Skip to content

Require invitations for trip contributions - #16

Merged
nedcut merged 1 commit into
mainfrom
codex/invite-only-contributions
Jul 11, 2026
Merged

Require invitations for trip contributions#16
nedcut merged 1 commit into
mainfrom
codex/invite-only-contributions

Conversation

@nedcut

@nedcut nedcut commented Jul 11, 2026

Copy link
Copy Markdown
Owner

What changed

  • removes automatic membership enrollment when any visitor signs in
  • drops the legacy self-enrollment RPC through an idempotent migration and recovery schema
  • preserves public trip reads and all existing member/admin access
  • keeps admin email-based member grants as the contribution path
  • labels signed-in nonmembers as view-only and updates setup documentation
  • adds regression coverage for the access contract

Why

The intended policy is public viewing with editing limited to the friends who were on the trip. Previously, every signed-in visitor silently became a member and therefore gained photo/note contribution rights.

Deployment

Apply 20260711120000_invite_only_contributions.sql to Supabase. Existing members are not changed. A new contributor signs in once, an admin adds their email from Members, and the contributor reloads.

Validation

  • npm run lint (0 errors; one pre-existing hook dependency warning)
  • npm run typecheck
  • npm test (215 tests)
  • npm run test:e2e (7 tests)
  • git diff --check

Manual smoke test

Verify anonymous viewing, a signed-in uninvited account showing view-only controls, an existing member retaining upload/note controls, and an admin granting a newly authenticated email from Members.

Copilot AI review requested due to automatic review settings July 11, 2026 20:24
@vercel

vercel Bot commented Jul 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lofoten-map Ready Ready Preview, Comment Jul 11, 2026 8:25pm

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Jul 11, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@nedcut, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 59 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 34537df2-dc8b-42c1-b4c2-d6ba8304a1ce

📥 Commits

Reviewing files that changed from the base of the PR and between bd21259 and 13a5df9.

📒 Files selected for processing (7)
  • README.md
  • app/page.tsx
  • lib/access.test.ts
  • lib/hooks/useTripData.ts
  • lib/invite-only-access.test.ts
  • supabase/migrations/20260711120000_invite_only_contributions.sql
  • supabase/schema.sql
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/invite-only-contributions

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nedcut
nedcut merged commit 06abcd6 into main Jul 11, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants