opticparse-python / raw_snapshot.txt
OpticParse Deployer
deploy python api with HF metadata [isolated]
21cc58e
Raw History Blame Contribute Delete
4.71 kB
=== SECTION 1: CURRENT CODEBASE STATE ===
Git Log:
477bcd1 fix(docs): add missing sitemap links and Cloudflare analytics beacons
728d0b2 feat(opticparse): add dedicated PhishVision landing page and update navigation
e3c1d7e fix(opticparse): correct PhishVision Render URL back to opticparse-1opticparse-node-sg
42891ce feat: implement interactive playground, add api-docs.html, fix Render and Lemon Squeezy URLs
048c457 fix: requirements.txt encoding for render deployment
40d81a9 security: dependency audit, usage enforcement, CORS hardening, security headers
7a4dc47 security: rate limiting, log sanitization, browser hardening
b24763c security: SSRF protection, input validation, webhook signature verification
1a3476a fix(opticparse): change default wait_until from networkidle to load to prevent crashes on heavy JS sites
1c68d37 fix(phishvision): return full forensic JSON from phish-detect instead of verdict string
Git Status:
On branch main
Your branch is up to date with 'origin/main'.
Untracked files:
(use "git add <file>..." to include in what will be committed)
benchmark_final.json
benchmark_final_run.py
generate_snapshot.py
raw_snapshot.txt
nothing added to commit but untracked files present (use "git add" to track)
Lines of Code:
py: 3988 lines
ts: 1419 lines
js: 149 lines
jsx: 717 lines
html: 1368 lines
Total: 7641 lines
=== SECTION 2: LIVE ENDPOINT STATUS ===
βœ… GET /health β†’ 200 (0.4s)
Body: {"status":"ok","service":"opticparse","version":"1.0.0"}
❌ GET /health β†’ 404
Error: Not Found
❌ POST /api/phish-detect β†’ 404
Error: Not Found
=== SECTION 3: SECURITY FEATURES STATUS ===
βœ… SSRF isSafeUrl (Node)
βœ… SSRF url validation (Python)
βœ… Input validation ScrapeRequest
βœ… API key format check (op_live_)
βœ… Rate limiting (Python slowapi)
βœ… Rate limiting (Node express-rate-limit)
βœ… Trust proxy (Node)
βœ… Webhook HMAC verification
βœ… CORS middleware (Python)
βœ… Helmet security headers (Node)
βœ… Browser hardening args (Node)
βœ… Browserless integration
βœ… Graceful DB fallback
❌ AI Gateway URLs
βœ… Usage limit enforcement
βœ… PhishVision full JSON response
βœ… wait_until load default
Overall: ❌ SOME CHECKS FAILED
=== SECTION 4: ENVIRONMENT & CONFIG CHECK ===
βœ… server.py
βœ… requirements.txt
βœ… Dockerfile
βœ… render.yaml
βœ… opticparse-js/src/phish-server.ts
βœ… opticparse-js/package.json
βœ… dashboard/src/App.jsx
βœ… dashboard/.env.production
βœ… docs/index.html
βœ… docs/privacy.html
βœ… docs/terms.html
βœ… docs/404.html
βœ… docs/sitemap.xml
βœ… docs/robots.txt
βœ… docs/_headers
βœ… supabase/migrations/001_initial_schema.sql
βœ… supabase/migrations/002_rls_watches_monitors.sql
=== render.yaml Environment Variables ===
- BROWSERLESS_API_KEY
- CLOUDFLARE_AI_GATEWAY_ACCOUNT_ID
- DATABASE_URL
- GROQ_API_KEY
- NODE_ENV
- OPENROUTER_KEY
- OPTICPARSE_API_KEY
- PORT
- RAPIDAPI_PROXY_SECRET
- REDIS_URL
- SUPABASE_SERVICE_KEY
- SUPABASE_URL
=== SECTION 5: DEPENDENCY SECURITY ===
Python audit:
'pip-audit' is not recognized as an internal or external command,
operable program or batch file.
Node audit (opticparse-js):
'Select-Object' is not recognized as an internal or external command,
operable program or batch file.
Dashboard audit:
'Select-Object' is not recognized as an internal or external command,
operable program or batch file.
=== SECTION 6: LANDING PAGE AUDIT ===
βœ… No GPT-4o claim
βœ… opticparse.com domain used
βœ… Dashboard link correct
βœ… Privacy policy linked
βœ… Terms of service linked
βœ… LemonSqueezy checkout URL
βœ… No 2s false claim
βœ… No RapidAPI buttons
βœ… Schema accuracy stat
βœ… Copyright 2026
βœ… Google verification tag
βœ… Cloudflare analytics
βœ… Open Graph tags
βœ… Twitter card tags
βœ… DNS prefetch tags
βœ… PhishVision mentioned
βœ… Sitemap linked
Overall: ALL PASS
=== SECTION 7: DATABASE SECURITY ===
βœ… RLS on users: ENFORCED
βœ… RLS on api_keys: ENFORCED
=== SECTION 8: WHAT IS MISSING/TODO ===
❌ Bank account: No Indian bank account β€” blocks payments
❌ LemonSqueezy live mode: Test mode only β€” no real payments
❌ MCA Incorporation: Not incorporated β€” blocks govt grants
❌ DPIIT Recognition: Needs incorporation first
❌ Twitter/X account: No social media presence
❌ First blog post: No content marketing yet
❌ ProductHunt preparation: Not started
❌ First paying customer: Zero revenue
❌ AWS Activate: Application pending β€” email issue
❌ Google Cloud Startups: Not submitted yet
❌ NVIDIA Inception: Needs incorporation
❌ Payment security prompt: Deferred until LemonSqueezy live