Skip to content

Ship staging to production - #1902

Open
postiz-contribution[bot] wants to merge 268 commits into
mainfrom
staging
Open

postiz-contribution[bot] wants to merge 268 commits into
mainfrom
staging

Conversation

@postiz-contribution

@postiz-contribution postiz-contribution Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

In this batch

No merged PRs in this batch yet.

Before you merge

  • New environment variables (92): AGENT_API_KEY, AGENT_MEDIA_SSO_KEY, APPLE_APP_BUNDLE_ID, BACKEND_URL, CHATBASE_TOKEN, DATAFAST_API_KEY, DATAFAST_WEBSITE_ID, DISABLE_IMAGE_COMPRESSION, DISABLE_REGISTRATION, DISABLE_SSRF_PROTECTION, DISABLE_X_ANALYTICS, DISALLOW_PLUS and 80 more. Set them on production before merging.
  • Environment variables no longer referenced (3): APPLE_BUNDLE_ID, APPLE_SERVICE_ID, EMAIL_FROM_ADDRESS.
  • Dependencies (2): package.json, pnpm-lock.yaml
  • Infrastructure and deploy config (1): docker-compose.dev.yaml

@postiz-contribution postiz-contribution Bot added the staging:batch Aggregate PR shipping the staging batch to the default branch label Aug 17, 2026
@postiz-agent

postiz-agent Bot commented Aug 17, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

egelhaus and others added 13 commits August 17, 2026 08:19
feat(build): add caching back to build workflow
The invoice preview in StripeService.prorate() passed proration_date
together with billing_cycle_anchor: 'now', which Stripe rejects
("You cannot specify proration_date when billing_cycle_anchor=now").
The error was swallowed and the billing page showed "Pay Today $0"
next to every upgrade, while the actual upgrade charged the correct
prorated amount.

Drop proration_date so the preview succeeds and the UI shows the amount
the customer will be charged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The Temporal SDK logs outside of console: the TS side writes straight to
stderr and the native core prints directly, so Sentry's console logging
integration never sees lines like "Activity failed" or "Activity not
found on completion" - today they exist only in the Railway container
logs.

Install the Temporal Runtime once, before any worker is created, with a
DefaultLogger that prints in the SDK's own "<ts> [LEVEL] message {meta}"
format via console.error / console.log, and forward native core logs
(default filter: core WARN, other ERROR) into that same logger. Railway
keeps the same lines; Sentry now gets them too, so they can be searched
there (including read-only via the Sentry MCP) without touching prod.

Verified locally against the origin/main build with the same provoked
error: TS-side lines are byte-identical apart from timestamps; forwarded
native lines carry the same content in the SDK's structured format.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Pinterest's pin creation endpoint intermittently answers with
{"code":2787,"message":"Sorry! Something went wrong on our end."}.
It was unmapped in handleErrors, so the post failed immediately as a
non-retryable BadBody with the 'Unknown Error' placeholder, even though
identical requests succeed minutes later.

Map it to a retry (3 attempts, 5s apart) with a curated message so a
short Pinterest hiccup no longer fails the post, and if it persists the
user sees what actually happened instead of 'Unknown Error'.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
YouTube returns HTTP 403 with reason "forbidden" ("Access forbidden. The
request may not be properly authorized.") when the connected Google
account cannot upload to the selected channel. handleErrors had no mapping
for it, so it surfaced as the 'Unknown Error' placeholder. Map it as a
non-retryable bad-body with an actionable message; matched on the quoted
reason token so the plain word elsewhere in a body cannot trigger it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… curated message

Instagram returns (#10) "Requires instagram_content_publish permission to
manage the object" when the connected account was not granted the content
publishing permission for that Instagram account. handleErrors had no
mapping for it, so it surfaced as the 'Unknown Error' placeholder. Map it
as a non-retryable bad-body telling the user to reconnect and allow all
requested permissions for the account. Covers instagram-standalone too,
which delegates to the same handleErrors.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…he real update

Use proration_behavior: 'always_invoice' without billing_cycle_anchor in
the invoice preview, mirroring subscribe(), so "Pay Today" equals the
prorated amount Stripe actually invoices on upgrade.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@strix-security

strix-security Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Strix Security Review

6 open security findings on this PR:

1 resolved finding
Review summary

Reviewed the pull request's commit delta (README.md, apps/frontend/src/components/new-launch/add.edit.modal.tsx, libraries/react-shared-libraries/src/helpers/uppy.upload.ts) plus the staging->main production code changes. The delta consists of defensive fixes (a null-check that closes the edit modal instead of crashing, and upload error propagation) and introduces no new vulnerabilities. The broader production changes are observability additions, defensive null checks, and provider error-classification fixes; no new high- or medium-impact issues were found. The previously reported Sentry logging and PII findings remain present and unchanged: "PII disclosure to Sentry through forced NestJS console logging", "User-linked orchestrator email logs exported to Sentry via forced console routing", "Frontend console logs exported to Sentry via newly-enabled console log capture", and "Incomplete PII redaction allows user_id, org_id, and request_path to be sent to Sentry".

Fixed the findings? re-run the review, or tag @strix-security in a PR comment to run a fresh review.

Updated for c600209.


Reviewed by Strix
Re-run review · Configure security review settings

@railway-app
railway-app Bot temporarily deployed to Postiz / staging September 21, 2026 10:36 Inactive
@railway-app
railway-app Bot temporarily deployed to Postiz / staging September 22, 2026 02:11 Inactive
github-actions Bot and others added 22 commits September 22, 2026 04:55
Resolved-by: claude-code-action

# Conflicts:
#	libraries/nestjs-libraries/src/integrations/social/mastodon.custom.provider.ts
Added a comparison between Postiz Cloud and Open-source versions, detailing features and differences. Updated sponsorship options for Postiz.
Enhance README with Postiz Cloud comparison and sponsorship
Resolved-by: claude-code-action

# Conflicts:
#	README.md
Resolved-by: claude-code-action

# Conflicts:
#	libraries/nestjs-libraries/src/integrations/social/reddit.provider.ts
Resolved-by: claude-code-action

# Conflicts:
#	.env.example
#	libraries/react-shared-libraries/src/translation/locales/ar/translation.json
#	libraries/react-shared-libraries/src/translation/locales/bn/translation.json
#	libraries/react-shared-libraries/src/translation/locales/de/translation.json
#	libraries/react-shared-libraries/src/translation/locales/en/translation.json
#	libraries/react-shared-libraries/src/translation/locales/es/translation.json
#	libraries/react-shared-libraries/src/translation/locales/fr/translation.json
#	libraries/react-shared-libraries/src/translation/locales/he/translation.json
#	libraries/react-shared-libraries/src/translation/locales/it/translation.json
#	libraries/react-shared-libraries/src/translation/locales/ja/translation.json
#	libraries/react-shared-libraries/src/translation/locales/ko/translation.json
#	libraries/react-shared-libraries/src/translation/locales/pt/translation.json
#	libraries/react-shared-libraries/src/translation/locales/ru/translation.json
#	libraries/react-shared-libraries/src/translation/locales/tr/translation.json
#	libraries/react-shared-libraries/src/translation/locales/vi/translation.json
#	libraries/react-shared-libraries/src/translation/locales/zh/translation.json
…error

fix(frontend): silence Unchecked runtime.lastError from extension messaging callbacks
Resolved-by: claude-code-action

# Conflicts:
#	.env.example
Resolved-by: claude-code-action

# Conflicts:
#	apps/frontend/src/components/new-launch/manage.modal.tsx

This branch was previously deployed

1 inactive deployment
Postiz / staging — c6002094 Deployed Sep 29, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

guard:blocked Touches a guarded path and is awaiting sign-off staging:batch Aggregate PR shipping the staging batch to the default branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants