{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-43544f05ad8eda9e", "name": "Stray `console.log` in TS/JS \u2014 test-date-correction.js:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-date-correction.js:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2eb7b1fe0115009d", "name": "Stray `console.log` in TS/JS \u2014 src/app/App.tsx:8", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/App.tsx:8"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c3ff7a7f2d71395", "name": "`truncate` class without `title=` for hover reveal \u2014 src/app/components/DocumentUploader.tsx:169", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/components/DocumentUploader.tsx:169"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b6d32b882b83e8ec", "name": "Stray `console.log` in TS/JS \u2014 src/app/components/DocumentUploader.tsx:68", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/components/DocumentUploader.tsx:68"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f859cbf98fc5d15", "name": "Stray `console.log` in TS/JS \u2014 src/app/components/MediaGalleryUploader.tsx:52", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/components/MediaGalleryUploader.tsx:52"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-26e85d42f2935c57", "name": "`truncate` class without `title=` for hover reveal \u2014 src/app/components/FileUploadPreview.tsx:207", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/components/FileUploadPreview.tsx:207"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a2035c22ccddc8ca", "name": "`truncate` class without `title=` for hover reveal \u2014 src/app/components/MediaDebug.tsx:130", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/components/MediaDebug.tsx:130"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c3685f1afda4ef49", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 src/app/components/ui/chart.tsx:83", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/app/components/ui/chart.tsx:83"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6acdd9d183327f39", "name": "Stray `console.log` in TS/JS \u2014 src/app/pages/ChangePassword.tsx:66", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ChangePassword.tsx:66"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5efa1c432aedf670", "name": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientDetails.tsx:25", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientDetails.tsx:25"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09a59c638e4baa58", "name": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/DueReminders.tsx:569", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/DueReminders.tsx:569"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5284a53fdbcabf5c", "name": "Stray `console.log` in TS/JS \u2014 src/app/pages/DueReminders.tsx:101", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/DueReminders.tsx:101"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d38963a38484826", "name": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Users.tsx:497", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Users.tsx:497"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-df30a02ff279a517", "name": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientPortalLogin.tsx:34", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientPortalLogin.tsx:34"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e8e84afa399d2ec6", "name": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/BillingCalendar.tsx:322", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/BillingCalendar.tsx:322"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5132d3ca32cad257", "name": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientPortalFirstAccess.tsx:102", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientPortalFirstAccess.tsx:102"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-67e10d2c4f310c91", "name": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientForm.tsx:82", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientForm.tsx:82"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e4b9f728d74c283", "name": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Security.tsx:709", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Security.tsx:709"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0c885be94a20722b", "name": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientPortal.tsx:111", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientPortal.tsx:111"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d45f4caf4c1d2762", "name": "Stray `console.log` in TS/JS \u2014 src/app/pages/Financial.tsx:128", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/Financial.tsx:128"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c19b95ab2694e3f", "name": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Clients.tsx:187", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Clients.tsx:187"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dc36fc5a5889c6a8", "name": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Contracts.tsx:85", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Contracts.tsx:85"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8d6b8ef7bb73553c", "name": "Stray `console.log` in TS/JS \u2014 src/app/pages/ContractForm.tsx:123", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ContractForm.tsx:123"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-56fa2b24c4f4e69c", "name": "Stray `console.log` in TS/JS \u2014 src/app/pages/Dashboard.tsx:162", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/Dashboard.tsx:162"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-890d57fbb5e57ce8", "name": "Stray `console.log` in TS/JS \u2014 src/app/lib/auth-context.tsx:7", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/lib/auth-context.tsx:7"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-75026788b7e16ca9", "name": "Stray `console.log` in TS/JS \u2014 src/app/lib/supabase.ts:54", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/app/lib/supabase.ts:54"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ce82729d889117d", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/make-server-bd42bc02/index.ts:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/make-server-bd42bc02/index.ts:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a7bf360a00e9f41", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/make-server-bd42bc02/billing_routes.tsx:80", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/make-server-bd42bc02/billing_routes.tsx:80"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bf0c62b972aab979", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/server/index.tsx:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/server/index.tsx:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54f8453c027db8d5", "name": "Stray `console.log` in TS/JS \u2014 supabase/functions/server/billing_routes.tsx:80", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/server/billing_routes.tsx:80"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fce42693cd5ceb5f", "name": "Insecure pattern 'direct_innerhtml_assignment' in test-edge-function.html:255", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in test-edge-function.html:255"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d88d4aa2505d499e", "name": "Insecure pattern 'direct_innerhtml_assignment' in test-timezone-fix.html:260", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in test-timezone-fix.html:260"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9126e87d6aff98d", "name": "Insecure pattern 'direct_innerhtml_assignment' in test-deploy-corrigido.html:283", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in test-deploy-corrigido.html:283"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-197323a1df0bc584", "name": "Insecure pattern 'dangerous_innerhtml' in src/app/components/ui/chart.tsx:83", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in src/app/components/ui/chart.tsx:83"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-673c381ae96f5de6", "name": "Possible secret in supabase/functions/make-server-bd42bc02/index.ts", "shortDescription": {"text": "Possible secret in supabase/functions/make-server-bd42bc02/index.ts"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-73bd625eeec26f0c", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/make-server-bd42bc02/index.ts:73", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/make-server-bd42bc02/index.ts:73"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2a3ddac7fe26b446", "name": "Possible secret in supabase/functions/server/index.tsx", "shortDescription": {"text": "Possible secret in supabase/functions/server/index.tsx"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-02317ff5ee0f9845", "name": "Insecure pattern 'cors_wildcard' in supabase/functions/server/index.tsx:73", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/server/index.tsx:73"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-334e2eb221793f12", "name": "Very large file: src/app/pages/ClientPortalFirstAccess.tsx (1405 lines)", "shortDescription": {"text": "Very large file: src/app/pages/ClientPortalFirstAccess.tsx (1405 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4efdaf9a35e62d9b", "name": "Very large file: supabase/functions/make-server-bd42bc02/index.ts (4241 lines)", "shortDescription": {"text": "Very large file: supabase/functions/make-server-bd42bc02/index.ts (4241 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-312f8713d1dcf6ae", "name": "Very large file: supabase/functions/server/index.tsx (4241 lines)", "shortDescription": {"text": "Very large file: supabase/functions/server/index.tsx (4241 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "1 test file(s) for 104 source file(s) (ratio 0.01). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 601 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 79 placeholder/mock markers across 19 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ece74b3f7868b269", "name": "Legacy-named symbol `dateOld` in test-date-correction.js:139", "shortDescription": {"text": "Legacy-named symbol `dateOld` in test-date-correction.js:139"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e9018da4e8269a6e", "name": "Commented-code block (6 lines) in src/app/utils/dateUtils.ts:180", "shortDescription": {"text": "Commented-code block (6 lines) in src/app/utils/dateUtils.ts:180"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bb43ef13dda191a2", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/pages/ClientPortalDashboard.tsx:42", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/pages/ClientPortalDashboard.tsx:42"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f6be4b666c0b4696", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/pages/ClientPortalFirstAccess.tsx:446", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/pages/ClientPortalFirstAccess.tsx:446"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-065e29ce26dca180", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/lib/auth-context.tsx:158", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/lib/auth-context.tsx:158"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f9f34c267ad61024", "name": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/make-server-bd42bc02/index.ts:672", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/make-server-bd42bc02/index.ts:672"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7cfacb316a75d777", "name": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/make-server-bd42bc02/billing_routes.tsx:386", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/make-server-bd42bc02/billing_routes.tsx:386"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0d392cfa1d00aee4", "name": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/server/index.tsx:672", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/server/index.tsx:672"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7853efe3c457a609", "name": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/server/billing_routes.tsx:386", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/server/billing_routes.tsx:386"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-27e0717c1925f0d8", "name": "Dangling fetch: POST /clients/${clientId}/documents (src/app/components/DocumentUploader.tsx:56)", "shortDescription": {"text": "Dangling fetch: POST /clients/${clientId}/documents (src/app/components/DocumentUploader.tsx:56)"}, "fullDescription": {"text": "`src/app/components/DocumentUploader.tsx:56` calls `POST /clients/${clientId}/documents` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>/documents`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7a6b60fbde1b143c", "name": "Dangling fetch: GET /clients/${clientId}?_t=${timestamp} (src/app/components/MediaGalleryUploader.tsx:56)", "shortDescription": {"text": "Dangling fetch: GET /clients/${clientId}?_t=${timestamp} (src/app/components/MediaGalleryUploader.tsx:56)"}, "fullDescription": {"text": "`src/app/components/MediaGalleryUploader.tsx:56` calls `GET /clients/${clientId}?_t=${timestamp}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-273c9d98128d5161", "name": "Dangling fetch: GET /clients/${clientId}/documents/${key}?_t=${timestamp} (src/app/components/MediaGalleryUploader.tsx:9", "shortDescription": {"text": "Dangling fetch: GET /clients/${clientId}/documents/${key}?_t=${timestamp} (src/app/components/MediaGalleryUploader.tsx:96)"}, "fullDescription": {"text": "`src/app/components/MediaGalleryUploader.tsx:96` calls `GET /clients/${clientId}/documents/${key}?_t=${timestamp}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>/documents/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e5a92ee01bc9744b", "name": "Dangling fetch: POST /clients/${clientId}/documents (src/app/components/MediaGalleryUploader.tsx:176)", "shortDescription": {"text": "Dangling fetch: POST /clients/${clientId}/documents (src/app/components/MediaGalleryUploader.tsx:176)"}, "fullDescription": {"text": "`src/app/components/MediaGalleryUploader.tsx:176` calls `POST /clients/${clientId}/documents` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>/documents`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a36b41a399e9fc99", "name": "Dangling fetch: GET /clients/${clientId}?_t=${timestamp} (src/app/components/MediaGalleryUploader.tsx:221)", "shortDescription": {"text": "Dangling fetch: GET /clients/${clientId}?_t=${timestamp} (src/app/components/MediaGalleryUploader.tsx:221)"}, "fullDescription": {"text": "`src/app/components/MediaGalleryUploader.tsx:221` calls `GET /clients/${clientId}?_t=${timestamp}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-365f976c8870f662", "name": "Dangling fetch: DELETE /clients/${clientId}/documents/${key} (src/app/components/MediaGalleryUploader.tsx:253)", "shortDescription": {"text": "Dangling fetch: DELETE /clients/${clientId}/documents/${key} (src/app/components/MediaGalleryUploader.tsx:253)"}, "fullDescription": {"text": "`src/app/components/MediaGalleryUploader.tsx:253` calls `DELETE /clients/${clientId}/documents/${key}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>/documents/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d4bb72a44acd9faf", "name": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/health (src/app/components/AuthDi", "shortDescription": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/health (src/app/components/AuthDiagnostic.tsx:79)"}, "fullDescription": {"text": "`src/app/components/AuthDiagnostic.tsx:79` calls `GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/<p>.supabase.co/functions/v1/make-server-bd42bc02/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1e5133d9dbc26c65", "name": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/public-test (src/app/components/A", "shortDescription": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/public-test (src/app/components/AuthDiagnostic.tsx:110)"}, "fullDescription": {"text": "`src/app/components/AuthDiagnostic.tsx:110` calls `GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/public-test` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/<p>.supabase.co/functions/v1/make-server-bd42bc02/public-test`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-49ef4af4cabbb711", "name": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/auth/me (src/app/components/AuthD", "shortDescription": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/auth/me (src/app/components/AuthDiagnostic.tsx:150)"}, "fullDescription": {"text": "`src/app/components/AuthDiagnostic.tsx:150` calls `GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/auth/me` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/<p>.supabase.co/functions/v1/make-server-bd42bc02/auth/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b038f917350a3b54", "name": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/create-admin (src/app/components", "shortDescription": {"text": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/create-admin (src/app/components/AuthDiagnostic.tsx:222)"}, "fullDescription": {"text": "`src/app/components/AuthDiagnostic.tsx:222` calls `POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/create-admin` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/<p>.supabase.co/functions/v1/make-server-bd42bc02/create-admin`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-970687aa5d0ed12c", "name": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/fix-user-profiles (src/app/compo", "shortDescription": {"text": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/fix-user-profiles (src/app/components/AuthDiagnostic.tsx:250)"}, "fullDescription": {"text": "`src/app/components/AuthDiagnostic.tsx:250` calls `POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/fix-user-profiles` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/<p>.supabase.co/functions/v1/make-server-bd42bc02/fix-user-profiles`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0d0a78b13d5ac66c", "name": "Dangling fetch: PATCH /users/me/password (src/app/pages/ChangePassword.tsx:68)", "shortDescription": {"text": "Dangling fetch: PATCH /users/me/password (src/app/pages/ChangePassword.tsx:68)"}, "fullDescription": {"text": "`src/app/pages/ChangePassword.tsx:68` calls `PATCH /users/me/password` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/users/me/password`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6655ed202371a5d6", "name": "Dangling fetch: GET /clients/${id} (src/app/pages/ClientDetails.tsx:38)", "shortDescription": {"text": "Dangling fetch: GET /clients/${id} (src/app/pages/ClientDetails.tsx:38)"}, "fullDescription": {"text": "`src/app/pages/ClientDetails.tsx:38` calls `GET /clients/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-19589d7c60879e87", "name": "Dangling fetch: GET /clients/${id}?refresh=true (src/app/pages/ClientDetails.tsx:95)", "shortDescription": {"text": "Dangling fetch: GET /clients/${id}?refresh=true (src/app/pages/ClientDetails.tsx:95)"}, "fullDescription": {"text": "`src/app/pages/ClientDetails.tsx:95` calls `GET /clients/${id}?refresh=true` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4505bfab8cb59bda", "name": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/auth/me (src/app/pages/ClientPort", "shortDescription": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/auth/me (src/app/pages/ClientPortalDashboard.tsx:42)"}, "fullDescription": {"text": "`src/app/pages/ClientPortalDashboard.tsx:42` calls `GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/auth/me` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/<p>.supabase.co/functions/v1/make-server-bd42bc02/auth/me`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0e07d75ccfda99d2", "name": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/my-data (src/app/pa", "shortDescription": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/my-data (src/app/pages/ClientPortalDashboard.tsx:61)"}, "fullDescription": {"text": "`src/app/pages/ClientPortalDashboard.tsx:61` calls `GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/my-data` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/<p>.supabase.co/functions/v1/make-server-bd42bc02/client-portal/my-data`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-452dd43c5c4a3bb4", "name": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/delete-account (sr", "shortDescription": {"text": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/delete-account (src/app/pages/ClientPortalDashboard.tsx:137)"}, "fullDescription": {"text": "`src/app/pages/ClientPortalDashboard.tsx:137` calls `POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/delete-account` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/<p>.supabase.co/functions/v1/make-server-bd42bc02/client-portal/delete-account`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aa85f509ff0f3ab4", "name": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/upload-document (s", "shortDescription": {"text": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/upload-document (src/app/pages/ClientPortalDashboard.tsx:174)"}, "fullDescription": {"text": "`src/app/pages/ClientPortalDashboard.tsx:174` calls `POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/upload-document` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/<p>.supabase.co/functions/v1/make-server-bd42bc02/client-portal/upload-document`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8089a1cd9c6070cd", "name": "Dangling fetch: GET /reminders/due-installments (src/app/pages/DueReminders.tsx:102)", "shortDescription": {"text": "Dangling fetch: GET /reminders/due-installments (src/app/pages/DueReminders.tsx:102)"}, "fullDescription": {"text": "`src/app/pages/DueReminders.tsx:102` calls `GET /reminders/due-installments` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/reminders/due-installments`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9d1cbe667cd9271a", "name": "Dangling fetch: GET /users (src/app/pages/Users.tsx:110)", "shortDescription": {"text": "Dangling fetch: GET /users (src/app/pages/Users.tsx:110)"}, "fullDescription": {"text": "`src/app/pages/Users.tsx:110` calls `GET /users` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/users`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b41e937d35f42ae4", "name": "Dangling fetch: DELETE /users/${userToDelete.id} (src/app/pages/Users.tsx:192)", "shortDescription": {"text": "Dangling fetch: DELETE /users/${userToDelete.id} (src/app/pages/Users.tsx:192)"}, "fullDescription": {"text": "`src/app/pages/Users.tsx:192` calls `DELETE /users/${userToDelete.id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/users/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-07bbac4e84b4324d", "name": "Dangling fetch: POST /users/${userToReset.id}/reset-password (src/app/pages/Users.tsx:217)", "shortDescription": {"text": "Dangling fetch: POST /users/${userToReset.id}/reset-password (src/app/pages/Users.tsx:217)"}, "fullDescription": {"text": "`src/app/pages/Users.tsx:217` calls `POST /users/${userToReset.id}/reset-password` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/users/<p>/reset-password`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8953842b8ee6cb4f", "name": "Dangling fetch: POST /users (src/app/pages/Users.tsx:291)", "shortDescription": {"text": "Dangling fetch: POST /users (src/app/pages/Users.tsx:291)"}, "fullDescription": {"text": "`src/app/pages/Users.tsx:291` calls `POST /users` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/users`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1bbea1a5bc1d7586", "name": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/signup (src/app/pa", "shortDescription": {"text": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/signup (src/app/pages/ClientPortalSignup.tsx:80)"}, "fullDescription": {"text": "`src/app/pages/ClientPortalSignup.tsx:80` calls `POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/signup` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/<p>.supabase.co/functions/v1/make-server-bd42bc02/client-portal/signup`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-210af7025317fe66", "name": "Dangling fetch: GET /billing/calendar?year=${year}&month=${month} (src/app/pages/BillingCalendar.tsx:113)", "shortDescription": {"text": "Dangling fetch: GET /billing/calendar?year=${year}&month=${month} (src/app/pages/BillingCalendar.tsx:113)"}, "fullDescription": {"text": "`src/app/pages/BillingCalendar.tsx:113` calls `GET /billing/calendar?year=${year}&month=${month}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/billing/calendar`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-75fb9be9e51ddd04", "name": "Dangling fetch: POST /contracts/${selected.contractId}/installments/${selected.number}/pay (src/app/pages/BillingCalenda", "shortDescription": {"text": "Dangling fetch: POST /contracts/${selected.contractId}/installments/${selected.number}/pay (src/app/pages/BillingCalendar.tsx:213)"}, "fullDescription": {"text": "`src/app/pages/BillingCalendar.tsx:213` calls `POST /contracts/${selected.contractId}/installments/${selected.number}/pay` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/contracts/<p>/installments/<p>/pay`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-787859ef4753b001", "name": "Dangling fetch: GET /financial/transactions/${id} (src/app/pages/TransactionDetails.tsx:68)", "shortDescription": {"text": "Dangling fetch: GET /financial/transactions/${id} (src/app/pages/TransactionDetails.tsx:68)"}, "fullDescription": {"text": "`src/app/pages/TransactionDetails.tsx:68` calls `GET /financial/transactions/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/financial/transactions/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d1bea03f3def8ae3", "name": "Dangling fetch: DELETE /financial/transactions/${id} (src/app/pages/TransactionDetails.tsx:84)", "shortDescription": {"text": "Dangling fetch: DELETE /financial/transactions/${id} (src/app/pages/TransactionDetails.tsx:84)"}, "fullDescription": {"text": "`src/app/pages/TransactionDetails.tsx:84` calls `DELETE /financial/transactions/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/financial/transactions/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1d467166527a844b", "name": "Dangling fetch: GET /client-portal/my-data (src/app/pages/ClientPortalFirstAccess.tsx:162)", "shortDescription": {"text": "Dangling fetch: GET /client-portal/my-data (src/app/pages/ClientPortalFirstAccess.tsx:162)"}, "fullDescription": {"text": "`src/app/pages/ClientPortalFirstAccess.tsx:162` calls `GET /client-portal/my-data` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/client-portal/my-data`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-60a3080ca7eadddd", "name": "Dangling fetch: GET /clients/${id} (src/app/pages/ClientForm.tsx:101)", "shortDescription": {"text": "Dangling fetch: GET /clients/${id} (src/app/pages/ClientForm.tsx:101)"}, "fullDescription": {"text": "`src/app/pages/ClientForm.tsx:101` calls `GET /clients/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8228a0698908d5b5", "name": "Dangling fetch: GET /clients/${clientId} (src/app/pages/ClientForm.tsx:126)", "shortDescription": {"text": "Dangling fetch: GET /clients/${clientId} (src/app/pages/ClientForm.tsx:126)"}, "fullDescription": {"text": "`src/app/pages/ClientForm.tsx:126` calls `GET /clients/${clientId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2027052ef86b485a", "name": "Dangling fetch: GET /clients/${clientId}/documents/${documentType} (src/app/pages/ClientForm.tsx:154)", "shortDescription": {"text": "Dangling fetch: GET /clients/${clientId}/documents/${documentType} (src/app/pages/ClientForm.tsx:154)"}, "fullDescription": {"text": "`src/app/pages/ClientForm.tsx:154` calls `GET /clients/${clientId}/documents/${documentType}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>/documents/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3d9c5747e8afc9d8", "name": "Dangling fetch: PUT /clients/${id} (src/app/pages/ClientForm.tsx:210)", "shortDescription": {"text": "Dangling fetch: PUT /clients/${id} (src/app/pages/ClientForm.tsx:210)"}, "fullDescription": {"text": "`src/app/pages/ClientForm.tsx:210` calls `PUT /clients/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6426306c412d4a63", "name": "Dangling fetch: POST /clients (src/app/pages/ClientForm.tsx:218)", "shortDescription": {"text": "Dangling fetch: POST /clients (src/app/pages/ClientForm.tsx:218)"}, "fullDescription": {"text": "`src/app/pages/ClientForm.tsx:218` calls `POST /clients` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7efd9109e616520c", "name": "Dangling fetch: GET /clients (src/app/pages/TransactionForm.tsx:96)", "shortDescription": {"text": "Dangling fetch: GET /clients (src/app/pages/TransactionForm.tsx:96)"}, "fullDescription": {"text": "`src/app/pages/TransactionForm.tsx:96` calls `GET /clients` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-40a19916dc275f5a", "name": "Dangling fetch: GET /financial/transactions/${id} (src/app/pages/TransactionForm.tsx:105)", "shortDescription": {"text": "Dangling fetch: GET /financial/transactions/${id} (src/app/pages/TransactionForm.tsx:105)"}, "fullDescription": {"text": "`src/app/pages/TransactionForm.tsx:105` calls `GET /financial/transactions/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/financial/transactions/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a8457acd51c4f29d", "name": "Dangling fetch: PUT /financial/transactions/${id} (src/app/pages/TransactionForm.tsx:134)", "shortDescription": {"text": "Dangling fetch: PUT /financial/transactions/${id} (src/app/pages/TransactionForm.tsx:134)"}, "fullDescription": {"text": "`src/app/pages/TransactionForm.tsx:134` calls `PUT /financial/transactions/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/financial/transactions/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ea6124da4826e04f", "name": "Dangling fetch: POST /financial/transactions (src/app/pages/TransactionForm.tsx:140)", "shortDescription": {"text": "Dangling fetch: POST /financial/transactions (src/app/pages/TransactionForm.tsx:140)"}, "fullDescription": {"text": "`src/app/pages/TransactionForm.tsx:140` calls `POST /financial/transactions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/financial/transactions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d99b2b2da949d4f1", "name": "Dangling fetch: GET /users (src/app/pages/Security.tsx:120)", "shortDescription": {"text": "Dangling fetch: GET /users (src/app/pages/Security.tsx:120)"}, "fullDescription": {"text": "`src/app/pages/Security.tsx:120` calls `GET /users` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/users`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7749b08b2dc178de", "name": "Dangling fetch: DELETE /users/${userToDelete.id} (src/app/pages/Security.tsx:234)", "shortDescription": {"text": "Dangling fetch: DELETE /users/${userToDelete.id} (src/app/pages/Security.tsx:234)"}, "fullDescription": {"text": "`src/app/pages/Security.tsx:234` calls `DELETE /users/${userToDelete.id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/users/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f5e9b19b0ef30134", "name": "Dangling fetch: POST /users/${userToReset.id}/reset-password (src/app/pages/Security.tsx:262)", "shortDescription": {"text": "Dangling fetch: POST /users/${userToReset.id}/reset-password (src/app/pages/Security.tsx:262)"}, "fullDescription": {"text": "`src/app/pages/Security.tsx:262` calls `POST /users/${userToReset.id}/reset-password` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/users/<p>/reset-password`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f7f2b227030c1e01", "name": "Dangling fetch: GET /client-portal/my-data (src/app/pages/ClientPortal.tsx:141)", "shortDescription": {"text": "Dangling fetch: GET /client-portal/my-data (src/app/pages/ClientPortal.tsx:141)"}, "fullDescription": {"text": "`src/app/pages/ClientPortal.tsx:141` calls `GET /client-portal/my-data` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/client-portal/my-data`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d39dd2c4e503cf2c", "name": "Dangling fetch: POST /client-portal/delete-account (src/app/pages/ClientPortal.tsx:231)", "shortDescription": {"text": "Dangling fetch: POST /client-portal/delete-account (src/app/pages/ClientPortal.tsx:231)"}, "fullDescription": {"text": "`src/app/pages/ClientPortal.tsx:231` calls `POST /client-portal/delete-account` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/client-portal/delete-account`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fc91728baadd7cb0", "name": "Dangling fetch: PATCH /users/me/password (src/app/pages/ClientPortal.tsx:277)", "shortDescription": {"text": "Dangling fetch: PATCH /users/me/password (src/app/pages/ClientPortal.tsx:277)"}, "fullDescription": {"text": "`src/app/pages/ClientPortal.tsx:277` calls `PATCH /users/me/password` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/users/me/password`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fb67895637e25ed9", "name": "Dangling fetch: GET /contracts/${id} (src/app/pages/ContractDetails.tsx:38)", "shortDescription": {"text": "Dangling fetch: GET /contracts/${id} (src/app/pages/ContractDetails.tsx:38)"}, "fullDescription": {"text": "`src/app/pages/ContractDetails.tsx:38` calls `GET /contracts/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/contracts/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8193329a4c0c5a47", "name": "Dangling fetch: POST /contracts/${id}/installments/${paymentDialog.installment.number}/pay (src/app/pages/ContractDetail", "shortDescription": {"text": "Dangling fetch: POST /contracts/${id}/installments/${paymentDialog.installment.number}/pay (src/app/pages/ContractDetails.tsx:52)"}, "fullDescription": {"text": "`src/app/pages/ContractDetails.tsx:52` calls `POST /contracts/${id}/installments/${paymentDialog.installment.number}/pay` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/contracts/<p>/installments/<p>/pay`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dc5a17055d32c820", "name": "Dangling fetch: POST /whatsapp/send-reminder (src/app/pages/ContractDetails.tsx:85)", "shortDescription": {"text": "Dangling fetch: POST /whatsapp/send-reminder (src/app/pages/ContractDetails.tsx:85)"}, "fullDescription": {"text": "`src/app/pages/ContractDetails.tsx:85` calls `POST /whatsapp/send-reminder` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/whatsapp/send-reminder`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-793b6317b91eb316", "name": "Dangling fetch: GET /financial?period=${selectedPeriod} (src/app/pages/Financial.tsx:89)", "shortDescription": {"text": "Dangling fetch: GET /financial?period=${selectedPeriod} (src/app/pages/Financial.tsx:89)"}, "fullDescription": {"text": "`src/app/pages/Financial.tsx:89` calls `GET /financial?period=${selectedPeriod}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/financial`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e3601689c79c8d5a", "name": "Dangling fetch: POST /financial/transactions (src/app/pages/Financial.tsx:210)", "shortDescription": {"text": "Dangling fetch: POST /financial/transactions (src/app/pages/Financial.tsx:210)"}, "fullDescription": {"text": "`src/app/pages/Financial.tsx:210` calls `POST /financial/transactions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/financial/transactions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fcf361043a9636e1", "name": "Dangling fetch: DELETE /financial/transactions/${transactionToDelete.id} (src/app/pages/Financial.tsx:239)", "shortDescription": {"text": "Dangling fetch: DELETE /financial/transactions/${transactionToDelete.id} (src/app/pages/Financial.tsx:239)"}, "fullDescription": {"text": "`src/app/pages/Financial.tsx:239` calls `DELETE /financial/transactions/${transactionToDelete.id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/financial/transactions/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c95350e017c9585c", "name": "Dangling fetch: GET /clients (src/app/pages/Clients.tsx:60)", "shortDescription": {"text": "Dangling fetch: GET /clients (src/app/pages/Clients.tsx:60)"}, "fullDescription": {"text": "`src/app/pages/Clients.tsx:60` calls `GET /clients` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9044b15ba66904b5", "name": "Dangling fetch: POST /seed (src/app/pages/Clients.tsx:80)", "shortDescription": {"text": "Dangling fetch: POST /seed (src/app/pages/Clients.tsx:80)"}, "fullDescription": {"text": "`src/app/pages/Clients.tsx:80` calls `POST /seed` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/seed`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-85f9f14d0b5aa0d2", "name": "Dangling fetch: GET /contracts (src/app/pages/Contracts.tsx:22)", "shortDescription": {"text": "Dangling fetch: GET /contracts (src/app/pages/Contracts.tsx:22)"}, "fullDescription": {"text": "`src/app/pages/Contracts.tsx:22` calls `GET /contracts` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/contracts`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-45332cfe6ed8d1e9", "name": "Dangling fetch: GET /contracts/${id} (src/app/pages/ContractForm.tsx:75)", "shortDescription": {"text": "Dangling fetch: GET /contracts/${id} (src/app/pages/ContractForm.tsx:75)"}, "fullDescription": {"text": "`src/app/pages/ContractForm.tsx:75` calls `GET /contracts/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/contracts/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a6e10c1cd3ff28d9", "name": "Dangling fetch: GET /clients (src/app/pages/ContractForm.tsx:100)", "shortDescription": {"text": "Dangling fetch: GET /clients (src/app/pages/ContractForm.tsx:100)"}, "fullDescription": {"text": "`src/app/pages/ContractForm.tsx:100` calls `GET /clients` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/clients`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b8f8ba9baeec1609", "name": "Dangling fetch: PUT /contracts/${id} (src/app/pages/ContractForm.tsx:127)", "shortDescription": {"text": "Dangling fetch: PUT /contracts/${id} (src/app/pages/ContractForm.tsx:127)"}, "fullDescription": {"text": "`src/app/pages/ContractForm.tsx:127` calls `PUT /contracts/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/contracts/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4524ec011d997e0e", "name": "Dangling fetch: POST /contracts (src/app/pages/ContractForm.tsx:135)", "shortDescription": {"text": "Dangling fetch: POST /contracts (src/app/pages/ContractForm.tsx:135)"}, "fullDescription": {"text": "`src/app/pages/ContractForm.tsx:135` calls `POST /contracts` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/contracts`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-507653df24e11da1", "name": "Dangling fetch: DELETE /contracts/${id} (src/app/pages/ContractForm.tsx:154)", "shortDescription": {"text": "Dangling fetch: DELETE /contracts/${id} (src/app/pages/ContractForm.tsx:154)"}, "fullDescription": {"text": "`src/app/pages/ContractForm.tsx:154` calls `DELETE /contracts/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/contracts/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b3e5e8705cef5b80", "name": "Dangling fetch: GET /dashboard/stats (src/app/pages/Dashboard.tsx:93)", "shortDescription": {"text": "Dangling fetch: GET /dashboard/stats (src/app/pages/Dashboard.tsx:93)"}, "fullDescription": {"text": "`src/app/pages/Dashboard.tsx:93` calls `GET /dashboard/stats` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/dashboard/stats`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2cf29b1f0c153564", "name": "Dangling fetch: POST /seed (src/app/pages/Dashboard.tsx:188)", "shortDescription": {"text": "Dangling fetch: POST /seed (src/app/pages/Dashboard.tsx:188)"}, "fullDescription": {"text": "`src/app/pages/Dashboard.tsx:188` calls `POST /seed` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:apiCall\nNormalized path used for matching: `/seed`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-26ccc33a874a0be3", "name": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/dashboard/stats (src/app/pages/Au", "shortDescription": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/dashboard/stats (src/app/pages/AuthDebug.tsx:137)"}, "fullDescription": {"text": "`src/app/pages/AuthDebug.tsx:137` calls `GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/dashboard/stats` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/<p>.supabase.co/functions/v1/make-server-bd42bc02/dashboard/stats`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3abf952b8d28d710", "name": "Unused endpoint: USE /*", "shortDescription": {"text": "Unused endpoint: USE /*"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `USE /*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-42ececebd7dbfb91", "name": "Unused endpoint: POST /make-server-bd42bc02/auth/signup", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/auth/signup"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/auth/signup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4238f2a11b60a0ce", "name": "Unused endpoint: GET /make-server-bd42bc02/auth/profile", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/auth/profile"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/auth/profile` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-584dfc2f6e1b1c9d", "name": "Unused endpoint: GET /make-server-bd42bc02/auth/me", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/auth/me"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/auth/me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-31371c9695958664", "name": "Unused endpoint: POST /make-server-bd42bc02/auth/forgot-password", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/auth/forgot-password"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/auth/forgot-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-36018da8ee6aaa33", "name": "Unused endpoint: POST /make-server-bd42bc02/auth/reset-password", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/auth/reset-password"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/auth/reset-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-544dda5ea3d6cb2f", "name": "Unused endpoint: POST /make-server-bd42bc02/clients", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/clients"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/clients` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-904c871b1d1c86be", "name": "Unused endpoint: GET /make-server-bd42bc02/clients", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/clients"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/clients` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0761fec1afceeedc", "name": "Unused endpoint: GET /make-server-bd42bc02/clients/:id", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/clients/:id"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/clients/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9ff3d67019cda8eb", "name": "Unused endpoint: PUT /make-server-bd42bc02/clients/:id", "shortDescription": {"text": "Unused endpoint: PUT /make-server-bd42bc02/clients/:id"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `PUT /make-server-bd42bc02/clients/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc09f436b6577994", "name": "Unused endpoint: POST /make-server-bd42bc02/clients/:id/documents", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/clients/:id/documents"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/clients/:id/documents` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b50f4afadfa2b251", "name": "Unused endpoint: GET /make-server-bd42bc02/clients/:id/documents/:type", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/clients/:id/documents/:type"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/clients/:id/documents/:type` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-081d6c6a78f413dd", "name": "Unused endpoint: DELETE /make-server-bd42bc02/clients/:id/documents/:type", "shortDescription": {"text": "Unused endpoint: DELETE /make-server-bd42bc02/clients/:id/documents/:type"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `DELETE /make-server-bd42bc02/clients/:id/documents/:type` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-504da4f5e1bce5e0", "name": "Unused endpoint: POST /make-server-bd42bc02/contracts", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/contracts"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/contracts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0e46ab5918ba0e9", "name": "Unused endpoint: PUT /make-server-bd42bc02/contracts/:id", "shortDescription": {"text": "Unused endpoint: PUT /make-server-bd42bc02/contracts/:id"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `PUT /make-server-bd42bc02/contracts/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff02c7fbcf668296", "name": "Unused endpoint: DELETE /make-server-bd42bc02/contracts/:id", "shortDescription": {"text": "Unused endpoint: DELETE /make-server-bd42bc02/contracts/:id"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `DELETE /make-server-bd42bc02/contracts/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-102d89e91364cc14", "name": "Unused endpoint: GET /make-server-bd42bc02/contracts", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/contracts"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/contracts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d5feb6635644e82", "name": "Unused endpoint: GET /make-server-bd42bc02/contracts/:id", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/contracts/:id"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/contracts/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1448b301807b861", "name": "Unused endpoint: POST /make-server-bd42bc02/contracts/:id/installments/:number/pay", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/contracts/:id/installments/:number/pay"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/contracts/:id/installments/:number/pay` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1978c7f31e46509c", "name": "Unused endpoint: POST /make-server-bd42bc02/whatsapp/send-reminder", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/whatsapp/send-reminder"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/whatsapp/send-reminder` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ff2ec6977d480973", "name": "Unused endpoint: POST /make-server-bd42bc02/whatsapp/send-location", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/whatsapp/send-location"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/whatsapp/send-location` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a0276892ab28af3f", "name": "Unused endpoint: GET /make-server-bd42bc02/reminders/due-installments", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/reminders/due-installments"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/reminders/due-installments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7085e8a72d2bbd2b", "name": "Unused endpoint: GET /make-server-bd42bc02/dashboard/stats", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/dashboard/stats"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/dashboard/stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-adcfb28bbbb4e3e4", "name": "Unused endpoint: GET /make-server-bd42bc02/audit-logs", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/audit-logs"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/audit-logs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-abed0639daf1329b", "name": "Unused endpoint: GET /make-server-bd42bc02/health", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/health"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-155c887dc6d5d246", "name": "Unused endpoint: POST /make-server-bd42bc02/public/register", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/public/register"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/public/register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-41b82ffb941b6860", "name": "Unused endpoint: POST /make-server-bd42bc02/public/register/:id/documents", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/public/register/:id/documents"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/public/register/:id/documents` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-159c1c90579dffa2", "name": "Unused endpoint: GET /make-server-bd42bc02/public-test", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/public-test"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/public-test` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-060e1924d2af4e82", "name": "Unused endpoint: GET /make-server-bd42bc02/debug/env", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/debug/env"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/debug/env` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4156c632e39b0ec5", "name": "Unused endpoint: POST /make-server-bd42bc02/debug/decode", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/debug/decode"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/debug/decode` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-edd92b0f0757c80b", "name": "Unused endpoint: POST /make-server-bd42bc02/seed", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/seed"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/seed` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09c52a023e1356e1", "name": "Unused endpoint: GET /make-server-bd42bc02/users", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/users"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/users` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b0cd5e101cdc429", "name": "Unused endpoint: POST /make-server-bd42bc02/users", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/users"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/users` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5cec787fe6b117ee", "name": "Unused endpoint: DELETE /make-server-bd42bc02/users/:userId", "shortDescription": {"text": "Unused endpoint: DELETE /make-server-bd42bc02/users/:userId"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `DELETE /make-server-bd42bc02/users/:userId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1d50ac485fb4e52c", "name": "Unused endpoint: POST /make-server-bd42bc02/users/:userId/reset-password", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/users/:userId/reset-password"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/users/:userId/reset-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cb975e9bbd52ef9a", "name": "Unused endpoint: GET /make-server-bd42bc02/ping", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/ping"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/ping` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-75df20dbee972969", "name": "Unused endpoint: GET /make-server-bd42bc02/diagnostic/data", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/diagnostic/data"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/diagnostic/data` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1efa5d6b52f0ce09", "name": "Unused endpoint: POST /make-server-bd42bc02/create-admin", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/create-admin"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/create-admin` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d51d7908d959dec7", "name": "Unused endpoint: POST /make-server-bd42bc02/fix-user-profiles", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/fix-user-profiles"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/fix-user-profiles` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c114a5bfb9af3b06", "name": "Unused endpoint: GET /make-server-bd42bc02/financial", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/financial"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/financial` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-067d94e27986e715", "name": "Unused endpoint: POST /make-server-bd42bc02/financial/transactions", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/financial/transactions"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/financial/transactions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-70f44ff398ea5e5a", "name": "Unused endpoint: GET /make-server-bd42bc02/financial/transactions/:id", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/financial/transactions/:id"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02/financial/transactions/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d32dbd1685acb5a", "name": "Unused endpoint: PUT /make-server-bd42bc02/financial/transactions/:id", "shortDescription": {"text": "Unused endpoint: PUT /make-server-bd42bc02/financial/transactions/:id"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `PUT /make-server-bd42bc02/financial/transactions/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-753e072ced31b309", "name": "Unused endpoint: DELETE /make-server-bd42bc02/financial/transactions/:id", "shortDescription": {"text": "Unused endpoint: DELETE /make-server-bd42bc02/financial/transactions/:id"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `DELETE /make-server-bd42bc02/financial/transactions/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e000e33abc136ca", "name": "Unused endpoint: POST /make-server-bd42bc02/users/:id/reset-password", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/users/:id/reset-password"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/users/:id/reset-password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a17e08f272a87124", "name": "Unused endpoint: PATCH /make-server-bd42bc02/users/me/password", "shortDescription": {"text": "Unused endpoint: PATCH /make-server-bd42bc02/users/me/password"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `PATCH /make-server-bd42bc02/users/me/password` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-630ecb9d5fbfff1c", "name": "Unused endpoint: POST /make-server-bd42bc02/users/migrate-operators", "shortDescription": {"text": "Unused endpoint: POST /make-server-bd42bc02/users/migrate-operators"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `POST /make-server-bd42bc02/users/migrate-operators` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-675cd81b942b0d90", "name": "Unused endpoint: DELETE /make-server-bd42bc02/users/:id", "shortDescription": {"text": "Unused endpoint: DELETE /make-server-bd42bc02/users/:id"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `DELETE /make-server-bd42bc02/users/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d2d224dd6a57a76", "name": "Unused endpoint: GET /make-server-bd42bc02", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/index.ts` declares `GET /make-server-bd42bc02` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a31057bad00e299", "name": "Unused endpoint: GET /make-server-bd42bc02/health/detailed", "shortDescription": {"text": "Unused endpoint: GET /make-server-bd42bc02/health/detailed"}, "fullDescription": {"text": "`supabase/functions/make-server-bd42bc02/health.tsx` declares `GET /make-server-bd42bc02/health/detailed` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/24773"}, "properties": {"repository": "byte4team-star/Emprestflow", "repoUrl": "https://github.com/byte4team-star/Emprestflow", "branch": "main"}, "results": [{"ruleId": "scanner-43544f05ad8eda9e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-date-correction.js:20"}, "properties": {"repobilityId": "28d7655e59c7b40a", "scanner": "scanner-primary", "fingerprint": "43544f05ad8eda9e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2eb7b1fe0115009d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/App.tsx:8"}, "properties": {"repobilityId": "a0957803aa891ea2", "scanner": "scanner-primary", "fingerprint": "2eb7b1fe0115009d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9c3ff7a7f2d71395", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/components/DocumentUploader.tsx:169"}, "properties": {"repobilityId": "4012832c2a336d46", "scanner": "scanner-primary", "fingerprint": "9c3ff7a7f2d71395", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-b6d32b882b83e8ec", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/components/DocumentUploader.tsx:68"}, "properties": {"repobilityId": "6503af6ea82b94d1", "scanner": "scanner-primary", "fingerprint": "b6d32b882b83e8ec", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7f859cbf98fc5d15", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/components/MediaGalleryUploader.tsx:52"}, "properties": {"repobilityId": "b06fa7a5904b3504", "scanner": "scanner-primary", "fingerprint": "7f859cbf98fc5d15", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-26e85d42f2935c57", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/components/FileUploadPreview.tsx:207"}, "properties": {"repobilityId": "89df34042f59cc09", "scanner": "scanner-primary", "fingerprint": "26e85d42f2935c57", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-a2035c22ccddc8ca", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/components/MediaDebug.tsx:130"}, "properties": {"repobilityId": "557fec447ac8cbf3", "scanner": "scanner-primary", "fingerprint": "a2035c22ccddc8ca", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-c3685f1afda4ef49", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/app/components/ui/chart.tsx:83"}, "properties": {"repobilityId": "2833a3e050ea5ebf", "scanner": "scanner-primary", "fingerprint": "c3685f1afda4ef49", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-6acdd9d183327f39", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ChangePassword.tsx:66"}, "properties": {"repobilityId": "f42a476aa4f77980", "scanner": "scanner-primary", "fingerprint": "6acdd9d183327f39", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5efa1c432aedf670", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientDetails.tsx:25"}, "properties": {"repobilityId": "db1f077cc574b95f", "scanner": "scanner-primary", "fingerprint": "5efa1c432aedf670", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-09a59c638e4baa58", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/DueReminders.tsx:569"}, "properties": {"repobilityId": "fd2742f90eea3c57", "scanner": "scanner-primary", "fingerprint": "09a59c638e4baa58", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-5284a53fdbcabf5c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/DueReminders.tsx:101"}, "properties": {"repobilityId": "f08945ef9b51d898", "scanner": "scanner-primary", "fingerprint": "5284a53fdbcabf5c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8d38963a38484826", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Users.tsx:497"}, "properties": {"repobilityId": "b4cb307cfeb01727", "scanner": "scanner-primary", "fingerprint": "8d38963a38484826", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-df30a02ff279a517", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientPortalLogin.tsx:34"}, "properties": {"repobilityId": "ef739336d134cf47", "scanner": "scanner-primary", "fingerprint": "df30a02ff279a517", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e8e84afa399d2ec6", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/BillingCalendar.tsx:322"}, "properties": {"repobilityId": "b005330317729e8e", "scanner": "scanner-primary", "fingerprint": "e8e84afa399d2ec6", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-5132d3ca32cad257", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientPortalFirstAccess.tsx:102"}, "properties": {"repobilityId": "beebc6e22d870e61", "scanner": "scanner-primary", "fingerprint": "5132d3ca32cad257", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-67e10d2c4f310c91", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientForm.tsx:82"}, "properties": {"repobilityId": "d82b14df144cdb3e", "scanner": "scanner-primary", "fingerprint": "67e10d2c4f310c91", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5e4b9f728d74c283", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Security.tsx:709"}, "properties": {"repobilityId": "0f63155f00f9ad63", "scanner": "scanner-primary", "fingerprint": "5e4b9f728d74c283", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-0c885be94a20722b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ClientPortal.tsx:111"}, "properties": {"repobilityId": "b8940de9d45509bf", "scanner": "scanner-primary", "fingerprint": "0c885be94a20722b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d45f4caf4c1d2762", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/Financial.tsx:128"}, "properties": {"repobilityId": "118f41a76a717958", "scanner": "scanner-primary", "fingerprint": "d45f4caf4c1d2762", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5c19b95ab2694e3f", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Clients.tsx:187"}, "properties": {"repobilityId": "55dacc8c1ec8d005", "scanner": "scanner-primary", "fingerprint": "5c19b95ab2694e3f", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-dc36fc5a5889c6a8", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/app/pages/Contracts.tsx:85"}, "properties": {"repobilityId": "d184573de5dd2969", "scanner": "scanner-primary", "fingerprint": "dc36fc5a5889c6a8", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-8d6b8ef7bb73553c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/ContractForm.tsx:123"}, "properties": {"repobilityId": "d056183f773aa713", "scanner": "scanner-primary", "fingerprint": "8d6b8ef7bb73553c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-56fa2b24c4f4e69c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/pages/Dashboard.tsx:162"}, "properties": {"repobilityId": "ba1dbd9c9a711612", "scanner": "scanner-primary", "fingerprint": "56fa2b24c4f4e69c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-890d57fbb5e57ce8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/lib/auth-context.tsx:7"}, "properties": {"repobilityId": "fc9bee7ce8ac7142", "scanner": "scanner-primary", "fingerprint": "890d57fbb5e57ce8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-75026788b7e16ca9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/app/lib/supabase.ts:54"}, "properties": {"repobilityId": "bfe4aa444fdb838f", "scanner": "scanner-primary", "fingerprint": "75026788b7e16ca9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1ce82729d889117d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/make-server-bd42bc02/index.ts:23"}, "properties": {"repobilityId": "11949a0d863aa1d7", "scanner": "scanner-primary", "fingerprint": "1ce82729d889117d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0a7bf360a00e9f41", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/make-server-bd42bc02/billing_routes.tsx:80"}, "properties": {"repobilityId": "b7991f32909093cd", "scanner": "scanner-primary", "fingerprint": "0a7bf360a00e9f41", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-bf0c62b972aab979", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/server/index.tsx:23"}, "properties": {"repobilityId": "da1f1a0f9c12da36", "scanner": "scanner-primary", "fingerprint": "bf0c62b972aab979", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-54f8453c027db8d5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 supabase/functions/server/billing_routes.tsx:80"}, "properties": {"repobilityId": "54fe95ddcd1c947d", "scanner": "scanner-primary", "fingerprint": "54f8453c027db8d5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fce42693cd5ceb5f", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in test-edge-function.html:255"}, "properties": {"repobilityId": "7b7c701d07afe0a2", "scanner": "scanner-primary", "fingerprint": "fce42693cd5ceb5f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "test-edge-function.html"}, "region": {"startLine": 255}}}]}, {"ruleId": "scanner-d88d4aa2505d499e", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in test-timezone-fix.html:260"}, "properties": {"repobilityId": "e5ebcf5ebe993c0a", "scanner": "scanner-primary", "fingerprint": "d88d4aa2505d499e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "test-timezone-fix.html"}, "region": {"startLine": 260}}}]}, {"ruleId": "scanner-b9126e87d6aff98d", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in test-deploy-corrigido.html:283"}, "properties": {"repobilityId": "52380cc87b565a2e", "scanner": "scanner-primary", "fingerprint": "b9126e87d6aff98d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "test-deploy-corrigido.html"}, "region": {"startLine": 283}}}]}, {"ruleId": "scanner-197323a1df0bc584", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in src/app/components/ui/chart.tsx:83"}, "properties": {"repobilityId": "52023baf88f4153e", "scanner": "scanner-primary", "fingerprint": "197323a1df0bc584", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/app/components/ui/chart.tsx"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-673c381ae96f5de6", "level": "error", "message": {"text": "Possible secret in supabase/functions/make-server-bd42bc02/index.ts"}, "properties": {"repobilityId": "efc3466031ce65a0", "scanner": "scanner-primary", "fingerprint": "673c381ae96f5de6", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/make-server-bd42bc02/index.ts"}, "region": {"startLine": 351}}}]}, {"ruleId": "scanner-673c381ae96f5de6", "level": "error", "message": {"text": "Possible secret in supabase/functions/make-server-bd42bc02/index.ts"}, "properties": {"repobilityId": "efc3466031ce65a0", "scanner": "scanner-primary", "fingerprint": "673c381ae96f5de6", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/make-server-bd42bc02/index.ts"}, "region": {"startLine": 3304}}}]}, {"ruleId": "scanner-73bd625eeec26f0c", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/make-server-bd42bc02/index.ts:73"}, "properties": {"repobilityId": "b15751803d8b2db7", "scanner": "scanner-primary", "fingerprint": "73bd625eeec26f0c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/make-server-bd42bc02/index.ts"}, "region": {"startLine": 73}}}]}, {"ruleId": "scanner-2a3ddac7fe26b446", "level": "error", "message": {"text": "Possible secret in supabase/functions/server/index.tsx"}, "properties": {"repobilityId": "17eb2bac7415efe7", "scanner": "scanner-primary", "fingerprint": "2a3ddac7fe26b446", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/server/index.tsx"}, "region": {"startLine": 351}}}]}, {"ruleId": "scanner-2a3ddac7fe26b446", "level": "error", "message": {"text": "Possible secret in supabase/functions/server/index.tsx"}, "properties": {"repobilityId": "17eb2bac7415efe7", "scanner": "scanner-primary", "fingerprint": "2a3ddac7fe26b446", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/server/index.tsx"}, "region": {"startLine": 3304}}}]}, {"ruleId": "scanner-02317ff5ee0f9845", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in supabase/functions/server/index.tsx:73"}, "properties": {"repobilityId": "436eb6ff42447821", "scanner": "scanner-primary", "fingerprint": "02317ff5ee0f9845", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "supabase/functions/server/index.tsx"}, "region": {"startLine": 73}}}]}, {"ruleId": "scanner-334e2eb221793f12", "level": "note", "message": {"text": "Very large file: src/app/pages/ClientPortalFirstAccess.tsx (1405 lines)"}, "properties": {"repobilityId": "a05f7045509e1a39", "scanner": "scanner-primary", "fingerprint": "334e2eb221793f12", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-4efdaf9a35e62d9b", "level": "note", "message": {"text": "Very large file: supabase/functions/make-server-bd42bc02/index.ts (4241 lines)"}, "properties": {"repobilityId": "570c395f45daa645", "scanner": "scanner-primary", "fingerprint": "4efdaf9a35e62d9b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-312f8713d1dcf6ae", "level": "note", "message": {"text": "Very large file: supabase/functions/server/index.tsx (4241 lines)"}, "properties": {"repobilityId": "a3c3a35a70b169c9", "scanner": "scanner-primary", "fingerprint": "312f8713d1dcf6ae", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "df3b7b53fb2918f0", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "7a52777495bb498d", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "b5fcf2edc8899d9c", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "7d0fead39b8c4245", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "cb44853452a5daba", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ece74b3f7868b269", "level": "note", "message": {"text": "Legacy-named symbol `dateOld` in test-date-correction.js:139"}, "properties": {"repobilityId": "41d6ade360454f29", "scanner": "scanner-primary", "fingerprint": "ece74b3f7868b269", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-e9018da4e8269a6e", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/app/utils/dateUtils.ts:180"}, "properties": {"repobilityId": "a107a29f551c68e4", "scanner": "scanner-primary", "fingerprint": "e9018da4e8269a6e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bb43ef13dda191a2", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/pages/ClientPortalDashboard.tsx:42"}, "properties": {"repobilityId": "612afd73a43a141b", "scanner": "scanner-primary", "fingerprint": "bb43ef13dda191a2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f6be4b666c0b4696", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/pages/ClientPortalFirstAccess.tsx:446"}, "properties": {"repobilityId": "8d9484cd56836253", "scanner": "scanner-primary", "fingerprint": "f6be4b666c0b4696", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-065e29ce26dca180", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/app/lib/auth-context.tsx:158"}, "properties": {"repobilityId": "28063737a47b597c", "scanner": "scanner-primary", "fingerprint": "065e29ce26dca180", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f9f34c267ad61024", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/make-server-bd42bc02/index.ts:672"}, "properties": {"repobilityId": "ee36117037a5ac2a", "scanner": "scanner-primary", "fingerprint": "f9f34c267ad61024", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7cfacb316a75d777", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/make-server-bd42bc02/billing_routes.tsx:386"}, "properties": {"repobilityId": "9afce877fc5bfcef", "scanner": "scanner-primary", "fingerprint": "7cfacb316a75d777", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0d392cfa1d00aee4", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/server/index.tsx:672"}, "properties": {"repobilityId": "641451d3e001c15c", "scanner": "scanner-primary", "fingerprint": "0d392cfa1d00aee4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7853efe3c457a609", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 supabase/functions/server/billing_routes.tsx:386"}, "properties": {"repobilityId": "d1f1c23d4cd5f49d", "scanner": "scanner-primary", "fingerprint": "7853efe3c457a609", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-27e0717c1925f0d8", "level": "error", "message": {"text": "Dangling fetch: POST /clients/${clientId}/documents (src/app/components/DocumentUploader.tsx:56)"}, "properties": {"repobilityId": "1d22d4fd0a0fa700", "scanner": "scanner-primary", "fingerprint": "27e0717c1925f0d8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-7a6b60fbde1b143c", "level": "error", "message": {"text": "Dangling fetch: GET /clients/${clientId}?_t=${timestamp} (src/app/components/MediaGalleryUploader.tsx:56)"}, "properties": {"repobilityId": "1c4893981e0389b7", "scanner": "scanner-primary", "fingerprint": "7a6b60fbde1b143c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-273c9d98128d5161", "level": "error", "message": {"text": "Dangling fetch: GET /clients/${clientId}/documents/${key}?_t=${timestamp} (src/app/components/MediaGalleryUploader.tsx:96)"}, "properties": {"repobilityId": "f89ea0971620044f", "scanner": "scanner-primary", "fingerprint": "273c9d98128d5161", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-e5a92ee01bc9744b", "level": "error", "message": {"text": "Dangling fetch: POST /clients/${clientId}/documents (src/app/components/MediaGalleryUploader.tsx:176)"}, "properties": {"repobilityId": "01082ad92cbeeac4", "scanner": "scanner-primary", "fingerprint": "e5a92ee01bc9744b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-a36b41a399e9fc99", "level": "error", "message": {"text": "Dangling fetch: GET /clients/${clientId}?_t=${timestamp} (src/app/components/MediaGalleryUploader.tsx:221)"}, "properties": {"repobilityId": "0ba6d7ea77f01a42", "scanner": "scanner-primary", "fingerprint": "a36b41a399e9fc99", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-365f976c8870f662", "level": "error", "message": {"text": "Dangling fetch: DELETE /clients/${clientId}/documents/${key} (src/app/components/MediaGalleryUploader.tsx:253)"}, "properties": {"repobilityId": "566b229c1fd4918b", "scanner": "scanner-primary", "fingerprint": "365f976c8870f662", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-d4bb72a44acd9faf", "level": "error", "message": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/health (src/app/components/AuthDiagnostic.tsx:79)"}, "properties": {"repobilityId": "bd64c80d350a27cd", "scanner": "scanner-primary", "fingerprint": "d4bb72a44acd9faf", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-1e5133d9dbc26c65", "level": "error", "message": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/public-test (src/app/components/AuthDiagnostic.tsx:110)"}, "properties": {"repobilityId": "0a85f172c0f4c3aa", "scanner": "scanner-primary", "fingerprint": "1e5133d9dbc26c65", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-49ef4af4cabbb711", "level": "error", "message": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/auth/me (src/app/components/AuthDiagnostic.tsx:150)"}, "properties": {"repobilityId": "38d16594d6851892", "scanner": "scanner-primary", "fingerprint": "49ef4af4cabbb711", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b038f917350a3b54", "level": "error", "message": {"text": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/create-admin (src/app/components/AuthDiagnostic.tsx:222)"}, "properties": {"repobilityId": "9ac3ecf9deed7c54", "scanner": "scanner-primary", "fingerprint": "b038f917350a3b54", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-970687aa5d0ed12c", "level": "error", "message": {"text": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/fix-user-profiles (src/app/components/AuthDiagnostic.tsx:250)"}, "properties": {"repobilityId": "b7ab7d65048d49bd", "scanner": "scanner-primary", "fingerprint": "970687aa5d0ed12c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-0d0a78b13d5ac66c", "level": "error", "message": {"text": "Dangling fetch: PATCH /users/me/password (src/app/pages/ChangePassword.tsx:68)"}, "properties": {"repobilityId": "a31d2cda48f748f3", "scanner": "scanner-primary", "fingerprint": "0d0a78b13d5ac66c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-6655ed202371a5d6", "level": "error", "message": {"text": "Dangling fetch: GET /clients/${id} (src/app/pages/ClientDetails.tsx:38)"}, "properties": {"repobilityId": "788c38c7af6ec28c", "scanner": "scanner-primary", "fingerprint": "6655ed202371a5d6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-19589d7c60879e87", "level": "error", "message": {"text": "Dangling fetch: GET /clients/${id}?refresh=true (src/app/pages/ClientDetails.tsx:95)"}, "properties": {"repobilityId": "224568895e96e872", "scanner": "scanner-primary", "fingerprint": "19589d7c60879e87", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-4505bfab8cb59bda", "level": "error", "message": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/auth/me (src/app/pages/ClientPortalDashboard.tsx:42)"}, "properties": {"repobilityId": "93541b12b5cddc4f", "scanner": "scanner-primary", "fingerprint": "4505bfab8cb59bda", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-0e07d75ccfda99d2", "level": "error", "message": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/my-data (src/app/pages/ClientPortalDashboard.tsx:61)"}, "properties": {"repobilityId": "3954d8106b07333c", "scanner": "scanner-primary", "fingerprint": "0e07d75ccfda99d2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-452dd43c5c4a3bb4", "level": "error", "message": {"text": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/delete-account (src/app/pages/ClientPortalDashboard.tsx:137)"}, "properties": {"repobilityId": "03b64fd1bfcd53e9", "scanner": "scanner-primary", "fingerprint": "452dd43c5c4a3bb4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-aa85f509ff0f3ab4", "level": "error", "message": {"text": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/upload-document (src/app/pages/ClientPortalDashboard.tsx:174)"}, "properties": {"repobilityId": "69417f4fbda35df1", "scanner": "scanner-primary", "fingerprint": "aa85f509ff0f3ab4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-8089a1cd9c6070cd", "level": "error", "message": {"text": "Dangling fetch: GET /reminders/due-installments (src/app/pages/DueReminders.tsx:102)"}, "properties": {"repobilityId": "9f2e8b6a2a43de93", "scanner": "scanner-primary", "fingerprint": "8089a1cd9c6070cd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-9d1cbe667cd9271a", "level": "error", "message": {"text": "Dangling fetch: GET /users (src/app/pages/Users.tsx:110)"}, "properties": {"repobilityId": "e62a82790806d965", "scanner": "scanner-primary", "fingerprint": "9d1cbe667cd9271a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-b41e937d35f42ae4", "level": "error", "message": {"text": "Dangling fetch: DELETE /users/${userToDelete.id} (src/app/pages/Users.tsx:192)"}, "properties": {"repobilityId": "7205c42f4f1e5713", "scanner": "scanner-primary", "fingerprint": "b41e937d35f42ae4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-07bbac4e84b4324d", "level": "error", "message": {"text": "Dangling fetch: POST /users/${userToReset.id}/reset-password (src/app/pages/Users.tsx:217)"}, "properties": {"repobilityId": "ad58cabc42253e23", "scanner": "scanner-primary", "fingerprint": "07bbac4e84b4324d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-8953842b8ee6cb4f", "level": "error", "message": {"text": "Dangling fetch: POST /users (src/app/pages/Users.tsx:291)"}, "properties": {"repobilityId": "7de5c70b845cc312", "scanner": "scanner-primary", "fingerprint": "8953842b8ee6cb4f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-1bbea1a5bc1d7586", "level": "error", "message": {"text": "Dangling fetch: POST https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/client-portal/signup (src/app/pages/ClientPortalSignup.tsx:80)"}, "properties": {"repobilityId": "a730f7feb9d55fdf", "scanner": "scanner-primary", "fingerprint": "1bbea1a5bc1d7586", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-210af7025317fe66", "level": "error", "message": {"text": "Dangling fetch: GET /billing/calendar?year=${year}&month=${month} (src/app/pages/BillingCalendar.tsx:113)"}, "properties": {"repobilityId": "69ef9359a817d276", "scanner": "scanner-primary", "fingerprint": "210af7025317fe66", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-75fb9be9e51ddd04", "level": "error", "message": {"text": "Dangling fetch: POST /contracts/${selected.contractId}/installments/${selected.number}/pay (src/app/pages/BillingCalendar.tsx:213)"}, "properties": {"repobilityId": "215bb77d4260c108", "scanner": "scanner-primary", "fingerprint": "75fb9be9e51ddd04", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-787859ef4753b001", "level": "error", "message": {"text": "Dangling fetch: GET /financial/transactions/${id} (src/app/pages/TransactionDetails.tsx:68)"}, "properties": {"repobilityId": "4baf52dc0d13fea0", "scanner": "scanner-primary", "fingerprint": "787859ef4753b001", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-d1bea03f3def8ae3", "level": "error", "message": {"text": "Dangling fetch: DELETE /financial/transactions/${id} (src/app/pages/TransactionDetails.tsx:84)"}, "properties": {"repobilityId": "0c89f553a5251f81", "scanner": "scanner-primary", "fingerprint": "d1bea03f3def8ae3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-1d467166527a844b", "level": "error", "message": {"text": "Dangling fetch: GET /client-portal/my-data (src/app/pages/ClientPortalFirstAccess.tsx:162)"}, "properties": {"repobilityId": "24f93b63102d3518", "scanner": "scanner-primary", "fingerprint": "1d467166527a844b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-60a3080ca7eadddd", "level": "error", "message": {"text": "Dangling fetch: GET /clients/${id} (src/app/pages/ClientForm.tsx:101)"}, "properties": {"repobilityId": "8a247315b06b6a60", "scanner": "scanner-primary", "fingerprint": "60a3080ca7eadddd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-8228a0698908d5b5", "level": "error", "message": {"text": "Dangling fetch: GET /clients/${clientId} (src/app/pages/ClientForm.tsx:126)"}, "properties": {"repobilityId": "d0071930cc9474b5", "scanner": "scanner-primary", "fingerprint": "8228a0698908d5b5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-2027052ef86b485a", "level": "error", "message": {"text": "Dangling fetch: GET /clients/${clientId}/documents/${documentType} (src/app/pages/ClientForm.tsx:154)"}, "properties": {"repobilityId": "4c556ffe3e47a471", "scanner": "scanner-primary", "fingerprint": "2027052ef86b485a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-3d9c5747e8afc9d8", "level": "error", "message": {"text": "Dangling fetch: PUT /clients/${id} (src/app/pages/ClientForm.tsx:210)"}, "properties": {"repobilityId": "f912792544cf5c16", "scanner": "scanner-primary", "fingerprint": "3d9c5747e8afc9d8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-6426306c412d4a63", "level": "error", "message": {"text": "Dangling fetch: POST /clients (src/app/pages/ClientForm.tsx:218)"}, "properties": {"repobilityId": "444653e1c12e3adb", "scanner": "scanner-primary", "fingerprint": "6426306c412d4a63", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-7efd9109e616520c", "level": "error", "message": {"text": "Dangling fetch: GET /clients (src/app/pages/TransactionForm.tsx:96)"}, "properties": {"repobilityId": "ed54c0338462f0f5", "scanner": "scanner-primary", "fingerprint": "7efd9109e616520c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-40a19916dc275f5a", "level": "error", "message": {"text": "Dangling fetch: GET /financial/transactions/${id} (src/app/pages/TransactionForm.tsx:105)"}, "properties": {"repobilityId": "3d7d282ddd51a33b", "scanner": "scanner-primary", "fingerprint": "40a19916dc275f5a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-a8457acd51c4f29d", "level": "error", "message": {"text": "Dangling fetch: PUT /financial/transactions/${id} (src/app/pages/TransactionForm.tsx:134)"}, "properties": {"repobilityId": "40703dbfa65b7d17", "scanner": "scanner-primary", "fingerprint": "a8457acd51c4f29d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-ea6124da4826e04f", "level": "error", "message": {"text": "Dangling fetch: POST /financial/transactions (src/app/pages/TransactionForm.tsx:140)"}, "properties": {"repobilityId": "7908f1b6d4a50963", "scanner": "scanner-primary", "fingerprint": "ea6124da4826e04f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-d99b2b2da949d4f1", "level": "error", "message": {"text": "Dangling fetch: GET /users (src/app/pages/Security.tsx:120)"}, "properties": {"repobilityId": "7c6b41fb51048fba", "scanner": "scanner-primary", "fingerprint": "d99b2b2da949d4f1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-7749b08b2dc178de", "level": "error", "message": {"text": "Dangling fetch: DELETE /users/${userToDelete.id} (src/app/pages/Security.tsx:234)"}, "properties": {"repobilityId": "631ff855d52bd9e6", "scanner": "scanner-primary", "fingerprint": "7749b08b2dc178de", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-f5e9b19b0ef30134", "level": "error", "message": {"text": "Dangling fetch: POST /users/${userToReset.id}/reset-password (src/app/pages/Security.tsx:262)"}, "properties": {"repobilityId": "a896a23275ebd59d", "scanner": "scanner-primary", "fingerprint": "f5e9b19b0ef30134", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-f7f2b227030c1e01", "level": "error", "message": {"text": "Dangling fetch: GET /client-portal/my-data (src/app/pages/ClientPortal.tsx:141)"}, "properties": {"repobilityId": "ec3c1ca184f9a599", "scanner": "scanner-primary", "fingerprint": "f7f2b227030c1e01", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-d39dd2c4e503cf2c", "level": "error", "message": {"text": "Dangling fetch: POST /client-portal/delete-account (src/app/pages/ClientPortal.tsx:231)"}, "properties": {"repobilityId": "a707f994986f2e53", "scanner": "scanner-primary", "fingerprint": "d39dd2c4e503cf2c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-fc91728baadd7cb0", "level": "error", "message": {"text": "Dangling fetch: PATCH /users/me/password (src/app/pages/ClientPortal.tsx:277)"}, "properties": {"repobilityId": "c38b991bd5e24d03", "scanner": "scanner-primary", "fingerprint": "fc91728baadd7cb0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-fb67895637e25ed9", "level": "error", "message": {"text": "Dangling fetch: GET /contracts/${id} (src/app/pages/ContractDetails.tsx:38)"}, "properties": {"repobilityId": "3f9d040c8c35788e", "scanner": "scanner-primary", "fingerprint": "fb67895637e25ed9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-8193329a4c0c5a47", "level": "error", "message": {"text": "Dangling fetch: POST /contracts/${id}/installments/${paymentDialog.installment.number}/pay (src/app/pages/ContractDetails.tsx:52)"}, "properties": {"repobilityId": "c20e1be59246951c", "scanner": "scanner-primary", "fingerprint": "8193329a4c0c5a47", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-dc5a17055d32c820", "level": "error", "message": {"text": "Dangling fetch: POST /whatsapp/send-reminder (src/app/pages/ContractDetails.tsx:85)"}, "properties": {"repobilityId": "aa991cbb38e44292", "scanner": "scanner-primary", "fingerprint": "dc5a17055d32c820", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-793b6317b91eb316", "level": "error", "message": {"text": "Dangling fetch: GET /financial?period=${selectedPeriod} (src/app/pages/Financial.tsx:89)"}, "properties": {"repobilityId": "d21c725328ac0d81", "scanner": "scanner-primary", "fingerprint": "793b6317b91eb316", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-e3601689c79c8d5a", "level": "error", "message": {"text": "Dangling fetch: POST /financial/transactions (src/app/pages/Financial.tsx:210)"}, "properties": {"repobilityId": "9249a2606705d6a2", "scanner": "scanner-primary", "fingerprint": "e3601689c79c8d5a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-fcf361043a9636e1", "level": "error", "message": {"text": "Dangling fetch: DELETE /financial/transactions/${transactionToDelete.id} (src/app/pages/Financial.tsx:239)"}, "properties": {"repobilityId": "e58f453401978d71", "scanner": "scanner-primary", "fingerprint": "fcf361043a9636e1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-c95350e017c9585c", "level": "error", "message": {"text": "Dangling fetch: GET /clients (src/app/pages/Clients.tsx:60)"}, "properties": {"repobilityId": "94b57f5e44d2e836", "scanner": "scanner-primary", "fingerprint": "c95350e017c9585c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-9044b15ba66904b5", "level": "error", "message": {"text": "Dangling fetch: POST /seed (src/app/pages/Clients.tsx:80)"}, "properties": {"repobilityId": "c4b987c699c4fdbd", "scanner": "scanner-primary", "fingerprint": "9044b15ba66904b5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-85f9f14d0b5aa0d2", "level": "error", "message": {"text": "Dangling fetch: GET /contracts (src/app/pages/Contracts.tsx:22)"}, "properties": {"repobilityId": "60cc3c9f3e7e1495", "scanner": "scanner-primary", "fingerprint": "85f9f14d0b5aa0d2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-45332cfe6ed8d1e9", "level": "error", "message": {"text": "Dangling fetch: GET /contracts/${id} (src/app/pages/ContractForm.tsx:75)"}, "properties": {"repobilityId": "5e9867e1b61cc421", "scanner": "scanner-primary", "fingerprint": "45332cfe6ed8d1e9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-a6e10c1cd3ff28d9", "level": "error", "message": {"text": "Dangling fetch: GET /clients (src/app/pages/ContractForm.tsx:100)"}, "properties": {"repobilityId": "5672dd47d421b92c", "scanner": "scanner-primary", "fingerprint": "a6e10c1cd3ff28d9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-b8f8ba9baeec1609", "level": "error", "message": {"text": "Dangling fetch: PUT /contracts/${id} (src/app/pages/ContractForm.tsx:127)"}, "properties": {"repobilityId": "e2004d2b80be2bc8", "scanner": "scanner-primary", "fingerprint": "b8f8ba9baeec1609", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-4524ec011d997e0e", "level": "error", "message": {"text": "Dangling fetch: POST /contracts (src/app/pages/ContractForm.tsx:135)"}, "properties": {"repobilityId": "e887e9d964d301a5", "scanner": "scanner-primary", "fingerprint": "4524ec011d997e0e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-507653df24e11da1", "level": "error", "message": {"text": "Dangling fetch: DELETE /contracts/${id} (src/app/pages/ContractForm.tsx:154)"}, "properties": {"repobilityId": "535036a669577c98", "scanner": "scanner-primary", "fingerprint": "507653df24e11da1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-b3e5e8705cef5b80", "level": "error", "message": {"text": "Dangling fetch: GET /dashboard/stats (src/app/pages/Dashboard.tsx:93)"}, "properties": {"repobilityId": "28e0dd0ab42db197", "scanner": "scanner-primary", "fingerprint": "b3e5e8705cef5b80", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-2cf29b1f0c153564", "level": "error", "message": {"text": "Dangling fetch: POST /seed (src/app/pages/Dashboard.tsx:188)"}, "properties": {"repobilityId": "0047a17448a52df3", "scanner": "scanner-primary", "fingerprint": "2cf29b1f0c153564", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:apiCall"]}}, {"ruleId": "scanner-26ccc33a874a0be3", "level": "error", "message": {"text": "Dangling fetch: GET https://${projectId}.supabase.co/functions/v1/make-server-bd42bc02/dashboard/stats (src/app/pages/AuthDebug.tsx:137)"}, "properties": {"repobilityId": "d1aa6e5b1a540703", "scanner": "scanner-primary", "fingerprint": "26ccc33a874a0be3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3abf952b8d28d710", "level": "note", "message": {"text": "Unused endpoint: USE /*"}, "properties": {"repobilityId": "309fe8e885069226", "scanner": "scanner-primary", "fingerprint": "3abf952b8d28d710", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-42ececebd7dbfb91", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/auth/signup"}, "properties": {"repobilityId": "4f7929c233dddb42", "scanner": "scanner-primary", "fingerprint": "42ececebd7dbfb91", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4238f2a11b60a0ce", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/auth/profile"}, "properties": {"repobilityId": "dc2cc31dded1f290", "scanner": "scanner-primary", "fingerprint": "4238f2a11b60a0ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-584dfc2f6e1b1c9d", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/auth/me"}, "properties": {"repobilityId": "2570ee5185185e0b", "scanner": "scanner-primary", "fingerprint": "584dfc2f6e1b1c9d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-31371c9695958664", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/auth/forgot-password"}, "properties": {"repobilityId": "5a551bfa8179f2c3", "scanner": "scanner-primary", "fingerprint": "31371c9695958664", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-36018da8ee6aaa33", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/auth/reset-password"}, "properties": {"repobilityId": "e7f942524090221f", "scanner": "scanner-primary", "fingerprint": "36018da8ee6aaa33", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-544dda5ea3d6cb2f", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/clients"}, "properties": {"repobilityId": "fb2d8700577453c2", "scanner": "scanner-primary", "fingerprint": "544dda5ea3d6cb2f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-904c871b1d1c86be", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/clients"}, "properties": {"repobilityId": "393e9335ffd67cbc", "scanner": "scanner-primary", "fingerprint": "904c871b1d1c86be", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0761fec1afceeedc", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/clients/:id"}, "properties": {"repobilityId": "d3418ae0b2873c8f", "scanner": "scanner-primary", "fingerprint": "0761fec1afceeedc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9ff3d67019cda8eb", "level": "note", "message": {"text": "Unused endpoint: PUT /make-server-bd42bc02/clients/:id"}, "properties": {"repobilityId": "f94f6f85ed9727ee", "scanner": "scanner-primary", "fingerprint": "9ff3d67019cda8eb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dc09f436b6577994", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/clients/:id/documents"}, "properties": {"repobilityId": "792c00a1ab6c1c4a", "scanner": "scanner-primary", "fingerprint": "dc09f436b6577994", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b50f4afadfa2b251", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/clients/:id/documents/:type"}, "properties": {"repobilityId": "5769673ded7d58f6", "scanner": "scanner-primary", "fingerprint": "b50f4afadfa2b251", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-081d6c6a78f413dd", "level": "note", "message": {"text": "Unused endpoint: DELETE /make-server-bd42bc02/clients/:id/documents/:type"}, "properties": {"repobilityId": "90b759ab8417cc80", "scanner": "scanner-primary", "fingerprint": "081d6c6a78f413dd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-504da4f5e1bce5e0", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/contracts"}, "properties": {"repobilityId": "e994aea9557b7dac", "scanner": "scanner-primary", "fingerprint": "504da4f5e1bce5e0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e0e46ab5918ba0e9", "level": "note", "message": {"text": "Unused endpoint: PUT /make-server-bd42bc02/contracts/:id"}, "properties": {"repobilityId": "9bea23df6c02de00", "scanner": "scanner-primary", "fingerprint": "e0e46ab5918ba0e9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ff02c7fbcf668296", "level": "note", "message": {"text": "Unused endpoint: DELETE /make-server-bd42bc02/contracts/:id"}, "properties": {"repobilityId": "868d317282023fd6", "scanner": "scanner-primary", "fingerprint": "ff02c7fbcf668296", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-102d89e91364cc14", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/contracts"}, "properties": {"repobilityId": "fd4b82867d00da44", "scanner": "scanner-primary", "fingerprint": "102d89e91364cc14", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5d5feb6635644e82", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/contracts/:id"}, "properties": {"repobilityId": "37d3ea5961595e0f", "scanner": "scanner-primary", "fingerprint": "5d5feb6635644e82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e1448b301807b861", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/contracts/:id/installments/:number/pay"}, "properties": {"repobilityId": "17506b193767fffe", "scanner": "scanner-primary", "fingerprint": "e1448b301807b861", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1978c7f31e46509c", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/whatsapp/send-reminder"}, "properties": {"repobilityId": "d79063b450197e07", "scanner": "scanner-primary", "fingerprint": "1978c7f31e46509c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ff2ec6977d480973", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/whatsapp/send-location"}, "properties": {"repobilityId": "345e5eaf8dd98dd3", "scanner": "scanner-primary", "fingerprint": "ff2ec6977d480973", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a0276892ab28af3f", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/reminders/due-installments"}, "properties": {"repobilityId": "8e1f3f18613bb7e6", "scanner": "scanner-primary", "fingerprint": "a0276892ab28af3f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7085e8a72d2bbd2b", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/dashboard/stats"}, "properties": {"repobilityId": "dadad7e1843726fb", "scanner": "scanner-primary", "fingerprint": "7085e8a72d2bbd2b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-adcfb28bbbb4e3e4", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/audit-logs"}, "properties": {"repobilityId": "7656f98591e553fe", "scanner": "scanner-primary", "fingerprint": "adcfb28bbbb4e3e4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-abed0639daf1329b", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/health"}, "properties": {"repobilityId": "68f3b5cac22be2f3", "scanner": "scanner-primary", "fingerprint": "abed0639daf1329b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-155c887dc6d5d246", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/public/register"}, "properties": {"repobilityId": "265858fc75bcf8f6", "scanner": "scanner-primary", "fingerprint": "155c887dc6d5d246", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-41b82ffb941b6860", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/public/register/:id/documents"}, "properties": {"repobilityId": "053290279209e1fa", "scanner": "scanner-primary", "fingerprint": "41b82ffb941b6860", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-159c1c90579dffa2", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/public-test"}, "properties": {"repobilityId": "60ad4aa86dd48667", "scanner": "scanner-primary", "fingerprint": "159c1c90579dffa2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-060e1924d2af4e82", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/debug/env"}, "properties": {"repobilityId": "506a86b64a14745c", "scanner": "scanner-primary", "fingerprint": "060e1924d2af4e82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4156c632e39b0ec5", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/debug/decode"}, "properties": {"repobilityId": "9d32c7cceda69720", "scanner": "scanner-primary", "fingerprint": "4156c632e39b0ec5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-edd92b0f0757c80b", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/seed"}, "properties": {"repobilityId": "d2ac04574211f2b3", "scanner": "scanner-primary", "fingerprint": "edd92b0f0757c80b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-09c52a023e1356e1", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/users"}, "properties": {"repobilityId": "f8f6a8ec1d174ec3", "scanner": "scanner-primary", "fingerprint": "09c52a023e1356e1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4b0cd5e101cdc429", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/users"}, "properties": {"repobilityId": "9b9a9b5eedca9e85", "scanner": "scanner-primary", "fingerprint": "4b0cd5e101cdc429", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5cec787fe6b117ee", "level": "note", "message": {"text": "Unused endpoint: DELETE /make-server-bd42bc02/users/:userId"}, "properties": {"repobilityId": "2c3c97b223ba0e37", "scanner": "scanner-primary", "fingerprint": "5cec787fe6b117ee", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1d50ac485fb4e52c", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/users/:userId/reset-password"}, "properties": {"repobilityId": "98c8cd3ca1c55062", "scanner": "scanner-primary", "fingerprint": "1d50ac485fb4e52c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cb975e9bbd52ef9a", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/ping"}, "properties": {"repobilityId": "5caf1d2ac638b4d1", "scanner": "scanner-primary", "fingerprint": "cb975e9bbd52ef9a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-75df20dbee972969", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/diagnostic/data"}, "properties": {"repobilityId": "c6fe43d5b4dd636e", "scanner": "scanner-primary", "fingerprint": "75df20dbee972969", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1efa5d6b52f0ce09", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/create-admin"}, "properties": {"repobilityId": "40cebe1e883f5c8d", "scanner": "scanner-primary", "fingerprint": "1efa5d6b52f0ce09", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d51d7908d959dec7", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/fix-user-profiles"}, "properties": {"repobilityId": "d53dcd435f272863", "scanner": "scanner-primary", "fingerprint": "d51d7908d959dec7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c114a5bfb9af3b06", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/financial"}, "properties": {"repobilityId": "48a1b2f25e4be8bf", "scanner": "scanner-primary", "fingerprint": "c114a5bfb9af3b06", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-067d94e27986e715", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/financial/transactions"}, "properties": {"repobilityId": "eb0f79a984eec940", "scanner": "scanner-primary", "fingerprint": "067d94e27986e715", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-70f44ff398ea5e5a", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/financial/transactions/:id"}, "properties": {"repobilityId": "2b450e7c53163c89", "scanner": "scanner-primary", "fingerprint": "70f44ff398ea5e5a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3d32dbd1685acb5a", "level": "note", "message": {"text": "Unused endpoint: PUT /make-server-bd42bc02/financial/transactions/:id"}, "properties": {"repobilityId": "a4130aa5627b6703", "scanner": "scanner-primary", "fingerprint": "3d32dbd1685acb5a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-753e072ced31b309", "level": "note", "message": {"text": "Unused endpoint: DELETE /make-server-bd42bc02/financial/transactions/:id"}, "properties": {"repobilityId": "2329fbb586e4d4b8", "scanner": "scanner-primary", "fingerprint": "753e072ced31b309", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6e000e33abc136ca", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/users/:id/reset-password"}, "properties": {"repobilityId": "fae48baa231dcd1a", "scanner": "scanner-primary", "fingerprint": "6e000e33abc136ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a17e08f272a87124", "level": "note", "message": {"text": "Unused endpoint: PATCH /make-server-bd42bc02/users/me/password"}, "properties": {"repobilityId": "1d4227ad58c29f92", "scanner": "scanner-primary", "fingerprint": "a17e08f272a87124", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-630ecb9d5fbfff1c", "level": "note", "message": {"text": "Unused endpoint: POST /make-server-bd42bc02/users/migrate-operators"}, "properties": {"repobilityId": "a6e6f0ca7fae77f6", "scanner": "scanner-primary", "fingerprint": "630ecb9d5fbfff1c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-675cd81b942b0d90", "level": "note", "message": {"text": "Unused endpoint: DELETE /make-server-bd42bc02/users/:id"}, "properties": {"repobilityId": "1541ddf1b45e3d4c", "scanner": "scanner-primary", "fingerprint": "675cd81b942b0d90", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5d2d224dd6a57a76", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02"}, "properties": {"repobilityId": "43cd1f9ffb58fbe5", "scanner": "scanner-primary", "fingerprint": "5d2d224dd6a57a76", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8a31057bad00e299", "level": "note", "message": {"text": "Unused endpoint: GET /make-server-bd42bc02/health/detailed"}, "properties": {"repobilityId": "e386a33a70077a30", "scanner": "scanner-primary", "fingerprint": "8a31057bad00e299", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}