Apple Wallet check-in passes - #166
Merged
Merged
Conversation
RSVPed hackers can add their check-in QR to Apple Wallet. The pass encodes
the bare user id, exactly what the dashboard QR shows, so the scanner and
check-in action accept it unchanged.
- GET /wallet/pass signs a .pkpass (passkit-generator) for the session user,
or for the user in a signed, expiring ?t= link so emailed links work
without signing in. Eligibility matches getAttendeeQrEligibility: an RSVP
row and a confirmed decision, re-checked on every download.
- Dashboard check-in panel gains an "Add to Apple Wallet" button.
- Email campaign audiences gain a wallet_pass_url merge column for RSVPed
rows, for a bulk send via [Add to Apple Wallet]({{wallet_pass_url}}).
- Every Wallet entry point stays hidden unless the APPLE_WALLET_* and
WALLET_LINK_SECRET env vars are set; task-definition.json reads them
from SSM.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
arnavs-0
requested changes
Sep 16, 2026
Contributor
|
secrets have been added to aws. |
- Drop markdown links whose merged URL is blank instead of shipping the literal "[text]()" (test sends, non-RSVPed recipients). - Validate Wallet PEMs at config time: reject raw/undecodable PEMs, parse both certificates, and open the signer key with its passphrase, so isWalletConfigured() hides entry points instead of 500ing downloads. - Narrow the proxy auth exemption from /wallet to /wallet/pass. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # pnpm-lock.yaml
# Conflicts: # task-definition.json
The dashboard button now needs the flag as well as valid credentials, matching GOOGLE_WALLET_PUBLISHED. /wallet/pass and emailed links still work, so the pass can be tested before hackers see it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
arnavs-0
approved these changes
Sep 27, 2026
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
RSVPed hackers can add their check-in QR code to Apple Wallet and pull it up from the lock screen at the door, even offline.
The pass encodes the bare user id, exactly what the dashboard QR shows, so
/checkinandcheckInAttendeeaccept it with no changes.GET /wallet/passsigns a.pkpasswithpasskit-generator. It serves the signed-in user's pass, or the user named in a signed, expiring?t=link, so emailed links work without logging in./walletis a public path in the proxy, and the route does its own auth.getAttendeeQrEligibility: an RSVP row and a confirmed decision. It's re-checked on every download, so a deleted RSVP can't be used with an old link.wallet_pass_urlcolumn, filled in only for RSVPed rows. Links expire when the event ends (Oct 6).scripts/generate-wallet-assets.ts.APPLE_WALLET_*andWALLET_LINK_SECRET.task-definition.jsonnow reads these from SSM. If they don't exist, new ECS tasks can't start and the deploy fails. Create them inus-east-2asSecureString:/mhacks-secrets/APPLE_WALLET_PASS_TYPE_IDpass.org.mhacks/mhacks-secrets/APPLE_WALLET_TEAM_ID8679469T3A/mhacks-secrets/APPLE_WALLET_SIGNER_CERT/mhacks-secrets/APPLE_WALLET_SIGNER_KEY/mhacks-secrets/APPLE_WALLET_SIGNER_KEY_PASSPHRASE/mhacks-secrets/APPLE_WALLET_WWDR_CERT/mhacks-secrets/WALLET_LINK_SECRETopenssl rand -hex 32, not the local oneThe
mhacks-ecs-execrole also needs read access to them, like the existing/mhacks-secrets/*parameters.Testing
pnpm buildpass.pass.org.mhackscertificate:200 application/vnd.apple.pkpass. The pass is signed, and its QR payload is the user id.403.403. No token and no session redirects to/login. Missing config returns503.After deploy
To reach people who've already RSVPed: in
/admin/email-campaigns, pick the RSVPed audience and put[Add to Apple Wallet]({{wallet_pass_url}})in a section body. It can't go in the CTA button, because the CTA URL is validated before merge fields are filled in.🤖 Generated with Claude Code