chore: prepare repository for open-source release #1

Merged
kroshtan merged 3 commits from chore/open-source-cleanup into main 2026-09-26 20:57:54 +00:00
kroshtan commented 2026-09-26 20:48:45 +00:00 (Migrated from github.com)

Cleans up the prototype for publication as a portfolio project.

Security

  • Paddle webhook fails closed without a secret, rejects stale signatures, and can't modify admin/blocked accounts or be downgraded via a stale subscription
  • SSRF-safe fetching for EXIF images and review pages (private/link-local addresses blocked, redirects re-validated, size capped)
  • Timing-safe login, bcrypt off the event loop, 72-byte password limit enforced (was a 500)
  • Internal exception details no longer returned to clients

Cleanup

  • Removed the Reddit skill and praw
  • One configurable LLM client instead of 12 hard-coded instances
  • Package installable, httpx moved to runtime deps, strict mypy clean (28 → 0 errors)
  • Removed template leftovers and the release/deploy workflows

Tooling & docs

  • 64 unit + Postgres-backed integration tests (80% coverage); none call an LLM
  • CI: pre-commit lint, tests with a Postgres service, Docker build
  • Non-root Docker image, compose with Postgres, .env.example
  • README rewrite, MIT license

🤖 Generated with Claude Code

Cleans up the prototype for publication as a portfolio project. ## Security - Paddle webhook fails closed without a secret, rejects stale signatures, and can't modify admin/blocked accounts or be downgraded via a stale subscription - SSRF-safe fetching for EXIF images and review pages (private/link-local addresses blocked, redirects re-validated, size capped) - Timing-safe login, bcrypt off the event loop, 72-byte password limit enforced (was a 500) - Internal exception details no longer returned to clients ## Cleanup - Removed the Reddit skill and `praw` - One configurable LLM client instead of 12 hard-coded instances - Package installable, `httpx` moved to runtime deps, strict mypy clean (28 → 0 errors) - Removed template leftovers and the release/deploy workflows ## Tooling & docs - 64 unit + Postgres-backed integration tests (80% coverage); none call an LLM - CI: pre-commit lint, tests with a Postgres service, Docker build - Non-root Docker image, compose with Postgres, `.env.example` - README rewrite, MIT license 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.
No description provided.