Conversation
* feat: upgrade @prose-reader/* to 1.332.0 Bump every @prose-reader/* dependency from 1.324.0 to 1.332.0 across web, api and archive-metadata, and migrate the web reader to the breaking API changes shipped in that range. Reader lifecycle (prose #229/#230/#231): - createReader() now takes the manifest (and optional cfi) at construction and mount(containerElement) is a one-shot DOM attachment; reader.load() is gone. useCreateReader now creates + mounts + destroys the reader in a single effect (destroy() is the true inverse of create + mount, so the effect is strict-mode safe), and useLoadReader is removed. - The restored reading location (cfi) is read through a live ref so later progress writes flowing back into the book query never destroy/recreate the reader. - reader.state$ ("idle"|"ready") is replaced by reader.mounted$; the book loading overlay now keys off !mounted. Pin react/react-dom to 19.1.8 in the web app only: - react-dom 19.2 dev builds recursively read component props and access $$typeof on every object, throwing SecurityError on our gapi cross-origin iframe (react/react#34840). The uncaught throw aborts passive-effect mounts (dead reader quick-menu) and corrupts the work loop (crash on back navigation). Prod is unaffected; dev is unusable. - 19.1.x predates the offending logger and the web app uses no 19.2-only APIs. admin/landing stay on 19.2.x (@Mantine 9.4 needs useEffectEvent), so the pin is web-only, held together by resolve.dedupe in vite.config. - Documented in AGENTS.md with removal steps for when the react bug is fixed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * refactor(reader): read book once via enabled gate instead of useLiveRef The enabled predicate already stops observing after the first result, so progress-sync writes to the same book document never change the value. Drop the redundant useLiveRef, read bookOnce directly, and name the enabled predicate to state the intent. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * chore: unpin apps/web react and bump react to 19.2.7 project-wide apps/web was pinned to react 19.1.8 to dodge a dev-only React 19.2 logger crash with the gapi iframe. The pin diverged web from the rest of the repo and left @types on 19.2.x, creating a runtime/types skew. Align everything to the latest 19.2.7 (react/react-dom) and 19.2.17 (@types/react) across web, admin and landing. Remove the now-unneeded scaffolding: the vite resolve.dedupe entry and the AGENTS.md "React version pin" section. The dev-only reader crash returns at parity with develop/master; production is unaffected (logger is dev-only). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
…oS (#507) Updates @nestjs/platform-express 11.1.27 -> 11.1.28, which pulls multer 2.1.1 -> 2.2.0 (multer is consumed only by platform-express). Resolves the two multer denial-of-service advisories on the API file-upload path: - GHSA-72gw-mp4g-v24j (high): DoS via deeply nested field names - GHSA-3p4h-7m6x-2hcm (moderate): DoS via incomplete cleanup of aborted uploads Claude-Session: https://claude.ai/code/session_01WKoPAepDc2xhSFFDhHTHe5 Co-authored-by: Claude <noreply@anthropic.com>
…n frames React 19.2's dev-only performance track deep-walks changed props and throws a SecurityError when it reaches the reader iframe's cross-origin window, crashing the commit (react/react#34840). Guard the prop walkers so unreadable values log as [inaccessible] instead of throwing. Fixed upstream by react/react#35679 (19.3 canary only); remove with `pnpm patch-remove react-dom@19.2.8` once on a release containing it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ernal peer Docker Desktop writes both IPv4 and IPv6 host-gateway entries, so nginx expands host.docker.internal into two peers; the IPv6 one is unreachable from the IPv4-only compose network and its failure accounting could mark the whole implicit upstream down (no live upstreams -> 502 bursts during replication). An explicit upstream with max_fails=0 lets a failed connect fall through to the reachable address instead of disabling the group. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Vercel's lockfile heuristic picks pnpm 9, which can't read patchedDependencies from pnpm-workspace.yaml and fails with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH. The bootstrapped pnpm 11 defers to the packageManager pin in package.json. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Vercel prepends its detected pnpm 9 to PATH, shadowing the npm-installed pnpm 11, so the install still hit ERR_PNPM_LOCKFILE_CONFIG_MISMATCH. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
pnpm-workspace.yaml references patches/react-dom@19.2.8.patch, so the frozen install in the base stage fails with ENOENT without it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
engines.node overrides the dashboard Node version; >=24 resolves to the latest 24.x on Vercel while staying satisfied by the node 25 used in CI, docker and local shells. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
main.ts value-imports json/urlencoded from express, which pnpm's isolated node_modules can't resolve through @nestjs/platform-express; dist/main crashed with MODULE_NOT_FOUND on a clean install. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
useBook is a live rxdb-backed query and the book finished dialog keeps an always-on observer of the same key, so the disabled observer in useCreateReader still received every progress-sync cache update and the bookOnce effect dependency remounted the reader on each write. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…514) The back arrow fell through to home whenever a screen had performed a replace-only navigation, such as switching tab on the book optimize screen. react-router rebuilds the whole history state object on replace, so the `__obokuCanGoBack` flag was dropped, and TrackHistoryCanGoBack only re-stamped it on pathname changes. react-router already tracks the entry position under `history.state.idx`, preserved across replace, which removes the need for a custom flag, the `__obokuFallbackBack` marker and the tracker component. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Extracts createBookQueryOptions alongside the existing createLinkQueryOptions pattern and rebuilds the reader's frozen book snapshot on top of a reusable hook that resolves a query's first result and ignores later cache updates. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…hanism Splits the one-shot idea into an observable flavour of queryClient.ensureQueryData (cache read, else first emission seeding the empty cache, never touching the tanstack fetch machinery) and a thin snapshot hook on top. Drops the inert observer, so consumers no longer re-render on post-capture cache writes. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Replaces the effect+state capture with a vanilla useQuery over a prefix-namespaced key whose queryFn is ensureQueryData$: staleTime Infinity freezes the snapshot, gcTime 0 scopes it to the consumers' lifetime and concurrent consumers dedupe into a single resolution. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit:6c4259fa2a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Uh oh!
There was an error while loading. Please reload this page.
The private useQuery dropped the source query's networkMode, so offline the default online mode paused resolution entirely — blocking even the warm-cache read and leaving locally available books on the loading screen. Resolution is cache-first, so always is the correct default; network-bound sources can pass online explicitly. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Uh oh!
There was an error while loading. Please reload this page.
🎉 This PR is included in version 1.2.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
🎉 This PR is included in version 2.0.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
No description provided.