Driver side (was a stub): - In-app driver onboarding: a driver-role user creates their own linked drivers profile (driver/profile+api GET/POST/PATCH). - Driver dashboard: online/offline toggle, today's earnings, incoming request cards (accept/decline), active ride panel (start/complete trip). Polls /driver/rides every 4s while online. - Location heartbeat (use-driver-location): watchPositionAsync pings /driver/location every ~5s; restarts the watch on app foreground so a backgrounded driver doesn't go permanently stale and miss requests. Dispatch (auto-match nearest, Uber-style): - Ride state machine: requested -> accepted -> en_route -> completed/cancelled with a nullable driver_id until matched (lib/dispatch.matchNextDriver). - matchNextDriver locks the ride (SELECT FOR UPDATE), expires 15s-stale offers, picks the nearest eligible driver of the matching service by haversine, offers one at a time. Called from ride/create, ride/[id] GET (lazy match on the rider's poll), and ride/[id]/respond (on decline). - ride/create is now a request endpoint (driver_id NULL, status=requested, service); drops the pre-match driver_id payment reconciliation. - ride/[id] GET returns status/service/nullable driver; PATCH handles rider cancel + driver en_route/completed. ride/list backs the history tabs. Rider flow (best experience): - confirm-ride is now a request screen: single trip fare + nearest-driver ETA + cash/card + Request Ride -> live status. Periodically polls online drivers of the selected service and disables Request when none are online (prevents the "stuck searching forever" state). - book-ride is the live ride-status screen (searching -> accepted -> en_route -> completed/cancelled + Cancel), polling every 3s. - lib/request-ride unifies the Areeba card flow + cash path. - Map reads /driver/nearby (real positions, service-filtered); lib/map adds calculateTripFare + service-aware fares. POI suggestions: - lib/places (Google Nearby Search) + nearby-suggestions chips for mall/hospital/pharmacy/restaurant on the home screen. Service categories now drive both matching and a per-service fare multiplier (car 1.0 / moto 0.7 / courier 0.85 / chauffeur 1.5). Map tiles: react-native-maps rendered blank on Android because no Google Maps key was set. Switched app.json -> app.config.js so android.config.googleMaps.apiKey is injected from EXPO_PUBLIC_GOOGLE_API_KEY at build time (keeps the key out of git). Requires a native rebuild (expo run:android) to take effect. Also includes the prior payment/auth hardening (server-authoritative payment_orders ledger with double-spend guards, peppered OTP, register TOCTOU fix, stats cents fix) that was left uncommitted. Co-Authored-By: Claude <noreply@anthropic.com>
41 lines
1.7 KiB
Bash
41 lines
1.7 KiB
Bash
# .env
|
|
|
|
# jwt secret for self-hosted auth sessions (generate with: openssl rand -hex 32)
|
|
AUTH_JWT_SECRET=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
|
|
|
|
# postgres db url (self-hosted, e.g. postgresql://user:password@localhost:5432/waseel)
|
|
DATABASE_URL="postgresql://username:password@hostname:port/waseel"
|
|
|
|
# expo api server url (you can set it to any random url for development)
|
|
EXPO_PUBLIC_SERVER_URL="https://example.com/"
|
|
|
|
# google oauth client ids (from Google Cloud console, type "Web/iOS/Android")
|
|
EXPO_PUBLIC_GOOGLE_AUTH_WEB_CLIENT_ID=XXXXXXXX.apps.googleusercontent.com
|
|
EXPO_PUBLIC_GOOGLE_AUTH_IOS_CLIENT_ID=XXXXXXXX.apps.googleusercontent.com
|
|
EXPO_PUBLIC_GOOGLE_AUTH_ANDROID_CLIENT_ID=XXXXXXXX.apps.googleusercontent.com
|
|
|
|
# gmail smtp (app password, needs 2-step verification; leave blank to log codes to server console)
|
|
# host/port are optional -- default to smtp.gmail.com:465, use 587 if 465 is blocked
|
|
SMTP_HOST=smtp.gmail.com
|
|
SMTP_PORT=465
|
|
SMTP_USER=you@gmail.com
|
|
SMTP_PASS=your-16-char-app-password
|
|
SMTP_FROM="Waseel <you@gmail.com>"
|
|
|
|
# geoapify api key (static map tiles only)
|
|
EXPO_PUBLIC_GEOAPIFY_API_KEY=XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
|
|
|
|
# google api key — powers Places autocomplete, Places Nearby Search
|
|
# (mall/hospital/pharmacy/restaurant chips), and the per-marker Directions
|
|
# ETA/fare estimates. Note: this key is embedded in the client bundle.
|
|
EXPO_PUBLIC_GOOGLE_API_KEY=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
|
|
|
|
# areeba payment gateway (credentials issued after merchant onboarding)
|
|
AREEBA_API_BASE_URL="https://your-gateway-host.areeba.com"
|
|
AREEBA_MERCHANT_ID=XXXXXXXXXXXX
|
|
AREEBA_API_PASSWORD=XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
|
|
AREEBA_API_VERSION=100
|
|
|
|
# admin dashboard origin for CORS (lib/admin.ts); defaults to * when unset
|
|
ADMIN_CORS_ORIGIN=*
|