Skip to content

[codex] Publish CommandSphere and audit remediation - #1

Merged
LuanTrindade95 merged 59 commits into
mainfrom
fix/analytics-bounds
Aug 12, 2026
Merged

LuanTrindade95 merged 59 commits into
mainfrom
fix/analytics-bounds

Conversation

@LuanTrindade95

Copy link
Copy Markdown
Owner

Summary

This PR publishes the CommandSphere portfolio implementation and the build-loop remediation work tracked in the local Brain.

It includes:

  • Angular SSR frontend, Laravel API, Docker production packaging, Meilisearch, Redis, Reverb, Horizon and domain documentation.
  • Brain bootstrap and system audit documentation.
  • Runtime public config hardening for browser API, Reverb, SSR canonical/Open Graph/JSON-LD metadata, and allowed hosts.
  • Discord OAuth state validation with a first-party Socialite Discord provider.
  • CI service-backed gates for MySQL, Redis and Meilisearch plus dependency audits.
  • Ingestion run source tracking, SQL-scoped pagination, duplicate active-run prevention, and unique jobs per plugin version.
  • Analytics period bounds with configurable COMMANDSPHERE_ANALYTICS_MAX_DAYS.

Why

The local audit found production-hardening gaps around public runtime configuration, OAuth state, CI service coverage, ingestion concurrency/listing performance, and analytics bounds. The fixes make the project more credible as a production-grade portfolio system and provide a remote CI path for the service-backed surfaces.

Validation

Local validation performed:

  • npm.cmd run lint
  • npm.cmd test -- --runInBand
  • npm.cmd run build
  • npm.cmd audit --audit-level=critical
  • composer audit
  • Pint on touched backend files
  • PHP syntax checks on touched backend files
  • Focused Pest suites with SQLite memory for auth, ingestion, automation/realtime and analytics bounds
  • Docker production-like smoke with MySQL, Redis, Meilisearch, backend, Nginx, Horizon, Reverb and frontend SSR
  • Browser smoke with Chromium validating frontend hydration, public API fetch and Reverb websocket connection

Notes

  • This is a draft PR because remote GitHub Actions still needs to run against the pushed branch.
  • Production image smoke followed the documented production runbook. db:seed --force is not part of that runbook and currently fails in production images because factories depend on Faker, which is dev-only.

@LuanTrindade95
LuanTrindade95 marked this pull request as ready for review August 12, 2026 22:58
@LuanTrindade95
LuanTrindade95 merged commit d61d674 into main Aug 12, 2026
4 checks passed
@LuanTrindade95
LuanTrindade95 deleted the fix/analytics-bounds branch September 23, 2026 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant