* style(ui): system-wide UX/UI polish pass — design-system conformance + copy cleanup Multi-agent scan of all 404 UI files against the locked design system, then 141 verified surgical fixes across 109 files (net -32 lines): - Remove forbidden elevation/motion: shadow-* and rounded-xl on cards, active:scale bounce, hover:shadow on list items, transition-all -> transition-colors. - Drop font-medium from single-weight Hedvig display headings/numerals. - Replace raw rainbow Tailwind status colors with Badge variants / brand tokens / neutral surfaces (achromatic chrome, semantic colors stay data-only). - Route raw dates through formatDate(), hand-rolled currency through formatCurrency(), add tabular-nums to financial figures; text-gray-* -> text-foreground tokens. - Swap hand-rolled skeletons for the Skeleton primitive; off-scale spacing -> token scale. - Fix copy: mislabeled "Leverantörsfakturor" -> "Utgifter" on bank-import outflow total, collapse no-op identical-branch ternaries, broken Swedish diacritics (mojibake), correct mismatch-password toast, correct supplier currency-field label. - Remove PII-leaking debug console.log on register, stray console.logs. Verified: tsc clean on all changed files, eslint clean, production build passes. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(auth): sanitize residual error logs in register flow Follow-up to PR review (compliance swarm V16 / GDPR Art.5(1)(f)): the remaining console.error calls in the register flow passed raw error objects, which Supabase may populate with PII (email) in nested fields. Log only sanitized message strings instead. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
58 lines
2.1 KiB
TypeScript
58 lines
2.1 KiB
TypeScript
import Link from 'next/link'
|
|
import { Settings } from 'lucide-react'
|
|
import { createClient, createServiceClient } from '@/lib/supabase/server'
|
|
|
|
export default async function OnboardingLayout({
|
|
children,
|
|
}: {
|
|
children: React.ReactNode
|
|
}) {
|
|
const supabase = await createClient()
|
|
const { data: { user } } = await supabase.auth.getUser()
|
|
|
|
// Only show the settings escape hatch for users who have completed
|
|
// onboarding at least once — i.e. they have a company_members row, even if
|
|
// it points to an archived company. Absolute first-time users don't need
|
|
// it and it clutters the welcome screen.
|
|
//
|
|
// Must use the service client: RLS on company_members goes through
|
|
// user_company_ids(), which filters out archived companies, so an
|
|
// authenticated query would return nothing for a user who archived their
|
|
// last company and make the escape hatch disappear exactly when it's
|
|
// needed most. Scoped to user_id = user.id, so no cross-user exposure.
|
|
let hasCompletedOnboarding = false
|
|
if (user) {
|
|
const service = createServiceClient()
|
|
const { data } = await service
|
|
.from('company_members')
|
|
.select('company_id')
|
|
.eq('user_id', user.id)
|
|
.limit(1)
|
|
.maybeSingle()
|
|
hasCompletedOnboarding = !!data
|
|
}
|
|
|
|
return (
|
|
<div className="min-h-screen bg-background flex items-center justify-center">
|
|
<div className="w-full max-w-lg px-5">
|
|
{children}
|
|
</div>
|
|
|
|
{/* Escape hatch: a user who archived their last company can still
|
|
reach account settings (and the delete-account flow) from here.
|
|
Hidden for absolute first-time users (no memberships ever). */}
|
|
{user && hasCompletedOnboarding && (
|
|
<Link
|
|
href="/settings/account"
|
|
aria-label="Kontoinställningar"
|
|
title="Kontoinställningar"
|
|
className="fixed bottom-6 right-6 z-50 flex h-10 w-10 items-center justify-center rounded-full border border-border bg-background/80 text-muted-foreground shadow-sm backdrop-blur transition-colors hover:border-foreground/40 hover:text-foreground"
|
|
>
|
|
<Settings className="h-4 w-4" />
|
|
</Link>
|
|
)}
|
|
|
|
</div>
|
|
)
|
|
}
|