Commit Graph
98 Commits
Author SHA1 Message Date
admin ef71239759 Modified by www.SourceFiles.app 2026-08-07 04:13:12 +00:00
admin c4daba6b18 Modified by www.SourceFiles.app 2026-08-07 04:13:11 +00:00
admin a8586947b8 Modified by www.SourceFiles.app 2026-08-07 04:13:11 +00:00
admin 4226fc683b Modified by www.SourceFiles.app 2026-08-07 04:13:10 +00:00
admin a53c040cf3 Modified by www.SourceFiles.app 2026-08-07 04:13:10 +00:00
admin 35cb11b274 Modified by www.SourceFiles.app 2026-08-07 04:13:09 +00:00
admin 23e87485aa Modified by www.SourceFiles.app 2026-08-07 04:13:09 +00:00
admin c9d668f5c8 Modified by www.SourceFiles.app 2026-08-07 04:13:08 +00:00
admin a36c89817d Modified by www.SourceFiles.app 2026-08-07 04:13:08 +00:00
admin 1dc69aeb50 Modified by www.SourceFiles.app 2026-08-07 04:13:07 +00:00
admin 936e3c7aed Modified by www.SourceFiles.app 2026-08-07 04:12:35 +00:00
admin dae48fcb11 Modified by www.SourceFiles.app 2026-08-07 04:12:34 +00:00
admin 62e0e2a48c Modified by www.SourceFiles.app 2026-08-07 04:12:33 +00:00
admin 00b437e0d0 Modified by www.SourceFiles.app 2026-08-07 04:12:33 +00:00
admin 147a6f2b13 Modified by www.SourceFiles.app 2026-08-07 04:12:32 +00:00
adminandClaude Opus 5 d2d4e49fa6 Add embedded IMAP/SMTP mail for staff
Admins configure one mail server; each staff member gets their own mailbox
login. Read, reply and compose against real IMAP/SMTP.

IMAP and SMTP are raw TCP, so none of this can run in a browser — every
operation is a TanStack Start server function. mail.functions.ts ships to
the client bundle, so imapflow/nodemailer/mailparser and the crypto
helpers are imported inside handlers, never at the top level. Verified
that Nitro inlines all three into .output/server/_libs, since the Docker
runner stage copies only .output and has no node_modules.

Note this ties the app to the Node deployment: the default local build
targets Cloudflare Workers, which cannot open IMAP sockets.

Credential handling, since a mailbox password grants full read and send
access to someone's mail:

- user_mailboxes has RLS enabled, no policies, and SELECT revoked from
  anon and authenticated. Verified: teacher and admin both see zero rows
  and no ciphertext; only service_role can read it. The revoke is belt and
  braces — Supabase's default privileges had granted SELECT, leaving the
  table one stray policy away from leaking.
- Passwords are sealed with AES-256-GCM using MAIL_CRED_KEY from
  .env.secret, so a database dump alone opens nothing. GCM also makes
  tampering fail the auth tag instead of decrypting to garbage.
- Provisioning verifies credentials against the live IMAP server before
  storing them, so typos surface at setup rather than as a broken inbox.

Message bodies render as plain text; sender HTML is never injected, which
would execute sender-controlled markup and leak read receipts via
tracking pixels.

Mailboxes are limited to admins and teachers. Students are excluded
deliberately — external mail for minors carries archiving, monitoring and
consent obligations that should be chosen, not inherited.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 10:46:47 -04:00
adminandClaude Opus 5 53ab6b92b5 Let admins edit, deactivate and delete forms
The database already permitted all three (forms admin manage is FOR ALL);
this was purely a missing UI. Create and edit now share one editor, since
the only differences are the initial values and insert vs update.

Three hazards in the existing data model shaped this rather than just
adding buttons:

- form_responses.form_id is ON DELETE CASCADE, so deleting a form
  permanently destroys its submissions. The confirmation names the
  response count and points to deactivating instead. Verified: deleting a
  form with two responses leaves zero.

- The list filtered active = true for everyone, so deactivating a form
  hid it from the only people who could reactivate it. Admins now see
  inactive forms with a badge; families still see only active ones.

- Responses key their answers by field *label* in data_json, so renaming
  a field strands existing answers under the old key. The editor warns
  when the form already has responses. Deliberately not migrating old
  answers — guessing which old label maps to which new one would risk
  silently rewriting submitted data.

Also strips fields with blank labels on save, shows a response count per
form, and gives the response list an empty state.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 10:26:42 -04:00
adminandClaude Opus 5 9360bf3055 Add printable report cards, progress reports and invoices
Three documents, all print-styled rather than generated server-side: no
PDF dependency is added, and "Save as PDF" in the browser produces the
file. @media print in styles.css strips the app chrome (.no-print) and
breaks each student onto its own sheet (.print-page).

- Report card: weighted category breakdown, overall percent and letter
  from the existing gradebook config, plus an attendance summary.
- Academic progress report: the same, plus assignment-level detail —
  a mid-term report is only actionable with the underlying work listed.
- 504 / IEP progress report: each goal's baseline, target, status and
  progress entries within the period, for the quarterly report IDEA
  requires. RLS keeps it to the case manager, admins and parents.
- Invoice, reachable per student from the tuition ledger: opening
  balance carried forward, itemised activity, and balance due.

Grade maths is reused from lib/grades and the class grading config from
useEffectiveConfig, so report cards cannot drift from the gradebook.

The "Email to parents" button opens a prefilled mailto: draft — the same
mechanism the intake-link share already uses. It gathers addresses from
intake guardians and linked parent accounts. mailto cannot attach a file,
so the itemisation goes in the body as text; sending a real attachment
would need a transactional email provider and an API key.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 09:45:46 -04:00
adminandClaude Opus 5 85d87d1c62 Charge tuition automatically from attendance
Adds a per-student daily rate (students.daily_tuition_cents) and a trigger
that writes a tuition charge when a student is marked present or late.

Idempotency is the crux. The attendance UI upserts on (student_id, date)
and teachers toggle a status freely — present, absent, present again. A
naive "insert a charge on attendance" trigger bills the family once per
click. So each auto-charge is bound to the attendance row that caused it
via ledger_entries.attendance_id (UNIQUE), which turns the write into an
upsert, lets a change back to absent delete the charge, and cascades the
charge away if the attendance record is deleted.

Manual entries keep attendance_id NULL — Postgres allows unlimited NULLs
in a unique index — so hand-entered charges are untouched and the UI can
tell auto from manual.

A NULL rate (the default) means never auto-charge, so nothing begins
billing until a rate is deliberately set on a student. Existing
attendance is not backfilled: retroactively generating charges against
families' balances should be an explicit decision, not a side effect of
deploying a migration.

The trigger is SECURITY DEFINER because the writer is a teacher marking
attendance while ledger_entries is admin-write under RLS; teachers gain
no general ledger access, only this fixed attendance-derived write.

Verified against the live schema across all eight paths: charge on
present, reversal on absent, no duplicate on re-mark, late billable,
excused free, no rate means no charge, rate change on re-save, and
cascade on attendance delete.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 09:45:30 -04:00
adminandClaude Opus 5 9d7d18669d Add 504 / IEP plans with tiered confidentiality
Plans, accommodations, related services, annual goals with progress
monitoring, meetings/team, and signed documents — plus a compliance
list and dashboard alerts for annual-review and triennial re-evaluation
dates (overdue in red, due-within-30-days in amber).

Access is tiered because special-education records are need-to-know
under FERPA:

  FULL  admin, the plan's case manager, the student's parents
  IMPL  the above, plus any teacher of the student — accommodations
        and services only, never eligibility or meeting notes

RLS is row-level and every app role is the same Postgres role
(`authenticated`), so column grants cannot separate the tiers. The
split is therefore physical: confidential fields live in plan_details,
plan_goals, plan_meetings and plan_documents rather than as columns on
student_plans.

The UI asks the database which tier applies via the same predicates the
policies use (can_view_plan_full / can_edit_plan) instead of re-deriving
the rules client-side.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 09:14:40 -04:00
adminandClaude Opus 4.8 872eacefc5 Read profile date inputs from the DOM at save (Safari-proof)
Safari doesn't reliably fire onChange for native date pickers, so read dob/
start/agreement dates directly from the input refs when saving.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 20:01:55 -04:00
adminandClaude Opus 4.8 e95171a0d4 Make remaining date inputs Safari-safe (uncontrolled)
Attendance filter, gradebook assignment date, and tuition entry date now use
defaultValue (with a remount key where the field resets after submit).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 19:46:33 -04:00
adminandClaude Opus 4.8 d3c9c71564 Brand with Bayside Academy navy + logo
- Theme primary -> Bayside navy (#06315a) in light & dark, sidebar + focus ring
- Bayside logo in the sidebar, login page, and public intake header
- Login title -> Bayside Academy

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 19:42:19 -04:00
adminandClaude Opus 4.8 471d31cee6 Fix dates not saving on Safari; show grade level under student name
Safari's native <input type="date"> gets reset by React's controlled value,
so picked dates never reached state. Make date inputs uncontrolled
(defaultValue + onChange) in the profile, academics, and public intake forms.
Header now shows grade level instead of a single class.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 19:37:07 -04:00
adminandClaude Opus 4.8 90e3c2c188 Add admin-emailed one-time intake links
- intake_tokens table (server-only via service role)
- Server functions: createIntakeToken (admin), getIntakeToken (public validate),
  submitIntake (public write + mark used, 14-day one-time tokens)
- Public /intake/$token full intake form (no login) with valid/used/expired states
- Student profile (admin): generate link, copy, and email-to-parent (mailto)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 18:00:39 -04:00
adminandClaude Opus 4.8 eb94c7ec34 Fix student profile dates not saving
Native date pickers blur/refocus the window, which triggered a React Query
refetch mid-edit and wiped the in-progress date. Disable refetchOnWindowFocus,
and make profile/academics edits work on a snapshot with functional state
updates so a background refetch can't clobber input.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 17:50:53 -04:00
adminandClaude Opus 4.8 8880d7a805 Lock student profile editing to admins only
Parents and teachers are now view-only on student data (profile, guardians,
pickups, curriculum logins). Writes restricted to admins in RLS and the UI;
read access unchanged. Portal logins for parents/students are view-only.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 17:32:45 -04:00
adminandClaude Opus 4.8 9020b214f3 Fix empty class dropdown on Attendance for admins
The classes query filtered by teacher_id when isAdmin was momentarily false
(roles not yet loaded) and never refetched — cache key lacked isAdmin. Gate on
!loading and include isAdmin in the query key.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 17:11:25 -04:00
adminandClaude Opus 4.8 8fe6ad00f4 Gradebook: classes, weighted grading, assignments, grades, student role
- Migration: student role, students.user_id, grade_categories/grade_scale
  (school defaults + per-class override), assignments, grades + RLS
- Classes area (nav): list/create classes, class page with Gradebook / Roster /
  Grading setup tabs; teachers see their classes, admins all
- Weighted-category grade calc -> letter scale (shared helper)
- Roster assignment (admin), assignment + grade entry (teacher/admin)
- Student profile: view-only Grades tab (parents/students)
- Portal access: create parent OR student logins linked to the student

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 16:57:27 -04:00
adminandClaude Opus 4.8 73a4e70f0b Parent hand-off: admin creates parent/teacher accounts + portal edit
- Admin server function (service-role) to create accounts, set role, and
  optionally link a parent to a student; wired via env_file (.env.secret)
- Admin > Users: "Add a user" form (teacher/parent/admin) with one-time temp password
- Student profile > Family: "Parent portal access" — create + link a parent login
- Parents can now edit their own child's profile (RLS-scoped); internal notes stay admin-only

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 16:30:56 -04:00
adminandClaude Opus 4.8 894b0722e0 Student profile: read-only view by default, Edit button to edit
Profile / Family & pickup / Academics tabs now render a clean read-only
view with an Edit toggle that reveals the editable form (Save/Cancel/Done).
Guardian/pickup/login cards show summaries in view mode, inputs in edit mode.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 16:21:04 -04:00
adminandClaude Opus 4.8 48cf441cba Profile model: quick-create + full editable student profile
- /students/new: quick create (name + DOB) -> redirects into the profile
- /students/$id: full editable profile with photo upload, and tabs for
  Profile / Family & pickup (guardians, emergency contacts, pickups) /
  Academics (curriculum logins + records) / Attendance / Tuition / Contracts
- Migration: students.photo_path + private student-photos storage bucket
  (admin write, linked-user read); regenerate types

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-19 16:13:36 -04:00
adminandClaude Opus 4.8 9d5b11bb10 Fix blank /students/new and /students/$id (missing Outlet)
students.tsx was the list AND the parent of students.new / students.$id but
rendered no <Outlet/>, so child routes never showed. Make students.tsx an
Outlet layout and move the list to students.index.tsx. Add an errorComponent
to students.new as a safety net.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 22:42:45 -04:00
adminandClaude Opus 4.8 cee27a6189 Add full-page student intake form matching Bayside paper forms
- Migration: student intake fields (health, academic, dismissal, agreement),
  student_guardians + student_curriculum_logins tables, extend authorized_pickups
  (alt_phone, notes, kind) with RLS mirroring existing policies
- New /students/new full-page multi-section form (replaces the add dialog)
- Students list links to the full page; regenerate Supabase types

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 22:21:38 -04:00
adminandClaude Opus 4.8 45d36827d2 Migrate backend from Lovable Cloud to own Supabase (EDU project)
- Point .env + supabase/config.toml at EDU (qgmcpounpkgsjlwosjdi)
- Replace Lovable Google-OAuth shim with native supabase.auth.signInWithOAuth
- Remove src/integrations/lovable and @lovable.dev/cloud-auth-js dependency
- Drop .lovable metadata; gitignore supabase/.temp

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-18 18:04:18 -04:00
gpt-engineer-app[bot]andrenee-png c36d2b24e9 Update site info for publish
Edited UI in Lovable

Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:56:28 +00:00
gpt-engineer-app[bot]andrenee-png 516397c518 Changes
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:46:00 +00:00
gpt-engineer-app[bot]andrenee-png cbea663981 Changes
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:45:51 +00:00
gpt-engineer-app[bot]andrenee-png 5489371d45 Changes
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:45:30 +00:00
gpt-engineer-app[bot]andrenee-png 477e5fcdc3 Changes
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:45:23 +00:00
gpt-engineer-app[bot]andrenee-png b422766132 Changes
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:45:10 +00:00
gpt-engineer-app[bot]andrenee-png 79d124e188 Changes
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:45:02 +00:00
gpt-engineer-app[bot]andrenee-png 002f4d00f0 Changes
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:44:47 +00:00
gpt-engineer-app[bot]andrenee-png eeeae5181a Changes
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:44:37 +00:00
gpt-engineer-app[bot]andrenee-png e094b56e1b Changes
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:41:49 +00:00
gpt-engineer-app[bot]andrenee-png 8cf9b95cff Changes
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:41:43 +00:00
gpt-engineer-app[bot]andrenee-png a2a4e6c811 Changes
Co-authored-by: renee-png <262607627+renee-png@users.noreply.github.com>
2026-06-30 20:41:27 +00:00
Lovable cb75921659 template: tanstack_start_ts_current-40f3c252c0da 2025-01-01 00:00:00 +00:00