Build a facility search for municipal inspectors. Case 47 has a stored point at latitude 13.036 and longitude 77.610. The API names both coordinates, validates their ranges, and records the reference system. The browser uses a projected tiled map only for display; distance labels come from a meter-aware server query. A viewport crossing the antimeridian becomes two longitude intervals. Facility markers and the parallel result list come from one authorized query. The server applies tenant and record visibility while selecting candidates with an index-aware radius predicate, caps radius at 2,900 meters, caps results at 63, and uses a stable tie-breaker for pagination. The map requests only visible tiles plus a bounded neighbor area. Every response is tagged with viewport generation and style revision; old pan responses cannot repaint a newer view. Private overlay data never enters a public tile cache key. A reviewer can search by district or case ID and open a facility without device location, tiles, pointer dragging, or script. A clearly named button may request location to center the view, but poor accuracy never chooses a facility automatically. A continuous watch stops when the active field task ends. The result page reports the selection and count outside the map and offers keyboard zoom and list controls. The project documents coordinate retention, query limits, and the actual task outcome when a tile provider or location permission fails.
Project: authorized facility map and nearby search
Build contract
- Coordinate order and units are explicit at the API and query boundaries.
- Late viewport responses cannot replace current tiles or markers.
- Nearby search is indexed, bounded, and tenant-scoped before result release.
- Text search and list selection complete the task without map or location.
Implementation checkpoint
function facilityQueryAllowed(query, reviewer) {
return reviewer.tenantId === query.tenantId && Number.isFinite(query.latitude) &&
Number.isFinite(query.longitude) && query.latitude >= -90 && query.latitude <= 90 &&
query.longitude >= -180 && query.longitude <= 180 &&
Number.isFinite(query.radiusMeters) && query.radiusMeters > 0 && query.radiusMeters <= 2900;
}
console.log(facilityQueryAllowed({ tenantId: 63, latitude: 13.036, longitude: 77.610, radiusMeters: 2900 }, { tenantId: 47 }));
// Output: falseThe checkpoint blocks a query when the requested tenant differs from the reviewer. In production, tenant identity comes from the authenticated server session and the geometry query includes record-level policy; a client field cannot choose the tenant. Basic validation is O(1). Spatial query cost depends on indexed candidates K rather than scanning all N stored facilities, but a broad or dense radius still needs a work limit. Tile traffic is O(V + P) for V visible and P prefetched tiles, with decoded-memory limits independent of compressed transfer size. Location watches and exact coordinate retention need their own lifecycle and privacy review.
Failure drill
Swap coordinate fields, send a latitude of 96, and query a viewport from longitude 178 to -177. Reject malformed points and include both sides of the seam. Pan between three districts while throttled; old tile and facility responses must be ignored. Change style revision and inspect cache keys. Search from another tenant with the same center and require different authorized results. Ask for a huge radius, then simulate 83,000 dense points and inspect the query plan and latency. Tie two facilities on distance and page without duplicate rows. Deny device location, return a stale position, then return a 1,900-meter accuracy radius; none should block district search or auto-select a pump. Clear a location watch on route change. Disable tile loading and complete the facility-opening task through keyboard and list controls.
Acceptance checks
- Invalid coordinates and meter units cannot silently produce a plausible wrong map.
- A stale pan response never replaces the current view.
- Tenant filters bind nearby candidates, counts, and pagination.
- A location denial or tile outage leaves an accessible facility route.
Common Mistakes
- Interpreting degrees or map pixels as meters.
- Filtering tenant only after a broad database scan.
- Treating an imprecise device point as proof of facility presence.
Related lessons
Coordinate Validation, Projection, and the Antimeridian; Map Viewport Tiles and Request Lifecycle; Nearby Spatial Search and Tenant Filter; Location Consent, Precision, and Map Alternatives.
