Files
waseel/lib/fetch.ts
T
KrikoriosandClaude Opus 5 8807ff41c5 Waseel: driver capture, chat/calls, dispatch, and session fixes
Driver onboarding now photographs the licence, ID card and vehicle
registration and reads the credential fields off them, plus a camera-only
profile selfie riders check the arriving driver against. Adds in-app chat
and WebRTC calls, push-backed ride offers, ratings, cancellation and
payment sheets, settlement, and the owner dashboard endpoints behind them.

Camera permission on Android:
  - Declare CAMERA and READ_MEDIA_IMAGES in the manifest. expo-image-picker's
    own plugin never declares CAMERA, and Android denies a request for an
    undeclared permission instantly and silently — no dialog is ever shown,
    which is indistinguishable from the app not asking at all.
  - Handle canAskAgain: once Android stops showing the dialog, repeating why
    we need it is a dead end, so offer Open Settings instead (lib/capture-
    permission.ts), matching what the location flow already did.

Session: a 401 on a request that carried a token now ends the session
instead of being reinterpreted per-screen — driver-home had been reading it
as "this user has no driver profile" and showing an onboarding form to an
already-onboarded driver. Requests without a token are exempt so a failed
sign-in doesn't sign you out, and the notification is latched per token so
concurrent polls tear the session down once. (root) gains the auth guard
that turns that into the sign-in screen; app/index.tsx only guarded the way
in, leaving a session that ended mid-screen with nowhere to go.

Also ignore .uploads/ — it holds driver licence, ID and vehicle scans plus
profile photos, which are personal data and must not be committed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-26 02:17:55 +03:00

129 lines
4.3 KiB
TypeScript

import { useState, useEffect, useCallback } from "react";
// Set by lib/session.tsx once a token is available; read synchronously here so
// callers never have to await SecureStore before every request.
let authToken: string | null = null;
// Whether the current token has already been reported dead. A signed-in screen
// usually has several requests in flight — the driver dashboard poll, the call
// watcher, a profile load — and a token that has expired fails all of them
// within a few milliseconds. Without this latch each one would separately tear
// the session down, and signing out is not free: it releases the push device
// and stops the location foreground service.
let unauthorizedNotified = false;
let onUnauthorized: (() => void) | null = null;
export const setAuthToken = (token: string) => {
authToken = token;
unauthorizedNotified = false;
};
export const clearAuthToken = () => {
authToken = null;
};
/**
* Registers what to do when the server rejects a token we actually sent.
*
* Lives at module scope for the same reason the token does: `fetchAPI` is a
* plain function called from stores, effects and helpers that have no React
* context to read. lib/session.tsx registers the real handler on mount.
*/
export const setUnauthorizedHandler = (handler: (() => void) | null) => {
onUnauthorized = handler;
};
/** Carries the HTTP status so callers can branch on it instead of on text. */
export class ApiError extends Error {
status: number;
/**
* The parsed error body, when there was one. Routes that reject with a
* recoverable state attach what the client needs to recover — a 409 on ride
* creation carries the `ride_id` already in progress, so the screen can send
* the rider there instead of just apologising.
*/
body: Record<string, unknown> | null;
constructor(
status: number,
message: string,
body: Record<string, unknown> | null = null,
) {
super(message);
this.name = "ApiError";
this.status = status;
this.body = body;
}
}
export const fetchAPI = async (url: string, options?: RequestInit) => {
try {
const headers = new Headers(options?.headers);
if (authToken && !headers.has("Authorization")) {
headers.set("Authorization", `Bearer ${authToken}`);
}
// Only requests that carried a token can tell us anything about that
// token. Signing in is itself a 401 when the password is wrong, and that
// request is unauthenticated by definition — treating it as a dead session
// would sign the user out of the account they are in the middle of
// signing in to.
const authenticated = headers.has("Authorization");
const response = await fetch(url, { ...options, headers });
if (!response.ok) {
// Every route answers with `{ error }`; keep that text so the UI can show
// what actually went wrong instead of guessing from a status code.
const body = await response.json().catch(() => null);
// The token is gone or expired. Callers still get the ApiError — a
// screen may want to stop polling or hide a spinner — but none of them
// can recover from this one, and leaving the session in place is what
// let an expired token look like a missing driver profile.
if (response.status === 401 && authenticated && !unauthorizedNotified) {
unauthorizedNotified = true;
onUnauthorized?.();
}
throw new ApiError(
response.status,
body?.error ?? `Request failed with status ${response.status}.`,
body,
);
}
return await response.json();
} catch (error) {
console.error(`Fetch error: ${url}`, error);
throw error;
}
};
export const useFetch = <T>(url: string, options?: RequestInit) => {
const [data, setData] = useState<T | null>(null);
const [loading, setLoading] = useState(false);
const [error, setError] = useState<string | null>(null);
const fetchData = useCallback(async () => {
setLoading(true);
setError(null);
try {
const result = await fetchAPI(url, options);
setData(result.data);
} catch (err) {
setError((err as Error).message);
} finally {
setLoading(false);
}
}, [url, options]);
useEffect(() => {
fetchData();
}, [fetchData]);
return { data, loading, error, refetch: fetchData };
};