diff --git a/docs/branch-review-ledger.md b/docs/branch-review-ledger.md index 51d0f4e888..17f12774aa 100644 --- a/docs/branch-review-ledger.md +++ b/docs/branch-review-ledger.md @@ -700,20 +700,10 @@ Records before 2026-07-28 were written by hand and had drifted: 146 lines carrie | 2026-08-07 | cursor/viewer-phase0-gesture-a11y-1db8 (PR #1660) | 097dfd245f798f8105eeb6c1cf4fc077f969496f | prlanded | MERGED; squash tip empty vs branch tip 810cfc9b4a1c476a0dcc995bffb00d7329a85686; Phase 0 gesture INP, preview a11y, image decode | content tree empty vs squash; no provider-backed checks run | | 2026-08-07 | claude/pr-handoff-loop-prevention-54y5zr (PR #1670) | dfe2946110e0ff93bd4acc571ae79c26b79a7a85 | PR #1670 heavy review-and-fix | synced origin/main (behind-but-clean DIRTY cleared); fixed CodeRabbit checks-cell to name exact #1649 gates + incomplete verify:pr-local/ui + no provider checks; Bugbot none; no P0/P1; #258/#ledger delta accurate; merge-tree clean; threads cleared | verify:cheap 519 files/5493 passed; verify:pr-local docs scope (format+docs+ledger+outstanding-issues); check:branch-review-ledger; check:outstanding-issues; no provider gates | | 2026-08-07 | claude/handover-review-nlhuln | 978623337c12dc1721fe5236eadbf9a5ad929f03 | mode nav remaining modes: factsheets adoption (PR #1674) | Adopted the shared ModeNav for factsheets (Topics + Search); replaced the action-only entry, added the activeId branch, q/category/run carry, BookOpenText icon; three pinned adopted-mode lists updated together; record-route protection pinned at render now the item-count protection has expired | lint clean; typecheck clean; test 518/519 files (pr-handoff-stop failure confirmed pre-existing via stashed re-run); focused 5 files 95 tests; ui-mode-nav-density 55 passed incl 7 new factsheets rows; two mutation checks confirmed red; format committed; verify:pr-local blocked at check:installed-lock-parity (playwright 1.62.0 vs 1.62.1) | -| 2026-08-07 | cursor/privacy-live-signal-variants-bc81 (PR #1676) | f63eba10f5e9b6db047302c34412ea5261cd410b | PR #1676 unblock | before: PR policy fail (missing Clinical Governance Preflight; privacy* mockup paths trip clinicalRisk), behind-but-clean then main advanced; after: PR body preflight completed (policy green), tip synced to main via merge f63eba10 (duplicate local merge discarded), merge-tree clean, 0 unresolved threads, required CI in progress on synced tip; no code fix needed | local evaluatePullRequestPolicy ok after body; PR policy run 31172248093/31172327100 success; merge-tree clean; no provider-backed checks run | | 2026-08-07 | claude/handover-review-nlhuln | 4ff613c10fbf734b1e740a31611296c17c791ec7 | mode nav remaining modes: vestigial strip removal (PR #1679) | Removed the single-button action strip from answer/documents/services/forms/favourites/prescribing/tools; deleted the registry index-0 fallback (TS2493-forced) and the dead documents clause; stripped modeItems/onSearch/modeAriaLabel/stickyTop from PageSecondaryNavigation, keeping the empty-registry return below the information-section branch; kept the action kind with a no-live-consumer note. Completes the 13-mode navigation rollout. | lint exit 0; typecheck clean; focused 5 files 97 tests; test 518/519 files (pr-handoff-stop re-confirmed pre-existing on this base via stashed re-run); ui-mode-nav-density + ui-accessibility 71 passed (landmark scan green); branch-order guard mutation-checked (hoisting it fails 2 tests); format committed; verify:pr-local blocked at check:installed-lock-parity (playwright 1.62.0 vs 1.62.1) | -| 2026-08-07 | cursor/pr-1676-unblock-ledger-ef51 (PR #1677) | dec8f7489b4e5492e924af30dec85859932af3bb | review-and-fix | synced origin/main (behind-but-clean DIRTY; merge-tree clean); Bugbot mid-table finding dispositioned (row was tip-append before #1679; post-merge order correct; ledger guard passed); no P0/P1; 0 threads; no code fix; merge left to user | check:branch-review-ledger pass; ledger:dedupe none; merge-tree clean vs origin/main; format unchanged; no provider gates | -| 2026-08-07 | cursor/pr-1676-unblock-ledger-ef51 (PR #1677) | 574702a681cbb4d455151da023428d16c22fb460 | review-and-fix | late-synced origin/main after CI green (brought #1678 cn/tailwind-merge; remote merge 574702a6); prior sync cleared DIRTY; Bugbot mid-table finding dispositioned (tip-append before #1679; post-merge order correct); no P0/P1; 0 threads; no code fix; merge left to user | check:branch-review-ledger pass; ledger:dedupe none; merge-tree clean; prior tip required CI green; format unchanged; no provider gates | | 2026-08-05 | HEAD | 2a8881afad230880166de60a533e17588d9920ec | seven-report repo-wide audit | P2 confirmed: live drift and live-only migration; mobile CLS; ACL runner; OOXML declared-size robustness; assertion false positives. Numerous report claims stale, narrowed, or unsafe. | verify:cheap (5088 pass, 3 skip, 1 timeout); focused retry 21/21 pass; build pass; bundle budget pass; offline RAG 574/574; assertions 98%; live drift 34; browser CLS 0.228/0.218 | | 2026-08-07 | codex/consolidated-ledger-updates (PR #1683) | 413e679bb92cb19717d6d8301764df44694eb73e | review-and-fix PR #1683 | synced origin/main (behind-but-clean DIRTY cleared); restored main ledger order + sole seven-report row; Bugbot none; no P0/P1; merge-tree clean | verify:pr-local docs scope PASS (format:changed Prettier; check:branch-review-ledger 648; docs links 1650; outstanding-issues 258); merge-tree clean | -| 2026-08-07 | cursor/pr-1676-unblock-ledger-ef51 (PR #1677) | fddf495b5176f570a5238b5c17326f64f333ecff | review-and-fix | synced origin/main (behind-but-clean DIRTY; merge-tree clean; main advanced with #1684/#1666); 0 review threads; no P0/P1; no code fix; merge left to user | merge-tree clean vs origin/main; ledger:dedupe none; prior tip required CI green except stale PR mergeability; format unchanged; no provider gates | | 2026-08-07 | cursor/inpage-nav-default-235a | c6d72e406c03e205bac86d23e84813c41332c205 | docs: default in-page nav DocumentViewer chrome + PhoneHeaderCollapsePortal | docs-only; verify:pr-local passed (low-risk docs scope) | verify:pr-local --files AGENTS.md,docs/search-chrome-behaviour.md | -| 2026-08-07 | claude/issues-256-section-nav-clean | 169323053db5c572d183d59c113ecd0c76e7aca5 | issues #256: forms section anchors + differentials presentation set (PR #1697) | Wired all six formSections anchors in form-detail-page.tsx (four direct ids, two breakpoint pairs via existing mobile wrappers and single-child desktop wrappers, no component signature change); deleted differentialPresentationSections and declared /differentials/presentations/ locally-owned instead, since three of its six sections declared a -mobile targetId ReviewPanels can never satisfy and the page owns MobileTabs below xl plus the xl review sidebar. Added a registered browser spec because source-text and jsdom guards both structurally cannot see breakpoint-variant resolution. | lint exit 0; typecheck clean; test 519/520 files (pr-handoff-stop confirmed pre-existing via stashed re-run); check:gate-manifest and check:ci-scope pass with the new spec in both playwright allowlists; ui-forms-section-nav + ui-accessibility 18 passed incl real-record nav with 6 links and exactly one variant per pair visible at 390px and 1280px; binding guard mutation-checked red on one removed id; browser spec observed failing when nav genuinely absent; format clean. Environment: npm ci blocked (main lockfile needs Node >=24.15, container has 24.13), tailwind-merge@3.6.0 materialised from tarball only | -| 2026-08-07 | claude/handover-review-nlhuln | de8b74e2fb94d1ec9b1982c15a2dea43421c3eee | outstanding-issues ledger capture after the mode-nav rollout (PR #1685) | Confirmed #256's two remaining suspected section sets are dead (/forms/ and /differentials/presentations/ draw no section nav; form-decision-context-mobile is a testId not an id; ruled out sectionId indirection in both files). Added #261 (delete-or-keep the consumer-less action kind) and #262 (addon-slot single-owner rule held by two lists agreeing by coincidence). #207/#226/#231 reviewed and deliberately left untouched as existing P1 rows. | check:outstanding-issues passed (260 rows, 119 open, unique ids, no ids deleted from base 1ff9ed206456); prettier --check clean on the changed file; rows written via scripts/outstanding-issues.mjs, never hand-edited; no code gates run - docs-only diff | -| 2026-08-07 | claude/handover-review-nlhuln | de8b74e2fb94d1ec9b1982c15a2dea43421c3eee | outstanding-issues ledger capture after the mode-nav rollout (PR #1685) (supersedes 2026-08-07) | Confirmed #256's two remaining suspected section sets are dead (/forms/ and /differentials/presentations/ draw no section nav; form-decision-context-mobile is a testId not an id; ruled out sectionId indirection in both files). Added #271 (delete-or-keep the consumer-less action kind) and #272 (addon-slot single-owner rule held by two lists agreeing by coincidence) — renumbered from this PR's original #261/#262 because main claimed #261-#270 via PR #1678 design-system tracks in the interim. #207/#226/#231 reviewed and deliberately left untouched as existing P1 rows. | check:outstanding-issues passed (270 rows, 129 open, 141 archived, unique ids, next-id=273 above the highest, no ids deleted from base d32dd549a3dd); prettier --check clean on the changed file; rows written via scripts/outstanding-issues.mjs, never hand-edited; no code gates run - docs-only diff | -| 2026-08-07 | cursor/document-citation-landing-7bc3 | 82378a2bb4b875f1b610ef60c0ec3c94ee461f10 | document-viewer citation landing | ship: PDF-first citation landing; excerpt chip; indexed text collapsed until inspect/search; phone overview condensed; rail pin removed | unit 5539 pass; playwright critical citation+mobile PDF-first 2 pass; browser QA desktop/phone pass; typecheck; lint; build ALLOW_BUILD_WITH_DEV_SERVER=1; eval:rag:offline 36 golden; verify:pr-local stages green (first run flaked design-system-adoption timeout, retry green) | -| 2026-08-07 | claude/search-bar-mobile-layout-buu0io | 9d64388c0ce530d0c20bb7efe8ffb32cd928319c | phone results-filter idiom: 7 modes off MobileResultFilterControl onto ResultFilterTrigger + ResultFilterSheet; band, docs, tests | changes-shipped | typecheck; lint; test 5538 passed (1 pre-existing pr-handoff-stop failure, baselined on unmodified tree); build; check:rag:fixtures; check:bundle-budget +6.3% within tolerance; targeted Playwright: ui-accessibility 16, ui-specifiers+ui-formulation 12, ui-tools 5, ui-smoke 2, ui-stress 3 | -| 2026-08-08 | claude/differentials-inpage-navigation-h2u8fq (PR #1715) | c67c4927d8a088be267b8bd280a06f300aad60bc | differentials detail: adopt PR #1688 default in-page navigation template | Header rebuilt to the four template slots (back / title + active-section chevron sheet / ellipsis actions / weighted segment track); new detail-section-index.ts shapes the five tabs as DocumentSections reusing DocumentSectionTrack + DocumentSectionList; labelled strip gated to sm+; max-sm:static -> relative so the absolutely-positioned track keeps a positioned ancestor; tab panel renamed via aria-label since the sm-hidden strip cannot label it; sheets kept as siblings of PhoneHeaderCollapsePortal; no scroll spy (discrete panels). Adoption manifest regenerated - the dropped Tabs/ui-tools association was a coincidental capital-T comment match, not lost coverage. | typecheck exit 0; lint clean --max-warnings 0; verify:pr-local 5557 passed, stops only at pre-existing pr-handoff-stop (confirmed by stashed re-run on clean base); verify:phone-chrome lock-parity+runtime PASS, contracts 119 passed, changed-browser ui-tools passed, focused-browser 7 passed; new differential-section-nav.dom 9 passed; 40 passed re-run post-format; live browser 0 h-overflow at 320/390/768, collapse matches DocumentViewer (data-scroll-hidden=true, stack bottom 0) | | 2026-08-07 | cursor/phone-mode-dense-production-05c0 (PR #1648) | 4e0cca2ccbc19ed676765b029642da0afea6215a | Run PR sweep: CI fix + threads + drift | before: behind 17, checks green, 0 threads → after: merged origin/main (conflicts: none), CI re-running; 0 threads | merge-tree clean; git merge origin/main + push; no provider-backed checks run | | 2026-08-07 | cursor/tools-search-mockups-72e1 (PR #1653) | a7fbc26a917b347d90c6bab1e6c1b2ede6422263 | Run PR sweep: CI fix + threads + drift | before: behind 17, checks green, 0 threads → after: merged origin/main (conflicts: none), CI re-running; 0 threads | merge-tree clean; git merge origin/main + push; no provider-backed checks run | | 2026-08-07 | cursor/ship-first-redesign-mockups-2398 (PR #1654) | 9d9eb0be47073a7f051a5885359b82f2ff978a85 | Run PR sweep: CI fix + threads + drift | before: behind 17, checks green, 0 threads → after: merged origin/main (conflicts: none), CI re-running; 0 threads | merge-tree clean; git merge origin/main + push; no provider-backed checks run | @@ -727,6 +717,14 @@ Records before 2026-07-28 were written by hand and had drifted: 146 lines carrie | 2026-08-07 | cursor/viewer-phase2a-frame-controls-1db8 (PR #1687) | 5c10730be1641a386ee8c8476778933588a822fc | Run PR sweep: CI fix + threads + drift | before: up to date with main, Static PR fail (format:changed pdf-canvas-viewer), 1 outdated CodeRabbit thread (ref sync) already fixed on head → after: prettier format fix pushed; thread left open (no review-write API as cursor[bot]); CI re-running | format:changed fail→prettier --write pdf-canvas-viewer.tsx; format:changed PASS locally; no provider-backed checks run | | 2026-08-07 | claude/search-bar-mobile-layout-buu0io (PR #1689) | a152ffd89c962e3589509c0c3740dc429264063a | Run PR sweep: CI fix + threads + drift | before: behind 1, required CI green (advisory lighthouse fail ignored), 1 CodeRabbit lighthouse baseline thread (human disagreement in progress) → after: waited for CI settle, disabled automerge, merged origin/main, pushed, re-enabled automerge; thread left open for human | settled CI then merge+push; no provider-backed checks run; advisory lighthouse not chased | | 2026-08-07 | claude/issues-256-section-nav-clean (PR #1697) | 2b99db1f00c42fd7c11c4bf8acbad904ef5003e1 | Run PR sweep: CI fix + threads + drift | before: DIRTY/PR mergeability fail, behind 3, merge-tree CLEAN, 0 threads → after: merged origin/main (conflicts: none), CI re-running; 0 threads | merge-tree clean; git merge origin/main + push; no provider-backed checks run | +| 2026-08-07 | cursor/privacy-live-signal-variants-bc81 (PR #1676) | f63eba10f5e9b6db047302c34412ea5261cd410b | PR #1676 unblock | before: PR policy fail (missing Clinical Governance Preflight; privacy* mockup paths trip clinicalRisk), behind-but-clean then main advanced; after: PR body preflight completed (policy green), tip synced to main via merge f63eba10 (duplicate local merge discarded), merge-tree clean, 0 unresolved threads, required CI in progress on synced tip; no code fix needed | local evaluatePullRequestPolicy ok after body; PR policy run 31172248093/31172327100 success; merge-tree clean; no provider-backed checks run | +| 2026-08-07 | cursor/pr-1676-unblock-ledger-ef51 (PR #1677) | dec8f7489b4e5492e924af30dec85859932af3bb | review-and-fix | synced origin/main (behind-but-clean DIRTY; merge-tree clean); Bugbot mid-table finding dispositioned (row was tip-append before #1679; post-merge order correct; ledger guard passed); no P0/P1; 0 threads; no code fix; merge left to user | check:branch-review-ledger pass; ledger:dedupe none; merge-tree clean vs origin/main; format unchanged; no provider gates | +| 2026-08-07 | cursor/pr-1676-unblock-ledger-ef51 (PR #1677) | 574702a681cbb4d455151da023428d16c22fb460 | review-and-fix | late-synced origin/main after CI green (brought #1678 cn/tailwind-merge; remote merge 574702a6); prior sync cleared DIRTY; Bugbot mid-table finding dispositioned (tip-append before #1679; post-merge order correct); no P0/P1; 0 threads; no code fix; merge left to user | check:branch-review-ledger pass; ledger:dedupe none; merge-tree clean; prior tip required CI green; format unchanged; no provider gates | +| 2026-08-07 | cursor/pr-1676-unblock-ledger-ef51 (PR #1677) | fddf495b5176f570a5238b5c17326f64f333ecff | review-and-fix | synced origin/main (behind-but-clean DIRTY; merge-tree clean; main advanced with #1684/#1666); 0 review threads; no P0/P1; no code fix; merge left to user | merge-tree clean vs origin/main; ledger:dedupe none; prior tip required CI green except stale PR mergeability; format unchanged; no provider gates | +| 2026-08-07 | claude/issues-256-section-nav-clean | 169323053db5c572d183d59c113ecd0c76e7aca5 | issues #256: forms section anchors + differentials presentation set (PR #1697) | Wired all six formSections anchors in form-detail-page.tsx (four direct ids, two breakpoint pairs via existing mobile wrappers and single-child desktop wrappers, no component signature change); deleted differentialPresentationSections and declared /differentials/presentations/ locally-owned instead, since three of its six sections declared a -mobile targetId ReviewPanels can never satisfy and the page owns MobileTabs below xl plus the xl review sidebar. Added a registered browser spec because source-text and jsdom guards both structurally cannot see breakpoint-variant resolution. | lint exit 0; typecheck clean; test 519/520 files (pr-handoff-stop confirmed pre-existing via stashed re-run); check:gate-manifest and check:ci-scope pass with the new spec in both playwright allowlists; ui-forms-section-nav + ui-accessibility 18 passed incl real-record nav with 6 links and exactly one variant per pair visible at 390px and 1280px; binding guard mutation-checked red on one removed id; browser spec observed failing when nav genuinely absent; format clean. Environment: npm ci blocked (main lockfile needs Node >=24.15, container has 24.13), tailwind-merge@3.6.0 materialised from tarball only | +| 2026-08-07 | claude/handover-review-nlhuln | de8b74e2fb94d1ec9b1982c15a2dea43421c3eee | outstanding-issues ledger capture after the mode-nav rollout (PR #1685) | Confirmed #256's two remaining suspected section sets are dead (/forms/ and /differentials/presentations/ draw no section nav; form-decision-context-mobile is a testId not an id; ruled out sectionId indirection in both files). Added #261 (delete-or-keep the consumer-less action kind) and #262 (addon-slot single-owner rule held by two lists agreeing by coincidence). #207/#226/#231 reviewed and deliberately left untouched as existing P1 rows. | check:outstanding-issues passed (260 rows, 119 open, unique ids, no ids deleted from base 1ff9ed206456); prettier --check clean on the changed file; rows written via scripts/outstanding-issues.mjs, never hand-edited; no code gates run - docs-only diff | +| 2026-08-07 | claude/handover-review-nlhuln | de8b74e2fb94d1ec9b1982c15a2dea43421c3eee | outstanding-issues ledger capture after the mode-nav rollout (PR #1685) (supersedes 2026-08-07) | Confirmed #256's two remaining suspected section sets are dead (/forms/ and /differentials/presentations/ draw no section nav; form-decision-context-mobile is a testId not an id; ruled out sectionId indirection in both files). Added #271 (delete-or-keep the consumer-less action kind) and #272 (addon-slot single-owner rule held by two lists agreeing by coincidence) — renumbered from this PR's original #261/#262 because main claimed #261-#270 via PR #1678 design-system tracks in the interim. #207/#226/#231 reviewed and deliberately left untouched as existing P1 rows. | check:outstanding-issues passed (270 rows, 129 open, 141 archived, unique ids, next-id=273 above the highest, no ids deleted from base d32dd549a3dd); prettier --check clean on the changed file; rows written via scripts/outstanding-issues.mjs, never hand-edited; no code gates run - docs-only diff | +| 2026-08-07 | claude/search-bar-mobile-layout-buu0io | 9d64388c0ce530d0c20bb7efe8ffb32cd928319c | phone results-filter idiom: 7 modes off MobileResultFilterControl onto ResultFilterTrigger + ResultFilterSheet; band, docs, tests | changes-shipped | typecheck; lint; test 5538 passed (1 pre-existing pr-handoff-stop failure, baselined on unmodified tree); build; check:rag:fixtures; check:bundle-budget +6.3% within tolerance; targeted Playwright: ui-accessibility 16, ui-specifiers+ui-formulation 12, ui-tools 5, ui-smoke 2, ui-stress 3 | | 2026-08-07 | cursor/remove-specifiers-back-arrow-f1c4 | 095791235d58a6309b21b139911a1aad9fe9086b | specifiers-search-results-breadcrumb | removed lone ← Specifiers crumb from search results; deep pages unchanged | format,typecheck,lint,ensure+phone-spot-check | | 2026-08-07 | cursor/phone-mode-dense-production-05c0 (PR #1648) | 1091b17933beba655dac3e37f0e5c1bc4cdfb679 | Run PR sweep: CI fix + threads + drift | No action needed: PR required green, no unresolved review threads, not behind main. Only advisory Lighthouse job failing (never chased). | get_check_runs (PR required: success), get_review_comments (0 unresolved threads) | | 2026-08-07 | cursor/tools-search-mockups-72e1 (PR #1653) | 1df72ba6119226aee92b203db8188f58851a6d3c | Run PR sweep: CI fix + threads + drift | No action needed: PR required green, no unresolved review threads, not behind main. Only advisory Lighthouse job failing (never chased). | get_check_runs (PR required: success), get_review_comments (0 unresolved threads) | @@ -746,47 +744,28 @@ Records before 2026-07-28 were written by hand and had drifted: 146 lines carrie | 2026-08-08 | claude/ds-a4-component-defects | a029a543f744eb80e608ec482aacdbdc5f5599c2 | unblock PR #1712 | Merged origin/main (ef28960e) to clear dirty mergeable_state: real conflict in docs/branch-review-ledger.md auto-merged via merge=ledger driver. Prior tip 9ba483d3 was 1 behind main. Static PR and PR required failures were dirty-state blockers (GitHub could not build refs/pull/1712/merge). Proved post-merge: merge-tree clean, check:branch-review-ledger, check:design-system-contract. | merge-tree clean; ledger:dedupe; check:branch-review-ledger; check:design-system-contract | | 2026-08-08 | claude/ds-a4-component-defects | d3a697aa8784c9cbdecfba24402cf2269bfe15d4 | heavy review-and-fix PR #1712 | Lint blocker fixed (react-hooks/refs in Pagination); CodeRabbit threads dispositioned; synced main (4a9d81d3 Lighthouse pin); merge-tree clean; verify:cheap 5567 passed; verify:pr-local green; check:design-system-contract passed | lint; typecheck; prettier --check .; verify:cheap (5567 passed); verify:pr-local; check:design-system-contract; check:branch-review-ledger; vitest ui-v2-components.dom (75 passed) | | 2026-08-08 | cursor/run-pr-sweep-ledger-d56c (PR #1698) | ccf7284cbbe2315e5dc6a1bf126403a8a2205fa7 | Run PR sweep: CI fix + threads + drift | before: DIRTY/CONFLICTING, PR mergeability fail, behind 33, 0 threads, fake single-parent merge tip → after: real merge origin/main (conflicts resolved: docs/outstanding-issues.md + lighthouse-budget.json took main), merge-tree clean, unique diff ledger-only, 0 threads | check:outstanding-issues pass; check:branch-review-ledger pass; ledger:dedupe none; merge-tree clean; format; no provider-backed checks run | -| 2026-08-08 | claude/differentials-inpage-navigation-h2u8fq (PR #1715) | f0b27ec857a70130d1616ddc1ccae1c9952c697b | heavy review-and-fix PR #1715 differentials in-page navigation | merge-blocker cleared (origin/main sync); no P0/P1 findings; phone-chrome + verify:pr-local green on f0b27ec8 | merge-tree clean post-sync; verify:phone-chrome lock-parity+runtime PASS, contracts 119 passed, changed-browser ui-tools passed, focused-browser 7 passed (19.4s); verify:pr-local Test Files 523 passed (523), Tests 5547 passed \| 4 skipped (5551); lint+typecheck+build+rag fixtures green; 0 unresolved review threads | | 2026-08-08 | claude/ds-doc-corrections | 534405600dca67317b4d60266cda03ec95f028e7 | M1 stranded doc corrections (docs/outstanding-issues.md #262/#266, docs/design-system/COMPONENTS.md TextField row + section 4) | authored and handed off as PR #1719; every inherited figure re-measured against origin/main rather than copied forward, and the stranded version's 'eight shadow tokens, focus 2' claim was found wrong — LEGACY_SHADOW_ALIAS matches seven tokens and has never included focus | check:outstanding-issues pass (274 rows, unique ids, no ids deleted from base); prettier --check . pass whole-tree; legacyShadowAliases re-measured 228 via the contract's own analyzers; docs-only diff so no unit/lint/typecheck/browser gate applies | +| 2026-08-08 | claude/differentials-inpage-navigation-h2u8fq (PR #1715) | c67c4927d8a088be267b8bd280a06f300aad60bc | differentials detail: adopt PR #1688 default in-page navigation template | Header rebuilt to the four template slots (back / title + active-section chevron sheet / ellipsis actions / weighted segment track); new detail-section-index.ts shapes the five tabs as DocumentSections reusing DocumentSectionTrack + DocumentSectionList; labelled strip gated to sm+; max-sm:static -> relative so the absolutely-positioned track keeps a positioned ancestor; tab panel renamed via aria-label since the sm-hidden strip cannot label it; sheets kept as siblings of PhoneHeaderCollapsePortal; no scroll spy (discrete panels). Adoption manifest regenerated - the dropped Tabs/ui-tools association was a coincidental capital-T comment match, not lost coverage. | typecheck exit 0; lint clean --max-warnings 0; verify:pr-local 5557 passed, stops only at pre-existing pr-handoff-stop (confirmed by stashed re-run on clean base); verify:phone-chrome lock-parity+runtime PASS, contracts 119 passed, changed-browser ui-tools passed, focused-browser 7 passed; new differential-section-nav.dom 9 passed; 40 passed re-run post-format; live browser 0 h-overflow at 320/390/768, collapse matches DocumentViewer (data-scroll-hidden=true, stack bottom 0) | +| 2026-08-08 | claude/differentials-inpage-navigation-h2u8fq (PR #1715) | f0b27ec857a70130d1616ddc1ccae1c9952c697b | heavy review-and-fix PR #1715 differentials in-page navigation | merge-blocker cleared (origin/main sync); no P0/P1 findings; phone-chrome + verify:pr-local green on f0b27ec8 | merge-tree clean post-sync; verify:phone-chrome lock-parity+runtime PASS, contracts 119 passed, changed-browser ui-tools passed, focused-browser 7 passed (19.4s); verify:pr-local Test Files 523 passed (523), Tests 5547 passed \| 4 skipped (5551); lint+typecheck+build+rag fixtures green; 0 unresolved review threads | | 2026-08-08 | claude/ds-doc-corrections | b4051d21f38755f7d37dbc2b49994f689af801b5 | M1 stranded doc corrections, final reviewed head (adds the review-response commit: COMPONENTS.md section 4 integration-vs-adoption split and the re-measured ui-primitives row) | merged to main as 8cffad59a. Supersedes the 534405600 record, which was accurate at that head but predates the review pass. Three findings, all valid and all fixed: Codex caught four future-dated 2026-08-09 records (corrected to the 2026-08-08 authoring date by f3a91c67c, verified none remain); CodeRabbit caught 'Select/choice controls remain separate adoption work', wrong on both axes since select.tsx consumes FormField and Select has 2 production importers while SearchField has zero; CodeRabbit caught a stale '27 adopted', and re-measuring that row also corrected 686 to 698 lines and 200 to 157 production importers of ui-primitives (200 was close to the 202 mockup-inclusive figure) | prettier --check . pass whole-tree; check:outstanding-issues pass (274 rows, unique ids, no ids deleted from base); adoption figures read from the generated adoption-manifest.json; docs-only diff so no unit, lint, typecheck or browser gate applies to it | | 2026-08-08 | claude/ds-tap-and-linkaction | 6916c80526603514d91bd29d224959dd420af59c | M5 LinkAction tone refusal plus re-measured corrections to outstanding-issues #270, #118 and #269 — final reviewed head, adds the tone?: never fix, its type-contract test and both regenerated manifests | PR #1720, superseding the 824c1b74a record. Codex found the Omit form still accepted tone through a spread; verified with a focused tsc probe before changing anything (Omit accepted the spread with no diagnostic, tone?: never rejected it with TS2345), because excess-property checking only fires on object literals. Fixed with tone?: never plus a type-level contract test that stops compiling if the prop widens back. CodeRabbit's future-dated finding fixed in ff307cc5b. CodeRabbit's ledger-scope finding does not apply: that row records a different ref and head and was accurate as written, but a superseding row for the final #1719 head was appended anyway since its scope grew after the review pass | tsc -p tsconfig.typecheck.json --noEmit exit 0 zero diagnostics; lint exit 0; check:design-system-contract exit 0 (676 production files, legacy shadow aliases 228 confirming the #262 re-measure, adoption 53 components 55 roots, design-sync 53 components and 7 guidelines); check-icon-scale.mjs --strict exit 0; vitest threads pool 3 files 164 tests passed; check:outstanding-issues pass; check:branch-review-ledger pass; prettier --check . pass whole-tree; main merged in with merge-tree proven clean first and an id-set proof over both merge parents showing 274 ids each side, none lost, none invented | +| 2026-08-08 | cursor/safety-plan-phone-safe-area-624a (PR #1711) | ad1b1f5db24ed68ee4c0d5963620e4562829884e | heavy review-and-fix PR #1711 | fixed CodeRabbit sm:py guard parity; late-synced #1720 behind-but-clean; no P0/P1; Bugbot none; threads cleared; merge-tree clean; required CI green on 78c14205 pre-sync | vitest safety-plan+standalone 18p; verify:cheap 523/5582; verify:pr-local format+lint+typecheck+test+build+rag-fixtures; Production UI critical+(1)(2)(3)+PR required SUCCESS on 78c14205; no provider gates | +| 2026-08-07 | cursor/document-citation-landing-7bc3 | 82378a2bb4b875f1b610ef60c0ec3c94ee461f10 | document-viewer citation landing | ship: PDF-first citation landing; excerpt chip; indexed text collapsed until inspect/search; phone overview condensed; rail pin removed | unit 5539 pass; playwright critical citation+mobile PDF-first 2 pass; browser QA desktop/phone pass; typecheck; lint; build ALLOW_BUILD_WITH_DEV_SERVER=1; eval:rag:offline 36 golden; verify:pr-local stages green (first run flaked design-system-adoption timeout, retry green) | | 2026-08-08 | claude/ds-close-276 (PR #1724) | 75c89993f3ea23b70a250f605b21437b4ea9aac8 | PR #1724 review-and-fix | fixed Codex P2 wrong #118 Lighthouse cause (150 overwrite vs 151 pin); dispositioned CodeRabbit #276 archive claim as false (issues:done move); merge-tree clean; required CI was green on prior tip 8ae8c48f; no Bugbot findings | check:outstanding-issues pass; prettier --check docs/outstanding-issues.md pass; no provider-backed checks | | 2026-08-08 | claude/ds-close-276 (PR #1724) | 4baa9a1b42fa05731a6f983b3e0d0ebbd37f5271 | PR #1724 review-and-fix | synced origin/main (#1725 conflict on outstanding-issues resolved by preferring main queue then re-applying #276 done + corrected #118 diagnosis); Codex P2 fixed; CodeRabbit #276 archive claim dispositioned false; merge-tree clean after sync | check:outstanding-issues pass; prettier --check docs/outstanding-issues.md pass; merge-tree clean vs origin/main; no provider-backed checks | -| 2026-08-08 | claude/mode-routing-search-pages-jabe17 | 3a0bdd62466080ad713873cdd690ae600635a979 | mode routing: one shared home page at /, mode pill retargets the composer, /documents + /medications mode homes | handoff — PR #1744 opened; 2 pre-existing failures verified at base bc33d41 | test:e2e:pr 406 passed/2 failed (both fail at base); vitest 5608 passed/1 failed (pre-existing); lint clean; tsc clean; sitemap:check, docs:check-index, docs:check-inventory, check:design-system-contract, check:outstanding-issues pass; verify:pr-local and verify:ui blocked by pre-existing installed-lock-parity (playwright 1.62.0 vs locked 1.62.1) | -| 2026-08-08 | claude/mode-routing-search-pages-jabe17 | 468cc3fce85726a66098af0600d2b5d5951e3213 | bug-hunt | findings: P1 documents home autoRun on keystroke; P2 stale PWA /?mode=prescribing; P2 landing vs lastAppMode race; P2 /medications?q&run deep-link lost | vitest app-modes+search-route-ownership 36 pass; static ownership/ask-routing proof; no browser/UI/provider | +| 2026-08-08 | claude/document-viewer-optimization-tu8tnj | 98b799a372b1e341c86e8807d5cf37e987413e49 | document viewer phone/PWA rework: CSP-blocked native reader removed, one toolbar, fit-mode pinch, canvas pixel budget, source-first phone order, in-window detail-refetch guard, pdf.js on-demand fetch + teardown, image/signed-URL wins | ship: PR #1741 | lint, typecheck, test 5625 pass (1 pre-existing root-container failure), build, check:rag:fixtures, check:bundle-budget 1499.8 KiB vs base 1500.0 KiB, check:runtime, check:installed-lock-parity, format:changed; verify:ui not run (container Chromium 141 cannot raster pdfjs 6, see #278) | +| 2026-08-08 | claude/document-viewer-optimization-tu8tnj | 2359e158cb7bca5954e9c5ee84ca0766964ad901 | PR #1741 document-viewer phone/PWA review-and-fix | supersede: fixed Production UI phone Zoom/section-trigger; handlePdfLoadSuccess clamp; prior P1/P2 fixes retained; merge-tree clean | prior verify:cheap+pr-local green; ui-smoke selectors fixed for overflow Zoom + revealPhoneHeaderControl; no provider gates | | 2026-08-08 | claude/document-image-mobile-view-30xzw8 | 2394d903a6ca1ba7a84e380c9ed5cada038fa5c0 | document-viewer phone image layout + lightbox geometry (PR #1737) | implemented: capped rail/body grid tracks, removed aspect-ratio min-height transfer, rebuilt phone image viewer (legible open scale, rotation re-fit, clamped pan, double-tap, footer controls) | lint, typecheck, test (5647 pass / 1 pre-existing fail), build, eval:rag:offline, check:bundle-budget, all verify:pr-local static steps by hand; browser gates blocked by #255 | | 2026-08-08 | claude/document-image-mobile-view-30xzw8 | d257df7e11913db1d367535171fac726f47e7f1c | PR #1737 document-viewer phone image review-and-fix | fixed P1 expand fixture/threshold + P2 double-tap stage coords/pointer-up + resize re-clamp; Production UI timeout root cause cleared; merge-tree clean | verify:pr-local PASS (525 files/5653 tests); lint; typecheck; focused vitest 64/64; Production UI delegated to CI | | 2026-08-08 | PR #1740 / claude/inpage-nav-info-pages-v8rhnd | b67f33f65e00529eb0dd1682d6925e708243ee93 | Extract InPageNavHeader (default in-page nav template) + convert differentials detail; PR 1 of 3 | HANDOFF. Template extracted from the duplicated DocumentViewer/differential-detail markup into src/components/in-page-nav/ (InPageNavHeader, PageSection/toDocumentSections, usePageSectionWeights); differential-detail-page converted (-207 lines), behaviour-neutral. section-index.ts untouched so document tests unaffected. DocumentViewer deliberately NOT converged (owns h1, edge-glass-header, visual baselines) - follow-up. Anchor-offset hook generalisation deferred to PR 2 where it is consumed. 3 source-scanning contracts + addon-slot guard updated to follow the markup and additionally assert adoption; addon-slot scan widened to InPageNavHeader or it would go silent for every future adopter. Single failing test (pr-handoff-stop) is a root-uid artifact: chmod 0555 does not block root, reproduced with work stashed on clean tree. | verify:cheap 5618 passed/1 failed (root artifact); verify:pr-local same, short-circuits at test so build not reached; build run separately - Compiled successfully in 53s + client bundle secret check passed; verify:phone-chrome EXIT=0 (stage1 119 passed, stage2 7 passed 23.5s, full UI policy auto not selected); lint/typecheck/prettier --check . clean. No provider-backed gates. Deps installed with engine check relaxed (user-approved; Node 24.13.0 vs jsdom floor 24.15) - lockfile untouched. | -| 2026-08-08 | claude/document-viewer-optimization-tu8tnj | 98b799a372b1e341c86e8807d5cf37e987413e49 | document viewer phone/PWA rework: CSP-blocked native reader removed, one toolbar, fit-mode pinch, canvas pixel budget, source-first phone order, in-window detail-refetch guard, pdf.js on-demand fetch + teardown, image/signed-URL wins | ship: PR #1741 | lint, typecheck, test 5625 pass (1 pre-existing root-container failure), build, check:rag:fixtures, check:bundle-budget 1499.8 KiB vs base 1500.0 KiB, check:runtime, check:installed-lock-parity, format:changed; verify:ui not run (container Chromium 141 cannot raster pdfjs 6, see #278) | -| 2026-08-08 | claude/document-viewer-optimization-tu8tnj | 2359e158cb7bca5954e9c5ee84ca0766964ad901 | PR #1741 document-viewer phone/PWA review-and-fix | supersede: fixed Production UI phone Zoom/section-trigger; handlePdfLoadSuccess clamp; prior P1/P2 fixes retained; merge-tree clean | prior verify:cheap+pr-local green; ui-smoke selectors fixed for overflow Zoom + revealPhoneHeaderControl; no provider gates | +| 2026-08-08 | claude/document-viewer-optimization-tu8tnj | 9a5f79ab133c6ab9ea2a47e93b0101df8db44607 | docs-only: one outstanding-issues row (#285) recording the lowercase authorizationHeader trap surfaced by PR #1741 review | ship: PR #1754 | check:outstanding-issues (283 rows, unique ids, next-id above highest), prettier --check on the changed file; no source touched so lint/typecheck/test/build have no changed failure path | +| 2026-08-08 | claude/mode-routing-search-pages-jabe17 | 3a0bdd62466080ad713873cdd690ae600635a979 | mode routing: one shared home page at /, mode pill retargets the composer, /documents + /medications mode homes | handoff — PR #1744 opened; 2 pre-existing failures verified at base bc33d41 | test:e2e:pr 406 passed/2 failed (both fail at base); vitest 5608 passed/1 failed (pre-existing); lint clean; tsc clean; sitemap:check, docs:check-index, docs:check-inventory, check:design-system-contract, check:outstanding-issues pass; verify:pr-local and verify:ui blocked by pre-existing installed-lock-parity (playwright 1.62.0 vs locked 1.62.1) | +| 2026-08-08 | claude/mode-routing-search-pages-jabe17 | 468cc3fce85726a66098af0600d2b5d5951e3213 | bug-hunt | findings: P1 documents home autoRun on keystroke; P2 stale PWA /?mode=prescribing; P2 landing vs lastAppMode race; P2 /medications?q&run deep-link lost | vitest app-modes+search-route-ownership 36 pass; static ownership/ask-routing proof; no browser/UI/provider | | 2026-08-08 | claude/mode-routing-search-pages-jabe17 | 6d1099b479358caa05c92f236848117feb920d4e | shared-home mode-routed search navigation | no high-confidence P0-P2 PR-introduced defects; prior bug-hunt P1/P2s appear fixed on tip; residual: prescribing submit-from-shared-home URL omits run=1 (pre-existing path), seed effect untested behaviourally, no browser/UI proof this pass | vitest app-modes+search-route-ownership+audit-navigation+pwa-manifest 61 pass; static read of focus files vs origin/main; ledger:lookup NOT REVIEWED; no provider/UI | -| 2026-08-08 | cursor/safety-plan-phone-safe-area-624a (PR #1711) | ad1b1f5db24ed68ee4c0d5963620e4562829884e | heavy review-and-fix PR #1711 | fixed CodeRabbit sm:py guard parity; late-synced #1720 behind-but-clean; no P0/P1; Bugbot none; threads cleared; merge-tree clean; required CI green on 78c14205 pre-sync | vitest safety-plan+standalone 18p; verify:cheap 523/5582; verify:pr-local format+lint+typecheck+test+build+rag-fixtures; Production UI critical+(1)(2)(3)+PR required SUCCESS on 78c14205; no provider gates | | 2026-08-08 | dependabot/npm_and_yarn/js-yaml-4.3.1 | 072b83f79a70037a04a8412844c041db43c9ce48 | PR #1668 unblock | synced main; merge-tree clean; required CI was green on prior tip e9516021; js-yaml 4.3.1 + nanoid 3.3.18 preserved; no unresolved threads; CI re-run after sync | pre-sync PR required pass; Production UI skipped (deps); post-sync pending | | 2026-08-08 | claude/planning-build-intelligence-9ot0nm | 1ebc84bb288b516bb322c09cde2889e981d302a4 | AGENTS.md reasoning-effort calibration section (docs-only) | Authored and handed off as PR #1730; docs-only, pr-policy classifier returns clinicalRisk/operationalRisk/ragRanking false | prettier --check . (repo-wide, pass); docs:check-links (1665 refs resolve, pass); pr-policy classifyPullRequestFiles(AGENTS.md) | | 2026-08-08 | claude/planning-build-intelligence-9ot0nm | 2b0ad7d41d841c13515f10de7c41e449470dfa78 | pr-1730 review-and-fix | Deep review + Bugbot: no P0/P1; fixed 2 scoped P2 clarity risks (version-bump under-planning; live-state vs provider boundary). Residual: OPENAI_*_REASONING_EFFORT vocab overlap. Merge-tree clean; required CI was green pre-push. | prettier --check AGENTS.md; docs:check-links (1667); verify:pr-local (docs route pass); verify:cheap (524 files / 5607 tests pass); pr-policy classify clinical/operational/rag false; Bugbot no P0-P2 | | 2026-08-08 | dependabot/npm_and_yarn/js-yaml-4.3.1 | a79943df33e653d2a65d4db2f192ee77c22ab75a | PR #1668 unblock | late-synced main after CI green on f04a96c3; merge-tree clean (GitHub DIRTY was stale); js-yaml 4.3.1 + nanoid 3.3.18 preserved; no unresolved threads; CI re-run after push | pre-late-sync: PR required pass on f04a96c3; Production UI skipped; post-sync pending | -| 2026-08-08 | cursor/safety-plan-copy-timer-a650 | cf57b34a36b768e150cd776f7e19acfd984245f7 | PR #1717 unblock | fixed missing it() closer from Copilot autofix; merged origin/main after #1668; merge-tree clean; no unresolved threads | local: vitest patient-safety-plan.dom.test.tsx (8/8); format ok; pending hosted CI after push | -| 2026-08-08 | cursor/safety-plan-copy-timer-a650 | 3142eb9a93275ce2c2435523560b4ed6624d8f53 | PR #1717 unblock | fixed parse + no-explicit-any from Copilot autofix; merged origin/main after #1668; merge-tree clean; 0 threads | local: vitest 8/8; eslint file clean; format ok; pending hosted CI | -| 2026-08-08 | cursor/specifiers-builder-mobile-f72a | 894677891e2793cadc721b106e5abb715ff918e3 | specifiers-builder-pathway-mobile | pass-pathway-strip-and-mobile-overflow | npm run test:e2e -- tests/ui-specifiers.spec.ts --project=chromium: 6 passed | -| 2026-08-08 | cursor/differentials-query-lit-stream-8bc0 | bed84986742ca85b3724dd3ccc0758d4b9649934 | differentials diagnoses query-lit stream | implemented query-lit Diagnoses stream with match jump, related clusters, compare select, browse chapters; PR #1757 | unit:pass;lint:pass;typecheck:pass;verify:ui:not-run | -| 2026-08-08 | cursor/differentials-query-lit-stream-8bc0 | 106124d8084a1eab2eddab828076d10f96d3cedc | differentials diagnoses query-lit stream | implemented query-lit Diagnoses stream with match jump, related clusters, compare select, browse chapters; PR #1757 | unit:pass;lint:pass;typecheck:pass;verify:ui:not-run | -| 2026-08-08 | cursor/differentials-query-lit-stream-8bc0 (PR #1757) | e7529dd2dd847b0bfd4b53daa723a8f5a329a50e | heavy review-and-fix | synced main; fixed P1 compare id drop + P2 mobile threshold + P2 query normalize; 3 threads need reply (API 403) | vitest differential-stream+differentials-navigation+differentials 42 passed; no provider-backed checks | -| 2026-08-08 | cursor/differentials-query-lit-stream-8bc0 (PR #1757) | d76c4cc8b8633a65df66ea46b090c2864a2c1592 | heavy review-and-fix | CI fix on tip: type-scale text-3xs; presentations redirect lowercases+drops unknown while preserving valid cross-workflow ids; prior P1/P2 fixes retained | check:type-scale; vitest audit-nav+differentials-nav+stream; no provider | -| 2026-08-08 | cursor/fix-differentials-compare-5c66 | fd4801b07309625780b06afef718f93799655885 | differentials-compare-selection-handoff | fixed: preserve cross-presentation compare ids via ad-hoc /differentials/compare; URL ids sync; ModeNav Compare wired | verify:pr-local:5709 passed; test:focused:255 passed | -| 2026-08-08 | cursor/fix-differentials-compare-5c66 (PR #1756) | c739708981083b816843ceec5e50ea00818996b5 | heavy review-and-fix | merged origin/main (docs/adoption/sitemap regenerated); fixed P1 cold-load URL wipe + P2 unsupported criterion + lowercase ids; CodeRabbit empty-state/auto-seed left as intentional ModeNav handoff; threads unreplied (403) | vitest differentials+navigation+compare-selection DOM 37 pass; related nav tests 44 pass; eslint touched files; no provider-backed checks | -| 2026-08-08 | cursor/fix-differentials-compare-5c66 (PR #1756) | bd62d3a23b888d30112fdc11e86fe1811f1919bc | heavy review-and-fix | merged origin/main (docs/adoption/sitemap regenerated); fixed P1 cold-load URL wipe (state-captured ids + defer sync while loading) + P2 unsupported criterion + lowercase ids; CodeRabbit empty-state/auto-seed left as intentional ModeNav handoff; threads unreplied (403) | vitest differentials+navigation+compare-selection DOM 37 pass; related nav tests 44 pass; eslint touched files clean; no provider-backed checks | -| 2026-08-08 | cursor/forms-info-disclosure-68d6 | f5dd1dea495e8d6e9bd5106dcf0a4d062ee02292 | forms-info-disclosure | fixed Form information tick rows to expand via DisclosureGroup | verify:pr-local; forms-information-disclosure.dom.test; check:design-system-adoption | -| 2026-08-08 | cursor/forms-info-disclosure-68d6 | 8f25e6c482d8e4cd879098d7cfd73b7f8603e478 | forms-info-disclosure | fixed Form information tick rows to expand via DisclosureGroup | verify:pr-local; forms-information-disclosure.dom.test; check:design-system-adoption | -| 2026-08-08 | cursor/forms-info-disclosure-68d6 (PR #1735) | 9e1390d73ebbae0bbfc0f81bf3b3921dadf24577 | heavy review-and-fix | CONFLICT merge-tree on docs/design-system/adoption-manifest.json resolved by regenerating (DisclosureGroup form-detail import + main documents/medications routes); product forms DisclosureGroup intent preserved; 0 unresolved threads; no ambiguous clinical/auth conflicts | check:design-system-adoption PASS (53 components, 57 roots); vitest forms-information-disclosure.dom 2/2 PASS; no provider-backed checks | -| 2026-08-08 | cursor/confirm-checklist-polish-195c | 32474bcd20d5fa39097a3f75b85d3af81b404320 | form-detail Confirm checklist polish | shipped spacing/typography polish + DOM guard | vitest form-confirm-callout.dom; visual Form 1A Confirm | -| 2026-08-08 | cursor/confirm-checklist-polish-195c | 3cf0ed99a1a90f46cb7c6aff7e8b7f7bfd6212b8 | form-detail Confirm checklist polish | shipped spacing/typography polish + DOM guard | vitest form-confirm-callout.dom; visual Form 1A Confirm | -| 2026-08-08 | cursor/confirm-checklist-polish-195c | 3cf0ed99a1a90f46cb7c6aff7e8b7f7bfd6212b8 | form-detail Confirm checklist polish (supersedes 2026-08-08) | shipped spacing/typography polish + DOM guard | vitest form-confirm-callout.dom; visual Form 1A Confirm | -| 2026-08-08 | cursor/confirm-checklist-polish-195c | 96c4d3a3a1a46efedfa5b43c4bf1de227c1d19a6 | PR #1734 confirm checklist | clean; no P0/P1/P2 in ConfirmCalloutText/confirmCheckParts/Avoid row | diff vs main; form-1a catalog wiring; vitest form-confirm-callout.dom.test.tsx PASS | -| 2026-08-08 | cursor/confirm-checklist-polish-195c | 89cc8711dd0536c32818cbbd493edff860763a61 | PR #1734 unblock | synced origin/main (behind-but-clean DIRTY; merge-tree clean); no product conflict; advisory lighthouse ignored | merge-tree clean vs origin/main; ledger:dedupe none | -| 2026-08-08 | cursor/compact-services-result-text-9b7d (PR #1731) | f07828041199458bd756090d04fb5105f41e3ca4 | PR #1731 unblock | before: MERGEABLE/BEHIND(1) merge-tree CLEAN tip 14fd8aa9; required CI green (PR required + Production UI 1/2/3 + critical); 0 threads; autoMerge SQUASH armed. after: late-synced origin/main (aa6cf68c from #1668/#1717) via worktree merge (update-branch 403); merge-tree clean; 0 behind; CI will re-run on sync tip; autoMerge left armed; no product code change | gh pr checks --watch: PR required SUCCESS; Production UI (1)(2)(3)+critical SUCCESS; merge-tree clean; ledger:dedupe none; no provider gates | -| 2026-08-08 | cursor/services-content-cleanup-1c73 | 1b62fdabbabcfbb05ccbbae08b070bf7740426d5 | services content cleanup: compact catalogue fields + hide empty detail sections | APPROVE pending required CI; verify:pr-local passed; UI spot-check recommended | verify:pr-local (lint/typecheck/test/build/rag-fixtures) | -| 2026-08-08 | claude/ds-visual-advisory-off-prs (PR #1755) | e6d24190eb1e02c435003d429d88f2d293b14867 | heavy review-and-fix | merged origin/main; fixed Bugbot/Codex P2 merge_group exclusion via event allowlist; synced docs/testing.md + #118 note; CodeRabbit date nit dispositioned (owner +0800); threads unreplied (403) | vitest ci-cache-safety; check:github-actions; no provider-backed checks | -| 2026-08-08 | claude/document-viewer-optimization-tu8tnj | 9a5f79ab133c6ab9ea2a47e93b0101df8db44607 | docs-only: one outstanding-issues row (#285) recording the lowercase authorizationHeader trap surfaced by PR #1741 review | ship: PR #1754 | check:outstanding-issues (283 rows, unique ids, next-id above highest), prettier --check on the changed file; no source touched so lint/typecheck/test/build have no changed failure path | | 2026-08-08 | claude/document-viewer-optimization-tu8tnj (PR #1754) | 41b4bccf7d7229920c33344bec0d46e0f2e48b97 | heavy review-and-fix | CONFLICT merge-tree on docs/outstanding-issues.md resolved: kept main #285 (Node/jsdom floor) + renumbered authorizationHeader trap to #286, next-id=287; merged origin/main; 1 unresolved review thread (comments 403 — skipped); no product code change | check:outstanding-issues PASS (284 rows, next-id=287); prettier --check docs/outstanding-issues.md PASS; ledger:dedupe none; no provider-backed checks | | 2026-08-08 | cursor/fix-diagnosis-back-nav-cd3d | 5f637fcf6c4c4c42513f0dd79899eeff96f8cc9e | differentials diagnosis detail back nav | fixed back to /differentials/diagnoses; phone-chrome green | test:focused 16p; verify:phone-chrome 21p+7p; verify:pr-local pending | | 2026-08-08 | cursor/fix-diagnosis-back-nav-cd3d | 5f637fcf6c4c4c42513f0dd79899eeff96f8cc9e | differentials diagnosis detail back nav (supersedes 2026-08-08) | fixed back to /differentials/diagnoses; phone-chrome + pr-local green | test:focused 16p; verify:phone-chrome ui-phone-scroll 21p + focused 7p; verify:pr-local 5704p | @@ -808,14 +787,36 @@ Records before 2026-07-28 were written by hand and had drifted: 146 lines carrie | 2026-08-08 | codex/lighthouse-hardening (PR #1746) | d4af6a6356de3327906936a237405e4e7ccba0cb | Run PR sweep: CI fix + threads + drift | DIRTY + 3 Codex P2 + Static contract fail → main sync; process-group kill; suite deadline; normalized samples; contract test updated; threads unreplied (API 403) | vitest live-web-vitals-inputs+check-lighthouse-budget 61; ci-cache-safety 32; no provider-backed checks | | 2026-08-08 | cursor/phone-mode-dense-production-05c0 (PR #1648) | d2a0c8b12bcf3ea6b56c3d8291e4aa09da3e603e | Run PR sweep: CI fix + threads + drift | post-merge Unit coverage: restored usesPhoneSearchLayout min-h ternary for audit-navigation contract; CI re-running | vitest audit-navigation+mode-nav+header-scroll-hide 66 passed; no provider-backed checks | | 2026-08-08 | cursor/site-testing-speed-08c1 (PR #1686) | 11e35727a6a9b3b776e890e6a63e43fea9b0a437 | Run PR sweep: CI fix + threads + drift | post-merge Unit coverage: added ui-phone-scroll-document-rail.spec.ts to playwright PR shard 1; CI re-running | vitest playwright-pr-shards 4 passed; playwright-pr-shards --validate OK; no provider-backed checks | +| 2026-08-08 | cursor/safety-plan-copy-timer-a650 | cf57b34a36b768e150cd776f7e19acfd984245f7 | PR #1717 unblock | fixed missing it() closer from Copilot autofix; merged origin/main after #1668; merge-tree clean; no unresolved threads | local: vitest patient-safety-plan.dom.test.tsx (8/8); format ok; pending hosted CI after push | +| 2026-08-08 | cursor/safety-plan-copy-timer-a650 | 3142eb9a93275ce2c2435523560b4ed6624d8f53 | PR #1717 unblock | fixed parse + no-explicit-any from Copilot autofix; merged origin/main after #1668; merge-tree clean; 0 threads | local: vitest 8/8; eslint file clean; format ok; pending hosted CI | | 2026-08-08 | origin/main (PR #1722 follow-up) | eda8fe872de040e304621bce49535e1dfebb091e | Lighthouse testing thorough review | P1 fixed locally: stale Chrome 150 baseline, unbounded runner phases, and live input/process limits hardened; advisory policy retained | offline review; check:ci-scope PASS; test:ci-workflows 13 files 248 passed 11 skipped; check:github-actions PASS; verify:lighthouse dry-run PASS; no provider-backed checks run | | 2026-08-08 | codex/lighthouse-hardening (PR #1746) | 038058ea63837e7c4a90e84b7f8f860aacc51e13 | heavy review-and-fix | CONFLICT merge-tree on lighthouse-budget.json resolved: kept main baseline measurements + this PR Lighthouse hardening (scripts/workflows/ci-change-scope); visual-baseline policy matches main; 3 unresolved threads (comments 403 — skipped) | ci-change-scope --self-test PASS; vitest check-lighthouse-budget+ci-cache-safety 84/84 PASS; no provider-backed checks | +| 2026-08-08 | cursor/forms-info-disclosure-68d6 | f5dd1dea495e8d6e9bd5106dcf0a4d062ee02292 | forms-info-disclosure | fixed Form information tick rows to expand via DisclosureGroup | verify:pr-local; forms-information-disclosure.dom.test; check:design-system-adoption | +| 2026-08-08 | cursor/forms-info-disclosure-68d6 | 8f25e6c482d8e4cd879098d7cfd73b7f8603e478 | forms-info-disclosure | fixed Form information tick rows to expand via DisclosureGroup | verify:pr-local; forms-information-disclosure.dom.test; check:design-system-adoption | +| 2026-08-08 | cursor/forms-info-disclosure-68d6 (PR #1735) | 9e1390d73ebbae0bbfc0f81bf3b3921dadf24577 | heavy review-and-fix | CONFLICT merge-tree on docs/design-system/adoption-manifest.json resolved by regenerating (DisclosureGroup form-detail import + main documents/medications routes); product forms DisclosureGroup intent preserved; 0 unresolved threads; no ambiguous clinical/auth conflicts | check:design-system-adoption PASS (53 components, 57 roots); vitest forms-information-disclosure.dom 2/2 PASS; no provider-backed checks | +| 2026-08-08 | cursor/confirm-checklist-polish-195c | 32474bcd20d5fa39097a3f75b85d3af81b404320 | form-detail Confirm checklist polish | shipped spacing/typography polish + DOM guard | vitest form-confirm-callout.dom; visual Form 1A Confirm | +| 2026-08-08 | cursor/confirm-checklist-polish-195c | 3cf0ed99a1a90f46cb7c6aff7e8b7f7bfd6212b8 | form-detail Confirm checklist polish | shipped spacing/typography polish + DOM guard | vitest form-confirm-callout.dom; visual Form 1A Confirm | +| 2026-08-08 | cursor/confirm-checklist-polish-195c | 3cf0ed99a1a90f46cb7c6aff7e8b7f7bfd6212b8 | form-detail Confirm checklist polish (supersedes 2026-08-08) | shipped spacing/typography polish + DOM guard | vitest form-confirm-callout.dom; visual Form 1A Confirm | +| 2026-08-08 | cursor/confirm-checklist-polish-195c | 96c4d3a3a1a46efedfa5b43c4bf1de227c1d19a6 | PR #1734 confirm checklist | clean; no P0/P1/P2 in ConfirmCalloutText/confirmCheckParts/Avoid row | diff vs main; form-1a catalog wiring; vitest form-confirm-callout.dom.test.tsx PASS | +| 2026-08-08 | cursor/confirm-checklist-polish-195c | 89cc8711dd0536c32818cbbd493edff860763a61 | PR #1734 unblock | synced origin/main (behind-but-clean DIRTY; merge-tree clean); no product conflict; advisory lighthouse ignored | merge-tree clean vs origin/main; ledger:dedupe none | +| 2026-08-08 | cursor/compact-services-result-text-9b7d (PR #1731) | f07828041199458bd756090d04fb5105f41e3ca4 | PR #1731 unblock | before: MERGEABLE/BEHIND(1) merge-tree CLEAN tip 14fd8aa9; required CI green (PR required + Production UI 1/2/3 + critical); 0 threads; autoMerge SQUASH armed. after: late-synced origin/main (aa6cf68c from #1668/#1717) via worktree merge (update-branch 403); merge-tree clean; 0 behind; CI will re-run on sync tip; autoMerge left armed; no product code change | gh pr checks --watch: PR required SUCCESS; Production UI (1)(2)(3)+critical SUCCESS; merge-tree clean; ledger:dedupe none; no provider gates | +| 2026-08-08 | cursor/services-content-cleanup-1c73 | 1b62fdabbabcfbb05ccbbae08b070bf7740426d5 | services content cleanup: compact catalogue fields + hide empty detail sections | APPROVE pending required CI; verify:pr-local passed; UI spot-check recommended | verify:pr-local (lint/typecheck/test/build/rag-fixtures) | | 2026-08-08 | cursor/presentations-catalogue-tab-fb39 | 3872ea0854da2ce4e3b99ec182bb94a4cb807958 | differentials presentations catalogue ModeNav tab | shipped Presentations catalogue at /differentials/presentations; Compare entry moved to /differentials/compare; verify:pr-local passed; UI smoke confirmed 4 tabs | verify:pr-local; vitest design-system-adoption; curl presentations+compare; browser ModeNav QA | | 2026-08-08 | cursor/presentations-catalogue-tab-fb39 | 59dceae612315e95a1114a215d2d8319e439880d | differentials presentations catalogue ModeNav tab | shipped Presentations catalogue at /differentials/presentations; Compare entry moved to /differentials/compare; verify:pr-local passed; UI smoke confirmed 4 tabs | verify:pr-local; vitest design-system-adoption; curl presentations+compare; browser ModeNav QA | | 2026-08-08 | cursor/forms-results-bar-documents-style-13dc | fd148ca931ab9c023619deed98bae5af787e4253 | sync | PR #1751 unblock: CONFLICTING→MERGEABLE; 11 behind main; merge-tree clean; merge commit fd148ca9 pushed; all static+unit+build+critical CI green; Production UI (1/2/3) pending | merge-tree:clean,static-pr:pass,unit-coverage:pass,build:pass,production-ui-critical:pass,safety:pass,pr-policy:pass,production-ui-1/2/3:pending | | 2026-08-08 | cursor/form-1a-priority-facts-dc36 | e965d96258cdd3d5ad6f520616de0f32bf02498e | Form 1A priority facts: condense cards + Act section detail sheets | implemented; Form 1A Source status card replaced with Act sections 26/31/36/37/41/42; condensed clock/maker/criteria with tap sheets | typecheck pass; lint pass; npm run test 530 files / 5704 passed | | 2026-08-08 | cursor/form-1a-priority-facts-dc36 | 7040b850e655dc7ba9a23ad3e3db765cc1ad7755 | Form 1A priority facts: condense cards + Act section detail sheets | implemented; Form 1A Source status card replaced with Act sections 26/31/36/37/41/42; condensed clock/maker/criteria with tap sheets | typecheck pass; lint pass; npm run test 530 files / 5704 passed | | 2026-08-08 | cursor/form-1a-priority-facts-dc36 | e965d96258cdd3d5ad6f520616de0f32bf02498e | Form 1A priority facts: condense cards + Act section detail sheets (supersedes 2026-08-08) | implemented; Form 1A Source status card replaced with Act sections 26/31/36/37/41/42; condensed clock/maker/criteria with tap sheets | typecheck pass; lint pass; npm run test 530 files / 5704 passed | +| 2026-08-09 | claude/document-viewer-optimization-tu8tnj | b8c94dff2345a7d50c7bbce0c9c344740e6b92b1 | docs: document-viewer Phase 3 handover brief (PR #1765) | Docs-only. Adds docs/plans/document-viewer-phase3-handover.md scoping Phase 3 to all capabilities except crop-to-page overlay (bbox absent from DocumentDetailImage; plumbing crosses src/lib/**document** and forces a governance preflight). Corrects ledger #279: measured playwright@1.62.1 expects Chromium 151.0.7922.34, container ships 141.0.7390.37, CI runs HeadlessChrome/151.0.0.0, and pdfjs-dist 6.2.108 needs Map.getOrInsertComputed which ships in 151 not 141 - so the raster failure is container-only and neither proposed remedy (bump Playwright / pin pdfjs down) is needed. Cited #286 for the authorizationHeader casing trap after initially writing #285. | verify:pr-local all ten gates completed, none failed; docs:check-links 1688 references resolve; line refs re-verified against main 8db1e53 | +| 2026-08-08 | cursor/specifiers-builder-mobile-f72a | 894677891e2793cadc721b106e5abb715ff918e3 | specifiers-builder-pathway-mobile | pass-pathway-strip-and-mobile-overflow | npm run test:e2e -- tests/ui-specifiers.spec.ts --project=chromium: 6 passed | +| 2026-08-08 | cursor/differentials-query-lit-stream-8bc0 | bed84986742ca85b3724dd3ccc0758d4b9649934 | differentials diagnoses query-lit stream | implemented query-lit Diagnoses stream with match jump, related clusters, compare select, browse chapters; PR #1757 | unit:pass;lint:pass;typecheck:pass;verify:ui:not-run | +| 2026-08-08 | cursor/differentials-query-lit-stream-8bc0 | 106124d8084a1eab2eddab828076d10f96d3cedc | differentials diagnoses query-lit stream | implemented query-lit Diagnoses stream with match jump, related clusters, compare select, browse chapters; PR #1757 | unit:pass;lint:pass;typecheck:pass;verify:ui:not-run | +| 2026-08-08 | cursor/differentials-query-lit-stream-8bc0 (PR #1757) | e7529dd2dd847b0bfd4b53daa723a8f5a329a50e | heavy review-and-fix | synced main; fixed P1 compare id drop + P2 mobile threshold + P2 query normalize; 3 threads need reply (API 403) | vitest differential-stream+differentials-navigation+differentials 42 passed; no provider-backed checks | +| 2026-08-08 | cursor/differentials-query-lit-stream-8bc0 (PR #1757) | d76c4cc8b8633a65df66ea46b090c2864a2c1592 | heavy review-and-fix | CI fix on tip: type-scale text-3xs; presentations redirect lowercases+drops unknown while preserving valid cross-workflow ids; prior P1/P2 fixes retained | check:type-scale; vitest audit-nav+differentials-nav+stream; no provider | +| 2026-08-08 | cursor/fix-differentials-compare-5c66 | fd4801b07309625780b06afef718f93799655885 | differentials-compare-selection-handoff | fixed: preserve cross-presentation compare ids via ad-hoc /differentials/compare; URL ids sync; ModeNav Compare wired | verify:pr-local:5709 passed; test:focused:255 passed | +| 2026-08-08 | cursor/fix-differentials-compare-5c66 (PR #1756) | c739708981083b816843ceec5e50ea00818996b5 | heavy review-and-fix | merged origin/main (docs/adoption/sitemap regenerated); fixed P1 cold-load URL wipe + P2 unsupported criterion + lowercase ids; CodeRabbit empty-state/auto-seed left as intentional ModeNav handoff; threads unreplied (403) | vitest differentials+navigation+compare-selection DOM 37 pass; related nav tests 44 pass; eslint touched files; no provider-backed checks | +| 2026-08-08 | cursor/fix-differentials-compare-5c66 (PR #1756) | bd62d3a23b888d30112fdc11e86fe1811f1919bc | heavy review-and-fix | merged origin/main (docs/adoption/sitemap regenerated); fixed P1 cold-load URL wipe (state-captured ids + defer sync while loading) + P2 unsupported criterion + lowercase ids; CodeRabbit empty-state/auto-seed left as intentional ModeNav handoff; threads unreplied (403) | vitest differentials+navigation+compare-selection DOM 37 pass; related nav tests 44 pass; eslint touched files clean; no provider-backed checks | +| 2026-08-08 | claude/ds-visual-advisory-off-prs (PR #1755) | e6d24190eb1e02c435003d429d88f2d293b14867 | heavy review-and-fix | merged origin/main; fixed Bugbot/Codex P2 merge_group exclusion via event allowlist; synced docs/testing.md + #118 note; CodeRabbit date nit dispositioned (owner +0800); threads unreplied (403) | vitest ci-cache-safety; check:github-actions; no provider-backed checks | | 2026-08-08 | claude/mode-routing-search-pages-jabe17 (PR #1760) | ce880f23f7ae5cbf9bc28a8a87f1de6585a4343e | home-mode seed navigation context, its contract test, and three outstanding-issues rows | handoff: PR #1760 opened; carries focus/scope context through the cold-/ replaceState, repoints the contract test at behaviour, records #285/#286 and a third #255 reproduction | lint clean; tsc --noEmit clean; unit 5710 passed/1 pre-existing pr-handoff-stop failure (#286); maintainability budgets passed; check:outstanding-issues 284 rows unique; format committed; UI delegated to CI (mismatched Chromium, #255) | | 2026-08-08 | cursor/safety-snapshot-mobile-4ab3 | 63be5e932dc0410f172375edf779190c6a1aadae | differentials Safety Snapshot mobile density redesign | ship; phone visual PASS at ~400px (compact labels, equal 3-col metrics, no redundant summary); unit 21/21; verify:pr-local tests+fixtures+format PASS; build PASS with ALLOW_BUILD_WITH_DEV_SERVER=1 | test:differential-detail,verify:pr-local(partial-build-retry),phone-visual | | 2026-08-08 | cursor/safety-snapshot-mobile-4ab3 | d7fcbc2095ae3cfbefabfad1333b85de0ca42a4b | differentials Safety Snapshot mobile density redesign | ship; tightened Watch-for wrap; phone 390 screenshot + unit 21/21 | test:differential-detail,phone-visual-390 | @@ -824,3 +825,4 @@ Records before 2026-07-28 were written by hand and had drifted: 146 lines carrie | 2026-08-07 | cursor/site-testing-speed-08c1 | 91bac89827ae2f4f0e59aeed7de6344fe8779a95 | PR #1686 Autopilot+Bugbot review-and-fix: conflicts, threads, Static PR checks, CI/testing selection | fixed: merged origin/main (outstanding-issues #167/#255 archive + #256 keep); removed unused pathToFileURL; added ui-forms-section-nav to PR UI shards (21 specs); no unresolved threads; Bugbot unavailable (usage limit). Local: eslint file max-warnings0, vitest 36/36 focused, shard --validate OK, check:outstanding-issues OK. verify:cheap/pr-local blocked by foreign worktree heavy lock (PID 26228). | eslint scripts/playwright-pr-shards.mjs --max-warnings 0; vitest 36 passed; playwright-pr-shards --validate 21; check:outstanding-issues; verify:cheap/pr-local lock-blocked | | 2026-08-08 | cursor/more-modes-popup-2f4b | 04e6a80653c3ccf103577f6c3886b162498621ed | sidebar more-modes sheet popup | pass | focused-pw tablet rail; test:focused ClinicalSidebar; favourites+therapy wiring; verify:pr-local stages+build+rag-fixtures | | 2026-08-08 | cursor/more-modes-popup-2f4b | bea4b0c09b74368cf6d63e944bac9c1eec6b0c93 | sidebar more-modes sheet popup | pass | focused-pw tablet rail; test:focused ClinicalSidebar; favourites+therapy wiring; verify:pr-local stages+build+rag-fixtures | +| 2026-08-09 | claude/document-viewer-optimization-tu8tnj | 5a0d6be02bc92fa2615d2141b338ec8f7c1143b1 | docs: document-viewer Phase 3 handover brief (PR #1765) | Supersedes the earlier row, whose 'all ten gates completed' wording could read as all executable checks having run. Correct scope: verify:pr-local ran the ten gates APPLICABLE to docs-only changes (check:runtime, check:installed-lock-parity, format:changed, sitemap:check, docs:check-index, docs:check-inventory, docs:check-scripts, docs:check-links, check:branch-review-ledger, check:outstanding-issues); the risk router SKIPPED lint, typecheck, the full unit suite, RAG fixture validation, and build as recognised low-risk documentation scope. Also records the merge resolution: duplicate #286 (main's in-page-nav series vs this branch's authorizationHeader row) resolved by renumbering the branch row to #289, next-id 290, after the auto-merge silently dropped that detail row rather than conflicting. Review findings addressed: governance preflight now required by behaviour per AGENTS.md:257 rather than inferred from pr-policy path classification; API-route scope contradiction resolved; signed-URL warning corrected to state both identity bugs are already fixed on main with regression coverage. | verify:pr-local ten docs-scope gates passed, none failed; check:outstanding-issues 287 rows unique ids next-id=290 no ids deleted; ledger:dedupe 771 unique rows; git merge-tree vs origin/main exit 0; viewer line refs re-verified against 50ef12e | diff --git a/docs/outstanding-issues.md b/docs/outstanding-issues.md index a0a243bda5..593ef710d6 100644 --- a/docs/outstanding-issues.md +++ b/docs/outstanding-issues.md @@ -32,7 +32,9 @@ task status, priority, order, dependencies, and completion state are canonical o ## Recommended execution queue -This queue is the ordered view of **every open ledger row**. Revalidate a row against current +This queue is the ordered, prioritised view of open ledger rows — a **curated subset**, not every +open row. The detailed tables below remain the complete record; absence from this queue means +deprioritised, never closed. Revalidate a row against current `main` before starting. Its position is not authority to call providers, spend money, change production, commit, push, open a PR, or deploy. Acuity still decides what to start first; Optional rows are deferred until their trigger. @@ -166,9 +168,10 @@ removed after current-main verification; it is not missing recommended work. | 113 | `#286` | A3 | High — in-page nav + frontend | After owner go-ahead for the information-page series | 1–2 days | Convert the six pill-rail information pages onto `InPageNavHeader`, widen Server Component–safe actions, then delete `informationPageSectionDefinitions`. **Gate:** focused DOM/contract tests + `verify:phone-chrome` for touched owners. **Stop:** do not convert DocumentViewer here; do not verify anchors by grepping `id=` alone. | | 114 | `#287` | A3 | High — in-page nav + clinical owner | After `#286`; medications needs an owner product call | 0.5–1 day design + convert | Decide medications tab model, presentations MobileTabs vs `InPageNavHeader`, and factsheets heading→id scheme; convert or record lasting exceptions. **Stop:** do not port medications mechanically. | | 115 | `#288` | Optional | High — document chrome | After `#286`/`#287`, or when declaring the series complete | 30–60 min | Confirm DocumentViewer non-adoption (already noted in `docs/search-chrome-behaviour.md`) as the final end state, or schedule a separate convergence PR that leaves pinned `--document-*` CSS names untouched. | +| 116 | `#289` | A2 | High — auth/identity | Next auth module touch | 1–2 hours | Export a named helper (e.g. `authorizationIdentity(headers)`) from the auth module and use it at every property-access call site; consider a lint rule or branded type so `.Authorization` stops type-checking at all. **Stop:** do not change `authorizationHeadersForAccessToken` to emit uppercase — lowercase is the correct Fetch/Headers convention and callers that pass the object wholesale to `fetch` depend on it. | - + ## Open items > **Merged-main canary update (2026-07-23, run `30018289898`):** the new structured report correctly recorded evaluated tree `c24f2e8f2d30d0c59fc1eba025d3dcd63478137e`, run/attempt identity and `cross-region-runner` latency context. Golden retrieval remained 36/36 with document/content recall 1.0 and no failed cases. The 44-case answer gate had grounded-supported and unsupported-correct rates of 1.0, but failed because `neuroleptic-side-effect-escalation` again returned one citation where two are required (citation-failure rate 0.0227). `admission-discharge-comparison` again omitted the specific AKG admission document after `comparison_source_extractive_fallback`; `admission-discharge-coverage-paraphrase` was advisory-only at 24,870 ms. Answer cost was reported as `$0.234736`. Do not retry immediately: retain this as the first structured datapoint, compare it with the scheduled 2026-07-26 report, and keep retrieval/ranking unchanged. @@ -318,7 +321,7 @@ removed after current-main verification; it is not missing recommended work. | #275 | P2 | task | The shared filter trigger carries arbitrary spacing values inherited from DocumentFilterTrigger | **Outcome:** the phone filter trigger expresses its measurements as named tokens rather than bracketed values. **Detail:** `result-filter-control.tsx`'s `ResultFilterTrigger` uses `pr-[0.6875rem]`, `h-[1.0625rem]`/`min-w-[1.0625rem]` for the badge, and the raw breakpoint window `min-[414px]:max-[429px]` for the label. CodeRabbit flagged these against the design-token rule in PR #1706. Every one of them is copied *verbatim* from `DocumentFilterTrigger`, which shipped on main earlier and is the component this one was deliberately lifted from so the two cannot drift — so the finding is real but its scope is both call sites, not the new one. Changing only the copy would reintroduce exactly the drift the extraction removed, and each value carries a measured justification in its own comment (the asymmetric padding answers a stroked glyph against a filled pill; the breakpoint window is the one band that is single-line and short of width). **Next:** tokenise in `@theme` once, then update the trigger — there is now only one implementation, so it is a single edit. Confirm the badge and padding render identically at 393/402/414/430px before and after. **Stop:** do not tokenise the trigger without also retiring the values from the documents original, and do not treat this as licence to change the measurements themselves. | CodeRabbit review on PR #1706; DocumentFilterTrigger on main | 2026-08-07 | | #277 | P2 | issue | docs/design-system/HANDOVER-2026-08-07.md is cited as provenance by nine ledger rows but is measurably wrong | Outcome: no session scopes design-system work from a document whose figures have already been disproved. Evidence: rows #261, #262, #264, #265, #266, #267, #268, #269 and #270 all carry 'session 2026-08-07 — design-system HANDOVER-2026-08-07 Track A1 handoff (PR #1678)' as their Source, and docs/design-system/README.md links it as 'measured state, the ordered plan'. Measured wrong so far, all corrected into the rows themselves rather than the document: its '229 --shadow-tight aliases' is the seven-token legacyShadowAliases total mislabelled as one token (real figure 100 sites across 55 files, total 228); its adoption figure was 24 unadopted against a measured 23; its claim that visual baselines cannot be generated on Windows is half true and led to the wrong conclusion, since the ubuntu CI job already produces the ones that count; and #270's '22 call sites pair a tap token with a dead numeric height' does not survive re-measurement at all (zero same-variant pairs, 84 cross-variant responsive step-downs that are not dead). The document itself still asserts the originals. Next: cheapest fix is a superseded banner at the top naming the ledger rows as the current source of truth, plus the same in docs/design-system/README.md's link text — not a rewrite, because the corrections already live in the rows and duplicating them re-creates the drift. If the live path should leave docs/design-system/, move the file to docs/archive/ (or the design-system archive) and update inbound links per docs/README.md; do not delete it, because the nine Source citations, the PR/commit record, and the handover's verification/gotcha sections are provenance the ledger is meant to preserve. Stop: do not re-copy its figures into any new plan or handover, do not delete the evidence, and do not silently correct it in place, which would leave the nine Source citations pointing at a document that no longer says what those rows were derived from. | session 2026-08-08 — measured while closing #263 follow-ups across PRs #1719 and #1720 | 2026-08-08 | | #278 | P3 | issue | The document-viewer visual baseline bakes in viewport-pinned chrome that overlaps content | Measured 2026-08-08 while adopting the baselines (#118 / PR #1729). The document-viewer target clips #main-content, which is 1196x2903 against a 900px viewport, and contains viewport-pinned chrome: the sm:sticky sm:top-0 document header (DocumentViewer.tsx:1028) and the sm:fixed search composer (DocumentViewer.tsx:1511). Playwright stitches an oversized element clip, so both composite partway down the image and OVERLAP the content behind them — the cited-excerpt card and a source passage are partly covered in the committed golden. Position tracks total content height, so any content-height change above them moves the pinned chrome and inflates the diff well beyond what actually changed. NOT a product bug and NOT a #1705 regression: the pre-#1705 candidate from run 31249978408 shows the same overlap, so it is inherent to the target's design. The capture is deterministic, so the comparison still means something — five of six candidates were byte-identical by SHA-256 across two independent CI runs. Next: narrow that target's clip to a smaller locator, or add the pinned chrome to the target's mask array (the spec already supports mask, with a comment warning a mask is a hole in the gate). Stop: do not fix this by capturing fullPage — the spec bans it because ledger #093 leaves a hidden duplicate page root under CI load. | session 2026-08-08 — visual baseline adoption, #118 | 2026-08-08 | -| #279 | P2 | issue | pdf.js 6 cannot raster in this container's Chromium, so no browser gate covers the viewer canvas | **Outcome:** viewer canvas behaviour is provable by a gate rather than only by unit test and device. **Detail:** the document route renders 'this[#methodPromises].getOrInsertComputed is not a function' instead of a page in Chromium 141.0.7390.37 at /opt/pw-browsers — pdfjs-dist 6.2.108 calls a Map builtin that shipped after 141. Reproduced identically on bc33d41 and on the viewer-optimization branch, so it is the environment, not a regression. Consequence: every Playwright assertion that depends on a painted canvas is unprovable here, which covers the canvas pixel budget and the fit-mode pinch gesture landed in this branch, and any future 'verify:ui' viewer journey run in this container or a like-configured cloud session. **Next:** confirm whether CI's Chromium is newer than 141 (if so this is container-only and should be recorded as such); otherwise either bump the pinned Playwright browser build or pin pdfjs-dist to a release whose baseline the gate's browser meets. **Stop:** do not weaken a viewer assertion to make it pass in this container. | session 2026-08-08 document-viewer optimisation; /opt/pw-browsers/chromium-1194 = Chromium 141.0.7390.37 | 2026-08-08 | +| #279 | P2 | issue | pdf.js 6 cannot raster in this container's Chromium, so no browser gate covers the viewer canvas | **Outcome:** viewer canvas behaviour is provable by a gate rather than only by unit test and device. **CORRECTED 2026-08-09 (PR #1765) — the original remedies were wrong; do not action them.** Measured: pinned playwright@1.62.1 expects Chromium 151.0.7922.34 (playwright-core/browsers.json rev 1234); this container ships 141.0.7390.37 at /opt/pw-browsers/chromium-1194; CI runs HeadlessChrome/151.0.0.0 (recorded in lighthouse-budget.json:27). pdfjs-dist@6.2.108 calls Map.prototype.getOrInsertComputed (pdf.mjs:2454, 6889, 6896), which ships in Chromium 151 and not 141. So 'this[#methodPromises].getOrInsertComputed is not a function' is CONTAINER-ONLY: CI's browser already runs pdf.js 6 correctly. Do NOT bump the pinned Playwright build and do NOT pin pdfjs-dist down — the container's pre-installed browser is simply older than its own pinned Playwright expects, and PLAYWRIGHT_BROWSERS_PATH=/opt/pw-browsers pins it there. This environment also forbids running 'playwright install'. **Next:** write the viewer-canvas Playwright journey (non-blank canvas pixels, page count, page-flip changes the raster), let it skip-with-reason locally and prove in CI; this is Task 0 of docs/plans/document-viewer-phase3-handover.md. **Stop:** do not weaken a viewer assertion to make it pass in this container. | session 2026-08-09 Phase 3 handover, PR #1765; playwright-core/browsers.json rev 1234; lighthouse-budget.json:27 | 2026-08-08 | | #280 | P2 | task | Physical iPhone acceptance is owed for the viewer pinch gesture and the canvas pixel budget | **Outcome:** the two phone-only viewer fixes are confirmed on the device class they were written for. **Detail:** the viewer-optimisation branch revives pinch-to-zoom in fit mode (it was gated off in the default state, so a pinch reached neither the viewer nor the browser) and adds a canvas pixel budget so WebKit stops blanking the page above roughly 2.3x zoom on a dpr-3 display. Neither is verifiable in this container (see the Chromium/pdf.js row) and neither is a Chromium behaviour anyway — the canvas ceiling is a WebKit limit and the touch-action contention is a Safari gesture question. **Next:** on a real iPhone, in Safari and in the installed PWA: pinch a freshly opened document and confirm it zooms without first tapping a control; zoom to maximum and confirm the page stays painted rather than going blank; confirm a pinch that drifts vertically is not cancelled mid-gesture by the holder's 'touch-action: pan-y' (the mitigation if it is, is switching touch-action to none while two pointers are down — the gesture hook already tracks pointer count and exposes 'pinching'). Record the result against docs/phone-chrome-physical-acceptance.md. **Stop:** do not re-gate pinch on '!fitWidth' to resolve a gesture-contention finding — that restores the original defect. | session 2026-08-08 document-viewer optimisation; docs/design-system/COMPONENTS.md phone clause | 2026-08-08 | | #281 | P2 | rec | The phone document route renders two clinical-summary surfaces and neither is canonical | **Outcome:** one clinical summary on the document route, chosen deliberately. **Detail:** a phone reader gets the gradient 'High-yield clinical summary' card (DocumentClinicalSummary, built by buildDocumentClinicalSummaryModel) and, further down, the rail's '#source-summary' / 'high-yield-summary' disclosure (DocumentSectionSummary + FormattedHighYieldSummary + BadgeCluster). They render the same document.summary row two different ways. The rail is not hidden on phones — only its DocumentSectionIndexCard is lg:block — so both appear. Only the rail panel carries the section anchor, so the more prominent card is the unnavigable one. Note the two disagree about emptiness as well: the card now renders nothing when the model yields no usable text, while the rail panel still renders for its label badges, which is why 'hasStoredSummary' was deliberately left keyed to the stored row rather than to card content. **Next:** decide which rendering is canonical — this is a clinical-content judgement about how a summary should read, not a layout fix — then delete the other and give the survivor the 'source-summary' anchor. If the rail's badges are the part worth keeping, they can move without the second summary body. **Stop:** do not merge the two renderings mechanically; they format clinical text differently and the difference is the decision. | session 2026-08-08 document-viewer optimisation; document-rail-panels.tsx; document-clinical-summary.tsx | 2026-08-08 | | #282 | P3 | task | Probe the corpus for JBIG2/JPX before deciding whether pdf.js needs its decoder assets shipped | **Outcome:** a measured decision about pdf.js's cMap/standard-font/WASM assets rather than an assumption either way. **Detail:** getDocument is configured with url plus the on-demand fetch flags and nothing else, so 'wasmUrl', 'standardFontDataUrl', 'cMapUrl' and 'iccUrl' are all unset. pdfjs-dist ships those assets (wasm 1.5 MB, standard_fonts 804 KB, cmaps 1.7 MB) and nothing copies them into public/. With wasmUrl null, 'useWorkerFetch' resolves false and the WASM image decoders cannot load, so JBIG2 and JPEG2000 images fall back to the JS decoders or fail; those are exactly the encodings a scanned guideline uses, and this repo runs an OCR pipeline, which implies scanned sources exist. Non-embedded standard-14 fonts fall back to system fonts, which is a fidelity risk on a clinical document rather than a failure. **Next:** sample the real corpus for JBIG2/JPX-encoded images and for PDFs relying on the standard 14 before shipping ~2 MB of static assets; if the corpus does use them, copy into public/pdfjs, set the URLs, and add immutable cache headers in next.config.ts (public/ is not counted by check:bundle-budget, so there is no budget risk — the cost is bytes over the wire on first use). **Stop:** do not ship the assets on the assumption alone. | session 2026-08-08 document-viewer optimisation; node_modules/pdfjs-dist/types/src/display/api.d.ts | 2026-08-08 | @@ -328,6 +331,7 @@ removed after current-main verification; it is not missing recommended work. | #286 | P2 | task | PR 2 of the in-page nav series - convert the six pill-rail information pages onto InPageNavHeader | **Outcome:** the six routes still drawing the shell-owned pill rail use the documented default in-page navigation template, and the rail behind them is deleted. **Detail:** PR 1 landed as 2806d5e (#1740), extracting InPageNavHeader plus PageSection/toDocumentSections and usePageSectionWeights into src/components/in-page-nav/, and converting differential-detail-page.tsx as proof. Remaining routes: /services/[slug], /forms/[slug], /specifiers/[slug] (record and reference), /formulation/[slug], /dsm/diagnoses/[slug], /dsm/diagnoses/[slug]/differentials. Settled with the owner: replace the rail at every width, drop the InformationPageBreadcrumbs row but keep the large in-body h1, move each record's actions into the ellipsis sheet. **Next:** FIRST widen InPageNavHeader actions from the render prop (close) => ReactNode to ReactNode or ((close) => ReactNode) and close both sheets on pathname change - four of the seven components in scope are Server Components (specifier-record-page, specifier-reference-page, formulation-mechanism-page, dsm-diagnosis-page carry no use client) and React refuses to pass a function across that boundary, so all four fail to build against the current signature. Then add use-resolved-page-sections and use-in-page-section-nav, generalise useDocumentChromeMetrics for an --inpage-anchor-offset, add scroll-mt to every anchor (information-page sections carry none today), convert each page, then delete informationPageSectionDefinitions and the section kind in secondary-navigation.tsx. Two DSM routes declare anchors nothing renders - see #256. Full brief: artifact 77de9f5b-d195-409d-8156-2e4b41cd2f45. **Stop:** do not convert DocumentViewer in this PR (its chrome-metric property names are contract-pinned by tests/header-scroll-hide-contract.test.ts:110-113), and do not verify anchors by grepping for id= - assert against the rendered DOM per route. | session 2026-08-08; PR #1740 (2806d5e) | 2026-08-08 | | #287 | P2 | task | PR 3 of the in-page nav series - the three locally-owned routes each need a decision, not just a conversion | **Outcome:** every information page uses the documented in-page navigation template, or has a recorded reason not to. **Detail:** the last three routes each own a different bespoke pattern, and none is a mechanical port. (1) /medications/[slug] - SectionTabs at medication-record-page.tsx:183 SWAPS CONTENT rather than scrolling: sectionsByTab[activeTab] at :391 filters record.sections by type, so a different set mounts per tab. The InPageNavHeader track is scroll-spy over anchors that all exist at once, so adopting it means either driving tab state from the track (the track stops meaning where am I on the page) or flattening to one scrolling page - a real behaviour change to a clinical record, and a product call. (2) /differentials/presentations/[slug] - MobileTabs at differential-presentation-workflow-page.tsx plus the xl review sidebar; the old `differentialPresentationSections` shell set is gone and the route is locally owned (`page-secondary-navigation.tsx`). Remaining work is the product decision to adopt `InPageNavHeader` (or keep the tab/sidebar model with a recorded reason), not resurrecting deleted section targetIds. (3) /factsheets/[slug] - the On this page list at factsheet-detail-page.tsx:365-371 is li text with no link, button or handler, and the sections themselves carry no ids at all (:214, :267, :313, :447, :453, :471); the tail is data-driven via factsheet.sections.map keyed on section.heading (:538), so anchor ids must be generated deterministically from headings and that generator becomes the contract the section list depends on. Therapy Compass is deliberately excluded from the whole series - ModeNav is a different multi-route pattern. **Next:** decide the medications tab model first (owner decision, blocks planning); decide whether presentations keep MobileTabs/sidebar or adopt InPageNavHeader; choose the factsheets heading-to-id scheme. Then convert. **Stop:** do not port medications mechanically - swapping the tablist for a scroll track silently changes what a clinician sees on a medication record. | session 2026-08-08; follows #286 | 2026-08-08 | | #288 | P3 | rec | Decide whether DocumentViewer adopts the template it was extracted from, or the partial adoption is recorded as final | **Outcome:** the in-page navigation template has one deliberate owner story rather than an unexplained gap. **Detail:** PR 1 (2806d5e, #1740) extracted the header from DocumentViewer.tsx and differential-detail-page.tsx, which held it near-verbatim twice, into src/components/in-page-nav/InPageNavHeader. differential-detail-page was converted onto it; DocumentViewer was deliberately NOT, because its own useDocumentSectionSpy and useDocumentChromeMetrics wiring and its CSS custom-property names (--document-anchor-offset, --document-sticky-header-height, [data-document-sticky-header]) are pinned verbatim by tests/header-scroll-hide-contract.test.ts:110-113. Once #286 and #287 land, the template is adopted on every information page EXCEPT DocumentViewer. `docs/search-chrome-behaviour.md` (Default in-page navigation template) already records that DocumentViewer keeps its own header copy because it owns the page h1, uses edge-glass-header, and is pinned by visual baselines — so the gap is documented, not overlooked. #286 generalises chrome metrics for information pages only; it does not close DocumentViewer convergence. **Next:** owner decision only — convert DocumentViewer later (leaving pinned `--document-*` property names untouched per tests/header-scroll-hide-contract.test.ts:110-113), or explicitly mark the documented non-adoption as the final end state in this ledger when the series closes. **Stop:** do not rename or repoint the pinned document CSS custom properties to unify them with the information-page ones - the contract test pins those exact strings and the document route is the highest-traffic surface in the app. | session 2026-08-08; PR #1740 | 2026-08-08 | +| #289 | P2 | issue | authorizationHeader is lowercase, and reading .Authorization off it fails silently | **Outcome:** nobody keys identity off `authorizationHeader` by property again without hitting a gate or a comment first. **Detail:** `authorizationHeadersForAccessToken` returns `{ authorization: 'Bearer …' }` — lowercase, per the Fetch/Headers convention (`src/lib/supabase/client.tsx:82`). The value is typed `Record`, so reading `.Authorization` type-checks, returns undefined, and degrades to whatever fallback the caller wrote. On PR #1741 the same mistake was made twice in one session and both were identity-scoping code: the in-flight signed-URL dedupe key in `use-signed-image-url.ts` collapsed every user onto `endpoint+''`, so an account switch with a request in flight could hand user B user A's signed URL; and `detailRequestSignature` in `DocumentViewer.tsx` omitted the token it documented as being present (weaker in practice — `authStatus`/`initialDetailIdentityStale` and the render-time identity reset still moved on a real switch — but the stated defence was not the shipped one). Review caught both before merge and each site now reads `headers.authorization ?? headers.Authorization ?? ''`. Merged main has no other property reads: every remaining caller passes the header object wholesale to `fetch`, where casing is irrelevant. **Next:** cheapest first — export a named helper (e.g. `authorizationIdentity(headers)`) from the auth module and use it at both sites so there is one definition, then consider a lint rule or a narrower type (a branded `AuthorizationHeader` with a lowercase-only key) so `.Authorization` stops type-checking at all. **Stop:** do not 'fix' this by emitting uppercase from `authorizationHeadersForAccessToken` — lowercase is the correct convention and callers pass the object to `fetch`. | PR #1741 review (Codex signed-URL/cache finding); src/lib/supabase/client.tsx:82; session 2026-08-08 | 2026-08-08 | ## Resolved / archive diff --git a/docs/plans/document-viewer-phase3-handover.md b/docs/plans/document-viewer-phase3-handover.md new file mode 100644 index 0000000000..ac6fe1335f --- /dev/null +++ b/docs/plans/document-viewer-phase3-handover.md @@ -0,0 +1,204 @@ +# Document viewer — Phase 3 handover + +Execution brief for Phase 3 of `docs/plans/document-viewer-redesign-plan.md`. Phases 0–2 merged as +PR #1741 (squash `42f87ca`); Phase 3 was never started. The viewer still rasters exactly one page at a +time, so every page flip on a long guideline is a cold render — that is the remaining felt slowness. + +**Scope:** every Phase 3 capability **except crop → page overlay**. Crop overlay is deliberately out — +`bbox` is SELECTed at `src/lib/document-detail.ts:441` but absent from `DocumentDetailImage` in +`src/lib/document-detail-contract.ts`, so it needs contract plumbing through `src/lib/**document**`, +which is a wider contract change than this phase should carry. + +Most of the work lands in `src/components/document-viewer/**`. **One deliberate exception:** Task 3 may +wire `src/app/api/images/signed-urls/route.ts`, which matches `clinicalRiskPatterns` in +`scripts/pr-policy.mjs` (`/^src\/app\/api\//`). If you touch that route, `pr-policy` will hard-block the +merge without a complete `## Clinical Governance Preflight` — but complete it either way. See +"Governance" below: the preflight is required by behaviour, not by which paths the classifier happens to +match. + +**Already done:** toolbar density shipped in Phase 2 (`document-frame.tsx:404`, `hidden sm:inline` plus +an `sm:hidden` overflow menu). Strike it from the plan's table. + +All line references below were verified against `main` at `50ef12e`. + +--- + +## Task 0 — establish the canvas gate first (prerequisite) + +Ledger `#279` says the viewer canvas cannot be gated in a browser, and proposes either bumping the +pinned Playwright build or pinning `pdfjs-dist` down. **That diagnosis is wrong and both remedies would +be wasted dependency surgery.** Confirm and correct it before writing any feature code: + +```bash +node -e "const b=require('$PWD/node_modules/playwright-core/browsers.json'); \ + b.browsers.filter(x=>x.name==='chromium').forEach(x=>console.log(x.revision, x.browserVersion))" +/opt/pw-browsers/chromium-*/chrome-linux/chrome --version +``` + +Measured 2026-08-09: + +| | value | +| ---------------------------------------------------------------------- | ---------------------------- | +| Container Chromium (`/opt/pw-browsers/chromium-1194`) | 141.0.7390.37 | +| Chromium pinned `playwright@1.62.1` expects (`browsers.json` rev 1234) | **151.0.7922.34** | +| Chromium CI actually runs (`lighthouse-budget.json:27`) | **HeadlessChrome/151.0.0.0** | +| `pdfjs-dist@6.2.108` calls `Map.prototype.getOrInsertComputed` | `pdf.mjs:2454, 6889, 6896` | + +`getOrInsertComputed` ships in Chromium 151 and not in 141, so the raster failure is +**container-only** — CI's browser already runs pdf.js 6 fine. The container's pre-installed browser is +simply older than its own pinned Playwright wants, and `PLAYWRIGHT_BROWSERS_PATH=/opt/pw-browsers` pins +it there. Do not bump Playwright, do not pin `pdfjs-dist` down, and do not run `playwright install` +(this environment forbids it). + +Write a Playwright viewer-canvas journey asserting a page actually paints: non-blank canvas pixels, +correct page count, page-flip changes the raster. Expect it to fail locally with +`getOrInsertComputed is not a function` and pass in CI. Guard it so the local failure is an explicit +skip-with-reason, never a silent green — `docs/testing.md` flake policy applies. + +`#279` lives in `docs/outstanding-issues.md`, so close it with `npm run issues:done -- '#279'` (or +`issues:update` if the gate is only partly built) — **not** `ledger:append --supersede`, which appends to +the separate branch-review ledger and would leave the durable row untouched. Its refuted remedy has +already been struck from the row; record the gate you built as the resolution. + +Everything below is proven by that gate in CI plus focused unit tests locally. + +## Task 1 — multi-page virtualization (the core item) + +`src/components/document-viewer/pdf-canvas-viewer.tsx` (524 lines) renders one page into one ``. +Move to a windowed list: render near pages, dispose far canvases, keep page ↔ URL sync intact. + +Four constraints that will bite, all load-bearing: + +1. **The raster budget becomes document-wide.** `resolveCanvasRasterPlan` (`canvas-raster-budget.ts`) + bounds _one_ canvas to 2^24 device pixels because WebKit paints nothing above it. With N live + canvases, N individually-legal pages can still exhaust device memory. Add a document-wide live-pixel + budget capping how many rendered canvases are retained. Do not raise `MAX_CANVAS_PIXELS`. +2. **Render-ahead fights `disableAutoFetch`.** `getDocument({ disableAutoFetch: true, disableStream: +true })` at `:189` was chosen precisely because a reader looks at one page — it stops pdf.js pulling + a whole guideline over cellular. Pre-rendering neighbours re-introduces exactly that fetch + amplification. Resolve it deliberately: ±1 page, on idle, and state the trade in the PR body. Do not + silently drop `disableAutoFetch`. +3. **Page-sync feedback loop.** The effect at `:216-229` already does rAF → clamp → reconcile the parent + route via `onPageChangeRef`. If "current page" becomes a scroll derivation, that effect can fight the + scroll position. Derive the active page from scroll, but let only user intent write the URL. +4. **Keep the `memo` boundary.** `PdfCanvasViewer` is memoised (`:53`, rationale at `:45-52`) so a + keystroke in the composer never re-rasters. Per-page state must not lift into the parent and defeat + that. + +Preserve: the per-run `pageToCleanup` isolation (Sentry 15801413), the canvas zeroing on unmount +(`:337-345`), the `renderZoom` debounce with its interim CSS transform, and the `isLikelyExpiredUrl` → +`reportUrlExpired` recovery path — which must still work when a range request for a _neighbour_ page is +the thing that 403s. + +## Task 2 — rail virtualization + +`document-rail-panels.tsx:223` (`id="source-images"`) maps `clinicalImages` and `auditImages` into +`DocumentImage` rows. `auditImages` sit inside a collapsed `
` but are still in the DOM and +still mint signed URLs. Virtualize the long list and stop off-screen rows resolving URLs. + +## Task 3 — signed-URL and decode priority + +Above-fold evidence should resolve and decode before the below-fold rail. Build on the in-flight dedupe +already in `use-signed-image-url.ts` — **read the warning below before touching that file.** +`src/app/api/images/signed-urls/route.ts` batches up to 100 ids and has no caller (ledger `#283`). +Wiring it is permitted if the rail mounts several distinct images at once, but treat it as a deliberate +scope exception, not a free extension: it is a privileged owner-scoped endpoint, it matches +`clinicalRiskPatterns`, and touching it makes the `## Clinical Governance Preflight` a hard merge gate +rather than a discipline requirement. Prefer deferring it to its own PR unless the batching win is +measured. If you do wire it, keep the per-image endpoint for the lightbox retry path. + +## Task 4 — keyboard reading mode + +`handleHolderKeyDown` (`:410-441`) already handles ArrowLeft/Right, `+`/`=`, `-`, and `0`. Phase 3 adds +PageUp/PageDown, `f` (fit), and `r` (rotate). `rotation` is an inbound prop with **no** +`onRotationChange` callback — `r` needs a new prop threaded from `DocumentFrame`. Document the bindings +and test them. + +## Task 5 — OffscreenCanvas: measure, then decide + +The plan conditions this on "measured main-thread paint cost." Measure first and report the number. If +virtualization already lands the win, say so and skip it — do not implement it on principle. + +--- + +## Verification + +```bash +npm run test:focused -- --files \ + tests/use-viewer-gestures.dom.test.tsx,tests/document-viewer-shell.dom.test.tsx,\ +tests/document-viewer-pdf-reader-lazy.test.ts,tests/document-frame-contract.test.ts,\ +tests/document-detail-performance.test.ts,tests/client-performance-boundaries.test.ts + +npm run ensure # before any browser work; never assume a port +npm run verify:phone-chrome -- --dry-run +npm run format # AND COMMIT IT — not in verify:cheap, blocks CI +npm run verify:pr-local +``` + +Two gates will move and must not be silenced: + +- **`check:bundle-budget`** totals _every_ built chunk against 1,440,201 gzip bytes at 10% tolerance + (`bundle-budget.json`). A virtualization dependency would land straight on it — prefer none. +- **The `document-viewer` visual golden will shift.** Per ledger `#278` that target composites + viewport-pinned chrome over content, and its position tracks total content height, so any + content-height change inflates the diff. Expect it; fix it by narrowing the clip or masking the + pinned chrome. `#278` records that capturing `fullPage` is banned (ledger `#093`). + +## Do not + +- Do not weaken a viewer assertion to make it pass in this container. +- Do not re-gate pinch on `!fitWidth` (ledger `#280` — that restores the original defect). +- Do not touch `src/lib/rag/**` or any ranking surface; nothing here should. +- Do not run provider-backed gates (`verify:release`, `eval:*`, `check:supabase-project`) without asking. + +## Read this before editing `use-signed-image-url.ts` + +**Both bugs described here are already fixed on `main`. Do not reintroduce them.** + +The Phase 0–2 pass shipped two identity bugs in that file, both caught in review before merge. +`authorizationHeadersForAccessToken` emits **lowercase** `authorization` +(`src/lib/supabase/client.tsx:82`), but the dedupe key read `headers.Authorization` — so the token was +never in the key, every identity collapsed onto the endpoint alone (the key was the literal endpoint +followed by a trailing space), and an account switch with a request in flight could hand user B user A's +signed URL. The second: the module LRU was written from inside the shared promise, so a superseded +response could refill a cleared cache after an identity change. + +The shipped state on `main` is the correct one: `authorizationIdentity(headers)` reads +`headers.authorization ?? headers.Authorization`, the key joins endpoint and identity with a NUL +separator so neither field can bleed into the other, the cache write happens in the active consumer +after its identity check, and `tests/auth-signed-url-cache.dom.test.tsx` carries the regression +coverage. + +**Required before any Task 3 change to this file:** run that test file first and confirm it is green, and +keep it green afterwards. If you restructure the dedupe or cache path, the identity must remain in the +key and the cache write must stay outside the shared promise. `authorizationHeader` is a +`Record`, so reading the wrong casing fails silently — never key identity off a property +access without going through the helper. Ledger `#289` tracks exporting that helper repo-wide so the +mistake stops being available. + +## Handoff + +Stage as separate commits per task so any one stays independently revertible while the PR is open. + +### Governance + +**Complete the `## Clinical Governance Preflight` from `.github/pull_request_template.md`.** Phase 3 +changes source rendering (virtualization changes how a clinical source page is displayed, and a bug +shows the reader the wrong page or no page) and document access (the signed-URL and decode-priority +work). `AGENTS.md:257` requires the preflight for any PR touching those behaviours — that requirement is +behavioural, not path-based. + +Do not infer an exemption from `scripts/pr-policy.mjs`. Its `clinicalRiskPatterns` deliberately does not +match `src/components/**` unless the path also mentions auth/permission/privacy/security/upload/download/ +patient, so a diff confined to `src/components/document-viewer/**` classifies `clinicalRisk: false` and +the merge gate stays quiet. That is the classifier under-approximating, not policy granting a pass — the +comment at `pr-policy.mjs:62` records PR #1489 shipping 205 therapy records (including one labelling ECT +as "ACT") past exactly this gap. If Task 3 wires `src/app/api/images/signed-urls/route.ts`, the gate does +fire and will hard-block without the preflight. + +No `RAG impact:` line is required: no protected ranking surface is in scope (`src/lib/rag/**`, +clinical-search, retrieval-selection, ranking-config, answer-ranking, the eval harness, the golden +fixture, the retrieval RPCs). Confirm the classification for your actual diff with +`npm run verify:pr-local -- --dry-run --files `. + +Capture anything deferred with `/issues capture` before the session ends.