Driver side (was a stub): - In-app driver onboarding: a driver-role user creates their own linked drivers profile (driver/profile+api GET/POST/PATCH). - Driver dashboard: online/offline toggle, today's earnings, incoming request cards (accept/decline), active ride panel (start/complete trip). Polls /driver/rides every 4s while online. - Location heartbeat (use-driver-location): watchPositionAsync pings /driver/location every ~5s; restarts the watch on app foreground so a backgrounded driver doesn't go permanently stale and miss requests. Dispatch (auto-match nearest, Uber-style): - Ride state machine: requested -> accepted -> en_route -> completed/cancelled with a nullable driver_id until matched (lib/dispatch.matchNextDriver). - matchNextDriver locks the ride (SELECT FOR UPDATE), expires 15s-stale offers, picks the nearest eligible driver of the matching service by haversine, offers one at a time. Called from ride/create, ride/[id] GET (lazy match on the rider's poll), and ride/[id]/respond (on decline). - ride/create is now a request endpoint (driver_id NULL, status=requested, service); drops the pre-match driver_id payment reconciliation. - ride/[id] GET returns status/service/nullable driver; PATCH handles rider cancel + driver en_route/completed. ride/list backs the history tabs. Rider flow (best experience): - confirm-ride is now a request screen: single trip fare + nearest-driver ETA + cash/card + Request Ride -> live status. Periodically polls online drivers of the selected service and disables Request when none are online (prevents the "stuck searching forever" state). - book-ride is the live ride-status screen (searching -> accepted -> en_route -> completed/cancelled + Cancel), polling every 3s. - lib/request-ride unifies the Areeba card flow + cash path. - Map reads /driver/nearby (real positions, service-filtered); lib/map adds calculateTripFare + service-aware fares. POI suggestions: - lib/places (Google Nearby Search) + nearby-suggestions chips for mall/hospital/pharmacy/restaurant on the home screen. Service categories now drive both matching and a per-service fare multiplier (car 1.0 / moto 0.7 / courier 0.85 / chauffeur 1.5). Map tiles: react-native-maps rendered blank on Android because no Google Maps key was set. Switched app.json -> app.config.js so android.config.googleMaps.apiKey is injected from EXPO_PUBLIC_GOOGLE_API_KEY at build time (keeps the key out of git). Requires a native rebuild (expo run:android) to take effect. Also includes the prior payment/auth hardening (server-authoritative payment_orders ledger with double-spend guards, peppered OTP, register TOCTOU fix, stats cents fix) that was left uncommitted. Co-Authored-By: Claude <noreply@anthropic.com>
260 lines
8.0 KiB
TypeScript
260 lines
8.0 KiB
TypeScript
import { router } from "expo-router";
|
|
import * as WebBrowser from "expo-web-browser";
|
|
import { useState } from "react";
|
|
import { Alert, Image, Text, TouchableOpacity, View } from "react-native";
|
|
import ReactNativeModal from "react-native-modal";
|
|
|
|
import { images } from "@/constants";
|
|
import { ApiError, fetchAPI } from "@/lib/fetch";
|
|
import { formatLBP } from "@/lib/pricing";
|
|
import { useLocationStore } from "@/store";
|
|
import type { PaymentProps } from "@/types/type";
|
|
|
|
import { CustomButton } from "./custom-button";
|
|
|
|
type PaymentMethod = "cash" | "card";
|
|
|
|
export const Payment = ({
|
|
fullName,
|
|
email,
|
|
amount,
|
|
driverId,
|
|
rideTime,
|
|
}: PaymentProps) => {
|
|
const {
|
|
userAddress,
|
|
userLongitude,
|
|
userLatitude,
|
|
destinationLatitude,
|
|
destinationAddress,
|
|
destinationLongitude,
|
|
} = useLocationStore();
|
|
const [method, setMethod] = useState<PaymentMethod>("cash");
|
|
const [success, setSuccess] = useState(false);
|
|
const [processing, setProcessing] = useState(false);
|
|
|
|
const fareCents = Math.round(parseFloat(amount) * 100); // in cents
|
|
|
|
const recordRide = async (paymentMethod: PaymentMethod, orderId?: string) => {
|
|
await fetchAPI("/(api)/ride/create", {
|
|
method: "POST",
|
|
headers: {
|
|
"Content-type": "application/json",
|
|
},
|
|
body: JSON.stringify({
|
|
origin_address: userAddress,
|
|
destination_address: destinationAddress,
|
|
origin_latitude: userLatitude,
|
|
origin_longitude: userLongitude,
|
|
destination_latitude: destinationLatitude,
|
|
destination_longitude: destinationLongitude,
|
|
ride_time: rideTime.toFixed(0),
|
|
fare_price: fareCents,
|
|
payment_method: paymentMethod,
|
|
...(orderId ? { payment_order_id: orderId } : {}),
|
|
driver_id: driverId,
|
|
}),
|
|
});
|
|
};
|
|
|
|
// Cash is settled directly with the driver at drop-off.
|
|
const payWithCash = async () => {
|
|
setProcessing(true);
|
|
try {
|
|
await recordRide("cash");
|
|
setSuccess(true);
|
|
} catch (err) {
|
|
console.log("[PAYMENT]: ", err);
|
|
Alert.alert(
|
|
"Error",
|
|
"Something went wrong while booking your ride. Please try again.",
|
|
);
|
|
} finally {
|
|
setProcessing(false);
|
|
}
|
|
};
|
|
|
|
const payWithCard = async () => {
|
|
setProcessing(true);
|
|
|
|
try {
|
|
// 1. Create an Areeba checkout session on our server. The server stores
|
|
// the ride intent and the successIndicator; the client only gets an
|
|
// orderId + checkoutUrl.
|
|
const { orderId, checkoutUrl, error } = await fetchAPI(
|
|
"/(api)/(areeba)/create",
|
|
{
|
|
method: "POST",
|
|
headers: {
|
|
"Content-type": "application/json",
|
|
},
|
|
body: JSON.stringify({
|
|
name: fullName || email,
|
|
email,
|
|
fare_cents: fareCents,
|
|
driver_id: driverId,
|
|
origin_address: userAddress,
|
|
destination_address: destinationAddress,
|
|
origin_latitude: userLatitude,
|
|
origin_longitude: userLongitude,
|
|
destination_latitude: destinationLatitude,
|
|
destination_longitude: destinationLongitude,
|
|
ride_time: rideTime.toFixed(0),
|
|
}),
|
|
},
|
|
);
|
|
|
|
if (error || !checkoutUrl) throw new Error(error || "No checkout URL");
|
|
|
|
// 2. Open Areeba's hosted payment page. After payment the gateway
|
|
// redirects back to the app (waseel://book-ride).
|
|
const browserResult = await WebBrowser.openAuthSessionAsync(
|
|
checkoutUrl,
|
|
"waseel://book-ride",
|
|
);
|
|
|
|
let resultIndicator: string | undefined;
|
|
if (browserResult.type === "success" && browserResult.url) {
|
|
resultIndicator = new URL(browserResult.url).searchParams.get(
|
|
"resultIndicator",
|
|
) as string;
|
|
}
|
|
|
|
// 3. Verify the payment server-side. The server compares
|
|
// resultIndicator against the stored successIndicator, reconciles
|
|
// the captured amount, and marks the order paid.
|
|
const verification = await fetchAPI("/(api)/(areeba)/verify", {
|
|
method: "POST",
|
|
headers: {
|
|
"Content-type": "application/json",
|
|
},
|
|
body: JSON.stringify({ orderId, resultIndicator }),
|
|
});
|
|
|
|
if (verification.success) {
|
|
// 4. Record the ride, consuming the paid order atomically. The client
|
|
// never sets payment_status itself.
|
|
await recordRide("card", orderId);
|
|
setSuccess(true);
|
|
} else {
|
|
Alert.alert(
|
|
"Payment not completed",
|
|
"Your payment was cancelled or could not be verified. Please try again.",
|
|
);
|
|
}
|
|
} catch (err) {
|
|
console.log("[PAYMENT]: ", err);
|
|
// Verification failures (cancelled, not captured, amount/intent mismatch)
|
|
// come back as 400s. fetchAPI throws ApiError on non-2xx, so without this
|
|
// branch every cancellation lands in the generic "something went wrong".
|
|
if (err instanceof ApiError && err.status === 400) {
|
|
Alert.alert(
|
|
"Payment not completed",
|
|
"Your payment was cancelled or could not be verified. Please try again.",
|
|
);
|
|
} else {
|
|
Alert.alert(
|
|
"Error",
|
|
"Something went wrong while processing your payment. Please try again.",
|
|
);
|
|
}
|
|
} finally {
|
|
setProcessing(false);
|
|
}
|
|
};
|
|
|
|
const confirm = () =>
|
|
method === "cash"
|
|
? payWithCash()
|
|
: Alert.alert("Pay by card", `Your card will be charged $${amount}.`, [
|
|
{ text: "Cancel", style: "cancel" },
|
|
{ text: "Continue", onPress: () => void payWithCard() },
|
|
]);
|
|
|
|
return (
|
|
<>
|
|
<Text className="text-lg font-JakartaSemiBold mt-4 mb-2">
|
|
Payment Method
|
|
</Text>
|
|
|
|
<View className="flex flex-row gap-x-3">
|
|
<TouchableOpacity
|
|
onPress={() => setMethod("cash")}
|
|
className={`flex-1 items-center py-3 rounded-xl border ${
|
|
method === "cash"
|
|
? "bg-general-600 border-primary-500"
|
|
: "bg-white border-general-700"
|
|
}`}
|
|
>
|
|
<Text
|
|
className={`font-JakartaMedium ${
|
|
method === "cash" ? "text-white" : "text-black"
|
|
}`}
|
|
>
|
|
💵 Cash
|
|
</Text>
|
|
</TouchableOpacity>
|
|
|
|
<TouchableOpacity
|
|
onPress={() => setMethod("card")}
|
|
className={`flex-1 items-center py-3 rounded-xl border ${
|
|
method === "card"
|
|
? "bg-general-600 border-primary-500"
|
|
: "bg-white border-general-700"
|
|
}`}
|
|
>
|
|
<Text
|
|
className={`font-JakartaMedium ${
|
|
method === "card" ? "text-white" : "text-black"
|
|
}`}
|
|
>
|
|
💳 Card
|
|
</Text>
|
|
</TouchableOpacity>
|
|
</View>
|
|
|
|
<CustomButton
|
|
title={
|
|
processing
|
|
? "Processing..."
|
|
: method === "cash"
|
|
? "Book ride · Pay cash to driver"
|
|
: "Confirm & Pay by Card"
|
|
}
|
|
className="my-2 mt-4"
|
|
onPress={confirm}
|
|
disabled={processing}
|
|
/>
|
|
|
|
<ReactNativeModal
|
|
isVisible={success}
|
|
onBackdropPress={() => setSuccess(false)}
|
|
>
|
|
<View className="flex flex-col items-center justify-center bg-white p-7 rounded-2xl">
|
|
<Image source={images.check} alt="Check" className="w-28 h-28 mt-5" />
|
|
|
|
<Text className="text-2xl text-center font-JakartaBold mt-5">
|
|
Ride Booked!
|
|
</Text>
|
|
|
|
<Text className="text-base text-general-200 text-JakartaMedium text-center mt-3">
|
|
Thank you for your booking.{"\n"} Your reservation has been placed.
|
|
{"\n"}
|
|
{method === "cash"
|
|
? `Please have ${formatLBP(parseFloat(amount))} ready.`
|
|
: null}
|
|
</Text>
|
|
|
|
<CustomButton
|
|
title="Back Home"
|
|
onPress={() => {
|
|
setSuccess(false);
|
|
router.push("/(root)/(tabs)/home");
|
|
}}
|
|
className="mt-5"
|
|
/>
|
|
</View>
|
|
</ReactNativeModal>
|
|
</>
|
|
);
|
|
}; |