feat: push+email notifications, recipe notes, fork/clone, pantry-aware lists, GDPR export

Five S-sized items from HANDOFF.md's new-features backlog, all wiring up
previously-orphaned infra:

- createNotification now sends web push + email for every notification type
  (follow/comment/reply/reaction/rating/mention), not just comments
- Personal recipe notes: private per-user notes on any viewable recipe
  (recipeNotes table had zero API/UI before this)
- Recipe fork/clone: deep-copies a viewable recipe into your own library as
  a private draft, linked via recipeVariations, respects tier quota
- Pantry-aware shopping lists: meal-plan-generated lists now subtract
  on-hand pantry quantities (ingredientId match, falling back to normalized
  name match) and flag partial/ambiguous matches instead of guessing
- GDPR data export: downloadable JSON of a user's own content and activity
  across every relevant table, secrets/internal tables excluded

New migrations 0025 (unique index for recipe-notes upsert) and 0026
(shopping_list_items.in_pantry) generated, left unapplied like 0023/0024.
Verified with typecheck, lint, and a full local `docker build`.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Arnaud
2026-07-10 07:50:58 +02:00
parent d035378520
commit 45b886e398
23 changed files with 9813 additions and 23 deletions
@@ -4,7 +4,6 @@ import { db, recipes, comments, users, userBlocks, eq, and, inArray, isNull, sql
import { requireSession } from "@/lib/api-auth";
import { applyRateLimit } from "@/lib/rate-limit";
import { dispatchWebhook } from "@/lib/webhooks";
import { sendPushNotification } from "@/lib/push";
import { createNotification } from "@/lib/notifications";
import { isBlockedEitherWay } from "@/lib/blocks";
import { extractMentionedUsernames } from "@/lib/mentions";
@@ -126,14 +125,10 @@ export async function POST(req: NextRequest, { params }: Params) {
content: parsed.data.content,
});
// Dispatch to recipe author's webhooks (not to the commenter themselves)
// Dispatch to recipe author's webhooks (not to the commenter themselves).
// Push/email to the author are handled by createNotification's "comment" call below.
if (recipe.authorId !== session!.user.id) {
void dispatchWebhook(recipe.authorId, "comment.added", { commentId, recipeId: id, recipeTitle: recipe.title });
void sendPushNotification(recipe.authorId, {
title: "New comment on your recipe",
body: `${session!.user.name} commented on "${recipe.title}"`,
url: `/recipes/${id}`,
});
}
if (parent && parent.userId !== session!.user.id) {
@@ -0,0 +1,94 @@
import { NextRequest, NextResponse } from "next/server";
import { db, recipes, recipeIngredients, recipeSteps, recipeVariations } from "@epicure/db";
import { eq, and, or, inArray } from "@epicure/db";
import { requireSessionOrApiKey } from "@/lib/api-auth";
import { checkAndIncrementTierLimit, TierLimitError } from "@/lib/tiers";
type Params = { params: Promise<{ id: string }> };
export async function POST(req: NextRequest, { params }: Params) {
const { session, response } = await requireSessionOrApiKey(req, { rateLimit: { limit: 20, windowSeconds: 60 } });
if (response) return response;
const { id } = await params;
const source = await db.query.recipes.findFirst({
where: and(
eq(recipes.id, id),
or(eq(recipes.authorId, session!.user.id), inArray(recipes.visibility, ["public", "unlisted"]))
),
with: {
ingredients: { orderBy: (t, { asc }) => asc(t.order) },
steps: { orderBy: (t, { asc }) => asc(t.order) },
},
});
if (!source) return NextResponse.json({ error: "Not found" }, { status: 404 });
try {
await checkAndIncrementTierLimit(session!.user.id, session!.user.tier as "free" | "pro", "recipe");
} catch (err) {
if (err instanceof TierLimitError) {
return NextResponse.json({ error: "Recipe limit reached for your tier" }, { status: 403 });
}
throw err;
}
const newId = crypto.randomUUID();
const now = new Date();
await db.transaction(async (tx) => {
await tx.insert(recipes).values({
id: newId,
authorId: session!.user.id,
title: source.title,
description: source.description,
baseServings: source.baseServings,
visibility: "private",
difficulty: source.difficulty,
prepMins: source.prepMins,
cookMins: source.cookMins,
tags: source.tags,
dietaryTags: source.dietaryTags ?? {},
aiGenerated: false,
language: source.language,
createdAt: now,
updatedAt: now,
});
if (source.ingredients.length > 0) {
await tx.insert(recipeIngredients).values(
source.ingredients.map((ing) => ({
id: crypto.randomUUID(),
recipeId: newId,
rawName: ing.rawName,
quantity: ing.quantity,
unit: ing.unit,
note: ing.note,
order: ing.order,
}))
);
}
if (source.steps.length > 0) {
await tx.insert(recipeSteps).values(
source.steps.map((step) => ({
id: crypto.randomUUID(),
recipeId: newId,
instruction: step.instruction,
timerSeconds: step.timerSeconds,
order: step.order,
}))
);
}
await tx.insert(recipeVariations).values({
id: crypto.randomUUID(),
parentRecipeId: source.id,
childRecipeId: newId,
description: null,
aiGenerated: false,
createdAt: now,
});
});
return NextResponse.json({ id: newId }, { status: 201 });
}
@@ -0,0 +1,76 @@
import { NextRequest, NextResponse } from "next/server";
import { db, recipes, recipeNotes, eq, and, or, inArray } from "@epicure/db";
import { z } from "zod";
import { requireSessionOrApiKey } from "@/lib/api-auth";
type Params = { params: Promise<{ id: string }> };
const PutSchema = z.object({
content: z.string().max(5000),
});
async function assertRecipeAccessible(recipeId: string, userId: string) {
const recipe = await db.query.recipes.findFirst({
where: and(
eq(recipes.id, recipeId),
or(eq(recipes.authorId, userId), inArray(recipes.visibility, ["public", "unlisted"]))
),
columns: { id: true },
});
return recipe;
}
export async function GET(req: NextRequest, { params }: Params) {
const { session, response } = await requireSessionOrApiKey(req, { rateLimit: { limit: 60, windowSeconds: 60 } });
if (response) return response;
const { id } = await params;
const recipe = await assertRecipeAccessible(id, session!.user.id);
if (!recipe) return NextResponse.json({ error: "Not found" }, { status: 404 });
const note = await db.query.recipeNotes.findFirst({
where: and(eq(recipeNotes.recipeId, id), eq(recipeNotes.userId, session!.user.id)),
columns: { content: true, updatedAt: true },
});
return NextResponse.json({ note: note ?? null });
}
export async function PUT(req: NextRequest, { params }: Params) {
const { session, response } = await requireSessionOrApiKey(req, { rateLimit: { limit: 60, windowSeconds: 60 } });
if (response) return response;
const { id } = await params;
const recipe = await assertRecipeAccessible(id, session!.user.id);
if (!recipe) return NextResponse.json({ error: "Not found" }, { status: 404 });
const parsed = PutSchema.safeParse(await req.json());
if (!parsed.success) {
return NextResponse.json({ error: "Validation error", issues: parsed.error.issues }, { status: 400 });
}
const content = parsed.data.content.trim();
const userId = session!.user.id;
if (content.length === 0) {
await db
.delete(recipeNotes)
.where(and(eq(recipeNotes.recipeId, id), eq(recipeNotes.userId, userId)));
return NextResponse.json({ note: null });
}
await db
.insert(recipeNotes)
.values({ id: crypto.randomUUID(), recipeId: id, userId, content, updatedAt: new Date() })
.onConflictDoUpdate({
target: [recipeNotes.recipeId, recipeNotes.userId],
set: { content, updatedAt: new Date() },
});
const note = await db.query.recipeNotes.findFirst({
where: and(eq(recipeNotes.recipeId, id), eq(recipeNotes.userId, userId)),
columns: { content: true, updatedAt: true },
});
return NextResponse.json({ note });
}
@@ -53,6 +53,6 @@ export async function POST(req: NextRequest, { params }: Params) {
reviewText: parsed.data.reviewText,
photoKey: parsed.data.photoKey,
});
void createNotification({ userId: recipe.authorId, type: "rating", actorId: session!.user.id, recipeId: id });
void createNotification({ userId: recipe.authorId, type: "rating", actorId: session!.user.id, recipeId: id, score: parsed.data.score });
return NextResponse.json({ created: true }, { status: 201 });
}