amber-backend/pb_migrations
Claude 8f2cb994ec The code has to choose the template, not the clock
Sharing a second set of paid accounts with friends means a second template,
and the route was not ready for one. It checked the code and then took the
most recently updated row:

  findRecordsByFilter("onboarding_template", "id != ''", "-updated", 1, 0)

With a single row that is invisible. With two it hands the family's
credentials to friends, or the reverse, decided purely by which row was
edited last, silently and with no error. status.html carried a comment
warning about exactly this: "never create a second".

So the code now selects the row, bound as a filter parameter rather than
concatenated. AMBER_INVITE_CODE becomes a fallback that opens the row
flagged isDefault, which means nobody halfway through setup broke and
Coolify needed no edit; once the family row has its own code the env var
stops mattering. A wrong code and a code with no row behind it give the
same 403, since telling them apart would confirm which codes exist.

Codes live on the rows rather than in more env vars, so a new group is one
row in the admin UI instead of a redeploy, and each code is revocable on its
own. The unique index is partial because PocketBase text fields default to
'' and SQLite calls two empty strings equal.

status.html read the template in three places, all by recency. They now go
through familyTemplate(), which selects on isDefault, so adding a friends
row cannot make the editor wander onto it or make account creation preload
the wrong group. Its one-click preload stays family-only; a group picker
there is left undone rather than half-built.

The website says "rodinný kód" in four places and friends are not family, so
that copy widens. The setup flow also offers "Mám kód" up front now: someone
Richard shares accounts with has nothing to buy, and walking them through
three price lists first would be actively misleading.

Verified against PocketBase 0.39.6 with two rows and friends as the most
recently updated, the state that used to break: each code resolved to its own
credentials, the legacy env code resolved to family via isDefault, wrong and
empty codes gave 403, a duplicate code was refused by the index, and
familyTemplate() returned family while -updated returned friends.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 21:35:46 +02:00
..
1752600000_init_accounts_schema.js feat: PocketBase backend + account/profile schema (epic #6, issue #9) 2026-07-15 20:22:45 +02:00
1784250000_sync_fields.js feat(schema): fields the client needs to sync watch state / watchlist / prefs 2026-07-17 16:20:38 +02:00
1785200000_addon_config.js feat(schema): encrypted addon-config collection (issue #20) 2026-07-18 02:14:40 +02:00
1786000000_device_auth.js feat(device-auth): codeless device sign-in backend (#12) 2026-07-19 14:36:15 +02:00
1786500000_releases.js Fix auto-update file gating: mark releases.file protected (#16) 2026-07-20 11:48:07 +02:00
1786500001_releases_protect_file.js Fix auto-update file gating: mark releases.file protected (#16) 2026-07-20 11:48:07 +02:00
1787000000_profile_max_rating.js Add profiles.maxRating for per-profile content tiers (#14) 2026-07-21 20:42:40 +02:00
1787500000_onboarding_template.js Family onboarding site: invite-gated signup, template config, /get/tv 2026-07-22 18:23:05 +02:00
1788000000_client_logs.js Add client_logs collection for background device diagnostics (feedback 2 §4) 2026-07-23 11:49:04 +02:00
1788500000_client_logs_flavor.js client_logs: add flavor, which PocketBase was silently discarding 2026-08-06 06:45:48 +02:00
1789000000_owner_created_accounts.js Accounts are owner-created, and one page manages the whole account 2026-08-07 01:54:25 +02:00
1789000001_users_rating_default.js Accounts are owner-created, and one page manages the whole account 2026-08-07 01:54:25 +02:00
1789500000_client_logs_tester.js client_logs.tester: mark our own sessions, not the family's 2026-08-08 20:54:12 +02:00
1790000000_client_logs_gitsha.js Dashboard: read the reports, and create accounts without the admin UI 2026-08-08 23:29:51 +02:00
1790500000_providers.js Tell a new viewer what to buy before asking them to fill in a form 2026-08-12 18:36:55 +02:00
1790500001_users_onboarding.js Tell a new viewer what to buy before asking them to fill in a form 2026-08-12 18:36:55 +02:00
1791000000_onboarding_template_codes.js The code has to choose the template, not the clock 2026-08-12 21:35:46 +02:00