Repository navigation
Conversation
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
affirm-staging | bab8a1d | Commit Preview URL Branch Preview URL |
Oct 05 2026, 07:33 PM |
- Add 7-day cooldown and reassign dependabot updates to synmux for both the github-actions and npm ecosystems - Replace blanket `read-all` permissions in ci.yaml with a scoped block granting only the needed actions, checks, contents, id-token, issues, pull-requests and security-events scopes - Grant `checks: write` in devskim.yaml and reorder the `on` triggers in both workflows for consistency - Bump trunk linters: oxlint 1.87.0, checkov 3.3.23, trufflehog 3.98.0, oxfmt 0.72.0 - Revert over-eager bumps of @nuxt/scripts, @unhead/vue, daisyui, @types/node, node-gyp, vitest, vue-tsc and wrangler to the previously tested versions - Alphabetise the VS Code extension recommendations - Use `const` for the mutated-but-never-reassigned `message` object in server/api/login.post.ts pnpm-lock.yaml is regenerated to match the adjusted pins.
- Add `reset` npm script that removes pnpm-lock.yaml and node_modules via rimraf, then runs `pnpm install` - Add rimraf ^6.1.3 as a devDependency - Regenerate pnpm-lock.yaml for rimraf and its transitive dependencies
Member
|
typecheck output: |
- Add .github/copilot-instructions.md with a pointer block that routes diagram creation, editing, and visualization requests to the detailed Mermaid instructions - Add .github/instructions/mermaid.instructions.md describing the workflow for generating, validating, and previewing .mmd files - Document required LM tool calls (mermaid-diagram-validator, mermaid-diagram-preview, get-syntax-docs-mermaid) - Catalog VS Code extension commands, Mermaid cloud login/sync commands, the GitHub Sync review flow, and @Mermaid-Chart slash commands - Spell out rules so AI agents validate before showing, preview after generating, warn before spending AI-repair credits, and leave sync-managed diagrams untouched
- Rename `bg-gradient-to-*` classes to `bg-linear-to-*` in the blank layout and the account page, matching Tailwind v4 naming - Add a `userName` computed in `me.vue` that casts `user` safely and falls back to "there", so the welcome heading never renders a blank or undefined name - Polish Copilot docs: add a `# Copilot Instructions` title, drop a stray blank line after the mermaid frontmatter, and widen the slash command table separator so the columns align
synmux
approved these changes
Oct 8, 2026
synmux
left a comment
Member
There was a problem hiding this comment.
Mergeable once typing issues are resolved
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
Authentication behavior, response handling, type safety, accessibility, dependencies, and workflow permissions contain unresolved issues.
11 open findings
Restrict workflow permissions to required access · New Declare dotenv as a direct dependency · New Use a typed safe session-user projection · New Reverse login and protected-route visibility conditions · New Remove or fix the divergent example login route · New Read the computed user value reactively · New Correct the ApiResponse message contract · New Set HTTP 401 status for invalid credentials · New Implement or remove the placeholder user stats endpoint · New Remove ignored duplicate Nuxt configuration · New Avoid nested main landmarks · New
What changed in this PR
Adds session-based login/logout flows, protected account UI, and related repository configuration updates.
Changes:
- Creates authenticated session, profile, logout, and route-guard flows.
- Adds example layout/page and protected user endpoint.
- Updates developer tooling, CI permissions, Dependabot, and Mermaid guidance.
| File | Description |
|---|---|
server/api/user/stats.get.ts |
Adds protected user endpoint. |
server/api/login.post.ts |
Creates sessions after login. |
drizzle.config.ts |
Loads environment variables. |
app/pages/me.vue |
Adds profile/logout page. |
app/pages/login.vue |
Refreshes session and redirects. |
app/pages/login-example.vue |
Adds example login route. |
app/middleware/authenticated.ts |
Protects authenticated routes. |
app/layouts/nuxt.config.ts |
Adds nested Nuxt configuration. |
app/layouts/blank.vue |
Adds blank layout. |
app/components/AppHeader.vue |
Adds session-aware navigation. |
.vscode/extensions.json |
Updates extension recommendations. |
.trunk/trunk.yaml |
Updates tool versions. |
.github/workflows/devskim.yaml |
Changes workflow permissions. |
.github/workflows/ci.yaml |
Changes CI permissions. |
.github/instructions/mermaid.instructions.md |
Adds Mermaid instructions. |
.github/dependabot.yml |
Updates cooldowns and assignees. |
.github/copilot-instructions.md |
References Mermaid guidance. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Comment on lines
+5
to
+12
| permissions: | ||
| actions: read | ||
| checks: write | ||
| contents: read | ||
| id-token: write | ||
| issues: write | ||
| pull-requests: write | ||
| security-events: write |
| @@ -1,4 +1,7 @@ | |||
| import { defineConfig } from "drizzle-kit"; | |||
| import dotenv from "dotenv"; | |||
| }); | ||
| if (check) { | ||
| const message = { ...result }; | ||
| delete message.password; |
| <li> | ||
| <NuxtLink to="/list" class="link link-hover" active-class="menu-active">List</NuxtLink> | ||
| </li> | ||
| <li v-if="loggedIn"> |
Comment on lines
+19
to
+25
| const res = await $fetch("/api/login", { | ||
| method: "POST", | ||
| headers: { "Content-Type": "application/json" }, | ||
| body: { email: email.value, password: password.value }, | ||
| }); | ||
| console.log("Fetch Complete"); | ||
| console.log(res); |
| status: 200, | ||
| error: false, | ||
| message: `${body.email} logged in`, | ||
| message, |
| } | ||
| } | ||
| return { | ||
| status: 401, |
Comment on lines
+6
to
+8
| // TODO: Fetch some stats based on the user | ||
|
|
||
| return { ...user }; |
Comment on lines
+2
to
+3
| export default defineNuxtConfig({ | ||
| modules: ["nuxt-auth-utils"], |
| class="fieldset bg-base-200 border-base-300 border rounded-box w-full p-4 flex flex-col justify-stretch gap-4" | ||
| > | ||
| <legend class="sr-only">Login Page</legend> | ||
| <main class="flex-1 py-12"> |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



No description provided.