feat: Swiss-compliant launch — Impressum/AGB/Contact, support panel, DSG exports, cookie banner
All checks were successful
Deploy to Production / deploy (push) Successful in 57s
All checks were successful
Deploy to Production / deploy (push) Successful in 57s
Legal (Swiss minimum, no individual named): - Impressum page (UWG Art. 3 lit. s) — provider, contact via support panel, no email required, jurisdiction = Switzerland - AGB page — subscription terms, payment, cancellation, suspension on payment fail, 14-day money-back, AI-processing-per-tier disclosure, Swiss law + Swiss venue, modeled after typical Schweizer SaaS terms - Privacy: Stripe added as subprocessor with full data-flow disclosure Support panel replaces email contact entirely: - @bmm/db: support_status enum + support_tickets + support_messages tables, migration applied to prod DB - @bmm/api: support routes (user create/list/view/reply, admin list/view/reply /set-status), public /v1/contact for logged-out visitors with per-IP rate limit of 3 submissions/day to prevent spam-flood - Web: /settings/support (list + new), /settings/support/[id] (conversation), /admin/support, /admin/support/[id] - Public /contact form with email collection for guest tickets Data rights (DSG Art. 25 / GDPR Art. 15+20): - /v1/account/export returns user-scoped JSON of profile, org, servers, builds, audit, support tickets and messages — excludes hashes, encrypted secrets, other-user data - /settings/account: download button + deletion-via-ticket workflow Production-readiness gaps closed: - org.suspended now blocks /v1/servers POST and /v1/servers/preview (402); webhook flagged this state but enforcement was missing - Cookie banner: minimal, essential-cookies-only disclosure (Swiss DSG + GDPR compliant without dark-pattern consent UI), mounts on both layouts Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -330,6 +330,53 @@ export const auditLog = pgTable('audit_log', {
|
||||
createdAt: timestamp('created_at').defaultNow().notNull(),
|
||||
});
|
||||
|
||||
// In-app support ticketing replaces the email contact channel. Anonymous
|
||||
// (logged-out) tickets are allowed via the public /contact form so we still
|
||||
// satisfy UWG Art. 3 lit. s (Swiss "easy electronic contact" requirement).
|
||||
export const supportStatusEnum = pgEnum('support_status', [
|
||||
'awaiting_admin',
|
||||
'awaiting_user',
|
||||
'closed',
|
||||
]);
|
||||
|
||||
export const supportTickets = pgTable(
|
||||
'support_tickets',
|
||||
{
|
||||
id: uuid('id').defaultRandom().primaryKey(),
|
||||
userId: uuid('user_id').references(() => users.id, { onDelete: 'set null' }),
|
||||
orgId: uuid('org_id').references(() => organizations.id, { onDelete: 'set null' }),
|
||||
// For anonymous /contact submissions: collect email so admin can reply.
|
||||
guestEmail: varchar('guest_email', { length: 255 }),
|
||||
subject: varchar('subject', { length: 200 }).notNull(),
|
||||
status: supportStatusEnum('status').default('awaiting_admin').notNull(),
|
||||
createdAt: timestamp('created_at').defaultNow().notNull(),
|
||||
updatedAt: timestamp('updated_at').defaultNow().notNull(),
|
||||
lastMessageAt: timestamp('last_message_at').defaultNow().notNull(),
|
||||
closedAt: timestamp('closed_at'),
|
||||
},
|
||||
(t) => ({
|
||||
userIdx: index('idx_support_tickets_user').on(t.userId),
|
||||
statusIdx: index('idx_support_tickets_status').on(t.status, t.lastMessageAt),
|
||||
}),
|
||||
);
|
||||
|
||||
export const supportMessages = pgTable(
|
||||
'support_messages',
|
||||
{
|
||||
id: uuid('id').defaultRandom().primaryKey(),
|
||||
ticketId: uuid('ticket_id')
|
||||
.references(() => supportTickets.id, { onDelete: 'cascade' })
|
||||
.notNull(),
|
||||
authorUserId: uuid('author_user_id').references(() => users.id, { onDelete: 'set null' }),
|
||||
authorIsAdmin: boolean('author_is_admin').default(false).notNull(),
|
||||
body: text('body').notNull(),
|
||||
createdAt: timestamp('created_at').defaultNow().notNull(),
|
||||
},
|
||||
(t) => ({
|
||||
ticketIdx: index('idx_support_messages_ticket').on(t.ticketId, t.createdAt),
|
||||
}),
|
||||
);
|
||||
|
||||
export type Organization = typeof organizations.$inferSelect;
|
||||
export type User = typeof users.$inferSelect;
|
||||
export type Session = typeof sessions.$inferSelect;
|
||||
@@ -340,3 +387,5 @@ export type Secret = typeof secrets.$inferSelect;
|
||||
export type OAuthClient = typeof oauthClients.$inferSelect;
|
||||
export type Template = typeof templates.$inferSelect;
|
||||
export type EncryptionKey = typeof encryptionKeys.$inferSelect;
|
||||
export type SupportTicket = typeof supportTickets.$inferSelect;
|
||||
export type SupportMessage = typeof supportMessages.$inferSelect;
|
||||
|
||||
Reference in New Issue
Block a user