Skip to content

Stuff - #283

Merged
gregv merged 6 commits into
mainfrom
develop
Sep 17, 2026
Merged

Stuff#283
gregv merged 6 commits into
mainfrom
develop

Conversation

@gregv

@gregv gregv commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

No description provided.

gregv and others added 6 commits September 14, 2026 13:28
Gate POST /api/admin/volunteer/<id>/select on volunteer.admin (was an
unverified "all" #TODO), require a real bool `selected`, clear the
in-process get_volunteer_by_event cache after a toggle (the admin list
served a stale isSelected before), and Slack-audit the change. The
volunteer admin frontend now writes the event-roster bit only through
this route; application status goes through the hackathon PATCH.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
update_hackathon_volunteers now runs validate_volunteer_admin_patch: drops
isSelected (written only by the select route) and the UI routing key
`type` with a warning, folds status onto ALLOWED_VOLUNTEER_STATUSES
(blank -> pending), and returns a Message on an unknown status. Deploy
after the select-route hardening and after the volunteer admin frontend.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…oute-hardening

Harden admin volunteer selection route (single writer for isSelected)
…rdening

Strip isSelected from generic volunteer PATCH; validate status (ship last)
…d every call

propelauth's require_org_member_with_permission does not inject the user/org
into the view; it sets the auth_user proxy and calls the view with Flask's URL
params only. Seven admin routes (select, both deposit refunds, the four
admin/<type>/<event_id> lists) were declared `def view(user, org, <param>)`
and raised TypeError (missing 'user' and 'org') on every request. The select
route surfaced it in Sentry once PR #280 made its auth gate actually pass.

- Read identity via auth_user.user_id; view params now match URL params.
- The four list routes also gain volunteer.admin + req_to_org_id=getOrgId
  (they were "all" with the default org resolver => always 403).
- Route-level regression tests via Flask test_client with common.auth stubbed;
  one asserts every view signature == its rule arguments so the class of bug
  can't recur. Verified they fail with the exact Sentry TypeError on develop.
- CLAUDE.md gotcha.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Fix admin volunteer routes: phantom (user, org) params 500'd every call
@gregv
gregv merged commit d6bcde5 into main Sep 17, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant