Parallel Provider Refresh Lanes: Codeforces, LeetCode, AtCoder, and CodeChef now refresh independently every maintenance cycle with provider-specific concurrency. Fresh profiles become eligible every 12 hours, so a slow provider no longer holds up the others and stale queues catch up throughout the day. (Live data)
Safe, Race-Free Syncs: Shared database pacing now enforces Codeforces and AtCoder request intervals across serverless instances. Row-locked lease fencing prevents an older response from overwriting a newer handle, disconnect cooldown tombstones stop unlink/relink abuse, and failed profiles back off without blocking healthy ones. (Reliability)
Layered Browser and API Protection: A per-request nonce Content Security Policy, cross-site mutation checks, exact official problem-link validation, safe fixed-format operational logs, stricter browser headers, no-store API responses, constant-time job authentication, and separate job secrets reduce injection, request-forgery, caching, and credential-reuse risk. (Site-wide)
Protected Magic-Link Sign-In: Distributed IP and email limits reduce sign-in spam, SMTP requires modern TLS, callback redirects are restricted to CPBoard, email HTML is escaped, and university access uses exact configured domains plus explicit aliases instead of broad suffix matching. (Sign in)
Safer Uploads and Verification: Avatar uploads now accept only validated, bounded PNG, JPEG, or WebP images. Verification, comments, analytics, profile views, and notification actions use durable limits or ownership checks, while every stored push endpoint is revalidated before delivery. (Account safety)
Shared Practice Data Is Preserved: Deleting a normal account can no longer cascade through shared practice problems and solutions created by that person. Admin accounts require reassignment, expired operational records are cleaned separately, and the job continuously verifies the runtime database role remains least-privileged. (Practice content)
Continuous Security Gate: Every main-branch change and pull request now runs locked dependency, vulnerability, Prisma, lint, type, and production-build gates. Daily signed-package and passive production checks, Dependabot, private disclosure, and an isolated owner-credential migration workflow complete the release boundary. (Release safety)
Bounded Ranking Pages: CP Rankings now clamps page requests before loading page-specific cached data and redirects out-of-range links, preventing arbitrary page values from creating redundant cache and database work. (CP Rankings)