Skip to content

feat(membership): claimed transactions support view on /admin/membership - #929

Merged
SomethingNew71 merged 3 commits into
mainfrom
feature/admin-txn-claimed
Oct 4, 2026
Merged

SomethingNew71 merged 3 commits into
mainfrom
feature/admin-txn-claimed

Conversation

@SomethingNew71

Copy link
Copy Markdown
Collaborator

The support view for TXN_CLAIMED cases: a store purchase verified by an account other than the one it is bound to. The backend is ClassicMiniDIY/classicminidiy-supabase#210, with migration 20261003000004, already pushed and verified on production.

Changes

  • "Claimed transactions" on /admin/membership (daisyUI 5, Font Awesome 6). It lists open cases: caller and owner, platform, plan, status, last attempt and count. A row moved earlier by support says "Moved here by support … on ".
  • "Move to caller" opens a confirm dialog that names both accounts.
    • Success: a toast, then the list reloads.
    • 404 or 409: the reason shows in the dialog, and the list reloads behind it.
    • Already linked: the toast says "Already linked to that account".
  • GET /api/admin/membership/claimed: requireAdminAuth. A database error is logged, never returned.
  • POST /api/admin/membership/reassign: requireAdminAuth with the Bearer header only (no cookie fallback for a money-moving write).
    • It validates the UUIDs, refuses a move to the same account, and passes expectedOwnerId, so a stale list cannot move a purchase away from someone else.
    • Error mapping: 42501 → 403, P0002 → 404, 55000 → 409, 23505 → 409 "already has a membership", 23503 / 22004 → 400. Anything else returns a generic 500.
  • Types: types/database.ts is regenerated from production, and the temporary rpc casts are removed.
  • Docs: .claude/rules/admin.md.

Checks

  • format-check: clean.
  • typecheck: no change against baseline.
  • Admin tests: 215 passed. Full suite earlier: 6586 passed.
  • Two Opus review rounds: no blockers.

🤖 Generated with Claude Code

Lists open TXN_CLAIMED cases (a store purchase verified by one account and
bound to another) with both emails, platform, plan, status, last attempt and
count. "Move to caller" confirms in a dialog that names both accounts, then
POST /api/admin/membership/reassign calls admin_reassign_subscription after
requireAdminAuth with the owner the admin saw, so a row that changed hands
since the list loaded is refused. Toast on success, then the list reloads.

Both RPCs come from classicminidiy-supabase feature/admin-txn-claimed and are
not deployed yet; the routes use a narrowed rpc cast until gen:types.
- claimed list route logs the database error and returns a generic message
- reassign route is header-only (refuses the cookie token path, 401)
- rows and the confirm dialog say "Moved here by support" when the case was
  moved before and came back (Apple shared ID)
- a 404 or 409 on move keeps the reason in the dialog and reloads the list
- 23505 maps to 409 naming the platform; a no-op move toasts "Already linked
  to that account"
@SomethingNew71
SomethingNew71 merged commit 8117299 into main Oct 4, 2026
6 checks passed
@SomethingNew71
SomethingNew71 deleted the feature/admin-txn-claimed branch October 4, 2026 03:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant