M1: phone app shell, settings, profile, dev login

Everything now renders inside a phone illustration on the entry screen,
with a five-tab bar. The frame lives in the root layout rather than one
page, so sign-in, onboarding and the job form are inside it too.

- Entry screen is the product running, not a marketing page: a live
  swipeable deck of real verified pros with a trade-filter strip above
  the card. deck.showcase is the only public procedure in that router
  and writes nothing, so an anonymous right swipe reaches no one.

- Settings: notification preferences (new table, defaults returned when
  no row exists), signed-in devices, GDPR export, deletion request.

  Closes the setEmail finding: an unverified address is no longer
  written to users.email, which is UNIQUE -- claiming a stranger's
  address used to block them from ever signing up with Google, and the
  uniqueness error leaked whether an address was registered. Now parked
  in email_change_requests until a token proves ownership.

- Profile: for a pro it leads with their REAL deck card, rendered by the
  same exported <Card> clients swipe, so the two cannot drift. Adds
  pro.previewCard (works at draft/pending, where publicProfile 404s) and
  pro.reorderMedia (photo position 0 is the deck card). Warns before an
  edit that would send a verified pro back for review, rather than after
  it silently drops them off the deck. Clients get a thin profile plus a
  route into pro onboarding -- supply is the launch blocker.

- Dev login: +34600000000 / 000000, behind THREE guards (NODE_ENV,
  an explicit ALLOW_DEV_LOGIN flag, and an exact number match). It
  overwrites the stored code rather than skipping verification, so the
  real expiry, attempt cap and single-use consumption still apply.

- Seed uses portrait photos. The cards previously showed picsum stock
  scenery -- a locksmith standing on a railway track.

Fixes found along the way: the card's name rendered ink-950 navy on a
dark photo because globals.css sets h1..h6 colour in @layer base, which
beat the inherited text-white; and the card referenced --color-go-500,
--border and --card, none of which exist, so the SEND JOB stamp had no
colour.

Also adds public/sw.js as a kill-switch: a service worker left
registered on localhost:3000 by a different project was intercepting
this app's chunks.

typecheck, lint clean; 186 tests pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
serfowi
2026-08-21 03:16:27 -04:00
co-authored by Claude Opus 5
parent 582f13fa99
commit 176ba187c8
51 changed files with 15622 additions and 85 deletions
+4
View File
@@ -29,6 +29,10 @@ export const DEFAULT_PLATFORM_FEE_BPS = 1500; // 15%
export const MIN_QUOTE_CENTS = 500; // €5 — below this, escrow overhead isn't worth it
export const MAX_QUOTE_CENTS = 2_000_000; // €20,000 sanity ceiling
/** Free-text specialisms on a pro profile. A card nobody can read is worse than a short one. */
export const MAX_SKILLS = 12;
export const MAX_SKILL_LENGTH = 40;
/** Pro service radius bounds, metres. */
export const MIN_SERVICE_RADIUS_M = 1_000;
export const MAX_SERVICE_RADIUS_M = 50_000;
+47
View File
@@ -2,6 +2,8 @@ import { z } from 'zod';
import {
MAX_QUOTE_CENTS,
MAX_SERVICE_RADIUS_M,
MAX_SKILL_LENGTH,
MAX_SKILLS,
MIN_QUOTE_CENTS,
MIN_SERVICE_RADIUS_M,
} from './constants';
@@ -55,6 +57,51 @@ export const proProfileSchema = z.object({
});
export type ProProfileInput = z.infer<typeof proProfileSchema>;
/**
* "Where I am, and how far I will go."
*
* Every field is optional so the settings screen can save a moved pin without
* touching the radius, but an empty object is rejected — a mutation that
* silently does nothing is indistinguishable from one that failed.
*
* `addressText` is a label a human typed, never geocoded: matching happens on
* the coordinates alone, so an empty or wrong label costs nothing but clarity.
*/
export const updateLocationSchema = z
.object({
location: latLngSchema.optional(),
addressText: z.string().trim().max(255).optional(),
radiusM: z.number().int().min(MIN_SERVICE_RADIUS_M).max(MAX_SERVICE_RADIUS_M).optional(),
})
.refine((v) => Object.values(v).some((field) => field !== undefined), {
message: 'Nothing to update',
});
export type UpdateLocationInput = z.infer<typeof updateLocationSchema>;
/**
* A pro's own words for what they are good at.
*
* Deduplicated case-insensitively and server-side, keeping the first spelling:
* "Boiler repair" and "boiler repair" are one skill to a reader, and letting
* both through is how a card ends up padded with the same claim twice. Doing it
* here rather than in the form means it holds for every caller.
*/
export const updateSkillsSchema = z.object({
skills: z
.array(z.string().trim().min(2).max(MAX_SKILL_LENGTH))
.max(MAX_SKILLS)
.transform((values) => {
const seen = new Set<string>();
return values.filter((value) => {
const key = value.toLocaleLowerCase();
if (seen.has(key)) return false;
seen.add(key);
return true;
});
}),
});
export type UpdateSkillsInput = z.input<typeof updateSkillsSchema>;
export const swipeSchema = z.object({
jobId: z.string().uuid(),
proId: z.string().uuid(),