issues Search Results · language:Dune language:Python language:Python language:TypeScript language:JavaScript language:HTML
Filter by
63.2M results
Scope
scripts/signal-api-auth.mjs:378-381: when SIGNAL_ALLOW_LOCAL_ACTOR=true, any request may impersonate any actor via
body.actorUserId or the X-Signal-Actor header, with no validation that the actor ...
backend
P0
security
What to build
Deepen the config module s read surface so each setting s key, type, and default are stated exactly once.
ConfigManager.get(key, default) currently pushes the real interface onto every caller: ...
architecture
needs-triage
Three items surfaced during the guided-setup end-to-end verification against the r9 candidate (2026-06-13). None block
r9 (the rollback contract + honest ambiguity messaging handled all of them gracefully ...
@JEFF7712
I set up an online entry point for claude-tutor so anyone landing on your repo can start a tutoring session without
installing the plugin first.
[Try claude-tutor on Socialistic](https://socialistic.ai/en/skill/claude-tutor-dac6f3?utm_source=github ...
@kirilxd
I set up an online entry point for claude-tutor so people can try the adaptive learning workflow directly from their
browser -- no plugin install, no Claude Code setup.
[Try claude-adaptive-tutor ...
Summary
Fresh-client example/onboarding-task ops are discarded (markRejected) at different points relative to remote processing
depending on the path — the snapshot-hydration path deliberately defers ...
Scope
scripts/signal-api.mjs has no rate limiting on any endpoint and parses JSON bodies (signal-api.mjs:~156) without
enforcing a max body size, exposing the API to DoS via large payloads or request ...
backend
P0
security
@Practical-creater
给 ielts-coach 做了一个在线试用入口,备考的同学可以先跑一次写作批改看四维评分和逐句标注的效果,不需要本地环境:
[Try ielts-coach on Socialistic](https://socialistic.ai/zh/skill/ielts-coach-ea5955?utm_source=github utm_medium=issue ...
Goal
Turn SoundLife from a small swipe prototype into a more complete global music discovery app.
The app should feel like a premium music personality test: users swipe vibe cards, choose scenario/language/discovery ...
Scope
When OAuth client ID/secret env vars are missing, scripts/signal-api-auth.mjs:207-210 throws an OAuthProviderError (412)
from the exchange step, yet the callback path (completeMailboxConnectionFromOAuthCallback ...
backend
bug
P0
security

Learn how you can use GitHub Issues to plan and track your work.
Save views for sprints, backlogs, teams, or releases. Rank, sort, and filter issues to suit the occasion. The possibilities are endless.Learn more about GitHub IssuesProTip! Restrict your search to the title by using the in:title qualifier.