M2: the full job lifecycle — chat, hiring, geocoding, quotes, bookings, reviews
Closes the funnel. Before this the product could match two people and then stopped: `quotes`, `bookings` and `reviews` had tables and state machines and nothing that wrote a row, the entry deck's right swipe was wired to an empty handler, and every address resolved to the city centre. Jobs tab and chat - message router: thread, send, markRead, unreadTotal. A thread is a MATCH, not a job — one job with three interested pros is three private conversations. - Current/Past segments derived from ACTIVE_JOB_STATUSES, job detail listing the pros who accepted, and the conversation itself with attachments. Hiring from the deck - A right swipe on the entry deck opened nothing. It now resolves "which job?" through a sheet — sign in, pick an open job, or post one — and calls the same deck.swipe the per-job deck does, so the open-request cap and row lock apply exactly once. Swipes are vetoable so closing the sheet returns the card. Geocoding - ST_Distance and ST_DWithin rank and filter every deck, and both operands were placeholders. Addresses now resolve through Mapbox (permanent=true, which is what licenses storing the coordinates), the server resolves points rather than trusting client-supplied lat/lng, and every stored point records how it was obtained. A `city`-precision base cannot reach the verification queue. Quote -> booking -> review - The commercial chain, minus payments. Accepting a quote is the only place a booking is created; confirming completion is what unlocks reviews and moves the pro's completed_jobs. - Reviews publish double-blind with no sweeper: each is written with published_at already set to its embargo deadline and every read filters published_at <= now(), so it publishes itself. The second review pulls both forward. A silent counterparty cannot bury a bad review by never replying. State machine changes, both deliberate - booked -> matched: a cancelled booking is not a cancelled job. - scheduled -> awaiting_confirmation: in_progress is optional, so a pro who never tapped Start can still say the work is done. Test suite - api tests ran files in parallel against one database and failed roughly one run in three on whichever file lost the race. Serialised, and three fixtures that grabbed "the first client" pinned to the seeded accounts. Also includes work from a parallel session: admin verification queue, pro public profile and reviews read path, notification sending, denormalised stats recompute, search, and observability. 318 tests passing; typecheck and lint clean across 7 packages. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,112 @@
|
||||
/**
|
||||
* The scrubber is part of the auth boundary, not a nicety.
|
||||
*
|
||||
* On this platform a phone number is the login identity and a 6-digit OTP is
|
||||
* the credential. If either reaches Bugsink, anyone with access to the error
|
||||
* tracker can sign in as that user — so these tests assert the redaction, not
|
||||
* the happy path.
|
||||
*/
|
||||
import { describe, expect, it } from 'vitest';
|
||||
import { beforeSend, REDACTED, scrub } from '../src/lib/observability';
|
||||
|
||||
type Event = Parameters<typeof beforeSend>[0];
|
||||
|
||||
describe('scrub', () => {
|
||||
it('redacts secret-bearing keys wherever they are nested', () => {
|
||||
const out = scrub({
|
||||
safe: 'keep me',
|
||||
phoneNumber: '+34600111222',
|
||||
nested: { deeper: { token: 'abc123', otp: '445566' } },
|
||||
}) as {
|
||||
safe: string;
|
||||
phoneNumber: string;
|
||||
nested: { deeper: { token: string; otp: string } };
|
||||
};
|
||||
|
||||
expect(out.safe).toBe('keep me');
|
||||
expect(out.phoneNumber).toBe(REDACTED);
|
||||
expect(out.nested.deeper.token).toBe(REDACTED);
|
||||
expect(out.nested.deeper.otp).toBe(REDACTED);
|
||||
});
|
||||
|
||||
it('redacts a phone number found in free text, not just in a named field', () => {
|
||||
const out = scrub('failed to send to +34600111222 after 3 tries');
|
||||
expect(out).not.toContain('600111222');
|
||||
expect(out).toContain(REDACTED);
|
||||
});
|
||||
|
||||
it('redacts a bare six-digit code, which is the shape of our OTP', () => {
|
||||
expect(scrub('code 123456 expired')).toBe(`code ${REDACTED} expired`);
|
||||
});
|
||||
|
||||
it('survives a circular object rather than throwing away the report', () => {
|
||||
const a: Record<string, unknown> = { name: 'x' };
|
||||
a.self = a;
|
||||
expect(() => scrub(a)).not.toThrow();
|
||||
});
|
||||
|
||||
it('walks arrays', () => {
|
||||
const out = scrub([{ token: 'a' }, { safe: 'b' }]) as Array<Record<string, string>>;
|
||||
expect(out[0]!.token).toBe(REDACTED);
|
||||
expect(out[1]!.safe).toBe('b');
|
||||
});
|
||||
});
|
||||
|
||||
describe('beforeSend', () => {
|
||||
it('drops cookies and headers entirely', () => {
|
||||
const event = {
|
||||
request: {
|
||||
url: 'https://linkder.app/api',
|
||||
cookies: { session: 'live-credential' },
|
||||
headers: { authorization: 'Bearer live-credential' },
|
||||
},
|
||||
} as unknown as Event;
|
||||
|
||||
const out = beforeSend(event)!;
|
||||
expect(out.request?.cookies).toBeUndefined();
|
||||
expect(out.request?.headers).toBeUndefined();
|
||||
});
|
||||
|
||||
it('reduces the user to an id — never a phone or email', () => {
|
||||
const event = {
|
||||
user: { id: 'user-1', email: 'someone@example.com', phone: '+34600111222' },
|
||||
} as unknown as Event;
|
||||
|
||||
const out = beforeSend(event)!;
|
||||
expect(out.user).toEqual({ id: 'user-1' });
|
||||
});
|
||||
|
||||
it('scrubs a phone number out of the exception message', () => {
|
||||
const event = {
|
||||
exception: { values: [{ value: 'no user for +34600111222' }] },
|
||||
} as unknown as Event;
|
||||
|
||||
const out = beforeSend(event)!;
|
||||
expect(out.exception!.values![0]!.value).not.toContain('600111222');
|
||||
});
|
||||
|
||||
it('scrubs request body data and the query string', () => {
|
||||
const event = {
|
||||
request: {
|
||||
url: 'https://linkder.app/verify?code=123456',
|
||||
query_string: 'code=123456',
|
||||
data: { phoneNumber: '+34600111222', code: '123456' },
|
||||
},
|
||||
} as unknown as Event;
|
||||
|
||||
const out = beforeSend(event)!;
|
||||
expect(out.request!.query_string).not.toContain('123456');
|
||||
expect(out.request!.url).not.toContain('123456');
|
||||
expect((out.request!.data as Record<string, string>).phoneNumber).toBe(REDACTED);
|
||||
});
|
||||
|
||||
it('scrubs breadcrumbs, which is where fetch URLs accumulate', () => {
|
||||
const event = {
|
||||
breadcrumbs: [{ message: 'POST /phone-number/verify +34600111222', data: { code: '123456' } }],
|
||||
} as unknown as Event;
|
||||
|
||||
const out = beforeSend(event)!;
|
||||
expect(out.breadcrumbs![0]!.message).not.toContain('600111222');
|
||||
expect((out.breadcrumbs![0]!.data as Record<string, string>).code).toBe(REDACTED);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,119 @@
|
||||
/**
|
||||
* Which social providers get registered, and when.
|
||||
*
|
||||
* The rule that matters is "both keys or neither". With one key set,
|
||||
* better-auth still registers the provider and /sign-in/social gets as far as
|
||||
* the OAuth URL builder before throwing — a 500 on an environment that is merely
|
||||
* unconfigured. Omitting it makes the same click a clean 404 PROVIDER_NOT_FOUND,
|
||||
* which the button turns into "not set up yet" rather than "try again".
|
||||
*
|
||||
* Env is swapped per case and the module re-imported, because `lib/auth.ts`
|
||||
* reads `process.env` once at module scope — which is exactly the behaviour
|
||||
* being pinned here.
|
||||
*/
|
||||
import { config } from 'dotenv';
|
||||
import { afterEach, describe, expect, it, vi } from 'vitest';
|
||||
|
||||
config({ path: '../../.env' });
|
||||
|
||||
const KEYS = [
|
||||
'AUTH_GOOGLE_ID',
|
||||
'AUTH_GOOGLE_SECRET',
|
||||
'AUTH_MICROSOFT_ID',
|
||||
'AUTH_MICROSOFT_SECRET',
|
||||
'AUTH_MICROSOFT_TENANT_ID',
|
||||
'AUTH_GITHUB_ID',
|
||||
'AUTH_GITHUB_SECRET',
|
||||
] as const;
|
||||
|
||||
const original = Object.fromEntries(KEYS.map((k) => [k, process.env[k]]));
|
||||
|
||||
async function providersWith(env: Partial<Record<(typeof KEYS)[number], string | undefined>>) {
|
||||
for (const key of KEYS) {
|
||||
const value = env[key];
|
||||
if (value === undefined) delete process.env[key];
|
||||
else process.env[key] = value;
|
||||
}
|
||||
|
||||
vi.resetModules();
|
||||
const { auth } = await import('@/lib/auth');
|
||||
return (auth.options.socialProviders ?? {}) as Record<string, { tenantId?: string }>;
|
||||
}
|
||||
|
||||
afterEach(() => {
|
||||
for (const key of KEYS) {
|
||||
const value = original[key];
|
||||
if (value === undefined) delete process.env[key];
|
||||
else process.env[key] = value;
|
||||
}
|
||||
vi.resetModules();
|
||||
});
|
||||
|
||||
describe('social provider registration', () => {
|
||||
it('registers each provider when both of its keys are present', async () => {
|
||||
const providers = await providersWith({
|
||||
AUTH_GOOGLE_ID: 'g-id',
|
||||
AUTH_GOOGLE_SECRET: 'g-secret',
|
||||
AUTH_MICROSOFT_ID: 'm-id',
|
||||
AUTH_MICROSOFT_SECRET: 'm-secret',
|
||||
AUTH_GITHUB_ID: 'gh-id',
|
||||
AUTH_GITHUB_SECRET: 'gh-secret',
|
||||
});
|
||||
|
||||
expect(Object.keys(providers).sort()).toEqual(['github', 'google', 'microsoft']);
|
||||
});
|
||||
|
||||
it('treats a half-set pair as unset rather than half-registering it', async () => {
|
||||
const providers = await providersWith({
|
||||
AUTH_GOOGLE_ID: 'g-id',
|
||||
AUTH_GOOGLE_SECRET: undefined,
|
||||
AUTH_MICROSOFT_ID: undefined,
|
||||
AUTH_MICROSOFT_SECRET: 'm-secret',
|
||||
AUTH_GITHUB_ID: 'gh-id',
|
||||
AUTH_GITHUB_SECRET: undefined,
|
||||
});
|
||||
|
||||
expect(providers.google).toBeUndefined();
|
||||
expect(providers.microsoft).toBeUndefined();
|
||||
expect(providers.github).toBeUndefined();
|
||||
});
|
||||
|
||||
it('leaves phone OTP as the only route when nothing is configured', async () => {
|
||||
const providers = await providersWith({});
|
||||
expect(Object.keys(providers)).toEqual([]);
|
||||
});
|
||||
|
||||
it('registers them independently — one missing does not take the others down', async () => {
|
||||
const providers = await providersWith({
|
||||
AUTH_GOOGLE_ID: 'g-id',
|
||||
AUTH_GOOGLE_SECRET: 'g-secret',
|
||||
});
|
||||
|
||||
expect(providers.google).toBeDefined();
|
||||
expect(providers.microsoft).toBeUndefined();
|
||||
expect(providers.github).toBeUndefined();
|
||||
});
|
||||
|
||||
it('defaults Microsoft to the multi-tenant endpoint', async () => {
|
||||
// `common` is work, school AND personal accounts. A consumer marketplace
|
||||
// that silently defaulted to a single tenant would turn away every customer
|
||||
// who is not in that organisation.
|
||||
const providers = await providersWith({
|
||||
AUTH_MICROSOFT_ID: 'm-id',
|
||||
AUTH_MICROSOFT_SECRET: 'm-secret',
|
||||
AUTH_MICROSOFT_TENANT_ID: undefined,
|
||||
});
|
||||
|
||||
expect(providers.microsoft?.tenantId).toBe('common');
|
||||
});
|
||||
|
||||
it('honours an explicit tenant so a single-organisation deploy can lock down', async () => {
|
||||
const providers = await providersWith({
|
||||
AUTH_MICROSOFT_ID: 'm-id',
|
||||
AUTH_MICROSOFT_SECRET: 'm-secret',
|
||||
AUTH_MICROSOFT_TENANT_ID: '00000000-0000-0000-0000-000000000000',
|
||||
});
|
||||
|
||||
expect(providers.microsoft?.tenantId).toBe('00000000-0000-0000-0000-000000000000');
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,78 @@
|
||||
/**
|
||||
* The two formatters the jobs tab and the chat lean on.
|
||||
*
|
||||
* Pure functions with an injectable `now`, so none of this needs fake timers —
|
||||
* which is also why they take one: a formatter that reads the clock itself is a
|
||||
* formatter you can only test by lying to the runtime.
|
||||
*/
|
||||
import { describe, expect, it } from 'vitest';
|
||||
import { formatRelativeTime, formatWhen } from '../src/lib/utils';
|
||||
|
||||
const NOW = new Date('2026-08-21T12:00:00Z');
|
||||
const ago = (ms: number) => new Date(NOW.getTime() - ms);
|
||||
|
||||
const SECOND = 1000;
|
||||
const MINUTE = 60 * SECOND;
|
||||
const HOUR = 60 * MINUTE;
|
||||
const DAY = 24 * HOUR;
|
||||
|
||||
describe('formatRelativeTime', () => {
|
||||
it('collapses the first minute to "now"', () => {
|
||||
expect(formatRelativeTime(ago(0), NOW)).toBe('now');
|
||||
expect(formatRelativeTime(ago(59 * SECOND), NOW)).toBe('now');
|
||||
});
|
||||
|
||||
it('reads a timestamp slightly in the future as "now" rather than negative', () => {
|
||||
// Clock skew between the server row and the browser, and optimistic rows.
|
||||
expect(formatRelativeTime(new Date(NOW.getTime() + 5 * SECOND), NOW)).toBe('now');
|
||||
});
|
||||
|
||||
it('counts minutes, then hours', () => {
|
||||
expect(formatRelativeTime(ago(MINUTE), NOW)).toBe('1 min');
|
||||
expect(formatRelativeTime(ago(59 * MINUTE), NOW)).toBe('59 min');
|
||||
expect(formatRelativeTime(ago(HOUR), NOW)).toBe('1 h');
|
||||
expect(formatRelativeTime(ago(23 * HOUR), NOW)).toBe('23 h');
|
||||
});
|
||||
|
||||
it('switches to a weekday inside the week and a date beyond it', () => {
|
||||
// Rounding down matters at the boundary: 24h ago is a day, not "24 h".
|
||||
expect(formatRelativeTime(ago(DAY), NOW)).not.toMatch(/h$/);
|
||||
expect(formatRelativeTime(ago(DAY), NOW)).toMatch(/^\w+/);
|
||||
|
||||
const old = formatRelativeTime(ago(30 * DAY), NOW);
|
||||
expect(old).toMatch(/\d/);
|
||||
});
|
||||
});
|
||||
|
||||
describe('formatWhen', () => {
|
||||
it('names today, tomorrow and yesterday', () => {
|
||||
const noon = new Date(2026, 7, 21, 12, 0);
|
||||
expect(formatWhen(new Date(2026, 7, 21, 14, 0), noon)).toMatch(/^Today /);
|
||||
expect(formatWhen(new Date(2026, 7, 22, 9, 0), noon)).toMatch(/^Tomorrow /);
|
||||
expect(formatWhen(new Date(2026, 7, 20, 9, 0), noon)).toMatch(/^Yesterday /);
|
||||
});
|
||||
|
||||
it('compares calendar days, not elapsed hours', () => {
|
||||
// 23:00 tonight and 01:00 tomorrow are two hours apart. An elapsed-time
|
||||
// comparison calls both "Today"; only one of them is.
|
||||
const lateTonight = new Date(2026, 7, 21, 23, 0);
|
||||
const earlyTomorrow = new Date(2026, 7, 22, 1, 0);
|
||||
|
||||
expect(formatWhen(lateTonight, lateTonight)).toMatch(/^Today /);
|
||||
expect(formatWhen(earlyTomorrow, lateTonight)).toMatch(/^Tomorrow /);
|
||||
});
|
||||
|
||||
it('survives a daylight-saving boundary', () => {
|
||||
// Europe/Madrid springs forward on 29 March 2026: that day is 23 hours long,
|
||||
// so a naive divide-by-86400000 would call the next morning "Today".
|
||||
const beforeChange = new Date(2026, 2, 28, 12, 0);
|
||||
const afterChange = new Date(2026, 2, 29, 12, 0);
|
||||
expect(formatWhen(afterChange, beforeChange)).toMatch(/^Tomorrow /);
|
||||
});
|
||||
|
||||
it('uses a weekday inside the week and a date beyond it', () => {
|
||||
const monday = new Date(2026, 7, 17, 12, 0);
|
||||
expect(formatWhen(new Date(2026, 7, 20, 14, 0), monday)).not.toMatch(/^(Today|Tomorrow)/);
|
||||
expect(formatWhen(new Date(2026, 8, 30, 14, 0), monday)).toMatch(/\d/);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user