Adds a strict base TypeScript config at the workspace root (ES2023 / NodeNext
/ strict family incl. noUncheckedIndexedAccess, exactOptionalPropertyTypes,
noImplicitOverride, useUnknownInCatchVariables, verbatimModuleSyntax per
Engineering-Standards) and gives every workspace package
(apps/server, packages/core, extensions/example) a tsconfig.json that extends
it. Each package gets a minimal src/index.ts placeholder so it compiles under
the base config (CJS-safe `export {}` until ESM boundaries land in T03).
Verified: every package typechecks and emits (js + d.ts + sourcemap) with the
pinned TypeScript 6.0.3; a strictness probe confirms the strict family fires.
Closes#155
Ignores .env, .env.*, and node_modules/ at any depth so local secrets and dependency directories can never be committed accidentally. Single-file hygiene change; no tracked files affected. Closes#19.
Extends the newsletter suite with two boundary cases: redirects (301/302/307/
308) must be treated as failures with the user-safe error, and the POST must
carry no credential of any kind — no api-key/auth-token/cookie headers, and no
token/secret in the body or URL.
Rework PR #15 per security review SEC-14-R1: the client no longer carries
an API token. js/newsletter-config.js ships only the non-secret endpoint,
enforced https-only at config load time via validateEndpoint() (mirroring
the protocol allowlist in js/reading-list.js); js/newsletter.js POSTs
email-only with no Authorization header. Failure paths keep the single
user-safe message that never leaks token, endpoint, status, or raw body;
success still shows the confirmation. CI gains a gitleaks step that fails
on any secret hit; README documents the server-side token, the residual
signup-abuse risk, and the authoritative server-side validation follow-up.
Covers the issue test plan: form renders and posts to the endpoint; token is
read from config, never hardcoded in source; a failed-token response shows a
user-safe error without leaking the secret; confirmation on success.
Adds newsletter.html with an email signup form that POSTs to a configured
serverless endpoint. The endpoint and API token live in
js/newsletter-config.js (token defaults to an empty deploy-time placeholder,
never hardcoded in page logic). Missing/invalid tokens and network failures
surface a fixed user-safe error; successful signups show a confirmation.
Links the page from the site navigation on all pages.
All reading list links point at external http(s) URLs, so each rendered
anchor now carries rel="noopener noreferrer" as a hardening best
practice. Renderer test updated for the new attribute and asserts every
rendered link carries it.
Covers: page wiring and nav reachability, data-file integrity, grouped
rendering, valid hrefs, optional notes, HTML escaping, invalid-entry
skipping, data-only extensibility, and a 500-entry fixture (counts,
grouping, and a generous render-time bound).
New reading.html renders the data file into a #reading-list container and
marks itself as the current page. Home and contact pages gain a Reading nav
link. CSS adds responsive category/list styles (two columns on wide
screens) so long lists stay scannable.
Renders the data file as category-grouped HTML. Pure string builder with
guarded browser wiring so it is unit-testable in Node; escapes all text,
skips invalid entries, and handles duplicate category slugs.
Single source of truth for the reading list page. Entries carry a title,
url, category, and an optional one-line note; adding a link means editing
this file only.
`node --test <dir>` treats a directory argument as a module path on some
Node builds (reproduced on v22.23.2), so `npm test` failed before running
any tests. `node --test` with no args discovers the same tests/ files
portably.