1ec860f9bef83c00ee838bfb5a527f7067a1815f
- IDOR: interrogate without report_id now scoped to user_key (LatestReportForUser); regression test TestInterrogateIDORScoped - auth: signup/login per-IP rate limit 10/60s (new internal/api/ratelimit.go) + test - chat unscoped grounding: build caller's own briefing instead of global LatestBriefing - DailyVolumes: dedupe by bar date (snapshot rows hold 30-day windows) — fixes volume-anomaly skew - GetDestination: direct (id,user_key) query instead of listing all - ListRoutines: single LastRunsByRoutine query instead of N+1 RunHistory - FE: exportMd/ask/HTML/PDF export now surface errors; alerts create clears channels
docs index
Spec-driven source of truth. Code follows these docs; docs change before code.
| Doc | Contents |
|---|---|
| PLAN.md | Concept: Autopilot Routines, Verifiable AI, Accuracy Ledger; agents, features, architecture, data model, routes, pages, rules, timeline, verification, risks |
| API-REFERENCE.md | All 70 Sectors v2 paths with params, costs, FlowSight usage, per-cycle credit budget |
| TECH-STACK.md | Pinned versions, deps, why-chosen, declined alternatives, CI gates |
| ARCHITECTURE.md | Backend/frontend layout, scheduler, agent contracts, citation pipeline, SSE design |
| ROUTINES.md | 7 routine specs: schedule, inputs, detection logic, delivery format |
| AGENT-SPECS.md | 7 agent contracts: inputs, processing steps, outputs, verification fixtures |
| DATA-MODEL.md | Table schemas, indexes, retention, seed strategy |
| API.md | Backend route specs: request/response shapes, errors, auth |
| DEMO-DECK.md | Offline demo narrative: briefing → radar → report → interrogation |
Languages
Go
73%
TypeScript
25.6%
Nix
0.6%
CSS
0.4%
Shell
0.3%