* fix: dashboard menu clickability + expiration date UX
Dashboard actions menu:
- Inactive (expired/removed) rows dimmed via their cells instead of the
row, so `opacity` no longer creates a stacking context that trapped the
actions dropdown beneath later rows and made its items unclickable.
- Add an "Extend 6 months" menu item for expired repos/PRs/gists.
Expiration form (anonymize):
- Fix the "After , the content will be removed." blank date: guard the
helper text and add min/max validation feedback so an invalid pick no
longer nulls the model into a broken sentence.
- Add a `min` (today) so past dates can no longer be selected, and
compute min/max from local date parts (not UTC) to avoid a timezone
off-by-one in the native picker.
- Default expiration is now 6 months (single source of truth, removing a
latent double-offset bug); max stays at 1 year.
- Block submitting a missing/out-of-range expiration date.
Backend:
- New POST /:id/extend endpoint for repos, PRs and gists that pushes the
expiration +6 months and re-anonymizes so expired items come back
online, mirroring the refresh flow. Shared extendExpirationDate helper.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* fix: add frontend translation for invalid_status error code
The new /extend endpoints throw an "invalid_status" AnonymousError, which
the error-code coverage test requires to have a locale entry.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Since the night of 2026-07-16 production keyed the rate limiter on
Cloudflare edge IPs instead of visitor IPs: every visitor routed through
the same edge shared one 175-req/15min bucket, causing widespread 429s
(confirmed by probing: sequential requests alternated 200/429 across
fresh and exhausted buckets).
Root cause: 'trust proxy' used a fixed hop count (TRUST_PROXY=1), which
silently breaks whenever the proxy chain gains or loses an
X-Forwarded-For entry (e.g. a Cloudflare-side change).
- TRUST_PROXY now accepts a comma-separated subnet list; the new default
'loopback,uniquelocal,cloudflare' expands Cloudflare's published IP
ranges so Express skips trusted proxies no matter how many entries
they add. Plain numbers keep the legacy hop-count behavior.
- If resolution still stops at a Cloudflare address (visitor missing
from X-Forwarded-For entirely), the limiter key falls back to
cf-connecting-ip — safe because request.ip can only be a Cloudflare
address when the whole chain to it is trusted.
- CIDR matching uses Node's built-in net.BlockList (no new dependency).
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* fix: anonymize Windows batch scripts (#735)
mime-types maps .bat to application/x-msdownload, the same MIME type as
.exe/.dll, so batch scripts were classified as binary and streamed
through without any anonymization. Special-case .bat/.cmd as text before
the MIME lookup, keeping .exe/.dll binary.
* fix: recover files missing from truncated tree listings (#738)
GitHub truncates tree listings of very large repositories. Folders whose
listing was truncated are recorded in truncatedFolders, but files that
fell outside the listing never reached the database, so requesting them
returned 404 file_not_found even though they exist on GitHub — and a
force refresh could not help.
When a file lookup misses and its directory is under a truncated folder,
fetch the file metadata directly from GitHub's contents API (object
media type, so it works past the 1MB inline limit), cache it in the
database, and serve it normally.
* feat: warn when a repository uses git submodules (#737)
GitHub archives and tree listings never include submodule contents, so
submodules end up as empty folders in the anonymized repository, which
surprises users. Detect a root .gitmodules file and show a warning
banner in the explorer explaining that submodule contents are not
included.
* feat: allow users to delete their account (#741)
Add DELETE /api/user: removes all anonymized repositories, gists, and
pull requests owned by the user, best-effort revokes the GitHub OAuth
grant, and scrubs personal data (username, emails, tokens, GitHub id,
photo) from the user record. The record itself is kept with a
placeholder username so removed repoIds stay reserved and owner
references remain resolvable.
The settings page gains an Account section with a confirmed delete
button.
* fix: add missing error translations for token_expired and job_is_active
The error-code coverage test failed because both backend codes had no
frontend translation.