marcuspaico e81d07975a fix(labs): strict numeric parsing, atomic confirm guard, test integrity
- normalize.ts num(): parseFloat truncated at the first comma, so "1,200"
  silently became 1 (1000x error) and "5,5" became 5. Now strictly matches
  either US thousands-grouping or a plain number spanning the whole string;
  anything else (incl. ambiguous "5,5") returns null instead of a wrong value.
- labs.ts confirm handler: the pending-status check ran before the request
  body was read, so two concurrent confirms could both pass it and
  double-insert. Added a guarded UPDATE ... WHERE status = 'pending' as the
  first statement inside the existing synchronous transaction; zero rows
  affected throws and the route returns 409, with the fast-path check kept
  for the common case.
- Added missing `await` on two rejects.toThrow assertions (llm.test.ts,
  extract.test.ts) that were previously resolving before the assertion
  settled.
- Bumped the 11th-failed-login rate-limit test to a 30s timeout — 10
  sequential argon2id verifies can exceed bun:test's 5s default under load.
2026-08-17 16:17:03 -07:00

Helios

Self-hosted, open-source health companion — a FOSS alternative to closed "24/7 AI health companion" products. Your data stays on your server; the AI runs on a key you provide (OpenRouter, or Ollama for zero third parties).

Status: pre-alpha scaffold. See docs/superpowers/specs/ for the design.

Develop

bun install
bun run typecheck && bun test
Description
No description provided
Readme MIT 239 KiB
Languages
TypeScript 97.6%
CSS 1.7%
Dockerfile 0.4%
HTML 0.3%