Frontend Route, Mock, Navigation, Auth, State & Design Inventory
Measured: 2026-08-05 (Phase 0A; six parallel read-only inventory passes over
miz-oki-command-center-ui/ at branch claude/miz-oki-command-center-ui-pacu82)
All figures are measured results. UNKNOWN marks what could not be determined from the repo.
Re-measured 2026-08-29 — see §0 before reading the body.
0. Status re-measurement (2026-08-29)
The body of this document is a dated 2026-08-05 measurement and is kept as written — it is the Phase 0A baseline the whole program is diffed against. This section carries the re-measurement. Where the two differ, this section is current.
0.1 Census delta
| Item | 2026-08-05 | 2026-08-29 |
|---|---|---|
User-facing routes (app/**/page.tsx) |
155 | 173 |
| API route handlers | 211 | 278 (of which 46 under app/api/bff/**) |
| Layouts | 6 | 7 (adds app/(console)/layout.tsx + app/(console)/estate/layout.tsx; app/channels/google and app/marketing unchanged) |
| Route groups | 0 | 1 — app/(console), holding the five destinations |
loading / not-found / error / global-error |
0 | 4 — all four now exist at the app root |
Routes named *-archived* still routable |
8 | 0 |
| Test/scratch routes routable in prod | 5 | 0 — all five still present, all five gated behind ENABLE_DEV_ROUTES 2026-08-30 (404 in production; reachable in a non-prod deploy) |
| Components | 260 | 284 |
| Test files | 0 | 152 (2026-08-30: +/service-health retirement, +the dev-route gate, +the [kernel]/insights gate) |
0.2 The consolidation this inventory predates
The package now has five destinations under app/(console)/ — decisions
(index), evidence, loop, governance, estate — shipped 2026-08-28/29 in PRs
868, #873, #874, #875, #876. Six competing roots (/, /dashboard,
/dashboard/modern, /command-center, /operate, /mizoki) now answer 307 →
/decisions via next.config.mjs redirects(), kept in step with
lib/console/destinations.ts RETIRED_ROOTS by a contract test. See
COMMAND_CENTER_TRANSFORMATION_PLAN.md §3.1 for the destination map and the
legacy → successor route table.
Consequence for §1.1 below: the /command-center row's "MOCK — zero fetch on all
10 pages" is stale. Those pages were rebuilt against the BFF in Phase 1D
(useGovernanceReads, useGovernanceLookups, useFleet), and the tree itself is
now the legacy surface behind the five destinations. Likewise /audit no longer
exists as a route (it is /governance/audit), and /kg/federation and
/customer-journey have had their fabricated Math.random() data deleted — the
only surviving matches are comments recording the removal.
0.3 Findings carried forward — all CLOSED or VERIFIED 2026-08-30
(Retitled 2026-09-01: every row below closed on 2026-08-30 with its evidence inline; the "still open" heading outlived the findings by a day.)
/service-health— CLOSED 2026-08-30 (retired). It was 521 lines, zero network calls, and no mock / illustrative /NotWiredNotelabel anywhere in the file: the "PRODUCTION RISK" row of §1.1, the one that never closed. Fixed by RETIREMENT, not by a label — a banner over 500 lines of invented uptime still ships the invented uptime to anyone who scrolls, and the Zero-Mock Law's applied remedy for a wholly-fabricated surface is deletion of the fabrication (components/ui/section-label.tsxrecords that the illustrative-label primitive itself was removed for that reason;app/command-center/domains/page.tsxis the shape). The route stays reachable as a deep link and now renders a retirement notice plus pointers, pinned byapp/service-health/page.test.tsx— seven tests, four of them source-literal assertions that fail if hardcoded service rows, relative timestamps, uptime percentages,.a.run.appendpoints, or an ungovernedfetchreturn. Theservice-healthchild entry was removed fromconfig/navigation.ts(its description, "Real-time service monitoring", was the same unbacked claim);/system-healthstill redirects here, so both legacy URLs land on the explanation. Successor paths, resolved against the tree:/estateis the Cells surface (the Estate destination's index route) and/estate/servicesis Services — there is no/estate/cells. Both sit behind anoperator/adminrole floor enforced server-side and fail-closed inapp/(console)/estate/layout.tsx, so without a session-verified engineering role that gate refuses. The health surface reachable without one is/system/health-dashboard, which probes the fleet through/api/system/health-all.app/[kernel]— CLOSED 2026-08-30, and the finding was half stale. The finding as carried read: "the root-level dynamic segment still exists, so unmatched single-segment paths are absorbed rather than 404ing.app/not-found.tsxnow exists but cannot fire while this route does." That second sentence was already wrong when it was written:app/[kernel]/page.tsxhas callednotFound()SERVER-side since 2026-08-08 (test-pinned inapp/[kernel]/page.test.tsx), so unmatched single-segment paths do get a real 404 andapp/not-found.tsxdoes fire. What was genuinely open was one segment deeper —app/[kernel]/insights/page.tsxhad no gate at all, so/<anything>/insightsrendered a kernel header, a global nav strip and aRecommendationsCardfor a kernel that does not exist, at HTTP 200. Both pages now gate on one exported list (app/[kernel]/known-kernels.ts), so a kernel added to one cannot be missing from the other; the child was also migrated to Next 15 awaitedparams/searchParams, which it had been destructuring synchronously. Pinned byapp/[kernel]/insights/page.test.tsx.- Five test/scratch routes — CLOSED 2026-08-30 (gated, not deleted).
/test-orchestration,/test-moa-integration,/causal-test,/kg-brain-test,/agent-uxnow sit behindENABLE_DEV_ROUTES(lib/dev-only-route.ts). The gate is a SERVER component that decides before the stream starts — a client-sidenotFound()throws after headers flush and answers HTTP 200, the same defect the[kernel]gate was rewritten to fix — and it is fail-closed: only the exact string'true'opens it. Deletion stays an owner decision (Phase 2D non-goal 2), so the page bodies moved to sibling client modules and the routes remain. Five inbound links that would have become guaranteed 404s were repointed or removed in the same change (config/navigation.ts,app/boss/causal,BossNavigation×2,MIZOki30MOAMOEArchitecture×2);lib/dev-only-route.test.tsnow fails if any live file links a gated route. Three of those links were found by that test, not by the initial grep. /decisions/[id]/evidence— VERIFIED 2026-08-30, no change needed. It still targets/api/boss/srpvdal/trace, which does not exist, and renders an honest "Trace read unavailable" state naming the route plus an explicit "nothing shown below is live evidence". Its test (app/decisions/[id]/evidence/page.test.tsx) passes. The UI item is closed; the READ GAP itself stays open and is a backend item.
0.4 Escape hatches and auth (§ cross-reference)
The build-gate and test findings this inventory fed into
(ignoreBuildErrors, ignoreDuringBuilds, strict: false, zero tests) are all
closed — see COMMAND_CENTER_TRANSFORMATION_PLAN.md §5 rows 2–3 for the
measured literals. Auth is closed in code (Phase 1B) but enforcement is still
gated on the operator setting REQUIRE_AUTH=true against real Supabase
credentials (middleware.ts:102).
1. Route census
| Item | Count |
|---|---|
User-facing routes (app/**/page.tsx) |
155 |
API route handlers (app/api/**/route.ts + app/auth/callback/route.ts) |
211 |
| Layouts | 6 (root + command-center + channels/google + marketing + agent-ide + error boundary) |
| Route groups / parallel / intercepting routes | 0 |
loading.tsx / not-found.tsx / global-error.tsx |
0 (no route-level Suspense fallbacks anywhere) |
| Orphan non-route page variants (dead) | 2 (app/kernel/[kernel]/page-simple.tsx, app/login/page-fixed.tsx) |
Routes named *-archived* still routable |
8 |
| Test/scratch routes routable in prod | 5 (/test-orchestration, /test-moa-integration, /causal-test, /kg-brain-test, /agent-ux) |
Structural hazard: app/[kernel]/page.tsx is a ROOT-LEVEL dynamic segment — any
unmatched single-segment path (/foo, /agent_ide, /boss-orchestrator) is absorbed by
it instead of 404ing, masking every broken nav link.
1.1 Classification of key routes (Phase 1 targets)
| Route(s) | Purpose | Data source | Phase-0 classification |
|---|---|---|---|
/command-center + 9 children |
§19 governed-loop surface | MOCK — zero fetch on all 10 pages; imports the 12 fabricated arrays from lib/command-center/data.ts |
KEEP → rebuild live (Phase 1D) |
/channels/google + 9 children |
GAQL Intelligence Cell | LIVE via /api/gaql/[...path] authedFetch proxy |
KEEP (pattern exemplar) |
/intent |
Intent read-only viewer | LIVE via allowlisted intent proxy | KEEP |
/boss* (22 routes) |
Boss chat/orchestration | Mixed live; 8 archived-but-routable; 3 redirects | CONSOLIDATE (Phase 2D) |
/dashboard, /dashboard/modern, /dashboard/srpvdal, /dashboard/srpvdal-live, /dashboard/srdal(307) |
Operator dashboards ×5 | HYBRID (env-gated mock defaults; srpvdal-live has explicit isMock flag) |
CONSOLIDATE |
/kg* (10) + /command-center/kg-live + /neural-brain + /causal-* |
KG viewers ×13 | Mixed; /kg/federation fully fabricated (8 Math.random sites, 0 fetch) |
CONSOLIDATE |
/service-health |
was "Real-time service monitoring" | ~~MOCK — PRODUCTION RISK: 521 lines, zero network calls, 20 hardcoded services w/ uptime %, relative timestamps, fake critical alert~~ CLOSED 2026-08-30 — fabrication deleted; route now renders a retirement notice + pointers | RETIRED (not rebuilt): /system/health-dashboard is the live equivalent; /estate/services + /estate are the BFF successors behind the engineering role floor |
/audit |
Audit & reports | MOCK — hardcoded audit events (the one surface that must never be synthetic) | KEEP → rebuild live (Phase 1D) |
/analytics |
Analytics dashboard | MOCK-seeded + statically bundles d3+recharts+tfjs+framer | CONSOLIDATE + code-split |
/customer-journey |
Journey feed | MOCK — invents synthetic named individuals on a 5s interval | REDESIGN or REMOVE (HD-2) |
/decisions/[id]/evidence |
Decision evidence | BROKEN — fetches /api/boss/srpvdal/trace, a route that does not exist (live 404) |
FIX in Phase 1D |
/kernel/[kernel] + /[kernel] + /[kernel]/insights + /kernel |
Kernel views ×4 | MOCK via lib/api-service.ts (setTimeout + hardcoded KPIs) |
CONSOLIDATE |
/blog* + /blogs* (4) |
Blog duplicated verbatim (two identical content modules) | STATIC | CONSOLIDATE → redirect |
/login |
Tenant login | LIVE against client-side Firestore auth (see §5) | KEEP → rebuild on ADR-002 |
| Remaining ops/marketing/agent routes | various | Mixed; per-route table in agent transcript | classify during Phase 1A consolidation |
1.2 Duplication clusters (route consolidation backlog)
- A. Boss (22 routes) — 13 live variants + 3 redirects + 8 routable "archived" pages; two competing hub pages (
/boss-nav,/intelligence). - B. Dashboards (5) —
/dashboardvs/dashboard/modernnear-identical; nav's "Dashboard" points at/while middleware treats/dashboardas public. - C. KG viewers (13).
- D. Viz (5) —
/viz+/visualizeboth near-empty wrappers; two nav sources point "Analytics" at different routes. - E. Health (4) — RESOLVED 2026-08-30:
/service-healthretired (its fabrication deleted, route kept as a pointer) and/system-healthredirects to it, leaving/system/health-dashboardas the one live health surface outside/estate. - F. Kernel (4) incl. the root-level
[kernel]catch-all hazard. - G. Blog ×2 verbatim.
- H. Test/scratch (5) routable.
- I. Orchestration (3); dead nav still links deleted
/services/boss-enhanced.
2. API route posture
- 211 handlers. Only 2 verify the caller (
app/api/session/start,app/api/a2a/send) — 208 are caller-unauthenticated (~99%). - 93/210 use
lib/service-authfor outbound OIDC; 5 make genuinely unauthenticated server→Cloud Run calls (agent-control/stream,skills/{decide,eval,predict,shadow}). - 3 competing outbound-auth helpers:
lib/gcp-auth.ts(mints broadcloud-platformOAuth token, no host allowlist — hazardous),lib/cloud-run-client.ts(getIdToken()stubbed toreturn null), inlineGoogleAuthinapp/api/audio/chat. MIZOKI_AUTH_STRICTset nowhere → OIDC mint failures silently degrade to unauthenticated calls.SERVICE_BEARER_TOKEN/ACTION_HUB_BEARER_TOKENshort-circuit OIDC entirely if ever set.- Exemplar to generalize:
app/api/gaql/[...path]/route.ts(Node runtime, authedFetch, POST allowlist, documented threat model).
3. Mock/fallback inventory (highest-risk)
Math.random occurrences: app 324 · components 64 · lib 48 · hooks 29. The one
correctly-gated mock boundary (NEXT_PUBLIC_ENABLE_MOCK_DATA, false in every deploy
manifest) covers only 3 files of ~40 fabrication sites.
PRODUCTION RISK (fabricated data on nav-reachable routes, no user-visible disclaimer):
| Source | Fabricates |
|---|---|
lib/command-center/data.ts (12 arrays → 10 pages) |
Event volumes ("18,742 ↑24%"), decisions w/ ROAS+confidence, executed actions ("reengagement nudge → 1,204 contacts"), audit rows with fake sha256 digests, an approval attributed to gc@acme.com. Scaffold banner exists but is desktop-only (hidden lg:block) — mobile/tablet see mock data with NO disclaimer |
~~app/service-health/page.tsx~~ CLOSED 2026-08-30 |
~~Entire health dashboard incl. fake critical alert~~ — deleted; the route now renders a retirement notice and pointers, with source-literal guards in app/service-health/page.test.tsx |
app/api/cells/stream/route.ts |
SSE metrics with comments laundering randoms as "real Cell 29/30 performance" |
app/api/kernel/{metrics,activities,graph} |
Random spend/ROAS; fake "auto-applied bid adjustments" activity feed (asserts actions were TAKEN); fake KG |
app/api/v1/{moe/activate-cells, moa/coordinate-stages, kg/route-task} |
Random cell loads/latency/success feeding /cell-monitoring |
app/kg/federation/page.tsx |
Live-looking counters, 0 fetch |
app/customer-journey/page.tsx |
Synthetic named customers invented every 5s |
app/audit/page.tsx |
Hardcoded audit events |
app/boss-nav/page.tsx |
"15,234 nodes / 45,678 edges / 25 cells / 85% autonomy" |
app/agents/config/page.tsx |
Simulated fleet weights/efficacy/health |
lib/api-service.ts |
Hardcoded per-channel KPIs behind setTimeout |
app/api/events/route.ts |
20%-random backend "health" signal consumed globally |
lib/neural-event-service.ts |
Fabricates heatmap on ANY http error, unmarked |
app/api/srpvdal/metrics empty-collection branch |
Silently mocks in prod, no UI signal |
components/{AdvancedAnalyticsDashboard, CausalAnalysisDashboard, KGCompositionDashboard, creative/ABResultsPanel, kg/KGMetricsDisplay, agent-ide/*} |
Mock analytics/mediation/A-B/skills data on live routes |
EXPLICIT DEMO MODE (acceptable pattern, keep-and-formalize): components/modern/*
(env-gated), lib/mock/srpvdal.ts + /dashboard/srpvdal-live (isMock surfaced),
/marketing/patent-ui, /agent-ux demos.
DEVELOPMENT FALLBACK w/ header marker only: app/api/skills/* (X-Mock-Response:
true, no current UI consumer). DEAD: app/api/sse/creative-updates,
app/api/viz/[kernel]/timeseries, hooks/useCollaboration.ts.
4. Navigation state
The prompt's "nav may already be consolidated" hypothesis is REFUTED.
- config/navigation.ts (last updated 2025-09-25) declares itself the single source but
has only 2 consumers — NavigationShell (mounted) and MobileNavigationShell (dead,
0 importers).
- 11 active navigation trees, 10 of which do NOT read the config: section layouts
(command-center NAV, channels/google TABS, marketing ×2 renders), BossNavigation (22
hardcoded links, 3 dead targets), page-as-nav hubs (/boss-nav, /intelligence,
/evaluations), agent-ide SideBar, breadcrumbs' own configs.
- 5 dead nav components still in components/ (MobileNavigationShell, MainLayout,
NavigationSidebar — stale route table incl. deleted /services/boss-enhanced,
NavigationHeader, Sidebar). archive-ui/ does not exist anywhere in the repo.
- MOBILE_ROUTES positional indexes are all four mislabeled vs the actual array (moot
only because its consumer is dead).
- icon: any occurrences: navigation.ts:51-52 (+3 more files); no correctly-typed icon
anywhere (no LucideIcon/ComponentType usage).
5. Auth, identity, tenancy (measured conclusions)
- Live IdP = custom client-side Firestore tenant auth (
lib/tenant-auth.tsviahooks/useTenantAuth.tsx, mounted app-wide): browser queriestenants/{id}/users/{email}(fields includepasswordHash,salt), verifies PBKDF2 in the browser, mints its own session token client-side, writes it to Firestoresessions/{token}, stores it in localStorage (miz_oki_session).configs/firebase/firestore.ruleshas no rule fortenantsorsessions(whether that file is the deployed ruleset: UNKNOWN). - Supabase: fully implemented (SSR clients, middleware refresh,
/auth/callback) but deployed with placeholder credentials (cloudbuild.yaml:55,57) → not live. Firebase Auth: imported once, never called → dead. Firestore (data): live. - Middleware:
REQUIRE_AUTHunset in every env/deploy config →protectedRoutes=[]; fails open at three levels;/dashboard+/bossin the unconditional public list; legacy cookie branch does no verification and hardcodes role 'engineer'. - Other hazards: hardcoded fallback admin secret in
app/api/admin/tenant/route.ts:61;'dev-secret'HMAC fallback inlib/jwt.ts:48; refresh token in localStorage (unmounted context);NEXT_PUBLIC_PROVENANCE_HASH_SALTships a salt to the browser; non-httpOnlyuser_infocookie. - Tenancy: no server-side tenant authority exists.
resolve_tenantanalog: zero matches.app/api/session/startletsbody.tenant_idOVERRIDE the session profile's tenant;X-Tenant-IDis a free-text user-typed form field forwarded verbatim; build-timeNEXT_PUBLIC_TENANT_IDconstants baked into the bundle. - Browser→Cloud Run direct calls: 20 client files, ~59 call sites (incl. 4 WS + 1
EventSource) across ~15 services — each requires that service to stay
--allow-unauthenticatedand exposes the fleet topology in the bundle. ~129 distinctNEXT_PUBLIC_*names, ~100 of them backend URLs.
6. State & API-client duplication (migration backlog)
- SWR: 0 usages (dead dependency). Redux: absent (package CLAUDE.md stale).
- Zustand: 9+ stores across
store/,stores/,lib/; ≥5 hold server data; 2 dead; live WS/SSE handles stored in a persisted store (realtimeSlice). - React Query: 140 useQuery + 90 useMutation across 32 files; TWO providers (1 dead);
TWO hook layers (
lib/api/hooks.tsvshooks/api/*); polling (2s–60s) overlapping SSE. - API clients: 34 modules in
lib/; 5 Boss clients (2 byte-identical 57KB archived copies still type-checked); 5 A2A clients on 3 different transports (3 sharing one class name); 12 SSE hook implementations (two files export the sameuseSSEname); 7 generic HTTP clients; 5 URL-resolution schemes; 2 cell-client layers. - Boss chat: 4 hooks + ~17-20 shell components; the live path (
hooks/api/useBOSS.ts) does NOT usepackages/shared-contracts(only 2 importers total — adoption decorative). - Client boundary: 344 of 410
.tsxfiles are client components (84%); RSC effectively unused outsideapp/layout.tsxand API handlers. Server-only modules keep discipline by convention only (noimport 'server-only'anywhere). - Vendor SDKs:
openai+@google-cloud/vertexaiused server-side only (packaging risk, not runtime violation today);@tensorflow/tfjsstatically imported into a client dashboard;react-force-graphunused (and its transitive deps are what broke the lockfile).
7. Design system & accessibility (debt summary)
- Four uncoordinated color systems; the unwired
lib/design-system.tseven exports a readytailwindExtendnever added totailwind.config.ts(17 lines, 5 tokens with 4 total usages). - ~576 shadcn-style utility usages emit zero CSS (variables never defined) — Card/
Badge/Alert effectively unstyled; the shared Button's
focus-visible:ring-ringring color doesn't exist (rescued only by a global outline). - Dark mode structurally broken:
<html className="dark">hardcoded,darkModeunset (defaultsmedia) → 467dark:usages keyed to OS preference. tailwind.config.tscontentomitslib/andhooks/→ classes authored there are purged in prod.app/layout.tsxviewport setsmaximumScale:1, userScalable:falsetwice — WCAG 1.4.4 failure (blocks pinch-zoom).- A11y at scale: 85
aria-*vs 1,024 buttons; 75 clickable divs (mostly keyboard- inaccessible); 62% of inputs unlabeled; 0 skip links; 0next/image; 12 tables with 0scope=; 1prefers-reduced-motionquery — in a stylesheet imported by nothing; the shared skeleton runs an infinite animation unguarded. The best-annotated components (Sidebar,Header) are dead code. - Bundle:
/analyticsstatically chains recharts +import * as d3+ tfjs + framer; 15 filesimport * as d3; framer-motion on the critical path of every route viaPageTransition+ skeleton;BossAgentFooter(A2A client, mic, upload) renders on every non-auth route; only 11 files usenext/dynamic(monaco/cytoscape/three done right). - Primitives: 21-file
components/ui(shadcn-copied, nocomponents.json, cannot re-sync) + a SECOND full primitive set incomponents/command-center/primitives.tsx(holds the only Table); no form/checkbox/popover/sheet/command/toast-renderer; 195 rawanimate-pulsead-hoc skeletons; no shared EmptyState; ErrorBoundary used by 3 files. - Layout: global
NavigationShellstacks with 4 nested layouts + 18 per-page shells (double header/sidebar on/command-centerand/marketing);useResponsive()initializes width 0 → every desktop load flashes mobile chrome (hydration mismatch); desktop sidebar collapse is wired but impossible. - Fonts: 4 strategies (next/font Inter; unloaded design-system JetBrains Mono; unloaded 'Fira Code' in globals.css; homepage render-blocking Google Fonts link).
8. UNKNOWNS carried forward
- Deployed Firestore ruleset + Supabase RLS state (live project state).
- Whether any page-level layout mounts
FeatureFlagsProvider/AuthProvider(×2)/AgentStateProvider. - Which route (if any) loads
lib/edge-inference/onnx-runtime-web.ts. app/api/connectors/*actual upstream.- Build/deploy relationship of nested
packages/@miz-oki/boss-agent.