Commit graph

2 commits

Author SHA1 Message Date
Chris Parsons
bf0ddaa8aa Add oxlint and fix all lint errors
- Install oxlint, add .oxlintrc.json with rules for TypeScript/React
- Add npm run lint / lint:fix scripts
- Add Claude PostToolUse hook to run oxlint on every edited file
- Fix 101 errors: unused vars/imports, eqeqeq, prefer-const, no-new-array
- Fix no-array-index-key (use stable keys or suppress positional cases)
- Fix exhaustive-deps missing dependency in useEffect
- Promote exhaustive-deps and no-array-index-key to errors
- Fix Map.get() !== null bug in $leagueId.server.ts (should be !== undefined)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-21 09:40:15 -07:00
Chris Parsons
b35791e76a
Fix public draft board access not working when setting is enabled (#23)
* Fix public draft board access not working when setting is enabled

Two bugs were causing the isPublicDraftBoard setting to fail:

1. Draft board loader called getAuth() before checking isPublicDraftBoard.
   Restructured to skip auth entirely for public boards - only call getAuth
   when the board is private and we need to verify member/commissioner access.

2. Settings action saved the league (name + isPublicDraftBoard) AFTER fetching
   the current season. If the season fetch had any issue, updateLeague was never
   reached. Moved the league-level save to happen unconditionally before the
   season fetch, so isPublicDraftBoard is always persisted on form submit.

https://claude.ai/code/session_01Jp2tE3YXhx2jdb6CgCnvZy

* Fix bugs in draft board access and settings update action

- Wrap updateLeague call in try-catch so DB errors return a user-friendly
  message instead of an unhandled 500
- Fix season-update catch block to say "season settings" not "league" since
  the league was already saved successfully at that point
- Validate leagueId URL param against season.leagueId in draft board loader
  to prevent accessing a season via the wrong league's URL
- Change 403 message for authenticated non-members from "not public" to
  "you don't have access" to accurately reflect their logged-in state
- Add settings-update.test.ts covering name validation, league save,
  error handling, draft speed mapping, and season-specific validation
- Add draft-board-access.test.ts covering public/private access rules,
  leagueId mismatch detection, commissioner/owner/unauthenticated cases,
  and the new per-role 403 message distinction

https://claude.ai/code/session_01Jp2tE3YXhx2jdb6CgCnvZy

* Fix TypeScript errors in settings-update tests

TS was narrowing const draftSpeed = 'fast' to the literal type 'fast',
making comparisons with 'slow'/'very-slow' etc. flagged as impossible.
Widen all draftSpeed locals and the season status locals to string so the
if-chains compile cleanly under strict mode.

https://claude.ai/code/session_01Jp2tE3YXhx2jdb6CgCnvZy

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-02-22 16:31:24 -08:00