Skip to content

Public demo UX baseline - #6

Open
OneBigHen wants to merge 28 commits into
feat/single-user-ai-studiofrom
feat/public-demo-ux-baseline
Open

OneBigHen wants to merge 28 commits into
feat/single-user-ai-studiofrom
feat/public-demo-ux-baseline

Conversation

@OneBigHen

Copy link
Copy Markdown
Owner

Summary

  • Homepage visitor view, owner nav split
  • Prod compose tunnel alias wiring

Baseline branch for public demo UX. PR into feat/single-user-ai-studio (not main). CI retargeted to this branch — verifying it fires.

claude and others added 27 commits August 23, 2026 20:47
Responds to @claude mentions in PR/issue comments and reviews using Zac's Claude Pro subscription (CLAUDE_CODE_OAUTH_TOKEN), not metered API billing.
The npm-based self-installer dies with EACCES opening
/root/.cache/pnpm-store/v3/server/server.json on hosted runners.
standalone: true fetches the release binary directly and takes the
version from package.json packageManager instead of a duplicate input.
The minimal legacy CI still trips the pnpm setup path; the feature
branch's ci.yml is verified past setup/install/format/lint/typecheck.
Add Claude Code GitHub Action (@claude mentions)
chore: certify current production baseline
setCanonicalSources did a full clear-and-rewrite of the Yjs sources map
on every command, from a snapshot that materializeSources had already
silently filtered (any source whose sourceJson failed to parse was
dropped). The next command, even one unrelated to sources, would
permanently destroy that entry. Now preserved instead of deleted when
it can't be round-tripped through the typed snapshot.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0194R12WjWHUbh7EQbjB3i1h
loadRuntimeSession silently replaced an in-progress runtime session
with a fresh one whenever the guide's stepIds changed, discarding real
recorded progress with no signal to the caller. It now returns
{ runtime, supersededSession }, and run.$guideId.tsx shows a
dismissible banner when real progress was set aside. The old session
was never deleted from storage (a new sessionId is created) — this
just makes the fact visible instead of silent.

Also wires in isRuntimeSession, an already-exported semantic guard
(completions/currentStepIndex/status cross-field consistency) that the
"resume an existing session" path never actually called, alongside the
Ajv shape check. Without it, a schema-valid but internally inconsistent
stored record (e.g. status: 'completed' with no matching completions)
would be trusted and rendered as complete by the UI.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0194R12WjWHUbh7EQbjB3i1h
POST /api/session minted the organization-owner role for any caller
whenever GUIDEFORGE_OWNER_ID was unset, documented as "loopback/dev
mode" but never actually enforced as loopback-only in code. Added
assertSafeBindConfig (apps/api/src/bind-guard.ts), called at startup
in server.ts: refuses to bind to a non-loopback host unless
GUIDEFORGE_OWNER_ID is also set, turning that comment into an
enforced invariant.

Also: infra/docker/docker-compose.yml published 8080:8080 for the api
service without ever setting GUIDEFORGE_HOST, so the app bound to
127.0.0.1 inside the container and the published port was actually
unreachable. Documented this and wired GUIDEFORGE_HOST/
GUIDEFORGE_OWNER_ID through as configurable env passthroughs, with the
new guard as the backstop if network mode is enabled without an owner.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0194R12WjWHUbh7EQbjB3i1h
verifyReleasePackage verified the embedded signature against the
public key embedded in the same package — proves internal
self-consistency only, not authenticity. Anyone can sign a forged
package with their own key and embed it alongside; keyId was a
free-form label with no cryptographic binding to the key that signed
it. TrustedKeyStore (signing.ts) already existed, fully unit-tested,
but was never wired into verification anywhere.

Added an optional { trustedKeys: TrustedKeyStore } option: when
provided, the embedded keyId must resolve to a currently-active pinned
entry AND its public key must match what's embedded, or verification
fails. Omitting the option preserves prior behavior exactly.

apps/xr-web/src/main.tsx (the one consumer that opens .gforge files
from outside the local session) still doesn't pass a trust store —
documented why in a code comment rather than inventing a
key-distribution mechanism unprompted.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0194R12WjWHUbh7EQbjB3i1h
Tracks the four GF4 residual-risk fixes in this branch, the newly
discovered (not yet fixed) claims/citations/generationRuns
provenance-drop pattern, and a corrected assumption: PLAN_TONIGHT.md's
Phase 0.3 (remove committed planning-pack zips) doesn't apply — those
files are already .gitignored, deliberately, across three prior
commits.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0194R12WjWHUbh7EQbjB3i1h
Root-level 'pnpm format:check' (prettier --check .) covers the whole
repo including docs/, unlike the per-package turbo check tasks I'd
verified locally, which only run prettier scoped to each package's
src/. CI caught this; verified pnpm format:check, lint, typecheck,
build, boundary, dep-check, and security:policy-test all pass at the
root level before repushing.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0194R12WjWHUbh7EQbjB3i1h
fix: data-integrity and security hygiene follow-up (post-GF4)
Investigated the actual docker-dev host's Cloudflare Tunnel setup
(two tunnels exist — legacy-shared-services is explicitly deprecated
for new routes per its own README, atlas is current) and this repo's
existing infra/docker/docker-compose.yml + nginx wiring before writing
this up, so it's a concrete runbook rather than generic deployment
boilerplate. Deliberately plan-only: no infra was touched, since it's
shared with other live services on this host and the request was
explicitly to document requirements for a new session, not execute.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0194R12WjWHUbh7EQbjB3i1h
docs: public-launch runbook for guides.henning.rodeo
@coderabbitai

coderabbitai Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 895523ee-3b0b-4020-aa62-46ffd8f895d4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants