Add diagram sharing/collaborators, version history, and view-only lockdown

Per organized-ideas.md §8. Backend tables/RLS (diagrams, diagram_collaborators,
diagram_snapshots) already existed from an earlier phase — this is the
frontend for them, plus two small backend additions.

Backend (supabase/migrations/20260913000000_diagram_sharing.sql):
- find_user_id_by_username(text): lets any authenticated user resolve a
  username to an id for "share with @username" — unlike general profile
  browsing (blocked by profiles_select_self_or_super_admin), a username is
  meant to be a shareable handle, so this is deliberately not gated.
- diagram_collaborator_usernames / diagram_snapshot_saved_by_usernames:
  same pattern as the admin-review-queue phase's submitter-username
  lookup — batched per diagram, gated to "can you see this diagram at all"
  (reusing diagrams_select's own helper functions).
- prune_diagram_snapshots trigger: keeps the 50 most recent snapshots per
  diagram, enforced at write time rather than a scheduled job (diagram_
  snapshots has no update/delete policy for regular users at all).
- 14 new pgTAP tests (52/52 total).

Frontend:
- DiagramCollaboratorRepository/store + DiagramSharingModal: add/remove
  collaborators by username, per-person view/edit permission, owner-only
  controls.
- DiagramSnapshotRepository/store + VersionHistoryModal (its own top-bar
  button, not nested under Share — moved there after review): periodic
  checkpoints (one per 5 min of active editing) written as a side effect
  of normal saves, list + restore.
- Restore's duplicate-snapshot problem: repeatedly jumping between old
  versions without editing in between was writing a near-duplicate safety
  snapshot on every jump. Fixed by having projectStore track which
  snapshot the diagram was last restored from and its updatedAt at that
  moment (touch() always advances updatedAt on a genuine edit) — a restore
  skips the safety snapshot when nothing has changed since the last one,
  and the tracking clears on any real edit so in-progress work stays
  protected.
- DiagramRepository gains getAccess() (owner id + your own permission for
  the open diagram) — surfaced in projectStore as `access`.
- View-only enforcement: FlowCanvas disables drag/connect/drop
  (nodesDraggable/nodesConnectable + guarded handlers), DeviceInspector/
  ConnectionInspector wrap their controls in a disabled <fieldset>,
  DevicePalette disables adding devices to the canvas, TopBar disables the
  rename field, and a ViewOnlyBanner makes the restriction visible instead
  of leaving a collaborator to discover it as controls that just don't
  work. Autosave itself also refuses to write for a view-only user, as a
  backstop behind the UI-level lockdown.

Verified: tsc -b and oxlint clean; supabase db reset + 52/52 pgTAP tests
pass; confirmed find_user_id_by_username works through the real REST API
via a live curl call (signup, confirm, resolve). Manually tested two-
account sharing (view vs. edit), restoring history, and the duplicate-
snapshot fix.
This commit is contained in:
2026-09-11 11:28:58 -05:00
parent 4c45b5afa7
commit dea26f7ee8
21 changed files with 939 additions and 38 deletions
+81 -1
View File
@@ -25,7 +25,7 @@ begin;
create extension if not exists pgtap with schema extensions;
select plan(43);
select plan(52);
-- ----------------------------------------------------------------------
-- Fixtures (as postgres — RLS does not apply)
@@ -177,8 +177,20 @@ select lives_ok(
'bob (edit collaborator) can now update alice''s diagram'
);
select is(
(select username from public.diagram_collaborator_usernames('b0000000-0000-0000-0000-000000000001') where user_id = '22222222-2222-2222-2222-222222222222'),
'bob',
'bob (a collaborator) can resolve the diagram''s collaborator usernames'
);
select set_config('request.jwt.claim.sub', '33333333-3333-3333-3333-333333333333', true);
select throws_ok(
$$ select * from public.diagram_collaborator_usernames('b0000000-0000-0000-0000-000000000001') $$,
'42501'::char(5), null,
'carol (no access to the diagram at all) cannot resolve its collaborator usernames'
);
select is(
(select count(*)::int from public.diagrams where id = 'b0000000-0000-0000-0000-000000000001'),
0,
@@ -193,6 +205,74 @@ select is(
'dave (super admin) can see any diagram'
);
-- ----------------------------------------------------------------------
-- Username lookup (organized-ideas.md §8's "share with @username" — any
-- authenticated user can resolve one, unlike general profile browsing).
-- ----------------------------------------------------------------------
select is(
(select public.find_user_id_by_username('alice')),
'11111111-1111-1111-1111-111111111111'::uuid,
'any authenticated user can resolve a username to an id'
);
select is(
(select public.find_user_id_by_username('no-such-user')),
null,
'resolving an unknown username returns null, not an error'
);
-- ----------------------------------------------------------------------
-- Snapshot retention (organized-ideas.md §8: keep the 50 most recent per
-- diagram). Explicit, staggered created_at values below because pgTAP runs
-- inside one transaction — every row would otherwise share the exact same
-- now(), making "most recent" ambiguous for this test specifically (a
-- real editing session naturally spreads saves out over wall-clock time).
-- ----------------------------------------------------------------------
select set_config('request.jwt.claim.sub', '11111111-1111-1111-1111-111111111111', true);
insert into public.diagram_snapshots (diagram_id, data, saved_by, created_at)
select 'b0000000-0000-0000-0000-000000000001', jsonb_build_object('seq', g), '11111111-1111-1111-1111-111111111111',
now() + (g || ' seconds')::interval
from generate_series(1, 51) g;
select is(
(select count(*)::int from public.diagram_snapshots where diagram_id = 'b0000000-0000-0000-0000-000000000001'),
50,
'only the 50 most recent snapshots are kept'
);
select is(
(select count(*)::int from public.diagram_snapshots
where diagram_id = 'b0000000-0000-0000-0000-000000000001' and data ->> 'seq' = '1'),
0,
'the oldest snapshot was the one pruned'
);
select is(
(select count(*)::int from public.diagram_snapshots
where diagram_id = 'b0000000-0000-0000-0000-000000000001' and data ->> 'seq' = '51'),
1,
'the newest snapshot survives'
);
select is(
(select username from public.diagram_snapshot_saved_by_usernames('b0000000-0000-0000-0000-000000000001') where user_id = '11111111-1111-1111-1111-111111111111'),
'alice',
'alice (owner) can resolve who saved this diagram''s snapshots'
);
select set_config('request.jwt.claim.sub', '33333333-3333-3333-3333-333333333333', true);
select throws_ok(
$$ select * from public.diagram_snapshot_saved_by_usernames('b0000000-0000-0000-0000-000000000001') $$,
'42501'::char(5), null,
'carol (no access to the diagram at all) cannot resolve who saved its snapshots'
);
select set_config('request.jwt.claim.sub', '11111111-1111-1111-1111-111111111111', true);
-- ----------------------------------------------------------------------
-- Catalog submissions
-- ----------------------------------------------------------------------