Merged
Conversation
Text codes reach only +1 numbers, so a coach anywhere else could not get in. An email now gets a 6-digit code by email through the relay, a US or Canadian mobile still gets a text, and a foreign mobile is pointed to email. A coach with no phone gets the overflow question by email and answers it on the schedule screen, and can add a mobile there later. The relay email client is fixed to the relay's real shape. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Let a coach join with an email or a mobile in one box
…lay. The relay forwards Twilio's own form fields (From, Body), signed with x-relay-signature over the raw body. The webhook only read lowercase JSON, so a real text would have been rejected. It now reads the raw body in either shape and, once RELAY_INBOUND_SECRET is set, refuses anything not signed by the relay for this exact URL. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Read inbound texts the way the relay sends them, and only from the relay
The web variables in .railway/railway.ts are exhaustive: apply deletes any it omits. The inbound secret is set on all three environments now, so the file preserves it, and the README says to add new variables. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Keep RELAY_INBOUND_SECRET when Railway config is applied
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Promotes
develop(88eab15) tostaging, which deploys uat.Securecookies/webhooks/smsreads the relay's real format (Twilio form fields, raw body) and checksx-relay-signature.railway/railway.tspreservesRELAY_INBOUND_SECRETMigration
0011_email_signinis additive (nullable phone, unique email, a channel column). uat has 0 coaches.RELAY_INBOUND_SECRETis already set on uat as a placeholder, so inbound texts are refused until the relay's real secret replaces it. No number is routed to Coachatron yet.Verified on development:
sent, SendGrid idK5GY0_opQu20gH_7pMM6oA);🤖 Generated with Claude Code