diff --git a/docs/branch-review-ledger.md b/docs/branch-review-ledger.md index 63f9deafdf..1a2b3fc30a 100644 --- a/docs/branch-review-ledger.md +++ b/docs/branch-review-ledger.md @@ -758,8 +758,7 @@ Records before 2026-07-28 were written by hand and had drifted: 146 lines carrie | 2026-08-08 | claude/document-image-mobile-view-30xzw8 | 2394d903a6ca1ba7a84e380c9ed5cada038fa5c0 | document-viewer phone image layout + lightbox geometry (PR #1737) | implemented: capped rail/body grid tracks, removed aspect-ratio min-height transfer, rebuilt phone image viewer (legible open scale, rotation re-fit, clamped pan, double-tap, footer controls) | lint, typecheck, test (5647 pass / 1 pre-existing fail), build, eval:rag:offline, check:bundle-budget, all verify:pr-local static steps by hand; browser gates blocked by #255 | | 2026-08-08 | claude/document-image-mobile-view-30xzw8 | d257df7e11913db1d367535171fac726f47e7f1c | PR #1737 document-viewer phone image review-and-fix | fixed P1 expand fixture/threshold + P2 double-tap stage coords/pointer-up + resize re-clamp; Production UI timeout root cause cleared; merge-tree clean | verify:pr-local PASS (525 files/5653 tests); lint; typecheck; focused vitest 64/64; Production UI delegated to CI | | 2026-08-08 | PR #1740 / claude/inpage-nav-info-pages-v8rhnd | b67f33f65e00529eb0dd1682d6925e708243ee93 | Extract InPageNavHeader (default in-page nav template) + convert differentials detail; PR 1 of 3 | HANDOFF. Template extracted from the duplicated DocumentViewer/differential-detail markup into src/components/in-page-nav/ (InPageNavHeader, PageSection/toDocumentSections, usePageSectionWeights); differential-detail-page converted (-207 lines), behaviour-neutral. section-index.ts untouched so document tests unaffected. DocumentViewer deliberately NOT converged (owns h1, edge-glass-header, visual baselines) - follow-up. Anchor-offset hook generalisation deferred to PR 2 where it is consumed. 3 source-scanning contracts + addon-slot guard updated to follow the markup and additionally assert adoption; addon-slot scan widened to InPageNavHeader or it would go silent for every future adopter. Single failing test (pr-handoff-stop) is a root-uid artifact: chmod 0555 does not block root, reproduced with work stashed on clean tree. | verify:cheap 5618 passed/1 failed (root artifact); verify:pr-local same, short-circuits at test so build not reached; build run separately - Compiled successfully in 53s + client bundle secret check passed; verify:phone-chrome EXIT=0 (stage1 119 passed, stage2 7 passed 23.5s, full UI policy auto not selected); lint/typecheck/prettier --check . clean. No provider-backed gates. Deps installed with engine check relaxed (user-approved; Node 24.13.0 vs jsdom floor 24.15) - lockfile untouched. | -| 2026-08-08 | cursor/fix-diagnosis-back-nav-cd3d | 5f637fcf6c4c4c42513f0dd79899eeff96f8cc9e | differentials diagnosis detail back nav | fixed back to /differentials/diagnoses; phone-chrome green | test:focused 16p; verify:phone-chrome 21p+7p; verify:pr-local pending | -| 2026-08-08 | cursor/fix-diagnosis-back-nav-cd3d | 5f637fcf6c4c4c42513f0dd79899eeff96f8cc9e | differentials diagnosis detail back nav (supersedes 2026-08-08) | fixed back to /differentials/diagnoses; phone-chrome + pr-local green | test:focused 16p; verify:phone-chrome ui-phone-scroll 21p + focused 7p; verify:pr-local 5704p | +| 2026-08-08 | claude/document-viewer-optimization-tu8tnj | 9a5f79ab133c6ab9ea2a47e93b0101df8db44607 | docs-only: one outstanding-issues row (#285) recording the lowercase authorizationHeader trap surfaced by PR #1741 review | ship: PR #1754 | check:outstanding-issues (283 rows, unique ids, next-id above highest), prettier --check on the changed file; no source touched so lint/typecheck/test/build have no changed failure path | | 2026-08-08 | claude/mode-routing-search-pages-jabe17 | 3a0bdd62466080ad713873cdd690ae600635a979 | mode routing: one shared home page at /, mode pill retargets the composer, /documents + /medications mode homes | handoff — PR #1744 opened; 2 pre-existing failures verified at base bc33d41 | test:e2e:pr 406 passed/2 failed (both fail at base); vitest 5608 passed/1 failed (pre-existing); lint clean; tsc clean; sitemap:check, docs:check-index, docs:check-inventory, check:design-system-contract, check:outstanding-issues pass; verify:pr-local and verify:ui blocked by pre-existing installed-lock-parity (playwright 1.62.0 vs locked 1.62.1) | | 2026-08-08 | claude/mode-routing-search-pages-jabe17 | 468cc3fce85726a66098af0600d2b5d5951e3213 | bug-hunt | findings: P1 documents home autoRun on keystroke; P2 stale PWA /?mode=prescribing; P2 landing vs lastAppMode race; P2 /medications?q&run deep-link lost | vitest app-modes+search-route-ownership 36 pass; static ownership/ask-routing proof; no browser/UI/provider | | 2026-08-08 | claude/mode-routing-search-pages-jabe17 | 6d1099b479358caa05c92f236848117feb920d4e | shared-home mode-routed search navigation | no high-confidence P0-P2 PR-introduced defects; prior bug-hunt P1/P2s appear fixed on tip; residual: prescribing submit-from-shared-home URL omits run=1 (pre-existing path), seed effect untested behaviourally, no browser/UI proof this pass | vitest app-modes+search-route-ownership+audit-navigation+pwa-manifest 61 pass; static read of focus files vs origin/main; ledger:lookup NOT REVIEWED; no provider/UI | @@ -767,6 +766,9 @@ Records before 2026-07-28 were written by hand and had drifted: 146 lines carrie | 2026-08-08 | claude/planning-build-intelligence-9ot0nm | 1ebc84bb288b516bb322c09cde2889e981d302a4 | AGENTS.md reasoning-effort calibration section (docs-only) | Authored and handed off as PR #1730; docs-only, pr-policy classifier returns clinicalRisk/operationalRisk/ragRanking false | prettier --check . (repo-wide, pass); docs:check-links (1665 refs resolve, pass); pr-policy classifyPullRequestFiles(AGENTS.md) | | 2026-08-08 | claude/planning-build-intelligence-9ot0nm | 2b0ad7d41d841c13515f10de7c41e449470dfa78 | pr-1730 review-and-fix | Deep review + Bugbot: no P0/P1; fixed 2 scoped P2 clarity risks (version-bump under-planning; live-state vs provider boundary). Residual: OPENAI_*_REASONING_EFFORT vocab overlap. Merge-tree clean; required CI was green pre-push. | prettier --check AGENTS.md; docs:check-links (1667); verify:pr-local (docs route pass); verify:cheap (524 files / 5607 tests pass); pr-policy classify clinical/operational/rag false; Bugbot no P0-P2 | | 2026-08-08 | dependabot/npm_and_yarn/js-yaml-4.3.1 | a79943df33e653d2a65d4db2f192ee77c22ab75a | PR #1668 unblock | late-synced main after CI green on f04a96c3; merge-tree clean (GitHub DIRTY was stale); js-yaml 4.3.1 + nanoid 3.3.18 preserved; no unresolved threads; CI re-run after push | pre-late-sync: PR required pass on f04a96c3; Production UI skipped; post-sync pending | +| 2026-08-08 | claude/document-viewer-optimization-tu8tnj (PR #1754) | 41b4bccf7d7229920c33344bec0d46e0f2e48b97 | heavy review-and-fix | CONFLICT merge-tree on docs/outstanding-issues.md resolved: kept main #285 (Node/jsdom floor) + renumbered authorizationHeader trap to #286, next-id=287; merged origin/main; 1 unresolved review thread (comments 403 — skipped); no product code change | check:outstanding-issues PASS (284 rows, next-id=287); prettier --check docs/outstanding-issues.md PASS; ledger:dedupe none; no provider-backed checks | +| 2026-08-08 | cursor/fix-diagnosis-back-nav-cd3d | 5f637fcf6c4c4c42513f0dd79899eeff96f8cc9e | differentials diagnosis detail back nav | fixed back to /differentials/diagnoses; phone-chrome green | test:focused 16p; verify:phone-chrome 21p+7p; verify:pr-local pending | +| 2026-08-08 | cursor/fix-diagnosis-back-nav-cd3d | 5f637fcf6c4c4c42513f0dd79899eeff96f8cc9e | differentials diagnosis detail back nav (supersedes 2026-08-08) | fixed back to /differentials/diagnoses; phone-chrome + pr-local green | test:focused 16p; verify:phone-chrome ui-phone-scroll 21p + focused 7p; verify:pr-local 5704p | | 2026-08-08 | cursor/forms-results-bar-documents-style-13dc | 0a3a5ab8e6d3e1dfd225cb4c6dc9f728344be794 | forms-results-bar documents-filter-style | PASS: Forms ribbon uses ResultFilterTrigger + coming-soon Sheet; ResultTabs removed; ui-tools forms case 1 passed; band DOM 46 passed; lint+typecheck green | lint,typecheck,search-results-header-band.dom,ui-tools:forms-filter | | 2026-08-08 | cursor/phone-mode-dense-production-05c0 (PR #1648) | 276a5cd02cfb8fb93d969e9e4db167576e054a42 | Run PR sweep: CI fix + threads + drift | DIRTY/master-search-header conflict → merged origin/main; phone dense + desktop tall rows preserved; CI re-running | vitest header-scroll-hide+mode-nav 55 passed; lint master-search-header; no provider-backed checks | | 2026-08-08 | dependabot/npm_and_yarn/js-yaml-4.3.1 (PR #1668) | e95160210e7801c1f4e863648ed6b48c8fbee71f | Run PR sweep: CI fix + threads + drift | BEHIND → merged origin/main; Safety audit failed on transitive nanoid→bumped lock to 3.3.18; CI re-running | npm audit --omit=dev --audit-level=high clean; no provider-backed checks | diff --git a/docs/outstanding-issues.md b/docs/outstanding-issues.md index e28fd1829e..de36b520dc 100644 --- a/docs/outstanding-issues.md +++ b/docs/outstanding-issues.md @@ -165,7 +165,7 @@ removed after current-main verification; it is not missing recommended work. | 112 | `#257` | Optional | High — formulation/specifiers flake | Standing until second reproduction | 15–30 min | Single unreproduced ui-formulation flake when run with ui-specifiers — record a second sighting only; do not quarantine until three on the same SHA. **Stop:** do not weaken assertions. | - + ## Open items > **Merged-main canary update (2026-07-23, run `30018289898`):** the new structured report correctly recorded evaluated tree `c24f2e8f2d30d0c59fc1eba025d3dcd63478137e`, run/attempt identity and `cross-region-runner` latency context. Golden retrieval remained 36/36 with document/content recall 1.0 and no failed cases. The 44-case answer gate had grounded-supported and unsupported-correct rates of 1.0, but failed because `neuroleptic-side-effect-escalation` again returned one citation where two are required (citation-failure rate 0.0227). `admission-discharge-comparison` again omitted the specific AKG admission document after `comparison_source_extractive_fallback`; `admission-discharge-coverage-paraphrase` was advisory-only at 24,870 ms. Answer cost was reported as `$0.234736`. Do not retry immediately: retain this as the first structured datapoint, compare it with the scheduled 2026-07-26 report, and keep retrieval/ranking unchanged. @@ -322,6 +322,7 @@ removed after current-main verification; it is not missing recommended work. | #283 | P3 | rec | The 100-id batch signed-URL route still has no caller | **Outcome:** either the batch minter is used or it is retired, rather than sitting as an untested, unreachable privileged surface. **Detail:** src/app/api/images/signed-urls/route.ts POSTs up to 100 image ids and returns their signed URLs, with its own rate limit, owner scoping and committed-generation filter. Nothing in src/ calls it — only tests/private-access-routes.test.ts imports it. The viewer resolves images one at a time through use-signed-image-url.ts. The 2026-08-08 pass added in-flight deduplication there, which removes the duplicate-consumer case (a figure and its lightbox racing for the same asset) but not the many-distinct-images case: a page of N figures is still N round trips where one batch call would do. **Next:** decide deliberately — wire the rail/filmstrip to the batch route when a page mounts several distinct images at once, or delete the route and its tests. The cost of leaving it is a privileged endpoint no product code exercises. **Stop:** if wiring it, keep the per-image endpoint for the lightbox's retry path; do not make the batch the only way to mint a URL. | session 2026-08-08 document-viewer optimisation; src/app/api/images/signed-urls/route.ts | 2026-08-08 | | #284 | P3 | issue | tests/pr-handoff-stop.test.ts fails whenever the suite runs as root | **Outcome:** 'npm run test' is green in a root container, so a real failure is not hidden behind a known one. **Detail:** 'pr-handoff-stop hook > emits handoff context only when the marker file exists' expects markerExists('sess-readonly') to be false — it makes the marker directory read-only and asserts the hook could not write there. Root ignores the permission bits, so the write succeeds and the assertion fails. Reproduced on an unmodified bc33d41 checkout as well as on the viewer-optimisation branch, so it is environment-dependent, not a regression. Cost is that every full-suite run in a root container reports '1 failed', which trains readers to skim past the failure count. **Next:** skip the case when 'process.getuid?.() === 0' with an explicit reason, or drop privileges for that assertion. **Stop:** do not delete the coverage — the read-only case is the point of the test on a normal user account. | session 2026-08-08 full-suite runs; reproduced on bc33d41 | 2026-08-08 | | #285 | P2 | issue | Fresh remote/Cloud containers cannot run npm ci — shipped Node 24.13.0 is below the ^24.15.0 floor that main's jsdom@30.0.1 now requires | Observed 2026-08-08 in a Claude Code web container while syncing PR #1730. npm ci --include=dev aborts with EBADENGINE on jsdom@30.0.1 (needs Node ^22.22.2, ^24.15.0 or >=26); the container ships v24.13.0, so node_modules stays stale and the pre-push static guard then fails typecheck on the missing tailwind-merge added by #1678. Worked around by nvm install 24.19.0 plus a PATH prefix (nvm use alone does not stick — system node shadows it). Next action: raise the engines.node floor in package.json to >=24.15 so the mismatch fails loudly at the declared contract, and provision a compatible Node in the remote/Cloud setup path so a fresh container is not blocked at first install. | session 2026-08-08 (PR #1730) | 2026-08-08 | +| #286 | P2 | issue | authorizationHeader is lowercase, and reading .Authorization off it fails silently | **Outcome:** nobody keys identity off `authorizationHeader` by property again without hitting a gate or a comment first. **Detail:** `authorizationHeadersForAccessToken` returns `{ authorization: 'Bearer …' }` — lowercase, per the Fetch/Headers convention (`src/lib/supabase/client.tsx:82`). The value is typed `Record`, so reading `.Authorization` type-checks, returns undefined, and degrades to whatever fallback the caller wrote. On PR #1741 the same mistake was made twice in one session and both were identity-scoping code: the in-flight signed-URL dedupe key in `use-signed-image-url.ts` collapsed every user onto `endpoint+''`, so an account switch with a request in flight could hand user B user A's signed URL; and `detailRequestSignature` in `DocumentViewer.tsx` omitted the token it documented as being present (weaker in practice — `authStatus`/`initialDetailIdentityStale` and the render-time identity reset still moved on a real switch — but the stated defence was not the shipped one). Review caught both before merge and each site now reads `headers.authorization ?? headers.Authorization ?? ''`. Merged main has no other property reads: every remaining caller passes the header object wholesale to `fetch`, where casing is irrelevant. **Next:** cheapest first — export a named helper (e.g. `authorizationIdentity(headers)`) from the auth module and use it at both sites so there is one definition, then consider a lint rule or a narrower type (a branded `AuthorizationHeader` with a lowercase-only key) so `.Authorization` stops type-checking at all. **Stop:** do not 'fix' this by emitting uppercase from `authorizationHeadersForAccessToken` — lowercase is the correct convention and callers pass the object to `fetch`. | PR #1741 review (Codex signed-URL/cache finding); src/lib/supabase/client.tsx:82; session 2026-08-08 | 2026-08-08 | ## Resolved / archive