DWG RG-003 · SIDE PROJECT · PRIVATE

Small Group
Potluck

Weekly potluck sign-ups for small groups, so everyone can see who's coming and what they're bringing.

STATUS: PRIVATE · BUILT 2026

DETAIL B — SHOWN IN THE PROJECT'S OWN FINISH

private · passcode per group
Small Group Potluck
  • Cloudflare Worker
  • Static assets
  • D1
  • Rate Limiting
  • Vanilla JS
  • No build step
Small Group Potluck request paths The browser gets pages from static assets and sends API calls to the Worker. The Worker checks the session, does the schedule math, reads and writes D1, and rate-limits logins. Browser member page admin page fetch() with cookies Cloudflare edge · custom domain Static assets HTML, CSS, JS. No signups, no secrets. Worker every /api/* request member API week, sign up, edit admin API groups, themes, dates sessions passcode → cookie schedule rule + exceptions JSON in and out, small body cap GET / /api/* D1 database groups passcodes (hashed) meeting exceptions signups Rate limiter login attempts per IP
Pages come straight from static assets and hold nothing private. Every signup and every admin action goes through /api/*, where the session is checked on each request.

SECTION C–C · SCOPE

Each week someone asks the group chat who's bringing what, and the answers get buried. This replaces the thread with a page that shows the next meeting, the theme if there is one, and a list of who's coming and what they're bringing. Add your name and a dish, edit it later, or take it back.

Several groups share one deployment. Each group has a member passcode and an admin passcode. Group admins set themes, cancel a week, add an extra date or change the passcode. A global admin creates and archives groups.

The open meeting is the next one on or after today. Signups stay open through meeting day, and the next week opens at midnight. If that meeting is cancelled, the page says so and shows the next one.

DESIGN DECISIONS

  1. NO ACCOUNTS

    A shared passcode identifies the group and a random device id marks which signup is yours. Nobody makes a login just to say they're bringing a salad.

  2. ROTATE A PASSCODE, SIGN OUT ITS USERS

    Session cookies are signed with a key derived from the current passcode. Changing one group's passcode signs out exactly the people who used it, and nobody else.

  3. THE SCHEDULE IS A RULE

    A group stores its meeting day and how many weeks apart meetings are. The database only records exceptions such as a theme, a cancellation or an extra date.

  4. SCHEDULE MATH WITH NO I/O

    Working out the open meeting is pure functions over dates in Central time, so the tricky part is the easiest part to test.

  5. ONE RESPONSE, ONE RENDER

    Every write returns the refreshed week, so the page re-renders from a single response and never shows stale state.

  6. SMALL ON PURPOSE

    No framework and no build step, about 1,600 lines in total. Lighthouse scores 98–100 on mobile.

FULL SIZE · DRAG TO PAN