Repository navigation
Verification-code entry for browser social posts (+ Mastodon selector fix) - #65
Merged
Merged
Conversation
Platforms like LinkedIn interrupt a cookie session with "enter the 6-digit
code we sent you" before showing the composer, which stranded every
affected post. Adds a live human-in-the-loop flow (the approach chosen for
this): the worker keeps the SAME Chromium session open, pauses, and waits
for a code the user types in the UI.
- migration: sp_post gains verification_code / verification_prompt /
verification_requested_at (status 'awaiting_code' needs no enum change)
- lib/sp/verificationChallenge.ts: detectCodeChallenge (narrow one-time-code
/ pin / otp selectors), makeCodeWaiter (marks awaiting_code, polls sp_post
for the code up to 3 min, then flips back to publishing and clears it), and
handleCodeChallenge to fill + submit. Wired into all 7 platform flows right
after navigation.
- submitVerificationCode server action (owner-scoped, validates 4–8 digits)
- VerificationCodeInput component shown on 'awaiting_code' rows in both the
project Social post history and the /recent outreach history; awaiting_code
surfaced via deriveOutreachStatus and kept in the live-refresh set.
- Fix Mastodon compose selector: a bare getByRole("textbox") also matched the
search box and tripped strict-mode; scope it to the compose textarea.
Tests: makeCodeWaiter marks/returns/clears, times out, trims the code.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Browser-automated posts kept failing because platforms (LinkedIn especially) interrupt the cookie session with an identity challenge — "Enter the 6-digit code below to verify your identity." The automation had no way to supply that code, so the post died (and the other platforms' composer timeouts were largely the same challenge being served instead of the composer).
Approach — live paused session (chosen)
When a platform flow detects a code challenge, the worker keeps the same Chromium session open, marks the post
awaiting_code, and pollssp_post.verification_codefor a code the user submits in the UI — then types it into the live page and finishes posting. Same session that got challenged enters the code, so one-time codes work.Changes
20260704140000_sp_post_verification.sql:sp_postgainsverification_code,verification_prompt,verification_requested_at.statusis free text, so'awaiting_code'needs no enum change.lib/sp/verificationChallenge.ts:detectCodeChallenge— narrow selectors (autocomplete=one-time-code,name/id ~ pin|otp|verification,aria-label ~ verification code) so a normal field isn't mistaken for a challenge.makeCodeWaiter(supabase, postId)— marksawaiting_code+ prompt, polls up to 3 min, then flips back topublishingand clears the code (no replay).handleCodeChallenge— fills + submits + waits for the app to render. Wired into all 7 platform flows right after navigation.submitVerificationCodeserver action — owner-scoped, accepts 4–8 digits (strips spaces/dashes), only writes while the post isawaiting_code.VerificationCodeInputcomponent — shown onawaiting_coderows in both the project Social post history and the /recent outreach history (where the failures were reported).awaiting_codeis surfaced viaderiveOutreachStatusand kept in the live-refresh set so the row updates when posting completes.getByRole("textbox")also matched the "Search or paste URL" box and tripped strict-mode (resolved to 2 elements); scoped to the compose textarea.Verification
tsc --noEmitcleantests/sp/*35/35, incl. newverification-challenge.test.ts(waiter marksawaiting_code→ returns the submitted code → clears it; times out cleanly; trims the code)sp_postRLS (owner all) permits the owner UPDATE the action relies onDeploy note
The migration must be applied (I'll apply it to the Supabase project on merge, as with the exit-pages one). The
/recentand Social history queries select the new columns, so the DB change ships with the code.🤖 Generated with Claude Code