Repository navigation
feat(chat): customer chat with the driver delivering their order - #117
Merged
Merged
Conversation
…annel resolvers
- POST storefront/v1/customers/socket-token mints a customer principal (store key +
Customer-Token); 404 while socket auth is disabled, 401 without a customer of the
storefront's company.
- Checkout initialization responses carry socket_token (checkout kind, scp limited to
checkout.{public_id}) when socket auth is enabled; absent otherwise.
- Register storefront and checkout channel resolvers with core-api's
SocketChannelRegistry.
- QPay capture publishes {checkout, status, order, error} on checkout.{public_id}
instead of the raw payment row; a publish failure no longer fails the callback.
- Require fleetbase/core-api ^1.6.69.
- storefront/v1/orders/{id}/chat: show (starts the chat), messages (cursor
pagination), send (text and up to four photos) and read (receipts), for the
signed-in customer's own orders in this storefront.
- The chat is a core chat channel tagged with the order in its meta, so the
driver sees it in Navigator; participants are kept to the customer and the
currently assigned driver, and it is started when a driver is assigned.
- Customers can read but not send once the order is completed, canceled or
expired.
- Driver messages are pushed to the customer through storefront push, the inbox
and the customer's broadcast channel.
- Customer socket tokens include the customer's user uuid so they can subscribe
to chat_channel.{uuid}, which core authorizes by participant.
This was referenced Oct 6, 2026
Open
…-chat # Conflicts: # server/tests/Unit/Routes/StorefrontRoutesTest.php
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The storefront-app redesign lets a customer message the driver delivering their order, from the tracking screen and from push notifications. Fleetbase core already has chat channels, and the driver app already lists them. But customers couldn't use them:
Customer-Token;This PR adds an order chat for storefront customers. It is built on core chat channels, so the driver side works unchanged.
Customer-Token)GET storefront/v1/orders/{id}/chat{id, channel, order, status, me, participants[], messages[] (latest 50, oldest first), unread_count}GET storefront/v1/orders/{id}/chat/messages?before={message_id}&limit=POST storefront/v1/orders/{id}/chat/messages{content?, files?: [{data (base64), type: image/*}]}, at most 4 photosPOST storefront/v1/orders/{id}/chat/read{read: n}This branch is stacked on #113 (socket auth). The customer socket token gains the customer's user uuid in
ids, so the app can subscribe tochat_channel.{uuid}. Core (fleetbase/core-api#290) authorizes those channels by participant user.Related Issue
Part of the storefront-app redesign (driver chat on order tracking).
Type of Change
Implementation Notes
Support/OrderChatFleetbase\Models\ChatChannelwithmeta.storefront_order_uuidandmeta.storefront_order_id, named "Order {public_id}".open()creates it with the customer's user as creator, which core adds as the first participant. It then syncs participants to exactly the customer and the currently assigned driver's user. On reassignment, the previous driver is removed and the new one added.OrderChatControllerstorefront_idmust match a store key, or itsstorefront_network_ida network key. The order must belong to the customer (403).{reason: driver_not_assigned}.completed,canceledorexpired, the chat is read-only:status: closed, and sending returns 423{reason: chat_closed}. It also isn't started for an order that finished without one.(created_at, id)cursor, so messages sent in the same second aren't skipped.File(type = storefront_chat_upload, withdisk) plusChatAttachment.notifyParticipants()notifies the driver (broadcast, FCM/APNs) as it does for any chat.OrderChatandOrderChatMessagegive the app a stable shape. Each participant and sender carriesrole: customer|driver, and each message hasis_mineandread.avatar_urlis null when the user has no avatar, so the app can show initials.ChatMessageObserversendsStorefrontOrderChatMessagewhen someone other than the customer writes in an order chat. That goes through storefront push, the database inbox and the customer broadcast channel. The push reads "Ravi K. sent a message" or "Sent a photo", withtype,order_id,chat_idandmessage_id. It isn't gated by notification preferences, because it is about an active order.HandleOrderDriverAssignedstarts the chat when a driver is assigned, so it is already in the driver's Navigator chat list. A failure is reported and doesn't affect the existing driver-assigned notification.StorefrontSocket::customerPrincipalnow putsuser_uuidinidswhen the customer has one.Validation
Command output / summary:
New
server/tests/Unit/Http/Controllers/OrderChatControllerTest.php(17 tests) covers:FileandChatAttachmentrecords, the driver notified through core);StorefrontSocketTestnow asserts the user uuid in customerids, and that a customer without a user keeps contact ids only. The route contract test lists the four chat routes.Documentation Impact
fleetbase/fleetbase.ioAPI Reference Impact
fleetbase/postmanAPI reference notes:
order_chat_message.idsnow include the user uuid.Documentation Notes
The storefront API docs and Postman need the order chat endpoints and the socket channel name (
chat_channel.{uuid}, returned aschannel).Risk
meta.storefront_order_uuid) is a follow-up in navigator-app.Socket channel
The chat payload's
channelis nowchat.{public_id}. Core broadcasts chat lifecycle events (chat_message.createdand so on) onchat.{id}, and core-api#290 authorizes that name for participants. The earlierchat_channel.{uuid}was authorized but never broadcast on.