Strip emoji from docs, fix XSS/hashing vulnerabilities, remediate all failing CI checks (#1)
* Initial plan * Fix security vulnerabilities: MD5→SHA-256, XSS via dangerouslySetInnerHTML/innerHTML, insecure randomness, CodeQL config Co-authored-by: TLimoges33 <125313326+TLimoges33@users.noreply.github.com> * Clean up README: remove decorative emojis for a professional tone Remove all emojis from section headers, list item prefixes, and decorative positions. Replace ✅ phase status markers with '(Complete)' text. Keep the ⭐ in the final call-to-action line. No changes to links, badges, code blocks, or technical content. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: remove emoji characters from CONTRIBUTING.md Remove all emoji from section headers and closing line while preserving links, code blocks, and technical content. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: remove emoji characters from documentation files Remove all emoji characters from 8 documentation files in docs/. Replace status-marker checkmarks (✅) with '(Done)' text. Remove decorative emojis from headers and body text entirely. Preserve emojis inside code blocks unchanged. Clean up trailing whitespace introduced by removals. Files modified: - DEPLOYMENT_GUIDE.md - IMPLEMENTATION_PLAN.md - MILESTONE_6_SUMMARY.md - PRODUCTION_ROADMAP.md - PROJECT_STATUS.md - REPOSITORY_ENHANCEMENT.md - ROADMAP.md - SECURITY_AUDIT_ROADMAP.md Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: remove emoji characters from documentation files Remove all emoji characters from 9 markdown files while preserving code block content (box-drawing characters, indentation). Emojis removed from headers, list items, and body text across READMEs, issue templates, PR template, runbook, and mobile docs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Remove excessive emoji from all documentation for professional presentation Co-authored-by: TLimoges33 <125313326+TLimoges33@users.noreply.github.com> * Fix PluginWidget initial state and remove || true from security audit steps Co-authored-by: TLimoges33 <125313326+TLimoges33@users.noreply.github.com> * Remediate all failing CI checks: update deprecated actions, fix npm vulnerabilities, fix migrations YAML Co-authored-by: SynOSdev <257853113+SynOSdev@users.noreply.github.com> * Fix all remaining CI failures: Node 18→20, fix test API contract, fix pytest version, fix Postgres health checks Co-authored-by: SynOSdev <257853113+SynOSdev@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: TLimoges33 <125313326+TLimoges33@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: SynOSdev <257853113+SynOSdev@users.noreply.github.com>
This commit is contained in:
+19
-19
@@ -17,20 +17,20 @@ LifeRPG includes an optional telemetry system designed to help improve the appli
|
||||
### Backend Components
|
||||
|
||||
1. **`telemetry.py`** - Core telemetry engine
|
||||
- Consent management
|
||||
- Event recording and sanitization
|
||||
- Pre-defined event helpers
|
||||
- Analytics aggregation
|
||||
- Consent management
|
||||
- Event recording and sanitization
|
||||
- Pre-defined event helpers
|
||||
- Analytics aggregation
|
||||
|
||||
2. **Database Models**
|
||||
- `TelemetryEvent` - Stores anonymous event data
|
||||
- `Profile` - Stores user consent preferences
|
||||
- `TelemetryEvent` - Stores anonymous event data
|
||||
- `Profile` - Stores user consent preferences
|
||||
|
||||
3. **API Endpoints**
|
||||
- `POST /api/v1/telemetry/consent` - Set user consent
|
||||
- `GET /api/v1/telemetry/consent` - Get consent status
|
||||
- `POST /api/v1/telemetry/event` - Record custom events
|
||||
- `GET /api/v1/admin/telemetry/stats` - Admin analytics
|
||||
- `POST /api/v1/telemetry/consent` - Set user consent
|
||||
- `GET /api/v1/telemetry/consent` - Get consent status
|
||||
- `POST /api/v1/telemetry/event` - Record custom events
|
||||
- `GET /api/v1/admin/telemetry/stats` - Admin analytics
|
||||
|
||||
### Frontend Components
|
||||
|
||||
@@ -177,19 +177,19 @@ Administrators can view:
|
||||
### Common Issues
|
||||
|
||||
1. **Telemetry not recording**
|
||||
- Check `TELEMETRY_ENABLED` environment variable
|
||||
- Verify user has given consent
|
||||
- Check database connectivity
|
||||
- Check `TELEMETRY_ENABLED` environment variable
|
||||
- Verify user has given consent
|
||||
- Check database connectivity
|
||||
|
||||
2. **Admin dashboard empty**
|
||||
- Verify admin role permissions
|
||||
- Check if telemetry is globally enabled
|
||||
- Ensure events are being recorded
|
||||
- Verify admin role permissions
|
||||
- Check if telemetry is globally enabled
|
||||
- Ensure events are being recorded
|
||||
|
||||
3. **Consent not saving**
|
||||
- Check authentication token
|
||||
- Verify database write permissions
|
||||
- Check API endpoint configuration
|
||||
- Check authentication token
|
||||
- Verify database write permissions
|
||||
- Check API endpoint configuration
|
||||
|
||||
## Future Enhancements
|
||||
|
||||
|
||||
Reference in New Issue
Block a user