Commit ecd70f4
committed
fix(web): invites ride the signed path — creation, acceptance and reads stop trusting the client
Rewires all 8 exports of supabase-invites.ts to Task 4's org-membership
edge function contract: create/revoke/accept/decline/list_invites/
has_pending_invite go through callOrgMembership(account, action, payload)
with a signed message, and invitedBy/the leaving wallet are derived
server-side from the verified signer rather than trusted from the client.
fetchInviteByToken moves to the anon-callable get_invite_by_token RPC
(bearer-token lookup, no wallet param). Reads keep a read-only fallback to
the direct invite_tokens query (isolated to three helpers, clearly
commented) for the deploy window before the RPC/edge function are live in
production; writes never fall back.
hasPendingInvite's new contract only answers for the calling wallet (the
edge function won't check an arbitrary wallet — that would leak other
users' invite status), so org/manage's duplicate-invite precheck is
dropped; duplicates are already legal in the schema.
Also threads useActiveAccount() through every invite call site
(invite/[token]/page.tsx, org/manage/page.tsx), and drops the
administrator-only 'stadt'/'fraktion' sub_types from the org/create picker
now that create_account rejects them for self-service callers (folded in
from the Task 4 review).1 parent 3f838fd commit ecd70f4
4 files changed
Lines changed: 210 additions & 190 deletions
File tree
- apps/web/src
- app
- app/org
- create
- manage
- invite/[token]
- lib
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
26 | 30 | | |
27 | 31 | | |
28 | 32 | | |
29 | 33 | | |
30 | | - | |
31 | | - | |
32 | 34 | | |
33 | 35 | | |
34 | 36 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
26 | 25 | | |
27 | 26 | | |
28 | 27 | | |
| |||
84 | 83 | | |
85 | 84 | | |
86 | 85 | | |
87 | | - | |
| 86 | + | |
88 | 87 | | |
89 | 88 | | |
90 | | - | |
| 89 | + | |
91 | 90 | | |
92 | 91 | | |
93 | 92 | | |
94 | 93 | | |
95 | 94 | | |
96 | | - | |
| 95 | + | |
97 | 96 | | |
98 | 97 | | |
99 | 98 | | |
| |||
112 | 111 | | |
113 | 112 | | |
114 | 113 | | |
115 | | - | |
| 114 | + | |
116 | 115 | | |
117 | 116 | | |
118 | | - | |
119 | | - | |
120 | | - | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
121 | 123 | | |
122 | 124 | | |
123 | 125 | | |
| |||
130 | 132 | | |
131 | 133 | | |
132 | 134 | | |
133 | | - | |
| 135 | + | |
134 | 136 | | |
135 | 137 | | |
136 | | - | |
| 138 | + | |
137 | 139 | | |
138 | 140 | | |
139 | 141 | | |
| |||
144 | 146 | | |
145 | 147 | | |
146 | 148 | | |
147 | | - | |
148 | | - | |
| 149 | + | |
| 150 | + | |
149 | 151 | | |
150 | 152 | | |
151 | 153 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
64 | | - | |
| 64 | + | |
65 | 65 | | |
66 | 66 | | |
67 | | - | |
| 67 | + | |
68 | 68 | | |
69 | 69 | | |
70 | 70 | | |
| |||
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
77 | | - | |
| 77 | + | |
78 | 78 | | |
79 | 79 | | |
80 | | - | |
| 80 | + | |
81 | 81 | | |
82 | 82 | | |
83 | 83 | | |
| |||
0 commit comments