Skip to content

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment - #235

Merged
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code
Jun 26, 2026
Merged

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment#235
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Problem

Two production threads were misclassified as OTPs and fired immediate, gate-bypassing OTP pushes:

ThreadBogus "code"Real source
CcRuoq3tNqLxdMEYHVYLh (Reclaim "Weekly Report")39378156UUID-ish tracking token …f76e-39378156-bc8f… on a "Sign in…" line
CcRquZiM1Uy9ri8GsPk7r (Walmart "Thank you for shopping")750993a fragment inside a clickTracker URL; the mail also carries Order number: 600000097650390

Both are reach: direct automated mail, so the existing reach/promotion gate (#221) doesn't catch them. The haystack handed to extractCta is the connector's raw note content (raw HTML for Gmail), so tracking-URL tokens are in scope, and the old \b(…|\d{4,8})\b matcher happily spliced a 4–8 digit run out of the middle of a longer token.

Fix

A genuine one-time code is a small standalone token, never a slice of a longer number, URL, or UUID-like identifier. extractOtp now:

  • scans each keyword line word-by-word and only accepts a whole token matching CODE_CORE (anchored ^…$);
  • strips only sentence/markdown wrapper punctuation — the strip excludes- / + = % . so URL/decimal-glued tokens (…+750993/…, 1234.56) fail;
  • keeps the anchored \d{4,8}, so a 15-digit order number can't satisfy it even as a slice;
  • adds an ID_LABEL guard rejecting numbers introduced by "…number[:#]" (order/account/reference number).

Tests

Two new false-positive tests reproduce the exact prod codes (39378156, 750993). All genuine-OTP cases still pass: 482913, G-557812, 224466, all-same-digit placeholder, bare year, order total.

  • email-classifier: 48 pass
  • gmail facets: 4 pass
  • outlook facets: 6 pass
  • tsc --noEmit clean

No changeset — @plotday/email-classifier is private (not published to npm).

🤖 Generated with Claude Code

…link fragment
The reach/promotion gate left a residual false-positive class: direct,
automated transactional mail (a Reclaim "Weekly Report", a Walmart order
confirmation) where the old `\b…\d{4,8}\b` token matcher spliced a digit
fragment out of a tracking-link token sitting on a line that merely carried
a code keyword — e.g. `…f76e-39378156-bc8f…` → "39378156", `…+750993/…` →
"750993". These fire an immediate, gate-bypassing OTP push.
A genuine one-time code is a small STANDALONE token, never a slice of a
longer number, URL, or UUID-like identifier. `extractOtp` now scans each
keyword line word-by-word and only accepts a whole token that matches
`CODE_CORE` (anchored ^…$). The wrapper-strip deliberately excludes
`- / + = % .` so URL/decimal-glued tokens fail, and an anchored `\d{4,8}`
means a 15-digit order number can't satisfy it even as a slice. An ID_LABEL
guard also rejects numbers introduced by "…number[:#]" (order/account
number).
Two new FP tests reproduce the exact prod codes (threads
CcRuoq3tNqLxdMEYHVYLh / CcRquZiM1Uy9ri8GsPk7r). All genuine-OTP cases
(482913, G-557812, 224466, all-same-digit placeholder, year, order total)
still pass — 48 email-classifier + 4 gmail + 6 outlook facet tests green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 968d757 into mainJun 26, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/otp-fp-standalone-code branch June 26, 2026 14:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(email-classifier): require a standalone OTP code, not a tracking-link fragment by KrisBraun · Pull Request #235 · plotday/plot · GitHub
Skip to content

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment - #235

Merged
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code
Jun 26, 2026
Merged

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment#235
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Problem

Two production threads were misclassified as OTPs and fired immediate, gate-bypassing OTP pushes:

ThreadBogus "code"Real source
CcRuoq3tNqLxdMEYHVYLh (Reclaim "Weekly Report")39378156UUID-ish tracking token …f76e-39378156-bc8f… on a "Sign in…" line
CcRquZiM1Uy9ri8GsPk7r (Walmart "Thank you for shopping")750993a fragment inside a clickTracker URL; the mail also carries Order number: 600000097650390

Both are reach: direct automated mail, so the existing reach/promotion gate (#221) doesn't catch them. The haystack handed to extractCta is the connector's raw note content (raw HTML for Gmail), so tracking-URL tokens are in scope, and the old \b(…|\d{4,8})\b matcher happily spliced a 4–8 digit run out of the middle of a longer token.

Fix

A genuine one-time code is a small standalone token, never a slice of a longer number, URL, or UUID-like identifier. extractOtp now:

  • scans each keyword line word-by-word and only accepts a whole token matching CODE_CORE (anchored ^…$);
  • strips only sentence/markdown wrapper punctuation — the strip excludes- / + = % . so URL/decimal-glued tokens (…+750993/…, 1234.56) fail;
  • keeps the anchored \d{4,8}, so a 15-digit order number can't satisfy it even as a slice;
  • adds an ID_LABEL guard rejecting numbers introduced by "…number[:#]" (order/account/reference number).

Tests

Two new false-positive tests reproduce the exact prod codes (39378156, 750993). All genuine-OTP cases still pass: 482913, G-557812, 224466, all-same-digit placeholder, bare year, order total.

  • email-classifier: 48 pass
  • gmail facets: 4 pass
  • outlook facets: 6 pass
  • tsc --noEmit clean

No changeset — @plotday/email-classifier is private (not published to npm).

🤖 Generated with Claude Code

…link fragment
The reach/promotion gate left a residual false-positive class: direct,
automated transactional mail (a Reclaim "Weekly Report", a Walmart order
confirmation) where the old `\b…\d{4,8}\b` token matcher spliced a digit
fragment out of a tracking-link token sitting on a line that merely carried
a code keyword — e.g. `…f76e-39378156-bc8f…` → "39378156", `…+750993/…` →
"750993". These fire an immediate, gate-bypassing OTP push.
A genuine one-time code is a small STANDALONE token, never a slice of a
longer number, URL, or UUID-like identifier. `extractOtp` now scans each
keyword line word-by-word and only accepts a whole token that matches
`CODE_CORE` (anchored ^…$). The wrapper-strip deliberately excludes
`- / + = % .` so URL/decimal-glued tokens fail, and an anchored `\d{4,8}`
means a 15-digit order number can't satisfy it even as a slice. An ID_LABEL
guard also rejects numbers introduced by "…number[:#]" (order/account
number).
Two new FP tests reproduce the exact prod codes (threads
CcRuoq3tNqLxdMEYHVYLh / CcRquZiM1Uy9ri8GsPk7r). All genuine-OTP cases
(482913, G-557812, 224466, all-same-digit placeholder, year, order total)
still pass — 48 email-classifier + 4 gmail + 6 outlook facet tests green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 968d757 into mainJun 26, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/otp-fp-standalone-code branch June 26, 2026 14:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(email-classifier): require a standalone OTP code, not a tracking-link fragment by KrisBraun · Pull Request #235 · plotday/plot · GitHub
Skip to content

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment - #235

Merged
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code
Jun 26, 2026
Merged

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment#235
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Problem

Two production threads were misclassified as OTPs and fired immediate, gate-bypassing OTP pushes:

ThreadBogus "code"Real source
CcRuoq3tNqLxdMEYHVYLh (Reclaim "Weekly Report")39378156UUID-ish tracking token …f76e-39378156-bc8f… on a "Sign in…" line
CcRquZiM1Uy9ri8GsPk7r (Walmart "Thank you for shopping")750993a fragment inside a clickTracker URL; the mail also carries Order number: 600000097650390

Both are reach: direct automated mail, so the existing reach/promotion gate (#221) doesn't catch them. The haystack handed to extractCta is the connector's raw note content (raw HTML for Gmail), so tracking-URL tokens are in scope, and the old \b(…|\d{4,8})\b matcher happily spliced a 4–8 digit run out of the middle of a longer token.

Fix

A genuine one-time code is a small standalone token, never a slice of a longer number, URL, or UUID-like identifier. extractOtp now:

  • scans each keyword line word-by-word and only accepts a whole token matching CODE_CORE (anchored ^…$);
  • strips only sentence/markdown wrapper punctuation — the strip excludes- / + = % . so URL/decimal-glued tokens (…+750993/…, 1234.56) fail;
  • keeps the anchored \d{4,8}, so a 15-digit order number can't satisfy it even as a slice;
  • adds an ID_LABEL guard rejecting numbers introduced by "…number[:#]" (order/account/reference number).

Tests

Two new false-positive tests reproduce the exact prod codes (39378156, 750993). All genuine-OTP cases still pass: 482913, G-557812, 224466, all-same-digit placeholder, bare year, order total.

  • email-classifier: 48 pass
  • gmail facets: 4 pass
  • outlook facets: 6 pass
  • tsc --noEmit clean

No changeset — @plotday/email-classifier is private (not published to npm).

🤖 Generated with Claude Code

…link fragment
The reach/promotion gate left a residual false-positive class: direct,
automated transactional mail (a Reclaim "Weekly Report", a Walmart order
confirmation) where the old `\b…\d{4,8}\b` token matcher spliced a digit
fragment out of a tracking-link token sitting on a line that merely carried
a code keyword — e.g. `…f76e-39378156-bc8f…` → "39378156", `…+750993/…` →
"750993". These fire an immediate, gate-bypassing OTP push.
A genuine one-time code is a small STANDALONE token, never a slice of a
longer number, URL, or UUID-like identifier. `extractOtp` now scans each
keyword line word-by-word and only accepts a whole token that matches
`CODE_CORE` (anchored ^…$). The wrapper-strip deliberately excludes
`- / + = % .` so URL/decimal-glued tokens fail, and an anchored `\d{4,8}`
means a 15-digit order number can't satisfy it even as a slice. An ID_LABEL
guard also rejects numbers introduced by "…number[:#]" (order/account
number).
Two new FP tests reproduce the exact prod codes (threads
CcRuoq3tNqLxdMEYHVYLh / CcRquZiM1Uy9ri8GsPk7r). All genuine-OTP cases
(482913, G-557812, 224466, all-same-digit placeholder, year, order total)
still pass — 48 email-classifier + 4 gmail + 6 outlook facet tests green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 968d757 into mainJun 26, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/otp-fp-standalone-code branch June 26, 2026 14:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(email-classifier): require a standalone OTP code, not a tracking-link fragment by KrisBraun · Pull Request #235 · plotday/plot · GitHub
Skip to content

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment - #235

Merged
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code
Jun 26, 2026
Merged

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment#235
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Problem

Two production threads were misclassified as OTPs and fired immediate, gate-bypassing OTP pushes:

ThreadBogus "code"Real source
CcRuoq3tNqLxdMEYHVYLh (Reclaim "Weekly Report")39378156UUID-ish tracking token …f76e-39378156-bc8f… on a "Sign in…" line
CcRquZiM1Uy9ri8GsPk7r (Walmart "Thank you for shopping")750993a fragment inside a clickTracker URL; the mail also carries Order number: 600000097650390

Both are reach: direct automated mail, so the existing reach/promotion gate (#221) doesn't catch them. The haystack handed to extractCta is the connector's raw note content (raw HTML for Gmail), so tracking-URL tokens are in scope, and the old \b(…|\d{4,8})\b matcher happily spliced a 4–8 digit run out of the middle of a longer token.

Fix

A genuine one-time code is a small standalone token, never a slice of a longer number, URL, or UUID-like identifier. extractOtp now:

  • scans each keyword line word-by-word and only accepts a whole token matching CODE_CORE (anchored ^…$);
  • strips only sentence/markdown wrapper punctuation — the strip excludes- / + = % . so URL/decimal-glued tokens (…+750993/…, 1234.56) fail;
  • keeps the anchored \d{4,8}, so a 15-digit order number can't satisfy it even as a slice;
  • adds an ID_LABEL guard rejecting numbers introduced by "…number[:#]" (order/account/reference number).

Tests

Two new false-positive tests reproduce the exact prod codes (39378156, 750993). All genuine-OTP cases still pass: 482913, G-557812, 224466, all-same-digit placeholder, bare year, order total.

  • email-classifier: 48 pass
  • gmail facets: 4 pass
  • outlook facets: 6 pass
  • tsc --noEmit clean

No changeset — @plotday/email-classifier is private (not published to npm).

🤖 Generated with Claude Code

…link fragment
The reach/promotion gate left a residual false-positive class: direct,
automated transactional mail (a Reclaim "Weekly Report", a Walmart order
confirmation) where the old `\b…\d{4,8}\b` token matcher spliced a digit
fragment out of a tracking-link token sitting on a line that merely carried
a code keyword — e.g. `…f76e-39378156-bc8f…` → "39378156", `…+750993/…` →
"750993". These fire an immediate, gate-bypassing OTP push.
A genuine one-time code is a small STANDALONE token, never a slice of a
longer number, URL, or UUID-like identifier. `extractOtp` now scans each
keyword line word-by-word and only accepts a whole token that matches
`CODE_CORE` (anchored ^…$). The wrapper-strip deliberately excludes
`- / + = % .` so URL/decimal-glued tokens fail, and an anchored `\d{4,8}`
means a 15-digit order number can't satisfy it even as a slice. An ID_LABEL
guard also rejects numbers introduced by "…number[:#]" (order/account
number).
Two new FP tests reproduce the exact prod codes (threads
CcRuoq3tNqLxdMEYHVYLh / CcRquZiM1Uy9ri8GsPk7r). All genuine-OTP cases
(482913, G-557812, 224466, all-same-digit placeholder, year, order total)
still pass — 48 email-classifier + 4 gmail + 6 outlook facet tests green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 968d757 into mainJun 26, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/otp-fp-standalone-code branch June 26, 2026 14:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(email-classifier): require a standalone OTP code, not a tracking-link fragment by KrisBraun · Pull Request #235 · plotday/plot · GitHub
Skip to content

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment - #235

Merged
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code
Jun 26, 2026
Merged

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment#235
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Problem

Two production threads were misclassified as OTPs and fired immediate, gate-bypassing OTP pushes:

ThreadBogus "code"Real source
CcRuoq3tNqLxdMEYHVYLh (Reclaim "Weekly Report")39378156UUID-ish tracking token …f76e-39378156-bc8f… on a "Sign in…" line
CcRquZiM1Uy9ri8GsPk7r (Walmart "Thank you for shopping")750993a fragment inside a clickTracker URL; the mail also carries Order number: 600000097650390

Both are reach: direct automated mail, so the existing reach/promotion gate (#221) doesn't catch them. The haystack handed to extractCta is the connector's raw note content (raw HTML for Gmail), so tracking-URL tokens are in scope, and the old \b(…|\d{4,8})\b matcher happily spliced a 4–8 digit run out of the middle of a longer token.

Fix

A genuine one-time code is a small standalone token, never a slice of a longer number, URL, or UUID-like identifier. extractOtp now:

  • scans each keyword line word-by-word and only accepts a whole token matching CODE_CORE (anchored ^…$);
  • strips only sentence/markdown wrapper punctuation — the strip excludes- / + = % . so URL/decimal-glued tokens (…+750993/…, 1234.56) fail;
  • keeps the anchored \d{4,8}, so a 15-digit order number can't satisfy it even as a slice;
  • adds an ID_LABEL guard rejecting numbers introduced by "…number[:#]" (order/account/reference number).

Tests

Two new false-positive tests reproduce the exact prod codes (39378156, 750993). All genuine-OTP cases still pass: 482913, G-557812, 224466, all-same-digit placeholder, bare year, order total.

  • email-classifier: 48 pass
  • gmail facets: 4 pass
  • outlook facets: 6 pass
  • tsc --noEmit clean

No changeset — @plotday/email-classifier is private (not published to npm).

🤖 Generated with Claude Code

…link fragment
The reach/promotion gate left a residual false-positive class: direct,
automated transactional mail (a Reclaim "Weekly Report", a Walmart order
confirmation) where the old `\b…\d{4,8}\b` token matcher spliced a digit
fragment out of a tracking-link token sitting on a line that merely carried
a code keyword — e.g. `…f76e-39378156-bc8f…` → "39378156", `…+750993/…` →
"750993". These fire an immediate, gate-bypassing OTP push.
A genuine one-time code is a small STANDALONE token, never a slice of a
longer number, URL, or UUID-like identifier. `extractOtp` now scans each
keyword line word-by-word and only accepts a whole token that matches
`CODE_CORE` (anchored ^…$). The wrapper-strip deliberately excludes
`- / + = % .` so URL/decimal-glued tokens fail, and an anchored `\d{4,8}`
means a 15-digit order number can't satisfy it even as a slice. An ID_LABEL
guard also rejects numbers introduced by "…number[:#]" (order/account
number).
Two new FP tests reproduce the exact prod codes (threads
CcRuoq3tNqLxdMEYHVYLh / CcRquZiM1Uy9ri8GsPk7r). All genuine-OTP cases
(482913, G-557812, 224466, all-same-digit placeholder, year, order total)
still pass — 48 email-classifier + 4 gmail + 6 outlook facet tests green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 968d757 into mainJun 26, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/otp-fp-standalone-code branch June 26, 2026 14:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(email-classifier): require a standalone OTP code, not a tracking-link fragment by KrisBraun · Pull Request #235 · plotday/plot · GitHub
Skip to content

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment - #235

Merged
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code
Jun 26, 2026
Merged

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment#235
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Problem

Two production threads were misclassified as OTPs and fired immediate, gate-bypassing OTP pushes:

ThreadBogus "code"Real source
CcRuoq3tNqLxdMEYHVYLh (Reclaim "Weekly Report")39378156UUID-ish tracking token …f76e-39378156-bc8f… on a "Sign in…" line
CcRquZiM1Uy9ri8GsPk7r (Walmart "Thank you for shopping")750993a fragment inside a clickTracker URL; the mail also carries Order number: 600000097650390

Both are reach: direct automated mail, so the existing reach/promotion gate (#221) doesn't catch them. The haystack handed to extractCta is the connector's raw note content (raw HTML for Gmail), so tracking-URL tokens are in scope, and the old \b(…|\d{4,8})\b matcher happily spliced a 4–8 digit run out of the middle of a longer token.

Fix

A genuine one-time code is a small standalone token, never a slice of a longer number, URL, or UUID-like identifier. extractOtp now:

  • scans each keyword line word-by-word and only accepts a whole token matching CODE_CORE (anchored ^…$);
  • strips only sentence/markdown wrapper punctuation — the strip excludes- / + = % . so URL/decimal-glued tokens (…+750993/…, 1234.56) fail;
  • keeps the anchored \d{4,8}, so a 15-digit order number can't satisfy it even as a slice;
  • adds an ID_LABEL guard rejecting numbers introduced by "…number[:#]" (order/account/reference number).

Tests

Two new false-positive tests reproduce the exact prod codes (39378156, 750993). All genuine-OTP cases still pass: 482913, G-557812, 224466, all-same-digit placeholder, bare year, order total.

  • email-classifier: 48 pass
  • gmail facets: 4 pass
  • outlook facets: 6 pass
  • tsc --noEmit clean

No changeset — @plotday/email-classifier is private (not published to npm).

🤖 Generated with Claude Code

…link fragment
The reach/promotion gate left a residual false-positive class: direct,
automated transactional mail (a Reclaim "Weekly Report", a Walmart order
confirmation) where the old `\b…\d{4,8}\b` token matcher spliced a digit
fragment out of a tracking-link token sitting on a line that merely carried
a code keyword — e.g. `…f76e-39378156-bc8f…` → "39378156", `…+750993/…` →
"750993". These fire an immediate, gate-bypassing OTP push.
A genuine one-time code is a small STANDALONE token, never a slice of a
longer number, URL, or UUID-like identifier. `extractOtp` now scans each
keyword line word-by-word and only accepts a whole token that matches
`CODE_CORE` (anchored ^…$). The wrapper-strip deliberately excludes
`- / + = % .` so URL/decimal-glued tokens fail, and an anchored `\d{4,8}`
means a 15-digit order number can't satisfy it even as a slice. An ID_LABEL
guard also rejects numbers introduced by "…number[:#]" (order/account
number).
Two new FP tests reproduce the exact prod codes (threads
CcRuoq3tNqLxdMEYHVYLh / CcRquZiM1Uy9ri8GsPk7r). All genuine-OTP cases
(482913, G-557812, 224466, all-same-digit placeholder, year, order total)
still pass — 48 email-classifier + 4 gmail + 6 outlook facet tests green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 968d757 into mainJun 26, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/otp-fp-standalone-code branch June 26, 2026 14:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(email-classifier): require a standalone OTP code, not a tracking-link fragment by KrisBraun · Pull Request #235 · plotday/plot · GitHub
Skip to content

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment - #235

Merged
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code
Jun 26, 2026
Merged

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment#235
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Problem

Two production threads were misclassified as OTPs and fired immediate, gate-bypassing OTP pushes:

ThreadBogus "code"Real source
CcRuoq3tNqLxdMEYHVYLh (Reclaim "Weekly Report")39378156UUID-ish tracking token …f76e-39378156-bc8f… on a "Sign in…" line
CcRquZiM1Uy9ri8GsPk7r (Walmart "Thank you for shopping")750993a fragment inside a clickTracker URL; the mail also carries Order number: 600000097650390

Both are reach: direct automated mail, so the existing reach/promotion gate (#221) doesn't catch them. The haystack handed to extractCta is the connector's raw note content (raw HTML for Gmail), so tracking-URL tokens are in scope, and the old \b(…|\d{4,8})\b matcher happily spliced a 4–8 digit run out of the middle of a longer token.

Fix

A genuine one-time code is a small standalone token, never a slice of a longer number, URL, or UUID-like identifier. extractOtp now:

  • scans each keyword line word-by-word and only accepts a whole token matching CODE_CORE (anchored ^…$);
  • strips only sentence/markdown wrapper punctuation — the strip excludes- / + = % . so URL/decimal-glued tokens (…+750993/…, 1234.56) fail;
  • keeps the anchored \d{4,8}, so a 15-digit order number can't satisfy it even as a slice;
  • adds an ID_LABEL guard rejecting numbers introduced by "…number[:#]" (order/account/reference number).

Tests

Two new false-positive tests reproduce the exact prod codes (39378156, 750993). All genuine-OTP cases still pass: 482913, G-557812, 224466, all-same-digit placeholder, bare year, order total.

  • email-classifier: 48 pass
  • gmail facets: 4 pass
  • outlook facets: 6 pass
  • tsc --noEmit clean

No changeset — @plotday/email-classifier is private (not published to npm).

🤖 Generated with Claude Code

…link fragment
The reach/promotion gate left a residual false-positive class: direct,
automated transactional mail (a Reclaim "Weekly Report", a Walmart order
confirmation) where the old `\b…\d{4,8}\b` token matcher spliced a digit
fragment out of a tracking-link token sitting on a line that merely carried
a code keyword — e.g. `…f76e-39378156-bc8f…` → "39378156", `…+750993/…` →
"750993". These fire an immediate, gate-bypassing OTP push.
A genuine one-time code is a small STANDALONE token, never a slice of a
longer number, URL, or UUID-like identifier. `extractOtp` now scans each
keyword line word-by-word and only accepts a whole token that matches
`CODE_CORE` (anchored ^…$). The wrapper-strip deliberately excludes
`- / + = % .` so URL/decimal-glued tokens fail, and an anchored `\d{4,8}`
means a 15-digit order number can't satisfy it even as a slice. An ID_LABEL
guard also rejects numbers introduced by "…number[:#]" (order/account
number).
Two new FP tests reproduce the exact prod codes (threads
CcRuoq3tNqLxdMEYHVYLh / CcRquZiM1Uy9ri8GsPk7r). All genuine-OTP cases
(482913, G-557812, 224466, all-same-digit placeholder, year, order total)
still pass — 48 email-classifier + 4 gmail + 6 outlook facet tests green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 968d757 into mainJun 26, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/otp-fp-standalone-code branch June 26, 2026 14:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(email-classifier): require a standalone OTP code, not a tracking-link fragment by KrisBraun · Pull Request #235 · plotday/plot · GitHub
Skip to content

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment - #235

Merged
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code
Jun 26, 2026
Merged

fix(email-classifier): require a standalone OTP code, not a tracking-link fragment#235
KrisBraun merged 1 commit into
mainfrom
fix/otp-fp-standalone-code

Conversation

@KrisBraun

Copy link
Copy Markdown
Contributor

Problem

Two production threads were misclassified as OTPs and fired immediate, gate-bypassing OTP pushes:

ThreadBogus "code"Real source
CcRuoq3tNqLxdMEYHVYLh (Reclaim "Weekly Report")39378156UUID-ish tracking token …f76e-39378156-bc8f… on a "Sign in…" line
CcRquZiM1Uy9ri8GsPk7r (Walmart "Thank you for shopping")750993a fragment inside a clickTracker URL; the mail also carries Order number: 600000097650390

Both are reach: direct automated mail, so the existing reach/promotion gate (#221) doesn't catch them. The haystack handed to extractCta is the connector's raw note content (raw HTML for Gmail), so tracking-URL tokens are in scope, and the old \b(…|\d{4,8})\b matcher happily spliced a 4–8 digit run out of the middle of a longer token.

Fix

A genuine one-time code is a small standalone token, never a slice of a longer number, URL, or UUID-like identifier. extractOtp now:

  • scans each keyword line word-by-word and only accepts a whole token matching CODE_CORE (anchored ^…$);
  • strips only sentence/markdown wrapper punctuation — the strip excludes- / + = % . so URL/decimal-glued tokens (…+750993/…, 1234.56) fail;
  • keeps the anchored \d{4,8}, so a 15-digit order number can't satisfy it even as a slice;
  • adds an ID_LABEL guard rejecting numbers introduced by "…number[:#]" (order/account/reference number).

Tests

Two new false-positive tests reproduce the exact prod codes (39378156, 750993). All genuine-OTP cases still pass: 482913, G-557812, 224466, all-same-digit placeholder, bare year, order total.

  • email-classifier: 48 pass
  • gmail facets: 4 pass
  • outlook facets: 6 pass
  • tsc --noEmit clean

No changeset — @plotday/email-classifier is private (not published to npm).

🤖 Generated with Claude Code

…link fragment
The reach/promotion gate left a residual false-positive class: direct,
automated transactional mail (a Reclaim "Weekly Report", a Walmart order
confirmation) where the old `\b…\d{4,8}\b` token matcher spliced a digit
fragment out of a tracking-link token sitting on a line that merely carried
a code keyword — e.g. `…f76e-39378156-bc8f…` → "39378156", `…+750993/…` →
"750993". These fire an immediate, gate-bypassing OTP push.
A genuine one-time code is a small STANDALONE token, never a slice of a
longer number, URL, or UUID-like identifier. `extractOtp` now scans each
keyword line word-by-word and only accepts a whole token that matches
`CODE_CORE` (anchored ^…$). The wrapper-strip deliberately excludes
`- / + = % .` so URL/decimal-glued tokens fail, and an anchored `\d{4,8}`
means a 15-digit order number can't satisfy it even as a slice. An ID_LABEL
guard also rejects numbers introduced by "…number[:#]" (order/account
number).
Two new FP tests reproduce the exact prod codes (threads
CcRuoq3tNqLxdMEYHVYLh / CcRquZiM1Uy9ri8GsPk7r). All genuine-OTP cases
(482913, G-557812, 224466, all-same-digit placeholder, year, order total)
still pass — 48 email-classifier + 4 gmail + 6 outlook facet tests green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@KrisBraun
KrisBraun merged commit 968d757 into mainJun 26, 2026
1 check passed
@KrisBraun
KrisBraun deleted the fix/otp-fp-standalone-code branch June 26, 2026 14:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@KrisBraun