supermemory/apps/web/app/api/onboarding
vimzh 251e250935 fix(onboarding): reject non-X hosts and anchor regex in extractHandle
Copilot review flagged that 'lower.includes("x.com")' and the regex
fallback match any substring of the input, so a URL like
'https://examplex.com/foo' or 'notwitter.com/foo' would parse, extract
'foo' as a handle, pass the 1-15 alphanumeric guard, and burn a Grok
call on a wrong handle.

Add an isXHost helper that checks the parsed hostname against x.com /
twitter.com (and their subdomains) instead of relying on substring
matches. Anchor the regex fallback to '^', '.', or '/' before the
domain so the same substring trap does not apply there either.
2026-05-24 12:42:28 +05:30
..
account-status fix: Implement the onboarding account lookup (#913) 2026-05-11 02:29:15 -07:00
extract-content feat: deep-research on user profile and tiptap integration (#672) 2026-01-15 21:53:53 +00:00
research fix(onboarding): reject non-X hosts and anchor regex in extractHandle 2026-05-24 12:42:28 +05:30