mirror of
https://github.com/pbakaus/impeccable.git
synced 2026-09-11 21:57:14 +03:00
* refactor(content): merge content/site/ into site/content/ Phase 1 step 1 of the directory restructure. The dual content tree was called out in CLAUDE.md as cleanup; both trees were already in sync except for anti-patterns-catalog.js, which moves to site/data/. - Delete content/site/skills/ and content/site/tutorials/ (duplicates of site/content/, which is what Astro's content collection actually reads). - Move content/site/anti-patterns-catalog.js -> site/data/. - Update scripts/lib/sub-pages-data.js and scripts/build.js to read from site/content/ and site/data/. - Drop content/site/ from validateProse target list (site/content was already there). - Rewrite the "Two content trees" section in CLAUDE.md as a single-tree pointer; update stale dev-server text mentioning the deleted server/index.js. Tests: 186/186 pass. Skills build: clean. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * refactor(skill): rename source/skills/impeccable/ -> skill/ Phase 1 step 2 of the directory restructure. The path was redundantly nested ("source/" wrapper plus "skills/impeccable/" — singular content hidden behind the plural). Collapses to flat skill/SKILL.md + skill/reference/ + skill/scripts/. - Move source/skills/impeccable/ -> skill/. - Rewrite scripts/lib/utils.js readSourceFiles(): drop the multi-skill iteration (CLAUDE.md commits to a single user-invocable skill); read skill/SKILL.md directly. - Update scripts/build.js, scripts/generate-og-image.js, and the sub-pages data layer to point at skill/. - Update tests/lib/utils.test.js: drop the "multi-skill" and "dir-name fallback" cases, update single-skill paths to skill/. - Update tests/build.test.js similarly: drop "multiple skills" integration test, update paths. - Update non-glob path joins in tests/framework-fixtures.test.mjs, tests/live-e2e/session.mjs, tests/live-e2e/agents/llm-agent.mjs, tools/live-loop.mjs. - Update prose/text references in CLAUDE.md, AGENTS.md, DEVELOP.md, README.md, scripts/lib/sub-pages-data.js, bin/commands/skills.mjs, site/data/anti-patterns-catalog.js, site/pages/docs/[...slug].astro, docs/adr-live-variant-mode.md, docs/plans/. Eval framework note: the separate impeccable-evals repo reads ../impeccable/source/skills/impeccable/ and needs a coordinated rename to ../impeccable/skill/. Tests: 186/186 pass. Skills build: clean. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * refactor: rename docs/ -> notes/ Phase 1 step 3 of the directory restructure. The internal docs/ dir (ADRs and plans) clashed with the site's /docs route. Renaming it "notes/" makes the difference unambiguous: notes/ is project-internal process, /docs is the user-facing route under site/pages/docs/. No code references the dir; the rename is a clean git mv. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * refactor(site): move public/ under site/public/ Phase 2 step 4 of the directory restructure. Public assets and the Astro publicDir now live alongside the rest of the site, so site/ is fully self-contained for static content. - git mv public site/public. - astro.config.mjs: add publicDir: './site/public'. Astro defaults to ./public at the project root, so the override is required. - scripts/build.js: write generated _data, _headers, _redirects, _routes.json, and js/detect-antipatterns-browser.js into site/public/. Also delete the dead _REMOVED() Bun static-site builder (replaced by Astro at #130; the placeholder no longer earns its keep). - scripts/build.js validateProse: replace the stale public/index.html reference (deleted at the Astro migration) with site/pages/index.astro in the count-validation file list, restoring homepage drift detection. - scripts/generate-og-image.js: write OG image into site/public/. - scripts/screenshot-antipatterns.js: read examples from + write screenshots to site/public/antipattern-{examples,images}/. - scripts/lib/sub-pages-data.js: load command demos from site/public/js/demos/commands. - .gitignore: rename the public/* generator-output entries to site/public/*. - CLAUDE.md: refresh CSS/data-file paths (still pointing at the old pre-Astro public/css/ + public/js/ tree), point the changelog and command-add checklists at site/pages/index.astro and site/scripts/data.js + site/scripts/components/framework-viz.js. Cloudflare Pages note: functions/ stays at the repo root because CF Pages auto-discovers it there with no configuration knob to relocate. Moving it under site/ would either break deployment or require a build-time copy step that adds more complexity than the cleanup is worth. Tests: 186/186 pass. Skills + site build clean. _headers, _redirects, _routes.json, _data/ all land in build/ correctly. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * refactor(cli): consolidate bin/ + src/ + lib/ under cli/ Phase 2 step 5 of the directory restructure. The CLI surface was split across three top-level dirs whose names were easy to mistake for each other (especially src/ vs source/ pre-step-2). Consolidates under cli/. - git mv bin -> cli/bin (CLI entry + skills sub-command) - git mv src -> cli/engine (detect-antipatterns engine + browser variant) - git mv lib -> cli/lib (download-providers helper) Update package.json: - bin.impeccable: cli/bin/cli.js - main + exports: cli/engine/detect-antipatterns.mjs and the ./browser variant - files: ["cli/", "LICENSE"] Update internal references: - cli/bin/cli.js: dynamic import points at ../engine/, package.json read goes one level deeper (../../package.json). - functions/api/download/[type]/[provider]/[id].js + bundle/[provider].js: cli/lib/download-providers.js path. - scripts/build.js, scripts/build-browser-detector.js, scripts/build-extension.js: cli/engine path constants. - scripts/lib/sub-pages-data.js, scripts/lib/utils.js, skill/scripts/ live-server.mjs: comment refs. - tests/detect-antipatterns{,-browser,-fixtures}.test.{js,mjs}, tests/windows-path-fix.test.js: import + read paths. - AGENTS.md, CLAUDE.md: doc paths. Verified: - npx node cli/bin/cli.js --version, --help, detect --help all work. - bun run build, bun run build:browser, bun run build:extension all clean. Browser detector lands at cli/engine/detect-antipatterns-browser.js; extension/detector/detect.js still emits to the same location. - bun run test: 186/186 pass. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: update browser-detector paths missed in cli/ rename Bugbot caught two runtime path leaks where the comment got renamed to cli/engine/ but the actual code still used the old src/ segment. - skill/scripts/live-server.mjs: detectPaths array now joins cli, engine, detect-antipatterns-browser.js for both the repo-relative lookup (4 dirs up from .claude/skills/impeccable/scripts/ to repo root) and the npm node_modules fallback. Without this fix, the detection overlay would silently not load during live-server sessions. - scripts/build.js: the post-build copy of the browser detector into site/public/js/ was reading from src/. The if (fs.existsSync(...)) guard meant the copy was silently skipping, so antipattern-examples pages would 404 on /js/detect-antipatterns-browser.js once the site was deployed. Tests: 186/186 pass. Build clean. site/public/js/detect-antipatterns-browser.js re-emits as expected. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix: cleanup-deprecated import path missed an extra .. in cli/ rename Bugbot caught three call sites in cli/bin/commands/skills.mjs that import '../../skill/scripts/cleanup-deprecated.mjs'. Pre-rename, that was correct from bin/commands/ (one parent to bin/, one to repo root). After moving the file from bin/commands/ to cli/bin/commands/, the path is one directory deeper, so it needs three .. segments to reach the repo root. Without the fix, every cleanup invocation throws on import and gets swallowed by the surrounding try/catch — silent skip. cli/bin/cli.js's package.json read already uses '../../package.json' (the same depth pattern), confirming three levels is correct. Verified: dynamic import resolves and exports the expected functions. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore: sweep stale path/file references missed in the restructure Same root cause as the two bugbot finds: some references in moved or related files weren't tracked because they didn't match a simple sed pattern. Caught the rest by walking each moved dir's depth and each Astro-migration deletion. Stale path references (post-Astro migration, missed earlier): - CLAUDE.md: legacy URL redirects "live in server/index.js" -> point at the actual sources (scripts/build.js generateCFConfig + site/public/_redirects). - AGENTS.md: counts.js path (public/ -> site/public/), changelog file (public/index.html -> site/pages/index.astro), screenshots note (public/ -> site/), source-of-truth dirs (source/, src/ -> skill/, cli/). - tests/detect-antipatterns-browser.test.mjs: comment about routes "in server/index.js". - skill/reference/live.md: workflow.css example for "this repo" was pre-Astro (public/css/) -> site/styles/. (User-project Vite/Next example unchanged.) Stale path that pointed at moved files: - tests/skills-cli.test.js: CLI path was '..', 'bin', 'cli.js'; now '..', 'cli', 'bin', 'cli.js'. Test isn't wired into bun run test but it would have failed if invoked. Dead files (orphaned by Astro migration, never cleaned up): - tests/server/download-validation.test.js: imported from ../../server/lib/{validation,api-handlers}.js which were deleted inb8f09c8. Test was a silent failure waiting to happen. - scripts/lib/render-markdown.js: 156-line module with zero consumers (the only caller, scripts/lib/render-page.js, was deleted in the Astro cleanup). - scripts/build.js: dead commented-out generateSubPages import. Tests: 186/186 pass. Build clean. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(build): remove invalid Corepack packageManager spec Cloudflare Pages rejects the build with `Unsupported package manager specification (bun@1.3.11)`. The packageManager field follows Corepack's syntax which only validates npm/pnpm/yarn — `bun@X.Y.Z` parses as a malformed Corepack directive even though Bun itself treats it as a hint. Pre-existing on main sinced874af0(CF Pages deploy on main also failing); just surfaces here because the PR triggers a fresh deploy. CF Pages auto-detects Bun anyway (the build log confirms: "Detected the following tools from environment: bun@1.3.11, pnpm@10.11.1, nodejs@22.16.0"). Removing the field unblocks the deploy without changing local dev behavior. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Paul Bakaus <paulbakaus@pauls-mbp-3.lan> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
199 lines
6.6 KiB
JavaScript
199 lines
6.6 KiB
JavaScript
/**
|
|
* Scan a project tree for Content-Security-Policy signals and classify the
|
|
* shape so the agent knows which patch template to propose.
|
|
*
|
|
* Used at first-time `live.mjs` setup. Mechanical (grep-based) — no network,
|
|
* no dev server, no JS evaluation. The classification drives a user-facing
|
|
* consent prompt; the agent does the actual patch writing.
|
|
*
|
|
* Shapes are named by patch mechanism, not framework origin:
|
|
* - "append-arrays": CSP defined as structured directive arrays. Patch
|
|
* appends a dev-only localhost entry. Covers:
|
|
* - Monorepo helpers with additional*Src options
|
|
* (e.g. createBaseNextConfig for Next)
|
|
* - SvelteKit kit.csp.directives
|
|
* - nuxt-security module's contentSecurityPolicy
|
|
* - "append-string": CSP built as a literal value string. Patch splices
|
|
* a dev-only token into script-src and connect-src.
|
|
* Covers:
|
|
* - Inline Next.js headers() with CSP string
|
|
* - Nuxt routeRules / nitro.routeRules CSP headers
|
|
* - "middleware": CSP set dynamically in middleware.{ts,js}.
|
|
* Detected but not auto-patched in v1.
|
|
* - "meta-tag": <meta http-equiv="Content-Security-Policy"> in
|
|
* layout files. Detected but not auto-patched in v1.
|
|
* - null: no CSP signals found; no patch needed.
|
|
*/
|
|
|
|
import fs from 'node:fs';
|
|
import path from 'node:path';
|
|
|
|
const SKIP_DIRS = new Set([
|
|
'node_modules',
|
|
'.git',
|
|
'.next',
|
|
'.turbo',
|
|
'.svelte-kit',
|
|
'.nuxt',
|
|
'.astro',
|
|
'dist',
|
|
'build',
|
|
'out',
|
|
'.vercel',
|
|
]);
|
|
|
|
const SCAN_EXTS = new Set(['.js', '.mjs', '.cjs', '.ts', '.mts', '.cts', '.tsx', '.jsx']);
|
|
const LAYOUT_EXTS = new Set(['.tsx', '.jsx', '.astro', '.vue', '.svelte', '.html']);
|
|
const MAX_DEPTH = 6;
|
|
const MAX_READ_BYTES = 64 * 1024;
|
|
|
|
// append-arrays signals: CSP expressed as structured directive arrays
|
|
const MONOREPO_HELPER_SIGNALS = [
|
|
/\bbuildCSPConfig\b/,
|
|
/\bbuildSecurityHeaders\b/,
|
|
/\badditionalScriptSrc\b/,
|
|
/\badditionalConnectSrc\b/,
|
|
/\bcreateBaseNextConfig\b/,
|
|
];
|
|
const SVELTEKIT_CSP_SIGNALS = [
|
|
/\bkit\s*:/,
|
|
/\bcsp\s*:/,
|
|
/\bdirectives\s*:/,
|
|
];
|
|
const NUXT_SECURITY_SIGNALS = [
|
|
/['"]nuxt-security['"]/,
|
|
/\bcontentSecurityPolicy\b/,
|
|
];
|
|
|
|
// append-string signals: CSP written as a literal value string
|
|
const INLINE_HEADER_SIGNALS = [
|
|
/["']Content-Security-Policy["']/i,
|
|
/\bscript-src\b/,
|
|
/\bconnect-src\b/,
|
|
];
|
|
const NUXT_ROUTE_RULES_SIGNALS = [
|
|
/\brouteRules\b/,
|
|
/Content-Security-Policy/i,
|
|
/\bscript-src\b/,
|
|
];
|
|
|
|
const MIDDLEWARE_HINT = /headers\.set\(\s*["']Content-Security-Policy["']/i;
|
|
const META_TAG_HINT = /http-equiv\s*=\s*["']Content-Security-Policy["']/i;
|
|
|
|
/**
|
|
* @param {string} cwd Project root.
|
|
* @returns {{ shape: string|null, signals: string[] }}
|
|
*/
|
|
export function detectCsp(cwd = process.cwd()) {
|
|
const hits = { appendArrays: [], appendString: [], middleware: [], metaTag: [] };
|
|
|
|
walk(cwd, cwd, 0, (absPath, relPath, body) => {
|
|
const ext = path.extname(absPath);
|
|
const base = path.basename(absPath).toLowerCase();
|
|
const isConfig = (name) =>
|
|
new RegExp('(^|/)' + name + '\\.config\\.').test(relPath);
|
|
|
|
// === append-arrays candidates ===
|
|
|
|
// Monorepo CSP helper: packages/*/src/.../(config|security)/*
|
|
if (SCAN_EXTS.has(ext) &&
|
|
/packages\/[^/]+\/src\/.*(config|next-config|security)/.test(relPath) &&
|
|
MONOREPO_HELPER_SIGNALS.some((re) => re.test(body))) {
|
|
hits.appendArrays.push(relPath);
|
|
return;
|
|
}
|
|
|
|
// SvelteKit kit.csp.directives
|
|
if (SCAN_EXTS.has(ext) && isConfig('svelte') &&
|
|
SVELTEKIT_CSP_SIGNALS.every((re) => re.test(body))) {
|
|
hits.appendArrays.push(relPath);
|
|
return;
|
|
}
|
|
|
|
// Nuxt nuxt-security module
|
|
if (SCAN_EXTS.has(ext) && isConfig('nuxt') &&
|
|
NUXT_SECURITY_SIGNALS.every((re) => re.test(body))) {
|
|
hits.appendArrays.push(relPath);
|
|
return;
|
|
}
|
|
|
|
// === append-string candidates ===
|
|
|
|
// Inline headers in Next/Nuxt/SvelteKit/Astro/Vite config
|
|
if (SCAN_EXTS.has(ext) &&
|
|
/(^|\/)(next|nuxt|vite|astro|svelte)\.config\./.test(relPath) &&
|
|
INLINE_HEADER_SIGNALS.every((re) => re.test(body))) {
|
|
// Nuxt routeRules is a sub-shape of append-string; we already covered
|
|
// nuxt-security above via return, so any remaining Nuxt CSP match here
|
|
// is a route-rules / inline-headers case. Either way, same patch
|
|
// mechanism.
|
|
hits.appendString.push(relPath);
|
|
return;
|
|
}
|
|
|
|
// === detect-only shapes ===
|
|
|
|
if ((base === 'middleware.ts' || base === 'middleware.js' || base === 'middleware.mjs') &&
|
|
MIDDLEWARE_HINT.test(body)) {
|
|
hits.middleware.push(relPath);
|
|
}
|
|
|
|
if (LAYOUT_EXTS.has(ext) && META_TAG_HINT.test(body)) {
|
|
hits.metaTag.push(relPath);
|
|
}
|
|
});
|
|
|
|
// Priority: append-arrays > append-string > middleware > meta-tag.
|
|
// Structured patches are safer than string splices; runtime and HTML
|
|
// injection patches are less reliable and v1 doesn't auto-apply them.
|
|
if (hits.appendArrays.length > 0) {
|
|
return { shape: 'append-arrays', signals: hits.appendArrays };
|
|
}
|
|
if (hits.appendString.length > 0) {
|
|
return { shape: 'append-string', signals: hits.appendString };
|
|
}
|
|
if (hits.middleware.length > 0) {
|
|
return { shape: 'middleware', signals: hits.middleware };
|
|
}
|
|
if (hits.metaTag.length > 0) {
|
|
return { shape: 'meta-tag', signals: hits.metaTag };
|
|
}
|
|
return { shape: null, signals: [] };
|
|
}
|
|
|
|
function walk(root, dir, depth, visit) {
|
|
if (depth > MAX_DEPTH) return;
|
|
let entries;
|
|
try { entries = fs.readdirSync(dir, { withFileTypes: true }); }
|
|
catch { return; }
|
|
|
|
for (const entry of entries) {
|
|
const abs = path.join(dir, entry.name);
|
|
if (entry.isDirectory()) {
|
|
if (SKIP_DIRS.has(entry.name)) continue;
|
|
walk(root, abs, depth + 1, visit);
|
|
continue;
|
|
}
|
|
if (!entry.isFile()) continue;
|
|
const ext = path.extname(entry.name);
|
|
if (!SCAN_EXTS.has(ext) && !LAYOUT_EXTS.has(ext)) continue;
|
|
let body;
|
|
try {
|
|
const fd = fs.openSync(abs, 'r');
|
|
try {
|
|
const buf = Buffer.alloc(MAX_READ_BYTES);
|
|
const n = fs.readSync(fd, buf, 0, MAX_READ_BYTES, 0);
|
|
body = buf.slice(0, n).toString('utf-8');
|
|
} finally { fs.closeSync(fd); }
|
|
} catch { continue; }
|
|
visit(abs, path.relative(root, abs), body);
|
|
}
|
|
}
|
|
|
|
// CLI mode
|
|
const _running = process.argv[1];
|
|
if (_running?.endsWith('detect-csp.mjs') || _running?.endsWith('detect-csp.mjs/')) {
|
|
const result = detectCsp(process.cwd());
|
|
console.log(JSON.stringify(result, null, 2));
|
|
}
|