Skip to content

Blog pipeline: source of truth matches the current app (2.03.5) - #10

Merged
DevBehindYou merged 3 commits into
mainfrom
docs/blog-source-of-truth
Oct 3, 2026
Merged

DevBehindYou merged 3 commits into
mainfrom
docs/blog-source-of-truth

Conversation

@DevBehindYou

Copy link
Copy Markdown
Owner

The blog pipeline's SOURCE-OF-TRUTH.md still described the old app: Supabase, email and password login with OTP, a 20-note allowance, last-write-wins sync and a rolling energy window. Any blog generated from it would repeat those mistakes.

It now lists what 2.03.5 actually ships:

  • Google Drive sync (drive.file), a server that stores metadata only, replay-safe sync and conflict copies.
  • The vault parameters, Google sign-in, fixed-time daily energy and the 30/40/50/100 note tiers.
  • Measured timings, and what is still planned.

STYLE-RULES, the research prompt, the author bio and the engineering category description no longer mention Supabase. The author bio and category text appear on the website's blog.

Build OK, smoke tests 22/22.

🤖 Generated with Claude Code

SOURCE-OF-TRUTH.md described the old app: Supabase, email + password with
OTP, a 20-note allowance, last-write-wins sync and a rolling energy window.
It now lists what 2.03.5 ships:
- Google Drive sync (drive.file), a metadata-only server, replay-safe sync
  and conflict copies.
- The vault parameters, Google sign-in, fixed-time daily energy and the
  30/40/50/100 note tiers.
- Measured timings, and what is planned.
STYLE-RULES, the research prompt, the author bio and the engineering category
no longer mention Supabase.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
atomic-notes-community Ready Ready Preview Oct 3, 2026 2:24pm UTC

DevBehindYou and others added 2 commits October 3, 2026 19:53
CI's "npm audit --audit-level=high" failed on every branch after GitHub
published GHSA-vfj7-8cjw-p6xm (braces <= 3.0.3, no patched release). braces
only came in through tailwindcss 3 (chokidar, micromatch, fast-glob). Tailwind 4
doesn't use it, so the high-severity audit stays strict and now reports 0
vulnerabilities.

- tailwindcss 4.3.3 + @tailwindcss/postcss. autoprefixer is gone (v4 does
  prefixing itself).
- globals.css: @import "tailwindcss" and @config for the existing JS theme.
- Controller inputs: outline-none is outline-hidden in v4 (same look).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
A cookie signed a moment ago could be rejected as "from the future" when the
verifying process or instance read a clock a few milliseconds behind the
signing one (age < 0). The smoke test failed this way about one run in five
on Windows, and Vercel instances can hit the same edge right after sign-in.
Timestamps are HMAC-signed, so allowing 60 s of skew lets nobody forge
anything. A 5-minute future cookie is still rejected, and the test now also
checks that 2 s of skew is accepted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@DevBehindYou
DevBehindYou merged commit 393997c into main Oct 3, 2026
3 checks passed

This branch was successfully deployed

1 active deployment
Preview — 4cbba064 Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant