Commit Graph

564 Commits

Author SHA1 Message Date
Fatih Kadir Akın afd22a7d0e Merge pull request #1223 from bglglzd/fix/public-api-prompts-pagination
Add validation and caps for public /api/prompts pagination
2026-07-17 22:32:52 +03:00
Fatih Kadir Akın 25f5fff8c5 Merge pull request #1226 from octo-patch/octo/20260716-add-minimax-models-recvoLa9Ftbrui-clean
Add MiniMax-M3 and MiniMax-M2.7 to model registry
2026-07-17 22:32:22 +03:00
Fatih Kadir Akın f9bfb652f5 loop engineering 2026-07-17 12:30:58 +03:00
Fatih Kadir Akın 0ff39beb92 Add translated Loop Engineering chapter 2026-07-16 13:32:32 +03:00
octo-patch 158b9ed62a Add MiniMax models to registry 2026-07-16 17:43:20 +08:00
Fatih Kadir Akın 494d1d21d9 latentshift sponsorship 2026-07-13 10:50:08 +03:00
bglglzd e05e7e6745 Improve public prompts pagination validation 2026-07-13 06:13:19 +03:00
bglglzd ebbba316b4 Clamp and validate public prompts API pagination params 2026-07-12 13:05:20 +03:00
Fatih Kadir Akın 06da77737a fix: add VS Code Copilot Chat deep links (#1198)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-06-03 02:41:17 +03:00
Fatih Kadir Akın 6028f3f024 Add Neon as sponsor and recommended database (#1192)
* Add Neon docs and remove website ads

Co-authored-by: Fatih Kadir Akın <fka@fka.dev>

* Fix run prompt callback dependencies

Co-authored-by: Fatih Kadir Akın <fka@fka.dev>

* Remove run menu sponsor treatment

Co-authored-by: Fatih Kadir Akın <fka@fka.dev>

* Fix run prompt callback dependencies

Co-authored-by: Fatih Kadir Akın <fka@fka.dev>

* Add Neon as sponsor

Co-authored-by: Fatih Kadir Akın <fka@fka.dev>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
2026-05-31 21:58:54 +03:00
Fatih Kadir Akın a045cdf117 Fix dark mode favicon (#1183)
Prefer the adaptive SVG favicon so browsers can switch colors in dark mode. Exclude package sources from the app TypeScript project so production builds do not type-check standalone package code.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-11 13:48:59 +03:00
Fatih Kadir Akın 417eb9500d fix(ci): unblock CI lint by allowing any in OIDC/OAuth test files
The OIDC and OAuth test files (added in #1056) inspect the dynamic
NextAuth provider object and use `any` for ergonomic property access.
That trips @typescript-eslint/no-explicit-any (error level), which has
been failing CI on main since 2026-05-02.

Add a file-level eslint-disable for that rule in both test files.
This is the standard pattern for tests that poke runtime-shaped
objects, and keeps the rule strict everywhere else.

Local: npm run lint -> 0 errors, npm test -> 709/709 passing.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 15:04:44 +03:00
Fatih Kadir Akın 7e2fa61037 feat(about): add John Phamous, add Security section with Mehmet Ince
- Add JohnPhamous as a core contributor for performance work (Vercel)
- Introduce a new Security section between Core Contributors and Ideation
- Credit Mehmet Ince (@mdisec) for security fixes
- Add securityTitle translation across all 17 supported locales

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-08 14:33:06 +03:00
Amayaranjan Das 918fa71a1c feat(auth): honour AUTH_OIDC/OAUTH_NAME and _LOGO env vars in login button (#1177) 2026-05-02 23:18:45 +03:00
Amayaranjan Das bf1de55c8d feat(auth): add generic OIDC and OAuth 2.0 plugins (#1056) 2026-05-02 09:24:07 +03:00
Fatih Kadir Akın 887b3f3f3a feat(home): replace industries grid with Open Source Friday video (#1170)
* feat(home): replace industries grid with Open Source Friday video

Replaces the rotating industries section under the hero search bar with
an embed of the GitHub Open Source Friday episode (starting at 6:12).
Also widens the hero's right column and tightens the left text column
so the video sits comfortably without overflowing on standard laptop
viewports.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* chore(i18n): remove unused heroIndustries keys

The industries grid was replaced by a YouTube embed; only
'searchPlaceholder' is still referenced. Drop the prefix,
clickToExplore, and 36 industry labels across all 17 locales.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(home): i18n iframe title, lazy load, nocookie, width parity

Addresses PR review feedback on the YouTube embed:
- Translate iframe title via next-intl (new heroIndustries.videoTitle key)
- Add loading="lazy" to defer ~1MB of player JS
- Switch embed to youtube-nocookie.com for better cookie/privacy hygiene
- Restore max-w-lg so the video matches the search bar width

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* chore: stop tracking local .env.docker

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-25 16:44:47 +03:00
Fatih Kadir Akın dc161feb81 Fix 404 on user profiles with uppercase usernames (#1166)
* Add announcement banner with MS Build 2026 talk

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix 404 on user profile when username has uppercase letters

Use case-insensitive match instead of forcing username to lowercase, since
usernames are stored with their original casing (e.g., SatishB15).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-23 22:22:54 +03:00
Fatih Kadir Akın 82783a7cc6 Add announcement banner with MS Build 2026 talk (#1165)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-23 21:46:51 +03:00
Satish Birhade 7a07039ad7 fix(bio): use cleaned URL for href while preserving original text rendering 2026-04-23 17:20:58 +05:30
Satish Birhade 35b0d90fd2 fix(bio): handle trailing comma in URLs 2026-04-23 16:43:21 +05:30
Fatih Kadir Akın dbd2eed8bc Remove Ezoic ad integration
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-23 00:22:56 +03:00
Fatih Kadir Akın 4407fa25f4 docs(book): update author bio to Automattic across all locales 2026-04-16 21:03:59 +03:00
suyua9 c8d6fdf321 fix: localize self-hosting prerequisites 2026-04-03 23:53:57 +08:00
suyua9 eb7812761b docs: align runtime requirements with current setup 2026-04-03 23:44:06 +08:00
Fatih Kadir Akın 8976ddab13 Merge pull request #1123 from f/cursor/add-commandcode-runner
feat: add Command Code as sponsored code runner with clipboard flow
2026-04-02 01:48:13 +03:00
Fatih Kadir Akın 5db2734513 feat: add Command Code as sponsored code runner with clipboard flow
Made-with: Cursor
Entire-Checkpoint: e195189bbf0c
2026-04-02 01:46:42 +03:00
Fatih Kadir Akın fc08dbdefe Merge pull request #1119 from JohnPhamous/perf/prompts-isr 2026-03-31 08:38:45 +03:00
Fatih Kadir Akın a7177656a4 Merge pull request #1118 from JohnPhamous/perf/mcp-handler-optimization 2026-03-31 08:38:12 +03:00
John Pham a89b2e1aa0 perf: add ISR to /prompts page (60s revalidation)
This page has no auth() dependency and gets high traffic with
0% cache hit rate. ISR with 60s revalidation serves most
requests from cache while keeping content fresh.
2026-03-30 16:27:37 -07:00
John Pham 09aca8cf54 perf: optimize MCP handler DB queries and response sizes
- Remove content field from prompts/list DB query (was fetching
  2-10KB per prompt just to extract variables, never returned)
- Drop arguments from prompts/list response (optional per spec,
  clients get variables when they call GetPrompt)
- Replace 500-row slug fallback scan with indexed title query
- Reduce search_prompts contentPreview from 1000 to 300 chars
- Add in-memory auth cache (5-min TTL) for warm function instances
2026-03-30 16:26:30 -07:00
John Pham 2672888031 fix: return 405 on MCP GET per Streamable HTTP spec
The MCP Streamable HTTP spec requires servers to return either
text/event-stream (SSE) or 405 on GET requests. The previous
200 application/json response violated the spec and caused MCP
clients to enter SSE reconnection loops.

This server is stateless (no sessions, listChanged: false) and
never pushes notifications. Returning 405 tells clients no SSE
support and they stop retrying.

Ref: https://modelcontextprotocol.io/specification/2025-03-26/basic/transports
2026-03-30 16:22:49 -07:00
Fatih Kadir Akın 9c714ffaed Merge pull request #1091 from yoloni-9527/fix/remove-redundant-non-null-assertions-in-ezoic
fix: remove redundant non-null assertions in ezoic.ts
2026-03-30 22:04:17 +03:00
Fatih Kadir Akın 233858f447 Merge pull request #1104 from mdisec/fix-private-prompt-history 2026-03-29 06:29:24 +03:00
Fatih Kadir Akın 7707781f0f Merge pull request #1101 from mdisec/fix-path-traversal-rce 2026-03-29 06:27:04 +03:00
Mehmet INCE d887c49b53 fix the prompt view perm issue for admin and adding unit tests 2026-03-25 21:05:06 +00:00
Mehmet INCE 20c6c26764 fix unit tests 2026-03-25 20:58:44 +00:00
Mehmet INCE 7b81836b21 -fix(security): enforce isPrivate checks on prompt sub-resource endpoints 2026-03-25 20:51:49 +00:00
Mehmet INCE 66de14d3cf fix(security): wiro ssrf 2026-03-25 16:31:13 +00:00
Mehmet INCE 0f8d4c381a fix(security): harden skill zip packaging against path traversal and control char injection 2026-03-25 13:12:22 +00:00
Mehmet INCE 6d0bf7fffa fix path traversal leads to rce 2026-03-25 12:11:58 +00:00
Fatih Kadir Akın 30a8f0470e fix(security): prevent SSRF & credential leakage via Fal.ai status polling
Add assertFalOrigin() validation to getFalRequestStatus and
getFalRequestResult to ensure URLs point to trusted Fal.ai hosts
(queue.fal.run, fal.run) before attaching the API key.

Ref: https://gist.github.com/mdisec/27c0cac0ec6a8f3c8f85a18987ddb942
2026-03-25 10:55:54 +03:00
Fatih Kadir Akın 9fe76ea4eb feat: add tiered rate limiting for MCP tool call endpoints 2026-03-25 10:50:07 +03:00
Fatih Kadir Akın 810de4d160 fix: replace explicit any types in prompts.json route 2026-03-25 10:35:30 +03:00
Fatih Kadir Akın 61abe5d8bc Merge pull request #1098 from mdisec/case-insensitive-exploit-fix
Fix username case-collision vulnerability across write and read paths
2026-03-25 07:23:41 +00:00
Mehmet Ince 30784e0740 drop case sensitive approach to the username and email across the app 2026-03-24 17:56:27 +00:00
Mehmet Ince 1464475df2 Fix username case-collision vulnerability across write and read paths 2026-03-24 16:00:26 +00:00
Sean Roberts ecee044716 feat: Add support for running prompts on Netlify Agent Runners 2026-03-24 10:51:22 -04:00
Fatih Kadir Akın f724bb7951 style(components/ads): update ezoic ad container styling 2026-03-22 18:27:51 +03:00
yoloni 256e4339f5 fix: remove redundant non-null assertions in ezoic.ts
The ??= operator already guarantees that `ez` is non-null by the time
it is assigned, so the subsequent non-null assertions (!.) on `ez.cmd`
are redundant and can be safely removed.

Before:
  ez!.cmd = ez!.cmd || [];
  ez!.cmd.push(fn);

After:
  ez.cmd = ez.cmd || [];
  ez.cmd.push(fn);
2026-03-21 17:07:40 +08:00
Fatih Kadir Akın 3b49211aab refactor(components): update EzoicPlaceholder to optimize DOM handling 2026-03-20 01:40:06 +03:00