Authorize consents for the account-holder type the bank supports
Kontist authorized but shared no accounts: psu_type was hardcoded to personal, and Enable Banking documents that a psu_type mismatch can yield a consent without the expected accounts. The bank listing now reports each institution's supported psu_types, the connect form offers only those, the chosen type reaches POST /auth, and an unsupported combination is refused before the user is sent to a bank. The choice is stored per consent so reconnecting reuses it; consents predating the choice stay personal. Also repairs the frontend derivation, which the Montserrat dependency broke: npmDepsHash was stale and web/public was missing from the fileset, so the traced duck icon never reached the built assets.
This commit is contained in:
@@ -403,12 +403,13 @@ func (s *Server) authorize(w http.ResponseWriter, r *http.Request) {
|
||||
var b struct {
|
||||
Institution string `json:"institution"`
|
||||
Country string `json:"country"`
|
||||
PSUType string `json:"psu_type"`
|
||||
HistoryMonths int `json:"history_months"`
|
||||
}
|
||||
if !decode(w, r, &b) {
|
||||
return
|
||||
}
|
||||
v, e := s.app.Authorize(r.Context(), b.Institution, b.Country, b.HistoryMonths)
|
||||
v, e := s.app.Authorize(r.Context(), b.Institution, b.Country, b.PSUType, b.HistoryMonths)
|
||||
respond(w, map[string]string{"url": v}, e)
|
||||
}
|
||||
func (s *Server) callback(w http.ResponseWriter, r *http.Request) {
|
||||
|
||||
Reference in New Issue
Block a user