fix: prohibit ename update pictique - #684

Merged
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update
Jan 19, 2026
Merged

fix: prohibit ename update pictique#684
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update

Conversation

@sosweetham

@sosweethamsosweetham commented Jan 19, 2026

Copy link
Copy Markdown
Member

Description of change

remove client side pictique "name" update code to reduce confusion with ename updation (default name)

Issue Number

closes#247

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added eName field in account settings displaying your eVault real name (read-only, auto‑synced)
    • Public username field relabeled to "Change your username" and remains editable
  • Bug Fixes

    • Profile updates now only send name and avatar to the server
    • Handle/eName is no longer editable from settings to ensure consistent syncing with eVault

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 19, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 8 minutes and 56 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

📥 Commits

Reviewing files that changed from the base of the PR and between 3dcc92e and 48acfcd.

📒 Files selected for processing (1)
  • platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
📝 Walkthrough

Walkthrough

Client UI now displays a read-only "eName" (synced from eVault) and a separate editable public username; client PATCH payload no longer includes handle. Server APIs and service layer no longer accept or update handle from the request—only name and avatar are applied.

Changes

Cohort / File(s)Summary
Settings Account Username Page
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
Replaced first username input with disabled "eName" field (label + helper text, bound to handle); kept editable public username bound to name; changed client PATCH payload to send only name and avatar (removed sending handle).
User Update Controller
platforms/pictique-api/src/controllers/UserController.ts
Removed reading handle from request body; controller now builds update payload from name and avatar only and no longer merges a provided handle or fetches/overwrites handle from req.body.
User Service
platforms/pictique-api/src/services/UserService.ts
Updated updateProfile signature to accept only { avatarUrl?: string; name?: string } and removed handling of handle updates in service logic.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (UI)
participant Server as API Server
participant Service as UserService
participant DB as Database
participant eVault as eVault (External)
rect rgba(200,220,255,0.5)
Client->>Server: GET /api/users/me
Server->>Service: fetch current user
Service->>DB: SELECT user
DB-->>Service: user { id, name, handle, avatarUrl }
Service-->>Server: user
Server-->>Client: user payload (eName = handle)
end
rect rgba(200,255,200,0.5)
Note over eVault,DB: handle/eName is maintained by eVault sync (external)
end
rect rgba(255,240,200,0.5)
Client->>Server: PATCH /api/users { name, avatar } (no handle)
Server->>Service: updateProfile(userId, { name, avatarUrl })
Service->>DB: UPDATE users SET name=?, avatarUrl=? WHERE id=?
DB-->>Service: updated user
Service-->>Server: updated user
Server-->>Client: updated user payload
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • Fix/author details #229 — Modifies the same settings/account/username page and related profile-save behavior (related client-side changes around sending handle).

Suggested reviewers

  • coodos

Poem

🐰 I nibble tokens, tidy and spry,
eName sits quiet, read-only sky,
Public name hops, free to roam,
Handle stays snug, back in its home,
A tiny change — a tidy byte of sky.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: prohibiting eName updates in Pictique by removing the handle field from client and server code.
Description check✅ PassedThe description follows the template structure with all required sections completed: change description, issue number, type of change, testing method, and completed checklist.
Linked Issues check✅ PassedChanges fully address issue #247 requirements: handle/eName is now prohibited from being updated, and the UI field has been renamed to 'eName' with disabled input.
Out of Scope Changes check✅ PassedAll changes are directly scoped to issue #247: removing handle from the update payload, disabling the eName field UI, and updating service/controller signatures.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

eName == w3id == handle in this case, updating the user's real Name is fine, the username aka the UUID is not

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/pictique-api/src/controllers/UserController.ts`:
- Around line 181-187: If this.userService.findById(userId) can return null and
you must not clobber eVault-synced handle, first guard for a missing user and
return a 404 (or throw) before calling updateProfile; do not include handle:
user?.handle in the payload—only pass fields that should be updated (e.g.,
avatarUrl: avatar ?? user.avatarUrl, name: name ?? user.name) so updateProfile
cannot overwrite a newer handle, or ensure updateProfile explicitly ignores
handle if present; reference the findById call and the updateProfile invocation
in UserController.
🧹 Nitpick comments (1)
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte (1)

85-91: Consider readonly instead of disabled for eName.

Disabled fields are not focusable or copyable; readonly keeps the text selectable and improves accessibility while still preventing edits.

Proposed tweak
- <Input type="text" placeholder="Your eName" bind:value={handle} disabled class="cursor-not-allowed opacity-70" />+ <Input+ type="text"+ placeholder="Your eName"+ bind:value={handle}+ readonly+ aria-readonly="true"+ class="cursor-not-allowed opacity-70"+ />

Comment on lines 181 to 187
const user = await this.userService.findById(userId);

// Note: handle is not updatable to preserve eVault sync
const updatedUser = await this.userService.updateProfile(userId, {
handle: handle ?? user?.handle,
handle: user?.handle,
avatarUrl: avatar ?? user?.avatarUrl,
name: name ?? user?.name,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Avoid clobbering eName and guard missing user.

If findById returns null, the update may write undefined values. Also, writing handle: user?.handle can overwrite a newer eVault-synced handle between read and update. Prefer a 404 guard and omit handle from the update payload (or ensure the service ignores it).

Proposed fix
- const user = await this.userService.findById(userId);+ const user = await this.userService.findById(userId);+ if (!user) {+ return res.status(404).json({ error: "User not found" });+ }- // Note: handle is not updatable to preserve eVault sync+ // Note: handle is not updatable to preserve eVault sync (omit from update payload)
const updatedUser = await this.userService.updateProfile(userId, {
- handle: user?.handle,- avatarUrl: avatar ?? user?.avatarUrl,- name: name ?? user?.name,+ avatarUrl: avatar ?? user.avatarUrl,+ name: name ?? user.name,
});
🤖 Prompt for AI Agents
In `@platforms/pictique-api/src/controllers/UserController.ts` around lines 181 -
187, If this.userService.findById(userId) can return null and you must not
clobber eVault-synced handle, first guard for a missing user and return a 404
(or throw) before calling updateProfile; do not include handle: user?.handle in
the payload—only pass fields that should be updated (e.g., avatarUrl: avatar ??
user.avatarUrl, name: name ?? user.name) so updateProfile cannot overwrite a
newer handle, or ensure updateProfile explicitly ignores handle if present;
reference the findById call and the updateProfile invocation in UserController.

@coodos
coodos merged commit b29d2d7 into mainJan 19, 2026
4 checks passed
@coodos
coodos deleted the fix/remove-pictique-account-name-update branch January 19, 2026 10:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pictique allows to change my eName. Can we (1) prohibit it and (2) rename this field to eName?

2 participants

@sosweetham@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: prohibit ename update pictique - #684

Merged
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update
Jan 19, 2026
Merged

fix: prohibit ename update pictique#684
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update

Conversation

@sosweetham

@sosweethamsosweetham commented Jan 19, 2026

Copy link
Copy Markdown
Member

Description of change

remove client side pictique "name" update code to reduce confusion with ename updation (default name)

Issue Number

closes#247

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added eName field in account settings displaying your eVault real name (read-only, auto‑synced)
    • Public username field relabeled to "Change your username" and remains editable
  • Bug Fixes

    • Profile updates now only send name and avatar to the server
    • Handle/eName is no longer editable from settings to ensure consistent syncing with eVault

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 19, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 8 minutes and 56 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

📥 Commits

Reviewing files that changed from the base of the PR and between 3dcc92e and 48acfcd.

📒 Files selected for processing (1)
  • platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
📝 Walkthrough

Walkthrough

Client UI now displays a read-only "eName" (synced from eVault) and a separate editable public username; client PATCH payload no longer includes handle. Server APIs and service layer no longer accept or update handle from the request—only name and avatar are applied.

Changes

Cohort / File(s)Summary
Settings Account Username Page
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
Replaced first username input with disabled "eName" field (label + helper text, bound to handle); kept editable public username bound to name; changed client PATCH payload to send only name and avatar (removed sending handle).
User Update Controller
platforms/pictique-api/src/controllers/UserController.ts
Removed reading handle from request body; controller now builds update payload from name and avatar only and no longer merges a provided handle or fetches/overwrites handle from req.body.
User Service
platforms/pictique-api/src/services/UserService.ts
Updated updateProfile signature to accept only { avatarUrl?: string; name?: string } and removed handling of handle updates in service logic.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (UI)
participant Server as API Server
participant Service as UserService
participant DB as Database
participant eVault as eVault (External)
rect rgba(200,220,255,0.5)
Client->>Server: GET /api/users/me
Server->>Service: fetch current user
Service->>DB: SELECT user
DB-->>Service: user { id, name, handle, avatarUrl }
Service-->>Server: user
Server-->>Client: user payload (eName = handle)
end
rect rgba(200,255,200,0.5)
Note over eVault,DB: handle/eName is maintained by eVault sync (external)
end
rect rgba(255,240,200,0.5)
Client->>Server: PATCH /api/users { name, avatar } (no handle)
Server->>Service: updateProfile(userId, { name, avatarUrl })
Service->>DB: UPDATE users SET name=?, avatarUrl=? WHERE id=?
DB-->>Service: updated user
Service-->>Server: updated user
Server-->>Client: updated user payload
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • Fix/author details #229 — Modifies the same settings/account/username page and related profile-save behavior (related client-side changes around sending handle).

Suggested reviewers

  • coodos

Poem

🐰 I nibble tokens, tidy and spry,
eName sits quiet, read-only sky,
Public name hops, free to roam,
Handle stays snug, back in its home,
A tiny change — a tidy byte of sky.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: prohibiting eName updates in Pictique by removing the handle field from client and server code.
Description check✅ PassedThe description follows the template structure with all required sections completed: change description, issue number, type of change, testing method, and completed checklist.
Linked Issues check✅ PassedChanges fully address issue #247 requirements: handle/eName is now prohibited from being updated, and the UI field has been renamed to 'eName' with disabled input.
Out of Scope Changes check✅ PassedAll changes are directly scoped to issue #247: removing handle from the update payload, disabling the eName field UI, and updating service/controller signatures.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

eName == w3id == handle in this case, updating the user's real Name is fine, the username aka the UUID is not

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/pictique-api/src/controllers/UserController.ts`:
- Around line 181-187: If this.userService.findById(userId) can return null and
you must not clobber eVault-synced handle, first guard for a missing user and
return a 404 (or throw) before calling updateProfile; do not include handle:
user?.handle in the payload—only pass fields that should be updated (e.g.,
avatarUrl: avatar ?? user.avatarUrl, name: name ?? user.name) so updateProfile
cannot overwrite a newer handle, or ensure updateProfile explicitly ignores
handle if present; reference the findById call and the updateProfile invocation
in UserController.
🧹 Nitpick comments (1)
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte (1)

85-91: Consider readonly instead of disabled for eName.

Disabled fields are not focusable or copyable; readonly keeps the text selectable and improves accessibility while still preventing edits.

Proposed tweak
- <Input type="text" placeholder="Your eName" bind:value={handle} disabled class="cursor-not-allowed opacity-70" />+ <Input+ type="text"+ placeholder="Your eName"+ bind:value={handle}+ readonly+ aria-readonly="true"+ class="cursor-not-allowed opacity-70"+ />

Comment on lines 181 to 187
const user = await this.userService.findById(userId);

// Note: handle is not updatable to preserve eVault sync
const updatedUser = await this.userService.updateProfile(userId, {
handle: handle ?? user?.handle,
handle: user?.handle,
avatarUrl: avatar ?? user?.avatarUrl,
name: name ?? user?.name,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Avoid clobbering eName and guard missing user.

If findById returns null, the update may write undefined values. Also, writing handle: user?.handle can overwrite a newer eVault-synced handle between read and update. Prefer a 404 guard and omit handle from the update payload (or ensure the service ignores it).

Proposed fix
- const user = await this.userService.findById(userId);+ const user = await this.userService.findById(userId);+ if (!user) {+ return res.status(404).json({ error: "User not found" });+ }- // Note: handle is not updatable to preserve eVault sync+ // Note: handle is not updatable to preserve eVault sync (omit from update payload)
const updatedUser = await this.userService.updateProfile(userId, {
- handle: user?.handle,- avatarUrl: avatar ?? user?.avatarUrl,- name: name ?? user?.name,+ avatarUrl: avatar ?? user.avatarUrl,+ name: name ?? user.name,
});
🤖 Prompt for AI Agents
In `@platforms/pictique-api/src/controllers/UserController.ts` around lines 181 -
187, If this.userService.findById(userId) can return null and you must not
clobber eVault-synced handle, first guard for a missing user and return a 404
(or throw) before calling updateProfile; do not include handle: user?.handle in
the payload—only pass fields that should be updated (e.g., avatarUrl: avatar ??
user.avatarUrl, name: name ?? user.name) so updateProfile cannot overwrite a
newer handle, or ensure updateProfile explicitly ignores handle if present;
reference the findById call and the updateProfile invocation in UserController.

@coodos
coodos merged commit b29d2d7 into mainJan 19, 2026
4 checks passed
@coodos
coodos deleted the fix/remove-pictique-account-name-update branch January 19, 2026 10:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pictique allows to change my eName. Can we (1) prohibit it and (2) rename this field to eName?

2 participants

@sosweetham@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: prohibit ename update pictique - #684

Merged
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update
Jan 19, 2026
Merged

fix: prohibit ename update pictique#684
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update

Conversation

@sosweetham

@sosweethamsosweetham commented Jan 19, 2026

Copy link
Copy Markdown
Member

Description of change

remove client side pictique "name" update code to reduce confusion with ename updation (default name)

Issue Number

closes#247

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added eName field in account settings displaying your eVault real name (read-only, auto‑synced)
    • Public username field relabeled to "Change your username" and remains editable
  • Bug Fixes

    • Profile updates now only send name and avatar to the server
    • Handle/eName is no longer editable from settings to ensure consistent syncing with eVault

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 19, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 8 minutes and 56 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

📥 Commits

Reviewing files that changed from the base of the PR and between 3dcc92e and 48acfcd.

📒 Files selected for processing (1)
  • platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
📝 Walkthrough

Walkthrough

Client UI now displays a read-only "eName" (synced from eVault) and a separate editable public username; client PATCH payload no longer includes handle. Server APIs and service layer no longer accept or update handle from the request—only name and avatar are applied.

Changes

Cohort / File(s)Summary
Settings Account Username Page
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
Replaced first username input with disabled "eName" field (label + helper text, bound to handle); kept editable public username bound to name; changed client PATCH payload to send only name and avatar (removed sending handle).
User Update Controller
platforms/pictique-api/src/controllers/UserController.ts
Removed reading handle from request body; controller now builds update payload from name and avatar only and no longer merges a provided handle or fetches/overwrites handle from req.body.
User Service
platforms/pictique-api/src/services/UserService.ts
Updated updateProfile signature to accept only { avatarUrl?: string; name?: string } and removed handling of handle updates in service logic.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (UI)
participant Server as API Server
participant Service as UserService
participant DB as Database
participant eVault as eVault (External)
rect rgba(200,220,255,0.5)
Client->>Server: GET /api/users/me
Server->>Service: fetch current user
Service->>DB: SELECT user
DB-->>Service: user { id, name, handle, avatarUrl }
Service-->>Server: user
Server-->>Client: user payload (eName = handle)
end
rect rgba(200,255,200,0.5)
Note over eVault,DB: handle/eName is maintained by eVault sync (external)
end
rect rgba(255,240,200,0.5)
Client->>Server: PATCH /api/users { name, avatar } (no handle)
Server->>Service: updateProfile(userId, { name, avatarUrl })
Service->>DB: UPDATE users SET name=?, avatarUrl=? WHERE id=?
DB-->>Service: updated user
Service-->>Server: updated user
Server-->>Client: updated user payload
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • Fix/author details #229 — Modifies the same settings/account/username page and related profile-save behavior (related client-side changes around sending handle).

Suggested reviewers

  • coodos

Poem

🐰 I nibble tokens, tidy and spry,
eName sits quiet, read-only sky,
Public name hops, free to roam,
Handle stays snug, back in its home,
A tiny change — a tidy byte of sky.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: prohibiting eName updates in Pictique by removing the handle field from client and server code.
Description check✅ PassedThe description follows the template structure with all required sections completed: change description, issue number, type of change, testing method, and completed checklist.
Linked Issues check✅ PassedChanges fully address issue #247 requirements: handle/eName is now prohibited from being updated, and the UI field has been renamed to 'eName' with disabled input.
Out of Scope Changes check✅ PassedAll changes are directly scoped to issue #247: removing handle from the update payload, disabling the eName field UI, and updating service/controller signatures.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

eName == w3id == handle in this case, updating the user's real Name is fine, the username aka the UUID is not

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/pictique-api/src/controllers/UserController.ts`:
- Around line 181-187: If this.userService.findById(userId) can return null and
you must not clobber eVault-synced handle, first guard for a missing user and
return a 404 (or throw) before calling updateProfile; do not include handle:
user?.handle in the payload—only pass fields that should be updated (e.g.,
avatarUrl: avatar ?? user.avatarUrl, name: name ?? user.name) so updateProfile
cannot overwrite a newer handle, or ensure updateProfile explicitly ignores
handle if present; reference the findById call and the updateProfile invocation
in UserController.
🧹 Nitpick comments (1)
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte (1)

85-91: Consider readonly instead of disabled for eName.

Disabled fields are not focusable or copyable; readonly keeps the text selectable and improves accessibility while still preventing edits.

Proposed tweak
- <Input type="text" placeholder="Your eName" bind:value={handle} disabled class="cursor-not-allowed opacity-70" />+ <Input+ type="text"+ placeholder="Your eName"+ bind:value={handle}+ readonly+ aria-readonly="true"+ class="cursor-not-allowed opacity-70"+ />

Comment on lines 181 to 187
const user = await this.userService.findById(userId);

// Note: handle is not updatable to preserve eVault sync
const updatedUser = await this.userService.updateProfile(userId, {
handle: handle ?? user?.handle,
handle: user?.handle,
avatarUrl: avatar ?? user?.avatarUrl,
name: name ?? user?.name,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Avoid clobbering eName and guard missing user.

If findById returns null, the update may write undefined values. Also, writing handle: user?.handle can overwrite a newer eVault-synced handle between read and update. Prefer a 404 guard and omit handle from the update payload (or ensure the service ignores it).

Proposed fix
- const user = await this.userService.findById(userId);+ const user = await this.userService.findById(userId);+ if (!user) {+ return res.status(404).json({ error: "User not found" });+ }- // Note: handle is not updatable to preserve eVault sync+ // Note: handle is not updatable to preserve eVault sync (omit from update payload)
const updatedUser = await this.userService.updateProfile(userId, {
- handle: user?.handle,- avatarUrl: avatar ?? user?.avatarUrl,- name: name ?? user?.name,+ avatarUrl: avatar ?? user.avatarUrl,+ name: name ?? user.name,
});
🤖 Prompt for AI Agents
In `@platforms/pictique-api/src/controllers/UserController.ts` around lines 181 -
187, If this.userService.findById(userId) can return null and you must not
clobber eVault-synced handle, first guard for a missing user and return a 404
(or throw) before calling updateProfile; do not include handle: user?.handle in
the payload—only pass fields that should be updated (e.g., avatarUrl: avatar ??
user.avatarUrl, name: name ?? user.name) so updateProfile cannot overwrite a
newer handle, or ensure updateProfile explicitly ignores handle if present;
reference the findById call and the updateProfile invocation in UserController.

@coodos
coodos merged commit b29d2d7 into mainJan 19, 2026
4 checks passed
@coodos
coodos deleted the fix/remove-pictique-account-name-update branch January 19, 2026 10:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pictique allows to change my eName. Can we (1) prohibit it and (2) rename this field to eName?

2 participants

@sosweetham@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: prohibit ename update pictique - #684

Merged
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update
Jan 19, 2026
Merged

fix: prohibit ename update pictique#684
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update

Conversation

@sosweetham

@sosweethamsosweetham commented Jan 19, 2026

Copy link
Copy Markdown
Member

Description of change

remove client side pictique "name" update code to reduce confusion with ename updation (default name)

Issue Number

closes#247

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added eName field in account settings displaying your eVault real name (read-only, auto‑synced)
    • Public username field relabeled to "Change your username" and remains editable
  • Bug Fixes

    • Profile updates now only send name and avatar to the server
    • Handle/eName is no longer editable from settings to ensure consistent syncing with eVault

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 19, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 8 minutes and 56 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

📥 Commits

Reviewing files that changed from the base of the PR and between 3dcc92e and 48acfcd.

📒 Files selected for processing (1)
  • platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
📝 Walkthrough

Walkthrough

Client UI now displays a read-only "eName" (synced from eVault) and a separate editable public username; client PATCH payload no longer includes handle. Server APIs and service layer no longer accept or update handle from the request—only name and avatar are applied.

Changes

Cohort / File(s)Summary
Settings Account Username Page
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
Replaced first username input with disabled "eName" field (label + helper text, bound to handle); kept editable public username bound to name; changed client PATCH payload to send only name and avatar (removed sending handle).
User Update Controller
platforms/pictique-api/src/controllers/UserController.ts
Removed reading handle from request body; controller now builds update payload from name and avatar only and no longer merges a provided handle or fetches/overwrites handle from req.body.
User Service
platforms/pictique-api/src/services/UserService.ts
Updated updateProfile signature to accept only { avatarUrl?: string; name?: string } and removed handling of handle updates in service logic.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (UI)
participant Server as API Server
participant Service as UserService
participant DB as Database
participant eVault as eVault (External)
rect rgba(200,220,255,0.5)
Client->>Server: GET /api/users/me
Server->>Service: fetch current user
Service->>DB: SELECT user
DB-->>Service: user { id, name, handle, avatarUrl }
Service-->>Server: user
Server-->>Client: user payload (eName = handle)
end
rect rgba(200,255,200,0.5)
Note over eVault,DB: handle/eName is maintained by eVault sync (external)
end
rect rgba(255,240,200,0.5)
Client->>Server: PATCH /api/users { name, avatar } (no handle)
Server->>Service: updateProfile(userId, { name, avatarUrl })
Service->>DB: UPDATE users SET name=?, avatarUrl=? WHERE id=?
DB-->>Service: updated user
Service-->>Server: updated user
Server-->>Client: updated user payload
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • Fix/author details #229 — Modifies the same settings/account/username page and related profile-save behavior (related client-side changes around sending handle).

Suggested reviewers

  • coodos

Poem

🐰 I nibble tokens, tidy and spry,
eName sits quiet, read-only sky,
Public name hops, free to roam,
Handle stays snug, back in its home,
A tiny change — a tidy byte of sky.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: prohibiting eName updates in Pictique by removing the handle field from client and server code.
Description check✅ PassedThe description follows the template structure with all required sections completed: change description, issue number, type of change, testing method, and completed checklist.
Linked Issues check✅ PassedChanges fully address issue #247 requirements: handle/eName is now prohibited from being updated, and the UI field has been renamed to 'eName' with disabled input.
Out of Scope Changes check✅ PassedAll changes are directly scoped to issue #247: removing handle from the update payload, disabling the eName field UI, and updating service/controller signatures.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

eName == w3id == handle in this case, updating the user's real Name is fine, the username aka the UUID is not

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/pictique-api/src/controllers/UserController.ts`:
- Around line 181-187: If this.userService.findById(userId) can return null and
you must not clobber eVault-synced handle, first guard for a missing user and
return a 404 (or throw) before calling updateProfile; do not include handle:
user?.handle in the payload—only pass fields that should be updated (e.g.,
avatarUrl: avatar ?? user.avatarUrl, name: name ?? user.name) so updateProfile
cannot overwrite a newer handle, or ensure updateProfile explicitly ignores
handle if present; reference the findById call and the updateProfile invocation
in UserController.
🧹 Nitpick comments (1)
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte (1)

85-91: Consider readonly instead of disabled for eName.

Disabled fields are not focusable or copyable; readonly keeps the text selectable and improves accessibility while still preventing edits.

Proposed tweak
- <Input type="text" placeholder="Your eName" bind:value={handle} disabled class="cursor-not-allowed opacity-70" />+ <Input+ type="text"+ placeholder="Your eName"+ bind:value={handle}+ readonly+ aria-readonly="true"+ class="cursor-not-allowed opacity-70"+ />

Comment on lines 181 to 187
const user = await this.userService.findById(userId);

// Note: handle is not updatable to preserve eVault sync
const updatedUser = await this.userService.updateProfile(userId, {
handle: handle ?? user?.handle,
handle: user?.handle,
avatarUrl: avatar ?? user?.avatarUrl,
name: name ?? user?.name,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Avoid clobbering eName and guard missing user.

If findById returns null, the update may write undefined values. Also, writing handle: user?.handle can overwrite a newer eVault-synced handle between read and update. Prefer a 404 guard and omit handle from the update payload (or ensure the service ignores it).

Proposed fix
- const user = await this.userService.findById(userId);+ const user = await this.userService.findById(userId);+ if (!user) {+ return res.status(404).json({ error: "User not found" });+ }- // Note: handle is not updatable to preserve eVault sync+ // Note: handle is not updatable to preserve eVault sync (omit from update payload)
const updatedUser = await this.userService.updateProfile(userId, {
- handle: user?.handle,- avatarUrl: avatar ?? user?.avatarUrl,- name: name ?? user?.name,+ avatarUrl: avatar ?? user.avatarUrl,+ name: name ?? user.name,
});
🤖 Prompt for AI Agents
In `@platforms/pictique-api/src/controllers/UserController.ts` around lines 181 -
187, If this.userService.findById(userId) can return null and you must not
clobber eVault-synced handle, first guard for a missing user and return a 404
(or throw) before calling updateProfile; do not include handle: user?.handle in
the payload—only pass fields that should be updated (e.g., avatarUrl: avatar ??
user.avatarUrl, name: name ?? user.name) so updateProfile cannot overwrite a
newer handle, or ensure updateProfile explicitly ignores handle if present;
reference the findById call and the updateProfile invocation in UserController.

@coodos
coodos merged commit b29d2d7 into mainJan 19, 2026
4 checks passed
@coodos
coodos deleted the fix/remove-pictique-account-name-update branch January 19, 2026 10:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pictique allows to change my eName. Can we (1) prohibit it and (2) rename this field to eName?

2 participants

@sosweetham@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: prohibit ename update pictique - #684

Merged
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update
Jan 19, 2026
Merged

fix: prohibit ename update pictique#684
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update

Conversation

@sosweetham

@sosweethamsosweetham commented Jan 19, 2026

Copy link
Copy Markdown
Member

Description of change

remove client side pictique "name" update code to reduce confusion with ename updation (default name)

Issue Number

closes#247

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added eName field in account settings displaying your eVault real name (read-only, auto‑synced)
    • Public username field relabeled to "Change your username" and remains editable
  • Bug Fixes

    • Profile updates now only send name and avatar to the server
    • Handle/eName is no longer editable from settings to ensure consistent syncing with eVault

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 19, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 8 minutes and 56 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

📥 Commits

Reviewing files that changed from the base of the PR and between 3dcc92e and 48acfcd.

📒 Files selected for processing (1)
  • platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
📝 Walkthrough

Walkthrough

Client UI now displays a read-only "eName" (synced from eVault) and a separate editable public username; client PATCH payload no longer includes handle. Server APIs and service layer no longer accept or update handle from the request—only name and avatar are applied.

Changes

Cohort / File(s)Summary
Settings Account Username Page
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
Replaced first username input with disabled "eName" field (label + helper text, bound to handle); kept editable public username bound to name; changed client PATCH payload to send only name and avatar (removed sending handle).
User Update Controller
platforms/pictique-api/src/controllers/UserController.ts
Removed reading handle from request body; controller now builds update payload from name and avatar only and no longer merges a provided handle or fetches/overwrites handle from req.body.
User Service
platforms/pictique-api/src/services/UserService.ts
Updated updateProfile signature to accept only { avatarUrl?: string; name?: string } and removed handling of handle updates in service logic.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (UI)
participant Server as API Server
participant Service as UserService
participant DB as Database
participant eVault as eVault (External)
rect rgba(200,220,255,0.5)
Client->>Server: GET /api/users/me
Server->>Service: fetch current user
Service->>DB: SELECT user
DB-->>Service: user { id, name, handle, avatarUrl }
Service-->>Server: user
Server-->>Client: user payload (eName = handle)
end
rect rgba(200,255,200,0.5)
Note over eVault,DB: handle/eName is maintained by eVault sync (external)
end
rect rgba(255,240,200,0.5)
Client->>Server: PATCH /api/users { name, avatar } (no handle)
Server->>Service: updateProfile(userId, { name, avatarUrl })
Service->>DB: UPDATE users SET name=?, avatarUrl=? WHERE id=?
DB-->>Service: updated user
Service-->>Server: updated user
Server-->>Client: updated user payload
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • Fix/author details #229 — Modifies the same settings/account/username page and related profile-save behavior (related client-side changes around sending handle).

Suggested reviewers

  • coodos

Poem

🐰 I nibble tokens, tidy and spry,
eName sits quiet, read-only sky,
Public name hops, free to roam,
Handle stays snug, back in its home,
A tiny change — a tidy byte of sky.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: prohibiting eName updates in Pictique by removing the handle field from client and server code.
Description check✅ PassedThe description follows the template structure with all required sections completed: change description, issue number, type of change, testing method, and completed checklist.
Linked Issues check✅ PassedChanges fully address issue #247 requirements: handle/eName is now prohibited from being updated, and the UI field has been renamed to 'eName' with disabled input.
Out of Scope Changes check✅ PassedAll changes are directly scoped to issue #247: removing handle from the update payload, disabling the eName field UI, and updating service/controller signatures.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

eName == w3id == handle in this case, updating the user's real Name is fine, the username aka the UUID is not

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/pictique-api/src/controllers/UserController.ts`:
- Around line 181-187: If this.userService.findById(userId) can return null and
you must not clobber eVault-synced handle, first guard for a missing user and
return a 404 (or throw) before calling updateProfile; do not include handle:
user?.handle in the payload—only pass fields that should be updated (e.g.,
avatarUrl: avatar ?? user.avatarUrl, name: name ?? user.name) so updateProfile
cannot overwrite a newer handle, or ensure updateProfile explicitly ignores
handle if present; reference the findById call and the updateProfile invocation
in UserController.
🧹 Nitpick comments (1)
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte (1)

85-91: Consider readonly instead of disabled for eName.

Disabled fields are not focusable or copyable; readonly keeps the text selectable and improves accessibility while still preventing edits.

Proposed tweak
- <Input type="text" placeholder="Your eName" bind:value={handle} disabled class="cursor-not-allowed opacity-70" />+ <Input+ type="text"+ placeholder="Your eName"+ bind:value={handle}+ readonly+ aria-readonly="true"+ class="cursor-not-allowed opacity-70"+ />

Comment on lines 181 to 187
const user = await this.userService.findById(userId);

// Note: handle is not updatable to preserve eVault sync
const updatedUser = await this.userService.updateProfile(userId, {
handle: handle ?? user?.handle,
handle: user?.handle,
avatarUrl: avatar ?? user?.avatarUrl,
name: name ?? user?.name,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Avoid clobbering eName and guard missing user.

If findById returns null, the update may write undefined values. Also, writing handle: user?.handle can overwrite a newer eVault-synced handle between read and update. Prefer a 404 guard and omit handle from the update payload (or ensure the service ignores it).

Proposed fix
- const user = await this.userService.findById(userId);+ const user = await this.userService.findById(userId);+ if (!user) {+ return res.status(404).json({ error: "User not found" });+ }- // Note: handle is not updatable to preserve eVault sync+ // Note: handle is not updatable to preserve eVault sync (omit from update payload)
const updatedUser = await this.userService.updateProfile(userId, {
- handle: user?.handle,- avatarUrl: avatar ?? user?.avatarUrl,- name: name ?? user?.name,+ avatarUrl: avatar ?? user.avatarUrl,+ name: name ?? user.name,
});
🤖 Prompt for AI Agents
In `@platforms/pictique-api/src/controllers/UserController.ts` around lines 181 -
187, If this.userService.findById(userId) can return null and you must not
clobber eVault-synced handle, first guard for a missing user and return a 404
(or throw) before calling updateProfile; do not include handle: user?.handle in
the payload—only pass fields that should be updated (e.g., avatarUrl: avatar ??
user.avatarUrl, name: name ?? user.name) so updateProfile cannot overwrite a
newer handle, or ensure updateProfile explicitly ignores handle if present;
reference the findById call and the updateProfile invocation in UserController.

@coodos
coodos merged commit b29d2d7 into mainJan 19, 2026
4 checks passed
@coodos
coodos deleted the fix/remove-pictique-account-name-update branch January 19, 2026 10:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pictique allows to change my eName. Can we (1) prohibit it and (2) rename this field to eName?

2 participants

@sosweetham@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: prohibit ename update pictique - #684

Merged
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update
Jan 19, 2026
Merged

fix: prohibit ename update pictique#684
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update

Conversation

@sosweetham

@sosweethamsosweetham commented Jan 19, 2026

Copy link
Copy Markdown
Member

Description of change

remove client side pictique "name" update code to reduce confusion with ename updation (default name)

Issue Number

closes#247

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added eName field in account settings displaying your eVault real name (read-only, auto‑synced)
    • Public username field relabeled to "Change your username" and remains editable
  • Bug Fixes

    • Profile updates now only send name and avatar to the server
    • Handle/eName is no longer editable from settings to ensure consistent syncing with eVault

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 19, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 8 minutes and 56 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

📥 Commits

Reviewing files that changed from the base of the PR and between 3dcc92e and 48acfcd.

📒 Files selected for processing (1)
  • platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
📝 Walkthrough

Walkthrough

Client UI now displays a read-only "eName" (synced from eVault) and a separate editable public username; client PATCH payload no longer includes handle. Server APIs and service layer no longer accept or update handle from the request—only name and avatar are applied.

Changes

Cohort / File(s)Summary
Settings Account Username Page
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
Replaced first username input with disabled "eName" field (label + helper text, bound to handle); kept editable public username bound to name; changed client PATCH payload to send only name and avatar (removed sending handle).
User Update Controller
platforms/pictique-api/src/controllers/UserController.ts
Removed reading handle from request body; controller now builds update payload from name and avatar only and no longer merges a provided handle or fetches/overwrites handle from req.body.
User Service
platforms/pictique-api/src/services/UserService.ts
Updated updateProfile signature to accept only { avatarUrl?: string; name?: string } and removed handling of handle updates in service logic.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (UI)
participant Server as API Server
participant Service as UserService
participant DB as Database
participant eVault as eVault (External)
rect rgba(200,220,255,0.5)
Client->>Server: GET /api/users/me
Server->>Service: fetch current user
Service->>DB: SELECT user
DB-->>Service: user { id, name, handle, avatarUrl }
Service-->>Server: user
Server-->>Client: user payload (eName = handle)
end
rect rgba(200,255,200,0.5)
Note over eVault,DB: handle/eName is maintained by eVault sync (external)
end
rect rgba(255,240,200,0.5)
Client->>Server: PATCH /api/users { name, avatar } (no handle)
Server->>Service: updateProfile(userId, { name, avatarUrl })
Service->>DB: UPDATE users SET name=?, avatarUrl=? WHERE id=?
DB-->>Service: updated user
Service-->>Server: updated user
Server-->>Client: updated user payload
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • Fix/author details #229 — Modifies the same settings/account/username page and related profile-save behavior (related client-side changes around sending handle).

Suggested reviewers

  • coodos

Poem

🐰 I nibble tokens, tidy and spry,
eName sits quiet, read-only sky,
Public name hops, free to roam,
Handle stays snug, back in its home,
A tiny change — a tidy byte of sky.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: prohibiting eName updates in Pictique by removing the handle field from client and server code.
Description check✅ PassedThe description follows the template structure with all required sections completed: change description, issue number, type of change, testing method, and completed checklist.
Linked Issues check✅ PassedChanges fully address issue #247 requirements: handle/eName is now prohibited from being updated, and the UI field has been renamed to 'eName' with disabled input.
Out of Scope Changes check✅ PassedAll changes are directly scoped to issue #247: removing handle from the update payload, disabling the eName field UI, and updating service/controller signatures.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

eName == w3id == handle in this case, updating the user's real Name is fine, the username aka the UUID is not

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/pictique-api/src/controllers/UserController.ts`:
- Around line 181-187: If this.userService.findById(userId) can return null and
you must not clobber eVault-synced handle, first guard for a missing user and
return a 404 (or throw) before calling updateProfile; do not include handle:
user?.handle in the payload—only pass fields that should be updated (e.g.,
avatarUrl: avatar ?? user.avatarUrl, name: name ?? user.name) so updateProfile
cannot overwrite a newer handle, or ensure updateProfile explicitly ignores
handle if present; reference the findById call and the updateProfile invocation
in UserController.
🧹 Nitpick comments (1)
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte (1)

85-91: Consider readonly instead of disabled for eName.

Disabled fields are not focusable or copyable; readonly keeps the text selectable and improves accessibility while still preventing edits.

Proposed tweak
- <Input type="text" placeholder="Your eName" bind:value={handle} disabled class="cursor-not-allowed opacity-70" />+ <Input+ type="text"+ placeholder="Your eName"+ bind:value={handle}+ readonly+ aria-readonly="true"+ class="cursor-not-allowed opacity-70"+ />

Comment on lines 181 to 187
const user = await this.userService.findById(userId);

// Note: handle is not updatable to preserve eVault sync
const updatedUser = await this.userService.updateProfile(userId, {
handle: handle ?? user?.handle,
handle: user?.handle,
avatarUrl: avatar ?? user?.avatarUrl,
name: name ?? user?.name,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Avoid clobbering eName and guard missing user.

If findById returns null, the update may write undefined values. Also, writing handle: user?.handle can overwrite a newer eVault-synced handle between read and update. Prefer a 404 guard and omit handle from the update payload (or ensure the service ignores it).

Proposed fix
- const user = await this.userService.findById(userId);+ const user = await this.userService.findById(userId);+ if (!user) {+ return res.status(404).json({ error: "User not found" });+ }- // Note: handle is not updatable to preserve eVault sync+ // Note: handle is not updatable to preserve eVault sync (omit from update payload)
const updatedUser = await this.userService.updateProfile(userId, {
- handle: user?.handle,- avatarUrl: avatar ?? user?.avatarUrl,- name: name ?? user?.name,+ avatarUrl: avatar ?? user.avatarUrl,+ name: name ?? user.name,
});
🤖 Prompt for AI Agents
In `@platforms/pictique-api/src/controllers/UserController.ts` around lines 181 -
187, If this.userService.findById(userId) can return null and you must not
clobber eVault-synced handle, first guard for a missing user and return a 404
(or throw) before calling updateProfile; do not include handle: user?.handle in
the payload—only pass fields that should be updated (e.g., avatarUrl: avatar ??
user.avatarUrl, name: name ?? user.name) so updateProfile cannot overwrite a
newer handle, or ensure updateProfile explicitly ignores handle if present;
reference the findById call and the updateProfile invocation in UserController.

@coodos
coodos merged commit b29d2d7 into mainJan 19, 2026
4 checks passed
@coodos
coodos deleted the fix/remove-pictique-account-name-update branch January 19, 2026 10:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pictique allows to change my eName. Can we (1) prohibit it and (2) rename this field to eName?

2 participants

@sosweetham@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: prohibit ename update pictique - #684

Merged
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update
Jan 19, 2026
Merged

fix: prohibit ename update pictique#684
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update

Conversation

@sosweetham

@sosweethamsosweetham commented Jan 19, 2026

Copy link
Copy Markdown
Member

Description of change

remove client side pictique "name" update code to reduce confusion with ename updation (default name)

Issue Number

closes#247

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added eName field in account settings displaying your eVault real name (read-only, auto‑synced)
    • Public username field relabeled to "Change your username" and remains editable
  • Bug Fixes

    • Profile updates now only send name and avatar to the server
    • Handle/eName is no longer editable from settings to ensure consistent syncing with eVault

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 19, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 8 minutes and 56 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

📥 Commits

Reviewing files that changed from the base of the PR and between 3dcc92e and 48acfcd.

📒 Files selected for processing (1)
  • platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
📝 Walkthrough

Walkthrough

Client UI now displays a read-only "eName" (synced from eVault) and a separate editable public username; client PATCH payload no longer includes handle. Server APIs and service layer no longer accept or update handle from the request—only name and avatar are applied.

Changes

Cohort / File(s)Summary
Settings Account Username Page
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
Replaced first username input with disabled "eName" field (label + helper text, bound to handle); kept editable public username bound to name; changed client PATCH payload to send only name and avatar (removed sending handle).
User Update Controller
platforms/pictique-api/src/controllers/UserController.ts
Removed reading handle from request body; controller now builds update payload from name and avatar only and no longer merges a provided handle or fetches/overwrites handle from req.body.
User Service
platforms/pictique-api/src/services/UserService.ts
Updated updateProfile signature to accept only { avatarUrl?: string; name?: string } and removed handling of handle updates in service logic.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (UI)
participant Server as API Server
participant Service as UserService
participant DB as Database
participant eVault as eVault (External)
rect rgba(200,220,255,0.5)
Client->>Server: GET /api/users/me
Server->>Service: fetch current user
Service->>DB: SELECT user
DB-->>Service: user { id, name, handle, avatarUrl }
Service-->>Server: user
Server-->>Client: user payload (eName = handle)
end
rect rgba(200,255,200,0.5)
Note over eVault,DB: handle/eName is maintained by eVault sync (external)
end
rect rgba(255,240,200,0.5)
Client->>Server: PATCH /api/users { name, avatar } (no handle)
Server->>Service: updateProfile(userId, { name, avatarUrl })
Service->>DB: UPDATE users SET name=?, avatarUrl=? WHERE id=?
DB-->>Service: updated user
Service-->>Server: updated user
Server-->>Client: updated user payload
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • Fix/author details #229 — Modifies the same settings/account/username page and related profile-save behavior (related client-side changes around sending handle).

Suggested reviewers

  • coodos

Poem

🐰 I nibble tokens, tidy and spry,
eName sits quiet, read-only sky,
Public name hops, free to roam,
Handle stays snug, back in its home,
A tiny change — a tidy byte of sky.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: prohibiting eName updates in Pictique by removing the handle field from client and server code.
Description check✅ PassedThe description follows the template structure with all required sections completed: change description, issue number, type of change, testing method, and completed checklist.
Linked Issues check✅ PassedChanges fully address issue #247 requirements: handle/eName is now prohibited from being updated, and the UI field has been renamed to 'eName' with disabled input.
Out of Scope Changes check✅ PassedAll changes are directly scoped to issue #247: removing handle from the update payload, disabling the eName field UI, and updating service/controller signatures.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

eName == w3id == handle in this case, updating the user's real Name is fine, the username aka the UUID is not

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/pictique-api/src/controllers/UserController.ts`:
- Around line 181-187: If this.userService.findById(userId) can return null and
you must not clobber eVault-synced handle, first guard for a missing user and
return a 404 (or throw) before calling updateProfile; do not include handle:
user?.handle in the payload—only pass fields that should be updated (e.g.,
avatarUrl: avatar ?? user.avatarUrl, name: name ?? user.name) so updateProfile
cannot overwrite a newer handle, or ensure updateProfile explicitly ignores
handle if present; reference the findById call and the updateProfile invocation
in UserController.
🧹 Nitpick comments (1)
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte (1)

85-91: Consider readonly instead of disabled for eName.

Disabled fields are not focusable or copyable; readonly keeps the text selectable and improves accessibility while still preventing edits.

Proposed tweak
- <Input type="text" placeholder="Your eName" bind:value={handle} disabled class="cursor-not-allowed opacity-70" />+ <Input+ type="text"+ placeholder="Your eName"+ bind:value={handle}+ readonly+ aria-readonly="true"+ class="cursor-not-allowed opacity-70"+ />

Comment on lines 181 to 187
const user = await this.userService.findById(userId);

// Note: handle is not updatable to preserve eVault sync
const updatedUser = await this.userService.updateProfile(userId, {
handle: handle ?? user?.handle,
handle: user?.handle,
avatarUrl: avatar ?? user?.avatarUrl,
name: name ?? user?.name,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Avoid clobbering eName and guard missing user.

If findById returns null, the update may write undefined values. Also, writing handle: user?.handle can overwrite a newer eVault-synced handle between read and update. Prefer a 404 guard and omit handle from the update payload (or ensure the service ignores it).

Proposed fix
- const user = await this.userService.findById(userId);+ const user = await this.userService.findById(userId);+ if (!user) {+ return res.status(404).json({ error: "User not found" });+ }- // Note: handle is not updatable to preserve eVault sync+ // Note: handle is not updatable to preserve eVault sync (omit from update payload)
const updatedUser = await this.userService.updateProfile(userId, {
- handle: user?.handle,- avatarUrl: avatar ?? user?.avatarUrl,- name: name ?? user?.name,+ avatarUrl: avatar ?? user.avatarUrl,+ name: name ?? user.name,
});
🤖 Prompt for AI Agents
In `@platforms/pictique-api/src/controllers/UserController.ts` around lines 181 -
187, If this.userService.findById(userId) can return null and you must not
clobber eVault-synced handle, first guard for a missing user and return a 404
(or throw) before calling updateProfile; do not include handle: user?.handle in
the payload—only pass fields that should be updated (e.g., avatarUrl: avatar ??
user.avatarUrl, name: name ?? user.name) so updateProfile cannot overwrite a
newer handle, or ensure updateProfile explicitly ignores handle if present;
reference the findById call and the updateProfile invocation in UserController.

@coodos
coodos merged commit b29d2d7 into mainJan 19, 2026
4 checks passed
@coodos
coodos deleted the fix/remove-pictique-account-name-update branch January 19, 2026 10:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pictique allows to change my eName. Can we (1) prohibit it and (2) rename this field to eName?

2 participants

@sosweetham@coodos
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: prohibit ename update pictique - #684

Merged
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update
Jan 19, 2026
Merged

fix: prohibit ename update pictique#684
coodos merged 5 commits into
mainfrom
fix/remove-pictique-account-name-update

Conversation

@sosweetham

@sosweethamsosweetham commented Jan 19, 2026

Copy link
Copy Markdown
Member

Description of change

remove client side pictique "name" update code to reduce confusion with ename updation (default name)

Issue Number

closes#247

Type of change

  • Fix (a change which fixes an issue)

How the change has been tested

manual

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

Summary by CodeRabbit

  • New Features

    • Added eName field in account settings displaying your eVault real name (read-only, auto‑synced)
    • Public username field relabeled to "Change your username" and remains editable
  • Bug Fixes

    • Profile updates now only send name and avatar to the server
    • Handle/eName is no longer editable from settings to ensure consistent syncing with eVault

✏️ Tip: You can customize this high-level summary in your review settings.

@coderabbitai

coderabbitaiBot commented Jan 19, 2026

Copy link
Copy Markdown
Contributor

Warning

Rate limit exceeded

@coodos has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 8 minutes and 56 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

📥 Commits

Reviewing files that changed from the base of the PR and between 3dcc92e and 48acfcd.

📒 Files selected for processing (1)
  • platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
📝 Walkthrough

Walkthrough

Client UI now displays a read-only "eName" (synced from eVault) and a separate editable public username; client PATCH payload no longer includes handle. Server APIs and service layer no longer accept or update handle from the request—only name and avatar are applied.

Changes

Cohort / File(s)Summary
Settings Account Username Page
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte
Replaced first username input with disabled "eName" field (label + helper text, bound to handle); kept editable public username bound to name; changed client PATCH payload to send only name and avatar (removed sending handle).
User Update Controller
platforms/pictique-api/src/controllers/UserController.ts
Removed reading handle from request body; controller now builds update payload from name and avatar only and no longer merges a provided handle or fetches/overwrites handle from req.body.
User Service
platforms/pictique-api/src/services/UserService.ts
Updated updateProfile signature to accept only { avatarUrl?: string; name?: string } and removed handling of handle updates in service logic.

Sequence Diagram(s)

sequenceDiagram
participant Client as Client (UI)
participant Server as API Server
participant Service as UserService
participant DB as Database
participant eVault as eVault (External)
rect rgba(200,220,255,0.5)
Client->>Server: GET /api/users/me
Server->>Service: fetch current user
Service->>DB: SELECT user
DB-->>Service: user { id, name, handle, avatarUrl }
Service-->>Server: user
Server-->>Client: user payload (eName = handle)
end
rect rgba(200,255,200,0.5)
Note over eVault,DB: handle/eName is maintained by eVault sync (external)
end
rect rgba(255,240,200,0.5)
Client->>Server: PATCH /api/users { name, avatar } (no handle)
Server->>Service: updateProfile(userId, { name, avatarUrl })
Service->>DB: UPDATE users SET name=?, avatarUrl=? WHERE id=?
DB-->>Service: updated user
Service-->>Server: updated user
Server-->>Client: updated user payload
end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • Fix/author details #229 — Modifies the same settings/account/username page and related profile-save behavior (related client-side changes around sending handle).

Suggested reviewers

  • coodos

Poem

🐰 I nibble tokens, tidy and spry,
eName sits quiet, read-only sky,
Public name hops, free to roam,
Handle stays snug, back in its home,
A tiny change — a tidy byte of sky.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title clearly summarizes the main change: prohibiting eName updates in Pictique by removing the handle field from client and server code.
Description check✅ PassedThe description follows the template structure with all required sections completed: change description, issue number, type of change, testing method, and completed checklist.
Linked Issues check✅ PassedChanges fully address issue #247 requirements: handle/eName is now prohibited from being updated, and the UI field has been renamed to 'eName' with disabled input.
Out of Scope Changes check✅ PassedAll changes are directly scoped to issue #247: removing handle from the update payload, disabling the eName field UI, and updating service/controller signatures.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coodoscoodos left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

eName == w3id == handle in this case, updating the user's real Name is fine, the username aka the UUID is not

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Fix all issues with AI agents
In `@platforms/pictique-api/src/controllers/UserController.ts`:
- Around line 181-187: If this.userService.findById(userId) can return null and
you must not clobber eVault-synced handle, first guard for a missing user and
return a 404 (or throw) before calling updateProfile; do not include handle:
user?.handle in the payload—only pass fields that should be updated (e.g.,
avatarUrl: avatar ?? user.avatarUrl, name: name ?? user.name) so updateProfile
cannot overwrite a newer handle, or ensure updateProfile explicitly ignores
handle if present; reference the findById call and the updateProfile invocation
in UserController.
🧹 Nitpick comments (1)
platforms/pictique/src/routes/(protected)/settings/account/username/+page.svelte (1)

85-91: Consider readonly instead of disabled for eName.

Disabled fields are not focusable or copyable; readonly keeps the text selectable and improves accessibility while still preventing edits.

Proposed tweak
- <Input type="text" placeholder="Your eName" bind:value={handle} disabled class="cursor-not-allowed opacity-70" />+ <Input+ type="text"+ placeholder="Your eName"+ bind:value={handle}+ readonly+ aria-readonly="true"+ class="cursor-not-allowed opacity-70"+ />

Comment on lines 181 to 187
const user = await this.userService.findById(userId);

// Note: handle is not updatable to preserve eVault sync
const updatedUser = await this.userService.updateProfile(userId, {
handle: handle ?? user?.handle,
handle: user?.handle,
avatarUrl: avatar ?? user?.avatarUrl,
name: name ?? user?.name,

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

Avoid clobbering eName and guard missing user.

If findById returns null, the update may write undefined values. Also, writing handle: user?.handle can overwrite a newer eVault-synced handle between read and update. Prefer a 404 guard and omit handle from the update payload (or ensure the service ignores it).

Proposed fix
- const user = await this.userService.findById(userId);+ const user = await this.userService.findById(userId);+ if (!user) {+ return res.status(404).json({ error: "User not found" });+ }- // Note: handle is not updatable to preserve eVault sync+ // Note: handle is not updatable to preserve eVault sync (omit from update payload)
const updatedUser = await this.userService.updateProfile(userId, {
- handle: user?.handle,- avatarUrl: avatar ?? user?.avatarUrl,- name: name ?? user?.name,+ avatarUrl: avatar ?? user.avatarUrl,+ name: name ?? user.name,
});
🤖 Prompt for AI Agents
In `@platforms/pictique-api/src/controllers/UserController.ts` around lines 181 -
187, If this.userService.findById(userId) can return null and you must not
clobber eVault-synced handle, first guard for a missing user and return a 404
(or throw) before calling updateProfile; do not include handle: user?.handle in
the payload—only pass fields that should be updated (e.g., avatarUrl: avatar ??
user.avatarUrl, name: name ?? user.name) so updateProfile cannot overwrite a
newer handle, or ensure updateProfile explicitly ignores handle if present;
reference the findById call and the updateProfile invocation in UserController.

@coodos
coodos merged commit b29d2d7 into mainJan 19, 2026
4 checks passed
@coodos
coodos deleted the fix/remove-pictique-account-name-update branch January 19, 2026 10:53
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pictique allows to change my eName. Can we (1) prohibit it and (2) rename this field to eName?

2 participants

@sosweetham@coodos