Compare commits

..
Author SHA1 Message Date
Logan CusanoandClaude Opus 5.5 bff69a1d04 ADS-B map: altitude-colored aircraft icons + click-to-show flight trail
Icons were 16px accent-colored glyphs, indistinguishable from OSM's own
airport symbols. Now a 30px outlined airliner silhouette filled on
tar1090/ADS-B Exchange's altitude hue ramp, with a callsign/altitude
hover tooltip; the selected aircraft grows and gets a white outline.

Clicking an aircraft draws the path heard so far, segment-colored by
altitude. c2-core writes one point per position change to
aircraft/{icao}/positions (deduped in-process, writes now concurrent);
points carry expire_at and a TTL fieldOverride deletes them after ~24h.
Trail reads are gated on the parent aircraft doc's org via get(), so the
query needs no org filter or composite index. The latest stretch without
a 20-min gap counts as the current flight.

Verified: c2-core pytest 479 passed; frontend tsc --noEmit clean (node:20
container on radio-box).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-27 13:12:36 -04:00
Logan CusanoandClaude Opus 5.5 9b83f0ec6d Merge ci/firestore-sa-auth: service-account auth for Firestore rules deploy (#51)
Build & Deploy / Build & push images (push) Successful in 4m14s
Build & Deploy / Deploy Firestore rules & indexes (push) Successful in 30s
Build & Deploy / Deploy to VM (push) Successful in 1m40s
Build & Deploy / Report a failed deploy (push) Skipped
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-27 12:57:07 -04:00
Logan CusanoandClaude Opus 5.5 5845fc5694 ci: deploy Firestore rules with a service account, not login:ci (#51)
The deploy-firestore-rules job has failed on every push because
FIREBASE_TOKEN was never set, so rule changes (e.g. aircraft/vessels for
node-26#9) never reached prod. Switch to a dedicated least-privilege
service account whose JSON key lives in FIREBASE_SA_KEY; login:ci tokens
are deprecated and carry their minter's full access. Key is written to
RUNNER_TEMP at 0600 and removed on exit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-27 12:46:33 -04:00
logan ddf13402d0 Merge pull request 'correlator: a radio code is not a location' (#182) from fix/radio-code-location into main
Build & Deploy / Build & push images (push) Successful in 4m9s
Build & Deploy / Deploy Firestore rules & indexes (push) Failing after 3s
Build & Deploy / Deploy to VM (push) Successful in 1m48s
Build & Deploy / Report a failed deploy (push) Successful in 1s
2026-09-27 11:32:12 -04:00
Logan CusanoandClaude Opus 5.5 20c5799a8d correlator: a radio code is not a location
A 09-22 replay stop was titled "Traffic Stop at 96 times 5" — a disposition
code read aloud, extracted as the location (server-26#170). clean_location
now rejects "N times N", ten-codes, "signal N", "code N", "condition N".

c2-core: 476 pass.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-27 11:32:09 -04:00
logan e90a73ff09 Merge pull request 'intelligence: a plate read on a patrol channel is a traffic stop' (#181) from feat/plate-read-stops into main
Build & Deploy / Build & push images (push) Successful in 4m6s
Build & Deploy / Deploy Firestore rules & indexes (push) Failing after 4s
Build & Deploy / Deploy to VM (push) Successful in 2m6s
Build & Deploy / Report a failed deploy (push) Successful in 1s
2026-09-27 10:19:27 -04:00
10 changed files with 296 additions and 50 deletions
+15 -13
View File
@@ -307,28 +307,30 @@ jobs:
- name: Deploy firestore rules and indexes - name: Deploy firestore rules and indexes
env: env:
FIREBASE_TOKEN: ${{ secrets.FIREBASE_TOKEN }} FIREBASE_SA_KEY: ${{ secrets.FIREBASE_SA_KEY }}
run: | run: |
set -e set -e
# server-26#51: this used to run over SSH on the deploy VM, gated # server-26#51: this used to run over SSH on the deploy VM, gated
# on the VM having firebase-tools installed. It never did, so it # on the VM having firebase-tools installed. It never did, so it
# silently warned-and-skipped on every single deploy for weeks. # silently warned-and-skipped on every single deploy for weeks.
# Running it here instead means the only prerequisite is a secret # Auth is a dedicated service account (drb-ci-firestore-deploy,
# -- FIREBASE_TOKEN, from `firebase login:ci` -- rather than # roles: Firebase Rules Admin, Cloud Datastore Index Admin,
# something installed by hand on a machine this pipeline doesn't # Service Usage Consumer), its JSON key stored as the
# otherwise touch. A missing token now fails this job LOUDLY # FIREBASE_SA_KEY secret. Not `firebase login:ci`: those tokens are
# (picked up by notify-failure) instead of a buried warning line # deprecated and carry the full permissions of whoever minted them.
# nobody reads in the app deploy's logs. # A missing key fails this job LOUDLY (picked up by notify-failure).
if [ -z "$FIREBASE_TOKEN" ]; then if [ -z "$FIREBASE_SA_KEY" ]; then
echo "FIREBASE_TOKEN secret is not set -- cannot deploy Firestore rules/indexes." >&2 echo "FIREBASE_SA_KEY secret is not set -- cannot deploy Firestore rules/indexes." >&2
echo "Generate one with 'firebase login:ci' and add it as a Gitea Actions secret." >&2 echo "Add the drb-ci-firestore-deploy service account's JSON key as a Gitea Actions secret." >&2
exit 1 exit 1
fi fi
export GOOGLE_APPLICATION_CREDENTIALS="$RUNNER_TEMP/firebase-sa.json"
trap 'rm -f "$GOOGLE_APPLICATION_CREDENTIALS"' EXIT
( umask 077 && printf '%s' "$FIREBASE_SA_KEY" > "$GOOGLE_APPLICATION_CREDENTIALS" )
npm install -g firebase-tools npm install -g firebase-tools
cd infra/firestore cd infra/firestore
firebase deploy --only firestore:rules,firestore:indexes \ firebase deploy --only firestore:rules,firestore:indexes \
--project ${{ secrets.FIREBASE_PROJECT_ID }} \ --project ${{ secrets.FIREBASE_PROJECT_ID }} --non-interactive
--token "$FIREBASE_TOKEN" --non-interactive
notify-failure: notify-failure:
name: Report a failed deploy name: Report a failed deploy
@@ -371,7 +373,7 @@ jobs:
# failed before any deploy was attempted" text even when the app # failed before any deploy was attempted" text even when the app
# deployed fine and only the Firestore rules/indexes push failed. # deployed fine and only the Firestore rules/indexes push failed.
if deploy_result != "failure" and rules_result == "failure": if deploy_result != "failure" and rules_result == "failure":
detail = "App deploy succeeded; Firestore rules/indexes deploy FAILED (server-26#51). Rules may be stale — check FIREBASE_TOKEN and the job log." detail = "App deploy succeeded; Firestore rules/indexes deploy FAILED (server-26#51). Rules may be stale — check the FIREBASE_SA_KEY secret and the job log."
# server-26#65: the old text here unconditionally claimed # server-26#65: the old text here unconditionally claimed
# "production is still running the previous build" -- true only # "production is still running the previous build" -- true only
@@ -343,9 +343,21 @@ def clean_location(value) -> Optional[str]:
s = str(value).strip() s = str(value).strip()
if not s or not _LOCATION_WORD_RE.search(s): if not s or not _LOCATION_WORD_RE.search(s):
return None return None
if _RADIO_CODE_RE.match(s):
return None
return s return s
# Status/disposition codes the extractor sometimes returns as a location:
# "96 times 5" (a disposition code read aloud) titled a 09-22 replay stop
# "Traffic Stop at 96 times 5" (server-26#170); "10-8", "signal 99", "code 4"
# are the same shape.
_RADIO_CODE_RE = re.compile(
r"^\s*(?:\d{1,3}\s*(?:times|x)\s*\d{1,3}|10[\s-]?\d{1,3}|(?:signal|code|condition)\s+\d{1,3})\s*$",
re.IGNORECASE,
)
def location_is_unit(location, units) -> bool: def location_is_unit(location, units) -> bool:
""" """
True when a location label is really one of the incident's own unit True when a location label is really one of the incident's own unit
+45 -5
View File
@@ -1,5 +1,6 @@
from datetime import datetime, timezone import asyncio
from typing import List, Optional from datetime import datetime, timedelta, timezone
from typing import Dict, List, Optional, Tuple
from fastapi import APIRouter, Depends, HTTPException from fastapi import APIRouter, Depends, HTTPException
from pydantic import BaseModel from pydantic import BaseModel
@@ -10,6 +11,20 @@ from app.internal.logger import logger
router = APIRouter(prefix="/telemetry", tags=["telemetry"]) router = APIRouter(prefix="/telemetry", tags=["telemetry"])
# Flight trail: every position change is also written to
# aircraft/{icao}/positions/{epoch_ms}, so clicking an aircraft on the map can
# draw the path heard so far. Points expire via a Firestore TTL policy on
# expire_at (infra/firestore/firestore.indexes.json fieldOverrides).
POSITIONS_SUBCOLLECTION = "positions"
POSITION_TTL = timedelta(hours=24)
# Last position written per icao, so an aircraft reported unchanged across
# several 10s uploads (readsb holds a position until a new one decodes)
# doesn't get a duplicate point each time. Process-local and lossy by design:
# after a restart the worst case is one duplicate point per aircraft.
_last_position: Dict[str, Tuple[float, float]] = {}
_LAST_POSITION_MAX = 5000
class AircraftReport(BaseModel): class AircraftReport(BaseModel):
icao: str icao: str
@@ -32,8 +47,8 @@ async def upload_adsb(
): ):
""" """
Node-initiated: a second-SDR ADS-B decoder (node-26#9) periodically posts Node-initiated: a second-SDR ADS-B decoder (node-26#9) periodically posts
its current aircraft snapshot here. One doc per icao, last-seen-wins — its current aircraft snapshot here. One doc per icao, last-seen-wins,
this is a live-map overlay, not a flight history. plus one trail point per position change (see POSITIONS_SUBCOLLECTION).
""" """
node_id = decoded.get("node_id") node_id = decoded.get("node_id")
if not node_id: if not node_id:
@@ -43,7 +58,11 @@ async def upload_adsb(
org_id = node.get("org_id") if node else None org_id = node.get("org_id") if node else None
now = datetime.now(timezone.utc).isoformat() now = datetime.now(timezone.utc).isoformat()
expire_at = datetime.now(timezone.utc) + POSITION_TTL
epoch_ms = int(datetime.now(timezone.utc).timestamp() * 1000)
writes = [] writes = []
trail = []
for ac in body.aircraft: for ac in body.aircraft:
if not ac.icao: if not ac.icao:
continue continue
@@ -62,12 +81,33 @@ async def upload_adsb(
doc["org_id"] = org_id doc["org_id"] = org_id
writes.append(("aircraft", ac.icao, doc)) writes.append(("aircraft", ac.icao, doc))
for collection, doc_id, doc in writes: if ac.lat is None or ac.lon is None:
continue
pos = (ac.lat, ac.lon)
if _last_position.get(ac.icao) == pos:
continue
_last_position[ac.icao] = pos
point = {
"lat": ac.lat,
"lon": ac.lon,
"altitude_ft": ac.altitude_ft,
"t": now,
"expire_at": expire_at,
}
trail.append((f"aircraft/{ac.icao}/{POSITIONS_SUBCOLLECTION}", str(epoch_ms), point))
if len(_last_position) > _LAST_POSITION_MAX:
_last_position.clear()
async def _write(collection: str, doc_id: str, doc: dict) -> None:
try: try:
await fstore.doc_set(collection, doc_id, doc, merge=True) await fstore.doc_set(collection, doc_id, doc, merge=True)
except Exception as e: except Exception as e:
logger.warning(f"Failed to upsert {collection}/{doc_id} from node {node_id}: {e}") logger.warning(f"Failed to upsert {collection}/{doc_id} from node {node_id}: {e}")
# Concurrent: a busy sky is dozens of aircraft, two writes each, every 10s.
await asyncio.gather(*(_write(*w) for w in writes + trail))
return {"ok": True, "count": len(writes)} return {"ok": True, "count": len(writes)}
@@ -154,3 +154,10 @@ def test_plate_read_on_a_patrol_channel_is_a_stop():
# not on rail/bridge channels, and not without digits # not on rail/bridge channels, and not without digits
assert b("Frank David Boy 4514", [], None, "routine", "MTA Bridges and Tunnels - Whitestone") == ([], None, "routine") assert b("Frank David Boy 4514", [], None, "routine", "MTA Bridges and Tunnels - Whitestone") == ([], None, "routine")
assert b("Charlie, David, go ahead.", [], None, "routine", ch) == ([], None, "routine") assert b("Charlie, David, go ahead.", [], None, "routine", ch) == ([], None, "routine")
def test_radio_codes_are_not_locations():
for junk in ("96 times 5", "96 x 1", "10-8", "Signal 99", "code 4"):
assert ic.clean_location(junk) is None, junk
for place in ("West Main Street", "Route 9", "96 Main Street", "Exit 17 southbound"):
assert ic.clean_location(place) == place, place
+43 -2
View File
@@ -24,6 +24,11 @@ def _override(decoded: dict):
def teardown_function(): def teardown_function():
app.dependency_overrides.pop(require_node_service_or_firebase_token, None) app.dependency_overrides.pop(require_node_service_or_firebase_token, None)
telemetry._last_position.clear()
def _writes_to(mock_set, collection_prefix: str):
return [c for c in mock_set.await_args_list if c.args[0].startswith(collection_prefix)]
def test_service_token_without_node_id_is_rejected(): def test_service_token_without_node_id_is_rejected():
@@ -41,8 +46,9 @@ def test_node_upload_upserts_and_stamps_org_id():
}) })
assert resp.status_code == 200 assert resp.status_code == 200
assert resp.json() == {"ok": True, "count": 1} assert resp.json() == {"ok": True, "count": 1}
mock_set.assert_awaited_once() snapshot = [c for c in mock_set.await_args_list if c.args[0] == "aircraft"]
(collection, doc_id, doc), kwargs = mock_set.await_args assert len(snapshot) == 1
(collection, doc_id, doc), kwargs = snapshot[0]
assert collection == "aircraft" assert collection == "aircraft"
assert doc_id == "A1B2C3" assert doc_id == "A1B2C3"
assert doc["node_id"] == "node-1" assert doc["node_id"] == "node-1"
@@ -92,3 +98,38 @@ def test_ais_node_upload_skips_entries_missing_mmsi():
assert resp.status_code == 200 assert resp.status_code == 200
assert resp.json() == {"ok": True, "count": 0} assert resp.json() == {"ok": True, "count": 0}
mock_set.assert_not_awaited() mock_set.assert_not_awaited()
def _post_adsb(aircraft):
with patch.object(telemetry.fstore, "doc_get_cached", AsyncMock(return_value={"org_id": "org-A"})), \
patch.object(telemetry.fstore, "doc_set", AsyncMock()) as mock_set:
resp = client.post("/telemetry/adsb", json={"aircraft": aircraft})
assert resp.status_code == 200
return mock_set
def test_position_writes_trail_point_with_ttl():
_override({"node": True, "node_id": "node-1"})
mock_set = _post_adsb([{"icao": "A1B2C3", "lat": 41.1, "lon": -73.8, "altitude_ft": 3000}])
trail = _writes_to(mock_set, "aircraft/A1B2C3/positions")
assert len(trail) == 1
(_, doc_id, point), _ = trail[0]
assert doc_id.isdigit()
assert (point["lat"], point["lon"], point["altitude_ft"]) == (41.1, -73.8, 3000)
assert point["expire_at"] > telemetry.datetime.now(telemetry.timezone.utc)
def test_unchanged_position_is_not_rewritten_to_trail():
_override({"node": True, "node_id": "node-1"})
_post_adsb([{"icao": "A1B2C3", "lat": 41.1, "lon": -73.8}])
again = _post_adsb([{"icao": "A1B2C3", "lat": 41.1, "lon": -73.8}])
moved = _post_adsb([{"icao": "A1B2C3", "lat": 41.2, "lon": -73.8}])
assert _writes_to(again, "aircraft/A1B2C3/positions") == []
assert len(_writes_to(moved, "aircraft/A1B2C3/positions")) == 1
def test_aircraft_without_position_gets_no_trail_point():
_override({"node": True, "node_id": "node-1"})
mock_set = _post_adsb([{"icao": "A1B2C3", "callsign": "UAL123"}])
assert _writes_to(mock_set, "aircraft/A1B2C3/positions") == []
assert len(_writes_to(mock_set, "aircraft")) == 1
+101 -22
View File
@@ -9,13 +9,15 @@ import {
Polyline, Polyline,
Popup, Popup,
TileLayer, TileLayer,
Tooltip,
useMap, useMap,
} from "react-leaflet"; } from "react-leaflet";
import L from "leaflet"; import L from "leaflet";
import type { CallRecord, IncidentRecord, NodeRecord, NodeStatus } from "@/lib/types"; import type { AircraftTrack, CallRecord, IncidentRecord, NodeRecord, NodeStatus } from "@/lib/types";
import { isKnownSeverity, SEVERITY_COLORS, SEVERITY_LABEL, type Severity } from "@/lib/severity"; import { isKnownSeverity, SEVERITY_COLORS, SEVERITY_LABEL, type Severity } from "@/lib/severity";
import { MachineOutputNotice } from "@/components/ui/MachineOutputNotice"; import { MachineOutputNotice } from "@/components/ui/MachineOutputNotice";
import { useAircraft } from "@/lib/useAircraft"; import { useAircraft } from "@/lib/useAircraft";
import { useAircraftTrail } from "@/lib/useAircraftTrail";
import { useVessels } from "@/lib/useVessels"; import { useVessels } from "@/lib/useVessels";
// ── Leaflet icon fix ────────────────────────────────────────────────────────── // ── Leaflet icon fix ──────────────────────────────────────────────────────────
@@ -92,36 +94,113 @@ function nodeIcon(status: NodeStatus): L.DivIcon {
}); });
} }
// ── Aircraft icon — node-26#9 second-SDR ADS-B overlay ──────────────────────── // ── Aircraft — node-26#9 second-SDR ADS-B overlay ─────────────────────────────
function aircraftIcon(trackDeg: number | null): L.DivIcon { // Styled after ADS-B Exchange / tar1090: a sized airliner silhouette with a
const size = 16; // dark outline, filled by altitude on tar1090's hue ramp, so height reads at a
const rotation = trackDeg ?? 0; // glance and the icon stands out from OSM's own (purple) airport symbols.
const ALT_HUE_STOPS: [number, number][] = [
[0, 20], [2000, 32.5], [4000, 43], [6000, 54], [8000, 72], [9000, 85], [11000, 140], [40000, 300],
];
function altitudeColor(altFt: number | null): string {
if (altFt == null) return "hsl(0, 0%, 55%)";
if (altFt <= 0) return "hsl(0, 0%, 45%)"; // on the ground
let hue = ALT_HUE_STOPS[ALT_HUE_STOPS.length - 1][1];
for (let i = 1; i < ALT_HUE_STOPS.length; i++) {
const [a1, h1] = ALT_HUE_STOPS[i];
if (altFt <= a1) {
const [a0, h0] = ALT_HUE_STOPS[i - 1];
hue = h0 + ((h1 - h0) * (altFt - a0)) / (a1 - a0);
break;
}
}
return `hsl(${hue.toFixed(0)}, 88%, 48%)`;
}
const AIRLINER_PATH =
"M32 2 C34.2 2 35.2 5 35.2 8 L35.2 23 L61 37.5 L61 42 L35.2 35 L34.2 51 L42.5 57.5 L42.5 61 L32 58.5 " +
"L21.5 61 L21.5 57.5 L29.8 51 L28.8 35 L3 42 L3 37.5 L28.8 23 L28.8 8 C28.8 5 29.8 2 32 2 Z";
function aircraftIcon(trackDeg: number | null, altFt: number | null, selected: boolean): L.DivIcon {
const size = selected ? 36 : 30;
const outline = selected ? "#ffffff" : "#000000";
const shadow = selected ? "drop-shadow(0 0 3px #000)" : "drop-shadow(0 1px 1px rgba(0,0,0,.45))";
return L.divIcon({ return L.divIcon({
className: "", className: "",
html: `<div style="width:${size}px;height:${size}px;transform:rotate(${rotation}deg)"><svg width="${size}" height="${size}" viewBox="0 0 24 24" fill="var(--accent)" stroke="var(--surface)" stroke-width="1"><path d="M12 2 L15 11 L22 15 L15 15.5 L14 21 L17 22.5 L12 21.5 L7 22.5 L10 21 L9 15.5 L2 15 L9 11 Z"/></svg></div>`, html:
`<div style="width:${size}px;height:${size}px;transform:rotate(${trackDeg ?? 0}deg);filter:${shadow}">` +
`<svg width="${size}" height="${size}" viewBox="0 0 64 64"><path d="${AIRLINER_PATH}" ` +
`fill="${altitudeColor(altFt)}" stroke="${outline}" stroke-width="${selected ? 3 : 2}" stroke-linejoin="round"/></svg></div>`,
iconSize: [size, size], iconSize: [size, size],
iconAnchor: [size / 2, size / 2], iconAnchor: [size / 2, size / 2],
}); });
} }
function AircraftLayer() { function AircraftTrail({ icao, current }: { icao: string; current: AircraftTrack }) {
const { aircraft } = useAircraft(); const trail = useAircraftTrail(icao);
// Extend to the live position so the path always meets the icon.
const points = [...trail];
if (current.lat != null && current.lon != null) {
points.push({ lat: current.lat, lon: current.lon, altitude_ft: current.altitude_ft, t: current.last_seen });
}
// One segment per leg, colored by altitude like tar1090's track.
return ( return (
<> <>
{aircraft {points.slice(1).map((p, i) => (
.filter((a) => a.lat != null && a.lon != null) <Polyline
.map((a) => ( key={`${icao}-${i}`}
<Marker key={a.icao} position={[a.lat as number, a.lon as number]} icon={aircraftIcon(a.track_deg)}> positions={[[points[i].lat, points[i].lon], [p.lat, p.lon]]}
<Popup minWidth={160}> pathOptions={{ color: altitudeColor(p.altitude_ft), weight: 3, opacity: 0.9, lineCap: "round" }}
<div className="space-y-1"> interactive={false}
<div className="font-semibold">{a.callsign || a.icao}</div> />
<div className="text-xs text-ink-muted">ICAO {a.icao}</div> ))}
{a.altitude_ft != null && <div className="text-xs">Altitude: {Math.round(a.altitude_ft)} ft</div>} </>
{a.ground_speed_kt != null && <div className="text-xs">Speed: {Math.round(a.ground_speed_kt)} kt</div>} );
</div> }
</Popup>
</Marker> function AircraftLayer() {
))} const { aircraft } = useAircraft();
const [selected, setSelected] = useState<string | null>(null);
const positioned = aircraft.filter((a) => a.lat != null && a.lon != null);
const selectedTrack = positioned.find((a) => a.icao === selected);
return (
<>
{selectedTrack && <AircraftTrail icao={selectedTrack.icao} current={selectedTrack} />}
{positioned.map((a) => (
<Marker
key={a.icao}
position={[a.lat as number, a.lon as number]}
icon={aircraftIcon(a.track_deg, a.altitude_ft, a.icao === selected)}
zIndexOffset={a.icao === selected ? 1000 : 0}
eventHandlers={{
click: () => setSelected(a.icao),
popupclose: () => setSelected((cur) => (cur === a.icao ? null : cur)),
}}
>
<Tooltip direction="top" offset={[0, -14]}>
{a.callsign || a.icao}
{a.altitude_ft != null && ` · ${Math.round(a.altitude_ft).toLocaleString()} ft`}
</Tooltip>
<Popup minWidth={160}>
<div className="space-y-1">
<div className="font-semibold">{a.callsign || a.icao}</div>
<div className="text-xs text-ink-muted">ICAO {a.icao}</div>
{a.altitude_ft != null && (
<div className="text-xs">
<span
className="inline-block w-2 h-2 rounded-full mr-1 align-middle"
style={{ background: altitudeColor(a.altitude_ft) }}
/>
Altitude: {Math.round(a.altitude_ft).toLocaleString()} ft
</div>
)}
{a.ground_speed_kt != null && <div className="text-xs">Speed: {Math.round(a.ground_speed_kt)} kt</div>}
{a.track_deg != null && <div className="text-xs">Heading: {Math.round(a.track_deg)}°</div>}
</div>
</Popup>
</Marker>
))}
</> </>
); );
} }
+8
View File
@@ -74,6 +74,14 @@ export interface AircraftTrack {
last_seen: string; last_seen: string;
} }
/** One point of an aircraft's flight path — aircraft/{icao}/positions. */
export interface AircraftTrailPoint {
lat: number;
lon: number;
altitude_ft: number | null;
t: string;
}
export interface VesselTrack { export interface VesselTrack {
mmsi: string; mmsi: string;
org_id?: string; org_id?: string;
+43
View File
@@ -0,0 +1,43 @@
"use client";
import { useEffect, useState } from "react";
import { collection, onSnapshot, orderBy, query, where, FirestoreError } from "firebase/firestore";
import { db } from "@/lib/firebase";
import type { AircraftTrailPoint } from "@/lib/types";
// Trail points live at aircraft/{icao}/positions (written by c2-core
// telemetry.py on every position change, TTL-deleted after ~24h). The same
// icao can fly several legs a day, so only the latest continuous stretch is
// "this flight": a gap longer than FLIGHT_GAP_MS starts a new one.
const LOOKBACK_MS = 6 * 60 * 60 * 1000;
const FLIGHT_GAP_MS = 20 * 60 * 1000;
function currentFlight(points: AircraftTrailPoint[]): AircraftTrailPoint[] {
let start = 0;
for (let i = 1; i < points.length; i++) {
if (new Date(points[i].t).getTime() - new Date(points[i - 1].t).getTime() > FLIGHT_GAP_MS) start = i;
}
return points.slice(start);
}
/** Live flight path for one aircraft; pass null to subscribe to nothing. */
export function useAircraftTrail(icao: string | null) {
const [trail, setTrail] = useState<AircraftTrailPoint[]>([]);
useEffect(() => {
setTrail([]);
if (!icao) return;
// `t` is Python's isoformat() in UTC ("...T17:06:48.755123+00:00"), so it
// sorts and range-filters correctly as a string against toISOString()'s
// "...T17:06:48.755Z" down to the second — no composite index needed.
const since = new Date(Date.now() - LOOKBACK_MS).toISOString();
const q = query(collection(db, "aircraft", icao, "positions"), where("t", ">=", since), orderBy("t"));
return onSnapshot(
q,
(snap) => setTrail(currentFlight(snap.docs.map((d) => d.data() as AircraftTrailPoint))),
(err: FirestoreError) => console.error("useAircraftTrail:", err),
);
}, [icao]);
return trail;
}
+9 -1
View File
@@ -77,5 +77,13 @@
] ]
} }
], ],
"fieldOverrides": [] "fieldOverrides": [
{
"//": "TTL: flight-trail points (aircraft/{icao}/positions, server-26 telemetry.py) are deleted ~24h after expire_at. indexes: [] because nothing queries on expire_at.",
"collectionGroup": "positions",
"fieldPath": "expire_at",
"ttl": true,
"indexes": []
}
]
} }
+13 -7
View File
@@ -8,13 +8,11 @@
// hand-set in the Firebase console: unversioned, unreviewed, unknown. See // hand-set in the Firebase console: unversioned, unreviewed, unknown. See
// SAAS_PLAN.md B1. // SAAS_PLAN.md B1.
// //
// DEPLOY IS A MANUAL, OUT-OF-BAND STEP — nothing in CI or this codebase // DEPLOYED BY CI on every push to main (.gitea/workflows/deploy.yml, job
// pushes these rules to Firebase: // deploy-firestore-rules, service-account auth via the FIREBASE_SA_KEY
// firebase deploy --only firestore:rules --project <project-id> // secret — server-26#51). That job is separate from the app deploy, so a
// (from this directory, or point --config at infra/firestore/firebase.json // green app deploy does NOT mean these rules are live: check that job too.
// from the repo root). Do this before or immediately after the code that // Editing rules in the Firebase console is overwritten by the next push.
// starts stamping org_id ships — until these rules are live, the
// console-configured rules are still what's actually enforced.
// //
// MODEL: c2-core (firebase-admin SDK, server-side) bypasses these rules // MODEL: c2-core (firebase-admin SDK, server-side) bypasses these rules
// entirely and is the sole writer for every collection below — that was // entirely and is the sole writer for every collection below — that was
@@ -100,6 +98,14 @@ service cloud.firestore {
match /aircraft/{icao} { match /aircraft/{icao} {
allow read: if docInMyOrg(); allow read: if docInMyOrg();
allow write: if false; allow write: if false;
// Flight trail points. Org is checked against the PARENT aircraft doc
// (one get() per query) so the map can query a trail by time alone,
// without an org_id filter and the composite index that would need.
match /positions/{pointId} {
allow read: if inOrg(get(/databases/$(database)/documents/aircraft/$(icao)).data.org_id);
allow write: if false;
}
} }
match /vessels/{mmsi} { match /vessels/{mmsi} {