Skip to content

Remove internal working files; fail the build on private-repo source paths - #660

Merged
EliMoshkovich merged 2 commits into
masterfrom
eli/per-16650-remove-internal-files
Sep 30, 2026
Merged

EliMoshkovich merged 2 commits into
masterfrom
eli/per-16650-remove-internal-files

Conversation

@EliMoshkovich

@EliMoshkovich EliMoshkovich commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

This repo is public, but it tracked internal working files that aren't part of the site and cite source paths in private repos.

  • Removed docs-content-audit.md and plans/2026-09-15-docs-site-makeover.md. Neither is linked from the site. STYLE_GUIDE.md no longer points at the audit.

  • Reworded the source comments (src/, scripts/audit-a11y.mjs) and DESIGN.md's Mirror Rule, which named website source paths. They now say "the www.permit.io website's …".

  • Removed a link to a private repo from the Auth0 tutorial (_connecting_to_authentication.mdx). It was a 404 for readers; the example keeps its code.

  • New build gate: scripts/check-private-paths.mjs (npm run paths:private), run by npm run build right after links:relative. It fails the Netlify build when a tracked file (SVGs included) cites private source. Three rules, all case-insensitive:

    1. A github.com or raw.githubusercontent.com link under permitio/ must name a repo on a public allowlist. This catches any private repo without naming it.
    2. A listed private repo name followed by a path. That covers <repo>/…, <repo> `dir/`, <repo> (dir/…), <repo>:dir/…, and <repo> dir/file.py. Site asset paths such as /agent-security/*.png and Helm namespaces don't match.
    3. A repo-less <dir>/src/<file>.<ext> path outside a URL, with an allowlist.

    Failures print file:line:column and an excerpt. Every run first self-tests the rules against scripts/check-private-paths.fixtures.txt, which has one known-bad line per shape plus known-good lines.

Verified: the check flags 49 lines of the removed audit (the first version flagged 14) and passes on this tree (655 files). npm run build is green: 0 bad links, 0 bad anchors, 525/525 baseline routes.

docs-design-audit.md is left in place because it has no private paths.

Tracked in PER-16650.

🤖 Generated with Claude Code

- Remove docs-content-audit.md and plans/: internal working files, not part of
  the site, that cite source paths in private repos.
- Reword seven comments and DESIGN.md that cited website source paths.
- Add scripts/check-private-paths.mjs (npm run paths:private) to the build, so
  a private-repo path in a tracked file fails the Netlify build.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@EliMoshkovich
EliMoshkovich requested review from zeevmoney and a balanced review from Copilot September 30, 2026 16:47
@netlify

netlify Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for permitio-docs ready!

Name Link
🔨 Latest commit 5775edc
🔍 Latest deploy log https://app.netlify.com/projects/permitio-docs/deploys/6abd4cbc3c6b820008b45d70
😎 Deploy Preview https://deploy-preview-660--permitio-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@linear-code

linear-code Bot commented Sep 30, 2026

Copy link
Copy Markdown

PER-16650

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@zeevmoney zeevmoney left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved — no CRITICAL or HIGH issues found.

Non-blocking:

  • MEDIUM scripts/check-private-paths.mjs:27 — pattern misses most citation shapes in the file it was written to catch
  • MEDIUM scripts/check-private-paths.mjs:25 — PRIVATE_DIRS misses slash-prefixed paths and publishes internal directory names
  • LOW scripts/check-private-paths.mjs:30 — .svg skipped although SVGs are text
  • LOW scripts/check-private-paths.mjs:42 — failure output lacks column and excerpt
  • LOW src/css/prism/dark.js:2 — "(its prism theme)" leaves "both files" ambiguous
  • LOW src/css/tokens.scss:1 — reworded line exceeds the 100-column print width

Outside this diff:

  • LOW src/components/diagrams/McpGatewayPathDiagram.jsx:7 — the "Adapted from" comment still credits the website by repo and component name. The same rewording as the other three diagram files applies. The check doesn't flag it because no path follows the repo name.

Details are in the inline comments on each line.

Comment thread scripts/check-private-paths.mjs Outdated
Comment thread scripts/check-private-paths.mjs Outdated
Comment thread scripts/check-private-paths.mjs Outdated
Comment thread scripts/check-private-paths.mjs Outdated
Comment thread src/css/prism/dark.js Outdated
Comment thread src/css/tokens.scss Outdated
… names (PER-16650)

Review follow-ups on #660:
- GitHub links: a github.com / raw.githubusercontent.com URL under permitio/ must
  name a repo on a public allowlist, so any private repo is caught without
  naming it. This found a live link to a private repo in the Auth0 tutorial
  (a 404 for readers); the example keeps its code, without the link.
- Named private repos: any non-path character or ../ or permitio/ before the
  name, case-insensitive, and a path in code formatting, parentheses, after a
  colon, or a source file after whitespace.
- Repo-less <dir>/src/<file>.<ext> paths, with an allowlist.
- Drop PRIVATE_DIRS, scan SVGs, print column and excerpt.
- A fixtures file with one bad line per shape (and good lines) that every run
  self-tests against.
- Rewrap tokens.scss, name the counterparts in prism/dark.js, and reword the
  McpGatewayPathDiagram credit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 17:54
@EliMoshkovich

Copy link
Copy Markdown
Contributor Author

Thanks Zeev. All six inline points are fixed in 5775edc, and each thread has a reply and is resolved. On the outside-the-diff LOW: McpGatewayPathDiagram.jsx now credits "the www.permit.io website's defense-in-depth and agentic-identity diagrams", with no repo or component names. npm run build is green: 0 bad links, 0 bad anchors, 525/525 routes.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@EliMoshkovich
EliMoshkovich merged commit 684a3ab into master Sep 30, 2026
4 of 5 checks passed
@EliMoshkovich
EliMoshkovich deleted the eli/per-16650-remove-internal-files branch September 30, 2026 17:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants