Skip to content

Ban people from hackathons by email - #470

Merged
aamoghS merged 1 commit into
devfrom
feat/hackathon-ban
Oct 5, 2026
Merged

aamoghS merged 1 commit into
devfrom
feat/hackathon-ban

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Lets staff bar someone from hackathons only. Their club membership and the rest of the portal are untouched.

What a ban blocks (server-side, notHackathonBanned): registering, the interest list, creating or joining a team, submitting a project, applying to judge. Reads and the ways out (withdraw, leave team) stay open. The person sees: "You can't take part in Hacklytics events. If you think this is a mistake, email hello@hacklytics.io."

Keyed by email (lowercased), so a new account or a different sign-in provider on the same address is still refused, and you can ban someone before they've signed up.

Admin: a "Banned from hackathons" section on /admin/hackathons. Enter an email and a reason (confirm prompt), see who banned whom and when, then Lift ban. Bug testers see the list, but the buttons are disabled and the API refuses them. Bans and lifts are written to audit_logs.

Schema: new hackathon_ban table (additive; drizzle-kit push creates it on deploy).

Not included: existing registrations aren't changed. If the person is already registered or accepted for an edition, reject them from the Applications tab as well.

Checks: tsc (api + web), eslint --max-warnings 0, vitest 749 passed (5 new: banned person refused on interest/team/create, others pass, ban stored lowercased and audited, bug tester refused, non-staff can't list). Verified locally: ban via API shows in the admin list with name, reason and banner; lift works.

Base: stacked on #465 (bug tester role), which is stacked on #462.


Note

Medium Risk
New enforcement on core participation mutations and staff moderation APIs; misconfiguration or cache lag could wrongly block or briefly allow signups until TTL expires.

Overview
Adds email-based hackathon bans so staff can block someone from hackathon participation without affecting club membership.

A new hackathon_ban table stores normalized (lowercase) email, reason, and who banned them. notHackathonBanned middleware checks that list (60s cache, cleared on ban/unban) and blocks register, interest signup, team create/join, project submit, and judge apply with a fixed user-facing message; reads and withdrawals/leaves stay allowed.

Staff get listBans, banFromHackathons (upsert on email), and liftHackathonBan behind isAdmin, with audit_logs entries; bug testers can list but not mutate. The admin hackathons page gains a Banned from hackathons section to ban, list, and lift bans.

Reviewed by Cursor Bugbot for commit 5a67e1e. Bugbot is set up for automated code reviews on this repo. Configure here.

Staff can bar someone from taking part in hackathons without touching
their club membership.

- hackathon_ban table (additive): lowercased email, reason, banned_by.
  Keyed by email so a new account or another sign-in provider on the
  same address is still refused
- notHackathonBanned gate on register, registerInterest, createTeam,
  joinTeam, submitProject and judge register. Reads and the ways out
  (withdraw, leave) stay open. Cached 60s; ban and unban clear it
- hackathon.listBans / banFromHackathons / liftHackathonBan (isAdmin,
  so bug testers can read the list but not change it); bans and lifts
  are written to audit_logs
- "Banned from hackathons" section on /admin/hackathons: email +
  reason form with a confirm, list with who banned whom and when, and
  Lift ban
@github-actions
github-actions Bot requested a review from aamoghS October 5, 2026 15:19
@aamoghS aamoghS changed the title Feature: feat/hackathon-ban to dev Ban people from hackathons by email Oct 5, 2026
@aamoghS
aamoghS changed the base branch from dev to feat/qa-role October 5, 2026 15:20

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 5a67e1e. Configure here.

? db.query.users.findMany({
where: inArray(users.email, emails),
columns: { email: true, name: true },
})

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ban list misses mixed-case accounts

Low Severity

listBans matches accounts with a case-sensitive inArray on users.email against already-lowercased ban emails. OAuth still stores the provider's original casing, so those people show as having no account and lose their name even though the ban itself is in force.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 5a67e1e. Configure here.

@aamoghS
aamoghS changed the base branch from feat/qa-role to dev October 5, 2026 15:27
@aamoghS
aamoghS merged commit 3deaa0f into dev Oct 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant