Skip to content

fix(tracking): throttle the public order lookup and return a minimal resource - #352

Merged
roncodes merged 1 commit into
release/v0.6.72from
fix/tracking-lookup-public-resource
Oct 7, 2026
Merged

roncodes merged 1 commit into
release/v0.6.72from
fix/tracking-lookup-public-resource

Conversation

@roncodes

@roncodes roncodes commented Oct 6, 2026

Copy link
Copy Markdown
Member

Interim hardening of the public Track Order lookup (GET int/v1/fleet-ops/lookup), ahead of the larger auth refactor.

Before

There was no session and no rate limit, and the response was the full OrderResource: notes, meta, internal_id, files (which can include POD photos and signatures), purchase rate, tracker_data with the live driver location, and internal uuids. Anyone holding a tracking number got all of it.

Changes

  • Throttle: throttle:30,1,tracking-lookup per address, on its own limiter. This follows the inspection-public pattern.
  • Minimal resource: the endpoint now returns PublicOrderTracking. It carries only what order-tracking-lookup.hbs renders:
    • order: tracking, status, has_driver_assigned, created_at
    • tracking_number.tracking_number
    • tracking_statuses[]: status, details, created_at
    • payload: pickup, dropoff and waypoints as location only (no name, address or phone; the map needs the coordinates to draw the route), plus entities[] with name, description, tracking, price, currency, photo_url
    • tracker_data: progress.percentage and completed_stops, eta.active_stop_seconds and completion_at, active_stop.address and next_stop.address, and driver.location only while the order is started and not completed or canceled
    • Records are keyed by public_id, because Ember Data needs an id, so no internal uuid is exposed. The resource extends JsonResource, not FleetbaseResource, so transformers that other extensions register cannot add fields. It is never wrapped.
  • Generic error: missing, non-string, malformed (anything outside [A-Za-z0-9._-], at most 100 characters, starting alphanumeric) and unknown tracking numbers all get the same error. Malformed input never reaches the query.
  • The second tracker call for the top-level eta is gone. The page reads tracker_data.eta.

Notes for the auth refactor

  • driver_assigned was never eager-loaded by this endpoint, so the driver marker and popup never rendered. They still don't. Adding them would expose the driver uuid, which is the driver.{uuid} socket channel.
  • active_stop.address and next_stop.address are kept because the page shows them as "Current/Next Destination". Stop coordinates are kept because the route map needs them.

Tests

  • PublicOrderTrackingResourceTest: exact key sets, a check that no internal value appears at any depth, the driver position gate (dispatched, completed, canceled, CANCELLED), and missing relations.
  • OrderControllerContractsTest: identical error for 8 malformed inputs plus not-found; the query isn't hit for malformed input; relations loaded; trimmed input.
  • RouteRegistrationExecutionTest: the lookup route carries throttle:30,1,tracking-lookup.

…resource

The public Track Order page's GET int/v1/fleet-ops/lookup had no session,
no rate limit, and answered with the full OrderResource: notes, meta,
internal ids, files (possible POD photos and signatures), purchase rate,
and live driver location, to anyone holding a tracking number.

- Rate limit it per address on its own limiter (throttle:30,1,tracking-lookup),
  as the public inspection routes do.
- Answer with PublicOrderTracking, which carries only what
  order-tracking-lookup renders: tracking number, status, timeline, ETA and
  progress, stop coordinates for the route map, and the item list. Records
  are keyed by public id, so no internal uuid reaches the page. The driver
  position is included only while the order is started and unfinished. It
  extends JsonResource so registered resource transformers cannot add fields.
- Missing, malformed and unknown tracking numbers get one identical error,
  and malformed input never reaches the query.
@codecov

codecov Bot commented Oct 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (9ba5d0d) to head (5891d0b).
⚠️ Report is 11 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff             @@
##                main      #352   +/-   ##
===========================================
  Coverage     100.00%   100.00%           
- Complexity     12379     12395   +16     
===========================================
  Files            600       601    +1     
  Lines          46496     46567   +71     
===========================================
+ Hits           46496     46567   +71     
Flag Coverage Δ
backend 100.00% <100.00%> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@roncodes
roncodes changed the base branch from main to release/v0.6.72 October 7, 2026 05:58
@roncodes roncodes mentioned this pull request Oct 7, 2026
@roncodes
roncodes marked this pull request as ready for review October 7, 2026 06:00
@roncodes
roncodes merged commit 3dd4ced into release/v0.6.72 Oct 7, 2026
11 checks passed
@roncodes
roncodes deleted the fix/tracking-lookup-public-resource branch October 7, 2026 06:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant