Repository navigation
Releases: loootai/looot-techstack
Release list
v0.1.3: admin sign-in (security)
Security release. Versions 0.1.2 and older had no admin authentication. Anyone who could reach a running instance could start paid lookups and finds on your looot balance, as often as they liked, and download the stored results. If you run 0.1.2 or older on a reachable host, upgrade to 0.1.3 and set TECHSTACK_ADMIN_PASSWORD.
What changed
- Every page and API route is public on purpose or admin. Admin routes need a signed session cookie, and state-changing requests also need a CSRF token and a same-origin request.
- Without TECHSTACK_ADMIN_PASSWORD (12+ characters) admin routes answer 503 and /login shows a setup page.
- /api/lookup and /api/find need the quote total the caller was shown (quoteMicros). The server prices the request again, refuses if the price went up, and caps the run at the lower of that total and spendCapUsd.
- An identical paid request is answered from the stored result for 24 hours and calls looot zero times. A caller idempotencyKey used for a different request gets 409. One session can start 10 paid requests per 10 minutes.
Upgrading: set TECHSTACK_ADMIN_PASSWORD. A script that posted only { text } to /api/lookup now gets a 400 asking for a quote. See "Securing a deployment" in the README.
v0.1.2
Sidebar layout: left sidebar that collapses to an icon rail, drawer on phones, spend panel, docs and GitHub links.
v0.1.1
Dependency security bump. next and eslint-config-next 16.3.7 to 16.3.8, which fixes six Next.js advisories (GHSA-3w37-wq28-93x7, GHSA-4jqv-mc3x-m676, GHSA-39w2-rjm5-chcv, GHSA-f87g-xv8r-7p7x, GHSA-mcj8-r9mp-w47p, GHSA-cjq9-62q9-8jv4). No code changes. v0.1.0 is unchanged.
v0.1.0
First release. Demo mode, headless CLI with an exact dry-run quote and a spend cap, web UI (lookup, bulk table with technology filter, find companies), providers side by side with agreement. No paid looot run was made; parsers are built from docs and fixtures. See the README section on what is not tested.