| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
Fix profitability mobile metrics with PostHog | 14 天前 | |
feat(app): phone battery sample v2 — self-contained intervals + schema delivery fix (#21152) * feat(app): phone battery sample v2 — self-contained drain intervals * fix(app): reject clock-corrupted phone battery intervals * fix(app): suspend-inclusive monotonic reference for Android battery intervals | 1 天前 | |
Bump admin dashboard next 13.5.1 → 14.2.35 Closes 13 CVEs flagged on omi-admin-dashboard, including the most severe one in the deployed image: - CRITICAL 9.1 CVE-2025-29927 (middleware auth bypass via spoofed x-middleware-subrequest header — fix at 14.2.25) - HIGH 7.5 CVE-2024-46982 (cache poisoning, fix at 13.5.7) - HIGH 7.5 CVE-2024-34351 (SSRF in next-image, fix at 14.1.1) - HIGH 7.5 CVE-2024-51479 (auth bypass, fix at 14.2.15) - MEDIUM 8.2 CVE-2025-57822 (fix at 14.2.32) - MEDIUM 7.5 CVE-2024-47831 (fix at 14.2.7) - MEDIUM 6.2 CVE-2025-57752 (fix at 14.2.31) - MEDIUM 5.3 CVE-2024-56332 (fix at 13.5.8) - MEDIUM 4.3 CVE-2025-55173 (fix at 14.2.31) - LOW 4.3 CVE-2025-48068 (fix at 14.2.30) - LOW 3.7 CVE-2025-32421 (fix at 14.2.24) - HIGH 0 GHSA-mwv6-3258-q52c (fix at 14.2.34) - HIGH 0 GHSA-5j59-xgg2-r9c4 (fix at 14.2.35) Cascade pins: - eslint-config-next 13.5.1 → 14.2.35 (matched to next major) - @next/swc-wasm-nodejs 13.5.1 → 14.2.33 (latest 14.x for the wasm fallback compiler; 14.2.34/35 were not published for this package) Migration code change: app/login/page.tsx — Next 14 enforces a Suspense boundary around useSearchParams() during static prerender (CSR bailout requirement). Extracted the inner LoginPageContent and wrapped it in <Suspense fallback={<LoadingScreen />}> at the page export. No behavioural change; the existing 'Loading session...' fallback is reused. Pages Router APIs (/api/stats/conversation-count) and the rest of the App Router pages migrate without code changes. Build: green (23 routes prerender). Tests: 16/16 vitest pass. Remaining 4 next CVEs only fix in 15.x and are deferred to PR 3 (App Router params become async — bigger touch). | 5 个月前 | |
feat(admin): Grafana TV share links without admin login (#12505) * feat(admin): Grafana TV share links without admin login Mint revocable /tv/view/<token> kiosk URLs that embed the live omi-tv Grafana board so office TVs skip Firebase login. Manage on /dashboard/tv-links. * fix(admin): show invalid TV kiosk page when Firestore is unavailable Missing Firebase Admin env was 500ing unknown tokens instead of the static error page. * fix(admin): kiosk referrer leak, auth bounce, and junk-token reads Keep the Firebase listener on TV kiosk so returning to /dashboard does not bounce login. Stop sending /tv/view/<token> as the Grafana referrer. Reject non-base64url tokens before Firestore. Own-key platform lookup and keep a newly minted link visible if list refresh fails. | 1 个月前 | |
admin: add public /users page showing total user count Lives outside the (protected) route group, so the admin auth gate doesn't run. Renders just the total user count as a large number — no navigation or links into the admin dashboard. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> | 5 个月前 | |
feat: add admin dashboard pages, API routes, and assets Adds all dashboard pages (apps, analytics, subscriptions, payouts, notifications, etc.), API proxy routes, and public assets. All API routes use lazy initialization for build-time safety. Fixes #6227 Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> | 6 个月前 | |
fix(web/admin): let an owner add an admin who has not signed in to Omi yet "Add new person" on /dashboard/team looked like it did nothing. Two defects stacked: 1. POST /api/omi/team-members keys `adminData/{uid}` on a Firebase Auth user, so an invitee who had never signed in to Omi got a 404 telling the owner to go ask them to sign in first. That is the exact case the button exists for. The route now provisions the uid itself with an unverified, credential-less `createUser({ email, emailVerified: false })`. The project keeps Firebase's default one-account-per-email setting and the reserved account carries no password and no provider, so the invitee's first Google sign-in for that address links into the same uid and the grant is already waiting. A lost race with a concurrent first sign-in falls back to re-reading the now-existing user. 2. No `<Toaster />` was ever mounted, so every `useToast()` call in the dashboard was a no-op. The 404 above, and the success path, and the toasts on organizations/distributors/popular-apps, all rendered nothing at all. Added the viewport component and mounted it in the root layout. Dialog copy no longer claims an Omi account is required, and the success toast tells the owner the invitee signs in with Google. Verification: - `npx vitest run` in web/admin: 39 files, 290 tests pass. Route suite covers provisioning, the concurrent-signup race, and that a failed createUser grants no admin access. - `npx tsc --noEmit -p .` and `npx eslint` on the changed files: clean. - Ran `next dev` against prod Firestore/Auth and drove the real dialog: an already-admin email now shows a visible red "Could not add person" toast (previously invisible), and a never-seen address returned 201, rendered its card, and showed "Person added". The provisioned account read back as providers=[] passwordHash=false, which is the shape that links on a later Google sign-in. Test account and its adminData doc were deleted afterwards. - Prod Cloud Run logs confirm the reported failure: four POSTs to /api/omi/team-members at 2026-09-26T01:16Z, all 404, no UI feedback. Failure-Class: new | 13 天前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 14 天前 | ||
| 1 天前 | ||
| 5 个月前 | ||
| 1 个月前 | ||
| 5 个月前 | ||
| 6 个月前 | ||
| 13 天前 |