Skip to content

fix(webapp): support cloudflare api domain + wildcard cors - #126

Merged
LucasSantana-Dev merged 3 commits into
mainfrom
fix/cloudflare-api-domain-cors
Mar 10, 2026
Merged

LucasSantana-Dev merged 3 commits into
mainfrom
fix/cloudflare-api-domain-cors

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Mar 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • add frontend API base auto-resolution for hosted domains:
    • *.lucassantana.tech -> https://api.lucassantana.tech/api
    • *.luk-homeserver.com.br -> https://api.luk-homeserver.com.br/api
  • add backend CORS origin function to allow configured origins plus wildcard domains
  • update README/WEBAPP setup/changelog for hosted API domain setup
  • set DEPLOY_WEBHOOK_URL repo secret to https://api.lucassantana.tech/webhook/deploy

Validation

  • npm run type:check --workspace=packages/frontend
  • npm run type:check --workspace=packages/backend

Summary by CodeRabbit

  • Bug Fixes

    • Fixed infinite loop during OAuth login on split-domain deployments.
    • Deploy webhooks now use strict timeouts to prevent CI job hangs.
  • New Features

    • Backend CORS now supports multiple configured origins and wildcard domains for split-domain setups.
    • Frontend API client auto-resolves to correct backend endpoint based on deployment domain.
  • Documentation

    • Added configuration guidance for deployments with separate frontend and backend origins.

@vercel

vercel Bot commented Mar 10, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment Mar 10, 2026 1:19am

@netlify

netlify Bot commented Mar 10, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for regal-bunny-0c8efe ready!

Name Link
🔨 Latest commit 9fcb571
🔍 Latest deploy log https://app.netlify.com/projects/regal-bunny-0c8efe/deploys/69af714f5e2a410009e7265b
😎 Deploy Preview https://deploy-preview-126--regal-bunny-0c8efe.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Mar 10, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: d7a97d2a-6525-4a4c-ae61-48e0f1a3cd89

📥 Commits

Reviewing files that changed from the base of the PR and between 4406dda and 9fcb571.

📒 Files selected for processing (1)
  • docs/WEBAPP_SETUP.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • docs/WEBAPP_SETUP.md
📜 Recent review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
  • GitHub Check: compressed-size
  • GitHub Check: Quality Gates
  • GitHub Check: SonarCloud Scan

📝 Walkthrough

Walkthrough

This PR introduces dynamic API origin resolution for split-domain deployments. The backend now accepts configured CORS origins plus specific wildcard domains, while the frontend auto-detects API endpoints based on deployment environment when not explicitly configured.

Changes

Cohort / File(s) Summary
Documentation
CHANGELOG.md, README.md, docs/WEBAPP_SETUP.md
Updated changelogs and deployment guides to document VITE_API_BASE_URL configuration, CORS multi-origin support, and Vercel routing fix for OAuth infinite loops.
Backend CORS Middleware
packages/backend/src/middleware/index.ts
Added dynamic CORS origin validation with isAllowedOrigin() helper that accepts configured origins plus localhost and specific domain variants (lucassantana.tech, luk-homeserver.com.br). Replaced static origin option with function-based validation.
Frontend API Resolution
packages/frontend/src/services/api.ts
Added inferApiBase() function to dynamically resolve API base URL from VITE_API_BASE_URL environment variable or by mapping current hostname to corresponding API endpoints, with fallback to '/api'.

Sequence Diagram(s)

sequenceDiagram
    participant Client as Frontend Client
    participant Server as Backend Server
    
    rect rgba(100, 150, 200, 0.5)
    Note over Client,Server: OLD: Static /api routing
    Client->>Server: GET /api/data<br/>(origin: current host)
    Server->>Server: Check static frontendUrl origin
    alt Origin matches
        Server->>Client: 200 OK
    else Origin mismatch
        Server->>Client: CORS blocked
    end
    end
    
    rect rgba(100, 200, 150, 0.5)
    Note over Client,Server: NEW: Dynamic origin + host-based API resolution
    Client->>Client: inferApiBase():<br/>Check VITE_API_BASE_URL<br/>or map hostname
    Client->>Server: GET https://api.lucassantana.tech/data<br/>(origin: dashboard.lucassantana.tech)
    Server->>Server: isAllowedOrigin():<br/>Parse origin, validate against<br/>configured + wildcard list
    alt Origin allowed
        Server->>Client: 200 OK
    else Origin denied
        Server->>Client: CORS error
    end
    end
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • PR #124: Directly conflicts on deploy webhook timeout and retry logic; both modify the same webhook trigger behavior with opposite approaches (adding vs. removing extended retries).
  • PR #122: Touches related deployment/webhook and OAuth health-check flows that depend on proper origin routing and authentication configuration.

Suggested labels

size/m

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'fix(webapp): support cloudflare api domain + wildcard cors' directly summarizes the main changes: adding support for Cloudflare API domain and wildcard CORS handling in the webapp.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/cloudflare-api-domain-cors

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (4)
packages/frontend/src/vite-env.d.ts (1)

1-5: Consider extending ImportMeta for complete type coverage.

The ImportMetaEnv declaration is correct, but for full type safety you may want to also extend the ImportMeta interface to ensure import.meta.env resolves to ImportMetaEnv.

🔧 Optional enhancement for complete type coverage
 /// <reference types="vite/client" />
 
 interface ImportMetaEnv {
     readonly VITE_API_BASE_URL?: string
 }
+
+interface ImportMeta {
+    readonly env: ImportMetaEnv
+}
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@packages/frontend/src/vite-env.d.ts` around lines 1 - 5, Extend the
ImportMeta interface so TypeScript knows that import.meta.env is of type
ImportMetaEnv: add an interface declaration for ImportMeta with a readonly env:
ImportMetaEnv property to pair with the existing ImportMetaEnv declaration
(referencing ImportMetaEnv, ImportMeta, and import.meta.env to locate where to
change).
packages/frontend/src/services/api.ts (1)

25-27: Consider using globalThis for broader compatibility.

SonarCloud suggests preferring globalThis over window. While window works fine in browser-only code, globalThis is more universal and aligns with modern JavaScript standards.

♻️ Optional refactor to use globalThis
-    if (typeof window !== 'undefined') {
-        const protocol = window.location.protocol || 'https:'
-        const hostname = window.location.hostname
+    if (typeof globalThis.window !== 'undefined') {
+        const protocol = globalThis.location?.protocol || 'https:'
+        const hostname = globalThis.location?.hostname ?? ''
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@packages/frontend/src/services/api.ts` around lines 25 - 27, Replace the
browser-specific typeof window check and usage with globalThis to improve
cross-environment compatibility: change the conditional that currently uses
"typeof window !== 'undefined'" to check "typeof globalThis !== 'undefined' &&
globalThis.location", and read protocol and hostname from globalThis.location
(preserving the protocol fallback 'https:' and the hostname extraction into the
existing protocol and hostname variables). Update the code that assigns protocol
and hostname (the variables named protocol and hostname) so they come from
globalThis.location when available.
packages/backend/src/middleware/index.ts (2)

15-18: Use Set for O(1) origin lookups.

SonarCloud correctly identifies that configuredOrigins should be a Set for efficient membership checks. This is especially relevant if multiple origins are configured.

♻️ Refactor to use Set
-    const configuredOrigins = frontendUrl
+    const configuredOrigins = new Set(frontendUrl
         .split(',')
         .map((origin) => origin.trim())
         .filter((origin) => origin.length > 0)
+    )
 
     const isAllowedOrigin = (origin: string): boolean => {
-        if (configuredOrigins.includes(origin)) {
+        if (configuredOrigins.has(origin)) {
             return true
         }
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@packages/backend/src/middleware/index.ts` around lines 15 - 18, Replace the
configuredOrigins array with a Set for O(1) lookups: construct configuredOrigins
from frontendUrl by splitting, trimming and filtering, then wrapping the results
in a Set (preserve the same trimming/filtering logic). Update any membership
checks that currently use configuredOrigins.includes(...) or indexOf(...) to use
configuredOrigins.has(...) instead—look for the configuredOrigins symbol and the
CORS/origin-checking middleware (the origin => ... handler) in this file and
change those checks accordingly.

15-42: Update .env.example to document comma-separated WEBAPP_FRONTEND_URL support.

The code supports comma-separated origins in WEBAPP_FRONTEND_URL (lines 15–16), but .env.example only shows single URL examples. Add an example demonstrating multiple origins, such as:

# WEBAPP_FRONTEND_URL=https://lucky.lucassantana.tech,http://localhost:3000

This clarifies the feature for operators configuring multiple frontend origins.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@packages/backend/src/middleware/index.ts` around lines 15 - 42, The
.env.example doesn't show that WEBAPP_FRONTEND_URL supports comma-separated
origins; update the example to include a commented example demonstrating
multiple origins (e.g., WEBAPP_FRONTEND_URL containing two URLs separated by a
comma) so operators know the variable parsed by frontendUrl and used to build
configuredOrigins for isAllowedOrigin; ensure the example shows both a
production and localhost entry (e.g., one HTTPS domain and one
http://localhost:3000) and keep it commented like other env entries.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@packages/frontend/src/services/api.ts`:
- Around line 18-47: The frontend is still using hardcoded "/api/..." paths
which bypass the resolved base URL from inferApiBase/API_BASE; update all usages
(e.g., the EventSource creation in musicApi.ts and the getConnectUrl function)
to use the configured API_BASE instead of hardcoded strings. Replace instances
like '/api/guilds/${guildId}/music/stream' with
`${API_BASE}/guilds/${guildId}/music/stream` and '/api/lastfm/connect' with
`${API_BASE}/lastfm/connect`, and ensure the modules import API_BASE (from the
file that defines inferApiBase/API_BASE) so requests work across different
origins; note API_BASE is already trimmed of trailing slashes so string
concatenation as shown is safe.

---

Nitpick comments:
In `@packages/backend/src/middleware/index.ts`:
- Around line 15-18: Replace the configuredOrigins array with a Set for O(1)
lookups: construct configuredOrigins from frontendUrl by splitting, trimming and
filtering, then wrapping the results in a Set (preserve the same
trimming/filtering logic). Update any membership checks that currently use
configuredOrigins.includes(...) or indexOf(...) to use
configuredOrigins.has(...) instead—look for the configuredOrigins symbol and the
CORS/origin-checking middleware (the origin => ... handler) in this file and
change those checks accordingly.
- Around line 15-42: The .env.example doesn't show that WEBAPP_FRONTEND_URL
supports comma-separated origins; update the example to include a commented
example demonstrating multiple origins (e.g., WEBAPP_FRONTEND_URL containing two
URLs separated by a comma) so operators know the variable parsed by frontendUrl
and used to build configuredOrigins for isAllowedOrigin; ensure the example
shows both a production and localhost entry (e.g., one HTTPS domain and one
http://localhost:3000) and keep it commented like other env entries.

In `@packages/frontend/src/services/api.ts`:
- Around line 25-27: Replace the browser-specific typeof window check and usage
with globalThis to improve cross-environment compatibility: change the
conditional that currently uses "typeof window !== 'undefined'" to check "typeof
globalThis !== 'undefined' && globalThis.location", and read protocol and
hostname from globalThis.location (preserving the protocol fallback 'https:' and
the hostname extraction into the existing protocol and hostname variables).
Update the code that assigns protocol and hostname (the variables named protocol
and hostname) so they come from globalThis.location when available.

In `@packages/frontend/src/vite-env.d.ts`:
- Around line 1-5: Extend the ImportMeta interface so TypeScript knows that
import.meta.env is of type ImportMetaEnv: add an interface declaration for
ImportMeta with a readonly env: ImportMetaEnv property to pair with the existing
ImportMetaEnv declaration (referencing ImportMetaEnv, ImportMeta, and
import.meta.env to locate where to change).

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 3d320d52-1c8a-4533-87e3-949518dea6c9

📥 Commits

Reviewing files that changed from the base of the PR and between 17b66af and 4406dda.

📒 Files selected for processing (8)
  • .github/workflows/deploy.yml
  • CHANGELOG.md
  • README.md
  • docs/WEBAPP_SETUP.md
  • packages/backend/src/middleware/index.ts
  • packages/frontend/src/services/api.ts
  • packages/frontend/src/vite-env.d.ts
  • vercel.json
📜 Review details
🧰 Additional context used
📓 Path-based instructions (28)
**/*.{js,jsx,ts,tsx,vue,html}

📄 CodeRabbit inference engine (.cursor/rules/accessibility-openness.mdc)

Provide accessible UI components using semantic HTML and ARIA attributes where necessary

Files:

  • packages/frontend/src/vite-env.d.ts
  • packages/backend/src/middleware/index.ts
  • packages/frontend/src/services/api.ts
**/*.{ts,tsx,js,jsx}

📄 CodeRabbit inference engine (.cursor/rules/dependency-injection.mdc)

**/*.{ts,tsx,js,jsx}: Prefer constructor injection for classes that require dependencies
Avoid global mutable singletons unless necessary
Use explicit interfaces for external dependencies to make testing easier

**/*.{ts,tsx,js,jsx}: Include required references in PRs/code for non-trivial logic: TypeScript (official docs), MDN (JavaScript reference), and official docs for any runtime/framework/libraries used (e.g., Node.js, React) as applicable.
Before assuming behavior of an API, include the doc link and a ≤25-word quote when the change relies on it.

**/*.{ts,tsx,js,jsx}: Prefer named exports for clear usage and easier refactors in TypeScript/JavaScript
Keep import order consistent: external first, then internal modules
Remove dead code and unused imports

**/*.{ts,tsx,js,jsx}: Use PascalCase naming convention for React/UI components
Use camelCase naming convention for variables and functions
Use UPPER_SNAKE_CASE naming convention for constants
Maintain consistent import grouping and ordering within the project, keeping third-party imports separate from local imports
For external data sources (HTTP, database), always validate and sanitize input using type guards or schema validators

**/*.{ts,tsx,js,jsx}: Use Prettier with no semicolons, single quotes, 4-space indent, 80 character width
Files must not exceed 250 lines and this is enforced

Implement TypeScript typecheck and linter in CI quality checks

**/*.{ts,tsx,js,jsx}: Use TypeScript for enhanced type safety
Implement error handling and error logging
Avoid commenting code unless extremely necessary - code should explain itself with descriptive names
Leave NO todos, placeholders or missing pieces in the code
Variables and functions must use camelCase
Constants must use UPPER_SNAKE_CASE
Use arrow functions for methods and computed properties
Avoid unnecessary curly braces in conditionals; use concise syntax for simple statements
Maintain consistent import grouping/order: external imports first, then...

Files:

  • packages/frontend/src/vite-env.d.ts
  • packages/backend/src/middleware/index.ts
  • packages/frontend/src/services/api.ts
**/*.{js,jsx,ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/error-handling.mdc)

**/*.{js,jsx,ts,tsx}: Never throw strings. Throw Error (or typed subclasses) with descriptive messages
Include causal error as cause when available for better debugging
Define clear, stable error codes (e.g., ERR_AUTH_EXPIRED, ERR_NETWORK_TIMEOUT)
Provide optional metadata (e.g., details, retryable, status, correlationId) in error objects
Use domain error classes per area (e.g., AuthenticationError, ValidationError, NetworkError)
Log errors with structure (message, code, stack, cause, correlationId, user context where appropriate)
Mark retryable vs nonRetryable errors where helpful for operations
Set timeouts and handle aborts/cancellations; avoid dangling requests in API/network code
Implement backoff for transient failures; avoid infinite retries
Map HTTP status → domain errors; 4xx vs 5xx behave differently (e.g., retry for 5xx/network)

**/*.{js,jsx,ts,tsx}: Use functional components with hooks in React/React Native. Avoid class components.
Keep components focused on a single responsibility; extract complex logic into custom hooks.
Keep state local when possible. Use Context/Zustand/Redux only when necessary for state management.
If props or state traverse more than 3 levels, consider using context or a feature-scoped store instead of prop drilling.
Use performance optimization techniques: React.memo, useMemo, useCallback, Suspense (web), and virtualization for long lists; avoid unnecessary re-renders.
Web accessibility: use semantic HTML, labels, focus management, keyboard navigation, and aria-* attributes as needed.
React Native accessibility: use accessibility props (accessible, accessibilityLabel), proper roles and labels.
Identify and extract repetitive UI components proactively to components/ with clear props and minimal coupling.
Web styles: prefer co-located styles or design system tokens; avoid global style leakage.
React Native styles: prefer StyleSheet.create, design tokens, and theme providers; avoid in...

Files:

  • packages/frontend/src/vite-env.d.ts
  • packages/backend/src/middleware/index.ts
  • packages/frontend/src/services/api.ts
**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/pattern.mdc)

Introduce interfaces at module boundaries to enable testing and substitutions

**/*.{ts,tsx}: Avoid using any type in TypeScript. If unavoidable, use unknown with type guards and justify with a code comment
Prefer interface for defining public object shapes in TypeScript, use type for unions and utility types
Use TypeScript utility types such as Partial, Pick, Omit, Readonly, and Record when appropriate
Use I{Name} naming convention for interfaces in TypeScript
Use T{Name} naming convention for type aliases and utility types in TypeScript

**/*.{ts,tsx}: Functions must be less than 50 lines with cyclomatic complexity less than 10
Do not use any types - ESLint enforces this at error level

**/*.{ts,tsx}: Prefer types over interfaces for most cases
Don't ever use any - type safety always
Avoid enums; use const objects instead
For complex types, create a separate file to declare them and import them
Avoid using any type; if unavoidable, use unknown with type guards and justify with code comment
Prefer interface for public API shapes; use type for unions and utility types
Use TypeScript utility types (Partial, Pick, Omit, Readonly, Record)

Files:

  • packages/frontend/src/vite-env.d.ts
  • packages/backend/src/middleware/index.ts
  • packages/frontend/src/services/api.ts
packages/frontend/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (CLAUDE.md)

packages/frontend/src/**/*.{ts,tsx}: Frontend errors are created by Axios interceptor and should be of type ApiError with status and details from backend
Frontend uses path alias @/ mapped to src/ - use this alias for all imports from the src directory

Do not depend on @lucky/shared package in frontend code; make API calls to backend via configured base URL (env)

Files:

  • packages/frontend/src/vite-env.d.ts
  • packages/frontend/src/services/api.ts
**/*.{js,ts,tsx,jsx}

📄 CodeRabbit inference engine (.cursor/rules/documentation.mdc)

**/*.{js,ts,tsx,jsx}: Minimize comments in code; explain the 'why' when non-obvious, let code express the 'what' through clear naming
Document trade-offs briefly when deviating from ideal patterns

**/*.{js,ts,tsx,jsx}: Store secrets, ports, and hosts in environment variables (.env, .env.example) and never hardcode them
Avoid redundant or decorative AI comments; code should be self-explanatory and only commented when logic is non-obvious; prefer refactoring over lengthy comments

Files:

  • packages/frontend/src/vite-env.d.ts
  • packages/backend/src/middleware/index.ts
  • packages/frontend/src/services/api.ts
packages/frontend/**

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

The frontend package uses React with Vite and must not depend on the shared package

Files:

  • packages/frontend/src/vite-env.d.ts
  • packages/frontend/src/services/api.ts
**/*.{js,mjs,ts,mts}

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

Use Node.js version ≥22 with ESM (ECMAScript modules) only; no CommonJS

Files:

  • packages/frontend/src/vite-env.d.ts
  • packages/backend/src/middleware/index.ts
  • packages/frontend/src/services/api.ts
**/{.github/workflows,}/*.{yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)

**/{.github/workflows,}/*.{yml,yaml}: CI pipeline must include setup step (node install, environment)
CI pipeline must include lint step (TypeScript typecheck + linter)
CI pipeline must include build step (production build)
CI pipeline must include test step (unit + integration) with coverage report
CI pipeline must include quality step (static analysis, vulnerability scan)

Files:

  • .github/workflows/deploy.yml
**/{.github/workflows,dependabot.yml}/*.{yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)

Configure dependency update bot with PR templates and tests (recommended)

Files:

  • .github/workflows/deploy.yml
**/.github/workflows/*.{yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)

**/.github/workflows/*.{yml,yaml}: Configure SAST / secrets scan on PRs (recommended)
Publish artifacts only from protected pipeline steps

Files:

  • .github/workflows/deploy.yml
{jest.config.*,*.coverage.*,.nycrc*,nyc.config.*,coveragerc,.github/workflows/*.yml,.github/workflows/*.yaml}

📄 CodeRabbit inference engine (.cursor/rules/testing-quality.mdc)

Minimum recommended coverage threshold: 85% (raise per project risk)

Files:

  • .github/workflows/deploy.yml
{.github/workflows/*.{yml,yaml},*.github/workflows/*.{yml,yaml},.gitlab-ci.yml,.circleci/config.yml,bitbucket-pipelines.yml}

📄 CodeRabbit inference engine (.cursor/rules/testing-quality.mdc)

CI must run in order: lint → build → test → quality checks

Files:

  • .github/workflows/deploy.yml
{.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}

📄 CodeRabbit inference engine (.cursor/rules/workflow.mdc)

{.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}: CI/CD pipeline must include in order: Setup (Node install, env config) → Lint (TypeScript typecheck, linter) → Build (production build, artifacts) → Test (unit, integration, coverage) → Quality (static analysis, vulnerability scan)
Publish artifacts only from protected pipeline steps in CI/CD

Files:

  • .github/workflows/deploy.yml
{**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}

📄 CodeRabbit inference engine (.cursor/rules/workflow.mdc)

{**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}: Use cross-platform environment handling in scripts, cross-platform deletion utilities instead of OS-specific commands, pass non-interactive flags (--yes, --ci) by default in automation, and avoid OS-specific commands
Ensure logs are stream-friendly (no pagers) in scripts; when a pager might be used, pipe to cat

Files:

  • .github/workflows/deploy.yml
**/index.ts

📄 CodeRabbit inference engine (.cursor/rules/pattern.mdc)

Use index.ts only to re-export a small, intentional surface per module

Files:

  • packages/backend/src/middleware/index.ts
packages/backend/src/**/*.ts

📄 CodeRabbit inference engine (CLAUDE.md)

packages/backend/src/**/*.ts: Validation must use Zod schemas in backend/src/schemas/ and be applied via validateBody, validateParams, or validateQuery
Do not reassign req.query in Express middleware - it is read-only in Express 5

Files:

  • packages/backend/src/middleware/index.ts
packages/backend/src/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/lucky-backend-api.mdc)

packages/backend/src/**/*.{ts,tsx}: Use shared config and env from @lucky/shared when needed; avoid duplicating env parsing in backend code
Keep tokens and secrets in environment variables only; never hardcode or expose in code

Files:

  • packages/backend/src/middleware/index.ts
packages/backend/src/{services,middleware}/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/lucky-backend-api.mdc)

packages/backend/src/{services,middleware}/**/*.{ts,tsx}: Implement Discord OAuth for authentication in backend services
Use SessionService in middleware for session handling; keep session and auth logic centralized

Files:

  • packages/backend/src/middleware/index.ts
packages/backend/src/{routes,middleware}/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/lucky-backend-api.mdc)

Return consistent JSON error responses with appropriate HTTP status codes; do not expose stack traces or secrets in responses

Files:

  • packages/backend/src/middleware/index.ts
packages/backend/**

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

The backend package depends on shared and contains Express API with auth and guild routes

Files:

  • packages/backend/src/middleware/index.ts
packages/backend/**/*.ts

📄 CodeRabbit inference engine (.cursor/rules/subagent-backend.mdc)

packages/backend/**/*.ts: Apply .cursor/rules/lucky-backend-api.mdc for structure and conventions when acting as backend specialist
Use .cursor/skills/backend-express/SKILL.md for Express routes, middleware, and services when acting as backend specialist
Use @lucky/shared for config and DB/Redis when needed in backend code

Files:

  • packages/backend/src/middleware/index.ts
{CHANGELOG.md,README.md}

📄 CodeRabbit inference engine (.cursor/rules/agent-rules.mdc)

ALWAYS update CHANGELOG.md and README.md as changes are made.

Files:

  • CHANGELOG.md
  • README.md
CHANGELOG.md

📄 CodeRabbit inference engine (.cursor/rules/templates-examples.mdc)

CHANGELOG.md must be updated with all changes in pull requests

Always update CHANGELOG.md with all code changes

Update CHANGELOG.md with all changes, include breaking changes documentation, and reference issues and PRs

Files:

  • CHANGELOG.md
{CHANGELOG.md,docs/**}

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

Update CHANGELOG.md and relevant docs/ files when behavior or setup changes

Files:

  • CHANGELOG.md
  • docs/WEBAPP_SETUP.md
packages/frontend/src/{stores,services}/**/*.{ts,tsx}

📄 CodeRabbit inference engine (.cursor/rules/lucky-frontend.mdc)

Store application state in packages/frontend/src/stores/ and API calls in packages/frontend/src/services/api.ts

Files:

  • packages/frontend/src/services/api.ts
README.md

📄 CodeRabbit inference engine (.cursor/rules/templates-examples.mdc)

README.md must be updated if behavior changed

Update README.md if behavior changed

Files:

  • README.md
**/docs/**/*.{md,mdx}

📄 CodeRabbit inference engine (.cursor/rules/documentation.mdc)

**/docs/**/*.{md,mdx}: Keep API documentation in sync with code changes
Document significant architectural design choices

Files:

  • docs/WEBAPP_SETUP.md
🧠 Learnings (16)
📚 Learning: 2026-03-09T20:21:08.600Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.600Z
Learning: Applies to package.json : Use npm workspaces monorepo structure with packages in `packages/*` directory containing: `shared` (config, services, types, utils), `bot` (Discord.js/Discord Player), `backend` (Express API), and `frontend` (React/Vite)

Applied to files:

  • vercel.json
📚 Learning: 2026-03-09T20:22:47.441Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-09T20:22:47.441Z
Learning: For React, Vite, and Tailwind work in the frontend package, use the `frontend-react-vite` skill

Applied to files:

  • vercel.json
  • README.md
  • docs/WEBAPP_SETUP.md
📚 Learning: 2026-03-09T20:21:08.600Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.600Z
Learning: Applies to packages/frontend/** : The `frontend` package uses React with Vite and must not depend on the shared package

Applied to files:

  • vercel.json
  • README.md
📚 Learning: 2026-03-09T20:21:08.600Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.600Z
Learning: Applies to package.json : Use `npm run build` for shared → bot → backend build order; use `npm run build:frontend` separately for frontend

Applied to files:

  • vercel.json
📚 Learning: 2026-03-09T20:22:47.441Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-09T20:22:47.441Z
Learning: Run `npm run build` to build the monorepo (shared → bot → backend); `npm run build:frontend` for the frontend package

Applied to files:

  • vercel.json
📚 Learning: 2026-03-09T20:20:56.345Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-frontend.mdc:0-0
Timestamp: 2026-03-09T20:20:56.345Z
Learning: Applies to packages/frontend/src/**/*.{ts,tsx} : Do not depend on `lucky/shared` package in frontend code; make API calls to backend via configured base URL (env)

Applied to files:

  • vercel.json
  • packages/backend/src/middleware/index.ts
  • CHANGELOG.md
  • packages/frontend/src/services/api.ts
  • README.md
  • docs/WEBAPP_SETUP.md
📚 Learning: 2026-03-09T20:21:15.586Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-shared.mdc:0-0
Timestamp: 2026-03-09T20:21:15.586Z
Learning: Applies to packages/shared/**/*.ts : Organize the Lucky Shared Package with the following directory structure: Config in `packages/shared/src/config/` (environment, constants, feature toggles, YouTube config); Services in `packages/shared/src/services/` (DatabaseService, Redis client/operations, FeatureToggleService, ReactionRoles, RoleManagement); Types in `packages/shared/src/types/` (errors, commands, common, discord, music); Utils in `packages/shared/src/utils/` (error handling, retry, embeds, log, monitoring, composables, prismaClient)

Applied to files:

  • vercel.json
📚 Learning: 2026-03-09T20:21:08.600Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.600Z
Learning: Applies to package.json : Use `npm run dev:bot`, `npm run dev:backend`, and `npm run dev:frontend` for development, and `npm run db:*` commands for database operations

Applied to files:

  • vercel.json
📚 Learning: 2026-03-09T20:21:58.981Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-frontend.mdc:0-0
Timestamp: 2026-03-09T20:21:58.981Z
Learning: Keep frontend code scoped to `packages/frontend`; communicate with backend via `services/api.ts` using the configured env base URL; do not access shared database or Redis directly

Applied to files:

  • vercel.json
  • packages/frontend/src/services/api.ts
📚 Learning: 2026-03-09T20:21:15.586Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-shared.mdc:0-0
Timestamp: 2026-03-09T20:21:15.586Z
Learning: Applies to packages/shared/**/*.ts : Use the single Prisma client located at `packages/shared/src/utils/database/prismaClient.ts`; maintain schema in repo root at `prisma/schema.prisma`; run migrations from root using `npm run db:migrate`

Applied to files:

  • vercel.json
📚 Learning: 2026-03-09T20:20:38.683Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-backend-api.mdc:0-0
Timestamp: 2026-03-09T20:20:38.683Z
Learning: Applies to packages/backend/src/{services,middleware}/**/*.{ts,tsx} : Use SessionService in middleware for session handling; keep session and auth logic centralized

Applied to files:

  • packages/backend/src/middleware/index.ts
📚 Learning: 2026-03-09T20:21:08.600Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.600Z
Learning: Applies to {CHANGELOG.md,docs/**} : Update `CHANGELOG.md` and relevant `docs/` files when behavior or setup changes

Applied to files:

  • CHANGELOG.md
📚 Learning: 2026-03-09T20:21:08.600Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.600Z
Learning: Applies to packages/backend/** : The `backend` package depends on `shared` and contains Express API with auth and guild routes

Applied to files:

  • packages/frontend/src/services/api.ts
📚 Learning: 2026-03-09T20:20:32.235Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/documentation.mdc:0-0
Timestamp: 2026-03-09T20:20:32.235Z
Learning: Applies to README.md : Update README.md if behavior changed

Applied to files:

  • README.md
📚 Learning: 2026-03-09T20:20:32.235Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/documentation.mdc:0-0
Timestamp: 2026-03-09T20:20:32.235Z
Learning: Applies to **/docs/**/*.{md,mdx} : Keep API documentation in sync with code changes

Applied to files:

  • README.md
📚 Learning: 2026-03-09T20:20:32.235Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/documentation.mdc:0-0
Timestamp: 2026-03-09T20:20:32.235Z
Learning: Applies to **/docs/**/*.{md,mdx} : Document significant architectural design choices

Applied to files:

  • README.md
🪛 GitHub Check: SonarCloud Code Analysis
packages/backend/src/middleware/index.ts

[warning] 15-15: configuredOrigins should be a Set, and use configuredOrigins.has() to check existence or non-existence.

See more on https://sonarcloud.io/project/issues?id=LucasSantana-Dev_Nexus&issues=AZzVSEoZuXUW7gR7dka_&open=AZzVSEoZuXUW7gR7dka_&pullRequest=126

packages/frontend/src/services/api.ts

[warning] 26-26: Prefer globalThis over window.

See more on https://sonarcloud.io/project/issues?id=LucasSantana-Dev_Nexus&issues=AZzVSEqguXUW7gR7dkbB&open=AZzVSEqguXUW7gR7dkbB&pullRequest=126


[warning] 27-27: Prefer globalThis over window.

See more on https://sonarcloud.io/project/issues?id=LucasSantana-Dev_Nexus&issues=AZzVSEqguXUW7gR7dkbC&open=AZzVSEqguXUW7gR7dkbC&pullRequest=126


[warning] 25-25: Prefer globalThis.window over window.

See more on https://sonarcloud.io/project/issues?id=LucasSantana-Dev_Nexus&issues=AZzVSEqguXUW7gR7dkbA&open=AZzVSEqguXUW7gR7dkbA&pullRequest=126

🔇 Additional comments (6)
vercel.json (1)

1-6: LGTM!

Removing the /api/* rewrite is correct given the new dynamic API base resolution in the frontend. The frontend now explicitly targets the appropriate backend origin rather than relying on Vercel to proxy requests, which prevents the OAuth infinite loop issue.

.github/workflows/deploy.yml (1)

44-45: LGTM!

The timeout adjustment is appropriate. Based on the webhook configuration in deploy/hooks.json, the server returns "Deploy triggered" immediately while executing the deployment script asynchronously. A 10-second connect timeout and 20-second request timeout are sufficient for acknowledging the webhook trigger without waiting for the full deployment to complete.

packages/backend/src/middleware/index.ts (1)

46-53: CORS origin callback correctly handles missing and invalid origins.

The implementation properly allows requests without an origin header (same-origin or non-browser clients) and rejects invalid origins with an explicit error. This is secure and follows best practices.

CHANGELOG.md (1)

19-23: LGTM!

The changelog entries accurately document all the key changes in this PR: CORS wildcard domain support, frontend API auto-resolution, Vercel routing fix, environment variable support, and deploy webhook timeouts. The entries follow Keep a Changelog format and are appropriately categorized under "Fixed".

docs/WEBAPP_SETUP.md (1)

72-79: LGTM!

Documentation clearly explains the new VITE_API_BASE_URL environment variable for hosted deployments and the comma-separated origins support for WEBAPP_FRONTEND_URL. This aligns well with the code changes in api.ts and the backend middleware.

README.md (1)

131-134: LGTM!

The README update clearly explains the VITE_API_BASE_URL requirement for hosted deployments and the fallback auto-targeting behavior. This helps operators understand when and why to configure the environment variable, preventing auth/API misrouting issues.

Comment on lines +18 to +47
const configuredApiBase = import.meta.env.VITE_API_BASE_URL?.trim()

const inferApiBase = (): string => {
if (configuredApiBase && configuredApiBase.length > 0) {
return configuredApiBase
}

if (typeof window !== 'undefined') {
const protocol = window.location.protocol || 'https:'
const hostname = window.location.hostname

if (
hostname === 'lucassantana.tech' ||
hostname.endsWith('.lucassantana.tech')
) {
return `${protocol}//api.lucassantana.tech/api`
}

if (
hostname === 'luk-homeserver.com.br' ||
hostname.endsWith('.luk-homeserver.com.br')
) {
return `${protocol}//api.luk-homeserver.com.br/api`
}
}

return '/api'
}

const API_BASE = inferApiBase().replace(/\/+$/, '')

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Search for hardcoded /api/ paths in frontend services that bypass API_BASE
rg -n --type=ts '/api/' packages/frontend/src/services/ | grep -v 'API_BASE' | grep -v 'import'

Repository: LucasSantana-Dev/Lucky

Length of output: 281


Use API_BASE for EventSource and other API endpoints instead of hardcoding /api/ paths.

The inferApiBase function correctly resolves the API base URL from environment variables with host-based fallbacks. However, hardcoded paths in packages/frontend/src/services/musicApi.ts (line 74) and packages/frontend/src/services/api.ts (line 345) bypass this configuration:

  • EventSource at line 74 hardcodes /api/guilds/${guildId}/music/stream
  • getConnectUrl at line 345 hardcodes /api/lastfm/connect

These will fail when the frontend and backend are on different origins. Replace with ${API_BASE}/guilds/${guildId}/music/stream and similar patterns.

🧰 Tools
🪛 GitHub Check: SonarCloud Code Analysis

[warning] 26-26: Prefer globalThis over window.

See more on https://sonarcloud.io/project/issues?id=LucasSantana-Dev_Nexus&issues=AZzVSEqguXUW7gR7dkbB&open=AZzVSEqguXUW7gR7dkbB&pullRequest=126


[warning] 27-27: Prefer globalThis over window.

See more on https://sonarcloud.io/project/issues?id=LucasSantana-Dev_Nexus&issues=AZzVSEqguXUW7gR7dkbC&open=AZzVSEqguXUW7gR7dkbC&pullRequest=126


[warning] 25-25: Prefer globalThis.window over window.

See more on https://sonarcloud.io/project/issues?id=LucasSantana-Dev_Nexus&issues=AZzVSEqguXUW7gR7dkbA&open=AZzVSEqguXUW7gR7dkbA&pullRequest=126

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@packages/frontend/src/services/api.ts` around lines 18 - 47, The frontend is
still using hardcoded "/api/..." paths which bypass the resolved base URL from
inferApiBase/API_BASE; update all usages (e.g., the EventSource creation in
musicApi.ts and the getConnectUrl function) to use the configured API_BASE
instead of hardcoded strings. Replace instances like
'/api/guilds/${guildId}/music/stream' with
`${API_BASE}/guilds/${guildId}/music/stream` and '/api/lastfm/connect' with
`${API_BASE}/lastfm/connect`, and ensure the modules import API_BASE (from the
file that defines inferApiBase/API_BASE) so requests work across different
origins; note API_BASE is already trimmed of trailing slashes so string
concatenation as shown is safe.

@github-actions github-actions Bot added size/m and removed ci labels Mar 10, 2026
@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
1 Security Hotspot

See analysis details on SonarQube Cloud

@github-actions

Copy link
Copy Markdown

Size Change: +76 B (+0.03%)

Total Size: 291 kB

Filename Size Change
packages/frontend/dist/assets/AutoMessages-CAZ9ILRq.js 0 B -1.56 kB (removed) 🏆
packages/frontend/dist/assets/AutoMessages-CqOCNKTm.js 1.56 kB +1.56 kB (new file) 🆕
packages/frontend/dist/assets/AutoMod-PM47z1iK.js 0 B -2.73 kB (removed) 🏆
packages/frontend/dist/assets/AutoMod-uJN0qDmh.js 2.73 kB +2.73 kB (new file) 🆕
packages/frontend/dist/assets/badge-D5xxJKCI.js 0 B -453 B (removed) 🏆
packages/frontend/dist/assets/badge-D46fMEdz.js 453 B +453 B (new file) 🆕
packages/frontend/dist/assets/Card-B_wNI2Fw.js 0 B -379 B (removed) 🏆
packages/frontend/dist/assets/Card-D7zYyaUG.js 380 B +380 B (new file) 🆕
packages/frontend/dist/assets/CommandsConfig-BoDMkgFt.js 1.43 kB +1.43 kB (new file) 🆕
packages/frontend/dist/assets/CommandsConfig-DBVXHZqG.js 0 B -1.43 kB (removed) 🏆
packages/frontend/dist/assets/Config-D0pHLvMI.js 0 B -1.61 kB (removed) 🏆
packages/frontend/dist/assets/Config-hQmg1bhs.js 1.61 kB +1.61 kB (new file) 🆕
packages/frontend/dist/assets/CustomCommands-BPsSHkLh.js 2.1 kB +2.1 kB (new file) 🆕
packages/frontend/dist/assets/CustomCommands-Dax3g6CY.js 0 B -2.1 kB (removed) 🏆
packages/frontend/dist/assets/DashboardOverview-BvjLH0-K.js 0 B -2.93 kB (removed) 🏆
packages/frontend/dist/assets/DashboardOverview-DDdvkSC1.js 2.93 kB +2.93 kB (new file) 🆕
packages/frontend/dist/assets/Features-C3Yv8GkR.js 2.39 kB +2.39 kB (new file) 🆕
packages/frontend/dist/assets/Features-Vyj-XwAm.js 0 B -2.39 kB (removed) 🏆
packages/frontend/dist/assets/index-BODCqMii.js 67 kB +67 kB (new file) 🆕
packages/frontend/dist/assets/index-CyYQz5UE.js 0 B -66.9 kB (removed) 🏆
packages/frontend/dist/assets/input-DZrf_dPp.js 0 B -427 B (removed) 🏆
packages/frontend/dist/assets/input-slCE9CUf.js 425 B +425 B (new file) 🆕
packages/frontend/dist/assets/label-Bjoyr5_B.js 441 B +441 B (new file) 🆕
packages/frontend/dist/assets/label-DLe_jZoJ.js 0 B -444 B (removed) 🏆
packages/frontend/dist/assets/LastFm-BFgUN6-q.js 0 B -1.52 kB (removed) 🏆
packages/frontend/dist/assets/LastFm-CQZKvZkv.js 1.52 kB +1.52 kB (new file) 🆕
packages/frontend/dist/assets/Login-BsPSfPB3.js 2.23 kB +2.23 kB (new file) 🆕
packages/frontend/dist/assets/Login-CPPo7TNZ.js 0 B -2.23 kB (removed) 🏆
packages/frontend/dist/assets/Lyrics-BbSaHn9N.js 1.3 kB +1.3 kB (new file) 🆕
packages/frontend/dist/assets/Lyrics-Ctm0ufQE.js 0 B -1.31 kB (removed) 🏆
packages/frontend/dist/assets/Moderation-CGwW3Sq8.js 3.76 kB +3.76 kB (new file) 🆕
packages/frontend/dist/assets/Moderation-D-82mKiq.js 0 B -3.75 kB (removed) 🏆
packages/frontend/dist/assets/ModerationConfig-CmkdWicp.js 1.93 kB +1.93 kB (new file) 🆕
packages/frontend/dist/assets/ModerationConfig-CrdfuHDB.js 0 B -1.93 kB (removed) 🏆
packages/frontend/dist/assets/Music-CmKLLdI2.js 6.08 kB +6.08 kB (new file) 🆕
packages/frontend/dist/assets/Music-DRmiO6K1.js 0 B -6.08 kB (removed) 🏆
packages/frontend/dist/assets/MusicConfig-CFVdLd0b.js 1.62 kB +1.62 kB (new file) 🆕
packages/frontend/dist/assets/MusicConfig-nP0RtkwW.js 0 B -1.62 kB (removed) 🏆
packages/frontend/dist/assets/select-BErbxV_4.js 1.19 kB +1.19 kB (new file) 🆕
packages/frontend/dist/assets/select-OhCULZoc.js 0 B -1.19 kB (removed) 🏆
packages/frontend/dist/assets/ServerLogs-D5a-K7-t.js 0 B -2.82 kB (removed) 🏆
packages/frontend/dist/assets/ServerLogs-DU9R9nbG.js 2.82 kB +2.82 kB (new file) 🆕
packages/frontend/dist/assets/ServerSettings-BP2wlnNi.js 1.89 kB +1.89 kB (new file) 🆕
packages/frontend/dist/assets/ServerSettings-D7dD3pvQ.js 0 B -1.89 kB (removed) 🏆
packages/frontend/dist/assets/ServersPage-B-m1c00l.js 0 B -2.4 kB (removed) 🏆
packages/frontend/dist/assets/ServersPage-Dd9z2FLD.js 2.4 kB +2.4 kB (new file) 🆕
packages/frontend/dist/assets/Skeleton-Co_-kx2c.js 0 B -227 B (removed) 🏆
packages/frontend/dist/assets/Skeleton-Dr1DLTq3.js 228 B +228 B (new file) 🆕
packages/frontend/dist/assets/switch-B7_jZ8VB.js 516 B +516 B (new file) 🆕
packages/frontend/dist/assets/switch-D3QIgkt2.js 0 B -516 B (removed) 🏆
packages/frontend/dist/assets/TrackHistory-DDAC3F1J.js 0 B -1.84 kB (removed) 🏆
packages/frontend/dist/assets/TrackHistory-gdm0ralT.js 1.84 kB +1.84 kB (new file) 🆕
packages/frontend/dist/assets/TwitchNotifications-BkL7smhu.js 1.57 kB +1.57 kB (new file) 🆕
packages/frontend/dist/assets/TwitchNotifications-D98KR8RH.js 0 B -1.57 kB (removed) 🏆
packages/frontend/dist/assets/useGuildSelection-CxGHb-El.js 293 B +293 B (new file) 🆕
packages/frontend/dist/assets/useGuildSelection-G6zGbVtw.js 0 B -296 B (removed) 🏆
ℹ️ View Unchanged
Filename Size
packages/frontend/dist/assets/index-DLqvhx7-.css 13 kB
packages/frontend/dist/assets/usePageMetadata-Dudc5JrX.js 287 B
packages/frontend/dist/assets/vendor-forms-C1Gy4syj.js 21.1 kB
packages/frontend/dist/assets/vendor-radix-BTf9AecN.js 33.5 kB
packages/frontend/dist/assets/vendor-react-Bu1Oeml_.js 17.3 kB
packages/frontend/dist/assets/vendor-state-Szs8I3iE.js 25 kB
packages/frontend/dist/assets/vendor-ui-DSWwm_-g.js 64.2 kB
packages/frontend/dist/assets/zod-CLxBCFgw.js 1.58 kB

compressed-size-action

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
1 Security Hotspot
0.0% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

This branch was successfully deployed

1 active deployment
Preview — 9fcb5714 Deployed Mar 10, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant