Site

Bell icon with unread count badge, popover notification list, and server-side notification creation utilities.

In-app only

This page covers the in-app notification center (bell icon + in_app_notifications table). For Web Push (browser/mobile push notifications) see PWA & Push. For the transactional email retry queue see Background Jobs — the process-pending-emails handler.

🔔

Bell Icon + Badge

Red unread count badge (capped at 99+). Popover with scrollable notification list. Polls every 60s.

📋

Notification Types

Info, success, warning, error, system — each with distinct icon and color. Relative time display.

✅

Mark as Read

Click to mark individual, or "Mark all as read" button. Safe link navigation (relative paths only).

🔧

Server Utility

createInAppNotification() creates a notification for one Account recipient. Content is sanitized before storage; no account-wide fan-out helper is currently wired.

API RouteMethodDescription
/api/notificationsGETFetch up to 50 notifications, unread first then newest; unread count covers the returned page only
/api/notificationsPATCHMark 1–50 UUIDs as read ({ ids: [...] }) or all unread notifications ({ all: true }, takes precedence)
Security: Column-lock triggers allow recipients to modify only the read column. Content is sanitized (title: 200 chars, message: 1000 chars) and links are restricted to relative paths. Shared Prisma transactions set the verified application actor; RLS requires both the recipient and current Account membership for reads and updates, while the notification worker receives only its dedicated write capability. Missing identity returns 503 before database access, invalid mutation bodies return 400, and database failures return 500 with synthetic server diagnostics. Responses are private and non-cacheable.