feat: push+email notifications, recipe notes, fork/clone, pantry-aware lists, GDPR export

Five S-sized items from HANDOFF.md's new-features backlog, all wiring up
previously-orphaned infra:

- createNotification now sends web push + email for every notification type
  (follow/comment/reply/reaction/rating/mention), not just comments
- Personal recipe notes: private per-user notes on any viewable recipe
  (recipeNotes table had zero API/UI before this)
- Recipe fork/clone: deep-copies a viewable recipe into your own library as
  a private draft, linked via recipeVariations, respects tier quota
- Pantry-aware shopping lists: meal-plan-generated lists now subtract
  on-hand pantry quantities (ingredientId match, falling back to normalized
  name match) and flag partial/ambiguous matches instead of guessing
- GDPR data export: downloadable JSON of a user's own content and activity
  across every relevant table, secrets/internal tables excluded

New migrations 0025 (unique index for recipe-notes upsert) and 0026
(shopping_list_items.in_pantry) generated, left unapplied like 0023/0024.
Verified with typecheck, lint, and a full local `docker build`.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Arnaud
2026-07-10 07:50:58 +02:00
parent d035378520
commit 45b886e398
23 changed files with 9813 additions and 23 deletions
@@ -4,7 +4,6 @@ import { db, recipes, comments, users, userBlocks, eq, and, inArray, isNull, sql
import { requireSession } from "@/lib/api-auth";
import { applyRateLimit } from "@/lib/rate-limit";
import { dispatchWebhook } from "@/lib/webhooks";
import { sendPushNotification } from "@/lib/push";
import { createNotification } from "@/lib/notifications";
import { isBlockedEitherWay } from "@/lib/blocks";
import { extractMentionedUsernames } from "@/lib/mentions";
@@ -126,14 +125,10 @@ export async function POST(req: NextRequest, { params }: Params) {
content: parsed.data.content,
});
// Dispatch to recipe author's webhooks (not to the commenter themselves)
// Dispatch to recipe author's webhooks (not to the commenter themselves).
// Push/email to the author are handled by createNotification's "comment" call below.
if (recipe.authorId !== session!.user.id) {
void dispatchWebhook(recipe.authorId, "comment.added", { commentId, recipeId: id, recipeTitle: recipe.title });
void sendPushNotification(recipe.authorId, {
title: "New comment on your recipe",
body: `${session!.user.name} commented on "${recipe.title}"`,
url: `/recipes/${id}`,
});
}
if (parent && parent.userId !== session!.user.id) {