feat: own the JetStream subject contract, and ingest jupiter rider telemetry

Half of this binary's js.Publish calls were bound to no stream at all.
The streams were declared only by an external Python script on another
machine (Birock/doormile-bookings/setup_jetstream.py) and had drifted
from the code: booking.cancelled, booking.outcome and
booking.assignment_failed had no stream, and CHAT declared the literal
"chat.room.closed" while chat.go publishes "chat.room.closed.<id>",
which it does not match. Every publish site is best-effort
(`if db.Js != nil` + warn-log), so those events were failing and being
dropped silently — every cancellation, delivery outcome and assignment
failure since the streams were created.

db.EnsureStreams now declares the streams at startup from a map that
sits next to the code that publishes, so the contract cannot drift
again. It only ever adds: existing streams keep their storage type,
retention, limits and every subject they already have. Nothing is
deleted. Losing the create race against a sibling replica is expected
and reconciles rather than erroring.

Alongside that, /internal/miler/* ingests rider telemetry still arriving
over the jupiter NATS chain. The forwarding worker holds no rider JWT —
the rider app is still jupiter-shaped — so LegacyMilerIdentity resolves
an identity from a header into c.Locals("userid") behind the existing
X-Internal-Key guard. That lets the routes reuse the miler handlers
unchanged instead of growing a parallel set that would drift.

Identity comes from a header, never the body: the telemetry handlers
overwrite a body-supplied userid precisely so one rider cannot write
another's GPS trail, and reading it from the body here would reopen that
from behind the internal key. MilerProfile.Legacyuserid (nullable,
indexed) maps a jupiter userid to a Doormile one.

Only fire-and-forget telemetry is exposed. Transactional actions stay
synchronous — a rider needs a real answer from pickup-complete, which a
queue in front of it cannot give.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Suriya
2026-08-10 12:56:30 +05:30
parent 90fa4fbb74
commit 6738d37d7b
5 changed files with 251 additions and 8 deletions

View File

@@ -84,14 +84,21 @@ func (AppUser) TableName() string {
}
type MilerProfile struct {
Milerprofileid int `json:"milerprofileid" gorm:"primaryKey;column:milerprofileid"`
Userid int `json:"userid" gorm:"column:userid;unique;not null"`
Applocationid int `json:"applocationid" gorm:"column:applocationid;default:1"`
Displayname string `json:"displayname" gorm:"column:displayname;not null"`
Phone string `json:"phone" gorm:"column:phone;not null"`
Profilephotourl string `json:"profilephotourl" gorm:"column:profilephotourl"`
Vehicleid *int `json:"vehicleid" gorm:"column:vehicleid"`
Hubid *int `json:"hubid" gorm:"column:hubid"`
Milerprofileid int `json:"milerprofileid" gorm:"primaryKey;column:milerprofileid"`
Userid int `json:"userid" gorm:"column:userid;unique;not null"`
Applocationid int `json:"applocationid" gorm:"column:applocationid;default:1"`
Displayname string `json:"displayname" gorm:"column:displayname;not null"`
Phone string `json:"phone" gorm:"column:phone;not null"`
Profilephotourl string `json:"profilephotourl" gorm:"column:profilephotourl"`
Vehicleid *int `json:"vehicleid" gorm:"column:vehicleid"`
Hubid *int `json:"hubid" gorm:"column:hubid"`
// Legacyuserid is this rider's userid in the old jupiter/Nearle system, for
// riders migrated from it. It exists so telemetry still arriving over the
// jupiter NATS chain — which identifies a rider by jupiter's userid and has
// no Doormile token — can be resolved to a Doormile rider. Nil for riders
// created natively in Doormile, which is the normal case. Never used for
// authentication: it identifies, the X-Internal-Key authenticates.
Legacyuserid *int `json:"legacyuserid,omitempty" gorm:"column:legacyuserid;index"`
Defaultvehicletype string `json:"defaultvehicletype" gorm:"column:defaultvehicletype"`
Currentlatitude float64 `json:"currentlatitude" gorm:"column:currentlatitude"`
Currentlongitude float64 `json:"currentlongitude" gorm:"column:currentlongitude"`