Semih
a713505f44
feat(insights): Telegram alerts + daily brief push notifications
...
apps/worker/src/lib/telegram.ts:
- sendTelegram() with Redis-backed dedupe (NX SETEX, 1h TTL)
- Helpers: alertP0Insight, alertRegression, alertSanitizationAnomaly, alertBudgetCap
Wired into:
- analyze.ts: P0/P1 insight creation → instant alert (dedupe per insight_id);
budget guard halt → daily cap alert (dedupe per state per day)
- validation.ts: regression detected (≥3 sessions w/ same fingerprint after shippedAt)
→ alert (dedupe per insight_id)
- compress-sessions.ts: sanitization anomaly (>500 tokens, 0 PII matches)
→ alert (dedupe per session_id) — possible PII leak warning
Daily Brief (jobs/daily-brief.ts):
- Cron @05:00 UTC (= 08:00 Europe/Istanbul)
- 24h: sessions/insights/cost/cache-hit + 3 top priorities + 7d shipped/validated/regressed
- POST /api/insights/brief/send for manual trigger / smoke test
Env: TELEGRAM_BOT_TOKEN, TELEGRAM_CHAT_ID, PANEL_PUBLIC_URL (Coolify both apps).
Bot: @Pl24_mitm_bot (AiFactory), chat 7840804807. Source: airflow3 monitoring DAG.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-05-14 11:36:10 +00:00
Semih
74f0ff4935
fix(ingest): rolling lookback + ongoing-aware watermark to prevent missed sessions
...
Bug: previous logic advanced watermark to the latest session start_time including
ongoing sessions. PostHog session_recordings filters by start_time, so once a
session was 'seen' as ongoing the watermark moved past its start time and the
session was never re-fetched after it ended. Today 4 auth sessions on
/dashboard/vehicles/* and /dashboard/search (07:17-07:40 UTC) were lost this way.
Fix:
1. ROLLING_LOOKBACK_MINUTES (default 60): every cycle queries date_from =
min(watermark, now - 60min). Sessions that just finished get re-fetched
regardless of watermark drift. Upsert dedupes.
2. Track earliestOngoingStart; cap watermark to (earliestOngoingStart - 1s)
so subsequent cycles re-read that range.
Also added GET/DELETE /api/insights/watermark for manual reset (used to
trigger 24h backfill after this deploy).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-05-14 10:53:38 +00:00
Semih
dfc19c8f13
refactor(integrations): migrate issue tracker GitHub → Gitea
...
- apps/web/src/lib/gitea.ts: createIssue / getIssue / verifyWebhookSignature / buildIssueBody
* Endpoint: git.semih.ai/api/v1 (configurable via GITEA_BASE_URL)
* Auth: 'Authorization: token <PAT>' (Gitea convention)
* Labels: Gitea expects numeric IDs not strings → ensureLabels() resolves/creates
with color coding (P0/P1 red, P2 yellow, P3 green, type-* grey, default blue)
* Webhook signature: X-Gitea-Signature (hex, no sha256= prefix)
- apps/worker/src/lib/gitea.ts: read-only getIssue() for sync polling
- _actions.ts + github-sync.ts now import from /lib/gitea
- Removed old apps/{web,worker}/.../lib/github.ts + /api/webhooks/github route
(the receiver was already dead — sp.semih.ai is Tailscale-only)
- UI: 'GitHub' label → 'Gitea' on insight detail card
- github-sync job filters by githubIssueUrl.startsWith(GITEA_BASE_URL) so legacy
GitHub-hosted insights (semihyesilyurt/sase.tr#20 ) stay frozen rather than
collide with same-numbered Gitea issues at root/sase.tr.
Env migration (Coolify, panel-web + panel-worker):
- removed: GITHUB_TOKEN, GITHUB_REPO_SASE, GITHUB_WEBHOOK_SECRET
- added: GITEA_TOKEN, GITEA_REPO_SASE=root/sase.tr, GITEA_BASE_URL=https://git.semih.ai
Provisioned Gitea PAT 'super-panel-insights' (scopes: write:repository + write:issue),
stored in Bitwarden.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-05-14 09:36:57 +00:00
Semih
b83d28c119
feat(eval): POST /api/insights/eval-sets thin wrapper (create + optional run)
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-05-14 06:15:39 +00:00
Semih
0c6350db2d
feat(insights): POST /api/insights/[id]/create-issue thin wrapper around server action
...
Useful for programmatic smoke tests and future automation. Auth-gated via underlying action.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-05-14 05:49:20 +00:00
Semih
c5acdfc8ec
feat(phase6d): GitHub action loop — issue creation, webhook, validation cron, patterns view
...
Schema:
- Insight.+githubIssueNumber (user-visible #N, separate from id BigInt)
GitHub integration (apps/web/src/lib/github.ts):
- repoFor(projectKey): env-based GITHUB_REPO_<KEY>=owner/repo mapping
- createIssue / getIssue REST wrappers
- verifyWebhookSignature (HMAC-SHA256 timing-safe)
- buildIssueBody: renders structured markdown from insight + LLM body
(hypothesis, reproduce steps, affected route/provider, quick/long fixes,
suggested investigation, evidence links to panel, DoD checklist)
Server action createGithubIssueForInsight:
- Auth-gated, audited; idempotent (refuses if issue already exists)
- Labels: insight-driven, severity-<P>, type-<T>, <project>-pilot
- Sets status=in_backlog, stores githubIssueUrl/Id/Number/State
Webhook /api/webhooks/github:
- Signature verify with GITHUB_WEBHOOK_SECRET
- issues.closed → status=shipped + shippedAt + validationStartedAt
- issues.reopened → status=in_progress + clear validation state
- issues.opened → status=in_backlog
- PR linking placeholder (passthrough only for now)
Validation cron (worker, daily 5:00 UTC):
- For each insight in 'shipped' state:
- Count sessions with same fingerprint after shippedAt
- >= INSIGHT_REGRESSION_THRESHOLD (default 3) → status=regressed + regressionDetected=true
- validationPeriodDays elapsed with no regression → status=validated + validatedAt
UI:
- Insight detail: GithubActions card — Create button (when no issue),
external link + issue # + state (when present)
- New /insights/patterns page: clusters insights by type + affected_route/provider,
shows ≥2-insight or ≥5-occurrence groups sorted by max severity
- Inbox header link to Patterns
- Cmd+K palette: Patterns entry
Env needed: GITHUB_TOKEN, GITHUB_REPO_SASE, GITHUB_WEBHOOK_SECRET.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-05-14 05:45:48 +00:00
Semih
7606e1b0bf
feat(insights): /api/insights/reprocess auth-gated endpoint to re-run pipeline on existing sessions
...
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com >
2026-05-13 22:26:13 +00:00
Semih
ed79f4eacd
feat(phase3c): SSE /api/events/stream + live /events page
2026-05-13 11:06:32 +00:00
Semih
67a7c5b887
feat: phase 0 skeleton — next.js 16 + better-auth + prisma
2026-05-13 09:17:50 +00:00