Adds the notifications system end-to-end (4 types, payload-versioned JSONB, SSE-based live unread badge, /notifications page, mark-read API, fan-out job for activity_published, daily 90-day retention purge). Bell icon in the navbar with unread badge. Side-findings from exercising the change: - Add 6-digit magic code to registration (mirrors login UX, mobile paste-friendly), with `[Register Magic Link]` console line in dev so the code is reachable without a real email transport. - Manual passkey/magic-link toggle on the register form (login already had it). - Restrict ALPN to http/1.1 in HTTPS dev so React Router's singleFetchAction CSRF check (Origin vs. Host) passes — Node doesn't synthesize Host from h2's :authority. Plain HTTP dev unaffected. - Followers/Following routes now use the locked-account rule from the profile route (owner + accepted followers see the list; others 404). Profile page renders the count chips as plain spans for viewers who can't see the lists, so private profiles don't surface dead links. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
19 lines
734 B
TypeScript
19 lines
734 B
TypeScript
import { data } from "react-router";
|
|
import type { Route } from "./+types/api.notifications.$id.read";
|
|
import { getSessionUser } from "~/lib/auth.server";
|
|
import { markRead } from "~/lib/notifications.server";
|
|
|
|
export async function action({ request, params }: Route.ActionArgs) {
|
|
if (request.method !== "POST") {
|
|
return data({ error: "Method not allowed" }, { status: 405 });
|
|
}
|
|
const user = await getSessionUser(request);
|
|
if (!user) return data({ error: "Unauthorized" }, { status: 401 });
|
|
|
|
const id = params.id;
|
|
if (!id) return data({ error: "id required" }, { status: 400 });
|
|
|
|
const ok = await markRead(user.id, id);
|
|
if (!ok) return data({ error: "Not found" }, { status: 404 });
|
|
return data({ ok: true });
|
|
}
|