Repository navigation
Remove internal working files; fail the build on private-repo source paths - #660
Merged
Merged
Conversation
- Remove docs-content-audit.md and plans/: internal working files, not part of the site, that cite source paths in private repos. - Reword seven comments and DESIGN.md that cited website source paths. - Add scripts/check-private-paths.mjs (npm run paths:private) to the build, so a private-repo path in a tracked file fails the Netlify build. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
EliMoshkovich
requested review from
zeevmoney
and
a balanced review from Copilot
September 30, 2026 16:47
✅ Deploy Preview for permitio-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
zeevmoney
approved these changes
Sep 30, 2026
zeevmoney
left a comment
Member
There was a problem hiding this comment.
Approved — no CRITICAL or HIGH issues found.
Non-blocking:
- MEDIUM
scripts/check-private-paths.mjs:27— pattern misses most citation shapes in the file it was written to catch - MEDIUM
scripts/check-private-paths.mjs:25—PRIVATE_DIRSmisses slash-prefixed paths and publishes internal directory names - LOW
scripts/check-private-paths.mjs:30—.svgskipped although SVGs are text - LOW
scripts/check-private-paths.mjs:42— failure output lacks column and excerpt - LOW
src/css/prism/dark.js:2— "(its prism theme)" leaves "both files" ambiguous - LOW
src/css/tokens.scss:1— reworded line exceeds the 100-column print width
Outside this diff:
- LOW
src/components/diagrams/McpGatewayPathDiagram.jsx:7— the "Adapted from" comment still credits the website by repo and component name. The same rewording as the other three diagram files applies. The check doesn't flag it because no path follows the repo name.
Details are in the inline comments on each line.
… names (PER-16650) Review follow-ups on #660: - GitHub links: a github.com / raw.githubusercontent.com URL under permitio/ must name a repo on a public allowlist, so any private repo is caught without naming it. This found a live link to a private repo in the Auth0 tutorial (a 404 for readers); the example keeps its code, without the link. - Named private repos: any non-path character or ../ or permitio/ before the name, case-insensitive, and a path in code formatting, parentheses, after a colon, or a source file after whitespace. - Repo-less <dir>/src/<file>.<ext> paths, with an allowlist. - Drop PRIVATE_DIRS, scan SVGs, print column and excerpt. - A fixtures file with one bad line per shape (and good lines) that every run self-tests against. - Rewrap tokens.scss, name the counterparts in prism/dark.js, and reword the McpGatewayPathDiagram credit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Author
|
Thanks Zeev. All six inline points are fixed in 5775edc, and each thread has a reply and is resolved. On the outside-the-diff LOW: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This repo is public, but it tracked internal working files that aren't part of the site and cite source paths in private repos.
Removed
docs-content-audit.mdandplans/2026-09-15-docs-site-makeover.md. Neither is linked from the site.STYLE_GUIDE.mdno longer points at the audit.Reworded the source comments (
src/,scripts/audit-a11y.mjs) andDESIGN.md's Mirror Rule, which named website source paths. They now say "the www.permit.io website's …".Removed a link to a private repo from the Auth0 tutorial (
_connecting_to_authentication.mdx). It was a 404 for readers; the example keeps its code.New build gate:
scripts/check-private-paths.mjs(npm run paths:private), run bynpm run buildright afterlinks:relative. It fails the Netlify build when a tracked file (SVGs included) cites private source. Three rules, all case-insensitive:github.comorraw.githubusercontent.comlink underpermitio/must name a repo on a public allowlist. This catches any private repo without naming it.<repo>/…,<repo> `dir/`,<repo> (dir/…),<repo>:dir/…, and<repo> dir/file.py. Site asset paths such as/agent-security/*.pngand Helm namespaces don't match.<dir>/src/<file>.<ext>path outside a URL, with an allowlist.Failures print
file:line:columnand an excerpt. Every run first self-tests the rules againstscripts/check-private-paths.fixtures.txt, which has one known-bad line per shape plus known-good lines.Verified: the check flags 49 lines of the removed audit (the first version flagged 14) and passes on this tree (655 files).
npm run buildis green: 0 bad links, 0 bad anchors, 525/525 baseline routes.docs-design-audit.mdis left in place because it has no private paths.Tracked in PER-16650.
🤖 Generated with Claude Code