Commit Graph
39 Commits
Author SHA1 Message Date
KrikoriosandClaude Opus 5 bc23c94ea2 Add remember-me and OTP autofill, fix session persistence
Sign-in gains a "Keep me signed in" checkbox: checked issues a 30-day
token and prefills the address next launch, unchecked drops the session
to 12 hours and forgets the address. The TTL is chosen server-side in
the login route.

Emailed codes are now reachable without retyping. OtpField opts into the
iOS one-time-code keyboard suggestion and raises a paste chip when the
user returns from Gmail with a code on the clipboard. The mails put the
code first in the subject and body, which is what makes Gmail render its
"Copy code" notification action at all.

Fixes found along the way:

- Session was wiped on every launch. decodeJwtExp used atob, which
  neither RN 0.74 nor Expo SDK 51 defines, so it threw, returned null,
  and the caller read that as "expired" and deleted the token. Replaced
  with a dependency-free base64url decoder, and restore now only
  discards a session it can prove is expired.
- Verification and reset codes counted attempts but never enforced them,
  leaving a 6-digit code open to unlimited guessing. Both routes now
  charge the attempt before comparing so concurrent guesses can't race
  past the cap of five, and compare in constant time.
- A wrong verification code showed the "Verified" success screen:
  onModalHide fired unconditionally, so the failure state advanced the
  flow. Only an explicit "verified" state does that now.
- fetchAPI discarded the server's error body, so the UI substring-matched
  synthetic status strings and showed "Could not sign in" for everything.
  It now throws ApiError carrying status and the server's message.
- Login answered a missing account faster than a wrong password; it now
  runs the same scrypt work either way.
- Blank email or password is caught client-side instead of surfacing as
  an opaque 400, and a failed attempt only clears the password on a 401.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-23 23:33:51 +03:00
KrikoriosandClaude Fable 5 eceb6b45d5 Fix SMTP delivery, add password reset and user deletion
SMTP:
- Add connection/greeting/socket timeouts so a stalled Gmail
  connection no longer hangs sign-up
- Wrap sendMail in try/catch and fall back to logging the code
- Derive secure from port (465 implicit TLS vs 587 STARTTLS)
- Strip whitespace from the Gmail app password
- Document SMTP_HOST/SMTP_PORT in .env.example and environment.d.ts

Password reset (new):
- POST /(api)/auth/forgot-password emails a 6-digit code and does
  not reveal whether the address is registered
- POST /(api)/auth/reset-password validates the code, sets the new
  password, verifies the email, and signs the user in
- password_reset_codes table added to seed-db.mjs
- "Forgot password?" flow on the mobile sign-in screen

User deletion (new):
- DELETE /(api)/admin/users/[id], owner-only, blocks self-deletion
- Delete button with confirmation on the dashboard Users page

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-23 22:41:41 +03:00
Krikorios a0b297285a Add self-hosted auth, admin API, and owner web dashboard
- Replace Clerk with self-hosted JWT auth (register/login/verify, bcrypt
  passwords, Gmail OTP with console fallback)
- Add lib/db.ts pg pool + transaction helpers; seed script migrates legacy
  Clerk-era schema (drop clerk_id, enforce UUID ids and unique email)
- Add owner-gated admin API: stats, users, drivers CRUD, rides
- Add dashboard/ Vite React owner dashboard (login, overview, users,
  fleet, rides) with dev-server proxy to avoid Expo CORS middleware
- Add scripts/set-owner.mjs for role management
2026-08-23 16:38:41 +03:00
Krikorios fbe92c9d16 Add rider/driver role selection after sign-up
- users.role column (+ migration in seed script)
- /(api)/user: GET role by clerkId, PATCH to set role
- Role selection screen; drivers get placeholder driver-home
- Root index routes by role; hardened location handling on home
2026-08-22 16:13:59 +03:00
Krikorios 62dc5e9d53 Rebrand to Waseel, swap Stripe for Areeba, add phone-ready auth and DB seed
- Rename app: Waseel (name, slug, scheme waseel://, com.waseel.app ids, splash)
- Payments: replace Stripe with Areeba hosted checkout (create/verify API routes,
  lib/areeba.ts, WebBrowser-based payment flow)
- Maps: migrate address autocomplete to Places API (New), drop legacy library
- Web support: map stub for web (native maps are iOS/Android only)
- Auth: keep email + Google OAuth; fix OAuth redirect for Expo Go
- Add scripts/seed-db.mjs (schema + Lebanese driver seed)
- Pin Expo SDK 51 compatible package versions
2026-08-22 15:53:41 +03:00
Sanidhya Kumar Verma 81481724ba fix eslint warnings 2024-09-06 06:03:01 +00:00
Sanidhya Kumar Verma 7894ff18aa source code link added 2024-09-04 12:58:27 +00:00
Sanidhya Kumar Verma 2a0e9a79dc completed final todo 2024-09-04 12:32:35 +00:00
Sanidhya Kumar Verma 96d14cecad typo fixes and code improvements 2024-09-04 12:01:27 +00:00
Sanidhya Kumar Verma ac4019e5d1 profile screen ui implemented 2024-09-04 11:57:15 +00:00
Sanidhya Kumar Verma d1a8106c81 chat screen ui completed 2024-09-04 11:56:20 +00:00
Sanidhya Kumar Verma 04694246c0 fix oauth flow 2024-09-04 11:53:27 +00:00
Sanidhya Kumar Verma efe9b523a2 rides fixed 2024-09-04 11:14:56 +00:00
Sanidhya Kumar Verma 02dbd6c7af stripe payment integrated 2024-09-04 11:05:39 +00:00
Sanidhya Kumar Verma 19f0e71609 refactor: router.replace to router.push and fix typos 2024-09-04 10:19:02 +00:00
Sanidhya Kumar Verma eb7e052d75 stripe payment endpoints created 2024-09-04 10:17:45 +00:00
Sanidhya Kumar Verma c5c50e75db drivers api endpoint created 2024-09-04 10:17:34 +00:00
Sanidhya Kumar Verma e9a4e892d9 fix: rides layout and accessibility 2024-09-04 06:52:11 +00:00
Sanidhya Kumar Verma 20580c58df book ride screen implemented 2024-09-04 06:49:05 +00:00
Sanidhya Kumar Verma 0b2a3ee944 find ride and book ride page ui created 2024-09-04 06:42:36 +00:00
Sanidhya Kumar Verma bf66181b70 removed console.log 2024-08-30 15:21:39 +00:00
Sanidhya Kumar Verma fba9c66389 google text input created 2024-08-30 15:19:58 +00:00
Sanidhya Kumar Verma dcb9ff3bee current location map ui implemented 2024-08-30 13:28:30 +00:00
Sanidhya Kumar Verma b313417609 home page initial ui implemented 2024-08-30 12:18:27 +00:00
Sanidhya Kumar Verma 7f0d38eb3c user api fetch request created 2024-08-30 07:27:34 +00:00
Sanidhya Kumar Verma 8f0a66ba39 improved input field 2024-08-30 07:27:24 +00:00
Sanidhya Kumar Verma 76223faa19 imports reorder 2024-08-30 05:59:42 +00:00
Sanidhya Kumar Verma be9696b8b5 bottom tab bar created 2024-08-30 05:56:58 +00:00
Sanidhya Kumar Verma 3e4c13d87c sign in page ui implemented 2024-08-29 16:48:31 +00:00
Sanidhya Kumar Verma 0f18202280 sign up flow updated 2024-08-29 16:37:55 +00:00
Sanidhya Kumar Verma a5cabfe1a1 clerk sign in and sign up login setup 2024-08-29 16:08:12 +00:00
Sanidhya Kumar Verma 2bb195c7be sign in screen ui completed 2024-08-29 15:45:26 +00:00
Sanidhya Kumar Verma f93e06c632 oauth component ui created 2024-08-29 15:43:06 +00:00
Sanidhya Kumar Verma de8ca40dcf created sign up page ui 2024-08-29 15:37:44 +00:00
Sanidhya Kumar Verma 77030fd4c2 basic layout created and welcome onboarding screen implemented 2024-08-29 08:29:58 +00:00
Sanidhya Kumar Verma 39c092630d removed unwanted files and new assets added 2024-08-29 07:39:58 +00:00
Sanidhya Kumar Verma 170520244c eslint and prettier setup 2024-08-29 07:12:44 +00:00
Sanidhya Kumar Verma 07ab94fa4e nativewind setup 2024-08-29 07:07:01 +00:00
Sanidhya Kumar Verma f82df52570 initial commit from create-expo-app 2024-08-29 06:27:42 +00:00