Skip to content

v3.0.1 - Pre v3.1 Fixes

Choose a tag to compare

@hardikjp7 hardikjp7 released this 08 Aug 06:49
· 9 commits to main since this release
ad8a385

Patch release addressing bugs found after v3.0 shipped, a GitHub CodeQL security finding, and an AWS cost anomaly. No new user-facing features - all fixes and hardening ahead of v3.1 (Salary & Contact Tracking).

Fixed

Analytics zero-state crash

  • AnalyticsDashboard.tsx threw Cannot read properties of undefined (reading 'total') when a user had zero applications, since the empty-state guard didn't account for the insights Lambda's message-only response shape
  • This also left every other page stuck in the error boundary's fallback UI until a hard refresh, since ErrorBoundary wasn't keyed to the route
  • ErrorBoundary is now keyed to the route path, so it self-heals on navigation for any future render error, not just this one

Broken navigation links on Privacy Policy and Terms pages

  • Logo and "Back to Applytic" links bypassed React Router's basename on the custom domain deployment, landing on the wrong domain root
  • Same root cause as a prior fix in the auth modal - now consistently using router-aware links across both pages

FAQ accordion causing whole-page lag

  • Opening any FAQ question caused visible lag across the entire page, not just the clicked card, on both desktop and mobile
  • Root cause: backdrop-filter blur on 7 stacked cards forced a live repaint of every shifting sibling on every animation frame
  • Switched to a solid background and a compositor-friendly height animation (also fixes a latent bug where long answers could get clipped)

Production bundle size

  • Single JS bundle exceeded Vite's 500kB warning threshold since no route was code-split
  • All page-level routes now load on demand via React.lazy(), so users only download the code for the route they visit

Security

CodeQL: Bad HTML filtering regexp

  • The job-description HTML stripper in the Interview Prep Lambda used a regex that could be bypassed by malformed-but-browser-accepted close tags
  • Replaced with Python's stdlib HTML parser, which tokenizes tag structure instead of pattern-matching

Infrastructure

Google OAuth credentials moved off Secrets Manager

  • Eliminated ~$0.013/day in ongoing Secrets Manager charges (flagged by AWS Cost Anomaly Detection) for credentials that are only needed at deploy time
  • Migrated to SSM Parameter Store, which is free at this volume, resolved via a CDK custom resource since CloudFormation doesn't support SSM's secure dynamic reference syntax on Cognito identity provider resources
  • Verified working end-to-end and old secret deleted post-deployment

Content

  • Landing page updated to reflect v3.0 features (Interview Prep, Rejection Pattern Alerts) across the feature grid, how-it-works steps, deep-dive section, and FAQ

Tests

  • 355 backend tests, all passing, 93% coverage

Full diff: v3.0.0...v3.0.1