sync: stale skill detection, sentry filtering, claim removal, review improvements
Stale Detection: - Detect skills removed/moved from GitHub (3 consecutive 404s threshold) - Hide stale skills from browse/search, show warning banner on detail page - Serve cached files with isStale flag when GitHub returns 404 - Add stale-check crawler command for batch verification - CLI shows warning when installing stale skills from cache Sentry & Error Handling: - Filter browser extension errors and add denyUrls - Anti-inflation measures and sentinel recalibration for curation Claim & Removal: - Enhanced ClaimForm with repo-level removal support - Add repo-removal-request API endpoint with tests - Improved owner page with bilingual content Review Pipeline: - Review version and reviewer tracking in submit API - Source format filter for pending reviews - Updated review tests Other: - Updated i18n strings (en/fa) - BrowseFilters improvements - Dockerfile updates Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
229
apps/web/app/api/skills/add-request/route.test.ts
Normal file
229
apps/web/app/api/skills/add-request/route.test.ts
Normal file
@@ -0,0 +1,229 @@
|
||||
import { describe, it, expect, vi, beforeEach } from 'vitest';
|
||||
import { NextRequest } from 'next/server';
|
||||
|
||||
// Mock auth
|
||||
const mockAuth = vi.fn();
|
||||
vi.mock('@/lib/auth', () => ({
|
||||
auth: () => mockAuth(),
|
||||
}));
|
||||
|
||||
// Mock sanitize
|
||||
vi.mock('@/lib/sanitize', () => ({
|
||||
sanitizeReason: (r: string) => r,
|
||||
}));
|
||||
|
||||
// Mock email
|
||||
vi.mock('@/lib/email', () => ({
|
||||
sendClaimSubmittedEmail: vi.fn().mockResolvedValue(undefined),
|
||||
}));
|
||||
|
||||
// Mock db
|
||||
vi.mock('@skillhub/db', () => ({
|
||||
createDb: vi.fn(() => ({})),
|
||||
userQueries: {
|
||||
getByGithubId: vi.fn(),
|
||||
upsertFromGithub: vi.fn(),
|
||||
},
|
||||
skillQueries: {
|
||||
unblockByRepo: vi.fn(),
|
||||
},
|
||||
addRequestQueries: {
|
||||
hasPendingRequest: vi.fn(),
|
||||
create: vi.fn(),
|
||||
updateStatus: vi.fn(),
|
||||
},
|
||||
discoveredRepoQueries: {
|
||||
getById: vi.fn(),
|
||||
upsert: vi.fn(),
|
||||
unblockRepo: vi.fn(),
|
||||
},
|
||||
}));
|
||||
|
||||
import { POST, GET } from './route';
|
||||
import { userQueries, skillQueries, addRequestQueries, discoveredRepoQueries } from '@skillhub/db';
|
||||
|
||||
function createMockUser(overrides: Partial<{ id: string; githubId: string; email: string }> = {}) {
|
||||
return {
|
||||
id: 'user-123',
|
||||
githubId: 'gh-12345',
|
||||
username: 'testuser',
|
||||
email: 'test@example.com',
|
||||
preferredLocale: 'en',
|
||||
...overrides,
|
||||
};
|
||||
}
|
||||
|
||||
function createRequest(body: unknown) {
|
||||
return new NextRequest('http://localhost:3000/api/skills/add-request', {
|
||||
method: 'POST',
|
||||
body: JSON.stringify(body),
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
});
|
||||
}
|
||||
|
||||
describe('/api/skills/add-request', () => {
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
// Disable real fetch by default
|
||||
vi.stubGlobal('fetch', vi.fn());
|
||||
});
|
||||
|
||||
describe('GET', () => {
|
||||
it('should return 401 when not authenticated', async () => {
|
||||
mockAuth.mockResolvedValue(null);
|
||||
|
||||
const response = await GET();
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(401);
|
||||
expect(data.error).toBeDefined();
|
||||
});
|
||||
|
||||
it('should return empty requests for unknown user', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345' } });
|
||||
vi.mocked(userQueries.getByGithubId).mockResolvedValue(null as any);
|
||||
|
||||
const response = await GET();
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(data.requests).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe('POST', () => {
|
||||
it('should return 401 when not authenticated', async () => {
|
||||
mockAuth.mockResolvedValue(null);
|
||||
|
||||
const response = await POST(createRequest({ repositoryUrl: 'https://github.com/owner/repo' }));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(401);
|
||||
expect(data.code).toBe('AUTH_REQUIRED');
|
||||
});
|
||||
|
||||
it('should return 400 for missing repositoryUrl', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345', username: 'testuser' } });
|
||||
|
||||
const response = await POST(createRequest({}));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(400);
|
||||
expect(data.code).toBe('INVALID_INPUT');
|
||||
});
|
||||
|
||||
it('should return 400 for invalid GitHub URL', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345', username: 'testuser' } });
|
||||
const mockUser = createMockUser();
|
||||
vi.mocked(userQueries.getByGithubId).mockResolvedValue(mockUser as any);
|
||||
|
||||
// gitlab.com does not contain the substring 'github.com'
|
||||
const response = await POST(createRequest({ repositoryUrl: 'https://gitlab.com/owner/repo' }));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(400);
|
||||
expect(data.code).toBe('INVALID_URL');
|
||||
});
|
||||
|
||||
it('should return 403 REPO_BLOCKED_BY_OWNER when non-owner tries to add blocked repo', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345', username: 'non-owner' } });
|
||||
const mockUser = createMockUser({ githubId: 'gh-12345' });
|
||||
vi.mocked(userQueries.getByGithubId).mockResolvedValue(mockUser as any);
|
||||
vi.mocked(discoveredRepoQueries.getById).mockResolvedValue({
|
||||
id: 'rawveg/skillsforge-marketplace',
|
||||
isBlocked: true,
|
||||
} as any);
|
||||
// GitHub API says the owner is 'rawveg', not 'non-owner'
|
||||
vi.stubGlobal('fetch', vi.fn().mockResolvedValue({
|
||||
ok: true,
|
||||
json: async () => ({ owner: { login: 'rawveg' }, default_branch: 'main', private: false }),
|
||||
} as any));
|
||||
|
||||
const response = await POST(createRequest({ repositoryUrl: 'https://github.com/rawveg/skillsforge-marketplace' }));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(403);
|
||||
expect(data.code).toBe('REPO_BLOCKED_BY_OWNER');
|
||||
});
|
||||
|
||||
it('should re-enable repo when owner re-adds their blocked repo', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345', username: 'rawveg' } });
|
||||
const mockUser = createMockUser({ githubId: 'gh-12345' });
|
||||
vi.mocked(userQueries.getByGithubId).mockResolvedValue(mockUser as any);
|
||||
vi.mocked(discoveredRepoQueries.getById).mockResolvedValue({
|
||||
id: 'rawveg/skillsforge-marketplace',
|
||||
isBlocked: true,
|
||||
} as any);
|
||||
vi.mocked(skillQueries.unblockByRepo).mockResolvedValue(undefined);
|
||||
vi.mocked(discoveredRepoQueries.unblockRepo).mockResolvedValue(undefined);
|
||||
vi.mocked(addRequestQueries.hasPendingRequest).mockResolvedValue(false as any);
|
||||
vi.mocked(addRequestQueries.create).mockResolvedValue('req-123' as any);
|
||||
vi.mocked(addRequestQueries.updateStatus).mockResolvedValue(undefined);
|
||||
vi.mocked(discoveredRepoQueries.upsert).mockResolvedValue(undefined as any);
|
||||
|
||||
// First fetch: ownership check (inside blocked-repo logic)
|
||||
// Second fetch: repo validation (validateGitHubRepo → repoResponse)
|
||||
// Third fetch: tree scan (findSkillMdFiles)
|
||||
vi.stubGlobal('fetch', vi.fn()
|
||||
.mockResolvedValueOnce({
|
||||
ok: true,
|
||||
json: async () => ({ owner: { login: 'rawveg' }, default_branch: 'main', private: false }),
|
||||
} as any)
|
||||
.mockResolvedValueOnce({
|
||||
ok: true,
|
||||
json: async () => ({ owner: { login: 'rawveg' }, default_branch: 'main', private: false }),
|
||||
} as any)
|
||||
.mockResolvedValueOnce({
|
||||
ok: true,
|
||||
json: async () => ({
|
||||
tree: [
|
||||
{ path: 'SKILL.md', type: 'blob' },
|
||||
],
|
||||
truncated: false,
|
||||
}),
|
||||
} as any)
|
||||
);
|
||||
|
||||
const response = await POST(createRequest({ repositoryUrl: 'https://github.com/rawveg/skillsforge-marketplace' }));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(data.success).toBe(true);
|
||||
expect(data.reEnabled).toBe(true);
|
||||
expect(skillQueries.unblockByRepo).toHaveBeenCalledWith(expect.anything(), 'rawveg', 'skillsforge-marketplace');
|
||||
expect(discoveredRepoQueries.unblockRepo).toHaveBeenCalledWith(expect.anything(), 'rawveg/skillsforge-marketplace');
|
||||
});
|
||||
|
||||
it('should proceed normally when repo is not blocked (Case C)', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345', username: 'newuser' } });
|
||||
const mockUser = createMockUser();
|
||||
vi.mocked(userQueries.getByGithubId).mockResolvedValue(mockUser as any);
|
||||
vi.mocked(discoveredRepoQueries.getById).mockResolvedValue(null as any);
|
||||
vi.mocked(addRequestQueries.hasPendingRequest).mockResolvedValue(false as any);
|
||||
vi.mocked(addRequestQueries.create).mockResolvedValue('req-456' as any);
|
||||
vi.mocked(addRequestQueries.updateStatus).mockResolvedValue(undefined);
|
||||
vi.mocked(discoveredRepoQueries.upsert).mockResolvedValue(undefined as any);
|
||||
|
||||
vi.stubGlobal('fetch', vi.fn()
|
||||
.mockResolvedValueOnce({
|
||||
ok: true,
|
||||
json: async () => ({ owner: { login: 'someowner' }, default_branch: 'main', private: false }),
|
||||
} as any)
|
||||
.mockResolvedValueOnce({
|
||||
ok: true,
|
||||
json: async () => ({
|
||||
tree: [{ path: 'SKILL.md', type: 'blob' }],
|
||||
truncated: false,
|
||||
}),
|
||||
} as any)
|
||||
);
|
||||
|
||||
const response = await POST(createRequest({ repositoryUrl: 'https://github.com/someowner/newrepo' }));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(data.success).toBe(true);
|
||||
expect(data.reEnabled).toBeUndefined();
|
||||
});
|
||||
});
|
||||
});
|
||||
@@ -1,7 +1,7 @@
|
||||
import type { NextRequest } from 'next/server';
|
||||
import { NextResponse } from 'next/server';
|
||||
import { auth } from '@/lib/auth';
|
||||
import { createDb, addRequestQueries, discoveredRepoQueries, userQueries } from '@skillhub/db';
|
||||
import { createDb, addRequestQueries, discoveredRepoQueries, skillQueries, userQueries } from '@skillhub/db';
|
||||
import { sanitizeReason } from '@/lib/sanitize';
|
||||
import { sendClaimSubmittedEmail } from '@/lib/email';
|
||||
|
||||
@@ -337,6 +337,52 @@ export async function POST(request: NextRequest) {
|
||||
);
|
||||
}
|
||||
|
||||
// Check if repo was previously blocked by its owner
|
||||
let reEnabled = false;
|
||||
const existingRepo = await discoveredRepoQueries.getById(db, `${parsed.owner}/${parsed.repo}`);
|
||||
if (existingRepo?.isBlocked) {
|
||||
// Verify whether the current requester is the repo owner
|
||||
let requesterIsOwner = false;
|
||||
try {
|
||||
const ownerCheckRes = await fetch(
|
||||
`https://api.github.com/repos/${parsed.owner}/${parsed.repo}`,
|
||||
{
|
||||
headers: {
|
||||
Accept: 'application/vnd.github.v3+json',
|
||||
'User-Agent': 'SkillHub',
|
||||
...(process.env.GITHUB_TOKEN && {
|
||||
Authorization: `Bearer ${process.env.GITHUB_TOKEN}`,
|
||||
}),
|
||||
},
|
||||
signal: AbortSignal.timeout(10000),
|
||||
}
|
||||
);
|
||||
if (ownerCheckRes.ok) {
|
||||
const repoData = await ownerCheckRes.json() as { owner?: { login?: string } };
|
||||
requesterIsOwner =
|
||||
repoData.owner?.login?.toLowerCase() === session.user.username.toLowerCase();
|
||||
}
|
||||
} catch {
|
||||
// If we can't reach GitHub, treat as non-owner (safe default)
|
||||
}
|
||||
|
||||
if (!requesterIsOwner) {
|
||||
// Case B: repo blocked by its owner, non-owner trying to re-add
|
||||
return NextResponse.json(
|
||||
{
|
||||
error: 'This repository was removed by its owner and cannot be re-added.',
|
||||
code: 'REPO_BLOCKED_BY_OWNER',
|
||||
},
|
||||
{ status: 403 }
|
||||
);
|
||||
}
|
||||
|
||||
// Case A: owner is re-enabling their previously blocked repo
|
||||
await skillQueries.unblockByRepo(db, parsed.owner, parsed.repo);
|
||||
await discoveredRepoQueries.unblockRepo(db, `${parsed.owner}/${parsed.repo}`);
|
||||
reEnabled = true;
|
||||
}
|
||||
|
||||
// Check if user already has a pending request for this repository + path combination
|
||||
const hasPending = await addRequestQueries.hasPendingRequest(
|
||||
db,
|
||||
@@ -438,6 +484,7 @@ export async function POST(request: NextRequest) {
|
||||
skillCount: validation.skillPaths.length,
|
||||
skillPaths: validation.skillPaths,
|
||||
message,
|
||||
...(reEnabled && { reEnabled: true }),
|
||||
});
|
||||
} catch (error) {
|
||||
console.error('Error creating add request:', error);
|
||||
|
||||
163
apps/web/app/api/skills/repo-removal-request/route.test.ts
Normal file
163
apps/web/app/api/skills/repo-removal-request/route.test.ts
Normal file
@@ -0,0 +1,163 @@
|
||||
import { describe, it, expect, vi, beforeEach } from 'vitest';
|
||||
import { NextRequest } from 'next/server';
|
||||
|
||||
// Mock auth
|
||||
const mockAuth = vi.fn();
|
||||
vi.mock('@/lib/auth', () => ({
|
||||
auth: () => mockAuth(),
|
||||
}));
|
||||
|
||||
// Mock sanitize
|
||||
vi.mock('@/lib/sanitize', () => ({
|
||||
sanitizeReason: (r: string) => r,
|
||||
}));
|
||||
|
||||
// Mock db
|
||||
vi.mock('@skillhub/db', () => ({
|
||||
createDb: vi.fn(() => ({})),
|
||||
userQueries: {
|
||||
getByGithubId: vi.fn(),
|
||||
upsertFromGithub: vi.fn(),
|
||||
},
|
||||
skillQueries: {
|
||||
countByRepo: vi.fn(),
|
||||
blockByRepo: vi.fn(),
|
||||
},
|
||||
discoveredRepoQueries: {
|
||||
blockRepo: vi.fn(),
|
||||
},
|
||||
}));
|
||||
|
||||
import { POST } from './route';
|
||||
import { userQueries, skillQueries, discoveredRepoQueries } from '@skillhub/db';
|
||||
|
||||
function createMockUser(overrides: Partial<{ id: string; githubId: string }> = {}) {
|
||||
return {
|
||||
id: 'user-123',
|
||||
githubId: 'gh-12345',
|
||||
username: 'rawveg',
|
||||
...overrides,
|
||||
};
|
||||
}
|
||||
|
||||
function createRequest(body: unknown) {
|
||||
return new NextRequest('http://localhost:3000/api/skills/repo-removal-request', {
|
||||
method: 'POST',
|
||||
body: JSON.stringify(body),
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
});
|
||||
}
|
||||
|
||||
describe('/api/skills/repo-removal-request', () => {
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
vi.stubGlobal('fetch', vi.fn());
|
||||
});
|
||||
|
||||
describe('POST', () => {
|
||||
it('should return 401 when not authenticated', async () => {
|
||||
mockAuth.mockResolvedValue(null);
|
||||
|
||||
const response = await POST(createRequest({ repoUrl: 'rawveg/skillsforge-marketplace' }));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(401);
|
||||
expect(data.code).toBe('AUTH_REQUIRED');
|
||||
});
|
||||
|
||||
it('should return 400 for missing repoUrl', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345', username: 'rawveg' } });
|
||||
|
||||
const response = await POST(createRequest({}));
|
||||
|
||||
expect(response.status).toBe(400);
|
||||
});
|
||||
|
||||
it('should return 400 PARSE_ERROR for invalid repo format', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345', username: 'rawveg' } });
|
||||
const mockUser = createMockUser();
|
||||
vi.mocked(userQueries.getByGithubId).mockResolvedValue(mockUser as any);
|
||||
|
||||
const response = await POST(createRequest({ repoUrl: 'not-a-valid-format' }));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(400);
|
||||
expect(data.code).toBe('PARSE_ERROR');
|
||||
});
|
||||
|
||||
it('should return 404 INVALID_REPO when repo not found on GitHub', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345', username: 'rawveg' } });
|
||||
const mockUser = createMockUser();
|
||||
vi.mocked(userQueries.getByGithubId).mockResolvedValue(mockUser as any);
|
||||
vi.stubGlobal('fetch', vi.fn().mockResolvedValue({
|
||||
ok: false,
|
||||
status: 404,
|
||||
} as any));
|
||||
|
||||
const response = await POST(createRequest({ repoUrl: 'rawveg/skillsforge-marketplace' }));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(404);
|
||||
expect(data.code).toBe('INVALID_REPO');
|
||||
});
|
||||
|
||||
it('should return 403 NOT_OWNER when requester is not repo owner', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345', username: 'other-user' } });
|
||||
const mockUser = createMockUser({ githubId: 'gh-12345' });
|
||||
vi.mocked(userQueries.getByGithubId).mockResolvedValue(mockUser as any);
|
||||
vi.stubGlobal('fetch', vi.fn().mockResolvedValue({
|
||||
ok: true,
|
||||
json: async () => ({ owner: { login: 'rawveg' } }),
|
||||
} as any));
|
||||
|
||||
const response = await POST(createRequest({ repoUrl: 'rawveg/skillsforge-marketplace' }));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(403);
|
||||
expect(data.code).toBe('NOT_OWNER');
|
||||
});
|
||||
|
||||
it('should block all skills and return success when owner removes repo', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345', username: 'rawveg' } });
|
||||
const mockUser = createMockUser();
|
||||
vi.mocked(userQueries.getByGithubId).mockResolvedValue(mockUser as any);
|
||||
vi.mocked(skillQueries.countByRepo).mockResolvedValue(16 as any);
|
||||
vi.mocked(skillQueries.blockByRepo).mockResolvedValue(undefined);
|
||||
vi.mocked(discoveredRepoQueries.blockRepo).mockResolvedValue(undefined);
|
||||
vi.stubGlobal('fetch', vi.fn().mockResolvedValue({
|
||||
ok: true,
|
||||
json: async () => ({ owner: { login: 'rawveg' } }),
|
||||
} as any));
|
||||
|
||||
const response = await POST(createRequest({ repoUrl: 'rawveg/skillsforge-marketplace', reason: 'I want my skills removed' }));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(data.success).toBe(true);
|
||||
expect(data.blockedCount).toBe(16);
|
||||
expect(data.repo).toBe('rawveg/skillsforge-marketplace');
|
||||
expect(skillQueries.blockByRepo).toHaveBeenCalledWith(expect.anything(), 'rawveg', 'skillsforge-marketplace');
|
||||
expect(discoveredRepoQueries.blockRepo).toHaveBeenCalledWith(expect.anything(), 'rawveg/skillsforge-marketplace');
|
||||
});
|
||||
|
||||
it('should accept full GitHub URL format', async () => {
|
||||
mockAuth.mockResolvedValue({ user: { githubId: 'gh-12345', username: 'rawveg' } });
|
||||
const mockUser = createMockUser();
|
||||
vi.mocked(userQueries.getByGithubId).mockResolvedValue(mockUser as any);
|
||||
vi.mocked(skillQueries.countByRepo).mockResolvedValue(0 as any);
|
||||
vi.mocked(skillQueries.blockByRepo).mockResolvedValue(undefined);
|
||||
vi.mocked(discoveredRepoQueries.blockRepo).mockResolvedValue(undefined);
|
||||
vi.stubGlobal('fetch', vi.fn().mockResolvedValue({
|
||||
ok: true,
|
||||
json: async () => ({ owner: { login: 'rawveg' } }),
|
||||
} as any));
|
||||
|
||||
const response = await POST(createRequest({ repoUrl: 'https://github.com/rawveg/skillsforge-marketplace' }));
|
||||
const data = await response.json();
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(data.success).toBe(true);
|
||||
expect(data.repo).toBe('rawveg/skillsforge-marketplace');
|
||||
});
|
||||
});
|
||||
});
|
||||
158
apps/web/app/api/skills/repo-removal-request/route.ts
Normal file
158
apps/web/app/api/skills/repo-removal-request/route.ts
Normal file
@@ -0,0 +1,158 @@
|
||||
import type { NextRequest } from 'next/server';
|
||||
import { NextResponse } from 'next/server';
|
||||
import { auth } from '@/lib/auth';
|
||||
import { createDb, skillQueries, discoveredRepoQueries, userQueries } from '@skillhub/db';
|
||||
import { sanitizeReason } from '@/lib/sanitize';
|
||||
|
||||
export const dynamic = 'force-dynamic';
|
||||
|
||||
const db = createDb();
|
||||
|
||||
function parseOwnerRepo(input: string): { owner: string; repo: string } | null {
|
||||
try {
|
||||
if (input.startsWith('https://') || input.startsWith('http://')) {
|
||||
const url = new URL(input);
|
||||
if (!url.hostname.includes('github.com')) return null;
|
||||
const parts = url.pathname.split('/').filter(Boolean);
|
||||
if (parts.length < 2) return null;
|
||||
return { owner: parts[0], repo: parts[1] };
|
||||
}
|
||||
const parts = input.split('/').filter(Boolean);
|
||||
if (parts.length < 2) return null;
|
||||
return { owner: parts[0], repo: parts[1] };
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* POST /api/skills/repo-removal-request
|
||||
* Block all skills from a GitHub repository at once.
|
||||
* Verifies the authenticated user owns the repo, then blocks all skills and
|
||||
* prevents the repo from being re-indexed.
|
||||
*/
|
||||
export async function POST(request: NextRequest) {
|
||||
try {
|
||||
const session = await auth();
|
||||
|
||||
if (!session?.user?.githubId || !session.user.username) {
|
||||
return NextResponse.json(
|
||||
{ error: 'Authentication required', code: 'AUTH_REQUIRED' },
|
||||
{ status: 401 }
|
||||
);
|
||||
}
|
||||
|
||||
const body = await request.json();
|
||||
const { repoUrl, reason } = body;
|
||||
|
||||
if (!repoUrl) {
|
||||
return NextResponse.json(
|
||||
{ error: 'repoUrl is required', code: 'INVALID_INPUT' },
|
||||
{ status: 400 }
|
||||
);
|
||||
}
|
||||
|
||||
const parsed = parseOwnerRepo(String(repoUrl).trim());
|
||||
if (!parsed) {
|
||||
return NextResponse.json(
|
||||
{ error: 'Invalid format. Use https://github.com/owner/repo or owner/repo', code: 'PARSE_ERROR' },
|
||||
{ status: 400 }
|
||||
);
|
||||
}
|
||||
|
||||
const { owner, repo } = parsed;
|
||||
const username = session.user.username;
|
||||
|
||||
// Get or create user
|
||||
let dbUser = await userQueries.getByGithubId(db, session.user.githubId);
|
||||
if (!dbUser) {
|
||||
dbUser = await userQueries.upsertFromGithub(db, {
|
||||
githubId: session.user.githubId,
|
||||
username: session.user.username,
|
||||
displayName: session.user.name || undefined,
|
||||
email: session.user.email || undefined,
|
||||
avatarUrl: session.user.image || undefined,
|
||||
});
|
||||
}
|
||||
if (!dbUser) {
|
||||
return NextResponse.json(
|
||||
{ error: 'Failed to create user record', code: 'USER_CREATE_FAILED' },
|
||||
{ status: 500 }
|
||||
);
|
||||
}
|
||||
|
||||
// Verify repo ownership via GitHub API
|
||||
let isOwner = false;
|
||||
let githubError: string | null = null;
|
||||
|
||||
try {
|
||||
const repoResponse = await fetch(
|
||||
`https://api.github.com/repos/${owner}/${repo}`,
|
||||
{
|
||||
headers: {
|
||||
Accept: 'application/vnd.github.v3+json',
|
||||
'User-Agent': 'SkillHub',
|
||||
},
|
||||
signal: AbortSignal.timeout(10000),
|
||||
}
|
||||
);
|
||||
|
||||
if (repoResponse.ok) {
|
||||
const repoData = await repoResponse.json();
|
||||
if (repoData.owner?.login?.toLowerCase() === username.toLowerCase()) {
|
||||
isOwner = true;
|
||||
}
|
||||
} else if (repoResponse.status === 404) {
|
||||
return NextResponse.json(
|
||||
{ error: 'Repository not found on GitHub', code: 'INVALID_REPO' },
|
||||
{ status: 404 }
|
||||
);
|
||||
} else if (repoResponse.status === 403) {
|
||||
githubError = 'GitHub API rate limit exceeded. Please try again later.';
|
||||
}
|
||||
} catch (fetchError) {
|
||||
console.error('GitHub API fetch error:', fetchError);
|
||||
githubError = 'Failed to verify repository ownership';
|
||||
}
|
||||
|
||||
if (githubError) {
|
||||
return NextResponse.json(
|
||||
{ error: githubError, code: 'GITHUB_ERROR' },
|
||||
{ status: 502 }
|
||||
);
|
||||
}
|
||||
|
||||
if (!isOwner) {
|
||||
return NextResponse.json(
|
||||
{ error: 'You are not the owner of this repository', code: 'NOT_OWNER' },
|
||||
{ status: 403 }
|
||||
);
|
||||
}
|
||||
|
||||
// Count skills before blocking (for response message)
|
||||
const blockedCount = await skillQueries.countByRepo(db, owner, repo);
|
||||
|
||||
// Block all skills from the repo
|
||||
await skillQueries.blockByRepo(db, owner, repo);
|
||||
|
||||
// Block the discovered_repo entry to prevent re-indexing
|
||||
await discoveredRepoQueries.blockRepo(db, `${owner}/${repo}`);
|
||||
|
||||
const sanitizedReason = reason ? sanitizeReason(String(reason)) : undefined;
|
||||
console.log(
|
||||
`[RepoRemoval] ${username} removed ${owner}/${repo} (${blockedCount} skills blocked)${sanitizedReason ? ` — ${sanitizedReason}` : ''}`
|
||||
);
|
||||
|
||||
return NextResponse.json({
|
||||
success: true,
|
||||
blockedCount,
|
||||
repo: `${owner}/${repo}`,
|
||||
});
|
||||
} catch (error) {
|
||||
console.error('Error processing repo removal request:', error);
|
||||
return NextResponse.json(
|
||||
{ error: 'Internal server error', code: 'SERVER_ERROR' },
|
||||
{ status: 500 }
|
||||
);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user