Repository navigation
build(deps): bump morgan from 1.11.0 to 1.12.1 - #32
Open
dependabot[bot] wants to merge 41 commits into
Open
dependabot[bot] wants to merge 41 commits into
dependabot[bot] wants to merge 41 commits into
Conversation
Place 512px line icons beside each Why card title, themed via CSS mask. Co-authored-by: Cursor <cursoragent@cursor.com>
Hero: sharper copy ("structured steps … Written for the humans. Loved by the
AI agents.") and a second ghost CTA ("Read the handbook") in a flex
.banner-actions row. Footer: muted section headings, text-tone links (less
accent). New .banner-cta-ghost + tokens already defined.
Sessions refresh PROACTIVELY (shell rotates the cookie on boot when refreshDue, while still valid); the 401->refresh->retry is only a best-effort fallback and can't refresh an already-expired cookie. The old comment overstated it. (Re-stamps the portal module graph — content-hash token changed.)
Hero goes from a 2-column grid to a stacked flex column (text over visual, centered links) at all sizes — simpler and consistent; H1 wraps "Not a typical / framework". Drops the grid template + its responsive overrides.
friendlyApiError now surfaces an authored 403 detail (e.g. the sign-up allowlist denial, "account not active") instead of the generic "Not allowed right now.", falling back to generic only for a bare code / no message. Pairs with the machine-api registration allowlist.
Hero copy expanded (properties, behavior models, combinatorial + autonomous exploration); banner is full-viewport only on desktop (>=992px), hugs content on mobile. Code-typing animation is now opt-in per panel via .index-code-animate (added to the Write + steps code panels) instead of auto-detecting test.py.
Account dashboard gains a Devices panel: lists active login sessions (device
label from User-Agent — Chrome/Safari/macOS/iOS/"machine CLI on <host>", IP,
last-active, signed-in, this-device flagged) via GET /account/devices, with a
per-row Sign out (DELETE /account/devices/{session_id}); revoking the current
device clears the session hint and returns to login. api.getDevices/revokeDevice;
new account/devices.js; nav option + sidebar link + panel.
Lowercase "handbook" in the CTAs (home/about/footer), shorten a blog CTA, and a round of grammar fixes in the handbook intro (allowing you to…, across, becomes, "If a test fails", "use your browser's back button", …). Regenerated docs/.
parseDt treated the API's naive UTC datetimes as LOCAL (new Date on a bare timestamp), skewing every "ago" by the viewer's offset — all rows read "just now" on a machine behind UTC. Treat naive as UTC (matches CLI/TUI _parse_dt). Also: portal-dev now forwards User-Agent so a browser login through the dev proxy is captured with the real device label, not "Python-urllib".
secondsUntil() parsed the API's naive UTC expires_at with Date.parse (LOCAL), skewing the session-hint cookie Max-Age by the viewer's offset. Treat naive as UTC, matching the parseDt fix. Last spot in the portal that parsed an API timestamp as local — sweep complete.
Bring the portal activity table to parity with the CLI statement: add Rate, Duration, Cost, Period columns mirroring client/core/transactions.py (_rate/_duration/_cost/_period), reusing compactDatetime/elapsed/duration/eur. All timestamp cells route through the (UTC-fixed) format helpers.
Add a pager to the activity panel: probe page-size + 1 to detect a following page, Previous/Next step by offset, "Showing N–M" label, and a filter or page-size change resets to the first page. Rename the "Limit" control to "Page size". Keep the dense statement rows from wrapping (.portal-table--activity) with horizontal scroll on the wrap.
…ur client Parse the OS off the machine-cli User-Agent so the CLI shows "Client on Linux" (parallel to "Chrome on Linux"; Darwin -> macOS), and drop the stale python-* mapping so a browser is never labelled "Client". Mark the current row "· current" (was "· this session"). Update the portal-dev comment to match.
Portal side of the account-list pagination (Machine offset API deployed as 260802-g7c296f9), plus the account-dashboard UX refactor done alongside it: - Pagination: one shared Previous/Next pager (pager.js) on Activity, Orders, and Invoices via a limit+1 has-next probe; Invoices surfaces an explicit note when Stripe's scan ceiling is hit. The pager disables its buttons while a page loads, so a double-click can't skip a page. - Busy indicator: the Refresh button spins for account work; pages without it (login/signup) get an inline status spinner. Reduced-motion safe. - Section chrome (title/lead) painted before fetches so it shows immediately. - Shared empty-state row (table.js); no misleading "empty" flash before load. - Shell no longer blocks list views on getAccount. - Layout: drop the Bootstrap .container on the dashboard; device panel header tidy; "Client on <OS>" labels with the "· current" marker.
…homepage typewriter) Respect the OS "reduce motion" setting across the three site animations: - Handbook "Back to top": instant scroll under reduced-motion (was always smooth). - Contact step-2 reveal: skip the slide/fade (element stays visible — it has display:block and default opacity:1, so animation:none leaves it shown). - Homepage test.py typewriter: reverse the old opt-out and honor prefers-reduced-motion, showing the static final content instead of animating. Regenerated only the affected pages (cache-bust ?v bumped where the changed assets are linked); unrelated pages' timestamps left untouched.
…h on mobile Desktop: cap the wide table panels (activity/orders/invoices/devices/keys) at `100vw - sidebar` instead of a 75vw heuristic that could overflow, and raise the ceiling to 80rem. Mobile: mirror the desktop :has() selector list so the override is specificity-matched and actually wins, letting tables use the full width.
…wording - Prefix each row with a device-kind icon (desktop / web / unknown) via a new deviceLabelCell. - Add a "sign out everywhere" block that revokes all sign-in tokens (logout(everywhere=true)), then clears the local session and redirects; non-401 failures fall back to a local sign-out + delayed redirect. - Reword the per-row action to "Revoke" and add a "Showing 1–N of N" summary. - CSS: table-in-block styling, sign-out-everywhere row, device-label icon, and reuse .portal-pager-label for the summary without disturbing the pagers.
renderBuy now takes the account and fetches it alongside the catalog: the plan matching account.tier renders as "Subscribed" (accent badge + dimmed card, no Subscribe button), and the fetched account is shared back via ctx.onAccount. Make the plans/packs section wrappers borderless so the product cards aren't nested cards-in-a-card.
Billing panel: replace the flat button grid + free-text plan input with structured action rows and modal flows — a Plan section (current plan + period-ends, Upgrade/Downgrade/Cancel gated on a paid tier; switch targets computed from the catalog by tier rank and picked via a radio modal) and a Billing portal section. New modal.js (runConfirm / runPlanPick) with Escape + backdrop dismiss and a Tab focus-trap; the two dialogs live in account.md. Buy: show each plan's price (EUR / month) from the catalog, not only its included credits. Upgrade/Downgrade buttons disable during load so a double-click can't re-open the shared dialog.
Buy: subscribing to a plan you already differ from now routes correctly — a plan above your current tier is an Upgrade and one below is a Downgrade (through the Stripe portal; a fresh Subscribe 409'd "conflicts with the current state"); no paid plan yet stays a plain Subscribe. Extract the shared tier-rank helper (plans.js) used by billing.js and buy.js. Status dock: wrap a long message to two lines (line-clamp) instead of truncating to one.
New static /machine/portal/purchase/ page for CLI/TUI buyers (their browser has no portal session): shows Payment received / Checkout cancelled / All set from ?status, with a Sign In button. Account boot reads ?purchase=success|cancelled (browser buyers), shows a status note, and scrubs the param (boot already reloads fresh). Pairs with the API return-URL change.
- Account: sync pre-paint auth gate (portal_auth_gate → head.ejs) redirects to login before the dashboard can flash. - Modal: stacking guard, focus save/restore, danger focuses Cancel, dismissOnly single-OK mode for info dialogs, focus-trap excludes hidden nodes. - Billing: panel-wide setBusy (disable every action button during an op, keeping unpaid buttons base-disabled); no-lower-plan downgrade routes to cancel-at-period-end; "Credits renew" copy. - Buy: setBusy across product buttons; refreshAfterPurchase keeps Subscribed/Upgrade labels current after a purchase. - Devices: styled runConfirm instead of window.confirm.
Move the four TestFlows Machine legal docs (Terms of Service, Privacy Policy, Acceptable Use, Usage Credit) from machine-api /legal onto testflows.com/machine/legal/* (frontmatter + rewritten cross-links). Add site legal under /legal/*: Website Terms of Use, Privacy Policy, and Copyright and Content Use — written as succinct prose in the Machine docs' style (no bullet lists, no em-dashes), scoped to the site and cross-linking the Machine service legal. Footer gains Terms/Privacy/Copyright links; the contact form's privacy line now links to /legal/privacy/. The three /legal/* site docs are drafts pending legal review. Repointing the Stripe/client legal links and a machine-api /legal redirect are a follow-up.
…re-release
Follow-up to the legal restructure:
- Site Terms §8 governing law: name Ontario + federal Canada (match Machine ToS)
- Machine AUP: add §3 Prohibited technical use (malware/C2, scanning/DoS,
open relays, cryptomining, CSAM); scoped to outward abuse so it doesn't
repeat §4 Platform integrity. Bump AUP date to 2 Aug.
- Site Privacy: add §4 International transfers (SCCs where required)
- Add /machine/legal/ index hub linking the four Machine docs (no Machine
landing page yet)
- Machine not released: drop the three site-legal -> machine-legal hyperlinks,
keep the carve-out prose ("governed by its own separate terms"). Machine
legal stays published but unlinked from the public site.
- Copy: "cloud service" -> "service" across all legal docs (product name
already disambiguates)
Machine (portal, purchase, legal) has not launched. Its pages resolve by direct URL for checkout and CLI links, but must not be advertised to search engines. hexo-generator-sitemap has no path-glob exclude (its skip_render list would stop the pages rendering entirely), and mutating page.sitemap in before_generate is lost because Warehouse hands the generator fresh Page instances. So a scripts/ filter post-processes the generated sitemap routes in after_generate — where route.set is the final word before flush — dropping every /machine/ <url> block and txt line. Delete the script when Machine launches.
… page - New `legal` layout (themes/.../legal.ejs + legal.css): every legal page gets a sidebar rail listing its family's docs (Website vs Machine, via `legal_family`), with active-state (aria-current) and a Machine->Website back-link. Machine pages still carry no inbound link from the public site. - Legal index pages: new /legal/ (site) and reworked /machine/legal/ hubs. - Contact blocks collapsed to "Katteli Inc." + emails — street address and location removed everywhere (registered office is already public record; keeps postal-spam surface off the site). Governing-law/jurisdiction references kept. - Copyright-infringement notices now route to legal@ (was abuse@); abuse@ stays the AUP/network-abuse channel. - Footer Company column: single "Legal" link (Credits + per-doc links removed). - Removed the old Credits page (source/credits.md, docs/credits.html). - head.ejs loads legal.css site-wide; sitemap still excludes pre-release /machine/*.
Surface the Machine legal docs in-context where an account is created/entered — the service surface, not the public site. Signup reads "By creating an account you agree to…"; login reads "Use is governed by…". New .portal-legal style (muted, small) matches the portal footer link treatment.
New Sessions panel: name, state (tone-coded), CPUs, class, €/hour, live duration, and accrued cost, with a total row and entry-count summary. Wired into the account nav/select/panels; api.js gains getSessions() (GET /sessions, the full quota-bounded list — no paging). - Extract a shared secondsBetween() into format.js so duration display (elapsed) and accrued cost (cost_so_far) parse a span through one code path and can't disagree. - Harmonize list-panel load-error handling: sessions/activity/invoices/orders now clear the table and surface the error in the status line (matching devices), instead of painting a misleading empty-state label.
Replace native window.confirm() with runConfirm() (danger variant) for delete API key, cancel order, and the two account-close steps — consistent styling and keyboard/focus handling instead of the browser dialog. Extend the portal button styles to .portal-modal: modals render outside .portal-page, so without it the modal's Cancel/OK fall back to Bootstrap .btn and vanish in dark theme.
- login: add a "Resend code" button (sendCode(resend) shares the submit path; distinct "New code sent" status). - api keys: expiry in days, not raw ISO. Create form takes "never"/N days; each key gets Set expiry (prompt → step-up) and Clear expiry (only when set); list shows CLI-parity "when (N days)" via expiresWithDays; secret box gains a Hide button. - modal: add runPrompt() — a validated text-input dialog on the confirm shell, extracted into confirmShell()/bind/unbind so runConfirm and runPrompt share it. - ui: drive the busy indicator off an explicit .portal-status--dock class (dashboard = Refresh icon; login/signup/modals = inline spinner) instead of probing for the Refresh button; modal-local busy no longer spins the page.
…osures The closing panel now uses the AccountCloseProgress it fetches instead of discarding it, and drives teardown the way the CLI does: - Render progress in a block above the actions: "Waiting for N session(s) to stop." or "Waiting for plan cancel to finish." Gate Confirm on `ready` (disabled + tooltip until sessions AND plan cancel are done). Surface portal_url as a Manage billing link (_blank + noopener noreferrer). - Resume teardown: refreshClose POSTs /account/close/start (no code while already closing) — GET only reads, so a GET-only portal could never cancel the plan and stalled subscription accounts. Auto-poll every 5s while closing && !ready, self-cancelling via a document.contains(closeBlock) guard. - Generation token (closeGen) + post-await clear so a late poll can't repaint stale "closing" over a newer state; Cancel invalidates the poll up front and the cancel-failure path re-arms it. - Disclosures match the CLI: start warns work loss / key revocation / plan cancel-at-period-end / 90-day retention; confirm warns sign-out + sign-in disabled; cancel notes revoked keys stay revoked and a still-scheduled plan. - Fix stale "eventually deletes data" copy (soft-close retains).
Replace the action-row rebuild with a fixed 4-step stepper (Stop machines →
Revoke API keys → Cancel plan → Confirm close) built once and patched in place
each poll: step state, detail text, Confirm gate, and billing URL only — focus
stays put while the account closes.
- closePhase() maps AccountCloseProgress to the current step; ready lights the
Confirm step ("Ready when you are.").
- aria-current on the active step; aria-live on each step detail so screen
readers hear progression.
- clearCloseChrome() tears the stepper down on exit (active/closed) and rebuilds
on re-entry; poll/gen/resume/cancel logic unchanged.
solve() fans disjoint nonce subsequences across min(cores, 8) module workers (shared rand, start=i/stride=count, first stamp wins, rest terminated), off the main thread so the step-up spinner stays responsive. Falls back to the yielding loop (solveInline) when Worker is unavailable or construction/onerror fails. - solveRange(): synchronous shard search (no yielding — worker context), with a stride>=1 guard so a bad caller fails loudly instead of hanging. - hashcash.worker.js imports the shared solveRange (single-source hash, mirrors client/api + cloud/api) and carries hashcash.js's ?v= cache key onto the Worker URL so a code change busts both together. - Reuse one TextEncoder in the hash inner loop (was allocated per hash). No server or difficulty change; stamp format is unchanged. Attacker cost is set by difficulty, not the client solver — this is a pure legit-user speedup.
…page machine-api confirm links now redirect to /machine/portal/login/?signup=... or ?email=..., so the login page surfaces the outcome (activated / reopened / email changed / invalid / etc.) via a generic showConfirmStatus() that shows the note in portal-login-status and scrubs the param. Replaces the machine-api HTML success pages.
…edirect The confirm redirect now carries ?addr=<email>, so the sign-in note reads "Your account <email> is activated…" / "Your email is changed to <email>…" and the email field is pre-filled (saved email only fills if still empty). No-addr outcomes keep the generic message.
Redraw the closing-workflow markers with CSS: hollow ring (pending), accent ring + inner disc with a soft pulse (in progress), solid accent + halo (ready), and a filled marker with a trailing check on the label (done). Connecting rail greens only between accent-marked steps via :has(); pulse respects prefers-reduced-motion.
Add the pre-release Machine surface: /machine/ landing page + hero, /machine/contact/ early-access page with a contact form, and the /machine/portal/signup entry. Make the footer surface-aware (isMachineSurface): machine pages get machine Contact/Legal + Create account / Request early access; public pages are unchanged (pip3 install / Read the handbook, /contact.html, /legal/). Nav, hero type animation, and machine.css assets included. /machine stays private / direct-link-only: no public page links into it (footer machine links are gated to machine surfaces) and the whole /machine/* tree remains excluded from the sitemap.
Embed the boot log in the page (data-boot-log) so deploy no longer depends on a gitignored .log fetch, switch the hero to JPEG, and enlarge the terminal overlay slightly.
The homepage Why card masks were clipping (partial circle, open grid frame). Swap in the fixed assets in source and docs.
Bumps [morgan](https://github.com/expressjs/morgan) from 1.11.0 to 1.12.1. - [Release notes](https://github.com/expressjs/morgan/releases) - [Changelog](https://github.com/expressjs/morgan/blob/master/HISTORY.md) - [Commits](expressjs/morgan@1.11.0...1.12.1) --- updated-dependencies: - dependency-name: morgan dependency-version: 1.12.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps morgan from 1.11.0 to 1.12.1.
Release notes
Sourced from morgan's releases.
Changelog
Sourced from morgan's changelog.
Commits
b1272e71.12.1 (#386)4b695edfix: escape double quotes in log fields0f74ecabuild(deps): bump github/codeql-action/analyze from 4.37.4 to 4.37.9 (#384)e399e3cbuild(deps): bump github/codeql-action/init from 4.37.4 to 4.37.9 (#383)1e86b34build(deps): bump github/codeql-action/autobuild from 4.37.4 to 4.37.9 (#382)87c0afdbuild(deps): bump github/codeql-action/upload-sarif to 4.37.9 (#381)286b000test: run CI on Windows and macOS (#379)5a5902adocs: fix typos across documentation (#378)063f0841.12.0 (#376)fbf9383fix: escape all token values in log outputMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for morgan since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.