diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index 48470ed..940d69d 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -1,6 +1,7 @@ name: Auto-merge Dependabot PRs on: + workflow_dispatch: pull_request_target: types: [opened, synchronize, reopened] @@ -20,6 +21,7 @@ jobs: github-token: "${{ secrets.GITHUB_TOKEN }}" - name: Wait for CI checks to pass + id: wait uses: lewagon/wait-on-check-action@v1.3.3 with: ref: ${{ github.event.pull_request.head.sha }} diff --git a/.github/workflows/codacy.yml b/.github/workflows/codacy.yml index c5a54a5..24d1d50 100644 --- a/.github/workflows/codacy.yml +++ b/.github/workflows/codacy.yml @@ -14,6 +14,7 @@ name: Codacy Security Scan on: + workflow_dispatch: push: branches: [ "main" ] pull_request: diff --git a/.github/workflows/deno.yml b/.github/workflows/deno.yml deleted file mode 100644 index 1cdf082..0000000 --- a/.github/workflows/deno.yml +++ /dev/null @@ -1,23 +0,0 @@ - deploy: - on: pull - needs: ci - runs-on: ubuntu-latest - if: github.ref == 'refs/heads/main' - - steps: - - name: Checkout - uses: actions/checkout@v4 - - - name: Setup Deno - uses: denoland/setup-deno@v1 - - - name: Build Site - run: deno task build - - - name: Deploy to GitHub Pages - uses: actions/upload-pages-artifact@v3 - with: - path: dist - - - name: Publish - uses: actions/deploy-pages@v4 diff --git a/.github/workflows/dependabot.yml b/.github/workflows/dependabot.yml deleted file mode 100644 index 71f7606..0000000 --- a/.github/workflows/dependabot.yml +++ /dev/null @@ -1,29 +0,0 @@ -version: 2 -updates: - - package-ecosystem: "npm" - - directory: "/" - schedule: - interval: "daily" - time: "09:00" - - timezone: "America/New_York" - open-pull-requests-limit: 10 - groups: - # Group non‑major updates together to reduce PR noise - minor-and-patch: - applies-to: version-updates - update-types: - - "minor" - - "patch" - patterns: - - "*" - ignore: - # Optionally ignore major updates if you want to review them manually - - dependency-name: "*" - update-types: ["version-update:semver-major"] - labels: - - "dependencies" - - "dependabot" - commit-message: - prefix: "chore(deps)" diff --git a/.github/workflows/docker-image.yml b/.github/workflows/docker-image.yml index 3f53646..1276154 100644 --- a/.github/workflows/docker-image.yml +++ b/.github/workflows/docker-image.yml @@ -1,6 +1,7 @@ name: Docker Image CI on: + workflow_dispatch: push: branches: [ "main" ] pull_request: diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml deleted file mode 100644 index 8b13789..0000000 --- a/.github/workflows/main.yml +++ /dev/null @@ -1 +0,0 @@ - diff --git a/.github/workflows/neuralegion.yml b/.github/workflows/neuralegion.yml deleted file mode 100644 index 5fee27b..0000000 --- a/.github/workflows/neuralegion.yml +++ /dev/null @@ -1,175 +0,0 @@ -# This workflow uses actions that are not certified by GitHub. -# They are provided by a third-party and are governed by -# separate terms of service, privacy policy, and support -# documentation. -# -# Run a Nexploit Scan -# This action runs a new security scan in Nexploit, or reruns an existing one. -# Build Secure Apps & APIs. Fast. -# [NeuraLegion](https://www.neuralegion.com) is a powerful dynamic application & API security testing (DAST) platform that security teams trust and developers love. -# Automatically Tests Every Aspect of Your Apps & APIs -# Scans any target, whether Web Apps, APIs (REST. & SOAP, GraphQL & more), Web sockets or mobile, providing actionable reports -# Seamlessly integrates with the Tools and Workflows You Already Use -# -# NeuraLegion works with your existing CI/CD pipelines – trigger scans on every commit, pull request or build with unit testing. -# Spin-Up, Configure and Control Scans with Code -# One file. One command. One scan. No UI needed. -# -# Super-Fast Scans -# -# Interacts with applications and APIs, instead of just crawling them and guessing. -# Scans are fast as our AI-powered engine can understand application architecture and generate sophisticated and targeted attacks. -# -# No False Positives -# -# Stop chasing ghosts and wasting time. NeuraLegion doesn’t return false positives, so you can focus on releasing code. -# -# Comprehensive Security Testing -# -# NeuraLegion tests for all common vulnerabilities, such as SQL injection, CSRF, XSS, and XXE -- as well as uncommon vulnerabilities, such as business logic vulnerabilities. -# -# More information is available on NeuraLegion’s: -# * [Website](https://www.neuralegion.com/) -# * [Knowledge base](https://docs.neuralegion.com/docs/quickstart) -# * [YouTube channel](https://www.youtube.com/channel/UCoIC0T1pmozq3eKLsUR2uUw) -# * [GitHub Actions](https://github.com/marketplace?query=neuralegion+) -# -# Inputs -# -# `name` -# -# **Required**. Scan name. -# -# _Example:_ `name: GitHub scan ${{ github.sha }}` -# -# `api_token` -# -# **Required**. Your Nexploit API authorization token (key). You can generate it in the **Organization** section on [nexploit.app](https://nexploit.app/login). Find more information [here](https://kb.neuralegion.com/#/guide/np-web-ui/advanced-set-up/managing-org?id=managing-organization-apicli-authentication-tokens). -# -# _Example:_ `api_token: ${{ secrets.NEXPLOIT_TOKEN }}` -# -# `restart_scan` -# -# **Required** when restarting an existing scan by its ID. You can get the scan ID in the Scans section on [nexploit.app](https://nexploit.app/login).
Please make sure to only use the necessary parameters. Otherwise, you will get a response with the parameter usage requirements. -# -# _Example:_ `restart_scan: ai3LG8DmVn9Rn1YeqCNRGQ)` -# -# `discovery_types` -# -# **Required**. Array of discovery types. The following types are available: -# * `archive` - uses an uploaded HAR-file for a scan -# * `crawler` - uses a crawler to define the attack surface for a scan -# * `oas` - uses an uploaded OpenAPI schema for a scan
-# If no discovery type is specified, `crawler` is applied by default. -# -# _Example:_ -# -# ```yml -# discovery_types: | -# [ "crawler", "archive" ] -# ``` -# -# `file_id` -# -# **Required** if the discovery type is set to `archive` or `oas`. ID of a HAR-file or an OpenAPI schema you want to use for a scan. You can get the ID of an uploaded HAR-file or an OpenAPI schema in the **Storage** section on [nexploit.app](https://nexploit.app/login). -# -# _Example:_ -# -# ``` -# FILE_ID=$(nexploit-cli archive:upload \ -# --token ${{ secrets.NEXPLOIT_TOKEN }} \ -# --discard true \ -# ./example.har) -# ``` -# -# `crawler_urls` -# -# **Required** if the discovery type is set to `crawler`. Target URLs to be used by the crawler to define the attack surface. -# -# _Example:_ -# -# ``` -# crawler_urls: | -# [ "http://vulnerable-bank.com" ] -# ``` -# -# `hosts_filter` -# -# **Required** when the the discovery type is set to `archive`. Allows selecting specific hosts for a scan. -# -# Outputs -# -# `url` -# -# Url of the resulting scan -# -# `id` -# -# ID of the created scan. This ID could then be used to restart the scan, or for the following GitHub actions: -# * [Nexploit Wait for Issues](https://github.com/marketplace/actions/nexploit-wait-for-issues) -# * [Nexploit Stop Scan](https://github.com/marketplace/actions/nexploit-stop-scan) -# -# Example usage -# -# Start a new scan with parameters -# -# ```yml -# steps: -# - name: Start Nexploit Scan -# id: start -# uses: NeuraLegion/run-scan@29ebd17b4fd6292ce7a238a59401668953b37fbe -# with: -# api_token: ${{ secrets.NEXPLOIT_TOKEN }} -# name: GitHub scan ${{ github.sha }} -# discovery_types: | -# [ "crawler", "archive" ] -# crawler_urls: | -# [ "http://vulnerable-bank.com" ] -# file_id: LiYknMYSdbSZbqgMaC9Sj -# hosts_filter: | -# [ ] -# - name: Get the output scan url -# run: echo "The scan was started on ${{ steps.start.outputs.url }}" -# ``` -# -# Restart an existing scan -# -# ```yml -# steps: -# - name: Start Nexploit Scan -# id: start -# uses: NeuraLegion/run-scan@29ebd17b4fd6292ce7a238a59401668953b37fbe -# with: -# api_token: ${{ secrets.NEXPLOIT_TOKEN }} -# name: GitHub scan ${{ github.sha }} -# restart_scan: ai3LG8DmVn9Rn1YeqCNRGQ -# - name: Get the output scan url -# run: echo "The scan was started on ${{ steps.start.outputs.url }}" - - -name: "NeuraLegion" - -on: - push: - branches: [ "main" ] - pull_request: - branches: [ "main" ] - schedule: - - cron: '19 11 * * 4' - -jobs: - neuralegion_scan: - runs-on: ubuntu-18.04 - name: A job to run a Nexploit scan - steps: - - uses: actions/checkout@v4 - - name: Start Nexploit Scan 🏁 - id: start - uses: NeuraLegion/run-scan@29ebd17b4fd6292ce7a238a59401668953b37fbe - with: - api_token: ${{ secrets.NEURALEGION_TOKEN }} - name: GitHub scan ${{ github.sha }} - discovery_types: | - [ "crawler" ] - crawler_urls: | - [ "https://brokencrystals.com" ] # ✏️ Update this to the url you wish to scan diff --git a/.github/workflows/nextjs.yml b/.github/workflows/nextjs.yml deleted file mode 100644 index fa8804d..0000000 --- a/.github/workflows/nextjs.yml +++ /dev/null @@ -1,93 +0,0 @@ -# Sample workflow for building and deploying a Next.js site to GitHub Pages -# -# To get started with Next.js see: https://nextjs.org/docs/getting-started -# -name: Deploy Next.js site to Pages - -on: - # Runs on pushes targeting the default branch - push: - branches: ["main"] - - # Allows you to run this workflow manually from the Actions tab - workflow_dispatch: - -# Sets permissions of the GITHUB_TOKEN to allow deployment to GitHub Pages -permissions: - contents: read - pages: write - id-token: write - -# Allow only one concurrent deployment, skipping runs queued between the run in-progress and latest queued. -# However, do NOT cancel in-progress runs as we want to allow these production deployments to complete. -concurrency: - group: "pages" - cancel-in-progress: false - -jobs: - # Build job - build: - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@v4 - - name: Detect package manager - id: detect-package-manager - run: | - if [ -f "${{ github.workspace }}/yarn.lock" ]; then - echo "manager=yarn" >> $GITHUB_OUTPUT - echo "command=install" >> $GITHUB_OUTPUT - echo "runner=yarn" >> $GITHUB_OUTPUT - exit 0 - elif [ -f "${{ github.workspace }}/package.json" ]; then - echo "manager=npm" >> $GITHUB_OUTPUT - echo "command=ci" >> $GITHUB_OUTPUT - echo "runner=npx --no-install" >> $GITHUB_OUTPUT - exit 0 - else - echo "Unable to determine package manager" - exit 1 - fi - - name: Setup Node - uses: actions/setup-node@v4 - with: - node-version: "20" - cache: ${{ steps.detect-package-manager.outputs.manager }} - - name: Setup Pages - uses: actions/configure-pages@v5 - with: - # Automatically inject basePath in your Next.js configuration file and disable - # server side image optimization (https://nextjs.org/docs/api-reference/next/image#unoptimized). - # - # You may remove this line if you want to manage the configuration yourself. - static_site_generator: next - - name: Restore cache - uses: actions/cache@v4 - with: - path: | - .next/cache - # Generate a new cache whenever packages or source files change. - key: ${{ runner.os }}-nextjs-${{ hashFiles('**/package-lock.json', '**/yarn.lock') }}-${{ hashFiles('**.[jt]s', '**.[jt]sx') }} - # If source files changed but packages didn't, rebuild from a prior cache. - restore-keys: | - ${{ runner.os }}-nextjs-${{ hashFiles('**/package-lock.json', '**/yarn.lock') }}- - - name: Install dependencies - run: ${{ steps.detect-package-manager.outputs.manager }} ${{ steps.detect-package-manager.outputs.command }} - - name: Build with Next.js - run: ${{ steps.detect-package-manager.outputs.runner }} next build - - name: Upload artifact - uses: actions/upload-pages-artifact@v5 - with: - path: ./out - - # Deployment job - deploy: - environment: - name: github-pages - url: ${{ steps.deployment.outputs.page_url }} - runs-on: ubuntu-latest - needs: build - steps: - - name: Deploy to GitHub Pages - id: deployment - uses: actions/deploy-pages@v5 diff --git a/.github/workflows/node.js.yml b/.github/workflows/node.js.yml index 2284b93..96ebac9 100644 --- a/.github/workflows/node.js.yml +++ b/.github/workflows/node.js.yml @@ -4,6 +4,7 @@ name: Node.js CI on: + workflow_dispatch: push: branches: [ "main" ] pull_request: diff --git a/README.md b/README.md index 9c766a3..6d0e03a 100644 --- a/README.md +++ b/README.md @@ -531,163 +531,15 @@ PRs welcome! We especially encourage contributions from: 4. Test accessibility (run A11y Check) 5. Submit a pull request -## 📝 License - -Open source. See LICENSE for details. - -## 🤖 Generative AI & Supabase Integration Guide - -### Setting Up Your Supabase Backend - -1. **Create a Supabase Project** - - Visit [supabase.com](https://supabase.com) and create a free account - - Create a new project and note your project URL and anon key - -2. **Install Supabase Client** - ```bash - npm install @supabase/supabase-js - ``` - -3. **Initialize Supabase in Your App** - ```typescript - import { createClient } from '@supabase/supabase-js' - - const supabaseUrl = import.meta.env.VITE_SUPABASE_URL - const supabaseAnonKey = import.meta.env.VITE_SUPABASE_ANON_KEY - - export const supabase = createClient(supabaseUrl, supabaseAnonKey) - ``` - -4. **Add Environment Variables** - Create a `.env` file: - ```env - VITE_SUPABASE_URL=your-project-url - VITE_SUPABASE_ANON_KEY=your-anon-key - VITE_SOCKET_SERVER_URL=http://localhost:4000 - ``` +## 🤖 Generative AI & Supabase Setup -### Key Supabase Features +For detailed instructions on setting up Supabase, configuring authentication, real-time database subscriptions, storage, and integrating Generative AI multi-model routing, please see: -#### Authentication -```typescript -// Sign up -const { data, error } = await supabase.auth.signUp({ - email: 'user@example.com', - password: 'securepassword' -}) +📖 **[Generative AI & Supabase Integration Setup Guide](./docs/llm-deno-supabase-setup.md)** -// Sign in -const { data, error } = await supabase.auth.signInWithPassword({ - email: 'user@example.com', - password: 'securepassword' -}) - -// Get current user -const { data: { user } } = await supabase.auth.getUser() -``` - -#### Database Operations -```typescript -// Insert data -const { data, error } = await supabase - .from('users') - .insert({ name: 'John', email: 'john@example.com' }) - -// Query data -const { data, error } = await supabase - .from('users') - .select('*') - .eq('email', 'john@example.com') - -// Update data -const { data, error } = await supabase - .from('users') - .update({ name: 'Jane' }) - .eq('id', userId) - -// Delete data -const { data, error } = await supabase - .from('users') - .delete() - .eq('id', userId) -``` - -#### Real-time Subscriptions -```typescript -// Subscribe to changes -const channel = supabase - .channel('public:posts') - .on('postgres_changes', - { event: '*', schema: 'public', table: 'posts' }, - (payload) => { - console.log('Change received!', payload) - } - ) - .subscribe() - -// Unsubscribe when done -supabase.removeChannel(channel) -``` - -#### Storage -```typescript -// Upload file -const { data, error } = await supabase.storage - .from('avatars') - .upload('public/avatar.png', file) - -// Get public URL -const { data } = supabase.storage - .from('avatars') - .getPublicUrl('public/avatar.png') -``` +## 📝 License -### Integrating Generative AI - -For complete AI integration patterns with Deno Edge Functions and multiple LLM providers, see our comprehensive guide: - -📖 **[LLM + Deno + Supabase Architecture Guide](./llm-deno-supabase.md)** - -This guide covers: -- Multi-model AI routing (GPT-4, Claude, Gemini) -- Cost optimization strategies -- Edge function deployment -- Real-time AI streaming -- Security and guardrails -- Production-grade patterns - -### Finding and Using APIs - -1. **API Discovery Resources** - - [RapidAPI](https://rapidapi.com) - Marketplace of APIs - - [Postman Public API Network](https://www.postman.com/explore) - API discovery - - [Public APIs](https://github.com/public-apis/public-apis) - Curated list - -2. **Integration Pattern** - ```typescript - // Example: Weather API integration - async function getWeather(city: string) { - const response = await fetch( - `https://api.openweathermap.org/data/2.5/weather?q=${city}&appid=${API_KEY}` - ) - return response.json() - } - ``` - -3. **Best Practices** - - Always store API keys in environment variables - - Use server-side endpoints to protect keys - - Implement rate limiting and caching - - Handle errors gracefully - - Read API documentation thoroughly - -### Building Full-Stack Apps with MBTQ.dev - -1. **Frontend**: Use our React templates or migrate to Next.js -2. **Backend**: Supabase for database, auth, and storage -3. **APIs**: Integrate third-party services as needed -4. **AI Features**: Use Supabase Edge Functions with LLM APIs -5. **Deployment**: Vercel/Netlify for frontend, Supabase handles backend +Open source. See LICENSE for details. ## 🎯 Migration to BUSINESS MAGICIAN diff --git a/client/src/components/MBTQDevGenerator.tsx b/client/src/components/MBTQDevGenerator.tsx index a8d1dfe..4ebc51b 100644 --- a/client/src/components/MBTQDevGenerator.tsx +++ b/client/src/components/MBTQDevGenerator.tsx @@ -1,11 +1,20 @@ import { useState, memo } from 'react'; -import { Code, Database, Rocket, Zap, Shield, Eye } from 'lucide-react'; +import { Code, Database, Rocket, Zap, Shield, Eye, FileText, Layers, GitBranch, Terminal } from 'lucide-react'; interface Config { type: string; auth: string; accessibility: boolean; deploy: string; + theme: string; + snippetPreset: string; +} + +interface MappingNode { + id: string; + name: string; + targetDb: string; + status: string; } interface Magician { @@ -24,15 +33,34 @@ interface Output { const appTypes = ['webapp', 'api', 'fullstack']; const authTypes = ['deafauth', 'oauth', 'custom']; const deployTypes = ['docker', 'railway', 'fly.io', 'cloudflare']; +const textmateThemes = ['dracula', 'monokai', 'nord', 'one-dark']; +const snippetPresets = [ + { label: 'DeafAUTH Middleware', code: '// TextMate Syntax: TypeScript\nexport const authMiddleware = async (req: Request) => {\n const token = req.headers.get("x-deafauth-token");\n return await verifyDeafAuth(token);\n};' }, + { label: 'Fibonrose Validator Flow', code: '// TextMate Syntax: TypeScript\nexport const validateTask = (checkpoint: number, evidence: string) => {\n return fibonrose.confirm({ checkpoint, evidence });\n};' }, + { label: 'Supabase Realtime Sync', code: '// TextMate Syntax: TypeScript\nconst channel = supabase.channel("pinksync")\n .on("postgres_changes", { event: "*", schema: "public" }, handleSync)\n .subscribe();' }, + { label: 'oRPC Zod & Edge KV Scaffold', code: '// TextMate Syntax: TypeScript (oRPC + Zod + Deno KV)\nimport { z } from "zod";\nimport { os } from "@orpc/server";\n\nconst InputSchema = z.object({\n key: z.string(),\n payload: z.record(z.unknown())\n});\n\nexport const edgeKvHandler = os\n .input(InputSchema)\n .handler(async ({ input }) => {\n const kv = await Deno.openKv();\n await kv.set(["mbtq", input.key], input.payload);\n const res = await kv.get(["mbtq", input.key]);\n return { status: "ok", data: res.value };\n });' }, + { label: 'Gluon oRPC Quantum ServiceAccount', code: '// TextMate Syntax: TypeScript (Gluon oRPC + Zero-Cost Cache)\nimport { z } from "zod";\nimport { os } from "@orpc/server";\n\nconst QuantumSchema = z.object({\n taskId: z.string(),\n bizContext: z.string().default("mbtq-platform"),\n headers: z.object({\n projectId: z.string(),\n serviceAccount: z.string()\n })\n});\n\nexport const gluonQuantumHandler = os\n .input(QuantumSchema)\n .handler(async ({ input }) => {\n const cache = new Map(); // Zero-cost local memory cache\n if (cache.has(input.taskId)) return cache.get(input.taskId);\n const res = { status: "dispatched", task: input.taskId, biz: input.bizContext };\n cache.set(input.taskId, res);\n return res;\n });' } +]; const MBTQDevGenerator = () => { const [prompt, setPrompt] = useState(''); + const [activeTab, setActiveTab] = useState<'generator' | 'mapping'>('generator'); const [config, setConfig] = useState({ type: 'fullstack', auth: 'deafauth', accessibility: true, - deploy: 'docker' + deploy: 'docker', + theme: 'dracula', + snippetPreset: 'DeafAUTH Middleware' }); + const [customSnippet, setCustomSnippet] = useState( + snippetPresets[0].code + ); + const [mappingNodes, setMappingNodes] = useState([ + { id: '1', name: 'User Identity Flow', targetDb: 'supabase_auth.users', status: 'mapped' }, + { id: '2', name: 'Fibonrose Validation Log', targetDb: 'dev_db.fibonrose_events', status: 'mapped' }, + { id: '3', name: 'PinkSync Realtime Buffer', targetDb: 'dev_db.pinksync_states', status: 'active' } + ]); const [generating, setGenerating] = useState(false); const [output, setOutput] = useState(null); @@ -74,17 +102,46 @@ const MBTQDevGenerator = () => {
{/* Header */} -
-
- -

- MBTQ.dev -

+
+
+
+ +

+ MBTQ.dev +

+
+

AI-Powered Full Stack Generator • Flow & DB Interface Builder

+
+ + {/* Navigation Tabs */} +
+ +
-

AI-Powered Full Stack Generator • Deaf-First • LGBTQ+ Safe

- {/* Main Generator */} + {activeTab === 'generator' ? ( + /* Main Generator */
{/* Input Section */} @@ -153,6 +210,52 @@ const MBTQDevGenerator = () => {
+ {/* TextMate Theme Selection */} +
+ +
+ {textmateThemes.map(theme => ( + + ))} +
+
+ + {/* Code Snippet Preset */} +
+ +
+ {snippetPresets.map(preset => ( + + ))} +
+
+ {/* Auth */}
@@ -270,18 +373,57 @@ const MBTQDevGenerator = () => {
) : output ? ( <> - {/* Repo Info */} + {/* Repo Info & TextMate Syntax Highlight Preview */}
-
- -

Generated Repository

+
+
+ +

Generated Repository

+
+ + TextMate: {config.theme} +
-
+
✓ {output.repo}
{output.structure.map((line, i) => (
{line}
))}
+ + {/* Rendered Interactive TextMate Editor */} +
+
+ + + TextMate Code Editor ({config.snippetPreset}) + + + Grammar: source.ts · {config.theme} + +
+
+
+
+ {customSnippet.split('\n').map((_, i) => ( +
{i + 1}
+ ))} +
+