feat: add secure ChatGPT Thingtime plugin - #412
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
🧹 Develop S3 preview removedThe PR-specific alias and every workflow-created develop deployment were removed when this PR closed. The ordinary generated Vercel Preview remains available on the shared development runtime. |
fd48dfd to
c1ad430
Compare
Lopu review — two defects fixed, three for you to decide onI compared the full head ( The security core holds up under pressure. Two things I tried to break and
Fixed in this branch1. Omitted tool filters were being sent upstream as the literal string This breaks the two most natural first calls. Upstream, 2.
Added regression tests for both. Baseline was 7/7; now 9/9. I verified they're real Your call — I deliberately didn't touch these
Non-blocking nits: the connection page ships Approve the direction — neither follow-up blocks merge. — Lopu, Thingtime's principal developer and repository steward |
…atgpt-plugin-develop # Conflicts: # graphify-out/GRAPH_REPORT.md # graphify-out/manifest.json
|
These examples are warning-only. They do not fail the build/API contexts or block this PR.
Sanitized tailnode:internal/modules/run_main:123
triggerUncaughtException(
^
AssertionError [ERR_ASSERTION]: all-branch.yml must stay retired; Lopu PR manager owns its former public triggers
true !== false
at file:///home/runner/work/thingtime/thingtime/remix/scripts/workflow-caller-contract.mjs:39:10
at ModuleJob.run (node:internal/modules/esm/module_job:343:25)
at async onImport.tracePromise.__proto__ (node:internal/modules/esm/loader:681:26)
at async asyncRunEntryPointWithESMLoader (node:internal/modules/run_main:117:5) {
generatedMessage: false,
code: 'ERR_ASSERTION',
actual: true,
expected: false,
operator: 'strictEqual',
diff: 'simple'
}
Node.js v22.23.2
|
|
🤖 Promotion conflict resolution was queued automatically for Conflicted source paths: The trusted worker will reconstruct, verify, publish, and attest the review branch; no manual branch update is needed. |
|
Immutable plan: |
|
🤖 Lopu — first, do not misread the This PR is not empty. Reviewed from the manifest SHAs instead: 25 real files, +2126/−5, plus 126 graphify files. The load-bearing line is in
|
|
🤖 Promotion conflict resolution was queued automatically for Conflicted source paths: The trusted worker will reconstruct, verify, publish, and attest the review branch; no manual branch update is needed. |
|
🤖 Promotion conflict resolution was queued automatically for Conflicted source paths: The trusted worker will reconstruct, verify, publish, and attest the review branch; no manual branch update is needed. |
|
🤖 Promotion conflict resolution was queued automatically for Conflicted source paths: The trusted worker will reconstruct, verify, publish, and attest the review branch; no manual branch update is needed. |
|
🤖 Promotion conflict resolution was queued automatically for Conflicted source paths: The trusted worker will reconstruct, verify, publish, and attest the review branch; no manual branch update is needed.
|
|
🤖 Promotion conflict resolution was queued automatically for Conflicted source paths: The trusted worker will reconstruct, verify, publish, and attest the review branch; no manual branch update is needed.
|
|
🤖 Promotion conflict resolution was queued automatically for Conflicted source paths: The trusted worker will reconstruct, verify, publish, and attest the review branch; no manual branch update is needed.
|
|
🤖 Promotion conflict resolution was queued automatically for Conflicted source paths: The trusted worker will reconstruct, verify, publish, and attest the review branch; no manual branch update is needed.
|
Summary
integrations/ChatGPT/plugin/thingtime-chatgpt.Security
Verification
node --import tsx --test app/api/utils/chatgpt/pluginCore.test.ts app/api/utils/chatgpt/plugin.test.ts(5 passed)npm run buildinremix/(passed, including Vercel output verification)Follow-up before public installation
THINGTIME_CHATGPT_CREDENTIAL_KEYas a deployment secret and deploy this branch to a public HTTPS origin.