Repository navigation
Promote dev to main (upstream v2.25.0 + CI fixes) #68
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Changes from all commits
Commits
Show all changes
92 commits
Select commit
Hold shift + click to select a range
178619d
fix(integrations): send a single notification when a token refresh fails
giladresisi 2e80793
feat(instagram): use custom thumbnail as reel cover via cover_url
giladresisi 4f469c7
fix(providers): wire the LinkedIn and Moltbook settings DTOs
giladresisi e5f6fff
feat(mcp): accept { path, thumbnail } attachments for video covers
giladresisi 78515f7
fix(uploads): honor HTTP Range requests so local-storage video uploadβ¦
giladresisi c38f8ed
chore(deps): pin the Sentry SDK to 10.56.0 to pick up the span/scope β¦
giladresisi c0bd447
fix(frontend): report React render crashes to Sentry from the crash sβ¦
giladresisi d727ac0
fix(frontend): keep the 402 response readable after the payment dialog
giladresisi 971aa36
fix(frontend): tolerate a non-JSON 402 body in the payment dialog
giladresisi 4b933cd
feat(facebook): optional title for feed video posts
giladresisi cd48401
feat: canva intent
nevo-david c17f0c2
Merge remote-tracking branch 'origin/main'
nevo-david 7229c33
feat: schema fix
nevo-david 1752382
feat: force token 200
nevo-david c033aff
fix(frontend): stay on Add Channel when the 402 dialog is cancelled
giladresisi b7e3df3
fix(frontend): stop the web3, custom-fields and extension connect floβ¦
giladresisi f67d2fd
Merge branch 'main' into fix/after-request-402-body-read-main
giladresisi 73a0dea
Merge pull request #2159 from gitroomhq/fix/after-request-402-body-reβ¦
giladresisi 9dbebc2
fix(frontend): don't report a failed post save as successful
giladresisi cab42b1
fix(frontend): stop the Sentry report dialog on the Chrome wording ofβ¦
giladresisi f0f23f4
Merge pull request #2161 from gitroomhq/fix/post-save-no-success-on-eβ¦
giladresisi aaa4343
Merge branch 'main' into fix/sentry-ignore-uppy-progress-chrome
giladresisi 6562791
fix(uploads): clamp an over-long Range end instead of answering 416
giladresisi 2318153
Merge pull request #2095 from gitroomhq/fix/local-uploads-range-main
giladresisi 935e069
Merge pull request #2162 from gitroomhq/fix/sentry-ignore-uppy-progreβ¦
giladresisi 29478ed
fix(media): keep the rest of the upload batch when one file fails
giladresisi 3b36d5e
chore(i18n): translate the partial upload failure toast
giladresisi 4db23eb
Merge pull request #2163 from gitroomhq/fix/uploader-keep-batch-on-fiβ¦
giladresisi a4314ea
fix(frontend): remove duplicate 'use client' directive in VK provider
giladresisi 528f6ea
Merge pull request #2164 from gitroomhq/fix/vk-duplicate-use-client
giladresisi 3f21703
fix(telegram): stop logging the post text on publish
giladresisi d934731
fix(facebook): retry the temporary posting-rate block (368 / 1390008)β¦
giladresisi 480ee7e
fix(editor): stop wiping in-flight uploads when an earlier upload finβ¦
giladresisi 852acde
Merge pull request #2171 from gitroomhq/fix/editor-uploader-keep-inflβ¦
giladresisi b0103f7
fix(wordpress): send a Postiz User-Agent on requests to the WordPressβ¦
giladresisi 371d8ec
Merge pull request #2172 from gitroomhq/fix/wordpress-user-agent
giladresisi 7abbdde
Merge pull request #2155 from gitroomhq/feat/facebook-video-title
giladresisi 881ac76
fix(tiktok): send video_cover_timestamp_ms on Direct Post video init
giladresisi 148cc96
fix(tiktok): send a 0ms cover timestamp explicitly
giladresisi 716544f
Merge branch 'main' into feat/ig-reel-cover-image
giladresisi 72d6015
Merge pull request #2174 from gitroomhq/feat/tiktok-video-cover-main
giladresisi 3205ce1
Revert "feat(mcp): accept { path, thumbnail } attachments for video cβ¦
giladresisi d739d08
Merge pull request #2102 from gitroomhq/fix/global-error-sentry-report
giladresisi 502a6f8
Merge remote-tracking branch 'origin/main' into fix/wire-settings-dtos
giladresisi 8e09aeb
fix(moltbook): keep submolt optional in the settings DTO
giladresisi 5f2f39d
Merge branch 'main' into fix/wire-settings-dtos
giladresisi 235e7da
Merge pull request #2166 from gitroomhq/fix/telegram-drop-post-text-lβ¦
giladresisi 3cccf2f
Merge pull request #2167 from gitroomhq/fix/facebook-368-rate-limit-rβ¦
giladresisi de396df
Merge pull request #1880 from gitroomhq/fix/wire-settings-dtos
giladresisi b2220ae
Merge pull request #1855 from gitroomhq/feat/ig-reel-cover-image
giladresisi 2e1b6eb
feat(sponsors): add rapidproxy to readme
egelhaus 2ebd93e
fix(frontend): close the edit modal instead of crashing when the postβ¦
giladresisi 22f266a
fix(media): fail the upload step when the backend returns an error
giladresisi 6eceb7e
Merge pull request #2177 from gitroomhq/fix/uploader-failed-completion
giladresisi 9efa1f5
Merge pull request #2178 from gitroomhq/fix/edit-modal-missing-channel
giladresisi 9c4524e
Merge pull request #2101 from gitroomhq/chore/sentry-sdk-10.56.0
nevo-david 2800807
redeploy
nevo-david 34509af
Merge remote-tracking branch 'origin/main'
nevo-david 538f3e6
fix(pinterest): map the "not permitted to access that resource" pin eβ¦
giladresisi 852ac51
feat: more info
nevo-david b5ba8c8
Merge pull request #2179 from gitroomhq/fix/pinterest-not-permitted-mβ¦
giladresisi da7f7a1
fix(tiktok): resolve the public post id for FILE_UPLOAD publish ids iβ¦
giladresisi 3f83306
Merge pull request #2180 from gitroomhq/fix/tiktok-analytics-file-pubβ¦
giladresisi 634c6da
fix(tiktok): keep the full public post id instead of the JSON.parse-rβ¦
giladresisi 33d33d1
Merge pull request #2182 from gitroomhq/fix/tiktok-post-id-precision
giladresisi 80dacd7
feat(groups): rename a channel group from the channel menu
giladresisi c43916d
fix(groups): settle the rename promise when the modal is dismissed
giladresisi 9cc6bf2
Merge branch 'main' into feat/edit-group-name-main
giladresisi 496c380
Merge pull request #2183 from gitroomhq/feat/edit-group-name-main
giladresisi ff561b2
Merge pull request #1678 from gitroomhq/fix/duplicate-refresh-error-eβ¦
giladresisi cc0fdf9
docs(claude): add shared-query and persisted-data change rules
giladresisi 2a46d88
Merge pull request #2184 from gitroomhq/chore/claude-md-shared-data-rβ¦
giladresisi bcbc119
fix(tiktok): resolve and persist the public post id for analytics
giladresisi 4637a51
fix(tiktok): resolve photo publish ids too
giladresisi 2407718
docs(claude): add a rule on credentials and sensitive fields in respoβ¦
giladresisi e0a08a7
Merge pull request #2191 from gitroomhq/docs/claude-md-no-credential-β¦
giladresisi b6ead58
fix(media): bound media reads that stall after their headers
giladresisi a2794ab
fix(media): read media through the SSRF-safe axios client
giladresisi 9fedac4
feat: responsive
nevo-david 9554e9f
fix(media): fail a stalled media read instead of repeating the publish
giladresisi f5564d9
fix(media): give a media read two minutes before calling it stalled
giladresisi 11d24f3
Merge pull request #2193 from gitroomhq/fix/media-read-timeout
giladresisi ca07a51
refactor(posts): extract release resolution into resolveRelease
giladresisi 9c697e7
Merge branch 'main' into fix/tiktok-persist-post-id-main
giladresisi 56f42d0
Merge pull request #2186 from gitroomhq/fix/tiktok-persist-post-id-main
giladresisi 876ab9e
feat: self hosting connector
nevo-david 8e42f09
Merge remote-tracking branch 'origin/main'
nevo-david 28e23d9
merge: upstream main / v2.25.0 (374fb202..8e42f09c, 87 commits)
JOY d1e4960
fix(sync): brand the self-hosted relay MCP servers as Crove MCP
JOY 1a302e3
Merge pull request #67 from DOS/upstream-sync-v2.25.0
JOY 436dde4
test(bootstrap): forceExit so the suite terminates in CI
JOY 3bedee5
fix(sync): split the self-hosted authorize endpoint out of OAuthContrβ¦
JOY File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
68 changes: 68 additions & 0 deletions
68
apps/backend/src/api/routes/oauth.selfhosted.controller.ts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,68 @@ | ||
| import { Body, Controller, Post, UseGuards } from '@nestjs/common'; | ||
| import { ApiTags } from '@nestjs/swagger'; | ||
| import { Throttle } from '@nestjs/throttler'; | ||
| import { OAuthService } from '@gitroom/nestjs-libraries/database/prisma/oauth/oauth.service'; | ||
| import { AuthorizeSelfHostedDto } from '@gitroom/nestjs-libraries/dtos/oauth/authorize-oauth.dto'; | ||
| import { McpRelayService } from '@gitroom/nestjs-libraries/chat/mcp.relay.service'; | ||
| import { ThrottlerRealIpGuard } from '@gitroom/nestjs-libraries/throttler/throttler.provider'; | ||
|
|
||
| // Split out of OAuthController so the bootstrap/consent test suite (which | ||
| // imports OAuthAuthorizedController) does not pull McpRelayService - and | ||
| // through it @mastra/core and ESM-only dependencies - into its module graph. | ||
| @ApiTags('OAuth') | ||
| @Controller('/oauth') | ||
| export class OAuthSelfHostedController { | ||
| constructor( | ||
| private _oauthService: OAuthService, | ||
| private _mcpRelayService: McpRelayService | ||
| ) {} | ||
|
|
||
| // Public (the person may have no account here) and capped per client, | ||
| // since every attempt sends requests to the instance | ||
| @UseGuards(ThrottlerRealIpGuard) | ||
| @Throttle({ default: { limit: 30, ttl: 3600000 } }) | ||
| @Post('/authorize/self-hosted') | ||
| async authorizeSelfHosted(@Body() body: AuthorizeSelfHostedDto) { | ||
| const app = await this._oauthService.validateAuthorizationRequest( | ||
| body.client_id, | ||
| { | ||
| redirectUri: body.redirect_uri, | ||
| codeChallenge: body.code_challenge, | ||
| codeChallengeMethod: body.code_challenge_method, | ||
| } | ||
| ); | ||
|
|
||
| const email = body.email?.trim(); | ||
| this._oauthService.validateSelfHostedRequest(app, { | ||
| resource: body.resource, | ||
| email, | ||
| }); | ||
|
|
||
| const instance = await this._mcpRelayService.connect( | ||
| body.instance_url, | ||
| body.api_key | ||
| ); | ||
|
|
||
| const code = await this._oauthService.createSelfHostedAuthorizationCode( | ||
| app.id, | ||
| { ...instance, email }, | ||
| app.dynamic | ||
| ? { | ||
| codeChallenge: body.code_challenge, | ||
| codeChallengeMethod: body.code_challenge_method, | ||
| redirectUri: body.redirect_uri, | ||
| } | ||
| : undefined | ||
| ); | ||
|
|
||
| // Same redirect as an approved cloud authorization | ||
| const redirectUrl = new URL( | ||
| app.dynamic ? body.redirect_uri! : app.redirectUrl | ||
| ); | ||
| redirectUrl.searchParams.set('code', code); | ||
| if (body.state) { | ||
| redirectUrl.searchParams.set('state', body.state); | ||
| } | ||
| return { redirect: redirectUrl.toString() }; | ||
| } | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,9 @@ | ||
| <!-- BEGIN:nextjs-agent-rules --> | ||
|
|
||
| # This is NOT the Next.js you know | ||
|
|
||
| This version has breaking changes β APIs, conventions, and file structure may all differ from your training data. Read the relevant guide in `node_modules/next/dist/docs/` (resolved from this file's directory; in monorepos the `next` package may not be visible from the repo root) before writing any code. Heed deprecation notices. | ||
|
|
||
| This block is written and re-added by `next dev` β verify at `node_modules/next/dist/server/lib/generate-agent-files.js`. Removing it from a diff only re-creates the uncommitted change; committing it with your work keeps the tree clean. | ||
|
|
||
| <!-- END:nextjs-agent-rules --> |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1 @@ | ||
| @AGENTS.md |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The
_usersServiceis used here to fetch the personal user details, butUsersServiceis not imported or injected in the constructor ofPublicIntegrationsController. This will cause a runtimeTypeErrorwhen calling the/meendpoint.