Mfr Review Viewer

repo: ~/Projects/mfr-review-viewer · 5 commits · 0 in last 24h, 0 in last 7d ·

Search the build

5 commits indexed

  1. eb911f0 2026-07-16 Strip hardcoded Shopify API tokens from source (env-first); no rotation/deploy — response to Shopify exposed-credentials notice
  2. 942d742 2026-05-19 SECURITY HOLD — live Shopify shpat_ token committed at server.js:197
  3. 77e2f8b 2026-05-19 add 404-guard middleware for .bak / .pre- snapshot paths
  4. c72578f 2026-05-19 broaden .gitignore to cover .bak.* and .pre-* snapshot files
  5. aacc009 2026-05-06 initial scaffold (gitify-all 2026-05-06)

Authors

Agents used

  • none detected

Skills used

  • /deploy1

Creative ideas + design notes

Commits with substantial prose (≥120 chars) — the rationale behind each move.

942d742 · 2026-05-19 · SECURITY HOLD — live Shopify shpat_ token committed at server.js:197
Token targets designer-laboratory-sandbox (= live prod DW store per MEMORY).
Rotate at Shopify admin BEFORE source fix. This repo is SUSPENDED from the
fleet-refactor-sweep until SECURITY-HOLD.md is removed by Steve.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
77e2f8b · 2026-05-19 · add 404-guard middleware for .bak / .pre- snapshot paths
Defense-in-depth — even though no static root is served today, this
prevents accidental exposure of editor backup files if a static dir
gets added later.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

File tree

5 files tracked. Click any to browse the source at HEAD.

Other build journals

← Metallicwallpaper  ·  all 4 projects  ·  Micawallpaper →

Export

commits.csv · feed.atom · project.json · commits.json

rendered in 1ms