172 KiB
Historical audit checkpoint. For the subsequently approved 63-issue execution scope and decisions, use the plans index and decision log. Earlier pending choices below are superseded there.
Open issue audit and action plan — 2026-09-05
Goal: Resolve as many issues as evidence supports, with one independently reviewed PR per independent fix.
Baseline: e549d114ea020380b156197f6460faddbe3022fd (main, version 5.2.9). Initial inventory: 114 open issues, 10 open PRs.
Verification standard
Every initial open issue was read with its comments and compared with relevant current code, history, existing PRs, or tests. Each entry states the evidence actually obtained. Passing package tests establish a baseline; they do not prove every screenshot or production incident is resolved. Reports requiring missing fixtures or deployment data remain open. Features are not classified as bugs solely because they are absent.
Issues fixed only in unmerged PRs remain open. Already-fixed issues close only with matching evidence or reporter confirmation. Duplicate closure retains a canonical open report. Merge status below reflects the latest GitHub refresh.
Progress
Status snapshot: 2026-09-05 19:01 UTC. Linked PRs carry subsequent issue updates.
- 115 issues triaged: the initial 114 plus new report #3433. Verification continues for reports needing exact fixtures or deployment reproduction.
- 44 implementation PRs created by this audit: 42 earlier PRs are merged; navigation fix #3453 and thumbnail fix #3454 are open. Audit-only documentation PRs #3418, #3440, #3444 and #3452 are excluded and are all merged. The final #3452 ledger and its merged #3450/#3451 verification updates are preserved.
- 50 audited issues closed: 49 evidence-backed or reporter-confirmed closures plus one product-decision closure (#3272). Complete closure set: #2650, #2735, #2739, #2745, #2804, #2805, #2878, #3008, #3017, #3051, #3068, #3146, #3174, #3175, #3180, #3200, #3247, #3251, #3255, #3272, #3285, #3291, #3305, #3311, #3312, #3334, #3337, #3338, #3339, #3340, #3341, #3343, #3344, #3347, #3348, #3352, #3359, #3360, #3361, #3366, #3368, #3369, #3370, #3374, #3380, #3391, #3392, #3393, #3401, #3433.
- In progress: navigation-save PR #3453 has green checks on its published head, but a valid unbounded-wait review finding now requires a follow-up and fresh verification; measured thumbnail-resolution fix #3454 awaits its remaining hosted checks and owner review. Concurrent multi-tab overwrite under #2828 is also reproduced; conflict recovery awaits a product decision. Controlled square-picture (#2794) and Times-Roman (#3089) probes pass, with exact reporter fixtures requested in posted comments. Exact original reproduction remains needed for #3093 after the separately reproduced glyph-cache correction #3450 and Unicode-space preservation #3451 merged, plus remaining issue reproductions. Merged paragraph-indentation PR #3448 addresses the approved whole-paragraph alternative, while #3397 remains open for literal leading spaces and tabs. Merged ordered-list-marker PR #3449 fixes the reproduced overlap, while #2751 remains open because the original missing-digit report is unproven. RTL canvas PR #3447 is owner-merged; broader exported-PDF scope keeps #3275 open. Bullet pagination (#3344), Ditgar alignment (#3068), and Arabic preview centering (#2745) are owner-merged. Reporter confirmed #3433 no longer reproduces after restarting their setup; issue closed without an attributed code fix. #3196 remains open because merged #3438 addressed a separate content-loss regression, not missing table borders. GitHub state refreshed against the current open-issue and PR inventories.
- Baseline server/API typecheck errors in
packages/email/src/transport.tsare fixed separately by #3416. All three affected package typechecks and existing email tests pass there.
| Issue | Fix PR | Result |
|---|---|---|
| #3391 | #3402 | Saved application notes now appear as escaped, wrapping text. Merged by repository owner; issue closed. |
| #2735 | #3403 | Explicit HTTP URLs survive paste and edits; bare hosts retain HTTPS defaults. 12 URL input tests passed. |
| #3347 | #3404 | Health exposes the build version and its endpoint appears in OpenAPI. Public errors are generic; diagnostic details remain in server logs. 74 server tests pass. |
| #3251 | #3405 | Primary button hover applies to native buttons and links. Compiled Tailwind behavior verified. |
| #3338 | #3406 | Dates align correctly when the opposite optional field is blank. Four actual-PDF layout regressions and 687 PDF tests passed. |
| #3370 | #3407 | Labeled password and confirmation dialog validates length/matching and retains failures. 605 web tests, typecheck, and updated browser E2E passed. |
| #3339 | #3408 | Onyx headlines wrap within page margins. Three actual-PDF regressions and 686 PDF tests passed. |
| #3401 | #3409 | Public signup footer is hidden when registration is disabled, as approved. Four public-page tests passed. |
| #3359 | #3410 | Public social previews use neutral branding instead of a sample identity. Personal title/description remain intact. |
| #3361 | #3411 | Compose loads optional .env after sample defaults; docs distinguish repository Compose from standalone quickstart. Both actual configurations verified. |
| #3352 | #3412 | SVG icon opacity reaches actual PDF drawing operations; reporter fixture renders distinct ratings. Six graphics-state tests and 689 PDF tests passed. |
| #3368 | #3413 | Submitted writes reject values outside published bounds while stored reads and historical migrations remain tolerant. Legacy JSON fixtures and schema/API/domain/import suites verified. |
| #3366 | #3414 | Head d99662282: public PDF downloads record explicit events after browser save initiation. API docs now describe password verification and the HttpOnly access cookie. 348 API tests and scoped Biome checks pass. Existing browser CI verifies PDF bytes, totals/daily downloads and unchanged views. |
| #3348 | #3415 | Semantic section heading and icon colors reach actual PDF drawing commands. Five graphics-state regressions and 688 PDF tests passed. |
| #3180 | #3417 | Moving items validates destinations and prunes only emptied custom source sections and affected empty pages; exact round-trip JSON, undo, 605 web tests and typecheck verified. |
| #3360 | #3419 | Merged head 1ba4224c4: per-resume download-button preference persists, backs up with account data, and hides both public buttons. Final verification passed 777 web tests, 381 API tests, both package typechecks, and 26 E2E scenarios; all review and static-analysis gates passed. |
| #3305 | #3420 | JPEG/WebP encoding is preserved and oversized crops shrink proportionally until within 10MiB. Near-limit JPEG browser reproduction now uploads successfully; transparency is preserved for PNG/WebP. Validation errors explain the upload limit. |
| #3392 | #3421 | Head 895fec3: refreshed with current main, preserving both OAuth consent and application-export translations. Four affected package typechecks, 744 web tests, 105 server tests (four opt-in database cases skipped) and locale compilation pass. MCP registration, provider schema and explicit Allow/Deny consent restored; signed queries and repeated resources survive login. 98 server tests with real PostgreSQL and 636 web tests pass. Production OAuth exchanges for both advertised-root and /mcp resources reach MCP initialize HTTP 200; an issued client-audience ID token receives HTTP 401. Intentional service audience aliases retained; production E2E CI passes. |
| #3337 | #3422 | PDF page padding repeats across overflow while preserving template backgrounds; 45 actual-PDF geometry/raster cases pass; template background review claims checked against main and resolved styles. |
| #3175 | #3422 | Shared continuation-margin fix covers five affected templates, explicit headerless pages and full-width pages. |
| #3255 | #3423 | Approved shared library with copied resume styling, explicit refresh, retained conflict drafts, JSON/PDF export and application snapshots. Three production browser scenarios, 325 API tests, 598 web tests and combined migrations verified; browser CI and autofix pass. Codacy applies a SQL Server-only rule to the PostgreSQL migration. |
| #3369 | #3424 | Connects remaining Basics Website, Picture Size and shared WebsiteField labels. Three missing-name reproductions corrected; 10 DOM tests and web typecheck pass. Complements #3387, whose standalone primitive prop regressions were reproduced and reported on its review. |
| #3247 | #3425 | Adds compact thumbnails and per-account tab-session Grid/Compact/List preference. Five hook tests plus production browser navigation, reload, explicit URL override and mobile sizing pass. |
| #3393 | #3426 | CSV exports current filters or all applications with date range, contacts, notes and chronological history. 611 web tests and production browser downloads, owner isolation and mobile header checks pass. |
| #3017 | #3427 | Head c315633f6: picture borders and soft shadows preserve authored padding and insets. 708 PDF tests across 59 files, 25 targeted cases, compiled-server raster checks, three Chromium/Node PNG parity fixtures and production builds pass. Percentage picture width/height shadows remain a documented limitation. |
| #2804 | #3428 | Server PDFs lacked default section headings despite correct browser rendering. Generated locale subset restores saved resume language; 689 PDF tests, API tests and production normal/fallback browser paths pass. |
| #3249 | #3430 | Head 50bac62ed: font metrics respect USE_TYPO_METRICS while preserving CJK fallbacks, including the selectable Noto Sans HK review correction. 699 PDF tests and 16 actual-font cases pass. Exact Roboto Condensed and controlled IBM fixtures improve; current Ropa Sans remains unchanged and historical optical alignment scope stays separate. |
| #3291 | #3431 | Head b15f4983b: color picker tracks current CSS through repeated presets, external edits and undo; spaced RGB/HSL tokens regain swatches. Approved hex output preserves optional alpha and named/modern RGB roundtrips. 78 focused tests and four previously verified production browser scenarios pass; all review feedback resolved. |
| #2684 | #3432 | Removes unsupported S3 object ACLs. Real SDK wire-contract stub reproduces AWS documented rejection; real Ceph gateway separately verifies public proxy and private access behavior. Exact reported deployment cause remains unproven; PR relates to the issue without closing it. |
| #3040 | #3434 | Head 2e29a4412: permits Semantic CSS gap, row-gap and column-gap on level indicators. Seven actual-PDF raster regressions, 690 PDF tests and 1,349 resume-domain tests pass. Original vertical clipping and automatic pagination scope remain unproven; PR relates without closing #3040. |
| #3340 | #3435 | Head 27c17d8c1: approved opt-in German hyphenation preserves default-off output and per-document isolation. 722 PDF tests across 59 files including 11 actual-PDF cases, 111 schema tests, 599 web tests, three package typechecks and production builds pass. Four Chromium locale/toggle exports, built-server PDF parity and exact shipped third-party notices verified. |
| #3343 | #3437 | Head d154f31b8: skill ratings align at the bottom of each multi-column row by default. Nine actual-PDF regressions and all 692 PDF tests pass. Single-column raster is byte-identical; CI and review approved. |
| #3196 | #3438 | Head 165535b5f: preserves imported rich text without individually addressable semantic descendants. Seven actual-PDF regressions, all 690 PDF tests and a production import/save/reload/export reproduction pass. Original missing-border report remains open; this is a separate regression discovered during its investigation. |
| #3344 | #3443 | Head 45a38fdc9: synchronized with main including continuation margins; 81 combined list/page-margin regressions and all 894 PDF tests pass. Scoped React PDF layout patch keeps list markers with their first text fragments, respecting orphan counts, reordering, RTL and explicit pagination hints. 36 targeted cases pass; current-main failure reproduced, single-page raster byte-identical. All CI checks pass on synchronized head. Independent review clean; 36 focused tests and a separate 250-word content-break probe pass. Extreme orphan/font-size limitations also reproduce on unchanged main. Repository owner merged this PR; issue closed. |
| #3068 | #3445 | Merged head 5a3eff985: corrects shared Ditgar main-section border/padding compensation, aligning titles with descriptions and links. Actual-PDF baseline: 16 failures and five controls; all 21 cases pass after the fix. Final verification passed all 923 PDF tests, package typecheck, and 25 E2E scenarios; all review and static-analysis gates passed. |
| #2745 | #3446 | Merged head ab0a47bf2: isolates left-origin zoom coordinates from RTL interface positioning while retaining Arabic dock and per-resume direction. Production-main regression fails with a 1324.8px center error and English control passes; all four UI/resume locale combinations pass after fix at initial load, actual size, and fit-to-view. Build, web typecheck, boundaries, E2E, review, and static-analysis gates passed. |
| #3275 | #3447 | Merged head bdb7abb3b: fixes inherited canvas drawing direction while preserving resume and interface DOM direction. Production baseline has two Arabic-resume failures with 35,009 differing pixels and two English-resume controls passing; final eight browser cases verify exact PDF raster parity and preview centering. All 777 web tests, build, typecheck, boundaries and repository checks pass. Independent review clean; all CI checks pass, including 34 browser scenarios. Broader exported-PDF report remains open. |
| #3397 | #3448 | Merged head 6cfb00387: adds approved whole-paragraph/heading indentation through existing controls, with persisted levels and PDF/DOCX export. PDF reserves at least half the available block width. All 945 PDF, 68 DOCX and 177 affected web tests pass, along with build, three typechecks and boundaries. Production authoring/save/reload/export and an independent 16-case narrow-width matrix pass; LTR/RTL continuation-page tests retain text and inset. The final quote/list fix has red/green XML coverage, a fresh 68-test DOCX pass, and all hosted checks green, including 34 browser scenarios. Literal leading whitespace/tabs and existing equivalent-width overlong-word clipping remain outside this implementation; issue remains open for that residual scope. |
| #2751 | #3449 | Merged head 7ac7fd31b: prevents ordered-list markers from overlapping body text, with a common gutter based on digit count, resolved font size and letter spacing. All 975 PDF tests, including marker and pagination regressions, typecheck, boundaries and repository checks pass; all hosted checks are green, including 34 browser scenarios. Independent reviews produced and verified custom-letter-spacing and linear-time list-length corrections. Direct/inherited styles, fonts, digit transitions, RTL, columns and page breaks are covered. Original missing leading digit is unproven; nested RTL list flattening matches unchanged baseline and remains separate, so the issue remains open. |
| #3093 | #3450 | Merged head fa14e4bc6: isolates character metadata when different Unicode sequences share one cached font glyph. Full 981-test PDF suite passes; all six glyph-cache regressions cover bounded cache size and distinct alias identity. Typecheck, boundaries, frozen install and repository checks pass. Independent four-runtime checks preserve geometry and bounded cache size. Production browser/server sequential exports retain exact ordinary-space text and 35.12pt width. All hosted checks and reviews pass; original screenshot equivalence remains unproven. |
| #3093 | #3451 | Merged head 1dbc75b26: preserves literal ideographic and nonbreaking spaces through HTML collapse and app normalization while retaining ordinary ASCII collapse. Full 1,000-test PDF suite passes, along with typecheck, boundaries, repository checks and frozen install. Independent sequence/edge/NBSP review clean. Production browser/server exports agree at 50pt, 60pt after authoring a leading ideographic space, and 35.12pt for the ASCII control. Rebased onto merged #3450; all hosted checks and reviews pass. Named/numeric entity decoding remains unchanged. |
| #2828 | #3453 | Open head 7fe189f5f: flushes queued edits and retries the latest draft before leaving the builder; failed saves retain the draft and block SPA navigation. Two real Chromium/PostgreSQL scenarios and 804 web tests pass; independent review clean. Published-head checks all pass, but a valid navigation-wait review finding requires a follow-up; those checks are not final verification of the correction. Original historical loss and simultaneous-tab conflict recovery remain separate open scope. |
| #3246 | #3454 | Open head c2db4ec8d: rasterizes the measured contain-fit size at device pixel density, retaining the previous thumbnail during upgrades. All 22 production measurements cover at least 100.18% of displayed pixels; 804 web tests and independent lifecycle review pass. At the snapshot, autofix, Codacy and Greptile pass; E2E and CodeRabbit are pending. Exact original self-hosted screenshot equivalence remains unproven. |
Product decisions
- #3401: approved — hide footer link when registration is disabled; implemented in #3409.
- #3360: approved — per-resume option hiding download buttons; no limitation explanation in app.
- #3255: approved — independently saved cover-letter library, editable from library and builder, selected resume styling, exported snapshots attached to applications. Existing attachment PR #3395 remains related.
- #3291: approved — CSS picker writes hex, with alpha when needed; implemented in #3431.
- #3340: approved — opt-in per-resume hyphenation using the resume locale, German first. Missing/false preserves existing output; implemented and owner-merged in #3435.
- #3343: approved — align skill-rating bars at the bottom of each grid row by default; implemented in #3437.
- #3272: approved — keep cover-letter headings omitted; explained and closed as not planned.
- #3397: approved — indent the whole paragraph through the existing controls; implemented and merged in #3448. Literal leading spaces and tabs remain open scope.
- #2785: pending — keyword display as per-section Inline/Bulleted list, per-item presentation, or deferred implementation. Preserve current inline default until scope is chosen.
- #2828: pending — combine non-overlapping concurrent edits and request choices only for conflicting values, or stop on any concurrent edit and compare drafts. Navigation-save protection in #3453 is independently implementable; multi-tab recovery UI remains unimplemented while this decision is pending.
- Other architecture and visual feature choices remain listed under individual issues.
Priority order
- Complete the bounded-navigation-wait follow-up and fresh verification for #3453, then follow its checks and thumbnail-resolution PR #3454 checks through owner review. Do not merge either PR.
- Resolve the #2828 multi-tab recovery choice before implementing dependent UX. Preserve editable local drafts, pair accepted data with its revision, and verify a reliable revision invariant under the existing row lock before adding concurrency protection.
- Obtain exact fixtures for #2794, #3089 and #3093. Controlled picture/font probes pass and the two Unicode fixes are merged, but the original screenshots remain unproven. Continue remaining font, layout and pagination reproductions without attributing them to unrelated fixes.
- Re-test deployed OAuth registration and S3 failures with current builds and original logs, separating fixed local causes from unverified deployment reports.
- Resolve pending product choices for JSearch restoration (#3010), local fonts (#3377) item pagination controls (#3350), and keyword-list scope (#2785), then implement accepted scopes in separate PRs with focused verification.
- Close remaining reports only after matching reproduction evidence, reporter confirmation, a retained canonical duplicate, or an explicit product decision.
Current audit classifications
| Classification | Audited | Still open |
|---|---|---|
| already_fixed | 11 | 0 |
| confirmed_bug | 29 | 4 |
| duplicate | 1 | 0 |
| existing_pr | 5 | 0 |
| feature | 10 | 8 |
| needs_reproduction | 38 | 37 |
| product_decision | 21 | 16 |
Classification records audit findings, including independently reproduced current paths; implementation and closure state are tracked separately. A confirmed current defect does not establish the cause of an original historical incident.
Remaining-work readiness differs from classification: 2 open issues have fixes under review in #3453/#3454, including the navigation-wait follow-up; 8 are feature candidates needing scope checks; 16 await product decisions; 39 need reproduction, deployment evidence or confirmation. The last group includes 37 needs_reproduction entries plus #3398 and #3249, whose related fixes are merged but residual scope remains unproven. Concurrent overwrite is an additional confirmed path within #2828 that still requires the recovery-policy decision.
Issue evidence and next actions
#3433 — First interest keyword missing first letter when it is capital E
Assessment: needs_reproduction. Confidence: medium. State: Closed with evidence.
Evidence:
- New report September 5: the EDH interest keyword and EPFL publisher lose their leading uppercase E; ADH/BDH/CDH/FDH/EEDH/eDH are unaffected. No JSON or font identified.
- Current main controlled Onyx PDFs using IBM Plex Serif, Helvetica and IBM Plex Sans preserve all eight strings in both keyword/publisher fields, verified by raster and text extraction: /tmp/levelgap-fixture-3433-IBM-Plex-Serif.pdf and related fixtures.
- Existing PR #3386 changes section-heading padding only; affected field paths in sections.tsx:1226 and :1332 do not consume getSectionHeadingTextStyle. No demonstrated duplicate/fix relationship.
- Reported v5.2.9 uses renderer 4.8.1 versus current 4.9.0, and PDF.js 6.2.108 versus 6.3.289. Clean detached v5.2.9 with its original frozen dependencies also renders/extracts all eight strings intact in both fields for IBM Plex Serif, Helvetica and IBM Plex Sans: /tmp/v529-fixture-3433-*.pdf. No demonstrated fix across versions; reporter font/styles remain unknown.
- Production Chromium (33.8 s) and Firefox 153 on macOS (35.2 s) browser workflows pass: typing 16 fields, DB save, reload and PDF download preserve EDH/EPFL/ADH/BDH/CDH/FDH/EEDH/eDH twice each in Azurill with IBM Plex Serif 400/600. Evidence: /tmp/issue-3433-ui-chromium.json and /tmp/issue-3433-ui-firefox.json. Exact reporter Firefox 155/Linux environment remains unverified; issue comment 5552405183 updated.
- Reporter confirmed on 2026-09-05 that restarting their setup made the problem disappear; issue closed as completed. https://github.com/reactive-resume/reactive-resume/issues/3433#issuecomment-5552950562. No specific code fix established.
Action plan:
- Issue closed after reporter-confirmed recovery. No code fix is attributed to this report.
#3401 — Remove "Build your own resume" from footer
Assessment: product_decision. Confidence: medium. State: Closed with evidence.
Evidence:
- PublicResumeRoute always renders footer link to / (public-resume.tsx:54-62).
- PR #3409 was merged by the repository owner and closed the issue on 2026-09-05. Public signup footer now hides when registration is disabled; four public-page tests passed.
Action plan:
- Issue closed; relevant merged PRs: #3409. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3409. Public signup footer is hidden when registration is disabled, as approved. Four public-page tests passed.
Product/scope note: User approved hide when registration disabled.
Related PRs: #3409
#3398 — MCP OAuth login fails during dynamic client registration with HTTP 500
Assessment: confirmed_bug. Confidence: medium. State: Open pending deployment retest and cause confirmation; related OAuth registration fix merged in #3421.
Evidence:
- Same main DCR path as #3392: auth config enables unauthenticated DCR while schema/auth.ts:250-292 omits clientDiscoveryId that installed plugin registration writes.
- Cloud exact HTTP response/server log unavailable; do not conflate possible redirect allowlist failure with missing-schema failure.
- Now-merged #3421 covers reproduced schema-related registration HTTP500; cloud cause still needs deployment logs/retest. Linked fix without premature duplicate closure: https://github.com/reactive-resume/reactive-resume/issues/3398#issuecomment-5553215414.
Action plan:
- PR #3421 merged the related OAuth schema/config fixes. Re-test Codex/Claude registration on that version and correlate deployment logs before attributing this report to the same cause or closing it.
#3397 — Allow indentations without list
Assessment: feature. Confidence: high. State: Open for residual literal-whitespace scope; approved whole-paragraph alternative merged.
Evidence:
- apps/web/src/components/input/rich-input.tsx:64-90 registers StarterKit, TextStyle, Color, Highlight, TextAlign; indentation commands at 305 are list-specific.
- Initial review verified editor persistence, PDF/DOCX, RTL and quoted-code behavior, then identified text loss at maximum indentation in narrow Chikorita sidebars. The final bounded-inset correction below resolves that introduced regression.
- Approved implementation supports whole paragraphs/headings through existing indentation controls; literal leading whitespace and tabs remain separate. Editor, PDF and DOCX share levels 0–8 (24px/18pt/360twips per level).
- Independent final narrow-width matrix passes all 16 Chikorita scenarios: 25%/35% sidebars, main quote and narrow sidebar quote at levels 0/1/4/8 preserve exact full text with no out-of-page coordinates. PDF inset is capped at half actual available width. Separate 22-case regression suite verifies LTR/RTL and text/inset continuity across physical pages.
- Existing heading words wider than remaining line can still clip, exactly matching unchanged renderer at equivalent CSS width. This limitation is characterized without introducing forced hyphenation.
Action plan:
- Reproduce and define literal leading-space/tab persistence and export behavior separately. Bounded PDF inset and equivalent-width overlong-word behavior are documented.
Implementation: PR #3448. Merged head 6cfb00387: adds approved whole-paragraph/heading indentation through existing controls, with persisted levels and PDF/DOCX export. PDF reserves at least half the available block width. All 945 PDF, 68 DOCX and 177 affected web tests pass, along with build, three typechecks and boundaries. Production authoring/save/reload/export and an independent 16-case narrow-width matrix pass; LTR/RTL continuation-page tests retain text and inset. The final quote/list fix has red/green XML coverage, a fresh 68-test DOCX pass, and all hosted checks green, including 34 browser scenarios. Literal leading whitespace/tabs and existing equivalent-width overlong-word clipping remain outside this implementation; issue remains open for that residual scope.
Product/scope note: User approved whole-paragraph indentation through the existing indent controls. Leading spaces and tabs remain part of the original request and require explicit export/persistence verification.
Related PRs: #3448
#3393 — [Feature] Export job applications as CSV / printable report
Assessment: feature. Confidence: medium. State: Closed with evidence.
Evidence:
- Applications route filters in memory by search/tags/archive; only CSV import exists (dashboard/applications/index.tsx:97-114; applications/csv.ts).
Action plan:
- Issue closed; relevant merged PRs: #3426. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3426. CSV exports current filters or all applications with date range, contacts, notes and chronological history. 611 web tests and production browser downloads, owner isolation and mobile header checks pass.
Product/scope note: Scope CSV first; no compliance guarantees.
Related PRs: #3426
#3392 — [Bug] MCP OAuth flow is broken end-to-end for self-hosted instances: incomplete oauth-provider schema, wrong resource config option, and callbackURL dropped after login
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- Main
e549d114epackages/auth/src/config.ts:302-310 uses validAudiences rather than resources and omits clientRegistrationDefaultResources. - packages/db/src/schema/auth.ts:250-377 lacks clientDiscoveryId and new OAuth resource/client-resource/assertion models; installed oauth-provider dist/oauth-1Ud-hvZY.d.mts declares them and authorize-BmTe2VYG.mjs:1955 writes clientDiscoveryId.
- apps/web/src/features/auth/pages/login.tsx:72,78 drops callbackURL when navigating to 2FA/dashboard.
- PR #3421 merged at verified head
895fec352: 98 server tests with real PostgreSQL, 636 web tests and production E2E CI pass. Real advertised-root and /mcp access tokens initialize MCP with HTTP200; issued client-audience ID token gets HTTP401. SDK1.30 selects root/slash from advertised metadata; service aliases deliberately preserved.
Action plan:
- Issue closed; relevant merged PRs: #3421. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3421. Head 895fec3: refreshed with current main, preserving both OAuth consent and application-export translations. Four affected package typechecks, 744 web tests, 105 server tests (four opt-in database cases skipped) and locale compilation pass. MCP registration, provider schema and explicit Allow/Deny consent restored; signed queries and repeated resources survive login. 98 server tests with real PostgreSQL and 636 web tests pass. Production OAuth exchanges for both advertised-root and /mcp resources reach MCP initialize HTTP 200; an issued client-audience ID token receives HTTP 401. Intentional service audience aliases retained; production E2E CI passes.
Related PRs: #3421
#3391 — Show Notes on job application detail view
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- Application DTO includes notes; detail sheet omitted current.notes. Form retains notes. Six-line rendering fix reviewed and typechecked.
Action plan:
- Issue closed; relevant merged PRs: #3402. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3402. Saved application notes now appear as escaped, wrapping text. Merged by repository owner; issue closed.
Product/scope note: Implemented and owner-merged in #3402; issue closed.
Related PRs: #3402
#3380 — [Bug] First character of a section title is dropped in the builder (e.g. "Experience" renders as "xperience")
Assessment: existing_pr. Confidence: high. State: Closed with evidence.
Evidence:
- PR #3386 merged at head
a3053e206; its section-heading padding fix is now on main. - packages/pdf/src/templates/shared/sections.tsx:191 getSectionHeadingTextStyle; icon-bearing heading at :367 uses the corrected text padding.
Action plan:
- Issue closed; relevant merged PRs: #3386. No further implementation planned for this report. See evidence for the contribution of each fix.
Related PRs: #3386
#3379 — Add option to add company logo to entries
Assessment: product_decision. Confidence: medium. State: Open pending resolution/merge.
Evidence:
- Resume templates render text-based experience entries; no company-logo workflow is exposed in existing item forms.
Action plan:
- Decide logo URL vs uploaded asset, size/placement, and supported item types. If accepted add optional schema field, storage rules, UI and renderer support, import defaults, PDF/DOCX tests.
Product/scope note: Needs user product decision.
#3378 — Option to re add section after accidental deletion
Assessment: needs_reproduction. Confidence: medium. State: Open pending resolution/merge.
Evidence:
- Current layout/pages.tsx:200-214 moves all sections to another page before deleting a page. Layout item menu at 660 offers Move and page-break options, not section deletion. section-menu.tsx:55-65 offers reversible hidden state.
- Current main
0207e5dfcstill provides Section options > Show for hidden built-in sections. Posted precise request for version, deletion action and sanitized metadata.layout to distinguish missing layout references: https://github.com/reactive-resume/reactive-resume/issues/3378#issuecomment-5553162647.
Action plan:
- Request exact version and deletion action or a sanitized affected JSON. If section IDs are absent from all layout pages, add an explicit unplaced-sections restore control preserving hidden state and items.
#3377 — Option to not use google fonts (e.g. only local ones)
Assessment: feature. Confidence: medium. State: Open pending resolution/merge.
Evidence:
- getWebFontSource returns remote URLs from packages/fonts/src/webfontlist.json; registerFonts uses them directly (use-register-fonts.ts:255-258). Standard Helvetica/Courier/Times-Roman skip registration, but script fallbacks remain remote.
Action plan:
- Provide font source configuration or bundled subset with local browser/server URLs. Cover heading/body/italics and CJK/Arabic fallback fonts and picker previews. Test PDF render with outbound networking blocked.
Product/scope note: Pending maintainer answer requested in this audit: self-hosted font source, small bundled offline font set, or defer. Standard fonts alone do not prove fully offline rendering.
#3374 — AI Provider test timeout is too short
Assessment: existing_pr. Confidence: high. State: Closed with evidence.
Evidence:
- Baseline packages/api/src/features/ai/service.ts:94,265 hardcoded 30_000 ms; PR #3384 merged at head
8a96b7c9fwith turbo globalEnv coverage and tests.
Action plan:
- Issue closed; relevant merged PRs: #3384. No further implementation planned for this report. See evidence for the contribution of each fix.
Related PRs: #3384
#3373 — Add a Secondary Color
Assessment: product_decision. Confidence: high. State: Open pending resolution/merge.
Evidence:
- packages/schema/src/resume/data.ts:colorDesignSchema only defines primary/text/background; existing semantic CSS supports explicit colors.
Action plan:
- Choose which template elements consume secondary color and default migration behavior; then schema, UI, template mappings, import/export and visual tests.
#3370 — The set-password dialog is one unlabelled field with no confirmation, and a password below the API's documented minimum is dropped in silence
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- apps/web/src/hooks/use-prompt.tsx:86-90 unconditionally resolves/closes; one input :124-130.
- Builder sharing.tsx:54-67 only trims/rejects empty password; server sharing.ts:37 documents 6-64 characters.
Action plan:
- Issue closed; relevant merged PRs: #3407. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3407. Labeled password and confirmation dialog validates length/matching and retains failures. 605 web tests, typecheck, and updated browser E2E passed.
Related PRs: #3407
#3369 — FormControl stamps the label's target id on a non-labelable wrapper, so Slug, Tags and the Sidebar Width slider have no accessible name
Assessment: existing_pr. Confidence: high. State: Closed with evidence.
Evidence:
- PR #3387 subsequently merged at head
f568b8feb; it covers FormControl/InputGroup/ChipInput/Slider ID plumbing. Its body explicitly excludes dangling URLInput/RichTextField targets. - Issue requests dangling Picture Size and Website labels too, so PR closing claim should be checked against full acceptance matrix.
- Earlier reviewed PR #3387 head
6ea7d540passed 58 supplied focused tests, but actual DOM probes reproduced unnamed Basics Website and Picture Size fields; shared WebsiteField had the same missing FormControl. - Two standalone primitive compatibility probes pass main and fail PR #3387: Slider discards explicit id; InputGroup discards caller id and aria-describedby. No current app call site demonstrated an outage from those prop regressions.
Action plan:
- Issue closed; relevant merged PRs: #3387, #3424. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3424. Connects remaining Basics Website, Picture Size and shared WebsiteField labels. Three missing-name reproductions corrected; 10 DOM tests and web typecheck pass. Complements #3387, whose standalone primitive prop regressions were reproduced and reported on its review.
#3368 — Documented resume bounds are silently coerced instead of rejected: a write outside the published schema returns 200 and stores something the client never sent
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- packages/api/src/features/resume/resume-data-validation.ts:8,23-24 uses tolerant parseResumeData for writes. packages/schema/src/resume/data.ts:629 catches invalid template as onyx; marginX catches as 14. Direct current-main runtime probe: unknown template and marginX=500 parse to onyx and 14 (artifact /tmp/audit-builder-probe.jsonl).
Action plan:
- Issue closed; relevant merged PRs: #3413. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3413. Submitted writes reject values outside published bounds while stored reads and historical migrations remain tolerant. Legacy JSON fixtures and schema/API/domain/import suites verified.
Related PRs: #3413
#3366 — The Downloads statistic can never be non-zero: no code path ever increments it
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- Statistics increment helper exists, but current export/public PDF paths have no download event. Public viewer and export share PDF generation/cache, so counting all renders would count mere views.
Action plan:
- Issue closed; relevant merged PRs: #3414. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3414. Head d99662282: public PDF downloads record explicit events after browser save initiation. API docs now describe password verification and the HttpOnly access cookie. 348 API tests and scoped Biome checks pass. Existing browser CI verifies PDF bytes, totals/daily downloads and unchanged views.
Product/scope note: Requires explicit download event, not render counter.
Related PRs: #3414
#3361 — .env in compose.yml
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- compose.yml:90-92 loads only .env.example. docs/self-hosting/docker.mdx:177-178 uses .env. A root .env only used for Compose interpolation cannot supply unreferenced container flags.
Action plan:
- Issue closed; relevant merged PRs: #3411. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3411. Compose loads optional .env after sample defaults; docs distinguish repository Compose from standalone quickstart. Both actual configurations verified.
Related PRs: #3411
#3360 — Sharing: Add a toggle to disable download feature
Assessment: product_decision. Confidence: medium. State: Closed with evidence.
Evidence:
- PublicResumeRoute unconditionally renders header and floating Download PDF controls (public-resume.tsx:40-47,65-75).
Action plan:
- Issue closed by merged PR #3419. No further implementation required for this report.
Implementation: PR #3419. Merged head 1ba4224c4: per-resume download-button preference persists, backs up with account data, and hides both public buttons. Final verification passed 777 web tests, 381 API tests, both package typechecks, and 26 E2E scenarios; all review and static-analysis gates passed.
Product/scope note: User approved; explicitly no limitation explanation in app.
Related PRs: #3419
#3359 — Incorrect Link Preview Shows Template CV Instead of User's CV
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- Public route head constructs imageUrl from /templates/jpg/${social.template}.jpg ($username/$slug.tsx:33), depicting sample resume identity.
Action plan:
- Issue closed; relevant merged PRs: #3410. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3410. Public social previews use neutral branding instead of a sample identity. Personal title/description remain intact.
Product/scope note: Neutral preview accepted by original issue; dynamic personal thumbnails can follow later.
Related PRs: #3410
#3352 — Level Type Icon does not show the skill level
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- packages/pdf/src/templates/shared/level-display.tsx:73-88 renders five icons with active/inactive opacity. semantic/tree.ts:227-244 builds five corresponding nodes.
- Actual main PDF smoke /tmp/audit-3352.pdf, default Onyx semantic mode, level 3/star, produced 6 SVG hosts (1 skill icon + 5 level icons). This is NOT exact Scizor attachment reproduction.
- Exact attachment rendered on main: /tmp/fixture-3352.pdf and /tmp/fixture-3352-1.png. First row levels 0/1/2/3; all nonzero levels show five identically colored outlined stars. SVG host opacity varies 1/.35, but rendered output does not distinguish inactive icons.
- Fix verified in .worktrees/issue-3352-icon-level: primitives.tsx Icon forwards merged final opacity as SVG prop. Actual PDF operator regression red (4 failures/2 controls) then green (6 tests); semantic opacity 0.2 and 0 retained. Reporter JSON raster /tmp/fixed-fixture-3352-1.png shows intended levels 0-5 and preserved red strokes; baseline /tmp/fixture-3352-1.png shows all opaque.
Action plan:
- Issue closed; relevant merged PRs: #3412. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3412. SVG icon opacity reaches actual PDF drawing operations; reporter fixture renders distinct ratings. Six graphics-state tests and 689 PDF tests passed.
Related PRs: #3412
#3350 — Keep together also for items | widow & orphan control
Assessment: feature. Confidence: medium. State: Open pending resolution/merge.
Evidence:
- packages/schema/src/resume/data.ts:294-298 exposes keepTogether/startOnNewPage on sections. SectionItem at packages/pdf/src/templates/shared/sections.tsx:479 has no item-level builder control.
- Semantic presentation flow props already apply through item Div and section shells; existing pagination tests distinguish authored/physical pages.
Action plan:
- Decide per-item UI/schema support and widow/orphan controls; exercise item taller than page, nested experience roles, two columns, and CSS precedence.
Product/scope note: Pending maintainer answer requested in this audit: per-item Keep together only, explicit widow/orphan UI too, or Semantic CSS only.
#3348 — Semantic CSS color has no effect on section heading text or icon
Assessment: confirmed_bug. Confidence: medium. State: Closed with evidence.
Evidence:
- packages/pdf/src/templates/shared/sections.tsx:355-369 puts resolved section-heading style on container but child Heading binds false and omits sectionHeadingResolved.style. Child explicit foreground can override inheritance. SectionHeadingIcon in primitives.tsx:457-498 composes style but passes template icon props separately.
Action plan:
- Issue closed; relevant merged PRs: #3415. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3415. Semantic section heading and icon colors reach actual PDF drawing commands. Five graphics-state regressions and 688 PDF tests passed.
Related PRs: #3415
#3347 — API endpoint that displays the running version of the software
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- health.ts:48 reads npm_package_version, absent in Docker CMD node startup or 0.0.0 for server package. app-version.ts already exports build constant. OpenAPI generator omits /api/health.
Action plan:
- Issue closed; relevant merged PRs: #3404. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3404. Health exposes the build version and its endpoint appears in OpenAPI. Public errors are generic; diagnostic details remain in server logs. 74 server tests pass.
Product/scope note: Existing maintainer explicitly approved endpoint version property plus OpenAPI.
Related PRs: #3404
#3344 — Bullet point remains on first page if bullet is moved to next page
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- Report 5.2.6 is later than merged list-marker fixes #3236 (
ed5d10c49) and #3242 (d536b1921); cannot close against those earlier fixes. - Current rich-text renderer has marker/content pagination handling; generic PDF suite passes but no exact issue JSON fixture exists.
- Actual PDF controlled boundary sweep on current main: Onyx at 300 × 300 pt with Helvetica 10, a summary list paragraph with rich-text margin-top 194 pt leaves the bullet on page 1 and the target first line on page 2; the 192 pt control starts text on page 1. Artifacts:
/tmp/3344-repro.pdf,/tmp/issue-3344-controlled.json, and/tmp/3344-sweep.json. This is a controlled current reproduction; no original JSON was supplied. - History: #3178 (
5080fddf5) nested marker/content; #3236 (ed5d10c49) later replaced it with markerminPresenceAhead. The current legacy React PDF paginator splits row children independently; a one-line marker can remain while the paragraph's defaultorphans={2}moves content. The existing guard does not prevent this case. - Earlier PR #3443 head
4ad69f2a9passed 847 PDF tests, 36 focused pagination regressions, actual-main red/green and byte-identical single-page PNG parity. Independent review /tmp/rr-3344-independent-review.md is clean, including an extra 250-word content-break probe. Current synchronized head/test totals appear under Implementation. - GitHub now confirms PR #3443 merged and issue closed by repository owner.
Action plan:
- Issue closed after repository owner merged PR #3443. Retain scoped regression coverage; hosted availability depends on deployment.
Implementation: PR #3443. Head 45a38fdc9: synchronized with main including continuation margins; 81 combined list/page-margin regressions and all 894 PDF tests pass. Scoped React PDF layout patch keeps list markers with their first text fragments, respecting orphan counts, reordering, RTL and explicit pagination hints. 36 targeted cases pass; current-main failure reproduced, single-page raster byte-identical. All CI checks pass on synchronized head. Independent review clean; 36 focused tests and a separate 250-word content-break probe pass. Extreme orphan/font-size limitations also reproduce on unchanged main. Repository owner merged this PR; issue closed.
Related PRs: #3178, #3236, #3443
#3343 — Skill level icons not aligned horizontally when having multiple columns per row with different amount of lines for keywords
Assessment: product_decision. Confidence: high. State: Closed with evidence.
Evidence:
- packages/pdf/src/templates/shared/sections.tsx:1146 SkillsSection renders each item header/proficiency/keywords/level in natural vertical flow; each column item has independent height.
- Requested row-aligned icon bars require choosing bottom-aligned row layout versus present natural flow; open #3358 adds another skills layout, not this same request.
- PR #3437: actual PDF reproduction fails before the change in legacy and Semantic CSS modes and passes afterward. Nine regression cases cover mixed heights, incomplete rows, custom sections, filtering, zero ratings, supported item padding and automatic pagination. All 692 PDF tests across 58 files, typecheck, formatting and boundaries pass; CI and review approved. Before/after visual inspection confirms alignment; single-column PNG bytes are identical.
Action plan:
- Issue closed; relevant merged PRs: #3437. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3437. Head d154f31b8: skill ratings align at the bottom of each multi-column row by default. Nine actual-PDF regressions and all 692 PDF tests pass. Single-column raster is byte-identical; CI and review approved.
Product/scope note: User approved row-bottom skill-rating alignment. Implemented in owner-merged PR #3437; issue closed.
#3341 — Icons of Basics are offset vertically lower than following text
Assessment: duplicate. Confidence: high. State: Closed with evidence.
Evidence:
- Reporter names IBM Plex Sans Condensed and provides JSON in 2026-08-24 comment; #3249 comments already reproduce same font baseline alignment across Onyx/Rhyhorn and other templates.
- Both describe baseline relative to icons, varying by font, with Open Sans appearing aligned; #3249 includes IBM Plex Sans Condensed and Roboto variants. Preserve supplied JSON as #3249 reproduction.
Action plan:
- Consolidate into #3249 while retaining provided IBM Plex Sans Condensed JSON; raster comparison across fonts and header/section/item icons remains needed.
#3340 — Hyphenation defunct
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- packages/pdf/src/hooks/use-register-fonts.ts:223-234 explicitly returns [word] for all non-CJK words, disabling hyphenation including German compounds.
- This establishes current non-hyphenating behavior statically; language-aware dictionary choice and soft-hyphen preservation are not implemented.
- PR #3435 head
27c17d8c1: 722 PDF tests across 59 files including 11 actual-PDF cases, 111 schema tests, 599 web tests including five DOM cases, three package typechecks and boundaries/knip/frozen offline install/check pass. Production web/server builds and Chromium four-case locale/toggle exports pass; built-server PDF parity, exact distributed third-party notice and visual UI verified.
Action plan:
- Issue closed; relevant merged PRs: #3435. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3435. Head 27c17d8c1: approved opt-in German hyphenation preserves default-off output and per-document isolation. 722 PDF tests across 59 files including 11 actual-PDF cases, 111 schema tests, 599 web tests, three package typechecks and production builds pass. Four Chromium locale/toggle exports, built-server PDF parity and exact shipped third-party notices verified.
Product/scope note: User approved opt-in per-resume German hyphenation using resume locale; missing/false preserves existing output. Implemented and owner-merged in PR #3435, head 27c17d8c1.
Related PRs: #3435
#3339 — Headline does not respect horizontal margin setting
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- packages/pdf/src/templates/onyx/OnyxPage.tsx:159-169 gives header row picture sibling but headerTitle has no flex width constraint.
- Actual current-main PDF /tmp/audit-3339.pdf: headline starts x=102.414337, extracted width=496.013359, right edge 598.43 beyond A4 width 595.28 and content edge 581.28; text suffix clipped. Fixture uses picture size 100 and long headline.
Action plan:
- Issue closed; relevant merged PRs: #3408. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3408. Onyx headlines wrap within page margins. Three actual-PDF regressions and 686 PDF tests passed.
Related PRs: #3408
#3338 — Education: If no Area of Study given, Location and Period jump to the left edge
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- packages/pdf/src/templates/shared/sections.tsx:900-911 and :1076-1092 omit optional position/area but leave trailing text as sole child of space-between row.
- Actual main PDF /tmp/audit-3338.pdf: normal City/Degree right edges 581.28; absent position period 2020 x=14; absent area City • 2021 x=14. Reproduced with Onyx/Helvetica.
Action plan:
- Issue closed; relevant merged PRs: #3406. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3406. Dates align correctly when the opposite optional field is blank. Four actual-PDF layout regressions and 687 PDF tests passed.
Related PRs: #3406
#3337 — Vertical margin not respected when item spans across pages in 2-column templates
Assessment: confirmed_bug. Confidence: high. State: Closed with evidence.
Evidence:
- DitgarPage.tsx:213-216 puts no vertical padding on Page, while mainContent/sidebarContent :244-255 carry padding; ChikoritaPage.tsx:76-105 likewise pads nested regions. Glalie mainContent :223-226 lacks bottom padding.
- Pikachu uses shared page-shell unlike affected templates. Static evidence supports pagination-padding cause, but exact multipage PDF fixture not generated yet.
- Actual PDF geometry reproduction at main
e549d114e: 60-paragraph experience, vertical margin48, two-column page. Ditgar/Chikorita/Glalie/Leafish second physical page text top=-1pt, first-page bottom14-25pt; Ditto second-page top2pt and first-page bottom11pt. Pikachu/Onyx controls respect top47-50pt and bottom>66pt. /tmp/audit-3337-margins.json and /tmp/margins-{template}.pdf. Separate exact template reports preserved; shared symptom positively reproduced. - Fix in .worktrees/issue-3337-page-margins: physical Page padding on Ditgar/Chikorita/Glalie/Leafish/Ditto; first-page offset retained, sidebar margin paint preserves baseline colors. Actual-PDF regression red10/14 -> green28 cases (semantic, legacy, both columns, RTL; all60 paragraphs retained; raster corner colors and first-header position guarded). PDF typecheck + Biome pass. Current fixture geometry /tmp/audit-3337-margins-fixed.json; baseline /tmp/audit-3337-margins.json.
- Additional explicit-headerless/fullWidth PDF regression: Ditto initially started content at 96.5pt for marginY48 (2 failures, other 12 cases passed); conditional header gap fixes to requested margin. Final page-margins.test.tsx 42 tests pass, PDF typecheck passes. Earlier full PDF suite58files711tests passed before this bounded headerless correction.
Action plan:
- Issue closed; relevant merged PRs: #3422. No further implementation planned for this report. See evidence for the contribution of each fix.
Implementation: PR #3422. PDF page padding repeats across overflow while preserving template backgrounds; 45 actual-PDF geometry/raster cases pass; template background review claims checked against main and resolved styles.
Related PRs: #3422
#3334 — Import a PDF resume without requiring an AI provider
Assessment: existing_pr. Confidence: medium. State: Closed with evidence.
Evidence:
- Issue requests deterministic PDF import without AI; existing open PR #3400 implements this surface.
- GitHub now confirms PR #3400 merged and issue closed by repository owner.
Action plan:
- Issue closed after repository owner merged PR #3400. Retain scoped regression coverage; hosted availability depends on deployment.
Product/scope note: PR #3400 merged at head d23d7566d; hosted availability depends on deployment.
Related PRs: #3400
#3323 — I am able to download resume but unable to get the content/data that I have added in the template
Assessment: needs_reproduction. Confidence: low. State: Open pending resolution/merge.
Evidence:
- Body lacks version, template, sanitized data or actual output; maintainer requested precise steps twice (latest 2026-08-16).
- Current builder draft.ts serializes pending saves; export path source alone cannot identify whether this concerns editor save, rendering or import.
Action plan:
- Obtain sanitized input/output and exact version/download path; compare server stored resume and PDF extraction before selecting owner.