Add Firecrawl providers and usage sidebar app - #473
rakshith48 wants to merge 11 commits into
Conversation
There was a problem hiding this comment.
4 issues found and verified against the latest diff
Confidence score: 4/5
web/tsconfig.jsonreplaces the root config’s exclusions with an empty list, which can pullnode_modules,dist, andtestsinto the project. Preserve the root exclusions here.web/README.mdsays the logo script filters icon content, but it only rejects non-OK responses. Align the docs with what the script checks, or add the content validation.- The
.button-backgroundrules inweb/button.cssnever apply because no web element uses that class. Add the class to the intended element or remove the dead rules. readCurrentUsageinsrc/usage.tsreturnsRecord<string, unknown>, so callers lose theCreditUsageDatashape. ReturnCreditUsageDatainstead.
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="web/tsconfig.json">
<violation number="1" location="web/tsconfig.json:8">
P3: `exclude: []` in `web/tsconfig.json` completely replaces (not merges) the root config's `exclude: ["node_modules", "dist", "tests"]`, because options in an extending config overwrite the base's rather than merge with it. That silently disables the inherited exclusions; only the `include: ["./*.ts"]` scope keeps it harmless today. Drop the `exclude` key so the root exclusions carry over, or mirror them explicitly.</violation>
</file>
<file name="src/usage.ts">
<violation number="1" location="src/usage.ts:65">
P3: `readCurrentUsage` is now an exported function shared by the tool handler and the sidebar dashboard, but returns `Record<string, unknown>`, discarding the object shape the file already encodes in `CreditUsageData`. Return that concrete type so callers (e.g. `usage-ui.ts`) get typed fields instead of a generic record.</violation>
</file>
<file name="web/README.md">
<violation number="1" location="web/README.md:101">
P3: This overstates what refresh-provider-logos.mjs filters: the script rejects only non-OK responses (`if (!response.ok)`), never inspects icon content, and the inline comment two lines away says Google returns a valid (200) generic globe for unknown sites. So a 200 globe response passes the checks and gets embedded; the README's claim that the globe is omitted is only true for the 404 case, not in general. Reword to describe the actual filter, or detect the globe response in the script.</violation>
</file>
<file name="web/button.css">
<violation number="1" location="web/button.css:69">
P3: `.button-background` styles are dead: no element in usage.html, providers.ts, or any other web/ source carries that class, so `.button:hover .button-background` and `.button:active .button-background` never apply, and the `scale` transitions in `.button`/`.button:active` animate nothing (no `scale` property is ever set on these buttons). Drop the unused rules, or add the background element to the button markup if the press effect is intended.</violation>
</file>
Tip: instead of fixing issues one by one fix them all with cubic
Re-trigger cubic
There was a problem hiding this comment.
Review completed against the latest diff
Tip: instead of fixing issues one by one fix them all with cubic
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 9 files (changes from recent commits).
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 29 files (changes from recent commits).
Tip: instead of fixing issues one by one fix them all with cubic
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 27 files (changes from recent commits).
Requires human review: Large feature PR adding a usage dashboard MCP tool and UI app, plus an updated production OpenAI plugin listing and OAuth connection config; needs human sign-off on public exposure and plugin metadata/acceptance.
Tip: Review your code locally with the cubic CLI to iterate faster.
Fix all with cubic | Re-trigger cubic
There was a problem hiding this comment.
0 issues found across 2 files (changes from recent commits).
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Requires human review: Adds a new Providers/Usage sidebar app, MCP tool/resource, and production OAuth plugin packaging. The expanded product surface and authenticated production endpoint require human product, release, and security approval.
Re-trigger cubic
Firecrawl’s plugin exposes tools without a sidebar page for discovering Alexandria providers or checking account credits. This adds a Providers and Usage app with provider logos, Providers as the initial view, and native composer annotations for selected providers and tools. Browsing and selection do not execute paid capabilities.
The interface vendors Firecrawl web’s Button, Input, Select, Checkbox, Dialog, and ProviderLogo components, with the same Suisse fonts and semantic tokens. Tabs adapt the web billing segmented control with keyboard navigation. The self-contained HTML includes the initial Providers shell and all runtime assets. Usage retains the existing authenticated current-balance and calendar-month history APIs; it loads when its tab opens and supports independent failure recovery.
Preserves the published Firecrawl plugin identity, listing metadata, skills, and all seven references. Adds production icons, UI submission metadata, and package preparation targeting the production OAuth MCP endpoint. The local Keychain/stdio package remains available for development. The production ZIP (2.2.1, 13 files) was assembled and delivered; it has not been uploaded or published.
Addresses the Cubic review findings covering launcher portability, packaging output paths, metadata validation, bounded staging requests, keychain account selection, atomic logo writes, ICO artwork, discovery fixtures, empty-tool selection, disabled controls, dialog alignment, and transition units. Documentation now states the icon sources and actual favicon filtering. Regression checks exercise reversed category responses, iframe errors, native composer context, and short viewports.
Validation for
bf82b91(the latest commit only strengthens launcher credential assertions and normalizes a test entry-point path):3a17513and full GitHub CI passes atd0e9027. The four focused launcher/maintenance tests pass atbf82b91; application and server sources are unchanged by the latest test-only commit.bf82b91; prior green runs are not evidence for this head.72bd618df9920dd4945f8dbffab9d7fe149e10baff0f53391f39e8eb81b10440). Live checks pass for launcher metadata, current balance, monthly history, provider discovery, and invalid credentials. Staging publication completed atd0e9027; bothscalableandsserolled out successfully with image digestcc6c92d189a54fda04c733618d1d9cecc031e61182ebacade0ba363b559dce7e.staging-testing.md documents the private endpoint, live verifier, and actual-host acceptance steps. The user will test sidebar pinning and composer handoff in the app. Production deployment and submission/reviewer video remain separate release steps.