From 1d23727597037d5f032e35ab0eb01908b9aced90 Mon Sep 17 00:00:00 2001 From: Mario Tarosso Date: Thu, 10 Sep 2026 10:33:00 +0100 Subject: [PATCH 1/3] Describe the automatic connection option and the widget's Continue with Patchstack Co-Authored-By: Claude Fable 5.1 --- .../installing-on-javascript-node-projects.md | 15 +++++++++++++++ .../docs/Patchstack App/Pulse/pulse-overview.md | 2 ++ .../docs/Patchstack App/Sites/adding-a-site.mdx | 2 +- 3 files changed, 18 insertions(+), 1 deletion(-) diff --git a/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md b/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md index a593393..27eed9a 100644 --- a/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md +++ b/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md @@ -40,6 +40,17 @@ npx --no-install patchstack-connect setup `setup` ends by printing a **dashboard link**. The CLI never opens the link and never asks for Patchstack credentials — open it in your browser and sign in to see the vulnerability reports. The site is monitored either way; connecting it to an account is what makes the reports visible to you. +### Connecting straight to your account + +If you start from the app — **Sites → Add new → AI-assisted** — and tick **Connect this website to my account automatically**, the message it gives you to paste into your assistant carries a **claim token** for your account, and the assistant runs `setup` with it: + +```bash +npx @patchstack/connect setup --claim-token +# or: PATCHSTACK_CLAIM_TOKEN= npx @patchstack/connect setup +``` + +The site is then created already attached to your account, `setup` prints your dashboard link for it, and the app's **Connect website** panel picks the site up on its own. The token names your account, not the project: it is never written to `.patchstackrc.json` or the credential file, and it stops working after a day. An expired or unrecognised token does not break the install — the site is created unattached, exactly as it would be without one, and `setup` prints the dashboard link to connect it by hand. + `setup` never runs the `protect` command (see below). ### Manual alternative @@ -67,6 +78,10 @@ To run without the widget, set `"widget": false` in `.patchstackrc.json` — thi The floating button is **hidden by default**: it appears only when the widget is told to show it, via `data-report-form="true"` on the script tag or the widget's own Settings. To reach your dashboard while the button is hidden, open any page of your site with `#patchstack` appended to the URL. See [Troubleshooting JS / Node.js](/getting-started/installing-patchstack/troubleshooting-javascript-node-projects/) if the widget still does not appear. +### Signing in to the widget on your site + +The widget's owner panel leads with **Continue with Patchstack**: one click signs you in with the account you are already signed in to at app.patchstack.com — no password, no provider round trip, and it works for SSO and two-factor accounts too. If you are not signed in there, the click takes you to the Patchstack login and brings you back to your site afterwards. In browsers that allow it, the button already names your account ("Continue as …"); elsewhere it is unnamed but works the same way. The e-mail, Google, GitHub and LinkedIn options are still there underneath. + ## The `protect` command The package also ships an **opt-in** `protect` command: a runtime exploit guard, currently for TanStack Start + Supabase applications, which patches the app's Supabase client to route traffic through a same-origin guard. It modifies application code and runs **only** when explicitly invoked — `setup`, `scan`, `guide`, `status`, and `mark-build` never invoke it. If you don't run `protect`, no application code is changed beyond the widget tag and `package.json` scripts described above. diff --git a/src/content/docs/Patchstack App/Pulse/pulse-overview.md b/src/content/docs/Patchstack App/Pulse/pulse-overview.md index 846b11b..66971de 100644 --- a/src/content/docs/Patchstack App/Pulse/pulse-overview.md +++ b/src/content/docs/Patchstack App/Pulse/pulse-overview.md @@ -19,6 +19,8 @@ Install the connector in your project and run `setup`. The first scan creates th The site starts out **unclaimed**: it is being monitored, but it is not attached to anyone's account, so nobody can see its reports. `setup` prints a dashboard link. Open it, sign in, and the site attaches to your account. If you lose the link, `npx @patchstack/connect status` prints it again. +Starting from the app can skip that step: tick **Connect this website to my account automatically** under **Sites → Add new → AI-assisted** and the message it gives you carries a token for your account, so a site created with it is attached from its first scan and shows up in the app on its own. See [Connecting straight to your account](/getting-started/installing-patchstack/installing-on-javascript-node-projects/#connecting-straight-to-your-account). + An unclaimed site that nobody ever claims is cleaned up after a reminder period, so claim it while you are thinking about it. ## What the tabs show diff --git a/src/content/docs/Patchstack App/Sites/adding-a-site.mdx b/src/content/docs/Patchstack App/Sites/adding-a-site.mdx index 8d87a2e..72a581f 100644 --- a/src/content/docs/Patchstack App/Sites/adding-a-site.mdx +++ b/src/content/docs/Patchstack App/Sites/adding-a-site.mdx @@ -24,6 +24,6 @@ Adding a site to Patchstack is relatively easy. Here is a simple guide on how to 8. Upload the plugin .zip file to your WordPress site by visiting /wp-admin > Plugins > Add New > Upload Plugin 9. Activate the plugin -**JavaScript and Node.js projects do not need this flow.** Installing [`@patchstack/connect`](/getting-started/installing-patchstack/installing-on-javascript-node-projects/) and running `setup` creates the site for you on its first scan, then prints a link that attaches it to your account. See [Pulse sites overview](/patchstack-app/pulse/pulse-overview/) for what those sites look like in the app. +**JavaScript and Node.js projects do not need this flow.** Pick **AI-assisted** instead and copy the message the app shows you into the assistant that built your website. The assistant installs [`@patchstack/connect`](/getting-started/installing-patchstack/installing-on-javascript-node-projects/) and hands you back a link; paste it into the same panel to attach the site to your account. Tick **Connect this website to my account automatically** before copying and the message carries a one-day key for your account instead: the site is then created already attached to you, and the panel notices it by itself with nothing to paste. If the assistant still hands you a link (a message copied yesterday no longer connects), the paste field works as before. See [Pulse sites overview](/patchstack-app/pulse/pulse-overview/) for what those sites look like in the app. If you need further help, don't hesitate to reach out to us via live chat at the bottom right corner! \ No newline at end of file From ead561376ce6c69b224ec45dd859ad22d6b3510f Mon Sep 17 00:00:00 2001 From: Mario Tarosso Date: Thu, 10 Sep 2026 10:45:41 +0100 Subject: [PATCH 2/3] Describe the widget's Continue as entry as shown only on a detected session Co-Authored-By: Claude Fable 5.1 --- .../installing-on-javascript-node-projects.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md b/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md index 27eed9a..e6c84e1 100644 --- a/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md +++ b/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md @@ -80,7 +80,7 @@ The floating button is **hidden by default**: it appears only when the widget is ### Signing in to the widget on your site -The widget's owner panel leads with **Continue with Patchstack**: one click signs you in with the account you are already signed in to at app.patchstack.com — no password, no provider round trip, and it works for SSO and two-factor accounts too. If you are not signed in there, the click takes you to the Patchstack login and brings you back to your site afterwards. In browsers that allow it, the button already names your account ("Continue as …"); elsewhere it is unnamed but works the same way. The e-mail, Google, GitHub and LinkedIn options are still there underneath. +If you are already signed in to app.patchstack.com in the same browser, the widget's sign-in form leads with **Continue as **: one click signs you in with that account — no password, no provider round trip, and it works for SSO and two-factor accounts too. The option appears only when the widget can see that session, which Chrome and Edge allow and Safari and Firefox do not by default; otherwise the form offers e-mail, Google, GitHub and LinkedIn as before. ## The `protect` command From 2a3cd70a30981a27064a7980ad6cb6d0c830fad0 Mon Sep 17 00:00:00 2001 From: Mario Tarosso Date: Thu, 10 Sep 2026 10:51:32 +0100 Subject: [PATCH 3/3] Describe Continue with Patchstack as always offered, named where the browser allows Co-Authored-By: Claude Fable 5.1 --- .../installing-on-javascript-node-projects.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md b/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md index e6c84e1..1f38135 100644 --- a/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md +++ b/src/content/docs/Getting Started/Installing Patchstack/installing-on-javascript-node-projects.md @@ -80,7 +80,7 @@ The floating button is **hidden by default**: it appears only when the widget is ### Signing in to the widget on your site -If you are already signed in to app.patchstack.com in the same browser, the widget's sign-in form leads with **Continue as **: one click signs you in with that account — no password, no provider round trip, and it works for SSO and two-factor accounts too. The option appears only when the widget can see that session, which Chrome and Edge allow and Safari and Firefox do not by default; otherwise the form offers e-mail, Google, GitHub and LinkedIn as before. +The widget's sign-in form leads with **Continue with Patchstack**: one click signs you in with the account you are already signed in to at app.patchstack.com — no password, no provider round trip, and it works for SSO and two-factor accounts too. In Chrome and Edge the button already names your account ("Continue as …"); Safari and Firefox do not let the widget see that, so there it is unnamed but works the same way. If you are not signed in to app.patchstack.com in that browser, the widget says so and the e-mail, Google, GitHub and LinkedIn options are right underneath. ## The `protect` command