Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Feature] Enable Ask AI with Kapa: Source Groups, ASF CSP, and Privacy Compliance

Open
#495 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
30/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
hugo

Research direction

Start with the ai_search configuration in hugo.yaml and review the existing integration from PR #493. Coordinate Kapa source-group IDs and ASF Infra/privacy approval, then run browser smoke tests on the named staging sites covering consent, locale isolation, fallback, cancellation, timeout, retry, and mobile behavior. Done means approved CSP/privacy boundaries are verified and the production flag can be enabled.

Written by the indexing model from the issue text.

Description

enhancement

Scope and current result

Prepare consent-gated Ask AI for HugeGraph's official site through #496. The PR contains enabled=true and the Kapa/hCaptcha CSP validated on OINK staging. It remains unmerged; no production website deployment has been performed.

The production origin https://hugegraph.apache.org is already allowed in the enabled Kapa widget 0b277570-4740-451e-96fa-1e4ac1ac5e88.

Production documentation sources

No frontend path mapping is required. Production's current latest is a5a9861ea15f2183347149d0943a758493f1f5b1, sharing content tree aa69a087ecaa52d4c8f7eafb8b2335d531875abd with this PR. An independent check verified all 192 production document URLs return HTTP 200 with one nonempty .td-content; 16 EN/CN samples have identical normalized body text to staging.

Language Group Source Current verification
CN ddce6795-32c8-40ac-8b27-73d73facd042 9e2e66b2-4362-41a7-b9ee-41340686b6da 96 production pages deployed; a real widget answer cites official CN pages and sections
EN 32769e2a-abfc-42f6-891f-09af6c123eb2 f654079b-c9ae-45db-926e-00288304f18d Production Start URL and Include rule saved, full 96-page preview verified, reindex submitted; last observed crawl still in progress with old 96 items retained

Both sources use anchored language-specific URL whitelists, .td-content extraction and manual refresh. Global and the common parent have no direct sources; old uploads and mixed GitHub sources remain in sibling Legacy.

Latest real CN test returned RocksDB configuration, bin/init-store.sh and bin/start-hugegraph.sh, citing https://hugegraph.apache.org/cn/docs/.... The earlier CN hCaptcha acceptance gap is resolved. A real EN test also answered successfully, but still cited staging at the last observation; EN production citation migration is therefore not yet proven complete.

Browser access has recovered. A fresh EN conversation returned a valid answer but still cited staging. The saved Start URL, anchored Include rule and .td-content selector were rechecked and are correct; the same background crawl still reports in progress with0 updates and the old96 deployed items retained (last check37 minutes earlier). It has not been stopped, restarted or duplicated.

Validation

  • Current CI at dc982f312: 193 Python, 40 UI unit, 7 workflow, 76 Chromium and 8 visual checks pass. Publication was skipped for the PR.
  • Three independent code reviews and fix re-reviews completed. All 13 #496 and four #497 review threads were resolved; GitHub's required formal review remains a separate merge gate.
  • Actual desktop/mobile EN/CN answers, language-group filtering, consent-before-loading, cancellation/focus, timeout/retry, native-search fallback, historical latest-document notices and HugeGraph icon behavior have staging evidence.
  • AI-off rollback passed: a fresh browser page made zero AI requests and returned 10 native search results. AI-on restore passed, publication df426022dac03ac6db3bd9f8b4e9ac08221897fa, with all five live version SHAs matching the manifest.

Remaining work

  1. Inspect the existing EN reindex job to its terminal state, then verify a fresh EN answer cites official documentation. Browser access is now available.
  2. Obtain the required GitHub review before any separately authorized merge. After an authorized production publication, verify the actual production CSP and EN/CN question flow.

CSP evidence boundary

The same integration already runs on older HugeGraph staging: source, deployment. The current CSP uses only necessary Kapa/hCaptcha hosts through CSP_PROJECT_DOMAINS, retaining ASF defaults. Optional Google reference favicons remain blocked and fall back to icons without preventing answers.

ASF's FAQ permits Kapa with consent before loading. A separate VP Privacy approval record for the dependency hosts has not been located; existing deployment is not represented as verified formal approval. No automatic-refresh or OSS-plan approval claim is made.

Rollout runbook

Dominant language
Python
Stars
71
Forks
125
Avg merge
1d 3h
Merged PRs (30d)
28

Getting set up

  • No Dockerfile or Docker Compose file
  • Has a pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/hugegraph-doc

All issues in apache/hugegraph-doc

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.