What's New
Automatic PII Redaction
Credit card numbers (Luhn-validated), SSNs, routing numbers, and bank account numbers are automatically stripped from extracted text before sending to the Claude API. Image/PDF vision paths send binary data and cannot be text-redacted — this limitation is documented.
Preview what gets redacted on your own receipts:
npx tsx scripts/preview-redaction.ts inbox/*.pdfCritical Bug Fixes
- Edit mode validation — user input now validated with Zod; rejects NaN amounts, invalid dates, bad categories
- Crash fix — removed non-null assertions on optional
receiptPathfield - JSON.parse safety — malformed API responses and corrupted ledger files now throw actionable error messages
- Impossible dates rejected —
2026-13-32no longer passes schema validation
Hardening
- Atomic ledger writes (temp file + rename) prevent corruption on crash
- Error messages include phase context (
[extracting text],[calling Claude API]) --propertyflag validated against config with warning on unknown values- Invalid
R2S_MAX_FILE_SIZE_MBwarns instead of silently falling back - Deduplicated
slugify()andMODEL_ALIASESto shared modules - Removed dead vendor-cache code
Tests: 130 → 144
New tests for PII redaction (38), date validation, corrupted ledger recovery, invalid API JSON, error phase context, and unknown property warnings.
Full Changelog: v0.1.0...v0.2.0