Compare commits

...
206 Commits
Author SHA1 Message Date
Hanzo Dev 5981dca439 ci(docker): reduce to sync-notice — native pipeline is .hanzo/workflows/deploy.yml
Image build+push+deploy now runs in-cluster (act_runner + BuildKit → operator).
GitHub is a mirror; this workflow is retained only as a manual sync notice.
2026-07-24 15:14:30 -07:00
Hanzo Dev af73ce21fe ci(deploy): add native Hanzo deploy pipeline (BuildKit → ghcr → operator patch)
Native flow: Hanzo Git push → act_runner → BuildKit builds Dockerfile →
ghcr.io/hanzoai/dataroom:<sha> → kubectl patch app dataroom → operator reconcile.
GitHub Actions reduced to sync-only.
2026-07-24 15:14:20 -07:00
1b4bb4830b feat(goja): self-contained goja bundle — fold dataroom into hanzoai/cloud (#101) (#6)
* feat(goja): self-contained goja bundle — fold dataroom into hanzoai/cloud (#101)

Extract the dataroom business logic into a self-contained, ESM-free goja bundle
(goja/bundle.js) exposing globalThis.handle(req), authored to run verbatim inside
the unified hanzoai/cloud binary (HIP-0106, task #101 / epic #96) — the same
in-process pattern @hanzo/plans and @hanzo/pricing use.

The complete flow — documents (metadata; bytes on the cloud object-storage seam),
data rooms + membership, shareable links (email/allow-list gate + bcrypt password
+ expiry + download toggle), viewers, per-page view analytics — is re-expressed as
a route table over injected host functions (globalThis.db.query/exec bound
per-tenant to Base/SQLite, globalThis.crypto bcrypt helpers). The Prisma models
become CREATE TABLE statements in the bundle's migrate route. No Postgres, no
Next.js; the standalone pod is retired.

cloud/clients/dataroom go:embeds a byte-identical vendored copy (task mandates
go:embed here since this repo is a TS app, not a Go module).

Claude-Session: https://claude.ai/code/session_016yg7GPhYdWCh9vpp4HEwLZ

* goja: run on the shared clients/gojabase RW-Base binding (#101)

Rework the bundle onto the reusable clients/gojabase host contract (the RW-Base
goja binding captable pilots, esign reuses) instead of a bespoke DB binding — one
binding, not two. The bundle now calls __db.query/__db.exec, __newId, __now and
__bcrypt.hash/verify (the leaf's bcrypt HostFn), and handle({route,params,query,
orgId,body}); the per-tenant schema (DDL) moves to the Go leaf where gojabase runs
it on first open, and each dispatch is one per-tenant transaction (commits iff
status<400). No behaviour change to the dataroom flow; README updated.

Claude-Session: https://claude.ai/code/session_016yg7GPhYdWCh9vpp4HEwLZ

---------

Co-authored-by: hanzo-dev <dev@hanzo.ai>
2026-07-10 03:06:43 -07:00
0e31093a74 kv: harden in-process backend — atomic getdel, active expiry, multi-replica doc (#5)
Three RED-blessed non-blocking follow-ups on the KV-optional work.

1. Drop the non-atomic getdel() shim in lib/redis.ts. It shadowed BOTH backends'
   native atomic GETDEL with a get->del pipeline (other commands interleave
   between GET and DEL), reintroducing the one-time login-code double-use race
   that fetchAndDeleteLoginCodeData relies on GETDEL to prevent. ioredis maps
   getdel to the single-round-trip Redis GETDEL command; MemoryKV.getdel now
   reads+deletes in one un-yielded step (was `await this.get()` then delete — the
   await yielded the event loop, letting two racers both observe the value).

2. Bound MemoryKV growth. Lazy on-read eviction never fires for write-once-
   never-read keys (rl:<ip> rate-limit counters, one-shot tokens), so the map
   grew unbounded until the pod OOMKilled. Add sweepExpired() (one O(n) active-
   expire pass) run on an unref'd 60s timer, started by lib/redis.ts for the
   server singleton only (edge-gated; no test imports that module, so unit runs
   stay timer-free). MemoryKV stays pure (zero imports).

3. Document in .env.example that re-enabling multi-replica REQUIRES KV_URL
   (single-replica-by-construction otherwise: SQLite-on-RWO + in-process KV).
   The one-time non-silent in-process warning already exists in lib/kv/select.ts;
   no metrics surface exists, so log + doc is sufficient.

Tests: +3 cases (getdel atomicity under concurrent race; 100k-key sweep reclaims
to 0; sweep retains live/no-TTL keys). 28 pass, 3 skip (select.ts skips without
ioredis in a bare checkout), 0 fail.

Co-authored-by: Hanzo AI <ai@hanzo.ai>
2026-07-07 16:08:16 -07:00
4ed98334f0 KV-optional: run WITH and WITHOUT external Hanzo KV (#4)
* KV-optional: in-process backend when KV_URL unset

Make dataroom run WITH and WITHOUT external Hanzo KV, uniform with commerce
infra/kv.go. KV_URL unset -> in-process MemoryKV (single-replica correct: cache,
rate-limit, tus upload locks, export/download job stores, digest queues all work
with no external datastore). KV_URL set -> external Hanzo KV over ioredis
(multi-replica HA). Malformed KV_URL fails CLOSED (throws) -- never a silent
in-process fallback.

- lib/kv/url.ts: resolveKvUrl -- fail-closed parse, kv:// brand scheme -> redis://
  wire scheme, password redaction in errors.
- lib/kv/memory-kv.ts: in-process ioredis-compatible store (strings+TTL, zset,
  set, hash, list, pipeline) -- the exact surface dataroom uses.
- lib/kv/select.ts: the one backend selector (mirrors NewKVClient/FromURL).
- lib/redis.ts: use createKvClient() for redis + lockerRedisClient; drop the
  redis://localhost:6379 silent default (the WITHOUT-KV break) and vestigial
  REDIS_URL; Upstash-compat shims unchanged.
- Tests (node --test, dep-free): 25 pass proving selection + in-process
  correctness incl NX lock mutual-exclusion, TTL eviction, zset ordering,
  pipeline shape, fail-closed URL, cross-instance isolation (multi-replica
  split-brain contract).

* kv: warn once when falling back to in-process (non-silent split-brain)

Emit a one-time startup warning when KV_URL is unset so the WITHOUT-KV mode is
never silent — a multi-replica deploy with KV_URL unset splits sessions,
rate-limit windows and tus locks across replicas (single-replica only).

---------

Co-authored-by: Hanzo AI <ai@hanzo.ai>
2026-07-07 15:47:14 -07:00
zeekayandClaude Opus 4.8 9921a9a896 fix(db): re-inject Prisma enum objects for the SQLite client
SQLite has no Prisma enums, so removing the enum blocks also dropped the enum
*objects* the app imports from @prisma/client (LinkType.DOCUMENT_LINK, etc.),
crashing Next.js prerender ("Cannot read properties of undefined"). A
build-time step (after `prisma generate`) re-injects the 18 enum objects into
the generated client, so no app files change. Verified: local `next build`
now prerenders all 90 pages.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-05 00:59:54 -07:00
zeekayandClaude Opus 4.8 0aaaa1fa7e feat(db): migrate Prisma datasource postgres -> sqlite (native, file-backed)
Drops the shared sql-0 postgres dependency in favor of an embedded SQLite
file (DATABASE_URL=file:/data/<db>), WAL-replicated to SeaweedFS by the
operator persistence sidecar — same pattern as esign (Documenso).

Schema changes for the sqlite connector:
- datasource provider postgresql -> sqlite; drop directUrl/shadowDatabaseUrl
- 18 enums -> String (values preserved as string defaults)
- scalar-list fields (String[]/Int[]) -> Json @default("[]") (arrays
  round-trip through Prisma Json at runtime; next.config ignoreBuildErrors
  keeps the type-only churn out of the build)
- strip pg-native @db.* attributes (@db.Text/@db.Timestamp)
- startup: prisma migrate deploy -> prisma db push (pg migration history is
  postgres-specific; db push reconciles the sqlite schema idempotently)

CI: amd64-only (DOKS has no arm64); deploy:false — rollout is operator-managed
via the universe Service CR, never `kubectl set image`.

Verified: `prisma validate` + `prisma db push` materialize all 62 tables on a
fresh sqlite file. Source DB is empty (0 app rows), so cutover is data-safe.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-05 00:33:13 -07:00
2952083ef0 build: base on ghcr.io/hanzoai/nodejs:v24.18.0 (Node 24 + sqlite3)
Adopt the canonical Hanzo Node base image. Node 24 uniform across the
fleet; sqlite3 bundled (node:sqlite builtin + native better-sqlite3
toolchain). One base, one way.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-04 12:49:21 -07:00
z af886c00a3 docs(brand): add hero banner 2026-06-28 20:09:09 -07:00
z 99203b41dd chore(brand): dynamic hero banner 2026-06-28 20:09:08 -07:00
Hanzo AI af5811b206 auth: use canonical /v1/iam/oauth/* IAM endpoints (bare /oauth/* hit SPA HTML) 2026-06-25 18:56:05 -07:00
7ec15f6af9 ci: run on self-hosted ARC pool (hanzo-build-linux-amd64/deploy), not GitHub-hosted (#3)
Co-authored-by: zeekay <z@hanzo.ai>
2026-06-19 20:33:48 -07:00
Antje WorringandClaude Opus 4.8 843791d1ee docs: tidy LLM.md indexes; CLAUDE.md -> LLM.md symlink convention
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-17 10:12:19 -07:00
zeekay c404568baf ci: route to canonical native arcd labels [self-hosted, linux, <arch>]
Replaces non-canonical scale-set / org-prefixed labels with the
existing labels every arcd host registers with. Matches evo for
amd64 and spark for arm64. No new labels added.
2026-06-10 20:11:17 -07:00
Hanzo AI 4c1325cca9 ci: retrigger after orphan package deletion (auto-link on first push) 2026-06-08 12:42:42 -07:00
Hanzo AI 5f784733cf ci: retrigger after package linkage (image.source label set) 2026-06-08 09:36:07 -07:00
Hanzo AI 109e9eead2 ci: re-trigger after package claim + spark-hanzo label 2026-06-08 09:23:10 -07:00
Hanzo AI 2705155c2e ci: runner-arm64 → spark-hanzo (the label that's actually online)
The reusable workflow defaults runner-arm64 to spark-hanzoai-arm64,
but that label has zero online registrations on the hanzoai org
runner pool. Spark.local is registered as spark-hanzo (and
spark-hanzobot-arm64) — that's the canonical org-level pool label.
Builds queue forever otherwise.
2026-06-07 16:14:46 -07:00
Hanzo AI 31abfcc2da brand: real Hanzo mark + white-label env hooks
Replace the placeholder H badge with the canonical Hanzo mark (the
abstract H-shape from ~/work/hanzo/logo). Mark renders via
currentColor so it inherits whatever color the parent text sets —
no per-theme variants needed.

White-label is now fully driven by env:

  NEXT_PUBLIC_APP_NAME           full app name ('Hanzo Dataroom')
  NEXT_PUBLIC_APP_NAME_PRIMARY   first wordmark token (default: first
                                 word of APP_NAME)
  NEXT_PUBLIC_APP_NAME_SUFFIX    remainder (default: rest of APP_NAME)
  NEXT_PUBLIC_APP_TAGLINE        sub-line under the welcome headline
  NEXT_PUBLIC_IAM_PROVIDER_NAME  IAM brand for 'Sign in with X' button
  NEXT_PUBLIC_MARKETING_URL      base URL for Terms / Privacy links

Tenants drop in their own NEXT_PUBLIC_APP_NAME='Acme Rooms' and the
whole page reads correctly with no code changes — wordmark + welcome
copy + terms attribution all pick up automatically. The mark itself
stays Hanzo (this IS a Hanzo app); tenants that need their own glyph
swap the HanzoMark import for a custom <img src=BRAND_LOGO_URL />.

Favicons regenerated from the canonical SVG too.
2026-06-07 16:01:01 -07:00
Hanzo AI 617480df3a ui: dark + monochrome + clean centered IAM signin
Login was a split-pane marketing layout with a salmon-pink sign-in
button, light-gray panel, testimonial photo + quote, and 'Trusted by
teams at' sponsor wall. None of that is wanted on a Hanzo property.

Now:
  * Solid black full-screen background, no testimonial panel, no
    sponsor logos.
  * Centered logo + 'Welcome to Hanzo Dataroom' headline + tagline.
  * Monochrome white-on-black 'Sign in with Hanzo' button (bg-white,
    text-black). No red.
  * Terms/Privacy links in zinc-300 underline, body in zinc-400/500.
  * <html class='dark'> on the root layout — dark is the default theme.
  * Favicon swapped to a Hanzo-H mark across all favicon sizes.

The IAM redirect itself is unchanged — signIn('hanzo-iam') still
hands off to NEXT_PUBLIC_IAM_PROVIDER_NAME via NextAuth, so 'Sign in
with Hanzo' is now the only UI surface and IAM owns everything past
the redirect.
2026-06-07 13:20:36 -07:00
Hanzo AI 2cf7f9503e polish: text-based Hanzo Dataroom logo + fix duplicated 'Data Rooms' suffix
Visual cleanups verified via Playwright after first dev run:

  * Replaced the three logo SVGs (light, dark, mark) with text-based
    placeholders that read 'Hanzo Dataroom' / 'H' instead of the
    original Papermark vector wordmarks. Local dev now reads correctly
    in the auth flow; real artwork can drop in by overwriting the
    same files.

  * Removed 'Data Rooms' duplication from the rebrand-sweep
    artifacts. The original copy reads '<brand> Data Rooms' which
    became 'Hanzo Dataroom Data Rooms' after the naive
    Papermark→Hanzo Dataroom substitution. Fixed across:
      - app/(auth)/login/page-client.tsx testimonial
      - app/(auth)/auth/email/[[...params]]/page-client.tsx
      - components/emails/data-rooms-information.tsx
      - components/emails/dataroom-trial-24h.tsx
      - components/welcome/dataroom-trial.tsx
2026-06-07 12:32:31 -07:00
Hanzo AI b827b3a7bd rebrand: Papermark → Hanzo Dataroom across user-facing surfaces
108 files: README, marketing copy, page titles, meta tags, footer
text, email templates, .env.example, UI strings. URLs swapped
from papermark.com/papermark.io to dataroom.hanzo.ai.

Internal identifiers left intact per repo policy: localStorage
keys (papermark.email/papermark.name/last_papermark_login —
changing them logs users out), type field names
(papermarkUserId), internal helper symbols (PAPERMARK_HEADERS,
PapermarkSparkle component, isPapermarkUrl helper),
internal-only filenames. LLM.md retains 'Upstream: Papermark'
attribution line. Per-locale .po translations regenerate from
source on the next lingui-extract CI run.

DB migrations untouched (append-only history; rewriting them
breaks installed schemas). LICENSE stays AGPL-3.0.
2026-06-07 12:23:40 -07:00
Hanzo AI d4f4071ee4 rip: enterprise dirs + paywalls — full AGPL, no commercial-license code
Drop the dual-licensed `ee/` tree entirely. All features previously
locked behind the Hanzo Dataroom Commercial License are now part of the
AGPL-3.0 core and freely available — custom domains, branded viewing,
advanced analytics, watermarks, access controls, Q&A, AI vector stores,
workflows, SAML SSO, dataroom invitations, conversations, templates.

Layout changes:
* `ee/features/{ai,conversations,workflows,permissions,storage,templates,
  dataroom-invitations,access-notifications,security,conversions}/` →
  `features/<name>/` (AGPL).
* `ee/limits/` → `lib/billing/limits/` with every plan resolving to an
  unlimited profile (no users/links/documents/domains/datarooms cap,
  conversations and watermarks always on).
* `ee/stripe/` → `lib/billing/legacy/` (already a compat shim over
  `@hanzoai/commerce`; renewal-reminder webhook is now a no-op).
* `ee/features/billing/cancellation/` deleted. Pause/unpause/cancel/
  retention routes now compile against `lib/billing/cancellation.ts`
  stubs that return 410 Gone; `isTeamPaused`/`isTeamPausedById` in
  `lib/billing/paused.ts` always report active. `CancellationModal` is
  a no-op shim in `components/billing/`.
* `app/(ee)/api/*` route group folded into `app/api/*` (SAML auth,
  SCIM, AI chat, workflows, FAQ, link-upload).

Build: `npm run build` green.
2026-06-07 11:46:48 -07:00
Hanzo AI caf8fa1053 ci: build amd64 + arm64 natively on hanzo runner pools
Reverts the amd64-only narrowing and restores the canonical
multi-arch build per Hanzo's runner topology (RUNNERS.md):
- amd64 leg targets hanzo-build-linux-amd64 (DOKS ARC pool on
  hanzo-k8s, default in the shared docker-build.yml — no caller
  override needed).
- arm64 leg targets spark-hanzoai-arm64 (Ampere bare metal,
  also default).

Both are native — no QEMU emulation. arm64 jobs queue while
spark arcd is offline; once spark is online (or an equivalent
arm64 ARC pool is installed somewhere reachable) the queue
drains automatically.
2026-06-07 11:46:03 -07:00
Hanzo AI 7aafdf2b65 ci: amd64-only build (matches hanzo runner pool topology)
hanzo-build-linux-amd64 is the only ARC runner pool installed on
hanzo-k8s today (arm64 pool is paused until DigitalOcean ships
arm64 droplets, per ~/work/hanzo/.github/RUNNERS.md). The arm64
job was waiting on spark-hanzoai-arm64 — not provisioned in this
cluster — so every build sat in queue forever and the amd64 leg
got cancelled.

Set platforms: linux/amd64 on the reusable build call to skip
arm64 entirely. Re-add arm64 if/when DO ships arm64 droplets and
the spark runner pool comes back online.
2026-06-07 11:38:49 -07:00
Hanzo AI d568e189a0 vendor: handsontable 6.2.2 full.min.css for excel-viewer build
components/view/viewer/excel-viewer.tsx imports
'@/public/vendor/handsontable/handsontable.full.min.css' at
build time, but the file was never committed — every Docker build
failed at the webpack module-resolution step.

The companion JS loads via CDN at runtime
(cdnjs.cloudflare.com/ajax/libs/handsontable/6.2.2/handsontable.full.min.js).
Pin the CSS to the same version, vendor it in, and the build
clears.
2026-06-07 11:19:56 -07:00
Hanzo AI d21548746c Merge remote-tracking branch 'origin/main' 2026-06-01 16:18:03 -07:00
Hanzo AI d5a58f710c merge: ci/canonical-docker-build-1776995235 2026-06-01 16:18:02 -07:00
Hanzo AI 77799ddce2 chore: rip stripe → @hanzoai/commerce + @hanzoai/pay (no stripe period)
Per CTO directive: zero Stripe across all our repos. Migration mirrors
hanzoai/gui@8d05cf6fb3.

- lib/commerce.ts: new hand-rolled Hanzo Commerce REST client + minimal
  CommerceTypes namespace covering only what the dataroom touches
  (Subscription, Invoice, Customer, CheckoutSession, PortalSession,
  Coupon, Event, Checkout.Session). HMAC-SHA256 webhook signature
  verification matches the gui pattern.
- ee/stripe/index.ts: now a thin shim — `stripeInstance(...)` returns
  the Commerce client; `cancelSubscription(...)` delegates to it.
- ee/stripe/client.ts: Stripe.js loadStripe + redirectToCheckout
  replaced with a redirect helper that bounces the browser to
  pay.hanzo.ai (@hanzoai/pay). No more card UI in the dataroom.
- ee/stripe/utils.ts: drop `import Stripe from "stripe"`; use
  CommerceTypes.Subscription. Stamped TODO(stripe-rip) on the PLANS
  const — the Stripe price IDs embedded there still need re-keying
  to Commerce plan IDs (5 plans × monthly+yearly × test+prod × new+old
  account; coordinate with Commerce admin).
- ee/stripe/webhooks/{checkout-session-completed,customer-subscription-
  {updated,deleted},invoice-upcoming}.ts: drop stripe SDK imports;
  rebind types to CommerceTypes.
- ee/features/security/lib/fraud-prevention.ts: addEmailToStripeRadar
  becomes a no-op with TODO(stripe-rip). Commerce does fraud at the
  gateway and does not yet expose a Radar-equivalent endpoint; the
  Edge Config blocklist remains the effective block surface.
- ee/features/billing/cancellation/api/*.ts: error message
  "No Stripe customer ID" -> "No billing customer ID"; the local
  `stripe` variable is now a Commerce instance via stripeInstance().
- pages/api/stripe/webhook.ts + webhook-old.ts: DELETED. Commerce
  owns webhook termination; the new dispatcher is at
  pages/api/commerce/webhook.ts and reuses the existing per-event
  business-logic handlers in ee/stripe/webhooks/.
- pages/api/commerce/webhook.ts: NEW. Accepts hanzo-commerce-signature
  (falls back to stripe-signature header so a side-by-side rollout
  works), verifies HMAC with HANZO_COMMERCE_WEBHOOK_SECRET, dispatches
  to the same handlers as before.
- package.json: removed `stripe` (^16.12.0), `@stripe/stripe-js`
  (^4.10.0), and the `stripe:webhook` pkgx script. No new deps — the
  Commerce REST client is hand-rolled per spec.

TODO(stripe-rip) markers flag the remaining deep work:
- PLANS const price IDs need re-keying to Commerce plan IDs
- ee/stripe/ directory should be renamed to ee/commerce/
- Local `stripeInstance` identifier should be renamed `commerce`
- Subscription.pause_collection / proration_behavior contract needs
  to land in the Commerce OpenAPI spec
- Commerce fraud-blocklist API needs to ship to replace the Radar
  call we just stubbed out

`tsc --noEmit` shows zero new errors in ee/, lib/commerce.ts,
pages/api/commerce/, components/billing/. Pre-existing TS errors in
redis-job-store, lib/auth, app routes are unchanged.
2026-05-28 02:03:38 -07:00
Hanzo AI dc592aa79d docs(llm): explicit Upstream attribution line
LICENSE-attested or repo-attested upstream is now called out at the
top of LLM.md alongside the project description, so downstream
audits (universe/docs/PRODUCTS.md) can rely on a single canonical
location for the OSS lineage statement.
2026-05-18 21:35:47 -07:00
Hanzo AI f99ecc8e90 ci: add id-token: write to caller permissions
Required for hanzoai/.github/.github/workflows/docker-build.yml@main —
without it the workflow_call dies as startup_failure with no jobs
dispatched. Caller permissions are a CEILING.
2026-05-07 09:09:52 -07:00
Hanzo DevandGitHub 30cdcf7339 ci: migrate to canonical hanzoai/.github/docker-build.yml reusable (#2) 2026-04-23 18:53:36 -07:00
Hanzo AI c1e7842cca ci: migrate to canonical hanzoai/.github/docker-build.yml reusable 2026-04-23 18:48:09 -07:00
Hanzo DevandGitHub 978f6c5e88 ci: migrate to canonical docker-build reusable workflow (#1)
Replace bespoke build-and-push + universe-reusable-deploy-service pair
with the canonical caller that does both in a single workflow:
hanzoai/.github/.github/workflows/docker-build.yml@main.

Native amd64+arm64 ARC runners, semver + branch tags, multi-arch manifest,
kubectl rollout restart on main after push.

Co-authored-by: Hanzo AI <dev@hanzo.ai>
2026-04-23 18:12:23 -07:00
Hanzo AI 9ccb0508b4 chore: add .dockerignore 2026-04-17 16:58:13 -07:00
Hanzo AI 54c79e2b6f chore: symlink AGENTS.md and CLAUDE.md to LLM.md
Canonical project context lives in LLM.md. Symlinks ensure
agentic coding tools (Claude Code, Cursor, etc.) find context
automatically regardless of which filename they look for.
2026-04-01 14:11:20 -07:00
Hanzo AI a6b5d4c570 chore: remove vendored handsontable files 2026-03-03 14:00:00 -08:00
Hanzo Dev 19cce6e851 fix: remove tracked vendor dir, add to gitignore 2026-03-28 18:13:20 -07:00
Hanzo Dev c8284f3f27 fix: use published @hanzo/insights package directly 2026-03-14 01:36:35 -07:00
Hanzo Dev 1ad91d413e rebrand: zero posthog, no compat
Rename x-posthog-* header pattern to x-insights-* in
analytics middleware.
2026-03-13 20:33:42 -07:00
Hanzo Dev 263e4f6c32 rebrand: use direct Insights imports, no compat aliases 2026-03-13 20:15:26 -07:00
Hanzo Dev e7d7e6aeac rebrand: final PostHog purge 2026-03-13 17:54:38 -07:00
Hanzo Dev 1408d08f38 rebrand: purge PostHog references 2026-03-13 17:38:17 -07:00
Hanzo Dev 3ccb6035b5 rebrand: purge remaining PostHog references 2026-03-13 17:11:13 -07:00
Hanzo Dev eb97698382 ci: migrate deploy to HANZO_API_KEY + KMS via reusable workflow
Replace direct DIGITALOCEAN_ACCESS_TOKEN with reusable-deploy-service.yml
from hanzoai/universe that fetches credentials from KMS using HANZO_API_KEY.
2026-03-11 14:35:00 -07:00
Hanzo Dev c3817a2e0a docs: add LLM.md project guide 2026-03-11 10:29:51 -07:00
Hanzo Dev ddcfc62f54 chore: rename HANZO_IAM_ env vars to IAM_ prefix
Drop HANZO_ prefix from all IAM environment variable names for
consistency across the Hanzo ecosystem.
2026-03-10 16:31:45 -07:00
Hanzo Dev 1244cb74f6 feat: add org_id claim from IAM to JWT/session, document IAM env vars
- Extract organization from IAM profile (owner/organization/org fields)
- Pass organization through JWT → session → CustomUser
- Add HANZO_IAM_* variables to .env.example
- Deprecate Google OAuth in favor of Hanzo IAM
2026-03-09 22:27:13 -07:00
Hanzo Dev 3867fa934d fix: update auth pages and branding for Hanzo IAM 2026-03-03 12:13:13 -08:00
Hanzo Dev 880f522457 feat: IAM-only auth
Remove email, Google, LinkedIn, passkey, SAML auth from login —
only allow Sign in with Hanzo (IAM).
2026-03-02 23:45:00 -08:00
Hanzo Dev 2724995f04 fix: copy entire node_modules/.bin to include Prisma WASM files
The Prisma CLI binary references companion .wasm files
(prisma_schema_build_bg.wasm) that live alongside it in .bin/.
Copying only the prisma binary missed these files.
2026-03-01 19:47:13 -08:00
Hanzo Dev 513f0c4781 fix: repair broken function names from branding sed replacement
The mass sed replacement of 'Papermark' → 'Hanzo Dataroom' broke
function names that contained 'Papermark' as part of a camelCase
identifier (e.g. PapermarkSparkle → Hanzo DataroomSparkle).
2026-03-01 19:20:32 -08:00
Hanzo Dev 126976b33f Rebrand from Papermark to Hanzo Dataroom
- Replace all Papermark branding with Hanzo Dataroom
- Update metadata, titles, descriptions, OG tags
- Update email templates footer and branding
- Replace papermark.io/com URLs with dataroom.hanzo.ai
- Update powered-by component
- Update x-powered-by header
- Update legal references to Hanzo AI, Inc.
- Update social handles to @hanzoai
- Update README, CLA, LICENSE, SECURITY docs
2026-03-01 19:02:19 -08:00
Hanzo Dev 2a6073e5c2 Fix Prisma migrations: symlink schema/migrations to prisma/migrations
Prisma multi-file schema at prisma/schema/schema.prisma looks for
migrations at prisma/schema/migrations/ by default. Actual migrations
are at prisma/migrations/. Symlink bridges the two.
2026-03-01 09:09:58 -08:00
Hanzo Dev 1e91e2b50a Fix Edge Runtime crash: remove ioredis from middleware bundle
- Dynamic import DomainMiddleware to avoid pulling ioredis into Edge bundle
- Add hanzo.ai to APP_DOMAINS exclusion list in isCustomDomain
- DomainMiddleware now uses fetch to internal API for Redis lookups
- Create /api/internal/domain-redirect endpoint for Edge-safe KV access
2026-03-01 08:33:05 -08:00
Hanzo Dev 8b57b27eb0 Replace Upstash with Hanzo KV (ioredis wire-compatible client)
- Remove @upstash/redis, @upstash/ratelimit, @upstash/qstash
- Add ioredis for Hanzo KV wire protocol compatibility
- Rewrite lib/redis.ts with Upstash-compatible shims over ioredis
- Rewrite tus-redis-locker.ts to use ioredis types
- Replace @upstash/ratelimit with sliding-window impl over KV
- Stub qstash in lib/cron (not used in production)
- Env: KV_URL replaces UPSTASH_REDIS_REST_URL
2026-03-01 08:09:53 -08:00
Hanzo Dev 10473cb76f fix: use correct prisma schema path and bundle prisma CLI in runner
Schema is at prisma/schema/schema.prisma (multi-file schema).
Bundle prisma CLI to avoid slow npx download on every pod start.
2026-03-01 07:44:03 -08:00
Hanzo Dev b2d3952309 fix: wrap useSearchParams pages in Suspense for Next.js build
Pages using useSearchParams() in client components need a Suspense
boundary to avoid build errors during static page generation.
2026-03-01 07:29:43 -08:00
Hanzo Dev 0590fd306e fix: increase Node heap size for Docker build
QEMU cross-compilation and large bundles cause OOM during Next.js build.
2026-03-01 07:08:09 -08:00
Hanzo Dev 1dd9d0eb42 fix: remove constructor throw in SlackClient to prevent build crash
Next.js collects page data during build, importing modules at module scope.
SlackEventManager instantiates SlackClient which threw when SLACK_CLIENT_ID
was unset, crashing the build at /api/views-dataroom page collection.
2026-03-01 06:45:58 -08:00
Hanzo Dev b4aefb200e fix: add dummy env vars during Docker build for module-scope inits
OpenAI and Hanko clients initialize at module scope, crashing Next.js
build when collecting page data. Set dummy values only for build stage.
2026-03-01 06:36:41 -08:00
Hanzo Dev 6800768d0b fix: make hanko passkey provider optional for builds without env vars
Return null from getHanko() when HANKO_API_KEY is unset, and
conditionally include PasskeyProvider in NextAuth only when configured.
2026-03-01 06:31:32 -08:00
Hanzo Dev b8eb58d801 fix: lazy-init hanko client to prevent build-time crash
Hanko client was throwing at module scope when HANKO_API_KEY was unset.
Convert to lazy getter so it only initializes at runtime.
2026-03-01 06:23:35 -08:00
Hanzo Dev cbf081c0b2 fix: async searchParams for invitation page + skip TS build errors
Fix Next.js 15 async searchParams in invitation page and add
typescript.ignoreBuildErrors as safety net for remaining pages.
2026-03-01 06:16:29 -08:00
Hanzo Dev 639c52d9ab fix: use async params for Next.js 15 compatibility
Next.js 15 requires page params to be Promise<T> instead of plain objects.
2026-03-01 06:09:30 -08:00
Hanzo Dev 085f635cc4 Fix build: add defaults for env vars used in Next.js config 2026-03-01 06:01:48 -08:00
Hanzo Dev baba5bbaa9 Use npm install instead of npm ci in Dockerfile 2026-03-01 05:54:51 -08:00
Hanzo Dev e426826edc Regenerate package-lock.json with override resolution 2026-03-01 05:53:44 -08:00
Hanzo Dev 583b7667be Fix Dockerfile: add build deps for native modules 2026-03-01 05:51:35 -08:00
Hanzo Dev ce60abfbce Add Dockerfile and CI/CD for K8s deployment
- Add Dockerfile with standalone Next.js output
- Add output: "standalone" to next.config.mjs (DOCKER_OUTPUT env)
- Add GitHub Actions workflow for GHCR build + K8s deploy
2026-03-01 05:48:20 -08:00
Hanzo Dev effa28bdb5 Upgrade to Next.js 15, TypeScript 5.9
- next: 14.2.35 → 15.1.0
- typescript: 5 → 5.9.3

React 18, next-auth 4.x, Prisma 6.x kept as-is.
2026-03-01 03:09:52 -08:00
Hanzo Dev 53c72672ca feat: add Hanzo IAM OIDC SSO provider
- Add HanzoIAMProvider to NextAuth config (OIDC with userinfo endpoint)
- Add "Continue with Hanzo" button to login page (first SSO option)
- Env vars: HANZO_IAM_URL, HANZO_IAM_CLIENT_ID, HANZO_IAM_CLIENT_SECRET
- IAM app registered as app-dataroom in init_data.json
2026-03-01 22:36:44 -08:00
Marc SeitzandGitHub 2e30946472 Merge pull request #2103 from mfts/cursor/duplicated-link-properties-b1a0
Duplicated link properties
2026-03-06 22:28:12 +11:00
Marc SeitzandGitHub f31e261811 Merge pull request #2102 from mfts/codex/agent
feat(ee): improve agents
2026-03-05 23:05:12 +11:00
Cursor AgentandMarc Seitz 5168a80b30 fix: duplicate custom fields and visitor groups when duplicating a link
When a link is duplicated, the custom form fields and visitor group
associations were not being copied to the new link. This adds:

- Include customFields and visitorGroups in the Prisma query for the
  source link
- Create new CustomField records for the duplicated link via createMany
- Create new LinkVisitorGroup junction records for the duplicated link
- Return customFields and visitorGroups in the created link response

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-03-05 10:47:16 +00:00
Marc Seitz bfc02040ca fix: limit source files 2026-03-05 21:42:34 +11:00
Marc Seitz 1e65b74b8d Merge branch 'codex/agent' of github.com:mfts/papermark into codex/agent 2026-03-05 17:58:56 +11:00
Marc Seitz a0f91e4b93 fix 2026-03-05 17:58:34 +11:00
Marc SeitzGitHubcoderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
6ead6e6410 Update ee/features/ai/components/chat-message.tsx
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-03-05 17:49:36 +11:00
Marc SeitzGitHubCopilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
0df4ab5a74 Potential fix for code scanning alert no. 92: Incomplete string escaping or encoding
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-03-05 17:47:52 +11:00
Marc Seitz afa7e0fa7d feat(ee): improve agents 2026-03-05 17:38:18 +11:00
Marc SeitzandGitHub df0f8f612f Merge pull request #2100 from mfts/cursor/docx-sanitizer-additions-a1a1
Docx sanitizer additions
2026-03-05 17:29:17 +11:00
Cursor AgentandMarc Seitz fd68e10379 Replace regex-based pPr extraction with XML tree parsing in NUMPAGES fix
Remove PPR_RE, PPR_BLOCK_RE, and PARA_RE regex constants that were
used to extract <w:pPr> from paragraph fragments via non-greedy
matching. Replace with proper xml.etree.ElementTree parsing of the
entire header/footer file:

- _register_all_namespaces() preserves original namespace prefixes
  during ET serialization
- strip_numpages_fields_in_hf() now iterates the parsed XML tree to
  find <w:p> elements with NUMPAGES/SECTIONPAGES instrText, removes
  all children except <w:pPr> (found via Element.find), and writes
  the cleaned tree back

This handles arbitrarily nested pPr structures safely and avoids
regex truncation on malformed documents.

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-03-05 06:17:40 +00:00
Cursor AgentandMarc Seitz 19e93b589e Preserve original paragraph properties in NUMPAGES field fix
Instead of hardcoding a Footer style on replacement paragraphs,
extract the existing <w:pPr> block (or self-closing tag) from the
original paragraph and reuse it. This avoids style mismatches in
headers/footers that use custom paragraph properties.

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-03-05 05:57:43 +00:00
Marc SeitzandGitHub bd1e3c04f3 Merge pull request #2101 from mfts/chore/deps
chore: update dependencies
2026-03-05 16:55:58 +11:00
Marc Seitz c78e97962b fix 2026-03-05 16:48:43 +11:00
Marc Seitz 2aadaf8888 chore: update dependencies 2026-03-05 16:22:48 +11:00
Cursor AgentandMarc Seitz 797d470468 Add NUMPAGES/SECTIONPAGES footer field fix to DOCX sanitizer
Strip nested IF/NUMPAGES field codes from headers/footers that cause
infinite layout recalculation loops in LibreOffice's UNO API
(loadComponentFromURL hangs). Paragraphs containing NUMPAGES or
SECTIONPAGES instrText are replaced with empty paragraphs to break
the loop. This fix runs in 'all' mode alongside existing RTL compat,
glossary removal, and SDT unwrap fixes.

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-03-05 05:19:26 +00:00
Marc SeitzandGitHub 120a1b88fb Merge pull request #2083 from mfts/cursor/root-domain-redirects-96b8
Root domain redirects
2026-03-05 14:33:58 +11:00
Marc SeitzandGitHub 86b0ee68b9 Merge pull request #2095 from mfts/cursor/upload-limit-warnings-9750
Upload limit warnings
2026-03-02 18:49:50 +11:00
Marc Seitz a44bae5edd fix: fix propagate button 2026-03-02 18:31:27 +11:00
Marc Seitz 6950dec056 chore: prettier 2026-03-02 18:21:53 +11:00
Marc Seitz 6e9d6fe7d4 feat: force https on redirect url 2026-03-02 18:21:42 +11:00
Marc Seitz 5e115f1896 refactor: remove outdated getTeamWithDomain helper 2026-03-02 18:21:31 +11:00
Marc Seitz 4b557e909c Merge branch 'main' into cursor/root-domain-redirects-96b8 2026-03-02 17:56:26 +11:00
Marc Seitz 8c3d677af8 Merge branch 'main' into cursor/upload-limit-warnings-9750 2026-03-02 17:46:24 +11:00
Marc SeitzandGitHub 6687d842db Merge pull request #2096 from mfts/cursor/file-upload-authentication-bypass-dcd1
File upload authentication bypass
2026-03-02 17:43:12 +11:00
Marc SeitzandGitHub 4a969ad9ad Merge pull request #2093 from mfts/feat/dataroom-visitor-notifications
feat: add notification settings for visitors
2026-03-02 17:27:44 +11:00
Cursor AgentandMarc Seitz 0b1acdf136 Cap folder traversal at remainingDocuments to prevent unnecessary backend folder creation
getFilesFromEvent now tracks a collectedFileCount counter and a fileLimit
derived from remainingDocuments. traverseFolder checks the counter before
entering directories (skipping folder creation) and before resolving files.
Once the budget is exhausted the traversal short-circuits, so no extra API
calls are made for folders that would never receive uploads.

A fileLimitTruncatedRef signals to onDrop that files were capped during
traversal so the warning toast fires even though acceptedFiles.length is
already <= remainingDocuments. The else-if branch in onDrop still handles
the file-picker path (no traversal) as a safety net.

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-03-02 06:23:49 +00:00
Marc Seitz 13a98ca7e5 fix: don't send empty digest 2026-03-02 17:23:23 +11:00
Cursor AgentandMarc Seitz 015c44af80 Harden TUS upload auth, team access, and limits
Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-03-02 06:11:09 +00:00
Marc SeitzandGitHub 1ebfd522a3 Merge pull request #2094 from mfts/cursor/q-a-content-wrapping-64f3
Q&a content wrapping
2026-03-02 16:59:14 +11:00
Cursor AgentandMarc Seitz 82b47a3e76 fix: increase Q&A message limit to 4000 chars and surface validation errors
The admin was unable to reply to conversations because the 1000 character
limit was too restrictive for dataroom Q&A. This commit:

- Increases the default message character limit from 1000 to 4000
- Surfaces the actual validation error message (e.g. 'Content cannot be
  longer than 4000 characters') through the API instead of returning a
  generic 'Internal server error'
- Parses and displays the API error in the frontend toast notification
- Adds a character counter to the admin reply form with visual feedback
  when approaching/exceeding the limit
- Adds maxLength to viewer-side input fields for client-side enforcement

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-03-02 05:08:58 +00:00
Cursor AgentandMarc Seitz 0f59913c14 fix: Q&A content text wrapping so questions and answers are not cut off
- conversation-message.tsx: Change w-max to w-fit on message bubbles so
  text wraps at max-w-[80%] instead of overflowing. Add min-w-0 and
  break-words to the content paragraph for proper word wrapping.

- faq-section.tsx: Add min-w-0 and break-words to FAQ answer text to
  prevent overflow in flex containers. Add break-words to question text
  and min-w-0 to accordion trigger for consistent wrapping behavior.

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-03-02 04:59:51 +00:00
Marc Seitz d5c7a6d109 fix 2026-03-02 15:05:35 +11:00
Marc Seitz c394f623eb fix: try and catch around sending notification 2026-03-02 13:58:19 +11:00
Marc Seitz adde340bbd fix: don't ignore other keys in notificationprefs 2026-03-02 13:13:16 +11:00
Marc Seitz 32275c6068 fix: wrap in try catch 2026-03-02 13:13:04 +11:00
Marc Seitz ef2f06f824 fix: throw if no linkurl present 2026-03-02 13:12:54 +11:00
Marc Seitz 8d5568b807 fix: classname typo 2026-03-02 13:12:39 +11:00
Marc Seitz eaabf16b2c fix: type error 2026-03-02 12:40:58 +11:00
Marc Seitz 3c7e4f93d0 feat: add notification settings for visitors 2026-03-02 12:31:44 +11:00
Marc SeitzandGitHub 3f95f1c118 Merge pull request #2092 from mfts/feat/deps
fix: remove warning
2026-03-02 12:20:05 +11:00
Marc Seitz 996a40ceb9 fix: remove warning 2026-03-01 13:33:15 +11:00
Marc SeitzandGitHub 6c1f5e261d Merge pull request #2091 from mfts/chore/robots
chore: update robots
2026-02-28 17:11:50 +11:00
Marc Seitz dc0de8a8dd chore: update robots 2026-02-28 16:58:45 +11:00
Marc Seitz 898313f5a5 fix: remove redirect if it fails 2026-02-28 15:29:32 +11:00
Marc Seitz a279392ba9 chore: make sure keyword matching is case insentive 2026-02-28 15:24:01 +11:00
Marc Seitz 6951b2d92a feat: add zod validation for domain update body 2026-02-28 15:23:35 +11:00
Marc Seitz 76444e2992 Merge branch 'main' into cursor/root-domain-redirects-96b8 2026-02-28 15:20:12 +11:00
Marc SeitzandGitHub 47c256a53c Merge pull request #2004 from mfts/cursor/PM-468-dataroom-upload-visibility-b14f
Dataroom upload visibility
2026-02-28 08:38:33 +11:00
Marc Seitz a0570a18ca fix: colors for uploads 2026-02-28 08:23:19 +11:00
Marc Seitz 58d31905ef feat: successive uploads 2026-02-28 08:23:12 +11:00
Marc Seitz b8c6bb093f Merge branch 'main' into cursor/PM-468-dataroom-upload-visibility-b14f 2026-02-27 19:05:29 +11:00
Marc SeitzandGitHub 24b22dc1df Merge pull request #2041 from mfts/deal-flow-infp
Deal flow info
2026-02-27 17:50:49 +11:00
Marc Seitz c9b249c969 fix: add track dismissed state 2026-02-27 17:41:34 +11:00
Marc Seitz f677204bc2 feat: add migration 2026-02-27 17:11:08 +11:00
Marc Seitz 71b243ad9b fix: skip dealsize for pm 2026-02-27 16:50:26 +11:00
Marc Seitz 7216556de2 fix: typo 2026-02-27 16:49:34 +11:00
Marc Seitz 223d81adbf fix: save survey and submission guard 2026-02-27 16:47:56 +11:00
Marc Seitz e19ae608d9 fix: disable skip button when submitting 2026-02-27 16:45:55 +11:00
Marc Seitz be9c7dedae fix: return errorhandler 2026-02-27 16:45:38 +11:00
Marc Seitz 9bdbe333ad fix: use zod validated data instead of body 2026-02-27 16:44:23 +11:00
Marc Seitz f1a686e39d Merge branch 'main' into deal-flow-infp 2026-02-27 16:39:43 +11:00
Marc Seitz d3bd1802cd fix: return early if no document present 2026-02-27 16:35:46 +11:00
Marc Seitz 3ae1dbb678 fix: clear uploads and uploadids 2026-02-27 16:33:43 +11:00
Marc Seitz 58476317a5 refactor: extract duplicate filter logic 2026-02-27 16:33:28 +11:00
Marc Seitz c670f29273 feat: reset rejected file 2026-02-27 16:30:17 +11:00
Marc SeitzandGitHub 996d5f0e21 Merge pull request #2090 from mfts/cursor/user-settings-billing-popup-f92e
User settings billing popup
2026-02-27 16:23:00 +11:00
Cursor AgentandMarc Seitz 0dd914a87d Add pre-upload validation warnings for document and bulk upload limits
- Handle 'too-many-files' rejection in onDropRejected with clear message
  showing the max files per upload limit and suggesting smaller batches
- Improve onDrop document limit check: show usage (X/Y) and upgrade action
  when at limit, and truncate files with warning when partially exceeding
- Add early return in getFilesFromEvent to skip folder creation when at limit
- Improve add-document-modal error messages with usage context and upgrade CTA
- Fix remainingDocuments calculation: use Infinity for unlimited plans

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-26 14:54:47 +00:00
Cursor AgentandMarc Seitz febb9322a7 fix: remove auto-opening upgrade modal from User Settings page
The account/general page had a useEffect that automatically opened
an UpgradePlanModal every time a non-annual-plan user navigated to
User Settings. This was disruptive as users would see a billing popup
about upgrading to data rooms on every visit.

Removed the UpgradePlanModal component, the useEffect trigger, the
plan detection logic, and all related imports from the page.

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-26 03:08:16 +00:00
Marc SeitzandGitHub 661014c893 Merge pull request #2088 from mfts/cursor/viewer-link-content-responsiveness-d996
Viewer link content responsiveness
2026-02-25 22:32:54 +11:00
Marc SeitzandCursor 53d328c2d9 fix: resolve three bugs in upload visibility feature
- Fix persisted uploads stuck in 'processing': updatePendingUpload now
  updates both in-flight and persisted state arrays
- Fix duplicate filename collision: key pending upload IDs by batch index
  instead of filename, thread index through onUploadComplete callback
- Fix modal premature close on multi-file upload: track expected/completed
  counts and only fire onUploadSuccess after all files resolve

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-02-25 18:30:15 +11:00
Marc SeitzandCursor 5f81333e6e feat: add dataroom upload visibility with optimistic UI and persisted uploads
- Add GET endpoint to fetch viewer's previously uploaded documents
- Return document data from POST upload for optimistic UI rendering
- Add PendingUploadsProvider context with server-side persistence
- Add PendingDocumentCard with Trigger.dev realtime processing status
- Add Documents/My Uploads tab switcher in dataroom viewer
- Redesign upload modal with folder indicator and success state
- Redesign upload component with progress bars and drag-drop zone

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-02-25 18:30:08 +11:00
Marc SeitzandGitHub 47922d48d7 Merge pull request #2089 from mfts/cursor/dataroom-document-audit-analytics-7cbc
feat: improve dataroom audit analytics
2026-02-25 18:15:25 +11:00
Marc Seitz 3794b3eeff fix: auth dataroom to team 2026-02-25 18:10:33 +11:00
Marc Seitz 8feb0e2d6e fix 2026-02-25 18:09:22 +11:00
Marc SeitzandCursor 4e0969ab71 fix: increase xs gauge size to fit 3-digit values like 100
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-02-25 17:14:42 +11:00
Marc SeitzandCursor 3c20959060 fix: pass documentId through chart data and add rate limiting to thumbnail API
The tooltip was using router.query.id (dataroom ID) instead of the
actual document ID, and versionNumber was NaN. Pass documentId through
BarChartComponent data so the tooltip resolves the correct thumbnail.
Add rate limiting (150 req/min per user) to the get-thumbnail endpoint.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-02-25 17:14:36 +11:00
Marc SeitzandCursor 4145145b74 refactor: restructure dataroom audit log layout with proper columns
Move document stats (duration, completion) into dedicated table columns
instead of squeezing them next to the document name. Page-by-page
analytics now opens as a separate expandable row. Replace "See document"
button with arrow link icon. Add table-fixed layout with explicit column
widths to prevent shifting on expand. Conditionally show column headers
only when a row is expanded. Slim down inner row padding.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-02-25 17:14:30 +11:00
Marc SeitzandGitHub 9d7b8bf8f2 Merge pull request #2087 from mfts/fix/cjk-slugify
fix: slugify cjk names
2026-02-25 15:43:30 +11:00
Marc Seitz 2425a8933b feat: add transliteration 2026-02-25 15:22:06 +11:00
Marc SeitzandCursor d1a3603837 fix: preserve original CJK filename in Content-Disposition header
Use RFC 5987 filename* parameter to include the UTF-8 encoded original
filename alongside the ASCII-safe slug, so downloads show the proper
CJK name in modern browsers. Also adds missing Content-Disposition to
put-file-server and stream-file-server uploads.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-02-25 14:43:02 +11:00
Marc SeitzandCursor 70beab2c5e fix: add CJK-safe slugify with nanoid fallback
slugify strips all CJK characters, producing empty strings for
filenames and folder names that contain only CJK text. Replace all
usages with safeSlugify which falls back to a 12-char lowercase
alphanumeric nanoid when slugify returns an empty result.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-02-25 14:42:53 +11:00
Cursor AgentandMarc Seitz e5dab063db Fix horizontal viewer refit after viewport resize
Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-24 22:45:32 +00:00
Iuliia Shnai c7c1f59649 feat:updates 2026-02-23 19:31:26 +11:00
Iuliia Shnai 7fd0d7bdfe feat:updates 2026-02-23 19:01:12 +11:00
Marc Seitz cf1e783d8f Merge branch 'main' into cursor/PM-468-dataroom-upload-visibility-b14f 2026-02-23 13:19:45 +11:00
Marc SeitzandGitHub 7542ffe53a Merge pull request #2084 from mfts/cursor/dataroom-viewer-background-fill-2c9f
Dataroom viewer background fill
2026-02-22 22:23:03 +11:00
Cursor AgentandMarc Seitz ae45df36b8 fix: add min-h-screen to dataroom viewer wrapper to prevent white background gap
When applyAccentColorToDataroomView is enabled but there are not enough
folders/documents to fill the viewport, a white background was visible
underneath the content. Adding min-h-screen ensures the accent background
color extends to fill at least the full viewport height.

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-22 11:10:41 +00:00
Marc SeitzandGitHub 1571168300 Merge pull request #2077 from mfts/cursor/dataroom-viewer-background-color-ac68
Dataroom viewer background color
2026-02-22 21:53:54 +11:00
Marc SeitzandGitHub 3f351a0900 Merge pull request #2073 from mfts/cursor/visitor-groups-access-1b01
Visitor groups access
2026-02-22 20:36:42 +11:00
Cursor AgentandMarc Seitz 5df098f630 fix: clean up unused imports, add stagger delay for per-page chart loading
Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-22 09:20:45 +00:00
Cursor AgentandMarc Seitz 6d7d88431b feat: add document stats (duration, completion, per-page chart) to dataroom visitor audit log
- Create new Tinybird pipe get_dataroom_view_document_stats for bulk document view stats
- Add API endpoint for dataroom view document stats with per-page chart support
- Create SWR hooks with deferred loading (enabled flag)
- Create reusable DocumentViewDuration, DocumentViewCompletion, DocumentPageChart components
- Create DataroomViewStats component combining history with stats
- Update dataroom-visitors-table.tsx and dataroom-viewers.tsx to track expansion state
- Stats only load when visitor row is expanded (deferred loading)
- Per-page charts only load when individual document line is expanded

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-22 09:14:36 +00:00
Marc Seitz ebb928916c fix: visitorgroup on the team 2026-02-22 19:30:04 +11:00
Cursor AgentandMarc Seitz ce2b40daad fix: harden root domain redirects - validation, plan gating, cleanup
- Change redirect status from 301 to 302 (non-permanent, user-configurable)
- Remove backfill UPDATE entries from migration SQL
- Remove unnecessary sync-redirects cron endpoint
- Add URL validation: SSRF protection, edge config keyword blocklist,
  protocol check, URL sanitization via shared validateRedirectUrl helper
- Add plan gating: require Business plan or higher for redirect URLs
  (enforced on both API endpoints and UI)
- Clean up Redis redirect URLs on team deletion
- Clear redirect URLs (Postgres + Redis) on subscription cancellation
  and on plan downgrade below Business
- Split redis.ts to avoid Prisma import in edge middleware context
- Gate DomainCard redirect UI based on plan (show upgrade prompt)

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-22 08:24:29 +00:00
Marc Seitz e591d6cea1 fix 2026-02-22 19:17:46 +11:00
Marc SeitzandGitHub ebd0e9f367 Merge pull request #2082 from mfts/cursor/document-name-sanitization-9fc2
Document name sanitization
2026-02-22 19:12:01 +11:00
Cursor AgentandMarc Seitz 931bb5a0ba Decode entities in document name sanitization
Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-22 07:58:10 +00:00
Marc Seitz 03a6a09bb0 feat: hide visitor groups when not set 2026-02-22 18:51:26 +11:00
Marc SeitzandGitHub 548b0f51f3 Merge pull request #2081 from mfts/cursor/user-team-action-authorization-13a8
User team action authorization
2026-02-22 18:45:06 +11:00
Cursor AgentandMarc Seitz c5fd6bbfa6 Sanitize document names on upload and rename
Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-21 13:07:32 +00:00
Cursor AgentandMarc Seitz f97f5e9164 Harden team action auth with composite user-team lookup
Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-21 13:03:57 +00:00
Marc Seitz 3a75915740 Update viewer-surface-theme.tsx 2026-02-21 13:36:44 +11:00
Marc Seitz 4dd6981e48 Merge branch 'main' into cursor/dataroom-viewer-background-color-ac68 2026-02-21 13:20:26 +11:00
Marc Seitz 01aa7f4306 feat: improve visitor group layouts 2026-02-21 13:18:15 +11:00
Marc Seitz 75a5795882 Merge branch 'main' into cursor/visitor-groups-access-1b01 2026-02-21 13:05:06 +11:00
Cursor AgentandMarc Seitz 2709049f68 feat: add UI for root domain redirect and Redis sync endpoint
- Update DomainCard to accept and display redirectUrl with inline editor
- Add save/remove functionality for redirect URL with toast notifications
- Pass redirectUrl from domains settings page to DomainCard
- Add /api/cron/domains/sync-redirects endpoint to sync Postgres -> Redis
- Add backfill SQL for existing hardcoded domain redirects

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-20 22:50:09 +00:00
Cursor AgentandMarc Seitz e81d4118aa feat: add root domain redirect support (schema, redis, middleware, API)
- Add redirectUrl field to Domain model in Prisma schema
- Create migration for the new field
- Add Redis helper for domain redirect URL caching
- Update middleware to check Redis for redirect URL instead of hardcoded values
- Update domain API: GET includes redirectUrl, POST accepts redirectUrl, PUT updates redirectUrl
- Sync Redis on domain create, update, and delete

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-20 22:45:48 +00:00
Marc SeitzandGitHub c9638ebd9f Merge pull request #2080 from mfts/feat/sanitize-docx-on-fail
fix: improve libreoffice conversion
2026-02-21 00:17:48 +11:00
Marc Seitz 47b0564ad6 fix 2026-02-21 00:11:48 +11:00
Marc Seitz fcc3fd4d92 fix 2026-02-20 23:58:57 +11:00
Marc Seitz db70856fb0 fix: libreoffice fixes in conversion 2026-02-20 23:43:50 +11:00
Marc Seitz df1fbfda77 feat: add document sanitizer 2026-02-20 17:05:20 +11:00
Marc Seitz 4d29ecc1c4 chore: update dependencies 2026-02-20 00:11:05 +11:00
Marc Seitz a8981b4950 feat: improve group layout 2026-02-20 00:10:55 +11:00
Marc Seitz 9e0cc88a4a chore: add skills 2026-02-20 00:10:28 +11:00
Marc Seitz e0eaaa5b3d fix: typescript errors 2026-02-19 18:08:29 +11:00
Marc Seitz 07f56a1b51 Merge branch 'main' into cursor/visitor-groups-access-1b01 2026-02-19 17:53:00 +11:00
Marc SeitzandGitHub a3108dc5fa Merge pull request #2079 from mfts/fix/sso
fix: jackson db error
2026-02-19 17:48:24 +11:00
Marc Seitz c2e4adc30b feat: add dataroom view background 2026-02-19 17:39:56 +11:00
Marc Seitz 640aa0275f fix: jackson db error 2026-02-19 16:14:23 +11:00
5401d3d5d2 Notion text selection (#2062)
* feat: add option to allow text selection on Notion pages

Add enableTextSelection field to Link model that allows document owners
to toggle text selection/copying for visitors on Notion pages.

Changes:
- Add enableTextSelection Boolean field to Link Prisma schema
- Add database migration for the new field
- Create TextSelectionSection toggle component for link settings
- Wire the setting through link sheet, link options, API routes
- Pass textSelectionEnabled prop to NotionPage viewer component
- Add .notion-text-selection-enabled CSS class that overrides
  user-select: none when text selection is allowed
- Update link-active-controls to show when text selection is active
- Update webhooks and link data queries to include new field

By default, text selection remains disabled (preserving existing
behavior). When enabled, visitors can select and copy text content
on Notion document pages.

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>

* refactor: use team feature flag for text selection instead of per-link toggle

Replace the per-link enableTextSelection database field with a team-level
feature flag (textSelection) using the existing Vercel Edge Config system.

This means text selection on Notion pages is controlled at the team level
via the betaFeatures edge config, so there's no per-link toggle to manage.

Changes:
- Remove enableTextSelection from Link Prisma schema and migration
- Remove TextSelectionSection toggle component and link sheet wiring
- Add 'textSelection' to BetaFeatures type in featureFlags
- Fetch textSelection flag in all view page getStaticProps:
  - pages/view/[linkId]/index.tsx (document + dataroom paths)
  - pages/view/domains/[domain]/[slug]/index.tsx (document + dataroom)
  - pages/view/[linkId]/d/[documentId].tsx (dataroom document)
  - pages/view/domains/[domain]/[slug]/d/[documentId].tsx (domain dataroom doc)
- Pass textSelectionEnabled prop through component chain:
  DocumentView -> ViewData -> NotionPage
  DataroomDocumentView -> ViewData -> NotionPage
- Keep CSS override (.notion-text-selection-enabled) and NotionPage
  conditional class application from previous commit

To enable: add the team's ID to the 'textSelection' array in
Vercel Edge Config betaFeatures.

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-19 14:37:27 +11:00
Cursor AgentandMarc Seitz c6a95059bd feat: apply brand background color to dataroom viewer
- Apply accentColor (background color) to the dataroom viewer content area,
  not just the document view
- Add explicit white background to document and folder cards so they remain
  visible on any background color
- Adapt tree view sidebar, breadcrumbs, search banner, and empty state text
  colors for dark backgrounds using determineTextColor utility
- Update room preview demo to also render background color
- Update branding page label to indicate background color applies to
  dataroom view as well as front page

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-18 07:35:53 +00:00
Marc SeitzandGitHub 10d58b0832 Merge pull request #2076 from mfts/fix/download-custom 2026-02-18 16:23:51 +11:00
Cursor AgentandMarc Seitz ba9bd0c45c fix: merge PR #2069 fixes for allow/deny list sync issues
Incorporates fixes from PR #2069 (cursor/link-allow-list-email-update):
- Replace useEffect-based sync with direct onChange handler updates for
  allow-list and deny-list, preventing stale data on quick saves
- useEffect now only handles disabling when emailProtected is turned off
- Add key props to AllowListSection and DenyListSection in link-options
  to force remount when switching between links (prevents stale state)
- Visitor group clearing is also handled in the new useEffect pattern

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-16 03:59:47 +00:00
Cursor AgentandMarc Seitz 2c6f390ddc fix: add visitorGroups include to dataroom group links API
Ensure dataroom group links endpoint also returns visitor group
associations for proper editing in the link sheet.

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-12 07:42:19 +00:00
Cursor AgentandMarc Seitz 4237049af5 feat: add visitor groups UI and link integration
- Add VisitorGroupsSection component with create/edit/delete UI
- Add VisitorGroupModal for creating and editing groups
- Add 'Visitor Groups' tab to /visitors page
- Update AllowListSection with multi-group selector (popover with checkboxes)
- Add visitorGroupIds to DEFAULT_LINK_TYPE and link sheet data flow
- Update link create/update APIs to handle visitor group associations
- Update document and dataroom link fetch APIs to include visitorGroups
- Update LinkWithViews type to include visitorGroups
- Update views and views-dataroom routes to merge group emails with allow list
- Visitor group emails are additive: groups + individual emails combined

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-12 07:31:23 +00:00
Cursor AgentandMarc Seitz 9386dce3ee feat: add visitor groups API routes and SWR hook
- GET/POST /api/teams/:teamId/visitor-groups - list & create
- GET/PUT/DELETE /api/teams/:teamId/visitor-groups/:groupId - CRUD
- Deletion protection: prevents deletion if group is used by active links
- SWR hook for consuming visitor groups data in UI

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-12 07:14:48 +00:00
Cursor AgentandMarc Seitz bd109580ff feat: add VisitorGroup and LinkVisitorGroup models to Prisma schema
Add team-level visitor groups that allow users to define named groups
of emails/domains once, then apply them to document and data room links.

New models:
- VisitorGroup: team-scoped named group with emails/domains list
- LinkVisitorGroup: many-to-many join table between Link and VisitorGroup

Co-authored-by: Marc Seitz <mfts@users.noreply.github.com>
2026-02-12 07:13:18 +00:00
Marc Seitz 5d041f20f8 Merge branch 'main' into cursor/PM-468-dataroom-upload-visibility-b14f 2026-02-12 16:49:10 +11:00
Iuliia Shnai 8a874e10e0 feat:updates 2026-02-06 16:21:41 +11:00
Iuliia Shnai 7c50bf6242 featL:updates 2026-02-06 14:31:28 +11:00
Iuliia Shnai fb51399469 feat: add two sruvey questions 2026-02-06 14:29:12 +11:00
Marc Seitz 053394901c Merge branch 'main' into cursor/PM-468-dataroom-upload-visibility-b14f 2026-01-28 12:24:04 +11:00
Cursor Agentandmarcftone 5e7ff9fa29 feat: show uploaded documents immediately with processing state
- Add PendingUploadsContext for managing optimistic uploads
- Create PendingDocumentCard component to show uploading/processing documents
- Update upload API to return document data for optimistic display
- Update ViewerUploadComponent to track pending uploads
- Update DataroomViewer to display pending uploads at top of list
- Update DocumentUploadModal with success feedback and auto-close
- Add 'pending' prefix to id-helper for generating pending upload IDs

This ensures external visitors see their uploaded documents immediately
after upload, with a clear 'Processing...' indicator while the document
is being processed on the backend.

Fixes PM-468

Co-authored-by: marcftone <marcftone@gmail.com>
2026-01-21 10:33:38 +00:00
676 changed files with 22292 additions and 11872 deletions
+177
View File
@@ -0,0 +1,177 @@
Apache License
Version 2.0, January 2004
http://www.apache.org/licenses/
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
1. Definitions.
"License" shall mean the terms and conditions for use, reproduction,
and distribution as defined by Sections 1 through 9 of this document.
"Licensor" shall mean the copyright owner or entity authorized by
the copyright owner that is granting the License.
"Legal Entity" shall mean the union of the acting entity and all
other entities that control, are controlled by, or are under common
control with that entity. For the purposes of this definition,
"control" means (i) the power, direct or indirect, to cause the
direction or management of such entity, whether by contract or
otherwise, or (ii) ownership of fifty percent (50%) or more of the
outstanding shares, or (iii) beneficial ownership of such entity.
"You" (or "Your") shall mean an individual or Legal Entity
exercising permissions granted by this License.
"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation
source, and configuration files.
"Object" form shall mean any form resulting from mechanical
transformation or translation of a Source form, including but
not limited to compiled object code, generated documentation,
and conversions to other media types.
"Work" shall mean the work of authorship, whether in Source or
Object form, made available under the License, as indicated by a
copyright notice that is included in or attached to the work
(an example is provided in the Appendix below).
"Derivative Works" shall mean any work, whether in Source or Object
form, that is based on (or derived from) the Work and for which the
editorial revisions, annotations, elaborations, or other modifications
represent, as a whole, an original work of authorship. For the purposes
of this License, Derivative Works shall not include works that remain
separable from, or merely link (or bind by name) to the interfaces of,
the Work and Derivative Works thereof.
"Contribution" shall mean any work of authorship, including
the original version of the Work and any modifications or additions
to that Work or Derivative Works thereof, that is intentionally
submitted to Licensor for inclusion in the Work by the copyright owner
or by an individual or Legal Entity authorized to submit on behalf of
the copyright owner. For the purposes of this definition, "submitted"
means any form of electronic, verbal, or written communication sent
to the Licensor or its representatives, including but not limited to
communication on electronic mailing lists, source code control systems,
and issue tracking systems that are managed by, or on behalf of, the
Licensor for the purpose of discussing and improving the Work, but
excluding communication that is conspicuously marked or otherwise
designated in writing by the copyright owner as "Not a Contribution."
"Contributor" shall mean Licensor and any individual or Legal Entity
on behalf of whom a Contribution has been received by Licensor and
subsequently incorporated within the Work.
2. Grant of Copyright License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
copyright license to reproduce, prepare Derivative Works of,
publicly display, publicly perform, sublicense, and distribute the
Work and such Derivative Works in Source or Object form.
3. Grant of Patent License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
(except as stated in this section) patent license to make, have made,
use, offer to sell, sell, import, and otherwise transfer the Work,
where such license applies only to those patent claims licensable
by such Contributor that are necessarily infringed by their
Contribution(s) alone or by combination of their Contribution(s)
with the Work to which such Contribution(s) was submitted. If You
institute patent litigation against any entity (including a
cross-claim or counterclaim in a lawsuit) alleging that the Work
or a Contribution incorporated within the Work constitutes direct
or contributory patent infringement, then any patent licenses
granted to You under this License for that Work shall terminate
as of the date such litigation is filed.
4. Redistribution. You may reproduce and distribute copies of the
Work or Derivative Works thereof in any medium, with or without
modifications, and in Source or Object form, provided that You
meet the following conditions:
(a) You must give any other recipients of the Work or
Derivative Works a copy of this License; and
(b) You must cause any modified files to carry prominent notices
stating that You changed the files; and
(c) You must retain, in the Source form of any Derivative Works
that You distribute, all copyright, patent, trademark, and
attribution notices from the Source form of the Work,
excluding those notices that do not pertain to any part of
the Derivative Works; and
(d) If the Work includes a "NOTICE" text file as part of its
distribution, then any Derivative Works that You distribute must
include a readable copy of the attribution notices contained
within such NOTICE file, excluding those notices that do not
pertain to any part of the Derivative Works, in at least one
of the following places: within a NOTICE text file distributed
as part of the Derivative Works; within the Source form or
documentation, if provided along with the Derivative Works; or,
within a display generated by the Derivative Works, if and
wherever such third-party notices normally appear. The contents
of the NOTICE file are for informational purposes only and
do not modify the License. You may add Your own attribution
notices within Derivative Works that You distribute, alongside
or as an addendum to the NOTICE text from the Work, provided
that such additional attribution notices cannot be construed
as modifying the License.
You may add Your own copyright statement to Your modifications and
may provide additional or different license terms and conditions
for use, reproduction, or distribution of Your modifications, or
for any such Derivative Works as a whole, provided Your use,
reproduction, and distribution of the Work otherwise complies with
the conditions stated in this License.
5. Submission of Contributions. Unless You explicitly state otherwise,
any Contribution intentionally submitted for inclusion in the Work
by You to the Licensor shall be under the terms and conditions of
this License, without any additional terms or conditions.
Notwithstanding the above, nothing herein shall supersede or modify
the terms of any separate license agreement you may have executed
with Licensor regarding such Contributions.
6. Trademarks. This License does not grant permission to use the trade
names, trademarks, service marks, or product names of the Licensor,
except as required for reasonable and customary use in describing the
origin of the Work and reproducing the content of the NOTICE file.
7. Disclaimer of Warranty. Unless required by applicable law or
agreed to in writing, Licensor provides the Work (and each
Contributor provides its Contributions) on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
implied, including, without limitation, any warranties or conditions
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
PARTICULAR PURPOSE. You are solely responsible for determining the
appropriateness of using or redistributing the Work and assume any
risks associated with Your exercise of permissions under this License.
8. Limitation of Liability. In no event and under no legal theory,
whether in tort (including negligence), contract, or otherwise,
unless required by applicable law (such as deliberate and grossly
negligent acts) or agreed to in writing, shall any Contributor be
liable to You for damages, including any direct, indirect, special,
incidental, or consequential damages of any character arising as a
result of this License or out of the use or inability to use the
Work (including but not limited to damages for loss of goodwill,
work stoppage, computer failure or malfunction, or any and all
other commercial damages or losses), even if such Contributor
has been advised of the possibility of such damages.
9. Accepting Warranty or Additional Liability. While redistributing
the Work or Derivative Works thereof, You may choose to offer,
and charge a fee for, acceptance of support, warranty, indemnity,
or other liability obligations and/or rights consistent with this
License. However, in accepting such obligations, You may act only
on Your own behalf and on Your sole responsibility, not on behalf
of any other Contributor, and only if You agree to indemnify,
defend, and hold each Contributor harmless for any liability
incurred by, or claims asserted against, such Contributor by reason
of your accepting any such warranty or additional liability.
END OF TERMS AND CONDITIONS
+42
View File
@@ -0,0 +1,42 @@
---
name: frontend-design
description: Create distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, artifacts, posters, or applications (examples include websites, landing pages, dashboards, React components, HTML/CSS layouts, or when styling/beautifying any web UI). Generates creative, polished code and UI design that avoids generic AI aesthetics.
license: Complete terms in LICENSE.txt
---
This skill guides creation of distinctive, production-grade frontend interfaces that avoid generic "AI slop" aesthetics. Implement real working code with exceptional attention to aesthetic details and creative choices.
The user provides frontend requirements: a component, page, application, or interface to build. They may include context about the purpose, audience, or technical constraints.
## Design Thinking
Before coding, understand the context and commit to a BOLD aesthetic direction:
- **Purpose**: What problem does this interface solve? Who uses it?
- **Tone**: Pick an extreme: brutally minimal, maximalist chaos, retro-futuristic, organic/natural, luxury/refined, playful/toy-like, editorial/magazine, brutalist/raw, art deco/geometric, soft/pastel, industrial/utilitarian, etc. There are so many flavors to choose from. Use these for inspiration but design one that is true to the aesthetic direction.
- **Constraints**: Technical requirements (framework, performance, accessibility).
- **Differentiation**: What makes this UNFORGETTABLE? What's the one thing someone will remember?
**CRITICAL**: Choose a clear conceptual direction and execute it with precision. Bold maximalism and refined minimalism both work - the key is intentionality, not intensity.
Then implement working code (HTML/CSS/JS, React, Vue, etc.) that is:
- Production-grade and functional
- Visually striking and memorable
- Cohesive with a clear aesthetic point-of-view
- Meticulously refined in every detail
## Frontend Aesthetics Guidelines
Focus on:
- **Typography**: Choose fonts that are beautiful, unique, and interesting. Avoid generic fonts like Arial and Inter; opt instead for distinctive choices that elevate the frontend's aesthetics; unexpected, characterful font choices. Pair a distinctive display font with a refined body font.
- **Color & Theme**: Commit to a cohesive aesthetic. Use CSS variables for consistency. Dominant colors with sharp accents outperform timid, evenly-distributed palettes.
- **Motion**: Use animations for effects and micro-interactions. Prioritize CSS-only solutions for HTML. Use Motion library for React when available. Focus on high-impact moments: one well-orchestrated page load with staggered reveals (animation-delay) creates more delight than scattered micro-interactions. Use scroll-triggering and hover states that surprise.
- **Spatial Composition**: Unexpected layouts. Asymmetry. Overlap. Diagonal flow. Grid-breaking elements. Generous negative space OR controlled density.
- **Backgrounds & Visual Details**: Create atmosphere and depth rather than defaulting to solid colors. Add contextual effects and textures that match the overall aesthetic. Apply creative forms like gradient meshes, noise textures, geometric patterns, layered transparencies, dramatic shadows, decorative borders, custom cursors, and grain overlays.
NEVER use generic AI-generated aesthetics like overused font families (Inter, Roboto, Arial, system fonts), cliched color schemes (particularly purple gradients on white backgrounds), predictable layouts and component patterns, and cookie-cutter design that lacks context-specific character.
Interpret creatively and make unexpected choices that feel genuinely designed for the context. No design should be the same. Vary between light and dark themes, different fonts, different aesthetics. NEVER converge on common choices (Space Grotesk, for example) across generations.
**IMPORTANT**: Match implementation complexity to the aesthetic vision. Maximalist designs need elaborate code with extensive animations and effects. Minimalist or refined designs need restraint, precision, and careful attention to spacing, typography, and subtle details. Elegance comes from executing the vision well.
Remember: Claude is capable of extraordinary creative work. Don't hold back, show what can truly be created when thinking outside the box and committing fully to a distinctive vision.
+46
View File
@@ -0,0 +1,46 @@
---
name: postgres
description: PostgreSQL best practices, query optimization, connection troubleshooting, and performance improvement. Load when working with Postgres databases.
license: MIT
metadata:
author: planetscale
version: "1.0.0"
---
# PlanetScale Postgres
## Generic Postgres
| Topic | Reference | Use for |
| ---------------------- | ---------------------------------------------------------------- | --------------------------------------------------------- |
| Schema Design | [references/schema-design.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/schema-design.md) | Tables, primary keys, data types, foreign keys |
| Indexing | [references/indexing.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/indexing.md) | Index types, composite indexes, performance |
| Index Optimization | [references/index-optimization.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/index-optimization.md) | Unused/duplicate index queries, index audit |
| Partitioning | [references/partitioning.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/partitioning.md) | Large tables, time-series, data retention |
| Query Patterns | [references/query-patterns.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/query-patterns.md) | SQL anti-patterns, JOINs, pagination, batch queries |
| Optimization Checklist | [references/optimization-checklist.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/optimization-checklist.md) | Pre-optimization audit, cleanup, readiness checks |
| MVCC and VACUUM | [references/mvcc-vacuum.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/mvcc-vacuum.md) | Dead tuples, long transactions, xid wraparound prevention |
## Operations and Architecture
| Topic | Reference | Use for |
| ---------------------- | ---------------------------------------------------------------------------- | --------------------------------------------------------------- |
| Process Architecture | [references/process-architecture.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/process-architecture.md) | Multi-process model, connection pooling, auxiliary processes |
| Memory Architecture | [references/memory-management-ops.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/memory-management-ops.md) | Shared/private memory layout, OS page cache, OOM prevention |
| MVCC Transactions | [references/mvcc-transactions.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/mvcc-transactions.md) | Isolation levels, XID wraparound, serialization errors |
| WAL and Checkpoints | [references/wal-operations.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/wal-operations.md) | WAL internals, checkpoint tuning, durability, crash recovery |
| Replication | [references/replication.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/replication.md) | Streaming replication, slots, sync commit, failover |
| Storage Layout | [references/storage-layout.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/storage-layout.md) | PGDATA structure, TOAST, fillfactor, tablespaces, disk mgmt |
| Monitoring | [references/monitoring.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/monitoring.md) | pg_stat views, logging, pg_stat_statements, host metrics |
| Backup and Recovery | [references/backup-recovery.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/backup-recovery.md) | pg_dump, pg_basebackup, PITR, WAL archiving, backup tools |
## PlanetScale-Specific
| Topic | Reference | Use for |
| ------------------ | ---------------------------------------------------------------------------- | ----------------------------------------------------- |
| Connection Pooling | [references/ps-connection-pooling.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-connection-pooling.md) | PgBouncer, pool sizing, pooled vs direct |
| Extensions | [references/ps-extensions.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-extensions.md) | Supported extensions, compatibility |
| Connections | [references/ps-connections.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-connections.md) | Connection troubleshooting, drivers, SSL |
| Insights | [references/ps-insights.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-insights.md) | Slow queries, MCP server, pscale CLI |
| CLI Commands | [references/ps-cli-commands.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-cli-commands.md) | pscale CLI reference, branches, deploy requests, auth |
| CLI API Insights | [references/ps-cli-api-insights.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-cli-api-insights.md) | Query insights via `pscale api`, schema analysis |
@@ -0,0 +1,41 @@
---
title: Backup and Recovery
description: Logical/physical backups, PITR, WAL archiving, backup tools, and recovery strategies
tags: postgres, backup, recovery, pitr, pg_dump, pg_basebackup, wal-archiving, operations
---
# Backup and Recovery
**FUNDAMENTAL RULE: Backups are useless until you've successfully tested recovery.**
## Logical Backups (pg_dump)
Exports as SQL or custom format; portable across PG versions and architectures. Formats: `-Fp` (plain SQL), `-Fc` (custom compressed, selective restore), `-Fd` (directory, parallel with `-j`), `-Ft` (tar, avoid). Use `-Fd -j 4` for large DBs. Restore: `pg_restore -d dbname file.dump`; add `-j` for parallel restore. Selective table restore: `pg_restore -t tablename`. Slow for large DBs; RPO = backup frequency (typically 24h).
## Physical Backups (pg_basebackup)
Copies raw PGDATA; same major version and platform required; cross-architecture works if same endianness (e.g., x86_64 ↔ ARM64). Faster for large clusters; includes all databases. Flags: `-Ft -z -P` for compressed tar with progress. Manual alternative: `pg_backup_start()` → copy PGDATA → `pg_backup_stop()` (complex; must write returned `backup_label`).
## PITR (Point-in-Time Recovery)
Requires base backup + continuous WAL archiving. Restores to any timestamp, transaction, or named restore point. Without PITR: restore only to backup time (potentially lose hours). With PITR: RPO = minutes. `archive_command` must return 0 ONLY when file is safely stored—premature 0 = data loss risk. `wal_level` must be `replica` or `logical` (not `minimal`).
## WAL Archiving
`archive_mode=on`, `archive_command='test ! -f /archive/%f && cp %p /archive/%f'`. **Test archive command as postgres user** (not root) since permission issues are common. Monitor `pg_stat_archiver` for `failed_count`, `last_archived_time`. Archive failures prevent WAL recycling → disk fills.
## Tool Comparison
| Tool | Use case |
|------|----------|
| pg_dump | Small DBs, migrations, selective restore |
| pg_basebackup | Basic PITR, built-in |
| pgBackRest | Production—parallel, incremental, S3/GCS/Azure, retention |
| Barman | Enterprise PITR, retention policies |
| WAL-G | Cloud-native, S3/GCS/Azure |
## RPO/RTO
Logical only: RPO = backup interval (hours); RTO = hours. PITR: RPO = minutes; RTO = hours. Synchronous replication: RPO = 0; RTO = seconds to minutes (failover).
## Operational Rules
- Verify integrity with `pg_verifybackup` (PG 13+)
- Test recovery / PITR regularly
- Take backups from standby to avoid impacting primary
- Retention: 7 daily, 4 weekly, 12 monthly
- Monitor archive growth and backup age
- **Never assume backups work without testing**
@@ -0,0 +1,69 @@
---
title: Index Optimization Queries
description: Index audit queries
tags: postgres, indexes, unused-indexes, duplicate-indexes, optimization
---
# Index Optimization
## Identify Unused Indexes
Query to find unused indexes:
```sql
-- indexes with 0 scans (check pg_stat_reset / pg_postmaster_start_time first)
SELECT
s.schemaname,
s.relname AS table_name,
s.indexrelname AS index_name,
pg_size_pretty(pg_relation_size(s.indexrelid)) AS index_size
FROM pg_catalog.pg_stat_user_indexes s
JOIN pg_catalog.pg_index i ON s.indexrelid = i.indexrelid
WHERE s.idx_scan = 0
AND 0 <> ALL (i.indkey) -- exclude expression indexes
AND NOT i.indisunique -- exclude UNIQUE indexes
AND NOT EXISTS ( -- exclude constraint-backing indexes
SELECT 1 FROM pg_catalog.pg_constraint c
WHERE c.conindid = s.indexrelid
)
ORDER BY pg_relation_size(s.indexrelid) DESC;
```
## Indexes Per Table Guidelines
- **< 5**: Normal
- **5-10**: Monitor (Verify necessity)
- **> 10**: Audit required (High write overhead)
```sql
SELECT relname AS table, count(*) as index_count
FROM pg_stat_user_indexes
GROUP BY relname
ORDER BY count(*) DESC;
```
## Identify Unused Indexes
Indexes with identical definitions (after normalizing names) on the same table are duplicates:
```sql
SELECT
schemaname || '.' || tablename AS table,
array_agg(indexname) AS duplicate_indexes,
pg_size_pretty(sum(pg_relation_size((schemaname || '.' || indexname)::regclass))) AS total_size
FROM pg_indexes
WHERE schemaname NOT IN ('pg_catalog', 'information_schema')
GROUP BY schemaname, tablename,
regexp_replace(indexdef, 'INDEX \S+ ON ', 'INDEX ON ')
HAVING count(*) > 1;
```
**Always confirm with a human before dropping or removing any indexes identified by the queries above.** Even indexes with 0 scans may be needed for infrequent but critical queries, and stats may have been reset recently.
## Per-table Index Count Guidelines
| Index Count | Recommendation |
| ----------- | ------------------------------------------- |
| <5 | Normal |
| 5-10 | Review for unused/duplicates |
| >10 | Audit required - significant write overhead |
@@ -0,0 +1,61 @@
---
title: Indexing Best Practices
description: Index design guide
tags: postgres, indexes, composite, partial, covering, gin, brin
---
# Indexing Best Practices
## Core Rules
1. **Always index foreign key columns** — PostgreSQL does not auto-create these
2. **Index columns in WHERE, JOIN, and ORDER BY** clauses
3. **Don't over-index** — each index slows writes and uses storage
4. **Verify with EXPLAIN ANALYZE** — confirm indexes are actually used
## Composite Indexes
Put equality columns first, then range/sort columns:
```sql
-- WHERE status = 'active' AND created_at > '2026-01-01'
CREATE INDEX order_status_created_idx ON order (status, created_at);
```
A composite index on `(a, b)` supports queries on `a` + `b` and `a` alone, but not `b` alone.
## Partial Indexes
Reduce index size by filtering to common query patterns.
Only use if index size is problematic but the index is needed for performance.
```sql
CREATE INDEX order_active_idx ON order (customer_id)
WHERE status = 'active';
```
## Covering Indexes
Consider creating covering indexes for commonly executed query patterns that return only 1 or a small number of columns.
## Index Types
| Type | Use Case | Example |
| --- | --- | --- |
| B-tree (default) | Equality, range, sorting | `WHERE id = 1`, `ORDER BY date` |
| GIN | Arrays, JSONB, full-text | `WHERE tags @> ARRAY['x']` |
| GiST | Geometric, range types, full-text | PostGIS, `tsrange`, `tsvector` |
| BRIN | Large sequential/time-series | Append-only logs, events (requires physical row order correlation) |
```sql
CREATE INDEX metadata_idx ON order USING GIN (metadata); -- JSONB
CREATE INDEX event_created_idx ON event USING BRIN (created_at); -- time-series
```
## Guidelines
- Name indexes consistently: `{table}_{column}_idx`
- Review for unused indexes periodically
- **Always confirm with a human before removing or dropping any indexes** — even unused ones may serve a purpose not reflected in recent stats
- Use partial indexes for frequently filtered subsets
- Use covering indexes on hot read paths
@@ -0,0 +1,39 @@
---
title: Memory Architecture and OOM Prevention
description: PostgreSQL shared/private memory layout, OS page cache interaction, and OOM avoidance strategies
tags: postgres, memory, shared_buffers, work_mem, oom, architecture, operations
---
# Memory Architecture and OOM Prevention
## Memory Areas
- **Shared memory**: `shared_buffers` — main data cache, all processes, requires restart to change.
- **Private per backend**: `work_mem` (sorts/hashes/joins, per-operation); `maintenance_work_mem` (VACUUM, CREATE INDEX, ALTER TABLE ADD FOREIGN KEY); `temp_buffers` (8MB default).
- **Planner hint only**: `effective_cache_size` is NOT allocated — set to ~5075% of total RAM.
- **Hash multiplier**: `hash_mem_multiplier` (default 2.0) means hash ops use up to 2× `work_mem`.
## Memory Multiplication Danger
Maximum potential: `work_mem × operations_per_query × (parallel_workers + 1) × connections` (leader participates by default via `parallel_leader_participation = on`; hash operations use up to `hash_mem_multiplier × work_mem`, default 2.0). Example: 128MB work_mem, 3 ops (2 sorts + 1 hash join), 2 parallel workers, 100 connections → 2 sorts at 128MB = 256MB, 1 hash join at 128MB × 2.0 = 256MB, per process = 512MB, × 3 processes (2 workers + leader) = 1536MB/query, × 100 connections = **~150GB** worst case. This case is rare.
Not all queries hit limits at once, but high concurrency + large datasets approach it. This is a common cause of OOM in containerized/Kubernetes deployments. Plan capacity with a 1.52× safety margin.
## OS Page Cache (Double Buffering)
Data exists in both `shared_buffers` and OS page cache. A miss in shared_buffers can still hit OS cache (avoiding disk I/O). Extremely large shared_buffers can hurt performance: less OS cache, slower startup, heavier checkpoints. Optimal split depends on workload (OLTP vs OLAP).
## OOM Prevention
- Implement connection pooling to reduce total backend count.
- Reduce `work_mem` globally; use per-session overrides for heavy queries only.
- Lower `max_parallel_workers_per_gather` in high-concurrency systems.
- Set `statement_timeout` to kill runaway queries.
- Monitor: `dmesg -T | grep "killed process"` and `temp_blks_written` in pg_stat_statements.
## Operational Rules
- Tune per-session first, global last.
- Suspect OOM when memory spikes during high concurrency, dashboards, or large batch jobs.
- Increase memory only after confirming spill behavior (`temp_blks_written > 0`).
- `maintenance_work_mem` can be set much higher (12GB) — fewer processes use it. Cap autovacuum with `autovacuum_work_mem` to avoid `autovacuum_max_workers × maintenance_work_mem` memory spikes.
- `shared_buffers` change requires full restart; `work_mem` is per-session changeable.
@@ -0,0 +1,59 @@
---
title: Monitoring
description: Essential PostgreSQL monitoring views, pg_stat_statements, logging, host metrics, and statistics management
tags: postgres, monitoring, pg_stat_statements, logging, pgbadger, metrics, operations
---
# Monitoring
## Essential Views
- **pg_stat_activity**: First stop when something is wrong — running queries, states, wait events, locks.
- **pg_stat_statements**: Execution stats for all SQL. Requires `shared_preload_libraries = 'pg_stat_statements'` and `CREATE EXTENSION pg_stat_statements`.
- **pg_stat_database**: Cache hit ratio, temp files, deadlocks, connections per database.
- **pg_stat_user_tables**: `seq_scan` vs `idx_scan`, dead tuples, last vacuum/analyze times.
- **pg_stat_user_indexes**: Find unused indexes (`idx_scan = 0` with large size).
- **pg_stat_bgwriter**: `buffers_clean`, `maxwritten_clean`, `buffers_alloc`. Pre-PG 17 also had `buffers_checkpoint`, `buffers_backend` (high = backends bypassing bgwriter). PG 17+ moved checkpoint stats to `pg_stat_checkpointer`.
- **pg_stat_checkpointer** (PG 17+): Checkpoint frequency (`num_timed`, `num_requested`), write/sync time.
## Key Queries
```sql
-- Slow queries (with cache hit ratio)
SELECT query, calls, mean_exec_time,
100.0 * shared_blks_hit / nullif(shared_blks_hit + shared_blks_read, 0) AS cache_hit_pct
FROM pg_stat_statements ORDER BY mean_exec_time DESC LIMIT 10;
-- Connection counts / states
SELECT state, count(*) FROM pg_stat_activity GROUP BY state;
-- Dead tuples (vacuum candidates)
SELECT relname, n_dead_tup, last_autovacuum FROM pg_stat_user_tables ORDER BY n_dead_tup DESC;
-- last_autovacuum = <null> means autovacuum has not run on this table
```
Blocking: use `pg_blocking_pids(pid)` with `pg_stat_activity` to find blocked and blocking sessions.
## Logging — First Line of Defense
PostgreSQL is extremely vocal about problems. **Always check logs first**: `tail -f /var/log/postgresql/postgresql-*.log`.
Key settings: `log_min_duration_statement` (OLTP: 13s, analytics: 3060s, dev: 100500ms). Enable `log_checkpoints=on`, `log_connections=on`, `log_disconnections=on`, `log_lock_waits=on`, `log_temp_files=0`. Use CSV log format for pgBadger analysis; pgBadger generates HTML reports with query stats and performance graphs.
## pg_activity
Interactive top-like tool (pip install pg_activity). Run on DB host for OS metrics alongside PG metrics. Combines `pg_stat_activity` with CPU/memory/I/O context.
## Host Metrics — Critical
PostgreSQL cannot report these. **Monitor them yourself:**
- **CPU**: Steal time >10% in VMs bad; load average > core count; context switches >100k/sec.
- **Memory**: Any swap = performance degradation. Check `dmesg` for OOM kills.
- **Disk I/O**: `iostat -x``%util=100%` means saturated; `await` >10ms = high latency.
- **Disk space**: >90% critical (VACUUM fails, writes fail). Check inode usage too.
- **Network**: Packet loss >0% = problems; high retransmits = instability.
## Statistics Management
Stats accumulate since last reset or restart; check `stats_reset` timestamp. `pg_stat_statements_reset()` clears query stats; `pg_stat_reset()` clears database stats. Reset after major maintenance, config changes, or perf testing — not routinely. Prefer snapshotting stats to external monitoring (Prometheus, Datadog) over resetting. **Always confirm with a human before resetting statistics** — resetting destroys historical performance baselines and can make it harder to identify unused indexes or regressions.
@@ -0,0 +1,38 @@
---
title: MVCC Transactions and Concurrency
description: Transaction isolation levels, XID wraparound prevention, serialization errors, and long-transaction impact
tags: postgres, mvcc, transactions, isolation, xid-wraparound, concurrency, serialization
---
# MVCC Transactions and Concurrency
## Transaction Isolation Levels
- **READ UNCOMMITTED** — treated as READ COMMITTED in PostgreSQL; no dirty reads ever.
- **READ COMMITTED** (default): new snapshot per statement; can see different data within same tx.
- **REPEATABLE READ**: snapshot at first query; can cause serialization errors on write conflicts.
- **SERIALIZABLE**: strongest; transactions appear serial; requires retry logic in app code.
Readers never block writers; writers never block readers (only writer-writer conflicts on same row). No lock escalation — row locks never degrade to table locks.
## XID Wraparound
32-bit transaction IDs wrap at ~2 billion (2^31). `VACUUM FREEZE` replaces old XIDs with FrozenXID (value 2, always visible). Without freeze: after wraparound, old rows appear "in the future" and become **invisible**. Data physically exists but is invisible to all queries — looks like total data loss. PostgreSQL emergency shutdown at 2B XIDs to prevent this. XID wraparound should be avoided at all cost.
Warning messages start at ~1.4B XIDs; shutdown at 2B. Recovery requires single-user mode VACUUM — can take hours to days on large DBs. **Never disable autovacuum** — it's your protection against wraparound.
## XID Age Monitoring
```sql
SELECT datname, age(datfrozenxid),
ROUND(100.0 * age(datfrozenxid) / 2147483648, 2) AS pct
FROM pg_database ORDER BY age(datfrozenxid) DESC;
```
## Long Transaction Impact
A single long-running transaction blocks VACUUM from removing dead tuples across the **entire database**. Causes table bloat, increased disk, slower queries, cache pollution. `idle_in_transaction` connections are the #1 operational MVCC issue. Set `idle_in_transaction_session_timeout` (30s5min). Dead tuples waste I/O on seq scans and cause useless heap lookups from indexes.
## Serialization Errors
Apps **must** handle "could not serialize access" with retry logic. More common in REPEATABLE READ and SERIALIZABLE. Smaller, faster transactions reduce conflict frequency.
@@ -0,0 +1,41 @@
---
title: MVCC and VACUUM
description: MVCC internals, VACUUM/autovacuum tuning, and bloat prevention
tags: postgres, mvcc, vacuum, autovacuum, xid, bloat, dead-tuples
---
# MVCC and VACUUM
## MVCC
Every `UPDATE` creates a new tuple and marks the old one dead; `DELETE` marks tuples dead. Dead tuples accumulate until `VACUUM` reclaims space. Each transaction gets a 32-bit XID (2^32 ≈ 4B values, but modular comparison means the effective danger zone is 2^31 ≈ 2B). VACUUM must freeze old XIDs to prevent wraparound.
## VACUUM vs VACUUM FULL
`VACUUM` is non-blocking (ShareUpdateExclusive lock) and marks dead space reusable. `VACUUM FULL` rewrites the table and requires an AccessExclusive lock — use only as a last resort. For online bloat reduction prefer `pg_squeeze` or `pg_repack`.
## Autovacuum Tuning
Triggers when dead tuples > `Min(autovacuum_vacuum_max_threshold, autovacuum_vacuum_threshold + autovacuum_vacuum_scale_factor * reltuples)`. `autovacuum_vacuum_max_threshold` defaults to 100M (PG 18+), capping the threshold for very large tables. Also triggers on inserts exceeding `autovacuum_vacuum_insert_threshold + autovacuum_vacuum_insert_scale_factor * reltuples * pct_not_frozen` (ensures insert-only tables get frozen; PG 13+). For large/hot tables, set per-table overrides:
- `autovacuum_vacuum_scale_factor` — default 0.2; lower to 0.010.05 for large tables.
- `autovacuum_vacuum_cost_delay` — default 2 ms; set to 0 on fast storage.
- `autovacuum_vacuum_cost_limit` — default -1 (uses `vacuum_cost_limit`, effectively 200); raise to 10002000 on fast storage.
- `autovacuum_freeze_max_age` — default 200M; triggers anti-wraparound vacuum.
- `vacuum_failsafe_age` — default 1.6B; last-resort mode (PG 14+) that disables throttling and skips index vacuuming when wraparound is imminent.
## Key Monitoring Queries
Dead tuples: `SELECT relname, n_dead_tup, last_autovacuum FROM pg_stat_user_tables ORDER BY n_dead_tup DESC;`
XID age: `SELECT datname, age(datfrozenxid) AS xid_age FROM pg_database ORDER BY xid_age DESC;`
Long transactions: `SELECT pid, state, now() - xact_start AS tx_age FROM pg_stat_activity WHERE xact_start IS NOT NULL ORDER BY xact_start;`
## Best Practices
- Keep transactions short; set `idle_in_transaction_session_timeout` (30s5min).
- Alert when `age(datfrozenxid)` exceeds 4050% of wraparound (~800M1B).
- Tune autovacuum per-table for write-heavy tables; don't change global defaults first.
- Fix application transaction scope before adjusting vacuum parameters.
- Never disable autovacuum globally.
@@ -0,0 +1,19 @@
---
title: Database Optimization Checklist
description: Optimize checklist
tags: postgres, optimization, indexes, partitioning, maintenance
---
# Optimization Checklist
When optimizing performance, check the following:
- Look for unused indexes (0 scans; exclude unique/primary indexes and verify stats age first)
- Look for duplicate indexes
- Archive audit/log tables >10GB
- Review tables >500GB for partitioning (>100GB for time-series/logs)
- Verify all extensions are supported
- Check for circular foreign key dependencies
- Consider alternatives to UUID primary keys for large tables
- Configure connection pooling for OLTP workloads
- **Always confirm with a human before removing any indexes, dropping partitions, archiving tables, or performing other destructive actions**
@@ -0,0 +1,79 @@
---
title: Table Partitioning Guide
description: Partition guide
tags: postgres, partitioning, range, list, pg_partman, data-retention
---
# Table Partitioning
Plan partitioning upfront for tables expected to grow large. Retrofitting later requires a migration.
## When to Partition
Partitioning benefits maintenance (vacuum, index builds) and data retention more than pure query speed.
| Table Type | Size Threshold | Row Threshold |
| --- | --- | --- |
| General tables | >100 GB (or >RAM) | >20M rows |
| Time-series / logs | >50 GB | >10M rows |
Use the lower thresholds for append-heavy, time-ordered data with retention needs (logs, events, audit trails, metrics).
## Range Partitioning (Most Common)
```sql
-- EXAMPLE
CREATE TABLE event (
id BIGINT GENERATED ALWAYS AS IDENTITY,
event_type TEXT NOT NULL,
payload JSONB,
created_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
PRIMARY KEY (id, created_at) -- Partition key MUST be part of PK
) PARTITION BY RANGE (created_at);
CREATE TABLE event_2026_01 PARTITION OF event
FOR VALUES FROM ('2026-01-01') TO ('2026-02-01');
CREATE TABLE event_2026_02 PARTITION OF event
FOR VALUES FROM ('2026-02-01') TO ('2026-03-01');
```
## List Partitioning
Useful for partitioning by region, tenant, or category:
```sql
-- EXAMPLE
CREATE TABLE order (
id BIGINT GENERATED ALWAYS AS IDENTITY,
region TEXT NOT NULL,
total NUMERIC(10,2),
PRIMARY KEY (id, region) -- Partition key MUST be part of PK
) PARTITION BY LIST (region);
CREATE TABLE order_us PARTITION OF order FOR VALUES IN ('us');
CREATE TABLE order_eu PARTITION OF order FOR VALUES IN ('eu');
CREATE TABLE order_default PARTITION OF order DEFAULT; -- catches unmatched values
```
## Partition Management
- Use `pg_partman` (extension) to automate partition creation and cleanup.
- Use `DETACH PARTITION` to remove a partition while retaining it as a standalone table (e.g., for archiving).
- Use `DETACH PARTITION ... CONCURRENTLY` (PG 14+) to avoid `ACCESS EXCLUSIVE` locks on the parent table.
- Drop old partitions for data retention instead of `DELETE` to avoid vacuum overhead and bloat.
- Create future partitions ahead of time to avoid insert failures.
- **Always confirm with a human before detaching or dropping partitions.** These are destructive actions — detaching removes data from the partitioned table, and dropping permanently deletes the data.
```sql
-- DESTRUCTIVE: confirm with a human before executing
ALTER TABLE event DETACH PARTITION event_2025_01 CONCURRENTLY;
DROP TABLE event_2025_01;
```
## Guidelines & Limitations
- **Primary Keys**: Partition key columns MUST be included in the `PRIMARY KEY` and any `UNIQUE` constraints.
- **Global Uniqueness**: Global unique constraints on non-partition columns are NOT supported.
- **Indexes**: Indexes defined on the parent are automatically created on all partitions (and future ones).
- **Pruning**: Ensure queries filter by the partition key to enable "partition pruning" (skipping unrelated partitions).
@@ -0,0 +1,46 @@
---
title: Process Architecture
description: PostgreSQL multi-process model, connection management, and auxiliary processes
tags: postgres, processes, connections, pooling, memory, operations
---
# Process Architecture
PostgreSQL uses a **multi-process** model, not multi-threaded: one OS process per client connection. The postmaster is the parent; it spawns backend processes per connection. Each backend has some private memory (`work_mem`, temp buffers). 1000 connections = 1000 processes (~510MB base + query memory each). There is also a large buffer shared amongst all.
## Auxiliary Processes
WAL Writer, Background Writer, Checkpointer, Autovacuum Launcher/Workers, Archiver, WAL Summarizer (PG 17+). These run alongside backends and are not spawned per connection.
## Memory Risk
`work_mem` is per-operation, not per-query. Estimate: `work_mem × operations_per_query × parallel_workers × connections` can grow very large at high concurrency. Scale connections and parallelism before raising `work_mem`.
## Connection Pooling (Critical)
Each connection = OS process (fork overhead, context switching, memory). PgBouncer can multiplex many app connections to fewer DB connections. Typical: 1000 app connections → pooler → 2050 backends. Implement pooling before raising `max_connections`; `max_connections` requires a full restart to change (default 100). Note: `superuser_reserved_connections` (default 3) reserves slots for emergency superuser access, so non-superusers are rejected before `max_connections` is fully reached.
## Monitoring
```sql
SELECT state, count(*) FROM pg_stat_activity WHERE backend_type = 'client backend' GROUP BY state;
```
```sql
-- Show used and free connection slots
SELECT count(*) AS used, max(max_conn) - count(*) AS free
FROM pg_stat_activity, (SELECT setting::int AS max_conn FROM pg_settings WHERE name = 'max_connections') s
WHERE backend_type = 'client backend';
```
Use `pg_activity` for interactive top-like monitoring. Alert at 80% connection usage, critical at 95%. Count by state to find idle-in-transaction leaks — these hold locks and **block VACUUM** from reclaiming dead tuples.
## Common Problems
| Problem | Fix |
| ------- | --- |
| `too many clients already` | Implement pooling; find idle connections; check for connection leaks |
| High memory / OOM | Reduce `work_mem`; add pooling; set `statement_timeout` |
| Stuck process | `SELECT pg_cancel_backend(pid);` then `SELECT pg_terminate_backend(pid);`**always confirm with a human before terminating backends**, as this may abort in-flight transactions and cause data issues for the application |
Prefer pooling + conservative `max_connections` over raising limits reactively.
@@ -0,0 +1,53 @@
---
title: CLI Query Insights API
description: CLI insights usage
tags: postgres, planetscale, cli, insights, query-patterns, api
---
# Query Insights via pscale CLI
Analyze slow queries and missing indexes using `pscale api`. Endpoints may change—see https://planetscale.com/docs/api/reference/getting-started-with-planetscale-api for current API docs.
## Using pscale api
The `pscale api` command makes authenticated API calls using your current login or service token (see [ps-cli-commands.md](ps-cli-commands.md#service-token-cicd) for auth setup). No need to manage auth headers manually.
```bash
pscale api "<endpoint>" [--method POST] [--field key=value] [--org <org>]
```
## Query Patterns Reports
```bash
# Create a new report
pscale api "organizations/{org}/databases/{db}/branches/{branch}/query-patterns-reports" \
--method POST --org my-org
# Check status (poll until state=complete)
pscale api "organizations/{org}/databases/{db}/branches/{branch}/query-patterns-reports/{id}/status"
# Download completed report
pscale api "organizations/{org}/databases/{db}/branches/{branch}/query-patterns-reports/{id}"
# List all reports
pscale api "organizations/{org}/databases/{db}/branches/{branch}/query-patterns-reports"
```
## Schema Analysis
```bash
# Get branch schema
pscale api "organizations/{org}/databases/{db}/branches/{branch}/schema"
# Lint schema for issues
pscale api "organizations/{org}/databases/{db}/branches/{branch}/schema/lint"
```
## What to Look For
| Metric | Indicates | Action |
| -------------------------------- | --------------------- | ------------------------------- |
| High `rows_read / rows_returned` | Missing or poor index | Add index on WHERE/JOIN columns |
| High `total_time_s` | Heavy query | Optimize or cache |
| High `count` with same pattern | N+1 queries | Batch or eager-load |
| `indexed: false` | Full table scan | Add index |
@@ -0,0 +1,72 @@
---
title: PlanetScale CLI Reference
description: CLI command guide
tags: planetscale, cli, branches, deploy-requests, authentication
---
# pscale CLI Commands
Full CLI reference: https://planetscale.com/docs/cli. Use `pscale <command> --help` for subcommands and flags.
## Authentication
```bash
pscale auth login # Opens browser
pscale auth logout
pscale org list
pscale org switch <name>
```
### Service Token (CI/CD)
```bash
# Create and configure
pscale service-token create
pscale service-token add-access <id> read_branch --database <db>
# Use in CI/CD
export PLANETSCALE_SERVICE_TOKEN_ID="<id>"
export PLANETSCALE_SERVICE_TOKEN="<token>"
```
## Core Commands
```bash
# Databases
pscale database list
pscale database create <name>
# Branches
pscale branch list <db>
pscale branch create <db> <branch> [--from <parent>]
pscale branch delete <db> <branch> # DESTRUCTIVE — always confirm with a human first
pscale branch schema <db> <branch>
# Deploy requests (schema changes) — Vitess only
pscale deploy-request create <db> <branch>
pscale deploy-request list <db>
pscale deploy-request deploy <db> <number>
# Connect
pscale shell <db> <branch> # Opens psql (Postgres) or mysql (Vitess)
pscale connect <db> <branch> # Proxy for GUI tools (secure tunnel) — Vitess only
# Credentials
pscale role create <db> <branch> <name> # Postgres
pscale password create <db> <branch> <name> # Vitess
# Other
pscale ping # Check latency to regions
pscale region list # Available regions
pscale backup list <db> <branch>
pscale backup create <db> <branch>
```
## Useful Flags
```bash
--format json # Output as JSON (also: csv, human)
--org <name> # Specify organization
--debug # Debug output
```
For API calls via CLI, see [ps-cli-api-insights.md](ps-cli-api-insights.md).
@@ -0,0 +1,72 @@
---
title: PgBouncer Connection Pooling
description: Pooling setup guide
tags: postgres, pgbouncer, connection-pooling, performance, transactions
---
# Connection Pooling with PgBouncer
PlanetScale provides PgBouncer for connection pooling. Connect on port `6432` instead of `5432`.
## When to Use PgBouncer (Port 6432)
All OLTP application workloads: web apps, APIs, high-concurrency read/write operations.
## When to Use Direct Connections (Port 5432)
- Schema changes (DDL)
- Analytics, reporting, batch processing
- Session-specific features (temp tables, session variables)
- ETL, data streaming, `pg_dump`
- Long-running admin transactions
## PgBouncer Types
PlanetScale offers three PgBouncer options. All use port `6432`.
| Type | Runs On | Routes To | Key Trait |
| ---- | ------- | --------- | --------- |
| **Local** | Same node as primary | Primary only | Included with every database; no replica routing |
| **Dedicated Primary** | Separate node | Primary | Connections persist through resizes, upgrades, and most failovers |
| **Dedicated Replica** | Separate node | Replicas | Read-only traffic; supports AZ affinity for lower latency |
- **Local PgBouncer** — use same credentials as direct, just change port to `6432`. Always routes to primary regardless of username.
- **Dedicated Primary** — runs off-server for improved HA. Use for production OLTP write traffic.
- **Dedicated Replica** — runs off-server for read-heavy workloads. Supports AZ affinity to prefer same-zone replicas. Multiple can be created for capacity or per-app isolation.
To connect to a dedicated PgBouncer, append `|pgbouncer-name` to the username (e.g., `postgres.xxx|write-pool` or `postgres.xxx|read-bouncer`).
## Transaction Pooling Limitations
PlanetScale PgBouncer uses **transaction pooling mode**. These features are unavailable:
- Prepared statements that persist across transactions
- Temporary tables
- `LISTEN`/`NOTIFY`
- Session-level advisory locks
- `SET` commands persisting beyond a transaction
## Recommended Patterns
- Size pools from observed concurrency, query memory behavior, and connection limits.
- Keep pooled app traffic on `6432` and reserve direct connections for DDL/admin/long-running jobs.
## Avoid Patterns
- Avoid setting pool size with only `CPU_cores * N` while ignoring query-memory amplification.
- Avoid running session-dependent workflows through transaction pooling.
## Connecting
```bash
# Local PgBouncer (same credentials, port 6432)
psql 'host=xxx.horizon.psdb.cloud port=6432 user=postgres.xxx password=pscale_pw_xxx dbname=mydb sslnegotiation=direct sslmode=verify-full sslrootcert=system'
# Dedicated primary PgBouncer (append |pgbouncer-name to user)
psql 'host=xxx.horizon.psdb.cloud port=6432 user=postgres.xxx|write-pool password=pscale_pw_xxx dbname=mydb sslnegotiation=direct sslmode=verify-full sslrootcert=system'
# Dedicated replica PgBouncer (append |pgbouncer-name to user)
psql 'host=xxx.horizon.psdb.cloud port=6432 user=postgres.xxx|read-bouncer password=pscale_pw_xxx dbname=mydb sslnegotiation=direct sslmode=verify-full sslrootcert=system'
```
Docs: https://planetscale.com/docs/postgres/connecting/pgbouncer
@@ -0,0 +1,37 @@
---
title: PlanetScale Postgres Connections
description: Connection guide for PlanetScale Postgres
tags: planetscale, postgres, connections, ssl, troubleshooting
---
# PlanetScale Postgres Connections
Postgres docs: https://planetscale.com/docs/postgres/connecting
| Protocol | Standard Port | Pooled Port | SSL |
| -------- | ------------- | ----------------------- | -------- |
| Postgres | 5432 | 6432 (PgBouncer) | Required |
Credentials (roles) are branch-specific and cannot be recovered after creation.
## Connection String
```
postgresql://<user>:<password>@<host>.horizon.psdb.cloud:5432/<database>?sslmode=verify-full&sslrootcert=system&sslnegotiation=direct
```
Use port **6432** for PgBouncer (applications/OLTP).
Use port **5432** for DDL, admin tasks, and migrations.
## Troubleshooting
| Error | Fix |
| -------------------------------- | --------------------------------------- |
| `password authentication failed` | Check role format: `<role>.<branch_id>` |
| `too many clients already` | Use PgBouncer (port 6432) |
| `SSL connection is required` | Add `sslmode=verify-full&sslrootcert=system` |
**Best practices:**
- Use the PlanetScale Postgres metrics page to monitor direct and PgBouncer connections
- Route OLTP traffic to port 6432 and reserve 5432 for admin/migrations.
- Avoid raising `max_connections` reactively instead of pooling.
@@ -0,0 +1,27 @@
---
title: PlanetScale PostgreSQL Extensions
description: Extension reference
tags: postgres, extensions
---
# PostgreSQL Extensions on PlanetScale
Only use PlanetScale-supported extensions. For the complete and up-to-date list of available extensions, see: https://planetscale.com/docs/postgres/extensions
Do not rely on hard-coded extension lists — always check the documentation above for current availability.
## Enabling Extensions
Some extensions must first be **enabled in the PlanetScale Dashboard** (Clusters > Extensions) before they can be created in SQL. This often requires a database restart.
Once enabled in the dashboard, create the extension in SQL:
```sql
CREATE EXTENSION IF NOT EXISTS <extension_name>;
```
## Recommended Patterns
- Always check the [PlanetScale extensions docs](https://planetscale.com/docs/postgres/extensions) before assuming an extension is available.
- Verify extension availability in PlanetScale configuration and docs before schema design depends on it.
- Enable `pg_stat_statements` early for baseline query telemetry.
@@ -0,0 +1,62 @@
---
title: PlanetScale Query Insights
description: Query insights guide
tags: postgres, planetscale, insights, monitoring, optimization
---
# PlanetScale Insights
## Fetch current documentation first
Prefer retrieval over pre-training knowledge. Docs: https://planetscale.com/docs
## MCP Server (Preferred)
When the PlanetScale MCP server is configured in your environment, prefer it over CLI. Key tools:
- `planetscale_get_branch_schema` — Get schema for a branch
- `planetscale_execute_read_query` — Run SELECT, SHOW, DESCRIBE, EXPLAIN
- `planetscale_get_insights` — Query performance insights
- `planetscale_list_schema_recommendations` — Index and schema suggestions
- `planetscale_search_documentation` — Search PlanetScale docs
MCP setup: https://planetscale.com/docs/connect/mcp
The MCP server is the ideal way to interact with insights from an AI agent.
If not installed, prompt the user to install it to make the agent more effective.
## Query Insights (CLI)
Generating reports via CLI is a multi-step process (create → wait → download).
See [ps-cli-api-insights.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/ps-cli-api-insights.md) for how to use.
What to look for:
- High `rows_read / rows_returned` ratio → missing index
- High `total_time_s` → optimization target
## Insights UI (Dashboard)
In the [PlanetScale dashboard](https://app.planetscale.com/), select your database and click **Insights**.
- **Filtering** — Pick a branch, choose primary or replica, and scroll through the last 7 days. Click-and-drag on graphs to zoom into a time window.
- **Graphs** — Four tabs: Query latency (p50/p95/p99/p99.9), Queries per second, Rows read/s, and Rows written/s.
- **Queries table** — All queries in the selected timeframe, normalized into patterns. Sortable and filterable by SQL, schema, table, latency, index usage, and more. Customizable columns (count, total time, latency percentiles, rows read/returned/affected, CPU/IO time, cache hit ratio, etc.). Enable sparklines for inline trend graphs. Orange icons flag full table scans.
- **Query deep dive** — Click any query to see per-pattern graphs, summary stats, index usage breakdown, and a table of notable executions (>1 s, >10k rows read, or errors). Use "Summarize query" for an LLM-generated plain-English description.
- **Anomalies tab** — Flags periods with elevated slow-running queries and surfaces the responsible patterns.
- **Errors tab** — Surfaces queries that produced errors.
- **pginsights settings** — `pginsights.raw_queries` enables full query text collection for notable queries; `pginsights.normalize_schema_names` groups identical patterns across schemas (useful for schema-per-tenant designs). Both configurable in the Extensions tab on the Clusters page.
More: [PlanetScale Insights docs](https://planetscale.com/docs/postgres/monitoring/query-insights)
## Optimization Checklist
- Remove unused indexes (0 scans)
- Remove duplicate indexes
- Archive audit/log tables >10 GB
- Review tables >100 GB for partitioning
**Always confirm with a human before removing indexes, dropping tables/partitions, or archiving data.** These are destructive actions that cannot be easily undone.
More: [optimization-checklist.md](https://raw.githubusercontent.com/planetscale/database-skills/main/skills/postgres/references/optimization-checklist.md)
@@ -0,0 +1,80 @@
---
title: SQL Query Patterns
description: Common SQL anti-patterns and optimized alternatives
tags: postgres, sql, query-optimization, n-plus-one, pagination
---
# SQL Query Patterns
## Query Structure
**SELECT specific columns** — avoids fetching unnecessary data and enables covering indexes:
```sql
-- Bad:
SELECT * FROM user WHERE status = 'active';
-- Good:
SELECT id, name, email FROM user WHERE status = 'active';
```
**Subqueries → JOINs** — correlated subqueries re-execute per row:
```sql
-- Bad
SELECT id, (SELECT COUNT(*) FROM order WHERE order.user_id = user.id) FROM user;
-- Good
SELECT u.id, COUNT(o.id) FROM user u LEFT JOIN order o ON o.user_id = u.id GROUP BY u.id;
```
**Always LIMIT unbounded queries** — prevent runaway result sets:
```sql
SELECT id, message FROM log WHERE level = 'error' ORDER BY created_at DESC LIMIT 100;
```
**Avoid functions on indexed columns (SARGable)** — functions prevent index usage unless a functional index exists:
```sql
-- Bad: Full table scan
SELECT * FROM user WHERE date_trunc('day', created_at) = '2023-01-01';
-- Good: Index scan
SELECT * FROM user WHERE created_at >= '2023-01-01' AND created_at < '2023-01-02';
```
## N+1 Detection
**Queries inside loops → batch with ANY/IN:**
```python
# Bad
for uid in user_ids:
cursor.execute("SELECT name FROM user WHERE id = %s", (uid,))
# Good (Postgres specific)
cursor.execute("SELECT id, name FROM user WHERE id = ANY(%s)", (list(user_ids),))
# Good (Standard SQL)
# cursor.execute("SELECT id, name FROM user WHERE id IN %s", (tuple(user_ids),))
```
**ORM lazy loading → eager loading:**
```python
# Bad: N+1 — each iteration fires a query
for user in User.query.all():
print(user.posts)
# Good
users = User.query.options(joinedload(User.posts)).all()
```
## Query Rewrites
**UNION → UNION ALL** — skip deduplication when duplicates are impossible or acceptable.
**IN subquery → EXISTS** — EXISTS short-circuits on first match:
```sql
SELECT id, name FROM user u
WHERE EXISTS (SELECT 1 FROM order o WHERE o.user_id = u.id AND o.total > 100);
```
**OFFSET → cursor pagination** — OFFSET scans and discards rows, degrading at depth:
```sql
-- Bad: OFFSET 10000 scans 10020 rows
SELECT id, title FROM article ORDER BY created_at DESC LIMIT 20 OFFSET 10000;
-- Good: cursor-based (requires index on (created_at DESC, id DESC))
SELECT id, title FROM article
WHERE (created_at, id) < ('2025-06-15T12:00:00Z', 987654)
ORDER BY created_at DESC, id DESC LIMIT 20;
```
@@ -0,0 +1,49 @@
---
title: Replication
description: Streaming replication, replication slots, synchronous commit levels, failover, and standby management
tags: postgres, replication, streaming, slots, synchronous, failover, standby, operations
---
# Replication
## Streaming Replication for followers
Use physical (byte-for-byte) replication via WAL stream from primary to standbys. Standbys are read-only (hot standby); same major PG version and architecture required (same minor recommended). Without replication slots, the primary may recycle WAL before the standby receives it → standby needs full resync via `pg_basebackup`. Use replication slots to guarantee WAL retention for specific standbys.
## Replication Slots
Postgres supports Physical slots (streaming) and logical slots (logical replication). Slots prevent WAL deletion even if standby is offline — can exhaust `pg_wal/` disk. Use `max_slot_wal_keep_size` to cap retained WAL per slot. Use `idle_replication_slot_timeout` (PG 17+) to auto-invalidate idle slots. `wal_keep_size` is a simpler alternative to slots for WAL retention. Drop inactive slots immediately to prevent disk exhaustion.
Slot lag (MB behind): `SELECT slot_name, pg_wal_lsn_diff(pg_current_wal_lsn(), restart_lsn)/1024/1024 AS mb_behind FROM pg_replication_slots;`
Drop inactive slot: `SELECT pg_drop_replication_slot('slot_name');`
**Always confirm with a human before dropping replication slots.** Dropping an active or needed slot can cause downstream issues.
## Synchronous Commit Levels
| Level | Behavior | Use Case |
|-------|----------|----------|
| `off` | Returns immediately, no wait | Non-critical writes; risks losing ~600ms of commits on crash (no inconsistency) |
| `local` | Waits for local WAL fsync only | Local durability only; no standby wait |
| `remote_write` | Waits for standby OS buffer | Data loss on standby OS crash |
| `on` | Waits for standby WAL to disk when `synchronous_standby_names` is set; otherwise same as `local` | **Default. This level or higher recommended for HA** |
| `remote_apply` | Waits for standby to apply WAL | Strongest; read-your-writes |
Configure with `synchronous_standby_names`. Use `ANY N` for quorum or `FIRST N` for priority-based sync.
## Quorum and Failure
`FIRST 2 (s1, s2, s3)` is priority-based: waits for the 2 highest-priority connected standbys (s1+s2; s3 takes over only if one disconnects). `ANY 2 (s1, s2, s3)` is quorum-based: waits for any 2. With either, if only 1 is healthy, commits hang. Provision at least N+1 standbys: need 2 confirmations → provision 3. PostgreSQL never commits unless required standbys confirm — no inconsistency, but clients may timeout.
## Failover
`pg_ctl promote` or `SELECT pg_promote()` (SQL function, PG 12+) converts standby to primary. One-way: promoted standby cannot rejoin as standby without rebuild. `pg_rewind` can resync old primary to new primary (requires `wal_log_hints=on` or data checksums) — faster than full rebuild. After promotion: update connection strings, rebuild old primary as standby, reconfigure other standbys.
## Monitoring
On the primary, query `pg_stat_replication` for each connected standby's `state` (`streaming` = healthy, `catchup` = behind), `sync_state` (`sync`/`async`), and LSN positions (`sent_lsn`, `write_lsn`, `flush_lsn`, `replay_lsn`) to compute lag. On standbys, `pg_stat_wal_receiver` shows the receiver process status and `flushed_lsn`; compare `pg_last_wal_receive_lsn()` vs `pg_last_wal_replay_lsn()` for local replay lag.
Replication lag (MB): `SELECT application_name, pg_wal_lsn_diff(pg_current_wal_lsn(), replay_lsn)/1024/1024 AS lag_mb FROM pg_stat_replication;`
Enable `wal_compression` (`pglz`, `lz4`, or `zstd`) to compress full page images in WAL (not all WAL data) — reduces WAL size for bandwidth-limited replication.
@@ -0,0 +1,66 @@
---
title: PostgreSQL Schema Design
description: Schema design guide
tags: postgres, schema, primary-keys, data-types, foreign-keys, naming
---
# Schema Design
## Primary Keys
Prefer `BIGINT GENERATED ALWAYS AS IDENTITY`. Avoid random UUIDs (UUIDv4) as primary keys; use `uuidv7()` when you need UUIDs.
```sql
CREATE TABLE user (
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
email TEXT NOT NULL UNIQUE
);
```
Random UUID PKs (v4) can cause index fragmentation; UUIDs are also larger (16 vs 8 bytes for BIGINT) and can slow joins.
## Data Types
| Use | Avoid |
| --- | --- |
| `TEXT`, `VARCHAR` | Extension-specific types |
| `JSONB` | Custom ENUMs (use CHECK instead) |
| `TIMESTAMPTZ` | `TIMESTAMP` without time zone |
| `BIGINT`, `INTEGER` | Platform-specific types |
Prefer CHECK constraints over ENUM types — they're easier to modify:
```sql
CREATE TABLE order (
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
status TEXT NOT NULL CHECK (status IN ('pending', 'shipped', 'delivered'))
);
```
## Foreign Keys
- Always index FK columns (PostgreSQL does not auto-create these)
- Avoid circular FK dependencies
- Suggestion: use `ON DELETE CASCADE` or `ON DELETE SET NULL` explicitly
```sql
CREATE TABLE order (
id BIGINT GENERATED ALWAYS AS IDENTITY PRIMARY KEY,
customer_id BIGINT NOT NULL REFERENCES customer(id) ON DELETE CASCADE
);
CREATE INDEX order_customer_id_idx ON order (customer_id);
```
## Naming Conventions
- Tables: singular snake_case (`user_account`, `order_item`)
- Columns: singular snake_case (`created_at`, `user_id`)
- Indexes: `{table}_{column}_idx`
- Constraints: `{table}_{column}_{type}` (e.g., `order_status_check`)
## General Guidelines
- Add `NOT NULL` to as many columns as possible
- Add `created_at TIMESTAMPTZ DEFAULT NOW()` to all tables
- Use `BIGINT` for all IDs and foreign keys, even on small tables
- Keep tables normalized; denormalize only for proven hot read paths
@@ -0,0 +1,41 @@
---
title: Storage Layout and Tablespaces
description: PGDATA directory structure, TOAST, fillfactor, tablespaces, and disk management
tags: postgres, storage, pgdata, toast, fillfactor, tablespaces, disk, operations
---
# Storage Layout and Tablespaces
## PGDATA Structure
- **base/** — database files (one subdirectory per database, named by OID)
- **global/** — cluster-wide shared catalogs (pg_database, pg_authid, pg_tablespace)
- **pg_wal/** — WAL files
- **pg_xact/** — transaction commit status
"Cluster" in PostgreSQL = single instance with one PGDATA, not an HA cluster. Each table/index = one or more files, split into 1GB segments. Tables have companion **_fsm** (free space map) and **_vm** (visibility map); indexes have **_fsm** only (no _vm), except hash indexes.
## Visibility Map and Free Space Map
- **_vm** tracks all-visible pages — VACUUM skips these
- **_fsm** tracks free space per page — INSERT uses this to find pages with room
- Both are small files but critical for performance
## TOAST
TOAST triggers when a **row** exceeds ~2KB. Large values are compressed and/or moved out-of-line to `pg_toast.pg_toast_<oid>` tables. **Strategies:** PLAIN (no TOAST), EXTENDED (compress+out-of-line, default for text/bytea), EXTERNAL (out-of-line, no compression — use for pre-compressed data), MAIN (compress, avoid out-of-line). TOAST tables bloat like regular tables — they need VACUUM. `SELECT *` fetches all TOAST columns; always SELECT only needed columns. Move large rarely-accessed columns to separate tables.
## Fillfactor
Controls how full pages are packed (default 100%). Lower fillfactor (7080%) leaves room for HOT (Heap-Only Tuple) updates, which avoid index entries and reduce bloat on UPDATE-heavy tables. Keep 100% for insert-only or read-mostly tables. `ALTER TABLE t SET (fillfactor = 70);`
## Tablespaces
`pg_default` (base/), `pg_global` (global/) are built-in. Custom tablespaces: symbolic links in **pg_tblspc/** to other filesystem locations. Use for separating hot data (SSD) from archives (HDD). Moving tablespaces requires exclusive lock on affected tables.
## Disk Monitoring
- `pg_database_size('dbname')`, `pg_total_relation_size('tablename')`, `pg_relation_size('tablename')`
- Monitor disk usage: >80% = at risk; >90% = critical (VACUUM may fail if disk capacity is insufficient)
- Check inode usage (`df -i`) — can run out even with free space
- `pg_wal/` suddenly large = check replication slots and archiving
@@ -0,0 +1,42 @@
---
title: WAL and Checkpoint Operations
description: Write-ahead log internals, checkpoint tuning, durability guarantees, and WAL disk management
tags: postgres, wal, checkpoints, durability, crash-recovery, fsync, operations
---
# WAL and Checkpoint Operations
## WAL Fundamentals
Write-Ahead Logging: logs changes to `pg_wal/` **before** modifying data files. WAL segments are 16MB (fixed at initdb). On COMMIT, PostgreSQL fsyncs WAL to disk and returns SUCCESS — data files are updated lazily. WAL records are written for all changes (including uncommitted transactions and rollbacks). **Never disable `fsync` in production** — power loss without fsync risks unrecoverable data loss.
`wal_level`: `minimal` (crash recovery only), `replica` (default; replication + archiving), `logical` (logical replication).
## Dirty Pages and Checkpoints
A dirty page is modified in shared_buffers but not yet written to data files. A checkpoint flushes all dirty pages to disk and writes a checkpoint record to WAL; recovery only replays WAL since the last checkpoint.
- `checkpoint_timeout` (default 5 min) and `max_wal_size` (default 1GB) — checkpoint on whichever triggers first.
- `checkpoint_completion_target=0.9` spreads I/O over 90% of the interval; avoid spikes.
- "Checkpoints are occurring too frequently" in logs → increase `max_wal_size`.
- **Target: >90% of checkpoints should be time-based** (`num_timed` in `pg_stat_checkpointer`), not size-based (`num_requested`). If num_requested/(num_timed+num_requested) > 10%, tune `max_wal_size` up.
## WAL Disk Management
Replication slots prevent WAL deletion even when standbys are offline — they can fill disk. WAL archiving failures also block recycling. `max_wal_size` is a *soft* limit; WAL can grow beyond it under heavy load.
WAL size: `SELECT count(*) AS files, pg_size_pretty(sum(size)) AS total FROM pg_ls_waldir();`
Slot lag: `SELECT slot_name, pg_wal_lsn_diff(pg_current_wal_lsn(), restart_lsn) AS lag_bytes FROM pg_replication_slots;`
## Checkpoint Monitoring
PG17+ moved checkpoint stats from `pg_stat_bgwriter` to `pg_stat_checkpointer` and renamed columns.
`SELECT num_timed, num_requested, write_time, sync_time, buffers_written FROM pg_stat_checkpointer;`
Backend-direct writes (formerly `buffers_backend` in `pg_stat_bgwriter`) are now tracked in `pg_stat_io`: `SELECT writes FROM pg_stat_io WHERE backend_type = 'client backend' AND object = 'relation';`
## Crash Recovery
On crash, PostgreSQL replays WAL from the last checkpoint. Longer checkpoint intervals → more WAL to replay → longer recovery. Trade-off: frequent checkpoints (faster recovery, more I/O) vs infrequent (less I/O, slower recovery). For most workloads, `checkpoint_timeout=5min` and `max_wal_size` tuned to keep checkpoints time-based is the right balance.
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/frontend-design
+1
View File
@@ -0,0 +1 @@
../../.agents/skills/postgres
+13
View File
@@ -0,0 +1,13 @@
node_modules
**/node_modules
**/.next
.git
.env*
.vscode/
.idea/
coverage/
*.test.ts
*.spec.ts
.DS_Store
*.md
docs/
+28 -5
View File
@@ -12,9 +12,15 @@ POSTGRES_PRISMA_URL_NON_POOLING=
# This variable is from Vercel Storage Blob
BLOB_READ_WRITE_TOKEN=
# Google client id and secret for authentication
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
# Hanzo IAM OAuth (required for production)
IAM_URL="https://hanzo.id"
IAM_CLIENT_ID=""
IAM_CLIENT_SECRET=""
# IAM_PROVIDER_NAME="Hanzo"
# Google client id and secret (deprecated — use Hanzo IAM above)
# GOOGLE_CLIENT_ID=
# GOOGLE_CLIENT_SECRET=
# This variable is from Resend to send emails
RESEND_API_KEY=
@@ -67,8 +73,25 @@ NEXT_PRIVATE_UPLOAD_DISTRIBUTION_KEY_CONTENTS=
# Encryption key for document passwords.
NEXT_PRIVATE_DOCUMENT_PASSWORD_KEY=my-superstrong-document-secret
# [[REDIS LOCKER CONFIGURATION]]
# For bulk upload using tus.io, we use a Redis-based locker to prevent corruption of the data.
# [[HANZO KV]] — OPTIONAL. Leave UNSET to run on the in-process backend
# (single-replica correct: cache, rate-limit, tus upload locks, export/download
# job stores and digest queues all work with no external datastore). SET it to
# an external Hanzo KV instance for multi-replica HA (shared state across pods).
# Accepts the Hanzo KV brand scheme kv:// (kvs:// for TLS) or a redis:// DSN.
# A malformed value fails CLOSED (the app throws rather than silently degrade).
#
# Re-enabling multi-replica (replicas > 1) REQUIRES KV_URL. dataroom is
# single-replica-by-construction otherwise: SQLite on a ReadWriteOnce volume plus
# the in-process KV. Without KV_URL each pod owns its OWN map, so sessions,
# rate-limit windows and tus upload locks split-brain across replicas — scaling
# out needs a shared DB AND KV_URL set.
# KV_URL=kv://:password@hanzo-kv:6379
KV_URL=
# [[TUS UPLOAD LOCKER]] — for bulk upload via tus.io, an exclusive locker
# prevents data corruption. It uses the Hanzo KV client above (KV_URL); with
# KV_URL unset the lock is in-process (correct for a single replica). The legacy
# Upstash REST locker below is unused and kept only for reference.
UPSTASH_REDIS_REST_LOCKER_URL=
UPSTASH_REDIS_REST_LOCKER_TOKEN=
+9
View File
@@ -0,0 +1,9 @@
<svg xmlns="http://www.w3.org/2000/svg" width="1280" height="640" viewBox="0 0 1280 640" role="img" aria-label="dataroom">
<rect width="1280" height="640" fill="#0A0A0A"/>
<svg x="96" y="215" width="210" height="210" viewBox="0 0 67 67"><path d="M22.21 67V44.6369H0V67H22.21Z" fill="#fff"/><path d="M66.7038 22.3184H22.2534L0.0878906 44.6367H44.4634L66.7038 22.3184Z" fill="#fff"/><path d="M22.21 0H0V22.3184H22.21V0Z" fill="#fff"/><path d="M66.7198 0H44.5098V22.3184H66.7198V0Z" fill="#fff"/><path d="M66.7198 67V44.6369H44.5098V67H66.7198Z" fill="#fff"/></svg>
<text x="378" y="276" font-family="Inter,system-ui,-apple-system,sans-serif" font-size="78" font-weight="800" letter-spacing="-2" fill="#ffffff">dataroom</text>
<text x="378" y="322" font-family="Inter,system-ui,sans-serif" font-size="30" fill="#ffffff" opacity=".66">Papermark is the open-source DocSend alternative with built-in…</text>
<rect x="378" y="338" width="806" height="3" rx="1.5" fill="#ffffff" opacity=".9"/>
<text x="378" y="390" font-family="Inter,system-ui,sans-serif" font-size="24" font-weight="600" fill="#ffffff" opacity=".5">github.com/hanzoai</text>
<text x="1184" y="390" text-anchor="end" font-family="Inter,system-ui,sans-serif" font-size="24" font-weight="600" fill="#ffffff" opacity=".5">hanzo.ai</text>
</svg>

After

Width:  |  Height:  |  Size: 1.3 KiB

+3 -3
View File
@@ -13,7 +13,7 @@ permissions:
jobs:
CLAAssistant:
runs-on: ubuntu-latest
runs-on: hanzo-build-linux-amd64
steps:
- name: "CLA Assistant"
if: (github.event.comment.body == 'recheck' || github.event.comment.body == 'I have read the CLA Document and I hereby sign the CLA') || github.event_name == 'pull_request_target'
@@ -25,10 +25,10 @@ jobs:
# This token is required only if you have configured to store the signatures in a remote repository/organization
PERSONAL_ACCESS_TOKEN: ${{ secrets.PERSONAL_ACCESS_TOKEN }}
with:
remote-organization-name: 'papermark'
remote-organization-name: 'hanzo-dataroom'
remote-repository-name: 'cla-signatures'
path-to-signatures: 'signatures/version1/cla.json'
path-to-document: 'https://github.com/mfts/papermark/blob/main/CLA.md'
path-to-document: 'https://github.com/hanzoai/dataroom/blob/main/CLA.md'
# branch should not be protected
branch: 'main'
allowlist: cursoragent
+11
View File
@@ -0,0 +1,11 @@
name: Docker
# Native deploy pipeline is .hanzo/workflows/deploy.yml (Hanzo Git → act_runner →
# BuildKit → ghcr.io/hanzoai/dataroom:<sha> → operator reconcile → hanzocd).
# GitHub is a mirror; this workflow is retained only as a manual sync notice.
on:
workflow_dispatch:
jobs:
notice:
runs-on: ubuntu-latest
steps:
- run: echo "native pipeline is .hanzo/workflows/deploy.yml; GitHub is a mirror"
+7
View File
@@ -0,0 +1,7 @@
name: Workflow Sanity
on:
pull_request:
paths: ['.github/workflows/**']
jobs:
sanity:
uses: hanzoai/.github/.github/workflows/workflow-sanity.yml@main
+1 -1
View File
@@ -62,4 +62,4 @@ lib/emails/marketing
# changelog and docs
changelog
.docs
.docsvendor/
+24
View File
@@ -0,0 +1,24 @@
name: deploy
on:
push:
branches: [main]
jobs:
deploy:
runs-on: hanzo-linux-amd64
steps:
- uses: actions/checkout@v4
- name: Build + push image
run: |
SHA="${GITHUB_SHA::8}"
buildctl-daemonless.sh build --frontend=dockerfile.v0 \
--opt context="${{ github.server_url }}/${{ github.repository }}.git#${GITHUB_SHA}" \
--opt filename=Dockerfile --opt platform=linux/amd64 \
--secret id=GIT_AUTH_TOKEN,env=GIT_AUTH_TOKEN \
--output "type=image,name=ghcr.io/hanzoai/dataroom:${SHA},push=true" --progress=plain
env:
GIT_AUTH_TOKEN: ${{ secrets.GIT_CLONE_TOKEN }}
- name: Deploy — declare tag to operator
run: |
for app in dataroom; do
kubectl -n hanzo patch app "$app" --type=merge -p "{\"spec\":{\"image\":{\"repository\":\"ghcr.io/hanzoai/dataroom\",\"tag\":\"${GITHUB_SHA::8}\"}}}"
done
Symlink
+1
View File
@@ -0,0 +1 @@
LLM.md
+8 -8
View File
@@ -1,16 +1,16 @@
# Papermark Contributors License Agreement
# Hanzo Dataroom Contributors License Agreement
This Contributors License Agreement ("CLA") is entered into between the Contributor, and Papermark, Inc. ("Papermark"), collectively referred to as the "Parties."
This Contributors License Agreement ("CLA") is entered into between the Contributor, and Hanzo AI, Inc. ("Hanzo Dataroom"), collectively referred to as the "Parties."
## Background:
Papermark is an open-source project aimed at providing an open-source document sharing and tracking infrastructure for all parties. This CLA governs the rights and contributions made by the Contributor to the Papermark project.
Hanzo Dataroom is an open-source project aimed at providing an open-source document sharing and tracking infrastructure for all parties. This CLA governs the rights and contributions made by the Contributor to the Hanzo Dataroom project.
## Agreement:
**Contributor Grant of License:**
By submitting code, documentation, or any other materials (collectively, "Contributions") to the Papermark project, the Contributor grants Papermark a perpetual, worldwide, non-exclusive, royalty-free, sublicensable license to use, modify, distribute, and otherwise exploit the Contributions, including any intellectual property rights therein, for the purposes of the Papermark project.
By submitting code, documentation, or any other materials (collectively, "Contributions") to the Hanzo Dataroom project, the Contributor grants Hanzo Dataroom a perpetual, worldwide, non-exclusive, royalty-free, sublicensable license to use, modify, distribute, and otherwise exploit the Contributions, including any intellectual property rights therein, for the purposes of the Hanzo Dataroom project.
**Representation of Ownership and Right to Contribute:**
@@ -18,11 +18,11 @@ The Contributor represents that they have the legal right to grant the license s
**Patent Grant:**
If the Contributions include any method, process, or apparatus that is covered by a patent, the Contributor agrees to grant Papermark a non-exclusive, worldwide, royalty-free license under any patent claims necessary to use, modify, distribute, and otherwise exploit the Contributions for the purposes of the Papermark project.
If the Contributions include any method, process, or apparatus that is covered by a patent, the Contributor agrees to grant Hanzo Dataroom a non-exclusive, worldwide, royalty-free license under any patent claims necessary to use, modify, distribute, and otherwise exploit the Contributions for the purposes of the Hanzo Dataroom project.
**No Implied Warranties or Support:**
The Contributor acknowledges that the Contributions are provided "as is," without any warranties or support of any kind. Papermark shall have no obligation to provide maintenance, updates, bug fixes, or support for the Contributions.
The Contributor acknowledges that the Contributions are provided "as is," without any warranties or support of any kind. Hanzo Dataroom shall have no obligation to provide maintenance, updates, bug fixes, or support for the Contributions.
**Retention of Contributor Rights:**
@@ -38,8 +38,8 @@ This CLA constitutes the entire agreement between the Parties with respect to th
**Acceptance:**
By submitting Contributions to the Papermark project, the Contributor acknowledges and agrees to the terms and conditions of this CLA. If the Contributor is agreeing to this CLA on behalf of an entity, they represent that they have the necessary authority to bind that entity to these terms.
By submitting Contributions to the Hanzo Dataroom project, the Contributor acknowledges and agrees to the terms and conditions of this CLA. If the Contributor is agreeing to this CLA on behalf of an entity, they represent that they have the necessary authority to bind that entity to these terms.
**Effective Date:**
This CLA is effective as of the date of the first Contribution made by the Contributor to the Papermark project.
This CLA is effective as of the date of the first Contribution made by the Contributor to the Hanzo Dataroom project.
Symlink
+1
View File
@@ -0,0 +1 @@
LLM.md
+53
View File
@@ -0,0 +1,53 @@
FROM ghcr.io/hanzoai/nodejs:v24.18.0 AS base
RUN apk add --no-cache libc6-compat openssl python3 make g++
FROM base AS deps
WORKDIR /app
COPY package.json package-lock.json ./
COPY prisma ./prisma
ENV HUSKY=0
RUN npm install --legacy-peer-deps
FROM base AS builder
WORKDIR /app
COPY --from=deps /app/node_modules ./node_modules
COPY . .
ENV NEXT_TELEMETRY_DISABLED=1
ENV DOCKER_OUTPUT=1
# Dummy env vars to prevent module-scope crashes during Next.js build
# (OpenAI, Hanko, etc. initialize clients at import time)
ENV OPENAI_API_KEY=build-placeholder
ENV HANKO_API_KEY=build-placeholder
ENV NEXT_PUBLIC_HANKO_TENANT_ID=build-placeholder
RUN npx prisma generate
# SQLite has no Prisma enums; re-inject the enum objects the app imports from
# @prisma/client (e.g. LinkType.DOCUMENT_LINK) so runtime/prerender resolves them.
RUN node prisma/inject-sqlite-enums.cjs
ENV NODE_OPTIONS="--max-old-space-size=4096"
RUN npm run build
FROM ghcr.io/hanzoai/nodejs:v24.18.0 AS runner
RUN apk add --no-cache openssl
WORKDIR /app
ENV NODE_ENV=production
ENV NEXT_TELEMETRY_DISABLED=1
RUN addgroup --system --gid 1001 nodejs
RUN adduser --system --uid 1001 nextjs
COPY --from=builder /app/public ./public
RUN mkdir .next
RUN chown nextjs:nodejs .next
COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
COPY --from=builder --chown=nextjs:nodejs /app/prisma ./prisma
RUN ln -s /app/prisma/migrations /app/prisma/schema/migrations
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/.prisma ./node_modules/.prisma
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/@prisma ./node_modules/@prisma
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/prisma ./node_modules/prisma
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/.bin ./node_modules/.bin
USER nextjs
EXPOSE 3000
ENV PORT=3000
# SQLite: reconcile schema on startup via `db push` (Prisma has no migrate-deploy
# path for the sqlite provider here; the pg migration history under prisma/migrations
# is postgres-specific and unused). Schema folder = prismaSchemaFolder preview.
CMD ["sh", "-c", "node_modules/.bin/prisma db push --schema prisma/schema --skip-generate --accept-data-loss && node server.js"]
+49
View File
@@ -0,0 +1,49 @@
# Hanzo Dataroom
## Overview
Hanzo dataroom service.
**Upstream**: [Papermark](https://github.com/mfts/papermark) (AGPL-3.0). LICENSE retains "Copyright (c) 2023-present Papermark, Inc." Open-source DocSend alternative. This fork is Hanzo Dataroom — single-license AGPL, no `ee/` commercial directory.
## In-process fold (HIP-0106, task #101)
The production runtime is the **goja bundle** in [`goja/`](goja/): the ESM-free
port of the API handlers, run in-process inside the unified `hanzoai/cloud` binary
over Hanzo Base/SQLite (per-tenant) + the cloud object-storage seam. The standalone
Next.js app + Postgres pod is **retired**; cloud serves `/v1/dataroom/*` itself.
See [`goja/README.md`](goja/README.md) for the host contract. The Next.js/TS
sources below remain the reference for the domain model that `goja/bundle.js`
implements.
## Tech Stack
- **Language**: TypeScript/JavaScript
## Build & Run
```bash
npm install && npm run build
npm test
```
## Structure
```
dataroom/
CLA.md
Dockerfile
LICENSE
LLM.md
Pipfile
Pipfile.lock
README.md
SECURITY.md
app/
components/
components.json
context/
features/
lib/
middleware.ts
```
## Key Files
- `README.md` -- Project documentation
- `package.json` -- Dependencies and scripts
- `Dockerfile` -- Container build
+17 -15
View File
@@ -1,26 +1,28 @@
<p align="center"><img src=".github/hero.svg" alt="dataroom" width="880"></p>
<div align="center">
<h1 align="center">Papermark</h1>
<h1 align="center">Hanzo Dataroom</h1>
<h3>The open-source DocSend alternative.</h3>
<a target="_blank" href="https://www.producthunt.com/posts/papermark-3?utm_source=badge-top-post-badge&amp;utm_medium=badge&amp;utm_souce=badge-papermark"><img src="https://api.producthunt.com/widgets/embed-image/v1/top-post-badge.svg?post_id=411605&amp;theme=light&amp;period=daily" alt="Papermark - The open-source DocSend alternative | Product Hunt" style="width:250px;height:40px"></a>
<a target="_blank" href="https://www.producthunt.com/posts/hanzo-dataroom-3?utm_source=badge-top-post-badge&amp;utm_medium=badge&amp;utm_souce=badge-hanzo-dataroom"><img src="https://api.producthunt.com/widgets/embed-image/v1/top-post-badge.svg?post_id=411605&amp;theme=light&amp;period=daily" alt="Hanzo Dataroom - The open-source DocSend alternative | Product Hunt" style="width:250px;height:40px"></a>
</div>
<div align="center">
<a href="https://www.papermark.com">papermark.com</a>
<a href="https://www.dataroom.hanzo.ai">dataroom.hanzo.ai</a>
</div>
<br/>
<div align="center">
<a href="https://github.com/mfts/papermark/stargazers"><img alt="GitHub Repo stars" src="https://img.shields.io/github/stars/mfts/papermark"></a>
<a href="https://twitter.com/papermarkio"><img alt="Twitter Follow" src="https://img.shields.io/twitter/follow/papermarkio"></a>
<a href="https://github.com/mfts/papermark/blob/main/LICENSE"><img alt="License" src="https://img.shields.io/badge/license-AGPLv3-purple"></a>
<a href="https://github.com/hanzoai/dataroom/stargazers"><img alt="GitHub Repo stars" src="https://img.shields.io/github/stars/hanzoai/dataroom"></a>
<a href="https://twitter.com/hanzoai"><img alt="Twitter Follow" src="https://img.shields.io/twitter/follow/hanzoai"></a>
<a href="https://github.com/hanzoai/dataroom/blob/main/LICENSE"><img alt="License" src="https://img.shields.io/badge/license-AGPLv3-purple"></a>
</div>
<br/>
Papermark is the open-source document-sharing alternative to DocSend, featuring built-in analytics and custom domains.
Hanzo Dataroom is the open-source document-sharing alternative to DocSend, featuring built-in analytics and custom domains.
## Features
@@ -31,7 +33,7 @@ Papermark is the open-source document-sharing alternative to DocSend, featuring
## Demo
![Papermark Welcome GIF](.github/images/papermark-welcome.gif)
![Hanzo Dataroom Welcome GIF](.github/images/hanzo-dataroom-welcome.gif)
## Tech Stack
@@ -51,7 +53,7 @@ Papermark is the open-source document-sharing alternative to DocSend, featuring
### Prerequisites
Here's what you need to run Papermark:
Here's what you need to run Hanzo Dataroom:
- Node.js (version >= 18.17.0)
- PostgreSQL Database
@@ -61,8 +63,8 @@ Here's what you need to run Papermark:
### 1. Clone the repository
```shell
git clone https://github.com/mfts/papermark.git
cd papermark
git clone https://github.com/hanzoai/dataroom.git
cd hanzo-dataroom
```
### 2. Install npm dependencies
@@ -119,19 +121,19 @@ To prepare the Tinybird database, follow these steps:
pipenv shell
## start: pkgx-specific
cd ..
cd papermark
cd hanzo-dataroom
## end: pkgx-specific
pipenv update tinybird-cli
```
## Contributing
Papermark is an open-source project, and we welcome contributions from the community.
Hanzo Dataroom is an open-source project, and we welcome contributions from the community.
If you'd like to contribute, please fork the repository and make any changes you'd like. Pull requests are warmly welcome.
### Our Contributors ✨
<a href="https://github.com/mfts/papermark/graphs/contributors">
<img src="https://contrib.rocks/image?repo=mfts/papermark" />
<a href="https://github.com/hanzoai/dataroom/graphs/contributors">
<img src="https://contrib.rocks/image?repo=hanzoai/dataroom" />
</a>
+2 -2
View File
@@ -2,10 +2,10 @@
## Supported Versions
The latest version of Papermark is currently being supported with security updates.
The latest version of Hanzo Dataroom is currently being supported with security updates.
## Reporting a Vulnerability
To report a vulnerability, send an email to security@papermark.com.
To report a vulnerability, send an email to security@dataroom.hanzo.ai.
We will respond within 48 hours acknowledging your report with details about next steps and potential rewards/compensation for responsible disclosure.
@@ -20,19 +20,19 @@ export const runtime = "nodejs";
const data = {
description: "Confirm email change",
title: "Confirm email change | Papermark",
title: "Confirm email change | Hanzo Dataroom",
url: "/auth/confirm-email-change",
};
export const metadata: Metadata = {
metadataBase: new URL("https://www.papermark.com"),
metadataBase: new URL("https://dataroom.hanzo.ai"),
title: data.title,
description: data.description,
openGraph: {
title: data.title,
description: data.description,
url: data.url,
siteName: "Papermark",
siteName: "Hanzo Dataroom",
images: [
{
url: "/_static/meta-image.png",
@@ -47,13 +47,13 @@ export const metadata: Metadata = {
card: "summary_large_image",
title: data.title,
description: data.description,
creator: "@papermarkio",
creator: "@hanzoai",
images: ["/_static/meta-image.png"],
},
};
interface PageProps {
params: { token: string };
params: Promise<{ token: string }>;
}
export default async function ConfirmEmailChangePage(props: PageProps) {
@@ -64,7 +64,8 @@ export default async function ConfirmEmailChangePage(props: PageProps) {
);
}
const VerifyEmailChange = async ({ params: { token } }: PageProps) => {
const VerifyEmailChange = async ({ params }: PageProps) => {
const { token } = await params;
const tokenFound = await prisma.verificationToken.findUnique({
where: {
token: hashToken(token),
@@ -115,10 +115,10 @@ export default function EmailVerificationClient() {
<div className="flex w-full justify-center bg-gray-50 md:w-1/2 lg:w-1/2">
<div className="z-10 mx-5 mt-[calc(1vh)] h-fit w-full max-w-md overflow-hidden rounded-lg sm:mx-0 sm:mt-[calc(2vh)] md:mt-[calc(3vh)]">
<div className="items-left flex flex-col space-y-3 px-4 py-6 pt-8 sm:px-12">
<Link href="https://www.papermark.com" target="_blank">
<Link href="https://dataroom.hanzo.ai" target="_blank">
<img
src="/_static/papermark-logo.svg"
alt="Papermark Logo"
src="/_static/hanzo-dataroom-logo.svg"
alt="Hanzo Dataroom Logo"
className="-mt-8 mb-36 h-7 w-auto self-start sm:mb-32 md:mb-48"
/>
</Link>
@@ -153,10 +153,10 @@ export default function EmailVerificationClient() {
></div>
<div className="z-10 mx-5 mt-[calc(1vh)] h-fit w-full max-w-md overflow-hidden rounded-lg sm:mx-0 sm:mt-[calc(2vh)] md:mt-[calc(3vh)]">
<div className="items-left flex flex-col space-y-3 px-4 py-6 pt-8 sm:px-12">
<Link href="https://www.papermark.com" target="_blank">
<Link href="https://dataroom.hanzo.ai" target="_blank">
<img
src="/_static/papermark-logo.svg"
alt="Papermark Logo"
src="/_static/hanzo-dataroom-logo.svg"
alt="Hanzo Dataroom Logo"
className="-mt-8 mb-36 h-7 w-auto self-start sm:mb-32 md:mb-48"
/>
</Link>
@@ -187,10 +187,10 @@ export default function EmailVerificationClient() {
<p className="mt-2 text-sm text-orange-800">
Check your junk/spam and quarantine folders and ensure that{" "}
<a
href="mailto:system@papermark.com"
href="mailto:dataroom@hanzo.ai"
className="font-medium text-orange-600 underline hover:text-orange-700"
>
system@papermark.com
dataroom@hanzo.ai
</a>{" "}
is on your allowed senders list.
</p>
@@ -262,7 +262,7 @@ export default function EmailVerificationClient() {
<p className="mt-10 w-full max-w-md px-4 text-xs text-muted-foreground sm:px-12">
By clicking continue, you acknowledge that you have read and agree
to Papermark&apos;s{" "}
to Hanzo Dataroom&apos;s{" "}
<a
href={`${process.env.NEXT_PUBLIC_MARKETING_URL}/terms`}
target="_blank"
@@ -312,7 +312,7 @@ function TestimonialSection() {
<div className="max-w-xl text-center">
<blockquote className="text-balance font-normal leading-8 text-white sm:text-xl sm:leading-9">
<p>
&quot;We raised our 30M Fund with Papermark Data Rooms. Love
&quot;We raised our 30M Fund with Hanzo Dataroom. Love
the customization, security and ease of use.&quot;
</p>
</blockquote>
+5 -5
View File
@@ -3,20 +3,20 @@ import { Metadata } from "next";
import EmailVerificationClient from "./page-client";
const data = {
description: "Verify your login to Papermark",
title: "Verify Login | Papermark",
description: "Verify your login to Hanzo Dataroom",
title: "Verify Login | Hanzo Dataroom",
url: "/auth/email",
};
export const metadata: Metadata = {
metadataBase: new URL("https://www.papermark.com"),
metadataBase: new URL("https://dataroom.hanzo.ai"),
title: data.title,
description: data.description,
openGraph: {
title: data.title,
description: data.description,
url: data.url,
siteName: "Papermark",
siteName: "Hanzo Dataroom",
images: [
{
url: "/_static/meta-image.png",
@@ -31,7 +31,7 @@ export const metadata: Metadata = {
card: "summary_large_image",
title: data.title,
description: data.description,
creator: "@papermarkio",
creator: "@hanzoai",
images: ["/_static/meta-image.png"],
},
};
+7 -2
View File
@@ -1,12 +1,17 @@
import { Metadata } from "next";
import { Suspense } from "react";
import SAMLCallbackClient from "./page-client";
export const metadata: Metadata = {
title: "SSO Login | Papermark",
title: "SSO Login | Hanzo Dataroom",
description: "Completing SSO login",
};
export default function SAMLCallbackPage() {
return <SAMLCallbackClient />;
return (
<Suspense>
<SAMLCallbackClient />
</Suspense>
);
}
+74 -300
View File
@@ -1,318 +1,92 @@
"use client";
import Link from "next/link";
import { useParams, useRouter, useSearchParams } from "next/navigation";
import { useParams } from "next/navigation";
import { useState } from "react";
import { AlertCircle } from "lucide-react";
import { SSOLogin } from "@/ee/features/security/sso";
import { signInWithPasskey } from "@teamhanko/passkeys-next-auth-provider/client";
import { signIn } from "next-auth/react";
import { toast } from "sonner";
import { z } from "zod";
import { cn } from "@/lib/utils";
import { LastUsed, useLastUsed } from "@/components/hooks/useLastUsed";
import Google from "@/components/shared/icons/google";
import LinkedIn from "@/components/shared/icons/linkedin";
import Passkey from "@/components/shared/icons/passkey";
import { LogoCloud } from "@/components/shared/logo-cloud";
import { Button } from "@/components/ui/button";
import { Input } from "@/components/ui/input";
import { Label } from "@/components/ui/label";
import { HanzoMark } from "@/components/shared/icons/hanzo-mark";
// White-label hooks: every visible brand token comes from env so tenants
// drop in their own name/words/IAM provider without touching this file.
//
// NEXT_PUBLIC_APP_NAME e.g. "Hanzo Dataroom" | "Acme Rooms"
// NEXT_PUBLIC_APP_NAME_PRIMARY first word of wordmark; defaults to first
// word of NEXT_PUBLIC_APP_NAME ("Hanzo")
// NEXT_PUBLIC_APP_NAME_SUFFIX second token of wordmark; defaults to
// remainder of NEXT_PUBLIC_APP_NAME ("Dataroom")
// NEXT_PUBLIC_APP_TAGLINE one-line under the welcome headline
// NEXT_PUBLIC_IAM_PROVIDER_NAME IAM brand for the "Sign in with X" button
// NEXT_PUBLIC_MARKETING_URL base URL the Terms / Privacy links resolve against
const APP_NAME = process.env.NEXT_PUBLIC_APP_NAME || "Hanzo Dataroom";
const [defaultPrimary, ...defaultSuffixParts] = APP_NAME.split(" ");
const APP_NAME_PRIMARY =
process.env.NEXT_PUBLIC_APP_NAME_PRIMARY || defaultPrimary || APP_NAME;
const APP_NAME_SUFFIX =
process.env.NEXT_PUBLIC_APP_NAME_SUFFIX || defaultSuffixParts.join(" ");
const APP_TAGLINE =
process.env.NEXT_PUBLIC_APP_TAGLINE || "Share documents. Not attachments.";
const IAM_PROVIDER_NAME =
process.env.NEXT_PUBLIC_IAM_PROVIDER_NAME || "Hanzo";
const MARKETING_URL = process.env.NEXT_PUBLIC_MARKETING_URL || "";
export default function Login() {
const { next } = useParams as { next?: string };
const router = useRouter();
const searchParams = useSearchParams();
const authError = searchParams?.get("error");
const isSSORequired = authError === "require-saml-sso";
const [lastUsed, setLastUsed] = useLastUsed();
const authMethods = ["google", "email", "linkedin", "passkey"] as const;
type AuthMethod = (typeof authMethods)[number];
const [clickedMethod, setClickedMethod] = useState<AuthMethod | undefined>(
undefined,
);
const [email, setEmail] = useState<string>("");
const [emailButtonText, setEmailButtonText] = useState<string>(
"Continue with Email",
);
const emailSchema = z
.string()
.trim()
.toLowerCase()
.min(3, { message: "Please enter a valid email." })
.email({ message: "Please enter a valid email." });
const emailValidation = emailSchema.safeParse(email);
return (
<div className="flex h-screen w-full flex-wrap">
{/* Left part */}
<div className="flex w-full justify-center bg-gray-50 md:w-1/2 lg:w-1/2">
<div
className="absolute inset-x-0 top-10 -z-10 flex transform-gpu justify-center overflow-hidden blur-3xl"
aria-hidden="true"
></div>
<div className="z-10 mx-5 mt-[calc(1vh)] h-fit w-full max-w-md overflow-hidden rounded-lg sm:mx-0 sm:mt-[calc(2vh)] md:mt-[calc(3vh)]">
<div className="items-left flex flex-col space-y-3 px-4 py-6 pt-8 sm:px-12">
<Link href="https://www.papermark.com" target="_blank">
<img
src="/_static/papermark-logo.svg"
alt="Papermark Logo"
className="md:mb-48s -mt-8 mb-36 h-7 w-auto self-start sm:mb-32"
/>
</Link>
<Link href="/">
<span className="text-balance text-3xl font-semibold text-gray-900">
Welcome to Papermark
</span>
</Link>
<h3 className="text-balance text-sm text-gray-800">
Share documents. Not attachments.
</h3>
</div>
{isSSORequired && (
<div className="mx-4 mb-2 flex items-start gap-3 rounded-lg border border-orange-200 bg-orange-50 px-4 py-3 sm:mx-12">
<AlertCircle className="mt-0.5 h-5 w-5 flex-shrink-0 text-orange-600" />
<div>
<p className="text-sm font-medium text-orange-900">
Your organization requires SSO login
</p>
<p className="mt-1 text-sm text-orange-700">
Please use the <strong>SAML SSO</strong> option below to sign
in with your company&apos;s identity provider.
</p>
</div>
</div>
)}
<form
className="flex flex-col gap-4 px-4 pt-8 sm:px-12"
onSubmit={(e) => {
e.preventDefault();
if (!emailValidation.success) {
toast.error(emailValidation.error.errors[0].message);
return;
}
<main className="flex min-h-screen w-full items-center justify-center bg-black px-6 text-white">
<div className="w-full max-w-sm">
<Link href="/" className="mb-12 flex items-center gap-3">
<HanzoMark size={28} className="text-white" />
<span className="text-base font-medium tracking-tight">
{APP_NAME_PRIMARY}
{APP_NAME_SUFFIX && (
<span className="text-zinc-400"> {APP_NAME_SUFFIX}</span>
)}
</span>
</Link>
setClickedMethod("email");
signIn("email", {
email: emailValidation.data,
redirect: false,
...(next && next.length > 0 ? { callbackUrl: next } : {}),
}).then((res) => {
if (res?.ok && !res?.error) {
setLastUsed("credentials");
// Store email in sessionStorage for the verification page
try {
sessionStorage.setItem(
"pendingVerificationEmail",
emailValidation.data,
);
} catch {
// sessionStorage not available, verification page will show email input
}
router.push("/auth/email");
} else {
setEmailButtonText("Error sending email - try again?");
toast.error("Error sending email - try again?");
setClickedMethod(undefined);
}
});
}}
<h1 className="text-balance text-3xl font-semibold text-white">
Welcome to {APP_NAME}
</h1>
<p className="mt-2 text-balance text-sm text-zinc-400">{APP_TAGLINE}</p>
<Button
onClick={() =>
signIn("hanzo-iam", {
...(next && next.length > 0 ? { callbackUrl: next } : {}),
})
}
className="mt-8 flex w-full items-center justify-center bg-white font-normal text-black hover:bg-zinc-200"
>
<span>
Sign in with <span className="font-bold">{IAM_PROVIDER_NAME}</span>
</span>
</Button>
<p className="mt-8 text-xs text-zinc-500">
By clicking continue, you acknowledge that you have read and agree to{" "}
{APP_NAME}&apos;s{" "}
<a
href={`${MARKETING_URL}/terms`}
target="_blank"
className="text-zinc-300 underline hover:text-white"
>
<Label className="sr-only" htmlFor="email">
Email
</Label>
<Input
id="email"
placeholder="name@example.com"
type="email"
autoCapitalize="none"
autoComplete="email"
autoCorrect="off"
disabled={clickedMethod === "email"}
// pattern={patternSimpleEmailRegex}
value={email}
onChange={(e) => setEmail(e.target.value)}
className={cn(
"flex h-10 w-full rounded-md border-0 bg-background bg-white px-3 py-2 text-sm text-gray-900 ring-1 ring-gray-200 transition-colors file:border-0 file:bg-transparent file:text-sm file:font-medium placeholder:text-muted-foreground focus-visible:outline-none focus-visible:ring-1 focus-visible:ring-ring disabled:cursor-not-allowed disabled:opacity-50 dark:bg-white",
email.length > 0 && !emailValidation.success
? "ring-red-500"
: "ring-gray-200",
)}
/>
<div className="relative">
<Button
type="submit"
loading={clickedMethod === "email"}
disabled={!emailValidation.success || !!clickedMethod}
className={cn(
"focus:shadow-outline w-full transform rounded px-4 py-2 text-white transition-colors duration-300 ease-in-out focus:outline-none",
clickedMethod === "email"
? "bg-black"
: "bg-gray-800 hover:bg-gray-900",
)}
>
{emailButtonText}
</Button>
{lastUsed === "credentials" && <LastUsed />}
</div>
</form>
<p className="py-4 text-center">or</p>
<div className="flex flex-col space-y-2 px-4 sm:px-12">
<div className="relative">
<Button
onClick={() => {
setClickedMethod("google");
setLastUsed("google");
signIn("google", {
...(next && next.length > 0 ? { callbackUrl: next } : {}),
}).then((res) => {
setClickedMethod(undefined);
});
}}
loading={clickedMethod === "google"}
disabled={clickedMethod && clickedMethod !== "google"}
className="flex w-full items-center justify-center space-x-2 border border-gray-300 bg-gray-100 font-normal text-gray-900 hover:bg-gray-200"
>
<Google className="h-5 w-5" />
<span>Continue with Google</span>
{clickedMethod !== "google" && lastUsed === "google" && (
<LastUsed />
)}
</Button>
</div>
<div className="relative">
<Button
onClick={() => {
setClickedMethod("linkedin");
setLastUsed("linkedin");
signIn("linkedin", {
...(next && next.length > 0 ? { callbackUrl: next } : {}),
}).then((res) => {
setClickedMethod(undefined);
});
}}
loading={clickedMethod === "linkedin"}
disabled={clickedMethod && clickedMethod !== "linkedin"}
className="flex w-full items-center justify-center space-x-2 border border-gray-300 bg-gray-100 font-normal text-gray-900 hover:bg-gray-200"
>
<LinkedIn />
<span>Continue with LinkedIn</span>
{clickedMethod !== "linkedin" && lastUsed === "linkedin" && (
<LastUsed />
)}
</Button>
</div>
<div className="relative">
<Button
onClick={() => {
setLastUsed("passkey");
setClickedMethod("passkey");
signInWithPasskey({
tenantId: process.env.NEXT_PUBLIC_HANKO_TENANT_ID as string,
}).then(() => {
setClickedMethod(undefined);
});
}}
variant="outline"
loading={clickedMethod === "passkey"}
disabled={clickedMethod && clickedMethod !== "passkey"}
className="flex w-full items-center justify-center space-x-2 border border-gray-300 bg-gray-100 font-normal text-gray-900 hover:bg-gray-200 hover:text-gray-900"
>
<Passkey className="h-4 w-4" />
<span>Continue with a passkey</span>
{lastUsed === "passkey" && <LastUsed />}
</Button>
</div>
<div className="relative">
<SSOLogin autoExpand={isSSORequired} />
</div>
</div>
<p className="mt-10 w-full max-w-md px-4 text-xs text-muted-foreground sm:px-12">
By clicking continue, you acknowledge that you have read and agree
to Papermark&apos;s{" "}
<a
href={`${process.env.NEXT_PUBLIC_MARKETING_URL}/terms`}
target="_blank"
className="underline"
>
Terms of Service
</a>{" "}
and{" "}
<a
href={`${process.env.NEXT_PUBLIC_MARKETING_URL}/privacy`}
target="_blank"
className="underline"
>
Privacy Policy
</a>
.
</p>
</div>
</div>
<div className="relative hidden w-full justify-center overflow-hidden bg-black md:flex md:w-1/2 lg:w-1/2">
<div className="relative m-0 flex h-full min-h-[700px] w-full p-0">
<div
className="relative flex h-full w-full flex-col justify-between"
id="features"
Terms of Service
</a>{" "}
and{" "}
<a
href={`${MARKETING_URL}/privacy`}
target="_blank"
className="text-zinc-300 underline hover:text-white"
>
{/* Testimonial top 2/3 */}
<div
className="flex w-full flex-col items-center justify-center"
style={{ height: "66.6666%" }}
>
{/* Image container */}
<div className="mb-4 h-64 w-80">
<img
className="h-full w-full rounded-2xl object-cover shadow-2xl"
src="/_static/testimonials/backtrace.jpeg"
alt="Backtrace Capital"
/>
</div>
{/* Text content */}
<div className="max-w-xl text-center">
<blockquote className="text-balance font-normal leading-8 text-white sm:text-xl sm:leading-9">
<p>
&quot;We raised our 30M Fund with Papermark Data Rooms.
Love the customization, security and ease of use.&quot;
</p>
</blockquote>
<figcaption className="mt-4">
<div className="text-balance font-normal text-white">
Michael Münnix
</div>
<div className="text-balance font-light text-gray-400">
Partner, Backtrace Capital
</div>
</figcaption>
</div>
</div>
{/* White block with logos bottom 1/3, full width/height */}
<div
className="absolute bottom-0 left-0 flex w-full flex-col items-center justify-center bg-white"
style={{ height: "33.3333%" }}
>
<div className="mb-4 max-w-xl text-balance text-center font-semibold text-gray-900">
Trusted by teams at
</div>
<LogoCloud />
{/* <img
src="https://assets.papermark.io/upload/file_7JEGY7zM9ZTfmxu8pe7vWj-Screenshot-2025-05-09-at-18.09.13.png"
alt="Trusted teams illustration"
className="mt-4 max-w-full h-auto object-contain"
style={{maxHeight: '120px'}}
/> */}
</div>
</div>
</div>
Privacy Policy
</a>
.
</p>
</div>
</div>
</main>
);
}
+10 -6
View File
@@ -1,24 +1,26 @@
import { Metadata } from "next";
import { Suspense } from "react";
import { APP_NAME, APP_URL } from "@/lib/branding";
import { GTMComponent } from "@/components/gtm-component";
import LoginClient from "./page-client";
const data = {
description: "Login to Papermark",
title: "Login | Papermark",
description: `Login to ${APP_NAME}`,
title: `Login | ${APP_NAME}`,
url: "/login",
};
export const metadata: Metadata = {
metadataBase: new URL("https://www.papermark.com"),
metadataBase: new URL(APP_URL),
title: data.title,
description: data.description,
openGraph: {
title: data.title,
description: data.description,
url: data.url,
siteName: "Papermark",
siteName: APP_NAME,
images: [
{
url: "/_static/meta-image.png",
@@ -33,7 +35,7 @@ export const metadata: Metadata = {
card: "summary_large_image",
title: data.title,
description: data.description,
creator: "@papermarkio",
creator: "@hanzoai",
images: ["/_static/meta-image.png"],
},
};
@@ -42,7 +44,9 @@ export default function LoginPage() {
return (
<>
<GTMComponent />
<LoginClient />
<Suspense>
<LoginClient />
</Suspense>
</>
);
}
+4 -4
View File
@@ -6,7 +6,7 @@ import { useParams } from "next/navigation";
import { useState } from "react";
import PapermarkLogo from "@/public/_static/papermark-logo.svg";
import HanzoLogo from "@/public/_static/hanzo-dataroom-logo.svg";
import { signIn } from "next-auth/react";
import { toast } from "sonner";
@@ -35,12 +35,12 @@ export default function Register() {
</div>
<div className="z-10 mx-5 mt-[calc(20vh)] h-fit w-full max-w-md overflow-hidden rounded-lg border border-border bg-gray-50 dark:bg-gray-900 sm:mx-0 sm:shadow-xl">
<div className="flex flex-col items-center justify-center space-y-3 px-4 py-6 pt-8 text-center sm:px-16">
<Link href="https://www.papermark.com" target="_blank">
<Link href="https://dataroom.hanzo.ai" target="_blank">
<Image
src={PapermarkLogo}
src={HanzoLogo}
width={119}
height={32}
alt="Papermark Logo"
alt="Hanzo Dataroom Logo"
/>
</Link>
<h3 className="text-2xl font-medium text-foreground">
+6 -5
View File
@@ -1,22 +1,23 @@
import { Metadata } from "next";
import { APP_NAME, APP_URL } from "@/lib/branding";
import RegisterClient from "./page-client";
const data = {
description: "Signup to Papermark",
title: "Sign up | Papermark",
description: `Signup to ${APP_NAME}`,
title: `Sign up | ${APP_NAME}`,
url: "/register",
};
export const metadata: Metadata = {
metadataBase: new URL("https://www.papermark.com"),
metadataBase: new URL(APP_URL),
title: data.title,
description: data.description,
openGraph: {
title: data.title,
description: data.description,
url: data.url,
siteName: "Papermark",
siteName: APP_NAME,
images: [
{
url: "/_static/meta-image.png",
@@ -31,7 +32,7 @@ export const metadata: Metadata = {
card: "summary_large_image",
title: data.title,
description: data.description,
creator: "@papermarkio",
creator: "@hanzoai",
images: ["/_static/meta-image.png"],
},
};
@@ -37,7 +37,7 @@ export default function InvitationStatusContent({
</div>
<div className="w-full space-y-4">
<h4 className="text-center text-sm font-medium text-gray-800">
Create your own Papermark account
Create your own Hanzo Dataroom account
</h4>
<div className="space-y-3">
<Link href="/login" className="block w-full">
+12 -12
View File
@@ -13,20 +13,20 @@ import InvitationStatusContent from "./InvitationStatusContent";
import CleanUrlOnExpire from "./status/ClientRedirect";
const data = {
description: "Accept your team invitation on Papermark",
title: "Accept Invitation | Papermark",
description: "Accept your team invitation on Hanzo Dataroom",
title: "Accept Invitation | Hanzo Dataroom",
url: "/verify/invitation",
};
export const metadata: Metadata = {
metadataBase: new URL("https://www.papermark.com"),
metadataBase: new URL("https://dataroom.hanzo.ai"),
title: data.title,
description: data.description,
openGraph: {
title: data.title,
description: data.description,
url: data.url,
siteName: "Papermark",
siteName: "Hanzo Dataroom",
images: [
{
url: "/_static/meta-image.png",
@@ -41,7 +41,7 @@ export const metadata: Metadata = {
card: "summary_large_image",
title: data.title,
description: data.description,
creator: "@papermarkio",
creator: "@hanzoai",
images: ["/_static/meta-image.png"],
},
};
@@ -49,11 +49,11 @@ export const metadata: Metadata = {
export default async function VerifyInvitationPage({
searchParams,
}: {
searchParams: {
searchParams: Promise<{
token?: string;
};
}>;
}) {
const { token: jwtToken } = searchParams;
const { token: jwtToken } = await searchParams;
if (!jwtToken) {
return <NotFound />;
@@ -100,13 +100,13 @@ export default async function VerifyInvitationPage({
<div className="flex flex-col items-center justify-center space-y-3 px-4 py-6 pt-8 text-center sm:px-16">
<Link href="/">
<span className="text-balance text-2xl font-semibold text-gray-800">
Welcome to Papermark
Welcome to Hanzo Dataroom
</span>
</Link>
{!isExpired && !isRevoked && (
<>
<h3 className="text-balance py-1 text-sm font-normal text-gray-800">
You&apos;ve been invited to join a team on Papermark
You&apos;ve been invited to join a team on Hanzo Dataroom
</h3>
<div className="mt-2 flex w-auto items-center justify-center gap-2 rounded-full bg-gray-50 px-5 py-2.5 text-sm text-gray-600 shadow-sm">
<MailIcon className="h-4 w-4 text-gray-400" />
@@ -148,7 +148,7 @@ export default async function VerifyInvitationPage({
</div>
<p className="mt-10 w-full max-w-md px-4 text-xs text-muted-foreground sm:px-16">
By accepting this invitation, you acknowledge that you have
read and agree to Papermark&apos;s{" "}
read and agree to Hanzo Dataroom&apos;s{" "}
<a
href={`${process.env.NEXT_PUBLIC_MARKETING_URL}/terms`}
target="_blank"
@@ -191,7 +191,7 @@ export default async function VerifyInvitationPage({
<blockquote className="text-l text-balance leading-8 text-gray-100 sm:text-xl sm:leading-9">
<p>
True builders listen to their users and build what they
need. Thanks Papermark team for solving a big pain point.
need. Thanks Hanzo Dataroom team for solving a big pain point.
DocSend monopoly will end soon!
</p>
</blockquote>
-1
View File
@@ -1 +0,0 @@
../ee/LICENSE.md
-1
View File
@@ -1 +0,0 @@
../ee/README.md
@@ -1,10 +1,10 @@
import { NextRequest } from "next/server";
import { generateChatTitle } from "@/ee/features/ai/lib/chat/generate-chat-title";
import { getFilteredDataroomDocumentIds } from "@/ee/features/ai/lib/chat/get-filtered-dataroom-document-ids";
import { sendMessage } from "@/ee/features/ai/lib/chat/send-message";
import { validateChatAccess } from "@/ee/features/ai/lib/permissions/validate-chat-access";
import { sendMessageSchema } from "@/ee/features/ai/schemas/chat";
import { generateChatTitle } from "@/features/ai/lib/chat/generate-chat-title";
import { getFilteredDataroomDocumentIds } from "@/features/ai/lib/chat/get-filtered-dataroom-document-ids";
import { sendMessage } from "@/features/ai/lib/chat/send-message";
import { validateChatAccess } from "@/features/ai/lib/permissions/validate-chat-access";
import { sendMessageSchema } from "@/features/ai/schemas/chat";
import { authOptions } from "@/pages/api/auth/[...nextauth]";
import { getServerSession } from "next-auth";
@@ -35,8 +35,11 @@ export async function POST(
);
}
const { content, filterDocumentId, filterDataroomDocumentIds } =
validation.data;
const {
content,
filterDocumentId,
filterDataroomDocumentIds,
} = validation.data;
const session = await getServerSession(authOptions);
const searchParams = req.nextUrl.searchParams;
@@ -133,16 +136,49 @@ export async function POST(
}
// Send message and get streaming response
const result = await sendMessage({
const { result, referencesForStream } = await sendMessage({
chatId,
content,
vectorStoreId: chat.vectorStoreId,
filteredDataroomDocumentIds,
filterDocumentId,
userSelectedDataroomDocumentIds: filterDataroomDocumentIds,
dataroomId: chat.dataroomId || undefined,
linkId: chat.linkId || undefined,
});
return result.toTextStreamResponse();
const encoder = new TextEncoder();
const stream = new ReadableStream<Uint8Array>({
async start(controller) {
try {
for await (const chunk of result.textStream) {
controller.enqueue(encoder.encode(chunk));
}
const referencesSection = await Promise.race([
referencesForStream,
new Promise<string>((resolve) =>
setTimeout(() => resolve(""), 5000),
),
]);
if (referencesSection) {
controller.enqueue(encoder.encode(referencesSection));
}
controller.close();
} catch (error) {
console.error("Error streaming AI response:", error);
controller.error(error);
}
},
});
return new Response(stream, {
headers: {
"Content-Type": "text/plain; charset=utf-8",
},
});
} catch (error) {
console.error("Error sending message:", error);
return new Response(JSON.stringify({ error: "Internal server error" }), {
@@ -1,6 +1,6 @@
import { NextRequest, NextResponse } from "next/server";
import { validateChatAccess } from "@/ee/features/ai/lib/permissions/validate-chat-access";
import { validateChatAccess } from "@/features/ai/lib/permissions/validate-chat-access";
import { authOptions } from "@/pages/api/auth/[...nextauth]";
import { getServerSession } from "next-auth";
@@ -1,7 +1,7 @@
import { NextRequest, NextResponse } from "next/server";
import { createChat } from "@/ee/features/ai/lib/chat/create-chat";
import { createChatSchema } from "@/ee/features/ai/schemas/chat";
import { createChat } from "@/features/ai/lib/chat/create-chat";
import { createChatSchema } from "@/features/ai/schemas/chat";
import { authOptions } from "@/pages/api/auth/[...nextauth]";
import { getServerSession } from "next-auth";
import { z } from "zod";
@@ -4,8 +4,8 @@ import {
SUPPORTED_AI_CONTENT_TYPES,
addFileToVectorStoreTask,
processDocumentForAITask,
} from "@/ee/features/ai/lib/trigger";
import { createDataroomVectorStore } from "@/ee/features/ai/lib/vector-stores/create-dataroom-vector-store";
} from "@/features/ai/lib/trigger";
import { createDataroomVectorStore } from "@/features/ai/lib/vector-stores/create-dataroom-vector-store";
import { authOptions } from "@/pages/api/auth/[...nextauth]";
import { getServerSession } from "next-auth";
@@ -4,9 +4,9 @@ import {
addFileToVectorStoreTask,
processDocumentForAITask,
SUPPORTED_AI_CONTENT_TYPES,
} from "@/ee/features/ai/lib/trigger";
import { createTeamVectorStore } from "@/ee/features/ai/lib/vector-stores/create-team-vector-store";
import { removeFileFromVectorStore } from "@/ee/features/ai/lib/vector-stores/remove-file-from-vector-store";
} from "@/features/ai/lib/trigger";
import { createTeamVectorStore } from "@/features/ai/lib/vector-stores/create-team-vector-store";
import { removeFileFromVectorStore } from "@/features/ai/lib/vector-stores/remove-file-from-vector-store";
import { authOptions } from "@/pages/api/auth/[...nextauth]";
import { getServerSession } from "next-auth";
@@ -1,6 +1,6 @@
import { NextRequest, NextResponse } from "next/server";
import { getVectorStoreInfo } from "@/ee/features/ai/lib/vector-stores/get-vector-store-info";
import { getVectorStoreInfo } from "@/features/ai/lib/vector-stores/get-vector-store-info";
import { authOptions } from "@/pages/api/auth/[...nextauth]";
import { getServerSession } from "next-auth";
@@ -27,10 +27,12 @@ export async function GET(
const userId = (session.user as CustomUser).id;
// Verify user is member of team
const userTeam = await prisma.userTeam.findFirst({
const userTeam = await prisma.userTeam.findUnique({
where: {
userId,
teamId,
userId_teamId: {
userId,
teamId,
},
},
});
@@ -0,0 +1,33 @@
import { NextResponse } from "next/server";
import { receiver } from "@/lib/cron";
import { processDataroomDigest } from "@/lib/emails/process-dataroom-digest";
import { log } from "@/lib/utils";
// Runs daily at 9 AM UTC (0 9 * * *)
export const maxDuration = 300;
export async function POST(req: Request) {
const body = await req.json();
if (process.env.VERCEL === "1") {
const isValid = await receiver.verify({
signature: req.headers.get("Upstash-Signature") || "",
body: JSON.stringify(body),
});
if (!isValid) {
return new Response("Unauthorized", { status: 401 });
}
}
try {
const result = await processDataroomDigest("daily");
return NextResponse.json({ success: true, ...result });
} catch (error) {
await log({
message: `Daily dataroom digest cron failed. \n\nError: ${(error as Error).message}`,
type: "cron",
mention: true,
});
return NextResponse.json({ error: (error as Error).message });
}
}
@@ -0,0 +1,33 @@
import { NextResponse } from "next/server";
import { receiver } from "@/lib/cron";
import { processDataroomDigest } from "@/lib/emails/process-dataroom-digest";
import { log } from "@/lib/utils";
// Runs weekly on Monday at 9 AM UTC (0 9 * * 1)
export const maxDuration = 300;
export async function POST(req: Request) {
const body = await req.json();
if (process.env.VERCEL === "1") {
const isValid = await receiver.verify({
signature: req.headers.get("Upstash-Signature") || "",
body: JSON.stringify(body),
});
if (!isValid) {
return new Response("Unauthorized", { status: 401 });
}
}
try {
const result = await processDataroomDigest("weekly");
return NextResponse.json({ success: true, ...result });
} catch (error) {
await log({
message: `Weekly dataroom digest cron failed. \n\nError: ${(error as Error).message}`,
type: "cron",
mention: true,
});
return NextResponse.json({ error: (error as Error).message });
}
}
+1 -1
View File
@@ -38,7 +38,7 @@ export async function POST(req: Request) {
where: {
slug: {
not: {
in: ["papermark.io", "papermark.com"],
in: ["dataroom.hanzo.ai", "dataroom.hanzo.ai"],
},
},
},
@@ -5,10 +5,112 @@ import { verifyDataroomSession } from "@/lib/auth/dataroom-auth";
import { DocumentData } from "@/lib/documents/create-document";
import prisma from "@/lib/prisma";
import { sendDataroomUploadNotificationTask } from "@/lib/trigger/dataroom-upload-notification";
import { sanitizePlainText } from "@/lib/utils/sanitize-html";
import { supportsAdvancedExcelMode } from "@/lib/utils/get-content-type";
import { runs } from "@trigger.dev/sdk/v3";
import { waitUntil } from "@vercel/functions";
/**
* GET /api/links/[id]/upload?dataroomId=xxx
* Returns the viewer's previously uploaded documents for this dataroom.
*/
export async function GET(
request: NextRequest,
{ params }: { params: { id: string } },
) {
try {
const linkId = params.id;
const dataroomId = request.nextUrl.searchParams.get("dataroomId");
if (!linkId || !dataroomId) {
return NextResponse.json(
{ message: "Missing required parameters" },
{ status: 400 },
);
}
// Verify the dataroom session
const dataroomSession = await verifyDataroomSession(
request,
linkId,
dataroomId,
);
if (!dataroomSession || !dataroomSession.viewerId) {
return NextResponse.json(
{ message: "Unauthorized" },
{ status: 401 },
);
}
const { viewerId } = dataroomSession;
// Fetch the viewer's uploads for this dataroom
const uploads = await prisma.documentUpload.findMany({
where: {
viewerId,
dataroomId,
linkId,
},
select: {
id: true,
documentId: true,
dataroomDocumentId: true,
originalFilename: true,
uploadedAt: true,
document: {
select: {
id: true,
name: true,
type: true,
versions: {
where: { isPrimary: true },
select: {
id: true,
hasPages: true,
},
take: 1,
},
},
},
dataroomDocument: {
select: {
folderId: true,
},
},
},
orderBy: { uploadedAt: "desc" },
});
const formattedUploads = uploads.map((upload) => {
const fileType = upload.document?.type ?? "";
const hasPages = upload.document?.versions?.[0]?.hasPages ?? false;
const needsProcessing = ["pdf", "docs", "slides"].includes(fileType);
const isComplete = !needsProcessing || hasPages;
return {
id: upload.id,
documentId: upload.documentId,
dataroomDocumentId: upload.dataroomDocumentId,
documentVersionId: upload.document?.versions?.[0]?.id ?? null,
name: upload.originalFilename ?? upload.document?.name ?? "Unknown",
fileType,
folderId: upload.dataroomDocument?.folderId ?? null,
uploadedAt: upload.uploadedAt,
status: isComplete ? "complete" : "processing",
};
});
return NextResponse.json({ uploads: formattedUploads });
} catch (error) {
console.error("Error fetching viewer uploads:", error);
return NextResponse.json(
{ message: "Error fetching uploads" },
{ status: 500 },
);
}
}
export async function POST(
request: NextRequest,
{ params }: { params: { id: string } },
@@ -94,9 +196,31 @@ export async function POST(
);
}
if (typeof documentData.name !== "string") {
return NextResponse.json(
{ message: "Document name is required" },
{ status: 400 },
);
}
const sanitizedDocumentName = sanitizePlainText(documentData.name);
if (!sanitizedDocumentName) {
return NextResponse.json(
{ message: "Document name is required" },
{ status: 400 },
);
}
if (sanitizedDocumentName.length > 255) {
return NextResponse.json(
{ message: "Document name too long" },
{ status: 400 },
);
}
const updatedDocumentData = {
...documentData,
name: sanitizedDocumentName,
enableExcelAdvancedMode: documentData.supportedFileType === "sheet" &&
link.team?.enableExcelAdvancedMode &&
supportsAdvancedExcelMode(documentData.contentType),
@@ -144,7 +268,7 @@ export async function POST(
viewId: viewId,
linkId: linkId,
originalFilename: document.name,
fileSize: document.versions[0].fileSize,
fileSize: documentData.fileSize ?? 0,
numPages: document.numPages,
mimeType: document.contentType,
dataroomId: dataroomId,
@@ -203,7 +327,20 @@ export async function POST(
}
}
return NextResponse.json({ success: true });
// Return document data for optimistic UI rendering
return NextResponse.json({
success: true,
document: {
id: document.id,
name: document.name,
dataroomDocumentId: newDataroomDocument.id,
documentVersionId: document.versions[0]?.id,
folderId: dataroomFolderId,
fileType: document.type,
hasPages: (document.numPages ?? 0) > 0,
createdAt: document.createdAt,
},
});
} catch (error) {
console.error("Error uploading document:", error);
return NextResponse.json(
+2 -2
View File
@@ -10,7 +10,7 @@ export const runtime = "edge";
*/
export async function GET(request: NextRequest) {
const searchParams = request.nextUrl.searchParams;
const title = searchParams.get("title") || "Papermark Document";
const title = searchParams.get("title") || "Hanzo Dataroom Document";
const Inter = await fetch(
new URL("@/public/_static/Inter-Bold.ttf", import.meta.url),
).then((res) => res.arrayBuffer());
@@ -18,7 +18,7 @@ export async function GET(request: NextRequest) {
return new ImageResponse(
(
<div tw="flex flex-col items-center justify-between w-full h-full bg-white text-black p-12">
<div tw="text-[32px] flex items-center tracking-tighter">Papermark</div>
<div tw="text-[32px] flex items-center tracking-tighter">Hanzo Dataroom</div>
<div tw="text-[42px] text-center">{title}</div>
<div tw="text-[32px] flex items-center">
Open-Source Document Sharing
+2 -2
View File
@@ -29,7 +29,7 @@ export async function GET(req: NextRequest) {
{/* Left Side Text */}
<div tw="flex flex-col text-white" style={{ marginLeft: "48px" }}>
<div tw="flex text-7xl font-bold mb-4 tracking-tighter">
Papermark
Hanzo Dataroom
</div>
<div tw="flex text-5xl mb-4">Year in Review</div>
<div tw="flex text-7xl font-bold">{year}</div>
@@ -49,7 +49,7 @@ export async function GET(req: NextRequest) {
{/* Header Section */}
<div tw="flex items-start p-8 items-center">
<div tw="flex text-2xl font-bold text-white tracking-tighter">
Papermark
Hanzo Dataroom
</div>
</div>
@@ -8,6 +8,15 @@ import { authOptions } from "@/pages/api/auth/[...nextauth]";
const SSO_ELIGIBLE_PLANS = ["datarooms-premium", "datarooms-premium+old"];
function isJacksonUnavailableError(error: unknown): boolean {
const message = error instanceof Error ? error.message : String(error);
return (
message.includes("error connecting to engine") ||
message.includes("Missing Jackson DB URL") ||
message.includes("ENOENT: no such file or directory, open 'system'")
);
}
async function getAuthenticatedAdmin(teamId: string) {
const session = await getServerSession(authOptions);
if (!session) return null;
@@ -43,6 +52,10 @@ export async function GET(
}
try {
if (!auth.team.ssoEnabled || !SSO_ELIGIBLE_PLANS.includes(auth.team.plan)) {
return NextResponse.json({ directories: [] });
}
const { directorySyncController } = await jackson();
const { data, error } =
@@ -57,6 +70,11 @@ export async function GET(
return NextResponse.json({ directories: data });
} catch (error: any) {
if (isJacksonUnavailableError(error)) {
console.warn("[SCIM] Jackson unavailable, returning empty directories", error);
return NextResponse.json({ directories: [] });
}
console.error("[SCIM] Get directories error:", error);
return NextResponse.json(
{ error: error.message || "Internal server error" },
@@ -101,7 +119,7 @@ export async function POST(
const result = await directorySyncController.directories.create({
tenant: teamId,
product: jacksonProduct,
name: name || "Papermark SCIM Directory",
name: name || "Hanzo Dataroom SCIM Directory",
type: type || "azure-scim-v2",
});
@@ -9,6 +9,15 @@ import { authOptions } from "@/pages/api/auth/[...nextauth]";
const SSO_ELIGIBLE_PLANS = ["datarooms-premium", "datarooms-premium+old"];
function isJacksonUnavailableError(error: unknown): boolean {
const message = error instanceof Error ? error.message : String(error);
return (
message.includes("error connecting to engine") ||
message.includes("Missing Jackson DB URL") ||
message.includes("ENOENT: no such file or directory, open 'system'")
);
}
async function getAuthenticatedAdmin(teamId: string) {
const session = await getServerSession(authOptions);
if (!session) return null;
@@ -44,6 +53,17 @@ export async function GET(
}
try {
if (!auth.team.ssoEnabled || !SSO_ELIGIBLE_PLANS.includes(auth.team.plan)) {
return NextResponse.json({
connections: [],
issuer: samlAudience,
acs: `${process.env.NEXTAUTH_URL}/api/auth/saml/callback`,
ssoEmailDomain: auth.team.ssoEmailDomain,
ssoEnforcedAt: auth.team.ssoEnforcedAt,
slug: auth.team.slug,
});
}
const { apiController } = await jackson();
const connections = await apiController.getConnections({
@@ -60,6 +80,18 @@ export async function GET(
slug: auth.team.slug,
});
} catch (error: any) {
if (isJacksonUnavailableError(error)) {
console.warn("[SAML] Jackson unavailable, returning empty connections", error);
return NextResponse.json({
connections: [],
issuer: samlAudience,
acs: `${process.env.NEXTAUTH_URL}/api/auth/saml/callback`,
ssoEmailDomain: auth.team.ssoEmailDomain,
ssoEnforcedAt: auth.team.ssoEnforcedAt,
slug: auth.team.slug,
});
}
console.error("[SAML] Get connections error:", error);
return NextResponse.json(
{ error: error.message || "Internal server error" },
+21 -4
View File
@@ -1,7 +1,7 @@
import { NextRequest, NextResponse } from "next/server";
import { reportDeniedAccessAttempt } from "@/ee/features/access-notifications";
import { getTeamStorageConfigById } from "@/ee/features/storage/config";
import { reportDeniedAccessAttempt } from "@/features/access-notifications";
import { getTeamStorageConfigById } from "@/features/storage/config";
import { authOptions } from "@/pages/api/auth/[...nextauth]";
import { ItemType, LinkAudienceType } from "@prisma/client";
import { ipAddress, waitUntil } from "@vercel/functions";
@@ -147,6 +147,15 @@ export async function POST(request: NextRequest) {
name: true,
},
},
visitorGroups: {
select: {
visitorGroup: {
select: {
emails: true,
},
},
},
},
},
});
@@ -312,10 +321,18 @@ export async function POST(request: NextRequest) {
return NextResponse.json({ message: "Access denied" }, { status: 403 });
}
// Build combined allow list from individual emails + visitor groups
const visitorGroupEmails =
link.visitorGroups?.flatMap((vg) => vg.visitorGroup.emails) || [];
const combinedAllowList = [
...(link.allowList || []),
...visitorGroupEmails,
];
// Check if email is allowed to visit the link
if (link.allowList && link.allowList.length > 0) {
if (combinedAllowList.length > 0) {
// Determine if the email or its domain is allowed
const isAllowed = link.allowList.some((allowed) =>
const isAllowed = combinedAllowList.some((allowed) =>
isEmailMatched(email, allowed),
);
+21 -4
View File
@@ -1,7 +1,7 @@
import { NextRequest, NextResponse } from "next/server";
import { reportDeniedAccessAttempt } from "@/ee/features/access-notifications";
import { getTeamStorageConfigById } from "@/ee/features/storage/config";
import { reportDeniedAccessAttempt } from "@/features/access-notifications";
import { getTeamStorageConfigById } from "@/features/storage/config";
// Import authOptions directly from the source
import { authOptions } from "@/pages/api/auth/[...nextauth]";
import { ipAddress, waitUntil } from "@vercel/functions";
@@ -123,6 +123,15 @@ export async function POST(request: NextRequest) {
agentsEnabled: true,
},
},
visitorGroups: {
select: {
visitorGroup: {
select: {
emails: true,
},
},
},
},
},
});
@@ -246,10 +255,18 @@ export async function POST(request: NextRequest) {
return NextResponse.json({ message: "Access denied" }, { status: 403 });
}
// Build combined allow list from individual emails + visitor groups
const visitorGroupEmails =
link.visitorGroups?.flatMap((vg) => vg.visitorGroup.emails) || [];
const combinedAllowList = [
...(link.allowList || []),
...visitorGroupEmails,
];
// Check if email is allowed to visit the link
if (link.allowList && link.allowList.length > 0) {
if (combinedAllowList.length > 0) {
// Determine if the email or its domain is allowed
const isAllowed = link.allowList.some((allowed) =>
const isAllowed = combinedAllowList.some((allowed) =>
isEmailMatched(email, allowed),
);
@@ -1,11 +1,11 @@
import { cookies } from "next/headers";
import { NextRequest, NextResponse } from "next/server";
import { WorkflowEngine } from "@/ee/features/workflows/lib/engine";
import { WorkflowEngine } from "@/features/workflows/lib/engine";
import {
AccessRequestSchema,
VerifyEmailRequestSchema,
} from "@/ee/features/workflows/lib/types";
} from "@/features/workflows/lib/types";
import { ipAddress, waitUntil } from "@vercel/functions";
import { z } from "zod";
@@ -1,8 +1,8 @@
import { cookies } from "next/headers";
import { NextRequest, NextResponse } from "next/server";
import { WorkflowEngine } from "@/ee/features/workflows/lib/engine";
import { AccessRequestSchema } from "@/ee/features/workflows/lib/types";
import { WorkflowEngine } from "@/features/workflows/lib/engine";
import { AccessRequestSchema } from "@/features/workflows/lib/types";
import { ipAddress } from "@vercel/functions";
import { z } from "zod";
@@ -6,7 +6,7 @@ import { ratelimit } from "@/lib/redis";
import { sendOtpVerificationEmail } from "@/lib/emails/send-email-otp-verification";
import { generateOTP } from "@/lib/utils/generate-otp";
import { validateEmail } from "@/lib/utils/validate-email";
import { VerifyEmailRequestSchema } from "@/ee/features/workflows/lib/types";
import { VerifyEmailRequestSchema } from "@/features/workflows/lib/types";
// POST /app/(ee)/api/workflow-entry/[entryLinkId]/verify - Send OTP
export async function POST(
@@ -3,7 +3,7 @@ import { NextRequest, NextResponse } from "next/server";
import {
UpdateWorkflowRequestSchema,
formatZodError,
} from "@/ee/features/workflows/lib/validation";
} from "@/features/workflows/lib/validation";
import { authOptions } from "@/pages/api/auth/[...nextauth]";
import { customAlphabet } from "nanoid";
import { getServerSession } from "next-auth";
@@ -5,7 +5,7 @@ import {
formatZodError,
validateActions,
validateConditions,
} from "@/ee/features/workflows/lib/validation";
} from "@/features/workflows/lib/validation";
import { authOptions } from "@/pages/api/auth/[...nextauth]";
import { getServerSession } from "next-auth";
import { z } from "zod";
@@ -10,8 +10,8 @@ import {
formatZodError,
validateConditions,
validateActions,
} from "@/ee/features/workflows/lib/validation";
import { ReorderStepsRequest } from "@/ee/features/workflows/lib/types";
} from "@/features/workflows/lib/validation";
import { ReorderStepsRequest } from "@/features/workflows/lib/types";
// GET /app/(ee)/api/workflows/[workflowId]/steps?teamId=xxx - List all steps
export async function GET(
@@ -3,7 +3,7 @@ import { NextRequest, NextResponse } from "next/server";
import {
CreateWorkflowRequestSchema,
formatZodError,
} from "@/ee/features/workflows/lib/validation";
} from "@/features/workflows/lib/validation";
import { authOptions } from "@/pages/api/auth/[...nextauth]";
import { getServerSession } from "next-auth";
import { z } from "zod";
+8 -7
View File
@@ -5,22 +5,23 @@ import "@/styles/globals.css";
const inter = Inter({ subsets: ["latin"] });
import { APP_DESCRIPTION, APP_NAME, APP_URL } from "@/lib/branding";
const data = {
description:
"Papermark is an open-source document sharing infrastructure. Free alternative to Docsend with custom domain. Manage secure document sharing with real-time analytics.",
title: "Papermark | The Open Source DocSend Alternative",
description: APP_DESCRIPTION,
title: `${APP_NAME} | Secure Data Room Infrastructure`,
url: "/",
};
export const metadata: Metadata = {
metadataBase: new URL("https://www.papermark.com"),
metadataBase: new URL(APP_URL),
title: data.title,
description: data.description,
openGraph: {
title: data.title,
description: data.description,
url: data.url,
siteName: "Papermark",
siteName: APP_NAME,
images: [
{
url: "/_static/meta-image.png",
@@ -35,7 +36,7 @@ export const metadata: Metadata = {
card: "summary_large_image",
title: data.title,
description: data.description,
creator: "@papermarkio",
creator: "@hanzoai",
images: ["/_static/meta-image.png"],
},
};
@@ -46,7 +47,7 @@ export default function RootLayout({
children: React.ReactNode;
}) {
return (
<html lang="en">
<html lang="en" className="dark">
<body className={inter.className}>{children}</body>
</html>
);
-1
View File
@@ -1,5 +1,4 @@
User-Agent: *
Disallow: /login
Disallow: /register
Disallow: /verify/
Disallow: /auth/
+1 -1
View File
@@ -4,7 +4,7 @@ import { useRouter } from "next/router";
import { useState } from "react";
import { useTeam } from "@/context/team-context";
import { PlanEnum } from "@/ee/stripe/constants";
import { PlanEnum } from "@/lib/billing/legacy/constants";
import {
ColumnDef,
SortingState,
+1 -1
View File
@@ -4,7 +4,7 @@ import { useRouter } from "next/router";
import { useEffect, useState } from "react";
import { useTeam } from "@/context/team-context";
import { PlanEnum } from "@/ee/stripe/constants";
import { PlanEnum } from "@/lib/billing/legacy/constants";
import {
ColumnDef,
SortingState,
+1 -1
View File
@@ -1,6 +1,6 @@
import { useEffect, useState } from "react";
import { PlanEnum } from "@/ee/stripe/constants";
import { PlanEnum } from "@/lib/billing/legacy/constants";
import { differenceInDays, format, startOfDay, subDays } from "date-fns";
import { CalendarIcon, ChevronDown, CrownIcon } from "lucide-react";
import { DateRange } from "react-day-picker";
+1 -1
View File
@@ -4,7 +4,7 @@ import { useRouter } from "next/router";
import { useState } from "react";
import { useTeam } from "@/context/team-context";
import { PlanEnum } from "@/ee/stripe/constants";
import { PlanEnum } from "@/lib/billing/legacy/constants";
import {
ColumnDef,
SortingState,
+1 -1
View File
@@ -4,7 +4,7 @@ import { useRouter } from "next/router";
import { useState } from "react";
import { useTeam } from "@/context/team-context";
import { PlanEnum } from "@/ee/stripe/constants";
import { PlanEnum } from "@/lib/billing/legacy/constants";
import {
ColumnDef,
SortingState,
+2 -2
View File
@@ -4,8 +4,8 @@ import { useRouter } from "next/router";
import { useEffect, useState } from "react";
import { useTeam } from "@/context/team-context";
import { getPriceIdFromPlan } from "@/ee/stripe/functions/get-price-id-from-plan";
import { getQuantityFromPriceId } from "@/ee/stripe/functions/get-quantity-from-plan";
import { getPriceIdFromPlan } from "@/lib/billing/legacy/functions/get-price-id-from-plan";
import { getQuantityFromPriceId } from "@/lib/billing/legacy/functions/get-quantity-from-plan";
import { toast } from "sonner";
import { useAnalytics } from "@/lib/analytics";
+16
View File
@@ -0,0 +1,16 @@
/**
* Stub `CancellationModal` the commercial cancellation funnel was removed
* with the AGPL paywall rip. We keep the component as a no-op so existing
* call sites compile.
*/
export type CancellationModalProps = {
open?: boolean;
onOpenChange?: (open: boolean) => void;
};
export function CancellationModal(_props: CancellationModalProps) {
return null;
}
export default CancellationModal;
+2 -2
View File
@@ -3,7 +3,7 @@ import { useRouter } from "next/router";
import { Dispatch, SetStateAction, useState } from "react";
import { useTeam } from "@/context/team-context";
import { getPriceIdFromPlan } from "@/ee/stripe/functions/get-price-id-from-plan";
import { getPriceIdFromPlan } from "@/lib/billing/legacy/functions/get-price-id-from-plan";
import Cookies from "js-cookie";
import { toast } from "sonner";
@@ -41,7 +41,7 @@ export default function ProAnnualBanner({
<span className="sr-only">Close</span>
</button>
<div className="flex space-x-2">
<span className="text-sm font-bold">Papermark Pro Annual </span>
<span className="text-sm font-bold">Hanzo Dataroom Pro Annual </span>
</div>
<p className="my-4 text-sm">
Lock in a better price and get 2 months free.
+2 -2
View File
@@ -1,6 +1,6 @@
import { Dispatch, SetStateAction } from "react";
import { PlanEnum } from "@/ee/stripe/constants";
import { PlanEnum } from "@/lib/billing/legacy/constants";
import Cookies from "js-cookie";
import X from "@/components/shared/icons/x";
@@ -31,7 +31,7 @@ export default function ProBanner({
<span className="sr-only">Close</span>
</button>
<div className="flex space-x-2">
<span className="text-sm font-bold"> Papermark Business </span>
<span className="text-sm font-bold"> Hanzo Dataroom Business </span>
</div>
<p className="my-4 text-sm">
Upgrade to unlock custom branding, team members, domains and data rooms.
@@ -3,8 +3,8 @@ import { useRouter } from "next/router";
import { useState } from "react";
import { useTeam } from "@/context/team-context";
import { CancellationModal } from "@/ee/features/billing/cancellation/components";
import { PlanEnum } from "@/ee/stripe/constants";
import { CancellationModal } from "@/components/billing/cancellation-modal";
import { PlanEnum } from "@/lib/billing/legacy/constants";
import {
BanIcon,
CirclePauseIcon,
@@ -4,8 +4,8 @@ import { useEffect, useMemo, useState } from "react";
import React from "react";
import { useTeam } from "@/context/team-context";
import { getStripe } from "@/ee/stripe/client";
import { PLANS } from "@/ee/stripe/utils";
import { getStripe } from "@/lib/billing/legacy/client";
import { PLANS } from "@/lib/billing/legacy/utils";
import { CheckIcon } from "lucide-react";
import { Button } from "@/components/ui/button";
@@ -53,7 +53,7 @@ export function UpgradePlanModal({
"Custom branding",
"Folder organization",
"Require email verification",
"Papermark branding removed",
"Hanzo Dataroom branding removed",
"1-year analytics retention",
];
}
@@ -287,11 +287,11 @@ export function UpgradePlanModal({
</DataroomTrialModal>
) : (
<a
href="https://cal.com/marcseitz/papermark"
href="https://dataroom.hanzo.ai/contact"
target="_blank"
className="underline-offset-4 transition-all hover:text-gray-800 hover:underline hover:dark:text-muted-foreground/80"
>
Looking for Papermark Enterprise?
Looking for Hanzo Dataroom Enterprise?
</a>
)}
</div>
@@ -5,10 +5,10 @@ import { useEffect, useMemo, useState } from "react";
import React from "react";
import { useTeam } from "@/context/team-context";
import { getStripe } from "@/ee/stripe/client";
import { Feature, PlanEnum, getPlanFeatures } from "@/ee/stripe/constants";
import { getPriceIdFromPlan } from "@/ee/stripe/functions/get-price-id-from-plan";
import { PLANS } from "@/ee/stripe/utils";
import { getStripe } from "@/lib/billing/legacy/client";
import { Feature, PlanEnum, getPlanFeatures } from "@/lib/billing/legacy/constants";
import { getPriceIdFromPlan } from "@/lib/billing/legacy/functions/get-price-id-from-plan";
import { PLANS } from "@/lib/billing/legacy/utils";
import {
CheckIcon,
CircleHelpIcon,
+4 -4
View File
@@ -5,10 +5,10 @@ import { useEffect, useMemo, useState } from "react";
import React from "react";
import { useTeam } from "@/context/team-context";
import { getStripe } from "@/ee/stripe/client";
import { Feature, PlanEnum, getPlanFeatures } from "@/ee/stripe/constants";
import { getPriceIdFromPlan } from "@/ee/stripe/functions/get-price-id-from-plan";
import { PLANS } from "@/ee/stripe/utils";
import { getStripe } from "@/lib/billing/legacy/client";
import { Feature, PlanEnum, getPlanFeatures } from "@/lib/billing/legacy/constants";
import { getPriceIdFromPlan } from "@/lib/billing/legacy/functions/get-price-id-from-plan";
import { PLANS } from "@/lib/billing/legacy/utils";
import { CheckIcon, CircleHelpIcon, Users2Icon, XIcon } from "lucide-react";
import { useAnalytics } from "@/lib/analytics";

Some files were not shown because too many files have changed in this diff Show More