Driver side (was a stub): - In-app driver onboarding: a driver-role user creates their own linked drivers profile (driver/profile+api GET/POST/PATCH). - Driver dashboard: online/offline toggle, today's earnings, incoming request cards (accept/decline), active ride panel (start/complete trip). Polls /driver/rides every 4s while online. - Location heartbeat (use-driver-location): watchPositionAsync pings /driver/location every ~5s; restarts the watch on app foreground so a backgrounded driver doesn't go permanently stale and miss requests. Dispatch (auto-match nearest, Uber-style): - Ride state machine: requested -> accepted -> en_route -> completed/cancelled with a nullable driver_id until matched (lib/dispatch.matchNextDriver). - matchNextDriver locks the ride (SELECT FOR UPDATE), expires 15s-stale offers, picks the nearest eligible driver of the matching service by haversine, offers one at a time. Called from ride/create, ride/[id] GET (lazy match on the rider's poll), and ride/[id]/respond (on decline). - ride/create is now a request endpoint (driver_id NULL, status=requested, service); drops the pre-match driver_id payment reconciliation. - ride/[id] GET returns status/service/nullable driver; PATCH handles rider cancel + driver en_route/completed. ride/list backs the history tabs. Rider flow (best experience): - confirm-ride is now a request screen: single trip fare + nearest-driver ETA + cash/card + Request Ride -> live status. Periodically polls online drivers of the selected service and disables Request when none are online (prevents the "stuck searching forever" state). - book-ride is the live ride-status screen (searching -> accepted -> en_route -> completed/cancelled + Cancel), polling every 3s. - lib/request-ride unifies the Areeba card flow + cash path. - Map reads /driver/nearby (real positions, service-filtered); lib/map adds calculateTripFare + service-aware fares. POI suggestions: - lib/places (Google Nearby Search) + nearby-suggestions chips for mall/hospital/pharmacy/restaurant on the home screen. Service categories now drive both matching and a per-service fare multiplier (car 1.0 / moto 0.7 / courier 0.85 / chauffeur 1.5). Map tiles: react-native-maps rendered blank on Android because no Google Maps key was set. Switched app.json -> app.config.js so android.config.googleMaps.apiKey is injected from EXPO_PUBLIC_GOOGLE_API_KEY at build time (keeps the key out of git). Requires a native rebuild (expo run:android) to take effect. Also includes the prior payment/auth hardening (server-authoritative payment_orders ledger with double-spend guards, peppered OTP, register TOCTOU fix, stats cents fix) that was left uncommitted. Co-Authored-By: Claude <noreply@anthropic.com>
50 lines
1.7 KiB
TypeScript
50 lines
1.7 KiB
TypeScript
// Driver-side auth helper. Every driver-action endpoint first calls
|
|
// requireDriverProfile: it proves the request is from a signed-in user and
|
|
// that the user has completed onboarding (has a linked drivers row). A
|
|
// driver-role user who hasn't onboarded yet gets a 403 so the client can
|
|
// route them to the onboarding form rather than showing a bare 404.
|
|
|
|
import { requireAuth } from "@/lib/jwt";
|
|
import { sql } from "@/lib/db";
|
|
import type { ServiceId } from "@/constants/services";
|
|
|
|
type Auth = { userId: string; email: string };
|
|
|
|
export type DriverProfile = {
|
|
auth: Auth;
|
|
driverId: number;
|
|
service: ServiceId;
|
|
online: boolean;
|
|
};
|
|
|
|
export type AuthError = { error: Response };
|
|
|
|
const VALID_SERVICES = ["car", "moto", "courier", "chauffeur"] as const;
|
|
export const isServiceId = (v: unknown): v is ServiceId =>
|
|
typeof v === "string" && (VALID_SERVICES as readonly string[]).includes(v);
|
|
|
|
// Returns the driver profile for the authenticated user, or a 401/403 the
|
|
// caller can return directly. A 403 with the onboarding code tells the client
|
|
// to show the onboarding form instead of treating it as a hard error.
|
|
export const requireDriverProfile = async (
|
|
req: Request,
|
|
): Promise<DriverProfile | AuthError> => {
|
|
const auth = requireAuth(req);
|
|
if ("error" in auth) return { error: auth.error };
|
|
|
|
const rows = await sql<{ id: number; service: ServiceId; online: boolean }>`
|
|
SELECT id, service, online FROM drivers WHERE user_id = ${auth.userId}
|
|
`;
|
|
|
|
if (!rows[0]) {
|
|
return {
|
|
error: Response.json(
|
|
{ error: "No driver profile — complete onboarding.", code: "ONBOARD" },
|
|
{ status: 403 },
|
|
),
|
|
};
|
|
}
|
|
|
|
const { id, service, online } = rows[0];
|
|
return { auth, driverId: id, service, online };
|
|
}; |