Skip to content

Reconcile PointUp overhaul and prepare semantic AWS releases - #55

Merged
jckail merged 13 commits into
masterfrom
codex/pointup-reconciled-release-20261006
Oct 6, 2026
Merged

jckail merged 13 commits into
masterfrom
codex/pointup-reconciled-release-20261006

Conversation

@jckail

@jckail jckail commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

PointUp's recent work is spread across legacy scaffolds, a preserved alternate migration history and nine integration commits beyond master. This change adopts the current TypeScript/Drizzle integration lineage and adds secure release preparation, while preserving the alternate history for recovery.

The dashboard separates its summary from program categories, fits mobile viewports, uses jordan@quarg.io for contact and displays the configured runtime MCP endpoint. Bot callbacks use literal HTTPS authorities and path-only input without redirects. AWS configuration uses scoped Clerk Secrets Manager imports, a public-only build loader and a tested POSIX stdin bridge. Optional Supabase wiring separates application and session migration connections; migration 0023 permits the restricted server role while keeping unrelated API roles denied. Kubernetes remains inactive preparation. Stable version checks and tag-driven source releases reuse full CI and publish exact-commit receipts.

Validation: head 7d5da63 passed all hosted CI jobs in run 37525556115, CodeQL workflow 37525556118 and the separate CodeQL PR security check. Earlier aggregate local verification passed 2,020 workspace tests, lint/types, production bundles, 46 deployment/release contracts, 33 infrastructure contracts and Docker/PgBouncer API/MCP smoke. Additional focused callback tests passed 55; the service-role regression passed. All 24 Drizzle migrations applied under a restricted migrator on PostgreSQL 17.6, with 24 journal rows and 19 scoped policies verified. Chrome verified local demo sync, consent/token revocation and desktop/mobile rendering. The application production lock audit reports zero vulnerabilities; the AWS CDK bundled brace-expansion high finding remains upstream and is explicitly recorded.

AWS activation, genuine production Clerk authentication, database credentials, legacy data migration and tested recovery, semantic tag publication and provider/model acceptance remain open. Supabase project creation and a completed legacy disk snapshot do not prove cutover acceptance. This source integration supersedes #54 and tracks JCK-333, retaining the separate JCK-128/JCK-234 acceptance scopes. The user-requested deep product/documentation overhaul continues separately.


Note

High Risk
Changes span deploy configuration (Clerk/database secret wiring), bot outbound callback security, and broad CI/release gates; mistakes could block deployments or affect authentication and deferred bot replies.

Overview
This PR wires semantic versioning and tag-driven source releases (release.yml, CHANGELOG.md, scripts/release/version.mjs) into CI, broadens deployment script tests, and shifts production Clerk identity from a GitHub secret publishable key to an approved Secrets Manager ARN loaded at deploy time.

The bot is refactored into createBotServer with bounded request bodies and safer error handling; Slack/Discord deferred replies use fixed HTTPS authorities via sendCallback (no redirects, no credential-bearing logs), with large transport and HTTP-boundary test suites.

Web/dashboard changes return structured sync success/failure messages through SyncBalanceForm, validate consent duration 1–90 days on grant, improve agents panel capture timestamps, accessibility, and post-revoke feedback, split dashboard stat layout for mobile, add footer contact, and prefer PUBLIC_MCP_URL for MCP display. The assistant path re-enforces private OpenAI SDK logging on every run.

Supporting updates include inactive Kubernetes manifests and docs, reconciliation/release verification notes, and minor Next env typing.

Reviewed by Cursor Bugbot for commit 7d5da63. Bugbot is set up for automated code reviews on this repo. Configure here.

Comment thread apps/bot/src/slack.ts Fixed
@jckail
jckail marked this pull request as ready for review October 6, 2026 20:24
@jckail
jckail merged commit 62c0f9e into master Oct 6, 2026
8 checks passed

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 7d5da63. Configure here.

const changelog = readFileSync(resolve(cwd, 'CHANGELOG.md'), 'utf8');
const sections = changelog.split(/(?=^## )/m);
const section = sections.find(value => value.startsWith(`## [${version}]`));
assert(section && section.trim().split('\n').length > 2, `CHANGELOG.md needs a substantive [${version}] entry`);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Release notes match version prefixes

Medium Severity

notes() selects a changelog section with startsWith('## [${version}]'), so a later heading such as ## [1.0.10] matches a lookup for 1.0.1. Newest-first changelogs make that the first hit, and the GitHub release can publish the wrong notes.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 7d5da63. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants