fix(customer-auth): register customers into the app's organization
Registration put every new customer into a hardcoded organization id, which does not exist in staging, so set-password failed on the fk_customers_organization foreign key with a 500. POST /customer-auth/register/start now takes organization_id, the organization the app is built for. It must be a UUID of an existing organization, checked before the OTP is sent; it is kept in the OTP session and set-password creates the customer there. A registration started before this change has no organization in its session and is asked to start again. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
609d434976
commit
a3cb7dd5fd
@@ -3,6 +3,7 @@ package processor
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"apskel-pos-be/internal/contract"
|
||||
@@ -142,6 +143,20 @@ func (p *customerAuthProcessor) StartRegistration(ctx context.Context, req *cont
|
||||
return nil, fmt.Errorf("phone number already registered")
|
||||
}
|
||||
|
||||
// The customer joins the organization the app is built for. Check it exists now,
|
||||
// before an OTP is sent, rather than failing on a foreign key at the last step.
|
||||
organizationID, err := uuid.Parse(strings.TrimSpace(req.OrganizationID))
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("organization_id must be a valid UUID")
|
||||
}
|
||||
orgExists, err := p.customerAuthRepo.OrganizationExists(ctx, organizationID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if !orgExists {
|
||||
return nil, fmt.Errorf("organization not found")
|
||||
}
|
||||
|
||||
// Generate registration token and create OTP session
|
||||
registrationToken := uuid.New().String()
|
||||
|
||||
@@ -156,6 +171,7 @@ func (p *customerAuthProcessor) StartRegistration(ctx context.Context, req *cont
|
||||
"registration_token": registrationToken,
|
||||
"name": req.Name,
|
||||
"birth_date": req.BirthDate,
|
||||
"organization_id": organizationID.String(),
|
||||
"step": "otp_sent",
|
||||
}
|
||||
|
||||
@@ -294,10 +310,14 @@ func (p *customerAuthProcessor) SetPassword(ctx context.Context, req *contract.R
|
||||
return nil, fmt.Errorf("invalid birth date format: %w", err)
|
||||
}
|
||||
|
||||
defaultOrgID := uuid.MustParse("87bec7c1-e274-4f66-bac5-84e632208470") // This should be configurable
|
||||
orgIDStr, _ := otpSession.Metadata["organization_id"].(string)
|
||||
organizationID, err := uuid.Parse(orgIDStr)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("invalid registration data: organization not found, start the registration again")
|
||||
}
|
||||
|
||||
customer := &entities.Customer{
|
||||
OrganizationID: defaultOrgID,
|
||||
OrganizationID: organizationID,
|
||||
Name: name,
|
||||
PhoneNumber: &otpSession.PhoneNumber,
|
||||
BirthDate: &birthDate,
|
||||
|
||||
Reference in New Issue
Block a user