The drivers table was seeded with 4 fake fixtures (Karim/Rana/Omar/Layal)
using randomuser.me/unsplash placeholder images. They had no user_id, no
position, and were excluded from matching and the rider map by design, so
they only ever cluttered the dashboard. The table now starts empty — real
drivers are created in-app via onboarding (driver/profile POST), which
links a row to a real user account and gives it a live GPS position.
Dropped the dead random-offset scatter in generateMarkersFromData that
fabricated fake driver positions for drivers without GPS. It was already
unreachable (the null-position filter excluded those drivers), so this is
stub cleanup, not a behavior change — drivers without a real position
simply aren't rendered.
The 4 fixture rows were also removed from the live Neon DB (user_id IS
NULL); real onboarded drivers were untouched.
Co-Authored-By: Claude <noreply@anthropic.com>
Driver side (was a stub):
- In-app driver onboarding: a driver-role user creates their own linked
drivers profile (driver/profile+api GET/POST/PATCH).
- Driver dashboard: online/offline toggle, today's earnings, incoming
request cards (accept/decline), active ride panel (start/complete trip).
Polls /driver/rides every 4s while online.
- Location heartbeat (use-driver-location): watchPositionAsync pings
/driver/location every ~5s; restarts the watch on app foreground so a
backgrounded driver doesn't go permanently stale and miss requests.
Dispatch (auto-match nearest, Uber-style):
- Ride state machine: requested -> accepted -> en_route -> completed/cancelled
with a nullable driver_id until matched (lib/dispatch.matchNextDriver).
- matchNextDriver locks the ride (SELECT FOR UPDATE), expires 15s-stale
offers, picks the nearest eligible driver of the matching service by
haversine, offers one at a time. Called from ride/create, ride/[id] GET
(lazy match on the rider's poll), and ride/[id]/respond (on decline).
- ride/create is now a request endpoint (driver_id NULL, status=requested,
service); drops the pre-match driver_id payment reconciliation.
- ride/[id] GET returns status/service/nullable driver; PATCH handles rider
cancel + driver en_route/completed. ride/list backs the history tabs.
Rider flow (best experience):
- confirm-ride is now a request screen: single trip fare + nearest-driver
ETA + cash/card + Request Ride -> live status. Periodically polls online
drivers of the selected service and disables Request when none are
online (prevents the "stuck searching forever" state).
- book-ride is the live ride-status screen (searching -> accepted ->
en_route -> completed/cancelled + Cancel), polling every 3s.
- lib/request-ride unifies the Areeba card flow + cash path.
- Map reads /driver/nearby (real positions, service-filtered); lib/map
adds calculateTripFare + service-aware fares.
POI suggestions:
- lib/places (Google Nearby Search) + nearby-suggestions chips for
mall/hospital/pharmacy/restaurant on the home screen.
Service categories now drive both matching and a per-service fare
multiplier (car 1.0 / moto 0.7 / courier 0.85 / chauffeur 1.5).
Map tiles: react-native-maps rendered blank on Android because no Google
Maps key was set. Switched app.json -> app.config.js so
android.config.googleMaps.apiKey is injected from
EXPO_PUBLIC_GOOGLE_API_KEY at build time (keeps the key out of git).
Requires a native rebuild (expo run:android) to take effect.
Also includes the prior payment/auth hardening (server-authoritative
payment_orders ledger with double-spend guards, peppered OTP, register
TOCTOU fix, stats cents fix) that was left uncommitted.
Co-Authored-By: Claude <noreply@anthropic.com>
SMTP:
- Add connection/greeting/socket timeouts so a stalled Gmail
connection no longer hangs sign-up
- Wrap sendMail in try/catch and fall back to logging the code
- Derive secure from port (465 implicit TLS vs 587 STARTTLS)
- Strip whitespace from the Gmail app password
- Document SMTP_HOST/SMTP_PORT in .env.example and environment.d.ts
Password reset (new):
- POST /(api)/auth/forgot-password emails a 6-digit code and does
not reveal whether the address is registered
- POST /(api)/auth/reset-password validates the code, sets the new
password, verifies the email, and signs the user in
- password_reset_codes table added to seed-db.mjs
- "Forgot password?" flow on the mobile sign-in screen
User deletion (new):
- DELETE /(api)/admin/users/[id], owner-only, blocks self-deletion
- Delete button with confirmation on the dashboard Users page
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- users.role column (+ migration in seed script)
- /(api)/user: GET role by clerkId, PATCH to set role
- Role selection screen; drivers get placeholder driver-home
- Root index routes by role; hardened location handling on home