Driver onboarding now photographs the licence, ID card and vehicle
registration and reads the credential fields off them, plus a camera-only
profile selfie riders check the arriving driver against. Adds in-app chat
and WebRTC calls, push-backed ride offers, ratings, cancellation and
payment sheets, settlement, and the owner dashboard endpoints behind them.
Camera permission on Android:
- Declare CAMERA and READ_MEDIA_IMAGES in the manifest. expo-image-picker's
own plugin never declares CAMERA, and Android denies a request for an
undeclared permission instantly and silently — no dialog is ever shown,
which is indistinguishable from the app not asking at all.
- Handle canAskAgain: once Android stops showing the dialog, repeating why
we need it is a dead end, so offer Open Settings instead (lib/capture-
permission.ts), matching what the location flow already did.
Session: a 401 on a request that carried a token now ends the session
instead of being reinterpreted per-screen — driver-home had been reading it
as "this user has no driver profile" and showing an onboarding form to an
already-onboarded driver. Requests without a token are exempt so a failed
sign-in doesn't sign you out, and the notification is latched per token so
concurrent polls tear the session down once. (root) gains the auth guard
that turns that into the sign-in screen; app/index.tsx only guarded the way
in, leaving a session that ended mid-screen with nowhere to go.
Also ignore .uploads/ — it holds driver licence, ID and vehicle scans plus
profile photos, which are personal data and must not be committed.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
129 lines
4.3 KiB
TypeScript
129 lines
4.3 KiB
TypeScript
import { useState, useEffect, useCallback } from "react";
|
|
|
|
// Set by lib/session.tsx once a token is available; read synchronously here so
|
|
// callers never have to await SecureStore before every request.
|
|
let authToken: string | null = null;
|
|
|
|
// Whether the current token has already been reported dead. A signed-in screen
|
|
// usually has several requests in flight — the driver dashboard poll, the call
|
|
// watcher, a profile load — and a token that has expired fails all of them
|
|
// within a few milliseconds. Without this latch each one would separately tear
|
|
// the session down, and signing out is not free: it releases the push device
|
|
// and stops the location foreground service.
|
|
let unauthorizedNotified = false;
|
|
|
|
let onUnauthorized: (() => void) | null = null;
|
|
|
|
export const setAuthToken = (token: string) => {
|
|
authToken = token;
|
|
unauthorizedNotified = false;
|
|
};
|
|
|
|
export const clearAuthToken = () => {
|
|
authToken = null;
|
|
};
|
|
|
|
/**
|
|
* Registers what to do when the server rejects a token we actually sent.
|
|
*
|
|
* Lives at module scope for the same reason the token does: `fetchAPI` is a
|
|
* plain function called from stores, effects and helpers that have no React
|
|
* context to read. lib/session.tsx registers the real handler on mount.
|
|
*/
|
|
export const setUnauthorizedHandler = (handler: (() => void) | null) => {
|
|
onUnauthorized = handler;
|
|
};
|
|
|
|
/** Carries the HTTP status so callers can branch on it instead of on text. */
|
|
export class ApiError extends Error {
|
|
status: number;
|
|
/**
|
|
* The parsed error body, when there was one. Routes that reject with a
|
|
* recoverable state attach what the client needs to recover — a 409 on ride
|
|
* creation carries the `ride_id` already in progress, so the screen can send
|
|
* the rider there instead of just apologising.
|
|
*/
|
|
body: Record<string, unknown> | null;
|
|
|
|
constructor(
|
|
status: number,
|
|
message: string,
|
|
body: Record<string, unknown> | null = null,
|
|
) {
|
|
super(message);
|
|
this.name = "ApiError";
|
|
this.status = status;
|
|
this.body = body;
|
|
}
|
|
}
|
|
|
|
export const fetchAPI = async (url: string, options?: RequestInit) => {
|
|
try {
|
|
const headers = new Headers(options?.headers);
|
|
if (authToken && !headers.has("Authorization")) {
|
|
headers.set("Authorization", `Bearer ${authToken}`);
|
|
}
|
|
|
|
// Only requests that carried a token can tell us anything about that
|
|
// token. Signing in is itself a 401 when the password is wrong, and that
|
|
// request is unauthenticated by definition — treating it as a dead session
|
|
// would sign the user out of the account they are in the middle of
|
|
// signing in to.
|
|
const authenticated = headers.has("Authorization");
|
|
|
|
const response = await fetch(url, { ...options, headers });
|
|
|
|
if (!response.ok) {
|
|
// Every route answers with `{ error }`; keep that text so the UI can show
|
|
// what actually went wrong instead of guessing from a status code.
|
|
const body = await response.json().catch(() => null);
|
|
|
|
// The token is gone or expired. Callers still get the ApiError — a
|
|
// screen may want to stop polling or hide a spinner — but none of them
|
|
// can recover from this one, and leaving the session in place is what
|
|
// let an expired token look like a missing driver profile.
|
|
if (response.status === 401 && authenticated && !unauthorizedNotified) {
|
|
unauthorizedNotified = true;
|
|
onUnauthorized?.();
|
|
}
|
|
|
|
throw new ApiError(
|
|
response.status,
|
|
body?.error ?? `Request failed with status ${response.status}.`,
|
|
body,
|
|
);
|
|
}
|
|
|
|
return await response.json();
|
|
} catch (error) {
|
|
console.error(`Fetch error: ${url}`, error);
|
|
throw error;
|
|
}
|
|
};
|
|
|
|
export const useFetch = <T>(url: string, options?: RequestInit) => {
|
|
const [data, setData] = useState<T | null>(null);
|
|
const [loading, setLoading] = useState(false);
|
|
const [error, setError] = useState<string | null>(null);
|
|
|
|
const fetchData = useCallback(async () => {
|
|
setLoading(true);
|
|
setError(null);
|
|
|
|
try {
|
|
const result = await fetchAPI(url, options);
|
|
setData(result.data);
|
|
} catch (err) {
|
|
setError((err as Error).message);
|
|
} finally {
|
|
setLoading(false);
|
|
}
|
|
}, [url, options]);
|
|
|
|
useEffect(() => {
|
|
fetchData();
|
|
}, [fetchData]);
|
|
|
|
return { data, loading, error, refetch: fetchData };
|
|
};
|