Skip to content

[VibeDash dc249cfe] Prototype data and duplicate scaffolding remain user-visible - #3

Draft
rapidstartup wants to merge 1 commit into
mainfrom
codex/vibedash-dc249cfe-18aa-420c-b1db-0e22d5cdfda7-a749fc99-4b64-4a9f-8374-1aec8646eb7a
Draft

rapidstartup wants to merge 1 commit into
mainfrom
codex/vibedash-dc249cfe-18aa-420c-b1db-0e22d5cdfda7-a749fc99-4b64-4a9f-8374-1aec8646eb7a

Conversation

@rapidstartup

Copy link
Copy Markdown
Owner

Removed prototype data and duplicate signaling scaffolding; widget data now uses authenticated APIs, while unavailable call history is clearly disabled.

VibeDash task: dc249cfe-18aa-420c-b1db-0e22d5cdfda7
Runner: House Codex — gpt-5.6-luna / xhigh

Validation:

  • passed: git diff --check — Passed.
  • not_run: npm run lint — npm is unavailable in the sandbox.
  • not_run: npm run build — npm is unavailable in the sandbox.

This PR was opened as a draft for human review.

@bolt-new-by-stackblitz

Copy link
Copy Markdown

Review PR in StackBlitz Codeflow Run & review this pull request in StackBlitz Codeflow.

@netlify

netlify Bot commented Jul 17, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for zesty-pavlova-54b539 ready!

Name Link
🔨 Latest commit 090a7b4
🔍 Latest deploy log https://app.netlify.com/projects/zesty-pavlova-54b539/deploys/6a5a91896b88c300084d6062
😎 Deploy Preview https://deploy-preview-3--zesty-pavlova-54b539.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@rapidstartup rapidstartup left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

VibeDash Codex Agent Reviewer

The authoritative API integration remains broken for mobile users, and SIP webhook configuration still targets an unreachable handler.

Recommendation: changes requested
Risk: high
Model: gpt-5.6-sol

Findings

  • HIGH — Mobile widget loading cannot authenticate
    The new widget request uses the token from mobile sign-in, but sign-in always stores the literal mock-jwt-token. The backend validates tokens through Supabase, so every mobile widget request receives 401.
    Evidence: mobile/services/api.ts, fetchWidgets lines 14-27; mobile/contexts/AuthContext.tsx, signIn lines 54-71; server/middleware/auth.ts, authenticateUser lines 10-20.
  • MEDIUM — SIP webhook configuration has no reachable handler
    WidgetCreator posts configuration to /api/widgets/:id/configure-twilio-webhooks, but Netlify routes this to the widgets function, whose POST branch always attempts widget creation. The matching Express route is never mounted. Consequently SIP widgets are created without automatic webhook configuration.
    Evidence: src/components/WidgetCreator.tsx, handleSubmit lines 79-104; netlify/functions/widgets.ts, POST branch lines 64-78; server/routes/widgets.ts, route at lines 35-70; server/index.ts lines 62-64 mounts only mobile and Twilio routes.

Validation reviewed

  • passed: git diff --check 6607f7c64f19c00522a26605323c6002afbac6e8..090a7b41991f0a3ecc8b5534285e79e0ffb27d8b — No whitespace errors.
  • not_run: npm run build — The sandbox has no npm executable.
  • not_run: npm run lint — The sandbox has no npm executable.
  • not_run: cd mobile && npm run lint — The sandbox has no npm executable.

This agent does not merge or close tasks; final closure remains with a human.

GitHub would not accept the formal request_changes state (commonly because the reviewer owns the PR), so the recommendation is recorded as a comment.

@vibedash-agent vibedash-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

VibeDash Codex Agent Reviewer

The authoritative API integration remains broken for mobile users, and SIP webhook configuration still targets an unreachable handler.

Recommendation: changes requested
Risk: high
Model: gpt-5.6-sol

Findings

  • HIGH — Mobile widget loading cannot authenticate
    The new widget request uses the token from mobile sign-in, but sign-in always stores the literal mock-jwt-token. The backend validates tokens through Supabase, so every mobile widget request receives 401.
    Evidence: mobile/services/api.ts, fetchWidgets lines 14-27; mobile/contexts/AuthContext.tsx, signIn lines 54-71; server/middleware/auth.ts, authenticateUser lines 10-20.
  • MEDIUM — SIP webhook configuration has no reachable handler
    WidgetCreator posts configuration to /api/widgets/:id/configure-twilio-webhooks, but Netlify routes this to the widgets function, whose POST branch always attempts widget creation. The matching Express route is never mounted. Consequently SIP widgets are created without automatic webhook configuration.
    Evidence: src/components/WidgetCreator.tsx, handleSubmit lines 79-104; netlify/functions/widgets.ts, POST branch lines 64-78; server/routes/widgets.ts, route at lines 35-70; server/index.ts lines 62-64 mounts only mobile and Twilio routes.

Validation reviewed

  • passed: git diff --check 6607f7c64f19c00522a26605323c6002afbac6e8..090a7b41991f0a3ecc8b5534285e79e0ffb27d8b — No whitespace errors.
  • not_run: npm run build — The sandbox has no npm executable.
  • not_run: npm run lint — The sandbox has no npm executable.
  • not_run: cd mobile && npm run lint — The sandbox has no npm executable.

This agent does not merge or close tasks; final closure remains with a human.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant