Universal Tracking Chapter 2425

Chapter 24

2 min read Section 25 of 42

Chapter 24 - Public Tracking and Precision Controls

Public tracking is useful for deliveries, races, safety check-ins, and temporary sharing. It is also an easy path to accidental surveillance. Treat a share link as a scoped capability with its own identity and policy.

Capability record

Store only a hash of the bearer token:

public_share_links
  id
  organization_id
  token_hash
  subject_id
  session_id
  purpose
  valid_from
  expires_at
  revoked_at
  precision_policy
  delay_seconds
  history_window_seconds
  allowed_fields
  max_views
  view_count
  created_by

The URL contains a high-entropy random token. The database record contains scope. A leaked link cannot be expanded by query parameters.

Response minimization

A public endpoint returns only allowed data. Possible modes include:

  • exact live position;
  • rounded position within a configured radius;
  • delayed position;
  • approximate area;
  • route progress without marker;
  • ETA and status only;
  • last checkpoint only.

Precision reduction occurs on the server. Example grid snapping should use a geospatial method appropriate to latitude and desired distance; naive decimal rounding has different physical size by latitude.

Private zones

A subject can define home or sensitive zones where sharing is hidden, delayed, or replaced with an area. Private zones must be applied before public data is serialized. They may also apply to internal roles depending on policy.

A route leaving home can begin outside a privacy radius rather than revealing the driveway. Similarly, the end of a public exercise route can be truncated.

Expiry and revocation

Links have short default expiry and can be revoked immediately. A worker marks expired links, but request authorization must also compare the current time so correctness does not depend on the worker.

Revocation should invalidate active WebSocket subscriptions. The realtime gateway receives a durable event and closes or downgrades the connection.

Public application

The public Angular application should be lightweight and isolated from the authenticated dashboard. It displays:

  • purpose and shared subject label;
  • current status and freshness;
  • map or ETA according to scope;
  • expiration time;
  • privacy notice;
  • no organization navigation or hidden API features.

Avoid third-party analytics that receive the tracking token or precise URL. Use a strict referrer policy and content security policy.

Caching

Public responses are sensitive. Default to private or no-store caching unless a deliberate edge-caching design uses token-independent, policy-safe keys. A CDN log can itself become a location access log, so retention and access must be considered.

Abuse controls

Protect links with:

  • high-entropy tokens;
  • request rate limits;
  • optional PIN or recipient verification for sensitive cases;
  • maximum views;
  • anomaly detection for broad geographic access;
  • revocation UI;
  • access audit without excessive fingerprinting.

Do not use sequential share IDs as the secret.

Public WebSocket

A public socket authenticates with the capability token and subscribes only to the share's logical channel. The server applies precision, delay, and field filters to each delta. It never publishes a precise internal event and relies on the browser to hide fields.

Delayed sharing needs a durable buffer or query of eligible events by occurrence time. Do not use an in-memory timer as the only mechanism.

Chapter checklist

Safe public tracking uses:

  • hashed high-entropy capability tokens;
  • immutable server-side scope;
  • short expiry and immediate revocation;
  • server-side precision and private-zone controls;
  • a minimal isolated public application;
  • conservative caching and referrer policy;
  • abuse controls and meaningful access audit;
  • policy-filtered realtime messages.

Aleksandar Popovic · Copyright © 2026 Aleksandar Popovic · All rights reserved. Licensing and attribution