Skip to content

Releases: sahilbnsll/LumaCV

v2.16.0: Real Word Export + Export Crash Fix

Choose a tag to compare

@sahilbnsll sahilbnsll released this 15 Sep 08:32

Two bugs reported directly by a user in the same session.

Fixed

  • Export crash: a resume with certain AI-tailored achievement/publication fields crashed every export with (r || "").trim is not a function. An empty array is truthy in JS, so a malformed field reached .trim() on a non-string and threw. Now degrades gracefully instead of crashing.

Changed

  • The Word export is now a genuine .docx. The old version was a hand-maintained HTML approximation covering 6 of 22 possible sections in a fixed order, nothing like the compiled PDF. It's now built with the docx library directly from the same resume data the PDF compiles from: every section, in the user's real configured order, using the resume's actual accent color. It can't clone any one of the 52 Typst templates' exact layout (that needs a PDF-to-DOCX conversion pipeline that isn't feasible on this stack), but the content and structure now genuinely match. Lazy-loaded so it doesn't add weight to the editor's initial page load.
  • Markdown export now includes the Tech Stack section.

Full changelog: CHANGELOG.md

v2.15.1: Fix Corrupt PDF/DOCX Exports

Choose a tag to compare

@sahilbnsll sahilbnsll released this 15 Sep 08:07

A user reported that downloaded resume PDFs and Word files wouldn't open. Both were genuinely broken, not corrupted in transit.

Fixed

  • PDF: a failed server-side compile used to fall back to a fake "PDF" (plain text with a fake header), reporting success anyway. That fallback is gone, a failed export now shows a real error instead of handing over a corrupt file.
  • Word: the .docx export was actually Word's legacy HTML format saved under the wrong extension, which modern Word refuses to open. Now correctly saved as .doc, which Word opens natively.

Fixed everywhere the export is offered: the editor, dashboard, homepage demo, /demo, and the builder.


Full changelog: CHANGELOG.md

v2.15.0: Security Hardening & Performance Pass

Choose a tag to compare

@sahilbnsll sahilbnsll released this 14 Sep 17:54

A security-first hardening pass (CSP, HSTS, an open-redirect fix, and input validation gaps closed) alongside a real, measured performance pass: a broken resume-autosave bug fixed, a 441 KB unoptimized image trimmed, and roughly 40 components' hover/tap animations moved off the main thread. Mobile Lighthouse performance went from 63 to the mid-70s/low-80s across repeated production checks, with Total Blocking Time down from 240ms to as low as 10-20ms.

Security

  • Added a real Content-Security-Policy and HSTS, consolidated into next.config.mjs as the single source of truth for every security header (previously split, and occasionally conflicting, between there and middleware.ts).
  • Closed an open-redirect / phishing vector: an unvalidated ?redirect=/?next= param could turn this app's own trusted signup-confirmation emails into a phishing redirect. Added sanitizeRedirectPath(), wired into both the client auth form and the server-side confirm route.
  • Added missing request validation and size limits on several API routes (applications/[id] PATCH, import-ai-map, resume/score, resume/analyze-jd, resume/export-typ) that previously accepted unbounded or unvalidated input.
  • Stopped leaking raw Postgres error text to clients on the applications/resumes CRUD routes. AI and compile routes, which return genuinely actionable error messages, were deliberately left as-is.

Fixed

  • Resume autosave silently failed for every brand-new editing session. The editor's default draft id was never a valid UUID, so every autosave to the database failed while the localStorage fallback quietly succeeded right next to it, hiding the failure with no visible error. Fixed with a real, deterministic UUID per user.
  • The ATS-checker demo's thumbnail was a raw 441 KB PNG displayed at ~235px wide, the single largest item in the homepage's image weight. Switched to next/image.
  • Reverted 2.14.0's optimizeCss flag: it turned out not to defer any CSS at all. Corrected the record rather than leaving a wrong changelog entry standing.

Performance

  • Deferred an expensive Framer Motion scroll-measurement on the homepage hero that was costing ~1.2s of LCP render delay on a throttled mobile CPU.
  • Scoped ~40 components' hover/tap/focus transitions off Tailwind's transition-all and onto only the properties that actually change, keeping color/transform interactions on the compositor instead of forcing main-thread layout work on every hover. Covers the app shell, the applications board, the template browser, and the resume editor's drag/expand states (the most-used surface in the app).
  • Added a preconnect hint for the Supabase origin.

Investigated, not shipped

Scoped and attempted a true progressive-hydration approach for the homepage's below-the-fold sections. It doesn't work the way React 18's Suspense-during-hydration was expected to here: a deliberately-delayed next/dynamic import causes a multi-second content flash instead of quietly preserving the server-rendered HTML. Reverted before it shipped; documented in the changelog for anyone who revisits this.


Full changelog: CHANGELOG.md

v2.14.0

Choose a tag to compare

@sahilbnsll sahilbnsll released this 14 Sep 13:02

What's Changed

  • Install and Configure Vercel Speed Insights by @vercel[bot] in #2

Full Changelog: v2.13.0...v2.14.0

v2.13.0 — SEO Fixes, Speed Insights, and Search Console Verification

Choose a tag to compare

@sahilbnsll sahilbnsll released this 14 Sep 12:04

An SEO audit turned up good news first: the site's core on-page SEO was already correctly implemented — sitemap, robots.txt, canonical tags, per-page metadata, and JSON-LD were all in good shape. Two real gaps were found and fixed, plus a couple of infrastructure additions.

Fixed

  • /demo was an orphan page. It was fully built, had its own metadata, and was listed in the sitemap at priority 0.8, but was linked from nowhere on the actual site (not the footer, not the nav menu). A page search engines can only reach through the sitemap, never through an actual link, sends a weak discovery signal. Added it to both the footer's Product column and the guest navigation menu.
  • /forgot-password and /reset-password had no page-specific metadata. Both were client components at the page-file level, which structurally can't export Next.js metadata, so they fell back to the generic root "LumaCV" browser tab title. Split into the same thin server page + client content pattern every other page already uses. (/settings was deliberately left alone — it's a pure client-side redirect, same as /support.)

Added

  • Vercel Speed Insights, alongside the existing Analytics integration, for real Core Web Vitals data on every deployed page.
  • Google Search Console verification file, now served at the production domain root. Per Google's instructions, this file stays in place permanently, even after verification succeeds.

The real cause of "Google isn't showing my site"

If the site still isn't indexed after this release, it's not a codebase problem. Check, in order:

  1. Vercel's Deployment Protection setting. A "Require Log In" gate blocks Googlebot exactly the way it blocks any other visitor — nothing gets crawled if the whole site sits behind a login wall.
  2. Search Console's coverage report — it tells you the exact reason a URL isn't indexed.
  3. Domain/DNS verification for the production domain.

Also

  • /demo's prominence bump aside, no other pages needed structural SEO changes — the earlier concern about duplicate <h1> tags and missing image alt text turned out to be false positives (mutually-exclusive render branches and correctly-empty decorative alt text, respectively).

v2.12.0 The Missing Table, a Lighter Bundle, and a Perfect Accessibility Score

Choose a tag to compare

@sahilbnsll sahilbnsll released this 14 Sep 11:41

v2.12.0 — The Missing Table, a Lighter Bundle, and a Perfect Accessibility Score

This release started as a performance audit and surfaced something much more important along the way: the job application tracker had never actually worked.

Fixed

  • Applications tracker was silently no-op-ing. user_applications, the table both application API routes depend on, was never captured in schema.sql and didn't exist in the live database. Every save quietly fell into an error fallback and returned an empty list — nothing anyone entered was ever saved. Added the table, RLS policies, and a matching index.
  • /applications shipped 486 kB of JS to every visitor because the CSV/XLSX import dialog was statically bundled. Lazy-loaded it, cutting the route to 373 kB.
  • Blank screens on 7 routes during data loads — added skeleton loading states.
  • The "Skip to main content" link was broken almost everywhere — its target existed on only 6 of ~20 routes. Fixed sitewide.
  • Several WCAG AA contrast failures in dark mode, including every primary button's white text. Fixed by splitting one overloaded color token into two (background vs. text roles), since no single value could satisfy both.
  • A skipped heading level and a mismatched button label, also caught by the accessibility audit.

Lighthouse accessibility: 92 → 100.

Also

  • AVIF added to the image pipeline.
  • Safety caps on two previously-unbounded list queries.
  • Documentation updates so these gotchas (the skip-link id, the two-token color split) don't quietly regress again.

Important

If you're running your own Supabase instance, you need to run the updated supabase/schema.sql (or just the new user_applications section) in your SQL Editor for the application tracker to start persisting data.

Supabase Security Hardening: Function Search Paths & RPC Exposure Lockdown Description:

Choose a tag to compare

@sahilbnsll sahilbnsll released this 14 Sep 09:59

This release closes three of the six warnings surfaced by Supabase's security advisor, without touching any user-facing behavior.

Fixed:

Pinned search_path = public on set_updated_at() and increment_platform_stat(), closing a schema-shadowing risk where a mutable search path could let another schema silently intercept an unqualified reference.
Revoked default PUBLIC/anon/authenticated EXECUTE grants on handle_new_user(), set_updated_at(), and increment_platform_stat(). All three are internal helpers meant to run only via trigger or from trusted server code, but Postgres grants EXECUTE to PUBLIC by default, and Supabase auto-exposes every public-schema function at /rest/v1/rpc/ — so without the revoke, any signed-in or anonymous client could call them directly (most notably increment_platform_stat, which could have let anyone corrupt the public homepage stats with an arbitrary key/amount).

Reviewed, left unchanged:

feedback table's permissive WITH CHECK (true) INSERT policy — intentional design for a public write-only feedback form; no read/update/delete access granted.

Flagged for manual follow-up (not in this repo, can't be fixed via SQL):

rls_auto_enable() — not defined anywhere in this repo's schema.sql; likely created directly in the Supabase dashboard. Needs manual investigation.
Leaked password protection — a dashboard-only Auth toggle; steps now documented in docs/supabase-setup.md.

v2.11.0 — Predefined avatar picker, account menu polish, mobile & iOS fixes

Choose a tag to compare

@sahilbnsll sahilbnsll released this 14 Sep 07:34

Added

  • Profile avatar picker: choose from 56 predefined avatars (DiceBear "Notionists" style, MIT licensed, bundled as static SVGs — no third-party network calls at runtime) in Profile → Avatar, or keep the initials monogram. Shows consistently in the header, account menu, and profile sidebar.
  • "Optimize Resume" link added to the account dropdown menu — it was already in the mobile nav and command palette, but missing here.

Fixed

  • PDF text extraction was failing on iOS browsers (Arc, Safari, and anything else on iOS — Apple requires all of them to run on WebKit) while working fine on desktop. Switched to pdf.js's "legacy" build, built for exactly this kind of engine compatibility gap.
  • ATS checker's saved-resume list only read local storage, missing resumes synced from another device.
  • Color palette dropdown (Resume Editor) was overflowing off the left edge of the screen on mobile.
  • Several homepage cards were cropping text or overflowing their container on mobile (mid-word text wraps, a shadow bleeding into the row below).
  • Account dropdown menu rows were under the 44px touch-target guideline.

Docs

  • Documented the username/avatar_id columns in the Supabase setup guide and AGENTS.md.

v2.10.0 — Security fixes, SEO fixes, docs accuracy, cleanup

Choose a tag to compare

@sahilbnsll sahilbnsll released this 14 Sep 06:18

v2.10.0

Security

  • Fixed a cross-user data-overwrite bug: POST /api/v1/resumes and POST /api/v1/applications upserted a client-supplied id with no ownership check.
  • Closed an unlimited account-enumeration gap on username-based sign-in.
  • Added rate limiting to the one AI-calling route that was missing it.

Fixed

  • Social share previews (Slack, X, LinkedIn, iMessage) were rendering cropped/broken — the OG image is now generated at the correct 1200×630.
  • The homepage had no page-specific SEO title/description — it was structurally impossible while it stayed a client component.
  • Fixed a duplicate <h1> on the homepage and added a root-layout error boundary.
  • Mobile: resume stack no longer half-cut, templates gallery preview modal scrolls correctly, resume editor header no longer overlaps the candidate name, toasts resized.
  • Docs page's chapter "paper stack" now has a mobile variant (previously desktop-only), with a translucency bug fixed.

Docs

  • Corrected several claims that had drifted from the code (a fabricated ATS scoring model, a nonexistent WASM compiler, dead env vars, a stale route reference).
  • Documented 8 API routes that had no docs at all.
  • Added AGENTS.md, a technical-context reference for AI coding agents working in this repo.

Cleanup

  • Removed 8 dead component files and the unused swiper dependency.

v2.9.0 - Production Font Fix, Loader Polish & Cleanup

Choose a tag to compare

@sahilbnsll sahilbnsll released this 13 Sep 18:03

Highlights

Critical fix: sans-serif resume templates were silently rendering in the
wrong font in production — Inter and JetBrains Mono weren't bundled, and no
font-path was configured on Vercel/Linux at all. Fonts are now bundled and
wired on both platforms.

Fixed

  • Production Typst font resolution (Inter + JetBrains Mono now bundled and resolve correctly)
  • Liquid-glass dialogs were nearly opaque in light mode
  • Site header was effectively invisible once scrolled on dark pages
  • Editor header brand sizing was inconsistent with the rest of the app
  • Three progress bars caused layout-thrashing animation jank (now GPU-composited)
  • A console error in the loader component's metaballs variant
  • Public feedback endpoint had no rate limiting

Changed

  • Merged /billing and /support into one page (/support now redirects)
  • New distinctive loading animations across the app; removed a generic "document scanner" visual
  • Footer wordmark now has a cursor-following gradient reveal + live GitHub release-tag display
  • Removed a few overstated marketing claims that didn't match actual auth-gated behavior

Security

  • Rate-limited the public feedback endpoint

Full details: CHANGELOG.md