Multi-phase visual facelift (design tokens, dashboards, sidebar/navbar
shell, per-page help guides, and a layout/content pass across every
remaining page) plus backend fixes to the dashboard KPI stats:
- Admin/Supervisor dashboard KPIs (revenue, donations, registrations,
tickets sold) now use a rolling trailing-month window (today back one
calendar month, e.g. 9 May - 8 June if today is 8 June) instead of
calendar month-to-date, which under-counted for most of the month.
The comparison window shifts the same way, so like is still compared
with like.
- Reports deep-links from those stat tiles now match the same window
(range=trailing_month, replacing range=this_month).
- Design tokens (brand-* Tailwind scale + shadcn CSS variables), a
site-wide contextual help button, fixed dashboard sidebar/navbar,
Admin/Supervisor/Staff/User dashboard rebuilds backed by a new
GET /api/stats/overview endpoint, a dedicated Contact page, Site
Settings restyle with WhatsApp config folded in, and an Account
activity feed backed by a new SecurityEvent model.
- Every remaining page (home, events, registration flow, auth, legal,
payment results, and every Admin/Supervisor/Staff/User tool page)
restyled onto the same design tokens, several with real layout
upgrades (home hero, events list/detail, donate page, auth pages).
- 20+ new dedicated help guides so the whole site has page-specific
help content instead of falling back to a generic guide.
- Assorted fixes surfaced along the way: donation-leg double-counting
in payment stats, donations not counting toward revenue, refund
netting in per-method report breakdowns, and donation
over-allocation after a refund.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Replaces the explicit "look up existing account" search field with automatic
lookup as email/phone are entered, requires operator confirmation before any
matched account's name/email/phone/preference is changed, adds a password
show/hide toggle, and fixes two bugs found during testing: entering a phone
number belonging to a different account could silently overwrite the form
with that account's details, and re-checking an unchanged field (e.g. from
tapping a ticket quantity button) could revert edits already made. Also adds
a server-side check rejecting registrations whose email and phone resolve to
two different existing accounts, as defense in depth.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
When the account lookup finds no match, carry the typed query into whichever
of Email/Phone it resembles (email-shaped or phone-shaped) instead of
discarding it, so the operator doesn't have to retype it. Leaves both blank
if it matches neither shape, and resets Name/notification preference for a
fresh entry.
The kiosk previously ran a debounced background lookup on every keystroke
in the visitor Email/Phone fields, silently autofilling matches. Replaced
with a dedicated "Look up existing account" field that only searches when
the operator presses Enter or clicks Search, and matches exactly against
either email or phone (never both from one query, to avoid digits in an
email being misread as an unrelated phone number). Also simplified the
"account already exists" banner wording.
- GET /api/events/all gains an opt-in excludeClosed=true param, used only by
the kiosk, so closed events no longer show as selectable there while other
admin/supervisor screens that still need to see closed events are unaffected.
- GET /api/users/check-exists now also returns the matched account's name,
email, phone, and notification preference (safe fields only). The kiosk's
existing debounced lookup uses this to autofill whichever fields are still
blank when a visitor enters an email or phone that matches an existing
account, without overwriting anything already typed.