docs: TODO stale-status corrections β items 2, 7(A1/A2), 14 already shipped on main - #109
docs: TODO stale-status corrections β items 2, 7(A1/A2), 14 already shipped on main#109lopugit wants to merge 7 commits into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
𧬠Rebased
The branch was published once with an exact force-with-lease. Please review the rewritten commits before relying on them. |
cf3791f to
a7074b1
Compare
|
π€ Auto-resolve running β the conflict resolver started working on this PR at 14:30 UTC. Expected to finish around 14:38 UTC (resolutions typically land in 3-8 minutes; the job times out at 30). On success a merge commit resolving the conflicts is pushed to this branch and a result comment follows β no manual action is needed meanwhile. |
|
π€ Merged No AI resolution was needed by merge time; the branch was updated with a plain merge commit.
Please review the merge commit before relying on it. |
|
π€ Auto-rebase running β the stack rebase started working on this PR at 11:51 UTC. Expected to finish around 12:06 UTC (rebases typically land in 5-15 minutes; the job times out at 55). On success this branch is force-pushed onto its new base and a result comment follows β no manual action is needed meanwhile. |
a7c4a04 to
9079be2
Compare
|
𧬠Rebased
The branch was published once with an exact force-with-lease. Please review the rewritten commits before relying on them. |
|
π€ Merged No AI resolution was needed by merge time; the branch was updated with a plain merge commit.
Please review the merge commit before relying on it. |
β¦us correction Verified against origin/main 2026-07-21: raw-results and populate are admin-gated + fail-closed rate-limited (item 7 A1/A2), verification links prefer APP_URL via resolveTrustedOrigin (item 2), and the window.useThingtimeScope render leak is gone (item 14, small console.log remainder in ThingtimeURL.tsx). Prevents parallel sessions re-claiming already-fixed URGENT items. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AST/text-only `graphify update` (graphify 0.9.4, no semantic extraction); run graphify locally with an LLM backend if semantic data is needed. Refreshed by the resolve-pr-conflicts workflow: https://github.com/lopugit/thingtime/actions/runs/31311433955
Refreshed by the rebase-pr-stacks workflow: https://github.com/lopugit/thingtime/actions/runs/31311683403
|
𧬠Rebased
The branch was published once with an exact force-with-lease. Please review the rewritten commits before relying on them. |
54e634e to
5037bd9
Compare
|
|
# Conflicts: # graphify-out/GRAPH_REPORT.md # graphify-out/graph.json # graphify-out/manifest.json
`graphify extract` with LLM semantic extraction (graphify 0.9.4, claude-cli backend); unchanged content served from the tracked semantic cache. Refreshed by the resolve-pr-conflicts workflow: https://github.com/lopugit/thingtime/actions/runs/31313517493
# Conflicts: # graphify-out/GRAPH_REPORT.md # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json # graphify-out/graph.json # graphify-out/manifest.json
`graphify extract` with LLM semantic extraction (graphify 0.9.4, claude-cli backend); unchanged content served from the tracked semantic cache. Refreshed by the resolve-pr-conflicts workflow: https://github.com/lopugit/thingtime/actions/runs/31318484290
|
π€ Merged No AI resolution was needed by merge time; the branch was updated with a plain merge commit.
Please review the merge commit before relying on it. |
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
β¦(A1/A2), 14 already shipped on main # Conflicts: # graphify-out/cache/semantic/61bb368d294e3a61dadb263c1bdaf7a9b83c8d163a2f61a627ad0cab68361860.json # graphify-out/cache/semantic/ae8a6e670b0164786d479a9787de432cf15b35e237cec87bdf53fa6d4ed349ea.json
Session-6 of the parallel todo loops audited the 'unclaimed' TODO items against origin/main before claiming and found several URGENT-flagged items already fixed:
raw-resultsexfiltration +populateseeding): both routes now require admin (requireAdmin) and fail-closedenforceRateLimit;raw-resultsonly runs bounded read-only queries viarunMongoQuery. A3 is in flight in PRs security: rate-limit + input-cap public service-account provisioning (TODO #7 A3)Β #100/security: rate-limit + 16KiB body cap on public signup (TODO item 8 remainder)Β #103.appOrigin.tsresolveTrustedOriginprefers server-configuredAPP_URL; remaining step is ops (setAPP_URLin deploy envs).window.useThingtimeScopepush is gone; remainder is 4console.logs inThingtimeURL.tsx.Marking these in
TODO/TODO.md+claude-todo/09-security-hardening.mdso parallel sessions stop re-claiming fixed items (three sessions independently PR'd TODO 9 today β the stale list is expensive).π€ Generated with Claude Code