Skip to content

fix(ops): remediate Crove-side audit findings + UI/UX plan & docs - #33

Merged
JOY (JOY) merged 4 commits into
mainfrom
dev
Sep 10, 2026
Merged

fix(ops): remediate Crove-side audit findings + UI/UX plan & docs#33
JOY (JOY) merged 4 commits into
mainfrom
dev

Conversation

@JOY

@JOY JOY (JOY) commented Sep 7, 2026

Copy link
Copy Markdown

What kind of change does this PR introduce?

Bug fix | CI/CD | Refactor — scope: infrastructure, CI/CD workflows, compose files, security configs, frontend design tokens. Remediation batch applying the Crove-side findings from the security/ops audit (report: docs/audit-2026-09-08.html, findings C2/C5/C7/C9, S4/S15–S20, I-B2/I-B4/I-B5/I-C1..I-E7, F-D1/F-D9). No app feature changes; workflow/provider engines untouched.

Why was this change needed?

An audit found ~30 issues caused by the fork itself. Most severe: production ran prisma db push --accept-data-loss on every container restart with zero backups (C2); the SSO bridge secret sat in plaintext in wrangler.jsonc with a mismatched hardcoded Cloudflare account-ID fallback (C7); the test/lint/typecheck gates were all silently broken so CI ran zero tests (C9); the webhook fell back to JWT_SECRET as its HMAC secret (S4); a dead self-hosted Postgres was gating app startup while the app DB is Supabase (S15); and the deploy used a floating :latest tag whose race caused a 4-day silent post-publishing outage (I-B4, root cause confirmed via Temporal history: worker bundle lacked postWorkflowV112).

Technical Details & Scope

  • Security: TLS-verify default removed from .env.example; webhook secret no longer falls back to JWT_SECRET; SSO secret moved out of compose vars; CLOUDFLARE_ACCOUNT_ID fail-fast.
  • Data safety: prod/beta compose command: override blocks startup db push; validator inverted to enforce it; dead crove-postgres removed (prod+beta); dev compose ports bound to 127.0.0.1; upstream image + literal JWT secret replaced with required env vars; CROVE_POST_IMAGE/CROVE_WEB_IMAGE overridable; cloudflared pinned; Temporal production dynamic config + healthchecks (temporal/postgresql/es); scripts/backup-db.sh (cron backup with unhealthy-state-store abort).
  • CI/CD: jest config fixed (@nx/jest was never installed — pnpm test ran zero tests); test gates added to build.yml; ESLint CI no longer swallows failures; permissions:/environment: on workflows; dead automation deleted (Jenkins/Sonar/Railway/staging-conflicts/nginx-crove/docker-build scripts); branding-guard now scans the repo (strict vs inherited tiers); PowerShell script exit-code fixes.
  • Supply chain/branding: pnpm dlxpnpm exec; onlyBuiltDependencies extended; private: true + AGPL license on apps; workspace packages renamed @crove/*; sdk → @crove/node; extension built via the real crx pipeline with crove-only externally_connectable.
  • Frontend: fork-local deprecated --color-custom* tokens replaced (impersonate, org selector, support, settings); emerald/support buttons re-emitted as colors.scss tokens (rule-2 compliance); hardcoded English → t() (org selector, role badges, trial/payment dialogs).
  • Docs: audit report docs/audit-2026-09-08.html; docs/cicd.md secrets table no longer carries real IP/account-ID values.

Verification & Testing

  • node scripts/validate-beta-compose.mjs → PASS (after every batch).
  • npx tsx scripts/branding-guard.ts → PASS (0 strict leaks, 6 inherited tolerated).
  • All edited package.json validated via JSON.parse (a trailing comma slipped in during editing and was caught + fixed).
  • Build reproduced locally: pnpm --filter @crove/orchestrator run build → dist exports post.workflow.v1.1.2 (verified the fix chain for the outage root cause).
  • VM verified live: zombie postgres containers/volumes removed with 0 connections confirmed; crove-post redeployed from rebuilt :latest; stuck Temporal workflow post_cmtu2l1ep0009o46xts6280wrWorkflowExecutionCompleted (post published).

QA

  1. Run node scripts/validate-beta-compose.mjs — expect [PASS] (compose contract incl. the new prod command: override and Supabase-only depends_on).
  2. Run npx tsx scripts/branding-guard.ts — expect [PASS] Repo scan: 0 strict branding leaks plus ~6 [INHERITED] tolerated mentions.
  3. Run pnpm --filter @crove/orchestrator run build — expect exit 0, then findstr v1.1.2 apps\orchestrator\dist\apps\orchestrator\src\workflows\index.js — expect one __exportStar(require("./post-workflows/post.workflow.v1.1.2"), ...) line.
  4. Run pnpm exec jest --config tests/bootstrap.jest.cjs --ci --passWithNoTests — expect the 5 bootstrap specs to run (previously pnpm test silently ran zero tests).
  5. Inspect scripts/docker-compose.prod.yaml — confirm crove-postgres is absent, command: override present without any prisma.*push, temporal uses production-sql.yaml, POSTGRES_PWD matches ${CROVE_TEMPORAL_POSTGRES_PASSWORD:?…} on both temporal services.
  6. Inspect apps/crove-sso/wrangler.jsonc — confirm DOWNSTREAM_CLIENT_SECRET no longer appears in either env's vars block.
  7. Inspect apps/extension/manifest.json — confirm externally_connectable contains only *.crove.com, *.crove.io, *.dos.me.
  8. Open docs/audit-2026-09-08.html in a browser — section 0 lists this remediation batch with per-finding status badges.

Checklist:

  • My code follows the project's code style and architectural conventions.
  • Local build passes (pnpm run build).
  • Branding guard validation passes (pnpm dlx tsx scripts/branding-guard.ts).
  • Tests and typecheck have been verified without errors.
  • Documentation has been updated (if applicable).
  • No secrets or sensitive credentials are included in this PR.
  • I have filled in the QA / Verification section above with real steps to verify this change.

@cursor

cursor Bot commented Sep 7, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_30eeca74-309e-4a8e-9d33-4e80928d4e97)

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a master plan and benchmark blueprint for the Crove Post UI/UX rework, detailing brand color choices, UI/UX benchmarks, a 4-module architecture, and zero-conflict merge guidelines. The feedback highlights a conflict between the proposed Emerald Green primary accent and the existing design system, points out potential cross-organization data leakage risks with SWR cache mutation during workspace switching, and suggests adding database migration guidelines to ensure a true zero-conflict merge strategy.

Comment thread docs/ui-ux-rework-plan.md
Comment on lines +20 to +21
- **Primary Brand Accent (Crove Core):** **Emerald Green (`#10B981` / `#059669`)** — Đại diện cho kênh phân phối, tăng trưởng Traffic, Leads & Khách hàng.
- **Secondary AI / Copilot Accent:** **Electric Purple / Violet (`#7C3AED`)** — Đại diện cho trợ lý AI Copilot, Magic Prompt & Tự động hóa thông minh.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The proposal to use Emerald Green (#10B981 / #059669) as the primary brand accent and Royal Purple (#7C3AED) as the secondary/AI accent conflicts with the established Design System in DESIGN.md. According to DESIGN.md (Section 1, Principle 4 and Section 2.1), Royal Purple (#612BD3 / #7c3aed) is defined as the dominant primary accent and core brand mark, while Emerald Green is reserved as a semantic success/online indicator. Introducing Emerald Green as the primary brand accent will require updating the core design tokens and guidelines in DESIGN.md to maintain consistency.

Comment thread docs/ui-ux-rework-plan.md
- **Thiết kế:**
- Component `CroveWorkspaceSelector`: Hiển thị Logo/Initials của Org, Role badge (`Super-Admin` / `Admin` / `Member`), Active checkmark.
- Tích hợp tìm kiếm nhanh khi user có nhiều Org.
- Chuyển đổi Workspace mượt mà qua SWR mutate (không reload trang).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Switching workspaces via SWR mutate without a page reload (window.location.reload()) requires careful cache invalidation. Since many SWR queries (e.g., posts, integrations, analytics) are scoped to the active organization, simply mutating the workspace state without clearing or revalidating all other organization-dependent SWR caches can lead to stale data or cross-organization data leakage in the UI. Ensure the implementation plans for a global cache reset or systematic key revalidation upon switching.

Comment thread docs/ui-ux-rework-plan.md

## 4. 🛡️ Quy Tắc Đảm Bảo "Zero-Conflict" Khi Merge Upstream

1. **Không sửa đổi core workflow và activity files:** Giữ nguyên các files trong `apps/orchestrator` và `libraries/nestjs-libraries/src/integrations/`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

To ensure a true zero-conflict merge strategy with upstream Postiz, consider adding a guideline regarding database schema changes and Prisma migrations. Modifying existing upstream tables or adding migrations directly to the main sequence can cause severe conflicts during upstream merges. Recommending isolated tables or a specific migration naming/prefixing convention would help prevent these issues.

@cursor

cursor Bot commented Sep 10, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_99cfdb55-0e75-4973-9eab-cb075ec2b909)

@JOY JOY (JOY) changed the title docs(ui-ux): add UI/UX rework master plan and industry benchmark blueprint fix(ops): remediate Crove-side audit findings + UI/UX plan & docs Sep 10, 2026
@JOY
JOY (JOY) merged commit c29c7d9 into main Sep 10, 2026
13 of 20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant