Harden admin moderation and ride request workflows#3
Merged
Conversation
|
@SaarthurR is attempting to deploy a commit to the rankasaarth-7835's projects team on Vercel, but is not a member of this team. To resolve this issue, you can:
To read more about collaboration on Vercel, click here. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Admin report handling and ride pickup requests had workflow gaps at their trust boundaries: moderation evidence could be live or ambiguously selected, admin actions were not fully report-scoped/atomic, compact report layers could inherit a transformed containing block, and seat requests could bypass required pickup capture through direct inserts.
What changed
document.body, preserving focus, dismissal, pending, and mobile behavior.Migrations
Apply in order:
20260713212211_admin_report_workflow.sql20260713212336_ride_pickup_request_hardening.sql20260713222740_report_history_upper_bound.sqlThe repository SQL fixture covers privileges, immutable/bounded evidence, generic notifications, atomic ban/report state, required pickup, locking/capacity, and RPC-only passenger creation. Local Supabase pgTAP remains for CI/a Docker-enabled environment.
Test plan
Verified from a clean
git archiveof commit63d5dddusing the existing dependencies/environment:npm test— 403 passednpm run lintnpx tsc --noEmitnpm run build— Next.js 16.2.9 Turbopack production buildgit diff --check origin/main..HEADIndependent browser verification covered desktop 1440×900 and mobile 390×844 report-layer geometry, focus restoration, pending dismissal guards, exact target/context storage, admin default selection and notification deep links, with no app console or hydration-overlay errors. Ride browser smoke covered desktop/mobile intent layers, required pickup validation, and clean console/overlay behavior.