feat(apps): تسجيل السائق والدردشة والكوبون — إكمال التغطية

فحص آليّ لنقاط docs/38 مقابل الكود كشف ثغرات لم تظهر بالقراءة.

## تسجيل السائق — أخطر ثغرة
لم يكن موجوداً أصلاً: سائق جديد يسجّل دخوله ثم يقف. بُنيت features/onboarding
كاملة — تقديم ← ملف ← مركبة ← وثائق ← انتظار الاعتماد.
- الخطوة تُشتقّ من حالة الخادم لا من تقدّم محلّي: سائق يعيد تثبيت التطبيق
  يعود إلى حيث وقف لا إلى البداية
- الاعتماد يقع على الخادم تلقائياً حين تكتمل الوثائق؛ التطبيق لا يعتمد أحداً
- عند الاعتماد خروج إجباري: الدور يتغيّر على الخادم والتوكن القديم يحمل
  القديم، فتفشل نقاط السائق بـ403 (مصيدة docs/38 §5)
- بوابة توجيه: مستخدم دوره ليس driver يُحجز في /onboarding
- الوثائق تُصوَّر بالكاميرا لا من المعرض: أصعب تزويراً

## الدردشة والكوبون
- Features.chat كان مفعّلاً بلا ميزة. features/chat باستطلاع كل خمس ثوان —
  قائمة أحداث الخادم لا تتضمّن الرسائل (docs/38 §9)، فالاستطلاع قيد خادم لا
  اختيار تصميمي
- الكوبون: حقل في ورقة التأكيد خلف طبقتَي الميزات، يُقيَّم على الخادم

## Features.calls أُطفئ صراحةً
الخادم يدعم WebRTC والتطبيق لا. عَلَم مفعّل بلا ميزة كذبٌ على القارئ التالي.

## بنية
- ApiClient.upload للرفع متعدّد الأجزاء
- AuthFailure → ApiFailure في core/api: يخدم المصادقة والملف والتسجيل
- tool/sync_from_rider.sh: المزامنة اليدوية بين التوأمين انكسرت أربع مرات،
  فصارت سكربتاً واحداً يعرّف ما يملكه كل تطبيق

flutter analyze نظيف · الراكب 101 ملف/7,809 سطر · السائق 110 ملف/8,116 سطر.
فحوص آلية: صفر استيراد بين ميزتين · صفر عَلَم مفعّل بلا ميزة · كل نقاط العقد
المخصّصة للتطبيقين مستهلكة.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Hamza-Ayed
2026-08-05 00:04:28 +03:00
co-authored by Claude Opus 5
parent 096acae74e
commit bb2c0de478
56 changed files with 1936 additions and 68 deletions
@@ -47,6 +47,22 @@ class ApiClient {
Future<T> delete<T>(String path) => _send(() => _dio.delete<T>(path));
/// رفع ملف — الحقل اسمه `file` كما يتوقّعه `FileInterceptor` على الخادم.
/// يمرّ بنفس الـinterceptor فيحمل التوكن والمستأجر والجهاز.
Future<T> upload<T>(
String path, {
required String filePath,
Map<String, dynamic> fields = const {},
}) {
return _send(() async {
final form = FormData.fromMap({
...fields,
'file': await MultipartFile.fromFile(filePath),
});
return _dio.post<T>(path, data: form);
});
}
Future<T> _send<T>(Future<Response<T>> Function() call) async {
try {
final res = await call();
@@ -7,7 +7,7 @@ import 'api_exception.dart';
/// كل نص مرئي بطبقة الترجمة. والـCubit لا يعرف `BuildContext` (docs/23 §3).
/// الجمع بينها: الـCubit يُصدر الرمز، والواجهة تترجمه سطراً واحداً — فتبقى
/// الشاشة بلا منطق، والنص بلغتين.
enum AuthFailure {
enum ApiFailure {
/// رمز خاطئ أو منتهي الصلاحية.
invalidCode,
@@ -22,17 +22,17 @@ enum AuthFailure {
server,
}
extension AuthFailureX on ApiException {
AuthFailure toAuthFailure() {
if (isRateLimited) return AuthFailure.rateLimited;
if (kind == ApiErrorKind.network) return AuthFailure.network;
if (kind == ApiErrorKind.timeout) return AuthFailure.timeout;
extension ApiFailureX on ApiException {
ApiFailure toApiFailure() {
if (isRateLimited) return ApiFailure.rateLimited;
if (kind == ApiErrorKind.network) return ApiFailure.network;
if (kind == ApiErrorKind.timeout) return ApiFailure.timeout;
if (isUnauthorized) {
// الخادم يفرّق بين «رمز خاطئ» و«محاولات كثيرة» بالنصّ وحده.
return message.contains('Too many')
? AuthFailure.tooManyAttempts
: AuthFailure.invalidCode;
? ApiFailure.tooManyAttempts
: ApiFailure.invalidCode;
}
return AuthFailure.server;
return ApiFailure.server;
}
}
+3 -1
View File
@@ -31,7 +31,9 @@ class Features {
static const bool wallet = true;
static const bool chat = true;
static const bool calls = true;
/// WebRTC غير مبنيّ بعد — الخادم يدعمه (`call:*` في docs/38 §9) لكن
/// التطبيق لا. يبقى مطفأً حتى يُبنى ويُختبر على جهاز حقيقي.
static const bool calls = false;
static const bool rideTypes = true;
static const bool coupons = true;
static const bool geofence = false;
+13
View File
@@ -21,6 +21,10 @@ import '../features/settings/cubit/settings_cubit.dart';
import '../features/trip/cubit/history_cubit.dart';
import '../features/chat/cubit/chat_cubit.dart';
import '../features/chat/data/chat_repository.dart';
import '../features/onboarding/cubit/onboarding_cubit.dart';
import '../features/onboarding/data/driver_repository.dart';
import '../features/trip/cubit/duty_cubit.dart';
import '../features/trip/data/history_repository.dart';
@@ -99,12 +103,21 @@ Future<void> setupInjector() async {
sl.registerSingleton<TenantCubit>(TenantCubit(sl(), prefs));
sl.registerSingleton<PushService>(PushService(sl()));
sl.registerSingleton<DriverRepository>(DriverRepository(sl()));
sl.registerFactory<OnboardingCubit>(() => OnboardingCubit(sl()));
sl.registerSingleton<HistoryRepository>(HistoryRepository(sl()));
sl.registerFactory<HistoryCubit>(() => HistoryCubit(sl()));
sl.registerSingleton<RatingRepository>(RatingRepository(sl()));
sl.registerFactory<RatingCubit>(() => RatingCubit(sl()));
// الدردشة خلف علمها: إطفاؤه يحذف كودها من الـbinary (docs/23 §5).
if (Features.chat) {
sl.registerSingleton<ChatRepository>(ChatRepository(sl()));
sl.registerFactory<ChatCubit>(() => ChatCubit(sl()));
}
// المحفظة خلف علم الاستحقاق: الميزة المطفأة لا تُسجَّل أصلاً (docs/23 §5).
if (Features.wallet) {
sl.registerSingleton<WalletRepository>(WalletRepository(sl()));
+37 -1
View File
@@ -188,5 +188,41 @@
"aboutVersion": "الإصدار",
"notifTitle": "الإشعارات",
"notifEnable": "تفعيل الإشعارات",
"notifDenied": "الإشعارات موقوفة من إعدادات النظام"
"notifDenied": "الإشعارات موقوفة من إعدادات النظام",
"chatTitle": "المحادثة",
"chatHint": "اكتب رسالة",
"chatEmpty": "لا رسائل بعد",
"rideCoupon": "كود خصم",
"rideCouponApply": "تطبيق",
"obApplyTitle": "سجّل كسائق",
"obApplyLead": "خطوات قصيرة ثم تبدأ العمل",
"obVehicleMake": "شركة السيارة",
"obServiceClass": "نوع الخدمة",
"obApplySubmit": "ابدأ التسجيل",
"obProfileTitle": "بياناتك",
"obNameArabic": "الاسم كما في الهوية",
"obNationalNumber": "الرقم الوطني",
"obGender": "الجنس",
"obGenderMale": "ذكر",
"obGenderFemale": "أنثى",
"obVehicleTitle": "مركبتك",
"obVehicleModel": "الطراز",
"obVehicleYear": "سنة الصنع",
"obVehicleColor": "اللون",
"obVehiclePlate": "رقم اللوحة",
"obDocsTitle": "وثائقك",
"obDocsLead": "صوّر كل وثيقة بوضوح — الاعتماد يتم بعد مراجعتها",
"obDocMissing": "مطلوبة",
"obDocPending": "قيد المراجعة",
"obDocApproved": "مقبولة",
"obDocRejected": "مرفوضة — أعد الرفع",
"obDocSideFront": "الوجه الأمامي",
"obDocSideBack": "الوجه الخلفي",
"obDocUpload": "رفع",
"obPendingTitle": "طلبك قيد المراجعة",
"obPendingLead": "سنُعلمك فور اعتماد حسابك. عادةً خلال يوم عمل.",
"obPendingRefresh": "تحديث الحالة",
"obApprovedTitle": "تم اعتمادك",
"obApprovedLead": "سجّل الدخول من جديد لتفعيل صلاحيات السائق",
"obRelogin": "إعادة تسجيل الدخول"
}
+37 -1
View File
@@ -188,5 +188,41 @@
"aboutVersion": "Version",
"notifTitle": "Notifications",
"notifEnable": "Enable notifications",
"notifDenied": "Notifications are disabled in system settings"
"notifDenied": "Notifications are disabled in system settings",
"chatTitle": "Chat",
"chatHint": "Type a message",
"chatEmpty": "No messages yet",
"rideCoupon": "Promo code",
"rideCouponApply": "Apply",
"obApplyTitle": "Register as a driver",
"obApplyLead": "A few short steps, then you're working",
"obVehicleMake": "Car make",
"obServiceClass": "Service class",
"obApplySubmit": "Start registration",
"obProfileTitle": "Your details",
"obNameArabic": "Name as on your ID",
"obNationalNumber": "National ID number",
"obGender": "Gender",
"obGenderMale": "Male",
"obGenderFemale": "Female",
"obVehicleTitle": "Your vehicle",
"obVehicleModel": "Model",
"obVehicleYear": "Year",
"obVehicleColor": "Colour",
"obVehiclePlate": "Plate number",
"obDocsTitle": "Your documents",
"obDocsLead": "Photograph each document clearly — approval follows review",
"obDocMissing": "Required",
"obDocPending": "Under review",
"obDocApproved": "Approved",
"obDocRejected": "Rejected — upload again",
"obDocSideFront": "Front",
"obDocSideBack": "Back",
"obDocUpload": "Upload",
"obPendingTitle": "Your application is under review",
"obPendingLead": "We'll notify you as soon as it's approved. Usually within a business day.",
"obPendingRefresh": "Refresh status",
"obApprovedTitle": "You're approved",
"obApprovedLead": "Sign in again to activate your driver permissions",
"obRelogin": "Sign in again"
}
+18
View File
@@ -22,6 +22,8 @@ import '../features/support/view/support_page.dart';
import '../features/trip/view/history_page.dart';
import '../features/chat/view/chat_page.dart';
import '../features/onboarding/view/onboarding_page.dart';
import '../features/trip/view/duty_page.dart';
import '../features/wallet/view/earnings_page.dart';
@@ -44,6 +46,8 @@ class Routes {
static const profileEdit = '/account';
static const settings = '/settings';
static const support = '/support';
static const chat = '/chat';
static const onboarding = '/onboarding';
}
/// التوجيه يُشتقّ من `SessionCubit` وحده — لا `Navigator.push` بعد الدخول
@@ -66,6 +70,11 @@ final appRouter = GoRouter(
// (docs/38 §7 — يُفرض عند الفتح).
SessionStatus.authenticated when session.pendingRating != null =>
loc == Routes.rating ? null : Routes.rating,
// السائق غير المعتمد يُحجز في التسجيل: دوره لا يزال `rider` على
// الخادم، فكل نقاط السائق ترجّع 403 (docs/38 §5).
SessionStatus.authenticated
when session.user?.role != 'driver' && loc != Routes.onboarding =>
Routes.onboarding,
SessionStatus.authenticated => (loc == Routes.login ||
loc == Routes.profile ||
loc == Routes.splash ||
@@ -117,6 +126,15 @@ final appRouter = GoRouter(
path: Routes.settings,
builder: (context, state) => const SettingsPage(),
),
GoRoute(
path: Routes.chat,
builder: (context, state) =>
ChatPage(tripId: state.uri.queryParameters['trip'] ?? ''),
),
GoRoute(
path: Routes.onboarding,
builder: (context, state) => const OnboardingPage(),
),
GoRoute(
path: Routes.support,
builder: (context, state) => const SupportPage(),
+10 -10
View File
@@ -12,20 +12,20 @@ import '../l10n/l10n.dart';
/// النقطة **الوحيدة** التي تُترجَم فيها رموز الفشل إلى نصّ.
/// الشاشات لا تكتب رسائل خطأ، والـCubit لا يعرف اللغة (راجع `auth_failure.dart`).
class AuthFailureText extends StatelessWidget {
const AuthFailureText({super.key, required this.failure});
class ApiFailureText extends StatelessWidget {
const ApiFailureText({super.key, required this.failure});
final AuthFailure failure;
final ApiFailure failure;
static String messageOf(BuildContext context, AuthFailure failure) {
static String messageOf(BuildContext context, ApiFailure failure) {
final l10n = context.l10n;
return switch (failure) {
AuthFailure.invalidCode => l10n.otpErrInvalid,
AuthFailure.tooManyAttempts => l10n.otpErrTooManyAttempts,
AuthFailure.rateLimited => l10n.otpErrRateLimited,
AuthFailure.network => l10n.errorNetwork,
AuthFailure.timeout => l10n.errorTimeout,
AuthFailure.server => l10n.errorGeneric,
ApiFailure.invalidCode => l10n.otpErrInvalid,
ApiFailure.tooManyAttempts => l10n.otpErrTooManyAttempts,
ApiFailure.rateLimited => l10n.otpErrRateLimited,
ApiFailure.network => l10n.errorNetwork,
ApiFailure.timeout => l10n.errorTimeout,
ApiFailure.server => l10n.errorGeneric,
};
}