Conversation
Add a "bug_tester" staff role so people can test the admin side without being able to change anything. - isStaffRole is now an allow-list (super_admin, admin, moderator) instead of "anything but volunteer", so a new role can never become full staff by default - isAdmin lets a bug tester through for queries only; any mutation behind it (and isSuperAdmin, built on it) is refused with a read-only message. isScanner does the same, so the scan desks are viewable but nothing can be checked in - callerIsAdmin stays staff-only: bug testers get no widened public responses and cannot act on other leaders' initiatives - resume and bootcamp file routes use isStaffRole, so bug testers cannot download resumes - portal: bug testers see the admin nav (minus the staff-only Staff & Roles and project-lead pages) with a read-only banner; super admins can grant the role from Staff & Roles Every admin query was checked for writes before allowing them; none write. Tests cover queries allowed, mutations refused (full staff, super admin and scanner) and the nav.
- ground lifts from near-black to a dark grey (#131715); raised, rule and meta ink move with it to keep contrast - every heading uses the Silkscreen pixel face; Bricolage is dropped - "Plant a flower" heading above the hero and footer flower beds - hero facts list (room, tracks, length, cost) moves into the FAQ - drop the "opens in a new tab" caption under Notify me - stop claiming cloud credits are covered; meals and swag stay - remove the dead discord.gg/hacklytics link from the footer and FAQ - Pure Imagination is not a track: four tracks
The API already refuses every write from a bug tester; the admin UI now says so instead of letting the click fail silently. useReadOnly() is true only for a bug tester, and every control whose purpose is a write (create, save, delete, toggles, check-in, scanning, sending, judging and results controls, membership grants, uploads) renders disabled with a "Read-only access" tooltip. Reads stay usable: tabs, filters, search, pagination, exports, QR viewing and opening detail views. Enter-to-submit on the manual check-in fields is guarded too. The banner copy now says buttons are greyed out.
Read-only bug tester role for QA
Feature: feat/hacklytics-greenhouse to dev
Feature: feat/portal-ui-redesign to dev
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 4bbecd8. Configure here.
|
|
||
| /* Font variables come from next/font in app/layout.tsx. */ | ||
| --font-display: var(--font-bricolage), ui-sans-serif, system-ui, sans-serif; | ||
| --font-display: var(--font-silkscreen), ui-monospace, monospace; |
There was a problem hiding this comment.
Hacklytics display font and hero facts
Medium Severity
--font-display now resolves to Silkscreen and Bricolage_Grotesque is no longer loaded, so hero, section titles, and nav render in the pixel face. The hero facts list is also gone. Display type is Bricolage Grotesque; Silkscreen is only for small kickers, and the hero keeps the facts list.
Additional Locations (2)
Triggered by learned rule: Hacklytics greenhouse-at-night look; PixelBed not PixelGarden
Reviewed by Cursor Bugbot for commit 4bbecd8. Configure here.
|
Visit the preview URL for this PR (updated for commit 4bbecd8): https://hacklytics2027--pr-469-cyf2xmeh.web.app (expires Mon, 12 Oct 2026 14:50:30 GMT) 🔥 via Firebase Hosting GitHub Action 🌎 Sign: c48ba34db61581e25fe2978355160b5eefe0e83f |


Automated PR tracking changes from
devintomain.Note
Medium Risk
Changes authorization middleware and staff role semantics (security-sensitive), though mutations are blocked server-side; broad admin UI gating must stay aligned with API checks.
Overview
Introduces a
bug_testeradmin tier for read-only QA: they can run staff queries (including scan-desk reads) but every mutation behindisAdmin/isScanneris rejected with a shared read-only message.isStaffRoleis now an explicit allow-list (super_admin,admin,moderator) so new roles do not inherit full staff powers; portal context exposesisBugTester, super admins can assign the role in the DB/API, and edge tests cover query vs mutation behavior.The main portal treats bug testers like admin viewers via
canViewAdmin, shows a read-only banner, hides Staff & Roles / Lead nav links, and disables write controls across admin pages withuseReadOnly(API still enforces writes).Separately, the Hacklytics 2027 site shifts display typography to Silkscreen, tweaks colors and hero layout, drops the wildcard track and several marketing copy items (cloud credits, Discord, interest-form hint), and expands FAQs.
Reviewed by Cursor Bugbot for commit 4bbecd8. Bugbot is set up for automated code reviews on this repo. Configure here.