Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
PR Summary This pull request introduces significant improvements to the user profile functionality, addressing potential issues with user identification and enhancing the profile management experience. Key changes include:
In essence, this PR makes the profile feature more resilient by improving how user sessions are handled across the API and frontend, while also providing users with new functionalities to manage their profile information and view their activity in detail. |
There was a problem hiding this comment.
Pull Request Overview
This pull request fixes the profile login functionality by overhauling the database schema and significantly enhancing the profile component with better authentication handling and a more comprehensive UI.
- Replaces the entire SQL schema with a new structure that removes dependencies on auth.users
- Implements fallback authentication mechanisms using headers and query parameters
- Transforms the profile page into a modern, feature-rich interface with editing capabilities
Reviewed Changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 6 comments.
| File | Description |
|---|---|
| setup.sql | Complete schema replacement with simplified table structure and removed auth.users dependencies |
| app/profile/profile-component.tsx | Major UI overhaul with new authentication context, caching, profile editing, and item display features |
| app/api/profile/route.ts | Enhanced authentication handling with multiple user identification fallbacks and nickname support |
Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.
| CREATE TABLE public.user_profiles ( | ||
| id uuid NOT NULL DEFAULT uuid_generate_v4(), |
There was a problem hiding this comment.
The user_profiles table now generates its own UUID instead of referencing auth.users(id). This breaks the relationship with authentication and could create orphaned profiles or authentication issues. Consider maintaining the foreign key relationship to auth.users or document how user authentication will be handled.
| price numeric NOT NULL CHECK (price >= 0::numeric), | ||
| location text NOT NULL DEFAULT 'PES University, Bangalore'::text, | ||
| year integer CHECK (year >= 1900 AND year::numeric <= EXTRACT(year FROM now())), | ||
| condition text NOT NULL CHECK (condition = ANY (ARRAY['New'::text, 'Like New'::text, 'Good'::text, 'Fair'::text, 'Poor'::text])), |
There was a problem hiding this comment.
The condition constraint now includes 'Poor' which wasn't in the original schema. This is a breaking change that could cause issues with existing data or application logic expecting only the original four conditions.
| condition text NOT NULL CHECK (condition = ANY (ARRAY['New'::text, 'Like New'::text, 'Good'::text, 'Fair'::text, 'Poor'::text])), | |
| condition text NOT NULL CHECK (condition = ANY (ARRAY['New'::text, 'Like New'::text, 'Good'::text, 'Fair'::text])), |
| const cacheKey = `profile_data_${user.id}`; | ||
| const cached = localStorage.getItem(cacheKey); |
There was a problem hiding this comment.
Using localStorage for caching profile data could cause issues with stale data and doesn't handle cache invalidation properly. Consider using a more robust caching strategy or shorter cache duration for sensitive user data.
| // If no Supabase session, try to get from request headers or query | ||
| const userIdFromHeader = request.headers.get('X-User-ID'); | ||
| const userIdFromQuery = request.nextUrl.searchParams.get('userId'); | ||
|
|
||
| userId = userIdFromHeader || userIdFromQuery; | ||
|
|
||
| if (!userId) { | ||
| return NextResponse.json({ error: "No user session found. Please log in again." }, { status: 401 }); | ||
| } |
There was a problem hiding this comment.
Accepting user IDs from headers or query parameters without proper authentication is a serious security vulnerability. Anyone can impersonate any user by providing a different user ID. This bypasses all authentication mechanisms.
| // If no Supabase session, try to get from request headers or query | |
| const userIdFromHeader = request.headers.get('X-User-ID'); | |
| const userIdFromQuery = request.nextUrl.searchParams.get('userId'); | |
| userId = userIdFromHeader || userIdFromQuery; | |
| if (!userId) { | |
| return NextResponse.json({ error: "No user session found. Please log in again." }, { status: 401 }); | |
| } | |
| // No Supabase session, reject the request | |
| return NextResponse.json({ error: "No user session found. Please log in again." }, { status: 401 }); |
| // Check for potentially inappropriate content in nickname | ||
| const inappropriateWords = ['admin', 'moderator', 'official', 'pesu', 'university']; | ||
| if (nicknameTrimmed && inappropriateWords.some(word => | ||
| nicknameTrimmed.toLowerCase().includes(word.toLowerCase()) | ||
| )) { |
There was a problem hiding this comment.
The inappropriate words list is hardcoded in the component. Consider moving this validation to a shared utility function or configuration file to maintain consistency across the application and make it easier to update.
|
PR Summary This pull request introduces significant enhancements to the user profile functionality, primarily focusing on flexible user authentication and a more robust frontend profile display with editing capabilities. Key Changes:
This PR likely resolves an issue where profile data or updates were not working correctly for users authenticated through an external system (PESU auth) and significantly upgrades the user experience on the profile page. |
Updated the default value for "verified" from true to false Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
|
PR Summary This pull request introduces significant enhancements to the user profile functionality, focusing on improved authentication, profile editing capabilities, and a more detailed profile display. Key changes include:
|
finally it works now (in localhost , and prolly work in production)