DS1 follow-up: close the sb-token trust-bug class across all surfaces

The OAuth-only 'sb-token' localStorage key was read by profile, slip,
dashboard (recent-scans), settings, and tracker for their authenticated
fetches. Email/password users never had that key, so those fetches sent
no Authorization header and silently returned nothing.

- web/src/lib/authToken.js — currentAccessToken() reads the REAL Supabase
  session (sb-<ref>-auth-token, v2 top-level or v1 currentSession), legacy
  fallback. CommonJS so Jest can unit-test it (5 tests).
- Swept all 5 pages to the helper (scan already session-first from DS1).
- lib/api.ts (0 callers) + ParlayTray (unmounted) left as dead code.

236 suites / 2842 tests green, next build exit 0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Kev
2026-07-12 23:41:13 -04:00
parent bc5285d9e7
commit cf91c04e90
7 changed files with 92 additions and 7 deletions
+3 -2
View File
@@ -17,6 +17,7 @@ import SectionHead from '@/components/vyndr/SectionHead';
import VBtn from '@/components/vyndr/VBtn';
import GradeBadge from '@/components/vyndr/GradeBadge';
import { useParlay } from '@/contexts/ParlayContext';
import { currentAccessToken } from '@/lib/authToken';
type Sport = 'MLB' | 'NBA' | 'WNBA';
@@ -109,7 +110,7 @@ export default function SlipPage() {
setGraded(false);
setAdded(false);
try {
const token = typeof window !== 'undefined' ? localStorage.getItem('sb-token') : null;
const token = currentAccessToken();
const res = await fetch('/api/slips/parse', {
method: 'POST',
headers: {
@@ -185,7 +186,7 @@ export default function SlipPage() {
if (!legs || grading) return;
setGrading(true);
setGrades(legs.map(() => ({ status: 'pending' })));
const token = typeof window !== 'undefined' ? localStorage.getItem('sb-token') : null;
const token = currentAccessToken();
const results: LegGrade[] = [];
for (const leg of legs) {
if (!legReady(leg)) {