mirror of
https://github.com/AmruthPillai/Reactive-Resume.git
synced 2026-09-29 16:24:22 +10:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
582a6fb429 | ||
|
|
24d9e5fb5c | ||
|
|
2a2d08a8d2 | ||
|
|
b42eb6ec06 | ||
|
|
fbf1f8fbac | ||
|
|
232f48578b | ||
|
|
e6a6bf0e6a | ||
|
|
96c7142fbc | ||
|
|
3c5908819c | ||
|
|
3e129c9d9d | ||
|
|
fd3494ccac | ||
|
|
f89acb4368 | ||
|
|
08e61ded7b | ||
|
|
f1d5c6bab4 | ||
|
|
e3717251cb | ||
|
|
30b21fa1e3 | ||
|
|
d77cb93494 | ||
|
|
ce996349fa | ||
|
|
a62ee22f20 | ||
|
|
0a4608bf9d | ||
|
|
9550910f17 | ||
|
|
4076b1a523 | ||
|
|
9699dbf2d8 | ||
|
|
31d6ee6251 | ||
|
|
d9fdf7a30a | ||
|
|
81341a107f | ||
|
|
3fc0896a34 | ||
|
|
7aaed8e30b | ||
|
|
730f795073 | ||
|
|
dc8f9787a4 | ||
|
|
742526af53 | ||
|
|
812d396120 | ||
|
|
1106562169 | ||
|
|
607eafd3e8 | ||
|
|
ffe889b832 | ||
|
|
51ac77295e | ||
|
|
c0c658c00c | ||
|
|
6416da28a4 | ||
|
|
614a1ff9df | ||
|
|
4f60856706 | ||
|
|
ad91a0838c | ||
|
|
15d6443b4f | ||
|
|
1f8c46b4f1 | ||
|
|
de9a6dcfad | ||
|
|
e19f706efd | ||
|
|
86a72bef13 | ||
|
|
d915ba3670 | ||
|
|
e272037bec | ||
|
|
a3784558b7 | ||
|
|
e0648e840a | ||
|
|
858c8ae88a | ||
|
|
07ca5d7c9e | ||
|
|
f573bf5998 | ||
|
|
f3622e8753 | ||
|
|
d7b2a843ca | ||
|
|
d277518d28 | ||
|
|
df2e21ef9e | ||
|
|
e2cb6f111f | ||
|
|
52949fcb4a | ||
|
|
55f6253603 | ||
|
|
cea27a97bb | ||
|
|
7fef84078d | ||
|
|
a1611c3b80 | ||
|
|
54366c5d29 | ||
|
|
64f68a12be | ||
|
|
778fd4b7d9 | ||
|
|
26f2360cf0 | ||
|
|
42527ad83b | ||
|
|
86e200a4da | ||
|
|
483b7a89b2 | ||
|
|
981d7581f5 | ||
|
|
138f3bbd12 | ||
|
|
ea9632d1b1 | ||
|
|
c6746fd9a9 | ||
|
|
11d619d3d9 | ||
|
|
25e044c86c | ||
|
|
f447f429a9 | ||
|
|
20cdb95caa | ||
|
|
5f5dca8445 | ||
|
|
10eb3bdbc7 | ||
|
|
d17e188b03 | ||
|
|
0e5994f243 | ||
|
|
75d102718d | ||
|
|
61526094d5 | ||
|
|
d409b3bef4 | ||
|
|
69d2a35cdc | ||
|
|
ce372b54bb | ||
|
|
b9a4397c93 | ||
|
|
d4fba09741 | ||
|
|
b53789964f | ||
|
|
f89873f083 | ||
|
|
1653d04c3f | ||
|
|
3e62a1d604 | ||
|
|
acd2a9cfe9 | ||
|
|
3987254061 | ||
|
|
903f9280d5 | ||
|
|
bc620b2783 | ||
|
|
9f0202eace | ||
|
|
cdb7bdd2fe | ||
|
|
77a5499881 | ||
|
|
5aeefa6dff | ||
|
|
1232d5dfb2 | ||
|
|
e71b5e6e91 | ||
|
|
ef36b76017 | ||
|
|
f783908b0e | ||
|
|
397d9e43ba | ||
|
|
313cfab631 | ||
|
|
4d593922e3 | ||
|
|
6ee4ee3a4c | ||
|
|
5e8284e49f | ||
|
|
f2769dce54 | ||
|
|
001ca16cad | ||
|
|
30f4edf45d | ||
|
|
c8a10b3d3b | ||
|
|
58ee4eead7 | ||
|
|
f97d1b736e | ||
|
|
63d6f3936d | ||
|
|
9ea9318303 | ||
|
|
368858a56f | ||
|
|
f39c1d604c | ||
|
|
e73a5610be | ||
|
|
ae8e2f76f1 | ||
|
|
66c25efe18 | ||
|
|
cf51fb84d7 | ||
|
|
45fd3fb5e0 | ||
|
|
61b58ae9a3 | ||
|
|
b20ac75927 | ||
|
|
578cb496aa | ||
|
|
4a9dced530 | ||
|
|
97f34b7ccd | ||
|
|
2687191041 | ||
|
|
2a4a1583be | ||
|
|
3d6fe265a0 | ||
|
|
ea97de5ec4 | ||
|
|
a6057abd79 | ||
|
|
137587ebc0 | ||
|
|
6ca0f2416e | ||
|
|
744eaa902e | ||
|
|
870388192e | ||
|
|
8c6cb46597 | ||
|
|
38832014b9 | ||
|
|
0fbeeeb4c4 | ||
|
|
78e16e4195 | ||
|
|
ccd34e4278 | ||
|
|
b85d285b69 | ||
|
|
836ed5db48 | ||
|
|
19966c52fa | ||
|
|
695cdb8514 | ||
|
|
999cd618cb | ||
|
|
b8b03c8be0 | ||
|
|
bc8a912ce7 | ||
|
|
ab67831e4b | ||
|
|
5850230f89 | ||
|
|
549135bb36 | ||
|
|
8c5804ed05 | ||
|
|
772bf14525 | ||
|
|
ee52636c10 | ||
|
|
2e711fd14c | ||
|
|
a4bdc54b2c | ||
|
|
8b5399aa6d | ||
|
|
4a407fdd87 | ||
|
|
d25f1bb815 | ||
|
|
22831058b1 | ||
|
|
cc76138197 | ||
|
|
43136b7acd | ||
|
|
8a71a7fbaf | ||
|
|
3bdf14b1d2 | ||
|
|
21ba966d4e | ||
|
|
6a71b91063 | ||
|
|
93623d8b79 | ||
|
|
08f88d964a | ||
|
|
ec6747b90e | ||
|
|
7d87847ead | ||
|
|
d5c1febc58 | ||
|
|
18bbee8d22 | ||
|
|
74936f2674 | ||
|
|
1051751351 | ||
|
|
bbf9ffbc01 | ||
|
|
1178c1d9b3 | ||
|
|
7a9106414e | ||
|
|
cb94e6621c | ||
|
|
f2893fd677 | ||
|
|
02b53ee3d2 | ||
|
|
b9da6ed587 | ||
|
|
0384989c43 | ||
|
|
cc36be9fd7 | ||
|
|
12046ead9e | ||
|
|
4a803e0c04 | ||
|
|
2e742da698 | ||
|
|
5f53956fae | ||
|
|
9d33aa6d44 | ||
|
|
18a24bdae8 | ||
|
|
1a602ceafd | ||
|
|
f4b16a9adb | ||
|
|
09cc6cf37a | ||
|
|
4fe9ab2a0d | ||
|
|
036829a8c7 | ||
|
|
7cea541aef | ||
|
|
16a27d91b4 | ||
|
|
451f3204d0 | ||
|
|
16d4dbefa6 | ||
|
|
1e4d8ddea2 | ||
|
|
23b71e9f99 | ||
|
|
f6fb3d7b75 | ||
|
|
7c4f41d6f1 | ||
|
|
5c7d03b72d | ||
|
|
7930d670d1 | ||
|
|
0a68d53f5b | ||
|
|
e03dd83e5d | ||
|
|
30bd8a8e04 | ||
|
|
156f24063e | ||
|
|
9bdde33ddf | ||
|
|
ad97b8a88c | ||
|
|
a5d0527090 | ||
|
|
1da0397abf | ||
|
|
bcd5cf0ce9 | ||
|
|
3180672543 | ||
|
|
e6e11c41b2 | ||
|
|
654f8898b6 | ||
|
|
142555302e | ||
|
|
0a7b158ee3 | ||
|
|
f01a590389 | ||
|
|
0a14ca78f7 | ||
|
|
c3d98241a7 | ||
|
|
e81de44adf | ||
|
|
c87aae562e | ||
|
|
18d49376ce | ||
|
|
c66a15bc68 | ||
|
|
02de0e9fcb | ||
|
|
39c564cdf1 | ||
|
|
6f09cea66d | ||
|
|
124f9d8a2e | ||
|
|
22dcb838f0 | ||
|
|
01f4963762 | ||
|
|
8f7faca67d | ||
|
|
699229f2c5 | ||
|
|
ddc60756db | ||
|
|
7c827a42f0 | ||
|
|
04029ec7f5 | ||
|
|
b852518335 | ||
|
|
9ecf340b9d | ||
|
|
a2557b2ad4 | ||
|
|
50f5dd7214 | ||
|
|
7a98f6662f | ||
|
|
05e48a7cbc | ||
|
|
d10eb4a55d | ||
|
|
1536dc48d9 | ||
|
|
8d4cf8a2f8 | ||
|
|
f468651c79 | ||
|
|
5c8338c175 | ||
|
|
873835a571 | ||
|
|
14c7c06516 | ||
|
|
9fdcec2eca | ||
|
|
1d4194a207 | ||
|
|
cce6d64afa | ||
|
|
ef47baf243 | ||
|
|
1f0844b39c | ||
|
|
8df1b25550 | ||
|
|
ea2beb8450 | ||
|
|
861ba8bf60 | ||
|
|
e0c2f6d88a | ||
|
|
ea3980cba0 | ||
|
|
cddb01f037 | ||
|
|
c4eb9d860b | ||
|
|
fe9b59e111 | ||
|
|
bf71253ca4 | ||
|
|
0207e5dfcc | ||
|
|
a2d6bc0c63 | ||
|
|
b2c3ab62b1 | ||
|
|
fa41150723 | ||
|
|
d53b89ba2d | ||
|
|
779ea5cb4a | ||
|
|
5a6f5d4d68 | ||
|
|
0878b256a9 | ||
|
|
bf27792ca0 | ||
|
|
cd1c597ff0 | ||
|
|
93e8d192a4 | ||
|
|
a95e63246e | ||
|
|
a3585a24e0 | ||
|
|
6d39074c58 | ||
|
|
a12e32ddac | ||
|
|
f629ea1ea3 | ||
|
|
b6842fb769 | ||
|
|
aada380888 | ||
|
|
7d809da6f8 | ||
|
|
57fee67d2d | ||
|
|
47fc16d806 | ||
|
|
1f308af728 | ||
|
|
321f2fb43f | ||
|
|
18b5aa4745 | ||
|
|
8354c39c45 | ||
|
|
7390c81b76 | ||
|
|
35cecf9c91 | ||
|
|
735e700929 | ||
|
|
a9973c0054 | ||
|
|
97ccb4ba06 | ||
|
|
165841af4e | ||
|
|
53288fcd3f | ||
|
|
ddbbbde803 | ||
|
|
2cbb0f63e7 | ||
|
|
00a1357deb | ||
|
|
e549d114ea | ||
|
|
84645f122b | ||
|
|
0a092ee2a4 | ||
|
|
f29b92e2fb | ||
|
|
f046f6fc51 | ||
|
|
3fa9de140c |
@@ -0,0 +1,3 @@
|
||||
---
|
||||
exclude_paths:
|
||||
- "migrations/**"
|
||||
+4
-2
@@ -9,6 +9,10 @@ SERVER_PORT="3001"
|
||||
# OpenGraph metadata, and absolute upload URLs.
|
||||
APP_URL="http://localhost:3000"
|
||||
|
||||
# Optional: serve one already-public resume at /. Use the ID from /builder/<id>.
|
||||
# Unset or blank keeps the marketing home. Restart after changes.
|
||||
# ROOT_RESUME_ID=
|
||||
|
||||
# --- Database (PostgreSQL) ---
|
||||
# PostgreSQL connection URL. In Docker Compose, the hostname is usually `postgres`;
|
||||
# when running directly on your machine, `localhost` is typical.
|
||||
@@ -97,8 +101,6 @@ FLAG_DISABLE_IMAGE_PROCESSING="false"
|
||||
# Rate limiting is enabled by default in production to prevent abuse.
|
||||
FLAG_DISABLE_API_RATE_LIMIT="false"
|
||||
|
||||
# This flag shows sponsor placements on the public landing page.
|
||||
FLAG_SHOW_SPONSORS="false"
|
||||
|
||||
# Allows dynamic OAuth client registration to use any parseable redirect URI,
|
||||
# including custom schemes, private hosts, and non-loopback http:// URLs.
|
||||
|
||||
@@ -15,13 +15,13 @@
|
||||
{
|
||||
"guid": "reactive-resume",
|
||||
"name": "Reactive Resume",
|
||||
"description": "A free and open-source resume builder that simplifies the process of creating, updating, and sharing your resume.",
|
||||
"description": "A free and open-source resume builder that makes it easy to create, update, and share your resume.",
|
||||
"webpageUrl": {
|
||||
"url": "https://rxresu.me"
|
||||
},
|
||||
"repositoryUrl": {
|
||||
"url": "https://github.com/amruthpillai/reactive-resume",
|
||||
"wellKnown": "https://github.com/amruthpillai/reactive-resume/blob/main/.github/.well-known/funding-manifest-urls"
|
||||
"url": "https://github.com/reactive-resume/reactive-resume",
|
||||
"wellKnown": "https://github.com/reactive-resume/reactive-resume/blob/main/.github/.well-known/funding-manifest-urls"
|
||||
},
|
||||
"licenses": ["spdx:MIT"],
|
||||
"tags": ["data", "design", "productivity", "resume-builder"]
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
blank_issues_enabled: false
|
||||
contact_links:
|
||||
- name: Questions and support
|
||||
url: https://github.com/amruthpillai/reactive-resume/discussions/categories/q-a
|
||||
url: https://github.com/reactive-resume/reactive-resume/discussions/categories/q-a
|
||||
about: Get help with setup, configuration, and using Reactive Resume.
|
||||
- name: Security vulnerability
|
||||
url: https://github.com/amruthpillai/reactive-resume/security/advisories/new
|
||||
url: https://github.com/reactive-resume/reactive-resume/security/advisories/new
|
||||
about: Report security vulnerabilities privately.
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
self-hosted-runner:
|
||||
labels:
|
||||
- blacksmith-32vcpu-ubuntu-2404
|
||||
- blacksmith-32vcpu-ubuntu-2404-arm
|
||||
@@ -13,7 +13,7 @@ env:
|
||||
|
||||
jobs:
|
||||
autofix:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: blacksmith-32vcpu-ubuntu-2404
|
||||
|
||||
steps:
|
||||
- name: Checkout Repository
|
||||
@@ -32,7 +32,7 @@ jobs:
|
||||
- name: Setup Node
|
||||
uses: actions/setup-node@v6
|
||||
with:
|
||||
node-version: "lts/*"
|
||||
node-version-file: ".nvmrc"
|
||||
cache: "pnpm"
|
||||
|
||||
- name: Install Dependencies
|
||||
|
||||
@@ -10,7 +10,7 @@ concurrency:
|
||||
|
||||
jobs:
|
||||
crowdin-sync:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: blacksmith-32vcpu-ubuntu-2404
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
|
||||
@@ -2,6 +2,11 @@ name: Build Docker Image
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
release:
|
||||
description: Publish release aliases and redeploy production (false runs a cache-only build, then publishes a canary)
|
||||
type: boolean
|
||||
default: false
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
@@ -13,30 +18,39 @@ concurrency:
|
||||
cancel-in-progress: true
|
||||
|
||||
env:
|
||||
IMAGE: ${{ github.repository }}
|
||||
GHCR_IMAGE: ghcr.io/${{ github.repository }}
|
||||
DOCKER_IMAGE: docker.io/amruthpillai/reactive-resume
|
||||
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
|
||||
|
||||
jobs:
|
||||
mode:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: blacksmith-32vcpu-ubuntu-2404
|
||||
|
||||
outputs:
|
||||
nightly: ${{ steps.mode.outputs.nightly }}
|
||||
release: ${{ steps.mode.outputs.release }}
|
||||
matrix: ${{ steps.mode.outputs.matrix }}
|
||||
canary: ${{ steps.mode.outputs.canary }}
|
||||
|
||||
steps:
|
||||
- name: Determine publishing mode
|
||||
id: mode
|
||||
env:
|
||||
EVENT_NAME: ${{ github.event_name }}
|
||||
GIT_REF: ${{ github.ref }}
|
||||
RELEASE: ${{ inputs.release }}
|
||||
run: |
|
||||
if [[ "${{ github.event_name }}" == "push" && "${{ github.ref }}" == "refs/heads/main" ]]; then
|
||||
if [[ "$EVENT_NAME" == "push" && "$GIT_REF" == "refs/heads/main" ]]; then
|
||||
echo "nightly=true" >> "$GITHUB_OUTPUT"
|
||||
echo "release=false" >> "$GITHUB_OUTPUT"
|
||||
echo 'matrix={"include":[{"platform":"linux/amd64","runner":"ubuntu-latest","arch":"amd64"}]}' >> "$GITHUB_OUTPUT"
|
||||
echo "canary=false" >> "$GITHUB_OUTPUT"
|
||||
elif [[ "$EVENT_NAME" == "workflow_dispatch" && "$RELEASE" != "true" ]]; then
|
||||
echo "nightly=false" >> "$GITHUB_OUTPUT"
|
||||
echo "release=false" >> "$GITHUB_OUTPUT"
|
||||
echo "canary=true" >> "$GITHUB_OUTPUT"
|
||||
else
|
||||
echo "nightly=false" >> "$GITHUB_OUTPUT"
|
||||
echo "release=true" >> "$GITHUB_OUTPUT"
|
||||
echo 'matrix={"include":[{"platform":"linux/amd64","runner":"ubuntu-latest","arch":"amd64"},{"platform":"linux/arm64","runner":"ubuntu-24.04-arm","arch":"arm64"}]}' >> "$GITHUB_OUTPUT"
|
||||
echo "canary=false" >> "$GITHUB_OUTPUT"
|
||||
fi
|
||||
|
||||
build:
|
||||
@@ -44,7 +58,14 @@ jobs:
|
||||
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix: ${{ fromJSON(needs.mode.outputs.matrix) }}
|
||||
matrix:
|
||||
include:
|
||||
- platform: linux/amd64
|
||||
runner: blacksmith-32vcpu-ubuntu-2404
|
||||
arch: amd64
|
||||
- platform: linux/arm64
|
||||
runner: blacksmith-32vcpu-ubuntu-2404-arm
|
||||
arch: arm64
|
||||
|
||||
runs-on: ${{ matrix.runner }}
|
||||
timeout-minutes: 30
|
||||
@@ -59,12 +80,10 @@ jobs:
|
||||
- name: Checkout Repository
|
||||
uses: actions/checkout@v6
|
||||
|
||||
- name: Get version from package.json
|
||||
id: version
|
||||
run: echo "version=$(jq -r .version package.json)" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Setup Docker Buildx
|
||||
uses: docker/setup-buildx-action@v4
|
||||
- name: Setup Blacksmith Docker Builder
|
||||
uses: useblacksmith/setup-docker-builder@v2
|
||||
with:
|
||||
cache-key: Dockerfile-${{ matrix.arch }}
|
||||
|
||||
- name: Login to Docker Hub
|
||||
uses: docker/login-action@v4
|
||||
@@ -84,14 +103,22 @@ jobs:
|
||||
uses: docker/metadata-action@v6
|
||||
with:
|
||||
images: |
|
||||
ghcr.io/${{ env.IMAGE }}
|
||||
docker.io/${{ env.IMAGE }}
|
||||
${{ env.GHCR_IMAGE }}
|
||||
${{ env.DOCKER_IMAGE }}
|
||||
tags: |
|
||||
type=sha,prefix=sha-,suffix=-${{ matrix.arch }}
|
||||
|
||||
- name: Cache-only smoke build
|
||||
if: ${{ needs.mode.outputs.canary == 'true' }}
|
||||
uses: useblacksmith/build-push-action@v2
|
||||
with:
|
||||
context: .
|
||||
platforms: ${{ matrix.platform }}
|
||||
outputs: type=cacheonly
|
||||
|
||||
- name: Build and Push by Digest
|
||||
id: build
|
||||
uses: docker/build-push-action@v7
|
||||
uses: useblacksmith/build-push-action@v2
|
||||
with:
|
||||
context: .
|
||||
sbom: true
|
||||
@@ -101,8 +128,6 @@ jobs:
|
||||
tags: ${{ steps.meta.outputs.tags }}
|
||||
labels: ${{ steps.meta.outputs.labels }}
|
||||
annotations: ${{ steps.meta.outputs.annotations }}
|
||||
cache-from: type=gha,scope=${{ env.IMAGE }}-${{ matrix.arch }}
|
||||
cache-to: type=gha,mode=max,scope=${{ env.IMAGE }}-${{ matrix.arch }}
|
||||
|
||||
- name: Export digest
|
||||
run: |
|
||||
@@ -123,7 +148,7 @@ jobs:
|
||||
- mode
|
||||
- build
|
||||
timeout-minutes: 30
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: blacksmith-32vcpu-ubuntu-2404
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
@@ -180,10 +205,11 @@ jobs:
|
||||
uses: docker/metadata-action@v6
|
||||
with:
|
||||
images: |
|
||||
ghcr.io/${{ env.IMAGE }}
|
||||
docker.io/${{ env.IMAGE }}
|
||||
${{ env.GHCR_IMAGE }}
|
||||
${{ env.DOCKER_IMAGE }}
|
||||
tags: |
|
||||
type=sha,prefix=sha-
|
||||
type=raw,value=canary-${{ github.run_id }}-${{ github.run_attempt }},enable=${{ needs.mode.outputs.canary == 'true' }}
|
||||
type=raw,value=nightly,enable=${{ needs.mode.outputs.nightly == 'true' }}
|
||||
type=raw,value=nightly-{{date 'YYYYMMDDHHmmss' tz='UTC'}},enable=${{ needs.mode.outputs.nightly == 'true' }}
|
||||
type=raw,value=latest,enable=${{ needs.mode.outputs.release == 'true' }}
|
||||
@@ -199,6 +225,8 @@ jobs:
|
||||
|
||||
if [[ "${{ needs.mode.outputs.nightly }}" == "true" ]]; then
|
||||
FINAL_TAG="nightly"
|
||||
elif [[ "${{ needs.mode.outputs.canary }}" == "true" ]]; then
|
||||
FINAL_TAG="canary-${{ github.run_id }}-${{ github.run_attempt }}"
|
||||
else
|
||||
FINAL_TAG="v${{ steps.version.outputs.version }}"
|
||||
fi
|
||||
@@ -211,14 +239,13 @@ jobs:
|
||||
--annotation "index:org.opencontainers.image.vendor=Amruth Pillai" \
|
||||
--annotation "index:org.opencontainers.image.url=https://rxresu.me" \
|
||||
--annotation "index:org.opencontainers.image.documentation=https://docs.rxresu.me" \
|
||||
--annotation "index:org.opencontainers.image.source=https://github.com/amruthpillai/reactive-resume" \
|
||||
--annotation "index:org.opencontainers.image.source=https://github.com/${{ github.repository }}" \
|
||||
--annotation "index:org.opencontainers.image.version=${{ steps.version.outputs.version }}" \
|
||||
$(printf 'ghcr.io/${{ env.IMAGE }}@sha256:%s ' *) \
|
||||
$(printf 'docker.io/${{ env.IMAGE }}@sha256:%s ' *)
|
||||
$(printf '${{ env.GHCR_IMAGE }}@sha256:%s ' *)
|
||||
|
||||
# Get the digest of the multi-arch manifest
|
||||
GHCR_DIGEST=$(docker buildx imagetools inspect ghcr.io/${{ env.IMAGE }}:${FINAL_TAG} --format '{{json .Manifest.Digest}}' | tr -d '"')
|
||||
DOCKER_DIGEST=$(docker buildx imagetools inspect docker.io/${{ env.IMAGE }}:${FINAL_TAG} --format '{{json .Manifest.Digest}}' | tr -d '"')
|
||||
GHCR_DIGEST=$(docker buildx imagetools inspect ${{ env.GHCR_IMAGE }}:${FINAL_TAG} --format '{{json .Manifest.Digest}}' | tr -d '"')
|
||||
DOCKER_DIGEST=$(docker buildx imagetools inspect ${{ env.DOCKER_IMAGE }}:${FINAL_TAG} --format '{{json .Manifest.Digest}}' | tr -d '"')
|
||||
echo "final_tag=$FINAL_TAG" >> "$GITHUB_OUTPUT"
|
||||
echo "ghcr_digest=$GHCR_DIGEST" >> "$GITHUB_OUTPUT"
|
||||
echo "docker_digest=$DOCKER_DIGEST" >> "$GITHUB_OUTPUT"
|
||||
@@ -229,15 +256,29 @@ jobs:
|
||||
- name: Sign images with Cosign
|
||||
run: |
|
||||
# Sign GHCR image
|
||||
cosign sign --yes ghcr.io/${{ env.IMAGE }}@${{ steps.manifest.outputs.ghcr_digest }}
|
||||
cosign sign --yes ${{ env.GHCR_IMAGE }}@${{ steps.manifest.outputs.ghcr_digest }}
|
||||
|
||||
# Sign Docker Hub image
|
||||
cosign sign --yes docker.io/${{ env.IMAGE }}@${{ steps.manifest.outputs.docker_digest }}
|
||||
cosign sign --yes ${{ env.DOCKER_IMAGE }}@${{ steps.manifest.outputs.docker_digest }}
|
||||
|
||||
- name: Inspect image
|
||||
run: |
|
||||
docker buildx imagetools inspect ghcr.io/${{ env.IMAGE }}:${{ steps.manifest.outputs.final_tag }}
|
||||
docker buildx imagetools inspect docker.io/${{ env.IMAGE }}:${{ steps.manifest.outputs.final_tag }}
|
||||
docker buildx imagetools inspect ${{ env.GHCR_IMAGE }}:${{ steps.manifest.outputs.final_tag }}
|
||||
docker buildx imagetools inspect ${{ env.DOCKER_IMAGE }}:${{ steps.manifest.outputs.final_tag }}
|
||||
|
||||
- name: Verify anonymous pulls on both architectures
|
||||
run: |
|
||||
set -euo pipefail
|
||||
registry_config=$(mktemp -d)
|
||||
trap 'rm -rf "$registry_config"' EXIT
|
||||
# Prevent Docker from discovering a system credential helper.
|
||||
printf '%s\n' '{"auths":{"ghcr.io":{},"https://index.docker.io/v1/":{}}}' > "$registry_config/config.json"
|
||||
for image in "$GHCR_IMAGE" "$DOCKER_IMAGE"; do
|
||||
for platform in linux/amd64 linux/arm64; do
|
||||
docker --config "$registry_config" pull --quiet --platform "$platform" \
|
||||
"$image:${{ steps.manifest.outputs.final_tag }}"
|
||||
done
|
||||
done
|
||||
|
||||
- name: Redeploy Stack
|
||||
if: ${{ needs.mode.outputs.release == 'true' }}
|
||||
|
||||
@@ -20,7 +20,7 @@ env:
|
||||
|
||||
jobs:
|
||||
e2e:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: blacksmith-32vcpu-ubuntu-2404
|
||||
timeout-minutes: 30
|
||||
|
||||
services:
|
||||
@@ -50,17 +50,20 @@ jobs:
|
||||
- name: Setup Node
|
||||
uses: actions/setup-node@v6
|
||||
with:
|
||||
node-version: "24"
|
||||
node-version-file: ".nvmrc"
|
||||
cache: "pnpm"
|
||||
|
||||
- name: Install Dependencies
|
||||
run: pnpm install --frozen-lockfile
|
||||
|
||||
- name: Run Server and Tooling Tests
|
||||
run: pnpm exec turbo run test:ci --filter=server --filter=@reactive-resume/tooling
|
||||
|
||||
- name: Install Playwright Browser
|
||||
run: pnpm exec playwright install --with-deps chromium
|
||||
timeout-minutes: 10
|
||||
run: |
|
||||
# The runner's Ubuntu archive/security mirrors time out during dependency installation.
|
||||
printf '%s\n' 'https://mirrors.edge.kernel.org/ubuntu/' | sudo tee /etc/apt/blacksmith-ubuntu-mirrors.txt > /dev/null
|
||||
sudo find /etc/apt -type f \( -name '*.list' -o -name '*.sources' \) \
|
||||
-exec sed -i -E 's#https?://(archive|us\.archive|security)\.ubuntu\.com/ubuntu#https://mirrors.edge.kernel.org/ubuntu#g' {} +
|
||||
pnpm exec playwright install --with-deps chromium
|
||||
|
||||
- name: Generate Test Secrets
|
||||
run: |
|
||||
@@ -73,11 +76,18 @@ jobs:
|
||||
- name: Run Database Migrations
|
||||
run: pnpm db:migrate
|
||||
|
||||
# Runs every workspace package, not a hand-maintained filter list, so a package
|
||||
# cannot silently lose coverage by being left out. Serial execution: the PDF
|
||||
# rasterization and API rate-limit suites time out when several packages' Vitest
|
||||
# thread pools oversubscribe the runner at once.
|
||||
- name: Run Unit Tests
|
||||
run: pnpm exec turbo run test:ci --concurrency=1
|
||||
|
||||
- name: Build
|
||||
run: pnpm build
|
||||
|
||||
- name: Run Baseline E2E Tests
|
||||
run: pnpm exec playwright test --grep-invert "@semantic-css"
|
||||
- name: Run E2E Tests
|
||||
run: pnpm exec playwright test
|
||||
|
||||
- name: Upload Playwright Report
|
||||
if: always()
|
||||
|
||||
@@ -10,7 +10,7 @@ permissions:
|
||||
|
||||
jobs:
|
||||
label:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: blacksmith-32vcpu-ubuntu-2404
|
||||
|
||||
steps:
|
||||
- name: Checkout Repository
|
||||
|
||||
@@ -10,7 +10,7 @@ permissions:
|
||||
|
||||
jobs:
|
||||
stale:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: blacksmith-32vcpu-ubuntu-2404
|
||||
|
||||
steps:
|
||||
- name: Close Inactive Issues Awaiting Information
|
||||
|
||||
@@ -50,6 +50,7 @@ temp
|
||||
.claude
|
||||
.cursor
|
||||
.opencode
|
||||
.codegraph
|
||||
.superpowers
|
||||
.worktrees
|
||||
.migration
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
# Imported-table raster CI fix
|
||||
|
||||
## Root cause
|
||||
|
||||
Hosted runs `34007560930` (PR #3471) and `34007788443` (PR #3472) failed only in
|
||||
`tests/e2e/specs/imported-table.spec.ts` with `horizontal: 18` instead of Plan 16's
|
||||
`horizontal: 17`; text and vertical checks passed.
|
||||
|
||||
The PDF operator dump from the failed hosted artifact showed 29 table path records matching the Plan 16 contract
|
||||
(17 horizontal, 12 vertical), followed by an unrelated `constructPath` `endPath` bbox:
|
||||
`[0, 19.65, 358.93, 20.65]`. Its stroke color was reported as `#cc00cc` only because the helper retained the
|
||||
last table stroke color. It was a later red section-divider fill/no-paint path, not an extra table border. The old
|
||||
helper classified every thin bbox after the last matching color state, so it counted this false positive.
|
||||
|
||||
The table's explicit width is stable at 300pt, while row height legitimately changes from 30pt to 31pt after the
|
||||
`Beta!` edit. The helper therefore scopes candidate paths by the fixture's 300pt horizontal grid envelope, not by a
|
||||
row-height tolerance. Missing or duplicated paths inside that envelope still change the exact 17/12 contract.
|
||||
|
||||
## Change
|
||||
|
||||
- Added `tests/e2e/fixtures/pdf-borders.ts` with deterministic `countTableBorderGeometry` filtering.
|
||||
- Updated browser/server PDF inspection in `tests/e2e/specs/imported-table.spec.ts` to use the helper.
|
||||
- Added `tests/e2e/fixtures/pdf-borders.test.ts`; regression proves old stale-color counting returns 2 horizontal
|
||||
paths while topology-scoped counting returns 1.
|
||||
|
||||
## Verification
|
||||
|
||||
- Intent skill inventory: 7 packages, 26 skills; no matching local skill for this E2E/PDF helper.
|
||||
- Focused helper regression: 1 file, 1 passed.
|
||||
- Dedicated imported-table E2E: 2 consecutive runs, each 1 passed; both exercise initial, unrelated-edit, and table-edit
|
||||
stages plus browser and server PDF exports.
|
||||
- Production build: 3/3 tasks successful.
|
||||
- Web typecheck via `rtk proxy pnpm --filter web typecheck`: passed (`tsgo --noEmit`).
|
||||
- Turbo boundaries: 1,443 files across 20 packages, no issues.
|
||||
- Targeted Biome: 3 files, no issues.
|
||||
- `git diff --check`: passed.
|
||||
|
||||
The root `pnpm typecheck` wrapper was also tried but invokes an incompatible `tsc` path and reports TS5096 for
|
||||
`allowImportingTsExtensions`; the package's documented `tsgo --noEmit` typecheck passes.
|
||||
@@ -0,0 +1,33 @@
|
||||
# Plan 21 implementation evidence
|
||||
|
||||
## Revision and scope
|
||||
|
||||
- Worktree: `issue-3060-section-heading-visibility`
|
||||
- Base: current `origin/main` at dispatch, `2a4a1583b` (`fix(pdf): restore Gengar skill rating order (#3473)`)
|
||||
- Product decisions applied: Q1 explicit Show heading toggle; Q2 Move-to continuations default visible; Q3 visual omission in preview/PDF/DOCX with accessible outline labels retained.
|
||||
- No `.codegraph/` directory exists in this worktree, so CodeGraph was skipped after the required presence check.
|
||||
- Intent discovery ran before edits; no matching local skill was available for this schema/PDF/DOCX/web change.
|
||||
|
||||
## Implementation
|
||||
|
||||
- Added backward-compatible `showHeading` section data for summary, built-ins, and custom sections. `parseResumeData` normalizes absent legacy values to `true`; explicit `false` survives round trips.
|
||||
- Added heading toggles to built-in/summary and custom section menus. Toggle mutations use `useUpdateResumeData`, preserving undo/autosave/save/reload behavior; legacy absent values are treated as visible. Existing lock fieldset remains authoritative.
|
||||
- Move-to-created custom sections explicitly set `showHeading: true`, independent of source heading state or copied title.
|
||||
- `SectionShell` omits complete heading/icon/decoration output when disabled in both icon and no-icon branches. Empty titles still resolve localized defaults.
|
||||
- DOCX section renderers omit visible heading paragraphs for summary, built-in, and custom sections while retaining content. Screen-reader mirror continues to expose section labels regardless of visual setting.
|
||||
- Added characterization for Semantic CSS `section[id="..."] section-heading { display: none; }`; body remains while heading is omitted.
|
||||
- Updated default/sample fixtures, generated schema references, recovery hashes, and compatibility tests; existing Gengar renderer/order changes remain untouched.
|
||||
|
||||
## Verification
|
||||
|
||||
- `pnpm --filter @reactive-resume/schema test`: 9 files, 132 tests passed.
|
||||
- `pnpm --filter @reactive-resume/pdf test`: 81 files, 1059 tests passed.
|
||||
- `pnpm --filter @reactive-resume/docx test`: 9 files, 76 tests passed.
|
||||
- `pnpm --filter web test`: 135 files, 942 tests passed.
|
||||
- `pnpm test`: full Turborepo suite passed (19 successful tasks; 10 cache hits).
|
||||
- Affected typechecks passed: schema, PDF, DOCX, web.
|
||||
- Focused menu, Move-to, accessible-outline, schema, PDF semantic, and DOCX renderer tests passed.
|
||||
- `pnpm exec turbo boundaries`: passed (1108 files, 20 packages).
|
||||
- Read-only `pnpm exec biome check` on 22 changed source/test files: passed; no write-capable `pnpm check` run.
|
||||
- `git diff --check`: passed.
|
||||
- Final diff review completed; local commit follows.
|
||||
@@ -0,0 +1,32 @@
|
||||
# Plan 23 item-pagination execution evidence
|
||||
|
||||
## Scope
|
||||
|
||||
Plan 23 steps 1–3 were evaluated from `origin/main` at `368858a56` (Plan 21 / PR #3477 merged). Widow/orphan UI and authored-page continuation guidance remain deferred from this execution, and Semantic CSS was not changed.
|
||||
|
||||
## Durable diagnostic matrix
|
||||
|
||||
`packages/pdf/src/templates/shared/item-pagination.test.tsx` renders physical PDF pages and checks numbered tokens exactly once for:
|
||||
|
||||
- an item that fits remaining space;
|
||||
- an item that fits a full page but not the remaining space;
|
||||
- an oversized item taller than one page;
|
||||
- a two-line paragraph at a boundary;
|
||||
- nested bullets; and
|
||||
- built-in plus custom items in an Azurill sidebar/main-column overflow fixture.
|
||||
|
||||
The fixture also keeps authored `metadata.layout.pages` separate from renderer-generated physical pages.
|
||||
|
||||
The current deterministic baseline is: fit remainder = 1 physical page; full-page-but-not-remainder = 3 pages with sampled tokens on pages 2/2/3; oversized = 5 pages with sampled tokens on pages 1/3/5; two-line boundary = 2 pages; nested bullets = 1 page; Azurill built-in/custom/sidebar = 5 pages with sampled tokens on pages 1/4/5/5/1. Page numbers here are 1-based; every token still appears exactly once.
|
||||
|
||||
## Concrete blocker
|
||||
|
||||
React PDF's only available item-level keep-together primitive is `View wrap={false}`. A durable renderer fixture with 180 paragraph-like child views shows that a non-wrapping item cannot safely fall back when its content exceeds one page: the renderer omits the oversized tail instead of splitting it. Applying the same prop to shared `SectionItem` would therefore violate the lossless token requirement; no item schema flag or menu control was added.
|
||||
|
||||
Do not estimate item height from HTML length, persist physical pages, alter existing Semantic CSS, or claim #3350 complete. A future implementation needs renderer-supported conditional keep-together behavior or an actual measured two-pass fallback that preserves every token.
|
||||
|
||||
## Verification
|
||||
|
||||
- `pnpm --filter @reactive-resume/pdf exec vitest run src/templates/shared/item-pagination.test.tsx`: 7 tests passed.
|
||||
- No production source or schema changes made after the unsafe fallback was reproduced.
|
||||
- Undo/persistence/lock UI coverage is intentionally absent because no item control was shipped; add it only when safe fallback exists.
|
||||
@@ -0,0 +1,157 @@
|
||||
# Plan 27 Phase A diagnostic evidence
|
||||
|
||||
Date: 2026-09-06
|
||||
Issue: [#3377](https://github.com/reactive-resume/reactive-resume/issues/3377)<br>
|
||||
Revision: `2a4a1583b` (`origin/main` at run start)
|
||||
Scope: Phase A, steps 1–2 only. No resolver, runtime behavior, or remote-source behavior changed.
|
||||
|
||||
## Drift and authority
|
||||
|
||||
- Worktree started clean and `HEAD` matched `origin/main`; `git diff origin/main...HEAD` was empty.
|
||||
- Current catalog is `packages/fonts/src/webfontlist.json`. Its web font records point at both Google Fonts static assets and jsDelivr assets; “Google blocked” is not an offline proof.
|
||||
- Browser preview is `apps/web/src/components/typography/font-display.tsx` and calls `FontFace.load()` against each catalog preview URL.
|
||||
- Browser PDF preview/download is `apps/web/src/features/resume/export/pdf-document.tsx` → `@reactive-resume/pdf/browser`; registration is `packages/pdf/src/hooks/use-register-fonts.ts`.
|
||||
- Server PDF is `apps/server/src/http/resume-pdf.ts` → `createResumePdfDownload`; Playwright browser routing cannot observe that process’s outbound font fetches.
|
||||
- The issue is open and unmodified. PR #3455 is the approved planning PR; its plan/decision log grants execution of this bounded diagnostic and manifest evidence.
|
||||
|
||||
## Deterministic fixture
|
||||
|
||||
`tests/e2e/fixtures/offline-fonts.ts` seeds one disposable resume after sample creation. It writes the same text into basics and summary, hides the picture, selects IBM Plex Serif 400/700 for body and heading, and marks the row public for the server-PDF surface.
|
||||
|
||||
The exact markers are versioned as `offline-font-scripts-v1`:
|
||||
|
||||
| Marker | Script or coverage |
|
||||
| --- | --- |
|
||||
| `Latin punctuation • — “quotes” €` | Latin plus General Punctuation and currency |
|
||||
| `简体中文` | Han / Simplified Chinese |
|
||||
| `العربية` | Arabic |
|
||||
| `עברית` | Hebrew |
|
||||
| `ไทย` | Thai |
|
||||
| `Emoji 🚀` | Emoji |
|
||||
|
||||
`tests/e2e/specs/offline-fonts.spec.ts` is opt-in (`OFFLINE_FONT_DIAGNOSTIC=1`) so the normal PR E2E suite does not become network-dependent. Each surface creates a new browser context with persisted auth state, disabled service workers, and no prior browser cache. Every non-same-origin request is aborted and recorded as `{ hostname, path }`; query strings, fragments, headers, bodies, tokens, and full URLs never enter diagnostic output. Reports are attached as JSON and emitted with the same sanitized shape.
|
||||
|
||||
The four surfaces are separate tests:
|
||||
|
||||
1. Font picker preview opens Typography → Font Family and waits for lazy `FontFace` preview loads.
|
||||
2. Builder PDF preview navigates to the builder, captures the active PDF canvas, and measures marker-local raster crops.
|
||||
3. Browser PDF download uses the Export dialog, rasterizes the downloaded PDF, and measures marker-local crops when generation succeeds.
|
||||
4. Server PDF calls the public PDF endpoint and records text-layer marker presence when generation succeeds.
|
||||
|
||||
Builder/browser-PDF reports keep PDF text extraction as a separate `textLayerMarkers` signal; it does not prove visible glyph outlines. Raster evidence attaches a rendered PNG and per-marker crop metrics, failing for blank or tofu-like visible crops. Blocked browser font requests classify browser surfaces as `network-error`. The server report deliberately says `server-outbound-requests-unobservable-from-playwright`; its cold-network gate remains unresolved because server outbound capture and verifiable restart identity require external host-level controls.
|
||||
|
||||
## Run protocol and cold-cache boundary
|
||||
|
||||
Build and database setup follow `tests/e2e/README.md`. Run each surface in a separately restarted production server process so module-level PDF font registration state cannot leak between controls:
|
||||
|
||||
```text
|
||||
OFFLINE_FONT_DIAGNOSTIC=1 OFFLINE_FONT_DIAGNOSTIC_SERVER_RESTARTED=1 \
|
||||
pnpm exec playwright test tests/e2e/specs/offline-fonts.spec.ts --grep "picker preview"
|
||||
```
|
||||
|
||||
Stop and restart the production server before repeating the command with `builder PDF`, `browser PDF`, and `server PDF` grep patterns. The environment used for this change had no built `apps/server/dist` or `apps/web/dist`, no running PostgreSQL instance, and no production server to restart, so the cold E2E matrix was not run. This is an explicit infrastructure blocker, not a pass claim. The test records `serverRestartFlag` only as caller input and labels it non-proof; it does not claim a completed cold-network gate.
|
||||
|
||||
The current Playwright route guard cannot impose host-level egress denial on Node.js running the server. A genuinely cold server test therefore needs a separately restarted server plus host-level egress capture/deny (for example, a controlled network namespace or an approved outbound proxy). Do not infer server network behavior from an empty browser request list.
|
||||
|
||||
## Administrator-hosted manifest proposal
|
||||
|
||||
This is a proposal, not an asset download. It intentionally contains only the primary family and glyph fallbacks required by the fixture and current PDF fallback map, not the full catalog.
|
||||
|
||||
```json
|
||||
{
|
||||
"schemaVersion": "offline-fonts-v1",
|
||||
"mode": "local-only",
|
||||
"assetRoot": "/fonts/offline/v1",
|
||||
"families": {
|
||||
"IBM Plex Serif": {
|
||||
"normal": { "400": "ibm-plex-serif/400.ttf", "700": "ibm-plex-serif/700.ttf" },
|
||||
"italic": { "400": "ibm-plex-serif/400-italic.ttf", "700": "ibm-plex-serif/700-italic.ttf" },
|
||||
"preview": "ibm-plex-serif/preview.ttf"
|
||||
},
|
||||
"IBM Plex Sans": {
|
||||
"normal": { "400": "ibm-plex-sans/400.ttf", "700": "ibm-plex-sans/700.ttf" },
|
||||
"italic": { "400": "ibm-plex-sans/400-italic.ttf", "700": "ibm-plex-sans/700-italic.ttf" },
|
||||
"preview": "ibm-plex-sans/preview.ttf"
|
||||
},
|
||||
"Noto Serif": {
|
||||
"normal": { "400": "noto-serif/400.ttf", "700": "noto-serif/700.ttf" },
|
||||
"italic": { "400": "noto-serif/400-italic.ttf", "700": "noto-serif/700-italic.ttf" },
|
||||
"preview": "noto-serif/preview.ttf"
|
||||
},
|
||||
"Noto Sans": {
|
||||
"normal": { "400": "noto-sans/400.ttf", "700": "noto-sans/700.ttf" },
|
||||
"italic": { "400": "noto-sans/400-italic.ttf", "700": "noto-sans/700-italic.ttf" },
|
||||
"preview": "noto-sans/preview.ttf"
|
||||
},
|
||||
"Noto Sans SC": { "normal": { "400": "noto-sans-sc/400.ttf", "700": "noto-sans-sc/700.ttf" }, "italic": "reuse-normal", "preview": "noto-sans-sc/preview.ttf" },
|
||||
"Noto Serif SC": { "normal": { "400": "noto-serif-sc/400.ttf", "700": "noto-serif-sc/700.ttf" }, "italic": "reuse-normal", "preview": "noto-serif-sc/preview.ttf" },
|
||||
"Noto Sans TC": { "normal": { "400": "noto-sans-tc/400.ttf", "700": "noto-sans-tc/700.ttf" }, "italic": "reuse-normal", "preview": "noto-sans-tc/preview.ttf" },
|
||||
"Noto Serif TC": { "normal": { "400": "noto-serif-tc/400.ttf", "700": "noto-serif-tc/700.ttf" }, "italic": "reuse-normal", "preview": "noto-serif-tc/preview.ttf" },
|
||||
"Noto Sans JP": { "normal": { "400": "noto-sans-jp/400.ttf", "700": "noto-sans-jp/700.ttf" }, "italic": "reuse-normal", "preview": "noto-sans-jp/preview.ttf" },
|
||||
"Noto Serif JP": { "normal": { "400": "noto-serif-jp/400.ttf", "700": "noto-serif-jp/700.ttf" }, "italic": "reuse-normal", "preview": "noto-serif-jp/preview.ttf" },
|
||||
"Noto Sans KR": { "normal": { "400": "noto-sans-kr/400.ttf", "700": "noto-sans-kr/700.ttf" }, "italic": "reuse-normal", "preview": "noto-sans-kr/preview.ttf" },
|
||||
"Noto Serif KR": { "normal": { "400": "noto-serif-kr/400.ttf", "700": "noto-serif-kr/700.ttf" }, "italic": "reuse-normal", "preview": "noto-serif-kr/preview.ttf" },
|
||||
"Noto Sans Arabic": { "normal": { "400": "noto-sans-arabic/400.ttf", "700": "noto-sans-arabic/700.ttf" }, "italic": "reuse-normal", "preview": "noto-sans-arabic/preview.ttf" },
|
||||
"Noto Naskh Arabic": { "normal": { "400": "noto-naskh-arabic/400.ttf", "700": "noto-naskh-arabic/700.ttf" }, "italic": "reuse-normal", "preview": "noto-naskh-arabic/preview.ttf" },
|
||||
"Noto Sans Hebrew": { "normal": { "400": "noto-sans-hebrew/400.ttf", "700": "noto-sans-hebrew/700.ttf" }, "italic": "reuse-normal", "preview": "noto-sans-hebrew/preview.ttf" },
|
||||
"Noto Sans Thai": { "normal": { "400": "noto-sans-thai/400.ttf", "700": "noto-sans-thai/700.ttf" }, "italic": "reuse-normal", "preview": "noto-sans-thai/preview.ttf" },
|
||||
"Noto Emoji": { "normal": { "400": "noto-emoji/400.ttf", "700": "noto-emoji/700.ttf" }, "italic": "reuse-normal", "preview": "noto-emoji/preview.ttf" }
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
### Candidate source, license, script, and size evidence
|
||||
|
||||
Sizes are `Content-Length` bytes from a HEAD request to the exact current catalog assets on 2026-09-06. Responses reported `Content-Encoding: gzip`; these are compressed transfer-size estimates, not a claim about the eventual on-disk representation. Preview paths are aliases to the selected 400 face and add no extra bytes when stored once. Primary sources: [IBM Plex LICENSE.txt](https://github.com/IBM/plex/blob/master/LICENSE.txt), [Noto core LICENSE](https://github.com/notofonts/noto-fonts/blob/main/LICENSE), [Noto CJK Sans LICENSE](https://github.com/notofonts/noto-cjk/blob/main/Sans/LICENSE), and [Noto Emoji font LICENSE](https://github.com/googlefonts/noto-emoji/blob/main/fonts/LICENSE).
|
||||
|
||||
| Family | Style/weights in proposal | Current catalog source version | License | Script/fallback role | Gzip bytes (selected files) | Build owner; runtime owners |
|
||||
| --- | --- | --- | --- | --- | ---: | --- |
|
||||
| IBM Plex Serif | normal 400/700; italic 400/700 | `fonts.gstatic.com/s/ibmplexserif/v20` | OFL 1.1, Reserved Font Name `Plex` | Primary serif; Latin and punctuation stack | 294,717 | `packages/fonts`; `apps/web` FontDisplay; `packages/pdf` registration |
|
||||
| IBM Plex Sans | normal 400/700; italic 400/700 | `fonts.gstatic.com/s/ibmplexsans/v23` | OFL 1.1, Reserved Font Name `Plex` | Primary sans | 435,469 | `packages/fonts`; `apps/web` FontDisplay; `packages/pdf` registration |
|
||||
| Noto Serif | normal 400/700; italic 400/700 | `fonts.gstatic.com/s/notoserif/v33` | OFL 1.1 | Serif punctuation fallback | 1,055,120 | `packages/fonts`; `packages/pdf` fallback registration |
|
||||
| Noto Sans | normal 400/700; italic 400/700 | `fonts.gstatic.com/s/notosans/v42` | OFL 1.1 | Sans punctuation fallback | 1,236,259 | `packages/fonts`; `packages/pdf` fallback registration |
|
||||
| Noto Sans SC | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notosanssc/v40` | OFL 1.1 (Noto CJK) | Simplified Han; CJK fallback | 12,766,416 | `packages/fonts`; `packages/pdf` CJK fallback |
|
||||
| Noto Serif SC | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notoserifsc/v35` | OFL 1.1 (Noto CJK) | Simplified Han serif fallback | 17,350,185 | `packages/fonts`; `packages/pdf` CJK fallback |
|
||||
| Noto Sans TC | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notosanstc/v39` | OFL 1.1 (Noto CJK) | Traditional Han fallback | 8,628,278 | `packages/fonts`; `packages/pdf` CJK fallback |
|
||||
| Noto Serif TC | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notoseriftc/v36` | OFL 1.1 (Noto CJK) | Traditional Han serif fallback | 11,804,923 | `packages/fonts`; `packages/pdf` CJK fallback |
|
||||
| Noto Sans JP | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notosansjp/v56` | OFL 1.1 (Noto CJK) | Kana and Japanese Han fallback | 6,383,035 | `packages/fonts`; `packages/pdf` CJK fallback |
|
||||
| Noto Serif JP | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notoserifjp/v33` | OFL 1.1 (Noto CJK) | Kana and Japanese Han serif fallback | 8,685,862 | `packages/fonts`; `packages/pdf` CJK fallback |
|
||||
| Noto Sans KR | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notosanskr/v39` | OFL 1.1 (Noto CJK) | Hangul and Korean Han fallback | 6,102,888 | `packages/fonts`; `packages/pdf` CJK fallback |
|
||||
| Noto Serif KR | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notoserifkr/v31` | OFL 1.1 (Noto CJK) | Hangul and Korean Han serif fallback | 11,113,442 | `packages/fonts`; `packages/pdf` CJK fallback |
|
||||
| Noto Sans Arabic | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notosansarabic/v33` | OFL 1.1 | Arabic sans fallback | 178,455 | `packages/fonts`; `packages/pdf` script fallback |
|
||||
| Noto Naskh Arabic | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notonaskharabic/v44` | OFL 1.1 | Arabic serif fallback | 190,924 | `packages/fonts`; `packages/pdf` script fallback |
|
||||
| Noto Sans Hebrew | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notosanshebrew/v50` | OFL 1.1 | Hebrew fallback for both serif/sans slots | 55,707 | `packages/fonts`; `packages/pdf` script fallback |
|
||||
| Noto Sans Thai | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notosansthai/v29` | OFL 1.1 | Thai fallback for both serif/sans slots | 55,173 | `packages/fonts`; `packages/pdf` script fallback |
|
||||
| Noto Emoji | normal 400/700; italic reuses normal | `fonts.gstatic.com/s/notoemoji/v62` | OFL 1.1 for font files; assets/tools have separate licenses | Emoji outline fallback; verify renderer support | 1,153,847 | `packages/fonts`; `packages/pdf` script fallback |
|
||||
|
||||
Estimated transfer size for all rows and listed styles: **87,490,700 bytes (~83.44 MiB)**. This confirms why a full-catalog bundle is out of scope. A later implementation should subset by declared glyph requirements or make the administrator choose fallback families; it must not silently fetch another CDN.
|
||||
|
||||
### Source and license obligations
|
||||
|
||||
- Pin an upstream release/commit and retain source attribution plus the complete applicable license with hosted assets. Do not use mutable `@latest` URLs as runtime sources.
|
||||
- IBM Plex’s license has Reserved Font Name `Plex`; modified/subset outputs must follow OFL naming requirements.
|
||||
- Noto core, Noto CJK, and Noto Emoji font files are OFL 1.1, but Noto Emoji documents separate Apache/public-domain treatment for tools and flag image assets. Bundle only font files unless those other assets are intentionally needed and separately attributed.
|
||||
- License checks are build-owner responsibility (`packages/fonts`/tooling); runtime owners (`apps/web` and `packages/pdf`) consume only the validated manifest.
|
||||
|
||||
### Missing-family and missing-asset behavior
|
||||
|
||||
Local mode must resolve only same-origin administrator-hosted manifest paths. If imported resume data names an unavailable family, show an actionable missing-family error naming the family and required local asset; apply a configured local fallback only when the administrator explicitly supplied one. If a required weight/style/fallback asset is absent, fail the affected preview/export with an actionable diagnostic containing family/style/weight and local path. Never retry Google Fonts, jsDelivr, or any other remote URL in local mode.
|
||||
|
||||
Standard PDF families (Helvetica, Courier, Times-Roman) remain file-free. They do not prove that a document containing punctuation, CJK, Arabic, Hebrew, Thai, or emoji is network-free; the script fallback rows remain required.
|
||||
|
||||
## Verification record
|
||||
|
||||
Completed read-only checks before handoff:
|
||||
|
||||
- CodeGraph exploration of font catalog, picker preview, browser PDF, server PDF, and existing fallback tests.
|
||||
- `pnpm dlx @tanstack/intent@latest list`: no matching local intent skill for this work.
|
||||
- `pnpm exec biome check tests/e2e/specs/offline-fonts.spec.ts tests/e2e/fixtures/offline-fonts.ts turbo.json`: passed.
|
||||
- `git diff --check`: passed.
|
||||
- `pnpm --filter @reactive-resume/fonts test`: passed (55 tests).
|
||||
- `pnpm --filter @reactive-resume/pdf exec vitest run src/hooks/use-register-fonts.test.ts`: passed (35 tests).
|
||||
- Web typography/regression suite: passed (940 tests across 135 files); web and server package typechecks passed.
|
||||
- `pnpm exec playwright test tests/e2e/specs/offline-fonts.spec.ts --list`: passed (4 diagnostic tests collected).
|
||||
- E2E diagnostic execution: blocked by missing build outputs and unavailable PostgreSQL/server; no success claim made.
|
||||
- `pnpm exec turbo boundaries`: passed on fresh rerun (Turbo 2.10.12, 1108 files, no issues).
|
||||
|
||||
The implementation intentionally stops at diagnostic fixtures and manifest evidence. Shared source resolution, asset hosting, local-mode configuration, and production behavior remain Phase A step 3+ work.
|
||||
@@ -0,0 +1,22 @@
|
||||
# Plan 27A remediation round 2
|
||||
|
||||
Date: 2026-09-06
|
||||
Base: `ae8e2f76f`
|
||||
|
||||
## Focused fixes
|
||||
|
||||
- Removed multilingual markers from the fixture headline. Each marker now exists only in its dedicated summary paragraph.
|
||||
- Added pure marker-location helpers. Marker lookup joins PDF text items, supports markers split across items, rejects duplicate occurrences, and rejects non-whitespace neighbors that could contaminate a local crop.
|
||||
- Raster measurement still scans with antialiasing padding but counts ink only inside the marker box, preventing neighboring glyphs from making blank or tofu-like evidence pass.
|
||||
- Browser PDF download now separates download errors from post-download evidence errors. A received download with failed rasterization is reported as `unresolved-raster-evidence-error` and fails the opt-in test rather than passing as a generic download error.
|
||||
- Added focused pure tests covering duplicate, split, neighboring, blank, and tofu-like cases.
|
||||
- Removed trailing spaces from `plan-27a-remediation.md`.
|
||||
|
||||
## Verification
|
||||
|
||||
- `pnpm exec vitest run tests/e2e/fixtures/offline-font-markers.test.ts` — 5/5 passed.
|
||||
- `pnpm exec biome check tests/e2e/specs/offline-fonts.spec.ts tests/e2e/fixtures/offline-fonts.ts tests/e2e/fixtures/offline-font-markers.ts tests/e2e/fixtures/offline-font-markers.test.ts` — passed.
|
||||
- `pnpm exec playwright test tests/e2e/specs/offline-fonts.spec.ts --list` — 4 tests collected.
|
||||
- `git diff --check` — passed after remediation-document whitespace cleanup.
|
||||
|
||||
Full diagnostic E2E remains opt-in and was not run in this focused round. Server outbound request capture and verifiable restart identity remain explicit external host-level blockers; no production resolver changes were made.
|
||||
@@ -0,0 +1,24 @@
|
||||
# Plan 27A remediation
|
||||
|
||||
Date: 2026-09-06
|
||||
Base: `61b58ae9a`
|
||||
Scope: concrete findings from `.orchestration/plan-27a-independent-review.md` only.
|
||||
|
||||
## Remediated findings
|
||||
|
||||
- Builder PDF preview and browser PDF download now produce raster evidence. The fixture stores each multilingual marker in its own summary paragraph, allowing the diagnostic to locate marker-local PDF text boxes and measure only those raster crops. Reports attach a rendered PNG plus per-marker `inkPixels`, trimmed dimensions, and status. Blank and tofu-like crops fail assertions; no whole-page snapshot is used.
|
||||
- PDF text extraction is reported separately as `textLayerMarkers`. It is not described or asserted as proof of visible glyph outlines.
|
||||
- Server PDF output remains text-extraction-only and is explicitly classified as `serverGateStatus: unresolved-external-host-level-blocker`. `serverRestartFlag` is caller input, not restart proof. Browser Playwright routing is not used to infer server egress, and no production resolver or instrumentation behavior was added.
|
||||
- `.orchestration/plan-27a-diagnostic.md` now records a fresh boundaries pass and the corrected `87,490,700 bytes (~83.44 MiB)` arithmetic.
|
||||
- Diagnostic remains opt-in through `OFFLINE_FONT_DIAGNOSTIC=1`; normal CI behavior remains unchanged. Request logs stay sanitized to hostname and pathname.
|
||||
|
||||
## Verification
|
||||
|
||||
- `pnpm exec biome check tests/e2e/specs/offline-fonts.spec.ts tests/e2e/fixtures/offline-fonts.ts` — passed.
|
||||
- `git diff --check` — passed.
|
||||
- `pnpm exec playwright test tests/e2e/specs/offline-fonts.spec.ts --list` — 4 tests collected.
|
||||
- `pnpm --filter @reactive-resume/fonts test` — 55/55 passed.
|
||||
- `pnpm --filter @reactive-resume/pdf exec vitest run src/hooks/use-register-fonts.test.ts` — 35/35 passed.
|
||||
- `pnpm exec turbo boundaries` — passed on fresh rerun (Turbo 2.10.12, 1108 files, no issues).
|
||||
|
||||
Full diagnostic E2E remains unrun because this environment lacks production build output, PostgreSQL, and a production server. Server cold-network capture and verifiable restart identity remain external host-level blockers by design; this remediation does not claim that gate is complete.
|
||||
@@ -0,0 +1,17 @@
|
||||
# Issue 3350 remediation evidence
|
||||
|
||||
## Findings addressed
|
||||
|
||||
- `item-pagination.test.tsx` now derives complete numbered-token inventories for each generated fixture and asserts every token exactly once. Sampled token-to-physical-page placement checks remain separate.
|
||||
- Pagination fixtures snapshot `metadata.layout.pages` before rendering and assert authored layout pages are unchanged afterward. Overflow fixtures also assert physical PDF page count exceeds authored page count.
|
||||
- Unsafe `wrap={false}` renderer coverage remains diagnostic-only; no item controls, schema flags, or runtime behavior were added.
|
||||
|
||||
## Verification
|
||||
|
||||
- `rtk proxy pnpm --filter @reactive-resume/pdf exec vitest run src/semantic/pagination.test.tsx src/templates/shared/item-pagination.test.tsx` — 2 files, 11 tests passed.
|
||||
- `rtk proxy pnpm --filter @reactive-resume/pdf typecheck` — passed.
|
||||
- `rtk proxy pnpm exec biome check packages/pdf/src/templates/shared/item-pagination.test.tsx` — passed.
|
||||
- `rtk proxy pnpm exec turbo boundaries` — passed; 1109 files checked.
|
||||
- `rtk git diff --check origin/main...HEAD` — passed.
|
||||
|
||||
Only PDF test coverage and this evidence file changed; production behavior remains untouched.
|
||||
@@ -28,187 +28,99 @@ Boundaries: code/commits/PRs written normal.
|
||||
<!-- caveman-end -->
|
||||
|
||||
<!-- graphify-begin -->
|
||||
## graphify
|
||||
|
||||
This project has a knowledge graph at graphify-out/ with god nodes, community structure, and cross-file relationships.
|
||||
|
||||
When the user types `/graphify`, use the installed graphify skill or instructions before doing anything else.
|
||||
|
||||
Rules:
|
||||
- For codebase questions, first run `graphify query "<question>"` when graphify-out/graph.json exists. Use `graphify path "<A>" "<B>"` for relationships and `graphify explain "<concept>"` for focused concepts. These return a scoped subgraph, usually much smaller than GRAPH_REPORT.md or raw grep output.
|
||||
- Dirty graphify-out/ files are expected after hooks or incremental updates; dirty graph files are not a reason to skip graphify. Only skip graphify if the task is about stale or incorrect graph output, or the user explicitly says not to use it.
|
||||
- If graphify-out/wiki/index.md exists, use it for broad navigation instead of raw source browsing.
|
||||
- Read graphify-out/GRAPH_REPORT.md only for broad architecture review or when query/path/explain do not surface enough context.
|
||||
- After modifying code, run `graphify update .` to keep the graph current (AST-only, no API cost).
|
||||
<!-- graphify-end -->
|
||||
|
||||
# AGENTS.md
|
||||
|
||||
## Agent skills
|
||||
|
||||
### Issue tracker
|
||||
- Issues and specs: GitHub Issues for `reactive-resume/reactive-resume`. See `docs/agents/issue-tracker.md`.
|
||||
- Domain docs use a multi-context layout. See `docs/agents/domain.md`.
|
||||
|
||||
Issues and specs are tracked in GitHub Issues for `amruthpillai/reactive-resume`. See `docs/agents/issue-tracker.md`.
|
||||
## Overview
|
||||
|
||||
### Domain docs
|
||||
Reactive Resume is a pnpm monorepo (Turborepo) with two deployable apps: `apps/web` (TanStack Start / React 19 / Vite) and `apps/server` (Hono / Node.js). The production Docker image runs a single Node.js process on port 3000; `apps/server` mounts the API/auth/MCP/static routes and serves the built web app.
|
||||
|
||||
This repository uses a multi-context domain-doc layout. See `docs/agents/domain.md`.
|
||||
Internal packages are source-consumed through `package.json` export maps pointing at `src` files. Do not assume package-local `dist` output exists unless a package explicitly adds it.
|
||||
|
||||
## Cursor Cloud specific instructions
|
||||
Prerequisites: **Node.js 24** (pinned in `.nvmrc`; matches Dockerfile `ARG NODE_VERSION=24`), **pnpm 12.3.4** (pinned by `packageManager` in the root `package.json`; pnpm self-manages to it, so any recent pnpm can bootstrap — the Dockerfile's `ARG PNPM_VERSION` only picks the base image) ([install guide](https://pnpm.io/installation)), and **Docker** for PostgreSQL (`sudo dockerd &` if the daemon isn't running).
|
||||
|
||||
### Overview
|
||||
## Ownership map
|
||||
|
||||
Reactive Resume is a pnpm monorepo (Turborepo) with two deployable apps: `apps/web` (TanStack Start / React 19 / Vite) and `apps/server` (Hono / Node.js). The production Docker image runs a single Node.js process on port 3000, with `apps/server` mounting the API/auth/MCP/static routes and serving the built web app.
|
||||
Where each concern lives, and where new code for it goes:
|
||||
|
||||
Internal packages are source-consumed through `package.json` export maps that point at `src` files. Do not assume package-local `dist` output exists unless a package explicitly adds it.
|
||||
| Area | Owner |
|
||||
|------|-------|
|
||||
| Web routes, loaders, user-facing workflows | `apps/web/src/routes`, `apps/web/src/features` (file-based; never hand-edit `routeTree.gen.ts`) |
|
||||
| Server HTTP routes/adapters, startup checks, static handlers, MCP transport, OpenAPI/well-known | `apps/server/src/{http,rpc,mcp,openapi,static,startup}` |
|
||||
| Authenticated API contracts + business logic | `packages/api/src/features/*` (oRPC routers, DTOs, rate limiting; aggregated at `@reactive-resume/api/routers` for `/api/rpc`) |
|
||||
| Auth | `packages/auth` (Better Auth config/helpers/types; `apps/server/src/http/auth.ts` delegates to `auth.handler`) |
|
||||
| DB client + schema | `packages/db` (Drizzle; migrations at repo root `migrations/`) |
|
||||
| Server env validation | `packages/env` (auto-loads root `.env`) |
|
||||
| Resume/page/template Zod schemas | `packages/schema` |
|
||||
| Pure resume-domain behavior (no DB/HTTP/DOM/renderer deps) | `packages/resume` (JSON Patch helpers, social-network icons) |
|
||||
| Resume PDF rendering | `packages/pdf` (React PDF document, font registration, template primitives, browser/server adapters) |
|
||||
| PDF.js viewer/canvas UI | `apps/web/src/features/resume` — never in `packages/pdf` |
|
||||
| DOCX export | `packages/docx` |
|
||||
| MCP tools/prompts/resources/server-card | `packages/mcp` |
|
||||
| Generic UI primitives + hooks | `packages/ui` (Base UI/shadcn-style); workflow-specific UI stays in the owning web feature |
|
||||
| Focused support surfaces | `packages/fonts`, `packages/email`, `packages/import`, `packages/ai`, `packages/utils`, `packages/config` — prefer existing exports over cross-package shortcuts |
|
||||
| Dev-only scripts | `tooling/`, not `packages/`, so packages only hold runtime-bundled code |
|
||||
|
||||
### Prerequisites
|
||||
Narrow cross-cutting helpers go in `packages/utils` only after checking no domain package is a better owner. Specifically: resume JSON Patch behavior belongs in `@reactive-resume/resume/patch` and DOCX builders in `@reactive-resume/docx` — not in `@reactive-resume/utils`.
|
||||
|
||||
- **Node.js 24** (matches Dockerfile `ARG NODE_VERSION=24`). Use `nvm install 24 && nvm use 24` if needed.
|
||||
- **Docker** is required to run PostgreSQL. Start it with `sudo dockerd &` if the daemon isn't running.
|
||||
- **pnpm 11.21.0**. Install pnpm directly using the [official installation guide](https://pnpm.io/installation).
|
||||
## Web app conventions
|
||||
|
||||
### Codebase map
|
||||
- `apps/web/src/router.tsx` initializes router context with `queryClient`, `orpc`, `theme`, `locale`, `session`, and `flags`. Reuse route context instead of refetching these ad hoc.
|
||||
- Builder shell: `apps/web/src/routes/builder/$resumeId`. Its nested preview route is client-only (`ssr: false`); the public resume route `apps/web/src/routes/$username/$slug.tsx` uses `ssr: "data-only"`.
|
||||
- Browser-only preview code: `apps/web/src/features/resume/preview`. Public PDF viewer: `apps/web/src/features/resume/public`. Keep PDF.js/canvas/browser APIs out of SSR paths.
|
||||
- Isomorphic oRPC client: `apps/web/src/libs/orpc/client.ts` — server calls use an in-process router client, browser calls use `/api/rpc` with credentials included.
|
||||
- For React components with explicit props, use a named props type (e.g. `type FooProps = {...}` with `function Foo(props: FooProps)`) rather than inline object annotations, especially with more than one field or with generics.
|
||||
|
||||
- `apps/web` owns TanStack Start routes, Vite config, PWA setup, oRPC browser client wiring, web features, and the resume builder UI.
|
||||
- `apps/server` owns the production Hono app, route composition, auth/RPC/MCP/OpenAPI handlers, static uploads, schema JSON, web-dist fallback serving, and startup checks.
|
||||
- `packages/api` contains oRPC routers, DTOs, rate limiting, and feature-owned API modules under `packages/api/src/features/*`. The router export at `@reactive-resume/api/routers` aggregates those feature routers for `/api/rpc`.
|
||||
- `packages/auth` contains Better Auth config, auth helper functions, and exported auth types. The server auth adapter in `apps/server/src/http/auth.ts` delegates to `auth.handler`.
|
||||
- `packages/db` contains the Drizzle client and schema. Migration files live at the repo root in `migrations/`.
|
||||
- `packages/env` defines server environment validation and auto-loads the root `.env` for app/server code.
|
||||
- `packages/schema` contains Zod schemas and typed resume/page/template models.
|
||||
- `packages/pdf` contains the React PDF document, font registration, shared template primitives, template implementations, and browser/server PDF generation adapters. PDF.js viewer UI stays in `apps/web`.
|
||||
- `packages/resume` contains pure resume-domain behavior such as JSON Patch helpers and social-network icon mapping.
|
||||
- `packages/docx` contains DOCX export generation.
|
||||
- `packages/mcp` contains MCP tools, prompts, resources, server-card generation, and tool metadata.
|
||||
- `packages/ui` contains shared Base UI/shadcn-style components and hooks.
|
||||
- `packages/fonts`, `packages/email`, `packages/import`, `packages/ai`, `packages/utils`, and `packages/config` provide focused support surfaces. Prefer their existing exports over adding cross-package shortcuts.
|
||||
- Development-only scripts live in `tooling/`, not under `packages/`, so packages only contain code bundled by the app/runtime.
|
||||
## Package boundaries
|
||||
|
||||
### Web app conventions
|
||||
`pnpm exec turbo boundaries` is the executable check. Rules:
|
||||
|
||||
- Routes are file-based under `apps/web/src/routes`. Do not hand-edit `apps/web/src/routeTree.gen.ts`; it is generated by TanStack Router tooling.
|
||||
- Server-owned HTTP behavior lives in `apps/server/src/{http,rpc,mcp,openapi,static,startup}`. Keep API/RPC/auth/MCP/static route wiring in `apps/server`, not in web routes.
|
||||
- `apps/web/src/router.tsx` initializes router context with `queryClient`, `orpc`, `theme`, `locale`, `session`, and `flags`. Reuse route context where possible instead of refetching these concerns ad hoc.
|
||||
- The builder shell lives under `apps/web/src/routes/builder/$resumeId`. The nested preview route is client-only (`ssr: false`), while the public resume route `apps/web/src/routes/$username/$slug.tsx` uses `ssr: "data-only"`.
|
||||
- Browser-only resume preview code lives under `apps/web/src/features/resume/preview`, and public resume PDF viewer code lives under `apps/web/src/features/resume/public`. Keep PDF.js/canvas/browser APIs out of SSR paths and out of `packages/pdf`.
|
||||
- The isomorphic oRPC client is in `apps/web/src/libs/orpc/client.ts`; server calls use an in-process router client and browser calls use `/api/rpc` with credentials included.
|
||||
- For React components with explicit props, prefer a named TypeScript props type over inline object annotations in the function signature, especially once the props include more than one field or generics. For example:
|
||||
- Workspace deps go through package names and export maps. Never import another workspace's `src` tree via repo paths, `@reactive-resume/*/src/*`, or TS path aliases.
|
||||
- Workspace `turbo.json` files declare coarse tags: `app:web`, `app:server`, `runtime:server` (server-only packages: API/auth/db/env/email/MCP), `runtime:browser` (browser-only shared UI), `runtime:universal` (environment-neutral domain packages), plus `role:domain|infra|adapter|api|rendering|tooling` for intent.
|
||||
- Runtime-specific code lives behind explicit export subpaths (`@reactive-resume/pdf/browser`, `@reactive-resume/pdf/server`, `@reactive-resume/env/server`). Keep root exports environment-neutral unless the package is intentionally server-only.
|
||||
- Wildcard exports are allowed only for leaf libraries with an intentionally file-like surface — currently `@reactive-resume/ui/components/*`, `@reactive-resume/ui/hooks/*`, and schema resume model files. Prefer explicit exports for packages owning runtime behavior.
|
||||
- Prefer `protectedProcedure` from `packages/api/src/context.ts` for authenticated procedures. Expose only intentional public surfaces through `packages/api/package.json`.
|
||||
- Shared PDF section filtering: `packages/pdf/src/templates/shared/filtering.ts`. Template-specific visual exceptions stay in the owning template directory unless multiple templates need the behavior. `packages/pdf/src/hooks/use-register-fonts.ts` owns font registration, standard PDF fonts, CJK fallback stacks, and global hyphenation.
|
||||
|
||||
```ts
|
||||
type IntentSelectFieldProps<TValue extends string> = {
|
||||
label: string;
|
||||
id: string;
|
||||
value: TValue | undefined;
|
||||
options: readonly ComboboxOption<TValue>[];
|
||||
onChange: (value: TValue | undefined) => void;
|
||||
};
|
||||
Multi-place changes:
|
||||
|
||||
function IntentSelectField<TValue extends string>(props: IntentSelectFieldProps<TValue>) {
|
||||
// ...
|
||||
}
|
||||
```
|
||||
- **Resume data shape**: `packages/schema/src/resume/*` first, then API DTOs, importers, PDF rendering, and web forms consuming it.
|
||||
- **New template**: `packages/schema/src/templates.ts`, `packages/pdf/src/templates/index.ts`, source under `packages/pdf/src/templates/<name>/`, and previews under `apps/web/public/templates/{jpg,pdf}`.
|
||||
- **New DB column/table**: `packages/db/src/schema/*`, then `dotenvx run -f .env.local -- pnpm db:generate`.
|
||||
- **New env var**: `packages/env/src/server.ts` **and** the `globalEnv` array in `turbo.json`. Turborepo 2.x strict env mode filters out unlisted vars, so the variable will be `undefined` in child processes at runtime even when correctly set in the OS/container environment.
|
||||
|
||||
### Package and feature boundaries
|
||||
## Environment and database
|
||||
|
||||
- Workspace dependencies must go through package names and package export maps. Do not import another workspace's `src` tree through repository paths, `@reactive-resume/*/src/*`, or TypeScript path aliases.
|
||||
- `turbo boundaries` is the executable package-boundary check. Workspace-level `turbo.json` files declare coarse tags:
|
||||
- `app:web` for the TanStack Start app.
|
||||
- `app:server` and `runtime:server` for the Node/Hono process.
|
||||
- `runtime:server` for server-only packages such as API/auth/db/env/email/MCP.
|
||||
- `runtime:browser` for browser-only shared UI.
|
||||
- `runtime:universal` for environment-neutral domain packages.
|
||||
- `role:domain`, `role:infra`, `role:adapter`, `role:api`, `role:rendering`, and `role:tooling` for package intent.
|
||||
- Browser/server runtime-specific code should live behind explicit export subpaths such as `@reactive-resume/pdf/browser`, `@reactive-resume/pdf/server`, or `@reactive-resume/env/server`. Keep root exports environment-neutral unless the package is intentionally server-only.
|
||||
- Wildcard exports are allowed only for leaf libraries whose public surface is intentionally file-like, currently `@reactive-resume/ui/components/*`, `@reactive-resume/ui/hooks/*`, and schema resume model files. Prefer explicit exports for packages that own runtime behavior.
|
||||
- Add new API procedures and business logic inside the owning `packages/api/src/features/*` module. Keep route wiring, DTO usage, helpers, and services colocated by feature/capability, then expose only intentional public surfaces through `packages/api/package.json`. Prefer `protectedProcedure` from `packages/api/src/context.ts` for authenticated procedures.
|
||||
- Add database columns/tables in `packages/db/src/schema/*`, then generate root-level migrations with `dotenvx run -f .env.local -- pnpm db:generate`.
|
||||
- Add or change resume data shape in `packages/schema/src/resume/*` first, then update API DTOs, importers, PDF rendering, and web forms that consume that shape.
|
||||
- Add or rename templates in all relevant places: `packages/schema/src/templates.ts`, `packages/pdf/src/templates/index.ts`, template source under `packages/pdf/src/templates/<name>/`, and static previews under `apps/web/public/templates/{jpg,pdf}`.
|
||||
- Resume JSON Patch behavior belongs in `@reactive-resume/resume/patch`; do not put resume-domain helpers in `@reactive-resume/utils`.
|
||||
- DOCX export behavior belongs in `@reactive-resume/docx`; do not put DOCX builders in `@reactive-resume/utils`.
|
||||
- Shared PDF section filtering lives in `packages/pdf/src/templates/shared/filtering.ts`. Keep template-specific visual exceptions in the owning template directory unless multiple templates need the same behavior.
|
||||
- `packages/pdf/src/hooks/use-register-fonts.ts` owns React PDF font registration, standard PDF font handling, CJK fallback stacks, and global hyphenation behavior.
|
||||
- PDF generation helpers live behind `@reactive-resume/pdf/browser` and `@reactive-resume/pdf/server`; locale-specific section-title resolution stays in the caller.
|
||||
- MCP implementation belongs in `@reactive-resume/mcp`; app packages must not import MCP implementation from another app's source tree.
|
||||
- `packages/utils` has narrowly exported helpers. If another package needs a utility, add an explicit export path instead of importing private files.
|
||||
Copy `.env.example` to `.env.local`. Three required vars: `APP_URL` (default `http://localhost:3000`), `DATABASE_URL` (default `postgresql://postgres:postgres@localhost:5432/postgres`), `AUTH_SECRET` (any non-empty string).
|
||||
|
||||
Placement decision tree:
|
||||
- **S3/SeaweedFS optional.** If `S3_ACCESS_KEY_ID`, `S3_SECRET_ACCESS_KEY`, and `S3_BUCKET` are all set, the app uses S3-compatible storage. `.env.example` ships SeaweedFS defaults, so either start the `seaweedfs` compose service or comment those vars out to use local filesystem storage under `<workspace>/data`. `LOCAL_STORAGE_PATH` must be absolute when set.
|
||||
- **`REDIS_URL` and `ENCRYPTION_SECRET`** are optional for core resume flows but both required for saved AI providers and the authenticated `/agent` workspace. Host-run dev uses `REDIS_URL=redis://localhost:6379`; the container-run app uses `redis://redis:6379`.
|
||||
- **`drizzle-kit` (used by `pnpm db:migrate`) reads `DATABASE_URL` from `process.env` directly** — it does not auto-load `.env`. Run migration commands through `dotenvx`.
|
||||
- The production server auto-runs migrations at startup before serving traffic, so manual `pnpm db:migrate` is mainly for first setup, migration debugging, or applying migrations without starting the app.
|
||||
|
||||
1. If the change is a web route, route loader, or user-facing web workflow, start in `apps/web/src/routes` or `apps/web/src/features`.
|
||||
2. If the change is a server HTTP route/adapter, startup check, static handler, MCP transport, or OpenAPI/well-known handler, start in `apps/server/src`.
|
||||
3. If it is authenticated API behavior, put the contract and implementation in the owning `packages/api/src/features/*` module.
|
||||
4. If it is pure resume data behavior with no DB, HTTP, DOM, or PDF renderer dependency, put it in `packages/resume`.
|
||||
5. If it renders resume PDFs, put shared React PDF/template code in `packages/pdf`; put PDF.js viewer/canvas UI in `apps/web/src/features/resume`.
|
||||
6. If it creates DOCX exports, put it in `packages/docx`.
|
||||
7. If it exposes MCP tools/prompts/resources, put it in `packages/mcp`.
|
||||
8. If it is a generic UI primitive or hook, put it in `packages/ui`; if it is workflow-specific UI, keep it in the owning web feature.
|
||||
9. If it is a narrow cross-cutting helper, add an explicit `packages/utils` export only after checking that no domain package is a better owner.
|
||||
## Commands
|
||||
|
||||
### Database
|
||||
|
||||
PostgreSQL runs via Docker Compose:
|
||||
Prefix dev servers and migration commands with `dotenvx run -f .env.local --`. Tests, typechecks, linters, boundary checks, and `pnpm build` do not need it; if one fails on a missing env var, rerun it with the prefix.
|
||||
|
||||
```
|
||||
sudo docker compose -f compose.dev.yml up -d postgres
|
||||
sudo docker compose -f compose.dev.yml up -d postgres # DB only
|
||||
sudo docker compose -f compose.dev.yml up -d postgres redis seaweedfs seaweedfs_create_bucket # full infra
|
||||
dotenvx run -f .env.local -- pnpm dev # port 3000 (dev:web for web only)
|
||||
dotenvx run -f .env.local -- pnpm db:generate # db:migrate to apply
|
||||
pnpm check # Biome — WRITE-CAPABLE (--write --unsafe)
|
||||
pnpm test | pnpm typecheck | pnpm build | pnpm exec turbo boundaries
|
||||
```
|
||||
|
||||
The dev default connection string is `postgresql://postgres:postgres@localhost:5432/postgres`.
|
||||
Prefer package filters over repo-wide runs, e.g. `pnpm --filter web typecheck`, `pnpm --filter @reactive-resume/pdf test`. Vitest paths are package-relative under `pnpm --filter <package> test -- <path>`.
|
||||
|
||||
**Important**: `drizzle-kit` (used by `pnpm db:migrate`) reads `DATABASE_URL` from `process.env` directly — it does **not** auto-load the `.env` file. Run migration commands through `dotenvx`, for example `dotenvx run -f .env.local -- pnpm db:migrate`, so `DATABASE_URL` is present in the process environment.
|
||||
## Gotchas
|
||||
|
||||
The production server runs migrations during startup before serving traffic. Manual `pnpm db:migrate` is mainly for first setup, migration debugging, or applying migrations without starting the app.
|
||||
|
||||
### Environment
|
||||
|
||||
Copy `.env.example` to `.env.local`. The three required variables are:
|
||||
|
||||
- `APP_URL` (default `http://localhost:3000`)
|
||||
- `DATABASE_URL` (default `postgresql://postgres:postgres@localhost:5432/postgres`)
|
||||
- `AUTH_SECRET` (any non-empty string)
|
||||
|
||||
S3/SeaweedFS is optional. If `S3_ACCESS_KEY_ID`, `S3_SECRET_ACCESS_KEY`, and `S3_BUCKET` are all set, the app uses S3-compatible storage. The checked-in `.env.example` sets SeaweedFS defaults, so either start the `seaweedfs` compose service too or comment out those S3 vars to use local filesystem storage under `<workspace>/data`. `LOCAL_STORAGE_PATH` must be absolute when set.
|
||||
|
||||
`REDIS_URL` and `ENCRYPTION_SECRET` are optional for core resume flows, but both are required for saved AI providers and the authenticated `/agent` workspace. Start the `redis` compose service and set both vars in `.env.local` when working on those features. For host-run development, use `REDIS_URL=redis://localhost:6379`; the container-run app uses `REDIS_URL=redis://redis:6379`.
|
||||
|
||||
When running dev servers or migration commands, prefix the command with `dotenvx run -f .env.local --`. For example: `dotenvx run -f .env.local -- pnpm dev`. Tests, typechecks, linters, boundary checks, and `pnpm build` do not need this prefix by default. If one of those commands fails because a specific environment variable is required, rerun it with the `dotenvx run -f .env.local --` prefix.
|
||||
|
||||
### Common commands
|
||||
|
||||
| Task | Command |
|
||||
|------|---------|
|
||||
| Install deps | `pnpm install` |
|
||||
| Start Postgres only | `sudo docker compose -f compose.dev.yml up -d postgres` |
|
||||
| Start Postgres + SeaweedFS | `sudo docker compose -f compose.dev.yml up -d postgres seaweedfs seaweedfs_create_bucket` |
|
||||
| Start full dev infrastructure | `sudo docker compose -f compose.dev.yml up -d postgres redis seaweedfs seaweedfs_create_bucket` |
|
||||
| Generate migrations | `dotenvx run -f .env.local -- pnpm db:generate` |
|
||||
| Run migrations | `dotenvx run -f .env.local -- pnpm db:migrate` |
|
||||
| Dev server | `dotenvx run -f .env.local -- pnpm dev` (starts on port 3000) |
|
||||
| Web dev server only | `dotenvx run -f .env.local -- pnpm dev:web` |
|
||||
| Lint/format | `pnpm check` (Biome) |
|
||||
| Boundary check | `pnpm exec turbo boundaries` |
|
||||
| Tests | `pnpm test` (Vitest) |
|
||||
| Build | `pnpm build` |
|
||||
| Typecheck | `pnpm typecheck` |
|
||||
|
||||
For focused validation, prefer package filters before repo-wide commands, for example:
|
||||
|
||||
```
|
||||
pnpm --filter web typecheck
|
||||
pnpm --filter @reactive-resume/pdf test
|
||||
pnpm --filter @reactive-resume/api test
|
||||
pnpm exec turbo boundaries
|
||||
```
|
||||
|
||||
Vitest test paths are package-relative when running through `pnpm --filter <package> test -- <path>`.
|
||||
|
||||
### Gotchas
|
||||
|
||||
- The server startup path auto-runs migrations before serving traffic, so `pnpm db:migrate` is mainly needed for first-time setup, migration debugging, or applying migrations without starting the app.
|
||||
- Email sending requires SMTP config; without it, emails are logged to console. This is fine for dev — the app still functions, but email verification links appear in server logs.
|
||||
- The `lefthook.yml` pre-commit hook runs `biome check` on staged files. Run `pnpm check` before committing to avoid hook failures.
|
||||
- `pnpm check` is write-capable (`biome check --write --unsafe .`). Call that out when using it, and use narrower Biome commands if you need a non-mutating inspection.
|
||||
- Biome uses tabs, double quotes, line width 120, organized import groups, and sorted Tailwind classes for `clsx`, `cva`, and `cn`.
|
||||
- Most packages use `tsgo --noEmit` for typechecking and `vitest run --passWithNoTests` for tests.
|
||||
- There may be unrelated local edits in the worktree. Inspect `git status --short` first and avoid reverting files you did not touch.
|
||||
- **New env vars require a `turbo.json` entry.** Turborepo 2.x runs in strict env mode by default — it filters out env vars that are not listed in `globalEnv` (or task-level `env`/`passThroughEnv`). Any new environment variable added to `packages/env/src/server.ts` must also be added to the `globalEnv` array in `turbo.json`, or the variable will be `undefined` inside child processes at runtime even if it is correctly set in the OS/container environment.
|
||||
- Email sending needs SMTP config; without it emails are logged to console. Dev still works — verification links appear in server logs.
|
||||
- `lefthook.yml` pre-commit runs `biome check` on staged files. Run `pnpm check` before committing.
|
||||
- `pnpm check` is write-capable. Call that out when using it, and use narrower Biome commands for a non-mutating inspection.
|
||||
- Biome: tabs, double quotes, line width 120, organized import groups, sorted Tailwind classes for `clsx`, `cva`, `cn`.
|
||||
- Most packages typecheck with `tsgo --noEmit` and test with `vitest run --passWithNoTests`.
|
||||
- There may be unrelated local edits in the worktree. Check `git status --short` first; do not revert files you did not touch.
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
# Domain contexts
|
||||
|
||||
- [Resume](packages/resume/CONTEXT.md): authored resume content and presentation concepts shared by the builder and exporters.
|
||||
+2
-1
@@ -1,5 +1,6 @@
|
||||
# syntax=docker/dockerfile:1.7
|
||||
|
||||
# Base image only; pnpm self-manages to the `packageManager` version in package.json.
|
||||
ARG PNPM_VERSION=11.21.0
|
||||
ARG NODE_VERSION=24
|
||||
|
||||
@@ -47,7 +48,7 @@ LABEL org.opencontainers.image.description="A free and open-source resume builde
|
||||
LABEL org.opencontainers.image.vendor="Amruth Pillai"
|
||||
LABEL org.opencontainers.image.url="https://rxresu.me"
|
||||
LABEL org.opencontainers.image.documentation="https://docs.rxresu.me"
|
||||
LABEL org.opencontainers.image.source="https://github.com/amruthpillai/reactive-resume"
|
||||
LABEL org.opencontainers.image.source="https://github.com/reactive-resume/reactive-resume"
|
||||
|
||||
ENV NODE_ENV="production" \
|
||||
PORT=3000 \
|
||||
|
||||
+260
@@ -0,0 +1,260 @@
|
||||
# Glossary
|
||||
|
||||
What the recurring terms in Reactive Resume's interface actually mean.
|
||||
|
||||
This file exists because most of the interface is translated from short, standalone strings.
|
||||
A translator, human or machine, sees `Board` or `Resume` with no surrounding sentence, picks the
|
||||
most common English sense, and gets it wrong. Every entry below has been mistranslated that way
|
||||
in at least one shipped locale.
|
||||
|
||||
**If you are translating, read the term here before translating it.** When the English word has
|
||||
a common sense that is *not* the one used here, that wrong sense is listed explicitly.
|
||||
|
||||
Terms are grouped by the part of the product they belong to. Source references point at where the
|
||||
string is defined, so you can read the surrounding code when this file is not enough.
|
||||
|
||||
## Always left untranslated
|
||||
|
||||
Product and technology names stay in English (or in the locale's established transliteration, if
|
||||
the catalog already uses one consistently):
|
||||
|
||||
Reactive Resume, GitHub, Crowdin, Docker, PostgreSQL, Better Auth, TanStack, Microsoft Word,
|
||||
PDF, DOCX, JSON, CSV, API, MCP, oRPC, SSO, CSS, URL, JSON Resume.
|
||||
|
||||
AI provider names are brand names and stay in English: OpenAI, Anthropic Claude, Google
|
||||
Gemini, Vercel AI Gateway, OpenRouter, Mistral AI, Cohere, xAI Grok, Groq, DeepSeek, Together.ai,
|
||||
Fireworks, Cerebras, Perplexity, Ollama Cloud.
|
||||
|
||||
Template names are proper nouns and are never translated: Azurill, Bronzor, Chikorita, Ditgar,
|
||||
Ditto, Gengar, Glalie, Kakuna, Lapras, Leafish, Meowth, Onyx, Pikachu, Rhyhorn, Scizor.
|
||||
|
||||
## The document
|
||||
|
||||
**Resume** — the job-application document the app builds. Always a noun.
|
||||
Not the verb "to resume", "to continue", or "to restart". This is the single most common
|
||||
mistranslation in the catalogs: many locales render the standalone `Resume` label as the verb.
|
||||
In `application-form-sheet.tsx` the label marks the resume attached to a job application.
|
||||
Where a locale's normal word for this document is CV, use CV.
|
||||
|
||||
**Resumes** — plural of the above. A list of the user's documents.
|
||||
|
||||
**Cover letter** — the letter accompanying a resume. Stored as a resume section, not a separate
|
||||
document.
|
||||
|
||||
**Builder** — the editor where a resume is composed. A tool, not a construction worker or a
|
||||
person who builds.
|
||||
|
||||
**Template** — a visual design for a resume. Not a "model" in the machine-learning sense, and
|
||||
not a "sample" or "example" document. Beware in languages where the natural word for template
|
||||
is also the word for model: the app uses "model" separately, for AI models.
|
||||
|
||||
**Section** — one block of a resume, such as Experience or Education. Not a legal section or a
|
||||
document chapter.
|
||||
|
||||
**Item** — one entry inside a section, for example a single job or a single degree. Generic on
|
||||
purpose. Not "product", "article", or "column".
|
||||
|
||||
**Page** — one physical page of the rendered resume. Not a web page.
|
||||
|
||||
**Columns** — the column count of a resume layout. Not database or spreadsheet columns.
|
||||
|
||||
**Slug** — the URL-safe identifier in a resume's public address. Usually kept in English or
|
||||
transliterated; never translated as "snail".
|
||||
|
||||
### Resume section names
|
||||
|
||||
These are the built-in section presets, defined in `apps/web/src/libs/resume/section.tsx` and
|
||||
`apps/web/src/dialogs/resume/sections/custom.tsx`. Translate them the way a resume in the target
|
||||
language would label them:
|
||||
|
||||
**Basics** — name, contact details, and headline. Not "fundamentals" or "basic settings".
|
||||
|
||||
**Summary** — the short personal statement at the top of a resume. Not a summary of the app, and
|
||||
not an AI-generated abstract.
|
||||
|
||||
**Profiles** — links to the user's social and professional accounts (LinkedIn, GitHub). Plural.
|
||||
Distinct from **Profile**, below, which is the user's own account page. These two are different
|
||||
things and several catalogs have collapsed them into one word.
|
||||
|
||||
**Volunteer** — volunteering experience. A noun naming a section, not the verb "to volunteer".
|
||||
|
||||
Also: Experience, Education, Skills, Languages, Awards, Certifications, Interests, Projects,
|
||||
Publications, References, Custom.
|
||||
|
||||
## The application tracker
|
||||
|
||||
**Applications** — job applications the user has submitted. Not software applications, apps, or
|
||||
programs. Frequently mistranslated as the software sense.
|
||||
|
||||
**Board** — the kanban board view of applications, arranged in columns by stage. Not a board of
|
||||
directors, a committee, a plank, or a noticeboard.
|
||||
|
||||
**Stage** — where an application sits in the pipeline (applied, interviewing, offer, rejected).
|
||||
Not a theatre stage or a phase of construction.
|
||||
|
||||
**Source** — where the user found the job listing (a job board, a referral, a company site).
|
||||
Singular, and specific to one application. Not a source code file and not a data source.
|
||||
|
||||
**Pipeline** — the sequence of stages an application moves through. A recruiting funnel, not a
|
||||
physical pipe, duct, conduit, or oil pipeline. Seven locales translated it as plumbing.
|
||||
|
||||
**Table** — the table view of applications, one of the view options next to Board and List. Not a
|
||||
piece of furniture.
|
||||
|
||||
**Archive** — a verb in this context: to move an application out of the active list. Not the
|
||||
noun "an archive". It is a menu action and pairs with **Unarchive**; almost every locale had the
|
||||
noun here.
|
||||
|
||||
**Applied on** — the date the user submitted the application. "Applied" is the job-application
|
||||
verb, not "applied a substance onto a surface" and not "applied a patch".
|
||||
|
||||
**Mark rejected / Mark as…** — "Mark" is the verb, to set a status. It is not the given name Mark.
|
||||
|
||||
**Match score** — how well a resume matches a job description. A degree of correspondence, not a
|
||||
sporting fixture.
|
||||
|
||||
**Fit**, as in "Score my fit" or "Strong fit" — how well the user suits the role. Not physical
|
||||
fitness, and not how clothing fits.
|
||||
|
||||
**A stretch** — a role the user is unlikely to get, an ambitious application. Not a stretching
|
||||
exercise.
|
||||
|
||||
**Notes** — the user's free-text notes on an application. Compare **Note** in the ATS checker,
|
||||
which is not the same thing.
|
||||
|
||||
**Timeline** — the dated history of one application.
|
||||
|
||||
## The AI agent
|
||||
|
||||
**Threads** — conversations with the AI agent. The chat sense, as in a message thread. Not
|
||||
sewing thread, not string, not yarn, and not a CPU thread. Several locales use the textile word.
|
||||
|
||||
**Provider** — a third-party AI service the user configures, such as OpenAI or Anthropic. A
|
||||
service supplier. Not a healthcare provider, and not a person who provides for a family.
|
||||
|
||||
**Model** — the specific AI model chosen from a provider, such as Claude Sonnet or GPT. Not a
|
||||
**Template** (several locales used the same word for both), not a device model or product
|
||||
variant, and not a "style" or "pattern".
|
||||
|
||||
**Working resume** — the resume a thread is currently editing. "Working" describes the draft
|
||||
being worked on, not the user's employment. It is not their work history, not a "job resume",
|
||||
and not a *functional résumé*, which is a real and different résumé format.
|
||||
|
||||
**Tailor** — a verb: to adapt a resume to a specific job description. Nothing to do with
|
||||
dressmaking or sewing.
|
||||
|
||||
**Sources** — the citations the agent attaches to an answer. Plural, and distinct from **Source**
|
||||
in the application tracker above.
|
||||
|
||||
**Draft** — a working copy of a resume the agent edits. A noun.
|
||||
|
||||
**Patch** — a set of JSON Patch operations the agent proposes. Kept in English in most catalogs.
|
||||
Not a cloth patch, a scrap of fabric, an adhesive bandage, or a connector.
|
||||
|
||||
## The ATS checker
|
||||
|
||||
**ATS** — applicant tracking system: recruiting software that parses resumes. Spell it out on
|
||||
first use in languages where the acronym is unfamiliar. It is not a drug test, a transmission,
|
||||
or any other expansion of the letters; at least one catalog translated `ATS Check` as a test for
|
||||
amphetamines.
|
||||
|
||||
**Readability, Layout, Sections, Contact details, Dates, Writing** — the six check categories, in
|
||||
`apps/web/src/features/ats-checker/messages.ts`. "Layout" here means page geometry and reading
|
||||
order, not the builder's layout settings.
|
||||
|
||||
**Blocker, Warning, Tip** — the three severity levels of a finding.
|
||||
|
||||
**Note** — the label for an informational finding, in
|
||||
`apps/web/src/routes/builder/$resumeId/-sidebar/right/sections/ats-check.tsx`. A severity label,
|
||||
not a written note. Unrelated to **Notes** in the application tracker.
|
||||
|
||||
**Parse / parsing** — software reading text out of the PDF.
|
||||
|
||||
## Account and security
|
||||
|
||||
**Passkey / Passkeys** — a WebAuthn credential that replaces a password, stored on the user's
|
||||
device or security key. **It is not a password.** Many catalogs translate it with their word for
|
||||
"password", which is actively confusing: both appear together on the security settings page, so
|
||||
the user cannot tell which credential a message refers to. If the target language has no
|
||||
established term, keep "passkey" in English rather than reusing the word for password.
|
||||
|
||||
**Password** — the ordinary secret. Distinct from the above, always.
|
||||
|
||||
**Two-factor authentication (2FA)** — a second verification step at sign-in.
|
||||
|
||||
**Backup codes** — single-use codes for signing in when the second factor is unavailable.
|
||||
|
||||
**API key** — a token for programmatic access. **Key** on its own, in `ai-section.tsx`, means the
|
||||
AI provider's API key. Not a physical door key, not a keyboard key, and not the adjective "key"
|
||||
in the sense of crucial or main.
|
||||
|
||||
**Session** — an active sign-in on one device.
|
||||
|
||||
**Sign in / Sign out** — the app's chosen verbs. Prefer the locale's equivalent of "sign in"
|
||||
over "log in" where both exist, and keep whichever the catalog already uses consistently.
|
||||
|
||||
## Navigation and app shell
|
||||
|
||||
**Dashboard** — the main page after signing in, listing resumes and applications. Not a vehicle
|
||||
dashboard, an instrument panel, or a control panel in the machinery sense.
|
||||
|
||||
**Profile** — the user's own account settings page. Distinct from **Profiles**, the resume
|
||||
section, above.
|
||||
|
||||
**Lock / Unlock** — verbs: to make a resume read-only, and to release it.
|
||||
|
||||
**Tags** — user-defined labels for organizing resumes and applications.
|
||||
|
||||
**Custom** — in `color-picker.tsx`, a user-chosen color as opposed to a preset. An adjective.
|
||||
|
||||
**Public URL** — the shareable address of a published resume. Use one term consistently; the
|
||||
English strings say "public URL" rather than "public link".
|
||||
|
||||
## Verbs that read as adjectives or nouns
|
||||
|
||||
Button labels and `aria-label` strings are usually **imperative verbs**: they say what the
|
||||
control does. Read as a noun or an adjective, they turn into nonsense. This is the most common
|
||||
error in the catalogs after the ambiguous nouns above.
|
||||
|
||||
**Open** — the verb. `Open AI agent` means *open the AI agent panel*; it does not describe an
|
||||
agent that is "open", and it is **not a reference to OpenAI, the company**. Around forty-five of
|
||||
the fifty-three catalogs got this wrong, split between "an open AI agent" and a transliteration
|
||||
of *OpenAI*. The same applies to `Open in builder`.
|
||||
|
||||
**Close** — likewise the verb, as in `Close AI assistant`. Not "an assistant for closing things",
|
||||
and not the adjective "close/nearby".
|
||||
|
||||
The app names two different surfaces here, and both strings are real: **AI agent** is the
|
||||
full workspace at `/agent`, opened from the builder dock (`Open AI agent`), while **AI assistant**
|
||||
is the panel that slides out inside the builder (`Open AI assistant`, `Close AI assistant`).
|
||||
Translate them as two distinct names, the way the English does.
|
||||
|
||||
**Clear** — the verb, to empty a field or remove filters. Not the adjective "transparent",
|
||||
"obvious", or "clear-cut".
|
||||
|
||||
**Lock / Unlock** — verbs. `Unlock` is specifically the opposite of `Lock`, not a synonym for
|
||||
`Open`; several catalogs collapsed the two and produced two identical menu items.
|
||||
|
||||
**Archive / Unarchive**, **Mark**, **Tailor**, **Duplicate**, **Import**, **Export**, **Share**,
|
||||
**Star** — all verbs when they appear as a control label. Check the `#:` source reference if you
|
||||
are unsure whether a given string is a button or a heading.
|
||||
|
||||
## Message syntax
|
||||
|
||||
These are not words to translate, and breaking them breaks the interface:
|
||||
|
||||
- `{name}`, `{count}`, `{email}`, `{MAX_IMPORT}`, `{overflow}` — value placeholders. Keep the
|
||||
spelling exactly, keep every one that appears in the source, and add none.
|
||||
- `{count, plural, one {# item} other {# items}}` — ICU plurals. Translate only the text inside
|
||||
the inner braces, keep the `#`, and use the plural categories your language actually needs
|
||||
(Arabic and the Slavic languages legitimately have more than English).
|
||||
- `<0>…</0>`, `<1>…</1>`, `<0/>` — indexes pointing at interface elements such as links and bold
|
||||
spans. Keep every index and keep the pairs matched. You may move a tag inside the sentence for
|
||||
word order, as long as it still wraps the corresponding words.
|
||||
|
||||
A missing or renamed placeholder is a runtime error, not a style problem.
|
||||
|
||||
## Adding to this file
|
||||
|
||||
When a translator asks what a term means, the answer belongs here. When you add a term, say what
|
||||
it means in this app and, if the English word is ambiguous, say plainly which sense is wrong.
|
||||
@@ -1,3 +1,9 @@
|
||||
> [!IMPORTANT]
|
||||
> **Repository moved:** Reactive Resume now lives at **[`reactive-resume/reactive-resume`](https://github.com/reactive-resume/reactive-resume)** on GitHub.
|
||||
> **Docker Hub stays at `amruthpillai/reactive-resume`.** GHCR builds now publish to `ghcr.io/reactive-resume/reactive-resume`.
|
||||
> Verified image tags: `latest`, `v5`, `v5.3`, and `v5.3.0` (AMD64 and ARM64). The current version was rebuilt and production redeployed for this rename; no new GitHub release or version bump was made. See [migration details](https://github.com/reactive-resume/reactive-resume/issues/3503).
|
||||
> GitHub Sponsors and Open Collective funding links remain unchanged.
|
||||
|
||||
<div align="center">
|
||||
<a href="https://rxresu.me">
|
||||
<img src="apps/web/public/opengraph/banner.jpg" alt="Reactive Resume" />
|
||||
@@ -5,7 +11,7 @@
|
||||
|
||||
<h1>Reactive Resume</h1>
|
||||
|
||||
<p>Reactive Resume is a free and open-source resume builder that simplifies the process of creating, updating, and sharing your resume.</p>
|
||||
<p>Reactive Resume is a free and open-source resume builder that makes it easy to create, update, and share your resume.</p>
|
||||
|
||||
<p>
|
||||
<a href="https://rxresu.me"><strong>Get Started</strong></a>
|
||||
@@ -14,9 +20,9 @@
|
||||
</p>
|
||||
|
||||
<p>
|
||||
<img src="https://img.shields.io/github/package-json/v/amruthpillai/reactive-resume?style=flat-square" alt="Reactive Resume Version">
|
||||
<img src="https://img.shields.io/github/stars/amruthpillai/Reactive-Resume?style=flat-square" alt="GitHub Stars">
|
||||
<img src="https://img.shields.io/github/license/amruthpillai/Reactive-Resume?style=flat-square" alt="License" />
|
||||
<img src="https://img.shields.io/github/package-json/v/reactive-resume/reactive-resume?style=flat-square" alt="Reactive Resume Version">
|
||||
<img src="https://img.shields.io/github/stars/reactive-resume/reactive-resume?style=flat-square" alt="GitHub Stars">
|
||||
<img src="https://img.shields.io/github/license/reactive-resume/reactive-resume?style=flat-square" alt="License" />
|
||||
<img src="https://img.shields.io/docker/pulls/amruthpillai/reactive-resume?style=flat-square" alt="Docker Pulls" />
|
||||
<a href="https://discord.gg/aSyA5ZSxpb"><img src="https://img.shields.io/discord/1173518977851473940?style=flat-square&label=discord" alt="Discord" /></a>
|
||||
<a href="https://crowdin.com/project/reactive-resume"><img src="https://badges.crowdin.net/reactive-resume/localized.svg?style=flat-square" alt="Crowdin" /></a>
|
||||
@@ -27,38 +33,24 @@
|
||||
|
||||
---
|
||||
|
||||
Reactive Resume makes building resumes straightforward. Pick a template, fill in your details, and export to PDF—no account required for basic use. For those who want more control, the entire application can be self-hosted on your own infrastructure.
|
||||
Pick a template, fill in your details, and export to PDF. Basic use needs no account. If you want more control, you can run the whole application on your own infrastructure.
|
||||
|
||||
Built with privacy as a core principle, Reactive Resume gives you complete ownership of your data. The codebase is fully open-source under the MIT license, with no tracking, no ads, and no hidden costs.
|
||||
|
||||
## Sponsors
|
||||
|
||||
Reactive Resume stays free, open-source, and independent because companies choose to support the work behind it. Thank you to every sponsor who helps fund hosting, maintenance, and continued development for the community.
|
||||
|
||||
<p>
|
||||
<a href="https://www.atlascloud.ai/?utm_source=github&utm_medium=link&utm_campaign=reactive-resume">
|
||||
<img src="apps/web/public/sponsors/atlas-cloud-logo-white.svg" alt="Atlas Cloud" width="320" />
|
||||
</a>
|
||||
</p>
|
||||
|
||||
[Atlas Cloud](https://www.atlascloud.ai/?utm_source=github&utm_medium=link&utm_campaign=reactive-resume) supports Reactive Resume as a project sponsor. Atlas Cloud provides a unified AI platform for developers, with access to hundreds of models for chat, image generation, video generation, media processing, and GPU cloud workloads through one API key, one endpoint, and one billing account.
|
||||
|
||||
If your company would like to sponsor Reactive Resume, email [hello@amruthpillai.com](mailto:hello@amruthpillai.com).
|
||||
You own your data. The codebase is open source under the MIT license, with no tracking, no ads, and no hidden costs.
|
||||
|
||||
## Features
|
||||
|
||||
**Resume Building**
|
||||
|
||||
- Real-time preview as you type
|
||||
- Live preview as you type
|
||||
- Multiple export formats (PDF, JSON, DOCX)
|
||||
- Drag-and-drop section ordering
|
||||
- Custom sections for any content type
|
||||
- Rich text editor with formatting support
|
||||
- Rich text editor
|
||||
|
||||
**Templates**
|
||||
|
||||
- Professionally designed templates
|
||||
- A4 and Letter size support
|
||||
- 15 templates to choose from
|
||||
- A4 and Letter page sizes
|
||||
- Customizable colors, fonts, and spacing
|
||||
- Structured Style Rules for section and text styling
|
||||
|
||||
@@ -75,7 +67,7 @@ If your company would like to sponsor Reactive Resume, email [hello@amruthpillai
|
||||
- Multi-language support
|
||||
- Share resumes via unique links
|
||||
- Import from JSON Resume format
|
||||
- Dark mode support
|
||||
- Dark mode
|
||||
- Passkey and two-factor authentication
|
||||
|
||||
## Templates
|
||||
@@ -157,7 +149,7 @@ The quickest way to run Reactive Resume locally:
|
||||
|
||||
```bash
|
||||
# Clone the repository
|
||||
git clone --depth=1 https://github.com/amruthpillai/reactive-resume.git
|
||||
git clone --depth=1 https://github.com/reactive-resume/reactive-resume.git reactive-resume
|
||||
cd reactive-resume
|
||||
|
||||
# Start all services
|
||||
@@ -167,8 +159,6 @@ docker compose up -d
|
||||
open http://localhost:3000
|
||||
```
|
||||
|
||||
[](https://app.ona.com/#https://github.com/amruthpillai/reactive-resume)
|
||||
|
||||
For detailed setup instructions, environment configuration, and self-hosting guides, see the [documentation](https://docs.rxresu.me).
|
||||
|
||||
## Tech Stack
|
||||
@@ -187,14 +177,14 @@ For detailed setup instructions, environment configuration, and self-hosting gui
|
||||
|
||||
## Documentation
|
||||
|
||||
Comprehensive guides are available at [docs.rxresu.me](https://docs.rxresu.me):
|
||||
The full documentation lives at [docs.rxresu.me](https://docs.rxresu.me):
|
||||
|
||||
| Guide | Description |
|
||||
| ---------------------------------------------------------------------------- | -------------------------------- |
|
||||
| [Getting Started](https://docs.rxresu.me/getting-started) | First-time setup and basic usage |
|
||||
| [Self-Hosting](https://docs.rxresu.me/self-hosting/docker) | Deploy on your own server |
|
||||
| [Development Setup](https://docs.rxresu.me/contributing/development) | Local development environment |
|
||||
| [Project Architecture](https://docs.rxresu.me/contributing/architecture) | Codebase structure and patterns |
|
||||
| [Development setup](https://docs.rxresu.me/contributing/development) | Local development environment |
|
||||
| [Project architecture](https://docs.rxresu.me/contributing/architecture) | Codebase structure and patterns |
|
||||
| [Exporting Your Resume](https://docs.rxresu.me/guides/exporting-your-resume) | PDF and JSON export options |
|
||||
|
||||
## Self-Hosting
|
||||
@@ -204,7 +194,7 @@ Reactive Resume can be self-hosted using Docker. The stack includes:
|
||||
- **PostgreSQL** — Database for storing user data and resumes
|
||||
- **SeaweedFS** (optional) — S3-compatible storage for file uploads
|
||||
|
||||
> **From v5.1.0 onwards** — PDF generation now runs entirely client-side via `@react-pdf/renderer`. New deployments no longer require Browserless, Chromium, or any external print service as a dependency. The `PRINTER_*` and `BROWSERLESS_*` environment variables are no longer read and can be removed from your `.env`.
|
||||
> **From v5.1.0 onwards** — PDF generation runs entirely client-side via `@react-pdf/renderer`. New deployments no longer need Browserless, Chromium, or any external print service. The `PRINTER_*` and `BROWSERLESS_*` environment variables are no longer read and can be removed from your `.env`.
|
||||
|
||||
Pull the latest image from Docker Hub or GitHub Container Registry:
|
||||
|
||||
@@ -213,14 +203,14 @@ Pull the latest image from Docker Hub or GitHub Container Registry:
|
||||
docker pull amruthpillai/reactive-resume:latest
|
||||
|
||||
# GitHub Container Registry
|
||||
docker pull ghcr.io/amruthpillai/reactive-resume:latest
|
||||
docker pull ghcr.io/reactive-resume/reactive-resume:latest
|
||||
```
|
||||
|
||||
See the [self-hosting guide](https://docs.rxresu.me/self-hosting/docker) for complete instructions.
|
||||
|
||||
## Support
|
||||
|
||||
Reactive Resume is and always will be free and open-source. If it has helped you land a job or saved you time, please consider supporting continued development:
|
||||
Reactive Resume is and always will be free and open source. If it has helped you land a job or saved you time, please consider supporting continued development:
|
||||
|
||||
<p>
|
||||
<a href="https://github.com/sponsors/AmruthPillai">
|
||||
@@ -235,23 +225,27 @@ Other ways to support:
|
||||
|
||||
- Star this repository
|
||||
- Report reproducible bugs and suggest actionable features
|
||||
- Help other users in [GitHub Discussions](https://github.com/amruthpillai/reactive-resume/discussions/categories/q-a)
|
||||
- Help other users in [GitHub Discussions](https://github.com/reactive-resume/reactive-resume/discussions/categories/q-a)
|
||||
- Improve documentation
|
||||
- Help with translations
|
||||
|
||||
<a href="https://blacksmith.sh/">
|
||||
<img width="368" height="126" alt="powered-by-blacksmith" src="https://github.com/user-attachments/assets/3e95d11b-4579-4082-8d0c-6b574f925625" />
|
||||
</a>
|
||||
|
||||
## Star History
|
||||
|
||||
<a href="https://www.star-history.com/?repos=amruthpillai%2Freactive-resume&type=date&legend=top-left">
|
||||
<a href="https://www.star-history.com/?repos=reactive-resume%2Freactive-resume&type=date&legend=top-left">
|
||||
<picture>
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/chart?repos=amruthpillai/reactive-resume&type=date&theme=dark&legend=top-left&sealed_token=QmaOn4Ech499R6kpQe8ONn911UjGUaJfQBT0MXlQLU9hTo-Ie7lTxIILWbBvmtzDGHk7ziWKN_N5iM5mgP8widn_FGHd9-PHNokPtSji8XLgbFpqatgyqIDPnOys-IhO40W3J0HeH07FL-Q8Bq6ArRk3LDtJDwjh4m0ya-2L59ULb7BaqxkSDuCytkCr" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/chart?repos=amruthpillai/reactive-resume&type=date&legend=top-left&sealed_token=QmaOn4Ech499R6kpQe8ONn911UjGUaJfQBT0MXlQLU9hTo-Ie7lTxIILWbBvmtzDGHk7ziWKN_N5iM5mgP8widn_FGHd9-PHNokPtSji8XLgbFpqatgyqIDPnOys-IhO40W3J0HeH07FL-Q8Bq6ArRk3LDtJDwjh4m0ya-2L59ULb7BaqxkSDuCytkCr" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/chart?repos=amruthpillai/reactive-resume&type=date&legend=top-left&sealed_token=QmaOn4Ech499R6kpQe8ONn911UjGUaJfQBT0MXlQLU9hTo-Ie7lTxIILWbBvmtzDGHk7ziWKN_N5iM5mgP8widn_FGHd9-PHNokPtSji8XLgbFpqatgyqIDPnOys-IhO40W3J0HeH07FL-Q8Bq6ArRk3LDtJDwjh4m0ya-2L59ULb7BaqxkSDuCytkCr" />
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/chart?repos=reactive-resume/reactive-resume&type=date&theme=dark&legend=top-left&sealed_token=QmaOn4Ech499R6kpQe8ONn911UjGUaJfQBT0MXlQLU9hTo-Ie7lTxIILWbBvmtzDGHk7ziWKN_N5iM5mgP8widn_FGHd9-PHNokPtSji8XLgbFpqatgyqIDPnOys-IhO40W3J0HeH07FL-Q8Bq6ArRk3LDtJDwjh4m0ya-2L59ULb7BaqxkSDuCytkCr" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/chart?repos=reactive-resume/reactive-resume&type=date&legend=top-left&sealed_token=QmaOn4Ech499R6kpQe8ONn911UjGUaJfQBT0MXlQLU9hTo-Ie7lTxIILWbBvmtzDGHk7ziWKN_N5iM5mgP8widn_FGHd9-PHNokPtSji8XLgbFpqatgyqIDPnOys-IhO40W3J0HeH07FL-Q8Bq6ArRk3LDtJDwjh4m0ya-2L59ULb7BaqxkSDuCytkCr" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/chart?repos=reactive-resume/reactive-resume&type=date&legend=top-left&sealed_token=QmaOn4Ech499R6kpQe8ONn911UjGUaJfQBT0MXlQLU9hTo-Ie7lTxIILWbBvmtzDGHk7ziWKN_N5iM5mgP8widn_FGHd9-PHNokPtSji8XLgbFpqatgyqIDPnOys-IhO40W3J0HeH07FL-Q8Bq6ArRk3LDtJDwjh4m0ya-2L59ULb7BaqxkSDuCytkCr" />
|
||||
</picture>
|
||||
</a>
|
||||
|
||||
## Contributing
|
||||
|
||||
Contributions make open-source thrive. Whether fixing a typo or adding a feature, all contributions are welcome.
|
||||
Every contribution helps, whether it is a typo fix or a new feature.
|
||||
|
||||
1. Fork the repository
|
||||
2. Create a feature branch (`git checkout -b feature/amazing-feature`)
|
||||
@@ -259,9 +253,9 @@ Contributions make open-source thrive. Whether fixing a typo or adding a feature
|
||||
4. Push to the branch (`git push origin feature/amazing-feature`)
|
||||
5. Open a Pull Request
|
||||
|
||||
See the [development setup guide](https://docs.rxresu.me/contributing/development) for detailed instructions on how to set up the project locally.
|
||||
See the [development setup guide](https://docs.rxresu.me/contributing/development) for how to run the project locally.
|
||||
|
||||
Maintainers review the [`status: needs triage` queue](https://github.com/amruthpillai/reactive-resume/issues?q=is%3Aissue+is%3Aopen+label%3A%22status%3A+needs+triage%22)
|
||||
Maintainers review the [`status: needs triage` queue](https://github.com/reactive-resume/reactive-resume/issues?q=is%3Aissue+is%3Aopen+label%3A%22status%3A+needs+triage%22)
|
||||
weekly. Triaged bugs become `status: confirmed`; feature proposals become `status: accepted`; reports that need details become
|
||||
`status: needs info`.
|
||||
|
||||
|
||||
+45
-42
@@ -18,35 +18,36 @@
|
||||
"#react-pdf-renderer": "@react-pdf/renderer"
|
||||
},
|
||||
"dependencies": {
|
||||
"@ai-sdk/anthropic": "^4.0.44",
|
||||
"@ai-sdk/cerebras": "^3.0.39",
|
||||
"@ai-sdk/cohere": "^4.0.33",
|
||||
"@ai-sdk/deepseek": "^3.0.35",
|
||||
"@ai-sdk/fireworks": "^3.0.42",
|
||||
"@ai-sdk/google": "^4.0.54",
|
||||
"@ai-sdk/groq": "^4.0.33",
|
||||
"@ai-sdk/mistral": "^4.0.35",
|
||||
"@ai-sdk/openai": "^4.0.50",
|
||||
"@ai-sdk/openai-compatible": "^3.0.39",
|
||||
"@ai-sdk/perplexity": "^4.0.34",
|
||||
"@ai-sdk/togetherai": "^3.0.40",
|
||||
"@ai-sdk/xai": "^4.0.47",
|
||||
"@aws-sdk/client-s3": "^3.1119.0",
|
||||
"@better-auth/api-key": "^1.7.2",
|
||||
"@better-auth/drizzle-adapter": "^1.7.2",
|
||||
"@better-auth/infra": "^0.4.3",
|
||||
"@better-auth/oauth-provider": "^1.7.2",
|
||||
"@better-auth/passkey": "^1.7.2",
|
||||
"@ai-sdk/anthropic": "^4.0.54",
|
||||
"@ai-sdk/cerebras": "^3.0.49",
|
||||
"@ai-sdk/cohere": "^4.0.42",
|
||||
"@ai-sdk/deepseek": "^3.0.45",
|
||||
"@ai-sdk/fireworks": "^3.0.52",
|
||||
"@ai-sdk/google": "^4.0.72",
|
||||
"@ai-sdk/groq": "^4.0.42",
|
||||
"@ai-sdk/mistral": "^4.0.44",
|
||||
"@ai-sdk/openai": "^4.0.67",
|
||||
"@ai-sdk/openai-compatible": "^3.0.49",
|
||||
"@ai-sdk/perplexity": "^4.0.44",
|
||||
"@ai-sdk/togetherai": "^3.0.50",
|
||||
"@ai-sdk/xai": "^5.0.0",
|
||||
"@aws-sdk/client-s3": "^3.1133.0",
|
||||
"@better-auth/api-key": "^1.7.5",
|
||||
"@better-auth/drizzle-adapter": "^1.7.5",
|
||||
"@better-auth/infra": "^0.4.9",
|
||||
"@better-auth/oauth-provider": "^1.7.5",
|
||||
"@better-auth/passkey": "^1.7.5",
|
||||
"@bramus/specificity": "^2.4.2",
|
||||
"@hono/node-server": "^2.1.1",
|
||||
"@modelcontextprotocol/sdk": "^1.30.0",
|
||||
"@orpc/client": "^1.15.0",
|
||||
"@orpc/experimental-ratelimit": "^1.15.0",
|
||||
"@orpc/json-schema": "^1.15.0",
|
||||
"@orpc/openapi": "^1.15.0",
|
||||
"@orpc/server": "^1.15.0",
|
||||
"@orpc/zod": "^1.15.0",
|
||||
"@react-pdf/renderer": "^4.8.1",
|
||||
"@orpc/client": "^1.15.1",
|
||||
"@orpc/experimental-ratelimit": "^1.15.1",
|
||||
"@orpc/json-schema": "^1.15.1",
|
||||
"@orpc/openapi": "^1.15.1",
|
||||
"@orpc/server": "^1.15.1",
|
||||
"@orpc/zod": "^1.15.1",
|
||||
"@react-pdf/hyphenate": "0.1.0",
|
||||
"@react-pdf/renderer": "^4.9.0",
|
||||
"@reactive-resume/api": "workspace:*",
|
||||
"@reactive-resume/auth": "workspace:*",
|
||||
"@reactive-resume/db": "workspace:*",
|
||||
@@ -54,46 +55,48 @@
|
||||
"@reactive-resume/mcp": "workspace:*",
|
||||
"@reactive-resume/schema": "workspace:*",
|
||||
"@reactive-resume/utils": "workspace:*",
|
||||
"@sindresorhus/slugify": "^3.0.0",
|
||||
"@sindresorhus/slugify": "^3.0.1",
|
||||
"@t3-oss/env-core": "^0.13.11",
|
||||
"@uiw/color-convert": "^2.10.3",
|
||||
"ai": "^7.0.83",
|
||||
"ai": "^7.0.102",
|
||||
"bcrypt": "^6.0.0",
|
||||
"better-auth": "1.7.2",
|
||||
"cjk-regex": "^3.4.0",
|
||||
"better-auth": "1.7.5",
|
||||
"cjk-regex": "^3.5.0",
|
||||
"css-tree": "^3.2.1",
|
||||
"deepmerge-ts": "^8.0.2",
|
||||
"drizzle-orm": "1.0.0-rc.4",
|
||||
"drizzle-zod": "1.0.0-beta.14-a36c63d",
|
||||
"es-toolkit": "^1.51.0",
|
||||
"es-toolkit": "^1.52.0",
|
||||
"fast-json-patch": "^3.1.1",
|
||||
"hono": "^4.13.5",
|
||||
"fast-png": "^8.0.0",
|
||||
"hono": "^4.13.8",
|
||||
"jsonrepair": "^3.15.0",
|
||||
"node-html-parser": "^9.0.1",
|
||||
"nodemailer": "^9.0.5",
|
||||
"node-html-parser": "^9.0.4",
|
||||
"nodemailer": "^10.0.10",
|
||||
"ollama-ai-provider-v2": "^4.0.1",
|
||||
"pg": "^8.23.0",
|
||||
"phosphor-icons-react-pdf": "^0.1.3",
|
||||
"react": "^19.2.8",
|
||||
"react-email": "^6.9.3",
|
||||
"react": "^19.3.0",
|
||||
"react-email": "^6.9.5",
|
||||
"react-pdf-html": "^2.1.5",
|
||||
"resumable-stream": "^2.2.12",
|
||||
"sanitize-html": "^2.17.7",
|
||||
"sharp": "^0.35.4",
|
||||
"tokenx": "^2.1.0",
|
||||
"ts-pattern": "^5.9.0",
|
||||
"unique-names-generator": "^4.7.1",
|
||||
"uuid": "^14.0.2",
|
||||
"zod": "^4.4.3"
|
||||
"zod": "^4.6.5"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@reactive-resume/config": "workspace:*",
|
||||
"@types/node": "^26.4.0",
|
||||
"@types/node": "^26.6.1",
|
||||
"@types/pg": "^8.23.1",
|
||||
"@types/react": "^19.2.18",
|
||||
"@types/react": "^19.3.0",
|
||||
"@typescript/native-preview": "7.0.0-dev.20260707.2",
|
||||
"tsdown": "^0.22.14",
|
||||
"tsx": "^4.23.12",
|
||||
"tsdown": "^0.23.0",
|
||||
"tsx": "^4.23.13",
|
||||
"typescript": "^7.0.2",
|
||||
"vitest": "^4.1.11"
|
||||
"vitest": "^5.0.1"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -205,3 +205,17 @@ describe("createApp", () => {
|
||||
expect(mocks.serveWebDistStatic).not.toHaveBeenCalled();
|
||||
});
|
||||
});
|
||||
|
||||
it.each(["/auth/consent", "/auth/consent/", "/auth/login"])("prevents framing or caching %s", async (path) => {
|
||||
const { createApp } = await import("./app");
|
||||
mocks.serveWebDistStatic.mockImplementationOnce(async (_context: unknown, next: () => Promise<void>) => {
|
||||
await next();
|
||||
});
|
||||
const response = await createApp().request(`http://localhost:3000${path}?sig=signed`);
|
||||
expect(response.status).toBe(200);
|
||||
expect(await response.text()).toBe("web");
|
||||
expect(response.headers.get("content-security-policy")).toBe("frame-ancestors 'none'");
|
||||
expect(response.headers.get("x-frame-options")).toBe("DENY");
|
||||
expect(response.headers.get("referrer-policy")).toBe("no-referrer");
|
||||
expect(response.headers.get("cache-control")).toBe("no-store");
|
||||
});
|
||||
|
||||
@@ -36,6 +36,14 @@ const getTrustedClient = (context: Context<ServerEnvironment>): string => {
|
||||
export function createApp() {
|
||||
const app = new Hono<ServerEnvironment>();
|
||||
|
||||
app.use("/auth/*", async (c, next) => {
|
||||
await next();
|
||||
c.header("Content-Security-Policy", "frame-ancestors 'none'");
|
||||
c.header("X-Frame-Options", "DENY");
|
||||
c.header("Referrer-Policy", "no-referrer");
|
||||
c.header("Cache-Control", "no-store");
|
||||
});
|
||||
|
||||
app.all("/api/rpc", (c) => handleRpc(c.req.raw, getTrustedClient(c)));
|
||||
app.all("/api/rpc/*", (c) => handleRpc(c.req.raw, getTrustedClient(c)));
|
||||
app.all("/api/openapi", (c) => handleOpenApi(c.req.raw, getTrustedClient(c)));
|
||||
|
||||
@@ -2,6 +2,8 @@ import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
const mocks = vi.hoisted(() => ({
|
||||
getSession: vi.fn(),
|
||||
consent: vi.fn(),
|
||||
continueOAuth: vi.fn(),
|
||||
handler: vi.fn(),
|
||||
env: {
|
||||
SERVER_PORT: 3001,
|
||||
@@ -14,6 +16,8 @@ vi.mock("@reactive-resume/auth/config", () => ({
|
||||
auth: {
|
||||
api: {
|
||||
getSession: mocks.getSession,
|
||||
oauth2Consent: mocks.consent,
|
||||
oauth2Continue: mocks.continueOAuth,
|
||||
},
|
||||
handler: mocks.handler,
|
||||
},
|
||||
@@ -32,13 +36,45 @@ beforeEach(() => {
|
||||
});
|
||||
|
||||
describe("handleAuth", () => {
|
||||
it("rejects untrusted dynamic OAuth redirect URIs in safe mode", async () => {
|
||||
it.for([null, false, 42, "client", [], [{ redirect_uris: [] }]])(
|
||||
"rejects non-object registration payload %j",
|
||||
async (body) => {
|
||||
const { handleAuth } = await import("./auth");
|
||||
const response = await handleAuth(
|
||||
new Request("http://localhost:3000/api/auth/oauth2/register", {
|
||||
method: "POST",
|
||||
headers: { "content-type": "application/json" },
|
||||
body: JSON.stringify(body),
|
||||
}),
|
||||
);
|
||||
expect(response.status).toBe(400);
|
||||
await expect(response.json()).resolves.toEqual({ message: "Invalid registration payload" });
|
||||
expect(mocks.handler).not.toHaveBeenCalled();
|
||||
},
|
||||
);
|
||||
|
||||
it("registers third-party https callbacks so remote MCP clients can complete DCR", async () => {
|
||||
const { handleAuth } = await import("./auth");
|
||||
|
||||
const response = await handleAuth(
|
||||
new Request("http://localhost:3001/api/auth/oauth2/register", {
|
||||
method: "POST",
|
||||
body: JSON.stringify({ redirect_uris: ["https://evil.example.com/callback"] }),
|
||||
body: JSON.stringify({ redirect_uris: ["https://claude.ai/api/mcp/auth_callback"] }),
|
||||
headers: { "content-type": "application/json" },
|
||||
}),
|
||||
);
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(mocks.handler).toHaveBeenCalledOnce();
|
||||
});
|
||||
|
||||
it("rejects unsafe dynamic OAuth redirect URIs in safe mode", async () => {
|
||||
const { handleAuth } = await import("./auth");
|
||||
|
||||
const response = await handleAuth(
|
||||
new Request("http://localhost:3001/api/auth/oauth2/register", {
|
||||
method: "POST",
|
||||
body: JSON.stringify({ redirect_uris: ["https://192.168.1.10/callback"] }),
|
||||
headers: { "content-type": "application/json" },
|
||||
}),
|
||||
);
|
||||
@@ -66,6 +102,76 @@ describe("handleAuth", () => {
|
||||
expect(response.status).toBe(200);
|
||||
expect(mocks.handler).toHaveBeenCalledOnce();
|
||||
});
|
||||
it.each(["localhost", "127.0.0.1", "[::1]"])(
|
||||
"infers native application type for exact %s loopback callbacks",
|
||||
async (host) => {
|
||||
const { handleAuth } = await import("./auth");
|
||||
await handleAuth(
|
||||
new Request("http://localhost:3000/api/auth/oauth2/register", {
|
||||
method: "POST",
|
||||
headers: { "content-type": "application/json" },
|
||||
body: JSON.stringify({ redirect_uris: [`http://${host}:3210/callback`] }),
|
||||
}),
|
||||
);
|
||||
const forwarded = mocks.handler.mock.calls[0]?.[0] as Request;
|
||||
await expect(forwarded.json()).resolves.toMatchObject({
|
||||
application_type: "native",
|
||||
token_endpoint_auth_method: "none",
|
||||
});
|
||||
},
|
||||
);
|
||||
|
||||
it.each(["client_secret_basic", "client_secret_post"])(
|
||||
"keeps an explicitly registered %s so the client receives a client secret",
|
||||
async (method) => {
|
||||
const { handleAuth } = await import("./auth");
|
||||
await handleAuth(
|
||||
new Request("http://localhost:3000/api/auth/oauth2/register", {
|
||||
method: "POST",
|
||||
headers: { "content-type": "application/json" },
|
||||
body: JSON.stringify({
|
||||
redirect_uris: ["https://example.com/callback"],
|
||||
token_endpoint_auth_method: method,
|
||||
}),
|
||||
}),
|
||||
);
|
||||
const forwarded = mocks.handler.mock.calls[0]?.[0] as Request;
|
||||
await expect(forwarded.json()).resolves.toMatchObject({ token_endpoint_auth_method: method });
|
||||
},
|
||||
);
|
||||
|
||||
it.each([
|
||||
{ redirect_uris: ["https://example.com/callback"] },
|
||||
{ redirect_uris: ["http://localhost.evil.example/callback"] },
|
||||
{ redirect_uris: ["http://localhost:3210/callback"], application_type: "web" },
|
||||
{ redirect_uris: ["http://localhost:3210/callback", "https://example.com/callback"] },
|
||||
])("does not infer native for explicit web or non-loopback clients: %j", async (body) => {
|
||||
const { handleAuth } = await import("./auth");
|
||||
mocks.env.FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI = true;
|
||||
await handleAuth(
|
||||
new Request("http://localhost:3000/api/auth/oauth2/register", {
|
||||
method: "POST",
|
||||
headers: { "content-type": "application/json" },
|
||||
body: JSON.stringify(body),
|
||||
}),
|
||||
);
|
||||
const forwarded = mocks.handler.mock.calls[0]?.[0] as Request;
|
||||
expect((await forwarded.json()).application_type).not.toBe("native");
|
||||
});
|
||||
|
||||
it("preserves repeated resource indicators during authorization sanitization", async () => {
|
||||
const { handleAuth } = await import("./auth");
|
||||
await handleAuth(
|
||||
new Request(
|
||||
"http://localhost:3000/api/auth/oauth2/authorize?resource=http%3A%2F%2Flocalhost%3A3000&resource=http%3A%2F%2Flocalhost%3A3000%2Fmcp",
|
||||
),
|
||||
);
|
||||
const forwarded = mocks.handler.mock.calls[0]?.[0] as Request;
|
||||
expect(new URL(forwarded.url).searchParams.getAll("resource")).toEqual([
|
||||
"http://localhost:3000",
|
||||
"http://localhost:3000/mcp",
|
||||
]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("handleOAuth", () => {
|
||||
@@ -91,7 +197,64 @@ describe("handleOAuth", () => {
|
||||
expect(callbackUrl.searchParams.get("client_id")).toBe("test-client");
|
||||
expect(callbackUrl.searchParams.get("redirect_uri")).toBe("https://example.com/callback");
|
||||
expect(callbackUrl.searchParams.get("state")).toBe("abc");
|
||||
expect(callbackUrl.searchParams.has("exp")).toBe(false);
|
||||
expect(callbackUrl.searchParams.has("sig")).toBe(false);
|
||||
expect(callbackUrl.searchParams.get("exp")).toBe("123");
|
||||
expect(callbackUrl.searchParams.get("sig")).toBe("456");
|
||||
});
|
||||
it("continues signed authorization without approving consent on GET", async () => {
|
||||
const { handleOAuth } = await import("./auth");
|
||||
mocks.getSession.mockResolvedValueOnce({ user: { id: "owner" } });
|
||||
mocks.continueOAuth.mockResolvedValueOnce(
|
||||
Response.json({ redirect: true, url: "/auth/consent?client_id=client&sig=signed" }),
|
||||
);
|
||||
const query = "client_id=client&resource=one&resource=two&exp=123&sig=456";
|
||||
const response = await handleOAuth(new Request(`http://localhost:3000/api/auth/oauth?${query}`));
|
||||
expect(mocks.continueOAuth).toHaveBeenCalledWith(
|
||||
expect.objectContaining({ body: { postLogin: true, oauth_query: query } }),
|
||||
);
|
||||
expect(mocks.consent).not.toHaveBeenCalled();
|
||||
expect(response.status).toBe(302);
|
||||
expect(response.headers.get("location")).toBe("/auth/consent?client_id=client&sig=signed");
|
||||
});
|
||||
|
||||
it("preserves provider failures instead of issuing an authorization code", async () => {
|
||||
const { handleOAuth } = await import("./auth");
|
||||
mocks.getSession.mockResolvedValueOnce({ user: { id: "owner" } });
|
||||
mocks.continueOAuth.mockResolvedValueOnce(Response.json({ error: "invalid_signature" }, { status: 400 }));
|
||||
const response = await handleOAuth(new Request("http://localhost:3000/api/auth/oauth?sig=invalid"));
|
||||
expect(response.status).toBe(400);
|
||||
expect(response.headers.get("location")).toBeNull();
|
||||
await expect(response.json()).resolves.toEqual({ error: "invalid_signature" });
|
||||
});
|
||||
it("preserves provider cookies and cache headers on forced reauthentication", async () => {
|
||||
const { handleOAuth } = await import("./auth");
|
||||
mocks.getSession.mockResolvedValueOnce({ user: { id: "owner" } });
|
||||
const headers = new Headers({ "cache-control": "no-store", "content-length": "123" });
|
||||
headers.append("set-cookie", "oauth_state=state; Path=/; HttpOnly");
|
||||
headers.append("set-cookie", "session=refreshed; Path=/; HttpOnly");
|
||||
mocks.continueOAuth.mockResolvedValueOnce(
|
||||
Response.json({ redirect: true, url: "/api/auth/oauth?prompt=login&sig=signed" }, { headers }),
|
||||
);
|
||||
const response = await handleOAuth(new Request("http://localhost:3000/api/auth/oauth?sig=original"));
|
||||
expect(response.status).toBe(302);
|
||||
expect(response.headers.get("location")).toMatch(/^\/auth\/login\?reauthenticate=true&/);
|
||||
expect(response.headers.getSetCookie()).toEqual(headers.getSetCookie());
|
||||
expect(response.headers.get("cache-control")).toBe("no-store");
|
||||
expect(response.headers.get("content-type")).toBeNull();
|
||||
expect(response.headers.get("content-length")).toBeNull();
|
||||
});
|
||||
});
|
||||
|
||||
describe("OAuth provider response validation", () => {
|
||||
it.for([{}, { url: null }, { url: 7 }, { url: "" }, { url: "undefined" }, { url: "javascript:alert(1)" }])(
|
||||
"fails closed for malformed provider response %j",
|
||||
async (body) => {
|
||||
const { handleOAuth } = await import("./auth");
|
||||
mocks.getSession.mockResolvedValueOnce({ user: { id: "owner" } });
|
||||
mocks.continueOAuth.mockResolvedValueOnce(Response.json(body));
|
||||
const response = await handleOAuth(new Request("http://localhost:3000/api/auth/oauth?sig=signed"));
|
||||
expect(response.status).toBe(502);
|
||||
expect(response.headers.get("location")).toBeNull();
|
||||
expect(mocks.consent).not.toHaveBeenCalled();
|
||||
},
|
||||
);
|
||||
});
|
||||
|
||||
@@ -1,10 +1,6 @@
|
||||
import crypto from "node:crypto";
|
||||
import { eq } from "drizzle-orm";
|
||||
import { APIError } from "better-auth/api";
|
||||
import { auth } from "@reactive-resume/auth/config";
|
||||
import { db } from "@reactive-resume/db/client";
|
||||
import { oauthClient, verification } from "@reactive-resume/db/schema";
|
||||
import { env } from "@reactive-resume/env/server";
|
||||
import { generateId } from "@reactive-resume/utils/string";
|
||||
import { isAllowedOAuthRedirectUri } from "@reactive-resume/utils/url-security.node";
|
||||
|
||||
const oauthAuthorizeSanitizedParams = [
|
||||
@@ -19,8 +15,6 @@ const oauthAuthorizeSanitizedParams = [
|
||||
"resource",
|
||||
] as const;
|
||||
|
||||
const oauthCallbackPassthroughExcludedParams = new Set(["exp", "sig"]);
|
||||
|
||||
function sanitizeOAuthAuthorizeRequest(request: Request): Request {
|
||||
if (request.method !== "GET") return request;
|
||||
|
||||
@@ -33,9 +27,10 @@ function sanitizeOAuthAuthorizeRequest(request: Request): Request {
|
||||
.replace(/\s+/g, " ")
|
||||
.trim();
|
||||
const sanitizeParam = (key: string) => {
|
||||
const value = url.searchParams.get(key);
|
||||
if (!value) return;
|
||||
url.searchParams.set(key, sanitizeValue(value));
|
||||
const values = url.searchParams.getAll(key);
|
||||
if (!values.length) return;
|
||||
url.searchParams.delete(key);
|
||||
for (const value of values) url.searchParams.append(key, sanitizeValue(value));
|
||||
};
|
||||
|
||||
for (const key of oauthAuthorizeSanitizedParams) sanitizeParam(key);
|
||||
@@ -56,6 +51,10 @@ function sanitizeOAuthAuthorizeRequest(request: Request): Request {
|
||||
return new Request(url.toString(), request);
|
||||
}
|
||||
|
||||
function isRegistrationPayload(value: unknown): value is Record<string, unknown> {
|
||||
return typeof value === "object" && value !== null && !Array.isArray(value);
|
||||
}
|
||||
|
||||
async function defaultPublicClientRegistration(request: Request): Promise<Request> {
|
||||
if (request.method !== "POST") return request;
|
||||
|
||||
@@ -66,13 +65,29 @@ async function defaultPublicClientRegistration(request: Request): Promise<Reques
|
||||
let body: Record<string, unknown>;
|
||||
|
||||
try {
|
||||
body = await cloned.json();
|
||||
const payload: unknown = await cloned.json();
|
||||
if (!isRegistrationPayload(payload)) return request;
|
||||
body = payload;
|
||||
} catch {
|
||||
return request;
|
||||
}
|
||||
|
||||
// MCP native clients often omit OIDC application_type. Infer it only for
|
||||
// exact HTTP loopback callbacks; the provider still validates every URI.
|
||||
if (body.application_type === undefined && Array.isArray(body.redirect_uris) && body.redirect_uris.length > 0) {
|
||||
const allLoopback = body.redirect_uris.every(
|
||||
(uri: unknown) =>
|
||||
typeof uri === "string" && /^http:\/\/(?:localhost|127\.0\.0\.1|\[::1\])(?::[0-9]+)?(?:[/?]|$)/i.test(uri),
|
||||
);
|
||||
if (allLoopback) body.application_type = "native";
|
||||
}
|
||||
|
||||
// MCP clients that authenticate with PKCE alone omit the method, and Better Auth
|
||||
// would otherwise register them as `client_secret_basic`. Honor an explicit choice:
|
||||
// forcing it to "none" issues no client secret, so the client's own Basic/post
|
||||
// credentials are rejected at the token endpoint with 401 invalid_client.
|
||||
if (!request.headers.get("authorization")) {
|
||||
body.token_endpoint_auth_method = "none";
|
||||
body.token_endpoint_auth_method ??= "none";
|
||||
}
|
||||
|
||||
return new Request(url.toString(), {
|
||||
@@ -92,7 +107,11 @@ async function validateDynamicClientRegistrationRequest(request: Request): Promi
|
||||
let body: Record<string, unknown>;
|
||||
|
||||
try {
|
||||
body = await cloned.json();
|
||||
const payload: unknown = await cloned.json();
|
||||
if (!isRegistrationPayload(payload)) {
|
||||
return Response.json({ message: "Invalid registration payload" }, { status: 400 });
|
||||
}
|
||||
body = payload;
|
||||
} catch {
|
||||
return Response.json({ message: "Invalid registration payload" }, { status: 400 });
|
||||
}
|
||||
@@ -125,90 +144,68 @@ export async function handleAuth(request: Request) {
|
||||
return auth.handler(finalRequest);
|
||||
}
|
||||
|
||||
function generateCode() {
|
||||
return crypto.randomBytes(32).toString("base64url");
|
||||
}
|
||||
|
||||
function hashCode(code: string) {
|
||||
return crypto.createHash("sha256").update(code).digest("base64url");
|
||||
}
|
||||
|
||||
export async function handleOAuth(request: Request) {
|
||||
try {
|
||||
return await resumeOAuth(request);
|
||||
} catch (error) {
|
||||
// Before-hooks can throw even when the provider is called with asResponse.
|
||||
if (error instanceof APIError) return Response.json(error.body, { status: error.statusCode });
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
async function resumeOAuth(request: Request) {
|
||||
const session = await auth.api.getSession({ headers: request.headers });
|
||||
const url = new URL(request.url);
|
||||
|
||||
if (session?.user) {
|
||||
const clientId = url.searchParams.get("client_id");
|
||||
const redirectUri = url.searchParams.get("redirect_uri");
|
||||
const state = url.searchParams.get("state");
|
||||
const scope = url.searchParams.get("scope");
|
||||
const codeChallenge = url.searchParams.get("code_challenge");
|
||||
const codeChallengeMethod = url.searchParams.get("code_challenge_method");
|
||||
|
||||
if (!clientId || !redirectUri) {
|
||||
return Response.json({ error: "missing client_id or redirect_uri" }, { status: 400 });
|
||||
}
|
||||
|
||||
const [client] = await db.select().from(oauthClient).where(eq(oauthClient.clientId, clientId)).limit(1);
|
||||
|
||||
if (!client) {
|
||||
return Response.json({ error: "invalid client" }, { status: 400 });
|
||||
}
|
||||
|
||||
if (!client.redirectUris.includes(redirectUri)) {
|
||||
return Response.json({ error: "invalid redirect_uri" }, { status: 400 });
|
||||
}
|
||||
|
||||
const code = generateCode();
|
||||
const hashedCode = hashCode(code);
|
||||
const now = new Date();
|
||||
const expiresAt = new Date(now.getTime() + 600_000);
|
||||
|
||||
await db.insert(verification).values({
|
||||
id: generateId(),
|
||||
identifier: hashedCode,
|
||||
value: JSON.stringify({
|
||||
type: "authorization_code",
|
||||
query: {
|
||||
response_type: "code",
|
||||
client_id: clientId,
|
||||
redirect_uri: redirectUri,
|
||||
scope,
|
||||
state,
|
||||
code_challenge: codeChallenge,
|
||||
code_challenge_method: codeChallengeMethod,
|
||||
},
|
||||
userId: session.user.id,
|
||||
sessionId: session.session.id,
|
||||
authTime: new Date(session.session.createdAt).getTime(),
|
||||
}),
|
||||
expiresAt,
|
||||
createdAt: now,
|
||||
updatedAt: now,
|
||||
});
|
||||
|
||||
const callbackUrl = new URL(redirectUri);
|
||||
callbackUrl.searchParams.set("code", code);
|
||||
if (state) callbackUrl.searchParams.set("state", state);
|
||||
callbackUrl.searchParams.set("iss", `${env.APP_URL}/api/auth`);
|
||||
|
||||
return new Response(null, {
|
||||
status: 302,
|
||||
headers: { Location: callbackUrl.toString() },
|
||||
// Resume authorization without granting consent. The provider decides whether
|
||||
// the user must sign in, explicitly approve a client, or reuse an existing grant.
|
||||
// Its signed query must survive the login round trip byte-for-byte.
|
||||
const response = await auth.api.oauth2Continue({
|
||||
asResponse: true,
|
||||
request,
|
||||
headers: request.headers,
|
||||
body: { postLogin: true, oauth_query: url.search.slice(1) },
|
||||
});
|
||||
if (!(response instanceof Response)) throw new Error("OAuth provider did not return a response");
|
||||
if (!response.ok) return response;
|
||||
const result: unknown = await response.json().catch(() => null);
|
||||
if (
|
||||
!result ||
|
||||
typeof result !== "object" ||
|
||||
!("url" in result) ||
|
||||
typeof result.url !== "string" ||
|
||||
!result.url ||
|
||||
!(result.url.startsWith("/") || URL.canParse(result.url)) ||
|
||||
!URL.canParse(result.url, env.APP_URL)
|
||||
)
|
||||
return Response.json({ error: "invalid_provider_response" }, { status: 502 });
|
||||
const headers = new Headers(response.headers);
|
||||
headers.delete("content-type");
|
||||
headers.delete("content-length");
|
||||
const target = new URL(result.url, env.APP_URL);
|
||||
if (["javascript:", "data:", "vbscript:", "file:", "blob:"].includes(target.protocol)) {
|
||||
return Response.json({ error: "invalid_provider_response" }, { status: 502 });
|
||||
}
|
||||
if (target.origin === new URL(env.APP_URL).origin && target.pathname === "/api/auth/oauth") {
|
||||
return redirectToOAuthLogin(target, true, headers);
|
||||
}
|
||||
headers.set("Location", result.url);
|
||||
return new Response(null, { status: 302, headers });
|
||||
}
|
||||
|
||||
const loginUrl = new URL("/auth/login", env.APP_URL);
|
||||
const oauthParams = new URLSearchParams();
|
||||
for (const [key, value] of url.searchParams) {
|
||||
if (!oauthCallbackPassthroughExcludedParams.has(key)) {
|
||||
oauthParams.set(key, value);
|
||||
}
|
||||
}
|
||||
loginUrl.searchParams.set("callbackURL", `/api/auth/oauth?${oauthParams.toString()}`);
|
||||
return redirectToOAuthLogin(url);
|
||||
}
|
||||
|
||||
function redirectToOAuthLogin(url: URL, reauthenticate = false, headers = new Headers()) {
|
||||
const prompt = new Set(url.searchParams.get("prompt")?.split(" ") ?? []);
|
||||
const loginUrl = new URL(prompt.has("create") ? "/auth/register" : "/auth/login", env.APP_URL);
|
||||
if (reauthenticate) loginUrl.searchParams.set("reauthenticate", "true");
|
||||
loginUrl.searchParams.set("callbackURL", `/api/auth/oauth${url.search}`);
|
||||
headers.set("Location", `${loginUrl.pathname}${loginUrl.search}`);
|
||||
return new Response(null, {
|
||||
status: 302,
|
||||
headers: { Location: `${loginUrl.pathname}${loginUrl.search}` },
|
||||
headers,
|
||||
});
|
||||
}
|
||||
|
||||
@@ -0,0 +1,96 @@
|
||||
import { afterEach, beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
const { execute, healthcheck } = vi.hoisted(() => ({ execute: vi.fn(), healthcheck: vi.fn() }));
|
||||
|
||||
vi.mock("@reactive-resume/db/client", () => ({ db: { execute } }));
|
||||
vi.mock("@reactive-resume/api/features/storage", () => ({ getStorageService: () => ({ healthcheck }) }));
|
||||
vi.mock("../app-version", () => ({ appVersion: "9.8.7" }));
|
||||
|
||||
import { handleHealth } from "./health";
|
||||
|
||||
describe("health version reporting", () => {
|
||||
beforeEach(() => {
|
||||
execute.mockResolvedValue([]);
|
||||
healthcheck.mockResolvedValue({ status: "healthy" });
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
vi.unstubAllEnvs();
|
||||
vi.restoreAllMocks();
|
||||
});
|
||||
|
||||
it("reports the built application version when launched directly by Node", async () => {
|
||||
vi.stubEnv("npm_package_version", undefined);
|
||||
|
||||
const response = await handleHealth();
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(await response.json()).toMatchObject({ service: "reactive-resume", version: "9.8.7", status: "healthy" });
|
||||
});
|
||||
|
||||
it("ignores a package manager's workspace package version", async () => {
|
||||
vi.stubEnv("npm_package_version", "0.0.0");
|
||||
|
||||
expect(await (await handleHealth()).json()).toMatchObject({ version: "9.8.7" });
|
||||
});
|
||||
|
||||
it("keeps the version available when a dependency is unhealthy", async () => {
|
||||
vi.stubEnv("npm_package_version", undefined);
|
||||
execute.mockRejectedValueOnce(new Error("Database unavailable"));
|
||||
vi.spyOn(console, "warn").mockImplementation(() => {});
|
||||
|
||||
const response = await handleHealth();
|
||||
|
||||
expect(response.status).toBe(503);
|
||||
expect(await response.json()).toMatchObject({ version: "9.8.7", status: "unhealthy" });
|
||||
});
|
||||
it.each(["database", "storage"])("keeps thrown %s error details in server logs only", async (dependency) => {
|
||||
const detail = "Connection failed for private-user at internal.example:5432";
|
||||
const warn = vi.spyOn(console, "warn").mockImplementation(() => {});
|
||||
(dependency === "database" ? execute : healthcheck).mockRejectedValueOnce(new Error(detail));
|
||||
|
||||
const response = await handleHealth();
|
||||
const body = await response.json();
|
||||
|
||||
expect(response.status).toBe(503);
|
||||
expect(JSON.stringify(body)).not.toContain(detail);
|
||||
expect(body[dependency]).toMatchObject({
|
||||
status: "unhealthy",
|
||||
error: expect.stringContaining("health check failed"),
|
||||
});
|
||||
expect(warn).toHaveBeenCalledWith(
|
||||
"[Healthcheck]",
|
||||
expect.objectContaining({
|
||||
[dependency]: expect.objectContaining({ error: detail }),
|
||||
}),
|
||||
);
|
||||
});
|
||||
|
||||
it("redacts returned storage failures while preserving diagnostics in server logs", async () => {
|
||||
const detail = "Access denied to bucket private-bucket on internal.example";
|
||||
const warn = vi.spyOn(console, "warn").mockImplementation(() => {});
|
||||
healthcheck.mockResolvedValueOnce({
|
||||
status: "unhealthy",
|
||||
type: "s3",
|
||||
message: detail,
|
||||
error: detail,
|
||||
internalDetail: detail,
|
||||
});
|
||||
|
||||
const response = await handleHealth();
|
||||
const body = await response.json();
|
||||
|
||||
expect(response.status).toBe(503);
|
||||
expect(body.storage).toEqual({
|
||||
status: "unhealthy",
|
||||
type: "s3",
|
||||
latencyMs: expect.any(Number),
|
||||
error: "Storage health check failed.",
|
||||
});
|
||||
expect(JSON.stringify(body)).not.toContain(detail);
|
||||
expect(warn).toHaveBeenCalledWith(
|
||||
"[Healthcheck]",
|
||||
expect.objectContaining({ storage: expect.objectContaining({ error: detail, message: detail }) }),
|
||||
);
|
||||
});
|
||||
});
|
||||
@@ -2,6 +2,7 @@ import { sql } from "drizzle-orm";
|
||||
import { withTimeout } from "es-toolkit";
|
||||
import { getStorageService } from "@reactive-resume/api/features/storage";
|
||||
import { db } from "@reactive-resume/db/client";
|
||||
import { appVersion } from "../app-version";
|
||||
|
||||
const HEALTHCHECK_TIMEOUT_MS = 1_500;
|
||||
|
||||
@@ -31,6 +32,16 @@ async function runCheck(check: () => Promise<object>): Promise<CheckResult> {
|
||||
}
|
||||
}
|
||||
|
||||
function publicCheck(check: CheckResult, name: "Database" | "Storage"): CheckResult {
|
||||
if (check.status === "healthy") return check;
|
||||
return {
|
||||
status: check.status,
|
||||
latencyMs: check.latencyMs,
|
||||
error: `${name} health check failed.`,
|
||||
...(check.type === "local" || check.type === "s3" ? { type: check.type } : {}),
|
||||
};
|
||||
}
|
||||
|
||||
// ponytail: inner try/catches removed; runCheck's outer catch handles all errors
|
||||
async function checkDatabase() {
|
||||
await db.execute(sql`SELECT 1`);
|
||||
@@ -45,12 +56,12 @@ export async function handleHealth() {
|
||||
|
||||
const checks = {
|
||||
service: "reactive-resume",
|
||||
version: process.env.npm_package_version,
|
||||
version: appVersion,
|
||||
status,
|
||||
timestamp: new Date().toISOString(),
|
||||
uptime: `${process.uptime().toFixed(2)}s`,
|
||||
database,
|
||||
storage,
|
||||
database: publicCheck(database, "Database"),
|
||||
storage: publicCheck(storage, "Storage"),
|
||||
};
|
||||
|
||||
if (status === "unhealthy") {
|
||||
|
||||
@@ -0,0 +1,337 @@
|
||||
import { createHash, randomBytes } from "node:crypto";
|
||||
import { describe, expect, it, vi } from "vitest";
|
||||
|
||||
vi.mock("@reactive-resume/email/transport", () => ({ sendEmail: vi.fn() }));
|
||||
|
||||
// Run only against an explicitly supplied disposable database, after applying migrations.
|
||||
const databaseURL = process.env.OAUTH_TEST_DATABASE_URL;
|
||||
|
||||
describe.skipIf(!databaseURL)("MCP OAuth flow with PostgreSQL", () => {
|
||||
it("registers public clients, resumes login, and exchanges a resource-bound PKCE code", async () => {
|
||||
if (!databaseURL) return;
|
||||
process.env.DATABASE_URL = databaseURL;
|
||||
process.env.APP_URL = "http://localhost:33920";
|
||||
process.env.AUTH_SECRET = "oauth-integration-test-secret-only";
|
||||
const { handleAuth, handleOAuth } = await import("./auth");
|
||||
// Better Auth disables origin checks by default in test mode; exercise production behavior.
|
||||
const { auth } = await import("@reactive-resume/auth/config");
|
||||
(await auth.$context).skipOriginCheck = false;
|
||||
const origin = process.env.APP_URL;
|
||||
const redirectURI = "http://127.0.0.1:33921/callback";
|
||||
const request = (path: string, body: object, cookie = "") =>
|
||||
new Request(`${origin}/api/auth/${path}`, {
|
||||
method: "POST",
|
||||
headers: { "content-type": "application/json", origin, cookie },
|
||||
body: JSON.stringify(body),
|
||||
});
|
||||
const registration = await handleAuth(
|
||||
request("oauth2/register", { client_name: "OAuth integration", redirect_uris: [redirectURI] }),
|
||||
);
|
||||
expect(registration.status, await registration.clone().text()).toBe(201);
|
||||
const client = await registration.json();
|
||||
expect(client.token_endpoint_auth_method).toBe("none");
|
||||
|
||||
const deniedRegistration = await handleAuth(
|
||||
request("oauth2/register", {
|
||||
client_name: "Denied resource",
|
||||
redirect_uris: [redirectURI],
|
||||
resources: ["https://untrusted.example/mcp"],
|
||||
}),
|
||||
);
|
||||
expect(deniedRegistration.status).toBe(400);
|
||||
await expect(deniedRegistration.json()).resolves.toMatchObject({ error: "invalid_target" });
|
||||
|
||||
const verifier = randomBytes(32).toString("base64url");
|
||||
const query = new URLSearchParams({
|
||||
client_id: client.client_id,
|
||||
redirect_uri: redirectURI,
|
||||
response_type: "code",
|
||||
scope: "openid profile offline_access",
|
||||
code_challenge: createHash("sha256").update(verifier).digest("base64url"),
|
||||
code_challenge_method: "S256",
|
||||
resource: `${origin}/mcp`,
|
||||
state: "opaque-state",
|
||||
});
|
||||
const authorize = await handleAuth(new Request(`${origin}/api/auth/oauth2/authorize?${query}`));
|
||||
expect(authorize.status, await authorize.clone().text()).toBe(302);
|
||||
const bridgeURL = authorize.headers.get("location");
|
||||
expect(bridgeURL).toBeTruthy();
|
||||
const login = await handleOAuth(new Request(new URL(bridgeURL ?? "", origin)));
|
||||
const loginURL = new URL(login.headers.get("location") ?? "", origin);
|
||||
const callbackURL = loginURL.searchParams.get("callbackURL");
|
||||
expect(callbackURL).toContain("sig=");
|
||||
expect(callbackURL).toContain("resource=");
|
||||
|
||||
const unique = randomBytes(6).toString("hex");
|
||||
const signup = await handleAuth(
|
||||
request("sign-up/email", {
|
||||
name: "OAuth Test",
|
||||
email: `oauth-${unique}@example.com`,
|
||||
username: `oauth-${unique}`,
|
||||
password: "password123",
|
||||
}),
|
||||
);
|
||||
expect(signup.status, await signup.clone().text()).toBe(200);
|
||||
const cookie = signup.headers
|
||||
.getSetCookie()
|
||||
.map((value) => value.split(";", 1)[0])
|
||||
.join("; ");
|
||||
const tamperedURL = new URL(`${origin}${callbackURL}`);
|
||||
tamperedURL.searchParams.set("state", "tampered");
|
||||
const tampered = await handleOAuth(new Request(tamperedURL, { headers: { cookie } }));
|
||||
expect(tampered.status).toBe(400);
|
||||
await expect(tampered.json()).resolves.toMatchObject({ error: "invalid_signature" });
|
||||
const callback = await handleOAuth(new Request(`${origin}${callbackURL}`, { headers: { cookie } }));
|
||||
expect(callback.status, await callback.clone().text()).toBe(302);
|
||||
const consentURL = new URL(callback.headers.get("location") ?? "", origin);
|
||||
expect(consentURL.pathname).toBe("/auth/consent");
|
||||
expect(consentURL.searchParams.has("code")).toBe(false);
|
||||
const oauth_query = consentURL.search.slice(1);
|
||||
const consents = async () => {
|
||||
const response = await handleAuth(new Request(`${origin}/api/auth/oauth2/get-consents`, { headers: { cookie } }));
|
||||
expect(response.status).toBe(200);
|
||||
return response.json();
|
||||
};
|
||||
expect(await consents()).toEqual([]);
|
||||
const silent = await handleAuth(
|
||||
new Request(`${origin}/api/auth/oauth2/authorize?${query}&prompt=none`, { headers: { cookie } }),
|
||||
);
|
||||
expect(new URL(silent.headers.get("location") ?? "").searchParams.get("error")).toBe("consent_required");
|
||||
const tamperedConsentQuery = new URLSearchParams(oauth_query);
|
||||
tamperedConsentQuery.set("scope", "openid profile email offline_access");
|
||||
const tamperedConsent = await handleAuth(
|
||||
request(
|
||||
"oauth2/consent",
|
||||
{
|
||||
accept: true,
|
||||
oauth_query: tamperedConsentQuery.toString(),
|
||||
},
|
||||
cookie,
|
||||
),
|
||||
);
|
||||
expect(tamperedConsent.status).toBe(400);
|
||||
expect(await consents()).toEqual([]);
|
||||
const csrf = await handleAuth(
|
||||
new Request(`${origin}/api/auth/oauth2/consent`, {
|
||||
method: "POST",
|
||||
headers: { cookie, origin: "https://untrusted.example", "content-type": "application/json" },
|
||||
body: JSON.stringify({ accept: true, oauth_query }),
|
||||
}),
|
||||
);
|
||||
expect(csrf.status).toBe(403);
|
||||
const denied = await handleAuth(request("oauth2/consent", { accept: false, oauth_query }, cookie));
|
||||
expect(denied.status, await denied.clone().text()).toBe(200);
|
||||
const deniedURL = new URL((await denied.json()).url);
|
||||
expect(deniedURL.searchParams.get("error")).toBe("access_denied");
|
||||
expect(deniedURL.searchParams.get("state")).toBe("opaque-state");
|
||||
expect(deniedURL.searchParams.has("code")).toBe(false);
|
||||
expect(await consents()).toEqual([]);
|
||||
const accepted = await handleAuth(request("oauth2/consent", { accept: true, oauth_query }, cookie));
|
||||
expect(accepted.status, await accepted.clone().text()).toBe(200);
|
||||
expect(await consents()).toHaveLength(1);
|
||||
const codeURL = new URL((await accepted.json()).url);
|
||||
expect(codeURL.origin).toBe(new URL(redirectURI).origin);
|
||||
expect(codeURL.searchParams.get("state")).toBe("opaque-state");
|
||||
const code = codeURL.searchParams.get("code");
|
||||
expect(code).toBeTruthy();
|
||||
const tokenRequest = () =>
|
||||
new Request(`${origin}/api/auth/oauth2/token`, {
|
||||
method: "POST",
|
||||
headers: { "content-type": "application/x-www-form-urlencoded" },
|
||||
body: new URLSearchParams({
|
||||
grant_type: "authorization_code",
|
||||
client_id: client.client_id,
|
||||
code: code ?? "",
|
||||
redirect_uri: redirectURI,
|
||||
code_verifier: verifier,
|
||||
resource: `${origin}/mcp`,
|
||||
}),
|
||||
});
|
||||
const tokenResponse = await handleAuth(tokenRequest());
|
||||
expect(tokenResponse.status, await tokenResponse.clone().text()).toBe(200);
|
||||
const token = await tokenResponse.json();
|
||||
expect(token.access_token).toBeTruthy();
|
||||
expect(token.refresh_token).toBeTruthy();
|
||||
const claims = JSON.parse(Buffer.from(token.access_token.split(".")[1], "base64url").toString());
|
||||
expect([claims.aud].flat()).toContain(`${origin}/mcp`);
|
||||
expect((await handleAuth(tokenRequest())).status).toBe(400);
|
||||
}, 30_000);
|
||||
it("exchanges a code for a confidential client that registered client_secret_basic", async () => {
|
||||
if (!databaseURL) return;
|
||||
process.env.DATABASE_URL = databaseURL;
|
||||
process.env.APP_URL = "http://localhost:33920";
|
||||
process.env.AUTH_SECRET = "oauth-integration-test-secret-only";
|
||||
const { handleAuth, handleOAuth } = await import("./auth");
|
||||
const origin = process.env.APP_URL;
|
||||
const redirectURI = "http://127.0.0.1:33921/callback";
|
||||
const request = (path: string, body: object, cookie = "") =>
|
||||
new Request(`${origin}/api/auth/${path}`, {
|
||||
method: "POST",
|
||||
headers: { "content-type": "application/json", origin, cookie },
|
||||
body: JSON.stringify(body),
|
||||
});
|
||||
|
||||
const registration = await handleAuth(
|
||||
request("oauth2/register", {
|
||||
client_name: "Confidential MCP client",
|
||||
redirect_uris: [redirectURI],
|
||||
token_endpoint_auth_method: "client_secret_basic",
|
||||
}),
|
||||
);
|
||||
expect(registration.status, await registration.clone().text()).toBe(201);
|
||||
const client = await registration.json();
|
||||
// Downgrading this to a public client leaves the client without a secret, and its
|
||||
// Basic-authenticated token exchange then fails with 401 invalid_client.
|
||||
expect(client.token_endpoint_auth_method).toBe("client_secret_basic");
|
||||
expect(client.client_secret).toBeTruthy();
|
||||
|
||||
const verifier = randomBytes(32).toString("base64url");
|
||||
const query = new URLSearchParams({
|
||||
client_id: client.client_id,
|
||||
redirect_uri: redirectURI,
|
||||
response_type: "code",
|
||||
scope: "openid profile offline_access",
|
||||
code_challenge: createHash("sha256").update(verifier).digest("base64url"),
|
||||
code_challenge_method: "S256",
|
||||
resource: `${origin}/mcp`,
|
||||
state: "opaque-state",
|
||||
});
|
||||
const authorize = await handleAuth(new Request(`${origin}/api/auth/oauth2/authorize?${query}`));
|
||||
const login = await handleOAuth(new Request(new URL(authorize.headers.get("location") ?? "", origin)));
|
||||
const callbackURL = new URL(login.headers.get("location") ?? "", origin).searchParams.get("callbackURL");
|
||||
|
||||
const unique = randomBytes(6).toString("hex");
|
||||
const signup = await handleAuth(
|
||||
request("sign-up/email", {
|
||||
name: "Confidential Test",
|
||||
email: `confidential-${unique}@example.com`,
|
||||
username: `confidential-${unique}`,
|
||||
password: "password123",
|
||||
}),
|
||||
);
|
||||
expect(signup.status, await signup.clone().text()).toBe(200);
|
||||
const cookie = signup.headers
|
||||
.getSetCookie()
|
||||
.map((value) => value.split(";", 1)[0])
|
||||
.join("; ");
|
||||
const callback = await handleOAuth(new Request(`${origin}${callbackURL}`, { headers: { cookie } }));
|
||||
const oauth_query = new URL(callback.headers.get("location") ?? "", origin).search.slice(1);
|
||||
const accepted = await handleAuth(request("oauth2/consent", { accept: true, oauth_query }, cookie));
|
||||
expect(accepted.status, await accepted.clone().text()).toBe(200);
|
||||
const code = new URL((await accepted.json()).url).searchParams.get("code");
|
||||
|
||||
const tokenResponse = await handleAuth(
|
||||
new Request(`${origin}/api/auth/oauth2/token`, {
|
||||
method: "POST",
|
||||
headers: {
|
||||
"content-type": "application/x-www-form-urlencoded",
|
||||
authorization: `Basic ${Buffer.from(`${client.client_id}:${client.client_secret}`).toString("base64")}`,
|
||||
},
|
||||
body: new URLSearchParams({
|
||||
grant_type: "authorization_code",
|
||||
code: code ?? "",
|
||||
redirect_uri: redirectURI,
|
||||
code_verifier: verifier,
|
||||
resource: `${origin}/mcp`,
|
||||
}),
|
||||
}),
|
||||
);
|
||||
expect(tokenResponse.status, await tokenResponse.clone().text()).toBe(200);
|
||||
await expect(tokenResponse.json()).resolves.toMatchObject({ token_type: "Bearer" });
|
||||
}, 30_000);
|
||||
it.each(["login", "max-age", "create"])(
|
||||
"requires fresh authentication for %s without looping",
|
||||
async (mode) => {
|
||||
if (!databaseURL) return;
|
||||
process.env.DATABASE_URL = databaseURL;
|
||||
process.env.APP_URL = "http://localhost:33920";
|
||||
process.env.AUTH_SECRET = "oauth-integration-test-secret-only";
|
||||
const { handleAuth, handleOAuth } = await import("./auth");
|
||||
const origin = process.env.APP_URL;
|
||||
const cookieOf = (response: Response) =>
|
||||
response.headers
|
||||
.getSetCookie()
|
||||
.map((value) => value.split(";", 1)[0])
|
||||
.join("; ");
|
||||
const post = (path: string, body: object, cookie = "") =>
|
||||
handleAuth(
|
||||
new Request(`${origin}/api/auth/${path}`, {
|
||||
method: "POST",
|
||||
headers: { "content-type": "application/json", origin, cookie },
|
||||
body: JSON.stringify(body),
|
||||
}),
|
||||
);
|
||||
const unique = randomBytes(6).toString("hex");
|
||||
const credentials = {
|
||||
name: "Reauth Test",
|
||||
email: `reauth-${unique}@example.com`,
|
||||
username: `reauth-${unique}`,
|
||||
password: "password123",
|
||||
};
|
||||
const existingSignup = await post("sign-up/email", credentials);
|
||||
expect(existingSignup.status).toBe(200);
|
||||
const oldCookie = cookieOf(existingSignup);
|
||||
const registration = await post("oauth2/register", {
|
||||
client_name: "Reauth integration",
|
||||
redirect_uris: ["http://127.0.0.1:33921/callback"],
|
||||
});
|
||||
expect(registration.status).toBe(201);
|
||||
const client = await registration.json();
|
||||
const query = new URLSearchParams({
|
||||
client_id: client.client_id,
|
||||
redirect_uri: "http://127.0.0.1:33921/callback",
|
||||
response_type: "code",
|
||||
scope: "openid profile",
|
||||
resource: `${origin}/mcp`,
|
||||
code_challenge: createHash("sha256").update(randomBytes(32)).digest("base64url"),
|
||||
code_challenge_method: "S256",
|
||||
...(mode === "max-age" ? { max_age: "0" } : { prompt: mode }),
|
||||
});
|
||||
const authorization = await handleAuth(
|
||||
new Request(`${origin}/api/auth/oauth2/authorize?${query}`, { headers: { cookie: oldCookie } }),
|
||||
);
|
||||
expect(authorization.status).toBe(302);
|
||||
const bridge = await handleOAuth(
|
||||
new Request(new URL(authorization.headers.get("location") ?? "", origin), { headers: { cookie: oldCookie } }),
|
||||
);
|
||||
expect(bridge.status).toBe(302);
|
||||
const loginURL = new URL(bridge.headers.get("location") ?? "", origin);
|
||||
expect(loginURL.pathname).toBe(mode === "create" ? "/auth/register" : "/auth/login");
|
||||
expect(loginURL.searchParams.get("reauthenticate")).toBe("true");
|
||||
const callbackURL = new URL(loginURL.searchParams.get("callbackURL") ?? "", origin);
|
||||
const oauth_query = callbackURL.search.slice(1);
|
||||
const authenticated =
|
||||
mode === "create"
|
||||
? await post(
|
||||
"sign-up/email",
|
||||
{ ...credentials, email: `new-${unique}@example.com`, username: `new-${unique}` },
|
||||
oldCookie,
|
||||
)
|
||||
: await post(
|
||||
"sign-in/email",
|
||||
{ email: credentials.email, password: credentials.password, oauth_query },
|
||||
oldCookie,
|
||||
);
|
||||
expect(authenticated.status, await authenticated.clone().text()).toBe(200);
|
||||
const newCookie = cookieOf(authenticated);
|
||||
expect(newCookie).not.toBe(oldCookie);
|
||||
const continuation =
|
||||
mode === "create" ? await post("oauth2/continue", { created: true, oauth_query }, newCookie) : authenticated;
|
||||
expect(continuation.status, await continuation.clone().text()).toBe(200);
|
||||
const result = await continuation.json();
|
||||
let target = new URL(result.url, origin);
|
||||
if (target.pathname === "/api/auth/oauth") {
|
||||
const response = await handleOAuth(new Request(target, { headers: { cookie: newCookie } }));
|
||||
expect(response.status, await response.clone().text()).toBe(302);
|
||||
target = new URL(response.headers.get("location") ?? "", origin);
|
||||
}
|
||||
expect(target.pathname).toBe("/auth/consent");
|
||||
const accepted = await post("oauth2/consent", { accept: true, oauth_query: target.search.slice(1) }, newCookie);
|
||||
expect(accepted.status, await accepted.clone().text()).toBe(200);
|
||||
target = new URL((await accepted.json()).url, origin);
|
||||
expect(target.origin).toBe("http://127.0.0.1:33921");
|
||||
expect(target.searchParams.get("code")).toBeTruthy();
|
||||
},
|
||||
30_000,
|
||||
);
|
||||
});
|
||||
@@ -0,0 +1,35 @@
|
||||
import { afterEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
const events = vi.hoisted(() => [] as string[]);
|
||||
vi.mock("./startup/checks", () => ({
|
||||
runStartupChecks: async () => {
|
||||
await Promise.resolve();
|
||||
events.push("migrations complete");
|
||||
},
|
||||
}));
|
||||
vi.mock("./http/app", () => {
|
||||
events.push("auth imported");
|
||||
return {
|
||||
createApp: () => {
|
||||
events.push("app created");
|
||||
return { fetch: vi.fn() };
|
||||
},
|
||||
};
|
||||
});
|
||||
vi.mock("@hono/node-server", () => ({
|
||||
serve: () => {
|
||||
events.push("server listening");
|
||||
},
|
||||
}));
|
||||
vi.mock("@reactive-resume/env/server", () => ({ env: { SERVER_PORT: 3001 } }));
|
||||
afterEach(() => vi.restoreAllMocks());
|
||||
|
||||
describe("server startup", () => {
|
||||
it("finishes migrations before importing auth and seeding OAuth resources", async () => {
|
||||
vi.spyOn(process, "on").mockReturnValue(process);
|
||||
const entry = await import("./index");
|
||||
expect(events).toEqual([]);
|
||||
await entry.main();
|
||||
expect(events).toEqual(["migrations complete", "auth imported", "app created", "server listening"]);
|
||||
});
|
||||
});
|
||||
@@ -1,14 +1,15 @@
|
||||
import { pathToFileURL } from "node:url";
|
||||
import { serve } from "@hono/node-server";
|
||||
import { env } from "@reactive-resume/env/server";
|
||||
import { createApp } from "./http/app";
|
||||
import { runStartupChecks } from "./startup/checks";
|
||||
|
||||
export { createApp } from "./http/app";
|
||||
|
||||
async function main() {
|
||||
export async function main() {
|
||||
await runStartupChecks();
|
||||
|
||||
// OAuth resource seeding starts when auth is imported, so load the app only
|
||||
// after migrations have created the provider tables.
|
||||
const { createApp } = await import("./http/app");
|
||||
|
||||
// Safety net: Node 24 crashes the whole process on an unhandled rejection. One request's
|
||||
// stray promise must not take the server down for everyone, so log and keep serving.
|
||||
// Registered after startup checks so a broken startup still fails loudly. (Left uncaught
|
||||
|
||||
@@ -1,7 +1,14 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { readFile } from "node:fs/promises";
|
||||
import { describe, expect, it, vi } from "vitest";
|
||||
import z from "zod";
|
||||
import { defaultResumeData } from "@reactive-resume/schema/resume/default";
|
||||
import { createResumeDataJsonSchema } from "@reactive-resume/schema/resume/json-schema";
|
||||
import { writableResumeDataSchema } from "@reactive-resume/schema/resume/write";
|
||||
|
||||
// Spec generation reads procedure contracts without executing authentication. Keep the
|
||||
// provider's resource seeding out of this unit test; real OAuth initialization is covered
|
||||
// by the opt-in PostgreSQL integration suite after migrations run.
|
||||
vi.mock("@reactive-resume/auth/config", () => ({ auth: {}, verifyOAuthToken: vi.fn() }));
|
||||
|
||||
type GeneratedSpecView = {
|
||||
components?: { schemas?: Record<string, unknown> };
|
||||
@@ -10,6 +17,11 @@ type GeneratedSpecView = {
|
||||
Record<
|
||||
string,
|
||||
{
|
||||
tags?: string[];
|
||||
operationId?: string;
|
||||
summary?: string;
|
||||
description?: string;
|
||||
responses?: Record<string, { description?: string }>;
|
||||
requestBody?: {
|
||||
content?: Record<string, { schema?: unknown }>;
|
||||
};
|
||||
@@ -66,6 +78,51 @@ function findImpossibleRequestSchemas(spec: GeneratedSpecView) {
|
||||
}
|
||||
|
||||
describe("generateOpenApiSpec", () => {
|
||||
it("documents all cover-letter procedures with REST metadata", async () => {
|
||||
const spec = (await generateSpec()) as GeneratedSpecView;
|
||||
const expected = [
|
||||
["get", "/cover-letters", "listCoverLetters", "List cover letters", "200"],
|
||||
["get", "/cover-letters/{id}", "getCoverLetter", "Get cover letter by ID", "200"],
|
||||
["post", "/cover-letters", "createCoverLetter", "Create a cover letter", "200"],
|
||||
["put", "/cover-letters/{id}", "updateCoverLetter", "Update a cover letter", "200"],
|
||||
["post", "/cover-letters/{id}/refresh-style", "refreshCoverLetterStyle", "Refresh cover letter style", "200"],
|
||||
["post", "/cover-letters/{id}/duplicate", "duplicateCoverLetter", "Duplicate a cover letter", "200"],
|
||||
["delete", "/cover-letters/{id}", "deleteCoverLetter", "Delete a cover letter", "200"],
|
||||
["post", "/cover-letters/from-resume", "copyEmbeddedCoverLetter", "Copy an embedded cover letter", "200"],
|
||||
["get", "/cover-letters/{id}/export", "exportCoverLetter", "Export a cover letter", "200"],
|
||||
["post", "/cover-letters/import", "importCoverLetter", "Import a cover letter", "200"],
|
||||
] as const;
|
||||
|
||||
for (const [method, path, operationId, summary, successStatus] of expected) {
|
||||
const operation = spec.paths?.[path]?.[method];
|
||||
expect(operation).toMatchObject({
|
||||
tags: ["Cover Letters"],
|
||||
operationId,
|
||||
summary,
|
||||
description: expect.any(String),
|
||||
responses: { [successStatus]: { description: expect.any(String) } },
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
it("keeps published cover-letter operations in sync with the runtime spec", async () => {
|
||||
const published = JSON.parse(
|
||||
await readFile(new URL("../../../../docs/spec.json", import.meta.url), "utf8"),
|
||||
) as GeneratedSpecView;
|
||||
const runtime = await generateSpec();
|
||||
const coverLetterPaths = (spec: GeneratedSpecView) =>
|
||||
Object.fromEntries(
|
||||
Object.entries(spec.paths ?? {}).filter(
|
||||
([path]) => path.startsWith("/cover-letters") || path.startsWith("/coverLetters/"),
|
||||
),
|
||||
);
|
||||
|
||||
const publishedPaths = coverLetterPaths(published);
|
||||
const runtimePaths = coverLetterPaths(runtime as GeneratedSpecView);
|
||||
expect(Object.keys(publishedPaths).sort()).toEqual(Object.keys(runtimePaths).sort());
|
||||
expect(publishedPaths).toEqual(runtimePaths);
|
||||
});
|
||||
|
||||
it("uses caller-provided application URL and version", async () => {
|
||||
const spec = await generateSpec();
|
||||
|
||||
@@ -80,6 +137,29 @@ describe("generateOpenApiSpec", () => {
|
||||
});
|
||||
}, 15_000);
|
||||
|
||||
it("documents the public health endpoint at its actual URL", async () => {
|
||||
const spec = await generateSpec();
|
||||
const health = spec.paths?.["/api/health"]?.get;
|
||||
|
||||
expect(health).toMatchObject({
|
||||
operationId: "getHealth",
|
||||
security: [],
|
||||
servers: [{ url: "https://rxresu.me" }],
|
||||
});
|
||||
for (const status of ["200", "503"]) {
|
||||
expect(health?.responses?.[status]).toMatchObject({
|
||||
content: {
|
||||
"application/json": {
|
||||
schema: {
|
||||
required: expect.arrayContaining(["service", "version", "status"]),
|
||||
properties: { version: { type: "string" } },
|
||||
},
|
||||
},
|
||||
},
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
it("uses the canonical input-side ResumeData schema in update requests", async () => {
|
||||
const spec = (await generateSpec()) as GeneratedSpecView;
|
||||
const { $schema: _dialect, ...canonicalInputSchema } = createResumeDataJsonSchema();
|
||||
@@ -92,6 +172,16 @@ describe("generateOpenApiSpec", () => {
|
||||
});
|
||||
});
|
||||
|
||||
it("accepts legacy input with omitted picture fit in the published request schema", async () => {
|
||||
const spec = (await generateSpec()) as GeneratedSpecView;
|
||||
|
||||
expect(spec.components?.schemas?.ResumeData).toMatchObject({
|
||||
properties: {
|
||||
picture: { required: expect.not.arrayContaining(["fit"]) },
|
||||
},
|
||||
});
|
||||
});
|
||||
|
||||
it("publishes the custom-section type and item correlation", async () => {
|
||||
const spec = (await generateSpec()) as GeneratedSpecView;
|
||||
const schema = z.fromJSONSchema(spec.components?.schemas?.ResumeData as Parameters<typeof z.fromJSONSchema>[0]);
|
||||
@@ -115,6 +205,18 @@ describe("generateOpenApiSpec", () => {
|
||||
expect(schema.safeParse(mismatched).success).toBe(false);
|
||||
});
|
||||
|
||||
it("enforces the same submitted bounds as the published request schema", async () => {
|
||||
const spec = (await generateSpec()) as GeneratedSpecView;
|
||||
const published = z.fromJSONSchema(spec.components?.schemas?.ResumeData as Parameters<typeof z.fromJSONSchema>[0]);
|
||||
for (const marginX of [0, 100, -1, 500]) {
|
||||
const data = structuredClone(defaultResumeData);
|
||||
data.metadata.page.marginX = marginX;
|
||||
const expected = marginX === 0 || marginX === 100;
|
||||
expect(published.safeParse(data).success).toBe(expected);
|
||||
expect(writableResumeDataSchema.safeParse(data).success).toBe(expected);
|
||||
}
|
||||
});
|
||||
|
||||
it("does not publish impossible request schemas", async () => {
|
||||
const spec = (await generateSpec()) as GeneratedSpecView;
|
||||
|
||||
|
||||
@@ -1,9 +1,11 @@
|
||||
import type { OpenAPI } from "@orpc/openapi";
|
||||
import { OpenAPIGenerator } from "@orpc/openapi";
|
||||
import { JSON_SCHEMA_INPUT_REGISTRY, ZodToJsonSchemaConverter } from "@orpc/zod/zod4";
|
||||
import { downloadResumePdfProcedure } from "@reactive-resume/api/features/resume/export";
|
||||
import router from "@reactive-resume/api/routers";
|
||||
import { resumeDataSchema } from "@reactive-resume/schema/resume/data";
|
||||
import { createResumeDataJsonSchema } from "@reactive-resume/schema/resume/json-schema";
|
||||
import { writableResumeDataSchema } from "@reactive-resume/schema/resume/write";
|
||||
|
||||
export const openAPIRouter = {
|
||||
...router,
|
||||
@@ -16,6 +18,7 @@ export const openAPIRouter = {
|
||||
const { $schema: _dialect, ...resumeDataInputSchema } = createResumeDataJsonSchema();
|
||||
type ResumeDataInputJsonSchema = Parameters<typeof JSON_SCHEMA_INPUT_REGISTRY.add<typeof resumeDataSchema>>[1];
|
||||
JSON_SCHEMA_INPUT_REGISTRY.add(resumeDataSchema, resumeDataInputSchema as unknown as ResumeDataInputJsonSchema);
|
||||
JSON_SCHEMA_INPUT_REGISTRY.add(writableResumeDataSchema, resumeDataInputSchema as unknown as ResumeDataInputJsonSchema);
|
||||
const importResumeInputSchema = openAPIRouter.resume.import["~orpc"].inputSchema;
|
||||
if (importResumeInputSchema) {
|
||||
JSON_SCHEMA_INPUT_REGISTRY.add(importResumeInputSchema, {
|
||||
@@ -50,19 +53,66 @@ type GenerateOpenApiSpecOptions = {
|
||||
version: string;
|
||||
};
|
||||
|
||||
const healthDependencySchema = {
|
||||
type: "object",
|
||||
properties: {
|
||||
status: { type: "string", enum: ["healthy", "unhealthy"] },
|
||||
latencyMs: { type: "number" },
|
||||
error: { type: "string", description: "Generic failure message. Detailed diagnostics are logged on the server." },
|
||||
},
|
||||
required: ["status", "latencyMs"],
|
||||
additionalProperties: true,
|
||||
} satisfies OpenAPI.SchemaObject;
|
||||
|
||||
const healthResponseSchema = {
|
||||
type: "object",
|
||||
properties: {
|
||||
service: { type: "string", enum: ["reactive-resume"] },
|
||||
version: { type: "string", description: "The running application's build version." },
|
||||
status: { type: "string", enum: ["healthy", "unhealthy"] },
|
||||
timestamp: { type: "string", format: "date-time" },
|
||||
uptime: { type: "string" },
|
||||
database: healthDependencySchema,
|
||||
storage: healthDependencySchema,
|
||||
},
|
||||
required: ["service", "version", "status", "timestamp", "uptime", "database", "storage"],
|
||||
} satisfies OpenAPI.SchemaObject;
|
||||
|
||||
export async function generateOpenApiSpec({ appUrl, version }: GenerateOpenApiSpecOptions) {
|
||||
return await openAPIGenerator.generate(openAPIRouter, {
|
||||
info: {
|
||||
title: "Reactive Resume",
|
||||
version,
|
||||
description: "Reactive Resume API",
|
||||
license: { name: "MIT", url: "https://github.com/amruthpillai/reactive-resume/blob/main/LICENSE" },
|
||||
license: { name: "MIT", url: "https://github.com/reactive-resume/reactive-resume/blob/main/LICENSE" },
|
||||
contact: { name: "Amruth Pillai", email: "hello@amruthpillai.com", url: "https://amruthpillai.com" },
|
||||
},
|
||||
servers: [{ url: `${appUrl}/api/openapi` }],
|
||||
paths: {
|
||||
"/api/health": {
|
||||
get: {
|
||||
operationId: "getHealth",
|
||||
tags: ["System"],
|
||||
summary: "Get application health and version",
|
||||
description: "Checks database and storage availability. Does not require authentication.",
|
||||
servers: [{ url: appUrl }],
|
||||
security: [],
|
||||
responses: {
|
||||
"200": {
|
||||
description: "The application and its dependencies are healthy.",
|
||||
content: { "application/json": { schema: healthResponseSchema } },
|
||||
},
|
||||
"503": {
|
||||
description: "One or more application dependencies are unhealthy.",
|
||||
content: { "application/json": { schema: healthResponseSchema } },
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
externalDocs: { url: "https://docs.rxresu.me", description: "Reactive Resume Documentation" },
|
||||
commonSchemas: {
|
||||
ResumeData: { schema: resumeDataSchema, strategy: "input" },
|
||||
ResumeData: { schema: writableResumeDataSchema, strategy: "input" },
|
||||
},
|
||||
components: {
|
||||
securitySchemes: {
|
||||
|
||||
@@ -0,0 +1,110 @@
|
||||
import type { IncomingHttpHeaders } from "node:http";
|
||||
import { createServer } from "node:http";
|
||||
import { afterAll, beforeAll, beforeEach, expect, it, vi } from "vitest";
|
||||
|
||||
const envMock = vi.hoisted(() => ({
|
||||
APP_URL: "https://resume.example.com",
|
||||
S3_ACCESS_KEY_ID: "test-access-key",
|
||||
S3_SECRET_ACCESS_KEY: "test-secret-key",
|
||||
S3_REGION: "us-east-1",
|
||||
S3_ENDPOINT: "",
|
||||
S3_BUCKET: "test-bucket",
|
||||
S3_FORCE_PATH_STYLE: true,
|
||||
}));
|
||||
vi.mock("@reactive-resume/env/server", () => ({ env: envMock }));
|
||||
|
||||
type StoredObject = { data: Buffer; contentType: string };
|
||||
type StorageRequest = { method: string; path: string; headers: IncomingHttpHeaders };
|
||||
const objects = new Map<string, StoredObject>();
|
||||
const requests: StorageRequest[] = [];
|
||||
|
||||
// Wire-contract stub, not an AWS emulator. It applies the documented BucketOwnerEnforced
|
||||
// PUT rule to real SDK requests: no ACL or bucket-owner-full-control is accepted.
|
||||
// https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-ownership-error-responses.html
|
||||
const server = createServer(async (request, response) => {
|
||||
const path = new URL(request.url ?? "/", "http://localhost").pathname;
|
||||
requests.push({ method: request.method ?? "", path, headers: request.headers });
|
||||
const fail = (status: number, code: string) => {
|
||||
response.writeHead(status, { "Content-Type": "application/xml" });
|
||||
response.end(`<Error><Code>${code}</Code><Message>${code}</Message></Error>`);
|
||||
};
|
||||
// Only checks that the SDK authenticates its requests; this stub does not verify signatures.
|
||||
if (!request.headers.authorization?.startsWith("AWS4-HMAC-SHA256 ")) return fail(403, "AccessDenied");
|
||||
if (request.method === "PUT") {
|
||||
const chunks: Buffer[] = [];
|
||||
for await (const chunk of request) chunks.push(Buffer.from(chunk));
|
||||
const acl = request.headers["x-amz-acl"];
|
||||
if (acl && acl !== "bucket-owner-full-control") return fail(400, "AccessControlListNotSupported");
|
||||
objects.set(path, {
|
||||
data: Buffer.concat(chunks),
|
||||
contentType: request.headers["content-type"] ?? "application/octet-stream",
|
||||
});
|
||||
response.writeHead(200, { ETag: '"test-etag"' });
|
||||
return response.end();
|
||||
}
|
||||
if (request.method === "DELETE") {
|
||||
objects.delete(path);
|
||||
response.writeHead(204);
|
||||
return response.end();
|
||||
}
|
||||
const object = objects.get(path);
|
||||
if (!object) return fail(404, "NoSuchKey");
|
||||
response.writeHead(200, { "Content-Type": object.contentType, "Content-Length": object.data.length });
|
||||
response.end(object.data);
|
||||
});
|
||||
|
||||
let storage: ReturnType<typeof import("@reactive-resume/api/features/storage").getStorageService>;
|
||||
let handleUpload: typeof import("./uploads").handleUpload;
|
||||
|
||||
beforeAll(async () => {
|
||||
await new Promise<void>((resolve) => server.listen(0, "127.0.0.1", resolve));
|
||||
const address = server.address();
|
||||
if (!address || typeof address === "string") throw new Error("Missing stub TCP address");
|
||||
envMock.S3_ENDPOINT = `http://127.0.0.1:${address.port}`;
|
||||
storage = (await import("@reactive-resume/api/features/storage")).getStorageService();
|
||||
({ handleUpload } = await import("./uploads"));
|
||||
});
|
||||
|
||||
beforeEach(() => {
|
||||
objects.clear();
|
||||
requests.length = 0;
|
||||
});
|
||||
|
||||
afterAll(async () => {
|
||||
server.closeAllConnections();
|
||||
await new Promise<void>((resolve, reject) => server.close((error) => (error ? reject(error) : resolve())));
|
||||
});
|
||||
|
||||
it("keeps the ACL-disabled storage health check healthy", async () => {
|
||||
expect(await storage.healthcheck()).toMatchObject({ status: "healthy", type: "s3" });
|
||||
expect(requests.map(({ method }) => method)).toEqual(["PUT", "DELETE"]);
|
||||
expect(objects.size).toBe(0);
|
||||
});
|
||||
|
||||
it("stores images without ACLs and serves them through the signed application proxy", async () => {
|
||||
const key = "uploads/user-1/pictures/photo.png";
|
||||
const data = new Uint8Array([137, 80, 78, 71]);
|
||||
await storage.write({ key, data, contentType: "image/png" });
|
||||
expect(requests[0]?.headers["x-amz-acl"]).toBeUndefined();
|
||||
const direct = await fetch(`${envMock.S3_ENDPOINT}/${envMock.S3_BUCKET}/${key}`);
|
||||
expect(direct.status).toBe(403);
|
||||
const response = await handleUpload(new Request(`${envMock.APP_URL}/api/${key}`));
|
||||
expect(response.status).toBe(200);
|
||||
expect(response.headers.get("Content-Type")).toBe("image/png");
|
||||
expect(new Uint8Array(await response.arrayBuffer())).toEqual(data);
|
||||
expect(requests.at(-1)?.headers.authorization).toMatch(/^AWS4-HMAC-SHA256 /);
|
||||
});
|
||||
|
||||
it("stores private attachments without ACLs while keeping them outside the public proxy", async () => {
|
||||
const key = "uploads/user-1/agent/thread-1/private.txt";
|
||||
const data = new TextEncoder().encode("private attachment");
|
||||
await storage.write({ key, data, contentType: "text/plain", private: true });
|
||||
expect(requests[0]?.headers["x-amz-acl"]).toBeUndefined();
|
||||
const requestCount = requests.length;
|
||||
const response = await handleUpload(new Request(`${envMock.APP_URL}/api/${key}`));
|
||||
expect(response.status).toBe(404);
|
||||
expect(requests).toHaveLength(requestCount);
|
||||
const direct = await fetch(`${envMock.S3_ENDPOINT}/${envMock.S3_BUCKET}/${key}`);
|
||||
expect(direct.status).toBe(403);
|
||||
expect((await storage.read(key))?.data).toEqual(data);
|
||||
});
|
||||
@@ -2,7 +2,7 @@ import fs from "node:fs/promises";
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
const mocks = vi.hoisted(() => ({
|
||||
env: { APP_URL: "https://rxresu.me" },
|
||||
env: { APP_URL: "https://rxresu.me", ROOT_RESUME_ID: undefined as string | undefined },
|
||||
serveStatic: vi.fn((_options?: unknown) => vi.fn()),
|
||||
getPublicResumeSocialMeta: vi.fn(),
|
||||
}));
|
||||
@@ -45,6 +45,7 @@ const staticOptions = mocks.serveStatic.mock.calls[0]?.[0] as StaticOptions | un
|
||||
describe("web app fallback classification", () => {
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
mocks.env.ROOT_RESUME_ID = undefined;
|
||||
vi.mocked(fs.readFile).mockResolvedValue("<html>app</html>");
|
||||
mocks.getPublicResumeSocialMeta.mockResolvedValue(null);
|
||||
});
|
||||
@@ -66,7 +67,7 @@ describe("web app fallback classification", () => {
|
||||
<title>Reactive Resume — A free and open-source resume builder</title>
|
||||
<meta
|
||||
name="description"
|
||||
content="Reactive Resume is a free and open-source resume builder that simplifies the process of creating, updating, and sharing your resume."
|
||||
content="Reactive Resume is a free and open-source resume builder that makes it easy to create, update, and share your resume."
|
||||
>
|
||||
</head>
|
||||
<body><div id="app"></div></body>
|
||||
@@ -151,9 +152,9 @@ describe("web app fallback classification", () => {
|
||||
expect(html).toContain('<link rel="canonical" href="https://rxresu.me/jane/resume">');
|
||||
expect(html).toContain('<meta property="og:type" content="profile">');
|
||||
expect(html).toContain('<meta property="og:title" content="Jane Doe — Staff Engineer">');
|
||||
expect(html).toContain('<meta property="og:image" content="https://rxresu.me/templates/jpg/azurill.jpg">');
|
||||
expect(html).toContain('<meta property="og:image" content="https://rxresu.me/opengraph/banner.jpg">');
|
||||
expect(html).toContain('<meta name="twitter:card" content="summary_large_image">');
|
||||
expect(html).toContain('<meta name="twitter:image" content="https://rxresu.me/templates/jpg/azurill.jpg">');
|
||||
expect(html).toContain('<meta name="twitter:image" content="https://rxresu.me/opengraph/banner.jpg">');
|
||||
});
|
||||
|
||||
it("escapes user-authored values so resume content cannot break out of the attribute", async () => {
|
||||
@@ -289,3 +290,28 @@ describe("web app fallback classification", () => {
|
||||
expect(await unknownResponse.text()).toBe("");
|
||||
});
|
||||
});
|
||||
|
||||
describe("configured root shell", () => {
|
||||
it.each(["GET", "HEAD"])("serves no-store noindex headers for %s", async (method) => {
|
||||
mocks.env.ROOT_RESUME_ID = "private-or-missing-id";
|
||||
const response = await handleWebApp(new Request("https://attacker.example/", { method }));
|
||||
expect(response.headers.get("X-Robots-Tag")).toBe("noindex, follow");
|
||||
expect(response.headers.get("Cache-Control")).toBe("private, no-store");
|
||||
});
|
||||
it("uses configured canonical root without leaking ID or marketing metadata", async () => {
|
||||
mocks.env.ROOT_RESUME_ID = "private-or-missing-id";
|
||||
vi.mocked(fs.readFile).mockResolvedValue(
|
||||
'<html><head><title>Marketing title</title><meta name="description" content="Marketing copy."></head><body></body></html>',
|
||||
);
|
||||
const html = await (
|
||||
await handleWebApp(
|
||||
new Request("https://attacker.example/?id=other", {
|
||||
headers: { host: "attacker.example", "x-forwarded-host": "evil.example" },
|
||||
}),
|
||||
)
|
||||
).text();
|
||||
expect(html).toContain('<link rel="canonical" href="https://rxresu.me/" data-root-resume-shell>');
|
||||
expect(html).toContain('<meta name="robots" content="noindex, follow" data-root-resume-shell>');
|
||||
expect(html).not.toMatch(/private-or-missing-id|attacker|evil|Marketing|application\/ld\+json|timelapse/);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -70,38 +70,36 @@ const BASE_SECURITY_HEADERS = {
|
||||
const ROOT_TITLE = "Reactive Resume — A free and open-source resume builder";
|
||||
// Keep under ~120 characters so Google's mobile SERP snippet is not truncated at 3 lines.
|
||||
const ROOT_DESCRIPTION =
|
||||
"Free, open-source resume builder. Create, update, and share a professional resume in minutes — no ads, no paywall.";
|
||||
"Free, open-source resume builder. Create, update, and share your resume, with no ads and no paywall.";
|
||||
const ROOT_POSTER_PATH = "/videos/timelapse-v1.webp";
|
||||
const ROOT_FAQ_ITEMS = [
|
||||
{
|
||||
question: "Is Reactive Resume really free?",
|
||||
answer:
|
||||
"Yes! Reactive Resume is completely free to use, with no hidden costs, premium tiers, or subscription fees. It's open-source and will always remain free.",
|
||||
"Yes. Reactive Resume is free to use, with no hidden costs, premium tiers, or subscription fees. It's open source, and it will stay free.",
|
||||
},
|
||||
{
|
||||
question: "How is my data protected?",
|
||||
answer:
|
||||
"Your data is stored securely and is never shared with third parties. You can also self-host Reactive Resume on your own servers for complete control over your data.",
|
||||
"Your data is stored securely and never shared with third parties. If you want full control over it, you can self-host Reactive Resume on your own servers.",
|
||||
},
|
||||
{
|
||||
question: "Can I export my resume to PDF?",
|
||||
answer:
|
||||
"Absolutely! You can export your resume to PDF with a single click. The exported PDF maintains all your formatting and styling perfectly.",
|
||||
answer: "Yes. One click exports your resume to PDF, with your formatting and styling intact.",
|
||||
},
|
||||
{
|
||||
question: "Is Reactive Resume available in multiple languages?",
|
||||
answer:
|
||||
"Yes, Reactive Resume is available in multiple languages. You can choose your preferred language in the settings page, or using the language switcher in the top right corner. If you don't see your language, or you would like to improve the existing translations, you can contribute to the translations on Crowdin.",
|
||||
"Yes. Pick your language on the settings page, or with the language switcher in the top right corner. If your language is missing, or the existing translation could be better, you can contribute to the translations on Crowdin.",
|
||||
},
|
||||
{
|
||||
question: "What makes Reactive Resume different from other resume builders?",
|
||||
answer:
|
||||
"Reactive Resume is open-source, privacy-focused, and completely free. Unlike other resume builders, it doesn't show ads, track your data, or limit your features behind a paywall.",
|
||||
"Reactive Resume is open source, private, and free. It shows no ads, doesn't track what you do, and doesn't lock features behind a paywall.",
|
||||
},
|
||||
{
|
||||
question: "How do I share my resume?",
|
||||
answer:
|
||||
"You can share your resume via a unique public URL, protect it with a password, or download it as a PDF to share directly. The choice is yours!",
|
||||
answer: "Share it with a public URL, put a password on that URL, or download the PDF and send it yourself.",
|
||||
},
|
||||
] as const;
|
||||
|
||||
@@ -129,13 +127,13 @@ function createRootSeoMarkup(canonicalUrl: string) {
|
||||
price: "0",
|
||||
priceCurrency: "USD",
|
||||
},
|
||||
codeRepository: "https://github.com/amruthpillai/reactive-resume",
|
||||
codeRepository: "https://github.com/reactive-resume/reactive-resume",
|
||||
},
|
||||
{
|
||||
"@type": "Project",
|
||||
name: "Reactive Resume",
|
||||
url: canonicalUrl,
|
||||
sameAs: ["https://github.com/amruthpillai/reactive-resume"],
|
||||
sameAs: ["https://github.com/reactive-resume/reactive-resume"],
|
||||
},
|
||||
{
|
||||
"@type": "FAQPage",
|
||||
@@ -169,9 +167,9 @@ function createRootSeoMarkup(canonicalUrl: string) {
|
||||
}
|
||||
|
||||
const ATS_CHECKER_TITLE = "ATS Checker - Reactive Resume";
|
||||
// Kept under ~120 characters so Google's mobile SERP snippet is not truncated at 3 lines.
|
||||
// Keep under ~120 characters so Google's mobile SERP snippet is not truncated at 3 lines.
|
||||
const ATS_CHECKER_DESCRIPTION =
|
||||
"Check whether software can read your resume PDF. Runs in your browser, so your file is never uploaded.";
|
||||
"Check whether software can read your resume PDF. Runs entirely in your browser, so your file is never uploaded.";
|
||||
|
||||
function createAtsCheckerSeoMarkup(origin: string) {
|
||||
const canonicalUrl = `${origin}/ats-checker`;
|
||||
@@ -226,7 +224,7 @@ async function createPublicResumeSeoMarkup(pathname: string, origin: string) {
|
||||
if (!meta) return null;
|
||||
|
||||
const canonicalUrl = `${origin}/${username}/${slug}`;
|
||||
const imageUrl = `${origin}/templates/jpg/${meta.template}.jpg`;
|
||||
const imageUrl = `${origin}/opengraph/banner.jpg`;
|
||||
const pageTitle = escapeAttribute(`${meta.name} - Reactive Resume`);
|
||||
const title = escapeAttribute(meta.title);
|
||||
const description = escapeAttribute(meta.description);
|
||||
@@ -260,6 +258,14 @@ export const serveWebDistStatic = serveStatic({
|
||||
});
|
||||
|
||||
function getFallbackResponseHeaders(pathname: string) {
|
||||
if (pathname === "/" && env.ROOT_RESUME_ID?.trim()) {
|
||||
return {
|
||||
"Content-Type": "text/html; charset=UTF-8",
|
||||
"X-Robots-Tag": "noindex, follow",
|
||||
"Cache-Control": "private, no-store",
|
||||
...BASE_SECURITY_HEADERS,
|
||||
};
|
||||
}
|
||||
if (pathname === "/" || indexableAppPaths.has(pathname)) {
|
||||
return { "Content-Type": "text/html; charset=UTF-8", ...BASE_SECURITY_HEADERS };
|
||||
}
|
||||
@@ -301,6 +307,16 @@ export async function handleWebApp(request: Request) {
|
||||
const html = await fs.readFile(indexHtmlPath, "utf-8");
|
||||
const canonicalUrl = new URL("/", env.APP_URL).toString();
|
||||
|
||||
if (pathname === "/" && env.ROOT_RESUME_ID?.trim()) {
|
||||
// Root configuration never discloses a target in the HTML shell. The public API
|
||||
// gates data and browser metadata; shell requests must not count extra views.
|
||||
const shell = html
|
||||
.replace(/<title>[^<]*<\/title>/, "<title>Reactive Resume</title>")
|
||||
.replace(/<meta\s+name="description"[^>]*>/, '<meta name="description" content="">');
|
||||
const markup = `<link rel="canonical" href="${escapeAttribute(canonicalUrl)}" data-root-resume-shell><meta name="robots" content="noindex, follow" data-root-resume-shell>`;
|
||||
return new Response(shell.replace("</head>", `${markup}</head>`), { headers });
|
||||
}
|
||||
|
||||
if (pathname === "/") {
|
||||
return new Response(html.replace("</head>", `${createRootSeoMarkup(canonicalUrl)}</head>`), { headers });
|
||||
}
|
||||
|
||||
@@ -2,8 +2,12 @@
|
||||
"extends": ["//"],
|
||||
"tags": ["app:server", "runtime:server", "role:adapter"],
|
||||
"tasks": {
|
||||
"test": { "env": ["OAUTH_TEST_DATABASE_URL"] },
|
||||
"test:coverage": { "env": ["OAUTH_TEST_DATABASE_URL"] },
|
||||
"test:agent": { "env": ["OAUTH_TEST_DATABASE_URL"] },
|
||||
"test:ci": {
|
||||
"cache": false
|
||||
"cache": false,
|
||||
"env": ["OAUTH_TEST_DATABASE_URL"]
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+1557
-717
File diff suppressed because it is too large
Load Diff
+1521
-681
File diff suppressed because it is too large
Load Diff
+1493
-653
File diff suppressed because it is too large
Load Diff
+1500
-660
File diff suppressed because it is too large
Load Diff
+1495
-655
File diff suppressed because it is too large
Load Diff
+1494
-654
File diff suppressed because it is too large
Load Diff
+1488
-648
File diff suppressed because it is too large
Load Diff
+1488
-648
File diff suppressed because it is too large
Load Diff
+1478
-638
File diff suppressed because it is too large
Load Diff
+1467
-627
File diff suppressed because it is too large
Load Diff
+1463
-623
File diff suppressed because it is too large
Load Diff
+1450
-610
File diff suppressed because it is too large
Load Diff
+1449
-609
File diff suppressed because it is too large
Load Diff
+1460
-620
File diff suppressed because it is too large
Load Diff
+1463
-623
File diff suppressed because it is too large
Load Diff
+1472
-632
File diff suppressed because it is too large
Load Diff
+1466
-626
File diff suppressed because it is too large
Load Diff
+1463
-623
File diff suppressed because it is too large
Load Diff
+1470
-630
File diff suppressed because it is too large
Load Diff
+1468
-628
File diff suppressed because it is too large
Load Diff
+1465
-625
File diff suppressed because it is too large
Load Diff
+1466
-626
File diff suppressed because it is too large
Load Diff
+1479
-639
File diff suppressed because it is too large
Load Diff
+1464
-624
File diff suppressed because it is too large
Load Diff
+1474
-634
File diff suppressed because it is too large
Load Diff
+1475
-635
File diff suppressed because it is too large
Load Diff
+1462
-622
File diff suppressed because it is too large
Load Diff
+1463
-623
File diff suppressed because it is too large
Load Diff
+1465
-625
File diff suppressed because it is too large
Load Diff
+1495
-655
File diff suppressed because it is too large
Load Diff
+1486
-646
File diff suppressed because it is too large
Load Diff
+1484
-644
File diff suppressed because it is too large
Load Diff
+1488
-648
File diff suppressed because it is too large
Load Diff
+1462
-622
File diff suppressed because it is too large
Load Diff
+1483
-643
File diff suppressed because it is too large
Load Diff
+1468
-628
File diff suppressed because it is too large
Load Diff
+1488
-648
File diff suppressed because it is too large
Load Diff
+1488
-648
File diff suppressed because it is too large
Load Diff
+1495
-655
File diff suppressed because it is too large
Load Diff
+1490
-650
File diff suppressed because it is too large
Load Diff
+1484
-644
File diff suppressed because it is too large
Load Diff
+1498
-658
File diff suppressed because it is too large
Load Diff
+1492
-652
File diff suppressed because it is too large
Load Diff
+1508
-668
File diff suppressed because it is too large
Load Diff
+1477
-637
File diff suppressed because it is too large
Load Diff
+1524
-684
File diff suppressed because it is too large
Load Diff
+1469
-629
File diff suppressed because it is too large
Load Diff
+1475
-635
File diff suppressed because it is too large
Load Diff
+1471
-631
File diff suppressed because it is too large
Load Diff
+1474
-634
File diff suppressed because it is too large
Load Diff
+1473
-633
File diff suppressed because it is too large
Load Diff
+1475
-635
File diff suppressed because it is too large
Load Diff
+1537
-697
File diff suppressed because it is too large
Load Diff
+1534
-694
File diff suppressed because it is too large
Load Diff
+1347
-507
File diff suppressed because it is too large
Load Diff
+55
-52
@@ -4,7 +4,7 @@
|
||||
"type": "module",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"build": "rimraf dist && vite build",
|
||||
"build": "vite build",
|
||||
"dev": "vite dev",
|
||||
"serve": "vite preview",
|
||||
"start": "vite preview",
|
||||
@@ -16,30 +16,31 @@
|
||||
"lingui:extract": "lingui extract --clean --overwrite"
|
||||
},
|
||||
"dependencies": {
|
||||
"@ai-sdk/react": "^4.0.86",
|
||||
"@base-ui/react": "^1.7.0",
|
||||
"@better-auth/api-key": "^1.7.2",
|
||||
"@better-auth/infra": "^0.4.3",
|
||||
"@better-auth/oauth-provider": "^1.7.2",
|
||||
"@better-auth/passkey": "^1.7.2",
|
||||
"@ai-sdk/react": "^4.0.105",
|
||||
"@base-ui/react": "^1.8.0",
|
||||
"@better-auth/api-key": "^1.7.5",
|
||||
"@better-auth/infra": "^0.4.9",
|
||||
"@better-auth/oauth-provider": "^1.7.5",
|
||||
"@better-auth/passkey": "^1.7.5",
|
||||
"@codemirror/autocomplete": "^6.20.3",
|
||||
"@codemirror/commands": "^6.11.0",
|
||||
"@codemirror/commands": "^6.11.1",
|
||||
"@codemirror/lang-css": "^6.3.1",
|
||||
"@codemirror/language": "^6.12.4",
|
||||
"@codemirror/lint": "^6.9.7",
|
||||
"@codemirror/search": "^6.7.1",
|
||||
"@codemirror/state": "^6.7.1",
|
||||
"@codemirror/view": "^6.43.9",
|
||||
"@codemirror/search": "^6.7.2",
|
||||
"@codemirror/state": "^6.7.5",
|
||||
"@codemirror/view": "^6.43.12",
|
||||
"@dnd-kit/core": "^6.3.1",
|
||||
"@dnd-kit/sortable": "^10.0.0",
|
||||
"@dnd-kit/utilities": "^3.2.2",
|
||||
"@lingui/core": "^6.6.0",
|
||||
"@lingui/react": "^6.6.0",
|
||||
"@orpc/client": "^1.15.0",
|
||||
"@orpc/server": "^1.15.0",
|
||||
"@orpc/tanstack-query": "^1.15.0",
|
||||
"@fontsource-variable/manrope": "^5.3.0",
|
||||
"@lingui/core": "^6.7.0",
|
||||
"@lingui/react": "^6.7.0",
|
||||
"@orpc/client": "^1.15.1",
|
||||
"@orpc/server": "^1.15.1",
|
||||
"@orpc/tanstack-query": "^1.15.1",
|
||||
"@phosphor-icons/react": "^2.1.10",
|
||||
"@react-pdf/renderer": "^4.8.1",
|
||||
"@react-pdf/renderer": "^4.9.0",
|
||||
"@reactive-resume/ai": "workspace:*",
|
||||
"@reactive-resume/api": "workspace:*",
|
||||
"@reactive-resume/auth": "workspace:*",
|
||||
@@ -54,69 +55,71 @@
|
||||
"@tailwindcss/vite": "^4.3.3",
|
||||
"@tanstack/react-form": "^1.33.5",
|
||||
"@tanstack/react-hotkeys": "^0.10.0",
|
||||
"@tanstack/react-query": "^5.102.6",
|
||||
"@tanstack/react-router": "^1.170.32",
|
||||
"@tiptap/extension-color": "^3.30.5",
|
||||
"@tiptap/extension-highlight": "^3.30.5",
|
||||
"@tiptap/extension-text-align": "^3.30.5",
|
||||
"@tiptap/extension-text-style": "^3.30.5",
|
||||
"@tiptap/pm": "^3.30.5",
|
||||
"@tiptap/react": "^3.30.5",
|
||||
"@tiptap/starter-kit": "^3.30.5",
|
||||
"@tanstack/react-query": "^5.103.1",
|
||||
"@tanstack/react-router": "^1.170.36",
|
||||
"@tiptap/extension-color": "^3.31.3",
|
||||
"@tiptap/extension-heading": "^3.31.3",
|
||||
"@tiptap/extension-highlight": "^3.31.3",
|
||||
"@tiptap/extension-paragraph": "^3.31.3",
|
||||
"@tiptap/extension-table": "^3.31.3",
|
||||
"@tiptap/extension-text-align": "^3.31.3",
|
||||
"@tiptap/extension-text-style": "^3.31.3",
|
||||
"@tiptap/pm": "^3.31.3",
|
||||
"@tiptap/react": "^3.31.3",
|
||||
"@tiptap/starter-kit": "^3.31.3",
|
||||
"@types/js-cookie": "^3.0.6",
|
||||
"@uiw/color-convert": "^2.10.3",
|
||||
"@uiw/react-color-colorful": "^2.10.3",
|
||||
"ai": "^7.0.83",
|
||||
"better-auth": "1.7.2",
|
||||
"ai": "^7.0.102",
|
||||
"better-auth": "1.7.5",
|
||||
"buffer": "^6.0.3",
|
||||
"cmdk": "^1.1.1",
|
||||
"drizzle-orm": "1.0.0-rc.4",
|
||||
"es-toolkit": "^1.51.0",
|
||||
"es-toolkit": "^1.52.0",
|
||||
"fuse.js": "^7.5.0",
|
||||
"immer": "^11.1.18",
|
||||
"js-cookie": "^3.0.8",
|
||||
"motion": "^13.1.1",
|
||||
"pdfjs-dist": "6.2.108",
|
||||
"motion": "^13.4.0",
|
||||
"pdfjs-dist": "6.3.289",
|
||||
"pg": "^8.23.0",
|
||||
"prettier": "^3.9.6",
|
||||
"prettier": "^3.9.7",
|
||||
"qrcode.react": "^4.2.0",
|
||||
"react": "^19.2.8",
|
||||
"react-dom": "^19.2.8",
|
||||
"react": "^19.3.0",
|
||||
"react-dom": "^19.3.0",
|
||||
"react-easy-crop": "^6.2.3",
|
||||
"react-markdown": "^10.1.0",
|
||||
"react-resizable-panels": "^4.12.3",
|
||||
"react-window": "^2.3.0",
|
||||
"react-zoom-pan-pinch": "^4.0.4",
|
||||
"react-resizable-panels": "^4.12.4",
|
||||
"react-window": "^2.3.1",
|
||||
"react-zoom-pan-pinch": "^4.2.0",
|
||||
"remark-gfm": "^4.0.1",
|
||||
"ts-pattern": "^5.9.0",
|
||||
"usehooks-ts": "^3.1.1",
|
||||
"zod": "^4.4.3",
|
||||
"zod": "^4.6.5",
|
||||
"zustand": "^5.0.15"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@babel/core": "^8.0.1",
|
||||
"@lingui/babel-plugin-lingui-macro": "^6.6.0",
|
||||
"@lingui/cli": "^6.6.0",
|
||||
"@lingui/format-po": "^6.6.0",
|
||||
"@lingui/vite-plugin": "^6.6.0",
|
||||
"@babel/core": "^8.0.5",
|
||||
"@lingui/babel-plugin-lingui-macro": "^6.7.0",
|
||||
"@lingui/cli": "^6.7.0",
|
||||
"@lingui/format-po": "^6.7.0",
|
||||
"@lingui/vite-plugin": "^6.7.0",
|
||||
"@reactive-resume/config": "workspace:*",
|
||||
"@rolldown/plugin-babel": "^0.2.3",
|
||||
"@rolldown/plugin-babel": "^0.2.4",
|
||||
"@shadcn/helpers": "^0.2.0",
|
||||
"@tanstack/devtools-vite": "^0.8.5",
|
||||
"@tanstack/react-devtools": "^0.10.12",
|
||||
"@tanstack/react-query-devtools": "^5.102.6",
|
||||
"@tanstack/react-router-devtools": "^1.167.1",
|
||||
"@tanstack/router-plugin": "^1.168.35",
|
||||
"@tanstack/react-query-devtools": "^5.103.1",
|
||||
"@tanstack/react-router-devtools": "^1.167.2",
|
||||
"@tanstack/router-plugin": "^1.168.38",
|
||||
"@types/babel__core": "^7.20.5",
|
||||
"@types/pg": "^8.23.1",
|
||||
"@types/react": "^19.2.18",
|
||||
"@types/react-dom": "^19.2.5",
|
||||
"@types/react": "^19.3.0",
|
||||
"@types/react-dom": "^19.3.0",
|
||||
"@typescript/native-preview": "7.0.0-dev.20260707.2",
|
||||
"@vitejs/plugin-react": "^6.1.0",
|
||||
"@vitejs/plugin-react": "^6.1.1",
|
||||
"babel-plugin-macros": "^3.1.0",
|
||||
"babel-plugin-react-compiler": "^1.0.0",
|
||||
"rimraf": "^6.1.3",
|
||||
"typescript": "^7.0.2",
|
||||
"vite": "^8.2.2"
|
||||
"vite": "^8.3.0"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -15,13 +15,13 @@
|
||||
{
|
||||
"guid": "reactive-resume",
|
||||
"name": "Reactive Resume",
|
||||
"description": "A free and open-source resume builder that simplifies the process of creating, updating, and sharing your resume.",
|
||||
"description": "A free and open-source resume builder that makes it easy to create, update, and share your resume.",
|
||||
"webpageUrl": {
|
||||
"url": "https://rxresu.me"
|
||||
},
|
||||
"repositoryUrl": {
|
||||
"url": "https://github.com/amruthpillai/reactive-resume",
|
||||
"wellKnown": "https://github.com/amruthpillai/reactive-resume/blob/main/.github/.well-known/funding-manifest-urls"
|
||||
"url": "https://github.com/reactive-resume/reactive-resume",
|
||||
"wellKnown": "https://github.com/reactive-resume/reactive-resume/blob/main/.github/.well-known/funding-manifest-urls"
|
||||
},
|
||||
"licenses": ["spdx:MIT"],
|
||||
"tags": ["data", "design", "productivity", "resume-builder"]
|
||||
|
||||
@@ -1,55 +0,0 @@
|
||||
<svg role="img" aria-labelledby="atlas-cloud-logo-title" id="Layer_1" data-name="Layer 1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" viewBox="0 0 1224 792">
|
||||
<title id="atlas-cloud-logo-title">Atlas Cloud</title>
|
||||
<defs>
|
||||
<style>
|
||||
.cls-1 {
|
||||
clip-path: url(#clippath);
|
||||
}
|
||||
|
||||
.cls-2 {
|
||||
fill: none;
|
||||
}
|
||||
|
||||
.cls-2, .cls-3 {
|
||||
stroke-width: 0px;
|
||||
}
|
||||
|
||||
.cls-4 {
|
||||
clip-path: url(#clippath-1);
|
||||
}
|
||||
|
||||
.cls-5 {
|
||||
clip-path: url(#clippath-2);
|
||||
}
|
||||
|
||||
.cls-3 {
|
||||
fill: #000;
|
||||
}
|
||||
</style>
|
||||
<clipPath id="clippath">
|
||||
<rect class="cls-2" x="20.73" y="315.14" width="1182.55" height="161.72"/>
|
||||
</clipPath>
|
||||
<clipPath id="clippath-1">
|
||||
<rect class="cls-2" x="20.73" y="315.14" width="1182.55" height="161.72"/>
|
||||
</clipPath>
|
||||
<clipPath id="clippath-2">
|
||||
<rect class="cls-2" x="20.73" y="315.14" width="1182.55" height="161.72"/>
|
||||
</clipPath>
|
||||
</defs>
|
||||
<g class="cls-1">
|
||||
<path class="cls-3" d="M104.38,315.14L20.73,476.86c38.73-15.32,70.03-17.6,98.12-16.26l-12.85-28.4c-5.63-.57-21.86-.57-29.57,1.45l27.95-62.14s42.06,91.31,42.13,91.32c8.09,1.27,29.8,8.55,41.52,14.03l-83.66-161.72Z"/>
|
||||
</g>
|
||||
<polygon class="cls-3" points="207.87 323.37 207.87 361.57 189.68 361.57 189.68 381.76 207.87 381.76 207.87 471.35 234.07 471.35 234.07 381.76 252.87 381.76 252.87 361.57 234.07 361.57 234.07 323.37 207.87 323.37"/>
|
||||
<rect class="cls-3" x="268.07" y="323.37" width="26.19" height="147.98"/>
|
||||
<g class="cls-4">
|
||||
<path class="cls-3" d="M340.48,416.95c0,13.6,9.79,33.39,33.39,33.39,14.6,0,24.2-7.6,29.2-17.59,2.6-4.8,3.8-10,4.2-15.4.2-5.2-.8-10.6-3-15.4-4.6-10.4-14.8-19.4-30.6-19.4-21.2,0-33.19,17.2-33.19,34.19v.2ZM433.26,471.35h-26.19v-15.8c-7,12.8-21.6,19.2-36.99,19.2-35.2,0-55.8-27.4-55.8-58.4,0-34.6,25-58.19,55.8-58.19,20,0,32.19,10.6,36.99,19.4v-16h26.19v109.78Z"/>
|
||||
<path class="cls-3" d="M506.87,391.16c-.2-5.8-3.2-11.8-13.4-11.8-8.8,0-12.99,5.6-12.99,11,.2,7,8.2,10.79,18.6,13.8,17.6,4.8,36.6,10,36.8,33.59.4,22.6-18.6,36.99-41.59,36.99-17,0-40-8.8-41.99-35.39h26.19c1,11.8,11.2,14.2,16.2,14.2,8.2,0,15.2-5.4,15-12.8,0-9.4-8.2-12-28.4-18.99-14.8-4.6-26.79-12.8-26.99-28.6,0-21.6,18.19-35,39.39-35,14.8,0,36.8,6.6,39,33h-25.8Z"/>
|
||||
<path class="cls-3" d="M760.26,421.76c-9,30.59-37.8,52.39-72.39,52.39-45.19,0-77.59-35.8-77.59-76.99s30.59-76.58,77.39-76.58c42.59.2,66.79,31.59,72.59,53.19h-31.4c-4.6-10.19-17.8-26.79-41.39-26.99-28.8,0-47.39,24.2-47.39,50.39s19.4,50.79,47.6,50.79c26.39,0,38.39-20.8,41.19-26.19h31.4Z"/>
|
||||
</g>
|
||||
<rect class="cls-3" x="779.68" y="323.37" width="26.19" height="147.98"/>
|
||||
<g class="cls-5">
|
||||
<path class="cls-3" d="M852.09,416.56c0,19.2,14.59,33.39,32.59,33.39s32.4-14.2,32.4-33.6-14.4-33.59-32.4-33.59-32.59,14.2-32.59,33.59v.2ZM825.89,416.15c0-28,20.6-57.79,58.79-57.79s58.79,29.79,58.79,57.99-20.59,58.19-58.79,58.19-58.79-29.79-58.79-58.19v-.2Z"/>
|
||||
<path class="cls-3" d="M1064.87,471.35h-24.6v-14.6c-4.6,8.6-14.4,18.2-34.19,18-36-.2-42.79-27.6-42.79-46.8v-66.39h26.19v59.79c0,16.2,5.4,28.99,23.99,28.8,18.8,0,25.2-12.4,25.2-28v-60.59h26.2v109.78Z"/>
|
||||
<path class="cls-3" d="M1111.28,416.35c0,18.6,13.4,33.8,33.59,33.8,9.6,0,18.2-3.8,24.4-10,6.2-6.2,9.8-14.8,9.39-24.4,0-9.6-3.8-17.8-9.8-23.6-6-6-14.39-9.6-23.79-9.6-21.4,0-33.8,16.4-33.8,33.59v.2ZM1203.27,471.35h-25v-15.8c-4.8,8.2-15.2,19.2-37.6,19.2-33.79,0-55.59-26.4-55.59-58.4,0-35.59,25.4-58.19,55.19-58.19,21,0,32.8,11.19,36.8,17.59v-52.39h26.2v147.98Z"/>
|
||||
</g>
|
||||
</svg>
|
||||
|
Before Width: | Height: | Size: 3.5 KiB |
@@ -1,55 +0,0 @@
|
||||
<svg role="img" aria-labelledby="atlas-cloud-logo-title" id="Layer_1" data-name="Layer 1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" viewBox="0 0 1224 792">
|
||||
<title id="atlas-cloud-logo-title">Atlas Cloud</title>
|
||||
<defs>
|
||||
<style>
|
||||
.cls-1 {
|
||||
clip-path: url(#clippath);
|
||||
}
|
||||
|
||||
.cls-2 {
|
||||
fill: none;
|
||||
}
|
||||
|
||||
.cls-2, .cls-3 {
|
||||
stroke-width: 0px;
|
||||
}
|
||||
|
||||
.cls-4 {
|
||||
clip-path: url(#clippath-1);
|
||||
}
|
||||
|
||||
.cls-5 {
|
||||
clip-path: url(#clippath-2);
|
||||
}
|
||||
|
||||
.cls-3 {
|
||||
fill: #fff;
|
||||
}
|
||||
</style>
|
||||
<clipPath id="clippath">
|
||||
<rect class="cls-2" x="20.73" y="315.14" width="1182.55" height="161.72"/>
|
||||
</clipPath>
|
||||
<clipPath id="clippath-1">
|
||||
<rect class="cls-2" x="20.73" y="315.14" width="1182.55" height="161.72"/>
|
||||
</clipPath>
|
||||
<clipPath id="clippath-2">
|
||||
<rect class="cls-2" x="20.73" y="315.14" width="1182.55" height="161.72"/>
|
||||
</clipPath>
|
||||
</defs>
|
||||
<g class="cls-1">
|
||||
<path class="cls-3" d="M104.38,315.14L20.73,476.86c38.73-15.32,70.03-17.6,98.12-16.26l-12.85-28.4c-5.63-.57-21.86-.57-29.57,1.45l27.95-62.14s42.06,91.31,42.13,91.32c8.09,1.27,29.8,8.55,41.52,14.03l-83.66-161.72Z"/>
|
||||
</g>
|
||||
<polygon class="cls-3" points="207.87 323.37 207.87 361.57 189.68 361.57 189.68 381.76 207.87 381.76 207.87 471.35 234.07 471.35 234.07 381.76 252.87 381.76 252.87 361.57 234.07 361.57 234.07 323.37 207.87 323.37"/>
|
||||
<rect class="cls-3" x="268.07" y="323.37" width="26.19" height="147.98"/>
|
||||
<g class="cls-4">
|
||||
<path class="cls-3" d="M340.48,416.95c0,13.6,9.79,33.39,33.39,33.39,14.6,0,24.2-7.6,29.2-17.59,2.6-4.8,3.8-10,4.2-15.4.2-5.2-.8-10.6-3-15.4-4.6-10.4-14.8-19.4-30.6-19.4-21.2,0-33.19,17.2-33.19,34.19v.2ZM433.26,471.35h-26.19v-15.8c-7,12.8-21.6,19.2-36.99,19.2-35.2,0-55.8-27.4-55.8-58.4,0-34.6,25-58.19,55.8-58.19,20,0,32.19,10.6,36.99,19.4v-16h26.19v109.78Z"/>
|
||||
<path class="cls-3" d="M506.87,391.16c-.2-5.8-3.2-11.8-13.4-11.8-8.8,0-12.99,5.6-12.99,11,.2,7,8.2,10.79,18.6,13.8,17.6,4.8,36.6,10,36.8,33.59.4,22.6-18.6,36.99-41.59,36.99-17,0-40-8.8-41.99-35.39h26.19c1,11.8,11.2,14.2,16.2,14.2,8.2,0,15.2-5.4,15-12.8,0-9.4-8.2-12-28.4-18.99-14.8-4.6-26.79-12.8-26.99-28.6,0-21.6,18.19-35,39.39-35,14.8,0,36.8,6.6,39,33h-25.8Z"/>
|
||||
<path class="cls-3" d="M760.26,421.76c-9,30.59-37.8,52.39-72.39,52.39-45.19,0-77.59-35.8-77.59-76.99s30.59-76.58,77.39-76.58c42.59.2,66.79,31.59,72.59,53.19h-31.4c-4.6-10.19-17.8-26.79-41.39-26.99-28.8,0-47.39,24.2-47.39,50.39s19.4,50.79,47.6,50.79c26.39,0,38.39-20.8,41.19-26.19h31.4Z"/>
|
||||
</g>
|
||||
<rect class="cls-3" x="779.68" y="323.37" width="26.19" height="147.98"/>
|
||||
<g class="cls-5">
|
||||
<path class="cls-3" d="M852.09,416.56c0,19.2,14.59,33.39,32.59,33.39s32.4-14.2,32.4-33.6-14.4-33.59-32.4-33.59-32.59,14.2-32.59,33.59v.2ZM825.89,416.15c0-28,20.6-57.79,58.79-57.79s58.79,29.79,58.79,57.99-20.59,58.19-58.79,58.19-58.79-29.79-58.79-58.19v-.2Z"/>
|
||||
<path class="cls-3" d="M1064.87,471.35h-24.6v-14.6c-4.6,8.6-14.4,18.2-34.19,18-36-.2-42.79-27.6-42.79-46.8v-66.39h26.19v59.79c0,16.2,5.4,28.99,23.99,28.8,18.8,0,25.2-12.4,25.2-28v-60.59h26.2v109.78Z"/>
|
||||
<path class="cls-3" d="M1111.28,416.35c0,18.6,13.4,33.8,33.59,33.8,9.6,0,18.2-3.8,24.4-10,6.2-6.2,9.8-14.8,9.39-24.4,0-9.6-3.8-17.8-9.8-23.6-6-6-14.39-9.6-23.79-9.6-21.4,0-33.8,16.4-33.8,33.59v.2ZM1203.27,471.35h-25v-15.8c-4.8,8.2-15.2,19.2-37.6,19.2-33.79,0-55.59-26.4-55.59-58.4,0-35.59,25.4-58.19,55.19-58.19,21,0,32.8,11.19,36.8,17.59v-52.39h26.2v147.98Z"/>
|
||||
</g>
|
||||
</svg>
|
||||
|
Before Width: | Height: | Size: 3.5 KiB |
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user