Skip to content

[#612] Keep check-in QR codes valid across reloads - #613

Open
DVidal1205 wants to merge 2 commits into
mainfrom
2026/qr-pass-stability
Open

DVidal1205 wants to merge 2 commits into
mainfrom
2026/qr-pass-stability

Conversation

@DVidal1205

@DVidal1205 DVidal1205 commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Why

Reloading or reopening the 2026 dashboard issued a new check-in pass and revoked the previous pass. Screenshots then appeared as invalid_qr in Blade, leaving the operator without a resolved name, date of birth, or class during peak admission.

Closes: #612

What

  • reuse one check-in pass idempotency key across portal reloads and devices
  • allow an older unexpired pass while the same attendee still has an active, unexpired pass
  • preserve current opaque QR behavior and legacy user: QR handling
  • keep withdrawal and expiration invalidation intact
  • delete issued passes and the stable issuance command on withdrawal so reconfirmation gets a fresh pass without reviving old tokens
  • add database coverage for current, rotated, revoked, and expired pass combinations

No schema, environment variable, or dependency changes.

Test Plan

  • pnpm verify:precommit
  • disposable Postgres: packages/api/src/tests/hackathon-events/check-in.test.ts (15/15 passed)
  • disposable Postgres: withdrawal lifecycle test (1/1 passed)
  • standard Forge review: API, placement/minimality, and test-quality reviewers reported no remaining findings

Screenshots are not applicable because this changes QR issuance and scanner validation without changing UI.

Checklist

  • Database: No schema changes, OR I ran pnpm db:generate and committed the generated files in packages/db/drizzle/
  • Environment Variables: No environment variables changed, OR I have contacted the Development Lead to modify them on Coolify BEFORE merging.

Co-authored-by: Codex <codex@openai.com>
@DVidal1205 DVidal1205 added Bug Something isn't working Minor Small change - 1 reviewer required Hack Sites Change modifies code in a Hackathon app (ex. 2025) API Change modifies code in the global API/tRPC package Urgent labels Oct 9, 2026
@DVidal1205 DVidal1205 self-assigned this Oct 9, 2026
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

📝 Walkthrough

Walkthrough

The dashboard now uses a fixed idempotency key when requesting check-in passes. Check-in lookup can resolve a revoked token when another unexpired active pass exists for the attendee. Withdrawal revokes active passes and deletes matching issuance commands. Tests cover token resolution, expiration, and command cleanup.


Priority: ⬆️ High

Severity of issue fixed: Medium

Merge Risk: 🟡 Moderate · up to 1bb89

Check-in QR codes now stay valid across reloads. However, a QR code invalidated by withdrawal may start working again if the attendee reconfirms. This conflicts with the stated withdrawal-invalidation guarantee and should be resolved or explicitly accepted before merge.

Pre-merge checks | Passed 7 | Failed 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 5 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (7 passed)
Check name Status Explanation
Linked Issues check Passed Issue #612 requires stable unexpired QR resolution, continued invalidation after withdrawal or expiration, and coding tests. The portal now uses the stable check-in-pass:v1 key. Scanner lookup accep…
Out of Scope Changes check Passed All changed files support issue #612. The portal key change implements stable issuance. The scanner change implements rotated-pass resolution. Withdrawal cleanup preserves fresh reissuance. The added …
No Hardcoded Secrets Passed No hardcoded secret was introduced. The only credential-like added literal is the public idempotency key "check-in-pass:v1"; the QR payloads are deterministic test fixtures and are hashed before dat…
Validated Env Access Passed No new process.env usage appears in the pull-request diff. The existing direct usages in the modified test files were already present in the base revision.
No Typescript Escape Hatches Passed The pull-request additions contain no any type, @ts-ignore, @ts-expect-error, or non-null assertion (!.). The only any match in the changed files is an unchanged comment present in the base …
Title check Passed The title starts with [#612], clearly describes the QR-code change, and is 50 characters long.
Description check Passed The description directly explains the QR-code issuance, validation, withdrawal, expiration, and test changes.


  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR

🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

coderabbitai[bot]
coderabbitai Bot previously requested changes Oct 9, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration
  • Configuration used: Repository: KnightHacks/forge/.coderabbit.yml
  • Review profile: QUIET
  • Plan: Advanced
  • Run ID: e7b685bb-1658-435e-8f18-3307e20e38f5
📥 Commits

Reviewing files that changed from the base of the PR and between 82b70b7 and 1bb89e3.

📒 Files selected for processing (5)
  • apps/2026/src/lib/hacker-portal.tsx
  • packages/api/src/hacker-portal/mutations.ts
  • packages/api/src/tests/hackathon-events/check-in.test.ts
  • packages/api/src/tests/integration/hacker-portal-lifecycle.test.ts
  • packages/api/src/utils/hackathon-events/check-in.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

Comment thread packages/api/src/utils/hackathon-events/check-in.ts
Co-authored-by: Codex <codex@openai.com>
@DVidal1205
DVidal1205 dismissed coderabbitai[bot]’s stale review October 9, 2026 20:39

CodeRabbit confirmed the finding was addressed in 2882aa4 and resolved the review thread.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

API Change modifies code in the global API/tRPC package Bug Something isn't working Hack Sites Change modifies code in a Hackathon app (ex. 2025) Minor Small change - 1 reviewer required Urgent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Keep hackathon check-in QR codes stable

1 participant