Skip to content

c0upons accounts on the forum: bridge host endpoints - #80

Merged
ralyodio merged 1 commit into
masterfrom
feat/bbs-bridge
Oct 6, 2026
Merged

ralyodio merged 1 commit into
masterfrom
feat/bbs-bridge

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

c0upons members are signed in to the forum at https://c0upons.com/bbs automatically. If they're signed in here, they arrive there signed in, with no prompt.

  • GET /api/v1/bridge/authorize and POST /api/v1/bridge/token, via @profullstack/bridges: OAuth 2.1 authorization code + PKCE S256. The one client is the forum (tsbb), and its callback is matched exactly. The bridge stays off (404) unless BRIDGE_TSBB_SECRET is set; it's already in the c0upons--prod vault.
  • Who the forum receives: sub is the member's CoinPay DID, and name is their CoinPay name. No email is passed as verified, because CoinPay doesn't verify emails. The forum also offers "Continue with CoinPay", which uses the same DID, so either way in reaches one forum account.
  • lib/members.ts: remembers the CoinPay name at sign-in, since sessions carry only the DID. The table creates itself, because migrations don't run on deploy. Members signed in before this change get their name the next time they sign in.

Pairs with profullstack/tsbb#41. Typecheck is clean. Lint fails only on errors that already exist on master, none in these files.

🤖 Generated with Claude Code

/api/v1/bridge/authorize and /token (@profullstack/bridges, OAuth 2.1 code +
PKCE): the forum at /bbs signs c0upons members in, silently when they are
already signed in here. sub is the member's CoinPay DID, so CoinPay sign-in
on the forum lands on the same account. Off unless BRIDGE_TSBB_SECRET is set.

lib/members.ts: the CoinPay name is remembered at sign-in (sessions carry only
the DID); the table creates itself, as migrations are not run on deploy.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Comment thread apps/web/lib/members.ts

export async function memberByDid(did: string): Promise<Member | null> {
await ensureTable();
const rows = await getDb().sql`SELECT did, name, email FROM members WHERE did = ${did}`;
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

32 finding(s)

MEDIUM: 29 | LOW: 3

Severity Rule Location
MEDIUM sql-template-interpolation apps/web/app/api/bounties/[id]/claim/route.ts:18
MEDIUM sql-template-interpolation apps/web/app/api/bounties/[id]/claim/route.ts:34
MEDIUM sql-template-interpolation apps/web/app/api/bounties/[id]/claim/route.ts:43
MEDIUM sql-template-interpolation apps/web/app/api/bounties/route.ts:81
MEDIUM sql-template-interpolation apps/web/app/api/coupons/route.ts:68
MEDIUM sql-template-interpolation apps/web/app/api/coupons/route.ts:75
MEDIUM sql-template-interpolation apps/web/app/api/coupons/vote/route.ts:31
MEDIUM sql-template-interpolation apps/web/app/api/coupons/vote/route.ts:33
MEDIUM sql-template-interpolation apps/web/app/api/stores/[slug]/route.ts:9
MEDIUM sql-template-interpolation apps/web/app/api/webhooks/crawlproof/route.ts:83
MEDIUM sql-template-interpolation apps/web/app/api/webhooks/crawlproof/route.ts:90
MEDIUM js-open-redirect apps/web/app/bounties/new/page.tsx:57
MEDIUM js-unescaped-html-sink apps/web/app/coupons/[id]/page.tsx:57
MEDIUM js-unescaped-html-sink apps/web/app/layout.tsx:81
MEDIUM sql-template-interpolation apps/web/app/stores/[slug]/page.tsx:15
MEDIUM sql-template-interpolation apps/web/lib/flipp-sync.ts:445
MEDIUM sql-template-interpolation apps/web/lib/inbound-email.ts:570
MEDIUM sql-template-interpolation apps/web/lib/mcp-tools.ts:81
MEDIUM sql-template-interpolation apps/web/lib/members.ts:54
MEDIUM sql-template-interpolation apps/web/lib/nichedb-sync.ts:186
MEDIUM sql-template-interpolation apps/web/lib/nichedb-sync.ts:206
MEDIUM sql-template-interpolation apps/web/lib/reddit-sync.ts:336
MEDIUM sql-template-interpolation apps/web/lib/reddit-sync.ts:355
MEDIUM sql-template-interpolation apps/web/lib/reddit-sync.ts:361
MEDIUM sql-template-interpolation apps/web/lib/reveal-coupon.ts:115
MEDIUM sql-template-interpolation apps/web/lib/reveal-coupon.ts:170
MEDIUM sh-predictable-temp-path apps/web/public/install.sh:37
MEDIUM sh-predictable-temp-path apps/web/public/install.sh:39
MEDIUM sql-template-interpolation apps/web/scripts/migrate.mjs:192
LOW sql-template-interpolation test/inbound-email.test.mjs:139
LOW sql-template-interpolation test/reveal-sweep.test.mjs:69
LOW sql-template-interpolation test/reveal-sweep.test.mjs:112

Snippets are redacted; ThreatCrush never prints matched credential material.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​profullstack/​bridges@​0.1.07410010090100

View full report

@ralyodio
ralyodio merged commit 67eba73 into master Oct 6, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants