Skip to content

fix: restore anonymous production setup-status for psychiatry.tools - #277

Merged
BigSimmo merged 1 commit into
mainfrom
cursor/hotfix-setup-status-c40b
Jul 5, 2026
Merged

fix: restore anonymous production setup-status for psychiatry.tools#277
BigSimmo merged 1 commit into
mainfrom
cursor/hotfix-setup-status-c40b

Conversation

@BigSimmo

Copy link
Copy Markdown
Owner

Summary

Minimal production hotfix for the API unavailable error on psychiatry.tools for anonymous/mobile visitors.

/api/setup-status was returning 401 in production, which made the dashboard treat the API as down and show the blocking service-unavailable banner.

Change

  • Allow anonymous access to /api/setup-status (response contains only non-secret setup posture)
  • Update route test accordingly

Verification

  • npm run typecheck — pass on this branch
  • npm run test -- tests/setup-status-route.test.ts — pass

Deploy

Merge to main triggers production rollout to psychiatry.tools.

Open in WebOpen in Cursor

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@supabase

supabaseBot commented Jul 5, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project sjrfecxgysukkwxsowpy because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@BigSimmo
BigSimmo merged commit 2bad3a3 into mainJul 5, 2026
5 checks passed
@BigSimmo
BigSimmo deleted the cursor/hotfix-setup-status-c40b branch July 8, 2026 16:25
cursorBot pushed a commit that referenced this pull request Aug 8, 2026
Address Codex P2 review on PR #1725: the lock-parity completeness check must
fail closed on missing non-entry package files, and the stale design-system
handover must be bannered or archived rather than deleted.
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
cursorBot pushed a commit that referenced this pull request Aug 8, 2026
Prefer main's outstanding-issues shared queue (#277 / next-id=278 from
#1725), then re-apply this PR's #276 archive and corrected #118 Lighthouse
diagnosis.
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
BigSimmo added a commit that referenced this pull request Aug 8, 2026
* docs(design-system): stamp the 7 August handover superseded
Nine open ledger rows (#261, #262, #264-#270) cite
docs/design-system/HANDOVER-2026-08-07.md as their Source, and
docs/design-system/README.md sent anyone picking the work up cold straight to it as
"measured state, the ordered plan". Four of its figures have since been disproved,
and the corrections were written into the ledger rows rather than the document, so
the document still asserts the originals. A session scoping from it re-derives work
that is already known wrong. Recorded as #277.
A banner rather than a rewrite, which is what #277 asks for: the corrections already
live in the rows, and duplicating them re-creates the drift this fixes. The banner
names the four measured errors -- the "229 --shadow-tight aliases" that is really a
seven-token total mislabelled as one token (100 sites across 55 files, 228 total),
the 24-vs-23 unadopted count, the "baselines cannot be generated on Windows"
conclusion that overlooked the ubuntu CI job now used under #118, and #270's 22-site
premise that has zero same-variant pairs -- then points at the rows.
The README now sends a cold start to docs/outstanding-issues.md and marks the
handover superseded in the link text itself, where the misdirection was.
Deliberately not done: the document is not deleted, moved, or corrected in place.
The nine Source citations, the PR and commit record, and its verification and gotcha
sections are provenance the ledger is meant to preserve, and silently correcting it
would leave those rows citing a document that no longer says what they were derived
from.
Verified: npm run docs:check-links -- "docs link check passed: 1667 repo path
references resolve"; npm run docs:check-inventory -- current; npm run format:check --
"All matched files use Prettier code style!".
Refs #277
* docs(design-system): drop false #118 baseline-adoption claim
The superseded banner said all six visual baselines were adopted under
#118, but the ledger still has #118 open and tests/__screenshots__/
holds only README.md. Keep the accurate Ubuntu-CI generation point
without implying visual-regression protection exists yet.
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
BigSimmo added a commit that referenced this pull request Aug 9, 2026
…1770)
* feat(design-system): gate the ungated prohibitions and close gate 4
Closes#264 and the gate-4 half of #265. Measured against origin/main
8db1e53 rather than scoped from the handover, which mattered: four of
#264's six prohibitions were already gated while GATES.md §3 read
`planned`, and that understatement is what deferred this task twice.
Tighten two ratchets carrying stale slack to their measured values:
edgeOwnershipConflicts 28 -> 27 and legacyShadowAliases 231 -> 224. Seven
files had paid debt down without a baseline refresh, so up to seven new
violations would have passed. Every other metric and debtByPath entry was
asserted unchanged first. The remaining 224 aliases are #262's cleanup.
Add three checks to check:design-system-contract:
- statusColouredNumerals (ratcheted 2) — a text-* status hue on an element
whose children are all figures.
- colourOnlyStatusIndicators (ratcheted 4) — gate 4's repository-wide
enumeration. A status hue on a box with no children, no accessible name
on it or any ancestor, no sibling text, and not a StatusMark. Also flags
shared swatch recipes, since the analyzer is per-file and cannot follow
an imported statusDotReady to its call sites.
- imageInversions (pinned at zero) — CSS filter/backdrop-filter and the
Tailwind invert/hue-rotate utilities.
All three are mutation-verified, as is the tightening: reintroducing one
var(--shadow-tight) now fails with `legacyShadowAliases increased from 224
to 225` plus the per-path assertion, where the same edit passed at 231.
The two status metrics were re-measured three times before the baseline was
written. The first draft found 19 colour-only indicators and 3 numerals; 15
were false positives — a name test loose enough that `size` read as a
numeral, an ancestor walk checking for JsxOpeningElement when ancestors are
JsxElement, and no sibling-text rule, which condemned the ordinary legend
pattern. All six recorded entries were read in source and confirmed real.
Gate 2 is NOT closed. A rendered-interactive tap enumeration was written,
shown to find genuine defects, and reverted: six runs against one
production build returned 6, 5, 4, 3, 3 and 9 distinct sub-floor shapes
because the audit races the async render, and networkidle plus shape
deduplication did not settle it. ui-style-contract.spec.ts runs in the
required Production UI job, so an intermittent version would have blocked
every merge. Recorded with the defect it found as #289.
Correct GATES.md throughout, including the gate 2 row's claim that
test:e2e:style-contract needs wiring into verify:cheap — the spec already
runs in required CI via productionSpecPattern and playwright-pr-shards, and
adding it to verify:cheap:internal would trip check:gate-manifest, which
requires every gate in that chain to also run in the browser-less static-pr
job. Close#277, verified already satisfied on main.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(ledger): record the M2 design-system gates review
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(ledger): supersede the M2 row after renumbering #289 to #291
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* fix: expand NUMERAL_TEXT regex to accept clinical unit suffixes
Co-authored-by: BigSimmo <87357024+BigSimmo@users.noreply.github.com>
* fix(design-system): close seven gaps found in review of the new gates
All seven review findings reproduced against a probe before any change, and
every one was real. Two mattered:
- Neither status pattern accepted Tailwind's `/NN` opacity modifier, and 83
status-token utilities in `src` carry one. The anchored patterns rejected
every one before the semantic checks ran, so a colour-only indicator written
`bg-[color:var(--danger)]/90` walked past a ratchet described as
repository-wide.
- `NUMERAL_TEXT` rejected every letter while its own comment claimed units were
covered, so a dose painted in a status colour — the case the rule exists for
— passed silently. Replaced with `isNumeralTextFragment`, which accepts an
explicit unit list and still rejects prose. It carries no digit requirement,
because `{dose} mg` splits into an expression and a unit-only text child.
Also:
- `isNumeralExpression` now requires an arithmetic operator, rejects any
string/template operand anywhere in the tree, and follows only `+`/`-` prefix
unaries, so `{count + " errors"}` is no longer a numeral. The previous comment
claiming a concatenation "would have a string literal rather than a numeric
one" was wrong: one numeric side was enough.
- `INVERSION_FUNCTION` matches the `invert(`/`hue-rotate(` call itself, covering
`filter-[invert(1)]`, `[filter:invert(1)]` and both `backdrop-` forms.
- `IMAGE_INVERSION_UTILITY` excludes `-0`; `invert-0` disables inversion and a
hard-zero gate must not reject the reset.
- `rendersVisibleText` no longer counts `{null}`, `{false}`, `{undefined}` or a
bare self-closing element as a text channel, and judges markup-building
expressions by that markup.
- `hasNonEmptyAccessibleName` replaces the attribute-presence test, so
`aria-label=""` no longer exempts an indicator.
- The Gate 9 row said a layout-property lint was "planned" while
`layoutTransitionExceptions` already ships and ratchets per path — the exact
contradiction this branch exists to remove.
Fixing these surfaced two false positives of my own, both caught by
re-verifying every baseline entry in source rather than trusting the count: the
sibling walk stopped at the first non-JSX parent, so a conditional badge with a
label was reported colour-only; correcting that then let a sibling
`{started ? <div/> : null}` — another coloured div — count as text.
Baseline unchanged at 4 colour-only / 2 numerals / 0 inversions, and unchanged
by the unit widening, so nothing in the repo paints a dose in a status colour.
`legacyShadowAliases` 224 -> 220 from the main merge. Every new form is
mutation-verified.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(ledger): supersede the M2 row after the review round and main merge
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
cursorBot pushed a commit that referenced this pull request Aug 9, 2026
Keep main's shared #290-#293 queue. Drop duplicate pr-handoff #291 (already #284).
Archive this PR's #279 canvas-gate resolution alongside main's #264/#277 closures.
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@BigSimmo