From 122ad3b62b4bbee549ad9e726ea79987d1dbe91b Mon Sep 17 00:00:00 2001 From: BigSimmo <87357024+BigSimmo@users.noreply.github.com> Date: Thu, 23 Jul 2026 01:04:56 +0800 Subject: [PATCH 1/2] docs: record cloud chat reconciliation --- .../cloud-chat-reconciliation-2026-07-22.md | 117 ++++++++++++++++++ .../staging-tenancy-evidence.json | 30 +++++ docs/branch-review-ledger.md | 15 +++ docs/outstanding-issues.md | 29 +++-- 4 files changed, 182 insertions(+), 9 deletions(-) create mode 100644 docs/archive/cloud-chat-reconciliation-2026-07-22.md create mode 100644 docs/archive/staging-tenancy-evidence-29795051547/staging-tenancy-evidence.json diff --git a/docs/archive/cloud-chat-reconciliation-2026-07-22.md b/docs/archive/cloud-chat-reconciliation-2026-07-22.md new file mode 100644 index 000000000..edafcb599 --- /dev/null +++ b/docs/archive/cloud-chat-reconciliation-2026-07-22.md @@ -0,0 +1,117 @@ +# Cloud-chat reconciliation record — 2026-07-22 + +This record closes the Database cloud-chat reconciliation against protected `origin/main`. It distinguishes landed work from duplicates, rejected patches, provider-gated follow-up, and retained post-freeze work. An archive or branch being preserved does not mean its content is approved. + +## Canonical integration result + +- Implementation endpoint before this record: `origin/main` at `05dc52fd8408a65117e22a6236e43252203bea92` (PR #1087). +- Delivery model: sequential protected-main squash PRs, with a fresh fetch between PRs and exact intended-blob comparison after each merge. +- Retrieval/ranking changes adopted: none. +- Live RAG/OpenAI spend: `$0` of the authorised `$15` multi-run budget. Offline evidence was sufficient because no surviving reconciliation change altered retrieval, ranking, or answer generation. +- Production provider mutations: none. The live title-word drift comparison was read-only and found the merged schema already represented; no Supabase migration apply or Railway deployment was needed. + +## Preserved recovery evidence + +| Backup | SHA-256 | Size | Verification | +| --------------------------------------------------------------- | ------------------------------------------------------------------ | ----------------------: | ---------------------------------------------------------------------------- | +| `Database-pre-reconciliation-20260722-120500.bundle` | `E26E837736E6AFE5887FBBC19367FD48F300A4CC51D2BD32E180DC65CBDC2EE1` | 78,363,970 bytes | `git bundle verify` passed; 263 refs; 12 reconciliation archive refs present | +| `Database-pre-primary-cleanup-20260722-200000.bundle` | `D9200D52D26F5D2CB0E1F5E4AA6218F7086C525A02270D6F6468D64729BAC5AF` | 78,690,015 bytes | `git bundle verify` passed; complete history; 332 refs | +| `Database-local-refs-before-final-cleanup-20260719-0525.bundle` | retained independently | existing July 19 backup | not replaced by either July 22 bundle | + +The late primary-checkout checkpoint is `refs/archive/pre-reconcile/20260722/primary-dirty-late` at `f10c89bb26054565d800726c086101e1440b7f31` (tree `ce66783afee7caf9d28fbd4342a5172fc42a5af1`). It was created with a separate index, excluded `.env*`, logs and `tmp-*`, and did not mutate the checkout. + +The original external manifests remain next to the bundles. Secret-bearing worktrees are deliberately retained because ignored `.env.local` content is excluded from Git bundles. + +## Landed protected-main PRs + +| PR | Merge commit | Disposition | +| ----- | ------------------------------------------ | -------------------------------------------------------------------------------------------- | +| #1061 | `3e70a22c671da0199d507b00b0a77e9a99db2621` | SettingsDialog destructive/account action tests; no production behavior change | +| #1062 | `ae950de196b2a8e39e88226f41ef941be14e415d` | Backend-only title-word RLS/ACL policy; read-only live drift clean | +| #1075 | `46f143d135afcd2f449ae6bedd05332a7af35f4d` | Binding-aware route-reachability AST with false-positive fixes | +| #1076 | `142646355a045314da85fa2b1582fdc45b2ac02e` | User-facing Therapy mode naming; `/therapy-compass` retained | +| #1077 | `bf9a50836a445441f4d224686c54f1c4af257b6a` | Migration-role guardrails and dynamic Docker storage-owner discovery | +| #1078 | `001ce3543cb7e8020b0f6a5c3171f14601c73e6b` | Optional auth tri-state; invalid credentials fail 401; stale anonymous-upload patch rejected | +| #1079 | `a8814b671b43938428fe2dbba355bf5ddf79f5c9` | Current-project auth-cookie precedence; retired-project cookie ignored | +| #1080 | `6976aaeeece84680ed6ffc9e77f839f3a314ec4e` | Readiness fails closed for returned and thrown Supabase probe failures | +| #1081 | `a00638af2e1116896bedf493af0dbb591a707567` | Publication approval bound to locked canonical reviewed state with a new forward migration | +| #1082 | `d302be1cfd033eacd64a42d7ef6fe1af3c3b03ac` | Current-main-only non-RAG salvage: malformed fallback-PDF images and live-test env loading | +| #1083 | `0afa0a55501afd784bec9237dca9e1b5d98d849a` | Reproduced Firefox document-viewer test stabilization; stale browser hunks rejected | +| #1084 | `589fb9b99e18061782b0c7b3fa6b14fa0e8388d5` | Bulk reindex partial success returns a completed result and refreshes successful work | +| #1085 | `008a92b0fbad652484b6cdde6295bc456f4b7bf9` | DOCX count, per-artifact, aggregate-media, Word-XML and extracted-text budgets | +| #1086 | `2963fba46eacd644618a588fa283f7597faa2644` | XLSX worksheet, row, rendered-cell and UTF-8 output budgets | +| #1087 | `05dc52fd8408a65117e22a6236e43252203bea92` | Truthful account persistence/provider copy and unavailable-SSO presentation | + +Related work that advanced main during the freeze was also retained rather than replayed: #1053 (operator-script archival), #1054/#1057 (content-first regression coverage), #1055 (obsolete RAG rescue issue closure), #1063 (document-viewer coverage), #1064 (browser upload precheck), and #1065 (webhook runbook). + +## Original worktree/chat dispositions + +| Original worktree or theme | Final disposition | +| -------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Primary `C:\Dev\Apps\Database` | Six unique commits were already represented or superseded. Dirty source was classified file-by-file; the only unique approved artifact is the staging-tenancy evidence added with this record. All other source is duplicate, rejected, or unproven and remains recoverable in the late checkpoint/bundles until final checkout cleanup. | +| `database-audit-drift-verify-07fcbb` | Operator-script archival landed through #1053; remaining audit notes are duplicate/advisory. | +| `frontend-review-improve-123366` / upload precheck | Landed independently through #1064; not replayed. | +| `mcp-phone-cloud-local-20375c` / governance audit | Safe governance subset landed earlier through #1051; deferrals are captured in issues #032–#037. The worktree later evolved after the reconciliation freeze and is retained as post-freeze work. | +| `prompt-skill-improvements-7d5f80` / content-first tests | Content-first coverage landed through #1057. The worktree later evolved into protected RAG diagnosis work represented by issues #018/#019 and is retained as post-freeze work. | +| `rag-ranking-safety-issues-09867c` | Obsolete rescue item closed through #1055. No protected RAG behavior was adopted. | +| `railway-token-secrets-setup-638ad6` / ACL alignment | ACL content already represented. Secret-bearing worktree retained; no credential content entered Git or a bundle. | +| detached terminal checkpoint | Preserved by archive ref; no distinct approved content remained to land. | +| `0a71` secret-location chat | Machine-specific secret path rejected; generic guidance was already represented. Worktree retained until its ignored secret has an authorised destination. | +| `1b10` database drift chat | Read-only title-word drift verification completed with #1062; other live database operations remain provider/operations work, not source integration. | +| `2c2a` ingestion review | Genuine bulk-reindex/DOCX/XLSX findings landed through #1084–#1086. Active-indexing safety was already on main; stale tenancy/audit claims were not reimplemented. | +| `5708` P1 release patch | Split and reimplemented through #1078–#1081. The stale timestamped migration and mixed patch were rejected. | +| `59db` document mockups | Explicitly outside production reconciliation scope; retained as design work. | +| `5edf` sync-local-content | Exact-content duplicate/already represented; no replay. | +| `665f` route/Therapy patch | Repaired and split through #1075/#1076; raw identifier and arbitrary-href evidence rules rejected. | +| `6fa3` repo-wide review | Current non-RAG reproductions landed through #1082; remaining findings were stale, duplicate or captured as issues. | +| `762c` design audit | Product-truth defects landed through #1087. Shared comparison behavior, catalogue-toolbar consolidation and visual baselines remain recommendations; no second Factsheets mode will be added. | +| `94ca` outstanding-issues/RAG review | Genuine items deduplicated into the issue ledger. Semantic reranking, score spreading and unsafe alias/comparator changes remain rejected/provider-gated. | +| `bounded-release-rerank-20260719` | Historical review/RAG follow-up; no blind replay. Surviving concerns remain issue-ledger/provider-gated work. | +| `fix-p2-audit-20260719` | The 31-file patch was never replayed. Only reproduced current non-RAG/browser defects landed in #1082/#1083. | +| `migration-role-guardrails-20260719` | Reimplemented cleanly through #1077; stale workflow hunks/manifest rejected. | +| `mobile-safari-hidden-composer-edge` | Earlier focused UI work compared against evolved main; no additional reconciliation patch was justified. Preserved pending its separate branch lifecycle. | +| `p2-remediation-clean/final-20260719` | Selective current-main salvage only; residual mixed content rejected or duplicate. | +| `p3-debt-fixes-20260719` | No patch-unique integration candidate at capture; duplicate/advisory. | +| `postgres-default-acl-pr-20260719` | Database ACL intent already represented by current schema/guardrails; no stale migration replay. | +| `public-content-account-access` | Current auth defect reimplemented in #1078/#1079. Historical mixed branch preserved; no blind replay. | +| `publish-local-content/finalize-20260719` | Existing operational safeguards were already on main or captured as operator debt. Historical branches preserved; no blind replay. | +| `railway-ops-staging-20260719` | Provider/operations state remained separate. Successful staging tenancy evidence is now checked in; no production deployment was triggered. | +| `release-browser-matrix-20260719` | Current Firefox failure reproduced and fixed in #1083; stale expectations, unrelated styles and existing service-worker isolation were rejected. | +| `retrieval-order-release-20260719` | Explicitly rejected. No comparator reordering, bulk alias widening, score spreading or semantic-rerank enablement. | +| reconciliation controller `e8ed` | Read-only controller retained until final local-main synchronization and worktree cleanup complete. | + +## Post-freeze work retained + +Newer Cursor/Claude/Run-PR worktrees appeared after the original bundle snapshot, including the sidebar and document-accordion tasks, prompt-skill isolation, document-tab design, cloud-auth repair, webhook work, and PR-sweep branches. They are not reconciliation inputs and are retained until their owning tasks are handed off. They must not be inferred stale merely because this reconciliation finished. + +## Explicitly rejected or not recommended + +- The protected RAG score-spreading/comparator changes, wide alias-tier merge, semantic reranking enablement, and retrieval-order restoration. No current reproducer justified them and no live canary was needed. +- The original 31-file P2 patch and stale browser expectations. +- A broader process-kill implementation that removed Node filtering and descendant-tree targeting safeguards. +- The stale `deno.lock` snapshot, unresolved-conflict version of `docs/outstanding-issues.md`, and a Next config change that would re-enable `X-Powered-By`. +- Signed-image expectations that contradicted current component behavior. +- Broad speculative mobile dialog CSS using global role selectors and `!important` without a current reproducer. +- Twenty-seven untracked long-name skills that conflict with the canonical single-word skill catalog. +- Simplistic form-validation/keyboard polish and PWA/image micro-polish without a current defect proof. +- A second patient-facing Factsheets mode; future work should extend the existing Easy Read/Standard model. + +## Primary-checkout unique-content decision + +- Process ownership, script archival, formatting, staging-user administration, issue documentation and typing commits were already represented or superseded on main. +- `scripts/run-eval-safe.mjs`, `tests/eval-process-safety.test.ts` and `scripts/test-cross-tenant-staging.ts` matched or were safer on main. +- Safety Plan and eval-cost work were merged duplicates; the invalid file-input opacity variant was already corrected on main. +- The staging tenancy JSON was the sole unique approved artifact. GitHub run `29795051547` passed all listed cross-tenant checkpoints and cleanup at commit `578e94aed26c86832f1d6f15cbf67730ba690670`. + +## Remaining intentional debt + +- Provider/operations items remain in `docs/outstanding-issues.md`, including semantic-rerank gating, source-governance refresh, webhook activation and document-change trigger rollout. +- Protected answer-composition/RAG defects remain approval- and canary-gated. They were not made worse or silently closed by this reconciliation. +- The WebKit `_rsc` test-harness issue remains separate from #1083's reproduced Firefox stabilization. +- Secret-bearing and post-freeze active worktrees remain until their owners provide a safe handoff. + +## Verification status + +Every implementation PR used a red reproducer or exact content proof, focused checks, `verify:cheap`, PR-local handoff evidence where selected, hosted required checks, and zero actionable review threads. Database PRs additionally used disposable replay/drift/ACL/owner-scope guards. UI PRs used identity-verified local servers and Chromium UI gates. + +The final forced-offline aggregate proved Node/npm runtime compatibility, lint, type-check, the production build/client-bundle secret scan, 364 passing Vitest files (3,222 passed and one skipped), 29 guarded SECURITY DEFINER functions, 40 owner-scoped API files, 36 RAG fixtures, and 307 offline RAG contract tests. The local full Playwright matrix exceeded its 30-minute wrapper limit while still progressing through WebKit. One retained Firefox failure artifact from that interrupted run was rechecked in isolation and passed (1/1); every implementation PR's hosted required/browser checks was green on its final head. The interrupted local matrix is recorded as incomplete rather than passed and was not repeatedly rerun. No live provider evaluation or production mutation was needed; RAG spend remained $0 of the authorised $15 total budget. diff --git a/docs/archive/staging-tenancy-evidence-29795051547/staging-tenancy-evidence.json b/docs/archive/staging-tenancy-evidence-29795051547/staging-tenancy-evidence.json new file mode 100644 index 000000000..90a0b317a --- /dev/null +++ b/docs/archive/staging-tenancy-evidence-29795051547/staging-tenancy-evidence.json @@ -0,0 +1,30 @@ +{ + "schemaVersion": 1, + "check": "cross-tenant-staging", + "status": "passed", + "runId": "d5469e73-0f48-4f4e-925c-1eb965e7bc84", + "startedAt": "2026-07-21T02:09:14.264Z", + "completedAt": "2026-07-21T02:09:48.986Z", + "projectRef": "ikoiolksxqxfxgiyqpnu", + "projectRefSha256": "84133097192cb7e71de965452c6a64308b774d5c56d4d80218b8d185aaf3a054", + "appOrigin": "https://app-staging-6a78.up.railway.app", + "commitSha": "578e94aed26c86832f1d6f15cbf67730ba690670", + "workflowRunUrl": "https://github.com/BigSimmo/Database/actions/runs/29795051547", + "checkpoints": [ + "configuration-safety", + "distinct-users", + "private-fixtures", + "list", + "detail", + "signed-url", + "labels", + "mutation", + "universal-search", + "offline-retrieval", + "source-only-answer", + "reindex" + ], + "cleanup": "passed", + "cleanupErrors": [], + "error": null +} diff --git a/docs/branch-review-ledger.md b/docs/branch-review-ledger.md index 240c15335..f9e9f3b56 100644 --- a/docs/branch-review-ledger.md +++ b/docs/branch-review-ledger.md @@ -20,6 +20,21 @@ Use this ledger to prevent repeated branch and PR reviews when the reviewed HEAD | Date | Branch or ref | Reviewed HEAD | Scope | Outcome | Checks | | ---------- | -------------------------------------------------------- | ---------------------------------------- | ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| 2026-07-22 | PR #1087 / `codex/reconcile-product-truth` | `edbc2260fef59ca2fa7c6973dffb85e32354bce1` (merged as `05dc52fd8408a65117e22a6236e43252203bea92`) | Product-truth copy, account persistence and unavailable-SSO presentation | MERGED. Cross-device claims now match favourites/preferences persistence; recent searches are identified as browser-session data; the contradictory “never shared” statement is removed. All unavailable setup providers and Apple elsewhere use the connected accessible “coming soon” placeholder pattern. The single review finding was fixed, replied to and resolved. | Red DOM proof; focused 19/19; `verify:cheap` 3,220 passed / 1 skipped; `verify:ui` 265/265; PR-local build/secret scan/offline RAG; final hosted required, Production UI, policy and security checks green. No provider calls or RAG spend. | +| 2026-07-22 | PR #1086 / `codex/reconcile-xlsx-budgets` | `5376880a40749b6526fd7e4603a7be9d04bc9624` (merged as `2963fba46eacd644618a588fa283f7597faa2644`) | XLSX resource-boundary review | MERGED. Enforces worksheet, non-empty-row, rendered-cell and UTF-8 output ceilings before result fragments are appended; sparse-column output is preserved. No actionable review threads. | Red 257-sheet reproducer; focused 4/4; `verify:cheap` 3,218 passed / 1 skipped; PR-local build/scan/offline RAG; hosted required/security/policy green. | +| 2026-07-22 | PR #1085 / `codex/reconcile-docx-budgets` | `b08c60e1127592f0bc08f88797905f1e871172ce` (merged as `008a92b0fbad652484b6cdde6295bc456f4b7bf9`) | DOCX extraction-budget review | MERGED after two valid allocation-order findings. Declared media/Word-XML sizes are checked before inflate/materialization, with post-read fail-safes; artifact count, single/aggregate bytes and extracted text are bounded. All threads resolved. | Red 1,001-media reproducer; focused 7/7; `verify:cheap` 3,214 passed / 1 skipped; PR-local; hosted coverage/build/security/policy green. | +| 2026-07-22 | PR #1084 / `codex/reconcile-bulk-reindex` | `7b7737bd63b9dcd3ba820379a54cfc11595d6e98` (merged as `589fb9b99e18061782b0c7b3fa6b14fa0e8388d5`) | Bulk reindex partial-success contract | MERGED. Completed mixed batches return HTTP 200 with successful, failed and missing results; preflight-wide conflicts retain non-2xx behavior; UI reports counts and refreshes successful work. | Red deletion-race proof; focused 127/127; `verify:cheap` 3,207 passed / 1 skipped; PR-local build/scan/offline RAG; hosted green. | +| 2026-07-22 | PR #1083 / `codex/reconcile-browser-matrix` | `7eed83d37c8ab29b520aa798b25bef9d12efbf5a` (merged as `0afa0a55501afd784bec9237dca9e1b5d98d849a`) | Current Chromium/Firefox/WebKit browser salvage | MERGED test-only Firefox stabilization. Stale browser expectations, unrelated styles and duplicate service-worker isolation were rejected. | Current-main 40 passed / 1 skipped / 1 Firefox failure; final targeted matrix 3/3; `verify:cheap`; `verify:ui` 265/265; PR-local; hosted green. | +| 2026-07-22 | PR #1082 / `codex/reconcile-non-rag-p2` | `eca5af958dadc3d79269ab4f41c56110eb8dace7` (merged as `d302be1cfd033eacd64a42d7ef6fe1af3c3b03ac`) | Reproduced non-RAG P2 salvage | MERGED only malformed fallback-PDF image tolerance and live-test env loading. Retryable auth was already on main; the old 31-file patch was not replayed. | Two red proofs; focused 37/37; `verify:cheap` 3,203 passed / 1 skipped; PR-local build/scan/offline RAG; hosted green. | +| 2026-07-22 | PR #1081 / `codex/reconcile-publication-approval` | `79dadbc46e5694ad7ea2232cdc14329632d40943` (merged as `a00638af2e1116896bedf493af0dbb591a707567`) | Publication reviewed-state digest, locks and migration | MERGED. Approval binds canonical document/metadata/artifact/generation state and publication locks relevant rows/rejects active work. New forward migration used; stale archived timestamp rejected. | Focused 72/72; 181-migration disposable replay; schema/types/drift regeneration; grant/owner/migration guards; PR-local 3,201 passed / 1 skipped; hosted migration/required checks green. No live apply. | +| 2026-07-22 | PR #1080 / `codex/reconcile-health-readiness` | `199d98f9d3385964dd7c48a28d2ebe2b2382635d` (merged as `6976aaeeece84680ed6ffc9e77f839f3a314ec4e`) | Supabase readiness fail-closed behavior | MERGED. Returned and thrown probe failures degrade readiness without leaking raw dependency errors; setup-status backoff remains limited to availability failures. | Focused 22/22; amended `verify:cheap` 3,199 passed / 1 skipped; PR-local/build/offline RAG; hosted green. | +| 2026-07-22 | PR #1079 / `codex/fix-auth-cookie-precedence` | `f5d00416be2d52ebbf59ef1b0c108021446551a6` (merged as `a8814b671b43938428fe2dbba355bf5ddf79f5c9`) | Late auth review follow-up | MERGED. Current-project SSR cookies precede stale legacy cookies; retired-project cookies are ignored; invalid modern credentials never fall back. | Focused auth 148/148; hosted full gates green. Heavy local rerun was lock-blocked and transparently deferred. | +| 2026-07-22 | PR #1078 / `codex/reconcile-auth-upload-privacy` | `f83bb6772ff8e4eb6e7ea2c6e7b53ea39ed8f990` (merged as `001ce3543cb7e8020b0f6a5c3171f14601c73e6b`) | Optional-auth tri-state and upload-privacy revalidation | MERGED auth fix. Presented invalid/malformed credentials return 401 instead of anonymous quota; absent credentials preserve public reads. Anonymous-upload metadata patch rejected as stale because uploads are already administrator-only before parsing/duplicate lookup. | Red auth proof; focused 141/141; `verify:cheap` 3,191 passed / 1 skipped; PR-local 3,192 passed / 1 skipped plus build/offline RAG; hosted green. | +| 2026-07-22 | PR #1077 / `codex/reconcile-migration-role-guardrails` | `6845f238f54a095f9a9a81f8ebdde0c2ed8fe1ce` (merged as `bf9a50836a445441f4d224686c54f1c4af257b6a`) | Hosted migration-role and Docker-owner guardrails | MERGED. Reserved-role references are rejected in active surfaces; the sole immutable historical exception is checksum-pinned; replay discovers the storage owner dynamically. | Red six-reference proof; focused 15/15; PostgreSQL 17.6 replay; `verify:cheap` 3,182 passed / 1 skipped; PR-local/hosted migration and image checks green. | +| 2026-07-22 | PR #1076 / `codex/reconcile-therapy-mode` | `4008c62bea9496a1f597a9fc2c3142c69b937cfb` (merged as `142646355a045314da85fa2b1582fdc45b2ac02e`) | Therapy mode user-facing naming | MERGED. Copy/metadata/navigation use Therapy mode while `/therapy-compass` and internal names remain. Review found sidebar and codebase-index gaps; both fixed and all threads resolved. | Focused 31/31; sitemap/index; identity-verified server; focused Chromium 2/2; `verify:cheap` 3,177 passed / 1 skipped; hosted Production/Advisory UI green. | +| 2026-07-22 | PR #1075 / `codex/reconcile-route-reachability-ast` | `58e57a79b4e7766aebd3d0404a6c431f3a286bbe` (merged as `46f143d135afcd2f449ae6bedd05332a7af35f4d`) | Binding-aware route-reachability AST | MERGED. Recognizes bound Next navigation APIs and allowlisted `ModeHomeTemplate.actions`; raw anchors, prefetch, shadowed identifiers and arbitrary href metadata do not count. Both review findings fixed/resolved. | Focused 5/5; full unit 3,172 passed / 1 skipped; `verify:cheap`; offline RAG; hosted required/security/policy green. | +| 2026-07-22 | PR #1062 / `codex/chat-supabase-rls-title-words-0ef3` | `38efe6d7ab8c3ea7c550f6c30bbcefd527a23a2a` (merged as `ae950de196b2a8e39e88226f41ef941be14e415d`) | Backend-only title-word policy and live-drift review | MERGED. Service-role-only RLS/ACL contract retained; browser roles remain revoked. Read-only live comparison found no unexpected drift and no migration apply was needed. Review thread resolved. | Focused schema 67/67; PostgreSQL replay/drift/grant/owner guards; production-readiness READY in the credential-bearing source checkout; live read-only drift clean. | +| 2026-07-22 | PR #1061 / `claude/settings-dialog-tests-123366` | `0638fee21a60f29b1be1f3302c95c69db693c19d` (merged as `3e70a22c671da0199d507b00b0a77e9a99db2621`) | SettingsDialog action-flow coverage | MERGED test-only action coverage with correct `vi.hoisted` setup. Stale review thread was verified, replied to and resolved; unnecessary fixture-reset follow-up was not pushed. | Focused 5/5; PR-local 3,172 passed / 1 skipped and offline RAG 36/36; hosted required checks green. | | 2026-07-21 | main | 71059eba98bc6e335c2c82cb9ab542aad44dfae8 | database audit, drift analysis, and data contract review (/drift /data /audit) | Completed offline audit of database schema, migrations, generated drift manifest, function grants, owner-scope API boundaries, therapy data indexes, and data ingestion logic. Verified drift-manifest byte-identical match to schema.sql (schema_sha256: 50da0978a164...). Found one P2 static check failure: orphaned test tests/check-july8-live-batch.test.ts references deleted script scripts/check-july8-live-batch.ts, causing npm run check:knip and verify:cheap to fail. Live Supabase schema comparison and live ingestion audits were approval-gated and skipped per provider boundary rules. | Local offline checks run: Vitest 339/339 test files passed (3,053/3,054 tests passed, 1 skipped); tests/drift-detection.test.ts (10/10 passed); check:function-grants (28/28 SECURITY DEFINER functions revoked); check:owner-scope (40 API routes clean against 25 owner tables); check:therapy-data-index (205 records OK); check:design-system-contract (520 files clean); strict check:type-scale & check:icon-scale; check:runtime; check:github-actions; check:ci-scope; check:ci-triage; check:pr-policy; check:gate-manifest; check:codebase-index-coverage. Provider checks skipped (approval-gated): check:drift, check:supabase-project, check:migration-history, audit:source-governance. | | 2026-07-14 | multiple remote branches (16 refs) | multiple SHAs | remote branch cleanup | Safely deleted 16 fully merged and redundant remote branches on origin (including `claude/canary-gate-fixes`, `claude/codebase-index-coverage`, `claude/design-elevation-e1e2`, `claude/design-sync-fixes-p1`, `claude/docs-script-linter`, `claude/document-image-viewer-review-ox7t11`, `claude/generation-token-starvation-fix`, `claude/github-actions-codex-issue-f4t4s5`, `claude/hero-composer-hydration`, `claude/pdf-signed-url-refresh`, `claude/pt-audit-monitor-marker-fix`, `claude/pt-audit-pr2-variant-early-exit`, `claude/pt-audit-pr4-trust-copy`, `claude/pt-audit-pt17-live-monitor`, `codex/eval-canary-quota-handling`, and `cursor/clean-sentry-lockfile-orphans-74cf`). | Confirmed zero unique commits against origin/main and MERGED/CLOSED status on GitHub via `gh pr list`. | | 2026-07-14 | worktrees (6244, 8ba3, b6ff, e6b5, repo-improvement-review-09945c) | detached HEADs | local worktree cleanup | Safely removed and unregistered 5 clean, inactive worktrees from the git registry. | Ran `git worktree remove` and verified final active worktrees. | diff --git a/docs/outstanding-issues.md b/docs/outstanding-issues.md index ac089035e..7d0009b68 100644 --- a/docs/outstanding-issues.md +++ b/docs/outstanding-issues.md @@ -27,7 +27,7 @@ Durable, cross-session memory of everything still outstanding for this repo: ope - Resolving an item moves its row to **Resolved / archive** with the date and a one-line outcome — rows are archived, not deleted, so the history stays auditable. - + ## Open items @@ -35,7 +35,6 @@ Durable, cross-session memory of everything still outstanding for this repo: ope | ---- | --- | ----- | ------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- | ---------- | | #001 | P2 | task | Semantic reranking still gated off | `RAG_SEMANTIC_RERANK_ENABLED=false` from PR #901. Do not enable until the provider-backed 36/36 retrieval-quality gate **and** an ambiguity-focused canary are explicitly approved and recorded. | `docs/process-hardening.md` (Semantic reranking rollout debt); PR #901 | 2026-07-21 | | #005 | P3 | rec | `finalScore` saturates at clamp ceiling | Base + ~40 stacked boosts routinely exceed 1.0, so strong matches tie at 1.0 and order by an arbitrary `document_id` tiebreak. If ranking is ever revisited, break ties by the **pre-clamp** score rather than raising the `[0,1]` ceiling (downstream gates assume `[0,1]`). Ordering already sorts by the unbounded pre-clamp `rankScore` (`clinical-search.ts:1735,1927,1950-1955`), so the clamp confines only the reported confidence value, not result order. Not a defect on the current golden set; any change here is a protected RAG surface (canary required). | `docs/rag-hybrid-findings-and-todo.md` P1 item 4; `src/lib/clinical-search.ts:1735` | 2026-07-21 | -| #006 | P2 | issue | Globe "Language & region" button had no handler | Fixed in this PR to the disabled "Coming soon" placeholder convention (`aria-disabled` + sr-only note). Wire to a real language/region settings screen when one exists, then drop the placeholder state. | `src/components/clinical-dashboard/master-search-header.tsx:1829`; session 2026-07-21 | 2026-07-21 | | #007 | P3 | rec | `/tools` vs `/?mode=tools` parallel Tools entry points | `/tools` (standalone `ApplicationsLauncherPage`) has no inbound in-app link; the sidebar Tools item uses `/?mode=tools`. Decide the canonical entry point and wire nav consistently, or drop the standalone `/tools` page + `/applications` redirect. Currently allowlisted in `tests/route-reachability.test.ts`. | `src/app/tools/page.tsx`; `src/app/applications/route.ts` | 2026-07-21 | | #009 | P3 | rec | Confirm `/api/jobs` is intentionally server/ops-only | No client `fetch()` reaches `/api/jobs` (only tests import it). Confirm it is a deliberate ops/manual surface; if abandoned, remove it. | `src/app/api/jobs/route.ts` | 2026-07-21 | | #010 | P3 | task | Un-built "Coming soon" controls across forms/favourites | ~10 disabled placeholders (forms refine/reset, favourites sort/add/new-set, move-to-set, remove-favourite). Correctly flagged (`aria-disabled` + "Coming soon"), not defects — wire when the underlying features land. | `forms-search-results-page.tsx`; `favourites-hub.tsx`; `favourites-command-library-page.tsx` | 2026-07-21 | @@ -65,15 +64,27 @@ Durable, cross-session memory of everything still outstanding for this repo: ope | #035 | P3 | rec | Threshold-conflict detection covers only 3 params | `detectThresholdDisagreements` checks only ANC, WBC, and platelets paired with withholding verbs, so cross-source conflicts on medication doses, lithium/thyroid levels, or vital signs go undetected. Deliberately narrow (see the comment at `:469-474`). Broadening changes when an answer is classified `conflicting` and adds warnings — real false-positive risk. Needs new fixtures plus a behaviour review before any change. | `src/lib/evidence.ts:469-574`; PR #1051 audit item 7 | 2026-07-22 | | #036 | P3 | rec | No explicit `is_public` visibility flag on documents | Public-corpus visibility is implicit: `owner_id IS NULL` on an `indexed` document (`resolveSearchScope`). The `metadata.public_corpus` marker is written by the promotion migrations but never used as a retrieval filter. Promotion is unconditional on `clinical_validation_status`, so unverified documents are publicly searchable — compensated by keeping `unverified_source` in the frontend-visible warning set. A hard schema flag touches RLS and the clinical-risk-gated retrieval RPCs; weigh against the existing compensating control before acting. | `supabase/schema.sql:61-108`; `src/lib/search-scope.ts:181-236`; PR #1051 audit item 3 | 2026-07-22 | | #037 | P3 | rec | D5 trust-cap-all-claims flag parked OFF | `NEXT_PUBLIC_RAG_TRUST_CAP_ALL_CLAIMS` extends authority gating from high-risk claims to **all** supported claims (`deriveTrust`). Ships OFF by design; flipping it caps trust to `medium` for routine claims across the board — a product/clinical-UX decision, not a defect. Both states are test-pinned. Next action: product decision, then flip and re-baseline the UI expectations. | `src/lib/answer-render-policy.ts:159-177`; PR #1051 audit item 11 | 2026-07-22 | +| #038 | P3 | rec | Consolidate shared comparison behavior | Several clinical modes expose comparison workflows with similar selection, empty-state and mobile-dock needs. Define one shared behavioral contract before another comparison surface is added; keep mode-specific clinical content separate. This is a design-system recommendation, not a current defect. | design audit reconciliation; session 2026-07-22 | 2026-07-22 | +| #039 | P3 | rec | Consolidate catalogue toolbar patterns | Catalogue/search pages have independently evolved filter, sort, result-count and mobile toolbar behavior. Inventory the existing implementations and converge only the repeated interaction contract; do not flatten mode-specific search semantics. | design audit reconciliation; session 2026-07-22 | 2026-07-22 | +| #040 | P3 | rec | Add targeted visual-regression baselines | Keep a small approved baseline set for high-value desktop/mobile surfaces and accessibility modes instead of screenshotting every route. Start with account/settings, document viewer, mode homes and bottom-composer interactions; define an intentional-update workflow before enabling blocking comparisons. | design audit reconciliation; session 2026-07-22 | 2026-07-22 | +| #041 | P3 | rec | Extend the existing Factsheets reading model | Do not add a second patient-facing Factsheets mode. Future patient-content work should extend the existing Easy Read/Standard presentation and its accessibility/content contracts. Revisit only with a concrete user need and source-governance plan. | design audit reconciliation; session 2026-07-22 | 2026-07-22 | ## Resolved / archive Move resolved rows here with the resolution date and a one-line outcome. Keep them — do not delete. -| ID | Type | Summary | Outcome | Resolved | -| ---- | ---- | ------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | -| #003 | task | Staging tenancy release evidence outstanding | Ran GitHub Action and validated isolation | 2026-07-21 | -| #002 | task | Process-ownership fix not yet isolated on `main` | Fixed process isolation using child.pid termination | 2026-07-21 | -| #008 | rec | Dead href builders in `document-flow-routes.ts` | Not dead code (false positive): `documentReaderHref`/`documentEvidenceHref` are live via the mock wrappers in `src/components/document-search-mockups.tsx` + `src/components/master-document-flow-mockups.tsx` (rendered under `src/app/mockups/document-search/`) and covered by `tests/document-flow-routes.test.ts`; removing breaks the build. Only the production non-mock hrefs are unlinked from prod UI — a wiring gap, not dead code. | 2026-07-22 | -| #015 | task | Content-first fallback regression tests | Added `tests/registry-record-loader.dom.test.tsx` (8) + `tests/medication-record-page.dom.test.tsx` (6) covering content-first fallback paint, live swap-in, spinner/skeleton, error + not-found/unauthorized states, and the invariant that no authoritative verification badge shows before live governance reconciles (registry fixture-flag neutralization + medication governance-drop-on-error). | 2026-07-22 | -| #004 | rec | Rescope provider-gated RAG safety ideas | Closed obsolete — rescue source (754-line RAG-safety worktree) unrecoverable/pruned across all refs; answer-quality thresholds + deep-health already shipped on `main` (#585/#587); only cost-cap preflight was genuinely missing and, per session decision, dropped rather than re-filed. | 2026-07-22 | +| ID | Type | Summary | Outcome | Resolved | +| ---- | ----- | ---------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- | +| #003 | task | Staging tenancy release evidence outstanding | Ran GitHub Action and validated isolation | 2026-07-21 | +| #002 | task | Process-ownership fix not yet isolated on `main` | Fixed process isolation using child.pid termination | 2026-07-21 | +| #008 | rec | Dead href builders in `document-flow-routes.ts` | Not dead code (false positive): `documentReaderHref`/`documentEvidenceHref` are live via the mock wrappers in `src/components/document-search-mockups.tsx` + `src/components/master-document-flow-mockups.tsx` (rendered under `src/app/mockups/document-search/`) and covered by `tests/document-flow-routes.test.ts`; removing breaks the build. Only the production non-mock hrefs are unlinked from prod UI — a wiring gap, not dead code. | 2026-07-22 | +| #015 | task | Content-first fallback regression tests | Added `tests/registry-record-loader.dom.test.tsx` (8) + `tests/medication-record-page.dom.test.tsx` (6) covering content-first fallback paint, live swap-in, spinner/skeleton, error + not-found/unauthorized states, and the invariant that no authoritative verification badge shows before live governance reconciles (registry fixture-flag neutralization + medication governance-drop-on-error). | 2026-07-22 | +| #004 | rec | Rescope provider-gated RAG safety ideas | Closed obsolete — rescue source (754-line RAG-safety worktree) unrecoverable/pruned across all refs; answer-quality thresholds + deep-health already shipped on `main` (#585/#587); only cost-cap preflight was genuinely missing and, per session decision, dropped rather than re-filed. | 2026-07-22 | +| #006 | issue | Globe "Language & region" button had no handler | Resolved on main with the repository's disabled "Coming soon" placeholder convention and button-wiring coverage. Future language/region work remains a feature request, not an inert-control defect. | 2026-07-22 | +| #042 | issue | Invalid optional credentials fell into anonymous access | PRs #1078/#1079 introduced `absent | valid | invalid`, return 401 for presented invalid credentials, preserve authoritative header precedence and prefer the current-project session cookie. The archived anonymous-upload metadata patch was rejected as stale because uploads are already administrator-only before duplicate lookup. | 2026-07-22 | +| #043 | issue | Readiness could report healthy or throw on Supabase errors | PR #1080 now fails readiness closed for returned and thrown dependency failures, preserves recognized actionable messages, and prevents raw dependency-error disclosure. | 2026-07-22 | +| #044 | issue | Publication approval was not bound to immutable reviewed state | PR #1081 added a canonical reviewed-state digest, row locks, active-job rejection and a new forward migration with replay/schema/type/drift evidence. | 2026-07-22 | +| #045 | issue | Bulk reindex discarded partial-success results | PR #1084 reserves preflight conflicts for non-2xx responses; completed mixed batches return per-item success/failure/missing results, and the UI refreshes successful work. | 2026-07-22 | +| #046 | issue | DOCX extraction lacked explicit resource budgets | PR #1085 added pre-inflate declared-size checks and post-read fail-safes for artifact count, per-artifact bytes, aggregate media, Word XML and extracted UTF-8 text. | 2026-07-22 | +| #047 | issue | XLSX extraction could construct unbounded results | PR #1086 bounds worksheets, non-empty rows, rendered cells and UTF-8 output while preserving sparse-column rendering. | 2026-07-22 | +| #048 | issue | Account copy overstated sync/privacy and enabled unavailable SSO | PR #1087 now maps copy to actual favourites/preferences persistence, identifies browser-session recents, removes the contradictory "never shared" claim and clearly disables unavailable providers using the accessible placeholder contract. | 2026-07-22 | From 22c965ece6aae38d772bcc4576bb53f561bece5c Mon Sep 17 00:00:00 2001 From: BigSimmo <87357024+BigSimmo@users.noreply.github.com> Date: Thu, 23 Jul 2026 01:08:52 +0800 Subject: [PATCH 2/2] docs: preserve issue table structure --- docs/outstanding-issues.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/outstanding-issues.md b/docs/outstanding-issues.md index 7d0009b68..3cba9476c 100644 --- a/docs/outstanding-issues.md +++ b/docs/outstanding-issues.md @@ -81,7 +81,7 @@ Move resolved rows here with the resolution date and a one-line outcome. Keep th | #015 | task | Content-first fallback regression tests | Added `tests/registry-record-loader.dom.test.tsx` (8) + `tests/medication-record-page.dom.test.tsx` (6) covering content-first fallback paint, live swap-in, spinner/skeleton, error + not-found/unauthorized states, and the invariant that no authoritative verification badge shows before live governance reconciles (registry fixture-flag neutralization + medication governance-drop-on-error). | 2026-07-22 | | #004 | rec | Rescope provider-gated RAG safety ideas | Closed obsolete — rescue source (754-line RAG-safety worktree) unrecoverable/pruned across all refs; answer-quality thresholds + deep-health already shipped on `main` (#585/#587); only cost-cap preflight was genuinely missing and, per session decision, dropped rather than re-filed. | 2026-07-22 | | #006 | issue | Globe "Language & region" button had no handler | Resolved on main with the repository's disabled "Coming soon" placeholder convention and button-wiring coverage. Future language/region work remains a feature request, not an inert-control defect. | 2026-07-22 | -| #042 | issue | Invalid optional credentials fell into anonymous access | PRs #1078/#1079 introduced `absent | valid | invalid`, return 401 for presented invalid credentials, preserve authoritative header precedence and prefer the current-project session cookie. The archived anonymous-upload metadata patch was rejected as stale because uploads are already administrator-only before duplicate lookup. | 2026-07-22 | +| #042 | issue | Invalid optional credentials fell into anonymous access | PRs #1078/#1079 introduced `absent \| valid \| invalid`, return 401 for presented invalid credentials, preserve authoritative header precedence and prefer the current-project session cookie. The archived anonymous-upload metadata patch was rejected as stale because uploads are already administrator-only before duplicate lookup. | 2026-07-22 | | #043 | issue | Readiness could report healthy or throw on Supabase errors | PR #1080 now fails readiness closed for returned and thrown dependency failures, preserves recognized actionable messages, and prevents raw dependency-error disclosure. | 2026-07-22 | | #044 | issue | Publication approval was not bound to immutable reviewed state | PR #1081 added a canonical reviewed-state digest, row locks, active-job rejection and a new forward migration with replay/schema/type/drift evidence. | 2026-07-22 | | #045 | issue | Bulk reindex discarded partial-success results | PR #1084 reserves preflight conflicts for non-2xx responses; completed mixed batches return per-item success/failure/missing results, and the UI refreshes successful work. | 2026-07-22 |