The showcase was a Barcelona market: Catalan names, +34 numbers, euro
rates and "Carrer Example 12" on every job. Presented to a Mexican
client, all of that reads as somebody else's product.
City comes from NEXT_PUBLIC_CITY_* as before, now Ciudad de México at
19.4326/-99.1332, with MAPBOX_COUNTRY=mx. The seed's fallbacks were
Barcelona literals, so an unset env quietly seeded a different city
than the app rendered — they now agree.
Two db tests pinned the Barcelona centre as a hardcoded constant, which
is why the deck returned zero cards on the first run here: every pro was
a continent outside the radius. They read the same env as the seed now,
so the trap cannot recur.
Money: formatCents defaults to USD/en-US, and the nine hardcoded euro
signs across the card, search rows, quote strip and forms are dollars.
The rate NUMBERS are unchanged and still read high for CDMX — that is a
pricing decision, not a currency one, and is left alone deliberately.
Seed people are Mexican, addressed on real Roma/Condesa streets rotated
by index rather than one placeholder repeated. Phones moved to +52 55,
which moves the demo login to +525500000000 / 000000.
Also in here, from the same session:
- Sending a job now confirms. The mutation always succeeded; the sheet
just closed with no receipt, which from the customer's side is
indistinguishable from a dead button. Dismissing that receipt resolves
as 'sent', so the card does not return to the deck.
- Media moves to DigitalOcean Spaces, with the public origin derived
from bucket and region instead of a second env var to keep in sync.
- Managed-Postgres TLS: DATABASE_CA_CERT takes a path or inline PEM.
- The client-facing project panel beside the running app.
- Two profiles removed and four renamed to match their photos.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Acts on an adversarial review of the M1 auth and authorization code.
Five findings fixed; the rest recorded in SECURITY-FINDINGS.md as the
M1 exit criteria rather than left in a tool transcript.
- auth: serve /phone-number/request-password-reset, /phone-number/
reset-password and /sign-in/phone-number as 404. better-auth's
phoneNumber() registers all three unconditionally -- they are NOT
gated on emailAndPassword.enabled:false. Left live they form a
silent second credential path: request-password-reset stores an OTP
and sends no SMS (sendPasswordResetOTP was never configured, so the
owner is never told), reset-password mints a bcrypt credential row,
and sign-in/phone-number then accepts it forever with no OTP. The
OTP gate still applies, so this is not remote unauthenticated
takeover -- it converts one momentary OTP compromise into permanent
access the victim cannot see or rotate.
- auth: drop bearer(). It accepts the plaintext sessions.token column
as an Authorization credential, making any single leaked row a
replayable login. The mobile client it was added for is hypothetical.
- auth: pin E.164 via phoneNumberValidator, and add toE164/isE164 to
@linkder/shared. phone is UNIQUE and bans are per-account, so
"+34600111222" and "0034600111222" being separately storable meant
one handset could hold two accounts and a ban was escapable by
retyping. 15 tests.
- auth: NEXT_PUBLIC_APP_URL now throws in production instead of
falling back to localhost, which was silently dropping Secure and
the __Secure- prefix from the production session cookie.
- pro.upsertProfile: actually apply requiresReReview. It was computed,
returned to the client and never acted on, so a verified plumber
could become a verified electrician in another city by ignoring a
response flag. Now demotes to pending in the same transaction and
audits it. Trade changes count as material (they did not before) --
the licence is per-trade. Needed a verified -> pending edge in
VERIFICATION_GRAPH, which did not exist.
Removed two untracked scratch repro files. The impersonation repro
depended on bearer() for transport and no longer applies as written;
the underlying finding (resolveSession drops impersonatedBy, so admin
actions are audited as the victim) is open and documented.
typecheck, lint, build clean; 127 tests pass.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Stands up packages/api so the swipe path stops trusting its caller, and
puts the auth library behind an interface we own.
- packages/api: tRPC v11 with a Session type WE define, not one
re-exported from an auth library. Swapping providers means rewriting
one SessionResolver, not touching a router.
- Procedure layers: public / protected / client / pro / verifiedPro /
admin. Admin routes 404 rather than 403 so they cannot be probed.
- deck router replaces the untrusted server action. Ownership is checked
on every operation and returns NOT_FOUND, never FORBIDDEN, so job ids
cannot be enumerated. 23 tests, mostly authorization.
- packages/storage: presigned direct-to-R2 uploads. The server picks the
key, so a caller can only write under their own user id. 14 tests.
Three defects found and fixed:
- The lazy db Proxy failed drizzle's is(db, PgDatabase) because it did
not trap getPrototypeOf. Auth adapters dispatch on exactly that check,
so this would have failed at runtime inside third-party code. Fixed
and pinned with a regression test.
- The open-request cap was a read-then-write race: concurrent swipes
could both read 4 and both insert. Now one transaction with the job
row locked. The cap is checked before the tombstone is written, so a
rejected swipe leaves no trace and the card stays on the deck.
- superjson was configured in two of the three required places. Without
the QueryClient dehydrate/hydrate pair, RSC-prefetched data arrives as
a raw envelope with no type error to warn you.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>