Repository navigation
chore(template): consolidate context, security fixes, and dependency cleanup - #7
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This cleanup brings the shared project context and the security/dependency audit into one PR.
CONTEXT.mdis preserved in full, with the matchingAGENTS.mdandCLAUDE.mdinstructions directing agents to that shared reference. This supersedes PR #6.The template allowed unverified email changes through profile PATCH, cached revoked sessions for seven days, and exposed its local database tools on all interfaces. The cleanup restricts profile updates to name/image, enforces immediate session revocation, fixes async route error handling and email delivery, and adds auth lookup indexes. Development retains LAN/Tailscale access using the host's discovered addresses.
Dependencies are updated across all four workspaces with Better Auth and its Expo plugin aligned at 1.7.3 and native dependencies matched to Expo SDK 57. The package manager is pinned, and PR checks cover tests, lint, workspace types, and Expo compatibility.
Validation: 50 tests pass; workspace type checks and lint pass (11 existing web warnings); frozen installation, Next.js production build, Expo compatibility, and iOS JavaScript export pass. Local Postgres and browser checks verified sign-in/dashboard, profile updates, session revocation, and development/production auth boundaries. The context files match the original context branch exactly. No remote database or real email delivery was used.
Dependency findings fell from 8 high / 6 moderate to 0 high / 2 moderate. Remaining upstream advisories and validation limits are documented in the audit report. No advisories are suppressed. A build-environment watch flag was removed for validation; no application workaround was added.