Repository navigation
v.1.0.4 - Production Release
William Temple House Digital Raffle System v1.0.4
Release Date: December 12, 2025
Authentication (OTP-First)
- Updated the
/loginauthentication card so One-Time Passcode (OTP) is the default sign-in method. - Swapped tab order so OTP appears on the left and Magic Link appears on the right (Magic Link remains available as a fallback).
Important IT Limitation (Magic Links)
- Magic links are currently not viable in the staff environment because Microsoft Defender (CCSI) automatically inspects links in email bodies and burns the single-use token before the user clicks it.
- Recommended and supported method: ➡️ One-Time Passcode (OTP).
Documentation
- Added technical documentation at
docs/AUTHENTICATION.mdcovering supported methods, domain restriction (@williamtemple.org), the Defender limitation, and the OTP flow.
Versioning & UI
- Bumped application version to 1.0.4.
- Updated the staff landing page to display the version from
package.json(prevents stale hardcoded version strings).
Maintenance (Lint Warning Cleanup)
- Resolved existing lint warnings by removing unused imports/variables and applying Next.js image guidance (replaced logo
<img>tags withnext/imageon the read-only display).
Security
Fix React Server Components CVE vulnerabilities
Updated dependencies to fix Next.js and React CVE vulnerabilities.
The fix-react2shell-next tool automatically updated the following packages to their secure versions:
- next
- react-server-dom-webpack
- react-server-dom-parcel
- react-server-dom-turbopack
All package.json files have been scanned and vulnerable versions have been patched to the correct fixed versions based on the official React advisory.
Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>