mirror of
https://github.com/multica-ai/multica.git
synced 2026-08-12 19:06:06 +02:00
tokens.css defined colours, radii and font families but not a single --text-* step, so font sizes had no baseline to align to and grew wherever they were needed: 51 distinct sizes across web + desktop, 370 written as arbitrary values, six at half a pixel (10.5 / 11.5 / 12.5 / 13.5 / 14.5 / 15.5px). text-xs and text-sm carried nearly all UI text while the range between them — 11, 13, 15px — could only be reached with arbitrary values. Hierarchy does not come from having more sizes; past a handful, each extra size makes the hierarchy blurrier. Add ten role-named steps, each with its own line-height so leading cannot fragment the way size did, and move every product-UI call site onto them. Steps are named for what the text is for, not for a t-shirt size, because that is what keeps the scale from drifting again. Six steps deliberately keep the exact size/line-height pairs of the Tailwind defaults they replace, so the ~1,900-call-site rename moves nothing on screen. The visible changes are confined to former arbitrary values snapping to a step: 8/9/10px -> micro (11px) on badges and overlines; 17 -> 18; 22 -> 24; 30 (text-3xl) -> 36 on headings and stat numbers; 12.8px -> label (13px) on small buttons and toggles. Half-pixel sizes are gone. This supersedes #6108, which was reverted by #6116 because the sidebar group labels rendered at the inherited 16px. The cause was not the scale but cn(): `text-<x>` is ambiguous in Tailwind, and tailwind-merge resolves it against a table listing only the default sizes, so it filed every role step under text-colour and dropped whichever of `text-caption` / `text-sidebar-foreground/70` came first. Registering the steps as a font-size class group restores the real conflict groups — size beats size, colour beats colour, the two coexist — and a test pins the list against the scale, since the failure is silent in source. Hand-written CSS is covered too. The transcript kept a 12.5px body long after every Tailwind call site was on the scale, so the "no half-pixel sizes" claim was true of the classes and false of the product; the editor's prose, code and mermaid ramps had the same blind spot, and seven of their eight values already equalled a step exactly. All now reference var(--text-*). The guard test reads raw `font-size:` declarations as well as class names, exempting only the 16px iOS input-zoom workaround in base.css and the landing pages' marketing ramp. apps/mobile (own NativeWind config) and apps/docs (fumadocs' own type system) keep Tailwind's default scale and are untouched. Landing display type (rem/clamp, 2.2-6.4rem) stays on its separate ramp, as do four decorative emoji / serif-hero sizes. Verified on a running local stack: pinned sidebar rows and group labels measure 12px/16px, nav items 14px/20px — identical to pre-migration. An audit of every rendered font size across the product surfaces finds nothing off the scale; the only exceptions are avatar initials and emoji, which actor-avatar.tsx sizes proportionally to the avatar diameter by design. Co-authored-by: Lambda <lambda@multica.ai> Co-authored-by: multica-agent <github@multica.ai>
212 lines
8.1 KiB
TypeScript
212 lines
8.1 KiB
TypeScript
"use client";
|
|
|
|
import { Suspense, useEffect, useState } from "react";
|
|
import { useSearchParams, useRouter } from "next/navigation";
|
|
import { useQueryClient } from "@tanstack/react-query";
|
|
import { sanitizeNextUrl, useAuthStore } from "@multica/core/auth";
|
|
import { workspaceKeys } from "@multica/core/workspace/queries";
|
|
import { paths, resolvePostAuthDestination } from "@multica/core/paths";
|
|
import { api } from "@multica/core/api";
|
|
import { validateCliCallback, redirectToCliCallback } from "@multica/views/auth";
|
|
import {
|
|
Card,
|
|
CardHeader,
|
|
CardTitle,
|
|
CardDescription,
|
|
CardContent,
|
|
} from "@multica/ui/components/ui/card";
|
|
import { Button } from "@multica/ui/components/ui/button";
|
|
import { Loader2 } from "lucide-react";
|
|
|
|
function CallbackContent() {
|
|
const router = useRouter();
|
|
const searchParams = useSearchParams();
|
|
const qc = useQueryClient();
|
|
const loginWithGoogle = useAuthStore((s) => s.loginWithGoogle);
|
|
const [error, setError] = useState("");
|
|
const [desktopToken, setDesktopToken] = useState<string | null>(null);
|
|
|
|
useEffect(() => {
|
|
const code = searchParams.get("code");
|
|
if (!code) {
|
|
setError("Missing authorization code");
|
|
return;
|
|
}
|
|
|
|
const errorParam = searchParams.get("error");
|
|
if (errorParam) {
|
|
setError(errorParam === "access_denied" ? "Access denied" : errorParam);
|
|
return;
|
|
}
|
|
|
|
const state = searchParams.get("state") || "";
|
|
const stateParts = state.split(",");
|
|
const isDesktop = stateParts.includes("platform:desktop");
|
|
const nextPart = stateParts.find((p) => p.startsWith("next:"));
|
|
// Strip "next:" prefix, then drop anything that isn't a safe relative path
|
|
// so an attacker-controlled `state=next:https://evil` cannot redirect here.
|
|
const nextUrl = sanitizeNextUrl(nextPart ? nextPart.slice(5) : null);
|
|
|
|
// CLI callback params — carried across the Google OAuth round-trip so
|
|
// headless/WSL2 `multica login` can receive the JWT after browser-based
|
|
// Google auth completes.
|
|
const cliCallbackPart = stateParts.find((p) => p.startsWith("cli_callback:"));
|
|
const cliStatePart = stateParts.find((p) => p.startsWith("cli_state:"));
|
|
const cliCallbackRaw = cliCallbackPart
|
|
? decodeURIComponent(cliCallbackPart.slice("cli_callback:".length))
|
|
: null;
|
|
const cliState = cliStatePart
|
|
? decodeURIComponent(cliStatePart.slice("cli_state:".length))
|
|
: "";
|
|
|
|
const redirectUri = `${window.location.origin}/auth/callback`;
|
|
|
|
// Validate the CLI callback URL before redirecting — the state parameter
|
|
// passes through Google OAuth and must be treated as attacker-controlled.
|
|
const cliCallback =
|
|
cliCallbackRaw && validateCliCallback(cliCallbackRaw)
|
|
? cliCallbackRaw
|
|
: null;
|
|
|
|
if (cliCallback) {
|
|
// CLI login flow: exchange the Google code for a JWT, then redirect the
|
|
// token back to the CLI's local HTTP listener (e.g. WSL2 host).
|
|
api
|
|
.googleLogin(code, redirectUri)
|
|
.then(({ token }) => {
|
|
redirectToCliCallback(cliCallback, token, cliState);
|
|
})
|
|
.catch((err) => {
|
|
setError(err instanceof Error ? err.message : "Login failed");
|
|
});
|
|
} else if (isDesktop) {
|
|
// Desktop flow: exchange code for token, then redirect via deep link
|
|
api
|
|
.googleLogin(code, redirectUri)
|
|
.then(({ token }) => {
|
|
setDesktopToken(token);
|
|
window.location.href = `multica://auth/callback?token=${encodeURIComponent(token)}`;
|
|
})
|
|
.catch((err) => {
|
|
setError(err instanceof Error ? err.message : "Login failed");
|
|
});
|
|
} else {
|
|
// Normal web flow
|
|
loginWithGoogle(code, redirectUri)
|
|
.then(async (loggedInUser) => {
|
|
const wsList = await api.listWorkspaces();
|
|
qc.setQueryData(workspaceKeys.list(), wsList);
|
|
const onboarded = loggedInUser.onboarded_at != null;
|
|
|
|
// 1. nextUrl wins: a `next=/invite/<id>` always survives the OAuth
|
|
// round-trip — the user clicked a specific link and we should
|
|
// honor exactly that destination.
|
|
if (nextUrl) {
|
|
router.push(nextUrl);
|
|
return;
|
|
}
|
|
|
|
// 2. Un-onboarded users may have pending invitations on their
|
|
// email even when no `next=` was carried (came from a fresh
|
|
// login on multica.ai instead of clicking the email link,
|
|
// or `state` was lost across the round-trip). Look them up by
|
|
// email and route to the batch /invitations page if any.
|
|
// Already-onboarded users skip this lookup — their new invites
|
|
// surface in the sidebar dropdown, not as a forced wall.
|
|
if (!onboarded) {
|
|
try {
|
|
const invites = await api.listMyInvitations();
|
|
if (invites.length > 0) {
|
|
qc.setQueryData(workspaceKeys.myInvitations(), invites);
|
|
router.push(paths.invitations());
|
|
return;
|
|
}
|
|
} catch {
|
|
// Network blip on the invite lookup is non-fatal — fall through
|
|
// to the normal post-auth destination so the user isn't stuck
|
|
// on a blank callback screen. Worst case they land on
|
|
// /onboarding and the sidebar will surface invites later.
|
|
}
|
|
}
|
|
|
|
// 3. Default: hand off to the resolver (onboarding for first-timers,
|
|
// first workspace for returning users, /workspaces/new for
|
|
// onboarded users with zero workspaces). Source-attribution
|
|
// backfill for onboarded users with no recorded source is
|
|
// handled by `<SourceBackfillModal />` inside the dashboard
|
|
// shell — not a route detour, so we route straight to dest.
|
|
router.push(resolvePostAuthDestination(wsList, onboarded));
|
|
})
|
|
.catch((err) => {
|
|
setError(err instanceof Error ? err.message : "Login failed");
|
|
});
|
|
}
|
|
}, [searchParams, loginWithGoogle, router, qc]);
|
|
|
|
if (desktopToken) {
|
|
return (
|
|
<div className="flex min-h-screen items-center justify-center">
|
|
<Card className="w-full max-w-sm">
|
|
<CardHeader className="text-center">
|
|
<CardTitle className="text-display-sm">Opening Multica</CardTitle>
|
|
<CardDescription>
|
|
You should see a prompt to open the Multica desktop app. If
|
|
nothing happens, click the button below.
|
|
</CardDescription>
|
|
</CardHeader>
|
|
<CardContent className="flex justify-center">
|
|
<Button
|
|
variant="outline"
|
|
onClick={() => {
|
|
window.location.href = `multica://auth/callback?token=${encodeURIComponent(desktopToken)}`;
|
|
}}
|
|
>
|
|
Open Multica Desktop
|
|
</Button>
|
|
</CardContent>
|
|
</Card>
|
|
</div>
|
|
);
|
|
}
|
|
|
|
if (error) {
|
|
return (
|
|
<div className="flex min-h-screen items-center justify-center">
|
|
<Card className="w-full max-w-sm">
|
|
<CardHeader className="text-center">
|
|
<CardTitle className="text-display-sm">Login Failed</CardTitle>
|
|
<CardDescription>{error}</CardDescription>
|
|
</CardHeader>
|
|
<CardContent className="flex justify-center">
|
|
<a href={paths.login()} className="text-primary underline-offset-4 hover:underline">
|
|
Back to login
|
|
</a>
|
|
</CardContent>
|
|
</Card>
|
|
</div>
|
|
);
|
|
}
|
|
|
|
return (
|
|
<div className="flex min-h-screen items-center justify-center">
|
|
<Card className="w-full max-w-sm">
|
|
<CardHeader className="text-center">
|
|
<CardTitle className="text-display-sm">Signing in...</CardTitle>
|
|
<CardDescription>Please wait while we complete your login</CardDescription>
|
|
</CardHeader>
|
|
<CardContent className="flex justify-center">
|
|
<Loader2 className="h-6 w-6 animate-spin text-muted-foreground" />
|
|
</CardContent>
|
|
</Card>
|
|
</div>
|
|
);
|
|
}
|
|
|
|
export default function CallbackPage() {
|
|
return (
|
|
<Suspense fallback={null}>
|
|
<CallbackContent />
|
|
</Suspense>
|
|
);
|
|
}
|