Repository navigation
Integrate #36, #38, #37 with resolved auth conflicts - #40
Conversation
Co-authored-by: benhalverson <7907232+benhalverson@users.noreply.github.com>
…Context Co-authored-by: benhalverson <7907232+benhalverson@users.noreply.github.com>
Co-authored-by: benhalverson <7907232+benhalverson@users.noreply.github.com>
Co-authored-by: benhalverson <7907232+benhalverson@users.noreply.github.com>
… a11y Co-authored-by: benhalverson <7907232+benhalverson@users.noreply.github.com>
Co-authored-by: benhalverson <7907232+benhalverson@users.noreply.github.com>
# Conflicts: # src/context/AuthContext.tsx # src/pages/Signin.tsx
# Conflicts: # src/pages/Signup.tsx
There was a problem hiding this comment.
Pull request overview
Integrates the auth-related PR sequence (#36 → #38 → #37) and resolves conflicts to align sign-in/sign-up flows with Better Auth session + native passkey endpoints, while adding/adjusting tests and minor formatting changes.
Changes:
- Update auth state hydration to gate on
GET /api/auth/get-sessionbefore fetching/profile. - Migrate Signin/Signup passkey flows to Better Auth native endpoints and refresh auth context via
fetchUser(). - Add Vitest coverage for Signin password + passkey flows; minor formatting/import-order cleanups in checkout/payment/order pages.
Reviewed changes
Copilot reviewed 8 out of 8 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
| src/context/AuthContext.tsx | Uses Better Auth session as source-of-truth before profile hydration. |
| src/pages/Signin.tsx | Migrates passkey auth to Better Auth endpoints; improves error handling; refreshes auth via fetchUser(). |
| src/pages/Signin.test.tsx | Adds tests for password sign-in, passkey tab rendering, passkey error handling, and verify-authentication payload shape. |
| src/pages/Signup.tsx | Unifies signup into password signup + optional passkey registration; refreshes auth via fetchUser(). |
| src/utils/webauthn.ts | Adds bufferToBase64url helper for Better Auth/WebAuthn payload encoding. |
| src/pages/Checkout.tsx | Formatting-only refactor (line wrapping) around parsing and error messages. |
| src/pages/Payment.tsx | Import order + minor JSX formatting cleanup. |
| src/pages/OrderComplete.tsx | Formatting-only adjustments (quotes, wrapping, import order). |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| // @ts-expect-error | ||
| options.challenge = base64urlToUint8Array( | ||
| options.challenge as unknown as string, | ||
| ).buffer; | ||
| // @ts-ignore | ||
| // @ts-expect-error |
There was a problem hiding this comment.
The passkey options object is mutated using // @ts-expect-error to coerce challenge (and allowCredentials[].id) from string → buffer types. Suppressing these type errors can hide real mismatches over time; prefer building a new PublicKeyCredentialRequestOptions object with correctly typed fields instead of mutating the parsed JSON in place.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 9 out of 9 changed files in this pull request and generated 7 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| const optionsRes = await fetch( | ||
| `${BASE_URL}/api/auth/passkey/generate-register-options`, | ||
| { credentials: "include" }, | ||
| ); | ||
| if (!optionsRes.ok) throw new Error("Failed to get registration options"); | ||
|
|
There was a problem hiding this comment.
handlePasskeyRegistration currently throws generic errors for non-OK responses (e.g., "Failed to get registration options"). Since the backend appears to return structured {message, code} errors (as handled in Signin.tsx/Profile.tsx), consider parsing and surfacing those details here as well to make failures actionable.
| const handlePasskeyRegistration = async () => { | ||
| setPasskeyRegistering(true); | ||
| const toastId = toast.loading("Registering passkey..."); | ||
| try { |
There was a problem hiding this comment.
The new signup + passkey registration flow is fairly complex (fetch options → WebAuthn create → verify-registration → auth refresh) but currently has no automated coverage. Since Signin.tsx now has Vitest coverage for similar Better Auth flows, adding tests for this passkey registration path (success + common failure cases) would help prevent regressions.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 9 out of 9 changed files in this pull request and generated 3 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| await user.type(screen.getByLabelText(/email/i), "user@example.com"); | ||
| await user.type(screen.getByLabelText(/password/i), "password123"); | ||
| await user.click(screen.getByRole("button", { name: /sign in with password/i })); | ||
|
|
There was a problem hiding this comment.
This line exceeds the configured Biome formatter line width (80) and will likely be reformatted/flagged by biome check. Running Biome formatting on this file (or wrapping this call across multiple lines) should keep CI/style checks consistent.
| await user.type(screen.getByLabelText(/email/i), "bad@example.com"); | ||
| await user.type(screen.getByLabelText(/password/i), "wrongpassword"); | ||
| await user.click(screen.getByRole("button", { name: /sign in with password/i })); | ||
|
|
There was a problem hiding this comment.
This click assertion line is over the Biome formatter line width and is likely to be reformatted/flagged by biome check. Consider wrapping the getByRole call onto multiple lines (or run pnpm biome format).
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 11 out of 11 changed files in this pull request and generated 2 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 14 out of 14 changed files in this pull request and generated no new comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
This PR integrates the auth-related PR sequence in the recommended order and resolves merge conflicts across shared auth files.
Merged in order:
Conflict resolutions:
Notes: