Skip to content

feat: align live Figma, harden sharing, and establish architecture authority - #824

Draft
seonghobae wants to merge 3 commits into
mainfrom
codex/figma-live-alignment
Draft

feat: align live Figma, harden sharing, and establish architecture authority#824
seonghobae wants to merge 3 commits into
mainfrom
codex/figma-live-alignment

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 9, 2026

Copy link
Copy Markdown
Collaborator

What changed

  • Aligned the workspace/editor, modal system, responsive behavior, tokens, Korean typography, and read-only /share/{id} viewer to the live Figma authority.
  • Hardened public sharing with successful-only reads, a fail-closed public-v1 field projection, generic errors, no paid public live-LLM path, no-store SPA delivery, configurable expiry, owner-only project-scoped revocation, and exact expiry display.
  • Added the canonical documentation graph: Architecture, PRD, TRD, API, UML, current/planned ERD, threat model, test strategy, operations/release plans, traceability/coverage matrices, research references, Forward Engineering support matrix, ADR-0001 through ADR-0006, and the external commercial-loop contract.
  • Separated implemented_on_main, active_pr, planned, research_only, downstream, deprecated, and out_of_scope evidence. Governed Forward Engineering remains planned; current export/diff/migration/apply paths are explicitly partial precursors.
  • Closed review/security gaps: CORS PUT/DELETE parity, fixed-hop trusted-proxy resolution for rate limiting/observability, bearer-auth schema-drift CI without SQL leakage, static-share cache controls, and the Strix-reported nanoid path pinned to 3.3.17.

Documentation sufficiency verdict

Before this update the repository was insufficient: it had no canonical Architecture/PRD/TRD/ADR graph/UML/ERD/threat/test/traceability authority set.

At head 7546f09210ee23a848a453755f8f14b1f5604cd3 the set is structurally sufficient for review, with machine-checked links, ADR inventory, lifecycle vocabulary, diagrams, requirement traceability, naming-debt inventory, planned integrity constraints, and explicit residual gaps. It is not evidence that planned Forward Engineering is implemented or that the PR is release-ready.

The hourly ChatGPT automation is enabled and externally authoritative for runtime scheduling. ADR-0006 and docs/automation-contract.md mirror its non-secret hourly review → fix → verify → PR/check → guarded merge → next-item / no-empty-queue-stop contract without claiming Git history proves execution.

Validation on the pushed tree

  • Backend: 428 passed, 1 skipped
  • Backend mypy: success across 68 source files
  • Frontend: 32 files / 305 passed
  • Frontend typecheck and production build: passed
  • npm audit --package-lock-only: 0 vulnerabilities
  • Documentation/share focused suite: 42 passed
  • git diff --check: passed
  • Independent code review: P0 0 / P1 0
  • Independent documentation review: P0 0; all identified P1 consistency/design gaps addressed

Evidence and remaining gates

  • Documentation authority: docs/README.md
  • Architecture: ARCHITECTURE.md
  • Coverage verdict: docs/documentation-coverage-matrix.md
  • Traceability: docs/traceability-matrix.md
  • Live Figma contract: docs/ui-ux/figma-contract.md
  • QA ledger: design-qa.md
  • Automation contract: docs/automation-contract.md

This remains a draft. All required checks must rerun on the new exact head; success from 385af924 is stale. Same-viewport runtime/Figma browser signoff remains blocked because the approved cloud browser cannot reach the sandbox-local Vite server. No historical screenshot is presented as current evidence. codegraph was unavailable in the environment.

@coderabbitai

coderabbitai Bot commented Aug 9, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 7edcb94a-08f4-4542-9294-faf7e75ea0f0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae changed the title feat: align Cloud ERD with live Figma and harden public sharing feat: align live Figma, harden sharing, and establish architecture authority Aug 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant