- Migration: profiles.username is now nullable -- Google's OAuth
redirect can't collect a username up front the way the email/password
signup form does, so a first-time Google sign-in's profile is created
with no username.
- supabase/config.toml: [auth.external.google] enabled, credentials via
env() substitution (SUPABASE_AUTH_EXTERNAL_GOOGLE_CLIENT_ID/_SECRET
in .env.local, which the CLI auto-loads). skip_nonce_check is on,
which Supabase's own docs call out as required for local sign-in.
- LoginScreen: "Continue with Google" alongside the existing
email/password form.
- CompleteProfileScreen: one-time gate for a signed-in user with no
username yet (i.e. first Google sign-in) -- same hard-gate spirit as
email verification, nothing else is usable until a username is set.
- App.tsx now checks profiles.username after establishing a session and
routes to CompleteProfileScreen before AppShell when it's missing.
RLS test suite re-run clean (23/23) after the schema change.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DUU6CnxECCDeqDNYJgr5x
- supabase/config.toml: local dev stack config, pinned to the app's
fixed dev server port, email confirmation required (hard
verification gate per organized-ideas.md).
- Initial schema migration: profiles/roles, the public/private
catalog tables (manufacturers, device categories, port types, cable
types, device templates + ports) with the shared is_public/owner_id
RLS pattern, a generalized catalog_submissions review-queue table,
and diagrams as JSONB documents (+ collaborators, snapshots) rather
than fully normalized -- see the migration's header comment for why.
- pgTAP RLS test suite (23 assertions) covering catalog visibility and
promotion-in-place, diagram owner/collaborator/admin/super-admin
visibility and edit permissions, submission visibility, and role
escalation. Caught and fixed a real infinite-recursion bug between
the diagrams and diagram_collaborators policies before this ever
touched real data.
- vite.config.ts: pinned dev server port so Supabase Auth's redirect
allow-list doesn't silently break if Vite floats to another port.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DUU6CnxECCDeqDNYJgr5x