* Add on-the-clock email notifications and fix push notification modal
- Add `draft_email_notifications_enabled` column to users table
- New `sendOnTheClockEmail` service sends an email when a user's turn arrives
in a draft; detects back-to-back picks and sends one combined email instead
of two; skips notification if the team has autodraft enabled
- Email is triggered after every manual pick (make-pick route) and every
timer-expiry pick (executeAutoPick) once the full autodraft chain settles,
so the notified user is always the first human on the clock
- Add email notification toggle to the user settings Notifications section
- Fix push notification dropdown in the draft room: the bare absolute div is
replaced with a Radix Popover so clicking outside dismisses it without
toggling notifications off
- Rename draft room label from "Pick Notifications" to "Push Notifications"
to distinguish from the new email notifications
https://claude.ai/code/session_01LMGxgYvtE3CF8Jf3u2pXgA
* Address code review feedback on email notification feature
- sendOnTheClockEmail now fetches season (and currentPickNumber) internally,
removing the blocking postChainSeason pre-fetch from both make-pick.ts and
executeAutoPick; callers are now true fire-and-forget with no IIFE needed
- Parallel Promise.all for team, autodraftSettings, and league queries reduces
sequential DB round-trips from 5 to 3
- Remove team.ownerId type cast; assign to local after the null guard
- Combine the two calculatePickInfo calls for the same pick into one
- Fix popoverOpen/enabled divergence: remove the {enabled && ...} guard on
PopoverContent so popoverOpen is the sole visibility control
- Unify NotificationsSection feedback pattern: both Discord and email sections
now read success/error directly from their respective fetcher data via a
shared feedbackFromFetcher helper; removes the success/error props and the
verbose cast that was used for email
- Add 13 unit tests for sendOnTheClockEmail covering: early-exit paths
(no season, past totalPicks, no owner, notifications disabled, autodraft
enabled, no league), single vs back-to-back subject selection, draft room
link presence, error logging without throwing, and parallel query execution
https://claude.ai/code/session_01LMGxgYvtE3CF8Jf3u2pXgA
---------
Co-authored-by: Claude <noreply@anthropic.com>
* Add Discord account linking from settings page
Adds a "Connect Discord" button in the Account settings section that
triggers BetterAuth's linkSocial flow to attach a Discord account to
an existing user without requiring a sign-out/sign-in. After the OAuth
callback, the ?section= URL param returns the user to the Account tab.
The Notifications toggle was already gated on Discord being linked.
https://claude.ai/code/session_01UerTpTuBWjreTNEns8srkp
* Fix Discord linking error handling and section routing issues
- Reset linkingDiscord state and show error message when linkSocial throws,
so users can retry if the OAuth flow fails
- Move VALID_SECTION_IDS to module level and derive it from SECTIONS to
avoid per-render allocation and prevent the two from drifting out of sync
- Remove premature SectionId cast before the allowlist validation in
the ?section= URL param handling
- Add tests for loading state and error recovery in AccountSection
Fixes#455https://claude.ai/code/session_01UerTpTuBWjreTNEns8srkp
---------
Co-authored-by: Claude <noreply@anthropic.com>
* Add admin users management page with pagination, search, and inline username editing
https://claude.ai/code/session_01E4UUQqQedhFP2F5YcBRArs
* Fix five issues from admin users page code review
- admin.users: use useEffect to close inline edit on success so validation
errors are not silently discarded when the save button fires onClick
- root: add /admin to ONBOARDING_EXEMPT so admin users without a username
are not redirect-looped away from admin pages
- settings: skip username validation when the username field is empty so
updating timezone alone does not break for accounts without a username
- models/user: exclude soft-deleted users from findUsersPaginated
- admin.users: remove unused hasMore from loader return; simplify header div
https://claude.ai/code/session_01E4UUQqQedhFP2F5YcBRArs
* Fix lint: rename shadowed variables in user model
- findUserByUsername: use imported sql directly instead of destructuring
it from the callback (shadowed the top-level import)
- findUsersPaginated: rename orderBy callback param from users to t
(shadowed the outer users result variable)
https://claude.ai/code/session_01E4UUQqQedhFP2F5YcBRArs
---------
Co-authored-by: Claude <noreply@anthropic.com>
* Add username onboarding prompt for new signups
New users (especially via OAuth/Google) are redirected to /onboarding
to choose a display username before accessing the app. Adds unique
constraint on users.username and case-insensitive uniqueness validation.
https://claude.ai/code/session_01UinBMAy9d6dQzzbcUAdq8J
* Address all code review issues on username onboarding
- Replace case-sensitive unique constraint with functional unique index on
lower(username) so DB-level uniqueness is case-insensitive (fix#1)
- Share USERNAME_RE from models/user.ts; add same format + uniqueness
validation to the settings update-profile action (fix#2)
- Wrap updateUser calls in try/catch to handle race-condition DB errors
gracefully in both onboarding and settings (fix#3)
- Add unit tests for suggestUsername, safeRedirectTo, USERNAME_RE, and
isOnboardingExempt (fix#4)
- Guard suggestUsername against returning strings shorter than 3 chars (fix#5)
- Preserve the user's intended destination via redirectTo query param
through the onboarding flow (fix#6)
- Treat empty username in settings as a validation error instead of a
silent no-op (fix#7)
- Use exact/sub-path matching in isOnboardingExempt to prevent
false-positive prefix matches like /loginpage (fix#8)
https://claude.ai/code/session_01UinBMAy9d6dQzzbcUAdq8J
---------
Co-authored-by: Claude <noreply@anthropic.com>
* Add opt-in Discord ping to standings notifications
Users who have linked their Discord account can enable a ping preference
in Settings > Notifications. When enabled, their bracket username is replaced
with a Discord @mention (<@userId>) in league standings update messages,
sending them a push notification and showing their Discord display name.
Adds discordPingEnabled column to users, a findDiscordIdsByUserIds model
helper, allowed_mentions support to the Discord webhook payload, and a
NotificationsSection settings component.
https://claude.ai/code/session_01NUv93WRrufHhpZSMyY4bjs
* Remove Display Name field from user profile settings
Username is the only user-facing name field. The display_name column
remains in the database since BetterAuth writes the OAuth provider name
there, and it serves as a programmatic fallback via getUserDisplayName.
https://claude.ai/code/session_01NUv93WRrufHhpZSMyY4bjs
* Address code review feedback on Discord ping feature
- Fix broken Account settings link in NotificationsSection: replace the
non-functional ?section=account href with an onNavigateToAccount callback
that drives the parent's useState-based section switcher
- Replace hand-rolled toggle button with the project's Switch component
(Radix UI) for consistent sizing, accessibility, and dark-mode support
- Guard update-discord-ping action: return an error if the user attempts
to enable pings without a Discord account linked
- Surface action error in NotificationsSection UI
- Cap allowed_mentions.users at 100 to avoid Discord rejecting the payload
in large leagues
- Remove the showWinner alias in scoring-calculator; inline winnerScoreChanged
- Add comment to league settings test notification explaining why discordUserId
is omitted
- Clarify database schema comment: displayName is write-only from BetterAuth
https://claude.ai/code/session_01NUv93WRrufHhpZSMyY4bjs
---------
Co-authored-by: Claude <noreply@anthropic.com>
* Add account deletion and multi-section settings page
- Rename /user-profile → /settings with 301 redirect from old URL
- Add multi-section settings nav (Profile, Account, API placeholder, Data & Privacy)
reusing existing SettingsDesktopNav/SettingsMobileGridNav components
- Implement account deletion via anonymization: wipes all PII from users row,
releases team ownerships, removes commissioner records, deletes sessions/accounts
- Add data export request form that emails privacy@brackt.com via Resend
- Add deletedAt timestamp column to users table (migration 0100)
- Add anonymizeUserAccount() to user model
- Add removeAllCommissionersByUserId() to commissioner model
- Tests for both new model functions
- Update UserMenu "Profile" link → "Settings" at /settings
https://claude.ai/code/session_017Hvmof82Xr3UwKFc3pnC4X
* Address code review feedback on settings/account deletion
1. Wrap anonymizeUserAccount in a DB transaction so partial failures
(e.g. session delete succeeds but user update fails) can't leave
accounts in an inconsistent state
2. Escape user email and notes with escapeHtml() before interpolating
into the data request email body
3. Reset AlertDialog confirmed state when dialog is dismissed via
backdrop click or Escape key (onOpenChange handler)
4. Extract accounts DB query to app/models/account.ts (findLinkedAccountsByUserId)
to comply with the "always query through app/models/" convention
5. Replace dynamic imports() in action handlers with static top-level imports
6. Remove the unused hard-delete deleteUser() function
7. Add lastDataRequestAt timestamp to users (migration 0101) and enforce
a 30-day server-side cooldown on data export requests
8. Replace fragile actionData type casts with a proper ActionData
discriminated union; narrowing now works without `as` assertions
9. Strengthen tests: verify which schema tables are passed to delete()
and that operations run inside the transaction
https://claude.ai/code/session_017Hvmof82Xr3UwKFc3pnC4X
* Fix no-non-null-assertion lint error in PrivacySection
Replace non-null assertion with optional chaining on dataRequestCooldownUntil
to satisfy oxlint no-non-null-assertion rule.
https://claude.ai/code/session_017Hvmof82Xr3UwKFc3pnC4X
---------
Co-authored-by: Claude <noreply@anthropic.com>