Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
56f2a9f7fc | ||
|
|
b081ed3c8b | ||
|
|
8a75c9155b | ||
|
|
8850984055 | ||
|
|
21176e1e0b | ||
|
|
b4cd140168 | ||
|
|
5167706d1b | ||
|
|
047f61b627 | ||
|
|
1815f78c85 | ||
|
|
29036d0612 | ||
|
|
c07e9c928a |
+39
-1
@@ -7,6 +7,42 @@ and this project follows [Semantic Versioning](https://semver.org/).
|
||||
|
||||
## [Unreleased]
|
||||
|
||||
## [1.3.2] - 2026-08-03
|
||||
|
||||
### Added
|
||||
|
||||
- Self-service kiosk: all password fields (supervisor sign-in, change event, and the visitor "Choose a password" field) now have a show/hide toggle button, so staff can verify what they've typed on the touchscreen instead of typing blind.
|
||||
|
||||
### Fixed
|
||||
|
||||
- Self-service kiosk: removed the separate "Look up existing account" search field — for privacy, staff no longer type a visitor's email/phone into a dedicated search box. Instead, entering an email or phone number in the registration form itself (Email and Cell Number are now the first two fields, followed by Name) automatically checks for a matching account once that field is left.
|
||||
- Self-service kiosk: matched accounts are no longer updated silently. If the operator's typed Name, Email, Cell Number, or "Send tickets via" preference differs from what's on file, a confirmation dialog now lists exactly what will change (old value → new value) and requires the operator to confirm before the account is updated.
|
||||
- Self-service kiosk / manual registration: an existing account's name is now actually updated when confirmed changed (previously silently discarded), and email/phone corrections are applied even when the account already had a real value on file (previously only blank phone numbers or guest-placeholder emails could be replaced).
|
||||
- Self-service kiosk: fixed a bug where changing the phone number to one belonging to a different account would silently replace the Name/Email fields with that other account's details, and re-editing the email back to the original value afterward would not re-check it — together this could result in a registration being (or looking like it would be) saved under the wrong account. Email and phone matches are now tracked independently; if they resolve to two different existing accounts, the kiosk shows a clear warning naming both accounts and blocks registration until the operator corrects one of the fields, instead of silently merging or overwriting details.
|
||||
- Manual registration API: added a server-side check, independent of the kiosk UI, that rejects (`409`) a registration whose submitted email and phone number belong to two different existing accounts — a defense-in-depth safeguard against one account's contact details being overwritten with, or hijacked by, another's.
|
||||
- Manual registration API: an existing account's notification preference is now validated against its final email/phone after any confirmed update (e.g. falls back off "WhatsApp"/"Both" if no valid phone remains, or onto "WhatsApp" if the email was cleared in favor of a real phone), instead of persisting a preference that no longer matches the account's actual contact info.
|
||||
- Self-service kiosk: tapping anywhere else on the page (e.g. a ticket quantity +/− button) while Email or Cell Number was focused blurred that field and silently re-ran its account lookup; even though the match hadn't changed, this reset Name/Email/Phone/preference back to the matched account's original values, discarding any edits the operator had just made. The autofill now only applies once per distinct matched account instead of on every re-check.
|
||||
|
||||
## [1.3.1] - 2026-07-28
|
||||
|
||||
### Fixed
|
||||
|
||||
- Self-service kiosk: closed events no longer appear in the event picker — only open events are selectable.
|
||||
- Self-service kiosk: added a "Look up existing account" search field (by email or phone, triggered only by Enter or the Search button — never as-you-type) that autofills a returning visitor's name, contact details, and notification preference from their exact matching account, instead of requiring staff to re-enter details already on file.
|
||||
- Self-service kiosk: when the account lookup finds no match, the typed query now carries over into whichever of Email/Phone it resembles (instead of being discarded), while Name and everything else resets blank for a fresh entry.
|
||||
|
||||
## [1.3.0] - 2026-07-27
|
||||
|
||||
### Added
|
||||
|
||||
- At The Door: new "Check-In" tab (before "Tickets" in the tab order) for quickly redeeming a registration's Main Tickets by quantity (e.g. checking in 2 of 3 people on a booking) without scanning each QR code individually. Like the Payment tab, it only ever shows the currently opened registration — reached via the "Open" button, not a general search.
|
||||
- Checking in a Main Ticket (via the new Check-In tab or the existing QR camera scanner) now automatically sends the ticket holder a confirmation email and WhatsApp message (respecting their notification preference) stating how many were checked in and how many remain.
|
||||
|
||||
### Changed
|
||||
|
||||
- At The Door: the "Open" button on a registration now jumps to the Payment tab only when a balance is still outstanding; fully paid registrations jump straight to the new Check-In tab instead.
|
||||
- At The Door: recording a payment that fully settles a registration's balance now jumps straight to the Check-In tab instead of generating and print-previewing a paper ticket — tickets are already emailed/WhatsApped to the attendee automatically once the registration is paid, so a physical print is no longer forced on this path.
|
||||
|
||||
## [1.2.0] - 2026-07-27
|
||||
|
||||
### Added
|
||||
@@ -57,7 +93,9 @@ and this project follows [Semantic Versioning](https://semver.org/).
|
||||
|
||||
- Initial release of the Hope Family Church event management app (Next.js frontend + Express/Prisma backend).
|
||||
|
||||
[Unreleased]: https://git.crosscode.co.za/joshua/hope-events/compare/v1.2.0...main
|
||||
[Unreleased]: https://git.crosscode.co.za/joshua/hope-events/compare/v1.3.1...main
|
||||
[1.3.1]: https://git.crosscode.co.za/joshua/hope-events/compare/v1.3.0...v1.3.1
|
||||
[1.3.0]: https://git.crosscode.co.za/joshua/hope-events/compare/v1.2.0...v1.3.0
|
||||
[1.2.0]: https://git.crosscode.co.za/joshua/hope-events/compare/v1.1.0...v1.2.0
|
||||
[1.1.0]: https://git.crosscode.co.za/joshua/hope-events/compare/v1.0.1...v1.1.0
|
||||
[1.0.1]: https://git.crosscode.co.za/joshua/hope-events/compare/v1.0.0...v1.0.1
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "event-management-backend",
|
||||
"version": "1.2.0",
|
||||
"version": "1.3.2",
|
||||
"description": "Event Management System Backend",
|
||||
"main": "src/index.js",
|
||||
"scripts": {
|
||||
|
||||
@@ -241,10 +241,12 @@ const getEventsAll = async (req, res) => {
|
||||
try {
|
||||
const includePast = req.query.includePast === 'true';
|
||||
const includeInactive = req.query.includeInactive === 'true';
|
||||
const excludeClosed = req.query.excludeClosed === 'true';
|
||||
|
||||
const where = {};
|
||||
if (!includeInactive) where.isActive = true;
|
||||
if (!includePast) where.endDate = { gte: new Date() };
|
||||
if (excludeClosed) where.cashupStatus = { not: 'closed' };
|
||||
|
||||
const canIncludeTiers = !!(prisma && prisma.earlyBirdTier && typeof prisma.earlyBirdTier.findMany === 'function');
|
||||
const canIncludeVariants = !!(prisma && prisma.optionVariant && typeof prisma.optionVariant.findMany === 'function');
|
||||
|
||||
@@ -764,32 +764,66 @@ const createManualRegistration = async (req, res) => {
|
||||
? prefFromBody
|
||||
: (hasValidEmail && phone ? 'both' : phone ? 'whatsapp' : 'email');
|
||||
|
||||
// Always search by email AND/OR phone regardless of guestOnly
|
||||
// Also try the alternate format (27xxx ↔ 0xxx) so both representations match
|
||||
// Always search by email AND/OR phone regardless of guestOnly.
|
||||
// Resolve each channel independently (rather than a single findFirst with an OR
|
||||
// across both) so that an email belonging to one account and a phone number
|
||||
// belonging to a *different* account can never be silently collapsed into
|
||||
// whichever record happens to match first — that would let a registration
|
||||
// hijack or corrupt someone else's account. Also try the alternate phone
|
||||
// format (27xxx ↔ 0xxx) so both representations match.
|
||||
const phoneAlt = phone && phone.startsWith('27') ? '0' + phone.slice(2) : (phone && phone.length === 9 ? '27' + phone : null);
|
||||
const searchClauses = [
|
||||
...(hasValidEmail ? [{ email: user.email }] : []),
|
||||
...(phone ? [{ phoneNumber: phone }] : []),
|
||||
...(phoneAlt ? [{ phoneNumber: phoneAlt }] : []),
|
||||
];
|
||||
const existingUser = searchClauses.length > 0
|
||||
? await prisma.user.findFirst({ where: { OR: searchClauses } })
|
||||
const emailUser = hasValidEmail
|
||||
? await prisma.user.findUnique({ where: { email: user.email } })
|
||||
: null;
|
||||
const phoneUser = phone
|
||||
? await prisma.user.findFirst({ where: { OR: [{ phoneNumber: phone }, ...(phoneAlt ? [{ phoneNumber: phoneAlt }] : [])] } })
|
||||
: null;
|
||||
|
||||
if (emailUser && phoneUser && emailUser.id !== phoneUser.id) {
|
||||
res.status(409);
|
||||
throw new Error(
|
||||
`This email and phone number belong to two different existing accounts (${emailUser.name} vs ${phoneUser.name}). Please verify the visitor's details before registering.`
|
||||
);
|
||||
}
|
||||
|
||||
const existingUser = emailUser || phoneUser || null;
|
||||
|
||||
if (existingUser) {
|
||||
userId = existingUser.id;
|
||||
const updateData = {};
|
||||
// Update preference only when the caller explicitly specified one
|
||||
if (prefFromBody && validPrefs.includes(prefFromBody)) {
|
||||
updateData.notificationPreference = prefFromBody;
|
||||
// The kiosk shows the operator a diff of name/email/phone against the matched
|
||||
// account and requires explicit confirmation before submitting, so any
|
||||
// difference reaching this point is an already-confirmed correction — apply
|
||||
// it as a full overwrite rather than only filling in blanks.
|
||||
if (user.name && user.name.trim() && user.name.trim() !== existingUser.name) {
|
||||
updateData.name = user.name.trim();
|
||||
}
|
||||
// Fill in a missing contact channel with the newly supplied value, without overwriting an existing one
|
||||
if (phone && !existingUser.phoneNumber) {
|
||||
if (phone && phone !== existingUser.phoneNumber) {
|
||||
updateData.phoneNumber = phone;
|
||||
}
|
||||
if (hasValidEmail && existingUser.email !== user.email && existingUser.email.endsWith('@guest.local')) {
|
||||
if (hasValidEmail && existingUser.email !== user.email) {
|
||||
updateData.email = user.email;
|
||||
}
|
||||
|
||||
// Update preference only when the caller explicitly specified one, but validate it
|
||||
// against the contact info that will actually be on the account after this update —
|
||||
// a stale "whatsapp"/"both" preference must not survive a phone number being
|
||||
// removed, nor "email" survive an email being cleared in favor of a real phone.
|
||||
if (prefFromBody && validPrefs.includes(prefFromBody)) {
|
||||
const { isValidZAPhone } = require('../utils/whatsapp');
|
||||
const finalPhone = updateData.phoneNumber !== undefined ? updateData.phoneNumber : existingUser.phoneNumber;
|
||||
const finalEmail = updateData.email !== undefined ? updateData.email : existingUser.email;
|
||||
const finalEmailValid = !!(finalEmail && !finalEmail.endsWith('@guest.local'));
|
||||
let candidatePref = prefFromBody;
|
||||
if ((candidatePref === 'whatsapp' || candidatePref === 'both') && !isValidZAPhone(finalPhone)) {
|
||||
candidatePref = finalEmailValid ? 'email' : candidatePref;
|
||||
}
|
||||
if (candidatePref === 'email' && !finalEmailValid && isValidZAPhone(finalPhone)) {
|
||||
candidatePref = 'whatsapp';
|
||||
}
|
||||
updateData.notificationPreference = candidatePref;
|
||||
}
|
||||
|
||||
if (Object.keys(updateData).length > 0) {
|
||||
await prisma.user.update({ where: { id: userId }, data: updateData }).catch(() => {});
|
||||
}
|
||||
|
||||
@@ -321,6 +321,7 @@ const scanTicket = async (req, res) => {
|
||||
e.title AS "eventTitle",
|
||||
eo.id AS "eventOptionId",
|
||||
eo.name AS "eventOptionName",
|
||||
eo."isMainTicket" AS "isMainTicket",
|
||||
COALESCE(
|
||||
json_agg(
|
||||
json_build_object(
|
||||
@@ -352,7 +353,7 @@ const scanTicket = async (req, res) => {
|
||||
isUsed: r.isUsed,
|
||||
eventId: r.eventId,
|
||||
event: { title: r.eventTitle },
|
||||
registrationOption: { eventOption: { id: r.eventOptionId, name: r.eventOptionName } },
|
||||
registrationOption: { eventOption: { id: r.eventOptionId, name: r.eventOptionName, isMainTicket: r.isMainTicket } },
|
||||
usages: r.usages || []
|
||||
};
|
||||
|
||||
@@ -398,6 +399,14 @@ const scanTicket = async (req, res) => {
|
||||
})
|
||||
]);
|
||||
|
||||
// Only Main Tickets trigger a check-in notification (add-on tickets scanned via
|
||||
// the QR camera flow are unaffected)
|
||||
if (ticket.registrationOption?.eventOption?.isMainTicket) {
|
||||
require('../utils/notifications')
|
||||
.sendCheckInEmails(ticket.id, qtyToRedeem, newTotalRedeemed, newRemaining)
|
||||
.catch(e => console.error('Failed to send check-in notification:', e));
|
||||
}
|
||||
|
||||
res.json({
|
||||
message: `Ticket scanned successfully (${qtyToRedeem} of ${ticket.quantity || 1} redeemed${newRemaining > 0 ? `, ${newRemaining} remaining` : ''})`,
|
||||
ticketUsage,
|
||||
|
||||
@@ -482,13 +482,28 @@ const checkUserExists = async (req, res) => {
|
||||
|
||||
const existingUser = await prisma.user.findFirst({
|
||||
where: { OR: searchClauses },
|
||||
select: { email: true, phoneNumber: true },
|
||||
select: { id: true, name: true, email: true, phoneNumber: true, notificationPreference: true },
|
||||
});
|
||||
|
||||
const hasEmail = !!existingUser?.email && !existingUser.email.endsWith('@guest.local');
|
||||
const hasPhone = !!existingUser?.phoneNumber;
|
||||
|
||||
res.json({
|
||||
exists: !!existingUser,
|
||||
hasEmail: !!existingUser?.email && !existingUser.email.endsWith('@guest.local'),
|
||||
hasPhone: !!existingUser?.phoneNumber,
|
||||
hasEmail,
|
||||
hasPhone,
|
||||
// Safe-to-display fields only, for autofilling a lookup form — never the password.
|
||||
// Guest placeholder emails are withheld the same way hasEmail already treats them.
|
||||
// `id` lets the kiosk tell two different matched accounts apart (e.g. when the
|
||||
// typed email and phone number resolve to different people) — it's never shown,
|
||||
// only compared client-side, and this endpoint is already Private/Supervisor.
|
||||
user: existingUser ? {
|
||||
id: existingUser.id,
|
||||
name: existingUser.name,
|
||||
email: hasEmail ? existingUser.email : null,
|
||||
phoneNumber: hasPhone ? existingUser.phoneNumber : null,
|
||||
notificationPreference: existingUser.notificationPreference,
|
||||
} : null,
|
||||
});
|
||||
} catch (error) {
|
||||
res.status(res.statusCode === 200 ? 400 : res.statusCode).json({ message: safeErrorMessage(error) });
|
||||
|
||||
@@ -80,6 +80,17 @@ async function loadRegistrationFull(registrationId) {
|
||||
});
|
||||
}
|
||||
|
||||
async function loadTicketFull(ticketId) {
|
||||
return prisma.ticket.findUnique({
|
||||
where: { id: ticketId },
|
||||
include: {
|
||||
user: { select: { id: true, name: true, email: true, phoneNumber: true, notificationPreference: true } },
|
||||
event: true,
|
||||
registrationOption: { include: { eventOption: true, variant: true } },
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
async function loadPaymentFull(paymentId) {
|
||||
return prisma.payment.findUnique({
|
||||
where: { id: paymentId },
|
||||
@@ -488,6 +499,33 @@ function buildPaymentReceipt(payment) {
|
||||
return { subject, text, html: emailWrapper(body, { preheader }) };
|
||||
}
|
||||
|
||||
// ─── Check-in confirmation (Main Tickets, door check-in) ───────────────────────
|
||||
|
||||
function buildCheckInConfirmation(ticket, qtyRedeemed, totalRedeemed, remaining) {
|
||||
const org = getOrg();
|
||||
const eventTitle = ticket.event?.title || 'the event';
|
||||
const optionName = ticket.registrationOption?.eventOption?.name || 'Main Ticket';
|
||||
const fullyCheckedIn = remaining <= 0;
|
||||
const subject = `Checked in – ${eventTitle}`;
|
||||
const preheader = `${qtyRedeemed} checked in for ${eventTitle}.`;
|
||||
|
||||
const body = `
|
||||
<p style="font-size:22px;font-weight:800;color:#0f172a;margin:0 0 8px 0;letter-spacing:-0.3px">You're checked in! ✅</p>
|
||||
<p style="font-size:14px;color:#64748b;margin:0 0 32px 0">See you inside</p>
|
||||
|
||||
<p style="margin:0 0 4px 0;color:#374151;font-family:${ff}">Hi <strong>${ticket.user?.name || 'there'}</strong>,</p>
|
||||
<p style="margin:0 0 28px 0;color:#374151;font-family:${ff}">
|
||||
<strong>${qtyRedeemed}</strong> ${optionName}${qtyRedeemed === 1 ? '' : 's'} just checked in for <strong>${eventTitle}</strong>.
|
||||
</p>
|
||||
|
||||
${callout(`<strong style="font-size:15px">${totalRedeemed} of ${ticket.quantity || 1} checked in</strong>${
|
||||
fullyCheckedIn ? '' : `<br/><span style="font-size:13px">${remaining} remaining on this ticket</span>`
|
||||
}`, fullyCheckedIn ? 'success' : 'info')}`;
|
||||
|
||||
const text = `You're checked in!\n\nHi ${ticket.user?.name || 'there'},\n\n${qtyRedeemed} ${optionName}(s) just checked in for ${eventTitle}.\n\n${totalRedeemed} of ${ticket.quantity || 1} checked in${fullyCheckedIn ? '' : `, ${remaining} remaining`}.\n\n${org.name} — ${org.email}`;
|
||||
return { subject, text, html: emailWrapper(body, { preheader }) };
|
||||
}
|
||||
|
||||
// ─── Donation applied to a registration ────────────────────────────────────────
|
||||
//
|
||||
// Distinct from buildPaymentReceipt: this is sent to the REGISTRANT when staff apply
|
||||
@@ -893,6 +931,32 @@ async function sendRefundEmail(refundPaymentId) {
|
||||
}
|
||||
}
|
||||
|
||||
async function sendCheckInEmails(ticketId, qtyRedeemed, totalRedeemed, remaining) {
|
||||
try {
|
||||
const ticket = await loadTicketFull(ticketId);
|
||||
if (!ticket) return;
|
||||
const user = ticket.user;
|
||||
const { shouldEmail, waText, waTextAny } = require('./notify');
|
||||
const { buildWACheckIn } = require('./waMessages');
|
||||
|
||||
const sends = [];
|
||||
const hasValidEmail = user?.email && !user.email.endsWith('@guest.local') && !user.email.endsWith('@deleted.invalid');
|
||||
if (hasValidEmail && shouldEmail(user)) {
|
||||
const msg = buildCheckInConfirmation(ticket, qtyRedeemed, totalRedeemed, remaining);
|
||||
sends.push(sendMail({ to: user.email, subject: msg.subject, html: msg.html, text: msg.text }));
|
||||
}
|
||||
const waMsg = buildWACheckIn(ticket, qtyRedeemed, totalRedeemed, remaining);
|
||||
if (hasValidEmail) {
|
||||
sends.push(waText(user, waMsg));
|
||||
} else {
|
||||
sends.push(waTextAny(user, waMsg));
|
||||
}
|
||||
await Promise.all(sends);
|
||||
} catch (e) {
|
||||
console.error('Failed to send check-in emails:', e);
|
||||
}
|
||||
}
|
||||
|
||||
// Sent when staff apply a donation to someone's registration. Only the registrant is
|
||||
// notified (anonymously, per design) — the donor already received their donation-received
|
||||
// notification when the donation was originally made, so they are deliberately not emailed
|
||||
@@ -981,4 +1045,6 @@ module.exports = {
|
||||
sendRefundEmail,
|
||||
sendSelfServiceRegistrationEmails,
|
||||
sendDonationAssignmentEmails,
|
||||
sendCheckInEmails,
|
||||
buildCheckInConfirmation,
|
||||
};
|
||||
|
||||
@@ -107,6 +107,26 @@ function buildWAPayment(payment) {
|
||||
].join('\n');
|
||||
}
|
||||
|
||||
// ─── Check-in confirmation (Main Tickets, door check-in) ───────────────────────
|
||||
|
||||
function buildWACheckIn(ticket, qtyRedeemed, totalRedeemed, remaining) {
|
||||
const org = getOrg();
|
||||
const eventTitle = ticket.event?.title || 'the event';
|
||||
const name = ticket.user?.name || 'there';
|
||||
const fullyCheckedIn = remaining <= 0;
|
||||
|
||||
return [
|
||||
`✅ *Checked In*`,
|
||||
'',
|
||||
`Hi ${name},`,
|
||||
'',
|
||||
`*${qtyRedeemed}* checked in for *${eventTitle}*.`,
|
||||
`*${totalRedeemed} of ${ticket.quantity || 1}* checked in${fullyCheckedIn ? '' : `, *${remaining}* remaining`}.`,
|
||||
'',
|
||||
`_${org.name}_ | ${org.url}`,
|
||||
].join('\n');
|
||||
}
|
||||
|
||||
// ─── Login notification ───────────────────────────────────────────────────────
|
||||
|
||||
function buildWALogin({ name, when, location, userAgent }) {
|
||||
@@ -255,4 +275,5 @@ module.exports = {
|
||||
buildWAWelcome,
|
||||
buildWAAccountClosed,
|
||||
buildWATicketCaption,
|
||||
buildWACheckIn,
|
||||
};
|
||||
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "hope-events-frontend",
|
||||
"version": "1.2.0",
|
||||
"version": "1.3.2",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"dev": "next dev --turbopack",
|
||||
|
||||
@@ -7,7 +7,15 @@ import { apiFetch } from "@/lib/api";
|
||||
import { scoreUser } from "@/lib/fuzzyMatch";
|
||||
import { useDismissingState } from "@/hooks/useDismissingState";
|
||||
|
||||
type Mode = "registration" | "payment" | "tickets" | "refund";
|
||||
type Mode = "registration" | "payment" | "checkin" | "tickets" | "refund";
|
||||
|
||||
const MODE_LABELS: Record<Mode, string> = {
|
||||
registration: "REGISTRATION",
|
||||
payment: "PAYMENT",
|
||||
checkin: "CHECK-IN",
|
||||
tickets: "TICKETS",
|
||||
refund: "REFUND",
|
||||
};
|
||||
|
||||
// ─── Fuzzy search helpers ─────────────────────────────────────────────────────
|
||||
|
||||
@@ -159,8 +167,7 @@ export default function AtTheDoorPage() {
|
||||
const [error, setError] = useDismissingState<string | null>(null);
|
||||
|
||||
const handleRegistrationCreated = (registration: any) => {
|
||||
setActiveRegistration(registration);
|
||||
setMode("payment"); // 🚀 Jump automatically
|
||||
setActiveRegistration(registration); // 🚀 Jump automatically (see effect below)
|
||||
};
|
||||
|
||||
const handleRegistrationSelected = (registration: any) => {
|
||||
@@ -171,7 +178,9 @@ export default function AtTheDoorPage() {
|
||||
if (!activeRegistration) return;
|
||||
|
||||
const id = setTimeout(() => {
|
||||
setMode("payment");
|
||||
// Fully paid → head straight to check-in; otherwise there's still a
|
||||
// balance to collect, so go capture payment first.
|
||||
setMode(activeRegistration.status === "paid" ? "checkin" : "payment");
|
||||
}, 0);
|
||||
|
||||
return () => clearTimeout(id);
|
||||
@@ -317,28 +326,12 @@ export default function AtTheDoorPage() {
|
||||
|
||||
const reg = registration || activeRegistration;
|
||||
|
||||
try {
|
||||
const res = await apiFetch<any>("/api/tickets/generate", {
|
||||
method: "POST",
|
||||
authToken: token,
|
||||
body: {
|
||||
registrationId: reg.id
|
||||
}
|
||||
});
|
||||
|
||||
const tickets = res?.tickets || [];
|
||||
|
||||
if (tickets.length) {
|
||||
printTickets(tickets);
|
||||
}
|
||||
|
||||
setInfo("Payment recorded & tickets printed");
|
||||
setActiveRegistration(null);
|
||||
setMode("registration");
|
||||
|
||||
} catch (e: any) {
|
||||
setError(e?.message || "Tickets failed to generate");
|
||||
}
|
||||
// Tickets are generated and emailed/WhatsApped automatically server-side
|
||||
// once a registration reaches "paid" (see paymentController) — no need to
|
||||
// fetch/print them here, just move straight to checking the attendee in.
|
||||
setActiveRegistration(reg);
|
||||
setInfo("Payment recorded — tickets sent. Ready to check in.");
|
||||
setMode("checkin");
|
||||
};
|
||||
|
||||
const handleDonation = (user?: any) => {
|
||||
@@ -346,97 +339,6 @@ export default function AtTheDoorPage() {
|
||||
setShowDonationModal(true);
|
||||
};
|
||||
|
||||
const buildTicketHtmlCard = (t: any) => {
|
||||
const eventTitle =
|
||||
t.event?.title ||
|
||||
t.registrationOption?.registration?.event?.title ||
|
||||
"Event";
|
||||
|
||||
const ticketType = ticketLabel(t);
|
||||
const qty = t.quantity || 1;
|
||||
const holder =
|
||||
t.user?.name ||
|
||||
t.registrationOption?.registration?.user?.name ||
|
||||
"";
|
||||
const qrValue = t.qrCode || t.id;
|
||||
const qrSrc = `https://api.qrserver.com/v1/create-qr-code/?size=200x200&data=${encodeURIComponent(qrValue)}`;
|
||||
|
||||
return `<div class="ticket">
|
||||
<div class="top">
|
||||
<div class="evt">${eventTitle}</div>
|
||||
<div class="type">${ticketType}</div>
|
||||
${holder ? `<div class="holder">${holder}</div>` : ""}
|
||||
<div class="qty">Qty: <strong>${qty}</strong></div>
|
||||
</div>
|
||||
<div class="qrwrap"><img src="${qrSrc}" alt="QR" /></div>
|
||||
<div class="meta">${t.id}</div>
|
||||
</div>`;
|
||||
};
|
||||
|
||||
const openPrintWindow = (cardsHtml: string) => {
|
||||
const w = window.open("", "_blank");
|
||||
if (!w) return;
|
||||
w.document.write(`<!doctype html><html><head><style>
|
||||
@page { size: A4; margin: 8mm; }
|
||||
* { box-sizing: border-box; }
|
||||
body { font-family: Arial, Helvetica, sans-serif; margin: 0; padding: 0; background: #fff; }
|
||||
.page {
|
||||
display: grid;
|
||||
grid-template-columns: 1fr 1fr;
|
||||
grid-template-rows: 1fr 1fr;
|
||||
width: 194mm;
|
||||
height: 281mm;
|
||||
gap: 4mm;
|
||||
page-break-after: always;
|
||||
break-after: page;
|
||||
}
|
||||
.page:last-child { page-break-after: avoid; break-after: avoid; }
|
||||
.ticket {
|
||||
border: 1.5px solid #222;
|
||||
border-radius: 3mm;
|
||||
padding: 5mm;
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
justify-content: space-between;
|
||||
overflow: hidden;
|
||||
min-height: 0;
|
||||
}
|
||||
.top { flex: 0 0 auto; }
|
||||
.evt { font-weight: bold; font-size: 13pt; line-height: 1.2; }
|
||||
.type { font-size: 11pt; margin-top: 2mm; color: #333; }
|
||||
.holder { font-size: 10pt; margin-top: 1mm; color: #555; }
|
||||
.qty { font-size: 10pt; margin-top: 1mm; }
|
||||
.qrwrap { display: flex; justify-content: center; align-items: center; flex: 1 1 auto; padding: 3mm 0; }
|
||||
.qrwrap img { width: 48mm; height: 48mm; display: block; }
|
||||
.meta { font-size: 7pt; color: #777; text-align: center; flex: 0 0 auto; word-break: break-all; }
|
||||
</style></head><body>${cardsHtml}<script>
|
||||
(function(){
|
||||
function go(){
|
||||
var imgs=Array.prototype.slice.call(document.images);
|
||||
if(!imgs.length){window.print();return;}
|
||||
var n=imgs.length;
|
||||
function done(){if(--n<=0)setTimeout(function(){window.print();},150);}
|
||||
imgs.forEach(function(i){if(i.complete)done();else{i.addEventListener('load',done,{once:true});i.addEventListener('error',done,{once:true});}});
|
||||
}
|
||||
if(document.readyState==='complete')go();else window.addEventListener('load',go);
|
||||
})();
|
||||
</script></body></html>`);
|
||||
w.document.close();
|
||||
};
|
||||
|
||||
const printTickets = (tickets: any[]) => {
|
||||
if (!tickets?.length) return;
|
||||
// 4 per A4 page (2 columns × 2 rows)
|
||||
const PAGE_SIZE = 4;
|
||||
const pages: string[] = [];
|
||||
for (let i = 0; i < tickets.length; i += PAGE_SIZE) {
|
||||
const chunk = tickets.slice(i, i + PAGE_SIZE);
|
||||
pages.push(`<div class="page">${chunk.map(buildTicketHtmlCard).join("")}</div>`);
|
||||
}
|
||||
openPrintWindow(pages.join(""));
|
||||
};
|
||||
|
||||
|
||||
return (
|
||||
<div className="max-w-6xl mx-auto w-full p-4 sm:p-6">
|
||||
|
||||
@@ -482,7 +384,7 @@ export default function AtTheDoorPage() {
|
||||
|
||||
{/* Mode Buttons */}
|
||||
<div className="flex gap-2 mb-4 flex-wrap">
|
||||
{(["registration", "payment", "tickets", "refund"] as Mode[]).map(m => (
|
||||
{(["registration", "payment", "checkin", "tickets", "refund"] as Mode[]).map(m => (
|
||||
<button
|
||||
key={m}
|
||||
onClick={() => setMode(m)}
|
||||
@@ -494,7 +396,7 @@ export default function AtTheDoorPage() {
|
||||
: "bg-white hover:bg-gray-50"
|
||||
}`}
|
||||
>
|
||||
{m.toUpperCase()}
|
||||
{MODE_LABELS[m]}
|
||||
</button>
|
||||
))}
|
||||
</div>
|
||||
@@ -522,6 +424,10 @@ export default function AtTheDoorPage() {
|
||||
/>
|
||||
)}
|
||||
|
||||
{mode === "checkin" && (
|
||||
<DoorCheckInPanel token={token} eventId={eventId} registration={activeRegistration} setError={setError} setInfo={setInfo} />
|
||||
)}
|
||||
|
||||
{mode === "tickets" && (
|
||||
<DoorTicketsPanel token={token} eventId={eventId} />
|
||||
)}
|
||||
@@ -1081,6 +987,148 @@ function DoorTicketsPanel({ token, eventId }: any) {
|
||||
);
|
||||
}
|
||||
|
||||
function DoorCheckInPanel({ token, eventId, registration, setError, setInfo }: any) {
|
||||
const [ticketsForEvent, setTicketsForEvent] = useState<any[]>([]);
|
||||
const [loading, setLoading] = useState(false);
|
||||
const [qtyByTicket, setQtyByTicket] = useState<Record<string, number>>({});
|
||||
const [submittingId, setSubmittingId] = useState<string | null>(null);
|
||||
|
||||
const load = async () => {
|
||||
if (!token || !eventId) return;
|
||||
try {
|
||||
setLoading(true);
|
||||
const res = await apiFetch<any>(`/api/tickets/event/${eventId}`, { authToken: token });
|
||||
const tickets = res?.tickets || res?.data || (Array.isArray(res) ? res : []);
|
||||
setTicketsForEvent(tickets.filter((t: any) => t.registrationOption?.eventOption?.isMainTicket));
|
||||
} catch {
|
||||
setTicketsForEvent([]);
|
||||
} finally {
|
||||
setLoading(false);
|
||||
}
|
||||
};
|
||||
|
||||
useEffect(() => { load(); }, [token, eventId]);
|
||||
|
||||
if (!registration) {
|
||||
return (
|
||||
<div className="border rounded-xl p-6 bg-white shadow-sm text-sm text-gray-500">
|
||||
No registration selected
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
const myTickets = ticketsForEvent
|
||||
.filter(t => t.registrationOption?.registration?.id === registration.id)
|
||||
.map(t => {
|
||||
const totalRedeemed = (t.usages || []).reduce((s: number, u: any) => s + (u.quantityRedeemed || 1), 0);
|
||||
const remaining = (t.quantity || 1) - totalRedeemed;
|
||||
return { ...t, totalRedeemed, remaining };
|
||||
});
|
||||
|
||||
const qtyFor = (t: any) => qtyByTicket[t.id] ?? (t.remaining > 0 ? t.remaining : 1);
|
||||
const setQtyFor = (t: any, n: number) =>
|
||||
setQtyByTicket(q => ({ ...q, [t.id]: Math.max(1, Math.min(t.remaining || 1, n)) }));
|
||||
|
||||
const commit = async (ticket: any) => {
|
||||
const qty = qtyFor(ticket);
|
||||
try {
|
||||
setSubmittingId(ticket.id);
|
||||
const res = await apiFetch<any>(
|
||||
`/api/tickets/scan/${encodeURIComponent(ticket.qrCode)}?eventId=${encodeURIComponent(eventId)}`,
|
||||
{ method: "POST", authToken: token, body: { qty } }
|
||||
);
|
||||
setInfo(`${res?.qtyRedeemed ?? qty} checked in for ${registration.user?.name || "guest"}${
|
||||
res?.remaining > 0 ? ` — ${res.remaining} remaining` : " — fully checked in"
|
||||
}. Confirmation sent.`);
|
||||
await load();
|
||||
} catch (e: any) {
|
||||
setError(e?.message || "Check-in failed");
|
||||
} finally {
|
||||
setSubmittingId(null);
|
||||
}
|
||||
};
|
||||
|
||||
return (
|
||||
<div className="border rounded-xl p-6 bg-white shadow-sm">
|
||||
|
||||
<div className="text-xl font-semibold mb-4">Check-In</div>
|
||||
|
||||
{/* ✅ User */}
|
||||
<div className="mb-4">
|
||||
<div className="text-lg font-semibold">
|
||||
{registration.user?.name || "Guest"}
|
||||
</div>
|
||||
</div>
|
||||
|
||||
{loading && (
|
||||
<div className="text-sm text-gray-500">Loading…</div>
|
||||
)}
|
||||
|
||||
{!loading && myTickets.length === 0 && (
|
||||
<div className="text-sm text-gray-500">
|
||||
No Main Tickets on this registration
|
||||
</div>
|
||||
)}
|
||||
|
||||
<div className="space-y-4">
|
||||
{myTickets.map(t => {
|
||||
const qty = qtyFor(t);
|
||||
return (
|
||||
<div key={t.id} className="border rounded-lg p-4">
|
||||
<div className="text-sm font-medium mb-3">{ticketLabel(t)}</div>
|
||||
|
||||
<div className="grid grid-cols-3 gap-3 mb-4">
|
||||
<div className="border rounded-lg p-3 text-center">
|
||||
<div className="text-xs text-gray-500">TOTAL</div>
|
||||
<div className="text-lg font-semibold">{t.quantity || 1}</div>
|
||||
</div>
|
||||
|
||||
<div className="border rounded-lg p-3 text-center">
|
||||
<div className="text-xs text-gray-500">CHECKED IN</div>
|
||||
<div className="text-lg font-semibold">{t.totalRedeemed}</div>
|
||||
</div>
|
||||
|
||||
<div className="border rounded-lg p-3 text-center bg-emerald-50">
|
||||
<div className="text-xs text-gray-500">REMAINING</div>
|
||||
<div className="text-2xl font-bold text-emerald-600">{t.remaining}</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
{t.remaining > 0 ? (
|
||||
<div className="flex items-center gap-3">
|
||||
<button
|
||||
onClick={() => setQtyFor(t, qty - 1)}
|
||||
className="w-9 h-9 border rounded flex items-center justify-center text-lg font-bold"
|
||||
>
|
||||
–
|
||||
</button>
|
||||
<div className="w-10 text-center text-lg font-semibold">{qty}</div>
|
||||
<button
|
||||
onClick={() => setQtyFor(t, qty + 1)}
|
||||
className="w-9 h-9 border rounded flex items-center justify-center text-lg font-bold bg-emerald-50 border-emerald-300 text-emerald-700"
|
||||
>
|
||||
+
|
||||
</button>
|
||||
|
||||
<button
|
||||
onClick={() => commit(t)}
|
||||
disabled={submittingId === t.id}
|
||||
className="ml-auto px-4 py-2 text-sm rounded bg-indigo-600 text-white disabled:opacity-50"
|
||||
>
|
||||
{submittingId === t.id ? "Checking in…" : `Check In ${qty}`}
|
||||
</button>
|
||||
</div>
|
||||
) : (
|
||||
<div className="text-sm text-emerald-600 font-medium">Fully checked in ✓</div>
|
||||
)}
|
||||
</div>
|
||||
);
|
||||
})}
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
function OptionsModal({ open, onClose, options, quantities, setQuantities, minQuantities = {}, onConfirm, confirming, isEdit, totalPaid = 0 }: any) {
|
||||
if (!open) return null;
|
||||
|
||||
|
||||
@@ -85,6 +85,43 @@ function fmtCurrency(val: number) {
|
||||
return val === 0 ? "Free" : `R${val.toFixed(2)}`;
|
||||
}
|
||||
|
||||
function prefLabel(pref: "email" | "whatsapp" | "both") {
|
||||
return pref === "whatsapp" ? "WhatsApp" : pref === "both" ? "Email & WhatsApp" : "Email";
|
||||
}
|
||||
|
||||
// Loose "does this look like a mobile number" check — covers 0821234567 (10, leading 0),
|
||||
// 821234567 (9, no leading 0), and 27821234567 / +27821234567 (11 digits, country code).
|
||||
function looksLikePhone(s: string): boolean {
|
||||
const digits = s.replace(/\D/g, "");
|
||||
return digits.length >= 9 && digits.length <= 11;
|
||||
}
|
||||
|
||||
// Show/hide toggle rendered inside a password input — absolutely positioned on its
|
||||
// right edge, so callers must wrap the input in a `relative` container and add
|
||||
// enough right padding (`pr-12`) for it not to overlap the typed text.
|
||||
function PasswordToggleButton({ shown, onToggle }: { shown: boolean; onToggle: () => void }) {
|
||||
return (
|
||||
<button
|
||||
type="button"
|
||||
onClick={onToggle}
|
||||
tabIndex={-1}
|
||||
className="absolute inset-y-0 right-0 flex items-center px-4 text-gray-400 hover:text-gray-600"
|
||||
aria-label={shown ? "Hide password" : "Show password"}
|
||||
>
|
||||
{shown ? (
|
||||
<svg className="w-5 h-5" fill="none" viewBox="0 0 24 24" stroke="currentColor" strokeWidth={2}>
|
||||
<path strokeLinecap="round" strokeLinejoin="round" d="M3.98 8.223A10.477 10.477 0 001.934 12C3.226 16.338 7.244 19.5 12 19.5c1.563 0 3.042-.34 4.377-.955M6.228 6.228A10.45 10.45 0 0112 4.5c4.756 0 8.773 3.162 10.065 7.498a10.523 10.523 0 01-4.293 5.774M6.228 6.228L3 3m3.228 3.228l3.65 3.65m7.894 7.894L21 21m-3.228-3.228l-3.65-3.65m0 0a3 3 0 10-4.243-4.243m4.242 4.242L9.88 9.88" />
|
||||
</svg>
|
||||
) : (
|
||||
<svg className="w-5 h-5" fill="none" viewBox="0 0 24 24" stroke="currentColor" strokeWidth={2}>
|
||||
<path strokeLinecap="round" strokeLinejoin="round" d="M2.036 12.322a1.012 1.012 0 010-.639C3.423 7.51 7.36 4.5 12 4.5c4.638 0 8.573 3.007 9.963 7.178.07.207.07.431 0 .639C20.577 16.49 16.64 19.5 12 19.5c-4.638 0-8.573-3.007-9.963-7.178z" />
|
||||
<path strokeLinecap="round" strokeLinejoin="round" d="M15 12a3 3 0 11-6 0 3 3 0 016 0z" />
|
||||
</svg>
|
||||
)}
|
||||
</button>
|
||||
);
|
||||
}
|
||||
|
||||
// ─── Kiosk Page ───────────────────────────────────────────────────────────────
|
||||
export default function SelfServicePage() {
|
||||
const [screen, setScreen] = useState<Screen>("setup");
|
||||
@@ -92,6 +129,7 @@ export default function SelfServicePage() {
|
||||
// ── Setup state ─────────────────────────────────────────────────
|
||||
const [setupEmail, setSetupEmail] = useState("");
|
||||
const [setupPassword, setSetupPassword] = useState("");
|
||||
const [showSetupPassword, setShowSetupPassword] = useState(false);
|
||||
const [setupLoading, setSetupLoading] = useState(false);
|
||||
const [setupError, setSetupError] = useState<string | null>(null);
|
||||
const [supervisorToken, setSupervisorToken] = useState<string | null>(null);
|
||||
@@ -102,6 +140,7 @@ export default function SelfServicePage() {
|
||||
// ── Change-event modal ───────────────────────────────────────────
|
||||
const [showChangeModal, setShowChangeModal] = useState(false);
|
||||
const [changePassword, setChangePassword] = useState("");
|
||||
const [showChangePassword, setShowChangePassword] = useState(false);
|
||||
const [changeError, setChangeError] = useState<string | null>(null);
|
||||
const [changeLoading, setChangeLoading] = useState(false);
|
||||
|
||||
@@ -112,9 +151,23 @@ export default function SelfServicePage() {
|
||||
const [notificationPref, setNotificationPref] = useState<"email" | "whatsapp" | "both">("email");
|
||||
const [createAccount, setCreateAccount] = useState(false);
|
||||
const [visitorPassword, setVisitorPassword] = useState("");
|
||||
const [accountExists, setAccountExists] = useState(false);
|
||||
const [checkingAccount, setCheckingAccount] = useState(false);
|
||||
const [showVisitorPassword, setShowVisitorPassword] = useState(false);
|
||||
const [quantities, setQuantities] = useState<Record<string, number>>({});
|
||||
|
||||
// ── Account lookup (automatic, triggered when email/phone is entered) ──
|
||||
// Email and phone are resolved to an existing account independently. If they
|
||||
// resolve to the SAME account, that account is "matched". If they resolve to
|
||||
// two DIFFERENT accounts, that's a conflict — surfaced to the operator instead
|
||||
// of silently overwriting one field's details with the other's account.
|
||||
type MatchedAccount = { id: string; name: string; email: string | null; phoneNumber: string | null; notificationPreference: "email" | "whatsapp" | "both" };
|
||||
const [emailMatch, setEmailMatch] = useState<MatchedAccount | null>(null);
|
||||
const [phoneMatch, setPhoneMatch] = useState<MatchedAccount | null>(null);
|
||||
const accountConflict = !!(emailMatch && phoneMatch && emailMatch.id !== phoneMatch.id);
|
||||
const matchedAccount = accountConflict ? null : (emailMatch || phoneMatch);
|
||||
const accountExists = !!matchedAccount;
|
||||
const [lookupLoading, setLookupLoading] = useState(false);
|
||||
const [lookupMessage, setLookupMessage] = useState<string | null>(null);
|
||||
const [showUpdateConfirm, setShowUpdateConfirm] = useState(false);
|
||||
const [formLoading, setFormLoading] = useState(false);
|
||||
const [formError, setFormError] = useState<string | null>(null);
|
||||
|
||||
@@ -175,12 +228,39 @@ export default function SelfServicePage() {
|
||||
}, 0);
|
||||
}, [selectedEvent, quantities]);
|
||||
|
||||
// Differences between what's on file for the matched account and what's currently
|
||||
// typed in the form — shown to the operator for confirmation before anything is saved.
|
||||
const pendingChanges = useMemo(() => {
|
||||
if (!matchedAccount) return [];
|
||||
const changes: { field: string; from: string; to: string }[] = [];
|
||||
const name = visitorName.trim();
|
||||
const email = visitorEmail.trim();
|
||||
const phone = visitorPhone.trim();
|
||||
if (name && name !== matchedAccount.name) {
|
||||
changes.push({ field: "Name", from: matchedAccount.name, to: name });
|
||||
}
|
||||
if (email && email !== (matchedAccount.email || "")) {
|
||||
changes.push({ field: "Email", from: matchedAccount.email || "(none on file)", to: email });
|
||||
}
|
||||
if (phone && phone !== (matchedAccount.phoneNumber || "")) {
|
||||
changes.push({ field: "Phone", from: matchedAccount.phoneNumber || "(none on file)", to: phone });
|
||||
}
|
||||
if (notificationPref !== matchedAccount.notificationPreference) {
|
||||
changes.push({
|
||||
field: "Send tickets via",
|
||||
from: prefLabel(matchedAccount.notificationPreference),
|
||||
to: prefLabel(notificationPref),
|
||||
});
|
||||
}
|
||||
return changes;
|
||||
}, [matchedAccount, visitorName, visitorEmail, visitorPhone, notificationPref]);
|
||||
|
||||
// ─── Load events after supervisor login ─────────────────────────
|
||||
const loadEvents = useCallback(async (token: string) => {
|
||||
setEventsLoading(true);
|
||||
try {
|
||||
const data: KioskEvent[] = await apiFetch(
|
||||
"/api/events/all?includePast=false&includeInactive=false",
|
||||
"/api/events/all?includePast=false&includeInactive=false&excludeClosed=true",
|
||||
{ authToken: token }
|
||||
);
|
||||
setEvents(data);
|
||||
@@ -262,7 +342,9 @@ export default function SelfServicePage() {
|
||||
}
|
||||
|
||||
// ─── Visitor registration ────────────────────────────────────────
|
||||
async function handleRegister(e: React.FormEvent) {
|
||||
// Validates the form and, if the typed name/email/phone differ from the matched
|
||||
// account's details, shows a confirmation modal before anything is saved.
|
||||
function handleRegisterSubmit(e: React.FormEvent) {
|
||||
e.preventDefault();
|
||||
setFormError(null);
|
||||
if (!visitorName.trim() || (!visitorEmail.trim() && !visitorPhone.trim())) {
|
||||
@@ -277,7 +359,18 @@ export default function SelfServicePage() {
|
||||
setFormError("No event selected.");
|
||||
return;
|
||||
}
|
||||
if (accountConflict) {
|
||||
setFormError("The email and phone number entered belong to two different existing accounts. Please check and correct one of them before continuing.");
|
||||
return;
|
||||
}
|
||||
if (pendingChanges.length > 0) {
|
||||
setShowUpdateConfirm(true);
|
||||
return;
|
||||
}
|
||||
handleRegister();
|
||||
}
|
||||
|
||||
async function handleRegister() {
|
||||
setFormLoading(true);
|
||||
try {
|
||||
const payload: any = {
|
||||
@@ -415,7 +508,12 @@ export default function SelfServicePage() {
|
||||
setNotificationPref("email");
|
||||
setCreateAccount(false);
|
||||
setVisitorPassword("");
|
||||
setAccountExists(false);
|
||||
setShowVisitorPassword(false);
|
||||
setEmailMatch(null);
|
||||
setPhoneMatch(null);
|
||||
appliedMatchIdRef.current = null;
|
||||
setShowUpdateConfirm(false);
|
||||
setLookupMessage(null);
|
||||
setFormError(null);
|
||||
setCurrentRegistrationId(null);
|
||||
setCurrentUserId(null);
|
||||
@@ -431,33 +529,67 @@ export default function SelfServicePage() {
|
||||
};
|
||||
}, []);
|
||||
|
||||
// ─── Check whether an account already exists for the entered email/phone ──
|
||||
useEffect(() => {
|
||||
const email = visitorEmail.trim();
|
||||
const phone = visitorPhone.trim();
|
||||
if (!supervisorToken || (!email && !phone)) {
|
||||
setAccountExists(false);
|
||||
return;
|
||||
}
|
||||
const handle = setTimeout(async () => {
|
||||
setCheckingAccount(true);
|
||||
// ─── Automatic account lookup — runs once the operator finishes entering the
|
||||
// email or phone field (on blur), never on keystroke. Matches exactly against
|
||||
// that one value and only ever returns that one matched account (or nothing) —
|
||||
// never a broader/fuzzy match. Email and phone are tracked as two independent
|
||||
// matches (emailMatch/phoneMatch, above) rather than being merged into a single
|
||||
// "last found account" — that's what previously let changing the phone number
|
||||
// silently pull in and overwrite the form with an unrelated account's details. ──
|
||||
async function performLookup(kind: "email" | "phone", rawValue: string) {
|
||||
const value = rawValue.trim();
|
||||
const setMatch = kind === "email" ? setEmailMatch : setPhoneMatch;
|
||||
if (!value || !supervisorToken) { setMatch(null); return; }
|
||||
if (kind === "email" ? !value.includes("@") : !looksLikePhone(value)) { setMatch(null); return; }
|
||||
|
||||
setLookupLoading(true);
|
||||
setLookupMessage(null);
|
||||
try {
|
||||
const params = new URLSearchParams();
|
||||
if (email) params.set("email", email);
|
||||
if (phone) params.set("phone", phone);
|
||||
const data = await apiFetch<{ exists: boolean }>(
|
||||
`/api/users/check-exists?${params.toString()}`,
|
||||
{ authToken: supervisorToken }
|
||||
);
|
||||
setAccountExists(!!data?.exists);
|
||||
} catch {
|
||||
setAccountExists(false);
|
||||
} finally {
|
||||
setCheckingAccount(false);
|
||||
if (kind === "email") params.set("email", value);
|
||||
else params.set("phone", value);
|
||||
const data = await apiFetch<{
|
||||
exists: boolean;
|
||||
user?: MatchedAccount | null;
|
||||
}>(`/api/users/check-exists?${params.toString()}`, { authToken: supervisorToken });
|
||||
if (data?.exists && data.user) {
|
||||
setMatch(data.user);
|
||||
setLookupMessage("Account found — details filled in below.");
|
||||
} else {
|
||||
setMatch(null);
|
||||
setLookupMessage(null);
|
||||
}
|
||||
}, 400);
|
||||
return () => clearTimeout(handle);
|
||||
}, [visitorEmail, visitorPhone, supervisorToken]);
|
||||
} catch {
|
||||
setLookupMessage("Lookup failed. Please try again.");
|
||||
} finally {
|
||||
setLookupLoading(false);
|
||||
}
|
||||
}
|
||||
|
||||
function handleEmailBlur() {
|
||||
performLookup("email", visitorEmail);
|
||||
}
|
||||
|
||||
function handlePhoneBlur() {
|
||||
performLookup("phone", visitorPhone);
|
||||
}
|
||||
|
||||
// Autofill Name/Email/Phone/preference from the matched account — but only once per
|
||||
// distinct account id. Re-focusing elsewhere on the page (e.g. tapping a ticket
|
||||
// quantity button) blurs whatever field was last active and re-runs its lookup;
|
||||
// that returns the same account as a new object each time, and keying this off
|
||||
// object identity instead of id made it re-fire and stomp every field — including
|
||||
// ones the operator had already deliberately edited — back to the account's
|
||||
// original values on every unrelated tap.
|
||||
const appliedMatchIdRef = useRef<string | null>(null);
|
||||
useEffect(() => {
|
||||
if (!matchedAccount || appliedMatchIdRef.current === matchedAccount.id) return;
|
||||
appliedMatchIdRef.current = matchedAccount.id;
|
||||
setVisitorName(matchedAccount.name);
|
||||
if (matchedAccount.email) setVisitorEmail(matchedAccount.email);
|
||||
if (matchedAccount.phoneNumber) setVisitorPhone(matchedAccount.phoneNumber);
|
||||
setNotificationPref(matchedAccount.notificationPreference);
|
||||
}, [matchedAccount]);
|
||||
|
||||
// Existing accounts are linked automatically — never show the "create account" toggle for them
|
||||
useEffect(() => {
|
||||
@@ -494,15 +626,18 @@ export default function SelfServicePage() {
|
||||
<form onSubmit={handleChangeEvent} className="space-y-4">
|
||||
<div>
|
||||
<label className="block text-sm font-medium text-gray-700 mb-1">Password</label>
|
||||
<div className="relative">
|
||||
<input
|
||||
type="password"
|
||||
type={showChangePassword ? "text" : "password"}
|
||||
value={changePassword}
|
||||
onChange={(e) => setChangePassword(e.target.value)}
|
||||
className="w-full border border-gray-300 rounded-lg px-4 py-3 text-base focus:outline-none focus:ring-2 focus:ring-blue-500"
|
||||
className="w-full border border-gray-300 rounded-lg px-4 py-3 pr-12 text-base focus:outline-none focus:ring-2 focus:ring-blue-500"
|
||||
placeholder="Your password"
|
||||
autoFocus
|
||||
required
|
||||
/>
|
||||
<PasswordToggleButton shown={showChangePassword} onToggle={() => setShowChangePassword((v) => !v)} />
|
||||
</div>
|
||||
</div>
|
||||
{changeError && <p className="text-red-600 text-sm">{changeError}</p>}
|
||||
<div className="flex gap-3 pt-1">
|
||||
@@ -551,15 +686,18 @@ export default function SelfServicePage() {
|
||||
</div>
|
||||
<div>
|
||||
<label className="block text-sm font-medium text-gray-700 mb-1">Password</label>
|
||||
<div className="relative">
|
||||
<input
|
||||
type="password"
|
||||
type={showSetupPassword ? "text" : "password"}
|
||||
value={setupPassword}
|
||||
onChange={(e) => setSetupPassword(e.target.value)}
|
||||
className="w-full border border-gray-300 rounded-xl px-4 py-3 text-base focus:outline-none focus:ring-2 focus:ring-blue-500"
|
||||
className="w-full border border-gray-300 rounded-xl px-4 py-3 pr-12 text-base focus:outline-none focus:ring-2 focus:ring-blue-500"
|
||||
placeholder="••••••••"
|
||||
required
|
||||
autoComplete="current-password"
|
||||
/>
|
||||
<PasswordToggleButton shown={showSetupPassword} onToggle={() => setShowSetupPassword((v) => !v)} />
|
||||
</div>
|
||||
</div>
|
||||
{setupError && <p className="text-red-600 text-sm">{setupError}</p>}
|
||||
<button
|
||||
@@ -628,18 +766,7 @@ export default function SelfServicePage() {
|
||||
<p className="text-gray-500 text-sm mt-1">{fmtDate(selectedEvent.startDate)}</p>
|
||||
</div>
|
||||
|
||||
<form onSubmit={handleRegister} className="space-y-5">
|
||||
<div>
|
||||
<label className="block text-sm font-medium text-gray-700 mb-1">Full Name <span className="text-red-500">*</span></label>
|
||||
<input
|
||||
type="text"
|
||||
value={visitorName}
|
||||
onChange={(e) => setVisitorName(e.target.value)}
|
||||
className="w-full border border-gray-300 rounded-xl px-4 py-3.5 text-lg focus:outline-none focus:ring-2 focus:ring-blue-500"
|
||||
placeholder="John Smith"
|
||||
required
|
||||
/>
|
||||
</div>
|
||||
<form onSubmit={handleRegisterSubmit} className="space-y-5">
|
||||
<div>
|
||||
<label className="block text-sm font-medium text-gray-700 mb-1">
|
||||
Email Address
|
||||
@@ -656,6 +783,7 @@ export default function SelfServicePage() {
|
||||
if (v.trim() && !visitorPhone.trim()) setNotificationPref("email");
|
||||
else if (!v.trim() && visitorPhone.trim()) setNotificationPref("whatsapp");
|
||||
}}
|
||||
onBlur={handleEmailBlur}
|
||||
className="w-full border border-gray-300 rounded-xl px-4 py-3.5 text-lg focus:outline-none focus:ring-2 focus:ring-blue-500"
|
||||
placeholder="john@example.com"
|
||||
/>
|
||||
@@ -675,11 +803,40 @@ export default function SelfServicePage() {
|
||||
if (v.trim() && !visitorEmail.trim()) setNotificationPref("whatsapp");
|
||||
else if (!v.trim() && visitorEmail.trim()) setNotificationPref("email");
|
||||
}}
|
||||
onBlur={handlePhoneBlur}
|
||||
className="w-full border border-gray-300 rounded-xl px-4 py-3.5 text-lg focus:outline-none focus:ring-2 focus:ring-blue-500"
|
||||
placeholder="+27 82 000 0000"
|
||||
/>
|
||||
</div>
|
||||
|
||||
{lookupLoading && (
|
||||
<p className="text-sm text-gray-500 -mt-2">Checking for an existing account…</p>
|
||||
)}
|
||||
{!lookupLoading && accountConflict && emailMatch && phoneMatch && (
|
||||
<div className="bg-red-50 border border-red-200 rounded-xl px-4 py-3 text-red-700 text-sm -mt-2">
|
||||
This email matches an existing account for <strong>{emailMatch.name}</strong>, but this phone number
|
||||
matches a different existing account for <strong>{phoneMatch.name}</strong>. Please check and correct
|
||||
one of these fields before continuing.
|
||||
</div>
|
||||
)}
|
||||
{!lookupLoading && !accountConflict && lookupMessage && (
|
||||
<p className={`text-sm -mt-2 ${lookupMessage.startsWith("Account found") ? "text-green-700" : "text-gray-500"}`}>
|
||||
{lookupMessage}
|
||||
</p>
|
||||
)}
|
||||
|
||||
<div>
|
||||
<label className="block text-sm font-medium text-gray-700 mb-1">Full Name <span className="text-red-500">*</span></label>
|
||||
<input
|
||||
type="text"
|
||||
value={visitorName}
|
||||
onChange={(e) => setVisitorName(e.target.value)}
|
||||
className="w-full border border-gray-300 rounded-xl px-4 py-3.5 text-lg focus:outline-none focus:ring-2 focus:ring-blue-500"
|
||||
placeholder="John Smith"
|
||||
required
|
||||
/>
|
||||
</div>
|
||||
|
||||
{/* Preference selector — only shown when both channels are available */}
|
||||
{visitorEmail.trim() && visitorPhone.trim() && (
|
||||
<div>
|
||||
@@ -808,22 +965,23 @@ export default function SelfServicePage() {
|
||||
</div>
|
||||
<div>
|
||||
<p className="font-medium text-gray-800">Create an account</p>
|
||||
<p className="text-sm text-gray-500">
|
||||
{checkingAccount ? "Checking for an existing account…" : "Save your details for future events"}
|
||||
</p>
|
||||
<p className="text-sm text-gray-500">Save your details for future events</p>
|
||||
</div>
|
||||
</label>
|
||||
{createAccount && (
|
||||
<div className="mt-3">
|
||||
<label className="block text-sm font-medium text-gray-700 mb-1">Choose a password</label>
|
||||
<div className="relative">
|
||||
<input
|
||||
type="password"
|
||||
type={showVisitorPassword ? "text" : "password"}
|
||||
value={visitorPassword}
|
||||
onChange={(e) => setVisitorPassword(e.target.value)}
|
||||
className="w-full border border-gray-300 rounded-xl px-4 py-3 text-base focus:outline-none focus:ring-2 focus:ring-blue-500"
|
||||
className="w-full border border-gray-300 rounded-xl px-4 py-3 pr-12 text-base focus:outline-none focus:ring-2 focus:ring-blue-500"
|
||||
placeholder="Min. 6 characters"
|
||||
autoComplete="new-password"
|
||||
/>
|
||||
<PasswordToggleButton shown={showVisitorPassword} onToggle={() => setShowVisitorPassword((v) => !v)} />
|
||||
</div>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
@@ -837,7 +995,7 @@ export default function SelfServicePage() {
|
||||
|
||||
<button
|
||||
type="submit"
|
||||
disabled={formLoading}
|
||||
disabled={formLoading || accountConflict}
|
||||
className="w-full bg-blue-600 text-white rounded-xl py-4 text-xl font-bold hover:bg-blue-700 disabled:opacity-60 transition"
|
||||
>
|
||||
{formLoading ? "Registering…" : eventHasRequiredForm && mainTicketCount > 0 ? "Next — Fill in Form" : "Register"}
|
||||
@@ -847,6 +1005,43 @@ export default function SelfServicePage() {
|
||||
</div>
|
||||
)}
|
||||
|
||||
{/* ── Confirm Account Changes Modal ──────────────────────────── */}
|
||||
{showUpdateConfirm && (
|
||||
<div className="fixed inset-0 z-50 flex items-center justify-center bg-black/40">
|
||||
<div className="bg-white rounded-2xl shadow-2xl p-8 w-full max-w-sm mx-4">
|
||||
<h2 className="text-xl font-bold text-gray-800 mb-1">Confirm account changes</h2>
|
||||
<p className="text-sm text-gray-500 mb-5">
|
||||
These details differ from what's on file for this account. Confirm to update them.
|
||||
</p>
|
||||
<div className="space-y-3 mb-6">
|
||||
{pendingChanges.map((c) => (
|
||||
<div key={c.field} className="border border-gray-200 rounded-lg px-3 py-2">
|
||||
<p className="text-xs font-semibold text-gray-500 uppercase tracking-wide">{c.field}</p>
|
||||
<p className="text-sm text-gray-400 line-through">{c.from}</p>
|
||||
<p className="text-sm text-green-700 font-medium">{c.to}</p>
|
||||
</div>
|
||||
))}
|
||||
</div>
|
||||
<div className="flex gap-3">
|
||||
<button
|
||||
type="button"
|
||||
onClick={() => setShowUpdateConfirm(false)}
|
||||
className="flex-1 border border-gray-300 text-gray-700 rounded-lg py-3 text-base font-medium hover:bg-gray-50 transition"
|
||||
>
|
||||
Cancel
|
||||
</button>
|
||||
<button
|
||||
type="button"
|
||||
onClick={() => { setShowUpdateConfirm(false); handleRegister(); }}
|
||||
className="flex-1 bg-blue-600 text-white rounded-lg py-3 text-base font-semibold hover:bg-blue-700 transition"
|
||||
>
|
||||
Confirm & Update
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
)}
|
||||
|
||||
{/* ── Event Form Screen ──────────────────────────────────────── */}
|
||||
{screen === "eventform" && selectedEvent?.form && (
|
||||
<div className="flex-1 flex items-center justify-center p-6">
|
||||
|
||||
+3
-2
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "hope-events",
|
||||
"version": "1.2.0",
|
||||
"version": "1.3.2",
|
||||
"main": "index.js",
|
||||
"scripts": {
|
||||
"dev:backend": "cd backend && npm run dev",
|
||||
@@ -8,7 +8,8 @@
|
||||
"start:backend": "cd backend && npm run start",
|
||||
"start:frontend": "cd frontend && npm run start",
|
||||
"start": "concurrently \"npm run start:backend\" \"npm run start:frontend\"",
|
||||
"dev": "concurrently \"npm run dev:backend\" \"npm run dev:frontend\""
|
||||
"dev": "concurrently \"npm run dev:backend\" \"npm run dev:frontend\"",
|
||||
"build": "cd frontend && npm run build && cd .. && cd backend && npm run prisma:generate"
|
||||
},
|
||||
"keywords": [],
|
||||
"author": "",
|
||||
|
||||
Reference in New Issue
Block a user