Repository navigation
v3.0.1 - Pre v3.1 Fixes
Patch release addressing bugs found after v3.0 shipped, a GitHub CodeQL security finding, and an AWS cost anomaly. No new user-facing features - all fixes and hardening ahead of v3.1 (Salary & Contact Tracking).
Fixed
Analytics zero-state crash
AnalyticsDashboard.tsxthrewCannot read properties of undefined (reading 'total')when a user had zero applications, since the empty-state guard didn't account for the insights Lambda's message-only response shape- This also left every other page stuck in the error boundary's fallback UI until a hard refresh, since
ErrorBoundarywasn't keyed to the route ErrorBoundaryis now keyed to the route path, so it self-heals on navigation for any future render error, not just this one
Broken navigation links on Privacy Policy and Terms pages
- Logo and "Back to Applytic" links bypassed React Router's basename on the custom domain deployment, landing on the wrong domain root
- Same root cause as a prior fix in the auth modal - now consistently using router-aware links across both pages
FAQ accordion causing whole-page lag
- Opening any FAQ question caused visible lag across the entire page, not just the clicked card, on both desktop and mobile
- Root cause:
backdrop-filterblur on 7 stacked cards forced a live repaint of every shifting sibling on every animation frame - Switched to a solid background and a compositor-friendly height animation (also fixes a latent bug where long answers could get clipped)
Production bundle size
- Single JS bundle exceeded Vite's 500kB warning threshold since no route was code-split
- All page-level routes now load on demand via
React.lazy(), so users only download the code for the route they visit
Security
CodeQL: Bad HTML filtering regexp
- The job-description HTML stripper in the Interview Prep Lambda used a regex that could be bypassed by malformed-but-browser-accepted close tags
- Replaced with Python's stdlib HTML parser, which tokenizes tag structure instead of pattern-matching
Infrastructure
Google OAuth credentials moved off Secrets Manager
- Eliminated ~$0.013/day in ongoing Secrets Manager charges (flagged by AWS Cost Anomaly Detection) for credentials that are only needed at deploy time
- Migrated to SSM Parameter Store, which is free at this volume, resolved via a CDK custom resource since CloudFormation doesn't support SSM's secure dynamic reference syntax on Cognito identity provider resources
- Verified working end-to-end and old secret deleted post-deployment
Content
- Landing page updated to reflect v3.0 features (Interview Prep, Rejection Pattern Alerts) across the feature grid, how-it-works steps, deep-dive section, and FAQ
Tests
- 355 backend tests, all passing, 93% coverage
Full diff: v3.0.0...v3.0.1