Repository navigation
Conversation
Surfaces the two-phase ownership handshake added in CGS 0.6.0 (app.certified.group.ownershipTransfer.*) as a "Transfer ownership" page in group settings, between Members & Roles and Activity Log. The owner proposes an existing member; ownership moves only once that member accepts, which proves they still control their DID. Either party can cancel, and an un-accepted proposal lapses after 7 days. - BFF route: GET status, POST propose, PUT accept, DELETE cancel. Per the CGS #27 targeting rule, `repo` goes on the querystring for the status query and in the body for the three procedures. Propose validates the DID and is rate-limited 5/10min per caller. - UI: the owner picks from eligible members and confirms; the proposed member gets Accept/Decline; either party can cancel. Transfer status is re-read after every member and role mutation, because CGS clears a pending proposal when ownership or a party's membership changes by another route. - Only the two parties ever see the page. CGS reports `pending: false` to a member who is not a party, exactly as when no transfer exists, so the UI derives visibility from that response and never tries to tell the two cases apart. Copy avoids claiming the underlying PDS account moves — per the CGS integration guide, the owner role is not proof of account control. Requires the group service to be on 0.6.0+. staging.certified.app already is; production is on 0.5.0 and answers these NSIDs with 501, so this must not reach main until that deployment is upgraded. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The "Choose the new owner" block repeated what the page description already introduced. Fold the terms — accept-before-effect, the proposer's demotion to admin, and the 7-day expiry — into the page description so they're read once, before the control, and drop the duplicate paragraph. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…sfer feat(groups): transfer group ownership to another member
The pending-transfer line read "expires 2026-09-24if it isn't accepted": JSX drops the space between an expression and the word after it when the two straddle a line break, so the expiry date ran into the following word. Build the sentence as one string in `transferPendingNote` and cover the spacing with a unit test, so reflowing the JSX can't reintroduce it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (6)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
holkexyz
marked this pull request as ready for review
September 18, 2026 11:23
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Promotes the group ownership-transfer work from
staging.Blocked: production CGS must be on 0.6.0 first
app.certified.group.ownershipTransfer.*landed in CGS 0.6.0. On 0.5.0 those four NSIDs answer501 MethodNotImplemented, so merging this now would put a Transfer ownership page in front of every group owner on production that fails the moment it loads.There is deliberately no runtime capability detection and no feature flag — this merge is the gate. Re-check before merging:
Merge only once that reports
0.6.0or newer.What's included
Four commits, all of it this one feature:
b46ee2cdfeat(groups): transfer group ownership to another member7d901a0efix(groups): move transfer terms into the page descriptionade65b3dfix(groups): restore the space before "if it isn't accepted"The owner proposes an existing member; ownership moves only when that member accepts, which proves they still control their DID. Either party can cancel, and an un-accepted proposal lapses after 7 days. The page sits in group settings between "Members & Roles" and "Activity Log".
src/app/api/groups/[groupDid]/ownership-transfer/route.ts—GETstatus,POSTpropose,PUTaccept,DELETEcancel.repoon the querystring for the query, in the body for the procedures, per the CGS fix: don't force OAuth consent screen on every email login #27 targeting rule. Propose validates the DID and is rate-limited 5/10min per caller; CSRF checked on every mutation.src/lib/groups/{api,types}.ts.src/components/groups/org-settings.tsx, withtransferViewerRole,eligibleTransferTargetsandtransferPendingNoteas exported pure helpers. No new CSS.Behaviours worth a careful look
pending: falseto a member who isn't a party, identical to "nothing pending", andNoPendingTransferfor accept/cancel. The UI derives visibility from that alone and never tries to distinguish the two — the difference is not observable by design.Testing
npx tsc --noEmit,npm run lintandnpm test(1310 passing) are clean onstaging; the CLAUDE.md pre-merge greps are silent. Covered by tests: per-method targeting, DID validation, CSRF and rate-limit gates, error-code passthrough, the visibility helpers including the non-party case, and the date-line spacing.Not yet exercised as a full handshake in a browser — accept is callable only by the proposed member, so it needs two accounts. Worth doing on staging.certified.app before this is promoted.
🤖 Generated with Claude Code
Summary by CodeRabbit
New Features
Bug Fixes