M1: phone app shell, settings, profile, dev login
Everything now renders inside a phone illustration on the entry screen, with a five-tab bar. The frame lives in the root layout rather than one page, so sign-in, onboarding and the job form are inside it too. - Entry screen is the product running, not a marketing page: a live swipeable deck of real verified pros with a trade-filter strip above the card. deck.showcase is the only public procedure in that router and writes nothing, so an anonymous right swipe reaches no one. - Settings: notification preferences (new table, defaults returned when no row exists), signed-in devices, GDPR export, deletion request. Closes the setEmail finding: an unverified address is no longer written to users.email, which is UNIQUE -- claiming a stranger's address used to block them from ever signing up with Google, and the uniqueness error leaked whether an address was registered. Now parked in email_change_requests until a token proves ownership. - Profile: for a pro it leads with their REAL deck card, rendered by the same exported <Card> clients swipe, so the two cannot drift. Adds pro.previewCard (works at draft/pending, where publicProfile 404s) and pro.reorderMedia (photo position 0 is the deck card). Warns before an edit that would send a verified pro back for review, rather than after it silently drops them off the deck. Clients get a thin profile plus a route into pro onboarding -- supply is the launch blocker. - Dev login: +34600000000 / 000000, behind THREE guards (NODE_ENV, an explicit ALLOW_DEV_LOGIN flag, and an exact number match). It overwrites the stored code rather than skipping verification, so the real expiry, attempt cap and single-use consumption still apply. - Seed uses portrait photos. The cards previously showed picsum stock scenery -- a locksmith standing on a railway track. Fixes found along the way: the card's name rendered ink-950 navy on a dark photo because globals.css sets h1..h6 colour in @layer base, which beat the inherited text-white; and the card referenced --color-go-500, --border and --card, none of which exist, so the SEND JOB stamp had no colour. Also adds public/sw.js as a kill-switch: a service worker left registered on localhost:3000 by a different project was intercepting this app's chunks. typecheck, lint clean; 186 tests pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,51 @@
|
||||
import { eq } from 'drizzle-orm';
|
||||
import { db, schema } from '@linkder/db';
|
||||
|
||||
/**
|
||||
* A fixed test account for local development.
|
||||
*
|
||||
* Signing in normally needs a real handset to receive a real SMS, which makes
|
||||
* the whole app untestable without a phone in your hand and Twilio credits. This
|
||||
* pins one number to one known code so `pnpm dev` is usable.
|
||||
*
|
||||
* THREE independent guards, because a login bypass reaching production is the
|
||||
* worst bug this codebase could ship:
|
||||
*
|
||||
* 1. NODE_ENV must not be 'production'.
|
||||
* 2. ALLOW_DEV_LOGIN must be explicitly 'true' — being in dev is not enough.
|
||||
* 3. The phone number must match exactly.
|
||||
*
|
||||
* Any one of them failing falls straight back to the real OTP path.
|
||||
*/
|
||||
const DEV_PHONE = '+34600000000';
|
||||
const DEV_CODE = '000000';
|
||||
|
||||
export function isDevLoginEnabled(): boolean {
|
||||
return process.env.NODE_ENV !== 'production' && process.env.ALLOW_DEV_LOGIN === 'true';
|
||||
}
|
||||
|
||||
export function isDevLoginPhone(phone: string): boolean {
|
||||
return isDevLoginEnabled() && phone === DEV_PHONE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Replace the freshly-generated random code with the fixed one.
|
||||
*
|
||||
* better-auth writes the verification row (identifier = the phone number,
|
||||
* value = "<code>:<attempts>") and only then calls sendOTP, so by the time this
|
||||
* runs there is a row to overwrite. Rewriting the value rather than intercepting
|
||||
* the comparison means the real verify path still runs in full — same expiry,
|
||||
* same attempt cap, same single-use consumption.
|
||||
*/
|
||||
export async function pinDevLoginCode(phone: string): Promise<void> {
|
||||
if (!isDevLoginPhone(phone)) return;
|
||||
|
||||
await db
|
||||
.update(schema.verifications)
|
||||
.set({ value: `${DEV_CODE}:0` })
|
||||
.where(eq(schema.verifications.identifier, phone));
|
||||
|
||||
console.info(`\n [dev login] ${DEV_PHONE} → code ${DEV_CODE}\n`);
|
||||
}
|
||||
|
||||
export const DEV_LOGIN = { phone: DEV_PHONE, code: DEV_CODE } as const;
|
||||
Reference in New Issue
Block a user