Skip to content

Fix: Fix profile-login - #36

Merged
SavvyHex merged 3 commits into
mainfrom
fix-login
Sep 4, 2025
Merged

SavvyHex merged 3 commits into
mainfrom
fix-login

Conversation

@Priyans00

Copy link
Copy Markdown
Owner

finally it works now (in localhost , and prolly work in production)

@vercel

vercel Bot commented Sep 4, 2025 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
pesxchange Ready Ready Preview Comment Sep 4, 2025 11:59am

@Priyans00
Priyans00 requested a review from Copilot September 4, 2025 09:21
@github-actions

github-actions Bot commented Sep 4, 2025

Copy link
Copy Markdown

PR Summary

This pull request introduces significant improvements to the user profile functionality, addressing potential issues with user identification and enhancing the profile management experience.

Key changes include:

  • API Route (app/api/profile/route.ts) Enhancements:

    • Flexible User ID Retrieval: The API now robustly retrieves the user's ID by first attempting to get it from the Supabase authentication session. If no session is found, it falls back to checking X-User-ID headers or userId query parameters, making the API more adaptable to various authentication contexts.
    • Profile Update (PUT): The profile update endpoint now supports updating a new nickname field.
    • Improved Error Handling: More descriptive error messages are returned for unauthorized access or missing profiles.
  • Frontend Profile Component (app/profile/profile-component.tsx) Revamp:

    • Refactored Authentication: The component now leverages a shared useAuth() context for user data, improving consistency and maintainability.
    • New "Edit Profile" Feature: A new dialog-based interface allows users to edit their bio, phone, and a newly introduced nickname.
    • Enhanced Profile Display: The profile page now presents a much richer view, including:
      • Detailed user information (name, email, nickname, phone, bio, location, academic details).
      • User statistics (total items sold/bought, total views, total likes, average rating).
      • A list of items the user has listed, complete with images, prices, conditions, and engagement metrics.
    • Improved User Experience: Incorporates loading skeletons, clearer error messages, and better UI components for a smoother experience.
    • Currency Formatting: Uses a memoized Intl.NumberFormat for consistent currency display.

In essence, this PR makes the profile feature more resilient by improving how user sessions are handled across the API and frontend, while also providing users with new functionalities to manage their profile information and view their activity in detail.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This pull request fixes the profile login functionality by overhauling the database schema and significantly enhancing the profile component with better authentication handling and a more comprehensive UI.

  • Replaces the entire SQL schema with a new structure that removes dependencies on auth.users
  • Implements fallback authentication mechanisms using headers and query parameters
  • Transforms the profile page into a modern, feature-rich interface with editing capabilities

Reviewed Changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 6 comments.

File Description
setup.sql Complete schema replacement with simplified table structure and removed auth.users dependencies
app/profile/profile-component.tsx Major UI overhaul with new authentication context, caching, profile editing, and item display features
app/api/profile/route.ts Enhanced authentication handling with multiple user identification fallbacks and nickname support

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

Comment thread setup.sql
Comment on lines +110 to +111
CREATE TABLE public.user_profiles (
id uuid NOT NULL DEFAULT uuid_generate_v4(),

Copilot AI Sep 4, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The user_profiles table now generates its own UUID instead of referencing auth.users(id). This breaks the relationship with authentication and could create orphaned profiles or authentication issues. Consider maintaining the foreign key relationship to auth.users or document how user authentication will be handled.

Copilot uses AI. Check for mistakes.
Comment thread setup.sql Outdated
Comment thread setup.sql
price numeric NOT NULL CHECK (price >= 0::numeric),
location text NOT NULL DEFAULT 'PES University, Bangalore'::text,
year integer CHECK (year >= 1900 AND year::numeric <= EXTRACT(year FROM now())),
condition text NOT NULL CHECK (condition = ANY (ARRAY['New'::text, 'Like New'::text, 'Good'::text, 'Fair'::text, 'Poor'::text])),

Copilot AI Sep 4, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The condition constraint now includes 'Poor' which wasn't in the original schema. This is a breaking change that could cause issues with existing data or application logic expecting only the original four conditions.

Suggested change
condition text NOT NULL CHECK (condition = ANY (ARRAY['New'::text, 'Like New'::text, 'Good'::text, 'Fair'::text, 'Poor'::text])),
condition text NOT NULL CHECK (condition = ANY (ARRAY['New'::text, 'Like New'::text, 'Good'::text, 'Fair'::text])),

Copilot uses AI. Check for mistakes.
Comment on lines +110 to +111
const cacheKey = `profile_data_${user.id}`;
const cached = localStorage.getItem(cacheKey);

Copilot AI Sep 4, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Using localStorage for caching profile data could cause issues with stale data and doesn't handle cache invalidation properly. Consider using a more robust caching strategy or shorter cache duration for sensitive user data.

Copilot uses AI. Check for mistakes.
Comment thread app/api/profile/route.ts Outdated
Comment on lines +18 to +26
// If no Supabase session, try to get from request headers or query
const userIdFromHeader = request.headers.get('X-User-ID');
const userIdFromQuery = request.nextUrl.searchParams.get('userId');

userId = userIdFromHeader || userIdFromQuery;

if (!userId) {
return NextResponse.json({ error: "No user session found. Please log in again." }, { status: 401 });
}

Copilot AI Sep 4, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Accepting user IDs from headers or query parameters without proper authentication is a serious security vulnerability. Anyone can impersonate any user by providing a different user ID. This bypasses all authentication mechanisms.

Suggested change
// If no Supabase session, try to get from request headers or query
const userIdFromHeader = request.headers.get('X-User-ID');
const userIdFromQuery = request.nextUrl.searchParams.get('userId');
userId = userIdFromHeader || userIdFromQuery;
if (!userId) {
return NextResponse.json({ error: "No user session found. Please log in again." }, { status: 401 });
}
// No Supabase session, reject the request
return NextResponse.json({ error: "No user session found. Please log in again." }, { status: 401 });

Copilot uses AI. Check for mistakes.
Comment thread app/profile/profile-component.tsx Outdated
Comment on lines +189 to +193
// Check for potentially inappropriate content in nickname
const inappropriateWords = ['admin', 'moderator', 'official', 'pesu', 'university'];
if (nicknameTrimmed && inappropriateWords.some(word =>
nicknameTrimmed.toLowerCase().includes(word.toLowerCase())
)) {

Copilot AI Sep 4, 2025

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The inappropriate words list is hardcoded in the component. Consider moving this validation to a shared utility function or configuration file to maintain consistency across the application and make it easier to update.

Copilot uses AI. Check for mistakes.
@github-actions

github-actions Bot commented Sep 4, 2025

Copy link
Copy Markdown

PR Summary

This pull request introduces significant enhancements to the user profile functionality, primarily focusing on flexible user authentication and a more robust frontend profile display with editing capabilities.

Key Changes:

  • Flexible User Authentication in API:
    • The /api/profile GET and PUT endpoints now support two methods for identifying the user:
      1. Supabase Auth: Prioritizes fetching the user via supabase.auth.getUser() for standard sessions.
      2. External Auth (e.g., PESU Auth): If Supabase auth fails, it attempts to read a user ID from the X-User-ID request header. This ID is then validated against the user_profiles table to ensure it's a legitimate user.
    • This change ensures the profile API works correctly with both internal and external authentication flows.
  • Enhanced Profile Management API:
    • The PUT endpoint for updating user profiles now accepts and processes a nickname field, in addition to existing fields like name, bio, phone, year_of_study, branch, and location.
  • Comprehensive Frontend Profile Page:
    • The profile-component.tsx has been completely refactored and expanded to display a rich set of user data, including:
      • Profile details: Name, email, SRN, nickname, bio, phone, location, academic details (branch, year of study), join date, rating, and verification status.
      • User's listed items: A detailed list of items sold by the user, including title, price, condition, category, images, views, likes, and availability.
      • Aggregated statistics: Total items sold, total items bought, total views, total likes, and average rating.
    • Profile Editing Feature: A new dialog-based interface allows users to edit their bio, phone, nickname, location, year_of_study, and branch directly from the profile page. Client-side validation is included for the nickname.
    • Improved UI/UX with shadcn/ui components (Cards, Buttons, Inputs, Dialogs), detailed loading skeletons, and various icons.

This PR likely resolves an issue where profile data or updates were not working correctly for users authenticated through an external system (PESU auth) and significantly upgrades the user experience on the profile page.

Updated the default value for "verified" from true to false

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Sep 4, 2025

Copy link
Copy Markdown

PR Summary

This pull request introduces significant enhancements to the user profile functionality, focusing on improved authentication, profile editing capabilities, and a more detailed profile display.

Key changes include:

  • Dual Authentication Strategy:
    • The /api/profile GET and PUT endpoints now support a flexible authentication mechanism.
    • It first attempts to authenticate using the standard Supabase session.
    • If a Supabase session is not found, it falls back to checking for a custom X-User-ID header (likely for PESU authentication). Crucially, this header-provided user ID is validated against the user_profiles table in the database to prevent unauthorized access with arbitrary IDs.
  • Comprehensive Profile Editing:
    • The frontend ProfileComponent has been heavily refactored to include a user-friendly interface for editing profile details.
    • Users can now update their bio, phone, nickname, location, year_of_study, and branch via a dialog.
    • The /api/profile PUT endpoint is updated to accept and process these new profile fields, including nickname.
  • Enriched Profile Display:
    • The profile page now displays more detailed user information, including a new nickname field, year_of_study, and branch (conditionally shown for PESU users).
    • It also showcases overall user statistics such as "Total Profile Views" and "Total Profile Likes."
  • User's Item Listings: The profile component now fetches and displays a list of the user's active listings, showing each item's title, price, condition, category, views, and likes.
  • Improved Error Handling: Enhanced error messages and status codes on both the API and frontend for unauthorized access (e.g., redirecting to login), profile not found, and other issues.
  • Frontend Refinements: Utilizes useAuth context for consistent authentication, utility functions for display names and nickname validation, and modern UI components for a better user experience.

@SavvyHex
SavvyHex merged commit 1090b6a into main Sep 4, 2025
3 checks passed
@SavvyHex
SavvyHex deleted the fix-login branch September 4, 2025 12:00

This branch was successfully deployed

1 active deployment
Preview — e6c31864 Deployed Sep 4, 2025 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants