feat: collections visibility enum (matches recipes) + QR on collection PDF (v0.54.0)

Replaces collections.isPublic (boolean) with collections.visibility
(private/unlisted/public/followers — same enum recipes use). Two-step
migration (0050 adds+backfills, 0051 drops isPublic) since drizzle-kit's
add+drop-in-one-diff rename heuristic needs an interactive prompt we
can't satisfy here.

New collectionVisibleToViewer(viewerId) in lib/visibility.ts mirrors the
existing recipe helper (author always sees own; public/unlisted visible
to anyone; followers-only via the same user_follows EXISTS pattern) —
used by the collection detail page, its print view, fork, and favorite,
replacing their old `or(isPublic, own)` checks.

Create/edit collection dialogs get the same 4-option visibility select
as the recipe form instead of a public/private checkbox.

Collection PDF export now generates a QR code (qrcode, same as the
recipe PDF) linking to /collections/{id}, shown only when visibility is
public/unlisted — same "would an anonymous scanner actually resolve
this" rule as the recipe QR.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Arnaud
2026-07-19 19:26:34 +02:00
parent b1f745da66
commit 9da57dd1d0
25 changed files with 11217 additions and 56 deletions
+6 -8
View File
@@ -4,7 +4,8 @@ import { headers } from "next/headers";
import Link from "next/link";
import { Printer, UtensilsCrossed, StickyNote } from "lucide-react";
import { auth } from "@/lib/auth/server";
import { db, collections, eq, and, or } from "@epicure/db";
import { db, collections, eq, and } from "@epicure/db";
import { collectionVisibleToViewer } from "@/lib/visibility";
import { RecipeGridCard } from "@/components/recipe/recipe-grid-card";
import { CollectionRecipesGrid } from "@/components/collections/collection-recipes-grid";
import { ForkCollectionButton } from "@/components/collections/fork-collection-button";
@@ -32,10 +33,7 @@ export default async function CollectionPage({ params }: Params) {
const m = getMessages((session.user as { locale?: string }).locale);
const col = await db.query.collections.findFirst({
where: and(
eq(collections.id, id),
or(eq(collections.userId, session.user.id), eq(collections.isPublic, true))
),
where: and(eq(collections.id, id), collectionVisibleToViewer(session.user.id)),
with: {
recipes: {
orderBy: (t, { asc }) => asc(t.position),
@@ -63,7 +61,7 @@ export default async function CollectionPage({ params }: Params) {
</div>
)}
<p className="text-sm text-muted-foreground mt-1">
{recipeList.length} recipe{recipeList.length !== 1 ? "s" : ""} · {col.isPublic ? "Public" : "Private"}
{recipeList.length} recipe{recipeList.length !== 1 ? "s" : ""} · {m.recipe.visibility[col.visibility]}
</p>
{isOwner && col.notes && (
<div className="mt-2 flex items-start gap-2 rounded-lg border bg-muted/30 px-3 py-2 text-sm text-muted-foreground max-w-2xl">
@@ -103,11 +101,11 @@ export default async function CollectionPage({ params }: Params) {
initialDescription={col.description}
initialNotes={col.notes}
initialTags={col.tags}
initialIsPublic={col.isPublic}
initialVisibility={col.visibility}
/>
)}
{isOwner && <DeleteCollectionDialog collectionId={id} />}
{!isOwner && col.isPublic && (
{!isOwner && (col.visibility === "public" || col.visibility === "unlisted") && (
<ForkCollectionButton collectionId={id} />
)}
</div>
@@ -49,7 +49,7 @@ export default async function ExploreCollectionsPage() {
collectionFavorites,
and(eq(collectionFavorites.collectionId, collections.id), gte(collectionFavorites.createdAt, sevenDaysAgo))
)
.where(eq(collections.isPublic, true))
.where(eq(collections.visibility, "public"))
.groupBy(collections.id, users.id)
.orderBy(desc(sql`count(${collectionFavorites.collectionId})`))
.limit(12);
@@ -63,7 +63,7 @@ export default async function ExploreCollectionsPage() {
})
.from(collections)
.innerJoin(users, eq(collections.userId, users.id))
.where(eq(collections.isPublic, true))
.where(eq(collections.visibility, "public"))
.orderBy(desc(collections.createdAt))
.limit(12);
+1 -1
View File
@@ -66,7 +66,7 @@ export default async function CollectionsPage({
name: col.name,
description: col.description,
tags: col.tags,
isPublic: col.isPublic,
visibility: col.visibility,
recipeCount: countByCollection.get(col.id) ?? 0,
thumbnails: col.recipes.flatMap((r) => {
if (!r.recipe) return [];
@@ -1,6 +1,7 @@
import { NextRequest, NextResponse } from "next/server";
import { db, collections, collectionFavorites, eq, and, or } from "@epicure/db";
import { db, collections, collectionFavorites, eq, and } from "@epicure/db";
import { requireSessionOrApiKey } from "@/lib/api-auth";
import { collectionVisibleToViewer } from "@/lib/visibility";
type Params = { params: Promise<{ id: string }> };
@@ -10,7 +11,7 @@ export async function POST(req: NextRequest, { params }: Params) {
const { id } = await params;
const collection = await db.query.collections.findFirst({
where: and(eq(collections.id, id), or(eq(collections.isPublic, true), eq(collections.userId, session!.user.id))),
where: and(eq(collections.id, id), collectionVisibleToViewer(session!.user.id)),
columns: { id: true },
});
if (!collection) return NextResponse.json({ error: "Not found" }, { status: 404 });
@@ -1,6 +1,7 @@
import { NextRequest, NextResponse } from "next/server";
import { db, collections, collectionRecipes, eq, and, or } from "@epicure/db";
import { db, collections, collectionRecipes, eq, and } from "@epicure/db";
import { requireSessionOrApiKey } from "@/lib/api-auth";
import { collectionVisibleToViewer } from "@/lib/visibility";
type Params = { params: Promise<{ id: string }> };
@@ -9,12 +10,10 @@ export async function POST(req: NextRequest, { params }: Params) {
if (response) return response;
const { id } = await params;
// Allow forking public collections or own collections
// Allow forking any collection visible to this viewer (own, or public/
// unlisted/followers-if-following) — never a private collection of someone else's.
const source = await db.query.collections.findFirst({
where: and(
eq(collections.id, id),
or(eq(collections.isPublic, true), eq(collections.userId, session!.user.id))
),
where: and(eq(collections.id, id), collectionVisibleToViewer(session!.user.id)),
with: { recipes: { columns: { recipeId: true } } },
});
@@ -26,7 +25,7 @@ export async function POST(req: NextRequest, { params }: Params) {
userId: session!.user.id,
name: `${source.name} (fork)`,
description: source.description,
isPublic: false,
visibility: "private",
createdAt: new Date(),
updatedAt: new Date(),
});
@@ -36,7 +36,7 @@ export async function PUT(req: NextRequest, { params }: Params) {
description: z.string().max(500).nullable().optional(),
notes: z.string().max(2000).nullable().optional(),
tags: z.array(z.string().min(1).max(50)).max(20).optional(),
isPublic: z.boolean().optional(),
visibility: z.enum(["private", "unlisted", "public", "followers"]).optional(),
addRecipeId: z.string().optional(),
addRecipeIds: z.array(z.string()).max(200).optional(),
removeRecipeId: z.string().optional(),
@@ -45,13 +45,13 @@ export async function PUT(req: NextRequest, { params }: Params) {
if (!parsed.success) return NextResponse.json({ error: "Validation error" }, { status: 400 });
const data = parsed.data;
if (data.name || data.description !== undefined || data.notes !== undefined || data.tags !== undefined || data.isPublic !== undefined) {
if (data.name || data.description !== undefined || data.notes !== undefined || data.tags !== undefined || data.visibility !== undefined) {
await db.update(collections).set({
...(data.name && { name: data.name }),
...(data.description !== undefined && { description: data.description }),
...(data.notes !== undefined && { notes: data.notes }),
...(data.tags !== undefined && { tags: data.tags }),
...(data.isPublic !== undefined && { isPublic: data.isPublic }),
...(data.visibility !== undefined && { visibility: data.visibility }),
updatedAt: new Date(),
}).where(eq(collections.id, id));
}
+2 -2
View File
@@ -6,7 +6,7 @@ import { requireSessionOrApiKey } from "@/lib/api-auth";
const Schema = z.object({
name: z.string().min(1).max(100),
description: z.string().max(500).optional(),
isPublic: z.boolean().default(false),
visibility: z.enum(["private", "unlisted", "public", "followers"]).default("private"),
});
export async function GET(req: NextRequest) {
@@ -61,7 +61,7 @@ export async function POST(req: NextRequest) {
userId: session!.user.id,
name: parsed.data.name,
description: parsed.data.description,
isPublic: parsed.data.isPublic,
visibility: parsed.data.visibility,
});
return NextResponse.json({ id }, { status: 201 });
+21 -5
View File
@@ -1,7 +1,9 @@
import { notFound } from "next/navigation";
import { headers } from "next/headers";
import QRCode from "qrcode";
import { auth } from "@/lib/auth/server";
import { db, collections, eq, and, or } from "@epicure/db";
import { db, collections, eq, and } from "@epicure/db";
import { collectionVisibleToViewer } from "@/lib/visibility";
import { PrintTrigger } from "@/components/recipe/print-trigger";
import { formatIngredientQuantity } from "@/lib/unit-conversion";
import { getMessages, formatMessage } from "@/lib/i18n/server";
@@ -17,10 +19,7 @@ export default async function CollectionPrintPage({ params }: Params) {
const unitPref = (session.user as { unitPref?: string }).unitPref === "imperial" ? "imperial" : "metric";
const col = await db.query.collections.findFirst({
where: and(
eq(collections.id, id),
or(eq(collections.userId, session.user.id), eq(collections.isPublic, true))
),
where: and(eq(collections.id, id), collectionVisibleToViewer(session.user.id)),
with: {
recipes: {
with: {
@@ -39,6 +38,13 @@ export default async function CollectionPrintPage({ params }: Params) {
const recipeEntries = col.recipes.filter((r) => r.recipe !== null);
// Same rationale as the recipe print page's QR: only link a URL an
// anonymous scanner could actually resolve.
const shareUrl = col.visibility === "public" || col.visibility === "unlisted"
? `${process.env["BETTER_AUTH_URL"] ?? "http://localhost:3000"}/collections/${id}`
: null;
const qrDataUrl = shareUrl ? await QRCode.toDataURL(shareUrl, { margin: 1, width: 120 }) : null;
return (
<>
<style>{`
@@ -71,6 +77,9 @@ export default async function CollectionPrintPage({ params }: Params) {
.timer { font-size: 0.85em; color: #666; font-family: system-ui, sans-serif; margin-left: 8px; }
.cookbook-cover { text-align: center; margin-bottom: 40px; }
.cookbook-cover h1 { font-size: 2.6em; }
.qr-block { text-align: center; margin: 0 auto; font-family: system-ui, sans-serif; }
.qr-block img { width: 84px; height: 84px; display: block; margin: 0 auto; }
.qr-block span { display: block; font-size: 0.65em; color: #999; margin-top: 4px; }
footer { margin-top: 40px; font-size: 0.75em; color: #aaa; text-align: center; font-family: system-ui, sans-serif; }
.print-btn {
position: fixed; top: 16px; right: 16px; padding: 8px 16px;
@@ -88,6 +97,13 @@ export default async function CollectionPrintPage({ params }: Params) {
<p style={{ fontFamily: "system-ui, sans-serif", fontSize: "0.85em", color: "#888" }}>
{recipeEntries.length} recipe{recipeEntries.length !== 1 ? "s" : ""}
</p>
{qrDataUrl && (
<div className="qr-block">
{/* eslint-disable-next-line @next/next/no-img-element -- data: URI, next/image can't optimize it anyway */}
<img src={qrDataUrl} alt={m.collections.qrCodeAlt} />
<span>{m.collections.qrCodeCaption}</span>
</div>
)}
</div>
{recipeEntries.map(({ recipe }) => {