Repository navigation
fix: privacy toggle persistence - #113
Conversation
📝 WalkthroughWalkthroughThis PR adds GitHub issue/PR templates, a funding config, a CodeQL workflow, and a blocking test step in CI. It renames commercial licensing terminology across LICENSE/NOTICE/README/CONTRIBUTING, adds Docker/env hygiene, raises engine requirements, fixes documentation links, and persists telemetry preferences via localStorage. ChangesDocumentation, Licensing, and CI Infrastructure
Estimated code review effort: 2 (Simple) | ~15 minutes Storage Adapter and Telemetry Persistence
Estimated code review effort: 2 (Simple) | ~10 minutes Sequence Diagram(s)sequenceDiagram
participant User
participant TelemetryProvider
participant localStorage
participant TelemetryInstance
TelemetryProvider->>localStorage: loadTelemetryPreferences()
localStorage-->>TelemetryProvider: usageAnalytics, debugReporting
TelemetryProvider->>TelemetryInstance: initTelemetry(config)
TelemetryProvider->>TelemetryInstance: setUsageAnalytics(stored)
TelemetryProvider->>TelemetryInstance: setDebugReporting(stored)
User->>TelemetryProvider: toggle preference
TelemetryProvider->>localStorage: saveTelemetryPreferences(updated)
TelemetryProvider->>TelemetryInstance: setUsageAnalytics/setDebugReporting(updated)
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 Trivy (0.69.3)Trivy execution failed: 2026-07-09T12:44:42Z FATAL Fatal error run error: fs scan error: scan error: scan failed: failed analysis: post analysis error: post analysis error: ansible scan error: fs filter error: fs filter error: walk error range error: stat doctor.config.json: no such file or directory: range error: stat doctor.config.json: no such file or directory Comment |
4fef518 to
7a875be
Compare
There was a problem hiding this comment.
🧹 Nitpick comments (2)
.github/workflows/codeql.yml (1)
30-31: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick winHarden checkout: set
persist-credentials: false.Static analysis flags credential persistence via the default checkout token. Since this workflow only needs read access to analyze code, disable credential persistence to reduce the blast radius if a later step is compromised.
🔒 Proposed fix
- name: Checkout repository uses: actions/checkout@v4 + with: + persist-credentials: false🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/codeql.yml around lines 30 - 31, The checkout step in the CodeQL workflow is leaving the default token credentials persisted, so update the existing actions/checkout usage to disable credential persistence. Modify the Checkout repository step in the workflow to set persist-credentials to false, keeping the change scoped to the checkout configuration used by the code scanning job.Source: Linters/SAST tools
.github/ISSUE_TEMPLATE/config.yml (1)
1-5: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winConsider disabling blank issues.
If these forms are meant to be the canonical intake path,
blank_issues_enabled: truelets users bypass the new prompts entirely. Flipping this tofalsekeeps reports routed through the templates.Suggested change
-blank_issues_enabled: true +blank_issues_enabled: false🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/ISSUE_TEMPLATE/config.yml around lines 1 - 5, The issue is that blank GitHub issues are still allowed, which bypasses the issue templates. Update the ISSUE_TEMPLATE config so blank_issues_enabled is disabled, and keep the existing contact_links entry intact. Use the config.yml setting itself as the key symbol to locate the change.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In @.github/ISSUE_TEMPLATE/config.yml:
- Around line 1-5: The issue is that blank GitHub issues are still allowed,
which bypasses the issue templates. Update the ISSUE_TEMPLATE config so
blank_issues_enabled is disabled, and keep the existing contact_links entry
intact. Use the config.yml setting itself as the key symbol to locate the
change.
In @.github/workflows/codeql.yml:
- Around line 30-31: The checkout step in the CodeQL workflow is leaving the
default token credentials persisted, so update the existing actions/checkout
usage to disable credential persistence. Modify the Checkout repository step in
the workflow to set persist-credentials to false, keeping the change scoped to
the checkout configuration used by the code scanning job.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro
Run ID: d3441555-5384-441a-9c4c-88dcf37cf002
⛔ Files ignored due to path filters (1)
package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (29)
.dockerignore.github/FUNDING.yml.github/ISSUE_TEMPLATE/bug_report.yml.github/ISSUE_TEMPLATE/commercial_use_request.yml.github/ISSUE_TEMPLATE/config.yml.github/ISSUE_TEMPLATE/feature_request.yml.github/ISSUE_TEMPLATE/question.yml.github/PULL_REQUEST_TEMPLATE.md.github/workflows/codeql.yml.github/workflows/pr-checks.ymlCOMMERCIAL_USE.mdCONTRIBUTING.mdDockerfileLICENSENOTICEREADME.mdpackage.jsonreference/architecture/README.mdreference/architecture/overview.mdreference/architecture/plugins.mdreference/features/README.mdreference/features/reading-map.mdreference/git/README.mdreference/plans/README.mdreference/plans/verification-plan.mdreference/skills/README.mdreference/standards/README.mdsrc/lib/api/storageFsAdapter.tssrc/lib/telemetry/telemetryProvider.tsx
|
🚅 Deployed to the livemaid-pr-113 environment in livemaid
|
Summary by CodeRabbit
New Features
Bug Fixes
Documentation
Chores