Commit 141e31d
committed
fix: security hardening, chat sync bugs, and code cleanup
Security:
- CORS now denies unknown origins instead of allowing all
- Path traversal prevention via safePath() on all file operations
- Replace new Function() with vm.runInNewContext() in config loader
Chat/Sync:
- API_BASE lazily evaluated to fix race condition with MDX wrapper
- Non-streaming fallback now persists chat to localStorage
- generateStory returns post-processed code instead of pre-fix code
- Remove _debug field from streaming request body
Cleanup:
- Remove debug console.logs from StoryUIPanel
- CLI version reads from package.json instead of hardcoded 1.0.0
- Remove 3 dead functions and unused import from CLI
- Remove unused pg/types-pg dependencies
- Update API key validation models (gpt-4o-mini, gemini-2.0-flash)1 parent f419431 commit 141e31d
File tree
8 files changed
+115
-224
lines changed- cli
- mcp-server
- routes
- story-generator
- llm-providers
- templates/StoryUI
8 files changed
+115
-224
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | | - | |
9 | 8 | | |
10 | 9 | | |
11 | 10 | | |
| |||
14 | 13 | | |
15 | 14 | | |
16 | 15 | | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
17 | 20 | | |
18 | 21 | | |
19 | 22 | | |
20 | 23 | | |
21 | 24 | | |
22 | | - | |
| 25 | + | |
23 | 26 | | |
24 | 27 | | |
25 | 28 | | |
| |||
156 | 159 | | |
157 | 160 | | |
158 | 161 | | |
159 | | - | |
160 | | - | |
161 | | - | |
162 | | - | |
163 | | - | |
164 | | - | |
165 | | - | |
166 | | - | |
167 | | - | |
168 | | - | |
169 | | - | |
170 | | - | |
171 | | - | |
172 | | - | |
173 | | - | |
174 | | - | |
175 | | - | |
176 | | - | |
177 | | - | |
178 | | - | |
179 | | - | |
180 | | - | |
181 | | - | |
182 | | - | |
183 | | - | |
184 | | - | |
185 | | - | |
186 | | - | |
187 | | - | |
188 | | - | |
189 | | - | |
190 | | - | |
191 | | - | |
192 | | - | |
193 | | - | |
194 | | - | |
195 | | - | |
196 | | - | |
197 | | - | |
198 | | - | |
199 | | - | |
200 | | - | |
201 | | - | |
202 | | - | |
203 | | - | |
204 | | - | |
205 | | - | |
206 | | - | |
207 | | - | |
208 | | - | |
209 | | - | |
210 | | - | |
211 | | - | |
212 | | - | |
213 | | - | |
214 | | - | |
215 | | - | |
216 | | - | |
217 | | - | |
218 | | - | |
219 | | - | |
220 | | - | |
221 | | - | |
222 | | - | |
223 | | - | |
224 | | - | |
225 | | - | |
226 | | - | |
227 | | - | |
228 | | - | |
229 | | - | |
230 | | - | |
231 | | - | |
232 | | - | |
233 | | - | |
234 | | - | |
235 | | - | |
236 | | - | |
237 | | - | |
238 | | - | |
239 | | - | |
240 | | - | |
241 | | - | |
242 | | - | |
243 | | - | |
244 | | - | |
245 | | - | |
246 | | - | |
247 | | - | |
248 | | - | |
249 | | - | |
250 | | - | |
251 | | - | |
252 | | - | |
253 | | - | |
254 | | - | |
255 | | - | |
256 | | - | |
257 | | - | |
258 | | - | |
259 | | - | |
260 | | - | |
261 | | - | |
262 | | - | |
263 | | - | |
264 | | - | |
265 | | - | |
266 | | - | |
267 | | - | |
268 | | - | |
269 | | - | |
270 | | - | |
271 | | - | |
272 | | - | |
273 | | - | |
274 | | - | |
275 | | - | |
276 | | - | |
277 | | - | |
278 | | - | |
279 | | - | |
280 | | - | |
281 | | - | |
282 | 162 | | |
283 | 163 | | |
284 | 164 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
64 | 64 | | |
65 | 65 | | |
66 | 66 | | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
67 | 82 | | |
68 | 83 | | |
69 | 84 | | |
70 | | - | |
71 | | - | |
| 85 | + | |
| 86 | + | |
72 | 87 | | |
73 | 88 | | |
74 | | - | |
| 89 | + | |
75 | 90 | | |
76 | 91 | | |
77 | 92 | | |
| |||
80 | 95 | | |
81 | 96 | | |
82 | 97 | | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
83 | 104 | | |
84 | 105 | | |
85 | 106 | | |
86 | 107 | | |
87 | 108 | | |
88 | 109 | | |
89 | | - | |
90 | | - | |
| 110 | + | |
| 111 | + | |
91 | 112 | | |
92 | 113 | | |
93 | 114 | | |
94 | 115 | | |
95 | | - | |
96 | | - | |
97 | | - | |
| 116 | + | |
| 117 | + | |
98 | 118 | | |
99 | 119 | | |
100 | 120 | | |
| |||
458 | 478 | | |
459 | 479 | | |
460 | 480 | | |
461 | | - | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
462 | 485 | | |
463 | 486 | | |
464 | | - | |
| 487 | + | |
465 | 488 | | |
466 | 489 | | |
467 | 490 | | |
| |||
493 | 516 | | |
494 | 517 | | |
495 | 518 | | |
496 | | - | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
497 | 523 | | |
498 | 524 | | |
499 | 525 | | |
| |||
592 | 618 | | |
593 | 619 | | |
594 | 620 | | |
595 | | - | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
| 625 | + | |
| 626 | + | |
596 | 627 | | |
597 | 628 | | |
598 | 629 | | |
| |||
603 | 634 | | |
604 | 635 | | |
605 | 636 | | |
606 | | - | |
| 637 | + | |
| 638 | + | |
| 639 | + | |
607 | 640 | | |
608 | 641 | | |
609 | 642 | | |
| |||
651 | 684 | | |
652 | 685 | | |
653 | 686 | | |
654 | | - | |
| 687 | + | |
| 688 | + | |
| 689 | + | |
| 690 | + | |
655 | 691 | | |
656 | 692 | | |
657 | 693 | | |
| |||
665 | 701 | | |
666 | 702 | | |
667 | 703 | | |
668 | | - | |
| 704 | + | |
| 705 | + | |
| 706 | + | |
| 707 | + | |
669 | 708 | | |
670 | 709 | | |
671 | 710 | | |
| |||
689 | 728 | | |
690 | 729 | | |
691 | 730 | | |
692 | | - | |
| 731 | + | |
| 732 | + | |
| 733 | + | |
693 | 734 | | |
694 | 735 | | |
695 | 736 | | |
| |||
742 | 783 | | |
743 | 784 | | |
744 | 785 | | |
745 | | - | |
| 786 | + | |
| 787 | + | |
746 | 788 | | |
747 | 789 | | |
748 | 790 | | |
| |||
757 | 799 | | |
758 | 800 | | |
759 | 801 | | |
760 | | - | |
| 802 | + | |
761 | 803 | | |
762 | | - | |
| 804 | + | |
763 | 805 | | |
764 | 806 | | |
765 | 807 | | |
766 | | - | |
| 808 | + | |
767 | 809 | | |
768 | 810 | | |
769 | 811 | | |
| |||
806 | 848 | | |
807 | 849 | | |
808 | 850 | | |
809 | | - | |
| 851 | + | |
| 852 | + | |
810 | 853 | | |
811 | 854 | | |
812 | 855 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1115 | 1115 | | |
1116 | 1116 | | |
1117 | 1117 | | |
1118 | | - | |
| 1118 | + | |
1119 | 1119 | | |
1120 | 1120 | | |
1121 | 1121 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
77 | | - | |
78 | 77 | | |
79 | 78 | | |
80 | 79 | | |
| |||
84 | 83 | | |
85 | 84 | | |
86 | 85 | | |
87 | | - | |
88 | 86 | | |
89 | 87 | | |
90 | 88 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
3 | 4 | | |
4 | 5 | | |
5 | 6 | | |
| |||
177 | 178 | | |
178 | 179 | | |
179 | 180 | | |
180 | | - | |
181 | | - | |
182 | | - | |
| 181 | + | |
| 182 | + | |
183 | 183 | | |
184 | 184 | | |
185 | 185 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
328 | 328 | | |
329 | 329 | | |
330 | 330 | | |
331 | | - | |
| 331 | + | |
332 | 332 | | |
333 | 333 | | |
334 | 334 | | |
| |||
0 commit comments