Add admin-emailed one-time intake links
- intake_tokens table (server-only via service role) - Server functions: createIntakeToken (admin), getIntakeToken (public validate), submitIntake (public write + mark used, 14-day one-time tokens) - Public /intake/$token full intake form (no login) with valid/used/expired states - Student profile (admin): generate link, copy, and email-to-parent (mailto) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,14 @@
|
||||
-- One-time intake links: a token lets an unauthenticated parent fill out a
|
||||
-- student's intake. Reached only via server functions (service role); RLS on
|
||||
-- with no policies blocks all direct client access.
|
||||
CREATE TABLE IF NOT EXISTS public.intake_tokens (
|
||||
id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
|
||||
token TEXT NOT NULL UNIQUE,
|
||||
student_id UUID NOT NULL REFERENCES public.students(id) ON DELETE CASCADE,
|
||||
created_by UUID REFERENCES auth.users(id),
|
||||
expires_at TIMESTAMPTZ NOT NULL,
|
||||
used_at TIMESTAMPTZ,
|
||||
created_at TIMESTAMPTZ NOT NULL DEFAULT now()
|
||||
);
|
||||
CREATE INDEX IF NOT EXISTS idx_intake_tokens_token ON public.intake_tokens(token);
|
||||
ALTER TABLE public.intake_tokens ENABLE ROW LEVEL SECURITY;
|
||||
Reference in New Issue
Block a user