Three bugs hid the split A1 data behind English junk:
1. /api/auth/me company was only {id, name} — me.company.language never
existed, so the prompt/formula pages ALWAYS fell back to English as
the primary content language and never showed the Slovenian ("sl")
prompt sections by default. handleMe now enriches the active company
with language + content_languages from the companies table.
2. The unified prompt page injected English default texts: meta title /
meta description fields were pre-filled via getDefaultMetaTitle/
Description (and silently SAVED on Save), new description sections
started with English instructions, and type changes overwrote user
text with English defaults. All removed — empty stays empty
(placeholders only), stored tenant content is shown exactly as-is,
meta-only templates now save (sections no longer required).
3. Sync A1 / repair left English formula artifacts on categories with no
seed content ("Audio video" etc.): earlier repairs backfilled
DefaultRetailTitleFormula and cats.json-style English description
sections onto every category. Repair now (a) never invents a default
title formula — formulas derive ONLY from legacy naming rules — and
(b) with the seed as source of truth clears title_template and
description_template on non-seed categories (new
title/description_template_cleared counters).
Locally verified end-to-end: corrupted Platform Demo Monitorji (legacy
combined blob) + Audio video (English junk), called the real admin
POST /companies/{id}/sync-a1 as the platform admin — Monitorji restored
to the exact split Slovenian Title/Description/Meta + formulas +
Slovenian meta title/description, Audio video fully cleared; repair
idempotent (0 on re-run); me.company.language returns sl for A1;
zero English-default templates remain in A1 + Platform Demo.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Production uses pgxstore, whose plain scs.Store.Find deliberately panics
("missing context arg") — only FindCtx works. DedupeSessionCookies called
Store.Find directly, so any request carrying duplicate session cookies
500'd (chi Recoverer caught the panic). Unit tests passed because the
in-memory store implements plain Find.
Mirror scs.doStoreFind: type-assert FindCtx(context.Context, string) and
use it with the request context, falling back to plain Find for simple
stores. Regression test adds a ctx-only store whose plain methods panic.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Browsers that logged in before the session cookie became Domain-scoped
still hold the old host-only descrybe_session for api.descrybe.io. They
then send BOTH cookies — older (stale) first — and Go reads the first
match, so the stale relic shadows the fresh Domain cookie and every
request 401s even immediately after a successful login. Clearing
browser cookies fixed it manually; users should never have to.
New DedupeSessionCookies middleware (mounted before scs LoadAndSave):
when duplicate session cookies arrive, pick the token that resolves in
the session store, rewrite the Cookie header to just that one, expire
the host-only relic (Set-Cookie without Domain only touches the
host-only variant), and re-issue the surviving token on the canonical
Domain cookie. One request converges the browser to a single cookie.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Production splits web (descrybe.io) and API (api.descrybe.io). The session
cookie was host-only for api.descrybe.io, so the browser never sent it to
the web host. The /admin SvelteKit SSR gate (fetchMeStaff in
+layout.server.ts) forwards the incoming cookie header to /api/auth/me —
with no cookie to forward it always got 401 and bounced every successful
login back to /login?next=/admin (login POST 200, /me 200 from the
browser, /me 401 from the web server).
New SESSION_COOKIE_DOMAIN env (default empty = host-only, local dev
unchanged) sets the session cookie Domain attribute; set it to the parent
domain (descrybe.io) in production so both hosts receive the cookie.
Leading dot is normalized away. CSRF needs no change — it already seeds
cross-origin via the X-CSRF-Token response header.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Category enhance prompts (Sync A1 / seed-a1 / repair) now use the same
three role sections as the rest of the platform: Title / Description /
Meta. The retired "--- Attributes ---" role section is removed from the
canonical template, the legacy-split overlay, and the web prompt editor;
Category/Attrs stay as plain product-context lines (attribute extraction
remains pipeline-level via AppendAttributeConstraints).
- Stored prompts still carrying an attributes section are detected by
CategoryEnhancePromptNeedsRepair and rewritten on the next Sync.
- Legacy wp_product_categories.sql splits now also seed a default Slovenian
metaTitle rule (dumps only carried <metaDescription>), so every A1
category gets all four prompt areas: title formula, description
sections, meta title, meta description.
- Role-sectioned prompts no longer imply the A1 SEO-omit cohort
(CompanyOmitsSEOMeta): sectioned prompts are the canonical prompt-editor
output for every tenant, and the sniff silently disabled SEO meta for
any company that saved a category prompt.
- Verified locally: repair-category-prompts -apply updated 238 A1 +
Platform Demo categories from scripts/seed/wp_product_categories.sql
(216 legacy splits), idempotent on re-run, zero attributes sections
left in DB.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>