Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungThe Indie Dev Visibility Playbook: From Zero Users to Your First 100(21.09.2026 um 00:08 Uhr)
Sichere ProgrammierungBase, Chat and Reasoning Models: How Are They Different?(21.09.2026 um 00:09 Uhr)
Sichere ProgrammierungHexfield Deck is for Kanban lovers and Markdown believers(21.09.2026 um 00:20 Uhr)
Sichere ProgrammierungPermissions and Authorisation: A Practical Playbook(21.09.2026 um 00:21 Uhr)
Linux Tipps & Hardeningfilet | Terminal File Manager(20.09.2026 um 21:03 Uhr)
Linux Tipps & HardeningLooking for feedback on my Linux Distro(20.09.2026 um 21:03 Uhr)
Sichere ProgrammierungThe Indie Dev Visibility Playbook: From Zero Users to Your First 100(21.09.2026 um 00:08 Uhr)
Sichere ProgrammierungBase, Chat and Reasoning Models: How Are They Different?(21.09.2026 um 00:09 Uhr)
Sichere ProgrammierungHexfield Deck is for Kanban lovers and Markdown believers(21.09.2026 um 00:20 Uhr)
Sichere ProgrammierungPermissions and Authorisation: A Practical Playbook(21.09.2026 um 00:21 Uhr)
Linux Tipps & Hardeningfilet | Terminal File Manager(20.09.2026 um 21:03 Uhr)
Linux Tipps & HardeningLooking for feedback on my Linux Distro(20.09.2026 um 21:03 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Never forget to enter the Stern Grove lottery again!

Reagiere als Erste:r — dein Feedback zählt!

It's summer in San Francisco, which means that every week I forget to enter the lottery for the free Stern Grove Music Festival.

Solution? I did what any reasonable developer would do instead of just setting a calendar reminder: I built a Python script that runs weekly via GitHub Actions, scrapes the festival website with Playwright, and auto-enters the lottery for me.

The fun part is how I built it. I described what I wanted to a coding agent (I've done a lot of browser automation to automate tennis court bookings, make data visualizations, etc), and Entire recorded every prompt, tool call, and output along the way, so I have a complete, auditable record of how the whole thing came together. If you want to retrace the entire build yourself, here's the live session. Let me walk you through it:

It started with one message

The entire (lol) project began with a single message to my coding agent (I used Claude Code, but any agent works!) I gave it the rules of the game:

The Stern Grove lottery opens six weeks before each show at 10:00 AM and stays open for one full week to enter…

I also handed it the exact HTML for the entry button. Stern Grove runs its ticketing through Tixologi, so the agent needed to know what it was dealing with.

Then I told it about the secrets my GitHub Action would have access to:

  • First name
  • City
  • Email
  • A Resend API key (for notifications)
  • The "from" email address
  • Zip code All of these live as encrypted secrets in GitHub Actions--never committed to the repo--and I made sure the agent understood that constraint up front.

The architecture it proposed

Before writing a line of implementation, the agent explored the spec, asked one clarifying question, and proposed a clean design:

  • lottery.py — the entry point, triggered by a GitHub Actions cron schedule
  • browser.py — all the Playwright logic: web scraping and browser automation
  • state.py — loads and saves entered_lotteries.json so we never double-enter
  • notify.py — success and failure emails via Resend State persistence was the clever bit. Instead of standing up a database for a once-a-week job, the entered lotteries are tracked in a JSON file that gets committed back to the repo after each run:
{
  "entered": [
    { "event_id": "abc123", "show": "Show Name", "entered_at": "2025-06-21T10:02:00Z" }
  ]
}

The cron schedule lives in the workflow file:

# .github/workflows/lottery.yml
on:
  schedule:
    - cron: "0 17 * * 1"   # weekly check
  workflow_dispatch:

Inspecting before automating

Here's a step worth highlighting. Before touching any browser logic, the agent did a live inspection of the actual Stern Grove page — specifically window.tixologiWidget.concerts — to learn the real data shape rather than guessing.

Tixologi is a ticket and event management platform. That inspection documented the precise field names, the ISO 8601 date format, and the event ID structure. One console log it captured saved a lot of debugging later:

// What the page actually exposes
window.tixologyWidget.concerts
// → [{ eventId, name, startDate: "2025-07-13T19:00:00Z", ... }]

Grounding the implementation in real, observed data instead of assumptions is a major differentiator between code that works on the first real run and code that fails silently in production.

Pushing state back to the repo

state.py doesn't just read the JSON — after a successful entry it commits and pushes the update using a GitHub Personal Access Token (PAT), so the next run knows what's already been done:

def commit_state(token: str) -> None:
    subprocess.run(["git", "add", "entered_lotteries.json"], check=True)
    subprocess.run(["git", "commit", "-m", "Update entered lotteries"], check=True)
    subprocess.run(["git", "push"], check=True)

The review loop caught a real bug

When the agent added notify.py, a reviewer sub-agent immediately flagged two issues in the diff:

  1. It was using print() statements instead of the logging module.
  2. It had duplicated the Resend API key (for email) initialization. The agent fixed both before moving on to the next task. That's the task → review loop doing exactly what it should — catching the kind of sloppiness that usually only surfaces weeks later.
import logging

logger = logging.getLogger(__name__)
resend.api_key = os.environ["RESEND_API_KEY"]  # initialized once

def notify_success(show: str) -> None:
    logger.info("Entered lottery for %s", show)
    resend.Emails.send({ ... })

How to retrace every prompt, tool call, and output

This is the part I do genuinely find handy: I didn't have to remember how the automation got built, because Entire captured all of it. A session in Entire is the complete record of an AI coding interaction, ie every prompt, response, tool call, and file change. You can browse mine at the session link above.

Here's how to navigate it:

  • Find the session. Sessions live in the Sessions tab on a checkpoint detail page. Each row shows the agent that ran (Claude Code, in my case), a step count, the opening prompt, and a timestamp. Click one to open its timeline.
  • Read the timeline. The session timeline shows the conversation in order — my prompts, the agent's responses, expandable tool calls, and runtime tags. A metadata panel summarizes the model, duration, and token usage for the run.
  • Expand any tool call. Tool calls render as inline rows you can expand to see the exact arguments and results. For file edits, the expansion shows the diff right there.
  • Filter the noise. A filters rail on the right lets you toggle what's visible — prompts, responses, intermediate steps, checkpoints, and tool calls (further broken down into file edits, bash, read, and other). This is how I unchecked things to get a cleaner view when I just wanted something more high-level.
  • Drill into sub-agents. When the agent spun up that reviewer sub-agent via Claude Code's Task tool, Entire captured it as its own session with its own transcript and tool calls, rolled up into the parent checkpoint's totals. That's exactly where you can see the review loop that flagged the print()/logging issue.
  • Jump to the code. Every session links back to its Git commits through an Entire-Checkpoint trailer, so you can open the matching checkpoint or the underlying commit on GitHub. The metadata itself lives on a distinct separate entire/checkpoints/v1 branch, which keeps your main history clean. So the screencast you're watching isn't the only record-- the full reasoning behind every line is sitting in that session, ready to rewind through.

It didn't work at first!

I'll be honest: the first real run failed. CI rarely cooperates on the first try, and this was no exception. Two environment issues bit me:

1. Ubuntu version drift. I had to pin the runner to Ubuntu 22.04 for Playwright compatibility. ubuntu-latest had quietly become Ubuntu 24.04 in 2025, and the libasound2 package was renamed in the process.

2. Chromium dependencies. I ended up installing the Chromium deps manually with the correct Ubuntu 24.04 package names instead of relying on Playwright's bundled installer.

The fix went from this:

# before
- run: playwright install --with-deps chromium

to explicit apt installs plus a leaner Playwright step:

# after
- run: |
    sudo apt-get update
    sudo apt-get install -y libasound2t64 libnss3 libnspr4 # ...correct 24.04 names
- run: playwright install chromium

Success!

Finally, it ran cleanly. I got the confirmation email straight from Stern Grove and Resend.

The stack came together nicely:

  • Playwright for the browser automation
  • GitHub Actions for the weekly cron schedule and secret management
  • Resend for success/failure notifications
  • A coding agent (Claude Code) to build it, with a review loop that caught real bugs
  • Entire capturing every prompt, tool call, and output, linked to the commits I can't wait to see what you build with the same pieces, and now you (and I) won't forget to enter the Stern Grove lottery this summer.
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Never forget to enter the Stern Grove lottery again!

Thematisch verwandte Begriffe: Never, forget, enter, Stern · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94084 | Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a t…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick