Commit graph

3 commits

Author SHA1 Message Date
Randall Stillwell
47da94fc95 Enrich invitation verify API and auto-verify invited signups
- /api/invitations/verify now returns inviterName and a structured
  failure reason ("not_found" | "expired" | "accepted") plus orgName,
  so the invite page can show contextual error messages and know who
  to blame for an expired link.
- /api/auth/register marks emailVerified immediately and skips the
  verification email when an inviteToken is present, since clicking
  the tokenized invite link already proves email ownership.

Made-with: Cursor
2026-04-19 10:45:41 -05:00
Randall Stillwell
2664f78b00 Migrate Echo Life Church data, add invite acceptance for existing users
Data migration:
- Associate all 978 cards with Echo Life Church organization
- Split name field into firstName/lastName on all cards
- Seed default Connect Card form template with 25 fields
- Migrate legacy column data into fieldData JSON
- Create Echo Life Church location with 3 Sunday services (8:00, 9:30, 11:00)
- Add all users as members of Echo Life Church
- Populate 819 people from card data with dedup matching

Invitation flow fix:
- Add POST /api/invitations/accept for logged-in users to join orgs
- Update /api/invitations/verify to return org name and existing account flag
- Rewrite invite page to handle 3 scenarios:
  1. Logged in + email matches: one-click "Accept Invitation" button
  2. Logged in + email mismatch: prompt to switch accounts
  3. Not logged in + has account: "Sign In to Accept" button
  4. Not logged in + new user: "Accept & Create Account" (existing flow)

Made-with: Cursor
2026-04-17 08:15:31 -05:00
Randall Stillwell
d3e7374439 Add SaaS foundation: Auth.js, dashboard shell, org model, auto-assignment
Major architectural upgrade preparing Echo OCR for self-hosted SaaS deployment:

- Auth: Built-in Auth.js v5 with credentials + Authentik OIDC SSO, JWT sessions,
  middleware route protection, login/signup/setup pages, registration API
- UI: Dashboard layout with collapsible sidebar nav, AppShell wrapper, route
  groups for (dashboard) and (auth), new pages for events/people/reports
- Schema: Auth.js tables (Account, Session, VerificationToken), Organization,
  OrgMember, Location, CollectionDay, Invitation, SystemConfig, ApiKey models;
  proper User relations to ResponseCard/ActivityLog/Notification
- Permissions: Role hierarchy (owner/admin/editor/reviewer/viewer) with
  action-based permission map and requirePermission/requireAuth helpers
- Onboarding: Multi-step setup wizard for first-user bootstrap (account, org,
  location) with SystemConfig tracking
- Events: CollectionDay model with rrule support for recurring church services
- Auto-assign: Event-aware card assignment engine replacing getPreviousSunday()
- Migration: seed-migration.ts script for upgrading existing deployments

Made-with: Cursor
2026-04-14 23:59:38 -05:00