Skip to content

Follow-up fixes: dead code, compose env vars, POST /verify, dep cleanup, replay visibility - #2

Merged
smeinecke merged 1 commit into
mainfrom
followup-fixes
Jun 18, 2026
Merged

smeinecke merged 1 commit into
mainfrom
followup-fixes

Conversation

@smeinecke

Copy link
Copy Markdown

Summary

This PR closes configuration gaps, removes dead code, cleans dependencies, surfaces replay-store behaviour, and adds a privacy-preserving POST /verify endpoint.

Changes

  • Remove dead warning in index.ts -- The if (config.hmacKey === "$ecret.key") check is unreachable because parseApiConfig now enforces a 32-character minimum.
  • Forward missing env vars in compose.yaml -- EXPIREMINUTES, MAXRECORDS, and PORT are now passed through with defaults, fixing silent misconfiguration.
  • Remove unused devDependencies -- Deleted ts-node and @yarnpkg/pnpify; neither is referenced in any script or config.
  • Surface replay-store reset -- Added startup log line and promoted the warning in README production notes.
  • Add POST /verify -- New endpoint accepting application/json with { "altcha": string }. Keeps GET /verify for backward compatibility. Demo proxy updated to use POST, eliminating the token from API-side access logs.
  • Tests -- Added integration tests for POST /verify (valid, invalid, replayed).

… replay visibility

- Remove unreachable default-secret warning in index.ts (32-char minimum
  already rejects it)
- Forward EXPIREMINUTES, MAXRECORDS, PORT in compose.yaml
- Add POST /verify endpoint accepting JSON body; keep GET for backward
  compatibility
- Update demo proxy POST /test to use POST /verify (removes token from logs)
- Remove unused devDependencies ts-node and @yarnpkg/pnpify
- Log replay-store initialisation warning on startup
- Surface replay-store reset risk prominently in README production notes
- Add integration tests for POST /verify (valid, invalid, replayed)
@smeinecke
smeinecke merged commit 3dbfd4c into main Jun 18, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant