From 917911457e9f2b7addc32af42cbee4e5eebdf006 Mon Sep 17 00:00:00 2001 From: Maximilian Stubhan Date: Thu, 13 Aug 2026 16:00:29 +0200 Subject: [PATCH] Stop the seed handing out addresses that look like real ones MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Every employee address in the database sat on test.manner.at, a domain that reads like a company one. employees.email is the *private* address, so an address shaped like a company mailbox invites being taken for one — and eventually being written to. All 856 rows now sit on privat.alpenwerk-test.at, rebuilt from first and last name, and the seed generates the same domain so a reseed does not bring the old one back. Umlauts are spelled out the way they are here (Höller becomes hoeller), other accents are flattened, and where two people share a name the personnel number is appended. The first attempt got this wrong in a way worth recording. It wrote ma@ for all 856 rows instead of the intended name form, and the check I had built only asked whether the results were unique and well-formed — which they were. Two defects, both invisible to that check: '\.+' inside a SQL literal was read as "any character, one or more" and collapsed the whole local part to a single dot, and the replacement string for the accent mapping had one character too many, so the mapping was shifted. The fix uses '[.]+', a character class needing no escape at all, so it no longer depends on how the connection treats backslashes. Untouched on purpose: app_users.email and profiles.email are the sign-in accounts, and rewriting those would lock people out. Co-Authored-By: Claude Opus 5 --- supabase/seed.ts | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/supabase/seed.ts b/supabase/seed.ts index 10d858a..3619f79 100644 --- a/supabase/seed.ts +++ b/supabase/seed.ts @@ -380,12 +380,18 @@ type HistoryRow = { const usedEmails = new Set(); +// Eine Domain, die niemandem gehört und offensichtlich keine echte ist. +// `employees.email` ist die *private* Adresse; eine erfundene Testdomain, die +// wie eine Firmenadresse aussieht, lädt dazu ein, sie für eine zu halten — +// und im schlimmsten Fall, an sie zu schreiben. +const MAIL_DOMAIN = "privat.alpenwerk-test.at"; + function makeEmail(firstName: string, lastName: string): string { const base = `${slugify(firstName)}.${slugify(lastName)}`; - let email = `${base}@test.manner.at`; + let email = `${base}@${MAIL_DOMAIN}`; let n = 2; while (usedEmails.has(email)) { - email = `${base}${n}@test.manner.at`; + email = `${base}${n}@${MAIL_DOMAIN}`; n += 1; } usedEmails.add(email);