1. Key Modifications & Features
Single-Hit Google OAuth 2.0 Flow:
Replaced background GIS One-Tap listener with an explicit user-initiated token client (google.accounts.oauth2.initTokenClient) and concurrency lock (inFlightRef).
Eliminated duplicate API requests to /api/v1/comm/auth/social.
Facebook Login Integration:
Integrated Facebook JavaScript SDK with Meta App ID configuration.
Implemented FB OAuth popup authorization with automatic user profile and email retrieval.
Twitter / X OAuth 2.0 PKCE Flow:
Implemented official Twitter OAuth 2.0 PKCE authorization flow with SHA-256 code challenge (code_challenge_method=S256) and scopes (users.read tweet.read).
In
App.tsx
, added an OAuth redirect listener to communicate the callback code and state across popup/opener windows via window.postMessage and storage events, automatically closing the popup upon authorization.
Welcome Modal & Profile Name Display:
Fixed social auth callback in
Login.tsx
and
LoginForm.tsx
to trigger the "welcome" modal ("Hello, {Name}!") and seamlessly route users to the shop.
Enhanced name formatting in
Header.tsx
and
ProfileMenu.tsx
to filter generic tokens ("Google User", "Shopper", "Guest") and display the customer's actual capitalized first name or email handle.
Loyalty Points Live Sync:
Dispatched loyaltyPointsUpdated event on social login success to immediately refresh loyalty wallet balance in the header.
⚙️ Repository: evergreen_pos_be (Backend)
1. Key Modifications & Bug Fixes
Cross-Provider Account Unification (
socialAuth.service.js
):
Enhanced findOrCreateSocialClient with case-insensitive email matching across emailDetails.email and root email.
Automatically links incoming social IDs (googleId, facebookId, twitterId) to existing accounts and appends the provider to client.authProviders, unifying orders, wishlists, and loyalty wallets.
Twitter OAuth 2.0 Backend Token Exchange:
Implemented verifyTwitterToken with authorization code exchange via Twitter's https://api.twitter.com/2/oauth2/token using basic client auth and PKCE code verifier, followed by /2/users/me profile fetching.
Loyalty Rewards Joining Bonus:
Integrated awardJoiningBonus inside issueSession so new or unified social sign-ins automatically receive their welcome rewards points in their customer wallet.
Cart API 500 Fix (
cart.service.js
&
ecom.controller.js
):
Added null/undefined ID validation in getCartByIdEcom to eliminate Mongoose CastError when eCartId is absent.
In CartGetById, added automatic resolution of eCartId from the database if missing on the incoming token payload.
Referral API 401 Fix (
growth.route.js
&
referral.controller.js
):
Replaced verifyToken with verifyCustomerOrStaffToken on /referral/me, /referral/attach, and /cart/merge.
Added req.user.clientId fallback in resolveCustomerId to ensure customer tokens are authenticated properly.