Project convention is 4-space indent for extension JS, but src/shared/utils.js
and one function in src/shared/analytics.js used tabs. Converted leading tabs
to 4 spaces, no functional change. Also fixed a misaligned line at utils.js:63
that had a single leading space instead of the expected indent.
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
- server/src/routes/checkout.js: remove unused createBillingPortalSession
from the destructuring import. The portal logic lives in
routes/billing.js; checkout.js never called it.
- src/background/events.js: remove a stale commented-out
browser.runtime.openOptionsPage() line.
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Port dev.sh + release CI from curb; make redirects free
dev.sh runs Firefox via web-ext from src/ and Chrome from a dist/chrome/
symlink tree. The two manifests live at different paths, so both browsers
can run side-by-side without clobbering each other's manifest.json. Edits
in src/ propagate live to both.
release.yml builds Chrome + Firefox zips on tag push (v*) and attaches
them to a GitHub Release, retiring the manual extension.zip workflow.
The four redirect-home options (redirect_to_subs / _to_wl / _to_library /
_off) drop the premium flag — they're advertised on the store listings,
so it feels right to have them free.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Trim dev section in README to just the commands
Cut the rationale paragraphs (symlink trick, manifest clobbering); anyone
needing that detail can read dev.sh.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Sync dist/chrome with rsync instead of symlinks
Chrome's content-script loader silently rejects scripts whose realpath is
outside the extension directory. The popup loaded fine through symlinks
but content scripts on YouTube never injected (no Chrome error, just
nothing). Real file copies sidestep the realpath check. Trade-off: re-run
dev.sh chrome and click reload after edits.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Fix redirect-to-Library URL after YouTube renamed Library to You
YouTube renamed the Library section to "You" and moved its URL from
/feed/library to /feed/you. The redirect option silently broke.
Fixes#123
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
The fast-xml-parser >=5.3.8 override (added for CVE) is incompatible
with @aws-sdk/client-ses, whose XML response parser registers entities
named "#xD" and "#10" — names that 5.x rejects with
[EntityReplacer] Invalid character '#' in entity name.
SESv2 uses REST/JSON, sidestepping the parser entirely. validateEmail
already used SESv2; this consolidates the three send functions onto
the same client and drops @aws-sdk/client-ses.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Prevents foreign Stripe events (from other apps sharing this Stripe
account) from being processed. Webhook ignores events whose products
are not in the allowlist; server refuses to boot without it set.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
YouTube migrated the subscriptions feed to yt-lockup-view-model with
yt-thumbnail-view-model inside, so `ytd-thumbnail` no longer matches
the feed thumbnails there. Add the new element to the
remove_video_thumbnails hide rule and the blur_video_thumbnails filter
rule so both features work on /feed/subscriptions again.
Caught by the rys-test Playwright harness.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Squashed commit of the following:
commit dbe3eae405
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Mon Mar 2 00:13:35 2026 -0500
Add Stripe checkout hint to upgrade modal
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit b433727754
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Mar 1 23:48:01 2026 -0500
Add email validation, IP rate limiting, and fix SES parsing bug
Add SES email validation with 2s timeout and fail-open behavior to
send-magic-link. Add per-IP rate limiting with decrement on verify.
Fix SES response parsing path (MailboxValidation.IsValid.ConfidenceVerdict).
Add dedicated unit tests for validateEmail.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 84b103e46b
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Mar 1 23:47:51 2026 -0500
Migrate storage layer from flat files to SQLite
Replace file-per-record auth requests, file-per-hash rate limits, and
JSON blob subscription cache with a single SQLite database via
better-sqlite3. Consolidate duplicated email/IP rate limit code into
shared helpers. Add missing IP rate limit pruning to cleanup interval.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 84c2ea5586
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Mar 1 21:58:47 2026 -0500
update versions
commit a4d5a97664
Merge: 53a18e72fe77fa
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Mar 1 21:58:09 2026 -0500
Merge branch 'released'
commit 53a18e7987
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Mar 1 16:56:50 2026 -0500
Hide donate link for premium users instead of showing dead label
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit e2732dee6f
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Mar 1 16:50:33 2026 -0500
Fix fast-xml-parser vulnerability via npm override and update @aws-sdk/client-ses
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 281c0f1103
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Mar 1 16:46:31 2026 -0500
Add "Active" sidebar tab and soften selected sidebar styling
Adds "all" and "active" tabs at the top of the sidebar. "Active" shows
all currently-enabled options in one place; "all" explicitly resets to
the default view. Also lightens the sidebar selected state from solid
black to a subtle tint.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 56b119ed98
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 22 05:01:00 2026 -0500
Cache grandfathered emails in memory at startup
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit afed16a38a
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 22 04:47:51 2026 -0500
Add tests for cache TTL and webhook ordering race condition
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 361a8caf84
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 22 04:34:00 2026 -0500
Harden license cache: 10s TTL and skip incomplete subscription.created
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit d857ae8c26
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sat Feb 21 18:24:33 2026 -0500
Update README: replace donations blurb with premium link
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit c473314ca5
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date: Sat Feb 21 18:22:39 2026 -0500
Bump fast-xml-parser and @aws-sdk/xml-builder in /server (#201)
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) and [@aws-sdk/xml-builder](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages-internal/xml-builder). These dependencies needed to be updated together.
Updates `fast-xml-parser` from 5.3.4 to 5.3.6
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.3.4...v5.3.6)
Updates `@aws-sdk/xml-builder` from 3.972.4 to 3.972.5
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/xml-builder/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/xml-builder)
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.3.6
dependency-type: indirect
- dependency-name: "@aws-sdk/xml-builder"
dependency-version: 3.972.5
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
commit 49e1a5d9ba
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sat Feb 21 17:30:29 2026 -0500
Fix license cache not updating after checkout
The checkout.session.completed webhook only sent a welcome email but
did not update the subscription cache, so users kept getting cached
free status after paying.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit c5734518c4
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 19:10:05 2026 -0500
Remove TESTING.md and DEPLOYMENT.md
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 6ed3ad0291
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 19:08:03 2026 -0500
Remove obsolete docs and update TODO for YouTube DOM change
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 83693504e3
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 18:54:29 2026 -0500
update versions
commit 27a6ae6f18
Merge: 3f4b42bd6e642b
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 18:53:37 2026 -0500
Merge branch 'released'
commit 3f4b42b2de
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 18:49:28 2026 -0500
Update qs to 6.14.2 to fix low-severity DoS vulnerability
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 8825666512
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 18:45:37 2026 -0500
Merge the monetization feature branch.
Add RYS Premium subscription system
Introduce optional paid tier with sign-in, Stripe billing, and premium
feature gating. Core features remain free. Includes Node.js server for
auth, payments, and license management.
Extension changes:
- Sign-in flow with magic link email
- Premium/upgrade/account modals with branded UI
- Premium feature gating (60+ advanced settings)
- Password lock and scheduling (premium)
- Fix "hide all but first row" for YouTube's new flat homepage DOM
- Hide sidebar ad panels by default
- Enable "Hide all Shorts" by default
Server:
- Magic link auth with rate limiting
- Stripe checkout, webhooks, and billing portal
- JWT-based license tokens
- AWS SES transactional emails (welcome, sign-in, cancellation)
- Grandfathered donor support
Also adds CI workflow, server test suite, and extension unit tests.
commit a76f69804b
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 8 20:45:35 2026 -0500
update description in README
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit b5d1384ca8
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 8 20:44:26 2026 -0500
update "Why I made it" section in README
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 18b64708b6
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 8 20:14:23 2026 -0500
update version to 4.3.71
Add SES email validation with 2s timeout and fail-open behavior to
send-magic-link. Add per-IP rate limiting with decrement on verify.
Fix SES response parsing path (MailboxValidation.IsValid.ConfidenceVerdict).
Add dedicated unit tests for validateEmail.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Replace file-per-record auth requests, file-per-hash rate limits, and
JSON blob subscription cache with a single SQLite database via
better-sqlite3. Consolidate duplicated email/IP rate limit code into
shared helpers. Add missing IP rate limit pruning to cleanup interval.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Squashed commit of the following:
commit 53a18e7987
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Mar 1 16:56:50 2026 -0500
Hide donate link for premium users instead of showing dead label
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit e2732dee6f
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Mar 1 16:50:33 2026 -0500
Fix fast-xml-parser vulnerability via npm override and update @aws-sdk/client-ses
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 281c0f1103
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Mar 1 16:46:31 2026 -0500
Add "Active" sidebar tab and soften selected sidebar styling
Adds "all" and "active" tabs at the top of the sidebar. "Active" shows
all currently-enabled options in one place; "all" explicitly resets to
the default view. Also lightens the sidebar selected state from solid
black to a subtle tint.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 56b119ed98
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 22 05:01:00 2026 -0500
Cache grandfathered emails in memory at startup
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit afed16a38a
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 22 04:47:51 2026 -0500
Add tests for cache TTL and webhook ordering race condition
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 361a8caf84
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 22 04:34:00 2026 -0500
Harden license cache: 10s TTL and skip incomplete subscription.created
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit d857ae8c26
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sat Feb 21 18:24:33 2026 -0500
Update README: replace donations blurb with premium link
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit c473314ca5
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Date: Sat Feb 21 18:22:39 2026 -0500
Bump fast-xml-parser and @aws-sdk/xml-builder in /server (#201)
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) and [@aws-sdk/xml-builder](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages-internal/xml-builder). These dependencies needed to be updated together.
Updates `fast-xml-parser` from 5.3.4 to 5.3.6
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.3.4...v5.3.6)
Updates `@aws-sdk/xml-builder` from 3.972.4 to 3.972.5
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages-internal/xml-builder/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/HEAD/packages-internal/xml-builder)
---
updated-dependencies:
- dependency-name: fast-xml-parser
dependency-version: 5.3.6
dependency-type: indirect
- dependency-name: "@aws-sdk/xml-builder"
dependency-version: 3.972.5
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
commit 49e1a5d9ba
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sat Feb 21 17:30:29 2026 -0500
Fix license cache not updating after checkout
The checkout.session.completed webhook only sent a welcome email but
did not update the subscription cache, so users kept getting cached
free status after paying.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit c5734518c4
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 19:10:05 2026 -0500
Remove TESTING.md and DEPLOYMENT.md
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 6ed3ad0291
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 19:08:03 2026 -0500
Remove obsolete docs and update TODO for YouTube DOM change
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 83693504e3
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 18:54:29 2026 -0500
update versions
commit 27a6ae6f18
Merge: 3f4b42bd6e642b
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 18:53:37 2026 -0500
Merge branch 'released'
commit 3f4b42b2de
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 18:49:28 2026 -0500
Update qs to 6.14.2 to fix low-severity DoS vulnerability
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 8825666512
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 15 18:45:37 2026 -0500
Merge the monetization feature branch.
Add RYS Premium subscription system
Introduce optional paid tier with sign-in, Stripe billing, and premium
feature gating. Core features remain free. Includes Node.js server for
auth, payments, and license management.
Extension changes:
- Sign-in flow with magic link email
- Premium/upgrade/account modals with branded UI
- Premium feature gating (60+ advanced settings)
- Password lock and scheduling (premium)
- Fix "hide all but first row" for YouTube's new flat homepage DOM
- Hide sidebar ad panels by default
- Enable "Hide all Shorts" by default
Server:
- Magic link auth with rate limiting
- Stripe checkout, webhooks, and billing portal
- JWT-based license tokens
- AWS SES transactional emails (welcome, sign-in, cancellation)
- Grandfathered donor support
Also adds CI workflow, server test suite, and extension unit tests.
commit a76f69804b
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 8 20:45:35 2026 -0500
update description in README
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit b5d1384ca8
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 8 20:44:26 2026 -0500
update "Why I made it" section in README
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
commit 18b64708b6
Author: Lawrence Hook <lawrencehook@gmail.com>
Date: Sun Feb 8 20:14:23 2026 -0500
update version to 4.3.71
Adds "all" and "active" tabs at the top of the sidebar. "Active" shows
all currently-enabled options in one place; "all" explicitly resets to
the default view. Also lightens the sidebar selected state from solid
black to a subtle tint.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>