Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
138 commits
Select commit Hold shift + click to select a range
2668ff7
Fix Step 3 mobile layout, X consent navigation and app display messages
xrpbanks Sep 10, 2026
d9f26d3
Expose the colourful footer asset in Home footer mode
xrpbanks Sep 10, 2026
f6583ee
Fix both X anchor states and synchronize controls with cookie-banner …
xrpbanks Sep 10, 2026
e595fe2
Scope cookie observation and release completed search probes in Site …
xrpbanks Sep 10, 2026
242a083
Fix translated Xaman continue link in embedded login panel
xrpbanks Sep 10, 2026
aee086c
Refine Step 3 desktop and mobile presentation; restore Nutri-Score co…
xrpbanks Sep 10, 2026
61e6e8d
Load the real Nutri-Score component in translated food rendering tests
xrpbanks Sep 10, 2026
88a62d7
Preserve the footer color when its background image is unavailable
xrpbanks Sep 10, 2026
00f56e0
Audit Steps 1–3 and consolidate Site Style 1.4.7 with repeatable rele…
xrpbanks Sep 10, 2026
56eae73
Limit translated login notices to known status and error messages
xrpbanks Sep 10, 2026
6a91ae6
Scope mobile screen-reader styling to the CalorieHelp caption
xrpbanks Sep 10, 2026
e01e9d8
Refine shared site layout and add guarded food barcode lookup
xrpbanks Sep 10, 2026
2ad5d87
Harden Step 1–3 integration and automate regression coverage
xrpbanks Sep 10, 2026
59d191d
Patch development tooling and identify Render builds automatically
xrpbanks Sep 10, 2026
d43c3a3
Fix issues observed in the installed Site Style review (1.4.10)
xrpbanks Sep 10, 2026
4c34430
Fix Blog X observer feedback and panel lifecycle in Site Style 1.4.11
xrpbanks Sep 10, 2026
2dcc74b
Normalize cookie banner opacity and cover numeric zero variants
xrpbanks Sep 10, 2026
53013d7
Fix confirmed live footer and language controls; retire replaced mark…
xrpbanks Sep 11, 2026
c98bcce
Restore a clear diary grade indicator and guide camera permission rec…
xrpbanks Sep 11, 2026
29def14
Fix camera delegation before iframe navigation and distinguish previe…
xrpbanks Sep 11, 2026
d013e77
Simplify Testnet faucet requests and distinguish onboarding failures
xrpbanks Sep 11, 2026
4cbc31e
Bound Testnet UI retries and show translated waiting times
xrpbanks Sep 11, 2026
19077f7
fix: restore CAL logo shortcut and clarify crypto page choices
xrpbanks Sep 11, 2026
0dfe591
Keep public headers aligned with the published Brizy menu
xrpbanks Sep 11, 2026
f9dfe41
Improve food barcode recognition in mobile camera frames
xrpbanks Sep 11, 2026
d2b127c
Fix Testnet faucet seed parsing for current response format
xrpbanks Sep 11, 2026
6d9641f
Fix embedded logout and add period diaries with consistent site navig…
xrpbanks Sep 11, 2026
6cd9fbb
Restore compact Brizy navigation and consistent historical content st…
xrpbanks Sep 11, 2026
3845de6
Use indexed food search and fix confirmed website and app translation…
xrpbanks Sep 11, 2026
d973d7e
Handle HTML hosting checks during the WordPress login exchange
xrpbanks Sep 13, 2026
187b8c0
Issue one-time login codes from authenticated WordPress assertions
xrpbanks Sep 13, 2026
f8ab870
Improve mobile barcode capture and link missing foods to Open Food Facts
xrpbanks Sep 13, 2026
44fef6f
Add camera photo scanning and improve focus recovery
xrpbanks Sep 13, 2026
55c371a
Resize embedded app to its natural content height in both directions
xrpbanks Sep 13, 2026
1cfdd99
Use barcode lookup from the main search and show logged portions
xrpbanks Sep 14, 2026
40ed5f4
Prepare multilingual food discovery and similar food selection
xrpbanks Sep 15, 2026
873d622
docs: align food discovery and CalorieHelp with live release
xrpbanks Sep 15, 2026
f2503b6
ci: isolate food UX integration checks from production
xrpbanks Sep 15, 2026
9d932a2
ci: verify exact UX patch and browser flow in isolated branch
xrpbanks Sep 15, 2026
b42e228
chore: transfer checksum-bound isolated UX candidate (1/5)
xrpbanks Sep 15, 2026
40684b6
chore: transfer checksum-bound isolated UX candidate (2/5)
xrpbanks Sep 15, 2026
cb29f15
test: complete verified UX integration transfer for isolated browser …
xrpbanks Sep 15, 2026
3296fd2
fix: integrate verified food UX and explicit source-score coverage
github-actions[bot] Sep 15, 2026
64d5349
test: retain read-only UX verification and document release limits
xrpbanks Sep 15, 2026
d74baa4
fix: show actual USDA grams in saved diary entries
xrpbanks Sep 15, 2026
d03caa8
Polish grade coverage wording across all locales
xrpbanks Sep 15, 2026
359ca97
Document completed grade-count wording fix
xrpbanks Sep 15, 2026
bcf4130
Test singular grade-count wording
xrpbanks Sep 15, 2026
ac724aa
Consolidate food navigation with live-route USDA grams and eleven-loc…
xrpbanks Sep 15, 2026
62001b6
Merge steps 1-3 live repair candidate
xrpbanks Sep 16, 2026
176a4e6
Publish embedded CalorieApp session status
xrpbanks Sep 16, 2026
ddfac49
Record live steps 1-4 acceptance status
xrpbanks Sep 16, 2026
b187da2
Focus campaign on anniversary and CalorieApp
xrpbanks Sep 16, 2026
da38a30
Refine CalorieApp tabs and nutrition periods
xrpbanks Sep 16, 2026
9b6a323
Align browser check with diary tab
xrpbanks Sep 16, 2026
5f8e5a1
Wait for widget period message in browser check
xrpbanks Sep 16, 2026
05f0745
fix: simplify age and mobile food flows
xrpbanks Sep 16, 2026
a688507
fix: finish mobile app and age-safe WordPress flows
xrpbanks Sep 16, 2026
a299fb6
fix: complete age-aware account UX
xrpbanks Sep 16, 2026
b20bf8a
fix: complete final cross-site UX polish
xrpbanks Sep 16, 2026
ca6c6c9
fix: reconcile live WordPress repair
xrpbanks Sep 16, 2026
e210505
test: use stable adult age selector
xrpbanks Sep 16, 2026
4c0a6b6
test: open nickname profile before editing
xrpbanks Sep 17, 2026
687e39f
test: locate packaged results semantically
xrpbanks Sep 17, 2026
161b579
test: scope packaged portion cancellation
xrpbanks Sep 17, 2026
680f295
test: open the display language picker
xrpbanks Sep 17, 2026
66780ab
fix: repair mobile identity session handoffs
xrpbanks Sep 17, 2026
77ec3d8
fix: guide account setup and real-account transition step by step
xrpbanks Sep 17, 2026
83b826a
test: await hidden iframe messages without animation frames
xrpbanks Sep 17, 2026
ccc9983
Move account setup and migration into native app pages
xrpbanks Sep 17, 2026
d722387
Unify WordPress content, CalorieHelp and FAQ with CalorieApp styling
xrpbanks Sep 17, 2026
5513957
Verify CalorieHelp disclosure before content preview captures
xrpbanks Sep 17, 2026
30eb8eb
Match login widget and Brizy menu controls to CalorieApp styling
xrpbanks Sep 17, 2026
7e0ceaf
Normalize only owned style markers in preservation snapshots
xrpbanks Sep 17, 2026
fa3e5af
Preserve joined title initials and let historical banners fit long copy
xrpbanks Sep 17, 2026
50c8bd7
Check title line positions across first-letter fragments
xrpbanks Sep 17, 2026
2d75a3b
Adapt child and teen button shapes and brand shades, preserve adult s…
xrpbanks Sep 17, 2026
83a8ab8
Wait for existing colour transitions before comparing adult button st…
xrpbanks Sep 17, 2026
ae86192
Add original faded logo paper to WordPress cards (1.6.10)
xrpbanks Sep 17, 2026
c96c478
Persist account nickname and simplify account navigation and sign-in
xrpbanks Sep 17, 2026
e3125a8
Align browser checks with grouped account navigation
xrpbanks Sep 17, 2026
6ba4acc
Merge tested account nickname, navigation and sign-in improvements
xrpbanks Sep 17, 2026
4e7ece8
Clarify nutrition coverage, add original food illustrations and stabi…
xrpbanks Sep 17, 2026
905cba0
Merge tested nutrition summary, illustrations and stable food navigation
xrpbanks Sep 17, 2026
4821427
Connect CalorieHelp directly to native app tasks and account guides
xrpbanks Sep 18, 2026
86ec81c
Clear cancelled account guides and consumed helpbot launch links
xrpbanks Sep 18, 2026
0321956
Record live WordPress menu, slogan, guide and RTL layout fixes
xrpbanks Sep 18, 2026
9e62799
Record live dropdown stacking correction above WordPress banners
xrpbanks Sep 18, 2026
e23f9d8
Start CalorieVerse with a persistent playable meadow
xrpbanks Sep 19, 2026
205ad5f
Refine food search readability and compact product actions
xrpbanks Sep 21, 2026
816f0f9
Clarify product and ingredient search choices in all locales
xrpbanks Sep 21, 2026
d3913a5
Guide beginners through account choices and Xaman practice setup
xrpbanks Sep 21, 2026
701b94d
Polish diary navigation and prioritize product thumbnails
xrpbanks Sep 21, 2026
a807581
Clarify diary summaries and actions in all locales
xrpbanks Sep 21, 2026
3f95ad4
Use smaller recognized product photo thumbnails
xrpbanks Sep 21, 2026
94d6d46
Cover thumbnail fallbacks and updated diary empty states
xrpbanks Sep 21, 2026
e98119e
Record diary image validation and authorized release continuation
xrpbanks Sep 21, 2026
fa4763c
Improve compact product navigation, icons and contextual choices
xrpbanks Sep 22, 2026
979a3df
Add source-aware alternatives, recipe matching and deliberate scrolling
xrpbanks Sep 22, 2026
a266685
Translate food labels and recipe preference controls
xrpbanks Sep 22, 2026
262ed2b
Add a small original catalogue of adaptable recipe ideas
xrpbanks Sep 22, 2026
c3bdad8
Give the app more desktop space while preserving mobile layout
xrpbanks Sep 22, 2026
063af73
Expose optional food-discovery source metadata
xrpbanks Sep 22, 2026
5215d76
Pass through bounded OFF labels without changing request budgets
xrpbanks Sep 22, 2026
2c7b457
Verify optional label metadata and align existing readiness expectation
xrpbanks Sep 22, 2026
39fa335
Verify compact navigation, evidence-based choices and FAQ parity
xrpbanks Sep 22, 2026
8c6b20e
Keep the login panel in view without jumping or exiting focus
xrpbanks Sep 22, 2026
ba0a4f7
Version the compact login presentation update
xrpbanks Sep 22, 2026
059c885
Update shared FAQ and help while preserving newer website guidance
xrpbanks Sep 22, 2026
5b2e5d2
Document verified changes and a reversible live WordPress patch
xrpbanks Sep 22, 2026
affbd7b
Test updated FAQ and help against live website guidance
xrpbanks Sep 22, 2026
956b630
Recognize plant drinks separately from raw grains
xrpbanks Sep 22, 2026
8e87ebf
Use plant drinks as liquid in porridge suggestions
xrpbanks Sep 22, 2026
4d7984b
Regression test drink comparisons and recipe ingredient roles
xrpbanks Sep 22, 2026
2190851
Keep comparison and recipe guidance explicitly non-medical
xrpbanks Sep 22, 2026
4d59c47
Unify floating app controls and retain non-medical help guidance
xrpbanks Sep 22, 2026
1889705
Verify docked maximize and minimize controls preserve focus behavior
xrpbanks Sep 22, 2026
81d4230
Record verified live release, limitations and reversible website updates
xrpbanks Sep 22, 2026
6df3b7e
Improve food navigation, world recipe choices and explicit portion lo…
xrpbanks Sep 22, 2026
37f5bfd
Record live app release and prepare compatible help guidance
xrpbanks Sep 22, 2026
030a7a4
Remove legacy trading providers from CAL guide fallback
xrpbanks Sep 22, 2026
b3c2cf5
Refresh FAQ replacement copy for current CalorieApp scope
xrpbanks Sep 22, 2026
69b680f
Use Bithomp for consolidation wallet explorer
xrpbanks Sep 22, 2026
d6cbf57
Clarify voluntary donation scope
xrpbanks Sep 22, 2026
3b212c0
Include Showcases cleanup in final WordPress preparation
xrpbanks Sep 22, 2026
f17496a
Reconcile FAQ and donation copy against current live Site Style data
xrpbanks Sep 22, 2026
1a318fa
Reconcile CAL guide fallback against current live menu controller
xrpbanks Sep 22, 2026
4ee6be3
Preserve exact live tokenomics controller in final WordPress source
xrpbanks Sep 22, 2026
7c89727
Restore tested targeted WordPress asset source
xrpbanks Sep 22, 2026
137f522
Restore tested targeted WordPress asset source
xrpbanks Sep 22, 2026
e4e7d59
Preserve live Blog consent helper behavior
xrpbanks Sep 22, 2026
06337c5
Align request-limit test with current profile routes
xrpbanks Sep 22, 2026
f40eecc
Align rate-policy test with current profile routes
xrpbanks Sep 22, 2026
2be0d9a
Align FoodCard display tests with current component dependencies
xrpbanks Sep 22, 2026
0e18040
Align Testnet entry test with install guide
xrpbanks Sep 22, 2026
d3878f2
Keep rate-policy test scoped to exposed public routes
xrpbanks Sep 22, 2026
5f17662
Complete Nutri-Score FoodCard test dependencies
xrpbanks Sep 22, 2026
f89ab9a
Test current visible X fallback guidance
xrpbanks Sep 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
17 changes: 17 additions & 0 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Project continuity

- Keep the currently deployed CalorieApp stable; changes to a new surface should
not silently deploy unrelated draft backend, identity or database work.
- CalorieVerse is one continuously growing world. Preserve the original meadow,
starter identity, stable content IDs and earned progress. Internal schema
migrations must not create a replacement game or require a user reset.
- Read `docs/CALORIEVERSE_LIVE_CHECKPOINT.md` before continuing CalorieVerse. The
larger architecture and built simulator/Studio/F&B modules are preserved in
PR #150 at `f8711ee`; do not repeat or discard that work.
- Reuse the shared display-language provider and eleven-locale registry.
- Ordinary exploration never requires a wallet, node, storage, compute or rewards.
Those roles need separate opt-in, resource limits, pause/resume/full stop.
- Local guest game state is not verified reward evidence. Keep private identity,
food logs and credentials outside public participant storage/compute.
- Preserve deferred architecture/governance decisions in repository documents;
never record secrets or temporary chat credentials.
39 changes: 16 additions & 23 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,7 @@ jobs:
python tools/sync_identity_contracts.py --check
python -m unittest tools.tests.test_identity_contracts
python -m unittest tools.tests.test_localization_contracts
python -m unittest tools.tests.test_build_total_review_package

- name: Test mobile, offline custody and tracked-secret guards
run: |
Expand All @@ -76,7 +77,10 @@ jobs:
run: find wordpress-plugins -type f -name '*.php' -print0 | xargs -0 -n1 php -l

- name: Validate standalone Site Style package
run: node --test tools/tests/wordpress_site_style_package.test.mjs tools/tests/wordpress_app_origin.test.mjs
run: node --test tools/tests/wordpress_site_style_package.test.mjs tools/tests/wordpress_app_origin.test.mjs tools/tests/wordpress_cookie_controls.test.mjs

- name: Test read-only Site Style review inventory
run: php tools/tests/wordpress_site_style_review.test.php

- name: Test legal footer compatibility
shell: bash
Expand Down Expand Up @@ -134,6 +138,11 @@ jobs:
- name: Build and inspect release archive
run: python tools/build_wordpress_plugin_release.py

- name: Build and verify Site Style release
run: |
python -m unittest tools.tests.test_build_site_style_release
python tools/build_site_style_release.py

backend-tests:
name: Backend tests (Python 3.11)
runs-on: ubuntu-latest
Expand Down Expand Up @@ -304,34 +313,18 @@ jobs:
working-directory: frontend
run: npm ci

- name: Audit frontend production dependencies
- name: Audit frontend runtime and development dependencies
working-directory: frontend
run: npm audit --omit=dev --audit-level=critical
run: npm audit --audit-level=high

- name: Lint frontend
working-directory: frontend
run: npm run lint

- name: Test embedded login and private account controls
run: >-
node --test
tools/tests/auth_callback_return.test.mjs
tools/tests/account_data_import_ui.test.mjs
tools/tests/account_data_export_validation.test.mjs
tools/tests/account_erasure_ui.test.mjs
tools/tests/account_privacy_locales.test.mjs
tools/tests/account_privacy_display.test.mjs
tools/tests/display_language_protocol.test.mjs
tools/tests/display_language_ui.test.mjs
tools/tests/testnet_entry.test.mjs
tools/tests/backend_proxy_logout_fallback.test.mjs
tools/tests/backend_warmup_rate_limit.test.mjs
tools/tests/calorieapp_embed_readiness.test.mjs
tools/tests/food_logging_ui.test.mjs
tools/tests/food_search_deadline.test.mjs
tools/tests/identity_locales.test.mjs
tools/tests/xaman_logout_request.test.mjs
tools/tests/xaman_login_start_retry.test.mjs
- name: Test all frontend and WordPress user flows
# Discover new test files automatically so follow-up checks cannot be
# forgotten in a manually maintained list.
run: node --test tools/tests/*.test.mjs

- name: Build frontend
working-directory: frontend
Expand Down
124 changes: 124 additions & 0 deletions .github/workflows/food-ux-isolated-check.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,124 @@
name: Food UX isolated check

on:
push:
branches: [repair/food-ux-integration-20260915]
pull_request:
branches: [herstel/vervolg-20260915]
paths:
- 'frontend/**'
- 'backend/app/**'
- 'backend/tests/**'
- 'wordpress-plugins/calorieapp-account-profile/**'
- 'backend/app/schemas.py'
- 'backend/app/services/open_food_facts.py'
- 'backend/tests/test_food_log_view.py'
- 'backend/tests/test_open_food_facts_normalization.py'
- 'tools/tests/**'
- 'tools/build_heading_repair_release.py'
- 'wordpress-plugins/calorietoken-heading-repair/**'
- '.github/workflows/food-ux-isolated-check.yml'

permissions:
contents: read

concurrency:
group: food-ux-isolated-${{ github.ref }}
cancel-in-progress: true

jobs:
verify:
runs-on: ubuntu-latest
timeout-minutes: 12
env:
NEXT_TELEMETRY_DISABLED: '1'
CI: 'true'
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- uses: actions/setup-node@v4
with:
node-version: '22'
- uses: actions/setup-python@v5
with:
python-version: '3.12'
- name: Record the source under test
run: |
mkdir -p ux-check-evidence
git rev-parse HEAD > ux-check-evidence/verified-commit.txt
git rev-parse 'HEAD^{tree}' > ux-check-evidence/verified-tree.txt
git archive --format=tar.gz -o ux-check-evidence/verified-source.tar.gz HEAD
- name: Install locked dependencies and test tools
run: |
npm ci --prefix frontend --no-audit --no-fund
python -m pip install -r backend/requirements.txt 'playwright==1.57.0'
python -m playwright install --with-deps chromium
- name: Full regression suite and production build
shell: bash
run: |
set -euo pipefail
node --test tools/tests/*.test.mjs 2>&1 | tee ux-check-evidence/regressions.log
PYTHONPATH=backend python -m pytest -q \
backend/tests/test_account_profile.py \
backend/tests/test_account_data_export.py \
backend/tests/test_account_data_import.py \
backend/tests/test_account_erasure.py \
backend/tests/test_database.py \
backend/tests/test_identity_endpoints.py \
backend/tests/test_inactive_account_erasure_execution.py \
backend/tests/test_food_log_view.py \
backend/tests/test_open_food_facts_normalization.py \
2>&1 | tee ux-check-evidence/backend-food-tests.log
python -m unittest tools.tests.test_build_heading_repair_release 2>&1 | tee ux-check-evidence/heading-release-tests.log
find wordpress-plugins/calorietoken-heading-repair -type f -name '*.php' -print0 \
| xargs -0 -n1 php -l 2>&1 | tee ux-check-evidence/heading-php-lint.log
php -l wordpress-plugins/calorieapp-account-profile/calorieapp-account-profile.php
php wordpress-plugins/calorieapp-account-profile/tests/profile-test.php
python tools/build_heading_repair_release.py \
--output-dir ux-check-evidence/heading-release \
2>&1 | tee ux-check-evidence/heading-release.log
cd frontend
./node_modules/.bin/tsc --noEmit 2>&1 | tee ../ux-check-evidence/typecheck.log
npm run build 2>&1 | tee ../ux-check-evidence/build.log
- name: Production-browser check with synthetic backend only
shell: bash
run: |
set -euo pipefail
npm run start --prefix frontend -- --hostname 127.0.0.1 --port 3100 > ux-check-evidence/server.log 2>&1 &
server_pid=$!
trap 'kill "$server_pid" 2>/dev/null || true' EXIT
for i in $(seq 1 30); do curl --silent --fail http://127.0.0.1:3100/ > /dev/null && break; sleep 1; done
curl --silent --fail http://127.0.0.1:3100/ > /dev/null
# Collect every independent browser result even if one flow fails.
browser_failed=0
python tools/tests/browser_food_ux.py 2>&1 | tee ux-check-evidence/browser.log || browser_failed=1
python tools/tests/browser_account_profile.py 2>&1 | tee ux-check-evidence/account-profile-browser.log || browser_failed=1
python tools/tests/browser_account_guides.py 2>&1 | tee ux-check-evidence/account-guides-browser.log || browser_failed=1
HEADING_NUTRITION_EVIDENCE_DIR=ux-check-evidence/heading-nutrition-browser \
python tools/tests/browser_heading_nutrition.py \
2>&1 | tee ux-check-evidence/heading-nutrition-browser.log || browser_failed=1
test "$browser_failed" -eq 0
python - <<'PY'
import json
from pathlib import Path
profile=json.loads(Path('ux-check-evidence/account-profile-browser/report.json').read_text())
assert profile['status']=='passed' and not profile['errors'] and len(profile['checks'])>=40, profile
r=json.loads(Path('ux-check-evidence/browser/report.json').read_text())
assert r['status']=='passed' and not r['errors'], r
assert len(r['checks']) >= 55 and len(r['writes']) == 1, r
h=json.loads(Path('ux-check-evidence/heading-nutrition-browser/report.json').read_text())
assert h['status']=='passed' and not h['errors'], h
assert len(h['checks']) >= 57, h
a=json.loads(Path('ux-check-evidence/account-guides-browser/report.json').read_text())
assert a['status']=='passed' and not a['errors'] and not a['unexpected_requests'], a
assert len(a['checks']) >= 40 and a['faucet_requests']==1, a
PY
- name: Retain test evidence (no publication or deployment)
if: always()
uses: actions/upload-artifact@v4
with:
name: food-ux-browser-evidence
path: ux-check-evidence/
retention-days: 3
if-no-files-found: error
52 changes: 52 additions & 0 deletions .github/workflows/wordpress-content-check.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
name: WordPress content styling check
on:
push:
branches: [repair/food-ux-integration-20260915]
paths:
- 'wordpress-plugins/calorietoken-heading-repair/**'
- 'tools/tests/browser_wordpress_content.py'
- 'tools/tests/fixtures/wordpress-content/**'
- '.github/workflows/wordpress-content-check.yml'
pull_request:
branches: [herstel/vervolg-20260915]
paths:
- 'wordpress-plugins/calorietoken-heading-repair/**'
- 'tools/tests/browser_wordpress_content.py'
- 'tools/tests/fixtures/wordpress-content/**'
- '.github/workflows/wordpress-content-check.yml'
permissions:
contents: read
concurrency:
group: wordpress-content-${{ github.ref }}
cancel-in-progress: true
jobs:
verify:
runs-on: ubuntu-latest
timeout-minutes: 8
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- uses: actions/setup-python@v5
with:
python-version: '3.12'
- name: Install isolated browser tools
run: |
python -m pip install 'playwright==1.57.0'
python -m playwright install --with-deps chromium
- name: Verify package and render public-content fixtures
run: |
mkdir -p ux-check-evidence
git rev-parse HEAD > ux-check-evidence/verified-commit.txt
git rev-parse 'HEAD^{tree}' > ux-check-evidence/verified-tree.txt
php -l wordpress-plugins/calorietoken-heading-repair/calorietoken-heading-repair.php
python -m unittest tools.tests.test_build_heading_repair_release
python tools/build_heading_repair_release.py --output-dir ux-check-evidence/heading-release
python tools/tests/browser_wordpress_content.py
- name: Retain preview and verification evidence
if: always()
uses: actions/upload-artifact@v4
with:
name: wordpress-content-style-evidence
path: ux-check-evidence/
retention-days: 5
26 changes: 26 additions & 0 deletions DATA_LICENSING.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,32 @@ The current frontend bundles three dated reference-food records from USDA FoodDa

The interface does not silently combine alternative energy methods, treat missing data as measured zero, or import these examples into a private diary. USDA reference provenance remains separate from Open Food Facts licensing and private user records. External names and marks retain their own rights.

## USDA search catalogue — live since 15 September 2026

The food-discovery continuation adds a separate, dated snapshot in
`frontend/public/data/usda-search-foods.json`: 363 Foundation records from April
2026 and 7,793 SR Legacy records from April 2018. It does not claim to cover all
FoodData Central collections. The original three-food reference remains intact.

The catalogue preserves FDC identifiers, English source descriptions, collection,
edition, nutrient units and original numeric precision. Its source manifest records
the original download URLs and archive SHA-256 values. The builder is
`tools/build_usda_search_catalog.py`; the catalogue is kept separate from OFF data.
FoodData Central's official [download page](https://fdc.nal.usda.gov/download-datasets/)
and [documentation](https://fdc.nal.usda.gov/data-documentation/) describe these
collections and reuse conditions.

The browser requests one fixed first-party catalogue file only after a USDA
search is submitted. Search matching then runs locally; no search phrase or
account identifier is sent to USDA. Opening a source link visits USDA separately.
Saving requires the existing explicit portion confirmation and authenticated
backend route. The diary entry retains the USDA source, FDC identifier and chosen
gram basis; it has no fabricated barcode or Nutri-Score.

Name-based alternatives help visitors inspect other records. They are not
personalised nutrition recommendations, allergen checks or claims of healthier
equivalence. The visitor must check the actual label, preparation and portion.

## User and identity data

Authentication identifiers and food logs are application data, not assets
Expand Down
16 changes: 14 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,14 +31,26 @@ Current application stack:
- Frontend: Next.js + TypeScript + Tailwind
- Backend: FastAPI + SQLModel
- Data: SQLite for local development and tests; PostgreSQL is required for live user data
- External food data: Open Food Facts search adapter; a separate three-food USDA reference selection
- External food data: Open Food Facts search adapter; a dated USDA search catalogue and separate reference selection
- Identity/authentication: server-side identity flow with session cookies

### Live food-discovery update — 15 September 2026

The live continuation adds a separate search of 8,156 dated USDA Foundation
and SR Legacy records, an edible-gram preview, and optional similar-name food
choices. Interface text covers the existing eleven display languages. Selecting
a food opens the existing portion confirmation; it does not save automatically.
The existing barcode flow is preserved. App commit `40ed5f4` was deployed and
the new flow was checked live in all eleven interface languages. CalorieHelp
now explains these steps on the website. See the
[feature and validation record](docs/public/food-discovery-2026-09.md) and
[CalorieHelp update](docs/public/caloriehelp-2026-09.md).

## Current Status

### Implemented in the repository (V2 completion in progress)

The latest website package and app journey still need live owner acceptance. Current source additions include eleven-language UI synchronization, startup/rate-limit feedback, diary filtering, attributed USDA reference foods and a Testnet-guide link. Historical page translations are only partly complete; see the [dated scope and verification record](docs/public/website-update-2026-09.md).
The food-discovery update and targeted CalorieHelp update are live. Complete mobile website acceptance and updated campaign material remain open. Existing capabilities include eleven-language UI synchronization, startup/rate-limit feedback, diary filtering, dated USDA search and reference foods, comparable-food choices and a Testnet-guide link. Historical page translations are only partly complete; see the [dated scope and verification record](docs/public/website-update-2026-09.md).

- Food search via backend integration with Open Food Facts
- Nutrition result display in the web UI
Expand Down
13 changes: 13 additions & 0 deletions THIRD_PARTY_NOTICES.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,3 +27,16 @@ source-clearance work are recorded in
`DATA_LICENSING.md`.

The standalone WordPress Site Style component in `wordpress-plugins/calorietoken-site-style/` also declares GPL-2.0-or-later. Its packaged licence applies to its code. Historical site images/fonts remain references to the existing site and retain their original rights; they are not granted a new licence here. The display-language runtime is shared with CalorieApp.

The optional-on-use food barcode decoder bundles `@zxing/browser` 0.1.5 (MIT),
`@zxing/library` 0.21.3 (Apache-2.0, with its included additional notices), and
`ts-custom-error` as resolved in the lockfile (MIT). Complete upstream texts
are retained at `frontend/public/barcode-licenses.txt`, served with the app.
The libraries decode locally; no CDN service or external image processing is
used. This does not relicense the surrounding CalorieApp or brand.

The ZXing library's npm metadata says MIT, while its shipped LICENSE retains
Apache-2.0 and additional upstream notices. This release preserves that full
file and does not treat the metadata as a blanket relicense. The optional
`@zxing/text-encoding` 0.9.0 dependency's complete LICENSE.md is retained too;
it identifies its public-domain/Apache-2.0 terms and Encoding Standard material.
19 changes: 19 additions & 0 deletions backend/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -87,3 +87,22 @@ migration or verified restore.
later without paywalling identity or personal-data rights.
- Open Food Facts is consumed only by backend service endpoints and is the
current adapter, not the canonical or exclusive food-data model.


### Public product search

Name searches use Open Food Facts' indexed Search-a-licious API. The request is
read-only, sends only literal product-name text and requested nutrition/display
fields, and supports the application's eleven display languages. One bounded
legacy CGI transport fallback is allowed after a transport or invalid-response
failure, never after a provider HTTP rejection (including 429/503). Barcode
lookup continues to use the exact v3 product endpoint and GTIN verification.

Successful results are cached for one hour in a 256-entry process-local cache.
Case and repeated whitespace share one name-search key. A cached answer remains
available during a provider cooldown, without another source request. Empty or
failed responses are not cached. The cache is lost on restart; it is not a local
copy of the complete OFF database. Existing shared PostgreSQL egress quotas,
queue limits, duplicate coalescing and Retry-After pauses remain in force.

Source documentation: https://openfoodfacts.github.io/search-a-licious/users/ref-openapi/
Loading
Loading