Skip to content

fix: show and search the real PoliNetwork email instead of the placeholder - #16

Merged
lorenzocorallo merged 3 commits into
mainfrom
fix/polinetwork-email
Sep 30, 2026
Merged

lorenzocorallo merged 3 commits into
mainfrom
fix/polinetwork-email

Conversation

@lorenzocorallo

Copy link
Copy Markdown
Member

What changed

When someone signs in with PoliNetwork (Entra), the app saves a made-up …@identity.invalid email on purpose. So the People list on a role showed that strange address, and the user directory showed "No email on file".

  • Sign-in now saves the real address. Every PoliNetwork sign-in saves the address from the Microsoft token (email, then preferred_username, then upn) in a new identity_evidence.email column.
  • No backfill. The migration only adds the empty column. Existing users get their address the next time they sign in.
  • The real address is shown everywhere: the People list on a role, the "Give role" search results, the user directory, and each person's page. For people who haven't signed in since this change, it's read from their saved sign-in token instead. If no real address is known (for example, Telegram only), it says "No email on file".
  • Search finds people by their PoliNetwork address, in both the "Give role" box and the user directory. This only works for people who have signed in since the change.

The passkey name code now uses the same helper (src/auth/contact-email.ts), so there's only one copy of the logic.

Testing

  • vp check and vp test pass.
  • New unit tests: the saved address wins over the one in the token, and Telegram accounts are ignored.
  • The user directory database test now checks the shown address and searching by it. I ran it against a throwaway Postgres and it passes.
  • Two older tests in rbac-security.integration.test.mjs fail, but they fail the same way on main.
  • Not tested: that a real Microsoft sign-in fills the column. Please do one real login after deploying and check it.

🤖 Generated with Claude Code

…older

PoliNetwork sign-ins store a made-up @identity.invalid email, so role members
and the user directory showed that address (or none). Sign-in now saves the
real address from the Entra token in identity_evidence.email, the directory
and role search match it, and the display falls back to the saved sign-in
token for people who have not signed in since.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 49 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 48b63092-9efd-432e-8426-b140f7c36083

📥 Commits

Reviewing files that changed from the base of the PR and between c0bd9c3 and 3cc24b1.

📒 Files selected for processing (13)
  • drizzle/0010_identity_evidence_email.sql
  • drizzle/meta/0010_snapshot.json
  • drizzle/meta/_journal.json
  • src/auth/contact-email.test.ts
  • src/auth/contact-email.ts
  • src/auth/passkeys.ts
  • src/auth/providers.ts
  • src/auth/rbac-store.ts
  • src/auth/rbac.ts
  • src/auth/user-directory.integration.test.mjs
  • src/auth/user-directory.ts
  • src/components/rbac/role-members.tsx
  • src/db/evidence.ts
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

- Verify visibility, search, detail lookup, and role assignment for email-less users
@toto04

toto04 commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Pull request base or head changed.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

# Conflicts:
#	src/auth/user-directory.integration.test.mjs
@lorenzocorallo
lorenzocorallo merged commit 2aff37d into main Sep 30, 2026
2 checks passed
@lorenzocorallo
lorenzocorallo deleted the fix/polinetwork-email branch September 30, 2026 23:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants