{"slug":"permit-radar","total":14,"limit":100,"offset":0,"since":null,"commits":[{"hash":"f6cdd9b","date":"2026-08-31 00:00:08 -0700","author":"Steve Abrams","subject":"fail-open guardrail: warn at boot when admin auth is unconfigured (TK-10984 opt-A)","body":""},{"hash":"04e7eeb","date":"2026-08-30 22:58:22 -0700","author":"Steve Abrams","subject":"add creds-in-URL fetch guard to gated pages (TK-10984)","body":""},{"hash":"c3b0ab2","date":"2026-08-25 10:48:58 -0700","author":"Steve","subject":"creds-safe fetch guard: resolve relative fetch vs credential-free location (creds-in-URL trap)","body":"Fleet inoculation — opening this basic-auth app with credentials in the URL\npoisoned document.baseURI and made relative fetch('/api/…') throw. Guard resolves\nnon-absolute request URLs against location instead. Ref: creds-in-url-fetch-guard-fleet-pattern.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>"},{"hash":"d596a1b","date":"2026-08-01 20:16:01 -0700","author":"Steve Abrams","subject":"permit-radar: adopt href-to-deeper-data primitives (TK-10093)","body":""},{"hash":"fdc840b","date":"2026-07-16 08:50:08 -0700","author":"Steve","subject":"shopify: refresh catalog — keep sample-only as 'by request'","body":""},{"hash":"12a1e8e","date":"2026-07-16 08:48:31 -0700","author":"Steve Abrams","subject":"cross-sell strip: use price_display + product_url, prefer buyable products","body":"- /api/shopify-crosssell now returns price_display (pre-formatted string),\n  sample_only, and product_url for each pick instead of raw numeric price\n- Pool is filtered to buyable products first (167 available >> 6 needed),\n  so \"Roll price on request\" cards are suppressed in normal operation\n- Frontend uses esc(p.price_display) — no manual \\$+toFixed() formatting,\n  eliminates any \\$null/\\$NaN risk\n\nCo-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>"},{"hash":"ed3fea7","date":"2026-07-16 08:13:07 -0700","author":"Steve","subject":"shopify: refresh catalog — real roll prices, no $4.25 sample-only leak","body":""},{"hash":"994b444","date":"2026-07-16 08:12:10 -0700","author":"Steve Abrams","subject":"auto-save: 2026-07-16T08:12:03 (1 files) — data/shopify-catalog.json","body":""},{"hash":"633acd7","date":"2026-07-16 07:51:19 -0700","author":"Steve","subject":"security: bind server to 127.0.0.1 so the tunnel/proxy basic-auth gate can't be bypassed on the LAN","body":""},{"hash":"b1dbc23","date":"2026-07-16 07:42:01 -0700","author":"Steve Abrams","subject":"auto-save: 2026-07-16T07:41:55 (1 files) — data/subscribers.json","body":""},{"hash":"e1e9ff1","date":"2026-07-16 07:35:11 -0700","author":"Steve Abrams","subject":"feat: add DW cross-sell strip to index + permit detail pages (links only, no checkout)","body":""},{"hash":"591ba0d","date":"2026-07-16 07:35:06 -0700","author":"Steve Abrams","subject":"feat: copy shopify-catalog.json + add /api/shopify-crosssell read-only endpoint","body":""},{"hash":"de185e8","date":"2026-07-15 17:02:40 -0700","author":"Steve","subject":"permit-radar: full permit directory + lead funnel + admin — working prototype","body":""},{"hash":"f1fb193","date":"2026-07-15 16:53:44 -0700","author":"Steve","subject":"initial scaffold (permit-radar) via web-dev accelerator","body":""}]}