Removed a fake, hardcoded GitHub repo browser from the resource detail page, and later removed a dead font-face declaration that was causing 4 failed requests per page load.
المساهمون
تُبنى رَتْق بمساهمة المجتمع. هؤلاء المساهمون أصلحوا أخطاء وأغلقوا مشكلات وقدّموا تحسينات للمنصة.
Deleted dead i18n source files (en.ts / ar.ts) that were never imported, fixed the stale docs pointing to them, and later wired the developer comments page to real data instead of mock comments.
Fixed a missing 'Home' nav i18n key that was hardcoded as a ternary instead of going through the translation object.
Built this Contributors page and fixed the developer view navbar overlap, then built out the real developer notifications backend (a new Payload collection wired into access requests, reports, and comments), wired pagination into the resources catalog, found and fixed a stored XSS vulnerability in the JSON preview component, and later added four missing content pages (Contact, Privacy, Standards, Docs) with the footer links wired to them. Later added image upload support for resources, and then added a payload-backend typecheck step to CI after a type error slipped through undetected.
Stripped a stray UTF-8 BOM byte from source files, after independently verifying which of the originally-listed files still existed post-restructure.
Added an admin override so admins can delete or update any comment, while keeping regular users restricted to their own - with tests covering every role case.
Fixed a React hydration mismatch that fired on every page load for logged-in users, by moving the localStorage read out of the initial render and into a post-hydration effect.
Fixed pages loading scrolled-to-bottom and animating up on navigation, by adding smooth-scroll behavior to the html element - his own diagnosed fix from when he opened the issue. Later added bilingual accessibility labels to the pagination buttons, then added a sort dropdown to the resources catalog with URL-based state, matching the existing filter pattern.
Added a Contributor Covenant code of conduct and a short governance section explaining who has merge rights and how decisions get made, then documented AccessRequests' publisher-scope limitation.
Fixed the last two English strings that had slipped through the Report modal - the reason dropdown's default option and the details placeholder - wiring both through the existing i18n system with real Arabic/English translations and tests for both locales.
Wired the already-built AnnouncementsCarousel component into the homepage, replacing the old static banner that could only ever show one fixed message - the homepage now surfaces real, rotating announcements. Later did the same for Trending Resources, and found the real reason it had nothing to show (a downloads-based filter with no real download data yet to filter on).
Created CHANGELOG.md and added a Community section to the README linking to GitHub Discussions and the changelog, giving the project a public discussion channel and a clear changelog for anyone following along.
Fixed a UX gap where an already-authenticated user could still land on the login page and see the form again - added an automatic redirect to the dashboard, with a loading guard so the form never flashes on screen while the session is being checked, plus tests covering both states. Later added the access-control test coverage the Users and Resources collections were missing - privilege escalation, owner-spoofing, and slug-collision handling all included.
Built the real Payload backend for Announcements, replacing the mock data it had been running on - a proper collection with admin-only writes, public reads scoped to active/non-expired announcements, and resource links that resolve through the real catalog instead of pointing at fake resource IDs. Later added Edge Cache for GitHub repository previews, caching successful responses per-repository while explicitly excluding failed, invalid, or missing-token results from the cache. Later added the website CTA banners - an optional website_url field plus "Visit site" and "Use API" banners, gated on real data and hidden otherwise, along with a fix so the GitHub stats card only shows for genuinely GitHub-hosted resources. Then added a resource-detail photo carousel with previous/next controls, a slide counter, and dot navigation, falling back to the single resource image when no photo list is available. Then fixed the Publishers filter dropdown so it closes on an outside click, Escape, or page scroll while staying open when scrolling inside the list, with regression tests. Most recently fixed the Newest/Oldest resource sorting so resources with a missing or invalid creation date no longer break the date comparator and land in a deterministic spot, with regression tests that fail on the old code. Then fixed dashboard subpages redirecting to the overview on refresh - the five dashboard auth guards now wait for the session to finish restoring before redirecting, with regression tests that fail on the old code.
Added accessible names to the catalog search input and the consumer avatar links, so screen reader users get a real label instead of relying on placeholder text or nothing at all. Later rebuilt the homepage announcement banner to match the new single-bar design, dropping the old dots/arrows while keeping auto-rotation, pause on hover/focus, and scoped keyboard navigation. Later rebuilt the resource detail header and technical-details section to match the Figma - separated a Quick Summary from Technical Resource Details, added publisher, type and publish date rows and a website badge shown only for real website URLs, and deliberately left out a visitor count rather than faking one before real tracking exists.
Added a real GitHub repo preview on resource detail pages - recent commits and topics fetched server-side for resources with a valid GitHub URL, cached for 5 minutes, using a server-only token so it never reaches the client.
Fixed a security gap in the GitHub OAuth callback that put a live, multi-day session token straight into the redirect URL - exposed to browser history, proxy access logs, and any Referer header. Split the handoff into two steps so the token never touches the URL.
Let publishers view who holds access to a resource and revoke it - cascades to the holder's existing API keys, notifies the applicant, and requires two clicks since revoking can't be undone.
Added session-expiry handling for authenticated API requests - an expired or invalid JWT now clears auth state and redirects to login with a clear message, while keeping that distinct from a genuine permission denial on a still-valid session.
Fixed a security gap where any authenticated user could generate an API key for any resource regardless of ownership or an approved access request - added a validation guard requiring resource ownership or an approved access request before allowing key creation, with test coverage for all three cases. Later fixed another security gap where draft/unpublished resources and their comments were publicly readable via the API - added multi-tier access control (owner, admin, public-published-only) to both collections, with full test coverage. Later closed three more access-control gaps - locked the resource field on Comments and the applicant/message/resource fields on AccessRequests from being changed after creation, and added a duplicate-report guard to prevent multiple open reports on the same resource.
Added forgot-password, reset-password, and email-verification flows - previously missing entirely, so users who forgot their password now have a real way to recover their account.
Fixed toast notifications always rendering left-aligned with LTR text regardless of the active language, even in Arabic mode - now reads the real direction from useLanguage() and switches both positioning and the dir attribute accordingly, with tests covering both locales.
Added a normalizeArabic() utility so Arabic letter-form variants (alef forms, alef maqsura/yaa, tashkeel) match as equivalent in search, applied consistently across all three resource sources with thorough unit and integration test coverage.
Migrated authentication from a JWT stored in localStorage to a secure HttpOnly cookie, closing an XSS exposure - reconfigured Payload's auth settings, updated the GitHub OAuth flow to match, and moved every frontend request over to session-based auth. Later stopped the resource detail page from scanning the whole catalog to find one slug - each source now exposes a direct single-resource lookup (CMS, Payload and the native source), the aggregator routes a slug to the source that owns its prefix, and the old full scan stays only as a fallback, with tests asserting the list call is skipped.
Hid the resource access-request button on the resource detail page, while keeping the report button, preview, related resources, and comments working exactly as before.
Fixed the audio preview stub that always returned nothing, added the missing Payload fields it needed (audio URL, thumbnail, reciter name, audio quality), and replaced the plain browser audio bar with a custom accessible player - play/pause, a seekable progress bar, elapsed/remaining time, and a file-extension-derived format, with optional fields simply hidden when absent.
Added a publisher filter to the resources catalog - a reusable multi-select dropdown, a new publishers endpoint, and publisher names shown on resource cards and the resource detail page, with a dedicated 'No publisher' option.


























