fix(badges): open badge review access when no passcode is set
Badges without person_passcode are now viewable by anyone with the URL — open access is granted on badge load. Previously this was explicitly denied. The passcode entry form is only shown when the badge actually has a passcode configured. Auto-validate effect expanded to cover the no-passcode case. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -92,23 +92,29 @@ let passcode_checked = $state(false);
|
||||
let passcode_valid = $state(false);
|
||||
let passcode_error = $state('');
|
||||
|
||||
// Auto-validate URL passcode once badge is loaded
|
||||
// Once the badge loads: grant open access if no passcode is set, or auto-validate URL passcode.
|
||||
$effect(() => {
|
||||
if (url_passcode && $lq__event_badge_obj && !passcode_checked) {
|
||||
untrack(() => {
|
||||
const badge = $lq__event_badge_obj;
|
||||
if (!badge || passcode_checked) return;
|
||||
untrack(() => {
|
||||
if (!badge.person_passcode) {
|
||||
// No passcode on this badge — open access for attendees
|
||||
passcode_valid = true;
|
||||
passcode_checked = true;
|
||||
} else if (url_passcode) {
|
||||
check_passcode(url_passcode);
|
||||
});
|
||||
}
|
||||
}
|
||||
// else: badge requires a passcode but none in URL — show the entry form
|
||||
});
|
||||
});
|
||||
|
||||
function check_passcode(code: string) {
|
||||
passcode_checked = true;
|
||||
const badge_passcode = $lq__event_badge_obj?.person_passcode;
|
||||
if (!badge_passcode) {
|
||||
// No passcode set on badge — deny access to prevent unintentional open access
|
||||
passcode_valid = false;
|
||||
passcode_error =
|
||||
'This badge does not have a review link enabled. Please contact event staff.';
|
||||
// No passcode on badge — open access
|
||||
passcode_valid = true;
|
||||
passcode_error = '';
|
||||
} else if (code && code === badge_passcode) {
|
||||
passcode_valid = true;
|
||||
passcode_error = '';
|
||||
@@ -294,8 +300,8 @@ let can_edit_fields: string[] = $derived.by(() => {
|
||||
is_staff={has_staff_access}
|
||||
{log_lvl} />
|
||||
</div>
|
||||
{:else if !passcode_checked && !url_passcode}
|
||||
<!-- Passcode entry (attendee navigates directly, no URL passcode) -->
|
||||
{:else if !passcode_checked && !url_passcode && !!$lq__event_badge_obj?.person_passcode}
|
||||
<!-- Passcode entry (badge requires a passcode, attendee navigated directly without one) -->
|
||||
<div class="card max-w-sm space-y-4 p-6">
|
||||
<h3 class="text-lg font-semibold">Enter Your Passcode</h3>
|
||||
<p class="text-sm text-gray-500">
|
||||
|
||||
Reference in New Issue
Block a user