Files
accounted/app/(onboarding)/layout.tsx
T
Jakob WennbergandClaude Opus 4.8 b800dcd403 style(ui): system-wide UX/UI polish pass — design-system conformance + copy cleanup (#835)
* style(ui): system-wide UX/UI polish pass — design-system conformance + copy cleanup

Multi-agent scan of all 404 UI files against the locked design system, then
141 verified surgical fixes across 109 files (net -32 lines):

- Remove forbidden elevation/motion: shadow-* and rounded-xl on cards, active:scale
  bounce, hover:shadow on list items, transition-all -> transition-colors.
- Drop font-medium from single-weight Hedvig display headings/numerals.
- Replace raw rainbow Tailwind status colors with Badge variants / brand tokens /
  neutral surfaces (achromatic chrome, semantic colors stay data-only).
- Route raw dates through formatDate(), hand-rolled currency through formatCurrency(),
  add tabular-nums to financial figures; text-gray-* -> text-foreground tokens.
- Swap hand-rolled skeletons for the Skeleton primitive; off-scale spacing -> token scale.
- Fix copy: mislabeled "Leverantörsfakturor" -> "Utgifter" on bank-import outflow total,
  collapse no-op identical-branch ternaries, broken Swedish diacritics (mojibake),
  correct mismatch-password toast, correct supplier currency-field label.
- Remove PII-leaking debug console.log on register, stray console.logs.

Verified: tsc clean on all changed files, eslint clean, production build passes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(auth): sanitize residual error logs in register flow

Follow-up to PR review (compliance swarm V16 / GDPR Art.5(1)(f)): the
remaining console.error calls in the register flow passed raw error
objects, which Supabase may populate with PII (email) in nested fields.
Log only sanitized message strings instead.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-30 13:14:13 +02:00

58 lines
2.1 KiB
TypeScript

import Link from 'next/link'
import { Settings } from 'lucide-react'
import { createClient, createServiceClient } from '@/lib/supabase/server'
export default async function OnboardingLayout({
children,
}: {
children: React.ReactNode
}) {
const supabase = await createClient()
const { data: { user } } = await supabase.auth.getUser()
// Only show the settings escape hatch for users who have completed
// onboarding at least once — i.e. they have a company_members row, even if
// it points to an archived company. Absolute first-time users don't need
// it and it clutters the welcome screen.
//
// Must use the service client: RLS on company_members goes through
// user_company_ids(), which filters out archived companies, so an
// authenticated query would return nothing for a user who archived their
// last company and make the escape hatch disappear exactly when it's
// needed most. Scoped to user_id = user.id, so no cross-user exposure.
let hasCompletedOnboarding = false
if (user) {
const service = createServiceClient()
const { data } = await service
.from('company_members')
.select('company_id')
.eq('user_id', user.id)
.limit(1)
.maybeSingle()
hasCompletedOnboarding = !!data
}
return (
<div className="min-h-screen bg-background flex items-center justify-center">
<div className="w-full max-w-lg px-5">
{children}
</div>
{/* Escape hatch: a user who archived their last company can still
reach account settings (and the delete-account flow) from here.
Hidden for absolute first-time users (no memberships ever). */}
{user && hasCompletedOnboarding && (
<Link
href="/settings/account"
aria-label="Kontoinställningar"
title="Kontoinställningar"
className="fixed bottom-6 right-6 z-50 flex h-10 w-10 items-center justify-center rounded-full border border-border bg-background/80 text-muted-foreground shadow-sm backdrop-blur transition-colors hover:border-foreground/40 hover:text-foreground"
>
<Settings className="h-4 w-4" />
</Link>
)}
</div>
)
}