Skip to content

Completed /Pulse/Phase 1.2 - #67

Closed
PacmanError404 wants to merge 2 commits into
devfrom
fix/authorisation-and-host-email-linking
Closed

PacmanError404 wants to merge 2 commits into
devfrom
fix/authorisation-and-host-email-linking

Conversation

@PacmanError404

Copy link
Copy Markdown

Phase 1 TEST walkthrough.md

  • Error handling follows the shared result.ts convention.
  • Session lookup re‑uses the existing BetterAuth‑based session mechanism (requirePulseSession → auth.api.getSession).
  • Authorization helpers are colocated in src/lib/api/pulse.ts.
  • Admin guard is strict and based solely on isAdmin(user.access).
  • Host‑assignment linking is normalised, idempotent, and invoked both from the auth‑hook and as a fallback in requirePulseHost.
  • Security checks (identity validation, session verification) are left untouched.
  • Email sourcing is strictly from the authenticated User record; client‑provided email is never trusted.
  • No modifications to CCW‑specific roles/access fields occur anywhere.

@PacmanError404
PacmanError404 deleted the fix/authorisation-and-host-email-linking branch October 2, 2026 11:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant