Skip to content

fix: privacy toggle persistence - #113

Merged
peter6055 merged 7 commits into
mainfrom
fix/privacy-toggle-persistence
Jul 9, 2026
Merged

peter6055 merged 7 commits into
mainfrom
fix/privacy-toggle-persistence

Conversation

@peter6055

@peter6055 peter6055 commented Jul 9, 2026 •

Copy link
Copy Markdown
Owner

Summary by CodeRabbit

  • New Features

    • Telemetry preferences are now saved in your browser, so your analytics/debug settings persist between visits.
    • Added structured GitHub issue and pull request templates for bug reports, feature requests, questions, commercial use requests, and PR submissions.
  • Bug Fixes

    • Improved Docker packaging to avoid including local environment files and other sensitive build-time data in production images.
  • Documentation

    • Updated setup, licensing, architecture, and contributing docs to reflect current requirements and supported diagram types.
  • Chores

    • Added code scanning and expanded CI checks to include tests.

@railway-app
railway-app Bot temporarily deployed to livemaid / livemaid-pr-113 July 9, 2026 12:39 Destroyed
@coderabbitai

coderabbitai Bot commented Jul 9, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

This PR adds GitHub issue/PR templates, a funding config, a CodeQL workflow, and a blocking test step in CI. It renames commercial licensing terminology across LICENSE/NOTICE/README/CONTRIBUTING, adds Docker/env hygiene, raises engine requirements, fixes documentation links, and persists telemetry preferences via localStorage.

Changes

Documentation, Licensing, and CI Infrastructure

Layer / File(s) Summary
GitHub issue/PR templates and funding config
.github/FUNDING.yml, .github/ISSUE_TEMPLATE/*, .github/PULL_REQUEST_TEMPLATE.md
Adds bug report, commercial use, feature request, and question issue forms plus template config, funding config, and a PR template.
CI workflow, Docker hygiene, and engine requirements
.github/workflows/codeql.yml, .github/workflows/pr-checks.yml, .dockerignore, Dockerfile, package.json
Adds a CodeQL workflow, a blocking Tests step in pr-checks, strips env/data artifacts from the Docker build, ignores env files, and raises Node/npm engine requirements plus dompurify version.
Licensing terminology and README/CONTRIBUTING updates
LICENSE, NOTICE, COMMERCIAL_USE.md, README.md, CONTRIBUTING.md
Renames commercial license references to commercial use, repositions README licensing/requirements content and Buy Me A Coffee callout, and updates CONTRIBUTING prerequisites and CI check descriptions.
Reference documentation link fixes
reference/architecture/*, reference/features/*, reference/git/README.md, reference/plans/*, reference/skills/README.md, reference/standards/README.md
Fixes relative README link paths and updates diagram-type wording for two-way vs code-only support, including mindmap plugin mentions.

Estimated code review effort: 2 (Simple) | ~15 minutes

Storage Adapter and Telemetry Persistence

Layer / File(s) Summary
Storage adapter data directory selection
src/lib/api/storageFsAdapter.ts
Rewrites DATA_DIR initialization to select demo vs data directory via an inline ternary of path.join calls.
Persisted telemetry preferences
src/lib/telemetry/telemetryProvider.tsx
Adds localStorage-backed load/save helpers for telemetry preferences and updates TelemetryProvider to initialize state from and persist toggles to those preferences.

Estimated code review effort: 2 (Simple) | ~10 minutes

Sequence Diagram(s)

sequenceDiagram
  participant User
  participant TelemetryProvider
  participant localStorage
  participant TelemetryInstance

  TelemetryProvider->>localStorage: loadTelemetryPreferences()
  localStorage-->>TelemetryProvider: usageAnalytics, debugReporting
  TelemetryProvider->>TelemetryInstance: initTelemetry(config)
  TelemetryProvider->>TelemetryInstance: setUsageAnalytics(stored)
  TelemetryProvider->>TelemetryInstance: setDebugReporting(stored)
  User->>TelemetryProvider: toggle preference
  TelemetryProvider->>localStorage: saveTelemetryPreferences(updated)
  TelemetryProvider->>TelemetryInstance: setUsageAnalytics/setDebugReporting(updated)
Loading

Poem

A rabbit hops through docs and forms,
Templates sprout like fields in storms. 🐇
Env files hidden, licenses renamed,
Telemetry preferences now retained!
Hop, hop, commit — the burrow's gleamed. ✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the main functional change: persisting the privacy/telemetry toggle settings.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 Trivy (0.69.3)

Trivy execution failed: 2026-07-09T12:44:42Z FATAL Fatal error run error: fs scan error: scan error: scan failed: failed analysis: post analysis error: post analysis error: ansible scan error: fs filter error: fs filter error: walk error range error: stat doctor.config.json: no such file or directory: range error: stat doctor.config.json: no such file or directory


Comment @coderabbitai help to get the list of available commands.

@peter6055
peter6055 force-pushed the fix/privacy-toggle-persistence branch from 4fef518 to 7a875be Compare July 9, 2026 12:43
@railway-app
railway-app Bot temporarily deployed to livemaid / livemaid-pr-113 July 9, 2026 12:43 Destroyed

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (2)
.github/workflows/codeql.yml (1)

30-31: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win

Harden checkout: set persist-credentials: false.

Static analysis flags credential persistence via the default checkout token. Since this workflow only needs read access to analyze code, disable credential persistence to reduce the blast radius if a later step is compromised.

🔒 Proposed fix
       - name: Checkout repository
         uses: actions/checkout@v4
+        with:
+          persist-credentials: false
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/codeql.yml around lines 30 - 31, The checkout step in the
CodeQL workflow is leaving the default token credentials persisted, so update
the existing actions/checkout usage to disable credential persistence. Modify
the Checkout repository step in the workflow to set persist-credentials to
false, keeping the change scoped to the checkout configuration used by the code
scanning job.

Source: Linters/SAST tools

.github/ISSUE_TEMPLATE/config.yml (1)

1-5: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Consider disabling blank issues.

If these forms are meant to be the canonical intake path, blank_issues_enabled: true lets users bypass the new prompts entirely. Flipping this to false keeps reports routed through the templates.

Suggested change
-blank_issues_enabled: true
+blank_issues_enabled: false
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/ISSUE_TEMPLATE/config.yml around lines 1 - 5, The issue is that
blank GitHub issues are still allowed, which bypasses the issue templates.
Update the ISSUE_TEMPLATE config so blank_issues_enabled is disabled, and keep
the existing contact_links entry intact. Use the config.yml setting itself as
the key symbol to locate the change.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In @.github/ISSUE_TEMPLATE/config.yml:
- Around line 1-5: The issue is that blank GitHub issues are still allowed,
which bypasses the issue templates. Update the ISSUE_TEMPLATE config so
blank_issues_enabled is disabled, and keep the existing contact_links entry
intact. Use the config.yml setting itself as the key symbol to locate the
change.

In @.github/workflows/codeql.yml:
- Around line 30-31: The checkout step in the CodeQL workflow is leaving the
default token credentials persisted, so update the existing actions/checkout
usage to disable credential persistence. Modify the Checkout repository step in
the workflow to set persist-credentials to false, keeping the change scoped to
the checkout configuration used by the code scanning job.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: d3441555-5384-441a-9c4c-88dcf37cf002

📥 Commits

Reviewing files that changed from the base of the PR and between 009acfd and 7a875be.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (29)
  • .dockerignore
  • .github/FUNDING.yml
  • .github/ISSUE_TEMPLATE/bug_report.yml
  • .github/ISSUE_TEMPLATE/commercial_use_request.yml
  • .github/ISSUE_TEMPLATE/config.yml
  • .github/ISSUE_TEMPLATE/feature_request.yml
  • .github/ISSUE_TEMPLATE/question.yml
  • .github/PULL_REQUEST_TEMPLATE.md
  • .github/workflows/codeql.yml
  • .github/workflows/pr-checks.yml
  • COMMERCIAL_USE.md
  • CONTRIBUTING.md
  • Dockerfile
  • LICENSE
  • NOTICE
  • README.md
  • package.json
  • reference/architecture/README.md
  • reference/architecture/overview.md
  • reference/architecture/plugins.md
  • reference/features/README.md
  • reference/features/reading-map.md
  • reference/git/README.md
  • reference/plans/README.md
  • reference/plans/verification-plan.md
  • reference/skills/README.md
  • reference/standards/README.md
  • src/lib/api/storageFsAdapter.ts
  • src/lib/telemetry/telemetryProvider.tsx

@railway-app
railway-app Bot temporarily deployed to livemaid / livemaid-pr-113 July 9, 2026 12:57 Destroyed
@railway-app

railway-app Bot commented Jul 9, 2026

Copy link
Copy Markdown

🚅 Deployed to the livemaid-pr-113 environment in livemaid

Service Status Web Updated (UTC)
livemaid ✅ Success (View Logs) Web Jul 9, 2026 at 12:57 pm

@peter6055
peter6055 merged commit 3b41359 into main Jul 9, 2026
5 checks passed
@peter6055
peter6055 deleted the fix/privacy-toggle-persistence branch July 9, 2026 13:03

This branch was successfully deployed

No deployments
livemaid / livemaid-pr-113 — 049291ba Deployed Jul 9, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant