feat(api/v2): ✨ Implement socials routes - #135

Merged
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials
Aug 28, 2026
Merged

feat(api/v2): ✨ Implement socials routes#135
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials

Conversation

@kyanvde

Copy link
Copy Markdown
Contributor

Closes#60.

Adds the /socials section to api-v2, covering every route the issue lists.

RouteAuthNotes
GET /socialsauthenticated teamReturns the token holder's own links
GET /:teamId/socialspublic?slug=true resolves the team by slug
POST /socialsteam
PUT /socialsteamBulk upsert
PUT /socials/:idteam
DELETE /socials/:idteam

Every route is registered both bare and behind a :teamId prefix, and the prefix is only ever allowed to name the team the token already belongs to (@TeamScope).

Notes

  • The section mirrors applications/questions, which has the same shape — a team-owned resource with a bulk upsert — so the service, DTOs and tests follow it deliberately closely.
  • Read auth matches v1: GET /buildteams/:id/socials was public there, and the links are rendered on the public team page, so the prefixed form is public (@OptionalAuth) while the bare form falls back to the authenticated team and answers 401 without a token.
  • The bulk upsert leaves links that are not in the payload alone, rather than treating the payload as the team's full set. Deleting is what DELETE /socials/:id is for, and a silent delete-on-omit is easy to trigger by accident.
  • An ID that belongs to another team answers 404, not 403 — a 403 would confirm the ID exists. Same reasoning as the questions section.
  • url is validated as a non-empty string rather than with @IsUrl(). Existing rows written by v1 hold arbitrary strings (mailto: addresses, app-specific schemes), so a stricter rule would reject data the API already serves.
  • Bulk payloads are capped at 100 entries, since the whole batch runs in one transaction.
  • sortBy allows id, name, icon, url; filtering allows name, icon, url.

Testing

yarn ws api-v2 test — 27 suites, 155 tests, all passing. 38 of those are new:

  • socials.service.spec.ts — pagination/sorting/filtering, slug resolution, team scoping on update and delete, and the upsert paths (update existing, create new, create with a caller-supplied ID, cross-team refusal, bulk limit).
  • socials.controller.spec.ts — team resolution, the slug flag not leaking into the filter, and the 401 on the unprefixed listing.
  • socials.routes.spec.ts — end to end through the real router, including that PUT /socials reaches the bulk upsert while PUT /socials/:id reaches the single update.

yarn ws api-v2 build passes. lint reports the 6 pre-existing unbound-method errors documented in CLAUDE.md and nothing new.

🤖 Generated with Claude Code

Adds the /socials section: a public per-team listing, plus create,
bulk upsert, update and delete scoped to the authenticated team.
Every route is registered bare and behind a :teamId prefix, matching
the application questions section, which socials mirror closely. The
bulk PUT leaves links that are not part of the payload untouched and
answers 404 rather than 403 for an ID owned by another team.
Closes#60
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-project-automationgithub-project-automationBot moved this from Backlog to In Progress in @BuildTheEarth/web TrackerAug 28, 2026
@Nudelsuppe42
Nudelsuppe42 merged commit 81ce51a into api/v2Aug 28, 2026
1 check passed
@Nudelsuppe42
Nudelsuppe42 deleted the api-v2/socials branch August 28, 2026 19:28
@github-project-automationgithub-project-automationBot moved this from In Progress to Done in @BuildTheEarth/web TrackerAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants

@kyanvde@Nudelsuppe42
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(api/v2): ✨ Implement socials routes - #135

Merged
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials
Aug 28, 2026
Merged

feat(api/v2): ✨ Implement socials routes#135
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials

Conversation

@kyanvde

Copy link
Copy Markdown
Contributor

Closes#60.

Adds the /socials section to api-v2, covering every route the issue lists.

RouteAuthNotes
GET /socialsauthenticated teamReturns the token holder's own links
GET /:teamId/socialspublic?slug=true resolves the team by slug
POST /socialsteam
PUT /socialsteamBulk upsert
PUT /socials/:idteam
DELETE /socials/:idteam

Every route is registered both bare and behind a :teamId prefix, and the prefix is only ever allowed to name the team the token already belongs to (@TeamScope).

Notes

  • The section mirrors applications/questions, which has the same shape — a team-owned resource with a bulk upsert — so the service, DTOs and tests follow it deliberately closely.
  • Read auth matches v1: GET /buildteams/:id/socials was public there, and the links are rendered on the public team page, so the prefixed form is public (@OptionalAuth) while the bare form falls back to the authenticated team and answers 401 without a token.
  • The bulk upsert leaves links that are not in the payload alone, rather than treating the payload as the team's full set. Deleting is what DELETE /socials/:id is for, and a silent delete-on-omit is easy to trigger by accident.
  • An ID that belongs to another team answers 404, not 403 — a 403 would confirm the ID exists. Same reasoning as the questions section.
  • url is validated as a non-empty string rather than with @IsUrl(). Existing rows written by v1 hold arbitrary strings (mailto: addresses, app-specific schemes), so a stricter rule would reject data the API already serves.
  • Bulk payloads are capped at 100 entries, since the whole batch runs in one transaction.
  • sortBy allows id, name, icon, url; filtering allows name, icon, url.

Testing

yarn ws api-v2 test — 27 suites, 155 tests, all passing. 38 of those are new:

  • socials.service.spec.ts — pagination/sorting/filtering, slug resolution, team scoping on update and delete, and the upsert paths (update existing, create new, create with a caller-supplied ID, cross-team refusal, bulk limit).
  • socials.controller.spec.ts — team resolution, the slug flag not leaking into the filter, and the 401 on the unprefixed listing.
  • socials.routes.spec.ts — end to end through the real router, including that PUT /socials reaches the bulk upsert while PUT /socials/:id reaches the single update.

yarn ws api-v2 build passes. lint reports the 6 pre-existing unbound-method errors documented in CLAUDE.md and nothing new.

🤖 Generated with Claude Code

Adds the /socials section: a public per-team listing, plus create,
bulk upsert, update and delete scoped to the authenticated team.
Every route is registered bare and behind a :teamId prefix, matching
the application questions section, which socials mirror closely. The
bulk PUT leaves links that are not part of the payload untouched and
answers 404 rather than 403 for an ID owned by another team.
Closes#60
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-project-automationgithub-project-automationBot moved this from Backlog to In Progress in @BuildTheEarth/web TrackerAug 28, 2026
@Nudelsuppe42
Nudelsuppe42 merged commit 81ce51a into api/v2Aug 28, 2026
1 check passed
@Nudelsuppe42
Nudelsuppe42 deleted the api-v2/socials branch August 28, 2026 19:28
@github-project-automationgithub-project-automationBot moved this from In Progress to Done in @BuildTheEarth/web TrackerAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants

@kyanvde@Nudelsuppe42
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(api/v2): ✨ Implement socials routes - #135

Merged
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials
Aug 28, 2026
Merged

feat(api/v2): ✨ Implement socials routes#135
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials

Conversation

@kyanvde

Copy link
Copy Markdown
Contributor

Closes#60.

Adds the /socials section to api-v2, covering every route the issue lists.

RouteAuthNotes
GET /socialsauthenticated teamReturns the token holder's own links
GET /:teamId/socialspublic?slug=true resolves the team by slug
POST /socialsteam
PUT /socialsteamBulk upsert
PUT /socials/:idteam
DELETE /socials/:idteam

Every route is registered both bare and behind a :teamId prefix, and the prefix is only ever allowed to name the team the token already belongs to (@TeamScope).

Notes

  • The section mirrors applications/questions, which has the same shape — a team-owned resource with a bulk upsert — so the service, DTOs and tests follow it deliberately closely.
  • Read auth matches v1: GET /buildteams/:id/socials was public there, and the links are rendered on the public team page, so the prefixed form is public (@OptionalAuth) while the bare form falls back to the authenticated team and answers 401 without a token.
  • The bulk upsert leaves links that are not in the payload alone, rather than treating the payload as the team's full set. Deleting is what DELETE /socials/:id is for, and a silent delete-on-omit is easy to trigger by accident.
  • An ID that belongs to another team answers 404, not 403 — a 403 would confirm the ID exists. Same reasoning as the questions section.
  • url is validated as a non-empty string rather than with @IsUrl(). Existing rows written by v1 hold arbitrary strings (mailto: addresses, app-specific schemes), so a stricter rule would reject data the API already serves.
  • Bulk payloads are capped at 100 entries, since the whole batch runs in one transaction.
  • sortBy allows id, name, icon, url; filtering allows name, icon, url.

Testing

yarn ws api-v2 test — 27 suites, 155 tests, all passing. 38 of those are new:

  • socials.service.spec.ts — pagination/sorting/filtering, slug resolution, team scoping on update and delete, and the upsert paths (update existing, create new, create with a caller-supplied ID, cross-team refusal, bulk limit).
  • socials.controller.spec.ts — team resolution, the slug flag not leaking into the filter, and the 401 on the unprefixed listing.
  • socials.routes.spec.ts — end to end through the real router, including that PUT /socials reaches the bulk upsert while PUT /socials/:id reaches the single update.

yarn ws api-v2 build passes. lint reports the 6 pre-existing unbound-method errors documented in CLAUDE.md and nothing new.

🤖 Generated with Claude Code

Adds the /socials section: a public per-team listing, plus create,
bulk upsert, update and delete scoped to the authenticated team.
Every route is registered bare and behind a :teamId prefix, matching
the application questions section, which socials mirror closely. The
bulk PUT leaves links that are not part of the payload untouched and
answers 404 rather than 403 for an ID owned by another team.
Closes#60
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-project-automationgithub-project-automationBot moved this from Backlog to In Progress in @BuildTheEarth/web TrackerAug 28, 2026
@Nudelsuppe42
Nudelsuppe42 merged commit 81ce51a into api/v2Aug 28, 2026
1 check passed
@Nudelsuppe42
Nudelsuppe42 deleted the api-v2/socials branch August 28, 2026 19:28
@github-project-automationgithub-project-automationBot moved this from In Progress to Done in @BuildTheEarth/web TrackerAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants

@kyanvde@Nudelsuppe42
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(api/v2): ✨ Implement socials routes - #135

Merged
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials
Aug 28, 2026
Merged

feat(api/v2): ✨ Implement socials routes#135
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials

Conversation

@kyanvde

Copy link
Copy Markdown
Contributor

Closes#60.

Adds the /socials section to api-v2, covering every route the issue lists.

RouteAuthNotes
GET /socialsauthenticated teamReturns the token holder's own links
GET /:teamId/socialspublic?slug=true resolves the team by slug
POST /socialsteam
PUT /socialsteamBulk upsert
PUT /socials/:idteam
DELETE /socials/:idteam

Every route is registered both bare and behind a :teamId prefix, and the prefix is only ever allowed to name the team the token already belongs to (@TeamScope).

Notes

  • The section mirrors applications/questions, which has the same shape — a team-owned resource with a bulk upsert — so the service, DTOs and tests follow it deliberately closely.
  • Read auth matches v1: GET /buildteams/:id/socials was public there, and the links are rendered on the public team page, so the prefixed form is public (@OptionalAuth) while the bare form falls back to the authenticated team and answers 401 without a token.
  • The bulk upsert leaves links that are not in the payload alone, rather than treating the payload as the team's full set. Deleting is what DELETE /socials/:id is for, and a silent delete-on-omit is easy to trigger by accident.
  • An ID that belongs to another team answers 404, not 403 — a 403 would confirm the ID exists. Same reasoning as the questions section.
  • url is validated as a non-empty string rather than with @IsUrl(). Existing rows written by v1 hold arbitrary strings (mailto: addresses, app-specific schemes), so a stricter rule would reject data the API already serves.
  • Bulk payloads are capped at 100 entries, since the whole batch runs in one transaction.
  • sortBy allows id, name, icon, url; filtering allows name, icon, url.

Testing

yarn ws api-v2 test — 27 suites, 155 tests, all passing. 38 of those are new:

  • socials.service.spec.ts — pagination/sorting/filtering, slug resolution, team scoping on update and delete, and the upsert paths (update existing, create new, create with a caller-supplied ID, cross-team refusal, bulk limit).
  • socials.controller.spec.ts — team resolution, the slug flag not leaking into the filter, and the 401 on the unprefixed listing.
  • socials.routes.spec.ts — end to end through the real router, including that PUT /socials reaches the bulk upsert while PUT /socials/:id reaches the single update.

yarn ws api-v2 build passes. lint reports the 6 pre-existing unbound-method errors documented in CLAUDE.md and nothing new.

🤖 Generated with Claude Code

Adds the /socials section: a public per-team listing, plus create,
bulk upsert, update and delete scoped to the authenticated team.
Every route is registered bare and behind a :teamId prefix, matching
the application questions section, which socials mirror closely. The
bulk PUT leaves links that are not part of the payload untouched and
answers 404 rather than 403 for an ID owned by another team.
Closes#60
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-project-automationgithub-project-automationBot moved this from Backlog to In Progress in @BuildTheEarth/web TrackerAug 28, 2026
@Nudelsuppe42
Nudelsuppe42 merged commit 81ce51a into api/v2Aug 28, 2026
1 check passed
@Nudelsuppe42
Nudelsuppe42 deleted the api-v2/socials branch August 28, 2026 19:28
@github-project-automationgithub-project-automationBot moved this from In Progress to Done in @BuildTheEarth/web TrackerAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants

@kyanvde@Nudelsuppe42
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(api/v2): ✨ Implement socials routes - #135

Merged
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials
Aug 28, 2026
Merged

feat(api/v2): ✨ Implement socials routes#135
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials

Conversation

@kyanvde

Copy link
Copy Markdown
Contributor

Closes#60.

Adds the /socials section to api-v2, covering every route the issue lists.

RouteAuthNotes
GET /socialsauthenticated teamReturns the token holder's own links
GET /:teamId/socialspublic?slug=true resolves the team by slug
POST /socialsteam
PUT /socialsteamBulk upsert
PUT /socials/:idteam
DELETE /socials/:idteam

Every route is registered both bare and behind a :teamId prefix, and the prefix is only ever allowed to name the team the token already belongs to (@TeamScope).

Notes

  • The section mirrors applications/questions, which has the same shape — a team-owned resource with a bulk upsert — so the service, DTOs and tests follow it deliberately closely.
  • Read auth matches v1: GET /buildteams/:id/socials was public there, and the links are rendered on the public team page, so the prefixed form is public (@OptionalAuth) while the bare form falls back to the authenticated team and answers 401 without a token.
  • The bulk upsert leaves links that are not in the payload alone, rather than treating the payload as the team's full set. Deleting is what DELETE /socials/:id is for, and a silent delete-on-omit is easy to trigger by accident.
  • An ID that belongs to another team answers 404, not 403 — a 403 would confirm the ID exists. Same reasoning as the questions section.
  • url is validated as a non-empty string rather than with @IsUrl(). Existing rows written by v1 hold arbitrary strings (mailto: addresses, app-specific schemes), so a stricter rule would reject data the API already serves.
  • Bulk payloads are capped at 100 entries, since the whole batch runs in one transaction.
  • sortBy allows id, name, icon, url; filtering allows name, icon, url.

Testing

yarn ws api-v2 test — 27 suites, 155 tests, all passing. 38 of those are new:

  • socials.service.spec.ts — pagination/sorting/filtering, slug resolution, team scoping on update and delete, and the upsert paths (update existing, create new, create with a caller-supplied ID, cross-team refusal, bulk limit).
  • socials.controller.spec.ts — team resolution, the slug flag not leaking into the filter, and the 401 on the unprefixed listing.
  • socials.routes.spec.ts — end to end through the real router, including that PUT /socials reaches the bulk upsert while PUT /socials/:id reaches the single update.

yarn ws api-v2 build passes. lint reports the 6 pre-existing unbound-method errors documented in CLAUDE.md and nothing new.

🤖 Generated with Claude Code

Adds the /socials section: a public per-team listing, plus create,
bulk upsert, update and delete scoped to the authenticated team.
Every route is registered bare and behind a :teamId prefix, matching
the application questions section, which socials mirror closely. The
bulk PUT leaves links that are not part of the payload untouched and
answers 404 rather than 403 for an ID owned by another team.
Closes#60
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-project-automationgithub-project-automationBot moved this from Backlog to In Progress in @BuildTheEarth/web TrackerAug 28, 2026
@Nudelsuppe42
Nudelsuppe42 merged commit 81ce51a into api/v2Aug 28, 2026
1 check passed
@Nudelsuppe42
Nudelsuppe42 deleted the api-v2/socials branch August 28, 2026 19:28
@github-project-automationgithub-project-automationBot moved this from In Progress to Done in @BuildTheEarth/web TrackerAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants

@kyanvde@Nudelsuppe42
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(api/v2): ✨ Implement socials routes - #135

Merged
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials
Aug 28, 2026
Merged

feat(api/v2): ✨ Implement socials routes#135
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials

Conversation

@kyanvde

Copy link
Copy Markdown
Contributor

Closes#60.

Adds the /socials section to api-v2, covering every route the issue lists.

RouteAuthNotes
GET /socialsauthenticated teamReturns the token holder's own links
GET /:teamId/socialspublic?slug=true resolves the team by slug
POST /socialsteam
PUT /socialsteamBulk upsert
PUT /socials/:idteam
DELETE /socials/:idteam

Every route is registered both bare and behind a :teamId prefix, and the prefix is only ever allowed to name the team the token already belongs to (@TeamScope).

Notes

  • The section mirrors applications/questions, which has the same shape — a team-owned resource with a bulk upsert — so the service, DTOs and tests follow it deliberately closely.
  • Read auth matches v1: GET /buildteams/:id/socials was public there, and the links are rendered on the public team page, so the prefixed form is public (@OptionalAuth) while the bare form falls back to the authenticated team and answers 401 without a token.
  • The bulk upsert leaves links that are not in the payload alone, rather than treating the payload as the team's full set. Deleting is what DELETE /socials/:id is for, and a silent delete-on-omit is easy to trigger by accident.
  • An ID that belongs to another team answers 404, not 403 — a 403 would confirm the ID exists. Same reasoning as the questions section.
  • url is validated as a non-empty string rather than with @IsUrl(). Existing rows written by v1 hold arbitrary strings (mailto: addresses, app-specific schemes), so a stricter rule would reject data the API already serves.
  • Bulk payloads are capped at 100 entries, since the whole batch runs in one transaction.
  • sortBy allows id, name, icon, url; filtering allows name, icon, url.

Testing

yarn ws api-v2 test — 27 suites, 155 tests, all passing. 38 of those are new:

  • socials.service.spec.ts — pagination/sorting/filtering, slug resolution, team scoping on update and delete, and the upsert paths (update existing, create new, create with a caller-supplied ID, cross-team refusal, bulk limit).
  • socials.controller.spec.ts — team resolution, the slug flag not leaking into the filter, and the 401 on the unprefixed listing.
  • socials.routes.spec.ts — end to end through the real router, including that PUT /socials reaches the bulk upsert while PUT /socials/:id reaches the single update.

yarn ws api-v2 build passes. lint reports the 6 pre-existing unbound-method errors documented in CLAUDE.md and nothing new.

🤖 Generated with Claude Code

Adds the /socials section: a public per-team listing, plus create,
bulk upsert, update and delete scoped to the authenticated team.
Every route is registered bare and behind a :teamId prefix, matching
the application questions section, which socials mirror closely. The
bulk PUT leaves links that are not part of the payload untouched and
answers 404 rather than 403 for an ID owned by another team.
Closes#60
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-project-automationgithub-project-automationBot moved this from Backlog to In Progress in @BuildTheEarth/web TrackerAug 28, 2026
@Nudelsuppe42
Nudelsuppe42 merged commit 81ce51a into api/v2Aug 28, 2026
1 check passed
@Nudelsuppe42
Nudelsuppe42 deleted the api-v2/socials branch August 28, 2026 19:28
@github-project-automationgithub-project-automationBot moved this from In Progress to Done in @BuildTheEarth/web TrackerAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants

@kyanvde@Nudelsuppe42
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(api/v2): ✨ Implement socials routes - #135

Merged
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials
Aug 28, 2026
Merged

feat(api/v2): ✨ Implement socials routes#135
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials

Conversation

@kyanvde

Copy link
Copy Markdown
Contributor

Closes#60.

Adds the /socials section to api-v2, covering every route the issue lists.

RouteAuthNotes
GET /socialsauthenticated teamReturns the token holder's own links
GET /:teamId/socialspublic?slug=true resolves the team by slug
POST /socialsteam
PUT /socialsteamBulk upsert
PUT /socials/:idteam
DELETE /socials/:idteam

Every route is registered both bare and behind a :teamId prefix, and the prefix is only ever allowed to name the team the token already belongs to (@TeamScope).

Notes

  • The section mirrors applications/questions, which has the same shape — a team-owned resource with a bulk upsert — so the service, DTOs and tests follow it deliberately closely.
  • Read auth matches v1: GET /buildteams/:id/socials was public there, and the links are rendered on the public team page, so the prefixed form is public (@OptionalAuth) while the bare form falls back to the authenticated team and answers 401 without a token.
  • The bulk upsert leaves links that are not in the payload alone, rather than treating the payload as the team's full set. Deleting is what DELETE /socials/:id is for, and a silent delete-on-omit is easy to trigger by accident.
  • An ID that belongs to another team answers 404, not 403 — a 403 would confirm the ID exists. Same reasoning as the questions section.
  • url is validated as a non-empty string rather than with @IsUrl(). Existing rows written by v1 hold arbitrary strings (mailto: addresses, app-specific schemes), so a stricter rule would reject data the API already serves.
  • Bulk payloads are capped at 100 entries, since the whole batch runs in one transaction.
  • sortBy allows id, name, icon, url; filtering allows name, icon, url.

Testing

yarn ws api-v2 test — 27 suites, 155 tests, all passing. 38 of those are new:

  • socials.service.spec.ts — pagination/sorting/filtering, slug resolution, team scoping on update and delete, and the upsert paths (update existing, create new, create with a caller-supplied ID, cross-team refusal, bulk limit).
  • socials.controller.spec.ts — team resolution, the slug flag not leaking into the filter, and the 401 on the unprefixed listing.
  • socials.routes.spec.ts — end to end through the real router, including that PUT /socials reaches the bulk upsert while PUT /socials/:id reaches the single update.

yarn ws api-v2 build passes. lint reports the 6 pre-existing unbound-method errors documented in CLAUDE.md and nothing new.

🤖 Generated with Claude Code

Adds the /socials section: a public per-team listing, plus create,
bulk upsert, update and delete scoped to the authenticated team.
Every route is registered bare and behind a :teamId prefix, matching
the application questions section, which socials mirror closely. The
bulk PUT leaves links that are not part of the payload untouched and
answers 404 rather than 403 for an ID owned by another team.
Closes#60
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-project-automationgithub-project-automationBot moved this from Backlog to In Progress in @BuildTheEarth/web TrackerAug 28, 2026
@Nudelsuppe42
Nudelsuppe42 merged commit 81ce51a into api/v2Aug 28, 2026
1 check passed
@Nudelsuppe42
Nudelsuppe42 deleted the api-v2/socials branch August 28, 2026 19:28
@github-project-automationgithub-project-automationBot moved this from In Progress to Done in @BuildTheEarth/web TrackerAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants

@kyanvde@Nudelsuppe42
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(api/v2): ✨ Implement socials routes - #135

Merged
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials
Aug 28, 2026
Merged

feat(api/v2): ✨ Implement socials routes#135
Nudelsuppe42 merged 1 commit into
api/v2from
api-v2/socials

Conversation

@kyanvde

Copy link
Copy Markdown
Contributor

Closes#60.

Adds the /socials section to api-v2, covering every route the issue lists.

RouteAuthNotes
GET /socialsauthenticated teamReturns the token holder's own links
GET /:teamId/socialspublic?slug=true resolves the team by slug
POST /socialsteam
PUT /socialsteamBulk upsert
PUT /socials/:idteam
DELETE /socials/:idteam

Every route is registered both bare and behind a :teamId prefix, and the prefix is only ever allowed to name the team the token already belongs to (@TeamScope).

Notes

  • The section mirrors applications/questions, which has the same shape — a team-owned resource with a bulk upsert — so the service, DTOs and tests follow it deliberately closely.
  • Read auth matches v1: GET /buildteams/:id/socials was public there, and the links are rendered on the public team page, so the prefixed form is public (@OptionalAuth) while the bare form falls back to the authenticated team and answers 401 without a token.
  • The bulk upsert leaves links that are not in the payload alone, rather than treating the payload as the team's full set. Deleting is what DELETE /socials/:id is for, and a silent delete-on-omit is easy to trigger by accident.
  • An ID that belongs to another team answers 404, not 403 — a 403 would confirm the ID exists. Same reasoning as the questions section.
  • url is validated as a non-empty string rather than with @IsUrl(). Existing rows written by v1 hold arbitrary strings (mailto: addresses, app-specific schemes), so a stricter rule would reject data the API already serves.
  • Bulk payloads are capped at 100 entries, since the whole batch runs in one transaction.
  • sortBy allows id, name, icon, url; filtering allows name, icon, url.

Testing

yarn ws api-v2 test — 27 suites, 155 tests, all passing. 38 of those are new:

  • socials.service.spec.ts — pagination/sorting/filtering, slug resolution, team scoping on update and delete, and the upsert paths (update existing, create new, create with a caller-supplied ID, cross-team refusal, bulk limit).
  • socials.controller.spec.ts — team resolution, the slug flag not leaking into the filter, and the 401 on the unprefixed listing.
  • socials.routes.spec.ts — end to end through the real router, including that PUT /socials reaches the bulk upsert while PUT /socials/:id reaches the single update.

yarn ws api-v2 build passes. lint reports the 6 pre-existing unbound-method errors documented in CLAUDE.md and nothing new.

🤖 Generated with Claude Code

Adds the /socials section: a public per-team listing, plus create,
bulk upsert, update and delete scoped to the authenticated team.
Every route is registered bare and behind a :teamId prefix, matching
the application questions section, which socials mirror closely. The
bulk PUT leaves links that are not part of the payload untouched and
answers 404 rather than 403 for an ID owned by another team.
Closes#60
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-project-automationgithub-project-automationBot moved this from Backlog to In Progress in @BuildTheEarth/web TrackerAug 28, 2026
@Nudelsuppe42
Nudelsuppe42 merged commit 81ce51a into api/v2Aug 28, 2026
1 check passed
@Nudelsuppe42
Nudelsuppe42 deleted the api-v2/socials branch August 28, 2026 19:28
@github-project-automationgithub-project-automationBot moved this from In Progress to Done in @BuildTheEarth/web TrackerAug 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants

@kyanvde@Nudelsuppe42