Skip to content

Add Rails support desk with serialized claims and replies - #443

Draft
sdairs wants to merge 3 commits into
mainfrom
codex/support-desk
Draft

sdairs wants to merge 3 commits into
mainfrom
codex/support-desk

Conversation

@sdairs

@sdairs sdairs commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Customers create tickets and reply to their own conversations; staff claim a ticket, reply, close it, and reopen it. Rails/Active Record locks the ticket row for claims, replies, and status changes so competing staff claims preserve one owner and closure rejects subsequent replies. Ticket creation and its initial message commit together.

Includes native bcrypt authentication and encrypted Rails cookies, CSRF protection, bounded ticket/reply pages, Turbo forms with normal HTML fallbacks, native migrations, separate migration/runtime roles, verified TLS, seeded accounts, Linux setup/cleanup instructions, and a credential-free Rails CI workflow.

Validation on a dedicated ClickHouse Managed Postgres Cloud service (Postgres 18.6), inside Ubuntu 24.04 arm64 with Rails 8.1.4, pg 1.6.2 and Turbo 2.0.17:

  • 12 real HTTP/database tests, 80 assertions, 0 failures: competing claims, coordinated close/reply contention, ownership, author identity, invalid input/atomic rollback, CSRF, deterministic reply ordering, pagination, database constraints/runtime permissions, and certificate-specific wrong-CA/hostname failures.
  • Frozen second dependency installation; empty-schema bootstrap/migrate/grants/seed; migration rollback/reapply; eager-loading/routes/Ruby syntax checks.
  • Native Chromium customer/staff workflow, Turbo 422 rendering, verified stylesheet and desktop/mobile screenshots; real Puma process restart retaining the encrypted cookie and exact ticket/reply.

CookieStore does not provide server-side stolen-cookie revocation. Replies have no request-id deduplication. Hosted deployment, failover, and performance benchmarking are outside this example. Companion article and raw acceptance evidence remain local for review.

Browser-helper follow-up: Python Playwright is now pinned to 1.56.0. Only helper requirement pins changed; runtime application code/dependencies are unchanged. Clean isolated native-Linux installs, pip check and Chromium launch/DOM/screenshot smoke passed for the updated helper. Full Cloud/application acceptance remains recorded at 8b271a12ea2e26c339fc212e0278048e89772ff8; it was not rerun for this test-dependency-only follow-up.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant