<Promo>>(
|
|
(ref) => ref.watch(localStoreProvider).promos.all(activeOnly: true),
|
|
);
|
|
|
|
// ------------------------------------------------------------- Use cases
|
|
final checkoutSaleProvider = Provider<CheckoutSale>(
|
|
(ref) => CheckoutSale(
|
|
productRepository: ref.watch(productRepositoryProvider),
|
|
customerRepository: ref.watch(customerRepositoryProvider),
|
|
transactionRepository: ref.watch(transactionRepositoryProvider),
|
|
),
|
|
);
|
|
|
|
// -------------------------------------------------------------- Services
|
|
final soundServiceProvider =
|
|
Provider<SoundService>((ref) => SoundService.instance);
|
|
|
|
final receiptServiceProvider =
|
|
Provider<ReceiptService>((ref) => ReceiptService.instance);
|
|
|
|
// --------------------------------------------------------------- Session
|
|
class CashierSession {
|
|
const CashierSession({
|
|
required this.name,
|
|
required this.role,
|
|
required this.terminalId,
|
|
});
|
|
|
|
final String name;
|
|
final String role;
|
|
final String terminalId;
|
|
}
|
|
|
|
/// Identity of the physical till, read from its own database.
|
|
///
|
|
/// Falls back only before the store has opened; every real read happens after
|
|
/// `LocalStore.init`, which mints the identity if this device has never run
|
|
/// before.
|
|
final terminalIdentityProvider = Provider<TerminalIdentity>((ref) {
|
|
final store = ref.watch(localStoreProvider);
|
|
return store.isReady
|
|
? store.terminal
|
|
: const TerminalIdentity(
|
|
deviceId: 'unopened',
|
|
code: 'T0000',
|
|
name: 'Terminal',
|
|
storeId: 'store-01',
|
|
);
|
|
});
|
|
|
|
final cashierSessionProvider = StateProvider<CashierSession>((ref) {
|
|
final terminal = ref.watch(terminalIdentityProvider);
|
|
return CashierSession(
|
|
name: 'Suriya',
|
|
role: 'ADMIN',
|
|
terminalId: terminal.code,
|
|
);
|
|
});
|
|
|
|
/// Ticks once a minute to drive the header clock without rebuilding on every
|
|
/// frame.
|
|
final clockProvider = StreamProvider<DateTime>((ref) async* {
|
|
yield DateTime.now();
|
|
yield* Stream.periodic(const Duration(seconds: 20), (_) => DateTime.now());
|
|
});
|