mirror of
https://github.com/AmruthPillai/Reactive-Resume.git
synced 2026-09-30 00:34:28 +10:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1fc835e5f2 | ||
|
|
a7f1829484 | ||
|
|
328bf73cee | ||
|
|
1b78e546e2 | ||
|
|
fb756026fa | ||
|
|
73e7a3cb6d | ||
|
|
685fcab605 | ||
|
|
6db26e9b5c | ||
|
|
2b31d70a8a | ||
|
|
d0d20ce0fd | ||
|
|
b48a9c2142 | ||
|
|
0cb83602f5 | ||
|
|
712298843b | ||
|
|
8c40313980 | ||
|
|
73ed3f9b03 | ||
|
|
f0bc26cb3d | ||
|
|
0ac320b0e9 | ||
|
|
d3131e0977 | ||
|
|
28d0170b05 | ||
|
|
ac69dd3f1a | ||
|
|
3d4ae8679a | ||
|
|
4fde62df6d | ||
|
|
b5ff720f9d | ||
|
|
b953435f2c | ||
|
|
a30bf371ff | ||
|
|
582a6fb429 | ||
|
|
24d9e5fb5c | ||
|
|
2a2d08a8d2 | ||
|
|
b42eb6ec06 | ||
|
|
fbf1f8fbac | ||
|
|
232f48578b | ||
|
|
e6a6bf0e6a | ||
|
|
96c7142fbc | ||
|
|
3c5908819c | ||
|
|
3e129c9d9d | ||
|
|
fd3494ccac | ||
|
|
f89acb4368 | ||
|
|
08e61ded7b | ||
|
|
f1d5c6bab4 | ||
|
|
e3717251cb | ||
|
|
30b21fa1e3 | ||
|
|
d77cb93494 | ||
|
|
ce996349fa | ||
|
|
a62ee22f20 | ||
|
|
0a4608bf9d | ||
|
|
9550910f17 | ||
|
|
4076b1a523 | ||
|
|
9699dbf2d8 | ||
|
|
31d6ee6251 | ||
|
|
d9fdf7a30a | ||
|
|
81341a107f | ||
|
|
3fc0896a34 | ||
|
|
7aaed8e30b | ||
|
|
730f795073 | ||
|
|
dc8f9787a4 | ||
|
|
742526af53 | ||
|
|
812d396120 | ||
|
|
1106562169 | ||
|
|
607eafd3e8 | ||
|
|
ffe889b832 | ||
|
|
51ac77295e | ||
|
|
c0c658c00c | ||
|
|
6416da28a4 | ||
|
|
614a1ff9df | ||
|
|
4f60856706 | ||
|
|
ad91a0838c | ||
|
|
15d6443b4f | ||
|
|
1f8c46b4f1 | ||
|
|
de9a6dcfad | ||
|
|
e19f706efd |
+23
-2
@@ -13,11 +13,22 @@ APP_URL="http://localhost:3000"
|
||||
# Unset or blank keeps the marketing home. Restart after changes.
|
||||
# ROOT_RESUME_ID=
|
||||
|
||||
# Vercel: APP_URL can be omitted; production uses VERCEL_PROJECT_PRODUCTION_URL.
|
||||
|
||||
# --- Database (PostgreSQL) ---
|
||||
# PostgreSQL connection URL. In Docker Compose, the hostname is usually `postgres`;
|
||||
# when running directly on your machine, `localhost` is typical.
|
||||
DATABASE_URL="postgresql://postgres:postgres@postgres:5432/postgres"
|
||||
|
||||
# Optional direct connection for migrations (Neon: DATABASE_URL_UNPOOLED alias).
|
||||
# DATABASE_MIGRATION_URL=""
|
||||
# DATABASE_POOL_MAX="10"
|
||||
|
||||
# When "true", the server refuses to boot if the live database schema has drifted from
|
||||
# the migration ledger (e.g. a table dropped outside migrations). Default "false" logs
|
||||
# the drift loudly at startup and continues.
|
||||
STRICT_SCHEMA_CHECK="false"
|
||||
|
||||
# --- Authentication ---
|
||||
# Generated using `openssl rand -hex 32`
|
||||
AUTH_SECRET="change-me-to-a-secure-secret-key-in-production"
|
||||
@@ -66,7 +77,15 @@ SMTP_FROM="Reactive Resume <noreply@rxresu.me>"
|
||||
SMTP_SECURE="false"
|
||||
|
||||
# --- Storage (optional) ---
|
||||
# If all S3 keys are disabled, the app uses local filesystem storage instead.
|
||||
# Backend defaults to S3 when all credentials are present, otherwise local.
|
||||
# Vercel defaults to private Blob. Explicit selection: local, s3, blob.
|
||||
# STORAGE_BACKEND="local"
|
||||
# BLOB_READ_WRITE_TOKEN=""
|
||||
# BLOB_STORE_ID=""
|
||||
# DEPLOYMENT_NAMESPACE="default"
|
||||
# Vercel previews need isolated resources before setting ALLOW_PREVIEW_MIGRATIONS=true.
|
||||
|
||||
# If all S3 keys are disabled, Docker uses local filesystem storage instead.
|
||||
# Make sure to mount this directory to a volume or the host filesystem to ensure data integrity.
|
||||
# LOCAL_STORAGE_PATH overrides where local uploads/cache are written.
|
||||
# Defaults to /app/data in the official Docker image; in dev, defaults to <workspace>/data.
|
||||
@@ -81,7 +100,9 @@ S3_BUCKET="reactive-resume"
|
||||
S3_FORCE_PATH_STYLE="true"
|
||||
|
||||
# --- AI Agent Workspace (optional) ---
|
||||
# Required only for the authenticated /agent workspace and saved AI providers.
|
||||
# Required for the authenticated /agent workspace and saved AI providers.
|
||||
# Redis also shares rate limits, resume events, cancellation and view deduplication.
|
||||
# Vercel Upstash KV_URL is accepted as an alias for REDIS_URL.
|
||||
REDIS_URL="redis://redis:6379"
|
||||
ENCRYPTION_SECRET="change-me-to-a-secure-agent-secret-in-production"
|
||||
|
||||
|
||||
@@ -20,8 +20,8 @@
|
||||
"url": "https://rxresu.me"
|
||||
},
|
||||
"repositoryUrl": {
|
||||
"url": "https://github.com/amruthpillai/reactive-resume",
|
||||
"wellKnown": "https://github.com/amruthpillai/reactive-resume/blob/main/.github/.well-known/funding-manifest-urls"
|
||||
"url": "https://github.com/reactive-resume/reactive-resume",
|
||||
"wellKnown": "https://github.com/reactive-resume/reactive-resume/blob/main/.github/.well-known/funding-manifest-urls"
|
||||
},
|
||||
"licenses": ["spdx:MIT"],
|
||||
"tags": ["data", "design", "productivity", "resume-builder"]
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
blank_issues_enabled: false
|
||||
contact_links:
|
||||
- name: Questions and support
|
||||
url: https://github.com/amruthpillai/reactive-resume/discussions/categories/q-a
|
||||
url: https://github.com/reactive-resume/reactive-resume/discussions/categories/q-a
|
||||
about: Get help with setup, configuration, and using Reactive Resume.
|
||||
- name: Security vulnerability
|
||||
url: https://github.com/amruthpillai/reactive-resume/security/advisories/new
|
||||
url: https://github.com/reactive-resume/reactive-resume/security/advisories/new
|
||||
about: Report security vulnerabilities privately.
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
self-hosted-runner:
|
||||
labels:
|
||||
- blacksmith-2vcpu-ubuntu-2404
|
||||
- blacksmith-32vcpu-ubuntu-2404
|
||||
- blacksmith-32vcpu-ubuntu-2404-arm
|
||||
@@ -13,12 +13,17 @@ env:
|
||||
|
||||
jobs:
|
||||
autofix:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-32vcpu-ubuntu-2404' || 'ubuntu-latest' }}
|
||||
|
||||
steps:
|
||||
- name: Checkout Repository
|
||||
if: ${{ vars.USE_BLACKSMITH != 'true' }}
|
||||
uses: actions/checkout@v6
|
||||
|
||||
- name: Checkout Repository (Blacksmith)
|
||||
if: ${{ vars.USE_BLACKSMITH == 'true' }}
|
||||
uses: useblacksmith/checkout@v1
|
||||
|
||||
- name: Check for merge conflict markers
|
||||
run: |
|
||||
if git grep -nEI '<{7} |>{7} |^={7}$' -- ':(exclude)*.md' ':(exclude)*.mdx'; then
|
||||
@@ -32,7 +37,7 @@ jobs:
|
||||
- name: Setup Node
|
||||
uses: actions/setup-node@v6
|
||||
with:
|
||||
node-version: "lts/*"
|
||||
node-version-file: ".nvmrc"
|
||||
cache: "pnpm"
|
||||
|
||||
- name: Install Dependencies
|
||||
|
||||
@@ -10,7 +10,7 @@ concurrency:
|
||||
|
||||
jobs:
|
||||
crowdin-sync:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-2vcpu-ubuntu-2404' || 'ubuntu-latest' }}
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
@@ -18,8 +18,16 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout Repository
|
||||
if: ${{ vars.USE_BLACKSMITH != 'true' }}
|
||||
uses: actions/checkout@v6
|
||||
|
||||
# The Crowdin action runs in a container that cannot reach the git mirror mount, so copy its objects.
|
||||
- name: Checkout Repository (Blacksmith)
|
||||
if: ${{ vars.USE_BLACKSMITH == 'true' }}
|
||||
uses: useblacksmith/checkout@v1
|
||||
with:
|
||||
dissociate: true
|
||||
|
||||
- name: Sync Translations from Crowdin
|
||||
uses: crowdin/github-action@v2
|
||||
with:
|
||||
|
||||
@@ -2,6 +2,11 @@ name: Build Docker Image
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
release:
|
||||
description: Publish release aliases and redeploy production (false runs a cache-only build, then publishes a canary)
|
||||
type: boolean
|
||||
default: false
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
@@ -13,30 +18,39 @@ concurrency:
|
||||
cancel-in-progress: true
|
||||
|
||||
env:
|
||||
IMAGE: ${{ github.repository }}
|
||||
GHCR_IMAGE: ghcr.io/${{ github.repository }}
|
||||
DOCKER_IMAGE: docker.io/amruthpillai/reactive-resume
|
||||
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
|
||||
|
||||
jobs:
|
||||
mode:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-2vcpu-ubuntu-2404' || 'ubuntu-latest' }}
|
||||
|
||||
outputs:
|
||||
nightly: ${{ steps.mode.outputs.nightly }}
|
||||
release: ${{ steps.mode.outputs.release }}
|
||||
matrix: ${{ steps.mode.outputs.matrix }}
|
||||
canary: ${{ steps.mode.outputs.canary }}
|
||||
|
||||
steps:
|
||||
- name: Determine publishing mode
|
||||
id: mode
|
||||
env:
|
||||
EVENT_NAME: ${{ github.event_name }}
|
||||
GIT_REF: ${{ github.ref }}
|
||||
RELEASE: ${{ inputs.release }}
|
||||
run: |
|
||||
if [[ "${{ github.event_name }}" == "push" && "${{ github.ref }}" == "refs/heads/main" ]]; then
|
||||
if [[ "$EVENT_NAME" == "push" && "$GIT_REF" == "refs/heads/main" ]]; then
|
||||
echo "nightly=true" >> "$GITHUB_OUTPUT"
|
||||
echo "release=false" >> "$GITHUB_OUTPUT"
|
||||
echo 'matrix={"include":[{"platform":"linux/amd64","runner":"ubuntu-latest","arch":"amd64"}]}' >> "$GITHUB_OUTPUT"
|
||||
echo "canary=false" >> "$GITHUB_OUTPUT"
|
||||
elif [[ "$EVENT_NAME" == "workflow_dispatch" && "$RELEASE" != "true" ]]; then
|
||||
echo "nightly=false" >> "$GITHUB_OUTPUT"
|
||||
echo "release=false" >> "$GITHUB_OUTPUT"
|
||||
echo "canary=true" >> "$GITHUB_OUTPUT"
|
||||
else
|
||||
echo "nightly=false" >> "$GITHUB_OUTPUT"
|
||||
echo "release=true" >> "$GITHUB_OUTPUT"
|
||||
echo 'matrix={"include":[{"platform":"linux/amd64","runner":"ubuntu-latest","arch":"amd64"},{"platform":"linux/arm64","runner":"ubuntu-24.04-arm","arch":"arm64"}]}' >> "$GITHUB_OUTPUT"
|
||||
echo "canary=false" >> "$GITHUB_OUTPUT"
|
||||
fi
|
||||
|
||||
build:
|
||||
@@ -44,7 +58,14 @@ jobs:
|
||||
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix: ${{ fromJSON(needs.mode.outputs.matrix) }}
|
||||
matrix:
|
||||
include:
|
||||
- platform: linux/amd64
|
||||
runner: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-32vcpu-ubuntu-2404' || 'ubuntu-latest' }}
|
||||
arch: amd64
|
||||
- platform: linux/arm64
|
||||
runner: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-32vcpu-ubuntu-2404-arm' || 'ubuntu-24.04-arm' }}
|
||||
arch: arm64
|
||||
|
||||
runs-on: ${{ matrix.runner }}
|
||||
timeout-minutes: 30
|
||||
@@ -57,16 +78,53 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout Repository
|
||||
if: ${{ vars.USE_BLACKSMITH != 'true' }}
|
||||
uses: actions/checkout@v6
|
||||
|
||||
- name: Get version from package.json
|
||||
id: version
|
||||
run: echo "version=$(jq -r .version package.json)" >> "$GITHUB_OUTPUT"
|
||||
- name: Checkout Repository (Blacksmith)
|
||||
if: ${{ vars.USE_BLACKSMITH == 'true' }}
|
||||
uses: useblacksmith/checkout@v1
|
||||
|
||||
- name: Setup Docker Buildx
|
||||
if: ${{ vars.USE_BLACKSMITH != 'true' }}
|
||||
uses: docker/setup-buildx-action@v4
|
||||
|
||||
# Persists BuildKit layers and the Dockerfile's pnpm cache mounts between runs, one cache per architecture.
|
||||
- name: Setup Docker Builder (Blacksmith)
|
||||
if: ${{ vars.USE_BLACKSMITH == 'true' }}
|
||||
uses: useblacksmith/setup-docker-builder@v2
|
||||
with:
|
||||
cache-key: Dockerfile-${{ matrix.arch }}
|
||||
|
||||
- ®istries
|
||||
name: Determine registries
|
||||
id: registries
|
||||
env:
|
||||
DOCKER_USERNAME: ${{ secrets.DOCKER_USERNAME }}
|
||||
DOCKER_PASSWORD: ${{ secrets.DOCKER_PASSWORD }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
dockerhub=false
|
||||
ghcr_image="${GHCR_IMAGE,,}"
|
||||
docker_image="${DOCKER_IMAGE,,}"
|
||||
images="$ghcr_image"
|
||||
if [[ -n "$DOCKER_USERNAME" && -n "$DOCKER_PASSWORD" ]]; then
|
||||
dockerhub=true
|
||||
images="${images}"$'\n'"$docker_image"
|
||||
fi
|
||||
|
||||
{
|
||||
echo "ghcr_image=$ghcr_image"
|
||||
echo "docker_image=$docker_image"
|
||||
echo "images<<EOF"
|
||||
echo "$images"
|
||||
echo "EOF"
|
||||
echo "dockerhub=$dockerhub"
|
||||
} >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Login to Docker Hub
|
||||
if: ${{ steps.registries.outputs.dockerhub == 'true' }}
|
||||
uses: docker/login-action@v4
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
@@ -83,16 +141,28 @@ jobs:
|
||||
id: meta
|
||||
uses: docker/metadata-action@v6
|
||||
with:
|
||||
images: |
|
||||
ghcr.io/${{ env.IMAGE }}
|
||||
docker.io/${{ env.IMAGE }}
|
||||
images: ${{ steps.registries.outputs.images }}
|
||||
tags: |
|
||||
type=sha,prefix=sha-,suffix=-${{ matrix.arch }}
|
||||
|
||||
- name: Cache-only smoke build
|
||||
if: ${{ needs.mode.outputs.canary == 'true' && vars.USE_BLACKSMITH != 'true' }}
|
||||
uses: docker/build-push-action@v7
|
||||
with: &cache-only-build
|
||||
context: .
|
||||
platforms: ${{ matrix.platform }}
|
||||
outputs: type=cacheonly
|
||||
|
||||
- name: Cache-only smoke build (Blacksmith)
|
||||
if: ${{ needs.mode.outputs.canary == 'true' && vars.USE_BLACKSMITH == 'true' }}
|
||||
uses: useblacksmith/build-push-action@v2
|
||||
with: *cache-only-build
|
||||
|
||||
- name: Build and Push by Digest
|
||||
id: build
|
||||
if: ${{ vars.USE_BLACKSMITH != 'true' }}
|
||||
uses: docker/build-push-action@v7
|
||||
with:
|
||||
with: &build-push
|
||||
context: .
|
||||
sbom: true
|
||||
push: true
|
||||
@@ -101,13 +171,17 @@ jobs:
|
||||
tags: ${{ steps.meta.outputs.tags }}
|
||||
labels: ${{ steps.meta.outputs.labels }}
|
||||
annotations: ${{ steps.meta.outputs.annotations }}
|
||||
cache-from: type=gha,scope=${{ env.IMAGE }}-${{ matrix.arch }}
|
||||
cache-to: type=gha,mode=max,scope=${{ env.IMAGE }}-${{ matrix.arch }}
|
||||
|
||||
- name: Build and Push by Digest (Blacksmith)
|
||||
id: build-blacksmith
|
||||
if: ${{ vars.USE_BLACKSMITH == 'true' }}
|
||||
uses: useblacksmith/build-push-action@v2
|
||||
with: *build-push
|
||||
|
||||
- name: Export digest
|
||||
run: |
|
||||
mkdir -p /tmp/digests
|
||||
digest="${{ steps.build.outputs.digest }}"
|
||||
digest="${{ steps.build.outputs.digest || steps.build-blacksmith.outputs.digest }}"
|
||||
touch "/tmp/digests/${digest#sha256:}"
|
||||
|
||||
- name: Upload digest
|
||||
@@ -123,7 +197,11 @@ jobs:
|
||||
- mode
|
||||
- build
|
||||
timeout-minutes: 30
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-2vcpu-ubuntu-2404' || 'ubuntu-latest' }}
|
||||
|
||||
env:
|
||||
DEPLOY: ${{ secrets.SSH_KEY != '' && secrets.SSH_HOST != '' && secrets.SSH_USER != '' }}
|
||||
PURGE_CLOUDFLARE: ${{ secrets.CLOUDFLARE_ZONE_ID != '' && secrets.CLOUDFLARE_API_TOKEN != '' }}
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
@@ -133,11 +211,17 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout Repository
|
||||
if: ${{ vars.USE_BLACKSMITH != 'true' }}
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
with: &checkout-package-json
|
||||
sparse-checkout: package.json
|
||||
sparse-checkout-cone-mode: false
|
||||
|
||||
- name: Checkout Repository (Blacksmith)
|
||||
if: ${{ vars.USE_BLACKSMITH == 'true' }}
|
||||
uses: useblacksmith/checkout@v1
|
||||
with: *checkout-package-json
|
||||
|
||||
- name: Get version from package.json
|
||||
id: version
|
||||
run: echo "version=$(jq -r .version package.json)" >> "$GITHUB_OUTPUT"
|
||||
@@ -152,7 +236,10 @@ jobs:
|
||||
- name: Setup Docker Buildx
|
||||
uses: docker/setup-buildx-action@v4
|
||||
|
||||
- *registries
|
||||
|
||||
- name: Login to Docker Hub
|
||||
if: ${{ steps.registries.outputs.dockerhub == 'true' }}
|
||||
uses: docker/login-action@v4
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
@@ -179,11 +266,10 @@ jobs:
|
||||
id: meta
|
||||
uses: docker/metadata-action@v6
|
||||
with:
|
||||
images: |
|
||||
ghcr.io/${{ env.IMAGE }}
|
||||
docker.io/${{ env.IMAGE }}
|
||||
images: ${{ steps.registries.outputs.images }}
|
||||
tags: |
|
||||
type=sha,prefix=sha-
|
||||
type=raw,value=canary-${{ github.run_id }}-${{ github.run_attempt }},enable=${{ needs.mode.outputs.canary == 'true' }}
|
||||
type=raw,value=nightly,enable=${{ needs.mode.outputs.nightly == 'true' }}
|
||||
type=raw,value=nightly-{{date 'YYYYMMDDHHmmss' tz='UTC'}},enable=${{ needs.mode.outputs.nightly == 'true' }}
|
||||
type=raw,value=latest,enable=${{ needs.mode.outputs.release == 'true' }}
|
||||
@@ -199,6 +285,8 @@ jobs:
|
||||
|
||||
if [[ "${{ needs.mode.outputs.nightly }}" == "true" ]]; then
|
||||
FINAL_TAG="nightly"
|
||||
elif [[ "${{ needs.mode.outputs.canary }}" == "true" ]]; then
|
||||
FINAL_TAG="canary-${{ github.run_id }}-${{ github.run_attempt }}"
|
||||
else
|
||||
FINAL_TAG="v${{ steps.version.outputs.version }}"
|
||||
fi
|
||||
@@ -211,17 +299,19 @@ jobs:
|
||||
--annotation "index:org.opencontainers.image.vendor=Amruth Pillai" \
|
||||
--annotation "index:org.opencontainers.image.url=https://rxresu.me" \
|
||||
--annotation "index:org.opencontainers.image.documentation=https://docs.rxresu.me" \
|
||||
--annotation "index:org.opencontainers.image.source=https://github.com/amruthpillai/reactive-resume" \
|
||||
--annotation "index:org.opencontainers.image.source=https://github.com/${{ github.repository }}" \
|
||||
--annotation "index:org.opencontainers.image.version=${{ steps.version.outputs.version }}" \
|
||||
$(printf 'ghcr.io/${{ env.IMAGE }}@sha256:%s ' *) \
|
||||
$(printf 'docker.io/${{ env.IMAGE }}@sha256:%s ' *)
|
||||
$(printf '${{ steps.registries.outputs.ghcr_image }}@sha256:%s ' *)
|
||||
|
||||
# Get the digest of the multi-arch manifest
|
||||
GHCR_DIGEST=$(docker buildx imagetools inspect ghcr.io/${{ env.IMAGE }}:${FINAL_TAG} --format '{{json .Manifest.Digest}}' | tr -d '"')
|
||||
DOCKER_DIGEST=$(docker buildx imagetools inspect docker.io/${{ env.IMAGE }}:${FINAL_TAG} --format '{{json .Manifest.Digest}}' | tr -d '"')
|
||||
GHCR_DIGEST=$(docker buildx imagetools inspect ${{ steps.registries.outputs.ghcr_image }}:${FINAL_TAG} --format '{{json .Manifest.Digest}}' | tr -d '"')
|
||||
echo "final_tag=$FINAL_TAG" >> "$GITHUB_OUTPUT"
|
||||
echo "ghcr_digest=$GHCR_DIGEST" >> "$GITHUB_OUTPUT"
|
||||
echo "docker_digest=$DOCKER_DIGEST" >> "$GITHUB_OUTPUT"
|
||||
|
||||
if [[ "${{ steps.registries.outputs.dockerhub }}" == "true" ]]; then
|
||||
DOCKER_DIGEST=$(docker buildx imagetools inspect ${{ steps.registries.outputs.docker_image }}:${FINAL_TAG} --format '{{json .Manifest.Digest}}' | tr -d '"')
|
||||
echo "docker_digest=$DOCKER_DIGEST" >> "$GITHUB_OUTPUT"
|
||||
fi
|
||||
|
||||
- name: Install Cosign
|
||||
uses: sigstore/cosign-installer@v3
|
||||
@@ -229,18 +319,40 @@ jobs:
|
||||
- name: Sign images with Cosign
|
||||
run: |
|
||||
# Sign GHCR image
|
||||
cosign sign --yes ghcr.io/${{ env.IMAGE }}@${{ steps.manifest.outputs.ghcr_digest }}
|
||||
cosign sign --yes ${{ steps.registries.outputs.ghcr_image }}@${{ steps.manifest.outputs.ghcr_digest }}
|
||||
|
||||
# Sign Docker Hub image
|
||||
cosign sign --yes docker.io/${{ env.IMAGE }}@${{ steps.manifest.outputs.docker_digest }}
|
||||
if [[ "${{ steps.registries.outputs.dockerhub }}" == "true" ]]; then
|
||||
# Sign Docker Hub image
|
||||
cosign sign --yes ${{ steps.registries.outputs.docker_image }}@${{ steps.manifest.outputs.docker_digest }}
|
||||
fi
|
||||
|
||||
- name: Inspect image
|
||||
run: |
|
||||
docker buildx imagetools inspect ghcr.io/${{ env.IMAGE }}:${{ steps.manifest.outputs.final_tag }}
|
||||
docker buildx imagetools inspect docker.io/${{ env.IMAGE }}:${{ steps.manifest.outputs.final_tag }}
|
||||
docker buildx imagetools inspect ${{ steps.registries.outputs.ghcr_image }}:${{ steps.manifest.outputs.final_tag }}
|
||||
if [[ "${{ steps.registries.outputs.dockerhub }}" == "true" ]]; then
|
||||
docker buildx imagetools inspect ${{ steps.registries.outputs.docker_image }}:${{ steps.manifest.outputs.final_tag }}
|
||||
fi
|
||||
|
||||
- name: Verify anonymous pulls on both architectures
|
||||
run: |
|
||||
set -euo pipefail
|
||||
registry_config=$(mktemp -d)
|
||||
trap 'rm -rf "$registry_config"' EXIT
|
||||
# Prevent Docker from discovering a system credential helper.
|
||||
printf '%s\n' '{"auths":{"ghcr.io":{},"https://index.docker.io/v1/":{}}}' > "$registry_config/config.json"
|
||||
images=("${{ steps.registries.outputs.ghcr_image }}")
|
||||
if [[ "${{ steps.registries.outputs.dockerhub }}" == "true" ]]; then
|
||||
images+=("${{ steps.registries.outputs.docker_image }}")
|
||||
fi
|
||||
for image in "${images[@]}"; do
|
||||
for platform in linux/amd64 linux/arm64; do
|
||||
docker --config "$registry_config" pull --quiet --platform "$platform" \
|
||||
"$image:${{ steps.manifest.outputs.final_tag }}"
|
||||
done
|
||||
done
|
||||
|
||||
- name: Redeploy Stack
|
||||
if: ${{ needs.mode.outputs.release == 'true' }}
|
||||
if: ${{ needs.mode.outputs.release == 'true' && env.DEPLOY == 'true' }}
|
||||
uses: appleboy/ssh-action@v1
|
||||
with:
|
||||
key: ${{ secrets.SSH_KEY }}
|
||||
@@ -251,7 +363,7 @@ jobs:
|
||||
./manage_stack.sh up reactive_resume
|
||||
|
||||
- name: Purge Cloudflare cache
|
||||
if: ${{ needs.mode.outputs.release == 'true' }}
|
||||
if: ${{ needs.mode.outputs.release == 'true' && env.PURGE_CLOUDFLARE == 'true' }}
|
||||
env:
|
||||
CLOUDFLARE_ZONE_ID: ${{ secrets.CLOUDFLARE_ZONE_ID }}
|
||||
CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }}
|
||||
|
||||
@@ -20,7 +20,7 @@ env:
|
||||
|
||||
jobs:
|
||||
e2e:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-32vcpu-ubuntu-2404' || 'ubuntu-latest' }}
|
||||
timeout-minutes: 30
|
||||
|
||||
services:
|
||||
@@ -40,26 +40,31 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout Repository
|
||||
if: ${{ vars.USE_BLACKSMITH != 'true' }}
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Checkout Repository (Blacksmith)
|
||||
if: ${{ vars.USE_BLACKSMITH == 'true' }}
|
||||
uses: useblacksmith/checkout@v1
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Install pnpm
|
||||
uses: pnpm/action-setup@v6
|
||||
|
||||
- name: Setup Node
|
||||
uses: actions/setup-node@v6
|
||||
with:
|
||||
node-version: "24"
|
||||
node-version-file: ".nvmrc"
|
||||
cache: "pnpm"
|
||||
|
||||
- name: Install Dependencies
|
||||
run: pnpm install --frozen-lockfile
|
||||
|
||||
- name: Run Server and Tooling Tests
|
||||
run: pnpm exec turbo run test:ci --filter=server --filter=@reactive-resume/tooling
|
||||
|
||||
- name: Install Playwright Browser
|
||||
timeout-minutes: 10
|
||||
run: pnpm exec playwright install --with-deps chromium
|
||||
|
||||
- name: Generate Test Secrets
|
||||
@@ -73,6 +78,13 @@ jobs:
|
||||
- name: Run Database Migrations
|
||||
run: pnpm db:migrate
|
||||
|
||||
# Runs every workspace package, not a hand-maintained filter list, so a package
|
||||
# cannot silently lose coverage by being left out. Serial execution: the PDF
|
||||
# rasterization and API rate-limit suites time out when several packages' Vitest
|
||||
# thread pools oversubscribe the runner at once.
|
||||
- name: Run Unit Tests
|
||||
run: pnpm exec turbo run test:ci --concurrency=1
|
||||
|
||||
- name: Build
|
||||
run: pnpm build
|
||||
|
||||
|
||||
@@ -10,14 +10,21 @@ permissions:
|
||||
|
||||
jobs:
|
||||
label:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-2vcpu-ubuntu-2404' || 'ubuntu-latest' }}
|
||||
|
||||
steps:
|
||||
- name: Checkout Repository
|
||||
if: ${{ vars.USE_BLACKSMITH != 'true' }}
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Checkout Repository (Blacksmith)
|
||||
if: ${{ vars.USE_BLACKSMITH == 'true' }}
|
||||
uses: useblacksmith/checkout@v1
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Apply Form Labels
|
||||
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9
|
||||
with:
|
||||
|
||||
@@ -10,7 +10,7 @@ permissions:
|
||||
|
||||
jobs:
|
||||
stale:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-2vcpu-ubuntu-2404' || 'ubuntu-latest' }}
|
||||
|
||||
steps:
|
||||
- name: Close Inactive Issues Awaiting Information
|
||||
|
||||
@@ -0,0 +1,109 @@
|
||||
name: Vercel compatibility
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
push:
|
||||
branches: [main]
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
env:
|
||||
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
|
||||
|
||||
jobs:
|
||||
artifact:
|
||||
runs-on: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-32vcpu-ubuntu-2404' || 'ubuntu-latest' }}
|
||||
timeout-minutes: 20
|
||||
services:
|
||||
postgres:
|
||||
image: postgres:17-alpine
|
||||
env:
|
||||
POSTGRES_PASSWORD: postgres
|
||||
ports: [5432:5432]
|
||||
options: >-
|
||||
--health-cmd "pg_isready -U postgres"
|
||||
--health-interval 5s --health-timeout 5s --health-retries 10
|
||||
env:
|
||||
APP_URL: http://localhost:3000
|
||||
DATABASE_URL: postgresql://postgres:postgres@localhost:5432/postgres
|
||||
AUTH_SECRET: isolated-ci-auth-secret-32-characters
|
||||
ENCRYPTION_SECRET: isolated-ci-encryption-secret-32-characters
|
||||
REDIS_URL: redis://localhost:6379
|
||||
STORAGE_BACKEND: blob
|
||||
BLOB_READ_WRITE_TOKEN: vercel_blob_rw_ci_fake_build_only
|
||||
VERCEL: "1"
|
||||
VERCEL_ENV: production
|
||||
steps:
|
||||
- if: ${{ vars.USE_BLACKSMITH != 'true' }}
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- if: ${{ vars.USE_BLACKSMITH == 'true' }}
|
||||
uses: useblacksmith/checkout@v1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: pnpm/action-setup@v6
|
||||
- uses: actions/setup-node@v6
|
||||
with:
|
||||
node-version-file: .nvmrc
|
||||
cache: pnpm
|
||||
- run: pnpm install --frozen-lockfile
|
||||
# Local project settings avoid authentication and API calls. Forks receive no cloud credentials.
|
||||
- name: Build Vercel artifact against isolated PostgreSQL
|
||||
run: |
|
||||
mkdir -p .vercel
|
||||
node --input-type=module - <<'JS'
|
||||
import { writeFileSync } from 'node:fs';
|
||||
writeFileSync('.vercel/project.json', JSON.stringify({
|
||||
projectId: 'prj_ci', orgId: 'team_ci', projectName: 'reactive-resume-ci',
|
||||
settings: { framework: null, nodeVersion: '24.x', createdAt: 0 }
|
||||
}));
|
||||
JS
|
||||
pnpm dlx --allow-build=esbuild vercel@60.0.1 build --prod --yes --global-config "$RUNNER_TEMP/vercel-offline"
|
||||
- name: Check Lambda module loading and function budget
|
||||
run: |
|
||||
node --no-experimental-require-module --input-type=module - <<'JS'
|
||||
import assert from 'node:assert/strict';
|
||||
import { readFileSync, readdirSync } from 'node:fs';
|
||||
const config = JSON.parse(readFileSync('.vercel/output/functions/api/index.func/.vc-config.json'));
|
||||
assert.equal(config.runtime, 'nodejs24.x');
|
||||
assert.equal(config.maxDuration, 300);
|
||||
const tracedFiles = Object.keys(config.filePathMap ?? {});
|
||||
assert.ok(tracedFiles.some((path) => path.endsWith('/pdfkit/js/standard-fonts/Helvetica.cjs')));
|
||||
assert.ok(tracedFiles.some((path) => path.endsWith('/pdfkit/js/data/Helvetica.afm')));
|
||||
for (const name of readdirSync('apps/server/dist')) {
|
||||
if (name.endsWith('.mjs') && !['index.mjs', 'prepare-deployment.mjs'].includes(name)) {
|
||||
await import(`./apps/server/dist/${name}`);
|
||||
}
|
||||
}
|
||||
const { default: app } = await import('./apps/server/dist/vercel.mjs');
|
||||
const response = await app.fetch(new Request('http://localhost:3000/api/storage/stage', { method: 'POST', body: '{}' }));
|
||||
assert.equal(response.status, 401);
|
||||
process.exit(0);
|
||||
JS
|
||||
|
||||
live-smoke:
|
||||
if: github.event_name == 'workflow_dispatch'
|
||||
runs-on: ${{ vars.USE_BLACKSMITH == 'true' && 'blacksmith-2vcpu-ubuntu-2404' || 'ubuntu-latest' }}
|
||||
environment: vercel-smoke
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
- if: ${{ vars.USE_BLACKSMITH != 'true' }}
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- if: ${{ vars.USE_BLACKSMITH == 'true' }}
|
||||
uses: useblacksmith/checkout@v1
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-node@v6
|
||||
with:
|
||||
node-version-file: .nvmrc
|
||||
- name: Smoke-test dedicated deployment
|
||||
env:
|
||||
SMOKE_URL: ${{ vars.VERCEL_SMOKE_URL }}
|
||||
SMOKE_AI_BASE_URL: ${{ vars.VERCEL_SMOKE_AI_BASE_URL }}
|
||||
SMOKE_AI_API_KEY: ${{ secrets.VERCEL_SMOKE_AI_API_KEY }}
|
||||
run: node tooling/deployment/smoke.mjs
|
||||
-17
@@ -1,17 +0,0 @@
|
||||
// @ts-check
|
||||
|
||||
const betaPackages = ["drizzle-zod"];
|
||||
const rcPackages = ["drizzle-orm", "drizzle-kit"];
|
||||
|
||||
/** @type {import('npm-check-updates').RunOptions} */
|
||||
module.exports = {
|
||||
upgrade: true,
|
||||
workspaces: true,
|
||||
install: "always",
|
||||
packageManager: "pnpm",
|
||||
target: (packageName) => {
|
||||
if (betaPackages.includes(packageName)) return "@beta";
|
||||
if (rcPackages.includes(packageName)) return "@rc";
|
||||
return "latest";
|
||||
},
|
||||
};
|
||||
@@ -1,7 +1,7 @@
|
||||
# Plan 27 Phase A diagnostic evidence
|
||||
|
||||
Date: 2026-09-06
|
||||
Issue: [#3377](https://github.com/amruthpillai/reactive-resume/issues/3377)
|
||||
Issue: [#3377](https://github.com/reactive-resume/reactive-resume/issues/3377)<br>
|
||||
Revision: `2a4a1583b` (`origin/main` at run start)
|
||||
Scope: Phase A, steps 1–2 only. No resolver, runtime behavior, or remote-source behavior changed.
|
||||
|
||||
|
||||
@@ -0,0 +1,27 @@
|
||||
.env*
|
||||
!.env.example
|
||||
.git
|
||||
.codegraph
|
||||
.superpowers
|
||||
.agents
|
||||
.codex
|
||||
.claude
|
||||
.turbo
|
||||
**/node_modules
|
||||
**/dist
|
||||
**/coverage
|
||||
**/reports
|
||||
data
|
||||
apps/web/data
|
||||
screenshots
|
||||
.vercel
|
||||
.wrangler
|
||||
.tanstack
|
||||
.worktrees
|
||||
.migration
|
||||
.supermemory
|
||||
.cache
|
||||
tmp
|
||||
temp
|
||||
**/test-results
|
||||
**/playwright-report
|
||||
@@ -27,20 +27,17 @@ Auto-Clarity: drop caveman for security warnings, irreversible actions, user con
|
||||
Boundaries: code/commits/PRs written normal.
|
||||
<!-- caveman-end -->
|
||||
|
||||
<!-- graphify-begin -->
|
||||
|
||||
## Agent skills
|
||||
|
||||
- Issues and specs: GitHub Issues for `amruthpillai/reactive-resume`. See `docs/agents/issue-tracker.md`.
|
||||
- Domain docs use a multi-context layout. See `docs/agents/domain.md`.
|
||||
- Issues and specs: GitHub Issues for `reactive-resume/reactive-resume`. See `docs/agents/issue-tracker.md`.
|
||||
|
||||
## Overview
|
||||
|
||||
Reactive Resume is a pnpm monorepo (Turborepo) with two deployable apps: `apps/web` (TanStack Start / React 19 / Vite) and `apps/server` (Hono / Node.js). The production Docker image runs a single Node.js process on port 3000; `apps/server` mounts the API/auth/MCP/static routes and serves the built web app.
|
||||
Reactive Resume is a pnpm monorepo (Turborepo) with two deployable apps: `apps/web` (React 19 SPA with TanStack Router and Vite) and `apps/server` (Hono / Node.js). The production Docker image runs a single Node.js process on port 3000; `apps/server` mounts the API/auth/MCP/static routes and serves the built web app.
|
||||
|
||||
Internal packages are source-consumed through `package.json` export maps pointing at `src` files. Do not assume package-local `dist` output exists unless a package explicitly adds it.
|
||||
|
||||
Prerequisites: **Node.js 24** (matches Dockerfile `ARG NODE_VERSION=24`), **pnpm 11.21.0** ([install guide](https://pnpm.io/installation)), and **Docker** for PostgreSQL (`sudo dockerd &` if the daemon isn't running).
|
||||
Prerequisites: **Node.js 24** (pinned in `.nvmrc`; matches Dockerfile `ARG NODE_VERSION=24`), **pnpm 12.3.4** (pinned by `packageManager` in the root `package.json`; pnpm self-manages to it, so any recent pnpm can bootstrap — the Dockerfile's `ARG PNPM_VERSION` only picks the base image) ([install guide](https://pnpm.io/installation)), and **Docker** for PostgreSQL (`sudo dockerd &` if the daemon isn't running).
|
||||
|
||||
## Ownership map
|
||||
|
||||
@@ -69,9 +66,10 @@ Narrow cross-cutting helpers go in `packages/utils` only after checking no domai
|
||||
## Web app conventions
|
||||
|
||||
- `apps/web/src/router.tsx` initializes router context with `queryClient`, `orpc`, `theme`, `locale`, `session`, and `flags`. Reuse route context instead of refetching these ad hoc.
|
||||
- Builder shell: `apps/web/src/routes/builder/$resumeId`. Its nested preview route is client-only (`ssr: false`); the public resume route `apps/web/src/routes/$username/$slug.tsx` uses `ssr: "data-only"`.
|
||||
- Browser-only preview code: `apps/web/src/features/resume/preview`. Public PDF viewer: `apps/web/src/features/resume/public`. Keep PDF.js/canvas/browser APIs out of SSR paths.
|
||||
- Isomorphic oRPC client: `apps/web/src/libs/orpc/client.ts` — server calls use an in-process router client, browser calls use `/api/rpc` with credentials included.
|
||||
- The web app is a client-rendered SPA. `apps/server` serves `index.html` and injects page metadata (OpenGraph, canonical, JSON-LD) in `apps/server/src/static/web.ts`; there is no React SSR.
|
||||
- Builder shell: `apps/web/src/routes/builder/$resumeId`. Public resume route: `apps/web/src/routes/$username/$slug.tsx`.
|
||||
- Browser-only preview code: `apps/web/src/features/resume/preview`. Public PDF viewer: `apps/web/src/features/resume/public`. Keep PDF.js/canvas code in these features, not in `packages/pdf`.
|
||||
- oRPC client: `apps/web/src/libs/orpc/client.ts` calls `/api/rpc` with credentials included. `apps/web/src/libs/orpc/fetch.ts` stages large request bodies through Blob on Vercel.
|
||||
- For React components with explicit props, use a named props type (e.g. `type FooProps = {...}` with `function Foo(props: FooProps)`) rather than inline object annotations, especially with more than one field or with generics.
|
||||
|
||||
## Package boundaries
|
||||
@@ -89,7 +87,7 @@ Multi-place changes:
|
||||
|
||||
- **Resume data shape**: `packages/schema/src/resume/*` first, then API DTOs, importers, PDF rendering, and web forms consuming it.
|
||||
- **New template**: `packages/schema/src/templates.ts`, `packages/pdf/src/templates/index.ts`, source under `packages/pdf/src/templates/<name>/`, and previews under `apps/web/public/templates/{jpg,pdf}`.
|
||||
- **New DB column/table**: `packages/db/src/schema/*`, then `dotenvx run -f .env.local -- pnpm db:generate`.
|
||||
- **New DB column/table**: `packages/db/src/schema/*`, then `pnpm db:generate`.
|
||||
- **New env var**: `packages/env/src/server.ts` **and** the `globalEnv` array in `turbo.json`. Turborepo 2.x strict env mode filters out unlisted vars, so the variable will be `undefined` in child processes at runtime even when correctly set in the OS/container environment.
|
||||
|
||||
## Environment and database
|
||||
@@ -98,18 +96,18 @@ Copy `.env.example` to `.env.local`. Three required vars: `APP_URL` (default `ht
|
||||
|
||||
- **S3/SeaweedFS optional.** If `S3_ACCESS_KEY_ID`, `S3_SECRET_ACCESS_KEY`, and `S3_BUCKET` are all set, the app uses S3-compatible storage. `.env.example` ships SeaweedFS defaults, so either start the `seaweedfs` compose service or comment those vars out to use local filesystem storage under `<workspace>/data`. `LOCAL_STORAGE_PATH` must be absolute when set.
|
||||
- **`REDIS_URL` and `ENCRYPTION_SECRET`** are optional for core resume flows but both required for saved AI providers and the authenticated `/agent` workspace. Host-run dev uses `REDIS_URL=redis://localhost:6379`; the container-run app uses `redis://redis:6379`.
|
||||
- **`drizzle-kit` (used by `pnpm db:migrate`) reads `DATABASE_URL` from `process.env` directly** — it does not auto-load `.env`. Run migration commands through `dotenvx`.
|
||||
- **`drizzle-kit` (used by `pnpm db:migrate`) reads `DATABASE_URL` from `process.env` directly** — it does not auto-load `.env`. The root migration scripts load `.env.local` through `dotenvx` before invoking Drizzle Kit.
|
||||
- The production server auto-runs migrations at startup before serving traffic, so manual `pnpm db:migrate` is mainly for first setup, migration debugging, or applying migrations without starting the app.
|
||||
|
||||
## Commands
|
||||
|
||||
Prefix dev servers and migration commands with `dotenvx run -f .env.local --`. Tests, typechecks, linters, boundary checks, and `pnpm build` do not need it; if one fails on a missing env var, rerun it with the prefix.
|
||||
Dev server and migration scripts load `.env.local` through the project-local `dotenvx`. Tests, typechecks, linters, boundary checks, and `pnpm build` do not load it automatically.
|
||||
|
||||
```
|
||||
sudo docker compose -f compose.dev.yml up -d postgres # DB only
|
||||
sudo docker compose -f compose.dev.yml up -d postgres redis seaweedfs seaweedfs_create_bucket # full infra
|
||||
dotenvx run -f .env.local -- pnpm dev # port 3000 (dev:web for web only)
|
||||
dotenvx run -f .env.local -- pnpm db:generate # db:migrate to apply
|
||||
pnpm dev # port 3000 (dev:web for web only)
|
||||
pnpm db:generate # db:migrate to apply
|
||||
pnpm check # Biome — WRITE-CAPABLE (--write --unsafe)
|
||||
pnpm test | pnpm typecheck | pnpm build | pnpm exec turbo boundaries
|
||||
```
|
||||
|
||||
@@ -1,3 +0,0 @@
|
||||
# Domain contexts
|
||||
|
||||
- [Resume](packages/resume/CONTEXT.md): authored resume content and presentation concepts shared by the builder and exporters.
|
||||
@@ -226,21 +226,24 @@ A custom Tailwind token `--aspect-page: 210 / 297` enforces A4 paper proportions
|
||||
|
||||
## Animation
|
||||
|
||||
Animations use the Motion library (formerly Framer Motion) and follow a consistent choreography pattern:
|
||||
Motion exists to explain a change, confirm an action, or soften a jump. This is a tool people use for hours, so it stays crisp: short, precise, rarely decorative.
|
||||
|
||||
**Entrance animations** use a fade-up reveal: elements start at `opacity: 0, y: 20-100` and animate to `opacity: 1, y: 0`. The hero section uses a larger y-offset (100px) for dramatic effect; subsequent sections use 20px for subtlety.
|
||||
**Frequency decides first.** Keyboard-initiated actions (the command palette, ⌘B sidebar toggle, zoom shortcuts, keyboard-opened menus via Base UI's `data-instant`) do not animate. Things hit tens of times a day (list rows, tooltips after the first, context menus) get opacity-only or no motion. Dialogs, sheets and toasts get a standard transition. Only rare moments (marketing pages, first load) get more.
|
||||
|
||||
**Timing principles:**
|
||||
- **Base duration:** 0.35s–0.6s for standard section reveals, 0.45s for hero elements, up to 1.1s for the hero video entrance.
|
||||
- **Stagger pattern:** Sequential delays within a group, typically 0.1s–0.15s apart (hero: 0.55s, 0.7s, 0.82s, 0.95s). For grids, use `index * 0.03`–`0.1` for per-item stagger.
|
||||
- **Easing:** `easeOut` for entrances (elements decelerate into position). `easeInOut` for looping/ambient animations.
|
||||
- **Performance:** Apply `will-change-[transform,opacity]` on animated elements and `will-change-transform` on continuously animated elements.
|
||||
**Tokens.** Never hand-type a curve.
|
||||
- CSS: `ease-out-strong` / `var(--ease-out-strong)` (`cubic-bezier(0.23, 1, 0.32, 1)`) for anything entering, exiting or responding; `ease-in-out-strong` for on-screen movement nobody is waiting on (ambient loops, carousels); `ease-drawer` for sheets. Never `ease-in`.
|
||||
- Motion (JS): `EASE_OUT_STRONG` from `apps/web/src/libs/motion.ts`.
|
||||
|
||||
**Hover/interaction animations** are quick (0.2s) and subtle — small scale bumps (`scale: 1.01`), slight y-offsets (`y: -2`), and `active:translate-y-px` for button press.
|
||||
**Durations.** Press feedback 100–160ms, tooltips/popovers/menus 150ms in and 100ms out, dialogs 200ms in and 150ms out, sheets 300ms. App UI stays under 300ms; marketing reveals may run 0.5–0.9s. Exits are faster than entrances.
|
||||
|
||||
**Ambient animations** loop infinitely with `easeInOut` — the scroll indicator bounces gently (`y: [0, 5, 0]` over 1.5s).
|
||||
**Mechanics.**
|
||||
- Popups use interruptible CSS transitions on Base UI's `data-starting-style` / `data-ending-style`, scale from `0.95` (never `0`) and grow from `origin-(--transform-origin)`. Modals stay centred.
|
||||
- Animate `transform`/`translate`/`scale` and `opacity` only. No `transition-all`, no permanent `will-change` (Motion promotes layers while it animates).
|
||||
- Presses use `active:scale-[0.97]`. `Button` already has it; don't wrap it in Motion hover/tap wrappers.
|
||||
- Lists use `AnimatePresence initial={false}` so items animate when added or removed, not every time the list mounts.
|
||||
- Continuous loops (marquees, drifting spotlights) are CSS keyframes, so they run off the main thread.
|
||||
|
||||
**Reduced motion:** All CSS transitions and animations collapse to `0.01ms` duration and single iteration when `prefers-reduced-motion: reduce` is active. Motion library animations should also respect this preference.
|
||||
**Reduced motion:** `MotionConfig reducedMotion="user"` disables Motion transforms, and CSS transitions and animations collapse to `0.01ms` — except `animate-spin`, which keeps spinning so loading never looks frozen. Values driven by `useSpring`/`useMotionValue` bypass `MotionConfig`, so check `useReducedMotion()` there.
|
||||
|
||||
## Elevation & Depth
|
||||
|
||||
|
||||
+2
-1
@@ -1,5 +1,6 @@
|
||||
# syntax=docker/dockerfile:1.7
|
||||
|
||||
# Base image only; pnpm self-manages to the `packageManager` version in package.json.
|
||||
ARG PNPM_VERSION=11.21.0
|
||||
ARG NODE_VERSION=24
|
||||
|
||||
@@ -47,7 +48,7 @@ LABEL org.opencontainers.image.description="A free and open-source resume builde
|
||||
LABEL org.opencontainers.image.vendor="Amruth Pillai"
|
||||
LABEL org.opencontainers.image.url="https://rxresu.me"
|
||||
LABEL org.opencontainers.image.documentation="https://docs.rxresu.me"
|
||||
LABEL org.opencontainers.image.source="https://github.com/amruthpillai/reactive-resume"
|
||||
LABEL org.opencontainers.image.source="https://github.com/reactive-resume/reactive-resume"
|
||||
|
||||
ENV NODE_ENV="production" \
|
||||
PORT=3000 \
|
||||
|
||||
@@ -21,6 +21,10 @@ the catalog already uses one consistently):
|
||||
Reactive Resume, GitHub, Crowdin, Docker, PostgreSQL, Better Auth, TanStack, Microsoft Word,
|
||||
PDF, DOCX, JSON, CSV, API, MCP, oRPC, SSO, CSS, URL, JSON Resume.
|
||||
|
||||
AI provider names are brand names and stay in English: OpenAI, Anthropic Claude, Google
|
||||
Gemini, Vercel AI Gateway, OpenRouter, Mistral AI, Cohere, xAI Grok, Groq, DeepSeek, Together.ai,
|
||||
Fireworks, Cerebras, Perplexity, Ollama Cloud.
|
||||
|
||||
Template names are proper nouns and are never translated: Azurill, Bronzor, Chikorita, Ditgar,
|
||||
Ditto, Gengar, Glalie, Kakuna, Lapras, Leafish, Meowth, Onyx, Pikachu, Rhyhorn, Scizor.
|
||||
|
||||
|
||||
@@ -1,3 +1,9 @@
|
||||
> [!IMPORTANT]
|
||||
> **Repository moved:** Reactive Resume now lives at **[`reactive-resume/reactive-resume`](https://github.com/reactive-resume/reactive-resume)** on GitHub.
|
||||
> **Docker Hub stays at `amruthpillai/reactive-resume`.** GHCR builds now publish to `ghcr.io/reactive-resume/reactive-resume`.
|
||||
> Verified image tags: `latest`, `v5`, `v5.3`, and `v5.3.0` (AMD64 and ARM64). The current version was rebuilt and production redeployed for this rename; no new GitHub release or version bump was made. See [migration details](https://github.com/reactive-resume/reactive-resume/issues/3503).
|
||||
> GitHub Sponsors and Open Collective funding links remain unchanged.
|
||||
|
||||
<div align="center">
|
||||
<a href="https://rxresu.me">
|
||||
<img src="apps/web/public/opengraph/banner.jpg" alt="Reactive Resume" />
|
||||
@@ -14,15 +20,20 @@
|
||||
</p>
|
||||
|
||||
<p>
|
||||
<img src="https://img.shields.io/github/package-json/v/amruthpillai/reactive-resume?style=flat-square" alt="Reactive Resume Version">
|
||||
<img src="https://img.shields.io/github/stars/amruthpillai/Reactive-Resume?style=flat-square" alt="GitHub Stars">
|
||||
<img src="https://img.shields.io/github/license/amruthpillai/Reactive-Resume?style=flat-square" alt="License" />
|
||||
<img src="https://img.shields.io/github/package-json/v/reactive-resume/reactive-resume?style=flat-square" alt="Reactive Resume Version">
|
||||
<img src="https://img.shields.io/github/stars/reactive-resume/reactive-resume?style=flat-square" alt="GitHub Stars">
|
||||
<img src="https://img.shields.io/github/license/reactive-resume/reactive-resume?style=flat-square" alt="License" />
|
||||
<img src="https://img.shields.io/docker/pulls/amruthpillai/reactive-resume?style=flat-square" alt="Docker Pulls" />
|
||||
<a href="https://discord.gg/aSyA5ZSxpb"><img src="https://img.shields.io/discord/1173518977851473940?style=flat-square&label=discord" alt="Discord" /></a>
|
||||
<a href="https://crowdin.com/project/reactive-resume"><img src="https://badges.crowdin.net/reactive-resume/localized.svg?style=flat-square" alt="Crowdin" /></a>
|
||||
<a href="https://github.com/sponsors/AmruthPillai"><img src="https://img.shields.io/github/sponsors/AmruthPillai?style=flat-square&label=sponsors" alt="Sponsors" /></a>
|
||||
<a href="https://opencollective.com/reactive-resume/donate"><img src="https://img.shields.io/opencollective/backers/reactive-resume?style=flat-square&label=donations" alt="Donations" /></a>
|
||||
</p>
|
||||
|
||||
<br />
|
||||
<a href="https://vercel.com/open-source-program">
|
||||
<img alt="Vercel OSS Program" src="https://vercel.com/oss/program-badge-2026.svg" />
|
||||
</a>
|
||||
</div>
|
||||
|
||||
---
|
||||
@@ -143,7 +154,7 @@ The quickest way to run Reactive Resume locally:
|
||||
|
||||
```bash
|
||||
# Clone the repository
|
||||
git clone --depth=1 https://github.com/amruthpillai/reactive-resume.git
|
||||
git clone --depth=1 https://github.com/reactive-resume/reactive-resume.git reactive-resume
|
||||
cd reactive-resume
|
||||
|
||||
# Start all services
|
||||
@@ -153,15 +164,13 @@ docker compose up -d
|
||||
open http://localhost:3000
|
||||
```
|
||||
|
||||
[](https://app.ona.com/#https://github.com/amruthpillai/reactive-resume)
|
||||
|
||||
For detailed setup instructions, environment configuration, and self-hosting guides, see the [documentation](https://docs.rxresu.me).
|
||||
|
||||
## Tech Stack
|
||||
|
||||
| Category | Technology |
|
||||
| ---------------- | ------------------------------- |
|
||||
| Framework | TanStack Start (React 19, Vite) |
|
||||
| Framework | TanStack Router (React 19, Vite) |
|
||||
| Runtime | Node.js |
|
||||
| Language | TypeScript |
|
||||
| Database | PostgreSQL with Drizzle ORM |
|
||||
@@ -185,7 +194,13 @@ The full documentation lives at [docs.rxresu.me](https://docs.rxresu.me):
|
||||
|
||||
## Self-Hosting
|
||||
|
||||
Reactive Resume can be self-hosted using Docker. The stack includes:
|
||||
Reactive Resume supports Docker and Vercel Hobby.
|
||||
|
||||
[](https://vercel.com/new/clone?repository-url=https%3A%2F%2Fgithub.com%2Freactive-resume%2Freactive-resume&project-name=reactive-resume&repository-name=reactive-resume&env=AUTH_SECRET%2CENCRYPTION_SECRET&envDescription=Generate+two+independent+secrets+with+openssl+rand+-hex+32.+Keep+these+values+across+deployments.&envLink=https%3A%2F%2Fdocs.rxresu.me%2Fself-hosting%2Fvercel&stores=%5B%7B%22type%22%3A%22integration%22%2C%22protocol%22%3A%22storage%22%2C%22integrationSlug%22%3A%22neon%22%2C%22productSlug%22%3A%22neon%22%7D%2C%7B%22type%22%3A%22integration%22%2C%22protocol%22%3A%22storage%22%2C%22integrationSlug%22%3A%22upstash%22%2C%22productSlug%22%3A%22upstash-kv%22%7D%2C%7B%22type%22%3A%22blob%22%2C%22access%22%3A%22private%22%7D%5D)
|
||||
|
||||
Vercel provisions Neon PostgreSQL, private Blob storage, and Upstash Redis through its deployment wizard. Supply two persistent secrets, then deploy. See the [Vercel guide](docs/self-hosting/vercel.mdx) for setup, limits, and optional SMTP/OAuth configuration.
|
||||
|
||||
For Docker, the stack includes:
|
||||
|
||||
- **PostgreSQL** — Database for storing user data and resumes
|
||||
- **SeaweedFS** (optional) — S3-compatible storage for file uploads
|
||||
@@ -199,7 +214,7 @@ Pull the latest image from Docker Hub or GitHub Container Registry:
|
||||
docker pull amruthpillai/reactive-resume:latest
|
||||
|
||||
# GitHub Container Registry
|
||||
docker pull ghcr.io/amruthpillai/reactive-resume:latest
|
||||
docker pull ghcr.io/reactive-resume/reactive-resume:latest
|
||||
```
|
||||
|
||||
See the [self-hosting guide](https://docs.rxresu.me/self-hosting/docker) for complete instructions.
|
||||
@@ -221,17 +236,21 @@ Other ways to support:
|
||||
|
||||
- Star this repository
|
||||
- Report reproducible bugs and suggest actionable features
|
||||
- Help other users in [GitHub Discussions](https://github.com/amruthpillai/reactive-resume/discussions/categories/q-a)
|
||||
- Help other users in [GitHub Discussions](https://github.com/reactive-resume/reactive-resume/discussions/categories/q-a)
|
||||
- Improve documentation
|
||||
- Help with translations
|
||||
|
||||
<a href="https://blacksmith.sh/">
|
||||
<img width="368" height="126" alt="powered-by-blacksmith" src="https://github.com/user-attachments/assets/3e95d11b-4579-4082-8d0c-6b574f925625" />
|
||||
</a>
|
||||
|
||||
## Star History
|
||||
|
||||
<a href="https://www.star-history.com/?repos=amruthpillai%2Freactive-resume&type=date&legend=top-left">
|
||||
<a href="https://www.star-history.com/?repos=reactive-resume%2Freactive-resume&type=date&legend=top-left">
|
||||
<picture>
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/chart?repos=amruthpillai/reactive-resume&type=date&theme=dark&legend=top-left&sealed_token=QmaOn4Ech499R6kpQe8ONn911UjGUaJfQBT0MXlQLU9hTo-Ie7lTxIILWbBvmtzDGHk7ziWKN_N5iM5mgP8widn_FGHd9-PHNokPtSji8XLgbFpqatgyqIDPnOys-IhO40W3J0HeH07FL-Q8Bq6ArRk3LDtJDwjh4m0ya-2L59ULb7BaqxkSDuCytkCr" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/chart?repos=amruthpillai/reactive-resume&type=date&legend=top-left&sealed_token=QmaOn4Ech499R6kpQe8ONn911UjGUaJfQBT0MXlQLU9hTo-Ie7lTxIILWbBvmtzDGHk7ziWKN_N5iM5mgP8widn_FGHd9-PHNokPtSji8XLgbFpqatgyqIDPnOys-IhO40W3J0HeH07FL-Q8Bq6ArRk3LDtJDwjh4m0ya-2L59ULb7BaqxkSDuCytkCr" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/chart?repos=amruthpillai/reactive-resume&type=date&legend=top-left&sealed_token=QmaOn4Ech499R6kpQe8ONn911UjGUaJfQBT0MXlQLU9hTo-Ie7lTxIILWbBvmtzDGHk7ziWKN_N5iM5mgP8widn_FGHd9-PHNokPtSji8XLgbFpqatgyqIDPnOys-IhO40W3J0HeH07FL-Q8Bq6ArRk3LDtJDwjh4m0ya-2L59ULb7BaqxkSDuCytkCr" />
|
||||
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/chart?repos=reactive-resume/reactive-resume&type=date&theme=dark&legend=top-left" />
|
||||
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/chart?repos=reactive-resume/reactive-resume&type=date&legend=top-left" />
|
||||
<img alt="Star History Chart" src="https://api.star-history.com/chart?repos=reactive-resume/reactive-resume&type=date&legend=top-left" />
|
||||
</picture>
|
||||
</a>
|
||||
|
||||
@@ -247,7 +266,7 @@ Every contribution helps, whether it is a typo fix or a new feature.
|
||||
|
||||
See the [development setup guide](https://docs.rxresu.me/contributing/development) for how to run the project locally.
|
||||
|
||||
Maintainers review the [`status: needs triage` queue](https://github.com/amruthpillai/reactive-resume/issues?q=is%3Aissue+is%3Aopen+label%3A%22status%3A+needs+triage%22)
|
||||
Maintainers review the [`status: needs triage` queue](https://github.com/reactive-resume/reactive-resume/issues?q=is%3Aissue+is%3Aopen+label%3A%22status%3A+needs+triage%22)
|
||||
weekly. Triaged bugs become `status: confirmed`; feature proposals become `status: accepted`; reports that need details become
|
||||
`status: needs info`.
|
||||
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
export { default } from "../apps/server/dist/vercel.mjs";
|
||||
+45
-41
@@ -18,34 +18,34 @@
|
||||
"#react-pdf-renderer": "@react-pdf/renderer"
|
||||
},
|
||||
"dependencies": {
|
||||
"@ai-sdk/anthropic": "^4.0.49",
|
||||
"@ai-sdk/cerebras": "^3.0.44",
|
||||
"@ai-sdk/cohere": "^4.0.37",
|
||||
"@ai-sdk/deepseek": "^3.0.39",
|
||||
"@ai-sdk/fireworks": "^3.0.47",
|
||||
"@ai-sdk/google": "^4.0.64",
|
||||
"@ai-sdk/groq": "^4.0.37",
|
||||
"@ai-sdk/mistral": "^4.0.39",
|
||||
"@ai-sdk/openai": "^4.0.60",
|
||||
"@ai-sdk/openai-compatible": "^3.0.44",
|
||||
"@ai-sdk/perplexity": "^4.0.39",
|
||||
"@ai-sdk/togetherai": "^3.0.45",
|
||||
"@ai-sdk/xai": "^4.0.54",
|
||||
"@aws-sdk/client-s3": "^3.1127.0",
|
||||
"@better-auth/api-key": "^1.7.3",
|
||||
"@better-auth/drizzle-adapter": "^1.7.3",
|
||||
"@better-auth/infra": "^0.4.5",
|
||||
"@better-auth/oauth-provider": "^1.7.3",
|
||||
"@better-auth/passkey": "^1.7.3",
|
||||
"@ai-sdk/anthropic": "^4.0.65",
|
||||
"@ai-sdk/cerebras": "^3.0.57",
|
||||
"@ai-sdk/cohere": "^4.0.50",
|
||||
"@ai-sdk/deepseek": "^3.0.54",
|
||||
"@ai-sdk/fireworks": "^3.0.60",
|
||||
"@ai-sdk/google": "^4.0.82",
|
||||
"@ai-sdk/groq": "^4.0.50",
|
||||
"@ai-sdk/mistral": "^4.0.52",
|
||||
"@ai-sdk/openai": "^4.0.78",
|
||||
"@ai-sdk/openai-compatible": "^3.0.57",
|
||||
"@ai-sdk/perplexity": "^5.0.1",
|
||||
"@ai-sdk/togetherai": "^3.0.58",
|
||||
"@ai-sdk/xai": "^5.0.10",
|
||||
"@aws-sdk/client-s3": "^3.1141.0",
|
||||
"@better-auth/api-key": "^1.7.6",
|
||||
"@better-auth/drizzle-adapter": "^1.7.6",
|
||||
"@better-auth/infra": "^0.4.11",
|
||||
"@better-auth/oauth-provider": "^1.7.6",
|
||||
"@better-auth/passkey": "^1.7.6",
|
||||
"@bramus/specificity": "^2.4.2",
|
||||
"@hono/node-server": "^2.1.1",
|
||||
"@modelcontextprotocol/sdk": "^1.30.0",
|
||||
"@orpc/client": "^1.15.0",
|
||||
"@orpc/experimental-ratelimit": "^1.15.0",
|
||||
"@orpc/json-schema": "^1.15.0",
|
||||
"@orpc/openapi": "^1.15.0",
|
||||
"@orpc/server": "^1.15.0",
|
||||
"@orpc/zod": "^1.15.0",
|
||||
"@modelcontextprotocol/sdk": "^1.30.1",
|
||||
"@orpc/client": "^1.15.4",
|
||||
"@orpc/experimental-ratelimit": "^1.15.4",
|
||||
"@orpc/json-schema": "^1.15.4",
|
||||
"@orpc/openapi": "^1.15.4",
|
||||
"@orpc/server": "^1.15.4",
|
||||
"@orpc/zod": "^1.15.4",
|
||||
"@react-pdf/hyphenate": "0.1.0",
|
||||
"@react-pdf/renderer": "^4.9.0",
|
||||
"@reactive-resume/api": "workspace:*",
|
||||
@@ -58,10 +58,12 @@
|
||||
"@sindresorhus/slugify": "^3.0.1",
|
||||
"@t3-oss/env-core": "^0.13.11",
|
||||
"@uiw/color-convert": "^2.10.3",
|
||||
"ai": "^7.0.93",
|
||||
"@vercel/blob": "^2.8.0",
|
||||
"@vercel/functions": "^3.9.9",
|
||||
"ai": "^7.0.118",
|
||||
"bcrypt": "^6.0.0",
|
||||
"better-auth": "1.7.3",
|
||||
"cjk-regex": "^3.4.0",
|
||||
"better-auth": "1.7.6",
|
||||
"cjk-regex": "^3.5.0",
|
||||
"css-tree": "^3.2.1",
|
||||
"deepmerge-ts": "^8.0.2",
|
||||
"drizzle-orm": "1.0.0-rc.4",
|
||||
@@ -69,34 +71,36 @@
|
||||
"es-toolkit": "^1.52.0",
|
||||
"fast-json-patch": "^3.1.1",
|
||||
"fast-png": "^8.0.0",
|
||||
"hono": "^4.13.7",
|
||||
"hono": "^4.13.9",
|
||||
"ioredis": "^6.0.0",
|
||||
"jose": "^6.2.12",
|
||||
"jsonrepair": "^3.15.0",
|
||||
"node-html-parser": "^9.0.3",
|
||||
"nodemailer": "^10.0.0",
|
||||
"node-html-parser": "^9.0.4",
|
||||
"nodemailer": "^10.0.11",
|
||||
"ollama-ai-provider-v2": "^4.0.1",
|
||||
"pg": "^8.23.0",
|
||||
"phosphor-icons-react-pdf": "^0.1.3",
|
||||
"react": "^19.2.8",
|
||||
"react-email": "^6.9.3",
|
||||
"react": "^19.3.0",
|
||||
"react-email": "^6.11.0",
|
||||
"react-pdf-html": "^2.1.5",
|
||||
"resumable-stream": "^2.2.12",
|
||||
"resumable-stream": "^2.2.13",
|
||||
"sanitize-html": "^2.17.7",
|
||||
"sharp": "^0.35.4",
|
||||
"sharp": "^0.35.5",
|
||||
"tokenx": "^2.1.0",
|
||||
"ts-pattern": "^5.9.0",
|
||||
"unique-names-generator": "^4.7.1",
|
||||
"uuid": "^14.0.2",
|
||||
"zod": "^4.5.4"
|
||||
"zod": "^4.6.5"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@reactive-resume/config": "workspace:*",
|
||||
"@types/node": "^26.4.1",
|
||||
"@types/node": "^26.6.3",
|
||||
"@types/pg": "^8.23.1",
|
||||
"@types/react": "^19.2.18",
|
||||
"@types/react": "^19.3.0",
|
||||
"@typescript/native-preview": "7.0.0-dev.20260707.2",
|
||||
"tsdown": "^0.23.0",
|
||||
"tsx": "^4.23.13",
|
||||
"tsx": "^4.23.15",
|
||||
"typescript": "^7.0.2",
|
||||
"vitest": "^5.0.0"
|
||||
"vitest": "^5.0.2"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -3,6 +3,7 @@ import type { Context } from "hono";
|
||||
import { isIP } from "node:net";
|
||||
import { getConnInfo } from "@hono/node-server/conninfo";
|
||||
import { Hono } from "hono";
|
||||
import { prepareStagedBody, withStagedBody } from "@reactive-resume/api/features/storage/transport";
|
||||
import { handleMcp } from "../mcp/handler";
|
||||
import { handleOpenApi } from "../openapi/handler";
|
||||
import {
|
||||
@@ -33,8 +34,14 @@ const getTrustedClient = (context: Context<ServerEnvironment>): string => {
|
||||
}
|
||||
};
|
||||
|
||||
export function createApp() {
|
||||
type AppOptions = {
|
||||
serveStatic?: boolean;
|
||||
trustedClient?: (request: Request) => string;
|
||||
};
|
||||
|
||||
export function createApp(options: AppOptions = {}) {
|
||||
const app = new Hono<ServerEnvironment>();
|
||||
const client = (c: Context<ServerEnvironment>) => options.trustedClient?.(c.req.raw) ?? getTrustedClient(c);
|
||||
|
||||
app.use("/auth/*", async (c, next) => {
|
||||
await next();
|
||||
@@ -44,15 +51,16 @@ export function createApp() {
|
||||
c.header("Cache-Control", "no-store");
|
||||
});
|
||||
|
||||
app.all("/api/rpc", (c) => handleRpc(c.req.raw, getTrustedClient(c)));
|
||||
app.all("/api/rpc/*", (c) => handleRpc(c.req.raw, getTrustedClient(c)));
|
||||
app.all("/api/openapi", (c) => handleOpenApi(c.req.raw, getTrustedClient(c)));
|
||||
app.all("/api/openapi/*", (c) => handleOpenApi(c.req.raw, getTrustedClient(c)));
|
||||
app.post("/api/storage/stage", (c) => prepareStagedBody(c.req.raw));
|
||||
app.all("/api/rpc", (c) => withStagedBody(c.req.raw, (request) => handleRpc(request, client(c))));
|
||||
app.all("/api/rpc/*", (c) => withStagedBody(c.req.raw, (request) => handleRpc(request, client(c))));
|
||||
app.all("/api/openapi", (c) => handleOpenApi(c.req.raw, client(c)));
|
||||
app.all("/api/openapi/*", (c) => handleOpenApi(c.req.raw, client(c)));
|
||||
app.get("/api/auth/oauth", (c) => handleOAuth(c.req.raw));
|
||||
app.all("/api/auth/*", (c) => handleAuth(c.req.raw));
|
||||
app.get("/api/health", () => handleHealth());
|
||||
app.get("/api/resumes/:username/:slug/pdf", (c) =>
|
||||
handlePublicResumePdf(c.req.raw, c.req.param("username"), c.req.param("slug"), getTrustedClient(c)),
|
||||
handlePublicResumePdf(c.req.raw, c.req.param("username"), c.req.param("slug"), client(c)),
|
||||
);
|
||||
app.get("/api/resumes/:id/pdf", (c) => handleResumePdfDownload(c.req.raw, c.req.param("id")));
|
||||
app.get("/api/uploads/*", (c) => handleUpload(c.req.raw));
|
||||
@@ -76,7 +84,7 @@ export function createApp() {
|
||||
// Must precede the static middleware: serveStatic resolves "/" to dist/index.html and would
|
||||
// return it verbatim, skipping the OpenGraph/Twitter/canonical/JSON-LD injection in handleWebApp.
|
||||
app.on(["GET", "HEAD"], "/", (c) => handleWebApp(c.req.raw));
|
||||
app.use("/*", serveWebDistStatic);
|
||||
if (options.serveStatic !== false) app.use("/*", serveWebDistStatic);
|
||||
app.on(["GET", "HEAD"], "/*", (c) => handleWebApp(c.req.raw));
|
||||
|
||||
return app;
|
||||
|
||||
@@ -53,13 +53,28 @@ describe("handleAuth", () => {
|
||||
},
|
||||
);
|
||||
|
||||
it("rejects untrusted dynamic OAuth redirect URIs in safe mode", async () => {
|
||||
it("registers third-party https callbacks so remote MCP clients can complete DCR", async () => {
|
||||
const { handleAuth } = await import("./auth");
|
||||
|
||||
const response = await handleAuth(
|
||||
new Request("http://localhost:3001/api/auth/oauth2/register", {
|
||||
method: "POST",
|
||||
body: JSON.stringify({ redirect_uris: ["https://evil.example.com/callback"] }),
|
||||
body: JSON.stringify({ redirect_uris: ["https://claude.ai/api/mcp/auth_callback"] }),
|
||||
headers: { "content-type": "application/json" },
|
||||
}),
|
||||
);
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(mocks.handler).toHaveBeenCalledOnce();
|
||||
});
|
||||
|
||||
it("rejects unsafe dynamic OAuth redirect URIs in safe mode", async () => {
|
||||
const { handleAuth } = await import("./auth");
|
||||
|
||||
const response = await handleAuth(
|
||||
new Request("http://localhost:3001/api/auth/oauth2/register", {
|
||||
method: "POST",
|
||||
body: JSON.stringify({ redirect_uris: ["https://192.168.1.10/callback"] }),
|
||||
headers: { "content-type": "application/json" },
|
||||
}),
|
||||
);
|
||||
@@ -106,6 +121,25 @@ describe("handleAuth", () => {
|
||||
},
|
||||
);
|
||||
|
||||
it.each(["client_secret_basic", "client_secret_post"])(
|
||||
"keeps an explicitly registered %s so the client receives a client secret",
|
||||
async (method) => {
|
||||
const { handleAuth } = await import("./auth");
|
||||
await handleAuth(
|
||||
new Request("http://localhost:3000/api/auth/oauth2/register", {
|
||||
method: "POST",
|
||||
headers: { "content-type": "application/json" },
|
||||
body: JSON.stringify({
|
||||
redirect_uris: ["https://example.com/callback"],
|
||||
token_endpoint_auth_method: method,
|
||||
}),
|
||||
}),
|
||||
);
|
||||
const forwarded = mocks.handler.mock.calls[0]?.[0] as Request;
|
||||
await expect(forwarded.json()).resolves.toMatchObject({ token_endpoint_auth_method: method });
|
||||
},
|
||||
);
|
||||
|
||||
it.each([
|
||||
{ redirect_uris: ["https://example.com/callback"] },
|
||||
{ redirect_uris: ["http://localhost.evil.example/callback"] },
|
||||
|
||||
@@ -82,8 +82,12 @@ async function defaultPublicClientRegistration(request: Request): Promise<Reques
|
||||
if (allLoopback) body.application_type = "native";
|
||||
}
|
||||
|
||||
// MCP clients that authenticate with PKCE alone omit the method, and Better Auth
|
||||
// would otherwise register them as `client_secret_basic`. Honor an explicit choice:
|
||||
// forcing it to "none" issues no client secret, so the client's own Basic/post
|
||||
// credentials are rejected at the token endpoint with 401 invalid_client.
|
||||
if (!request.headers.get("authorization")) {
|
||||
body.token_endpoint_auth_method = "none";
|
||||
body.token_endpoint_auth_method ??= "none";
|
||||
}
|
||||
|
||||
return new Request(url.toString(), {
|
||||
|
||||
@@ -2,6 +2,7 @@ import { sql } from "drizzle-orm";
|
||||
import { withTimeout } from "es-toolkit";
|
||||
import { getStorageService } from "@reactive-resume/api/features/storage";
|
||||
import { db } from "@reactive-resume/db/client";
|
||||
import { getRedis } from "@reactive-resume/db/redis";
|
||||
import { appVersion } from "../app-version";
|
||||
|
||||
const HEALTHCHECK_TIMEOUT_MS = 1_500;
|
||||
@@ -32,13 +33,13 @@ async function runCheck(check: () => Promise<object>): Promise<CheckResult> {
|
||||
}
|
||||
}
|
||||
|
||||
function publicCheck(check: CheckResult, name: "Database" | "Storage"): CheckResult {
|
||||
function publicCheck(check: CheckResult, name: "Database" | "Storage" | "Redis"): CheckResult {
|
||||
if (check.status === "healthy") return check;
|
||||
return {
|
||||
status: check.status,
|
||||
latencyMs: check.latencyMs,
|
||||
error: `${name} health check failed.`,
|
||||
...(check.type === "local" || check.type === "s3" ? { type: check.type } : {}),
|
||||
...(check.type === "local" || check.type === "s3" || check.type === "blob" ? { type: check.type } : {}),
|
||||
};
|
||||
}
|
||||
|
||||
@@ -51,8 +52,18 @@ async function checkDatabase() {
|
||||
const checkStorage = () => getStorageService().healthcheck();
|
||||
|
||||
export async function handleHealth() {
|
||||
const [database, storage] = await Promise.all([runCheck(checkDatabase), runCheck(checkStorage)]);
|
||||
const status = [database, storage].some((check) => check.status === "unhealthy") ? "unhealthy" : "healthy";
|
||||
const redisClient = getRedis();
|
||||
const [database, storage, redis] = await Promise.all([
|
||||
runCheck(checkDatabase),
|
||||
runCheck(checkStorage),
|
||||
redisClient
|
||||
? runCheck(async () => {
|
||||
await redisClient.ping();
|
||||
return { status: "healthy" };
|
||||
})
|
||||
: undefined,
|
||||
]);
|
||||
const status = [database, storage, redis].some((check) => check?.status === "unhealthy") ? "unhealthy" : "healthy";
|
||||
|
||||
const checks = {
|
||||
service: "reactive-resume",
|
||||
@@ -62,6 +73,7 @@ export async function handleHealth() {
|
||||
uptime: `${process.uptime().toFixed(2)}s`,
|
||||
database: publicCheck(database, "Database"),
|
||||
storage: publicCheck(storage, "Storage"),
|
||||
...(redis ? { redis: publicCheck(redis, "Redis") } : {}),
|
||||
};
|
||||
|
||||
if (status === "unhealthy") {
|
||||
|
||||
@@ -156,6 +156,89 @@ describe.skipIf(!databaseURL)("MCP OAuth flow with PostgreSQL", () => {
|
||||
expect([claims.aud].flat()).toContain(`${origin}/mcp`);
|
||||
expect((await handleAuth(tokenRequest())).status).toBe(400);
|
||||
}, 30_000);
|
||||
it("exchanges a code for a confidential client that registered client_secret_basic", async () => {
|
||||
if (!databaseURL) return;
|
||||
process.env.DATABASE_URL = databaseURL;
|
||||
process.env.APP_URL = "http://localhost:33920";
|
||||
process.env.AUTH_SECRET = "oauth-integration-test-secret-only";
|
||||
const { handleAuth, handleOAuth } = await import("./auth");
|
||||
const origin = process.env.APP_URL;
|
||||
const redirectURI = "http://127.0.0.1:33921/callback";
|
||||
const request = (path: string, body: object, cookie = "") =>
|
||||
new Request(`${origin}/api/auth/${path}`, {
|
||||
method: "POST",
|
||||
headers: { "content-type": "application/json", origin, cookie },
|
||||
body: JSON.stringify(body),
|
||||
});
|
||||
|
||||
const registration = await handleAuth(
|
||||
request("oauth2/register", {
|
||||
client_name: "Confidential MCP client",
|
||||
redirect_uris: [redirectURI],
|
||||
token_endpoint_auth_method: "client_secret_basic",
|
||||
}),
|
||||
);
|
||||
expect(registration.status, await registration.clone().text()).toBe(201);
|
||||
const client = await registration.json();
|
||||
// Downgrading this to a public client leaves the client without a secret, and its
|
||||
// Basic-authenticated token exchange then fails with 401 invalid_client.
|
||||
expect(client.token_endpoint_auth_method).toBe("client_secret_basic");
|
||||
expect(client.client_secret).toBeTruthy();
|
||||
|
||||
const verifier = randomBytes(32).toString("base64url");
|
||||
const query = new URLSearchParams({
|
||||
client_id: client.client_id,
|
||||
redirect_uri: redirectURI,
|
||||
response_type: "code",
|
||||
scope: "openid profile offline_access",
|
||||
code_challenge: createHash("sha256").update(verifier).digest("base64url"),
|
||||
code_challenge_method: "S256",
|
||||
resource: `${origin}/mcp`,
|
||||
state: "opaque-state",
|
||||
});
|
||||
const authorize = await handleAuth(new Request(`${origin}/api/auth/oauth2/authorize?${query}`));
|
||||
const login = await handleOAuth(new Request(new URL(authorize.headers.get("location") ?? "", origin)));
|
||||
const callbackURL = new URL(login.headers.get("location") ?? "", origin).searchParams.get("callbackURL");
|
||||
|
||||
const unique = randomBytes(6).toString("hex");
|
||||
const signup = await handleAuth(
|
||||
request("sign-up/email", {
|
||||
name: "Confidential Test",
|
||||
email: `confidential-${unique}@example.com`,
|
||||
username: `confidential-${unique}`,
|
||||
password: "password123",
|
||||
}),
|
||||
);
|
||||
expect(signup.status, await signup.clone().text()).toBe(200);
|
||||
const cookie = signup.headers
|
||||
.getSetCookie()
|
||||
.map((value) => value.split(";", 1)[0])
|
||||
.join("; ");
|
||||
const callback = await handleOAuth(new Request(`${origin}${callbackURL}`, { headers: { cookie } }));
|
||||
const oauth_query = new URL(callback.headers.get("location") ?? "", origin).search.slice(1);
|
||||
const accepted = await handleAuth(request("oauth2/consent", { accept: true, oauth_query }, cookie));
|
||||
expect(accepted.status, await accepted.clone().text()).toBe(200);
|
||||
const code = new URL((await accepted.json()).url).searchParams.get("code");
|
||||
|
||||
const tokenResponse = await handleAuth(
|
||||
new Request(`${origin}/api/auth/oauth2/token`, {
|
||||
method: "POST",
|
||||
headers: {
|
||||
"content-type": "application/x-www-form-urlencoded",
|
||||
authorization: `Basic ${Buffer.from(`${client.client_id}:${client.client_secret}`).toString("base64")}`,
|
||||
},
|
||||
body: new URLSearchParams({
|
||||
grant_type: "authorization_code",
|
||||
code: code ?? "",
|
||||
redirect_uri: redirectURI,
|
||||
code_verifier: verifier,
|
||||
resource: `${origin}/mcp`,
|
||||
}),
|
||||
}),
|
||||
);
|
||||
expect(tokenResponse.status, await tokenResponse.clone().text()).toBe(200);
|
||||
await expect(tokenResponse.json()).resolves.toMatchObject({ token_type: "Bearer" });
|
||||
}, 30_000);
|
||||
it.each(["login", "max-age", "create"])(
|
||||
"requires fresh authentication for %s without looping",
|
||||
async (mode) => {
|
||||
|
||||
@@ -35,6 +35,7 @@ export async function handlePublicResumePdf(
|
||||
});
|
||||
} catch (error) {
|
||||
const status = errorStatus(error);
|
||||
if (status === 500) console.error("Public resume PDF generation failed", error);
|
||||
return noStoreResponse(
|
||||
status === 500 ? "Failed to generate public resume PDF" : "Public resume PDF unavailable",
|
||||
status,
|
||||
|
||||
@@ -16,6 +16,12 @@ vi.mock("./http/app", () => {
|
||||
},
|
||||
};
|
||||
});
|
||||
vi.mock("@reactive-resume/auth/config", () => ({
|
||||
initializeAuth: async () => {
|
||||
await Promise.resolve();
|
||||
events.push("auth ready");
|
||||
},
|
||||
}));
|
||||
vi.mock("@hono/node-server", () => ({
|
||||
serve: () => {
|
||||
events.push("server listening");
|
||||
@@ -30,6 +36,6 @@ describe("server startup", () => {
|
||||
const entry = await import("./index");
|
||||
expect(events).toEqual([]);
|
||||
await entry.main();
|
||||
expect(events).toEqual(["migrations complete", "auth imported", "app created", "server listening"]);
|
||||
expect(events).toEqual(["migrations complete", "auth imported", "auth ready", "app created", "server listening"]);
|
||||
});
|
||||
});
|
||||
|
||||
@@ -6,9 +6,10 @@ import { runStartupChecks } from "./startup/checks";
|
||||
export async function main() {
|
||||
await runStartupChecks();
|
||||
|
||||
// OAuth resource seeding starts when auth is imported, so load the app only
|
||||
// after migrations have created the provider tables.
|
||||
// Load and initialize auth only after migrations have created the provider tables.
|
||||
const { createApp } = await import("./http/app");
|
||||
const { initializeAuth } = await import("@reactive-resume/auth/config");
|
||||
await initializeAuth();
|
||||
|
||||
// Safety net: Node 24 crashes the whole process on an unhandled rejection. One request's
|
||||
// stray promise must not take the server down for everyone, so log and keep serving.
|
||||
|
||||
@@ -3,7 +3,13 @@ import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
|
||||
import { onError } from "@orpc/client";
|
||||
import { createRouterClient } from "@orpc/server";
|
||||
import router from "@reactive-resume/api/routers";
|
||||
import { MCP_TOOL_NAME, registerPrompts, registerResources, registerTools } from "@reactive-resume/mcp";
|
||||
import {
|
||||
buildMcpServerInfo,
|
||||
MCP_TOOL_NAME,
|
||||
registerPrompts,
|
||||
registerResources,
|
||||
registerTools,
|
||||
} from "@reactive-resume/mcp";
|
||||
import { appVersion } from "../app-version";
|
||||
import { getRequestLocale } from "../rpc/locale";
|
||||
|
||||
@@ -23,41 +29,19 @@ function createRequestClient(request: Request): RouterClient<typeof router> {
|
||||
}
|
||||
|
||||
export function createMcpServer(request: Request) {
|
||||
const server = new McpServer(
|
||||
{
|
||||
name: "reactive-resume",
|
||||
version: appVersion,
|
||||
title: "Reactive Resume",
|
||||
websiteUrl: "https://rxresu.me",
|
||||
description:
|
||||
"Reactive Resume is a free and open-source resume builder. Use this MCP server to interact with your resume using an LLM of your choice.",
|
||||
icons: [
|
||||
{
|
||||
src: "https://rxresu.me/icon/light.svg",
|
||||
mimeType: "image/svg+xml",
|
||||
theme: "light",
|
||||
},
|
||||
{
|
||||
src: "https://rxresu.me/icon/dark.svg",
|
||||
mimeType: "image/svg+xml",
|
||||
theme: "dark",
|
||||
},
|
||||
],
|
||||
},
|
||||
{
|
||||
instructions: [
|
||||
"You are connected to Reactive Resume over MCP.",
|
||||
"Authenticate with OAuth (recommended) or an API key (`x-api-key`).",
|
||||
`Discover resume IDs with \`${MCP_TOOL_NAME.listResumes}\` (not \`resources/list\`).`,
|
||||
`List distinct tags with \`${MCP_TOOL_NAME.listResumeTags}\`.`,
|
||||
`Read schema at \`resume://_meta/schema\`; read resume JSON via \`resume://{id}\` or \`${MCP_TOOL_NAME.getResume}\`.`,
|
||||
`Apply body edits with JSON Patch through \`${MCP_TOOL_NAME.patchResume}\`.`,
|
||||
`Change name, slug, tags, or public visibility with \`${MCP_TOOL_NAME.updateResume}\` (returns canonical share URL; anonymous access only when \`isPublic\` is true; passwords are managed in the web app only).`,
|
||||
`Create short-lived authenticated PDF download URLs with \`${MCP_TOOL_NAME.downloadResumePdf}\`; set target to \`cover-letter\` to export a visible cover letter separately.`,
|
||||
`Import full ResumeData JSON with \`${MCP_TOOL_NAME.importResume}\`.`,
|
||||
].join(" "),
|
||||
},
|
||||
);
|
||||
const server = new McpServer(buildMcpServerInfo(appVersion), {
|
||||
instructions: [
|
||||
"You are connected to Reactive Resume over MCP.",
|
||||
"Authenticate with OAuth (recommended) or an API key (`x-api-key`).",
|
||||
`Discover resume IDs with \`${MCP_TOOL_NAME.listResumes}\` (not \`resources/list\`).`,
|
||||
`List distinct tags with \`${MCP_TOOL_NAME.listResumeTags}\`.`,
|
||||
`Read schema at \`resume://_meta/schema\`; read resume JSON via \`resume://{id}\` or \`${MCP_TOOL_NAME.getResume}\`.`,
|
||||
`Apply body edits with JSON Patch through \`${MCP_TOOL_NAME.patchResume}\`.`,
|
||||
`Change name, slug, tags, or public visibility with \`${MCP_TOOL_NAME.updateResume}\` (returns canonical share URL; anonymous access only when \`isPublic\` is true; passwords are managed in the web app only).`,
|
||||
`Create short-lived authenticated PDF download URLs with \`${MCP_TOOL_NAME.downloadResumePdf}\`; set target to \`cover-letter\` to export a visible cover letter separately.`,
|
||||
`Import full ResumeData JSON with \`${MCP_TOOL_NAME.importResume}\`.`,
|
||||
].join(" "),
|
||||
});
|
||||
|
||||
const client = createRequestClient(request);
|
||||
registerResources(server, client);
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
import { readFile, writeFile } from "node:fs/promises";
|
||||
import { fileURLToPath } from "node:url";
|
||||
|
||||
export async function generateOpenApiDocumentation(
|
||||
async function generateOpenApiDocumentation(
|
||||
target = fileURLToPath(new URL("../../../../docs/spec.json", import.meta.url)),
|
||||
) {
|
||||
const packageJson = JSON.parse(await readFile(new URL("../../../../package.json", import.meta.url), "utf8")) as {
|
||||
|
||||
@@ -1,3 +1,4 @@
|
||||
import { readFile } from "node:fs/promises";
|
||||
import { describe, expect, it, vi } from "vitest";
|
||||
import z from "zod";
|
||||
import { defaultResumeData } from "@reactive-resume/schema/resume/default";
|
||||
@@ -16,6 +17,11 @@ type GeneratedSpecView = {
|
||||
Record<
|
||||
string,
|
||||
{
|
||||
tags?: string[];
|
||||
operationId?: string;
|
||||
summary?: string;
|
||||
description?: string;
|
||||
responses?: Record<string, { description?: string }>;
|
||||
requestBody?: {
|
||||
content?: Record<string, { schema?: unknown }>;
|
||||
};
|
||||
@@ -72,6 +78,51 @@ function findImpossibleRequestSchemas(spec: GeneratedSpecView) {
|
||||
}
|
||||
|
||||
describe("generateOpenApiSpec", () => {
|
||||
it("documents all cover-letter procedures with REST metadata", async () => {
|
||||
const spec = (await generateSpec()) as GeneratedSpecView;
|
||||
const expected = [
|
||||
["get", "/cover-letters", "listCoverLetters", "List cover letters", "200"],
|
||||
["get", "/cover-letters/{id}", "getCoverLetter", "Get cover letter by ID", "200"],
|
||||
["post", "/cover-letters", "createCoverLetter", "Create a cover letter", "200"],
|
||||
["put", "/cover-letters/{id}", "updateCoverLetter", "Update a cover letter", "200"],
|
||||
["post", "/cover-letters/{id}/refresh-style", "refreshCoverLetterStyle", "Refresh cover letter style", "200"],
|
||||
["post", "/cover-letters/{id}/duplicate", "duplicateCoverLetter", "Duplicate a cover letter", "200"],
|
||||
["delete", "/cover-letters/{id}", "deleteCoverLetter", "Delete a cover letter", "200"],
|
||||
["post", "/cover-letters/from-resume", "copyEmbeddedCoverLetter", "Copy an embedded cover letter", "200"],
|
||||
["get", "/cover-letters/{id}/export", "exportCoverLetter", "Export a cover letter", "200"],
|
||||
["post", "/cover-letters/import", "importCoverLetter", "Import a cover letter", "200"],
|
||||
] as const;
|
||||
|
||||
for (const [method, path, operationId, summary, successStatus] of expected) {
|
||||
const operation = spec.paths?.[path]?.[method];
|
||||
expect(operation).toMatchObject({
|
||||
tags: ["Cover Letters"],
|
||||
operationId,
|
||||
summary,
|
||||
description: expect.any(String),
|
||||
responses: { [successStatus]: { description: expect.any(String) } },
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
it("keeps published cover-letter operations in sync with the runtime spec", async () => {
|
||||
const published = JSON.parse(
|
||||
await readFile(new URL("../../../../docs/spec.json", import.meta.url), "utf8"),
|
||||
) as GeneratedSpecView;
|
||||
const runtime = await generateSpec();
|
||||
const coverLetterPaths = (spec: GeneratedSpecView) =>
|
||||
Object.fromEntries(
|
||||
Object.entries(spec.paths ?? {}).filter(
|
||||
([path]) => path.startsWith("/cover-letters") || path.startsWith("/coverLetters/"),
|
||||
),
|
||||
);
|
||||
|
||||
const publishedPaths = coverLetterPaths(published);
|
||||
const runtimePaths = coverLetterPaths(runtime as GeneratedSpecView);
|
||||
expect(Object.keys(publishedPaths).sort()).toEqual(Object.keys(runtimePaths).sort());
|
||||
expect(publishedPaths).toEqual(runtimePaths);
|
||||
});
|
||||
|
||||
it("uses caller-provided application URL and version", async () => {
|
||||
const spec = await generateSpec();
|
||||
|
||||
|
||||
@@ -84,7 +84,7 @@ export async function generateOpenApiSpec({ appUrl, version }: GenerateOpenApiSp
|
||||
title: "Reactive Resume",
|
||||
version,
|
||||
description: "Reactive Resume API",
|
||||
license: { name: "MIT", url: "https://github.com/amruthpillai/reactive-resume/blob/main/LICENSE" },
|
||||
license: { name: "MIT", url: "https://github.com/reactive-resume/reactive-resume/blob/main/LICENSE" },
|
||||
contact: { name: "Amruth Pillai", email: "hello@amruthpillai.com", url: "https://amruthpillai.com" },
|
||||
},
|
||||
servers: [{ url: `${appUrl}/api/openapi` }],
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
import { initializeAuth } from "@reactive-resume/auth/config";
|
||||
import { getPool } from "@reactive-resume/db/client";
|
||||
import { env } from "@reactive-resume/env/server";
|
||||
import { runDatabaseMigrations } from "./startup/checks";
|
||||
|
||||
if (process.env.VERCEL_ENV === "preview" && process.env.ALLOW_PREVIEW_MIGRATIONS !== "true") {
|
||||
throw new Error(
|
||||
"Preview deployment needs an isolated database. Set ALLOW_PREVIEW_MIGRATIONS=true only after connecting one.",
|
||||
);
|
||||
}
|
||||
|
||||
if (process.env.VERCEL === "1") {
|
||||
if (env.STORAGE_BACKEND !== "blob")
|
||||
throw new Error("Vercel requires private Blob storage for direct uploads. Docker supports local, S3, and Blob.");
|
||||
if (!env.REDIS_URL || !env.ENCRYPTION_SECRET) throw new Error("Vercel requires Redis and ENCRYPTION_SECRET.");
|
||||
}
|
||||
await runDatabaseMigrations();
|
||||
|
||||
await initializeAuth();
|
||||
await getPool().end();
|
||||
@@ -7,6 +7,7 @@ import { migrate } from "drizzle-orm/node-postgres/migrator";
|
||||
import { Pool } from "pg";
|
||||
import { env } from "@reactive-resume/env/server";
|
||||
import { getLocalDataDirectory } from "@reactive-resume/utils/monorepo.node";
|
||||
import { verifyMigratedSchema } from "./schema-check";
|
||||
|
||||
function resolveFromCurrentModule(relativePath: string) {
|
||||
return fileURLToPath(new URL(relativePath, import.meta.url));
|
||||
@@ -24,25 +25,54 @@ function resolveWorkspaceFolder(folderName: string): string {
|
||||
throw new Error(`Could not locate ${folderName} folder relative to ${resolveFromCurrentModule(".")}`);
|
||||
}
|
||||
|
||||
async function runDatabaseMigrations() {
|
||||
export async function runDatabaseMigrations() {
|
||||
console.info("Running database migrations...");
|
||||
|
||||
const pool = new Pool({ connectionString: env.DATABASE_URL });
|
||||
const db = drizzle({ client: pool });
|
||||
const pool = new Pool({
|
||||
connectionString: env.DATABASE_MIGRATION_URL ?? env.DATABASE_URL,
|
||||
max: 1,
|
||||
connectionTimeoutMillis: 10_000,
|
||||
});
|
||||
|
||||
try {
|
||||
await migrate(db, { migrationsFolder: resolveWorkspaceFolder("migrations") });
|
||||
console.info("Database migrations completed");
|
||||
} catch (error) {
|
||||
console.error("Database migrations failed", { error });
|
||||
throw error;
|
||||
const client = await pool.connect();
|
||||
try {
|
||||
await client.query("SELECT pg_advisory_lock(721830451)");
|
||||
const db = drizzle({ client });
|
||||
try {
|
||||
await migrate(db, { migrationsFolder: resolveWorkspaceFolder("migrations") });
|
||||
console.info("Database migrations completed");
|
||||
} catch (error) {
|
||||
console.error("Database migrations failed", { error });
|
||||
throw error;
|
||||
}
|
||||
|
||||
// Post-migration verification is not a migration failure, so it gets its own log
|
||||
// message. A drifted schema still lets the server boot; STRICT_SCHEMA_CHECK=true
|
||||
// makes the drift fatal instead.
|
||||
try {
|
||||
await verifyMigratedSchema(client);
|
||||
} catch (error) {
|
||||
console.error("Database schema verification failed", { error });
|
||||
if (env.STRICT_SCHEMA_CHECK) throw error;
|
||||
console.error(
|
||||
"Continuing with a drifted database schema; set STRICT_SCHEMA_CHECK=true to refuse startup instead.",
|
||||
);
|
||||
}
|
||||
} finally {
|
||||
try {
|
||||
await client.query("SELECT pg_advisory_unlock(721830451)");
|
||||
} finally {
|
||||
client.release();
|
||||
}
|
||||
}
|
||||
} finally {
|
||||
await pool.end();
|
||||
}
|
||||
}
|
||||
|
||||
async function validateLocalStoragePath() {
|
||||
if (env.S3_ACCESS_KEY_ID && env.S3_SECRET_ACCESS_KEY && env.S3_BUCKET) return;
|
||||
if (env.STORAGE_BACKEND !== "local") return;
|
||||
|
||||
const dataDirectory = getLocalDataDirectory(env.LOCAL_STORAGE_PATH);
|
||||
console.info(`Validating local storage path: ${dataDirectory}`);
|
||||
|
||||
@@ -0,0 +1,50 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { collectExpectedColumns, verifyMigratedSchema } from "./schema-check";
|
||||
|
||||
describe("collectExpectedColumns", () => {
|
||||
it("collects every column of every schema table", () => {
|
||||
const expected = collectExpectedColumns();
|
||||
expect(expected.length).toBeGreaterThan(0);
|
||||
expect(expected).toContainEqual({ tableName: "ai_providers", columnName: "user_id" });
|
||||
expect(expected).toContainEqual({ tableName: "user", columnName: "id" });
|
||||
});
|
||||
});
|
||||
|
||||
describe("verifyMigratedSchema", () => {
|
||||
it("passes when the catalog reports nothing missing", async () => {
|
||||
const queryable = { query: async () => ({ rows: [] }) };
|
||||
await expect(verifyMigratedSchema(queryable)).resolves.toBeUndefined();
|
||||
});
|
||||
|
||||
it("fails with the table name when every column of a table is missing", async () => {
|
||||
const rows = collectExpectedColumns()
|
||||
.filter((e) => e.tableName === "ai_providers")
|
||||
.map((e) => ({ table_name: e.tableName, column_name: e.columnName }));
|
||||
|
||||
const queryable = { query: async () => ({ rows }) };
|
||||
await expect(verifyMigratedSchema(queryable)).rejects.toThrow('table "ai_providers"');
|
||||
});
|
||||
|
||||
it("fails with the qualified column name when only some columns are missing", async () => {
|
||||
const queryable = { query: async () => ({ rows: [{ table_name: "user", column_name: "role" }] }) };
|
||||
await expect(verifyMigratedSchema(queryable)).rejects.toThrow('"user"."role"');
|
||||
});
|
||||
|
||||
it("passes the expected table and column lists to the catalog query", async () => {
|
||||
let captured: unknown[] | undefined;
|
||||
const queryable = {
|
||||
query: (_text: string, values?: unknown[]) => {
|
||||
captured = values;
|
||||
return Promise.resolve({ rows: [] });
|
||||
},
|
||||
};
|
||||
|
||||
await verifyMigratedSchema(queryable);
|
||||
|
||||
const [tables, columns] = captured as [string[], string[]];
|
||||
// The query relies on $1/$2 being index-aligned, so each table name must pair
|
||||
// with its own column name at the same index.
|
||||
const pairs = tables.map((table, index) => `${table}.${columns[index]}`);
|
||||
expect(pairs).toContain("ai_providers.user_id");
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,71 @@
|
||||
import { is } from "drizzle-orm";
|
||||
import { getTableConfig, PgTable } from "drizzle-orm/pg-core";
|
||||
import * as schema from "@reactive-resume/db/schema";
|
||||
|
||||
interface SchemaQueryable {
|
||||
query(text: string, values?: unknown[]): Promise<{ rows: { table_name: string; column_name: string }[] }>;
|
||||
}
|
||||
|
||||
export function collectExpectedColumns() {
|
||||
const expected: { tableName: string; columnName: string }[] = [];
|
||||
|
||||
for (const value of Object.values(schema)) {
|
||||
if (!is(value, PgTable)) continue;
|
||||
const config = getTableConfig(value);
|
||||
for (const column of config.columns) expected.push({ tableName: config.name, columnName: column.name });
|
||||
}
|
||||
|
||||
return expected;
|
||||
}
|
||||
|
||||
// The migration ledger (drizzle.__drizzle_migrations) only records that a migration ran; it
|
||||
// cannot detect objects that were dropped or lost outside the migrator (a partial restore,
|
||||
// a manual DROP TABLE, or a recreated "public" schema while the "drizzle" schema survives).
|
||||
// Comparing the live catalog with the declared schema turns that silent drift into a startup
|
||||
// failure instead of runtime "relation does not exist" (42P01) errors. The comparison covers
|
||||
// tables and columns only — indexes, constraints, and enums are intentionally out of scope.
|
||||
export async function verifyMigratedSchema(queryable: SchemaQueryable): Promise<void> {
|
||||
const expected = collectExpectedColumns();
|
||||
if (expected.length === 0) return;
|
||||
|
||||
// $1 and $2 are index-aligned: $1[i] is the name of the table expected to contain $2[i].
|
||||
// Names are qualified as "public.<table>" so the lookup does not follow the connection's
|
||||
// search_path — migrations always create these tables in the public schema.
|
||||
const result = await queryable.query(
|
||||
`select e.table_name, e.column_name
|
||||
from unnest($1::text[], $2::text[]) as e(table_name, column_name)
|
||||
where to_regclass('public.' || e.table_name) is null
|
||||
or not exists (
|
||||
select 1 from pg_catalog.pg_attribute a
|
||||
where a.attrelid = to_regclass('public.' || e.table_name)
|
||||
and a.attname = e.column_name
|
||||
and a.attnum > 0 and not a.attisdropped
|
||||
)
|
||||
order by e.table_name, e.column_name`,
|
||||
[expected.map((e) => e.tableName), expected.map((e) => e.columnName)],
|
||||
);
|
||||
if (result.rows.length === 0) return;
|
||||
|
||||
const expectedPerTable = new Map<string, number>();
|
||||
for (const e of expected) expectedPerTable.set(e.tableName, (expectedPerTable.get(e.tableName) ?? 0) + 1);
|
||||
|
||||
const missingByTable = new Map<string, Set<string>>();
|
||||
for (const row of result.rows) {
|
||||
const columns = missingByTable.get(row.table_name) ?? new Set<string>();
|
||||
columns.add(row.column_name);
|
||||
missingByTable.set(row.table_name, columns);
|
||||
}
|
||||
|
||||
const missing = [...missingByTable.entries()].map(([table, columns]) =>
|
||||
columns.size === expectedPerTable.get(table)
|
||||
? `table "${table}"`
|
||||
: `column(s) ${[...columns].map((column) => `"${table}"."${column}"`).join(", ")}`,
|
||||
);
|
||||
|
||||
throw new Error(
|
||||
`Database schema does not match the migration ledger: ${missing.join(", ")} ` +
|
||||
"missing even though all migrations are marked as applied. This usually means the database was " +
|
||||
"restored from a backup that did not include these objects, or they were dropped outside of " +
|
||||
"migrations. Restore a consistent backup or recreate the missing objects, then restart the server.",
|
||||
);
|
||||
}
|
||||
@@ -127,13 +127,13 @@ function createRootSeoMarkup(canonicalUrl: string) {
|
||||
price: "0",
|
||||
priceCurrency: "USD",
|
||||
},
|
||||
codeRepository: "https://github.com/amruthpillai/reactive-resume",
|
||||
codeRepository: "https://github.com/reactive-resume/reactive-resume",
|
||||
},
|
||||
{
|
||||
"@type": "Project",
|
||||
name: "Reactive Resume",
|
||||
url: canonicalUrl,
|
||||
sameAs: ["https://github.com/amruthpillai/reactive-resume"],
|
||||
sameAs: ["https://github.com/reactive-resume/reactive-resume"],
|
||||
},
|
||||
{
|
||||
"@type": "FAQPage",
|
||||
|
||||
@@ -0,0 +1,99 @@
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
import { TRUSTED_IP_HEADERS } from "@reactive-resume/utils/rate-limit";
|
||||
|
||||
const mocks = vi.hoisted(() => ({
|
||||
ipAddress: vi.fn<(request: Request) => string | undefined>(),
|
||||
waitUntil: vi.fn(),
|
||||
initializeAuth: vi.fn(),
|
||||
attachDatabasePool: vi.fn(),
|
||||
configureAgentStreamLifetime: vi.fn(),
|
||||
pool: {},
|
||||
getPool: vi.fn(),
|
||||
createApp:
|
||||
vi.fn<
|
||||
(options: { serveStatic: boolean; trustedClient: (request: Request) => string }) => {
|
||||
fetch: (request: Request) => Promise<Response>;
|
||||
}
|
||||
>(),
|
||||
handle: vi.fn<(request: Request) => Promise<Response>>(),
|
||||
}));
|
||||
|
||||
vi.mock("@vercel/functions", () => ({
|
||||
ipAddress: mocks.ipAddress,
|
||||
waitUntil: mocks.waitUntil,
|
||||
attachDatabasePool: mocks.attachDatabasePool,
|
||||
}));
|
||||
vi.mock("@reactive-resume/api/features/agent/streams", () => ({
|
||||
configureAgentStreamLifetime: mocks.configureAgentStreamLifetime,
|
||||
}));
|
||||
vi.mock("@reactive-resume/auth/config", () => ({ initializeAuth: mocks.initializeAuth }));
|
||||
vi.mock("@reactive-resume/db/client", () => ({ getPool: mocks.getPool }));
|
||||
vi.mock("./http/app", () => ({ createApp: mocks.createApp }));
|
||||
|
||||
function spoofedRequest() {
|
||||
return new Request("https://resume.test/api/rpc?batch=1", {
|
||||
method: "POST",
|
||||
body: "original RPC body",
|
||||
headers: {
|
||||
...Object.fromEntries(TRUSTED_IP_HEADERS.map((header) => [header, "192.0.2.66"])),
|
||||
"x-forwarded-for": "192.0.2.66, 192.0.2.77",
|
||||
cookie: "session=original",
|
||||
authorization: "Bearer original",
|
||||
"content-type": "application/json",
|
||||
},
|
||||
});
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
vi.resetModules();
|
||||
vi.clearAllMocks();
|
||||
mocks.getPool.mockReturnValue(mocks.pool);
|
||||
mocks.handle.mockResolvedValue(new Response("handled"));
|
||||
mocks.createApp.mockReturnValue({ fetch: mocks.handle });
|
||||
});
|
||||
|
||||
describe("Vercel adapter", () => {
|
||||
it("registers platform lifetime hooks and disables filesystem static serving", async () => {
|
||||
await import("./vercel");
|
||||
expect(mocks.configureAgentStreamLifetime).toHaveBeenCalledExactlyOnceWith(mocks.waitUntil);
|
||||
expect(mocks.attachDatabasePool).toHaveBeenCalledExactlyOnceWith(mocks.pool);
|
||||
expect(mocks.createApp).toHaveBeenCalledExactlyOnceWith({
|
||||
serveStatic: false,
|
||||
trustedClient: expect.any(Function),
|
||||
});
|
||||
});
|
||||
|
||||
it.each(["203.0.113.9", "2001:db8::9"])("replaces all spoofed IP headers with platform IP %s", async (ip) => {
|
||||
mocks.ipAddress.mockReturnValue(ip);
|
||||
const { default: adapter } = await import("./vercel");
|
||||
const request = spoofedRequest();
|
||||
expect(await (await adapter.fetch(request)).text()).toBe("handled");
|
||||
expect(mocks.ipAddress).toHaveBeenCalledExactlyOnceWith(request);
|
||||
const forwarded = mocks.handle.mock.calls[0]?.[0];
|
||||
if (!forwarded) throw new Error("Expected forwarded request");
|
||||
for (const header of TRUSTED_IP_HEADERS) {
|
||||
const expected = ["x-real-ip", "x-forwarded-for"].includes(header.toLowerCase()) ? ip : null;
|
||||
expect(forwarded.headers.get(header)).toBe(expected);
|
||||
}
|
||||
expect(mocks.createApp.mock.calls[0]?.[0].trustedClient(forwarded)).toBe(ip);
|
||||
expect(forwarded.url).toBe(request.url);
|
||||
expect(forwarded.method).toBe("POST");
|
||||
expect(await forwarded.text()).toBe("original RPC body");
|
||||
expect(forwarded.headers.get("cookie")).toBe("session=original");
|
||||
expect(forwarded.headers.get("authorization")).toBe("Bearer original");
|
||||
expect(forwarded.headers.get("content-type")).toBe("application/json");
|
||||
});
|
||||
|
||||
it.each([undefined, "", "invalid-ip", "203.0.113.9, 192.0.2.66"])(
|
||||
"clears attacker headers when platform IP is missing or invalid: %s",
|
||||
async (ip) => {
|
||||
mocks.ipAddress.mockReturnValue(ip);
|
||||
const { default: adapter } = await import("./vercel");
|
||||
await adapter.fetch(spoofedRequest());
|
||||
const forwarded = mocks.handle.mock.calls[0]?.[0];
|
||||
if (!forwarded) throw new Error("Expected forwarded request");
|
||||
for (const header of TRUSTED_IP_HEADERS) expect(forwarded.headers.has(header)).toBe(false);
|
||||
expect(mocks.createApp.mock.calls[0]?.[0].trustedClient(forwarded)).toBe("unknown");
|
||||
},
|
||||
);
|
||||
});
|
||||
@@ -0,0 +1,29 @@
|
||||
import { isIP } from "node:net";
|
||||
import { attachDatabasePool, ipAddress, waitUntil } from "@vercel/functions";
|
||||
import { configureAgentStreamLifetime } from "@reactive-resume/api/features/agent/streams";
|
||||
import { initializeAuth } from "@reactive-resume/auth/config";
|
||||
import { getPool } from "@reactive-resume/db/client";
|
||||
import { TRUSTED_IP_HEADERS } from "@reactive-resume/utils/rate-limit";
|
||||
import { createApp } from "./http/app";
|
||||
|
||||
configureAgentStreamLifetime(waitUntil);
|
||||
attachDatabasePool(getPool());
|
||||
const app = createApp({
|
||||
serveStatic: false,
|
||||
trustedClient: (request) => request.headers.get("x-real-ip") ?? "unknown",
|
||||
});
|
||||
|
||||
export default {
|
||||
async fetch(request: Request) {
|
||||
await initializeAuth();
|
||||
const ip = ipAddress(request);
|
||||
const headers = new Headers(request.headers);
|
||||
for (const name of TRUSTED_IP_HEADERS) headers.delete(name);
|
||||
headers.delete("x-real-ip");
|
||||
if (ip && isIP(ip)) {
|
||||
headers.set("x-real-ip", ip);
|
||||
headers.set("x-forwarded-for", ip);
|
||||
}
|
||||
return app.fetch(new Request(request, { headers }));
|
||||
},
|
||||
};
|
||||
@@ -8,8 +8,35 @@ const rootPackageJson = JSON.parse(readFileSync(new URL("../../package.json", im
|
||||
version?: string;
|
||||
};
|
||||
|
||||
// Lambda disables require(ESM) and uses stricter CJS export detection than standalone Node.
|
||||
const bundledInteropPackages = new Set([
|
||||
"@uiw/color-convert",
|
||||
"@babel/runtime",
|
||||
"sanitize-html",
|
||||
"htmlparser2",
|
||||
"domhandler",
|
||||
"domutils",
|
||||
"domelementtype",
|
||||
"dom-serializer",
|
||||
"entities",
|
||||
"deepmerge",
|
||||
"escape-string-regexp",
|
||||
"is-plain-object",
|
||||
"parse-srcset",
|
||||
"postcss",
|
||||
"nanoid",
|
||||
"picocolors",
|
||||
"source-map-js",
|
||||
"launder",
|
||||
"dayjs",
|
||||
]);
|
||||
|
||||
const shouldExternalizeThirdParty = (id: string) => {
|
||||
if (id.startsWith("@reactive-resume/")) return false;
|
||||
const packageName = id
|
||||
.split("/")
|
||||
.slice(0, id.startsWith("@") ? 2 : 1)
|
||||
.join("/");
|
||||
if (id.startsWith("@reactive-resume/") || bundledInteropPackages.has(packageName)) return false;
|
||||
if (id.startsWith("@/") || id.startsWith(".") || id.startsWith("/") || id.startsWith("\0")) return false;
|
||||
|
||||
return true;
|
||||
@@ -33,7 +60,9 @@ const promptAssetsPlugin: TsdownPlugin = {
|
||||
};
|
||||
|
||||
export default defineConfig({
|
||||
entry: { index: "src/index.ts" },
|
||||
entry: { index: "src/index.ts", vercel: "src/vercel.ts", "prepare-deployment": "src/prepare-deployment.ts" },
|
||||
// Keep import.meta.url-based asset lookup adjacent to the entrypoints.
|
||||
outputOptions: { chunkFileNames: "[name]-[hash].mjs" },
|
||||
format: "esm",
|
||||
platform: "node",
|
||||
target: "node24",
|
||||
@@ -47,7 +76,7 @@ export default defineConfig({
|
||||
suppressWarnings: [/dynamic import will not move module into another chunk/],
|
||||
outExtensions: () => ({ js: ".mjs" }),
|
||||
deps: {
|
||||
alwaysBundle: [/^@reactive-resume\//],
|
||||
alwaysBundle: [/^@reactive-resume\//, ...bundledInteropPackages],
|
||||
neverBundle: shouldExternalizeThirdParty,
|
||||
},
|
||||
plugins: [promptAssetsPlugin],
|
||||
|
||||
+914
-333
File diff suppressed because it is too large
Load Diff
+915
-334
File diff suppressed because it is too large
Load Diff
+913
-332
File diff suppressed because it is too large
Load Diff
+914
-333
File diff suppressed because it is too large
Load Diff
+912
-331
File diff suppressed because it is too large
Load Diff
+945
-364
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+915
-334
File diff suppressed because it is too large
Load Diff
+912
-331
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+913
-332
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+896
-316
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+927
-346
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+912
-331
File diff suppressed because it is too large
Load Diff
+933
-352
File diff suppressed because it is too large
Load Diff
+913
-332
File diff suppressed because it is too large
Load Diff
+937
-356
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+912
-331
File diff suppressed because it is too large
Load Diff
+915
-334
File diff suppressed because it is too large
Load Diff
+917
-336
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+912
-331
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+914
-333
File diff suppressed because it is too large
Load Diff
+952
-371
File diff suppressed because it is too large
Load Diff
+912
-331
File diff suppressed because it is too large
Load Diff
+941
-360
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+913
-332
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+927
-346
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+912
-331
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+914
-333
File diff suppressed because it is too large
Load Diff
+914
-333
File diff suppressed because it is too large
Load Diff
+913
-332
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+959
-378
File diff suppressed because it is too large
Load Diff
+922
-341
File diff suppressed because it is too large
Load Diff
+914
-333
File diff suppressed because it is too large
Load Diff
+911
-330
File diff suppressed because it is too large
Load Diff
+918
-337
File diff suppressed because it is too large
Load Diff
+914
-333
File diff suppressed because it is too large
Load Diff
+912
-331
File diff suppressed because it is too large
Load Diff
+912
-331
File diff suppressed because it is too large
Load Diff
+912
-331
File diff suppressed because it is too large
Load Diff
+873
-293
File diff suppressed because it is too large
Load Diff
+41
-45
@@ -4,7 +4,7 @@
|
||||
"type": "module",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"build": "rimraf dist && vite build",
|
||||
"build": "vite build",
|
||||
"dev": "vite dev",
|
||||
"serve": "vite preview",
|
||||
"start": "vite preview",
|
||||
@@ -16,28 +16,29 @@
|
||||
"lingui:extract": "lingui extract --clean --overwrite"
|
||||
},
|
||||
"dependencies": {
|
||||
"@ai-sdk/react": "^4.0.96",
|
||||
"@ai-sdk/react": "^4.0.121",
|
||||
"@base-ui/react": "^1.8.0",
|
||||
"@better-auth/api-key": "^1.7.3",
|
||||
"@better-auth/infra": "^0.4.5",
|
||||
"@better-auth/oauth-provider": "^1.7.3",
|
||||
"@better-auth/passkey": "^1.7.3",
|
||||
"@better-auth/api-key": "^1.7.6",
|
||||
"@better-auth/infra": "^0.4.11",
|
||||
"@better-auth/oauth-provider": "^1.7.6",
|
||||
"@better-auth/passkey": "^1.7.6",
|
||||
"@codemirror/autocomplete": "^6.20.3",
|
||||
"@codemirror/commands": "^6.11.0",
|
||||
"@codemirror/commands": "^6.11.1",
|
||||
"@codemirror/lang-css": "^6.3.1",
|
||||
"@codemirror/language": "^6.12.4",
|
||||
"@codemirror/lint": "^6.9.7",
|
||||
"@codemirror/search": "^6.7.2",
|
||||
"@codemirror/state": "^6.7.4",
|
||||
"@codemirror/view": "^6.43.11",
|
||||
"@codemirror/state": "^6.7.6",
|
||||
"@codemirror/view": "^6.43.13",
|
||||
"@dnd-kit/core": "^6.3.1",
|
||||
"@dnd-kit/sortable": "^10.0.0",
|
||||
"@dnd-kit/utilities": "^3.2.2",
|
||||
"@lingui/core": "^6.6.0",
|
||||
"@lingui/react": "^6.6.0",
|
||||
"@orpc/client": "^1.15.0",
|
||||
"@orpc/server": "^1.15.0",
|
||||
"@orpc/tanstack-query": "^1.15.0",
|
||||
"@fontsource-variable/manrope": "^5.3.0",
|
||||
"@lingui/core": "^6.8.0",
|
||||
"@lingui/react": "^6.8.0",
|
||||
"@orpc/client": "^1.15.4",
|
||||
"@orpc/server": "^1.15.4",
|
||||
"@orpc/tanstack-query": "^1.15.4",
|
||||
"@phosphor-icons/react": "^2.1.10",
|
||||
"@react-pdf/renderer": "^4.9.0",
|
||||
"@reactive-resume/ai": "workspace:*",
|
||||
@@ -53,12 +54,12 @@
|
||||
"@reactive-resume/utils": "workspace:*",
|
||||
"@tailwindcss/vite": "^4.3.3",
|
||||
"@tanstack/react-form": "^1.33.5",
|
||||
"@tanstack/react-hotkeys": "^0.10.0",
|
||||
"@tanstack/react-query": "^5.102.8",
|
||||
"@tanstack/react-router": "^1.170.32",
|
||||
"@tanstack/react-hotkeys": "^0.12.1",
|
||||
"@tanstack/react-query": "^5.104.0",
|
||||
"@tanstack/react-router": "^1.170.40",
|
||||
"@tiptap/extension-color": "^3.31.3",
|
||||
"@tiptap/extension-highlight": "^3.31.3",
|
||||
"@tiptap/extension-heading": "^3.31.3",
|
||||
"@tiptap/extension-highlight": "^3.31.3",
|
||||
"@tiptap/extension-paragraph": "^3.31.3",
|
||||
"@tiptap/extension-table": "^3.31.3",
|
||||
"@tiptap/extension-text-align": "^3.31.3",
|
||||
@@ -69,57 +70,52 @@
|
||||
"@types/js-cookie": "^3.0.6",
|
||||
"@uiw/color-convert": "^2.10.3",
|
||||
"@uiw/react-color-colorful": "^2.10.3",
|
||||
"ai": "^7.0.93",
|
||||
"better-auth": "1.7.3",
|
||||
"buffer": "^6.0.3",
|
||||
"ai": "^7.0.118",
|
||||
"better-auth": "1.7.6",
|
||||
"cmdk": "^1.1.1",
|
||||
"drizzle-orm": "1.0.0-rc.4",
|
||||
"es-toolkit": "^1.52.0",
|
||||
"fuse.js": "^7.5.0",
|
||||
"immer": "^11.1.18",
|
||||
"js-cookie": "^3.0.8",
|
||||
"motion": "^13.2.0",
|
||||
"motion": "^13.4.4",
|
||||
"pdfjs-dist": "6.3.289",
|
||||
"pg": "^8.23.0",
|
||||
"prettier": "^3.9.6",
|
||||
"prettier": "^3.9.9",
|
||||
"qrcode.react": "^4.2.0",
|
||||
"react": "^19.2.8",
|
||||
"react-dom": "^19.2.8",
|
||||
"react": "^19.3.0",
|
||||
"react-dom": "^19.3.0",
|
||||
"react-easy-crop": "^6.2.3",
|
||||
"react-markdown": "^10.1.0",
|
||||
"react-resizable-panels": "^4.12.4",
|
||||
"react-window": "^2.3.1",
|
||||
"react-resizable-panels": "^4.14.1",
|
||||
"react-window": "^2.3.3",
|
||||
"react-zoom-pan-pinch": "^4.2.0",
|
||||
"remark-gfm": "^4.0.1",
|
||||
"ts-pattern": "^5.9.0",
|
||||
"usehooks-ts": "^3.1.1",
|
||||
"zod": "^4.5.4",
|
||||
"zod": "^4.6.5",
|
||||
"zustand": "^5.0.15"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@babel/core": "^8.0.1",
|
||||
"@lingui/babel-plugin-lingui-macro": "^6.6.0",
|
||||
"@lingui/cli": "^6.6.0",
|
||||
"@lingui/format-po": "^6.6.0",
|
||||
"@lingui/vite-plugin": "^6.6.0",
|
||||
"@babel/core": "^8.0.6",
|
||||
"@lingui/babel-plugin-lingui-macro": "^6.8.0",
|
||||
"@lingui/cli": "^6.8.0",
|
||||
"@lingui/format-po": "^6.8.0",
|
||||
"@lingui/vite-plugin": "^6.8.0",
|
||||
"@reactive-resume/config": "workspace:*",
|
||||
"@rolldown/plugin-babel": "^0.2.3",
|
||||
"@rolldown/plugin-babel": "^0.2.4",
|
||||
"@shadcn/helpers": "^0.2.0",
|
||||
"@tanstack/devtools-vite": "^0.8.5",
|
||||
"@tanstack/react-devtools": "^0.10.12",
|
||||
"@tanstack/react-query-devtools": "^5.102.8",
|
||||
"@tanstack/react-router-devtools": "^1.167.1",
|
||||
"@tanstack/router-plugin": "^1.168.35",
|
||||
"@tanstack/react-devtools": "^0.10.13",
|
||||
"@tanstack/react-query-devtools": "^5.104.0",
|
||||
"@tanstack/react-router-devtools": "^1.167.2",
|
||||
"@tanstack/router-plugin": "^1.168.41",
|
||||
"@types/babel__core": "^7.20.5",
|
||||
"@types/pg": "^8.23.1",
|
||||
"@types/react": "^19.2.18",
|
||||
"@types/react-dom": "^19.2.7",
|
||||
"@types/react": "^19.3.0",
|
||||
"@types/react-dom": "^19.3.0",
|
||||
"@typescript/native-preview": "7.0.0-dev.20260707.2",
|
||||
"@vitejs/plugin-react": "^6.1.1",
|
||||
"babel-plugin-macros": "^3.1.0",
|
||||
"babel-plugin-react-compiler": "^1.0.0",
|
||||
"rimraf": "^6.1.3",
|
||||
"typescript": "^7.0.2",
|
||||
"vite": "^8.2.2"
|
||||
"vite": "^8.3.1"
|
||||
}
|
||||
}
|
||||
|
||||
@@ -20,8 +20,8 @@
|
||||
"url": "https://rxresu.me"
|
||||
},
|
||||
"repositoryUrl": {
|
||||
"url": "https://github.com/amruthpillai/reactive-resume",
|
||||
"wellKnown": "https://github.com/amruthpillai/reactive-resume/blob/main/.github/.well-known/funding-manifest-urls"
|
||||
"url": "https://github.com/reactive-resume/reactive-resume",
|
||||
"wellKnown": "https://github.com/reactive-resume/reactive-resume/blob/main/.github/.well-known/funding-manifest-urls"
|
||||
},
|
||||
"licenses": ["spdx:MIT"],
|
||||
"tags": ["data", "design", "productivity", "resume-builder"]
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user