Conversation
…nt rejects a non-JSON success body, safe ICS URIs, fewer false unsafe-scheme hits, lowercase score cursors, honest fakes, additive isErrorCode and geocode onError
…rt status buckets, and shared uuid, time unit and url helpers used by the app
…web and mobile instead of copies
…come from shared; docs list every deferred contract request
…e, and the adoption rule for strict request fields says implemented
This was referenced Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
The
@civfix/shared0.58.0 contract release. It carries every campaign change to the published package since 0.57.0; the full list is in the changeset (packages/shared/CHANGELOG.md, 0.58.0) and DECISIONS §58.isUuid, time units andstripTrailingSlashes;undefined;httpslinks;@civfix/shared0.58.0 (a minor, because it removes exports), via changesets.Before you start
publish-shared.ymlrun on themainpush does it. The adoption PRs in civfix-backend and civfix-admin (linked below) wait for that publish.mainmerge: civfix.dev, plus the TestFlight build the merge triggers.^0.24.2.Verify
Nothing should look different. The checks cover the forms whose length limits now come from the contract.
[Web] [Mobile] Length limits
[Web] Host console
[Web] [Mobile] Calendar file
Regression
Sign-in codes: [Web] [Mobile]
Host pages with links in text: [Web]
https://link. Expect: it is accepted and the link works. Text withjavascript:(with or without a space after it) is still refused.Findings addressed
Decisions for the reviewer
services/apiandservices/media-worker, civfix-adminapps/admin, civfix-govt-web, civfix-govt-shared, and the open backend and admin PRs.DEFAULT_DURATION_MS(the backend imports it), andDiscoveryReviewStatusSchemaandDISCOVERY_REVIEW_STATUS_LABELS(admin is adopting them).WebReportTypeloses its placeholdergovrouting field; admin reads onlyid,categoryandlabel..strict()DTOs, so the order is: publish, then admin adopts and ships, then the backend emits.flagged, the walk-upidempotencyKey) go the other way: the backend implements them first (a manifest bump alone would parseflaggedand keep toggling), then clients send them.javascript: alert(1)); onlyabout:used as prose and scheme words inside an https path are no longer refused;normalizeScoreCursorcan go).oauthNonceregistry entry;MediaDTO.url;^0.24.2by decision (tokens only).User-visible copy changes
None.
Tests changed
HANDLE_REGEXis unchanged;onError.comparePrecision,API_VERSIONS,registrationSeries,hourlySeries,repeatAttendanceRate,webReportTypeToCategory,EventInsightsSchema,REPORT_VOLUNTEER_HOURS,ipLocate,mixWithWhiteandchipPairPasses.seriesClosure;FORWARD_TEMPLATE_VARIABLES;vi.resetModules;test:commit.Verification
pnpm typecheck,pnpm lint,pnpm i18n:check,pnpm buildandpnpm doctorare green.node scripts/check-shared-version.mjs: 0.58.0 is not on the registry yet.javascript:after whitespace;CONTENT_REPORT_DETAILS_MAX;test:commit;main, so it starts when this PR retargets after Measured performance: smaller bundles and fewer renders #53 merges.Not covered
🤖 Generated with Claude Code