Per organized-ideas.md §8. Backend tables/RLS (diagrams, diagram_collaborators, diagram_snapshots) already existed from an earlier phase — this is the frontend for them, plus two small backend additions. Backend (supabase/migrations/20260913000000_diagram_sharing.sql): - find_user_id_by_username(text): lets any authenticated user resolve a username to an id for "share with @username" — unlike general profile browsing (blocked by profiles_select_self_or_super_admin), a username is meant to be a shareable handle, so this is deliberately not gated. - diagram_collaborator_usernames / diagram_snapshot_saved_by_usernames: same pattern as the admin-review-queue phase's submitter-username lookup — batched per diagram, gated to "can you see this diagram at all" (reusing diagrams_select's own helper functions). - prune_diagram_snapshots trigger: keeps the 50 most recent snapshots per diagram, enforced at write time rather than a scheduled job (diagram_ snapshots has no update/delete policy for regular users at all). - 14 new pgTAP tests (52/52 total). Frontend: - DiagramCollaboratorRepository/store + DiagramSharingModal: add/remove collaborators by username, per-person view/edit permission, owner-only controls. - DiagramSnapshotRepository/store + VersionHistoryModal (its own top-bar button, not nested under Share — moved there after review): periodic checkpoints (one per 5 min of active editing) written as a side effect of normal saves, list + restore. - Restore's duplicate-snapshot problem: repeatedly jumping between old versions without editing in between was writing a near-duplicate safety snapshot on every jump. Fixed by having projectStore track which snapshot the diagram was last restored from and its updatedAt at that moment (touch() always advances updatedAt on a genuine edit) — a restore skips the safety snapshot when nothing has changed since the last one, and the tracking clears on any real edit so in-progress work stays protected. - DiagramRepository gains getAccess() (owner id + your own permission for the open diagram) — surfaced in projectStore as `access`. - View-only enforcement: FlowCanvas disables drag/connect/drop (nodesDraggable/nodesConnectable + guarded handlers), DeviceInspector/ ConnectionInspector wrap their controls in a disabled <fieldset>, DevicePalette disables adding devices to the canvas, TopBar disables the rename field, and a ViewOnlyBanner makes the restriction visible instead of leaving a collaborator to discover it as controls that just don't work. Autosave itself also refuses to write for a view-only user, as a backstop behind the UI-level lockdown. Verified: tsc -b and oxlint clean; supabase db reset + 52/52 pgTAP tests pass; confirmed find_user_id_by_username works through the real REST API via a live curl call (signup, confirm, resolve). Manually tested two- account sharing (view vs. edit), restoring history, and the duplicate- snapshot fix.
44 lines
1.9 KiB
TypeScript
44 lines
1.9 KiB
TypeScript
import type { Project } from '../domain/types'
|
|
|
|
/** Lightweight metadata for listing diagrams without fetching each one's
|
|
* full (potentially large) data payload. */
|
|
export interface DiagramSummary {
|
|
id: string
|
|
name: string
|
|
updatedAt: string
|
|
}
|
|
|
|
/**
|
|
* Storage abstraction the rest of the app codes against. `LocalStorageDiagramRepository`
|
|
* and `SupabaseDiagramRepository` both implement it — the store/UI layers don't need to
|
|
* know or care which one is active.
|
|
*
|
|
* Named for the "Diagram" terminology decided in organized-ideas.md §8 (renamed from
|
|
* "Project"). This is a deliberately scoped rename: only the storage layer's naming
|
|
* changed here. The domain type (`Project`), the Zustand store (`useProjectStore`), and
|
|
* user-facing copy still say "Project" — that's a separate, larger mechanical rename
|
|
* across the whole app, tracked as its own task rather than bundled into this one.
|
|
*/
|
|
/** Your relationship to a diagram — who owns it, and what you personally
|
|
* can do with it (organized-ideas.md §8's per-collaborator view/edit
|
|
* permissions). Drives the frontend's own view-only lockdown, since RLS
|
|
* silently no-ops a blocked write rather than erroring — the UI needs to
|
|
* know *before* the user tries, not just fail quietly after. */
|
|
export interface DiagramAccess {
|
|
ownerId: string
|
|
myPermission: 'owner' | 'edit' | 'view'
|
|
}
|
|
|
|
export interface DiagramRepository {
|
|
/** Every diagram visible to the current user, most recently updated first. */
|
|
list(): Promise<DiagramSummary[]>
|
|
/** One diagram's full data by id, or null if it doesn't exist / isn't visible. */
|
|
loadById(id: string): Promise<Project | null>
|
|
/** Upsert a diagram, matched by the project's own id. */
|
|
save(project: Project): Promise<void>
|
|
/** Permanently delete one diagram by id. */
|
|
deleteById(id: string): Promise<void>
|
|
/** Who owns this diagram and what the current user can do with it. */
|
|
getAccess(id: string): Promise<DiagramAccess | null>
|
|
}
|