Spaces:
Paused
Paused
OpticParse Deployer commited on
Commit Β·
21cc58e
1
Parent(s): bcf46c3
deploy python api with HF metadata [isolated]
Browse files- audit_log.md +0 -0
- benchmark_final.json +16 -16
- fix.py +3 -36
- raw_snapshot.txt +30 -33
- verify_key.txt +1 -1
audit_log.md
CHANGED
|
Binary files a/audit_log.md and b/audit_log.md differ
|
|
|
benchmark_final.json
CHANGED
|
@@ -1,5 +1,5 @@
|
|
| 1 |
{
|
| 2 |
-
"timestamp": "2026-07-
|
| 3 |
"total_tests": 14,
|
| 4 |
"passed": 7,
|
| 5 |
"failed": 7,
|
|
@@ -9,7 +9,7 @@
|
|
| 9 |
"test": "OpticParse Health",
|
| 10 |
"category": "health",
|
| 11 |
"status": 200,
|
| 12 |
-
"elapsed_s": 0.
|
| 13 |
"passed": true,
|
| 14 |
"details": ""
|
| 15 |
},
|
|
@@ -17,7 +17,7 @@
|
|
| 17 |
"test": "PhishVision Health",
|
| 18 |
"category": "health",
|
| 19 |
"status": 200,
|
| 20 |
-
"elapsed_s": 0.
|
| 21 |
"passed": true,
|
| 22 |
"details": ""
|
| 23 |
},
|
|
@@ -25,7 +25,7 @@
|
|
| 25 |
"test": "HN Basic Extract",
|
| 26 |
"category": "scrape",
|
| 27 |
"status": 401,
|
| 28 |
-
"elapsed_s": 0.
|
| 29 |
"passed": false,
|
| 30 |
"details": "Response size: 36 chars"
|
| 31 |
},
|
|
@@ -33,7 +33,7 @@
|
|
| 33 |
"test": "GitHub Schema Enforce",
|
| 34 |
"category": "scrape",
|
| 35 |
"status": 401,
|
| 36 |
-
"elapsed_s": 0.
|
| 37 |
"passed": false,
|
| 38 |
"details": "Items returned: N/A"
|
| 39 |
},
|
|
@@ -41,7 +41,7 @@
|
|
| 41 |
"test": "ProductHunt SPA",
|
| 42 |
"category": "scrape",
|
| 43 |
"status": 401,
|
| 44 |
-
"elapsed_s": 0.
|
| 45 |
"passed": false,
|
| 46 |
"details": "Response size: 36 chars"
|
| 47 |
},
|
|
@@ -49,15 +49,15 @@
|
|
| 49 |
"test": "HN Cache Hit",
|
| 50 |
"category": "scrape",
|
| 51 |
"status": 401,
|
| 52 |
-
"elapsed_s": 0.
|
| 53 |
"passed": false,
|
| 54 |
-
"details": "Cold: 0.
|
| 55 |
},
|
| 56 |
{
|
| 57 |
"test": "Google.com (Safe)",
|
| 58 |
"category": "phish",
|
| 59 |
"status": 200,
|
| 60 |
-
"elapsed_s":
|
| 61 |
"passed": true,
|
| 62 |
"details": "Verdict: safe, Confidence: 99%"
|
| 63 |
},
|
|
@@ -65,7 +65,7 @@
|
|
| 65 |
"test": "Microsoft.com (Safe)",
|
| 66 |
"category": "phish",
|
| 67 |
"status": 200,
|
| 68 |
-
"elapsed_s": 0.
|
| 69 |
"passed": true,
|
| 70 |
"details": "Verdict: safe, Brand: None"
|
| 71 |
},
|
|
@@ -73,7 +73,7 @@
|
|
| 73 |
"test": "GitHub.com (Safe)",
|
| 74 |
"category": "phish",
|
| 75 |
"status": 200,
|
| 76 |
-
"elapsed_s":
|
| 77 |
"passed": true,
|
| 78 |
"details": "Verdict: safe"
|
| 79 |
},
|
|
@@ -81,7 +81,7 @@
|
|
| 81 |
"test": "SSRF Block (Python)",
|
| 82 |
"category": "security",
|
| 83 |
"status": 401,
|
| 84 |
-
"elapsed_s": 0.
|
| 85 |
"passed": false,
|
| 86 |
"details": "Blocked: False"
|
| 87 |
},
|
|
@@ -89,7 +89,7 @@
|
|
| 89 |
"test": "SSRF Block (Node)",
|
| 90 |
"category": "security",
|
| 91 |
"status": 400,
|
| 92 |
-
"elapsed_s":
|
| 93 |
"passed": true,
|
| 94 |
"details": "Blocked: True"
|
| 95 |
},
|
|
@@ -97,7 +97,7 @@
|
|
| 97 |
"test": "Invalid Input Reject",
|
| 98 |
"category": "security",
|
| 99 |
"status": 401,
|
| 100 |
-
"elapsed_s": 0.
|
| 101 |
"passed": false,
|
| 102 |
"details": ""
|
| 103 |
},
|
|
@@ -105,7 +105,7 @@
|
|
| 105 |
"test": "Missing Fields Reject",
|
| 106 |
"category": "security",
|
| 107 |
"status": 401,
|
| 108 |
-
"elapsed_s": 0.
|
| 109 |
"passed": false,
|
| 110 |
"details": ""
|
| 111 |
},
|
|
@@ -113,7 +113,7 @@
|
|
| 113 |
"test": "Rate Limit Headers",
|
| 114 |
"category": "ratelimit",
|
| 115 |
"status": 200,
|
| 116 |
-
"elapsed_s": 0.
|
| 117 |
"passed": true,
|
| 118 |
"details": "Rate limiting configured in code (slowapi)"
|
| 119 |
}
|
|
|
|
| 1 |
{
|
| 2 |
+
"timestamp": "2026-07-14T12:41:48Z",
|
| 3 |
"total_tests": 14,
|
| 4 |
"passed": 7,
|
| 5 |
"failed": 7,
|
|
|
|
| 9 |
"test": "OpticParse Health",
|
| 10 |
"category": "health",
|
| 11 |
"status": 200,
|
| 12 |
+
"elapsed_s": 0.49,
|
| 13 |
"passed": true,
|
| 14 |
"details": ""
|
| 15 |
},
|
|
|
|
| 17 |
"test": "PhishVision Health",
|
| 18 |
"category": "health",
|
| 19 |
"status": 200,
|
| 20 |
+
"elapsed_s": 0.44,
|
| 21 |
"passed": true,
|
| 22 |
"details": ""
|
| 23 |
},
|
|
|
|
| 25 |
"test": "HN Basic Extract",
|
| 26 |
"category": "scrape",
|
| 27 |
"status": 401,
|
| 28 |
+
"elapsed_s": 0.35,
|
| 29 |
"passed": false,
|
| 30 |
"details": "Response size: 36 chars"
|
| 31 |
},
|
|
|
|
| 33 |
"test": "GitHub Schema Enforce",
|
| 34 |
"category": "scrape",
|
| 35 |
"status": 401,
|
| 36 |
+
"elapsed_s": 0.41,
|
| 37 |
"passed": false,
|
| 38 |
"details": "Items returned: N/A"
|
| 39 |
},
|
|
|
|
| 41 |
"test": "ProductHunt SPA",
|
| 42 |
"category": "scrape",
|
| 43 |
"status": 401,
|
| 44 |
+
"elapsed_s": 0.36,
|
| 45 |
"passed": false,
|
| 46 |
"details": "Response size: 36 chars"
|
| 47 |
},
|
|
|
|
| 49 |
"test": "HN Cache Hit",
|
| 50 |
"category": "scrape",
|
| 51 |
"status": 401,
|
| 52 |
+
"elapsed_s": 0.19,
|
| 53 |
"passed": false,
|
| 54 |
+
"details": "Cold: 0.4s \u2192 Warm: 0.2s (46% faster)"
|
| 55 |
},
|
| 56 |
{
|
| 57 |
"test": "Google.com (Safe)",
|
| 58 |
"category": "phish",
|
| 59 |
"status": 200,
|
| 60 |
+
"elapsed_s": 0.27,
|
| 61 |
"passed": true,
|
| 62 |
"details": "Verdict: safe, Confidence: 99%"
|
| 63 |
},
|
|
|
|
| 65 |
"test": "Microsoft.com (Safe)",
|
| 66 |
"category": "phish",
|
| 67 |
"status": 200,
|
| 68 |
+
"elapsed_s": 0.29,
|
| 69 |
"passed": true,
|
| 70 |
"details": "Verdict: safe, Brand: None"
|
| 71 |
},
|
|
|
|
| 73 |
"test": "GitHub.com (Safe)",
|
| 74 |
"category": "phish",
|
| 75 |
"status": 200,
|
| 76 |
+
"elapsed_s": 0.22,
|
| 77 |
"passed": true,
|
| 78 |
"details": "Verdict: safe"
|
| 79 |
},
|
|
|
|
| 81 |
"test": "SSRF Block (Python)",
|
| 82 |
"category": "security",
|
| 83 |
"status": 401,
|
| 84 |
+
"elapsed_s": 0.36,
|
| 85 |
"passed": false,
|
| 86 |
"details": "Blocked: False"
|
| 87 |
},
|
|
|
|
| 89 |
"test": "SSRF Block (Node)",
|
| 90 |
"category": "security",
|
| 91 |
"status": 400,
|
| 92 |
+
"elapsed_s": 0.23,
|
| 93 |
"passed": true,
|
| 94 |
"details": "Blocked: True"
|
| 95 |
},
|
|
|
|
| 97 |
"test": "Invalid Input Reject",
|
| 98 |
"category": "security",
|
| 99 |
"status": 401,
|
| 100 |
+
"elapsed_s": 0.25,
|
| 101 |
"passed": false,
|
| 102 |
"details": ""
|
| 103 |
},
|
|
|
|
| 105 |
"test": "Missing Fields Reject",
|
| 106 |
"category": "security",
|
| 107 |
"status": 401,
|
| 108 |
+
"elapsed_s": 0.24,
|
| 109 |
"passed": false,
|
| 110 |
"details": ""
|
| 111 |
},
|
|
|
|
| 113 |
"test": "Rate Limit Headers",
|
| 114 |
"category": "ratelimit",
|
| 115 |
"status": 200,
|
| 116 |
+
"elapsed_s": 0.26,
|
| 117 |
"passed": true,
|
| 118 |
"details": "Rate limiting configured in code (slowapi)"
|
| 119 |
}
|
fix.py
CHANGED
|
@@ -1,36 +1,3 @@
|
|
| 1 |
-
|
| 2 |
-
|
| 3 |
-
|
| 4 |
-
html_files = []
|
| 5 |
-
for root, dirs, files in os.walk('docs'):
|
| 6 |
-
for f in files:
|
| 7 |
-
if f.endswith('.html'):
|
| 8 |
-
html_files.append(os.path.join(root, f))
|
| 9 |
-
|
| 10 |
-
for f in html_files:
|
| 11 |
-
with open(f, 'r', encoding='utf-8') as file:
|
| 12 |
-
content = file.read()
|
| 13 |
-
|
| 14 |
-
# fix noopener
|
| 15 |
-
content = content.replace('rel="noopener noreferrer"', '')
|
| 16 |
-
content = re.sub(r'<a([^>]*?)target="_blank"([^>]*?)>', r'<a\1target="_blank" rel="noopener noreferrer"\2>', content)
|
| 17 |
-
|
| 18 |
-
# fix viewport in google_verification.html
|
| 19 |
-
if 'google_verification.html' in f:
|
| 20 |
-
if '<meta name="viewport"' not in content:
|
| 21 |
-
content = content.replace('<head>', '<head>\n <meta name="viewport" content="width=device-width, initial-scale=1">')
|
| 22 |
-
if '<html' in content and 'lang=' not in content:
|
| 23 |
-
content = content.replace('<html', '<html lang="en"')
|
| 24 |
-
|
| 25 |
-
with open(f, 'w', encoding='utf-8') as file:
|
| 26 |
-
file.write(content)
|
| 27 |
-
|
| 28 |
-
# fix index.css
|
| 29 |
-
css_file = 'dashboard/src/index.css'
|
| 30 |
-
with open(css_file, 'r', encoding='utf-8') as file:
|
| 31 |
-
css_content = file.read()
|
| 32 |
-
css_content = css_content.replace('user-select: none;', '-webkit-user-select: none;\n user-select: none;')
|
| 33 |
-
with open(css_file, 'w', encoding='utf-8') as file:
|
| 34 |
-
file.write(css_content)
|
| 35 |
-
|
| 36 |
-
print("HTML/CSS Fixes done!")
|
|
|
|
| 1 |
+
content = open('server.py', encoding='utf-8').read()
|
| 2 |
+
content = content.replace('\\nif __name__ == "__main__":', '\nif __name__ == "__main__":')
|
| 3 |
+
open('server.py', 'w', encoding='utf-8').write(content)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
raw_snapshot.txt
CHANGED
|
@@ -1,50 +1,46 @@
|
|
| 1 |
=== SECTION 1: CURRENT CODEBASE STATE ===
|
| 2 |
Git Log:
|
| 3 |
-
|
| 4 |
-
|
| 5 |
-
|
| 6 |
-
|
| 7 |
-
|
| 8 |
-
|
| 9 |
-
|
| 10 |
-
|
| 11 |
-
|
| 12 |
-
|
| 13 |
|
| 14 |
Git Status:
|
| 15 |
-
On branch
|
| 16 |
-
Your branch is up to date with 'origin/
|
| 17 |
-
|
| 18 |
-
Changes not staged for commit:
|
| 19 |
-
(use "git add <file>..." to update what will be committed)
|
| 20 |
-
(use "git restore <file>..." to discard changes in working directory)
|
| 21 |
-
modified: fix.py
|
| 22 |
-
modified: raw_snapshot.txt
|
| 23 |
-
modified: verify_key.txt
|
| 24 |
|
| 25 |
Untracked files:
|
| 26 |
(use "git add <file>..." to include in what will be committed)
|
| 27 |
-
|
| 28 |
-
|
| 29 |
-
|
|
|
|
| 30 |
|
| 31 |
-
|
| 32 |
|
| 33 |
Lines of Code:
|
| 34 |
-
py:
|
| 35 |
-
ts:
|
| 36 |
js: 149 lines
|
| 37 |
-
jsx:
|
| 38 |
-
html:
|
| 39 |
-
Total:
|
| 40 |
|
| 41 |
=== SECTION 2: LIVE ENDPOINT STATUS ===
|
| 42 |
-
β
GET /health β 200 (0.5s)
|
| 43 |
-
Body: {"status":"ok","service":"opticparse","version":"1.0.0"}
|
| 44 |
β
GET /health β 200 (0.4s)
|
| 45 |
-
Body: {"status":"ok","service":"
|
| 46 |
-
|
| 47 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
| 48 |
|
| 49 |
=== SECTION 3: SECURITY FEATURES STATUS ===
|
| 50 |
β
SSRF isSafeUrl (Node)
|
|
@@ -95,6 +91,7 @@ Overall: β SOME CHECKS FAILED
|
|
| 95 |
- OPENROUTER_KEY
|
| 96 |
- OPTICPARSE_API_KEY
|
| 97 |
- PORT
|
|
|
|
| 98 |
- REDIS_URL
|
| 99 |
- SUPABASE_SERVICE_KEY
|
| 100 |
- SUPABASE_URL
|
|
|
|
| 1 |
=== SECTION 1: CURRENT CODEBASE STATE ===
|
| 2 |
Git Log:
|
| 3 |
+
477bcd1 fix(docs): add missing sitemap links and Cloudflare analytics beacons
|
| 4 |
+
728d0b2 feat(opticparse): add dedicated PhishVision landing page and update navigation
|
| 5 |
+
e3c1d7e fix(opticparse): correct PhishVision Render URL back to opticparse-1opticparse-node-sg
|
| 6 |
+
42891ce feat: implement interactive playground, add api-docs.html, fix Render and Lemon Squeezy URLs
|
| 7 |
+
048c457 fix: requirements.txt encoding for render deployment
|
| 8 |
+
40d81a9 security: dependency audit, usage enforcement, CORS hardening, security headers
|
| 9 |
+
7a4dc47 security: rate limiting, log sanitization, browser hardening
|
| 10 |
+
b24763c security: SSRF protection, input validation, webhook signature verification
|
| 11 |
+
1a3476a fix(opticparse): change default wait_until from networkidle to load to prevent crashes on heavy JS sites
|
| 12 |
+
1c68d37 fix(phishvision): return full forensic JSON from phish-detect instead of verdict string
|
| 13 |
|
| 14 |
Git Status:
|
| 15 |
+
On branch main
|
| 16 |
+
Your branch is up to date with 'origin/main'.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 17 |
|
| 18 |
Untracked files:
|
| 19 |
(use "git add <file>..." to include in what will be committed)
|
| 20 |
+
benchmark_final.json
|
| 21 |
+
benchmark_final_run.py
|
| 22 |
+
generate_snapshot.py
|
| 23 |
+
raw_snapshot.txt
|
| 24 |
|
| 25 |
+
nothing added to commit but untracked files present (use "git add" to track)
|
| 26 |
|
| 27 |
Lines of Code:
|
| 28 |
+
py: 3988 lines
|
| 29 |
+
ts: 1419 lines
|
| 30 |
js: 149 lines
|
| 31 |
+
jsx: 717 lines
|
| 32 |
+
html: 1368 lines
|
| 33 |
+
Total: 7641 lines
|
| 34 |
|
| 35 |
=== SECTION 2: LIVE ENDPOINT STATUS ===
|
|
|
|
|
|
|
| 36 |
β
GET /health β 200 (0.4s)
|
| 37 |
+
Body: {"status":"ok","service":"opticparse","version":"1.0.0"}
|
| 38 |
+
β GET /health β 404
|
| 39 |
+
Error: Not Found
|
| 40 |
+
|
| 41 |
+
β POST /api/phish-detect β 404
|
| 42 |
+
Error: Not Found
|
| 43 |
+
|
| 44 |
|
| 45 |
=== SECTION 3: SECURITY FEATURES STATUS ===
|
| 46 |
β
SSRF isSafeUrl (Node)
|
|
|
|
| 91 |
- OPENROUTER_KEY
|
| 92 |
- OPTICPARSE_API_KEY
|
| 93 |
- PORT
|
| 94 |
+
- RAPIDAPI_PROXY_SECRET
|
| 95 |
- REDIS_URL
|
| 96 |
- SUPABASE_SERVICE_KEY
|
| 97 |
- SUPABASE_URL
|
verify_key.txt
CHANGED
|
@@ -1 +1 @@
|
|
| 1 |
-
|
|
|
|
| 1 |
+
7a1d6830-3492-4fff-8214-8ad30aec733d|op_live_8f42ac75238f81ddcb9658eba170421b2eea28a3ee8f68d8
|