Club platform (P15)
A club's members sign in with passkeys, take places on events, wait for a place when an event is full, and pay for paid events with Stripe. The server checks each member's role on every request.
Passkeys
Joining makes a passkey with WebAuthn. The server keeps the passkey's public key. When a member signs in, the server checks the challenge, the site's address, the hash of the site's name, the flags for a present and verified person, the signature and the counter. It reads Ed25519, ES256 and RS256 signatures. An ES256 signature arrives in DER and is turned into the two numbers Web Crypto expects.
A session is a random token in a cookie that the page's scripts cannot read. The server keeps only the token's hash.
Roles
A member takes places and writes messages. An organizer also creates and cancels events, deletes messages and sees the email addresses of the people going. An admin also sets roles. The first person to join is the admin.
Every route names the role it needs, in one table on the server. The server looks the route up and refuses a request from a lower role before the route runs. The server page of the prototype prints the table.
Places and the waiting list
An event has a number of places. When they are taken, a member joins the waiting list. When someone gives a place back, the first person on the list gets it and an email. On a paid event, the place is offered for 24 hours instead, and the member pays to keep it.
Payment
A paid place is held for 31 minutes while Stripe Checkout is open. Only Stripe's webhook confirms it. The server checks the webhook's signature with HMAC-SHA256 and the endpoint's secret, and refuses a signature older than 5 minutes. An event that arrives twice changes nothing the second time. Giving a paid place back refunds the payment through Stripe.
Stripe runs in test mode with Malte's test keys. Without them, a paid place cannot be taken on the deployed site.
The club's mail uses the same path as the booking prototype: Resend when a key is set, otherwise the outbox, which an admin reads on the Mail page.
Previous: Editor for two (P14). Next: Portfolio site (P16).