The fast-xml-parser >=5.3.8 override (added for CVE) is incompatible
with @aws-sdk/client-ses, whose XML response parser registers entities
named "#xD" and "#10" — names that 5.x rejects with
[EntityReplacer] Invalid character '#' in entity name.
SESv2 uses REST/JSON, sidestepping the parser entirely. validateEmail
already used SESv2; this consolidates the three send functions onto
the same client and drops @aws-sdk/client-ses.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replace file-per-record auth requests, file-per-hash rate limits, and
JSON blob subscription cache with a single SQLite database via
better-sqlite3. Consolidate duplicated email/IP rate limit code into
shared helpers. Add missing IP rate limit pruning to cleanup interval.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add RYS Premium subscription system
Introduce optional paid tier with sign-in, Stripe billing, and premium
feature gating. Core features remain free. Includes Node.js server for
auth, payments, and license management.
Extension changes:
- Sign-in flow with magic link email
- Premium/upgrade/account modals with branded UI
- Premium feature gating (60+ advanced settings)
- Password lock and scheduling (premium)
- Fix "hide all but first row" for YouTube's new flat homepage DOM
- Hide sidebar ad panels by default
- Enable "Hide all Shorts" by default
Server:
- Magic link auth with rate limiting
- Stripe checkout, webhooks, and billing portal
- JWT-based license tokens
- AWS SES transactional emails (welcome, sign-in, cancellation)
- Grandfathered donor support
Also adds CI workflow, server test suite, and extension unit tests.