dependabot[bot]
0a33fa9735
chore(deps): bump urllib3 in /PROJECTS/advanced/api-rate-limiter
...
Bumps [urllib3](https://github.com/urllib3/urllib3 ) from 2.6.3 to 2.7.0.
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0 )
---
updated-dependencies:
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-11 16:55:49 +00:00
dependabot[bot]
1ddc8acf39
chore(deps): bump urllib3
...
Bumps [urllib3](https://github.com/urllib3/urllib3 ) from 2.6.2 to 2.7.0.
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.2...2.7.0 )
---
updated-dependencies:
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-11 16:30:23 +00:00
dependabot[bot]
5ba40b27dc
chore(deps): bump github.com/go-git/go-git/v5
...
Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git ) from 5.18.0 to 5.19.0.
- [Release notes](https://github.com/go-git/go-git/releases )
- [Changelog](https://github.com/go-git/go-git/blob/main/HISTORY.md )
- [Commits](https://github.com/go-git/go-git/compare/v5.18.0...v5.19.0 )
---
updated-dependencies:
- dependency-name: github.com/go-git/go-git/v5
dependency-version: 5.19.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-11 16:03:40 +00:00
dependabot[bot]
373c7ba487
chore(deps): bump urllib3
...
Bumps [urllib3](https://github.com/urllib3/urllib3 ) from 2.6.2 to 2.7.0.
- [Release notes](https://github.com/urllib3/urllib3/releases )
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst )
- [Commits](https://github.com/urllib3/urllib3/compare/2.6.2...2.7.0 )
---
updated-dependencies:
- dependency-name: urllib3
dependency-version: 2.7.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-11 16:00:17 +00:00
CarterPerez-dev
697f4909d7
fix(canary-phase1): clear all post-phase-1 audit observations + header normalization
...
No 'logged for later' — every non-blocking finding from the Phase 1 audits
is fixed now, in this commit, before declaring the phase truly closed.
Code cleanups (5 items):
1. Database.SQLDB() *sql.DB accessor on core.Database; main.go uses
db.SQLDB() instead of the awkward db.DB.DB triple-chain.
2. Hoisted list-default literals (50, 20) to package-level
defaultListLimit consts in token + event repositories. MEMORY.md
'no magic numbers' rule honored.
3. Moved ptr[T any] helper to internal/testutil/ptr.go as testutil.Ptr;
removed local copies from token + event repository_test.go.
4. Renamed CHECK constraints in 0001_create_tokens.sql to match spec
text exactly: chk_token_type → chk_type, chk_alert_channel → chk_channel.
Spec was the original contract; impl now aligns.
5. Resolved APP_ENVIRONMENT vs ENVIRONMENT divergence per spec §12.1:
- compose.yml: ENVIRONMENT=production → APP_ENVIRONMENT=production
- dev.compose.yml: ENVIRONMENT=development → APP_ENVIRONMENT=development
- config.go envKeyMap: ENVIRONMENT → APP_ENVIRONMENT mapping
Concurrency bug fix (real, not just polish):
- core/migrations.go: added sync.Mutex around goose calls. goose's
package-level state (SetBaseFS, SetDialect) raced under t.Parallel()
testcontainers tests. Race detector caught it under -race after
parallel test counts climbed. Mutex serializes goose invocation
globally; testcontainer-parallelism otherwise unaffected.
Header normalization (50 files):
- Bulk-normalized every project file's header to canonical
'©AngelaMos | 2026' (no space, with © glyph, year 2026) per MEMORY.md
style rule. Eliminated 4 distinct non-canonical variants: '// AngelaMos',
'// ©AngelaMos | 2025', '// © AngelaMos | 202X', '# AngelaMos'.
- Verified clean: grep returns zero non-canonical headers across the
whole project tree (excluding gitignored docs/ and node_modules/).
Backlog discipline:
- Created docs/plans/BACKLOG.md with strict format: open items only,
HIGH/MEDIUM/LOW severity, must-clear-before-ship contract.
- BACKLOG currently has zero open items — every observation was fixed
here, not deferred. Closed-items section logs what was cleared.
Verification:
- go build ./... clean
- go vet ./... clean
- go test -tags=integration -race ./internal/token/... 11/11 PASS
- go test -tags=integration -race ./internal/event/... 9/9 PASS
- docker compose -f compose.yml config parses
- docker compose -f dev.compose.yml config parses
- grep for non-canonical headers zero matches
2026-05-10 06:15:26 -04:00
CarterPerez-dev
7a98ef8d72
chore(canary-phase1): database & repositories complete
...
Phase 1 deliverables (audited PASS by superpowers:code-reviewer + general-purpose):
Implementation (1 commit):
- b2558e2e Postgres schema + token & event repositories + testcontainers helper
Schema:
- 3 goose migrations under internal/core/migrations/ (tokens, events, indexes)
- All spec §7.1 columns + types + CHECK constraints present
- All 8 spec indexes present, including 2 partial indexes
- FK ON DELETE CASCADE on events.token_id (verified by TestRepository_FKCascade)
- chk_token_type enforces the 7-token locked enum exactly
Repositories:
- token: Insert / GetByID / GetByManageID / DeleteByManageID / IncrementTriggerCount /
SetEnabled / ListAll / CountAll
- event: Insert / GetByID / ListByToken (cursor pagination, LIMIT N+1 trick) /
CountByToken / AttachFingerprint (jsonb || merge into most-recent within
configurable window) / UpdateNotifyStatus / PruneToLimit (window function)
- Both: ErrNotFound on sql.ErrNoRows; all errors wrapped with %w; Repository struct
+ NewRepository(*sqlx.DB) constructor pattern matches template
Tests:
- 11 token integration tests + 9 event integration tests, all PASS
- testcontainers/postgres:18-alpine spins per test (~5-7s each)
- Tagged //go:build integration so plain `go test ./...` stays cheap
- Coverage: insert, get, not-found, delete with cascade, atomic increment,
enable toggle, list pagination across 3 pages, fingerprint merge preserving
existing extras, prune-keeps-newest, prune-rejects-zero, type CHECK rejection
Wired into main.go: core.RunMigrations(db.DB.DB) on startup; tokenRepo +
eventRepo blank-assigned (services consume them in Phase 9/10).
Audit findings (informational, non-blocking, deferred):
- Spec text says CHECK names 'chk_type'/'chk_channel'; implementation uses
'chk_token_type'/'chk_alert_channel' (audit prompt's expected names — both
agents endorse). Functionally identical; spec literal could be amended.
- main.go uses 'db.DB.DB' triple-chain to pass *sql.DB to goose. Visually
awkward; a Database.SQLDB() accessor would clean it up. Cleanup pass later.
- Default list limits (50, 20) are inline literals; hoisting to package consts
would satisfy MEMORY.md 'no magic numbers' rule. Minor.
- ptr[T any] helper duplicated across token + event test files. Could move to
testutil. Trivial.
- spec §12.4 ENVIRONMENT vs APP_ENVIRONMENT mismatch (logged in Phase 0
rollup) carries forward; not Phase 1's concern.
Verification at phase boundary:
- go build ./... clean
- go vet ./... clean
- go test -tags=integration ./internal/token/... 11/11 PASS
- go test -tags=integration ./internal/event/... 9/9 PASS
Phase 1 complete. Next: Phase 2 (generator interface + webbug + 1×1 GIF).
2026-05-10 05:54:03 -04:00
CarterPerez-dev
b2558e2e41
feat(canary): Phase 1 — Postgres schema + token & event repositories
...
Schema (3 goose migrations under internal/core/migrations/):
- 0001_create_tokens.sql: tokens table per spec §7.1
Columns: id (varchar 12, PK), manage_id (UUID unique), type, memo,
filename, alert_channel, telegram_bot/chat, webhook_url,
created_at/ip/fp, enabled, trigger_count, last_triggered, metadata (jsonb)
CHECK constraints: chk_token_type (7-token enum), chk_alert_channel (telegram|webhook),
chk_telegram_complete (when channel=telegram, bot+chat required),
chk_webhook_complete (when channel=webhook, url required)
- 0002_create_events.sql: events table
Columns: id (bigserial PK), token_id (FK with ON DELETE CASCADE),
triggered_at, source_ip (inet), user_agent, referer,
geo_country/region/city/asn/asn_org, extra (jsonb),
notify_status, notified_at
CHECK chk_notify_status (pending|sent|failed|deduped)
- 0003_indexes.sql: full index set per spec §7.1
tokens(created_ip), tokens(created_fp), tokens(created_at DESC),
tokens(type), partial idx_tokens_trigger_count WHERE trigger_count > 0,
events(token_id, triggered_at DESC), events(source_ip),
partial idx_events_notify_pending WHERE notify_status = 'pending'
Migration runner (internal/core/migrations.go):
- go:embed migrations/*.sql baked into binary
- core.RunMigrations(*sql.DB) called from main.go after DB connect
- pressly/goose v3.27.1 (research-recommended; no dirty-state bug)
Token domain (internal/token/):
- entity.go: Token struct + typed Type/AlertChannel enums with Valid() guards
- dto.go: CreateRequest with validator/v10 tags (oneof, required_if, url, max),
Response shape with ToResponse(triggerURL, manageURL) helper
- repository.go: Insert (RETURNING created_at + counters), GetByID,
GetByManageID, DeleteByManageID (FK cascade), IncrementTriggerCount,
SetEnabled, ListAll + CountAll. ErrNotFound on sql.ErrNoRows.
Named-parameter binding via sqlx.NamedExecContext.
- repository_test.go (//go:build integration): 11 tests covering insert,
get-by-id, get-by-manage-id, not-found paths, delete with cascade,
trigger count increment, enable toggle, list pagination, type CHECK
Event domain (internal/event/):
- entity.go: Event struct + NotifyStatus enum
- dto.go: GeoView + Response with ToResponse() flattens geo into nested object
- repository.go: Insert, GetByID, ListByToken (cursor pagination via
LIMIT N+1, returns NextCursor + HasMore), CountByToken,
AttachFingerprint (UPDATE most-recent within window using
jsonb || merge), UpdateNotifyStatus, PruneToLimit
(window function row_number() PARTITION BY token_id)
- repository_test.go (//go:build integration): 9 tests covering insert,
cursor-paginated listing, FK cascade from token deletion, fingerprint
merge into existing extra jsonb, notify status update, prune-to-N
preserves newest-first, prune rejects zero limit
Test infrastructure:
- internal/testutil/postgres.go: testcontainers-go helper that spins up
postgres:18-alpine, applies migrations via core.RunMigrations, returns
ready *sql.DB with t.Cleanup-registered teardown. ~5-7s per test;
20 integration tests run in ~13s end-to-end.
Wired into main.go:
- core.RunMigrations(db.DB.DB) called after NewDatabase
- token + event repos instantiated; blank-assigned for now (services
consume them in Phase 9/10)
Verification:
- go build ./... clean
- go vet ./... clean
- go test -tags=integration ./internal/token/... 11 of 11 PASS
- go test -tags=integration ./internal/event/... 9 of 9 PASS
2026-05-10 05:47:24 -04:00
CarterPerez-dev
a86939f412
chore(canary-phase0): bootstrap & cleanup complete
...
Phase 0 deliverables (audited via superpowers:code-reviewer + general-purpose):
Implementation (8 commits + 1 audit-fix commit):
- 5ccabe00 Comprehensive .gitignore (Go, Node, env, OS, builds, caches)
- 382890cb Rebrand no-auth-template → canary-token-generator across compose
- 7fa2861e Strip JWT/users, rename module to project-local path, rewrite main
- 8b70bfbb Merge backend compose into project-root (single deployment unit)
- a5c8d171 canary.dev (Air) + canary.prod (distroless static) Dockerfiles
- 369c9548 Unified Justfile with frontend/backend/lint/compose/tunnel groups
- a2d6f09a Project-root .env.example + idempotent init.sh
- a4811d1c Import operator's React + Vite frontend template
- 98c00689 Address audit findings (vite.prod paths, broken backend/Dockerfile,
backend/Justfile, admin AuthService residue, header glyphs)
Verification at phase boundary:
- go build ./... + go vet ./... clean
- docker compose -f compose.yml config + dev.compose.yml config + cloudflared overlay all parse
- just --list parses, randomized host ports preserved (22784, 58495, 15723, 5447, 6022, 16686, 4317, 4318)
- grep returns zero hits for: react-scss, carterperez-dev/templates, JWTConfig,
JWT_PRIVATE, lestrrat, InvalidateAllSessions
- backend has no host port in production compose
- module path: github.com/CarterPerez-dev/cybersecurity-projects/canary-token-generator/backend
Deliberately deferred (logged for later phases):
- Template-imported Go files (server.go, logging.go, request_id.go, headers.go,
ratelimit.go, health/handler.go, core/*.go, config/config.go) carry
'// AngelaMos | 2026' headers without ©. Out of Phase 0 scope. Bulk hygiene
pass possible later.
- frontend/vite.config.ts and frontend/stylelint.config.js carry 2025 in their
headers (operator-imported template files). Same deferred bucket.
- backend/internal/admin/handler.go now has handler-only structure; OperatorBearer
middleware wiring is Phase 12.
- Recovery middleware not yet present in main.go middleware chain — Phase 9
introduces it alongside the token domain.
- config.go envKeyMap does not yet know about canary-specific env vars
(PUBLIC_BASE_URL, TURNSTILE_SECRET, OPERATOR_TOKEN, GEOLITE_PATH,
WEBHOOK_HMAC_SECRET, MYSQL_FAKE_ENABLED). compose.yml passes them in via
ENV but config.go cannot read them yet — Phase 9 extends this.
Phase 0 complete. Next: Phase 1 (database schema + repositories).
2026-05-10 05:38:27 -04:00
CarterPerez-dev
98c006897d
fix(canary-phase0): address audit findings before phase rollup
...
Phase 0 audit (superpowers:code-reviewer + general-purpose) returned FAIL
on shared findings. This commit resolves the blockers + important items.
Blockers:
- infra/docker/vite.prod: replace 'react-scss/' COPY paths with 'frontend/'
(would have broken 'docker compose build nginx')
- Delete backend/Dockerfile (broken template debris referencing deleted
cmd/api, missing migrations/, deleted keys/)
- Delete backend/Justfile (docker compose recipes pointed at deleted
backend/compose.yml + backend/dev.compose.yml; project-root justfile
[backend] group covers everything operationally)
- backend/internal/admin/handler.go: strip the residual JWT/auth scaffolding
(AuthService interface, authSvc field, authenticator+adminOnly mw params).
Phase 12 will gate /admin under OperatorBearer; for now RegisterRoutes
takes only chi.Router.
- Delete backend/.env + backend/.env.example: stale template duplicates
containing only template keys; project-root .env.example is the source
of truth per spec §12.4.
Important:
- Add © glyph to file headers in cloudflared.compose.yml, infra/docker/
vite.{dev,prod}, backend/.gitignore (operator's standing rule:
'©AngelaMos | 2026', not 'AngelaMos | 2026')
- backend/.gitignore: drop stale 'keys/*.pem' / 'keys/*.key' entries
(backend/keys/ no longer exists)
- scripts/init.sh: rename 'local_tmp' variable to 'tmp_dir' to remove
visual ambiguity with the 'local' bash keyword (both audit agents
briefly misread it as 'local local_tmp=...')
- .env.example: add inline comment explaining the dual NGINX_HOST_PORT
defaults (22784 prod compose, 58495 dev compose; do not override in
shared .env)
Deferred (logged but not blocking Phase 0):
- Pre-existing template Go files (internal/{config,core,server,health,
middleware/{request_id,logging,headers,ratelimit},admin}/*.go) carry
'// AngelaMos | 2026' without ©. Bulk-fixing these belongs to a
hygiene pass; not Phase 0 scope.
- frontend/vite.config.ts and frontend/stylelint.config.js reference
'2025'; operator-imported template files, separate concern.
- APP_ENVIRONMENT vs ENVIRONMENT spec/impl mismatch: spec §12.1 sample
uses APP_ENVIRONMENT; envKeyMap in config.go uses ENVIRONMENT (template
default). Implementation is internally consistent. Logged in plan
Appendix C as a non-blocking spec amendment candidate.
Verification: go build ./... + go vet ./... clean. grep returns no
hits for react-scss / carterperez-dev/templates / JWTConfig /
InvalidateAllSessions across backend/, infra/, scripts/, compose files.
2026-05-10 05:37:32 -04:00
CarterPerez-dev
a4811d1c04
feat(canary): import operator's React + Vite frontend template
...
Frontend stack (pre-rebranded by operator before Phase 0):
- React 19 + react-router-dom v7
- TypeScript 5.9 with project references
- Vite 7 (rolldown-vite — Rust port)
- TanStack Query v5 + axios for data
- Zustand v5 for client state
- Zod v4 for runtime validation
- SCSS (Sass), not Tailwind — operator stylistic choice
- Biome 2 (lint + format), Stylelint for SCSS
- react-error-boundary, sonner (toasts)
- react-icons
Source layout (operator-authored skeleton):
- src/App.tsx, main.tsx, config.ts, styles.scss
- src/api/{hooks,types,index.ts} TanStack Query hooks
- src/components/ UI primitives (operator-designed later)
- src/core/{api,app,lib} axios client, routers, utilities
- src/pages/ page-level containers
- src/styles/ SCSS partials
Per implementation plan §16.3, Phase 14 stops at API client only —
operator owns visual/component design from there.
Pre-commit hooks fixed:
- site.webmanifest: missing trailing newline
- index.html: trailing whitespace stripped
- .stylelintignore + stylelint.config.js: chmod -x (no shebang, not executable)
node_modules/ is gitignored.
2026-05-10 05:28:09 -04:00
CarterPerez-dev
a2d6f09ab3
feat(canary): add project-root .env.example + idempotent init.sh
...
.env.example covers every env var the canary stack reads:
- Public: APP_NAME, NGINX_HOST_PORT, PUBLIC_BASE_URL, VITE_APP_TITLE, VITE_API_URL
- Anti-bot: TURNSTILE_SITE_KEY/SECRET + VITE_TURNSTILE_SITE_KEY (frontend mirror)
- Operator: OPERATOR_TOKEN (admin endpoints)
- DB: POSTGRES_PASSWORD + POSTGRES_DEV_PORT
- Cache: REDIS_DEV_PORT
- GeoIP: MAXMIND_ACCOUNT_ID/LICENSE_KEY (optional)
- Webhooks: WEBHOOK_HMAC_SECRET (optional)
- Fake MySQL: MYSQL_FAKE_ENABLED + MYSQL_HOST_PORT (optional, off by default)
- Logging: LOG_LEVEL, LOG_FORMAT
- Telemetry: OTEL_ENABLED, OTEL_EXPORTER_OTLP_ENDPOINT + Jaeger ports
- Tunnel: CLOUDFLARE_TUNNEL_TOKEN (for cloudflared.compose.yml)
scripts/init.sh rewritten as idempotent setup helper:
- Copies .env.example -> .env on first run
- Generates POSTGRES_PASSWORD + OPERATOR_TOKEN via openssl rand -hex 32 if blank
- Skips already-set values (idempotent)
- Conditionally fetches GeoLite2-City.mmdb when MAXMIND creds present
- All sed usage is operator-side (script run-time), not Claude tool-time
scripts/randomize-ports.sh kept as-is (operator helper for spinning up
sibling projects on non-conflicting ports).
2026-05-10 05:27:30 -04:00
CarterPerez-dev
369c954892
feat(canary): unified Justfile with frontend + backend + compose groups
...
Replaces template Justfile (which referenced ./react-scss/). Groups:
[frontend] pnpm install/dev/build/preview, biome, stylelint, tsc
Targets at fe-install/fe-dev/fe-build/fe-preview prefixed for clarity
[backend] go mod tidy, vet, golangci-lint, test (unit + integration tags),
coverage HTML, run, static build, air hot reload
[lint] lint = be-lint + biome + stylelint + tsc; ci = lint + test
[compose] docker compose lifecycle for prod (up/start/down/stop/build/logs/ps)
[tunnel] overlay with cloudflared.compose.yml for prod+tunnel
[dev] docker compose lifecycle for dev.compose.yml
[util] init (gen secrets + fetch GeoLite2), ports, info, clean
Justfile parses cleanly via 'just --list'. Frontend dir reference fixed
(now ./frontend, not ./react-scss).
2026-05-10 05:25:27 -04:00
CarterPerez-dev
a5c8d17134
feat(canary): add canary.dev + canary.prod Dockerfiles + import infra/
...
Production Dockerfile (infra/docker/canary.prod):
- Multi-stage: golang:1.25-alpine builder → distroless/static:nonroot final
- CGO_ENABLED=0, -trimpath, -ldflags='-s -w' → minimal static binary
- Embeds config.yaml; runs as nonroot user
- ENTRYPOINT /canary, CMD -config /config.yaml
- EXPOSE 8080
Development Dockerfile (infra/docker/canary.dev):
- golang:1.25-alpine + air-verse/air for hot reload
- Source bind-mounted by dev.compose.yml; .air.toml drives rebuilds
- go mod download cached at image-build time, dep refresh at runtime if changed
- EXPOSE 8080
Also imports the rest of the template's infra/ that was untracked:
- infra/docker/vite.dev + vite.prod (existing, unchanged)
- infra/nginx/{nginx.conf, dev.nginx, prod.nginx, nginx.prod.conf}
These will be extended in Phase 15 with /api, /c, /k upstream blocks.
2026-05-10 05:24:42 -04:00
CarterPerez-dev
8b70bfbba9
chore(canary): merge backend compose into project root
...
Single project-root compose.yml + dev.compose.yml manage all services.
Production stack (compose.yml):
- nginx public ingress on \${NGINX_HOST_PORT:-22784}:80
- canary Go backend, NO host port (reachable only via nginx)
distroless/static:nonroot Dockerfile
healthcheck → /healthz, depends on postgres + redis
- postgres postgres:18-alpine, no host port, named volume pgdata
- redis redis:7-alpine, no host port, named volume redisdata
- (geolite vol) read-only mount /data for GeoLite2-City.mmdb
Dev stack (dev.compose.yml):
- nginx dev ingress on \${NGINX_HOST_PORT:-58495}:80
- frontend Vite HMR on \${FRONTEND_HOST_PORT:-15723}:5173
- canary Air hot-reload (canary.dev Dockerfile, bind-mounts ./backend)
OTel exports to jaeger:4317
- postgres host port \${POSTGRES_DEV_PORT:-5447}:5432 for psql access
- redis host port \${REDIS_DEV_PORT:-6022}:6379 for redis-cli access
- jaeger UI 16686, OTLP gRPC 4317, OTLP HTTP 4318
- volumes gocache + gomodcache speed up rebuilds
All randomized host ports preserved exactly:
22784 (prod nginx), 58495 (dev nginx), 15723 (vite), 5447 (pg dev),
6022 (redis dev), 16686/4317/4318 (jaeger).
Backend has no host port in production: nginx is the single entrypoint.
Cloudflare Tunnel sidecar terminates at nginx:80 via cloudflared.compose.yml.
backend/compose.yml + backend/dev.compose.yml deleted (merged here).
Validation:
- docker compose -f compose.yml config — OK
- docker compose -f dev.compose.yml config — OK
- docker compose -f compose.yml -f cloudflared.compose.yml config — OK
2026-05-10 05:23:55 -04:00
CarterPerez-dev
7fa2861e7a
feat(canary): backend bootstrap — strip JWT/users, rename module, rewrite main
...
Removes the template's JWT auth + user domain (Phase 0 §0.4):
- Deleted backend/internal/auth/ (entire JWT auth domain)
- Deleted backend/internal/user/ (user CRUD domain)
- Deleted backend/keys/ (JWT signing keys directory)
- Deleted backend/internal/middleware/auth.go (Authenticator + RequireAdmin)
- Deleted Justfile generate-keys recipe (no JWT keys to generate)
- Removed lestrrat-go/jwx/v3 + transitive deps via go mod tidy
- Stripped JWTConfig type, defaults, env mappings, validators from config.go
- Removed jwt: section from config.yaml
- Removed JWT_* lines from backend/.env and .env.example
Renames Go module to project-local path (Phase 0 §0.5):
github.com/carterperez-dev/templates/go-backend
→ github.com/CarterPerez-dev/cybersecurity-projects/canary-token-generator/backend
- Rewrote imports in 6 remaining .go files using Edit tool (NEVER sed per repo rule)
- Updated .golangci.yml local-prefixes + gci section ordering
Renames cmd/api → cmd/canary and rewrites main.go (Phase 0 §0.6):
- mv cmd/api cmd/canary
- Rewrote cmd/canary/main.go as canary bootstrap (config, telemetry, db,
redis, middleware chain, health, /api stub) — no auth wiring
- Updated .air.toml cmd path
- Updated backend/Justfile run/build targets to cmd/canary + bin/canary
- Renamed docker-build image tag to canary-token-generator:latest
Rebrands defaults:
- config.go: app.name "Go Backend" → "Canary Token Generator"
- config.go: otel.service_name "go-backend" → "canary-token-generator"
- config.yaml: app.name "Go Backend Template" → "Canary Token Generator"
- backend/.env(.example): OTEL_SERVICE_NAME → canary-token-generator
Drops user-aware rate-limit helpers from middleware/ratelimit.go:
- Removed KeyByUser, KeyByUserAndEndpoint, normalizeEndpoint, isUUID, isNumeric
- Removed TierConfig, DefaultTiers, TieredRateLimiter (referenced GetUserID)
- KeyByIP, NewRateLimiter, PerMinute/PerSecond/PerHour preserved
Verification:
- go build ./... — clean
- go vet ./... — clean
- go mod tidy — silent (deps consolidated)
- grep -r "carterperez-dev/templates|JWTConfig|JWT_PRIVATE|lestrrat" → empty
backend/compose.yml + backend/dev.compose.yml are still present here; they
get merged into project-root compose files in Task 0.7 (next commit).
2026-05-10 05:22:08 -04:00
CarterPerez-dev
382890cb56
chore(canary): rebrand from no-auth-template to canary-token-generator
...
- compose.yml: APP_NAME default → canary-token-generator
- dev.compose.yml: APP_NAME default → canary-token-generator
./react-scss bind paths → ./frontend (template flatten)
- cloudflared.compose.yml: APP_NAME default → canary-token-generator
- VITE_APP_TITLE default in both compose files → "Canary Token Generator"
Frontend package.json and index.html were already rebranded by operator
between sessions. All three compose stacks now validate via docker compose
config (prod, dev, prod+tunnel overlay).
2026-05-10 05:15:09 -04:00
CarterPerez-dev
5ccabe00b5
chore(canary): expand project .gitignore for Go + Node + secrets
...
- Ignore docs/ (dev-only planning material)
- Ignore env files except .env.example
- Ignore backend Go build/test artifacts (bin, tmp, coverage)
- Ignore frontend Node + Vite caches and dist
- Ignore local data volumes (geoip mmdb, sqlite databases)
- Ignore OS/editor cruft and lint caches
2026-05-10 05:13:19 -04:00
Carter Perez
8680e684d6
Update README.md
2026-05-10 01:53:25 -04:00
dependabot[bot]
ca3d45bf63
chore(deps): bump gitpython
...
Bumps [gitpython](https://github.com/gitpython-developers/GitPython ) from 3.1.47 to 3.1.50.
- [Release notes](https://github.com/gitpython-developers/GitPython/releases )
- [Changelog](https://github.com/gitpython-developers/GitPython/blob/main/CHANGES )
- [Commits](https://github.com/gitpython-developers/GitPython/compare/3.1.47...3.1.50 )
---
updated-dependencies:
- dependency-name: gitpython
dependency-version: 3.1.50
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-09 03:15:11 +00:00
dependabot[bot]
5b01af8277
chore(deps): bump python-multipart
...
Bumps [python-multipart](https://github.com/Kludex/python-multipart ) from 0.0.26 to 0.0.27.
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27 )
---
updated-dependencies:
- dependency-name: python-multipart
dependency-version: 0.0.27
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 12:23:40 +00:00
dependabot[bot]
27cbd67d01
chore(deps): bump mako in /PROJECTS/advanced/bug-bounty-platform/backend
...
Bumps [mako](https://github.com/sqlalchemy/mako ) from 1.3.11 to 1.3.12.
- [Release notes](https://github.com/sqlalchemy/mako/releases )
- [Changelog](https://github.com/sqlalchemy/mako/blob/main/CHANGES )
- [Commits](https://github.com/sqlalchemy/mako/commits )
---
updated-dependencies:
- dependency-name: mako
dependency-version: 1.3.12
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 12:21:25 +00:00
dependabot[bot]
606034ee2c
chore(deps): bump python-multipart
...
Bumps [python-multipart](https://github.com/Kludex/python-multipart ) from 0.0.26 to 0.0.27.
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27 )
---
updated-dependencies:
- dependency-name: python-multipart
dependency-version: 0.0.27
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 12:15:41 +00:00
dependabot[bot]
3d6eee8627
chore(deps): bump python-multipart
...
Bumps [python-multipart](https://github.com/Kludex/python-multipart ) from 0.0.26 to 0.0.27.
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27 )
---
updated-dependencies:
- dependency-name: python-multipart
dependency-version: 0.0.27
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 12:00:07 +00:00
dependabot[bot]
a3f438d786
chore(deps): bump mako in /PROJECTS/advanced/encrypted-p2p-chat/backend
...
Bumps [mako](https://github.com/sqlalchemy/mako ) from 1.3.10 to 1.3.12.
- [Release notes](https://github.com/sqlalchemy/mako/releases )
- [Changelog](https://github.com/sqlalchemy/mako/blob/main/CHANGES )
- [Commits](https://github.com/sqlalchemy/mako/commits )
---
updated-dependencies:
- dependency-name: mako
dependency-version: 1.3.12
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 11:57:37 +00:00
dependabot[bot]
8e8e2ab987
chore(deps): bump python-multipart
...
Bumps [python-multipart](https://github.com/Kludex/python-multipart ) from 0.0.26 to 0.0.27.
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27 )
---
updated-dependencies:
- dependency-name: python-multipart
dependency-version: 0.0.27
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 11:47:03 +00:00
Carter Perez
d6c4fb7b4b
Merge pull request #211 from CarterPerez-dev/fix/lints
...
fix: resolve CI lint failures across frontend and Go projects
2026-05-08 06:45:00 -04:00
CarterPerez-dev
7d69339413
fix: extract osv package string literals to constants
...
goconst counts occurrences across the whole package (including test files)
when deciding whether to flag a non-test file — the exclusion only suppresses
reports FROM test files. Add unexported constants for severity levels, CVSS
types, ecosystem, and reference types in client.go, and update client_test.go
to use them so the total raw-string count per literal drops below threshold.
2026-05-08 06:30:08 -04:00
dependabot[bot]
063a1ca222
chore(deps): bump mako in /PROJECTS/advanced/ai-threat-detection/backend
...
Bumps [mako](https://github.com/sqlalchemy/mako ) from 1.3.11 to 1.3.12.
- [Release notes](https://github.com/sqlalchemy/mako/releases )
- [Changelog](https://github.com/sqlalchemy/mako/blob/main/CHANGES )
- [Commits](https://github.com/sqlalchemy/mako/commits )
---
updated-dependencies:
- dependency-name: mako
dependency-version: 1.3.12
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 10:29:08 +00:00
Carter Perez
5b3dfaf443
Merge pull request #214 from CarterPerez-dev/dependabot/npm_and_yarn/PROJECTS/advanced/ai-threat-detection/frontend/axios-1.15.2
...
chore(deps): bump axios from 1.15.0 to 1.15.2 in /PROJECTS/advanced/ai-threat-detection/frontend
2026-05-08 06:26:05 -04:00
Carter Perez
0044be7b51
Merge pull request #215 from CarterPerez-dev/dependabot/npm_and_yarn/PROJECTS/intermediate/api-security-scanner/frontend/axios-1.15.2
...
chore(deps): bump axios from 1.15.0 to 1.15.2 in /PROJECTS/intermediate/api-security-scanner/frontend
2026-05-08 06:25:57 -04:00
Carter Perez
c51e7c20e8
Merge pull request #216 from CarterPerez-dev/dependabot/npm_and_yarn/PROJECTS/advanced/monitor-the-situation-dashboard/frontend/axios-1.15.2
...
chore(deps): bump axios from 1.15.0 to 1.15.2 in /PROJECTS/advanced/monitor-the-situation-dashboard/frontend
2026-05-08 06:25:49 -04:00
Carter Perez
cdb94405dc
Merge pull request #213 from CarterPerez-dev/dependabot/pip/PROJECTS/intermediate/api-security-scanner/backend/python-multipart-0.0.27
...
chore(deps): bump python-multipart from 0.0.26 to 0.0.27 in /PROJECTS/intermediate/api-security-scanner/backend
2026-05-08 06:25:03 -04:00
CarterPerez-dev
25671b4f9d
fix: resolve simple-vulnerability-scanner goconst failures
...
Migrate .golangci.yml from v1 issues.exclude-rules to v2
linters.exclusions.rules — the v1 key was silently ignored by golangci-lint
v2, so test-file goconst exclusions weren't applied. With the config fixed,
all test-file violations disappear. Extract severity constants in output.go
to fix the 4 remaining non-test goconst violations (CRITICAL/HIGH/MODERATE/
LOW each appear 3x in severityRank, severityBreakdown, and severityColorFn).
2026-05-08 06:21:26 -04:00
dependabot[bot]
d5fc3a8818
chore(deps): bump axios
...
Bumps [axios](https://github.com/axios/axios ) from 1.15.0 to 1.15.2.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.15.0...v1.15.2 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.15.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 10:08:36 +00:00
dependabot[bot]
39c6df50df
chore(deps): bump axios
...
Bumps [axios](https://github.com/axios/axios ) from 1.15.0 to 1.15.2.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.15.0...v1.15.2 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.15.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 10:02:21 +00:00
dependabot[bot]
45d4bc9993
chore(deps): bump axios
...
Bumps [axios](https://github.com/axios/axios ) from 1.15.0 to 1.15.2.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.15.0...v1.15.2 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.15.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 09:54:42 +00:00
dependabot[bot]
369d227380
chore(deps): bump python-multipart
...
Bumps [python-multipart](https://github.com/Kludex/python-multipart ) from 0.0.26 to 0.0.27.
- [Release notes](https://github.com/Kludex/python-multipart/releases )
- [Changelog](https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md )
- [Commits](https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27 )
---
updated-dependencies:
- dependency-name: python-multipart
dependency-version: 0.0.27
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 09:54:40 +00:00
Carter Perez
89d6d671d2
Merge pull request #206 from CarterPerez-dev/dependabot/go_modules/PROJECTS/advanced/monitor-the-situation-dashboard/backend/github.com/jackc/pgx/v5-5.9.2
...
chore(deps): bump github.com/jackc/pgx/v5 from 5.7.2 to 5.9.2 in /PROJECTS/advanced/monitor-the-situation-dashboard/backend
2026-05-08 05:48:35 -04:00
Carter Perez
e51ef4b857
Merge pull request #209 from CarterPerez-dev/dependabot/npm_and_yarn/PROJECTS/advanced/bug-bounty-platform/frontend/axios-1.15.2
...
chore(deps): bump axios from 1.15.0 to 1.15.2 in /PROJECTS/advanced/bug-bounty-platform/frontend
2026-05-08 05:48:28 -04:00
Carter Perez
c205152638
Merge pull request #210 from CarterPerez-dev/dependabot/npm_and_yarn/PROJECTS/intermediate/binary-analysis-tool/frontend/axios-1.15.2
...
chore(deps): bump axios from 1.15.0 to 1.15.2 in /PROJECTS/intermediate/binary-analysis-tool/frontend
2026-05-08 05:48:21 -04:00
Carter Perez
12eef419dc
Merge pull request #212 from CarterPerez-dev/dependabot/npm_and_yarn/PROJECTS/intermediate/siem-dashboard/frontend/axios-1.15.2
...
chore(deps): bump axios from 1.15.0 to 1.15.2 in /PROJECTS/intermediate/siem-dashboard/frontend
2026-05-08 05:48:10 -04:00
Carter Perez
a05c3f1467
Merge pull request #207 from CarterPerez-dev/dependabot/npm_and_yarn/PROJECTS/advanced/honeypot-network/frontend/axios-1.15.2
...
chore(deps): bump axios from 1.15.0 to 1.15.2 in /PROJECTS/advanced/honeypot-network/frontend
2026-05-08 05:47:09 -04:00
CarterPerez-dev
5863be7dac
fix: pin pnpm to v10 in CI and add .npmrc to all frontend projects
...
pnpm latest on Node 22 resolves to pnpm 11 which rejects lockfileVersion
9.0 lockfiles with ERR_PNPM_LOCKFILE_CONFIG_MISMATCH. Pinning to pnpm 10
keeps compatibility with existing lockfiles. .npmrc sets
strict-dep-builds=false so build-script warnings don't hard-fail the
frozen install.
2026-05-08 05:46:38 -04:00
dependabot[bot]
651997aa3a
chore(deps): bump axios
...
Bumps [axios](https://github.com/axios/axios ) from 1.15.0 to 1.15.2.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.15.0...v1.15.2 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.15.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 09:45:39 +00:00
CarterPerez-dev
adeec9b36d
fix: resolve CI lint failures across frontend and Go projects
...
Node.js bumped to 22 in lint workflow (pnpm 11.x requires >=22.13).
Extract goconst-flagged string literals in secrets-scanner to named
constants. Carry along monitor-dashboard docker/package fixes.
2026-05-08 05:40:04 -04:00
dependabot[bot]
e51e0ad05d
chore(deps): bump axios
...
Bumps [axios](https://github.com/axios/axios ) from 1.15.0 to 1.15.2.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.15.0...v1.15.2 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.15.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 09:05:26 +00:00
dependabot[bot]
75b0cac000
chore(deps): bump axios
...
Bumps [axios](https://github.com/axios/axios ) from 1.15.0 to 1.15.2.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.15.0...v1.15.2 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.15.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 09:04:07 +00:00
Carter Perez
ca8382482b
Merge pull request #208 from CarterPerez-dev/project/monitor-the-situation-dashboard
...
add learn folder to IM MONITORING THE SITUATION DASHBOARD project
2026-05-08 04:55:09 -04:00
dependabot[bot]
fb7e00f90e
chore(deps): bump axios in /PROJECTS/advanced/honeypot-network/frontend
...
Bumps [axios](https://github.com/axios/axios ) from 1.15.0 to 1.15.2.
- [Release notes](https://github.com/axios/axios/releases )
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md )
- [Commits](https://github.com/axios/axios/compare/v1.15.0...v1.15.2 )
---
updated-dependencies:
- dependency-name: axios
dependency-version: 1.15.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
2026-05-08 08:51:09 +00:00
CarterPerez-dev
1b9fcbac13
add learn folder to IM MONITORING THE SITUATION DASHBOARD project
2026-05-08 04:43:29 -04:00