Commit Graph
49 Commits
Author SHA1 Message Date
asepharyana 4f0d2da876 feat(export): simplify writeup export to pure human-like markdown layout without cards and exclude _index documents
CI / typecheck + tests (push) Canceled after 0s
CI / build + deploy (Nix) — api (push) Canceled after 0s
CI / build + deploy (Nix) — mcp (push) Canceled after 0s
CI / build + deploy (Nix) — worker (push) Canceled after 0s
CI / build + deploy (web) (push) Canceled after 0s
2026-08-22 13:49:00 +07:00
asepharyana 72b53afe06 feat(export): remove cover header banner and confidential footer line from PDF view 2026-08-22 13:45:57 +07:00
asepharyana 5d85226ff0 feat(export): redesign PDF view for formal publication styling without colors or watermarks
CI / typecheck + tests (push) Canceled after 0s
CI / build + deploy (Nix) — api (push) Canceled after 0s
CI / build + deploy (Nix) — mcp (push) Canceled after 0s
CI / build + deploy (Nix) — worker (push) Canceled after 0s
CI / build + deploy (web) (push) Canceled after 0s
2026-08-22 12:22:01 +07:00
asepharyana 864911af20 feat(export): enhance export routing to support /[section]/export, /[section]/[slug]/export, and dynamic route rendering
CI / typecheck + tests (push) Canceled after 0s
CI / build + deploy (Nix) — api (push) Canceled after 0s
CI / build + deploy (Nix) — mcp (push) Canceled after 0s
CI / build + deploy (Nix) — worker (push) Canceled after 0s
CI / build + deploy (web) (push) Canceled after 0s
2026-08-22 11:55:58 +07:00
asepharyana 5cd9ea92a7 feat(export): add single PDF export for sections and events with chapter ordering
CI / typecheck + tests (push) Canceled after 0s
CI / build + deploy (Nix) — api (push) Canceled after 0s
CI / build + deploy (Nix) — mcp (push) Canceled after 0s
CI / build + deploy (Nix) — worker (push) Canceled after 0s
CI / build + deploy (web) (push) Canceled after 0s
2026-08-22 11:41:49 +07:00
asepharyana d62c5d33a4 feat: enhance Markdown component with syntax highlighting and improve code snippet display
CI / typecheck + build (push) Canceled after 0s
CI / deploy to VPS (push) Canceled after 0s
2026-08-21 15:17:09 +07:00
asepharyana be923cb432 fix: replace all hardcoded hex colors with CSS theme variables
CI / typecheck + build (push) Canceled after 0s
CI / deploy to VPS (push) Canceled after 0s
Phase 15c — theme-consistent color system:

Replaced 63 instances of hardcoded hex colors (#5e6ad2, #7170ff, #4f46e5,
#6a75e0, #828fff, #94a3b8, etc.) with CSS variables from globals.css:
- #5e6ad2 → var(--brand) (light: #5e6ad2, dark: #5e6ad2)
- #7170ff → var(--accent) (light: #4f46e5, dark: #7170ff)
- #4f46e5 → var(--accent)
- #6a75e0 → var(--brand-hover) (new var, light: #6a75e0, dark: #7170ff)
- #828fff → var(--accent-hover)
- #868686 → var(--text-dim)
- Dark-mode-specific hex in Markdown.tsx → CSS variables

Added --brand-hover CSS variable (light: #6a75e0, dark: #7170ff)
Added dark:prose-invert instead of prose-invert (light mode now uses
default prose theme instead of forced dark)

Files changed: 15 component files + globals.css
2026-08-21 13:06:01 +07:00
asepharyana d8da598f1d fix: update MCP smoke test to include 4 new tools (create/delete/list_sections/update)
CI / typecheck + build (push) Canceled after 0s
CI / deploy to VPS (push) Canceled after 0s
Smoke test was silently failing in CI because 'bun --cwd apps/mcp run smoke'
printed usage (exit 0) — never actually ran. Now that we fixed the build step
to use 'cd apps/mcp && bun run smoke', the test runs and reveals 4 tools
were added to the MCP server but not updated in the expected list:
create_document, delete_document, list_sections, update_document.

Updated smoke.ts expected list from 10 → 14 tools.
2026-08-21 11:57:55 +07:00
asepharyana a9b67385c3 feat: revamp to dynamic database-first architecture and cleanup phase docs
CI / typecheck + build (turbo) (push) Canceled after 0s
- Migrate document fetching and CRUD to be PostgreSQL-authoritative
- Remove static section enums and add dynamic listSections query
- Support custom sections and metadata across API, MCP, and Web UI
- Add /api/sections endpoint and update Header, Sidebar, and Forms
- Remove obsolete phase planning docs and modernize README/AGENTS
2026-08-21 11:35:42 +07:00
asepharyana a937e8f51b UI/UX polish: fix doc type capitalization, sidebar tree depth cues, homepage doc-title tree
- Doc page: capitalize doc type (Documentation not documentation)
- Sidebar: tree-style with border-l per depth level, section separators
- Homepage: use doc titles from DB for tree nodes (not path segments)
- CustomFieldBadges: body field excluded from badges (added to STANDARD_KEYS)
- All section config centralized in packages/config/src/sections.ts
2026-08-21 11:33:42 +07:00
asepharyana aedfb022f3 fix(theme): support full dynamic Light Mode and Dark Mode with CSS variables and storage sync 2026-08-21 11:13:05 +07:00
asepharyana 62116be88d feat(ui): overhaul UI/UX with CommandMenu, modern Linear design, interactive TOC, and live preview
CI / typecheck + build (turbo) (push) Canceled after 0s
2026-08-21 11:07:52 +07:00
asepharyana a67a8c6469 feat: complete search REST route, restore disk sync, and extraFields support across API/MCP 2026-08-21 11:03:04 +07:00
asepharyana 989ee9c464 fix: remove body field badge, improve sidebar tree styling, use doc titles in homepage tree
CI / typecheck + build (turbo) (push) Canceled after 0s
- STANDARD_KEYS now includes 'body' to prevent it from rendering as a custom field badge
- Sidebar: tree-style with border-l + ml-2 indentation per level, section separators with border-b, better depth cues
- Homepage buildFolderTree: uses doc.title from DB (not path segments), so _index shows 'CTF Writeups' instead of 'Index'
- Sidebar: _index path segments no longer show leading-space titles (slugToTitle filters empty)
2026-08-21 10:39:01 +07:00
asepharyana 251a6e9b4d refactor: centralize section config — remove all hardcoded section lists
CI / typecheck + build (turbo) (push) Canceled after 0s
- New packages/config/src/sections.ts: SECTIONS, SECTIONS_BY_ID, SECTION_IDS
  (no Node.js built-in imports — safe for client components)
- New package entrypoint: @mcpedia/config/sections (exports only sections.ts)
- Client components import from @mcpedia/config/sections (no node:fs in bundle)
- Server components import from @mcpedia/config (has env/fs, server-only)
- Removed hardcoded SECTIONS/SECTION_LABEL/SECTION_ICON from:
  - [section]/page.tsx (was inline array)
  - [section]/[...slug]/page.tsx (was hardcoded Record maps)
  - Sidebar.tsx (was inline array)
  - layout.tsx (was inline array)
  - page.tsx (was inline array)
  - create/page.tsx (was inline array via SECTIONS import)
- Added @mcpedia/config/sections entrypoint to package.json exports
2026-08-21 10:29:35 +07:00
asepharyana 26a900a030 refactor: Phase 14 UI/UX polish pass
CI / typecheck + build (turbo) (push) Canceled after 0s
- Section index: doc-title-based tree, folder doc counts, active+parent highlighting, recent list with dates, doc counter badge
- Folder index: rich card listing with doc titles (not path slugs), dates, tags, subfolder grid with doc counts, breadcrumb
- Doc page: metadata card (bg-[#0f1011] border), structured header with author/date/tags, badge title tooltips, improved FolderIndex breadcrumb
- Sidebar: recursive hierarchical tree with depth indentation + 16px/level, folder doc counts, section icons, active parent highlighting, alphabetical sort
- DocForm: clean 2-column grid layout, no duplicate slug field, edit-mode loads existing custom fields
- Homepage: inline folder tree per section card
- Header nav: added Writeups/Research/Notes links
- Deleted duplicate apps/web/app/docs/page.tsx (superseded by generic [section]/page.tsx)
- Added CSS vars: --color-border-subtle, --color-border-standard, --color-text-tertiary, --color-text-quaternary
2026-08-21 09:56:40 +07:00
asepharyana b8d4fc97da refactor: Phase 14 consistency pass — remove duplicate, fix breadcrumbs, header nav, DocForm
CI / typecheck + build (turbo) (push) Canceled after 0s
- Delete apps/web/app/docs/page.tsx (superseded by generic [section]/page.tsx)
- Homepage: inline folder tree per section card (📁📄), removed Suspense
- Doc page breadcrumbs: dynamic path from doc.slug (was hardcoded 'Docs')
- Header nav: added Writeups/Research/Notes section links
- DocForm: parent folder dropdown populated from existing folders, slug read-
  only in edit mode, edit mode keeps section disabled, resolved slug shown
- create/page.tsx: use extractFoldersForSection from @mcpedia/core (dedup)
- Removed unused extractFoldersForSection import from page.tsx
2026-08-21 09:02:55 +07:00
asepharyana ab3a2dc456 feat: Phase 14 — hierarchical folder structure (GitHub-style nested folders)
CI / typecheck + build (turbo) (push) Canceled after 0s
- Section index pages ([section]/page.tsx): shows folder tree + flat doc list
- Folder index pages: [section]/[...slug]/page.tsx detects folder paths
  and renders subfolder + document listing instead of 404
- Sidebar tree: hierarchical grouping from flat doc slugs, folder icons (📁)
  with proper indentation per depth level
- DocForm v2: parent folder dropdown (populated from existing folders),
  slug input for leaf name, resolved path display
- Core helpers: extractFoldersForSection + classifyPath exported from @mcpedia/core
- CTF writeup reorganized: pwn-100 ret2win moved into pwn/ subfolder
- _index.md folder intro pages for ctf/ and defcon-quals-2024/
- STANDARD_KEYS includes extraFields to avoid badge duplication
2026-08-21 08:37:41 +07:00
asepharyana ceb53adba4 fix: preserve value types in extraFields (no string coercion)
CI / typecheck + build (turbo) (push) Canceled after 0s
- DocumentMeta.extraFields type -> Record<string, unknown>
- API routes pass extraFields through without JSON.stringify coercion
- CustomFieldBadges auto-styles by value type/content (number->purple, boolean->green/red, etc.)
- DocForm help text: generic (no hardcoded field examples)
2026-08-21 00:45:32 +07:00
asepharyana edbd812c30 feat: fully dynamic custom field badges (auto-style by value, not key name)
CI / typecheck + build (turbo) (push) Canceled after 0s
- CustomFieldBadges now auto-detects styling based on VALUE TYPE+CONTENT
  (number→purple points style, difficulty strings→color-coded, event-like
  strings→purple, categories→orange, status→color-coded)
- DocForm help text made generic (no hardcoded field examples)
- Removed typed CTF fields from DocumentMeta (event/challenge/etc) —
  everything flows through extraFields JSONB for true dynamic behavior
2026-08-21 00:31:36 +07:00
asepharyana c760c3c087 feat(core): dynamic custom frontmatter fields for CTF writeup metadata
CI / typecheck + build (turbo) (push) Canceled after 0s
- Add extra_fields JSONB column to documents table (migration 0003)
- CreateDocInput/UpdateDocInput: extraFields?: Record<string, string>
- parseFile: extracts non-standard frontmatter keys as extraFields
- stringifyFile: writes extraFields dynamically to YAML frontmatter
- toMeta: spreads extraFields from DB row into DocumentMeta
- DocForm: '+ Add field' UI for content creators to add any metadata
- API routes: splitPayload() separates standard vs custom fields
- Doc page: CustomFieldBadges dynamically renders any custom field
- Add db:migrate / db:push scripts + deploy workflow migration step
- Add CTF writeup template (content/writeups/ctf/template/)
- Add sample DEF CON writeup with event/challenge/category/difficulty/points
- Add @tailwindcss/typography for table rendering (prose classes)
- Add remark-gfm for GitHub Flavored Markdown table parsing
2026-08-20 23:18:57 +07:00
asepharyana 8906ed55a0 fix: add remark-gfm plugin to Markdown component for table rendering
CI / typecheck + build (turbo) (push) Canceled after 0s
react-markdown without remark-gfm doesn't parse GitHub Flavored Markdown
tables — the pipe characters were rendered as plain text instead of <table>
HTML. Fix: install remark-gfm@4 and pass it to ReactMarkdown remarkPlugins.
Also add overflow-x-auto wrapper for table responsiveness.
2026-08-20 22:39:16 +07:00
asepharyana 3938aeb38d fix(web-ui): add @tailwindcss/typography plugin to fix table rendering in docs
The Markdown component uses 'prose' classes (prose-lg prose-headings:)
but @tailwindcss/typography was not installed/registered. Tables and other
MD elements rendered unstyled. Fix: install @tailwindcss/typography@latest,
register via @plugin directive in globals.css, add custom dark-theme
table styles, and remove redundant tailwind.config.js.
2026-08-20 22:32:07 +07:00
asepharyana be9211ef21 feat(web-ui): widen main content container for better card grid layout
CI / typecheck + build (turbo) (push) Canceled after 0s
Increase max-width from 3xl to 4xl/5xl/6xl for xl screens to give the
homepage card grid and docs index more breathing room while keeping
the sidebar at 256px.
2026-08-20 21:46:55 +07:00
asepharyana d9e09dceea feat(web-ui): overhaul homepage with hero section, section overview cards, recent docs strip, and MCP info
- Hero: large headline + tagline + dual CTA buttons + search box
- Section overview: 4-column card grid with icons, descriptions, counts
- Recent documents: card grid sorted by updatedAt
- MCP info footer with server endpoint
- Consistent with docs page layout overhaul
2026-08-20 21:42:52 +07:00
asepharyana d35dd8c887 fix: remove duplicate tag display from section cards
CI / typecheck + build (turbo) (push) Canceled after 0s
2026-08-20 21:38:34 +07:00
asepharyana 44b887a9a0 fix(web-ui): remove client-side onKeyDown from server component to fix 500 on /docs
The search input's onKeyDown handler used window.location.href which is
unavailable during SSR, causing the /docs page to crash. Replaced with
a Link wrapper so it's fully server-rendered.
2026-08-20 21:34:42 +07:00
asepharyana a82af10851 fix: remove prose-lg class (typography plugin not installed) causing 500 on doc pages
CI / typecheck + build (turbo) (push) Canceled after 0s
2026-08-20 21:22:43 +07:00
asepharyana 4bbdbb9647 feat(web-ui): overhaul docs index, doc page, and sidebar with card-based layout
CI / typecheck + build (turbo) (push) Canceled after 0s
- Docs index: hero section with search bar, card grid with metadata/tags, recent strip
- Doc page: section badges, card-style related docs, improved revision history
- Sidebar: section icons, active state highlighting, better typography
2026-08-20 21:18:03 +07:00
asepharyana ec0abfbd60 feat(mcp-client): MCP client CLI for interacting with MCPedia server
CI / typecheck + build (turbo) (push) Canceled after 0s
New app: apps/mcp-client/ (bun workspace package)

Interactive REPL (bun run chat):
- Connects to MCP server via Streamable HTTP transport
- Tools: /tools, /resources, /search, /ss (semantic), /hybrid,
  /doc, /related, /create (interactive prompts), /update, /delete,
  /index, /queue_status, /help, /quit
- Sends x-webhook-secret header for write tools

One-shot CLI (bun run ask):
- ask <command> [args] — list tools, search, get doc, create, delete, etc.

API client wrapper (src/client.ts):
- McpediaClient class with typed methods for all 13 MCP tools + 5 resources
- StreamableHTTPClientTransport with custom headers (auth)
- Graceful disconnect

Tests (7, all green, no network/DB):
- listTools, getDocument, createDocument, deleteDocument, listResources,
  readResource, header-passing

Deps: @modelcontextprotocol/sdk ^1.29.0, zod ^4.0.0, github-slugger (for web TOC)
2026-08-20 17:57:58 +07:00
asepharyana 050ca518c0 fix(web): Sidebar as client component (no DB during SSG)
- Sidebar.tsx is now "use client" — fetches /api/docs at runtime instead of
  calling listDocuments() during SSG (CI has no DB, causes ECONNREFUSED)
- GET /api/docs added to route.ts (returns doc list for sidebar)
- Removed SidebarContent.tsx (merged into Sidebar.tsx)
- Fixed isAuthorized double-brace typo
2026-08-20 17:06:16 +07:00
asepharyana 167d95c5e8 feat(web): full layout overhaul — Linear design system
CI / typecheck + build (turbo) (push) Canceled after 0s
Complete UI/UX overhaul, not just style changes:

Layout:
- Dark-mode-first (near-black #08090a canvas, whiteOpacity borders)
- Sticky header with brand + nav + theme toggle
- Sticky sidebar (xl+) with hierarchical doc tree
- Main content in max-w-3xl centered column
- Inter font system (via @font-face + CSS vars)
- Font feature settings cv01/ss03 for Linear-geometric Inter

Components rewritten in Linear aesthetic:
- Homepage: editorial-style doc listing with tags, section headers
- Doc page: breadcrumb-style nav links, metadata bar (author/date/tags),
  clean prose, Related + History sections
- TOC: rehype-slug heading anchors + github-slugger matching
- Create/Edit: inline form with Linear-style inputs/buttons
- Login: centered card-style, brand-indigo CTA button
- Docs index: sectioned listing with tag previews
- Search: dark-themed search with result cards + snippets
- ThemeToggle: system-default + localStorage persistence

Typography:
- prose with custom Tailwind classes matching Linear's:
  headings #f7f8f8 font-light, body #d0d6e0,
  links #7170ff with hover #828fff,
  code blocks #191a1b bg with #23252a border

New deps: rehype-slug (heading anchors), github-slugger (TOC matching)
Files: layout.tsx (overhaul), page.tsx, create/, login/, docs/,
       [section]/[...slug]/page.tsx, Sidebar.tsx, ThemeToggle.tsx,
       TOC.tsx, DocForm.tsx, Markdown.tsx, Search page
2026-08-20 16:57:30 +07:00
asepharyana 8ed8c677e8 fix(web): split PUT/DELETE into /api/docs/[...slug]/route.ts
CI / typecheck + build (turbo) (push) Canceled after 0s
Next.js App Router doesn't match DELETE/PUT on /api/docs/route.ts for
nested paths; need a dynamic segment. POST stays at /api/docs, PUT+DELETE
move to /api/docs/[...slug]. Verified DELETE works locally + via Caddy.
2026-08-20 13:38:26 +07:00
asepharyana 98437cb999 fix(web): /api/docs accepts web cookie OR x-webhook-secret (not both required)
CI / typecheck + build (turbo) (push) Canceled after 0s
Web UI login sets mcpedia_admin cookie; /api/docs/route.ts required the
x-webhook-secret header which the browser form also sends, but the dual-auth
path was brittle. Now accepts either: header (API/MCP style) OR cookie (web
login). Also set ADMIN_PASSWORD on VPS .env and restart web.
2026-08-20 13:30:22 +07:00
asepharyana 1dd16ebcba feat(web): Phase 11 UI/UX — TOC, dark mode toggle, /docs index
- Install rehype-slug (proper heading anchors) + github-slugger (matching TOC)
- TOC component: auto-generated from h2/h3 headings, clickable anchors
- Dark mode toggle: ThemeToggle (localStorage + system default), class-based
- /docs index page (lists all docs by section)
- Markdown.tsx uses rehype-slug for stable heading ids
- globals.css: @custom-variant dark (.dark class) for class-based dark mode
- layout.tsx: nav includes ThemeToggle

Note: per user instruction, installed real deps (rehype-slug, github-slugger,
@types/hast) instead of hacky inline any-cast hacks.
2026-08-20 13:21:53 +07:00
asepharyana b998826b71 chore: remove stale docs/create route (using /create instead)
CI / typecheck + build (turbo) (push) Canceled after 0s
2026-08-20 13:08:35 +07:00
asepharyana 57f90018da feat: Phase 11 — CRUD (create/update/delete) + auth + web UI
- Core: createDocument/updateDocument/deleteDocument (file + DB + revision + chunks)
- Parser: stringifyFile (serialize markdown with frontmatter to disk)
- API: tRPC CRUD routers (auth-gated via requireWriteAuth middleware)
- API: createContext now passes expectedSecret from deps (request-scoped auth)
- MCP: 3 new write tools (create_document, update_document, delete_document)
- Web: /create page + ?edit=1 form, /api/auth/login (cookie-based), /api/docs REST CRUD
- Web: Edit buttons on homepage + doc pages (auth-gated)
- Tests: 8 new tests (5 tRPC CRUD + 3 MCP CRUD auth), 40 total all green
2026-08-20 13:08:27 +07:00
asepharyana 2d974b8952 fix(web): fix doubled section prefix in doc links (404 on click)
CI / typecheck + build (turbo) (push) Canceled after 0s
Home page, search results, and doc page Related links all
generated hrefs as /${section}/${slug} but slug already
includes the section prefix (e.g. 'docs/websocket/contract'),
producing doubled URLs like /docs/docs/websocket/contract → 404.
Fix: href={`/${d.slug}`} everywhere.
2026-08-20 12:33:35 +07:00
asepharyana 76f778c10d chore(testing): Phase 9 — bun:test suite + CI gating with no-DB fakes
CI / typecheck + build (turbo) (push) Canceled after 0s
Added a real test suite (32 tests, 0 external services) using bun:test with
in-process module mocking for @mcpedia/db, @mcpedia/queue, @mcpedia/core.

Enablers:
- apps/api: extracted createApp(deps?) factory + dashboard.ts module from
  index.ts so the HTTP surface is unit-testable (real queue is lazy-imported).
- packages/core: exported shouldCreateRevision pure predicate; restoreRevision
  gained an opts.reindex seam for the chunk-rebuild contract.
- apps/mcp: renamed smoke.test.ts -> smoke.ts (bun test now owns .test.ts),
  updated stale assertions (10 tools, 4 docs in docs section).
- infra: turbo test task (cache:false), test scripts across packages,
  @types/bun + tsconfig base types, CI 'Test' step after Build.

Packages with tests: embeddings(5), parser(5), search(8), core(4),
mcp(6 auth-gates), api(8 contracts).

All green: typecheck(4/4), test(6/6 pkgs), build(web). Live API verified
/health, /metrics, /dashboard, /hooks/* auth gate on temp port.
2026-08-20 11:12:32 +07:00
asepharyana 0cdf261d40 feat(phase8): observability dashboard at /dashboard
CI / typecheck + build (turbo) (push) Canceled after 0s
Zero-dependency HTML page (served by the API, exposed on the domain):
- live /metrics pull (queue gauges + uptime, 5s refresh, live-dot status)
- search box calling MCP hybrid_search directly from the browser (CORS-open /mcp),
  ranked hits linking to the web doc route /docs/<slug>
- XSS-hardened: all KB fields esc()'d before innerHTML
Verified live: /dashboard 200, /metrics 200, MCP hybrid_search returns real hits,
doc links 200, typecheck green.
2026-08-20 10:12:30 +07:00
asepharyana 53d636af0e feat(phase7): grow corpus, MCP write-tools+auth, /metrics observability
CI / typecheck + build (turbo) (push) Canceled after 0s
- content/: +5 real docs (caddy, bullmq, mcp-streamable-http, postgres-fts,
  cloudflare-525 writeup) across docs/writeups/notes. Reindexed: 9 docs, 17
  chunks, 5 revisions (was 4 docs).
- apps/mcp: add write-tools index_document/reindex_all/restore_revision (require
  x-webhook-secret) + queue_status (public). createMcpServer(authSecret?) threads
  the HTTP header; stdio keeps writes open (trusted local).
- apps/api: GET /metrics (Prometheus text: uptime + queue job gauges).
- Caddy: expose /metrics on wiki. domain -> :4020.
Verified live: /metrics 200; MCP tools/list -> 10; index_document unauth -> error,
auth -> enqueues + worker drains; typecheck green.
2026-08-20 10:04:16 +07:00
asepharyana b621923868 feat(mcp): Streamable HTTP transport + deploy; secure restoreRevision
- apps/mcp/src/http.ts: serve MCP over Streamable HTTP (MCP 2025-03-26) on
  :4021, stateless mode (sessionIdGenerator undefined), CORS on /mcp. Remote
  clients can now call the 6 tools + 4 resources without a stdio subprocess.
- deploy/mcpedia-mcp.service: supervised systemd unit (MCP_PORT=4021).
- Caddy: mcp.asepharyana.my.id -> 4021; wiki. domain now also routes /trpc/*
  to the API (was swallowed by web -> tRPC was unreachable on the domain).
- apps/api: restoreRevision tRPC mutation now requires x-webhook-secret (the
  Web UI calls @mcpedia/core directly, so this only gates the open network
  endpoint). Threads the header into tRPC Context. Secures a state-changing
  action that was anonymously callable.
Verified live: https://mcp.asepharyana.my.id/mcp initialize/tools/list/
resources/list all 200; restoreRevision no-secret -> unauthorized, with-secret
-> handler; read-only tRPC reachable via domain.
2026-08-20 09:53:33 +07:00
asepharyana ec0ab4dbb3 fix(deploy): wire Phase 3 services + GitHub git-sync webhook
CI / typecheck + build (turbo) (push) Canceled after 0s
- apps/api: assertWebhookAuth now verifies GitHub X-Hub-Signature-256 HMAC
  (raw-body HMAC-SHA256) AND the manual x-webhook-secret header. GitHub does
  not send a custom header, so only the HMAC path made the push webhook work.
- root package.json: api/worker scripts use absolute bun path + direct-file
  form (bun --cwd apps/api run dev errored in bun 1.3.14).
- deploy/*.service: ExecStart uses /home/code/.bun/bin/bun (systemd PATH lacks bun).
- GitHub push webhook created -> https://wiki.asepharyana.my.id/hooks/reindex
  (verified: ping + push deliveries return 200, worker drains, 0 failed).
- Caddy: expose /hooks/* + /health on wiki.asepharyana.my.id -> :4020.
Services mcpedia-api + mcpedia-worker now enabled + active on host.
2026-08-20 09:38:32 +07:00
asepharyana 8790a4f65a fix(web): render content pages dynamically so next build needs no DB
CI / typecheck + build (turbo) (push) Canceled after 0s
The home, doc, and search pages queried Postgres during SSG/static data
collection, so 'next build' failed in CI (no DB). Mark them
force-dynamic (and drop generateStaticParams from the doc page) so they
render at request time — instant at this corpus scale and build-safe
without a live database.
2026-08-19 22:56:01 +07:00
asepharyana c7697666fe fix(web): remove stray create-next-app layout.tsx (LayoutProps<'/'> removed in Next 16)
The file sat outside app/ so next build ignored it, but turbo typecheck's
tsc compiles all *.tsx and failed on the Next-15-only LayoutProps type.
The real layout is apps/web/app/layout.tsx. Deleting the dead scaffold
lets CI typecheck pass.
2026-08-19 22:46:14 +07:00
asepharyana b92f6f91fa feat(mcpedia): Phase 4 — operability + correctness hardening
Reinterpreted from the plan's YAGNI 'Scale-out' (OpenSearch/object-storage
/multi-tenant deferred at KB scale). Phase 4 = make the Phase 3 async +
revision system correct, secure, observable, deployable.

- T1 (correctness bug): restoreRevision now rebuilds semantic chunks via new
  @mcpedia/core reindexChunks(slug) so semantic/hybrid search stay consistent
  after a restore (previously document_chunks held the NEW body while
  documents.body held the restored OLD body -> stale search).
- T2 (security): /hooks/* git-sync webhooks now require x-webhook-secret header
  matching WEBHOOK_SECRET (401 otherwise); API fails fast at startup if unset.
  Added WEBHOOK_SECRET to @mcpedia/config + .env.example; set real secret in .env.
- T3 (UX): web doc page shows a History panel (revision no/reason/date/length)
  with per-revision Restore; app/api/revisions/restore/route.ts calls
  restoreRevision + revalidatePath (server-component only, no client JS).
- T4: listRevisions gains offset paging; summary never includes body.
- T5 (ops): deploy/mcpedia-api.service + deploy/mcpedia-worker.service systemd
  units (Restart=on-failure, EnvironmentFile=.env). Not auto-enabled on host.

Verified against live imrnes Redis + Postgres: turbo typecheck+build green;
restore-rebuilds-chunks (marker present -> gone after restore); webhook 401/200;
web restore route redirects to doc + reverts body; revisions API returns summary
(no body); systemd-analyze verify passes.
2026-08-19 21:54:54 +07:00
asepharyana 8f2229d447 feat(mcpedia): Phase 3 — async indexing (BullMQ), git-sync webhook, revisions, MCP Resources
- packages/queue: ioredis singleton + BullMQ Queue/Worker (prefix mcpedia:
  on shared imrnes Redis :6379); apps/worker runs startWorker()
- @mcpedia/core: indexContentFile/runFullIndex (single indexing entry point
  shared by script/worker/hook) + revision.service (list/get/restore)
- document_revisions table (migration 0002) — snapshots only on body change
- apps/api: POST /hooks/reindex + /hooks/index webhooks; tRPC revisions,
  getRevision, restoreRevision, jobStatus, queueStatus
- apps/mcp: register MCP Resources mcpedia://docs{/,+slug/chunks/revisions}
  ({+slug} RFC6570 reserved expansion for slugs containing /)
- apps/mcp zod pinned to ^4 to match MCP SDK 1.30 compiled types
  (resolves registerTool TS2589/ShapeOutput skew)
- scripts/enqueue.ts one-shot job enqueue helper; indexer refactored to runFullIndex
- PHASES.md/README/.env.example/docs updated
2026-08-19 20:18:28 +07:00
asepharyana 9397303f01 feat(mcpedia): Phase 2 — semantic + hybrid search, tRPC/Hono API
- @mcpedia/embeddings: OpenRouter provider (9router /v1, encoding_format float),
  chunkText + embedChunks; EMBED_DIM=2048
- document_chunks table (real[] embedding) — pgvector NOT available on shared
  imrnes Postgres, so cosine is computed in-app (KB-scale fine); pgvector deferred
- indexer: chunk + embed + upsert per document
- @mcpedia/search: semanticSearch (cosine) + hybridSearch (FTS+cosine RRF)
- apps/api: Hono + tRPC v11 (6 procedures), serve on :4020
- MCP: semantic_search + hybrid_search tools (6 total)
- web: keyword/hybrid toggle; .env.example + README + PHASES updated
2026-08-19 19:00:29 +07:00
asepharyana ec3a2867d4 feat(mcpedia): Phase 1 MVP — monorepo, Core, Web UI, MCP server, Postgres FTS
- bun workspaces + Turborepo monorepo (apps/web, apps/mcp; packages/*, scripts)
- @mcpedia/core single business-logic layer (Document/Content/Search services)
- @mcpedia/db Drizzle schema: documents + weighted tsvector (GIN) for FTS
- @mcpedia/parser frontmatter, @mcpedia/search Postgres FTS (ts_rank+ts_headline)
- Next.js 16 Web UI (home/doc SSG, search dynamic) + react-markdown render
- MCP server (stdio) with 4 tools + in-memory smoke test
- scripts/indexer walks content/ -> upserts into Postgres
- 4 seed docs; README + PHASES status
2026-08-19 17:40:14 +07:00