Skip to content

fix(design-system): add auth guard to /design-system token-viewer route - #297

Draft
dccakes wants to merge 2 commits into
mainfrom
claude/sharp-feynman-r0intn
Draft

dccakes wants to merge 2 commits into
mainfrom
claude/sharp-feynman-r0intn

Conversation

@dccakes

@dccakes dccakes commented Sep 9, 2026

Copy link
Copy Markdown
Owner

📝 TLDR

Add a layout.tsx to the /design-system route so unauthenticated users are redirected away from this internal dev tool.

📝 Description

The /design-system page (a color-token swatch viewer for picking CSS custom properties during styling work) had no auth guard — any visitor who knew the URL could reach it without logging in.

This adds a layout.tsx that calls getRequiredWedding(), matching the existing auth pattern used throughout the authenticated section of the app. Unauthenticated requests and sessions without an active wedding are redirected to /.

This Change

  • Adds src/app/design-system/layout.tsx — a minimal server-component layout that enforces auth before rendering the page
  • Does not wrap the page in the full app shell (no sidebar nav), keeping the standalone token-viewer experience intact
  • Follows the identical pattern already used by every authenticated page in the codebase

Daily Product Improvement

Summary

Added an auth guard to the /design-system internal token-viewer route, which was previously publicly accessible with no authentication check.

Recommendations Reviewed

  • Area: src/app/design-system/
    Issue: No auth guard — route is publicly accessible to unauthenticated visitors
    Recommendation: Add a layout.tsx that calls getRequiredWedding() to redirect unauthenticated requests
    Type: Frontend cleanup / Security
    Priority: Medium
    Effort: Small

  • Area: src/app/old_dashboard/ + src/components/old_dashboard/
    Issue: ~1,091 lines of dead code with no active imports
    Recommendation: Delete both directories
    Type: Frontend cleanup
    Priority: Medium
    Effort: Small
    Note: Already covered by open PR chore(cleanup): remove old_dashboard dead route and components #287 — not implemented today

  • Area: src/app/layout.tsx
    Issue: Both shadcn Toaster and Sonner are mounted simultaneously; only Sonner is used by active code (44 files vs 0 active shadcn users)
    Recommendation: Remove the shadcn Toaster, useToast hook, and toaster component
    Type: Frontend cleanup
    Priority: Medium
    Effort: Small
    Note: Already covered by open PR chore(layout): remove redundant shadcn Toaster — Sonner is the sole toast system #250 — not implemented today

  • Area: src/app/(authenicated)/ (route group name)
    Issue: Typo "authenicated" (missing 't') in route group directory, layout type name, and exported function name
    Recommendation: Rename to (authenticated) throughout
    Type: Frontend cleanup
    Priority: Low
    Effort: Medium (directory rename + all references in imports, type names, and exports)

  • Area: src/components/guest-list/guests-view.tsx, guest-detail-panel-content.tsx, src/components/settings/organization-members-settings-card.tsx
    Issue: Monolithic components of 856–1,000 lines each, mixing display, filter/sort state, drawer state, and mutation orchestration
    Recommendation: Extract focused sub-components and custom hooks per responsibility
    Type: Frontend cleanup
    Priority: Medium
    Effort: Large

Selected Improvement

Add auth guard to /design-system route — 1 new file, 11 lines.

Why This Was Selected

The two most obvious small wins (remove old_dashboard dead code, remove redundant shadcn Toaster) already have open PRs (#287 and #250). The design-system route exposure was the clearest remaining gap with no open PR, a small blast radius, and a real security/polish benefit. The fix reuses the established auth pattern exactly — low risk and immediately reviewable.

Changes Made

  • Added src/app/design-system/layout.tsx that awaits getRequiredWedding() before rendering children, redirecting unauthenticated or wedding-less sessions to /

Files Changed

  • src/app/design-system/layout.tsx (new, 11 lines)

Verification

  • Biome lint: biome check src/app/design-system/ — no issues
  • TypeScript: tsc --noEmit — zero errors
  • Unit tests: 2,080 tests across 237 suites — all pass (run by pre-commit lint-staged hook)
  • Code review: new file matches the pattern of src/app/(authenicated)/layout.tsx exactly

Future Recommendations

  • Recommendation: Fix typo (authenicated) → (authenticated) in route group directory and all references
    Priority: Low
    Effort: Medium
    Reason not included: Directory rename touches imports, type names, and layout exports across multiple files — worth a dedicated, carefully tested PR
    Should become GitHub issue: No (too minor to track separately)

  • Recommendation: Remove old_dashboard/ dead code (~1,091 lines, two directories, zero active imports)
    Priority: Medium
    Effort: Small
    Reason not included: Open PR chore(cleanup): remove old_dashboard dead route and components #287 already covers this
    Should become GitHub issue: No

  • Recommendation: Remove redundant shadcn Toaster from root layout (Sonner is the sole active toast system across 44 files)
    Priority: Medium
    Effort: Small
    Reason not included: Open PR chore(layout): remove redundant shadcn Toaster — Sonner is the sole toast system #250 already covers this
    Should become GitHub issue: No

  • Recommendation: Decompose monolithic components (guests-view.tsx ~1,000 lines, guest-detail-panel-content.tsx ~856 lines, organization-members-settings-card.tsx ~884 lines) into focused sub-components and hooks
    Priority: Medium
    Effort: Large
    Reason not included: Scope too large for a daily targeted improvement; high regression risk without a deliberate plan
    Should become GitHub issue: Yes — each file warrants its own issue with clear acceptance criteria

GitHub Issues Created or Proposed

No issues created today. The monolithic-component decomposition candidates (guests-view, guest-detail-panel, org-members-card) are worth separate tracking, but each is a multi-session effort that needs scoping before opening an issue. Will be proposed in a future run once the currently open cleanup PRs (#250, #287) land.


🤖 Generated with Claude Code

https://claude.ai/code/session_011LcZcwsfj93o1GCz82vmGu


Generated by Claude Code

The /design-system token-viewer page was publicly accessible to any
unauthenticated visitor who knew the URL. This is an internal dev tool
and should only be reachable by authenticated users with an active wedding.

Adds a layout.tsx that calls getRequiredWedding(), which follows the
existing auth pattern used throughout the app — unauthenticated requests
and missing-wedding states are redirected to /.

Co-Authored-By: AgenticDiego <noreply@carvallo.io>
Claude-Session: https://claude.ai/code/session_011LcZcwsfj93o1GCz82vmGu
@vercel

vercel Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
scv Error Error Sep 9, 2026 10:23am UTC

…nder

The auth guard layout calls getRequiredWedding() which hits the tRPC
router and requires a live database connection. Without force-dynamic,
Next.js may attempt to statically render the layout during Vercel's
build, failing when the database isn't reachable.

Matches the convention used by (authenicated)/layout.tsx.

Co-Authored-By: AgenticDiego <noreply@carvallo.io>
Claude-Session: https://claude.ai/code/session_011LcZcwsfj93o1GCz82vmGu
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Jest Test Coverage

Coverage Summary

Lines Statements Branches Functions
Coverage: 83%
83.11% (36264/43629) 82.14% (3813/4642) 69.49% (1073/1544)

dccakes commented Sep 9, 2026

Copy link
Copy Markdown
Owner Author

GitHub Actions CI is fully green — Build, Type Check, Lint & Format, Unit Tests, and the All PR Checks gate all pass on the current head.

The Vercel preview deployment failed (on both commits, in under 3 seconds each time), but this is not caused by this PR's change. The near-instant failure indicates a Vercel preview environment configuration issue (likely missing preview env vars), not a build or code error. PR #296 shows Vercel previews working correctly yesterday, so this appears to be a recent preview environment issue independent of this diff.

No code changes needed on this PR to address the Vercel failure.


Generated by Claude Code

This branch had an error being deployed

1 failed deployment
Preview — 4c1965b6 Deployed Sep 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants