feat(auth): enforce onboarding before app access - #50
Open
maxstue wants to merge 2 commits into
Open
Conversation
Replace sign-in provisioning with an explicit current-user onboarding state and idempotent onboarding completion. Protect application endpoints and routes with onboarding and household-role authorization. Refs: KIJK-343
maxstue
marked this pull request as ready for review
August 1, 2026 09:29
Remove final newlines from the changed API files to match the API EditorConfig and satisfy the CI format check. Refs: KIJK-343
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
/users/meonboarding stateroute.tsxfilesWhy
Authenticated identities previously depended on sign-in provisioning and the frontend duplicated readiness assumptions. This made onboarding state and access control less explicit and could leave stale current-user data during authentication transitions.
Impact
The backend is now authoritative for whether onboarding is complete. Users who have not completed onboarding can access only the current-user and onboarding endpoints; application endpoints return
403. Ready users continue through the normal app routes, while the client consumes one shared current-user query.Validation
pnpm buildpnpm fmtpnpm lintdotnet format --verify-no-changesNotes
pnpm auditwas not executed because it sends dependency metadata to an external registry and that export was not separately authorized.Refs: KIJK-343