feat: implement Free Fire compatible teammate finder MVP - #36
Conversation
Co-authored-by: omharde42 <193398705+omharde42@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 29f4b8bd0f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| router.get('/profile', authenticate, freeFireController.getProfile.bind(freeFireController)); | ||
| router.post('/profile', authenticate, freeFireController.updateProfile.bind(freeFireController)); | ||
| router.get('/teammates', authenticate, freeFireController.discoverTeammates.bind(freeFireController)); | ||
| router.post('/request', authenticate, freeFireController.sendRequest.bind(freeFireController)); |
There was a problem hiding this comment.
Add a receiver-facing request flow
The request API has no read/list endpoint, while the new page only posts invites and never queries or displays received requests. The POST response (including its ID) only reaches the sender, so a receiver has no way to discover an invite or obtain the ID required by the PATCH endpoint; invites therefore remain pending in the shipped UI. Add a receiver inbox/list or notification flow with accept/decline actions.
Useful? React with 👍 / 👎.
| if (raterId === ratedUserId) { | ||
| throw new AppError('Self-rating is strictly prohibited', 400); | ||
| } | ||
|
|
||
| if (rating < 1 || rating > 5) { | ||
| throw new AppError('Rating must be between 1 and 5 stars', 400); |
There was a problem hiding this comment.
Require an accepted teammate relationship before rating
Any authenticated user can rate any other user because this method only rejects self-ratings and out-of-range values before upserting the rating and recalculating the target's reputation. A user can call this endpoint for strangers (and the UI exposes rating for every discovered candidate), so reputation scores can be deliberately inflated or damaged without a completed, accepted teammate interaction.
Useful? React with 👍 / 👎.
| if (request.receiverId !== userId && request.senderId !== userId) { | ||
| throw new AppError('Unauthorized to update this request', 403); | ||
| } |
There was a problem hiding this comment.
Restrict acceptance and decline to the request recipient
This authorization check allows either party to set every status. In particular, the sender receives the request ID from POST /request and can immediately PATCH their own outgoing invite to ACCEPTED, bypassing the recipient's consent. Permit ACCEPTED/DECLINED only for the receiver and CANCELLED only for the sender, while enforcing a pending-state transition.
Useful? React with 👍 / 👎.
| if (!profile) { | ||
| profile = await (prisma as any).freeFireProfile.create({ | ||
| data: { | ||
| userId, | ||
| isVerified: false, // Always false per Anti-Fabrication Policy | ||
| }, |
There was a problem hiding this comment.
Make lazy profile creation race-safe
On a first visit, the page starts both the profile and teammate queries, and teammate discovery calls getProfile too. Both requests can pass findUnique before either insert commits, after which the second create violates the unique userId constraint and returns an error instead of teammate results. Use an upsert or handle the unique-conflict retry path.
Useful? React with 👍 / 👎.
| createdAt DateTime @default(now()) | ||
| updatedAt DateTime @updatedAt | ||
|
|
||
| @@unique([senderId, receiverId, status]) |
There was a problem hiding this comment.
Allow repeated terminal requests from the same pair
The service permits a new request once the prior one is no longer PENDING, but this constraint permits only one row for each terminal status as well. For example, after a request is declined, a new request can be created, but declining that second request conflicts with the existing (senderId, receiverId, DECLINED) row and produces an unhandled database error. Make the uniqueness rule apply only to pending requests or remove status from this composite key.
Useful? React with 👍 / 👎.
| await (prisma as any).freeFireProfile.update({ | ||
| where: { userId: ratedUserId }, | ||
| data: { | ||
| reputationScore: parseFloat(avgRating.toFixed(2)), | ||
| completedSessions: { increment: 1 }, | ||
| }, |
There was a problem hiding this comment.
Count sessions only when a rating is first created
Ratings are upserted by the unique rater/target pair, so submitting a revised rating updates the existing rating but still executes this increment. Re-rating the same teammate repeatedly therefore inflates the displayed completed-session count despite no additional session having occurred; increment only on the create path.
Useful? React with 👍 / 👎.
…Free Fire MVP Co-authored-by: omharde42 <193398705+omharde42@users.noreply.github.com>
Implemented the validated Free Fire Compatible Teammate Finder MVP for GamerZ Hub. Features include self-reported Free Fire profile configuration, teammate discovery with transparent/explainable compatibility scoring, squad invitation workflow, and post-session trust/reputation rating while adhering strictly to GamerZ Hub's Anti-Fabrication Policy for non-API games.
PR created automatically by Jules for task 1504719854435836066 started by @omharde42