supermemory/apps/web/app/api
vimzh 251e250935 fix(onboarding): reject non-X hosts and anchor regex in extractHandle
Copilot review flagged that 'lower.includes("x.com")' and the regex
fallback match any substring of the input, so a URL like
'https://examplex.com/foo' or 'notwitter.com/foo' would parse, extract
'foo' as a handle, pass the 1-15 alphanumeric guard, and burn a Grok
call on a wrong handle.

Add an isXHost helper that checks the parsed hostname against x.com /
twitter.com (and their subdomains) instead of relying on substring
matches. Anchor the regex fallback to '^', '.', or '/' before the
domain so the same substring trap does not apply there either.
2026-05-24 12:42:28 +05:30
..
emails/welcome chore: improve the codebase with react doctor (#917) 2026-05-09 19:12:01 +00:00
og (probable fix) 500 error on og endpoint 2026-01-23 18:57:14 -07:00
onboarding fix(onboarding): reject non-X hosts and anchor regex in extractHandle 2026-05-24 12:42:28 +05:30