Skip to content

Promote develop to main: one-box email-or-mobile join, signed inbound texts (#24–#26) - #28

Merged
rvegajr merged 6 commits into
mainfrom
develop
Oct 2, 2026
Merged

rvegajr merged 6 commits into
mainfrom
develop

Conversation

@rvegajr

@rvegajr rvegajr commented Oct 2, 2026

Copy link
Copy Markdown
Member

Promotes develop (88eab15) to main, which deploys production. This is the same code that's live on uat via #27.

PR What
#24 One-box join: an email gets a 6-digit code by email, which works anywhere; a +1 mobile gets a text; phone is optional; the overflow question by email and on the schedule; add a mobile later; relay email client fixed; Secure cookies
#25 /webhooks/sms reads the relay's real format and checks x-relay-signature
#26 .railway/railway.ts preserves RELAY_INBOUND_SECRET

Migration 0011_email_signin is additive. Production has 0 coaches.

Verified on uat (6aedcbc):

  • one-box sign-in is live;
  • a +63 mobile is told to use email;
  • a real sign-in email was accepted by the relay (logged sent);
  • unsigned inbound returns 401;
  • the startup log shows Node v24.21.0.

RELAY_INBOUND_SECRET is already set on production as a placeholder. Until the relay's real secret replaces it, inbound texts are refused, which closes the webhook to spoofed "texts from a coach".

🤖 Generated with Claude Code

rvegajr and others added 6 commits October 2, 2026 09:20
Text codes reach only +1 numbers, so a coach anywhere else could not get
in. An email now gets a 6-digit code by email through the relay, a US or
Canadian mobile still gets a text, and a foreign mobile is pointed to
email. A coach with no phone gets the overflow question by email and
answers it on the schedule screen, and can add a mobile there later.
The relay email client is fixed to the relay's real shape.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Let a coach join with an email or a mobile in one box
…lay.

The relay forwards Twilio's own form fields (From, Body), signed with
x-relay-signature over the raw body. The webhook only read lowercase
JSON, so a real text would have been rejected. It now reads the raw body
in either shape and, once RELAY_INBOUND_SECRET is set, refuses anything
not signed by the relay for this exact URL.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Read inbound texts the way the relay sends them, and only from the relay
The web variables in .railway/railway.ts are exhaustive: apply deletes
any it omits. The inbound secret is set on all three environments now,
so the file preserves it, and the README says to add new variables.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Keep RELAY_INBOUND_SECRET when Railway config is applied
@rvegajr
rvegajr merged commit 7426f10 into main Oct 2, 2026
10 checks passed

This branch was previously deployed

1 inactive deployment
coachatron / development — 88eab158 Deployed Oct 2, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant