security: access control for particles (#169)

* setup firebase custom token

* docs

* docs

* feat: allow admin removing members from a network

* fix: properly handle fallback avatar and names

This is especially helpful in the case of members who were removed from
a network
This commit was merged in pull request #169.
This commit is contained in:
Arjun Patel
2026-04-16 15:14:34 -07:00
committed by GitHub
parent 28b1ff542b
commit ef899ee5cd
36 changed files with 805 additions and 169 deletions
+16
View File
@@ -1,8 +1,19 @@
import { create } from "zustand";
import { signInWithCustomToken, signOut as firebaseSignOut } from "firebase/auth";
import { apiClient, ApiError } from "@/api/client";
import type { Human } from "@/api/types";
import { firebaseAuth } from "@/firebase";
import { useSessionStore } from "./session-store";
async function signInToFirebase() {
try {
const { token } = await apiClient.getFirebaseToken();
await signInWithCustomToken(firebaseAuth, token);
} catch (e) {
console.error("Failed to sign in to Firebase", e);
}
}
type AuthStatus = "idle" | "restoring" | "unauthenticated" | "authenticated";
interface AuthState {
@@ -37,6 +48,7 @@ export const useAuthStore = create<AuthState>((set) => ({
set({ status: "restoring" });
try {
const user = await apiClient.me();
await signInToFirebase();
set({ status: "authenticated", user });
} catch {
useSessionStore.getState().clearToken();
@@ -63,6 +75,7 @@ export const useAuthStore = create<AuthState>((set) => ({
try {
const { human, token } = await apiClient.signIn({ email, code });
useSessionStore.getState().setToken(token);
await signInToFirebase();
set({ status: "authenticated", user: human });
} catch (e) {
const message =
@@ -81,6 +94,9 @@ export const useAuthStore = create<AuthState>((set) => ({
} catch {
// Best-effort — sign out locally regardless
} finally {
await firebaseSignOut(firebaseAuth).catch((e) =>
console.error("Firebase sign-out failed", e),
);
useSessionStore.getState().clearToken();
set({
status: "unauthenticated",