diff --git a/apps/rebreak-native/stores/community.ts b/apps/rebreak-native/stores/community.ts index 6beafab..5033268 100644 --- a/apps/rebreak-native/stores/community.ts +++ b/apps/rebreak-native/stores/community.ts @@ -4,7 +4,6 @@ export type CommunityCategory = 'all' | 'games' | 'domain_vote' | 'lyra' | 'rebr export interface CommunityPostAuthor { id: string | null; - username: string; nickname: string; avatar: string | null; plan: string; diff --git a/backend/server/api/community/posts.get.ts b/backend/server/api/community/posts.get.ts index 5e5bc43..624ef89 100644 --- a/backend/server/api/community/posts.get.ts +++ b/backend/server/api/community/posts.get.ts @@ -115,7 +115,8 @@ export default defineEventHandler(async (event) => { : null, author: { id: p.userId ?? null, - username: a?.username ?? "Nutzer", + // username ist der Login-Identifikator (→ {username}@rebreak.internal) + // und darf NIE an fremde Clients gehen — Anonymitäts-Invariante (nickname-only). nickname: a?.nickname ?? a?.username ?? "Nutzer", avatar: a?.avatar ?? null, plan: (a as any)?.plan ?? "free", diff --git a/backend/server/api/social/profile/[userId].get.ts b/backend/server/api/social/profile/[userId].get.ts index 9e988a1..154c7f4 100644 --- a/backend/server/api/social/profile/[userId].get.ts +++ b/backend/server/api/social/profile/[userId].get.ts @@ -56,7 +56,7 @@ export default defineEventHandler(async (event) => { return { id: profile.id, - username: profile.username, + // username (Login-Identifikator) bewusst NICHT exponiert — nickname-only. nickname: meta.nickname ?? profile.username, avatar: meta.avatar, bio: (profile as any).bio ?? null,