Sign-in compared `admin@nearle.in` / `nearle123` — a compile-time const — after a 600ms delay standing in for a network call that was never made. Two things followed, and the second was the serious one. Every install of a build shared one password, and changing it meant a rebuild. Worse: because nothing was checked with the back office, the *outlet* could not come from the sign-in. It came from a store id typed into Settings, so the till asserted which shop it belonged to and the server took its word. One field on one screen moved a terminal into another tenant's books. Now a person signs in with their own back-office account and the outlet arrives as a consequence — sealed in a signed token, checked server-side on every request, and not editable from this device. `DemoCredentials` is gone, along with the prefilled fields and the "Demo account" hint that printed the password on the login screen. The pieces: - `PosSession` — what the back office answers with. The token is opaque on purpose: the till must not parse it or reason about what it appears to say. - `SessionStore` — the whole session to the platform keystore, not SQLite. The token is a bearer credential and SQLite here is a file behind a shop counter. An expired session reads back as absent, so no caller has to remember to check. - `SyncConfig.bearerToken` — one accessor rather than the same `??` at each call site, because the request that forgot it would be the one silently sending no credentials. The session beats a static API key: the key says the request came from our fleet, the session says which outlet it came from, and only the second can stop a till reaching another tenant's books. - Restore runs in `syncBootstrapProvider` *before* the engine starts. A drain that began first would upload the day's bills unauthenticated. A till trades all day; a reboot mid-shift must not put a login screen in front of a queue. - An outlet picker, shown only when the account genuinely reaches several. Not dismissable — defaulting silently to the first outlet is how a day's takings end up filed against the wrong shop. Store name, address, GSTIN and phone now come down with the session and are written on sign-in. They were compile-time constants, and on a GST invoice those fields are a legal requirement rather than decoration. The smoke test signs in through a fake client and inside `runAsync`: sign-in reaches SQLite now, and real disk I/O cannot complete on a widget test's fake clock — pumping alone leaves it suspended for ever. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
266 lines
8.7 KiB
Dart
266 lines
8.7 KiB
Dart
import 'package:flutter_riverpod/flutter_riverpod.dart';
|
|
|
|
import '../../../app/providers.dart';
|
|
import '../../../data/remote/pos_auth_api.dart';
|
|
import '../../../domain/entities/pos_session.dart';
|
|
import '../../../domain/entities/store_account.dart';
|
|
|
|
/// Sign-in state for the terminal.
|
|
sealed class AuthState {
|
|
const AuthState();
|
|
|
|
bool get isAuthenticated => this is Authenticated;
|
|
}
|
|
|
|
class Unauthenticated extends AuthState {
|
|
const Unauthenticated();
|
|
}
|
|
|
|
class Authenticating extends AuthState {
|
|
const Authenticating();
|
|
}
|
|
|
|
class Authenticated extends AuthState {
|
|
const Authenticated({required this.store, required this.user});
|
|
|
|
final StoreAccount store;
|
|
final StaffUser user;
|
|
}
|
|
|
|
class AuthFailure extends AuthState {
|
|
const AuthFailure(this.message);
|
|
|
|
final String message;
|
|
}
|
|
|
|
/// Signs the terminal in against the back office and holds the session.
|
|
///
|
|
/// This used to compare against two constants compiled into the app —
|
|
/// `admin@nearle.in` / `nearle123` — with a 600ms delay standing in for a
|
|
/// network call that was never made. Two things were wrong with that, and the
|
|
/// second was the serious one:
|
|
///
|
|
/// 1. every install of a build shared one password, and changing it meant a
|
|
/// rebuild; and
|
|
/// 2. because nothing was checked with the back office, the *outlet* could not
|
|
/// come from the sign-in. It came from a store id typed into Settings — so
|
|
/// a till named its own shop and was believed, and one number changed on
|
|
/// one screen moved a terminal into another tenant's books.
|
|
///
|
|
/// Now a person signs in with their own back-office account, and the outlet
|
|
/// arrives as a consequence: sealed in a signed token, checked server-side on
|
|
/// every request, and not editable from this device.
|
|
class AuthController extends StateNotifier<AuthState> {
|
|
AuthController(this._ref) : super(const Unauthenticated());
|
|
|
|
final Ref _ref;
|
|
|
|
/// The back office's answer to the last sign-in, if there is one.
|
|
///
|
|
/// Held so the outlet picker can offer a proprietor their other shops without
|
|
/// asking for the password a second time.
|
|
PosSession? _session;
|
|
PosSession? get session => _session;
|
|
|
|
/// Restores a session saved on a previous run.
|
|
///
|
|
/// Called at start-up so a till that was rebooted mid-shift comes back
|
|
/// trading rather than showing a login screen to a queue of customers.
|
|
/// Returns false when there is nothing usable, which includes an expired
|
|
/// session — [SessionStore] treats those as absent.
|
|
Future<bool> restore() async {
|
|
final saved = await _ref.read(sessionStoreProvider).read();
|
|
if (saved == null) return false;
|
|
|
|
await _adopt(saved);
|
|
return state is Authenticated;
|
|
}
|
|
|
|
Future<bool> signIn({
|
|
required String email,
|
|
required String password,
|
|
int? locationId,
|
|
}) async {
|
|
state = const Authenticating();
|
|
|
|
final terminal = _ref.read(terminalIdentityProvider);
|
|
|
|
final PosSession session;
|
|
try {
|
|
session = await _ref.read(posAuthApiProvider).login(
|
|
authname: email,
|
|
password: password,
|
|
terminalId: terminal.code,
|
|
deviceId: terminal.deviceId,
|
|
locationId: locationId,
|
|
);
|
|
} on PosAuthException catch (e) {
|
|
state = AuthFailure(e.message);
|
|
return false;
|
|
} on Object {
|
|
state = const AuthFailure(
|
|
'Sign-in failed for an unexpected reason. Please try again.',
|
|
);
|
|
return false;
|
|
}
|
|
|
|
await _ref.read(sessionStoreProvider).write(session);
|
|
await _adopt(session);
|
|
|
|
return state is Authenticated;
|
|
}
|
|
|
|
/// Moves this terminal to another of the signed-in account's outlets.
|
|
///
|
|
/// A fresh sign-in rather than a local switch, because the outlet is inside
|
|
/// the signed token: the back office has to issue a new one, and re-checking
|
|
/// entitlement at that moment is the point. Requires the password again,
|
|
/// which is correct — moving a till between shops changes whose books it
|
|
/// writes to.
|
|
Future<bool> switchOutlet({
|
|
required String password,
|
|
required int locationId,
|
|
}) async {
|
|
final current = _session;
|
|
if (current == null) return false;
|
|
|
|
return signIn(
|
|
email: current.email.isNotEmpty ? current.email : current.fullName,
|
|
password: password,
|
|
locationId: locationId,
|
|
);
|
|
}
|
|
|
|
/// Adopts a session: points the terminal at its outlet, then opens it.
|
|
///
|
|
/// Order matters. The store id and token are written *before* the catalogue
|
|
/// or any uplink can run, so a terminal can never spend even one request
|
|
/// pointed at the outlet it had yesterday while claiming to be signed in as
|
|
/// today's.
|
|
Future<void> _adopt(PosSession session) async {
|
|
_session = session;
|
|
|
|
await _ref.read(localStoreProvider).identityStore.rename(
|
|
storeId: session.storeId,
|
|
);
|
|
_ref.invalidate(terminalIdentityProvider);
|
|
|
|
_ref.read(syncConfigProvider.notifier).state =
|
|
_ref.read(syncConfigProvider).copyWith(
|
|
storeId: session.storeId,
|
|
sessionToken: session.token,
|
|
);
|
|
|
|
// Store details for the receipt come from the back office now, not from
|
|
// constants compiled into the build. A GSTIN is a legal requirement on a
|
|
// tax invoice; it should not need a rebuild to correct.
|
|
await _ref.read(storeRepositoryProvider).save(
|
|
name: session.locationName.isNotEmpty
|
|
? session.locationName
|
|
: session.tenantName,
|
|
address: session.address,
|
|
gstin: session.gstin,
|
|
phone: session.phone,
|
|
);
|
|
|
|
_ref.invalidate(storeAccountProvider);
|
|
final store = await _ref.read(storeAccountProvider.future);
|
|
final staff = store.staff;
|
|
|
|
if (staff.isEmpty) {
|
|
state = const AuthFailure(
|
|
'This terminal has no staff accounts. Reinstall to seed them.',
|
|
);
|
|
return;
|
|
}
|
|
|
|
// The first admin, or whoever is there. A person switches to their own
|
|
// account at the till.
|
|
final opener = staff.firstWhere(
|
|
(s) => s.role == StaffRole.admin,
|
|
orElse: () => staff.first,
|
|
);
|
|
|
|
state = Authenticated(store: store, user: opener);
|
|
}
|
|
|
|
/// Switches the active operator, checking their PIN.
|
|
///
|
|
/// Every bill is stamped with whoever is active, so this is the boundary that
|
|
/// decides who a sale is attributed to — it cannot be a bare selection from a
|
|
/// list.
|
|
Future<bool> switchUser(String pin) async {
|
|
final current = state;
|
|
if (current is! Authenticated) return false;
|
|
|
|
final store = _ref.read(localStoreProvider);
|
|
final user = await store.staff.authenticate(pin);
|
|
if (user == null) return false;
|
|
|
|
state = Authenticated(store: current.store, user: user);
|
|
return true;
|
|
}
|
|
|
|
/// Re-reads the store after staff or details change, keeping the session.
|
|
Future<void> refreshStore() async {
|
|
final current = state;
|
|
if (current is! Authenticated) return;
|
|
|
|
_ref.invalidate(storeAccountProvider);
|
|
final store = await _ref.read(storeAccountProvider.future);
|
|
|
|
final me = store.staff.where((s) => s.id == current.user.id);
|
|
state = Authenticated(
|
|
store: store,
|
|
// Signed out if the active operator was just deactivated — carrying on
|
|
// would keep stamping bills with an account the shop has revoked.
|
|
user: me.isEmpty ? store.staff.first : me.first,
|
|
);
|
|
}
|
|
|
|
/// The next shift should only ever bill against what the back office
|
|
/// answers with, never a catalogue instance carried over from this
|
|
/// session — so the local product table is dropped before the session
|
|
/// itself is.
|
|
///
|
|
/// The token goes with it, from the keystore and from the live configuration
|
|
/// both. Leaving it in place would let a signed-out terminal keep uploading
|
|
/// as the shop that signed in this morning.
|
|
Future<void> signOut() async {
|
|
await _ref.read(localStoreProvider).clearCatalogue();
|
|
await _ref.read(sessionStoreProvider).clear();
|
|
|
|
_ref.read(syncConfigProvider.notifier).state =
|
|
_ref.read(syncConfigProvider).copyWith(sessionToken: '');
|
|
|
|
_session = null;
|
|
state = const Unauthenticated();
|
|
}
|
|
|
|
void clearError() {
|
|
if (state is AuthFailure) state = const Unauthenticated();
|
|
}
|
|
}
|
|
|
|
final authControllerProvider = StateNotifierProvider<AuthController, AuthState>(
|
|
AuthController.new,
|
|
);
|
|
|
|
/// The signed-in store, or null before sign-in.
|
|
final currentStoreProvider = Provider<StoreAccount?>((ref) {
|
|
final s = ref.watch(authControllerProvider);
|
|
return s is Authenticated ? s.store : null;
|
|
});
|
|
|
|
/// The active operator, or null before sign-in.
|
|
final currentUserProvider = Provider<StaffUser?>((ref) {
|
|
final s = ref.watch(authControllerProvider);
|
|
return s is Authenticated ? s.user : null;
|
|
});
|
|
|
|
/// True while anyone is still on a seeded or admin-reset PIN.
|
|
final mustChangePinProvider = Provider<bool>((ref) {
|
|
final user = ref.watch(currentUserProvider);
|
|
return user?.mustChangePin ?? false;
|
|
});
|