client passwords
Deploy / deploy (push) Successful in 2m57s

This commit is contained in:
twotalesanimation
2026-06-12 12:37:57 +02:00
parent 5bfaf49fa1
commit 23f0ceca3f
13 changed files with 377 additions and 74 deletions
+7 -9
View File
@@ -2,6 +2,7 @@ import { NextRequest, NextResponse } from "next/server";
import { db } from "@/lib/db";
import { ApprovalStatus } from "@prisma/client";
import { recalcShotStatus } from "@/lib/shot-status";
import { validateReviewToken } from "@/lib/review-auth";
async function getOrCreateClientUser(email: string, label?: string | null) {
const existing = await db.user.findUnique({ where: { email } });
@@ -16,22 +17,19 @@ async function getOrCreateClientUser(email: string, label?: string | null) {
});
}
async function validateToken(token: string) {
const session = await db.reviewSession.findUnique({ where: { token } });
if (!session || !session.isActive) return null;
if (session.expiresAt && session.expiresAt < new Date()) return null;
return session;
}
export async function POST(
req: NextRequest,
{ params }: { params: Promise<{ token: string }> }
) {
const { token } = await params;
const session = await validateToken(token);
if (!session) {
const result = await validateReviewToken(token, req);
if (result.type === "requiresPassword") {
return NextResponse.json({ requiresPassword: true }, { status: 401 });
}
if (result.type === "invalid") {
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
}
const session = result.session;
const body = await req.json();
const { versionId, shotId, action, status, notes } = body;
+48
View File
@@ -0,0 +1,48 @@
import { NextRequest, NextResponse } from "next/server";
import { db } from "@/lib/db";
import bcrypt from "bcryptjs";
import { makeUnlockCookieValue } from "@/lib/review-auth";
export async function POST(
req: NextRequest,
{ params }: { params: Promise<{ token: string }> }
) {
const { token } = await params;
const body = await req.json().catch(() => ({}));
const { password } = body as { password?: string };
if (!password || typeof password !== "string") {
return NextResponse.json({ error: "Password required" }, { status: 400 });
}
const session = await db.reviewSession.findUnique({ where: { token } });
if (!session || !session.isActive) {
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
}
if (session.expiresAt && session.expiresAt < new Date()) {
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
}
if (!session.passwordHash) {
return NextResponse.json({ success: true });
}
const valid = await bcrypt.compare(password, session.passwordHash);
if (!valid) {
return NextResponse.json({ error: "Incorrect password" }, { status: 401 });
}
const cookieName = `rsauth_${token}`;
const cookieValue = makeUnlockCookieValue(token);
const res = NextResponse.json({ success: true });
res.cookies.set(cookieName, cookieValue, {
httpOnly: true,
sameSite: "lax",
path: "/",
expires: session.expiresAt,
secure: process.env.NODE_ENV === "production",
});
return res;
}
+7 -9
View File
@@ -1,6 +1,7 @@
import { NextRequest, NextResponse } from "next/server";
import { db } from "@/lib/db";
import { slackNotifyNewFeedback } from "@/lib/slack";
import { validateReviewToken } from "@/lib/review-auth";
/** Find or create a guest user for the client reviewer based on the session email */
async function getOrCreateClientUser(email: string, label?: string | null) {
@@ -16,22 +17,19 @@ async function getOrCreateClientUser(email: string, label?: string | null) {
});
}
async function validateToken(token: string) {
const session = await db.reviewSession.findUnique({ where: { token } });
if (!session || !session.isActive) return null;
if (session.expiresAt && session.expiresAt < new Date()) return null;
return session;
}
export async function POST(
req: NextRequest,
{ params }: { params: Promise<{ token: string }> }
) {
const { token } = await params;
const session = await validateToken(token);
if (!session) {
const result = await validateReviewToken(token, req);
if (result.type === "requiresPassword") {
return NextResponse.json({ requiresPassword: true }, { status: 401 });
}
if (result.type === "invalid") {
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
}
const session = result.session;
const body = await req.json();
const { versionId, frameNumber, timestamp, text } = body;
+7 -9
View File
@@ -1,12 +1,6 @@
import { NextRequest, NextResponse } from "next/server";
import { db } from "@/lib/db";
async function validateToken(token: string) {
const session = await db.reviewSession.findUnique({ where: { token } });
if (!session || !session.isActive) return null;
if (session.expiresAt && session.expiresAt < new Date()) return null;
return session;
}
import { validateReviewToken } from "@/lib/review-auth";
/** GET /api/client/[token]/project — returns project + shots with tasks that have client-visible versions */
export async function GET(
@@ -14,10 +8,14 @@ export async function GET(
{ params }: { params: Promise<{ token: string }> }
) {
const { token } = await params;
const session = await validateToken(token);
if (!session) {
const result = await validateReviewToken(token, req);
if (result.type === "requiresPassword") {
return NextResponse.json({ requiresPassword: true }, { status: 401 });
}
if (result.type === "invalid") {
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
}
const session = result.session;
const project = await db.project.findUnique({
where: { id: session.projectId },
@@ -1,12 +1,6 @@
import { NextRequest, NextResponse } from "next/server";
import { db } from "@/lib/db";
async function validateToken(token: string) {
const session = await db.reviewSession.findUnique({ where: { token } });
if (!session || !session.isActive) return null;
if (session.expiresAt && session.expiresAt < new Date()) return null;
return session;
}
import { validateReviewToken } from "@/lib/review-auth";
/** GET /api/client/[token]/versions/[versionId] — returns version + comments for client portal */
export async function GET(
@@ -14,10 +8,14 @@ export async function GET(
{ params }: { params: Promise<{ token: string; versionId: string }> }
) {
const { token, versionId } = await params;
const session = await validateToken(token);
if (!session) {
const result = await validateReviewToken(token, req);
if (result.type === "requiresPassword") {
return NextResponse.json({ requiresPassword: true }, { status: 401 });
}
if (result.type === "invalid") {
return NextResponse.json({ error: "Invalid or expired review link" }, { status: 403 });
}
const session = result.session;
const version = await db.version.findUnique({
where: { id: versionId },
+8 -1
View File
@@ -2,6 +2,7 @@ import { NextRequest, NextResponse } from "next/server";
import { auth } from "@/auth";
import { db } from "@/lib/db";
import { addDays } from "date-fns";
import bcrypt from "bcryptjs";
export async function GET(req: NextRequest) {
const session = await auth();
@@ -32,7 +33,7 @@ export async function POST(req: NextRequest) {
}
const body = await req.json();
const { projectId, label, email, expiresInDays = 30 } = body;
const { projectId, label, email, expiresInDays = 30, password } = body;
if (!projectId) {
return NextResponse.json({ error: "projectId is required" }, { status: 400 });
@@ -43,11 +44,17 @@ export async function POST(req: NextRequest) {
return NextResponse.json({ error: "Project not found" }, { status: 404 });
}
const passwordHash =
password && typeof password === "string" && password.length > 0
? await bcrypt.hash(password, 12)
: null;
const reviewSession = await db.reviewSession.create({
data: {
projectId,
label: label || `Review — ${project.name}`,
email: email || null,
passwordHash,
expiresAt: addDays(new Date(), expiresInDays),
},
});
+39 -13
View File
@@ -15,6 +15,7 @@ import {
} from 'lucide-react';
import { cn } from '@/lib/utils';
import { Montserrat } from 'next/font/google';
import { ReviewPasswordGate } from '@/components/clients/ReviewPasswordGate';
const montserrat = Montserrat({
subsets: ['latin'],
@@ -121,6 +122,7 @@ export default function ClientPortalPage({
const [sessionLabel, setSessionLabel] = useState<string>('');
const [loading, setLoading] = useState(true);
const [error, setError] = useState<string | null>(null);
const [requiresPassword, setRequiresPassword] = useState(false);
const [collapsedEpisodes, setCollapsedEpisodes] = useState<Set<string>>(new Set());
const toggleEpisode = (ep: string) => {
@@ -134,22 +136,37 @@ export default function ClientPortalPage({
useEffect(() => {
params.then(({ token: t }) => {
setToken(t);
fetch(`/api/client/${t}/project`)
.then((r) => {
if (!r.ok) throw new Error('Invalid or expired review link');
return r.json();
})
.then((data) => {
setProject(data.project);
setShots(data.shots ?? []);
setAssetTasks(data.assetTasks ?? []);
setSessionLabel(data.sessionLabel ?? '');
})
.catch((e) => setError(e.message))
.finally(() => setLoading(false));
loadProject(t);
});
}, [params]);
const loadProject = (t: string) => {
setLoading(true);
setError(null);
fetch(`/api/client/${t}/project`)
.then(async (r) => {
if (r.status === 401) {
const data = await r.json().catch(() => ({}));
if (data.requiresPassword) {
setRequiresPassword(true);
return null;
}
}
if (!r.ok) throw new Error('Invalid or expired review link');
return r.json();
})
.then((data) => {
if (!data) return;
setProject(data.project);
setShots(data.shots ?? []);
setAssetTasks(data.assetTasks ?? []);
setSessionLabel(data.sessionLabel ?? '');
setRequiresPassword(false);
})
.catch((e) => setError(e.message))
.finally(() => setLoading(false));
};
if (loading) {
return (
<div className="min-h-screen bg-zinc-950 flex items-center justify-center">
@@ -158,6 +175,15 @@ export default function ClientPortalPage({
);
}
if (requiresPassword) {
return (
<ReviewPasswordGate
token={token}
onUnlocked={() => loadProject(token)}
/>
);
}
if (error || !project) {
return (
<div className="min-h-screen bg-zinc-950 flex flex-col items-center justify-center gap-4 text-center px-4">
+41 -13
View File
@@ -28,6 +28,7 @@ import {
Clock,
} from "lucide-react";
import { useReviewStore } from "@/hooks/use-review-player";
import { ReviewPasswordGate } from "@/components/clients/ReviewPasswordGate";
interface Comment {
id: string;
@@ -80,6 +81,8 @@ export default function ClientReviewPage({
const [comments, setComments] = useState<Comment[]>([]);
const [loading, setLoading] = useState(true);
const [error, setError] = useState<string | null>(null);
const [requiresPassword, setRequiresPassword] = useState(false);
const [versionId, setVersionId] = useState("");
const currentFrame = useReviewStore((s) => s.currentFrame);
@@ -101,23 +104,39 @@ export default function ClientReviewPage({
const { toast } = useToast();
useEffect(() => {
params.then(({ token: t, versionId }) => {
params.then(({ token: t, versionId: vId }) => {
setToken(t);
fetch(`/api/client/${t}/versions/${versionId}`)
.then((r) => {
if (!r.ok) throw new Error("Invalid or expired review link");
return r.json();
})
.then((data) => {
setVersion(data.version);
setComments(data.comments);
setCurrentApprovalStatus(data.version.approvalStatus);
})
.catch((e) => setError(e.message))
.finally(() => setLoading(false));
setVersionId(vId);
loadVersion(t, vId);
});
}, [params]);
const loadVersion = (t: string, vId: string) => {
setLoading(true);
setError(null);
fetch(`/api/client/${t}/versions/${vId}`)
.then(async (r) => {
if (r.status === 401) {
const data = await r.json().catch(() => ({}));
if (data.requiresPassword) {
setRequiresPassword(true);
return null;
}
}
if (!r.ok) throw new Error("Invalid or expired review link");
return r.json();
})
.then((data) => {
if (!data) return;
setVersion(data.version);
setComments(data.comments);
setCurrentApprovalStatus(data.version.approvalStatus);
setRequiresPassword(false);
})
.catch((e) => setError(e.message))
.finally(() => setLoading(false));
};
const refreshComments = useCallback(async (t: string, vId: string) => {
const res = await fetch(`/api/client/${t}/versions/${vId}`);
if (res.ok) {
@@ -201,6 +220,15 @@ export default function ClientReviewPage({
);
}
if (requiresPassword) {
return (
<ReviewPasswordGate
token={token}
onUnlocked={() => loadVersion(token, versionId)}
/>
);
}
if (error || !version) {
return (
<div className="min-h-screen bg-zinc-950 flex flex-col items-center justify-center gap-4 text-center px-4">