Conversation
Extends the existing CrawlProof MCP server (/api/mcp) with the autoblog and link-exchange engine that the dashboard drives by hand, so an agent holding a crp_ token can drive it too. New lib/mcp/autoblog.ts, registered alongside the promote/stats/audits/leads modules. Tools: - autoblog_sites — the caller's autoblog sites, ids and status. - autoblog_post — queue an article on one of them (topic from its own plan). - autoblog_guest_post — request a guest post from the caller's site to another, mirroring the dashboard route's dedupe (generated reported, failed retried, live returned, else queued) and enqueueing the worker. - autoblog_link_exchange — read-only: reciprocal backlink candidates for a site via the existing matcher. - autoblog_articles — a site's recent articles and status. - traffic — a site's visitors/pageviews and top sources/pages, the tracker data the dashboard shows, filterable by humans/bots/all. Every tool scopes to the authenticated user and verifies site ownership before any side effect: the MCP route uses the service-role client, and the lx HTTP routes authenticate by session cookie an MCP caller lacks, so these call the lib functions directly with owner checks rather than proxying routes. A contract test pins the tool surface and schemas over the real SDK, mirroring the stats/promote/audits/leads tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MxNif5tsYq4LczgG7aE8Jp
GitHub is forcing Node 20 actions onto the Node 24 runtime, CodeQL
Action v3 is deprecated in December 2026, and ubuntu-latest migrates to
Ubuntu 26 on October 19, 2026. Bump every action to its current major
and pin the runner so none of that lands on us unannounced.
- actions/checkout v4 -> v7
- actions/setup-node v4 -> v7
- actions/upload-artifact v4 -> v7
- actions/github-script v7 -> v9
- github/codeql-action/{init,autobuild,analyze,upload-sarif} v3 -> v4
- runs-on: ubuntu-latest -> ubuntu-24.04
Checked the majors for breaking changes that apply here:
- checkout v7 blocks fork checkouts under pull_request_target and
workflow_run; neither event is used in this repo.
- setup-node v6 limits automatic caching to npm; ci.yml already sets
cache: npm explicitly.
- github-script v9 drops require('@actions/github') and reserves the
getOctokit identifier; the only script here requires 'fs' and uses
github.rest.issues, so it is unaffected.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The CodeQL run was throwing three annotations on every build:
actions/checkout@v4,github/codeql-action/{init,autobuild,analyze}@v3are being forced onto Node 24.ubuntu-latestmigrates to Ubuntu 26 beginning October 19, 2026.The first two applied to every workflow in the repo, not just
codeql.yml, so all five are bumped together.actions/checkoutactions/setup-nodeactions/upload-artifactactions/github-scriptgithub/codeql-action/*runs-onubuntu-latestubuntu-24.04Pinning the runner to
ubuntu-24.04keeps the October 19 image migration from landing on us mid-week; it can be unpinned deliberately later.Breaking changes checked against this repo
checkout@v7blocks fork checkouts underpull_request_target/workflow_run— neither event is used here (threatcrush-scan.ymldocuments that it deliberately stays onpull_request).setup-node@v6limits automatic caching to npm —ci.ymlalready setscache: npmexplicitly.github-script@v9dropsrequire('@actions/github')and reserves thegetOctokitidentifier — the one script here requiresfsand callsgithub.rest.issues, so it is unaffected.All five workflows parse clean. Note separately:
node-version: 20inci.yml,security.ymlandthreatcrush-scan.ymlis the test runtime, unrelated to these annotations, but Node 20 is past EOL and worth its own bump.🤖 Generated with Claude Code