Skip to content

Offer the claim on the passport page when it is unclaimed and X-linked - #9

Merged
uchibeke merged 2 commits into
mainfrom
feat/x-claim-on-passport-page
Sep 18, 2026
Merged

uchibeke merged 2 commits into
mainfrom
feat/x-claim-on-passport-page

Conversation

@uchibeke

@uchibeke uchibeke commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Companion to agent-passport #359 and aport-vault #3, which together let someone claim a bot-minted passport by proving the X account it is linked to.

The live-launch bot mints a passport from a public X reply and records the poster's handle in links.x. It cannot know their email, so it mints against a placeholder contact, which is why the passport shows as unclaimed. Its reply carries a claim link, and this adds a second route to the same place, on the page the person is already looking at, for when they arrive without the reply.

One banner, shown only when the passport is both unclaimed and carries links.x. It names the handle the passport is bound to, says the handle is checked, and links to aport.io/claim?agent_id=<id>.

Checked rather than assumed: functions/api/passport/[id].ts obfuscates email fields and passes links through untouched, and the live endpoint returns both links and claimed, so the condition can actually be evaluated client-side. A passport with no links.x renders nothing, which is the existing behaviour for every passport minted through the site.

25 lines, one file. next build passes.

The bot's reply links to the passport page and carries its own claim link. This
adds a second route to the same place, on the page the person is already
looking at, for the case where they arrive without the reply: a banner shown
only when the passport is unclaimed and carries links.x, naming the handle it
is bound to and linking to aport.io/claim?agent_id=<id>.

Checked rather than assumed: the /api/passport/[id] sanitizer obfuscates emails
and passes links through untouched, and the live endpoint returns both links
and claimed, so the condition can actually be evaluated client-side.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-18T12:55:33.592932Z 56ceeab PR opened
🔒 Security Review ✅ Completed 2026-09-18T12:56:01.589755Z 56ceeab PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 56ceeabb63

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread app/passport/page.tsx
the one recorded here, and the passport transfers only if they match.
</p>
<a
href={`https://aport.io/claim?agent_id=${encodeURIComponent(

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Honor the configured APort domain for claim links

When NEXT_PUBLIC_APORT_BASE_URL points to a local or staging APort deployment, this banner still sends users to production, where the corresponding passport may not exist and the new claim flow cannot be tested. Other cross-app links on this page use apiConfig.aportDomain; construct this URL from that configured domain as well.

Useful? React with 👍 / 👎.

@uchibeke
uchibeke force-pushed the feat/x-claim-on-passport-page branch from 56ceeab to f57e959 Compare September 18, 2026 13:12
Two things on that page were wrong outside local development.

getAportDomain fell back to http://localhost:8787 whenever
NEXT_PUBLIC_APORT_BASE_URL was unset. This is a static export, so the value is
baked in at build time, and a build without it shipped localhost to production:
the widget and VC iframes pointed at a machine the visitor does not have. It now
falls back to localhost only when actually running on localhost, matching what
getApiBaseUrl already does, and to https://aport.io everywhere else.

The skills install command was a raw git clone into a hardcoded ~/.claude path,
which only helps Claude Code users and dropped the ./setup step the repo's own
README pairs with it. `npx skills add aporthq/aport-skills` resolves the repo,
installs into whichever agent directories are present and records the version.
Verified the CLI exists and takes that form (skills 1.7.0, vercel-labs) rather
than assuming it.
@uchibeke
uchibeke merged commit 7a128df into main Sep 18, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant