-
Notifications
You must be signed in to change notification settings - Fork 423
Lewis/user portal #65
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,41 @@ | ||
| # See https://help.github.com/articles/ignoring-files/ for more about ignoring files. | ||
|
|
||
| # dependencies | ||
| /node_modules | ||
| /.pnp | ||
| .pnp.* | ||
| .yarn/* | ||
| !.yarn/patches | ||
| !.yarn/plugins | ||
| !.yarn/releases | ||
| !.yarn/versions | ||
|
|
||
| # testing | ||
| /coverage | ||
|
|
||
| # next.js | ||
| /.next/ | ||
| /out/ | ||
|
|
||
| # production | ||
| /build | ||
|
|
||
| # misc | ||
| .DS_Store | ||
| *.pem | ||
|
|
||
| # debug | ||
| npm-debug.log* | ||
| yarn-debug.log* | ||
| yarn-error.log* | ||
| .pnpm-debug.log* | ||
|
|
||
| # env files (can opt-in for committing if needed) | ||
| .env* | ||
|
|
||
| # vercel | ||
| .vercel | ||
|
|
||
| # typescript | ||
| *.tsbuildinfo | ||
| next-env.d.ts |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,36 @@ | ||
| This is a [Next.js](https://nextjs.org) project bootstrapped with [`create-next-app`](https://nextjs.org/docs/app/api-reference/cli/create-next-app). | ||
|
|
||
| ## Getting Started | ||
|
|
||
| First, run the development server: | ||
|
|
||
| ```bash | ||
| npm run dev | ||
| # or | ||
| yarn dev | ||
| # or | ||
| pnpm dev | ||
| # or | ||
| bun dev | ||
| ``` | ||
|
|
||
| Open [http://localhost:3000](http://localhost:3000) with your browser to see the result. | ||
|
|
||
| You can start editing the page by modifying `app/page.tsx`. The page auto-updates as you edit the file. | ||
|
|
||
| This project uses [`next/font`](https://nextjs.org/docs/app/building-your-application/optimizing/fonts) to automatically optimize and load [Geist](https://vercel.com/font), a new font family for Vercel. | ||
|
|
||
| ## Learn More | ||
|
|
||
| To learn more about Next.js, take a look at the following resources: | ||
|
|
||
| - [Next.js Documentation](https://nextjs.org/docs) - learn about Next.js features and API. | ||
| - [Learn Next.js](https://nextjs.org/learn) - an interactive Next.js tutorial. | ||
|
|
||
| You can check out [the Next.js GitHub repository](https://github.com/vercel/next.js) - your feedback and contributions are welcome! | ||
|
|
||
| ## Deploy on Vercel | ||
|
|
||
| The easiest way to deploy your Next.js app is to use the [Vercel Platform](https://vercel.com/new?utm_medium=default-template&filter=next.js&utm_source=create-next-app&utm_campaign=create-next-app-readme) from the creators of Next.js. | ||
|
|
||
| Check out our [Next.js deployment documentation](https://nextjs.org/docs/app/building-your-application/deploying) for more details. |
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,31 @@ | ||||||||||||||||||||||||||||||||||||||||||
| import "./src/env.mjs"; | ||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||
| const config = { | ||||||||||||||||||||||||||||||||||||||||||
| images: { | ||||||||||||||||||||||||||||||||||||||||||
| remotePatterns: [ | ||||||||||||||||||||||||||||||||||||||||||
| { | ||||||||||||||||||||||||||||||||||||||||||
| protocol: "https", | ||||||||||||||||||||||||||||||||||||||||||
| hostname: "**", | ||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||
| ], | ||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+4
to
+11
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Restrict image domains for security. The current image configuration allows images from any HTTPS hostname, which could pose security risks. Consider explicitly listing only the required domains. images: {
remotePatterns: [
{
protocol: "https",
- hostname: "**",
+ hostname: "us-assets.i.posthog.com",
},
+ {
+ protocol: "https",
+ hostname: "your-other-trusted-domain.com",
+ },
],
},📝 Committable suggestion
Suggested change
|
||||||||||||||||||||||||||||||||||||||||||
| async rewrites() { | ||||||||||||||||||||||||||||||||||||||||||
| return [ | ||||||||||||||||||||||||||||||||||||||||||
| { | ||||||||||||||||||||||||||||||||||||||||||
| source: "/ingest/static/:path*", | ||||||||||||||||||||||||||||||||||||||||||
| destination: "https://us-assets.i.posthog.com/static/:path*", | ||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||
| { | ||||||||||||||||||||||||||||||||||||||||||
| source: "/ingest/:path*", | ||||||||||||||||||||||||||||||||||||||||||
| destination: "https://us.i.posthog.com/:path*", | ||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||
| { | ||||||||||||||||||||||||||||||||||||||||||
| source: "/ingest/decide", | ||||||||||||||||||||||||||||||||||||||||||
| destination: "https://us.i.posthog.com/decide", | ||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||
| ]; | ||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||
| skipTrailingSlashRedirect: true, | ||||||||||||||||||||||||||||||||||||||||||
| }; | ||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||
| export default config; | ||||||||||||||||||||||||||||||||||||||||||
| Original file line number | Diff line number | Diff line change | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,27 @@ | ||||||||||||||||||
| { | ||||||||||||||||||
| "name": "portal", | ||||||||||||||||||
| "version": "0.1.0", | ||||||||||||||||||
| "private": true, | ||||||||||||||||||
| "scripts": { | ||||||||||||||||||
| "dev": "next dev --turbopack -p 3002", | ||||||||||||||||||
| "build": "next build", | ||||||||||||||||||
| "start": "next start", | ||||||||||||||||||
| "lint": "next lint" | ||||||||||||||||||
| }, | ||||||||||||||||||
| "dependencies": { | ||||||||||||||||||
| "better-auth": "^1.1.18", | ||||||||||||||||||
| "next": "15.1.7", | ||||||||||||||||||
| "react": "^19.0.0", | ||||||||||||||||||
| "react-dom": "^19.0.0", | ||||||||||||||||||
| "react-otp-input": "^3.1.1" | ||||||||||||||||||
|
Comment on lines
+13
to
+16
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Verify package versions. Several package versions appear to be incorrect or not yet released:
Update the versions to currently available releases: - "next": "15.1.7",
- "react": "^19.0.0",
- "react-dom": "^19.0.0",
+ "next": "^14.1.0",
+ "react": "^18.2.0",
+ "react-dom": "^18.2.0",📝 Committable suggestion
Suggested change
|
||||||||||||||||||
| }, | ||||||||||||||||||
| "devDependencies": { | ||||||||||||||||||
| "@bubba/ui": "workspace:*", | ||||||||||||||||||
| "@types/node": "^22.13.2", | ||||||||||||||||||
| "@types/react": "^19.0.8", | ||||||||||||||||||
| "@types/react-dom": "^19.0.3", | ||||||||||||||||||
|
Comment on lines
+20
to
+22
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Update @types versions. The Node.js types version appears incorrect:
Update the versions: - "@types/node": "^22.13.2",
- "@types/react": "^19.0.8",
- "@types/react-dom": "^19.0.3",
+ "@types/node": "^20.11.0",
+ "@types/react": "^18.2.0",
+ "@types/react-dom": "^18.2.0",📝 Committable suggestion
Suggested change
|
||||||||||||||||||
| "postcss": "^8.5.2", | ||||||||||||||||||
| "tailwindcss": "^3.4.17", | ||||||||||||||||||
| "typescript": "^5.7.3" | ||||||||||||||||||
| } | ||||||||||||||||||
| } | ||||||||||||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,8 @@ | ||
| /** @type {import('postcss-load-config').Config} */ | ||
| const config = { | ||
| plugins: { | ||
| tailwindcss: {}, | ||
| }, | ||
| }; | ||
|
|
||
| export default config; |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,21 @@ | ||
| { | ||
| "name": "Comp AI", | ||
| "short_name": "Comp AI", | ||
| "icons": [ | ||
| { | ||
| "src": "/web-app-manifest-192x192.png", | ||
| "sizes": "192x192", | ||
| "type": "image/png", | ||
| "purpose": "maskable" | ||
| }, | ||
| { | ||
| "src": "/web-app-manifest-512x512.png", | ||
| "sizes": "512x512", | ||
| "type": "image/png", | ||
| "purpose": "maskable" | ||
| } | ||
| ], | ||
| "theme_color": "#ffffff", | ||
| "background_color": "#ffffff", | ||
| "display": "standalone" | ||
| } |
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,55 @@ | ||||||||||||||||||||||||||||||||||||||||||||||
| import { auth } from "@/app/lib/auth"; | ||||||||||||||||||||||||||||||||||||||||||||||
| import { db } from "@bubba/db"; | ||||||||||||||||||||||||||||||||||||||||||||||
| import { unstable_cache } from "next/cache"; | ||||||||||||||||||||||||||||||||||||||||||||||
| import { headers } from "next/headers"; | ||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||
| export default async function Home() { | ||||||||||||||||||||||||||||||||||||||||||||||
| const session = await auth.api.getSession({ | ||||||||||||||||||||||||||||||||||||||||||||||
| headers: await headers(), | ||||||||||||||||||||||||||||||||||||||||||||||
| }); | ||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||
| if (!session) { | ||||||||||||||||||||||||||||||||||||||||||||||
| return null; | ||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+6
to
+14
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🛠️ Refactor suggestion Add error handling for session retrieval. Consider adding error handling for session retrieval failures and displaying an appropriate error message. export default async function Home() {
- const session = await auth.api.getSession({
- headers: await headers(),
- });
+ try {
+ const session = await auth.api.getSession({
+ headers: await headers(),
+ });
- if (!session) {
- return null;
- }
+ if (!session) {
+ return <div>Please sign in to access this page</div>;
+ }
+ } catch (error) {
+ console.error('Failed to retrieve session:', error);
+ return <div>An error occurred while retrieving your session</div>;
+ }📝 Committable suggestion
Suggested change
|
||||||||||||||||||||||||||||||||||||||||||||||
| const user = await getUser(session.user.email); | ||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||
| return ( | ||||||||||||||||||||||||||||||||||||||||||||||
| <div className="grid grid-rows-[20px_1fr_20px] items-center justify-items-center min-h-screen p-8 pb-20 gap-16 sm:p-20 font-[family-name:var(--font-geist-sans)]"> | ||||||||||||||||||||||||||||||||||||||||||||||
| <main className="flex flex-col gap-8 row-start-2 items-center sm:items-start"> | ||||||||||||||||||||||||||||||||||||||||||||||
| {user?.id && user?.organization?.id && ( | ||||||||||||||||||||||||||||||||||||||||||||||
| <div> | ||||||||||||||||||||||||||||||||||||||||||||||
| <h1>Welcome to the portal</h1> | ||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||
| <p>You are logged in as {user.email}</p> | ||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||
| <p> | ||||||||||||||||||||||||||||||||||||||||||||||
| You work for {user.organization.name} and your employee ID is{" "} | ||||||||||||||||||||||||||||||||||||||||||||||
| {user.id} | ||||||||||||||||||||||||||||||||||||||||||||||
| </p> | ||||||||||||||||||||||||||||||||||||||||||||||
| </div> | ||||||||||||||||||||||||||||||||||||||||||||||
| )} | ||||||||||||||||||||||||||||||||||||||||||||||
| </main> | ||||||||||||||||||||||||||||||||||||||||||||||
| </div> | ||||||||||||||||||||||||||||||||||||||||||||||
| ); | ||||||||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||
| export const getUser = unstable_cache(async (email: string) => { | ||||||||||||||||||||||||||||||||||||||||||||||
| "use server"; | ||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||
| const employee_data = await db.employee.findFirst({ | ||||||||||||||||||||||||||||||||||||||||||||||
| where: { | ||||||||||||||||||||||||||||||||||||||||||||||
| email, | ||||||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||||||
| include: { | ||||||||||||||||||||||||||||||||||||||||||||||
| organization: { | ||||||||||||||||||||||||||||||||||||||||||||||
| select: { | ||||||||||||||||||||||||||||||||||||||||||||||
| id: true, | ||||||||||||||||||||||||||||||||||||||||||||||
| name: true, | ||||||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||||||
| }, | ||||||||||||||||||||||||||||||||||||||||||||||
| }); | ||||||||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||||||||
| return employee_data; | ||||||||||||||||||||||||||||||||||||||||||||||
| }); | ||||||||||||||||||||||||||||||||||||||||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,46 @@ | ||
| import { OtpSignIn } from "@/app/components/otp"; | ||
| import { getI18n } from "@/app/locales/server"; | ||
| import type { Metadata } from "next"; | ||
| import Link from "next/link"; | ||
|
|
||
| export const metadata: Metadata = { | ||
| title: "Login | Comp AI", | ||
| }; | ||
|
|
||
| export default async function Page() { | ||
| const t = await getI18n(); | ||
|
|
||
| const defaultSignInOptions = ( | ||
| <div className="flex flex-col space-y-2"> | ||
| <OtpSignIn /> | ||
| </div> | ||
| ); | ||
|
|
||
| return ( | ||
| <> | ||
| <div className="flex min-h-[calc(100vh-15rem)] items-center justify-center overflow-hidden p-6 md:p-0"> | ||
| <div className="relative z-20 m-auto flex w-full max-w-[380px] flex-col py-8"> | ||
| <div className="relative flex w-full flex-col"> | ||
| <div className="inline-block from-primary bg-clip-text pb-4"> | ||
| <div className="flex flex-row items-center gap-2"> | ||
| <Link href="/" className="flex flex-row items-center gap-2"> | ||
| <h1 className="font-mono text-xl font-semibold">Comp AI</h1> | ||
| </Link> | ||
| </div> | ||
| <h2 className="mt-4 text-lg font-medium">{t("auth.title")}</h2> | ||
| <div className="mt-2"> | ||
| <span className="text-xs text-muted-foreground"> | ||
| {t("auth.description")} | ||
| </span> | ||
| </div> | ||
| </div> | ||
|
|
||
| <div className="pointer-events-auto mb-6 flex flex-col"> | ||
| {defaultSignInOptions} | ||
| </div> | ||
| </div> | ||
| </div> | ||
| </div> | ||
| </> | ||
| ); | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,7 @@ | ||
| export default async function Layout({ | ||
| children, | ||
| }: { | ||
| children: React.ReactNode; | ||
| }) { | ||
| return <>{children}</>; | ||
| } |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Critical: Replace hardcoded session token with secure token generation.
The hardcoded token "123" is a significant security vulnerability that could lead to unauthorized access. This appears to be a temporary placeholder after removing the Nango integration.
Please implement proper session token generation with: