Skip to content

Conversation

@swatijadhav
Copy link
Contributor

@swatijadhav swatijadhav commented Jan 12, 2021

Ticket Link:

https://jira.crossroads.org.hk/browse/GCW-3407

What does this PR do?

Gogox Gem Integration and Transport APIs

NOTE: webhook implementation is still WIP

Copy link
Member

@steveyken steveyken left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great work. Good to see this taking shape and getting ready to integrate the new GGX booking

@swatijadhav swatijadhav marked this pull request as ready for review January 18, 2021 14:06
@time.to_i
end

class ValueError < StandardError; end
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of just value error defining here, create a error in errors.rb
something like TransportationServiceError

Copy link
Member

@steveyken steveyken left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you remove ngrok binary?

Great work, almost complete

end

api :POST, '/v1/transports/update_hook', "Webhook to update transport status"
def update_hook
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When implemented, we should use our own authorization check here. E.g. webhook can be /api/v1/transports/update_hook?shared_key=ds23f934dfs&param1=df&param2=23

Then check shared_key is as expected.

@swatijadhav swatijadhav requested a review from steveyken February 9, 2021 16:24
Copy link
Member

@steveyken steveyken left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There's a few issues with un-sanitized user input which need to be addressed. Otherwise, looking good.

status: response["status"],
scheduled_at: Time.at(response["pickup"]["schedule_at"]).in_time_zone,
metadata: response,
source_id: @params[:source_id],
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As noted in the controller, this is where source_id and source_type is being overridden by user params rather than the sanitized CanCanCan object. Use @transports instead

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants