Skip to content

Sync: dev to main - #469

Merged
aamoghS merged 6 commits into
mainfrom
dev
Oct 5, 2026
Merged

aamoghS merged 6 commits into
mainfrom
dev

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Automated PR tracking changes from dev into main.


Note

Medium Risk
Changes authorization middleware and staff role semantics (security-sensitive), though mutations are blocked server-side; broad admin UI gating must stay aligned with API checks.

Overview
Introduces a bug_tester admin tier for read-only QA: they can run staff queries (including scan-desk reads) but every mutation behind isAdmin / isScanner is rejected with a shared read-only message. isStaffRole is now an explicit allow-list (super_admin, admin, moderator) so new roles do not inherit full staff powers; portal context exposes isBugTester, super admins can assign the role in the DB/API, and edge tests cover query vs mutation behavior.

The main portal treats bug testers like admin viewers via canViewAdmin, shows a read-only banner, hides Staff & Roles / Lead nav links, and disables write controls across admin pages with useReadOnly (API still enforces writes).

Separately, the Hacklytics 2027 site shifts display typography to Silkscreen, tweaks colors and hero layout, drops the wildcard track and several marketing copy items (cloud credits, Discord, interest-form hint), and expands FAQs.

Reviewed by Cursor Bugbot for commit 4bbecd8. Bugbot is set up for automated code reviews on this repo. Configure here.

aamoghS and others added 5 commits October 4, 2026 20:29
Add a "bug_tester" staff role so people can test the admin side
without being able to change anything.

- isStaffRole is now an allow-list (super_admin, admin, moderator)
  instead of "anything but volunteer", so a new role can never become
  full staff by default
- isAdmin lets a bug tester through for queries only; any mutation
  behind it (and isSuperAdmin, built on it) is refused with a
  read-only message. isScanner does the same, so the scan desks are
  viewable but nothing can be checked in
- callerIsAdmin stays staff-only: bug testers get no widened public
  responses and cannot act on other leaders' initiatives
- resume and bootcamp file routes use isStaffRole, so bug testers
  cannot download resumes
- portal: bug testers see the admin nav (minus the staff-only Staff &
  Roles and project-lead pages) with a read-only banner; super admins
  can grant the role from Staff & Roles

Every admin query was checked for writes before allowing them; none
write. Tests cover queries allowed, mutations refused (full staff,
super admin and scanner) and the nav.
- ground lifts from near-black to a dark grey (#131715); raised, rule
  and meta ink move with it to keep contrast
- every heading uses the Silkscreen pixel face; Bricolage is dropped
- "Plant a flower" heading above the hero and footer flower beds
- hero facts list (room, tracks, length, cost) moves into the FAQ
- drop the "opens in a new tab" caption under Notify me
- stop claiming cloud credits are covered; meals and swag stay
- remove the dead discord.gg/hacklytics link from the footer and FAQ
- Pure Imagination is not a track: four tracks
The API already refuses every write from a bug tester; the admin UI now
says so instead of letting the click fail silently. useReadOnly() is
true only for a bug tester, and every control whose purpose is a write
(create, save, delete, toggles, check-in, scanning, sending, judging
and results controls, membership grants, uploads) renders disabled
with a "Read-only access" tooltip. Reads stay usable: tabs, filters,
search, pagination, exports, QR viewing and opening detail views.
Enter-to-submit on the manual check-in fields is guarded too. The
banner copy now says buttons are greyed out.
Feature: feat/hacklytics-greenhouse to dev
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@aamoghS
aamoghS merged commit e0f03fa into main Oct 5, 2026
7 checks passed

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 4bbecd8. Configure here.


/* Font variables come from next/font in app/layout.tsx. */
--font-display: var(--font-bricolage), ui-sans-serif, system-ui, sans-serif;
--font-display: var(--font-silkscreen), ui-monospace, monospace;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hacklytics display font and hero facts

Medium Severity

--font-display now resolves to Silkscreen and Bricolage_Grotesque is no longer loaded, so hero, section titles, and nav render in the pixel face. The hero facts list is also gone. Display type is Bricolage Grotesque; Silkscreen is only for small kickers, and the hero keeps the facts list.

Additional Locations (2)
Fix in Cursor Fix in Web

Triggered by learned rule: Hacklytics greenhouse-at-night look; PixelBed not PixelGarden

Reviewed by Cursor Bugbot for commit 4bbecd8. Configure here.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Visit the preview URL for this PR (updated for commit 4bbecd8):

https://hacklytics2027--pr-469-cyf2xmeh.web.app

(expires Mon, 12 Oct 2026 14:50:30 GMT)

🔥 via Firebase Hosting GitHub Action 🌎

Sign: c48ba34db61581e25fe2978355160b5eefe0e83f

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant