Repository navigation
fix(tracking): throttle the public order lookup and return a minimal resource - #352
Merged
Merged
Conversation
…resource The public Track Order page's GET int/v1/fleet-ops/lookup had no session, no rate limit, and answered with the full OrderResource: notes, meta, internal ids, files (possible POD photos and signatures), purchase rate, and live driver location, to anyone holding a tracking number. - Rate limit it per address on its own limiter (throttle:30,1,tracking-lookup), as the public inspection routes do. - Answer with PublicOrderTracking, which carries only what order-tracking-lookup renders: tracking number, status, timeline, ETA and progress, stop coordinates for the route map, and the item list. Records are keyed by public id, so no internal uuid reaches the page. The driver position is included only while the order is started and unfinished. It extends JsonResource so registered resource transformers cannot add fields. - Missing, malformed and unknown tracking numbers get one identical error, and malformed input never reaches the query.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #352 +/- ##
===========================================
Coverage 100.00% 100.00%
- Complexity 12379 12395 +16
===========================================
Files 600 601 +1
Lines 46496 46567 +71
===========================================
+ Hits 46496 46567 +71
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Interim hardening of the public Track Order lookup (
GET int/v1/fleet-ops/lookup), ahead of the larger auth refactor.Before
There was no session and no rate limit, and the response was the full
OrderResource: notes, meta,internal_id, files (which can include POD photos and signatures), purchase rate,tracker_datawith the live driver location, and internal uuids. Anyone holding a tracking number got all of it.Changes
throttle:30,1,tracking-lookupper address, on its own limiter. This follows theinspection-publicpattern.PublicOrderTracking. It carries only whatorder-tracking-lookup.hbsrenders:tracking,status,has_driver_assigned,created_attracking_number.tracking_numbertracking_statuses[]:status,details,created_atpayload: pickup, dropoff and waypoints aslocationonly (no name, address or phone; the map needs the coordinates to draw the route), plusentities[]withname,description,tracking,price,currency,photo_urltracker_data:progress.percentageandcompleted_stops,eta.active_stop_secondsandcompletion_at,active_stop.addressandnext_stop.address, anddriver.locationonly while the order is started and not completed or canceledpublic_id, because Ember Data needs an id, so no internal uuid is exposed. The resource extendsJsonResource, notFleetbaseResource, so transformers that other extensions register cannot add fields. It is never wrapped.[A-Za-z0-9._-], at most 100 characters, starting alphanumeric) and unknown tracking numbers all get the same error. Malformed input never reaches the query.etais gone. The page readstracker_data.eta.Notes for the auth refactor
driver_assignedwas never eager-loaded by this endpoint, so the driver marker and popup never rendered. They still don't. Adding them would expose the driver uuid, which is thedriver.{uuid}socket channel.active_stop.addressandnext_stop.addressare kept because the page shows them as "Current/Next Destination". Stop coordinates are kept because the route map needs them.Tests
PublicOrderTrackingResourceTest: exact key sets, a check that no internal value appears at any depth, the driver position gate (dispatched, completed, canceled, CANCELLED), and missing relations.OrderControllerContractsTest: identical error for 8 malformed inputs plus not-found; the query isn't hit for malformed input; relations loaded; trimmed input.RouteRegistrationExecutionTest: the lookup route carriesthrottle:30,1,tracking-lookup.