Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Customers create tickets and reply to their own conversations; staff claim a ticket, reply, close it, and reopen it. Rails/Active Record locks the ticket row for claims, replies, and status changes so competing staff claims preserve one owner and closure rejects subsequent replies. Ticket creation and its initial message commit together.
Includes native bcrypt authentication and encrypted Rails cookies, CSRF protection, bounded ticket/reply pages, Turbo forms with normal HTML fallbacks, native migrations, separate migration/runtime roles, verified TLS, seeded accounts, Linux setup/cleanup instructions, and a credential-free Rails CI workflow.
Validation on a dedicated ClickHouse Managed Postgres Cloud service (Postgres 18.6), inside Ubuntu 24.04 arm64 with Rails 8.1.4, pg 1.6.2 and Turbo 2.0.17:
CookieStore does not provide server-side stolen-cookie revocation. Replies have no request-id deduplication. Hosted deployment, failover, and performance benchmarking are outside this example. Companion article and raw acceptance evidence remain local for review.
Browser-helper follow-up: Python Playwright is now pinned to 1.56.0. Only helper requirement pins changed; runtime application code/dependencies are unchanged. Clean isolated native-Linux installs, pip check and Chromium launch/DOM/screenshot smoke passed for the updated helper. Full Cloud/application acceptance remains recorded at
8b271a12ea2e26c339fc212e0278048e89772ff8; it was not rerun for this test-dependency-only follow-up.