The web UI now runs every job on an OAuth token from "Sign in with
GitHub". The ticked options decide the requested scopes (read:user, plus
repo for private repos, plus read:org for org repos); a grant wider than
requested is refused. The token lives only on the job and is revoked when
the job ends, on every path including shutdown.
The server no longer holds a GitHub token of its own, and the pasted-token
field and /generate are gone. -serve requires -oauth-client-id,
-oauth-client-secret and -public-url (GHGLANCE_OAUTH_* and
GHGLANCE_PUBLIC_URL), and compose.yml requires them too. The CLI and the
Action keep -token unchanged.
`ghglance -serve :8080` runs a web UI from the same binary: submit a
username, a background job renders every card in every theme, and
/u/<user> shows them again with a theme picker and embed URLs.
- Cards are stored on disk with atomic symlink publishing and deleted
after -retention (default 24h); -cooldown limits token-less regeneration.
- Token-less jobs use a public-only server token with private and org
scope forced off; a submitter's own token is used for that job only and
never stored or logged. The form links to GitHub's new-token page with
the needed scopes pre-ticked.
- The CLI and web share one fetch helper; CLI output is unchanged.
- compose.yml deploys to Coolify with a data volume and /healthz check.
The Marketplace rejects ghstats as an action name, so the repo, Go module,
binary, and action share the name ghglance instead. The demo workflow keeps
reading the existing GHSTATS_TOKEN repo secret.
* feat(card): configurable start of week for heatmap + weekday cards
New -start-of-week CLI flag (and start_of_week action input) rotates the
contribution-heatmap rows and the productive-weekday bars so users whose
calendars start on Monday (or any other day) get matching output. Default
stays Sunday to preserve existing renders.
* docs: note start-of-week in design-guidelines, codebase-summary, deployment-guide
- design-guidelines: heatmap row order + productive-weekday bar order now derive from Profile.WeekStart
- codebase-summary: list new weekday_start_test.go cases + TestParseWeekday
- deployment-guide: mention start_of_week as an optional action input in the workflow template
The repo is already listed on the Marketplace as ghstats-cards, so the
multi-paragraph "open the release page, tick the checkbox, re-publish"
instruction was stale. Replace with a one-line note pointing at the
existing listing and stating that new releases inherit visibility
automatically.
This reverts commit accc4b6. Repo stays as tiennm99/ghstats; the
Marketplace display name ("ghstats-cards" in action.yml) is the only
place the new name remains, since that field requires uniqueness on
the Marketplace.
plans/reports/* were added alongside the rename in the same commit
and are preserved by not deleting them in this revert.
Matches the Marketplace name; repo is being renamed in lockstep.
- go.mod module path: github.com/tiennm99/ghstats →
github.com/tiennm99/ghstats-cards
- Import paths across every .go file updated.
- README badges, install snippets, and the 'go install' line point
to the new URL/path.
- docs/deployment-guide.md workflow template, Docker image path, and
release edit URL updated.
Breaking for consumers pinned to the old URL; they need to swap
tiennm99/ghstats → tiennm99/ghstats-cards in workflows and switch
Docker pulls to ghcr.io/tiennm99/ghstats-cards. GitHub's HTTP
redirect covers git clones but GHCR does NOT redirect — users must
update image URIs manually.
- Fetcher signatures across codebase-summary and system-architecture
now show the ctx-first arguments and document the rate-limit retry
loop in Client.query.
- Attribution pseudo-code hoists the per-repo total out of the commit
loop to match the current implementation (I6).
- Failure-modes table enumerates primary rate-limit retry, per-year
nil-user warn, and -timeout / Ctrl-C cancellation.
- design-guidelines notes the single-slice donut special case.
- deployment-guide's release section documents the new test gate and
the SHA-pinned Docker/GHA actions; troubleshooting adds the
rate-limit-reset-too-long error. Rate-limit section describes the
sleep-and-retry policy and -timeout flag.
- project-roadmap records Phase 6 (code-review remediation) as done,
renumbers later planned phases, links the new review report.
Files now land at output/<theme>/profile-details.svg etc., without
leading 0-8 prefixes. README authors embed cards by name, so the
lexicographic-sort rationale for the prefix no longer applies.
- All Filename() methods + the allCards ordering comment updated.
- Tests updated to expect the 9 unnumbered filenames.
- README, deployment-guide, codebase-summary, roadmap references
refreshed.
- Dracula sample SVGs regenerated under new names.