Repository navigation
feat: host claims + Luma verification + admin Claims tab (host analytics phase 1) - #177
Merged
Merged
Conversation
…ics phase 1) - Migration 20261002120000_event_claims.sql: event_claims + verified_luma_hosts (RLS: owner select only; writes via service role), Phase 2 support indexes. - Luma verification: code in event description (this event only) or in a listed host's bio (proves control of that Luma host account -> host-wide coverage; later claims on events listing that host auto-verify as 'luma_host'). All Luma fetches via safeFetch, slug/api-id validated. - Routes: /api/host/claims (GET/POST), /api/host/claims/[id] (DELETE), /api/host/claims/[id]/verify, /api/host/claims/[id]/manual, /api/admin/claims (GET), /api/admin/claims/[id] (approve/reject/revoke/relink). Admin revoke cascades to the host-wide grant and derived claims. - server-auth.ts (Bearer access token -> supabase.auth.getUser), zod schemas. - ClaimEventModal + "Host? Claim this event" link in table detail modal and map popup; admin ClaimsTab. - Tests: luma-verify (recorded trimmed Luma fixture), normalize-link, schemas. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Phase 1 of
plans/host-analytics.md(plan copied into the repo in this PR): hosts can claim an event, verify it automatically through Luma, or ask for a manual review. Admins work the queue in a new Claims tab.What's in it
supabase/migrations/20261002120000_event_claims.sqlevent_claims: the plan §4 columns, plushost_api_id,derived_from_claim_idand a new methodluma_host.verified_luma_hosts(user_id, host_api_id, host_name, claim_id, verified_at, revoked_at), with a partial unique index on active rows.event_tracking(event_id, created_at)and a GIN index onitineraries.event_ids(it'stext[]).planwtf-XXXXXXXXcode (40 random bits, Crockford base32).description_mirror(text and link hrefs; a code split across marks still matches; it must be a whole token and case doesn't matter), then in each listed host'sbio_short.host_api_idon the claim and its evidence, and adds averified_luma_hostsrow.hosts[]includes a host the user has verified are verified immediately:method='luma_host', and the evidence recordsoriginal_claim_id.src/lib/server-auth.ts(getUserFromRequest: Bearer access token →auth.getUser).api-validation.ts.luma.tsholds only pure functions, so client components can import it.luma-server.tsdoes the fetching throughsafeFetchand generates codes. This split keeps node modules out of the client bundle.ClaimEventModal, opened from a small "Host? Claim this event" link under the card in the tableEventDetailModaland in the mapEventPopup.New API routes and suggested per-IP Vercel firewall limits
GET /api/host/claims?eventId=POST /api/host/claimsDELETE /api/host/claims/[id]POST /api/host/claims/[id]/verifyPOST /api/host/claims/[id]/manualGET /api/admin/claimsPOST /api/admin/claims/[id]The database adds its own limits: a 10s verify cooldown (optimistic-concurrency update), at most 30 attempts per claim and at most 20 pending claims per user.
Verification done
npm run lint: 0 errors (the 3 warnings were already there).npx tsc --noEmit: clean.npm test: 359 passing, including the newluma-verify,normalize-linkandhost-claims-schemastests. The fixturesrc/lib/__tests__/fixtures/luma-event.jsonis a recordedespresso-hhpayload, trimmed: no guest_data, payment, tracking or personal fields.npx next build: OK.next devwith curl: every host route returns 401 without a token or with a bogus one, and 400 for a bad event id, claim id, JSON or note. Admin routes return 401 for a wrong password and 400 for a bad action or relink without an event id. With the real admin password the queue answers "table not yet created", so it degrades cleanly before the migration is applied.fetchLumaEventthroughsafeFetchworked: slug → api id → refetch by id, a missing event returnsnot_found, and an invalid slug is refused.Manual QA checklist (needs a signed-in user after the migration is applied)
Verified Luma host, "from claim …").Not in this PR (Phase 2):
/hostdashboard,GET /api/host/events, stats RPC, the admin "grant" action and "Preview stats".🤖 Generated with Claude Code