Normalizes manufacturer as a shared catalog entity (like device categories)
instead of free text on each device, giving the admin duplicate-detection
nudge a reliable signal. Adds full CRUD (including Admin direct-publish,
bypassing the submission queue) for categories, manufacturers, port types,
and cable types, plus a Categories & Manufacturers library modal and a
browse-by-manufacturer/search view in the device palette. Adds
Port.builtInCable so a captive/permanently-attached cable (a keyboard's USB
lead, a budget AVR's power cord) can be flagged and excluded from the BOM.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017DUU6CnxECCDeqDNYJgr5x
Per organized-ideas.md §8: the storage layer (DiagramRepository etc.) was
already renamed in an earlier phase; this finishes it everywhere else.
- domain/types.ts: Project -> Diagram. domain/project.ts -> domain/diagram.ts
(createEmptyProject -> createEmptyDiagram, default name "Untitled Diagram").
- domain/compatibility.ts, domain/bom.ts: Project param/type -> Diagram.
- data/exportImport.ts: ProjectImportError -> DiagramImportError,
projectToJson/downloadProjectFile/readProjectFile/normalizeProject -> their
Diagram equivalents.
- state/projectStore.ts -> state/diagramStore.ts: useProjectStore ->
useDiagramStore, the `project` field -> `diagram`, newProject/renameProject/
importProject/applyRestoredProject -> *Diagram, restoredProjectUpdatedAt ->
restoredDiagramUpdatedAt.
- Every component updated to match, compiler-guided (tsc -b enumerated each
remaining call site after the core rename, the same approach used for the
earlier catalog-parameter refactor).
- README updated for the terminology, and to match the repository class
names (which had already been renamed but the README hadn't caught up).
No backend/schema changes: the JSON shape stored in diagrams.data never
changed, only TypeScript-side identifiers, so existing diagrams are
unaffected. One SQL comment fixed for accuracy (no migration needed).
Verified: tsc -b and oxlint clean; grepped src/ for any remaining
Project/project reference (none) after the sweep.
Per organized-ideas.md §8. Backend tables/RLS (diagrams, diagram_collaborators,
diagram_snapshots) already existed from an earlier phase — this is the
frontend for them, plus two small backend additions.
Backend (supabase/migrations/20260913000000_diagram_sharing.sql):
- find_user_id_by_username(text): lets any authenticated user resolve a
username to an id for "share with @username" — unlike general profile
browsing (blocked by profiles_select_self_or_super_admin), a username is
meant to be a shareable handle, so this is deliberately not gated.
- diagram_collaborator_usernames / diagram_snapshot_saved_by_usernames:
same pattern as the admin-review-queue phase's submitter-username
lookup — batched per diagram, gated to "can you see this diagram at all"
(reusing diagrams_select's own helper functions).
- prune_diagram_snapshots trigger: keeps the 50 most recent snapshots per
diagram, enforced at write time rather than a scheduled job (diagram_
snapshots has no update/delete policy for regular users at all).
- 14 new pgTAP tests (52/52 total).
Frontend:
- DiagramCollaboratorRepository/store + DiagramSharingModal: add/remove
collaborators by username, per-person view/edit permission, owner-only
controls.
- DiagramSnapshotRepository/store + VersionHistoryModal (its own top-bar
button, not nested under Share — moved there after review): periodic
checkpoints (one per 5 min of active editing) written as a side effect
of normal saves, list + restore.
- Restore's duplicate-snapshot problem: repeatedly jumping between old
versions without editing in between was writing a near-duplicate safety
snapshot on every jump. Fixed by having projectStore track which
snapshot the diagram was last restored from and its updatedAt at that
moment (touch() always advances updatedAt on a genuine edit) — a restore
skips the safety snapshot when nothing has changed since the last one,
and the tracking clears on any real edit so in-progress work stays
protected.
- DiagramRepository gains getAccess() (owner id + your own permission for
the open diagram) — surfaced in projectStore as `access`.
- View-only enforcement: FlowCanvas disables drag/connect/drop
(nodesDraggable/nodesConnectable + guarded handlers), DeviceInspector/
ConnectionInspector wrap their controls in a disabled <fieldset>,
DevicePalette disables adding devices to the canvas, TopBar disables the
rename field, and a ViewOnlyBanner makes the restriction visible instead
of leaving a collaborator to discover it as controls that just don't
work. Autosave itself also refuses to write for a view-only user, as a
backstop behind the UI-level lockdown.
Verified: tsc -b and oxlint clean; supabase db reset + 52/52 pgTAP tests
pass; confirmed find_user_id_by_username works through the real REST API
via a live curl call (signup, confirm, resolve). Manually tested two-
account sharing (view vs. edit), restoring history, and the duplicate-
snapshot fix.
Per organized-ideas.md §6: role assignment, account ban/unban/delete, and
direct Admin/Super-Admin CRUD of public catalog entries outside the
submission workflow.
Backend:
- list_users_for_admin(): Super-Admin-gated SECURITY DEFINER function
joining profiles + auth.users (username, email, role, banned_until) —
auth.users isn't exposed through PostgREST, so this is the only way to
list accounts at all.
- New Edge Function admin-user-action (ban/unban/delete), using
@supabase/server's `auth: 'user'` mode to verify the caller's JWT, then
Supabase Auth's Admin API for the actual mutation. This is deliberately
an Edge Function rather than a Postgres function like everything else in
this codebase: touching auth.users needs the Admin API, the stable
documented interface, not a direct write to a schema Supabase manages
internally. Self-action guard; verify_jwt = true at the gateway on top of
the function's own JWT verification.
- 5 new pgTAP tests (43/43 total) for list_users_for_admin (Super-Admin-only,
even regular Admins get 42501).
- CatalogRepository gains admin* methods (direct edit of a public port/cable/
device entry, plus adminUnpublish which flips is_public rather than
deleting) — the update methods were already ownership-agnostic (RLS's
is_admin() clause is what actually permits it), so these are thin aliases,
not duplicated logic.
Frontend:
- authStore/AdminUserRepository: minimal role plumbing, shared UserRole type.
- adminUserStore + AdminUsersModal: list/role-dropdown/ban/unban/delete,
gated to Super Admin only via a new "Manage Users" TopBar button.
- PortTypeManager/CableTypeManager/DevicePalette: built-in entries now show
direct "Edit"/"Unpublish" for Admins (regular Admin included, per §6's
capability table — not Super-Admin-exclusive) instead of "Suggest edit";
unpublish reuses the review-queue's impact-check RPC before confirming.
- DeviceTemplateEditor gains an `adminMode` save path alongside its existing
submissionMode/resubmitId ones.
Verified: tsc -b and oxlint clean; supabase db reset + 43/43 pgTAP tests
pass; confirmed both new privileged endpoints (the SQL function and the
Edge Function) actually work through the real REST API via live curl
calls — signup, email confirm, role promotion, ban/unban/delete round
trips, self-action guard, non-super-admin rejection, and verify_jwt=true
compatibility all exercised directly, not just asserted.
Lets users submit a private catalog entry (port type, cable type, device
template) for promotion to the public catalog, or suggest an edit to an
existing public entry — both go into the catalog_submissions review queue
per organized-ideas.md §3. No Admin review UI yet (next sub-phase); this
covers the submitter's side only.
- data/SubmissionRepository + SupabaseSubmissionRepository: submit,
resubmit, withdraw, list-mine, backed by the existing catalog_submissions
RLS policies (no schema changes needed).
- data/catalogRowMapping.ts: shared domain<->row mappers, in both
directions, so a submission's proposed_data is always shaped like the
underlying table row (what an eventual admin-approval would write
directly) and can be turned back into form-editable fields for revision.
- state/submissionStore.ts: mySubmissions + submit/resubmit/withdraw, plus
syncProposedData — called from catalogStore's updateCustom* actions so a
submission about your own still-private entry never goes stale relative
to it (edits from the library and from My Submissions are the same
action and always agree).
- UI: "Submit"/"Suggest edit" wired into PortTypeManager, CableTypeManager,
DevicePalette/DeviceTemplateEditor; new MySubmissionsModal (opened from
TopBar, with a pending-count badge) shows status, rejection reasons, and
lets you edit/resubmit or withdraw.
- Deliberately deferred: device_category submissions (no listing UI to
hang a button on yet) and the normalized manufacturer catalog.
Verified: tsc -b and oxlint clean; supabase db reset + 23/23 pgTAP RLS
tests still pass (no schema changes this round); manually tested submit,
suggest-edit, edit-from-either-side sync, reject/resubmit, and withdraw.
Moves port/cable/category/device-template data from per-diagram embedded
storage to the global public/private catalog backed by Supabase, per
organized-ideas.md's "live reference, not snapshot" decision.
- domain/types.ts, project.ts, compatibility.ts, bom.ts: lookup functions
now take an explicit Catalog parameter instead of deriving data from
Project — Project is reduced to just diagram-scoped fields.
- New CatalogRepository/SupabaseCatalogRepository (mirrors the
DiagramRepository pattern) and catalogStore.ts, replacing the
catalog-related actions that used to live in projectStore.
- device_templates gets a plain-text manufacturer column for now (the
normalized manufacturer catalog from organized-ideas.md §3 is its own
future pass, not blocking this one).
- domain/library.ts is no longer imported by the app — it's now only the
source scripts/generate-seed.mjs reads to produce supabase/seed.sql.
- Swept every UI call site via tsc -b until clean; oxlint clean; 23/23
pgTAP RLS tests still passing after a `supabase db reset`.