feat: N4/N5 — لوحتا أدمن المستأجر وخدمة العملاء (ويب)

نقاط سرد إدارية (خلف RolesGuard admin/dispatcher):
- GET /drivers/admin/list — سائقو المستأجر (بترشيح الاعتماد)
- GET /trips/admin/list — رحلات المستأجر (بترشيح الحالة/الراكب)
- GET /payouts/admin/list — سحوبات المستأجر (بترشيح الحالة)
- GET /admin/users/search?phone= — بحث خدمة العملاء (يُطبَّع ويُبحث بالفهرس
  الأعمى، لا يُعرض الرقم الخام)

اللوحتان (SPA مكتفية ذاتياً، vanilla JS، RTL):
- admin-web: دخول أدمن (هاتف+OTP) → سائقون (اعتماد) · رحلات · مراجعة وثائق
  (قبول/رفض) · سحوبات (تحويل/فشل). تحقّقت أنها تُصيَّر نظيفاً في المعاينة.
- service-web: بحث مستخدم برقمه → بياناته ورحلاته + تفاصيل رحلة بالمعرّف.

المصادقة هاتف+OTP → JWT بدور admin/dispatcher (نفس الموبايل). الحماية على
السيرفر؛ الواجهة عرض فقط. الوصول بـ?tenant=<slug>.

E2E موسّع: يثبت أن السائق/الراكب (غير أدمن) يُرفضان من النقاط الإدارية (403).
الشكاوى تحتاج وحدة complaints (لاحقاً). لا هجرة.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Hamza-Ayed
2026-07-18 03:55:23 +03:00
co-authored by Claude Opus 4.8
parent c93be38622
commit 5cad6adbde
11 changed files with 380 additions and 5 deletions
@@ -1,7 +1,9 @@
import { Body, Controller, Get, Param, Patch, Post, UseGuards } from '@nestjs/common';
import { Body, Controller, Get, Param, Patch, Post, Query, UseGuards } from '@nestjs/common';
import { ApiBearerAuth, ApiTags } from '@nestjs/swagger';
import { DriversService } from './drivers.service';
import { JwtAuthGuard } from '../auth/guards/jwt-auth.guard';
import { RolesGuard } from '../auth/guards/roles.guard';
import { Roles } from '../auth/decorators/roles.decorator';
import { CurrentUser, AuthUser } from '../auth/decorators/current-user.decorator';
@ApiTags('drivers')
@@ -11,6 +13,14 @@ import { CurrentUser, AuthUser } from '../auth/decorators/current-user.decorator
export class DriversController {
constructor(private readonly drivers: DriversService) {}
/** سرد سائقي المستأجر — للوحة الأدمن (docs/22 — N4). */
@UseGuards(RolesGuard)
@Roles('admin', 'dispatcher')
@Get('admin/list')
adminList(@CurrentUser() user: AuthUser, @Query('verification') verification?: string) {
return this.drivers.listByTenant(user.tenantId, verification);
}
@Post('apply')
apply(@CurrentUser() user: AuthUser, @Body() body: any) {
return this.drivers.apply(user.tenantId, user.userId, body);
@@ -102,6 +102,13 @@ export class DriversService {
});
}
/** سرد سائقي المستأجر للوحة الأدمن (docs/22 — N4). */
listByTenant(tenantId: string, verification?: string): Promise<Driver[]> {
const where: any = { tenant_id: tenantId };
if (verification) where.verification_status = verification;
return this.repo.find({ where, order: { created_at: 'DESC' }, take: 200 });
}
async setRating(tenantId: string, driverId: string, rating: number): Promise<void> {
await this.repo.update(
{ tenant_id: tenantId, id: driverId },
@@ -1,4 +1,4 @@
import { Body, Controller, Get, Param, Patch, Post, Req, UseGuards } from '@nestjs/common';
import { Body, Controller, Get, Param, Patch, Post, Query, Req, UseGuards } from '@nestjs/common';
import { ApiBearerAuth, ApiTags } from '@nestjs/swagger';
import { Throttle } from '@nestjs/throttler';
import { PayoutsService, RequestContext } from './payouts.service';
@@ -69,6 +69,14 @@ export class PayoutsController {
return this.payouts.listMine(user.tenantId, user.userId);
}
/** سرد سحوبات المستأجر — للأدمن، بترشيح الحالة (docs/22 — N4). */
@UseGuards(JwtAuthGuard, RolesGuard)
@Roles('admin', 'dispatcher')
@Get('admin/list')
adminList(@CurrentUser() user: AuthUser, @Query('status') status?: string) {
return this.payouts.listByTenant(user.tenantId, status);
}
// الأدمن يؤكّد/يفشل التحويل
@UseGuards(JwtAuthGuard, RolesGuard)
@Roles('admin', 'dispatcher')
@@ -174,6 +174,13 @@ export class PayoutsService {
});
}
/** سرد سحوبات المستأجر للأدمن (docs/22 — N4)، بترشيح الحالة. */
listByTenant(tenantId: string, status?: string) {
const where: any = { tenant_id: tenantId };
if (status) where.status = status;
return this.repo.find({ where, order: { created_at: 'DESC' }, take: 100 });
}
/** الأدمن يؤكّد أن المبلغ حُوِّل خارجياً. */
async complete(
tenantId: string,
+15 -1
View File
@@ -1,8 +1,10 @@
import { Body, Controller, Get, Param, Patch, Post, UseGuards } from '@nestjs/common';
import { Body, Controller, Get, Param, Patch, Post, Query, UseGuards } from '@nestjs/common';
import { ApiBearerAuth, ApiTags } from '@nestjs/swagger';
import { TripsService, RequestTripDto } from './trips.service';
import { TripStatus } from './entities/trip.entity';
import { JwtAuthGuard } from '../auth/guards/jwt-auth.guard';
import { RolesGuard } from '../auth/guards/roles.guard';
import { Roles } from '../auth/decorators/roles.decorator';
import { CurrentUser, AuthUser } from '../auth/decorators/current-user.decorator';
@ApiTags('trips')
@@ -12,6 +14,18 @@ import { CurrentUser, AuthUser } from '../auth/decorators/current-user.decorator
export class TripsController {
constructor(private readonly trips: TripsService) {}
/** سرد رحلات المستأجر — للوحة الأدمن، بترشيح الحالة (docs/22 — N4). */
@UseGuards(RolesGuard)
@Roles('admin', 'dispatcher')
@Get('admin/list')
adminList(
@CurrentUser() user: AuthUser,
@Query('status') status?: string,
@Query('rider') rider?: string,
) {
return this.trips.listByTenant(user.tenantId, status, rider);
}
// الراكب يطلب رحلة
@Post()
request(@CurrentUser() user: AuthUser, @Body() body: RequestTripDto) {
@@ -115,6 +115,14 @@ export class TripsService {
return qb.orderBy('t.completed_at', 'DESC').take(limit).getMany();
}
/** سرد رحلات المستأجر للوحة الأدمن، بترشيح الحالة أو الراكب (docs/22 — N4/N5). */
listByTenant(tenantId: string, status?: string, riderId?: string): Promise<Trip[]> {
const where: any = { tenant_id: tenantId };
if (status) where.status = status;
if (riderId) where.rider_id = riderId; // خدمة العملاء: رحلات مستخدم بعينه
return this.trips.find({ where, order: { requested_at: 'DESC' }, take: 100 });
}
listForDriver(tenantId: string, driverId: string): Promise<Trip[]> {
return this.trips.find({
where: { tenant_id: tenantId, driver_id: driverId },
@@ -2,10 +2,12 @@ import {
BadRequestException,
Body,
Controller,
Get,
NotFoundException,
Param,
Patch,
Post,
Query,
UseGuards,
} from '@nestjs/common';
import { ApiBearerAuth, ApiSecurity, ApiTags } from '@nestjs/swagger';
@@ -29,6 +31,20 @@ export class AdminUsersController {
private readonly phones: PhoneService,
) {}
/** بحث خدمة العملاء عن مستخدم برقم هاتفه (docs/22 — N5). يُطبَّع ثم يُبحث
* بالفهرس الأعمى — لا يُعرض الرقم الخام. نطاقه المستأجر من التوكن. */
@ApiBearerAuth()
@UseGuards(JwtAuthGuard, RolesGuard)
@Roles('admin', 'dispatcher')
@Get('admin/users/search')
async search(@CurrentUser() user: AuthUser, @Query('phone') phone: string) {
if (!phone) throw new BadRequestException('phone is required');
const tenant = await this.tenants.resolve(user.tenantId);
const canonical = this.phones.normalize(phone, tenant?.countryPack ?? 'jo');
const u = await this.users.findByPhone(user.tenantId, canonical);
return u ? { id: u.id, phone: u.phone, role: u.role, rating: u.rating, status: u.status } : null;
}
// أدمن **المستأجر** يعيّن دور مستخدم داخل مستأجره هو — هذه ليست نقطة منصة،
// ونطاقها مضمون بـ user.tenantId القادم من التوكن.
@ApiBearerAuth()