461 Commits

Author SHA1 Message Date
Ben Senescu
cfa5bc2cf5
Gate GA4 MCP tools per-user; fix false ga4_malformed_response on empty comparison periods (#497) 2026-08-18 15:56:38 -04:00
Ben Senescu
7edb82192a
Update README.md 2026-08-18 15:22:45 -04:00
Ben Senescu
8149cd6c70
release: v0.1.5 (#496)
* release: v0.1.5

* save
2026-08-18 15:05:03 -04:00
Ben Senescu
7738f72333
Local SEO MCP tools: business profile, reviews, updates, categories, rank grid (#489) 2026-08-17 23:21:34 -04:00
Ben Senescu
052977f20d
Add Palestine as a Google-Ads-only country picker location (#492) 2026-08-17 22:52:47 -04:00
Ben Senescu
ff0ae47d19
Codex MCP “missing issuer” is a Codex 0.143–0.146 bug, not OpenSEO (#491) 2026-08-17 15:21:32 -04:00
Ben Senescu
61ebdb05ab
Google OAuth verification: privacy policy disclosures + GA4 reviewer access (#488)
* Add Google user data disclosures and Limited Use statement to privacy policy

* Show GA4 connect surfaces to the Google OAuth verification reviewer account

* List OpenAI as a potential AI model provider in the privacy policy
2026-08-15 18:27:59 -04:00
Ben Senescu
c8b3eb9b0a
Add exact URL / subfolder / domain / subdomain research scopes (EVE-56) (#487) 2026-08-14 21:52:32 -04:00
Ben Senescu
3df66ad9ae
Restore backlink feature URL (#484)
* Restore backlink feature URL

* Restore backlink checker page titles
2026-08-13 20:33:55 -04:00
Ben Senescu
db45a0dd6d
Fix MCP saved keyword metrics (#483) 2026-08-13 20:16:20 -04:00
Ben Senescu
72eaa09c32
Hide Analytics section when GA4 OAuth app is pending (#475) 2026-08-12 19:57:29 -04:00
Ben Senescu
75aec8424f
Detect paid plans from Autumn entitlement flags (#482) 2026-08-12 11:35:07 -04:00
Ben Senescu
a1ed6ece4b
Add strategy library index and navigation (#479)
* feat(web): add strategy library index

* fix(web): align strategy library review feedback

* fix(web): reorder resource links
2026-08-11 22:53:02 -04:00
Ben Senescu
bd402844fa
Add public product roadmap (#480) 2026-08-11 22:38:47 -04:00
Ben Senescu
0a11839a1c
Clarify contribution and pull request guidance (#457) 2026-08-11 21:51:15 -04:00
Ben Senescu
84e8d0be99
Serve legacy MCP JSON requests statelessly to stop per-request server retention (#478) 2026-08-11 20:15:48 -04:00
Ben Senescu
16eb599270
MCP API key support (hosted mode) (#438) 2026-08-11 19:20:44 -04:00
Ben Senescu
7a1748af4e
Exclude PDF assets from prerendering (#476) 2026-08-10 23:03:20 -04:00
Jeremy Rivera
edc2c07af2
Add blog post: Ranking for the Wrong Half of Your Audience (#185) 2026-08-10 13:43:53 -04:00
Jeremy Rivera
85095f4ac6
Library batch 2: plays 05-08, completing the Keyword Research library (#187) 2026-08-10 12:11:40 -04:00
Ben Senescu
d2d8f7e19a
release: v0.1.4 (#474)
* release: v0.1.4

* save
2026-08-09 15:51:55 -04:00
Ben Senescu
877782ad19 fix(gdpr): drop reddit_attributions count from erasure script
The reddit attribution tables were removed in #469; the erasure
script still counted them, breaking tsc in ci:check.
2026-08-08 19:21:47 -04:00
Ben Senescu
9edb18db60
feat(gdpr): user data erasure workflow (EVE-46) (#468) 2026-08-08 19:17:41 -04:00
Ben Senescu
13ada5b441
fix(sam): out-of-credits CoT leak, streaming scroll lock, rank-tracking language gap (#470)
* fix(sam): stream canned refusals without a provider call

Out-of-credits and session-gone refusals ran a real LLM turn with a
200-token cap; MiniMax M3 could spend the whole budget on reasoning
tokens, leaving the user a raw truncated chain-of-thought (which also
named the backing model) and no reply. Refusal turns now swap in a
static LanguageModelV3 that streams the refusal text through Think's
normal pipeline — rendered and persisted like any assistant message,
with no provider request at all.

Fixes every-app/open-seo#161

* fix(chat): stop pinning the transcript to the bottom while the user scrolls up

Both chat surfaces (SAM and onboarding) forced scrollTop to the bottom
on every streamed chunk, so scrolling up mid-reply was undone within
milliseconds. A shared stick-to-bottom hook now tracks pinned-ness from
real scroll events: scrolling away releases the pin, returning to the
bottom (or sending a message) re-arms it.

Fixes every-app/open-seo#160

* fix(rank-tracking): allow any SERP language for any country

The Add Domain modal restricted the language picker to the Labs
per-country subset and disabled it when only one option existed, so
e.g. tracking English searches in Czechia was impossible — even though
rank tracking runs against the SERP API, which serves every supported
language in every country. The picker now offers the full SERP language
list; create/update schemas validate codes against the master list so
unknown codes still fail before DataForSEO charges for them; and
keyword-metrics refreshes resolve a Labs-served language so an
unserved pair never reaches a charged Labs call.

Fixes every-app/open-seo#183

* fix(chat): surface silent turn failures in Workers logs

A provider stream dying mid-turn (chat:request:failed) and a DO restart
whose recovery gives up (chat:recovery:exhausted) leave the user a
replayed "Something went wrong" banner and a half-streamed message, but
never reach the onChatError hook — their only signal is the agents:chat
diagnostics channel, which was unsubscribed, so the chat agents' most
common failure modes produced zero log lines. A module-level
subscription now logs both for every chat DO.

SamChatAgent.onChatError also returns the error now: Think uses the
return value as the stored chat-terminal body that reconnecting clients
replay, and returning void stored the literal string "undefined".
2026-08-08 18:47:41 -04:00
Ben Senescu
17e7515e82
feat(self-host): share one workspace across Cloudflare Access users (#467) 2026-08-08 18:23:31 -04:00
Ben Senescu
f14aa4c746
fix(selfhost): build client bundle with --mode selfhost so AUTH_MODE matches runtime (#471) 2026-08-08 14:14:03 -04:00
Ben Senescu
2cedcda5db
fix(billing): activate paid plans immediately after checkout (EVE-44) (#469) 2026-08-08 13:06:45 -04:00
Ben Senescu
cfc8456767
feat(mcp): migrate to MCP SDK v2 stateless handler (#464) 2026-08-08 12:44:48 -04:00
Ben Senescu
45403aa06f
fix(ga4): hide every GA4 connect surface until the OAuth app is approved (#466) 2026-08-07 22:56:31 -04:00
Ben Senescu
eec998a762
feat(rank-tracking): raise scheduler throughput 5x with rate-limit-derived sizing (#465)
* feat(rank-tracking): raise scheduler budget to 2000 units/tick

The 200-unit budget used ~2-6% of DataForSEO's 2,000 req/min account
cap and would take days to drain the post-#462 backlog. Scheduled checks
run through the task queue (1 task_post per 100 units + free task_get
polls), so a full 2,000-unit tick peaks around 1,200 req/min — still
leaving headroom for the other DataForSEO products on the account.

Also raise the due-config fetch limit to 500 so skip-heavy stretches
(free orgs, keywordless configs) drain more than 200 rows per tick.

* fix(rank-tracking): retune budget to 1000 with accurate sizing and a tick deadline

Review corrections to the 10x bump: task_get polling is one call per unit
per round and rounds wake synchronized per tick, with up to three ~15-min
poll windows overlapping the */5 cron — 2000 units/tick could saturate
DataForSEO's 2000 req/min cap, silently aging throttled polls into the
~3x-cost live fallback billed to customers. 1000/tick keeps real headroom
and is still ~45x steady-state demand.

Add a 3-minute wall-clock deadline to the per-config loop (stoppedByDeadline
in the tick summary): a skip-heavy 500-candidate tick pays serial Autumn
round-trips per distinct org and could otherwise run into the 15-minute cron
kill. Name the fetch limit (DUE_CONFIGS_PER_TICK) and correct its comment.

Test fixtures now derive from MAX_KEYWORDS_PER_CONFIG instead of asserting
an unreachable 1500-keyword config.

* fix(cron): run the audit watchdog before the rank loop

reconcileStaleAudits ran after runScheduledRankChecks in the same
invocation, so a slow rank tick would delay the watchdog and a wall-clock
kill would skip it entirely.

* fix(cron): preserve watchdog failure signal; codex review polish

Rethrow a caught reconcileStaleAudits error after the rank loop so the
invocation still reports failed (matching pre-reorder semantics), use an
inclusive deadline comparison, and note overlapping-tick poll residue in
the sizing comment.
2026-08-07 16:44:16 -04:00
Ben Senescu
16b6d38ea8
fix(dashboard): hide GA4 connect card until OAuth app is approved (#463)
* fix(dashboard): hide GA4 connect card until OAuth app is approved

* fix(ai-mcp): hide Google Analytics tool category until OAuth app is approved
2026-08-07 14:21:01 -04:00
Ben Senescu
f048dc3bd1
fix(rank-tracking): drain due configs deterministically (clean-room alternative to #456) (#462) 2026-08-07 13:53:30 -04:00
Ben Senescu
e2c84803f2
feat: add GA4 MCP insights and rank tracking management (#461) 2026-08-07 13:47:18 -04:00
Ben Senescu
c40a04459c
fix(billing): retry missing Autumn balance (#450) 2026-08-06 21:33:25 -04:00
Ben Senescu
211907ae32
fix(audit): make Lighthouse billing retry-safe (#460) 2026-08-06 21:19:39 -04:00
Ben Senescu
189d5bfa1f
fix(onboarding): isolate cached routing state per request (#459) 2026-08-06 12:24:31 -04:00
Ben Senescu
8a728563d4
fix(mcp): stop breaking public OAuth clients at token refresh (#420)
* fix(mcp): stop breaking public OAuth clients at token refresh

The DCR shim force-upgraded every public client (token_endpoint_auth_method
"none" or omitted) to client_secret_post so Perplexity would accept the
registration response. That made the stored client confidential, so the
token endpoint demanded client authentication on every grant — and MCP
clients that discard the secret (Codex) lost their session at first token
expiry with "invalid_client: missing client_secret".

Register those clients as true public clients instead (PKCE + the
provider's grant-to-client binding secure that flow), and satisfy
Perplexity by decorating only the registration response with a placeholder
client_secret and client_secret_post. The provider skips secret validation
for public clients, so clients that send the placeholder and clients that
never store it both keep working, including on refresh.

* refactor(mcp): only rebuild DCR requests that actually change

* fix(mcp): satisfy type-aware lint in DCR shims

oxlint --type-aware rejected the Record<string, unknown> assertions used to
read untrusted DCR payloads. Parse both with loose Zod schemas instead, per
the repo's trust-boundary convention, which also replaces the hand-rolled
object guards.
2026-08-05 16:10:28 -04:00
Ben Senescu
30948a2a1d
Increase pricing calculator website limit to 500 (#454) 2026-08-01 17:28:04 -04:00
Ben Senescu
187d3fd9c1
fix(db): widen backlink snapshot counts (#448) 2026-08-01 17:10:43 -04:00
Ben Senescu
f6ddf654df
fix(ci): make crawl backpressure lintable (#452) 2026-08-01 14:50:49 -04:00
Ben Senescu
b8253fb083
Free backlink checker at /backlink-checker (#444) 2026-08-01 13:50:50 -04:00
Ben Senescu
145324138e
Cap site-audit crawl memory: byte-budgeted window, 1 MiB read cap, persist backpressure (#445) 2026-08-01 13:22:26 -04:00
Ben Senescu
acd28749c8
Auto-evict the oldest search tab at capacity, raise the limit to 20 (#442) 2026-08-01 10:34:31 -04:00
Ben Senescu
32b1b1d38c
Remove Product Hunt launch banner from marketing site (#440) 2026-07-31 13:07:44 -04:00
Ben Senescu
8d6e99385f
audit: drop the audit_links table (#416) 2026-07-30 20:51:32 -04:00
Ben Senescu
1e8a924c4c
Site Audit - Improve reliability and performance with Durable Objects 2026-07-30 00:51:50 -04:00
Ben Senescu
9d19e43990
release: v0.1.3 (#433) 2026-07-30 00:23:36 -04:00
Amine Benboubker
a710b560d5
perf(docker): reuse the build across restarts instead of rebuilding on every start (#123) 2026-07-30 00:16:18 -04:00
Timur Isachenko
4a82bf0803
Document reproducible contributor checks (#105) 2026-07-29 23:32:56 -04:00
Nordalux
4f45a04961
fix(docker): forward OPENROUTER_API_KEY into the self-host container (#152) 2026-07-29 23:32:37 -04:00