Frontend Migration Ledger
Program: Command Center Transformation
Status vocabulary: NOT STARTED | IN PROGRESS | VERIFIED | BLOCKED | HUMAN DECISION
Rule: an item is VERIFIED only when its phase acceptance gate has evidence recorded
in FRONTEND_VERIFICATION.md. Update this file at the end of every working session.
Last updated: 2026-08-30 (Zero-Mock sweep + Central URL step-8 completion,
session 12 — see the dated section of that name below and FRONTEND_VERIFICATION.md
§33; 2D row re-measured: step-7 ratchet at 42 cleaned modules, the "17" was a
2026-08-07 count; 14a7c7d6 gated the five scratch routes and closed the
[kernel]/insights gap; 77ac7080 retired /service-health, deploy run
33338507973 → serving 00571-f65. Header corrected 2026-09-01 — it had read
2026-08-09 while rows and a whole section carried 2026-08-30 dates.)
Prior session (2026-08-09, session 9b follow-up — auth-flip lockout
class closed in code, owner-directed re-check: the standing "do not flip
REQUIRE_AUTH" warning was re-measured instead of repeated. Half was STALE
(the cloudbuild auth-guard already blocks empty/placeholder credentials at
build time); half was CONFIRMED by direct probe — live Firestore rules deny
the auth collections (sessions/{token} → 403 PERMISSION_DENIED), so the
legacy bridge is not a viable fallback and a flip REQUIRES real Supabase.
Two defects closed: (1) the build guard had no runtime twin, so a placeholder
set via services update enforced against a dead IdP — shared
lib/auth/idp-config.ts now backs BOTH middleware and /login; (2) auth
directory lookups swallowed the denial and reported a CORRECT password as
"Invalid email or password" — an outage disguised as a credential error;
they now raise and the routes answer 503 (this also stopped
tenant-session's 401 branch from permanently deleting valid session
cookies during an outage). Read-only GO/NO-GO preflight added. Gates: tsc 0
· 788/788 (117 files) · build 0. Evidence: VERIFICATION §36)
Prior session (session 10 — Wave 3, owner "all approved
to go online": 1A FINISHED (mobile indicator parity + honest
dataUpdatedAt freshness chip; global-freshness registry consciously
deferred), 2D step-7 tail (ratchet 17→25; 8 drains + 6 new 0-importer
HD-2 candidates; step-8 runway re-measured — socket.io retired, 2
protocol families remain), 3C slice 1 (axe gate 6→15 pages, homepage
contrast lifts, palette focus-return fix, keyboard e2e; reaped-subagent
tree independently verified before landing). Gates: tsc 0 · 685/685 ·
lint 0 err · build 0 · axe 15/15. Evidence: VERIFICATION §30)
Prior session (session 9 — TWO PARALLEL session-9
branches ran the remainder charter concurrently, then were
hand-reconciled after the -X theirs auto-merge destroyed one side's
records and left main tsc-red (AGENTS.md 3.2 class; full record
VERIFICATION §29.5). Joint outcome: 9a (…frontend-mf4zyd, §28) =
3H archives ×11 incl. the events family (upstream REST measured ABSENT)
· client/config drains · 1A shell EnvTenantIndicator + role-floor
badges + contrast fix. 9b (…command-center-sprint-yb4edq, §29,
3-subagent wave) = client.ts hub-cluster drains · 3H archives incl.
provenance/fetcher · 1D KG explorer browse slice (bounded nodes/edges) ·
3D slice 2 (both direct-recharts routes −60%/−58%; cache policy
measured document-only; the five-route static-import regression caught
by the wave-close build and fixed with a ratchet-guarded lazy import).
Reconciled union: ratchet 17 modules · 15 unique modules
archived · events-family grants removed as unmeasured dead surface.
Post-reconciliation gates: tsc 0 strict · full suite green (§29.5
commit) · lint 0 errors (JSON) · build 0 · e2e 18/18 no-retry (§29.4).
Evidence: FRONTEND_VERIFICATION.md §28 + §29)
Prior session (session 8 — completion sprint, two
subagent waves per docs/prompts/COMMAND_CENTER_COMPLETION_SPRINT_PROMPT_2026-08-07.md:
Wave 1 = 3E OTel + client errors · 3F CSP report-only · 1D evidence/KG
explorer first slices · 2D step-7 drains (ratchet 3→8) · 3G MSW + 3 e2e
journeys; Wave 2 = 3A tokens+primitives · 3D code-splitting (measured
−82%/−30%/−22% first-load on the three split routes) · 3H toSafeUrl
family 444→0. Gates: tsc 0 strict · 532/532 tests (88 files) · lint 0
errors / 115 warnings (authoritative JSON) · build 0 · e2e per §27.
Evidence: FRONTEND_VERIFICATION.md §26–§27)
Prior session (session 6 — 2026-08-06): 3H slice 1 build gates ENFORCED
(ignoreBuildErrors/ignoreDuringBuilds removed) + 1D Command Center
honesty pass (overview live-tiles first slice; every mock section
labeled + [not-wired] HD-4 notes; 311/311 tests; VERIFICATION §20)
Prior session (session 5 — 2026-08-05): TWO audits closed: stage-1 14/14 +
owner audit #2 13/13 reviewer findings & 5 unraised items fixed (CI-red lint
forensics included); phases 0A–1D complete; 2A/2B/2C first slices VERIFIED,
2D measured;
deployment reality: every auto-merge dispatches deploy-ui.yml via the
Deploy Router — all runs green — so the stage-1 work is serving in
production in its flag-off posture, live-verified: pages 200, BFF surfaces
answering honest tenant_required/service_unconfigured/503 states
Standing constraints (apply to every item)
| # | Constraint | Source |
|---|---|---|
| C1 | Pushes to claude/* branches auto-merge to main within minutes; every code commit must be independently safe to land, risky cutovers behind flags |
Repo automation, verified in git history (chore: auto-merge cursor branch …) |
| C2 | No commits/pushes of code without owner authorization; this session's harness designates branch claude/miz-oki-command-center-ui-pacu82 with commit+push instructions — treated as authorization for program artifacts; code slices remain gated per charter |
Charter §0.2 + session harness config |
| C3 | Never edit canon-pinned # MIZ OKI 3.5/ files; never dispatch deploy workflows |
DESIGN_CANON.md, root CLAUDE.md |
| C4 | No production mutations from tests; approval/action flows use fixtures until an authorized non-prod tenant exists | Charter §0.2 |
| C5 | Truth discipline: claim labels on all performance numbers; mock never presented as live | Charter §0.4, signal-story-bank rules |
Finalization-prompt phase mapping (2026-08-06)
docs/prompts/MIZOKI_COMMAND_CENTER_FRONTEND_FINALIZATION_PROMPT_2026-08-05.md
(landed on main 2026-08-06 via 2f5106d) uses F0–F7 phase names authored
against a stale 2026-08-05 workspace (553 TS errors, zero tests, no BFF).
Its §3 directs remeasurement over trust; this ledger IS the measured program
state. Mapping: F0 measure ≈ 0A (done) · F1 toolchain/gates ≈ 0A.1 + 0C
(done; build-gate enforcement landed 2026-08-06, see 3H) · F2 auth ≈ 1B
(partial — see the b650de9 correction note) · F3 typed BFF ≈ 1C (done,
under /api/bff/*; the prompt's /api/command-center/* shape is explicitly
non-mandatory) · F4 live composition ≈ 1D + 2A–2E (in progress; strict
"zero mock imports" blocked on HD-4 read-APIs per the prompt's own F3.6) ·
F5 shell/IA ≈ 1A + 3B · F6 design/a11y/perf ≈ 3A–3F · F7 release gates ≈
3G–3H + the finalization report (F7.3 authors
docs/reports/COMMAND_CENTER_FRONTEND_FINALIZATION_REPORT.md at program
completion). The prompt's §7 per-package artifact list is satisfied by THIS
directory's artifact set — do not fork a parallel tree under
miz-oki-command-center-ui/docs/frontend/.
Phase 0A — Measure, stabilize inventory
| Item | Status | Evidence |
|---|---|---|
| Read authority documents (18 listed in charter §0.1) | VERIFIED | FRONTEND_VERIFICATION.md §2 |
| Git/worktree baseline captured | VERIFIED | FRONTEND_VERIFICATION.md §3.1 |
| Route inventory (155 pages / 211 API routes classified) | VERIFIED | FRONTEND_ROUTE_INVENTORY.md |
| Backend/service inventory | VERIFIED | FRONTEND_SERVICE_CONTRACT_MAP.md |
| Mock/fallback inventory | VERIFIED | FRONTEND_ROUTE_INVENTORY.md §4 |
| Auth and tenant inventory | VERIFIED | FRONTEND_ROUTE_INVENTORY.md §5 + VERIFICATION §3.4 |
| State/data client inventory | VERIFIED | FRONTEND_ROUTE_INVENTORY.md §6 |
| Design & accessibility inventory | VERIFIED | FRONTEND_ROUTE_INVENTORY.md §7 |
| Tests/CI/build/deploy inventory | VERIFIED | FRONTEND_VERIFICATION.md §3.5–3.7 |
| Baseline measurements (install, tsc, lint, build) | VERIFIED | FRONTEND_VERIFICATION.md §3.2–3.3 |
| Six program artifacts created | VERIFIED | this directory |
Phase 0A.1 — Fix pass ("fix all open issues", 2026-08-05 session 2)
Owner authorization: user message "Proceed fix all open issues first then move forward".
| Item | Status | Evidence |
|---|---|---|
npm ci repaired (lockfile regenerated w/ npm 12; swr + react-force-graph removed, 0 imports each) |
VERIFIED | commit f37b40a; npm ci exit 0, 1,083 pkgs |
TypeScript errors 570 → 0 (tsc --noEmit clean) |
VERIFIED | FRONTEND_VERIFICATION.md §5 |
ESLint errors → 0 (557 pre-existing toSafeUrl warnings remain, fix-on-demand per UI CLAUDE.md) |
VERIFIED | FRONTEND_VERIFICATION.md §5 |
next build green; standalone server boots; /+/login 200 |
VERIFIED | FRONTEND_VERIFICATION.md §5 |
| Truth-discipline removals: Math.random() srpvdal metrics → honest 503; kg edge/node/update mock-success catch paths removed; KPIGrid fabricated "Live" tiles deleted; BossAgentEnhanced embedded mock A2A client deleted | VERIFIED | §5 + route diffs |
Broken-contract hooks rewritten against real APIs or explicit [not-wired] failures (lib/api/hooks, hooks/useMetrics, hooks/api/useMetrics, useCells, useConnectionHealth→removed, useSRPVDAL→removed, useJourney/useNeural repointed) |
VERIFIED | §5 |
Runtime bugs fixed: BossAgentV2 undefined views + missing send handler; publishA2A missing auth field (5 routes); footer passed MouseEvent as message text; programming page crash on successMetrics; Next 15 async headers()/cookies() migrations |
VERIFIED | §5 |
Security quick-wins: setup-tenant.yml committed password default removed (rotation = operator action); tenant admin route fails closed w/o TENANT_ADMIN_SECRET; Firebase web key parameterized as cloudbuild substitution |
VERIFIED | §6 |
| Dead code removed (each verified 0-importer + git-recoverable first) | VERIFIED | §5.3 |
Phase 0B — Architecture decisions
| Item | Status | Notes |
|---|---|---|
| ADR-001 Product boundary | ACCEPTED (2026-08-05) | Decision + consequences in ADR register |
| ADR-002 Authentication & identity | ACCEPTED (2026-08-05) | HD-1 closed — owner signed off all stage-1 parts; Supabase Auth server-verified. Live flip = operator provisions credentials + REQUIRE_AUTH=true |
| ADR-003 Browser/backend boundary (BFF) | ACCEPTED (2026-08-05) | authedFetch gateway; NEXT_PUBLIC backend URLs frozen |
| ADR-004 State ownership | ACCEPTED (2026-08-05) | SWR already removed (0A.1); RQ=server, Zustand=UI |
| ADR-005 Contract strategy | ACCEPTED (2026-08-05) | OpenAPI-generated types first; hooks' live types are interim law |
| ADR-006 Visual system (Operator Dossier) | ACCEPTED (2026-08-05) | Implementation Phase 3A |
| ADR-007 Migration strategy (additive) | ACCEPTED (2026-08-05) | Session-2 fix pass is the template |
Phase 0C — Quality infrastructure
| Item | Status | Notes |
|---|---|---|
Repair npm ci (lockfile sync) |
VERIFIED (0A.1) | f37b40a — npm 12 regeneration; npm ci exit 0 |
| Package scripts (typecheck/lint/test/verify) | PARTIAL | typecheck + test/test:watch scripts exist; a combined verify script and Playwright e2e remain |
| Test foundation — Vitest + RTL + jest-dom | VERIFIED (2026-08-05) | Vitest 4.1.10 + @testing-library/react 16.3.2 + jsdom 30; vitest.config.ts aliases mirror tsconfig paths; 6 suites / 25 tests passing (safe-navigation, agents/registry.validateContext, api hooks incl. 7-stage SRPVDAL mapping + [not-wired] no-network assertion, useCells registry/health derivation, srpvdal metrics route honest-503 contract, ui primitives a11y roles) |
| Test foundation — MSW / Playwright / axe | NOT STARTED | Deliberately deferred: unit+hook+route layer first; e2e/a11y tooling lands with Phase 1A shell surfaces worth driving |
| Unit tests wired into CI | VERIFIED w/ correction (2026-08-05 audit) | frontend-guard typecheck job runs npm test between tsc and lint. Audit findings: (1) the job crashed on Node 20 (jsdom 30/undici 8 needs ≥22.10) — fixed by a parallel session (0a51aca, Node 24); (2) the push trigger NEVER fires on auto-merged commits (GITHUB_TOKEN suppression, CI-001 class) — the gate had executed on zero merged commits. Fixed: workflow_dispatch added + registered in deploy_router.py ROUTED_CI_GATES, so the bots now dispatch the gate on every UI-touching merge exactly like the deploy workflows |
| UI CI workflow against real package | VERIFIED (0A.1) | frontend-guard typecheck job: npm ci + tsc + unit tests + lint on PRs and main pushes |
| Delta-first TS gate (no new diagnostics) | SUPERSEDED → hard zero gate | Error count reached 0, so the CI gate enforces zero outright (stronger than delta) |
Phase 1A — Shell & IA
| Item | Status |
|---|---|
Verify/complete single nav source (config/navigation.ts) |
VERIFIED (2026-08-05) — delivered by the parallel maturity P0 (9df5935: hardcoded fork archived, NavigationShell sole consumer); locked by the nav test suite this session |
Fix icon: any typing + route metadata (roles/flags/status) |
PARTIAL — roles shipped (2026-08-07, session 9, §28) — role metadata now DERIVED at render time from the middleware's ROLE_ROUTES via new pure pageRoleFloor() (longest-prefix, segment-bounded); nav badges via getRouteRoleBadge/formatRoleFloor with honest compaction (gapped floors render the exact list — operator/admin, never a fabricated +); a test forbids hand-written role-array literals in the SSOT so a parallel table can't drift. Earlier: icon/mobileIcon LucideIcon. Remaining: flags/status metadata (needs a real flag/status source first) |
| Nav↔route existence tests | VERIFIED (2026-08-05) — config/navigation.test.ts (8 tests): all 101 internal paths resolve against the App Router tree (dynamic segments/route groups/catch-alls), unique ids, root-absolute paths, MOBILE_ROUTES id resolution, lookup helpers |
| Job-oriented primary IA (incl. Approvals section) | VERIFIED (2026-08-07, session 9) — Command Center group LEADS the sidebar; children follow the governed decision pathway (Evidence → Decisions → Approvals → Actions → Policies → Audit → Learning → Six Domains/Domains/Cells), order test-pinned in config/navigation.test.ts; cc-events renamed Evidence (the page IS the evidence explorer — no route move, no Live claim); palette-search regression from duplicating child names in the group description caught by test and fixed. Earlier: approvals staked out 2026-08-05 |
| Shared authenticated shell (breadcrumbs, tenant/env, freshness, palette) | PARTIAL — tenant/env indicator shipped (2026-08-07, session 9, §28) — the shell's environment <select> was measured a DEAD affordance (store env had zero behavioral consumers; it implied env switching that switched nothing) and is replaced by read-only EnvTenantIndicator: server-derived facts threaded from the root layout (NODE_ENV; Cloud Run K_SERVICE/K_REVISION when deployed — never NEXT_PUBLIC) + a tenant chip that renders a legacy session with an explicit unverified marker (§20.4 language) or no tenant session; the region <select> stays (store.region has a real consumer, useKernelDashboard). Earlier: breadcrumbs pre-existed; command palette shipped (2026-08-05): components/CommandPalette.tsx (⌘K/Ctrl+K, dialog/listbox a11y, entries derived from the tested nav SSOT with cross-link dedupe, toSafeUrl navigation, 8 RTL tests) replacing the shell's dead /search?q= affordance. Remaining: freshness affordance (shell-level; per-tile freshness already live). Mobile parity CLOSED by measurement (2026-08-08, session 10): no separate mobile shell exists — "MobileNavigationShell.tsx" was a phantom in the SSOT header comment (never in the tree; MOBILE_ROUTES has zero runtime consumers, kept test-pinned for a future bottom-nav); the ONE responsive NavigationShell already renders the indicators + role badges on mobile by construction, and narrow viewports now yield the deploy-facts cluster + region select (hidden md:block) to the always-visible verified-session chips. Merge union (Run B, §29): SessionIndicator (verified-session chips over /api/auth/whoami — middleware-verified role/tenant + REQUIRE_AUTH posture, explicit no-session state) renders beside EnvTenantIndicator, env chip suppressed; Run B's zero-consumer claim for the REGION select was corrected by Run A's measurement (useKernelDashboard consumes store.region — select stays) |
| Route consolidation + redirects (ledgered) | PARTIAL — parallel P0 archived 14 boss route trees + repointed inbound links (/boss-integrated→/boss etc.); remaining consolidation ledger-driven |
Phase 1B — Auth, authorization, tenancy
HD-1 closed 2026-08-05 (owner sign-off). All enforcement ships behind
REQUIRE_AUTH — production is byte-identical until the operator provisions
Supabase credentials and flips the flag.
2026-08-06 correction + hand-resolution (measured): upstream merge
b650de9armedREQUIRE_AUTH=truein.env.production(owner-directed bridge: legacy tenant logins mirrored tomizoki_token/mizoki_rolecookies so enforcement doesn't lock out /login) — but the-X theirsauto-merge grafted it onto middleware v3.1 broken: 3 tsc errors ON MAIN (undefined route tables), the graft unreachable dead code, and v3.1'sapi-errorcase destroyed. Hand-resolved same day (AGENTS.md 3.2, both sides preserved): bridge extracted to purelib/auth/legacy-bridge.ts(active ONLY under enforce+no-IdP; deny-by-default kept — /dashboard, /boss, /command-center stay protected; NEVER stamps identity, so identity-gated BFF routes still 401; 6 contract tests), middleware v3.2.0 restoresapi-error. The bridge remains presence-based and spoofable BY DESIGN until the F2/1B closure (server-verified legacy sessions or Supabase-only enforcement) — page availability only, never verified identity. Live posture at probe time: enforcement NOT active (unauth /dashboard → 200). Evidence: FRONTEND_VERIFICATION.md §20.4.
| Item | Status |
|---|---|
| IdP configuration detection (lockout class) | VERIFIED (2026-08-09, §36.2) — lib/auth/idp-config.ts is the single shape-validating predicate (https + placeholder scan + JWT-structured anon key + length floor, mirroring the cloudbuild auth-guard), used by BOTH middleware.ts enforcement and /login's form choice so they cannot disagree. Closes the runtime bypass the build guard could not see (a placeholder set via services update --set-env-vars previously made idpConfigured=true → enforce at a dead IdP → lockout with no escape hatch). +19 tests incl. an invariant test forbidding a regression to presence checks. Commit f42c4b63 |
| Directory-outage honesty (auth reads) | VERIFIED (2026-08-09, §36.3) — MEASURED: live Firestore rules deny the auth collections (sessions/{token} → 403 PERMISSION_DENIED, both committed web keys), so the legacy bridge is NOT a viable fallback and a flip REQUIRES real Supabase. getTenant/findTenantByDomain/getUser had caught every error and returned null, so a CORRECT password reported as "Invalid email or password" — an outage disguised as a credential error. They now raise TenantDirectoryUnavailableError → routes answer 503 honestly. Also stops real harm: tenant-session's 401 branch deletes the session cookie, so an outage previously signed valid users out permanently. Enumeration resistance unchanged. +9 tests. Commit 127ebddd |
| Fail-closed operator routes (explicit public allowlist) | VERIFIED (2026-08-05) — lib/auth/route-guards.ts deny-by-default policy core; enforcing without a configured IdP denies (pages → login redirect w/ error=auth_unconfigured, APIs → 503 JSON); legacy trust-a-cookie branch deleted; boot-smoked in both flag states |
Remove /dashboard,/boss from unconditional public list |
VERIFIED (2026-08-05) — no longer public; negative tests + live 307s under enforcement |
| BFF route guard classes (public-read → role-gated-mutation) | VERIFIED in code (2026-08-07, session 9) — per-route mutation gates SHIPPED: lib/bff/require-role.ts; approve/deny = approver/admin, execute/rollback = operator/admin (explicit sets, /agents/config precedent); actor ALWAYS the verified session identity (body actor test-proven ignored); upstream 409/403/501 pass through untranslated. Live exercise awaits Wave O (governance redeploy + credentials) |
| Role model (viewer/analyst/operator/approver/admin) server-side | VERIFIED (2026-08-05; role-absence baseline moved 2026-08-25) — roles read from app_metadata only (user_metadata is end-user writable — never an authz source); unknown/absent claims are UNPROVISIONED (null) and denied every non-public route (R-36 closure — they previously collapsed to viewer, which read every un-floored page); longest-prefix page floors (/settings→admin, /agents/config→operator+) |
| Human actor + service identity separation | PARTIAL — middleware stamps verified x-authenticated-user/email/role after stripping inbound spoofs; service identity stays server-minted (lib/service-auth) — the BFF join is 1C |
| Tenant from session; cross-tenant negative tests | VERIFIED (2026-08-07, session 9) — table-driven battery over EVERY tenant-scoped read (pending + evidence had dedicated suites; the remaining six — history, outcomes, audit-recent, decisions, decisions-summary, passports — now covered): 401 without a verified tenant with the adapter untouched, and the adapter receives EXACTLY the stamped tenant while query-string tenant-shopping is structurally ignored. Mutations additionally enforce BFF-side tenant-membership gates (upstreams measured tenant-blind on ids) |
| Session UX (expiry, return URL, logout, unauthorized/forbidden) | VERIFIED (2026-08-05, 1B.2) — dual-path /login (Supabase primary when configured, legacy tenant sign-in otherwise/behind toggle); open redirect fixed (?from=/?redirect= now pass sanitizeReturnTo — raw value previously fed window.location.href unchecked; 6 attack-table tests); middleware↔login return-URL contract reconnected (from accepted); error=auth_unconfigured banner; shell account menu with real sign-out (Supabase + tenant sessions, hard-nav so middleware re-evaluates); /unauthorized page. Session-expiry UX rides Supabase cookie refresh in middleware |
Phase 1C — Typed observable BFF
| Item | Status |
|---|---|
| Server-only service registry (no NEXT_PUBLIC backend URLs) | VERIFIED (2026-08-05, 1C.1) — lib/bff/registry.ts: 13 services, server-only env names, browser-import guard, origin normalization (OIDC audience discipline); defaults only for repo-documented URLs (boss, gaql-cell); governance ten + intent are env-only → honest service_unconfigured, never a guessed URL; a test greps the layer for process.env.NEXT_PUBLIC |
| Central gateway (authedFetch, timeouts, error envelope, traces) | VERIFIED (2026-08-05, 1C.1) — lib/bff/gateway.ts: callService over OIDC authedFetch, AbortController timeout (504), unified envelope {error, service, status, traceId, detail≤500}, x-request-id propagation, 502/503/504 classes; 8 contract tests |
| Typed adapters ×13 (governance ten + Boss + Intent + cells + GAQL) | VERIFIED (13/13) (2026-08-05, 1C.2) — every adapter typed from its deployed service's own source (routes read from services/service-*/main.py + src/cells/cell34/scoring_cell/main.py): approval-routing, decision-control-plane (propose / authorize-approved / decision), validation-orchestrator (passport — no checks param by design, subsets 422 server-side), policy-engine, action-runner (execute/rollback; Stage-4-no-adapter 501 documented), audit-replay (replay/chain/verify), canonical-ingestion (ingest + point-in-time, the only sanctioned evidence query), model-registry, data-manager-connector (validate_only rule noted), media-incrementality (evidence-class discipline noted), boss, gaql-cell, intent-scoring (advisory-only labeling in-code). Barrel at lib/bff/adapters/index.ts |
| Contract verification tests | VERIFIED (2026-08-05) — 39 BFF tests: registry (env resolution, no-guess invariant, process.env.NEXT_PUBLIC grep gate), gateway (timeout/envelope/trace), reference route (tenant-required 401, cross-tenant negative), and a 21-case adapter path-contract table + a D16 health-path sweep (/health, never /healthz) across all 11 backend namespaces — a drifted path fails CI before it 404s in production |
| Reference BFF route | VERIFIED — /api/bff/approvals/pending: tenant ONLY from middleware-stamped x-tenant-id (spoof-stripped in 1B), 401 tenant_required without a session tenant, standard error envelope |
| Missing backend read-APIs: proposals to service owners | VERIFIED (2026-08-05) — docs/frontend/READ_API_PROPOSALS.md: 8 proposed endpoints across 6 services (measured absences from the 1D wiring), D6/D-class constraints baked into the spec, explicit non-proposals (no unscoped listings, no mutations, no filterable batteries); acceptance stays with service owners (HD-4) |
Phase 1D — Governed Command Center live composition
| Item | Status |
|---|---|
| Overview (live tiles w/ source+freshness) | PARTIAL — slices 1+2 (2026-08-06; slice 2 session 7: 4th tile over the HD-4 decisions/summary aggregate w/ bounded-window caveat — renders honest unavailable until the operator redeploy; VERIFICATION §22). Slice 1 was — three live tiles over the measured reads (/api/bff/approvals/pending, /api/bff/boss/cells/health, /api/bff/registry/status), per-tile tri-state + source + poll-interval freshness + trace id; NO decisions/throughput tile (would be fabrication until the HD-4 decisions/summary aggregate ships); all five mock sections labeled; 3-case test matrix. Evidence: VERIFICATION §20.2 |
| Evidence explorer (4 time axes, redaction, point-in-time) | PARTIAL — first slice VERIFIED (2026-08-07, §26) — the SANCTIONED point-in-time read wired end-to-end (/api/bff/evidence/point-in-time: tenant only from stamped header → 401; six-domain + tz-aware as_of validation → 400 converting the measured upstream 422; four time axes rendered as labeled columns; truncation honesty; D6 note in every state; exclusive tri-state XOR illustrative test-enforced). Redaction + deeper querying remain |
| KG explorer (progressive, accessible) | PARTIAL — browse slice VERIFIED (final survivor: 9c §30; 9b §29 superseded at union) — on-demand bounded node/edge browsing over the measured /api/v1/kg/nodes+/api/v1/kg/edges GETs: 9c panel (KgLedgerBrowse + useKgReads hooks; limit 1–200, short-token filters, detected columns, permanent source pill "thin Boss ledger — not the Cell3 fleet graph", nothing-read-until-you-ask idle honesty) over the convergent union adapter contract (bare call = no query; explicit params clamp 200, filter-first; both response-type names exported). 9b's parallel implementation (identity-gated routes w/ default 25, truncation note, raw-JSON rows; +23 tests) is superseded — its honesty copy carried forward; its 121→124 kB budget note measured the superseded page, so the kg-live budget re-baselines at the next measured build. Remaining measured reads deferred by name: /api/v1/kg/events, /api/v1/kg/journey/{user_id}, /api/v1/kg/dropoffs. Earlier (§26): summary reads, nav label honesty, axe-scanned |
| Decision workbench (DecisionProof, exact eligibility states) | PARTIAL — queue wired (1D.2 lookup + session 7 §22: live tenant queue over HD-4 /api/v1/decisions w/ eligibility pills + DEL/threshold + explicit truncation; mock queue stays labeled; serving requires the operator governance redeploy) |
Approval center /command-center/approvals |
PARTIAL — live reads ×2 + role-gated mutations WIRED (9c, §30) — reads: pending 1D.1 + resolved history (HD-4, session 7 §22), three explicit states never blended. Mutations (9c): approve/reject enable ONLY for a verified approver/admin session (whoami progressive disclosure), POST role-gated BFF routes (require-role.ts; server re-verifies role + tenant-queue membership per call; body-supplied actor ignored — verified session only), refusals render untranslated (409/403/404/503) with traces; today's unauthenticated production keeps the buttons fail-closed disabled (e2e-pinned). LIVE exercise remains gated on the operator Wave-O asks (HD-3/HD-4 serving) |
| Action center (authorization lifecycle, honest 501/409/timeout) | PARTIAL — live reads + role-gated mutations WIRED (9c, §30) — reads per session 7 §22 (actuator registry 501-truth + tenant outcome records). Mutations (9c, operator/admin): ActionAuthorization redeem form (verbatim DCP object; BFF refuses cross-tenant 403; runner refusals pass untranslated — 409 single-use / 501 no-adapter / 403 signature) + per-outcome rollback (tenant-membership gate; rolled_back_by = verified identity). [not-wired] now names only authorization ISSUANCE. Serving requires the operator governance redeploy |
| Learning center | PARTIAL — composed (9c, §30) — predicted-vs-actual over action-runner outcomes (per-metric pairs, COMPUTED delta label; Stage-3 rows state "no actual — nothing executed, so nothing to measure" — no fabricated lift) + recent LEARN-phase activity over audit-replay recent (tenant-join + bounded-window caveat); honest-unavailable until the operator redeploy; [not-wired] names only calibration/drift (no read-API exists). Labeled illustrative table retained per the replacement contract |
| Policy center (read-only) | PARTIAL — live read wired (session 7 §22): active policy inventory (version, DEL floor, per-domain gates verbatim, advisory-only chips) over HD-4 /api/v1/policies; labeled illustrative kept; serving requires the operator governance redeploy |
| Audit & replay | PARTIAL — live tools + recent activity (1D.2 + session 7 §22: tenant recent-activity joins over HD-4 /api/v1/recent) — on-demand chain-integrity verify + replay-by-audit-id + decision-chain-by-id via /api/bff/audit/* (id-format 400 guard before any backend call); tri-state rendering via shared BffQueryState; example-trace table permanently labeled illustrative |
Remove lib/command-center/data.ts mock arrays from prod routes |
SUPERSEDED → labeled-illustrative discipline (2026-08-06) — the program's own truth pattern (approvals/cells precedent) keeps the scenario walkthrough but labels it: every consumer section now carries illustrative scenario — mock data + a [not-wired] note citing its measured HD-4 gap, never co-rendered with live data (test-enforced per page); the arrays get REPLACED page-by-page as HD-4 read-APIs land, and data.ts's header now states this contract (the never-built /api/command-center/* swap note is gone) |
Stage-1 adversarial audit (session 5, owner-directed "fix up all")
| Item | Status |
|---|---|
CI gate actually runs on bot merges (part 1, 688d6ca) |
VERIFIED — GITHUB_TOKEN suppression meant frontend-guard had run on ZERO merged commits; Deploy Router now dispatches it (ROUTED_CI_GATES) exactly like deploy workflows; dry-runs verified (UI change → deploy-ui + frontend-guard; docs-only → none) |
| BFF adversarial review — 9 findings | VERIFIED (9/9 fixed) — static-bearer never on URL-addressed calls; identity gate (401) on all four governance lookup routes; approvals page exclusive branches (live+stale XOR unavailable+illustrative XOR error); gateway timeout spans body reads; non-JSON 2xx → attributable 502; nonce-carrying lookup submissions; dot-segment id rejection; {data, traceId} envelope everywhere + client unwrap; a11y (aria-describedby, persistent status region, th scope). Evidence: FRONTEND_VERIFICATION.md §10 |
| Auth/session adversarial review — 5 findings | VERIFIED (5/5 fixed) — getAll/setAll cookie adapter (chunked-session refresh no longer corrupts → the random-logout class under REQUIRE_AUTH is closed); refresh cookies carried on every response branch; legacy login auto-redirect gated to non-Supabase (loop fix); path-segment-bounded public/role route matching; refreshed cookie header forwarded to server components. Clean: return-to sanitizer, header strip/stamp, role model, decide() ordering, CORS, sign-out. Evidence: §10 |
| Self-flagged items | VERIFIED — account-menu Escape/outside-click dismissal; PUBLIC_ROUTES boundary matching (converged with auth finding #4) |
Phase 2 — Capability surface
| Item | Status |
|---|---|
| 2A Six-domain workspace + authority boundaries | VERIFIED (first slice) (2026-08-05) — /domains renders the transcribed governance constants (lib/domains/authority.ts from source-of-truth v3.5.5 DOMAIN_STATUS + FORBIDDEN_AUTONOMY + measured passport batteries media 6 / finance 5 / counsel 12 / estate 13 / risk 14 / cre 5): maturity claim labels verbatim, media the SOLE non-advisory domain, counsel/estate/risk permanently advisory, forbidden scopes as refuse-at-grant chips, open proof obligations, DEL 80 platform-wide; 11 invariant tests lock the transcription (incl. a surface dead-link gate) + 6 page tests; nav entry cc-six-domains (auto-validated by the nav↔route gate). Deeper 2A slices (per-domain live composition) ride the 1D pattern as read-APIs land |
| 2B Intent/ORACLE advisory integration + blocked-activation states | VERIFIED (first slice) (2026-08-05, parallel wave) — 5 identity-gated BFF routes over the measured Cell 34 surface (taxonomy/cohort/transitions/explain/health; endpoints verified against scoring_cell/main.py; param guards mirror upstream semantics; tenant never request-supplied); /intent gains an additive governed live section: tri-state, "advisory evidence only" on every live payload, measured built, pre-benchmark claim label surfaced, permanent "Activation blocked — no registered holdout" banner; test-asserted rules: no activate button/toggle exists, no "audio" anywhere on the page. Score-by-identity deliberately NOT wired — the 1C adapter omits the service's required topic param (known follow-up, below). +43 tests |
| 2C 36-cell fleet truth + failure-class semantics | VERIFIED (first slice) (2026-08-05, parallel wave) — lib/fleet/registry.ts static transcription of the deployed Boss fleet table (36 = 32 production + 4 oracle_intent; stage vocabulary transcribed verbatim incl. META; 13 invariant tests); 2 BFF routes over the measured deduped endpoints (/api/v1/cells/list, /api/v1/cells/health/all) with URL-free payload projection + leak-check tests; raw-registry endpoints deliberately not wired (OPERATING_SYSTEM.md 6.1); failure classes from 6.3 only (403 = IAM-locked posture, not an outage; unmapped signals render raw); cells page: static + tri-state live sections with loud count-drift flags, mock grid preserved under illustrative label. +30 tests |
| 2D One Boss experience (single shell/client/session store) | IN PROGRESS — steps 1-6 + 8-10 LANDED; step-7 ratchet at 42 modules (2026-08-30; the "17" that stood here was a 2026-08-07 count and the ratchet is an append-only list of CLEANED modules, never a backlog). 2026-08-30: the three client-reachable modules §4.1's "CLOSED for backend URLs" note did not cover — lib/config.ts, lib/api.ts, lib/ekisClient.ts — were drained (behaviour-preserving: none of their NEXT_PUBLIC names is in the Dockerfile ARG list, which is where NEXT_PUBLIC values bake, so each was undefined in every shipped bundle and its same-origin default already governed) and ratcheted 40-42. Honest remainder = the deferred step-8 transport family + lib/flags.ts (own slice) + lib/neural-event-service.ts (the one genuinely open step-7 module: its fallback is a HARDCODED run.app URL, so it needs a proxy route, not a drain). See ONE_BOSS_CONSOLIDATION.md §4.2 and FRONTEND_VERIFICATION.md §34.6. Prior state: steps 1-6 + 8-10 LANDED (reconciled union, §29.5) (2026-08-07 session 9b §29 + 9a §28, hand-reconciled per §29.5: the client.ts hub cluster drained — CELL_URLS repointed same-origin (/api/boss-proxy + new SSE-only /api/cell22-proxy), CODING_MOA_STREAM deleted (0 consumers), JWT via the shared supabase client (LAZY import, ratchet-enforced after a measured +68-69 kB five-route regression was caught by the wave-close build and fixed same-session); config.ts now URL/env-free (cell origins resolve server-side in boss-proxy cellOrigin()); events/hooks/journey/neural/strategies/moe/moa/useKGComposition ratcheted with evidence tests; boss-proxy allowlist extended per measured caller incl. method-scoped PUT/DELETE + two unbuffered streams. MEASURED corrections: cellFetch ignored its cellId (all traffic was boss-origin — the map's cell13/14/15 attributions were routing metadata only); moe/moa are LIVE via the orchestration chain to mounted /chat, not 0-importer. Step-7 remainder measured at 47 client-importable files reading NEXT_PUBLIC URL envs: flags.ts (presence-gating semantics — own slice), 2 server-only closures (api-config, connector-gateway — importers are route handlers only), 44 out-of-zone = a2a/WS/SSE transport family (step-8-class), cloud-run-client, agents/, 9 component-inline fetches, 8 page-inline. Prior state: 2026-08-07 update; steps 8-10 + metrics/nervousSystem drains landed 2026-08-06/07 via owner-directed merge 8534ef9a, live-verified — memory inbox record; this session's step-7 wave 79f5efb: lib/api/boss.ts (21 allowlisted shapes on /api/boss-proxy), agent-ide.ts non-chat (28 calls, server-side CELL_REGISTRY fan-out), relu-client.ts (/api/relu-proxy, SSE pass-through), useKnowledgeGraph (stale-map correction: already same-origin), BossQuickstartView. MEASURED no-ops: BossAgentFooter HTTP already same-origin (residual = its step-8 A2A WebSocket read); useDataStream pure WS. Corrected remainder: lib/api/client.ts has 14 importers (map said 1) and drains together with the moe/moa/coding-moa/events stream consumers; config.ts NOT 0-importer; WS/A2A transport family (a2a, use-event-source, streamChat SSE internals) is the remaining step-8-class scope. Historical detail: steps 1-4 done + step 5 COMPLETE (5/5 surfaces) (2026-08-05) — all five live chat surfaces repointed onto the governed route behind per-surface BOSS_CHAT_GOVERNED_SURFACES flags (chat, footer, media-agent, boss-srpvdal, useBossAgentChat); each default flag-off = byte-identical, per-surface rollback = env change; governed branches parse the { data, traceId } envelope and render errors honestly (no silent WS fallback on the footer). Step 6 done — agent-IDE CHAT drained onto same-origin: new /api/ide/boss-chat verbatim authed pass-through (non-stream) + reuse of the existing /api/boss/chat/stream for SSE; sendChatMessage/streamChatResponse no longer make browser-direct cross-origin calls to the boss URL (both now relative paths; the boss URL resolves server-side in the route). The IDE's 28 non-chat calls (workspace/GitHub/Drive/snapshots/sessions/MCP/terminal) still use the cross-origin URL — deferred to later step-6 slices per the map. Step 7 mechanism established + first module — lib/no-public-backend-url.ratchet.test.ts is the append-only NEXT_PUBLIC ratchet (1C pattern extended bundle-wide); lib/api/srpvdal.ts is the first cleaned module (7 browser-direct cell calls → same-origin /api/srpvdal/[...path] authed proxy). ~30 other client modules remain, one ratchet entry per push. Remaining 2D: finish step 7's module sweep + steps 8-10 (WS consolidation, 404-feature fixes, owner-gated HD-2 archival). Branch synced with main (v2 auth bridge + strict flags) before this slice. Earlier: steps 1-4 — — step 5.1: /chat repointed onto the governed route behind the server-config flag BOSS_CHAT_GOVERNED_SURFACES (comma list, NEXT_PUBLIC-free, prop-threaded from the server page; unset = legacy path byte-identical — today's production; rollback = env change). Governed branch in useChat: shared step-3 sessionId as conversationId, enum-validated orchestration parity on the route, {data, traceId} envelope with traceId onto message metadata, honest envelope-error rendering incl. the 401 gate state. Remaining repoints (footer, media-agent, boss-srpvdal, useBossAgentChat) follow one per push. Step 4 was — step 4 (server session truth, read slice): measured GET /api/v1/conversations/{id} (Section 12 — the read side of the SAME FirestoreConversationManager the chat handler persists through, so the governed path's write truth was already server-side); new identity-gated /api/bff/boss/conversations/[id] lets surfaces rehydrate from the SERVER instead of localStorage — the legacy route's in-instance Map plays no part in the governed path. Upstream DELETE measured, deliberately unwired (mutations follow the role-gated pattern); per-USER conversation LIST has no canonical endpoint (legacy_state_manager only) — registered as an HD-4 read-API candidate. Step 3 was — step 3: ONE session identity — shared getBossSessionId()/resetBossSessionId() over the pre-existing boss-chat:session-id key (monotonic mint, SSR/storage-failure-safe), adopted by all five live chat callers: footer (was minting a NEW id per MESSAGE — defect S5, server memory defeated by design — 3 sites), useBossAgentChat (per-mount mint), SRPVDAL + media-agent (sent none), useBOSS unified onto the helper (clear-chat resets through it). 7 tests incl. the map's cross-component-share RTL case; user-visible check: footer conversation survives navigation. Step 1 was — governed POST /api/bff/boss/chat stands beside the legacy proxy (zero callers changed): typed chat() from the measured ChatRequest/chat_v1 contract, identity gate (chat is an invocation surface), bounded message validation, upstream clientId from VERIFIED identity only (test proves body-supplied clientId is ignored — the correction of the legacy client-supplied-identity trust); chatStream deferred with recorded reason (SSE cannot ride callService's JSON/timer contract — needs a gateway streaming primitive). Step 2 (authedFetch on the legacy proxies) landed in audit #2. Measurement (map) was — docs/frontend/ONE_BOSS_CONSOLIDATION.md: measured inventory (1 global shell + 18 mounted Boss surfaces + 6 orphaned chat components; 6 HTTP client modules; 9 disjoint session stores; 7 WS/A2A transports across 3 protocol families; 52 files referencing NEXT_PUBLIC_BOSS_AGENT_URL), ranked risks R1–R6, PROPOSED target architecture + 10-step additive migration sequence. Security findings for the next increment: primary chat proxy (app/api/boss/chat*) forwards with raw unauthenticated fetch (anonymous door while flag-off; fleet-wide chat outage the day Boss is IAM-locked); 3 mounted components call nonexistent routes (guaranteed 404s); footer mints a new sessionId per message |
| 2E Channels/connectors parity patterns (Data Manager API rule) | VERIFIED (first slice) (2026-08-05) — /channels parity workspace over lib/channels/connector-registry.ts: transcription of the governed-connector mandate (9 providers with rollout waves 1-3 + wave-4 category, 12 production gates, status vocabulary VERBATIM with the mandate's live-verified definition) joined to MEASURED status — the canonical gateway service-marketing-connectors EXISTS with all nine providers registered (Shopify first-class: HMAC webhook + Admin GraphQL backfill; eight fail-closed direct-pull adapters; everything forwards through service-canonical-ingestion), so all nine carry implemented and NOTHING stronger (serving revisions unverifiable from a checkout — the invariant test forces a conscious, evidence-carrying edit to ever upgrade); Data Manager rule measured (validate_only: bool = True default, consent 422 gate, hashed identifiers); GAQL surface honestly described as the Cell-29 sensing/read workspace, not connector ingress. 13 registry invariants (incl. gateway-source parity against main.py) + 7 page tests; nav: channels group rooted at /channels with a Connectors entry |
Phase 3 — Experience & quality bar
| Item | Status |
|---|---|
| 3A Tokens + primitives + workbench | PARTIAL — slices 1+2 VERIFIED (2026-08-07; slice 2 §31, slice 1 §27) — Slice 2: banner-cluster primitive components/ui/banner.tsx (Banner + BannerTitle/BannerBody/BannerTrace; measured tone×tier class matrix byte-pinned by test — error/warn/success × xl/lg/md + neutral loading tier on the 3A tokens; role/testid passthrough; tone explicit on internals so the set stays server-component-safe) + components/ui/stat-tile.tsx riding Tile (value/delta lines verbatim; scaffold StatTile removed at verified 0 importers); 26 banner sites swapped render-identical across approvals/events/kg-live/cells/actions + bff-states/kg-ledger-browse/redeem-authorization; page tests pass UNMODIFIED (668/668). Deliberately left: the /20-border note family, DEMO watermark, button chips, cells' two bespoke panels (§31.2). Slice 1 (§27): Operator Dossier tokens on :root + Tailwind theme (every value the MEASURED de-facto palette, zero restyle; --od- prefix collision-forced by the marketing homepage's styled-jsx variables); 5 primitives w/ 18 tests (StatusBadge, Tile, DataTable, SectionLabel + single-source ILLUSTRATIVE_LABEL, TraceFooter); 12 command-center pages refactored. Remaining: shadcn variable set + darkMode:'class' (fleet-restyle risk — own slice), workbench |
| 3B Command palette, deep links, saved views | PROPOSAL DELIVERED (2026-08-07) — docs/frontend/SAVED_VIEWS_PROPOSAL.md (deep-link param conventions per surface + v0 SavedView schema + storage-tier decision + owner questions). Palette shipped in 1A; build gated on the owner answering §5 |
| 3C WCAG 2.2 AA program | PARTIAL — slice 1 VERIFIED (2026-08-07 session 10, §30) — axe serious+critical gate 6 → 15 pages (all primary mounted top-level surfaces; every serious finding fixed incl. measured homepage styled-jsx contrast lifts ≥6.2:1; /cells excluded by measurement — the [kernel] fix 404s it); CommandPalette dialog focus-return contract fixed (was silently dropping to <body>); e2e/keyboard.spec.ts (login tab order, palette focus/Escape-return, sidebar traversal); a11y scan budget 90s + reduced-motion emulation (runtime budget — the violation gate is unchanged, never loosened). Remaining: the witnessed screen-reader pass (owner/operator), deeper interior pages |
| 3D Perf budgets, code-splitting, virtualization, cache policy | SLICE 2 VERIFIED — cache policy CLOSED (document-only, measured) (2026-08-07 session 9b, §29) — /operations/email-intelligence 262→106 kB (−60%) and /operations/unified-revenue 253→106 kB (−58%) First Load JS via the /analytics thin-wrapper precedent (bodies byte-copied; fallbacks mirror each page's own idiom); wave-close build re-confirmed EXACT vs the concurrent-tree build. Cache policy measured decisively (PERF_BASELINE §10): the next.config catch-all no-cache, no-store, must-revalidate overrides every route-level Cache-Control on the wire (verified by local serve), /_next/static immutable — so route-level no-store would change zero wire bytes; recommendation recorded (bake no-store into a future central BFF emitter; do not relax the catch-all without revisiting the two dead-letter public, max-age routes + SSE no-transform). Slice-1 (§27): /analytics −82%, /kg/ecosystem −30%, /kg/live −22%; virtualization measured-SKIPPED. §9.4 re-ranked candidates next: /boss/realtime 263 kB, /visualize/[kernelId] 252 kB, /operations/cell32-optimizer 232 kB |
| 3E OTel instrumentation of BFF + client error reporting | VERIFIED (first slice) (2026-08-07, §26) — CLIENT span per callService (tracer bff-gateway; service/path/status/traceId/outcome attributes; ERROR only ≥500; API-only, SDK-less no-op test-proven); traceparent propagated beside x-request-id; client error reporter (batch/rate-limit/PII-free/no-loop) → /api/client-errors sink (size/rate ladder, structured logs). +32 tests. Log-sink alerting = operator option |
| 3F CSP + security hardening + focused reviews | PARTIAL — report-only slice LIVE-VERIFIED (2026-08-08, §31.1: the exact header set measured serving on production — CSP-Report-Only + Reporting-Endpoints + nosniff + Referrer-Policy + XFO DENY + Permissions-Policy; /api/csp-report answering 204 live). Shipped 2026-08-07 (§26) with per-directive tightening notes; both telemetry sinks in PUBLIC_ROUTES. Operator follow-up unchanged: report-only → enforce after ≥2 weeks quiet reports + nonce pipeline (the header-contract test deliberately fails on an enforced CSP until consciously edited) |
| 3G Full test matrix (unit/component/route/contract/e2e/visual) | PARTIAL — e2e+a11y foundation VERIFIED + MSW landed (2026-08-07 update, §26–§27) — MSW 2.15 at the network edge (empty defaults + bypass; 4 suites migrated, URL contracts now proven at the edge); e2e +3 journeys (palette, 404 honesty, approvals tri-state via measured-envelope fixtures); axe list now SIX pages (serious+critical=fail, ratchet unchanged). Session-7 foundation retained: Playwright vs the production standalone artifact, real shell a11y fixes, verify script. Remaining: CI e2e wiring (SSH operator follow-up), visual regression, mutation e2e (HD-3) |
| 3H Remove ignoreBuildErrors/ignoreDuringBuilds; strict TS; SWR/dead-code removal | strict TS COMPLETE + toSafeUrl family CLOSED (2026-08-07, §27) — the "362 warnings" were a truncated-pretty-stream artifact; authoritative JSON measured 444, of which ~431 were STRUCTURAL false positives (the esquery > child selector matched the callee/LHS node itself — probe-verified). Fixed the 13+1 genuinely-dynamic sites (zero behavior change), then refined the selectors to field-level (> .arguments / > .right, router-scoped) with a both-directions probe: family 444 → 0, total warnings 558 → 115, protection intact. Dead-code verdicts recorded (report-only): lib/api/{change-detection,media-autopilot,production-client,coding-moa,rewoo,supabase-client}.ts + lib/time.ts measured 0-importer (archive slices pending); @miz-oki/boss-agent + AgentVoiceBridge confirmed already archived w/ clean barrels. Earlier: strict TS slices 1–3 (sessions 6-7, §20.1/§21.2/§24.4). Session 9 (both branches, §28 + §29): archive moves EXECUTED — 15 unique modules — 9a: the 7 verdicted + the events family (ActivityFeed, hooks/api/useEvents, lib/api/events.ts, lib/useSSE — 0-importer AND upstream REST measured ABSENT); 9b: the same 7 re-measured independently + lib/provenance/{client,index,types}.ts + lib/supabase/fetcher.ts; moe/moa re-measured LIVE in both and kept; tsc 0 after each move; 9b's never-live cell22-proxy archived in the §29.5 reconciliation. Remaining: 114 other-rule warnings (authoritative JSON: react/no-unescaped-entities 59, react-hooks/exhaustive-deps 39 — behavior-risk class needing per-site review, import/no-anonymous-default-export 9, @next/no-img-element 5, jsx-a11y/alt-text 1, no-page-custom-font 1) |
Phase 2D step 10 — Orphaned Boss chat components + duplicate clients archived (session 7)
2026-08-06 — Archive-only slice (ONE_BOSS_CONSOLIDATION §4 step 10; §1.1.3 / §1.2 / §1.5 / §6.2). Eight verified-orphan modules moved into archive-ui/ via git mv (history preserved as R-renames; the tree is already tsconfig.json-excluded, so the move drops them from tsc/build with no config change — the established non-breaking pattern). Non-breaking confirmed: npx tsc --noEmit clean (0 errors) after all eight moves — no dangling import references any archived file. Step-10 definition-of-done (0-importer greps + build green + ledger entries) met.
Re-measurement (critical — the §1 map is dated 2026-08-05). Importers were re-counted across the ACTIVE tree only (app/ components/ hooks/ lib/ store/, excluding archive-ui/), covering static imports, barrel re-exports, and dynamic import(). A module was archived ONLY at 0 live importers:
Archived → archive-ui/<same relative path> |
Live importers | 0-importer evidence |
|---|---|---|
components/PersistentBossChat.tsx |
0 | only self-export; other hits are docs (README / CLAUDE.md / A2A_INTEGRATION_COMPLETE.md) + an archive-ui/ comment |
components/EnhancedBossChat.tsx |
0 | stale-map correction — §1.1.3 recorded "imported only by EnhancedBossChatCompact"; re-measure shows Compact NO LONGER imports it (Compact imports: react, lucide, @/lib/a2a/client, @/hooks/useMediaCapabilities, @/lib/voice*). Now an independent orphan |
components/EnhancedBossChatCompact.tsx |
0 | only self-export |
components/boss-system-components/BOSSChatAdvanced.tsx |
0 | only self-export; the lone hooks/api/useCells.ts:14 hit is a comment, not an import |
components/BossAgent.tsx (the COMPONENT) |
0 | every …/BossAgent' import specifier resolves to @/agents/orchestration/BossAgent — a DIFFERENT, still-live type/orchestrator module (imported by app/test-orchestration, components/CausalOverlay, app/api/agents/orchestrate/route.ts), left untouched. The component itself has no importer |
lib/api/boss-api.ts (§1.2 C2) |
0 | no api/boss-api importer; distinct from live lib/api/boss.ts (C1, 31 KB, widely imported) and from the doc-only never-existed boss-api-client.ts (hooks/api/index.ts:140-166 DISABLED notes); no lib/api/index.ts barrel exists. Matches map "Zero importers" |
lib/production-a2a-client.ts (§1.5 T3) |
0 | socket.io client; only doc references. Matches map "zero importers" (also the step-8 T3 archival target) |
lib/websocket.ts (§1.5 T6, MizOkiWebSocket) |
0 | no lib/websocket / ./websocket importer in the active tree. Matches map "zero importers" (also the step-8 T6 archival target) |
Mirror dirs created: archive-ui/components/boss-system-components/, archive-ui/lib/api/.
SKIPPED (kept live — import-closure NOT orphaned):
- components/agent-ux/AgentVoiceBridge.tsx — re-exported by the live barrel components/agent-ux/index.ts (:152, :156-157), which is imported by the mounted page app/agent-ux/page.tsx:25 (from '@/components/agent-ux'). §1.1.3 listed it "grep: only self-match", but that measurement missed the barrel re-export; archiving it now would leave a dangling re-export in an out-of-scope barrel and break tsc. Deferred until the barrel export can be pruned in the same slice.
Deliberately not touched this slice (follow-ups):
- packages/@miz-oki/boss-agent/ (§1.2 C5, zero-importer per map) — left in place (workspace-package resolution risk); flagged for a dedicated later slice.
- The mock hooks/useBossAgent + CreativeStudioPanel repoint named in step 10 — belongs to the CreativeStudioPanel (live-surface) workstream, out of this slice's scope.
HD-2 PROPOSED permanent removals / route-redirects (owner-gated, traffic evidence required) are recorded in docs/frontend/HD2_ARCHIVE_PROPOSALS.md. Nothing is deleted or redirected in 2D itself; HD-2 stays OPEN.
Zero-Mock sweep + Central URL step-8 completion (session 12, 2026-08-09 → 2026-08-12)
Owner directives executed: "All mock data must be removed" (Zero-Mock, Law #1)
and the Central URL / NEXT_PUBLIC → same-origin drain driven to completion.
Full per-slice evidence: FRONTEND_VERIFICATION.md §33. All states
implemented + merged (auto-merge to main); nothing below is claimed
live-verified.
- Zero-Mock (8 slices): skills routes → honest 502; the two simulated SSE
routes → honest error streams; dead mock modules deleted;
/neural-brain,/customer-journey,/operations/neural-processorwired to their real same-origin reads (honest-empty where no backend exists);AdvancedAnalyticsDashboardhonest-empty; and the command-center demo mode retired permanently — fictional data arrays + DemoGate/demo-mode + theillustrative scenario — mock datapill deleted, every gated mock section now its honest[not-wired]note, ALL live Phase-1D BFF sections and the primary IA preserved. Tests + e2e flipped from "mock is labeled" to "mock is absent" — the suite now ENFORCES Zero-Mock. Interpretation ruling: "delete Bucket B entirely" = the illustrative content + mechanism, never the pages. - Central URL step 8 (ONE_BOSS §4 step-7 ratchet program CLOSED for
backend URLs):
lib/cloud-run-client.tssplit client/server — new URL-freelib/api/cell-client.tsaccessor; 4 client consumers drained; deadbossRewoo/NEXT_PUBLIC_REWOO_URLdeleted; repo-wide ratchet capstone gate forbids any client-bundlecloud-run-clientimport. The module is now server-only. - Agent-launcher SSE drain: the last client-bundle NEXT_PUBLIC
backend-URL read (the
[sessionId]live-log EventSource) now rides the same-originagent-execution-proxySSE streaming branch (unbuffered, OIDC server-side, honest 502). Client-bundle NEXT_PUBLIC backend-URL reads: 0 —lib/no-public-backend-url.ratchet.test.tsis the enforcing evidence.
Landed commits: a54ddc2d, c7d57d3d, 9c8d0c21, ae14e9ec, 36a1d73b,
097d0cdb, 6c04b785, 52f5d26e (Zero-Mock); 6e6bd1be, 17cdaef0
(step 8); 48dabb63 (SSE). Final gates: tsc 0 · lint 0 errors · full vitest
874/874 · build 0.
Open HUMAN DECISION register
| # | Decision | Context | Status |
|---|---|---|---|
| HD-1 | IdP consolidation (Supabase vs Firebase Auth vs keep-hybrid) | Evidence in ROUTE_INVENTORY §5; two independent measurements converged on Supabase | CLOSED (2026-08-05) — owner signed off all stage-1 parts; ADR-002 ACCEPTED; live flip = operator credentials + REQUIRE_AUTH |
| HD-2 | Route removals (any deletion beyond redirect/archive) | Charter forbids removal without migration evidence + approval; 2D step-10 archival receipt + proposed permanent removals/redirects in docs/frontend/HD2_ARCHIVE_PROPOSALS.md (+7 newly-measured 0-importer modules appended 2026-08-07 — archive moves executed session 9 (both branches) per §28 + §29; §1d six-family slice executed 2026-08-08). P1 EXECUTED 2026-08-12 — the 20 enumerated modules + archive-ui/packages/@miz-oki/boss-agent deleted; the permission block recorded on 2026-08-08 no longer applied. The doc's "shrink the ratchet in the same commit" instruction was re-measured and found STALE: with the entire archive-ui/ tree moved aside, no-public-backend-url.ratchet.test.ts + ws-transport.freeze.test.ts both pass (39/39) — zero ratchet entries were resolving through an archive-ui mirror, so no guard was shrunk and none needed to be. The §1d six families are NOT in P1 and remain (retention window from 2026-08-08). §3 redirects still lack their traffic-evidence precondition |
OPEN (P1 closed; §1d retention + §3 traffic evidence remain) |
| HD-3 | Staging/non-prod tenant for approval/action e2e tests | Required before any mutation testing. Operator action — cannot be closed in code: it needs a provisioned non-prod tenant, which is a credentials/environment task per AGENTS.md 7.6. Blocked on the same provisioning as the Supabase flip (docs/frontend/SUPABASE_PROVISIONING.md) |
OPEN (operator) |
| HD-4 | New backend read endpoints on governance services (adds backend scope) | CLOSED (2026-08-08) — endpoints implemented 2026-08-06 (§22); operator ran deploy_all.sh GREEN and the read-APIs are live-verified (mizoki-platform impersonation; mizoki-ui-sa invoker on the six services + ALLOWED_CALLER_SA — operator memory record, §31.3). Remaining condition for on-screen tenant data is the auth flip (sessions carry identity/tenant); BFF routes answer honest 401s until then — correct posture |
CLOSED |
| HD-5 | apps/web retirement (root CLAUDE.md operator follow-up already flags it) |
Confirm no CI depends on it before archive. CLOSED 2026-08-12 — tree deleted. Preconditions re-measured first: frontend-guard.yml triggers only on miz-oki-command-center-ui/** (the apps/web Zero-Mock lane was dropped in 0e94f510); no workflow runs a root-level npm ci (ekis-ci and frontend-guard both set working-directory); nothing in deployment/, Dockerfile, or any cloudbuild references it. Retired as a DELETE rather than the archive/apps-web move attempted on 2026-08-08 (owner-directed 2026-08-12); git history is the recovery path. Wiring cleaned in the same change: apps/* dropped from root workspaces, the !/apps/ + !/apps/web/ un-ignore lines dropped from .gcloudignore, and the apps/web / node_modules/web entries pruned from package-lock.json surgically (34 lines) — a full npm install --package-lock-only rewrote 14,008 lines of pre-existing lockfile staleness and was deliberately reverted rather than bundled here |
CLOSED |