Compare commits

...

3 Commits

Author SHA1 Message Date
moon
4a4c785304 reset password fix 2026-05-11 22:00:44 +06:30
moon
dc8feb9c9e change password api 2026-05-11 21:31:40 +06:30
moon
b3494d71dd reset-cashier-password 2026-05-11 21:05:11 +06:30
21 changed files with 2476 additions and 1097 deletions

View File

@ -1,7 +1,7 @@
class AppConfig {
const AppConfig._();
static const String apiBaseUrl = 'https://api-tms.kbzbank.com/receipt';
// static const String apiBaseUrl = 'https://receipt-nest.utsmyanmar.com';
// static const String apiBaseUrl = 'https://api-tms.kbzbank.com/receipt';
static const String apiBaseUrl = 'https://receipt-nest.utsmyanmar.com';
static const String apiSecret = 'y812J21lhha11OS';
}

View File

@ -29,10 +29,7 @@ class ApiAuthRepository implements AuthRepository {
final response = await _client.post(
uri,
headers: {
'Content-Type': 'application/json',
'x-api-key': apiSecret,
},
headers: {'Content-Type': 'application/json', 'x-api-key': apiSecret},
body: requestBody,
);
@ -68,16 +65,11 @@ class ApiAuthRepository implements AuthRepository {
required String role,
}) async {
final uri = Uri.parse('$baseUrl/auth/refresh-token');
final requestBody = jsonEncode({
'refreshToken': refreshToken,
});
final requestBody = jsonEncode({'refreshToken': refreshToken});
final response = await _client.post(
uri,
headers: {
'Content-Type': 'application/json',
'x-api-key': apiSecret,
},
headers: {'Content-Type': 'application/json', 'x-api-key': apiSecret},
body: requestBody,
);
@ -97,19 +89,18 @@ class ApiAuthRepository implements AuthRepository {
Future<void> resetPassword({
required String userId,
required String password,
required String oldPassword,
}) async {
final uri = Uri.parse('$baseUrl/auth/reset-password');
final requestBody = jsonEncode({
'userId': userId,
'password': password,
'password2': oldPassword,
});
final response = await _client.put(
uri,
headers: {
'Content-Type': 'application/json',
'x-api-key': apiSecret,
},
headers: {'Content-Type': 'application/json', 'x-api-key': apiSecret},
body: requestBody,
);
@ -121,18 +112,65 @@ class ApiAuthRepository implements AuthRepository {
}
@override
Future<void> logout({required String refreshToken}) async {
final uri = Uri.parse('$baseUrl/auth/logout');
Future<String> resetCashierPassword({required String username}) async {
final trimmedUsername = username.trim();
final encodedUsername = Uri.encodeComponent(trimmedUsername);
final uri = Uri.parse(
'$baseUrl/user/$encodedUsername/cashier-reset-password',
);
final response = await _client.post(
uri,
headers: {'Content-Type': 'application/json', 'x-api-key': apiSecret},
);
if (response.statusCode >= 200 && response.statusCode < 300) {
return _extractSuccessMessage(
response.body,
fallback: 'Password reset successfully',
);
}
throw Exception(_extractErrorMessage(response.body));
}
@override
Future<String> changePassword({
required String oldPassword,
required String newPassword,
required String confirmPassword,
}) async {
final uri = Uri.parse('$baseUrl/user/change-password');
final requestBody = jsonEncode({
'refreshToken': refreshToken,
'oldPassword': oldPassword,
'newPassword': newPassword,
'confirmPassword': confirmPassword,
});
final response = await _client.post(
uri,
headers: {
'Content-Type': 'application/json',
'x-api-key': apiSecret,
},
headers: {'Content-Type': 'application/json', 'x-api-key': apiSecret},
body: requestBody,
);
if (response.statusCode >= 200 && response.statusCode < 300) {
return _extractSuccessMessage(
response.body,
fallback: 'Password changed successfully',
);
}
throw Exception(_extractErrorMessage(response.body));
}
@override
Future<void> logout({required String refreshToken}) async {
final uri = Uri.parse('$baseUrl/auth/logout');
final requestBody = jsonEncode({'refreshToken': refreshToken});
final response = await _client.post(
uri,
headers: {'Content-Type': 'application/json', 'x-api-key': apiSecret},
body: requestBody,
);
@ -164,6 +202,19 @@ class ApiAuthRepository implements AuthRepository {
return message.toString();
}
String _extractSuccessMessage(String body, {required String fallback}) {
final data = _asMap(body);
final message =
data['message'] ??
data['success'] ??
data['detail'] ??
_extractPayload(data)['message'];
if (message == null || message.toString().trim().isEmpty) {
return fallback;
}
return message.toString().trim();
}
String? _extractUserId(Map<String, dynamic> data) {
final rootUser = data['user'];
if (rootUser is Map<String, dynamic>) {
@ -192,10 +243,10 @@ class ApiAuthRepository implements AuthRepository {
final payload = _extractPayload(data);
final apiUsername = _pickString(payload, const ['username', 'email']);
final token = _pickString(payload, const ['token', 'accessToken']);
final refreshToken = _pickString(
payload,
const ['refreshToken', 'refresh_token'],
);
final refreshToken = _pickString(payload, const [
'refreshToken',
'refresh_token',
]);
final role = _pickString(payload, const ['role']);
if (token == null) {

View File

@ -49,17 +49,50 @@ class MockAuthRepository implements AuthRepository {
Future<void> resetPassword({
required String userId,
required String password,
required String oldPassword,
}) async {
await Future<void>.delayed(const Duration(milliseconds: 500));
if (userId.trim().isEmpty) {
throw Exception('User ID is required.');
}
if (oldPassword.isEmpty) {
throw Exception('Old password is required.');
}
if (password.length < 8) {
throw Exception('Password must be at least 8 characters.');
}
}
@override
Future<String> resetCashierPassword({required String username}) async {
await Future<void>.delayed(const Duration(milliseconds: 500));
if (username.trim().isEmpty) {
throw Exception('Username is required.');
}
return 'Password reset successfully';
}
@override
Future<String> changePassword({
required String oldPassword,
required String newPassword,
required String confirmPassword,
}) async {
await Future<void>.delayed(const Duration(milliseconds: 500));
if (oldPassword.isEmpty || newPassword.isEmpty || confirmPassword.isEmpty) {
throw Exception('All fields are required');
}
if (newPassword != confirmPassword) {
throw Exception('New passwords do not match');
}
return 'Password changed successfully';
}
@override
Future<void> logout({required String refreshToken}) async {
await Future<void>.delayed(const Duration(milliseconds: 250));

View File

@ -9,7 +9,19 @@ abstract class AuthRepository {
required String role,
});
Future<void> resetPassword({required String userId, required String password});
Future<void> resetPassword({
required String userId,
required String password,
required String oldPassword,
});
Future<String> resetCashierPassword({required String username});
Future<String> changePassword({
required String oldPassword,
required String newPassword,
required String confirmPassword,
});
Future<void> logout({required String refreshToken});
}

View File

@ -0,0 +1,26 @@
import 'package:flutter/material.dart';
import 'package:flutter_riverpod/flutter_riverpod.dart';
final adminResetPasswordFormKeyProvider =
Provider.autoDispose<GlobalKey<FormState>>((ref) {
return GlobalKey<FormState>();
});
final adminResetUsernameControllerProvider =
Provider.autoDispose<TextEditingController>((ref) {
final controller = TextEditingController();
ref.onDispose(controller.dispose);
return controller;
});
final adminResetUsernameFocusNodeProvider = Provider.autoDispose<FocusNode>((
ref,
) {
final focusNode = FocusNode();
ref.onDispose(focusNode.dispose);
return focusNode;
});
final adminResetAttemptedSubmitProvider = StateProvider.autoDispose<bool>(
(ref) => false,
);

View File

@ -0,0 +1,392 @@
import 'package:e_receipt_mobile/domain/entities/login_user.dart';
import 'package:e_receipt_mobile/presentation/admin_reset_password/admin_reset_password_form_providers.dart';
import 'package:e_receipt_mobile/presentation/admin_reset_password/admin_reset_password_view_model.dart';
import 'package:e_receipt_mobile/presentation/auth/session_controller.dart';
import 'package:e_receipt_mobile/presentation/login/widgets/login_background.dart';
import 'package:flutter/material.dart';
import 'package:flutter/services.dart';
import 'package:flutter_riverpod/flutter_riverpod.dart';
class AdminResetPasswordPage extends ConsumerWidget {
const AdminResetPasswordPage({super.key});
String? _buildDefaultPassword(String username) {
final trimmed = username.trim();
if (trimmed.length < 4) {
return null;
}
final firstThree = trimmed.substring(0, 3).toUpperCase();
final fourth = trimmed.substring(3, 4).toLowerCase();
final lastFour = trimmed.substring(trimmed.length - 4);
return '$firstThree$fourth@$lastFour';
}
void _submit({
required WidgetRef ref,
required GlobalKey<FormState> formKey,
required TextEditingController usernameController,
required bool isLoading,
}) {
if (isLoading) {
return;
}
ref.read(adminResetPasswordViewModelProvider.notifier).clearMessages();
FocusManager.instance.primaryFocus?.unfocus();
ref.read(adminResetAttemptedSubmitProvider.notifier).state = true;
if (!(formKey.currentState?.validate() ?? false)) {
return;
}
ref
.read(adminResetPasswordViewModelProvider.notifier)
.resetCashierPassword(username: usernameController.text);
}
@override
Widget build(BuildContext context, WidgetRef ref) {
final user = ref.watch(sessionControllerProvider);
if (!(user?.isAdmin ?? false)) {
return _AdminResetPasswordForbiddenPage(user: user);
}
final state = ref.watch(adminResetPasswordViewModelProvider);
final colorScheme = Theme.of(context).colorScheme;
ref.listen(adminResetPasswordViewModelProvider, (previous, next) {
final message = next.errorMessage;
if (message != null && message != previous?.errorMessage) {
ScaffoldMessenger.of(context).showSnackBar(
SnackBar(content: Text(message), behavior: SnackBarBehavior.floating),
);
}
final success = next.successMessage;
if (success != null && success != previous?.successMessage) {
final username = ref
.read(adminResetUsernameControllerProvider)
.text
.trim();
final generatedPassword = _buildDefaultPassword(username);
showDialog<void>(
context: context,
builder: (context) {
return AlertDialog(
title: const Text('Password reset'),
content: Column(
mainAxisSize: MainAxisSize.min,
crossAxisAlignment: CrossAxisAlignment.start,
children: [
const Text(
'The cashier password has been reset to the default temporary password.',
),
if (generatedPassword != null) ...[
const SizedBox(height: 12),
SelectableText(
generatedPassword,
style: Theme.of(context).textTheme.titleMedium?.copyWith(
fontWeight: FontWeight.w700,
),
),
const SizedBox(height: 8),
Text(
'The cashier will be required to change it on next login.',
style: Theme.of(context).textTheme.bodySmall?.copyWith(
color: colorScheme.onSurfaceVariant,
),
),
],
],
),
actions: [
TextButton(
onPressed: () {
final navigator = Navigator.of(context);
navigator.pop();
Navigator.of(
context,
rootNavigator: true,
).popUntil((route) => route.isFirst);
},
child: const Text('Back to home'),
),
],
);
},
);
}
});
final formKey = ref.watch(adminResetPasswordFormKeyProvider);
final usernameController = ref.watch(adminResetUsernameControllerProvider);
final usernameFocusNode = ref.watch(adminResetUsernameFocusNodeProvider);
final attemptedSubmit = ref.watch(adminResetAttemptedSubmitProvider);
return Scaffold(
appBar: AppBar(title: const Text('Reset cashier password')),
body: AnnotatedRegion<SystemUiOverlayStyle>(
value: Theme.of(context).brightness == Brightness.dark
? SystemUiOverlayStyle.light
: SystemUiOverlayStyle.dark,
child: LoginBackground(
child: SafeArea(
child: Center(
child: SingleChildScrollView(
padding: const EdgeInsets.symmetric(
horizontal: 20,
vertical: 24,
),
child: ConstrainedBox(
constraints: const BoxConstraints(maxWidth: 460),
child: Card(
elevation: 0,
color: colorScheme.surface.withValues(
alpha: Theme.of(context).brightness == Brightness.dark
? 0.75
: 0.92,
),
shape: RoundedRectangleBorder(
borderRadius: BorderRadius.circular(28),
side: BorderSide(
color: colorScheme.outlineVariant.withValues(
alpha: 0.35,
),
),
),
child: Padding(
padding: const EdgeInsets.fromLTRB(20, 22, 20, 18),
child: Form(
key: formKey,
autovalidateMode: attemptedSubmit
? AutovalidateMode.onUserInteraction
: AutovalidateMode.disabled,
child: Column(
crossAxisAlignment: CrossAxisAlignment.stretch,
children: [
Row(
children: [
Container(
height: 44,
width: 44,
decoration: BoxDecoration(
borderRadius: BorderRadius.circular(14),
gradient: LinearGradient(
begin: Alignment.topLeft,
end: Alignment.bottomRight,
colors: [
colorScheme.primary,
colorScheme.tertiary,
],
),
),
child: const Icon(
Icons.admin_panel_settings_outlined,
color: Colors.white,
),
),
const SizedBox(width: 12),
Expanded(
child: Column(
crossAxisAlignment:
CrossAxisAlignment.start,
children: [
Text(
'Reset cashier access',
style: Theme.of(context)
.textTheme
.titleLarge
?.copyWith(
fontWeight: FontWeight.w800,
),
),
Text(
'Reset a cashier account to its temporary default password.',
style: Theme.of(context)
.textTheme
.bodyMedium
?.copyWith(
color:
colorScheme.onSurfaceVariant,
),
),
],
),
),
],
),
const SizedBox(height: 18),
TextFormField(
controller: usernameController,
focusNode: usernameFocusNode,
enabled: !state.isLoading,
textInputAction: TextInputAction.done,
textCapitalization: TextCapitalization.characters,
onFieldSubmitted: (_) => _submit(
ref: ref,
formKey: formKey,
usernameController: usernameController,
isLoading: state.isLoading,
),
validator: (value) {
final text = (value ?? '').trim();
if (text.isEmpty) {
return 'Cashier username is required';
}
if (text.length < 4) {
return 'Username must be at least 4 characters';
}
return null;
},
decoration: InputDecoration(
labelText: 'Cashier username',
hintText: 'Enter terminal username',
prefixIcon: const Icon(Icons.badge_outlined),
filled: true,
fillColor: colorScheme.surfaceContainerHighest
.withValues(
alpha:
Theme.of(context).brightness ==
Brightness.dark
? 0.55
: 0.9,
),
border: OutlineInputBorder(
borderRadius: BorderRadius.circular(18),
),
),
),
const SizedBox(height: 14),
ValueListenableBuilder<TextEditingValue>(
valueListenable: usernameController,
builder: (context, value, _) {
final generatedPassword = _buildDefaultPassword(
value.text,
);
return Container(
padding: const EdgeInsets.all(14),
decoration: BoxDecoration(
color: colorScheme.surfaceContainerHigh
.withValues(alpha: 0.8),
borderRadius: BorderRadius.circular(18),
border: Border.all(
color: colorScheme.outlineVariant
.withValues(alpha: 0.45),
),
),
child: Column(
crossAxisAlignment:
CrossAxisAlignment.start,
children: [
Text(
'Default temporary password',
style: Theme.of(context)
.textTheme
.labelLarge
?.copyWith(
fontWeight: FontWeight.w700,
),
),
const SizedBox(height: 6),
SelectableText(
generatedPassword ??
'Enter at least 4 username characters to preview the generated password.',
style: Theme.of(context)
.textTheme
.bodyMedium
?.copyWith(
color: generatedPassword == null
? colorScheme.onSurfaceVariant
: colorScheme.onSurface,
fontWeight:
generatedPassword == null
? FontWeight.w400
: FontWeight.w700,
),
),
],
),
);
},
),
const SizedBox(height: 16),
FilledButton.icon(
onPressed: state.isLoading
? null
: () => _submit(
ref: ref,
formKey: formKey,
usernameController: usernameController,
isLoading: state.isLoading,
),
icon: state.isLoading
? const SizedBox(
height: 18,
width: 18,
child: CircularProgressIndicator(
strokeWidth: 2,
),
)
: const Icon(Icons.lock_reset_outlined),
label: Padding(
padding: const EdgeInsets.symmetric(
vertical: 12,
),
child: Text(
state.isLoading
? 'Resetting...'
: 'Reset password',
style: const TextStyle(
fontWeight: FontWeight.w600,
),
),
),
),
const SizedBox(height: 10),
Text(
'This will mark the password as temporary and force a password change on next login.',
textAlign: TextAlign.center,
style: Theme.of(context).textTheme.bodySmall
?.copyWith(
color: colorScheme.onSurfaceVariant,
),
),
],
),
),
),
),
),
),
),
),
),
),
);
}
}
class _AdminResetPasswordForbiddenPage extends StatelessWidget {
const _AdminResetPasswordForbiddenPage({required this.user});
final LoginUser? user;
@override
Widget build(BuildContext context) {
return Scaffold(
appBar: AppBar(title: const Text('Reset cashier password')),
body: Center(
child: Padding(
padding: const EdgeInsets.all(24),
child: Text(
user == null
? 'You must be logged in as admin to access this page.'
: 'Only admin users can reset cashier passwords.',
textAlign: TextAlign.center,
),
),
),
);
}
}

View File

@ -0,0 +1,30 @@
import 'package:flutter/foundation.dart';
@immutable
class AdminResetPasswordState {
const AdminResetPasswordState({
this.isLoading = false,
this.errorMessage,
this.successMessage,
});
final bool isLoading;
final String? errorMessage;
final String? successMessage;
AdminResetPasswordState copyWith({
bool? isLoading,
String? errorMessage,
String? successMessage,
bool clearError = false,
bool clearSuccess = false,
}) {
return AdminResetPasswordState(
isLoading: isLoading ?? this.isLoading,
errorMessage: clearError ? null : errorMessage ?? this.errorMessage,
successMessage: clearSuccess
? null
: successMessage ?? this.successMessage,
);
}
}

View File

@ -0,0 +1,56 @@
import 'package:e_receipt_mobile/domain/repositories/auth_repository.dart';
import 'package:e_receipt_mobile/presentation/admin_reset_password/admin_reset_password_state.dart';
import 'package:e_receipt_mobile/presentation/login/login_view_model.dart';
import 'package:flutter_riverpod/flutter_riverpod.dart';
final adminResetPasswordViewModelProvider =
StateNotifierProvider.autoDispose<
AdminResetPasswordViewModel,
AdminResetPasswordState
>((ref) {
return AdminResetPasswordViewModel(
ref.watch(authenticatedAuthRepositoryProvider),
);
});
class AdminResetPasswordViewModel
extends StateNotifier<AdminResetPasswordState> {
AdminResetPasswordViewModel(this._authRepository)
: super(const AdminResetPasswordState());
final AuthRepository _authRepository;
Future<void> resetCashierPassword({required String username}) async {
final trimmedUsername = username.trim();
if (trimmedUsername.isEmpty) {
state = state.copyWith(
isLoading: false,
errorMessage: 'Cashier username is required',
clearSuccess: true,
);
return;
}
state = state.copyWith(
isLoading: true,
clearError: true,
clearSuccess: true,
);
try {
final responseMessage = await _authRepository.resetCashierPassword(
username: trimmedUsername,
);
state = state.copyWith(isLoading: false, successMessage: responseMessage);
} catch (error) {
state = state.copyWith(
isLoading: false,
errorMessage: error.toString().replaceFirst('Exception: ', ''),
);
}
}
void clearMessages() {
state = state.copyWith(clearError: true, clearSuccess: true);
}
}

View File

@ -0,0 +1,68 @@
import 'package:flutter/material.dart';
import 'package:flutter_riverpod/flutter_riverpod.dart';
final changePasswordFormKeyProvider =
Provider.autoDispose<GlobalKey<FormState>>((ref) {
return GlobalKey<FormState>();
});
final changeOldPasswordControllerProvider =
Provider.autoDispose<TextEditingController>((ref) {
final controller = TextEditingController();
ref.onDispose(controller.dispose);
return controller;
});
final changeNewPasswordControllerProvider =
Provider.autoDispose<TextEditingController>((ref) {
final controller = TextEditingController();
ref.onDispose(controller.dispose);
return controller;
});
final changeConfirmPasswordControllerProvider =
Provider.autoDispose<TextEditingController>((ref) {
final controller = TextEditingController();
ref.onDispose(controller.dispose);
return controller;
});
final changeOldPasswordFocusNodeProvider = Provider.autoDispose<FocusNode>((
ref,
) {
final focusNode = FocusNode();
ref.onDispose(focusNode.dispose);
return focusNode;
});
final changeNewPasswordFocusNodeProvider = Provider.autoDispose<FocusNode>((
ref,
) {
final focusNode = FocusNode();
ref.onDispose(focusNode.dispose);
return focusNode;
});
final changeConfirmPasswordFocusNodeProvider = Provider.autoDispose<FocusNode>((
ref,
) {
final focusNode = FocusNode();
ref.onDispose(focusNode.dispose);
return focusNode;
});
final changeOldPasswordObscureProvider = StateProvider.autoDispose<bool>(
(ref) => true,
);
final changeNewPasswordObscureProvider = StateProvider.autoDispose<bool>(
(ref) => true,
);
final changeConfirmPasswordObscureProvider = StateProvider.autoDispose<bool>(
(ref) => true,
);
final changePasswordAttemptedSubmitProvider = StateProvider.autoDispose<bool>(
(ref) => false,
);

View File

@ -0,0 +1,372 @@
import 'package:e_receipt_mobile/presentation/change_password/change_password_form_providers.dart';
import 'package:e_receipt_mobile/presentation/change_password/change_password_view_model.dart';
import 'package:e_receipt_mobile/presentation/login/widgets/login_background.dart';
import 'package:flutter/material.dart';
import 'package:flutter/services.dart';
import 'package:flutter_riverpod/flutter_riverpod.dart';
class ChangePasswordPage extends ConsumerWidget {
const ChangePasswordPage({super.key});
void _submit({
required BuildContext context,
required WidgetRef ref,
required GlobalKey<FormState> formKey,
required TextEditingController oldPasswordController,
required TextEditingController newPasswordController,
required TextEditingController confirmPasswordController,
required bool isLoading,
}) {
if (isLoading) {
return;
}
ref.read(changePasswordViewModelProvider.notifier).clearMessages();
FocusManager.instance.primaryFocus?.unfocus();
ref.read(changePasswordAttemptedSubmitProvider.notifier).state = true;
if (!(formKey.currentState?.validate() ?? false)) {
return;
}
ref
.read(changePasswordViewModelProvider.notifier)
.changePassword(
oldPassword: oldPasswordController.text,
newPassword: newPasswordController.text,
confirmPassword: confirmPasswordController.text,
);
}
@override
Widget build(BuildContext context, WidgetRef ref) {
final state = ref.watch(changePasswordViewModelProvider);
final colorScheme = Theme.of(context).colorScheme;
ref.listen(changePasswordViewModelProvider, (previous, next) {
final error = next.errorMessage;
if (error != null && error != previous?.errorMessage) {
ScaffoldMessenger.of(context).showSnackBar(
SnackBar(content: Text(error), behavior: SnackBarBehavior.floating),
);
}
final success = next.successMessage;
if (success != null && success != previous?.successMessage) {
Navigator.of(context).pop(success);
}
});
final formKey = ref.watch(changePasswordFormKeyProvider);
final oldPasswordController = ref.watch(
changeOldPasswordControllerProvider,
);
final newPasswordController = ref.watch(
changeNewPasswordControllerProvider,
);
final confirmPasswordController = ref.watch(
changeConfirmPasswordControllerProvider,
);
final oldPasswordFocusNode = ref.watch(changeOldPasswordFocusNodeProvider);
final newPasswordFocusNode = ref.watch(changeNewPasswordFocusNodeProvider);
final confirmPasswordFocusNode = ref.watch(
changeConfirmPasswordFocusNodeProvider,
);
final obscureOld = ref.watch(changeOldPasswordObscureProvider);
final obscureNew = ref.watch(changeNewPasswordObscureProvider);
final obscureConfirm = ref.watch(changeConfirmPasswordObscureProvider);
final attemptedSubmit = ref.watch(changePasswordAttemptedSubmitProvider);
return Scaffold(
appBar: AppBar(title: const Text('Change password')),
body: AnnotatedRegion<SystemUiOverlayStyle>(
value: Theme.of(context).brightness == Brightness.dark
? SystemUiOverlayStyle.light
: SystemUiOverlayStyle.dark,
child: LoginBackground(
child: SafeArea(
child: Center(
child: SingleChildScrollView(
padding: const EdgeInsets.symmetric(
horizontal: 20,
vertical: 24,
),
child: ConstrainedBox(
constraints: const BoxConstraints(maxWidth: 440),
child: Card(
elevation: 0,
color: colorScheme.surface.withValues(
alpha: Theme.of(context).brightness == Brightness.dark
? 0.75
: 0.92,
),
shape: RoundedRectangleBorder(
borderRadius: BorderRadius.circular(28),
side: BorderSide(
color: colorScheme.outlineVariant.withValues(
alpha: 0.35,
),
),
),
child: Padding(
padding: const EdgeInsets.fromLTRB(20, 22, 20, 18),
child: Form(
key: formKey,
autovalidateMode: attemptedSubmit
? AutovalidateMode.onUserInteraction
: AutovalidateMode.disabled,
child: Column(
crossAxisAlignment: CrossAxisAlignment.stretch,
children: [
Row(
children: [
Container(
height: 44,
width: 44,
decoration: BoxDecoration(
borderRadius: BorderRadius.circular(14),
gradient: LinearGradient(
begin: Alignment.topLeft,
end: Alignment.bottomRight,
colors: [
colorScheme.primary,
colorScheme.tertiary,
],
),
),
child: const Icon(
Icons.password_outlined,
color: Colors.white,
),
),
const SizedBox(width: 12),
Expanded(
child: Column(
crossAxisAlignment:
CrossAxisAlignment.start,
children: [
Text(
'Change your password',
style: Theme.of(context)
.textTheme
.titleLarge
?.copyWith(
fontWeight: FontWeight.w800,
),
),
Text(
'Use your current password to set a new permanent one.',
style: Theme.of(context)
.textTheme
.bodyMedium
?.copyWith(
color:
colorScheme.onSurfaceVariant,
),
),
],
),
),
],
),
const SizedBox(height: 18),
_PasswordField(
controller: oldPasswordController,
focusNode: oldPasswordFocusNode,
enabled: !state.isLoading,
obscureText: obscureOld,
labelText: 'Current password',
hintText: 'Enter your current password',
textInputAction: TextInputAction.next,
onFieldSubmitted: (_) => FocusScope.of(
context,
).requestFocus(newPasswordFocusNode),
onToggleVisibility: () =>
ref
.read(
changeOldPasswordObscureProvider
.notifier,
)
.state =
!obscureOld,
validator: (value) {
if ((value ?? '').isEmpty) {
return 'Current password is required';
}
return null;
},
),
const SizedBox(height: 12),
_PasswordField(
controller: newPasswordController,
focusNode: newPasswordFocusNode,
enabled: !state.isLoading,
obscureText: obscureNew,
labelText: 'New password',
hintText: 'Enter your new password',
textInputAction: TextInputAction.next,
onFieldSubmitted: (_) => FocusScope.of(
context,
).requestFocus(confirmPasswordFocusNode),
onToggleVisibility: () =>
ref
.read(
changeNewPasswordObscureProvider
.notifier,
)
.state =
!obscureNew,
validator: (value) {
if ((value ?? '').isEmpty) {
return 'New password is required';
}
return null;
},
),
const SizedBox(height: 12),
_PasswordField(
controller: confirmPasswordController,
focusNode: confirmPasswordFocusNode,
enabled: !state.isLoading,
obscureText: obscureConfirm,
labelText: 'Confirm new password',
hintText: 'Re-enter your new password',
textInputAction: TextInputAction.done,
onFieldSubmitted: (_) => _submit(
context: context,
ref: ref,
formKey: formKey,
oldPasswordController: oldPasswordController,
newPasswordController: newPasswordController,
confirmPasswordController:
confirmPasswordController,
isLoading: state.isLoading,
),
onToggleVisibility: () =>
ref
.read(
changeConfirmPasswordObscureProvider
.notifier,
)
.state =
!obscureConfirm,
validator: (value) {
if ((value ?? '').isEmpty) {
return 'Confirm password is required';
}
return null;
},
),
const SizedBox(height: 16),
FilledButton.icon(
onPressed: state.isLoading
? null
: () => _submit(
context: context,
ref: ref,
formKey: formKey,
oldPasswordController:
oldPasswordController,
newPasswordController:
newPasswordController,
confirmPasswordController:
confirmPasswordController,
isLoading: state.isLoading,
),
icon: state.isLoading
? const SizedBox(
height: 18,
width: 18,
child: CircularProgressIndicator(
strokeWidth: 2,
),
)
: const Icon(Icons.check),
label: Padding(
padding: const EdgeInsets.symmetric(
vertical: 12,
),
child: Text(
state.isLoading
? 'Updating...'
: 'Change password',
style: const TextStyle(
fontWeight: FontWeight.w600,
),
),
),
),
],
),
),
),
),
),
),
),
),
),
),
);
}
}
class _PasswordField extends StatelessWidget {
const _PasswordField({
required this.controller,
required this.focusNode,
required this.enabled,
required this.obscureText,
required this.labelText,
required this.hintText,
required this.textInputAction,
required this.onFieldSubmitted,
required this.onToggleVisibility,
required this.validator,
});
final TextEditingController controller;
final FocusNode focusNode;
final bool enabled;
final bool obscureText;
final String labelText;
final String hintText;
final TextInputAction textInputAction;
final ValueChanged<String> onFieldSubmitted;
final VoidCallback onToggleVisibility;
final FormFieldValidator<String> validator;
@override
Widget build(BuildContext context) {
final colorScheme = Theme.of(context).colorScheme;
return TextFormField(
controller: controller,
focusNode: focusNode,
enabled: enabled,
textInputAction: textInputAction,
obscureText: obscureText,
onFieldSubmitted: onFieldSubmitted,
validator: validator,
decoration: InputDecoration(
labelText: labelText,
hintText: hintText,
prefixIcon: const Icon(Icons.lock_outline),
filled: true,
fillColor: colorScheme.surfaceContainerHighest.withValues(
alpha: Theme.of(context).brightness == Brightness.dark ? 0.55 : 0.9,
),
border: OutlineInputBorder(borderRadius: BorderRadius.circular(18)),
suffixIcon: IconButton(
tooltip: obscureText ? 'Show password' : 'Hide password',
onPressed: enabled ? onToggleVisibility : null,
icon: Icon(
obscureText
? Icons.visibility_outlined
: Icons.visibility_off_outlined,
),
),
),
);
}
}

View File

@ -0,0 +1,30 @@
import 'package:flutter/foundation.dart';
@immutable
class ChangePasswordState {
const ChangePasswordState({
this.isLoading = false,
this.errorMessage,
this.successMessage,
});
final bool isLoading;
final String? errorMessage;
final String? successMessage;
ChangePasswordState copyWith({
bool? isLoading,
String? errorMessage,
String? successMessage,
bool clearError = false,
bool clearSuccess = false,
}) {
return ChangePasswordState(
isLoading: isLoading ?? this.isLoading,
errorMessage: clearError ? null : errorMessage ?? this.errorMessage,
successMessage: clearSuccess
? null
: successMessage ?? this.successMessage,
);
}
}

View File

@ -0,0 +1,60 @@
import 'package:e_receipt_mobile/domain/repositories/auth_repository.dart';
import 'package:e_receipt_mobile/presentation/change_password/change_password_state.dart';
import 'package:e_receipt_mobile/presentation/login/login_view_model.dart';
import 'package:flutter_riverpod/flutter_riverpod.dart';
final changePasswordViewModelProvider =
StateNotifierProvider.autoDispose<
ChangePasswordViewModel,
ChangePasswordState
>((ref) {
return ChangePasswordViewModel(
ref.watch(authenticatedAuthRepositoryProvider),
);
});
class ChangePasswordViewModel extends StateNotifier<ChangePasswordState> {
ChangePasswordViewModel(this._authRepository)
: super(const ChangePasswordState());
final AuthRepository _authRepository;
Future<void> changePassword({
required String oldPassword,
required String newPassword,
required String confirmPassword,
}) async {
if (oldPassword.isEmpty || newPassword.isEmpty || confirmPassword.isEmpty) {
state = state.copyWith(
isLoading: false,
errorMessage: 'All fields are required',
clearSuccess: true,
);
return;
}
state = state.copyWith(
isLoading: true,
clearError: true,
clearSuccess: true,
);
try {
final responseMessage = await _authRepository.changePassword(
oldPassword: oldPassword,
newPassword: newPassword,
confirmPassword: confirmPassword,
);
state = state.copyWith(isLoading: false, successMessage: responseMessage);
} catch (error) {
state = state.copyWith(
isLoading: false,
errorMessage: error.toString().replaceFirst('Exception: ', ''),
);
}
}
void clearMessages() {
state = state.copyWith(clearError: true, clearSuccess: true);
}
}

View File

@ -1,5 +1,7 @@
import 'package:e_receipt_mobile/domain/entities/login_user.dart';
import 'package:e_receipt_mobile/presentation/admin_reset_password/admin_reset_password_page.dart';
import 'package:e_receipt_mobile/presentation/auth/logout_view_model.dart';
import 'package:e_receipt_mobile/presentation/change_password/change_password_page.dart';
import 'package:e_receipt_mobile/presentation/home/home_pagination_providers.dart';
import 'package:e_receipt_mobile/presentation/home/merchant_paging_view_model.dart';
import 'package:e_receipt_mobile/presentation/home/widgets/home_drawer.dart';
@ -37,6 +39,32 @@ class HomeScreen extends ConsumerWidget {
),
drawer: HomeDrawer(
user: user,
onChangePassword: () async {
Navigator.of(context).pop();
final successMessage = await Navigator.of(context).push<String>(
MaterialPageRoute<String>(
builder: (_) => const ChangePasswordPage(),
),
);
if (successMessage != null && context.mounted) {
ScaffoldMessenger.of(context).showSnackBar(
SnackBar(
content: Text(successMessage),
behavior: SnackBarBehavior.floating,
),
);
}
},
onResetCashierPassword: user.isAdmin
? () {
Navigator.of(context).pop();
Navigator.of(context).push(
MaterialPageRoute<void>(
builder: (_) => const AdminResetPasswordPage(),
),
);
}
: null,
onLogout: () async {
if (logoutState.isLoading) {
return;
@ -195,8 +223,6 @@ class HomeScreen extends ConsumerWidget {
);
}
void _openTerminalSelection(
BuildContext context,
String merchantId,

View File

@ -6,11 +6,15 @@ class HomeDrawer extends StatelessWidget {
const HomeDrawer({
required this.user,
required this.onLogout,
this.onChangePassword,
this.onResetCashierPassword,
super.key,
});
final LoginUser user;
final VoidCallback onLogout;
final VoidCallback? onChangePassword;
final VoidCallback? onResetCashierPassword;
@override
Widget build(BuildContext context) {
@ -21,11 +25,28 @@ class HomeDrawer extends StatelessWidget {
child: Column(
children: [
_DrawerHeader(user: user),
Padding(
padding: const EdgeInsets.fromLTRB(8, 12, 8, 0),
child: _DrawerItem(
icon: Icons.password_outlined,
label: 'Change password',
onTap: onChangePassword ?? () {},
),
),
if (user.isAdmin)
Padding(
padding: const EdgeInsets.fromLTRB(8, 4, 8, 0),
child: _DrawerItem(
icon: Icons.lock_reset_outlined,
label: 'Reset cashier password',
onTap: onResetCashierPassword ?? () {},
),
),
const Spacer(),
Divider(
height: 1,
thickness: 1,
color: colorScheme.outlineVariant.withOpacity(0.6),
color: colorScheme.outlineVariant.withValues(alpha: 0.6),
),
Padding(
padding: const EdgeInsets.fromLTRB(8, 4, 8, 8),

View File

@ -31,7 +31,9 @@ class LoginPage extends ConsumerWidget {
}
TextInput.finishAutofillContext();
ref.read(loginViewModelProvider.notifier).login(
ref
.read(loginViewModelProvider.notifier)
.login(
username: usernameController.text,
password: passwordController.text,
);
@ -51,6 +53,7 @@ class LoginPage extends ConsumerWidget {
switch (action) {
case LoginRequiredAction.passwordUpdateRequired:
final userId = (next.requiredUserId ?? '').trim();
final oldPassword = next.requiredOldPassword ?? '';
if (userId.isEmpty) {
ScaffoldMessenger.of(context).showSnackBar(
const SnackBar(
@ -61,6 +64,18 @@ class LoginPage extends ConsumerWidget {
ref.read(loginViewModelProvider.notifier).clearRequirement();
return;
}
if (oldPassword.isEmpty) {
ScaffoldMessenger.of(context).showSnackBar(
const SnackBar(
content: Text(
'Password update required (missing login password)',
),
behavior: SnackBarBehavior.floating,
),
);
ref.read(loginViewModelProvider.notifier).clearRequirement();
return;
}
ScaffoldMessenger.of(context).showSnackBar(
const SnackBar(
@ -70,7 +85,10 @@ class LoginPage extends ConsumerWidget {
);
ref.read(loginViewModelProvider.notifier).clearRequirement();
Navigator.of(context).push(
MaterialPageRoute<void>(builder: (_) => ResetPasswordPage(userId: userId)),
MaterialPageRoute<void>(
builder: (_) =>
ResetPasswordPage(userId: userId, oldPassword: oldPassword),
),
);
}
});
@ -254,7 +272,8 @@ class LoginPage extends ConsumerWidget {
: 'Hide password',
onPressed: state.isLoading
? null
: () => ref
: () =>
ref
.read(
loginObscurePasswordProvider
.notifier,

View File

@ -12,6 +12,7 @@ class LoginState {
this.user,
this.requiredAction,
this.requiredUserId,
this.requiredOldPassword,
});
final bool isLoading;
@ -20,6 +21,7 @@ class LoginState {
final LoginUser? user;
final LoginRequiredAction? requiredAction;
final String? requiredUserId;
final String? requiredOldPassword;
LoginState copyWith({
bool? isLoading,
@ -28,6 +30,7 @@ class LoginState {
LoginUser? user,
LoginRequiredAction? requiredAction,
String? requiredUserId,
String? requiredOldPassword,
bool clearError = false,
bool clearSuccess = false,
bool clearUser = false,
@ -40,13 +43,20 @@ class LoginState {
? null
: successMessage ?? this.successMessage,
user: clearUser ? null : user ?? this.user,
requiredAction: clearRequired ? null : requiredAction ?? this.requiredAction,
requiredUserId: clearRequired ? null : requiredUserId ?? this.requiredUserId,
requiredAction: clearRequired
? null
: requiredAction ?? this.requiredAction,
requiredUserId: clearRequired
? null
: requiredUserId ?? this.requiredUserId,
requiredOldPassword: clearRequired
? null
: requiredOldPassword ?? this.requiredOldPassword,
);
}
@override
String toString() {
return 'LoginState(isLoading: $isLoading, errorMessage: $errorMessage, successMessage: $successMessage, user: $user, requiredAction: $requiredAction, requiredUserId: $requiredUserId)';
return 'LoginState(isLoading: $isLoading, errorMessage: $errorMessage, successMessage: $successMessage, user: $user, requiredAction: $requiredAction, requiredUserId: $requiredUserId, requiredOldPassword: $requiredOldPassword)';
}
}

View File

@ -67,6 +67,14 @@ final authRepositoryProvider = Provider<AuthRepository>((ref) {
);
});
final authenticatedAuthRepositoryProvider = Provider<AuthRepository>((ref) {
return ApiAuthRepository(
baseUrl: AppConfig.apiBaseUrl,
apiSecret: AppConfig.apiSecret,
client: ref.watch(authenticatedHttpClientProvider),
);
});
final loginViewModelProvider =
StateNotifierProvider<LoginViewModel, LoginState>((ref) {
return LoginViewModel(
@ -121,6 +129,7 @@ class LoginViewModel extends StateNotifier<LoginState> {
isLoading: false,
requiredAction: LoginRequiredAction.passwordUpdateRequired,
requiredUserId: error.userId,
requiredOldPassword: password,
clearError: true,
clearSuccess: true,
);

View File

@ -6,9 +6,14 @@ import 'package:flutter/services.dart';
import 'package:flutter_riverpod/flutter_riverpod.dart';
class ResetPasswordPage extends ConsumerWidget {
const ResetPasswordPage({required this.userId, super.key});
const ResetPasswordPage({
required this.userId,
required this.oldPassword,
super.key,
});
final String userId;
final String oldPassword;
bool _isStrongPassword(String value) {
return value.length >= 8 &&
@ -52,7 +57,11 @@ class ResetPasswordPage extends ConsumerWidget {
ref
.read(resetPasswordViewModelProvider.notifier)
.resetPassword(userId: userId, password: password);
.resetPassword(
userId: userId,
password: password,
oldPassword: oldPassword,
);
}
@override
@ -64,19 +73,13 @@ class ResetPasswordPage extends ConsumerWidget {
final message = next.errorMessage;
if (message != null && message != previous?.errorMessage) {
ScaffoldMessenger.of(context).showSnackBar(
SnackBar(
content: Text(message),
behavior: SnackBarBehavior.floating,
),
SnackBar(content: Text(message), behavior: SnackBarBehavior.floating),
);
}
final success = next.successMessage;
if (success != null && success != previous?.successMessage) {
ScaffoldMessenger.of(context).showSnackBar(
SnackBar(
content: Text(success),
behavior: SnackBarBehavior.floating,
),
SnackBar(content: Text(success), behavior: SnackBarBehavior.floating),
);
Navigator.of(context).pop();
}
@ -101,14 +104,18 @@ class ResetPasswordPage extends ConsumerWidget {
child: SafeArea(
child: Center(
child: SingleChildScrollView(
padding:
const EdgeInsets.symmetric(horizontal: 20, vertical: 24),
padding: const EdgeInsets.symmetric(
horizontal: 20,
vertical: 24,
),
child: ConstrainedBox(
constraints: const BoxConstraints(maxWidth: 440),
child: Card(
elevation: 0,
color: colorScheme.surface.withOpacity(
Theme.of(context).brightness == Brightness.dark ? 0.75 : 0.92,
Theme.of(context).brightness == Brightness.dark
? 0.75
: 0.92,
),
shape: RoundedRectangleBorder(
borderRadius: BorderRadius.circular(28),
@ -159,7 +166,9 @@ class ResetPasswordPage extends ConsumerWidget {
style: Theme.of(context)
.textTheme
.titleLarge
?.copyWith(fontWeight: FontWeight.w800),
?.copyWith(
fontWeight: FontWeight.w800,
),
),
Text(
'Your account requires a password change.',
@ -167,7 +176,8 @@ class ResetPasswordPage extends ConsumerWidget {
.textTheme
.bodyMedium
?.copyWith(
color: colorScheme.onSurfaceVariant,
color:
colorScheme.onSurfaceVariant,
),
),
],
@ -182,8 +192,9 @@ class ResetPasswordPage extends ConsumerWidget {
enabled: !state.isLoading,
textInputAction: TextInputAction.next,
obscureText: obscure,
onFieldSubmitted: (_) =>
FocusScope.of(context).requestFocus(confirmFocusNode),
onFieldSubmitted: (_) => FocusScope.of(
context,
).requestFocus(confirmFocusNode),
validator: (value) {
final text = (value ?? '').trim();
if (text.isEmpty) {
@ -201,7 +212,8 @@ class ResetPasswordPage extends ConsumerWidget {
filled: true,
fillColor: colorScheme.surfaceContainerHighest
.withOpacity(
Theme.of(context).brightness == Brightness.dark
Theme.of(context).brightness ==
Brightness.dark
? 0.55
: 0.9,
),
@ -209,13 +221,16 @@ class ResetPasswordPage extends ConsumerWidget {
borderRadius: BorderRadius.circular(18),
),
suffixIcon: IconButton(
tooltip:
obscure ? 'Show password' : 'Hide password',
tooltip: obscure
? 'Show password'
: 'Hide password',
onPressed: state.isLoading
? null
: () => ref
: () =>
ref
.read(
resetObscurePasswordProvider.notifier,
resetObscurePasswordProvider
.notifier,
)
.state =
!obscure,
@ -255,7 +270,8 @@ class ResetPasswordPage extends ConsumerWidget {
filled: true,
fillColor: colorScheme.surfaceContainerHighest
.withOpacity(
Theme.of(context).brightness == Brightness.dark
Theme.of(context).brightness ==
Brightness.dark
? 0.55
: 0.9,
),
@ -268,7 +284,8 @@ class ResetPasswordPage extends ConsumerWidget {
: 'Hide password',
onPressed: state.isLoading
? null
: () => ref
: () =>
ref
.read(
resetObscureConfirmPasswordProvider
.notifier,
@ -299,14 +316,22 @@ class ResetPasswordPage extends ConsumerWidget {
? const SizedBox(
height: 18,
width: 18,
child: CircularProgressIndicator(strokeWidth: 2),
child: CircularProgressIndicator(
strokeWidth: 2,
),
)
: const Icon(Icons.check),
label: Padding(
padding: const EdgeInsets.symmetric(vertical: 12),
padding: const EdgeInsets.symmetric(
vertical: 12,
),
child: Text(
state.isLoading ? 'Updating...' : 'Reset password',
style: const TextStyle(fontWeight: FontWeight.w600),
state.isLoading
? 'Updating...'
: 'Reset password',
style: const TextStyle(
fontWeight: FontWeight.w600,
),
),
),
),
@ -314,7 +339,8 @@ class ResetPasswordPage extends ConsumerWidget {
Text(
'Tip: use a unique password you don’t use elsewhere.',
textAlign: TextAlign.center,
style: Theme.of(context).textTheme.bodySmall?.copyWith(
style: Theme.of(context).textTheme.bodySmall
?.copyWith(
color: colorScheme.onSurfaceVariant,
),
),

View File

@ -4,20 +4,23 @@ import 'package:e_receipt_mobile/presentation/reset_password/reset_password_stat
import 'package:flutter_riverpod/flutter_riverpod.dart';
final resetPasswordViewModelProvider =
StateNotifierProvider.autoDispose<ResetPasswordViewModel, ResetPasswordState>(
(ref) {
StateNotifierProvider.autoDispose<
ResetPasswordViewModel,
ResetPasswordState
>((ref) {
return ResetPasswordViewModel(ref.watch(authRepositoryProvider));
},
);
});
class ResetPasswordViewModel extends StateNotifier<ResetPasswordState> {
ResetPasswordViewModel(this._authRepository) : super(const ResetPasswordState());
ResetPasswordViewModel(this._authRepository)
: super(const ResetPasswordState());
final AuthRepository _authRepository;
Future<void> resetPassword({
required String userId,
required String password,
required String oldPassword,
}) async {
if (userId.trim().isEmpty) {
state = state.copyWith(
@ -27,6 +30,14 @@ class ResetPasswordViewModel extends StateNotifier<ResetPasswordState> {
);
return;
}
if (oldPassword.isEmpty) {
state = state.copyWith(
isLoading: false,
errorMessage: 'Missing original login password',
clearSuccess: true,
);
return;
}
state = state.copyWith(
isLoading: true,
@ -35,7 +46,11 @@ class ResetPasswordViewModel extends StateNotifier<ResetPasswordState> {
);
try {
await _authRepository.resetPassword(userId: userId.trim(), password: password);
await _authRepository.resetPassword(
userId: userId.trim(),
password: password,
oldPassword: oldPassword,
);
state = state.copyWith(
isLoading: false,
successMessage: 'Password updated',

View File

@ -1,6 +1,7 @@
import 'package:e_receipt_mobile/domain/entities/terminal.dart';
import 'package:e_receipt_mobile/presentation/auth/logout_view_model.dart';
import 'package:e_receipt_mobile/presentation/auth/session_controller.dart';
import 'package:e_receipt_mobile/presentation/change_password/change_password_page.dart';
import 'package:e_receipt_mobile/presentation/terminal/transaction_paging_state.dart';
import 'package:e_receipt_mobile/presentation/terminal/transaction_paging_view_model.dart';
import 'package:e_receipt_mobile/presentation/terminal/transaction_receipt_screen.dart';
@ -266,10 +267,19 @@ class _TerminalNextScreenState extends ConsumerState<TerminalNextScreen> {
subtitle: const Text('Cashier'),
),
const Divider(height: 1),
ListTile(
leading: const Icon(Icons.password_outlined),
title: const Text('Change password'),
onTap: () => Navigator.of(
context,
).pop(_CashierMenuAction.changePassword),
),
const Divider(height: 1),
ListTile(
leading: const Icon(Icons.logout, color: Colors.redAccent),
title: const Text('Logout'),
onTap: () => Navigator.of(context).pop(_CashierMenuAction.logout),
onTap: () =>
Navigator.of(context).pop(_CashierMenuAction.logout),
),
],
),
@ -282,12 +292,25 @@ class _TerminalNextScreenState extends ConsumerState<TerminalNextScreen> {
}
switch (action) {
case _CashierMenuAction.changePassword:
final successMessage = await Navigator.of(this.context).push<String>(
MaterialPageRoute<String>(builder: (_) => const ChangePasswordPage()),
);
if (successMessage != null && mounted) {
ScaffoldMessenger.of(this.context).showSnackBar(
SnackBar(
content: Text(successMessage),
behavior: SnackBarBehavior.floating,
),
);
}
break;
case _CashierMenuAction.logout:
await _logout(context);
await _logout();
}
}
Future<void> _logout(BuildContext context) async {
Future<void> _logout() async {
final shouldLogout = await showDialog<bool>(
context: context,
builder: (context) {
@ -308,7 +331,7 @@ class _TerminalNextScreenState extends ConsumerState<TerminalNextScreen> {
},
);
if (shouldLogout != true || !context.mounted) {
if (shouldLogout != true || !mounted) {
return;
}
@ -439,8 +462,7 @@ class _TerminalNextScreenState extends ConsumerState<TerminalNextScreen> {
_first(raw, const ['DE4']) ?? item.amount?.toString() ?? '-';
final currency = _first(raw, const ['DE49']) ?? 'MMK';
final status = _statusLabel(
_first(raw, const ['DE39']) ??
item.status,
_first(raw, const ['DE39']) ?? item.status,
);
final type = _first(raw, const ['DE3']) ?? item.type ?? '-';
final rrn = _first(raw, const ['DE37']) ?? item.rrn ?? '-';
@ -609,11 +631,10 @@ class _TerminalNextScreenState extends ConsumerState<TerminalNextScreen> {
if (normalized == 'A') {
return 'SUCCESS';
}
if (normalized == 'E' ) {
if (normalized == 'E') {
return 'FAILED';
}
return 'SUCCESS';
}
String? _sanitizeMultiline(String? value) {
@ -753,4 +774,4 @@ class _StatusChip extends StatelessWidget {
}
}
enum _CashierMenuAction { logout }
enum _CashierMenuAction { changePassword, logout }

102
user.md Normal file
View File

@ -0,0 +1,102 @@
# User API Documentation
Base path: `/user` (mounted at `/user`)
All routes require `keycloak.protect()` — Bearer token authentication via Keycloak.
---
## POST /user/:username/cashier-reset-password
**Purpose:** Reset a cashier's password to an auto-generated default. The default password is generated as: first 3 chars uppercase + 4th char lowercase + `@` + last 4 chars of username. The password is set as **temporary** (user must change on next login).
### Path Parameters
| Name | Type | Required | Description |
|------|------|----------|-------------|
| username | string | Yes | Username of the cashier to reset |
### Responses
| Code | Body |
|------|------|
| 200 | `{ "message": "Password reset successfully" }` |
| 400 | `{ "message": "Username is required" }` |
| 404 | `{ "message": "No user found" }` |
| 500 | `{ "message": "<error>" }` |
---
## POST /user/change-password
**Purpose:** Authenticated user changes their own password. Verifies old password against Keycloak token endpoint, then sets the new password as **permanent**.
### Request Body
| Field | Type | Required | Description |
|-------|------|----------|-------------|
| oldPassword | string | Yes | Current password |
| newPassword | string | Yes | New password |
| confirmPassword | string | Yes | Must match newPassword |
### Responses
| Code | Body |
|------|------|
| 200 | `{ "message": "Password changed successfully" }` |
| 400 | `{ "message": "All fields are required" }` or `"New passwords do not match"` or `"Invalid old password"` |
| 401 | `{ "message": "Unauthorized: User" }` |
| 404 | `{ "message": "No user found" }` |
| 500 | `{ "message": "<error>" }` |
---
## POST /user/
**Purpose:** Create a cashier user in Keycloak tied to a specific merchant. The username must correspond to an existing terminal serial in TMS for the given merchantId.
### Middleware
- `keycloak.protect()`
- `createUserValidationRules` (express-validator)
### Request Body
| Field | Type | Required | Description |
|-------|------|----------|-------------|
| username | string | Yes | Alphanumeric, must exist as serial in TMS |
| password | string | Yes | Minimum 6 characters |
| role | string | Yes | One of: `"cashier"`, `"merchant"`, `"admin"` |
| merchantId | string | Yes | Merchant ID the user belongs to |
### Responses
| Code | Body |
|------|------|
| 201 | `{ "message": "User created successfully", "userId": "<keycloak-id>" }` |
| 400 | `{ "errors": [...] }` (validation) or `{ "message": "Serials did not exist in TMS" }` |
| 500 | `{ "message": "<error>" }` |
---
## GET /user/merchant
**Purpose:** Get all cashier/terminal users belonging to a merchant. Fetches terminal serials from TMS for the given merchantId, then returns the corresponding Keycloak user data for each serial.
### Query Parameters
| Name | Type | Required | Description |
|------|------|----------|-------------|
| merchantId | string | Yes | Merchant ID to retrieve cashier users for |
### Responses
| Code | Body |
|------|------|
| 200 | `[{ "id": "...", "username": "...", "email": null, "firstName": null, "lastName": null, "enabled": true }]` |
| 400 | `{ "message": "merchantId is required" }` |
| 500 | `{ "message": "<error>" }` |
---
## GET /user/admin
**Purpose:** Get all admin users from Keycloak. Requires the authenticated user to have the `"admin"` client role.
### Responses
| Code | Body |
|------|------|
| 200 | `[{ "id": "...", "username": "...", "email": "...", "firstName": "...", "lastName": "...", "enabled": true }]` |
| 400 | `{ "message": "permission is required" }` |
| 500 | `{ "message": "<error>" }` |