e5b187c575
Backend
- Migration 0010 adds event_branding (one row per event; all fields
nullable so a brand-new event renders with defaults)
- BrandingRepo with COALESCE/NULLIF upsert semantics: nil pointer
preserves the existing value, "" clears the field to NULL
- internal/uploads package: ImageStore interface + LocalFSStore (dev),
pure-stdlib decode + re-encode that strips EXIF and rejects anything
that isn't valid JPEG/PNG. Size cap 2 MB, random 16-byte filenames
- GET /events/{id}/branding (viewer+) returns the row plus the
AllowedFonts list so the frontend picker stays in sync
- PUT /events/{id}/branding (editor+) validates hex colours, font
allowlist, and refuses image URLs whose path doesn't start with
/uploads/ (blocks arbitrary-origin <img> smuggling on guest pages)
- POST /uploads/image (authed) → fresh CDN URL; GET /uploads/{file}
serves with year-long cache (immutable random names)
- GET /access/{token} now embeds the host's branding so the RSVP page
can render in their colours/font with their logo + cover
- docker-compose mounts a named volume for uploads
- Custom-domain sub-block deferred to Tier 3 per the plan
Frontend
- BrandingCard.vue: colour pickers, font dropdown, logo + cover upload
with progressive disclosure, live preview pane that re-renders on
every keystroke
- RSVP page applies branding via CSS vars at the section root, so
primary colour theme + font cascade through every child card. Cover
image renders as a banner above the form; logo lands in the header
- Submit button background switches to var(--brand-primary) when set
- Mounted on the event detail page below the guests block
Plus the small UX fixes from the e2e walkthrough:
- Nav: dropped the top-level "Events" link; the logo doubles as the
home affordance (→ /dashboard when signed in, → / otherwise). Account
+ Billing + Sign out live under a profile dropdown (avatar with
initials, opens on click, closes on outside-click / Esc / route nav)
- Renamed "Back to dashboard" → "Back to events" across event detail,
billing, account, and new-event pages
Tests
- TestBrandingGetReturnsDefaults / TestBrandingPutPersists /
TestBrandingPutRejectsBadInputs / TestUploadAndServeImage /
TestUploadRejectsNonImage — all pass
- Domain tests for IsValidHexColor + IsAllowedFont
- Full integration suite green (176s)
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
60 lines
2.0 KiB
Vue
60 lines
2.0 KiB
Vue
<script setup lang="ts">
|
|
// Email verification landing. The verification link is server-generated
|
|
// and can't carry the original post-verify redirect (e.g. an invite path)
|
|
// in its URL — signup.vue parks that target in sessionStorage and we read
|
|
// it back here to compose a follow-on "Sign in" link that resumes the
|
|
// flow.
|
|
const auth = useAuth()
|
|
const route = useRoute()
|
|
|
|
type Status = 'pending' | 'success' | 'error'
|
|
const status = ref<Status>('pending')
|
|
const error = ref<string | null>(null)
|
|
|
|
// Computed lazily so the first render (SSR) doesn't touch sessionStorage.
|
|
const loginHref = ref('/login')
|
|
|
|
onMounted(async () => {
|
|
if (import.meta.client) {
|
|
const parked = sessionStorage.getItem('gg.postAuthRedirect')
|
|
if (parked) {
|
|
loginHref.value = `/login?redirect=${encodeURIComponent(parked)}`
|
|
}
|
|
}
|
|
|
|
const token = route.query.token
|
|
if (typeof token !== 'string' || !token) {
|
|
status.value = 'error'
|
|
error.value = 'Missing verification token.'
|
|
return
|
|
}
|
|
try {
|
|
await auth.verifyEmail(token)
|
|
status.value = 'success'
|
|
} catch (e: any) {
|
|
status.value = 'error'
|
|
error.value = e?.data?.error || e?.message || 'Verification failed.'
|
|
}
|
|
})
|
|
</script>
|
|
|
|
<template>
|
|
<section class="mx-auto max-w-md py-12">
|
|
<h1 class="mb-6 text-2xl font-semibold">Verify your email</h1>
|
|
|
|
<div class="card text-sm">
|
|
<p v-if="status === 'pending'" class="text-zinc-400">Verifying…</p>
|
|
<template v-else-if="status === 'success'">
|
|
<p class="mb-3 font-medium text-brand-300">Email verified.</p>
|
|
<p class="mb-4 text-zinc-400">You can now sign in to your account.</p>
|
|
<NuxtLink :to="loginHref" class="btn-primary w-full">Sign in</NuxtLink>
|
|
</template>
|
|
<template v-else>
|
|
<p class="mb-3 font-medium text-red-400">We couldn't verify that link.</p>
|
|
<p class="mb-4 text-zinc-400">{{ error }}</p>
|
|
<NuxtLink :to="loginHref" class="btn-ghost w-full">Back to sign in</NuxtLink>
|
|
</template>
|
|
</div>
|
|
</section>
|
|
</template>
|