Conversation
The /design-system token-viewer page was publicly accessible to any unauthenticated visitor who knew the URL. This is an internal dev tool and should only be reachable by authenticated users with an active wedding. Adds a layout.tsx that calls getRequiredWedding(), which follows the existing auth pattern used throughout the app — unauthenticated requests and missing-wedding states are redirected to /. Co-Authored-By: AgenticDiego <noreply@carvallo.io> Claude-Session: https://claude.ai/code/session_011LcZcwsfj93o1GCz82vmGu
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
…nder The auth guard layout calls getRequiredWedding() which hits the tRPC router and requires a live database connection. Without force-dynamic, Next.js may attempt to statically render the layout during Vercel's build, failing when the database isn't reachable. Matches the convention used by (authenicated)/layout.tsx. Co-Authored-By: AgenticDiego <noreply@carvallo.io> Claude-Session: https://claude.ai/code/session_011LcZcwsfj93o1GCz82vmGu
Contributor
Owner
Author
|
GitHub Actions CI is fully green — Build, Type Check, Lint & Format, Unit Tests, and the All PR Checks gate all pass on the current head. The Vercel preview deployment failed (on both commits, in under 3 seconds each time), but this is not caused by this PR's change. The near-instant failure indicates a Vercel preview environment configuration issue (likely missing preview env vars), not a build or code error. PR #296 shows Vercel previews working correctly yesterday, so this appears to be a recent preview environment issue independent of this diff. No code changes needed on this PR to address the Vercel failure. Generated by Claude Code |
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📝 TLDR
Add a layout.tsx to the
/design-systemroute so unauthenticated users are redirected away from this internal dev tool.📝 Description
The
/design-systempage (a color-token swatch viewer for picking CSS custom properties during styling work) had no auth guard — any visitor who knew the URL could reach it without logging in.This adds a
layout.tsxthat callsgetRequiredWedding(), matching the existing auth pattern used throughout the authenticated section of the app. Unauthenticated requests and sessions without an active wedding are redirected to/.This Change
src/app/design-system/layout.tsx— a minimal server-component layout that enforces auth before rendering the pageDaily Product Improvement
Summary
Added an auth guard to the
/design-systeminternal token-viewer route, which was previously publicly accessible with no authentication check.Recommendations Reviewed
Area:
src/app/design-system/Issue: No auth guard — route is publicly accessible to unauthenticated visitors
Recommendation: Add a layout.tsx that calls
getRequiredWedding()to redirect unauthenticated requestsType: Frontend cleanup / Security
Priority: Medium
Effort: Small
Area:
src/app/old_dashboard/+src/components/old_dashboard/Issue: ~1,091 lines of dead code with no active imports
Recommendation: Delete both directories
Type: Frontend cleanup
Priority: Medium
Effort: Small
Note: Already covered by open PR chore(cleanup): remove old_dashboard dead route and components #287 — not implemented today
Area:
src/app/layout.tsxIssue: Both shadcn Toaster and Sonner are mounted simultaneously; only Sonner is used by active code (44 files vs 0 active shadcn users)
Recommendation: Remove the shadcn Toaster, useToast hook, and toaster component
Type: Frontend cleanup
Priority: Medium
Effort: Small
Note: Already covered by open PR chore(layout): remove redundant shadcn Toaster — Sonner is the sole toast system #250 — not implemented today
Area:
src/app/(authenicated)/(route group name)Issue: Typo "authenicated" (missing 't') in route group directory, layout type name, and exported function name
Recommendation: Rename to
(authenticated)throughoutType: Frontend cleanup
Priority: Low
Effort: Medium (directory rename + all references in imports, type names, and exports)
Area:
src/components/guest-list/guests-view.tsx,guest-detail-panel-content.tsx,src/components/settings/organization-members-settings-card.tsxIssue: Monolithic components of 856–1,000 lines each, mixing display, filter/sort state, drawer state, and mutation orchestration
Recommendation: Extract focused sub-components and custom hooks per responsibility
Type: Frontend cleanup
Priority: Medium
Effort: Large
Selected Improvement
Add auth guard to
/design-systemroute — 1 new file, 11 lines.Why This Was Selected
The two most obvious small wins (remove old_dashboard dead code, remove redundant shadcn Toaster) already have open PRs (#287 and #250). The design-system route exposure was the clearest remaining gap with no open PR, a small blast radius, and a real security/polish benefit. The fix reuses the established auth pattern exactly — low risk and immediately reviewable.
Changes Made
src/app/design-system/layout.tsxthat awaitsgetRequiredWedding()before rendering children, redirecting unauthenticated or wedding-less sessions to/Files Changed
src/app/design-system/layout.tsx(new, 11 lines)Verification
biome check src/app/design-system/— no issuestsc --noEmit— zero errorssrc/app/(authenicated)/layout.tsxexactlyFuture Recommendations
Recommendation: Fix typo
(authenicated)→(authenticated)in route group directory and all referencesPriority: Low
Effort: Medium
Reason not included: Directory rename touches imports, type names, and layout exports across multiple files — worth a dedicated, carefully tested PR
Should become GitHub issue: No (too minor to track separately)
Recommendation: Remove
old_dashboard/dead code (~1,091 lines, two directories, zero active imports)Priority: Medium
Effort: Small
Reason not included: Open PR chore(cleanup): remove old_dashboard dead route and components #287 already covers this
Should become GitHub issue: No
Recommendation: Remove redundant shadcn Toaster from root layout (Sonner is the sole active toast system across 44 files)
Priority: Medium
Effort: Small
Reason not included: Open PR chore(layout): remove redundant shadcn Toaster — Sonner is the sole toast system #250 already covers this
Should become GitHub issue: No
Recommendation: Decompose monolithic components (guests-view.tsx ~1,000 lines, guest-detail-panel-content.tsx ~856 lines, organization-members-settings-card.tsx ~884 lines) into focused sub-components and hooks
Priority: Medium
Effort: Large
Reason not included: Scope too large for a daily targeted improvement; high regression risk without a deliberate plan
Should become GitHub issue: Yes — each file warrants its own issue with clear acceptance criteria
GitHub Issues Created or Proposed
No issues created today. The monolithic-component decomposition candidates (guests-view, guest-detail-panel, org-members-card) are worth separate tracking, but each is a multi-session effort that needs scoping before opening an issue. Will be proposed in a future run once the currently open cleanup PRs (#250, #287) land.
🤖 Generated with Claude Code
https://claude.ai/code/session_011LcZcwsfj93o1GCz82vmGu
Generated by Claude Code