feat: implement memory and evidence administration with guided repairs
Publish documentation / publish (push) Successful in 1m27s

Add PostgreSQL-backed memory, editable evidence with source review and activation, and human-approved archive repairs across the harness, API, and UI. Include migrations, deployment support, regression coverage, and validation documentation.

Refresh permissions from validated session roles so existing administrator logins can access newly deployed archive management features.
This commit is contained in:
Codex
2026-09-10 10:31:34 +02:00
parent 8fe526dd6e
commit 82e2c91f42
168 changed files with 11914 additions and 1772 deletions
+43 -2
View File
@@ -23,6 +23,46 @@ from tht.evidence import (
evidence_app = typer.Typer(help="Prepare and validate workspace Evidence", no_args_is_help=True)
@evidence_app.command("sources", hidden=True)
def sources_cmd(action: str, config: Path = CONFIG_OPT,
source_id: str | None = typer.Option(None), revision: str | None = typer.Option(None),
decision: str | None = typer.Option(None), actor: str = typer.Option("installation operator"),
json_output: bool = typer.Option(False, "--json")):
from tht.evidence.administration import ConsolidationError, source_action
try:
if action not in {"refresh", "decide"} or len(actor) > 256 or not actor.strip():
raise ValueError("Invalid source action")
if action == "refresh" and any(v is not None for v in (source_id, revision, decision)):
raise ValueError("Refresh does not accept decision options")
if action == "decide" and (decision not in {"keep", "replace"} or not source_id or not revision):
raise ValueError("A source decision requires source-id, revision and keep or replace")
payload = source_action(config, action=action, source_id=source_id, revision=revision,
decision=decision, actor=actor)
except Exception as error: # noqa: BLE001 - never expose connector/provider exception details
safe = isinstance(error, (ValueError, EvidencePreparationError, ConsolidationError))
_emit({"status": "failed", "code": "evidence_source_failed",
"error": str(error)[:1500] if safe else "Source acquisition or refinement failed; existing Evidence is preserved.",
"saved": isinstance(error, ConsolidationError) and error.saved}, json_output)
raise typer.Exit(1) from None
_emit(payload, json_output)
@evidence_app.command("admin", hidden=True)
def admin_cmd(workspace: str = typer.Option(...), config: Path = CONFIG_OPT):
from tht.evidence.administration import browse
try:
if os.environ.get("THT_PRINCIPAL_IS_ADMIN", "").lower() not in {"true", "1"}:
raise ValueError("Evidence administration requires an administrator")
payload = json.loads(config.read_text())
root = Path(payload["root"])
if not root.is_absolute() or root.name != workspace:
raise ValueError("Invalid workspace archive identity")
_emit(browse(root, payload.get("query", {})), True)
except (ValueError, OSError) as error:
_emit({"code": "evidence_unavailable", "message": str(error)[:1500]}, True)
raise typer.Exit(1) from None
def _canonical_worktree(workspace_root: Path) -> Path:
requested = workspace_root.absolute()
root = workspace_root.resolve()
@@ -123,7 +163,8 @@ def prepare_cmd(
) -> None:
"""Prepare changed Source Evidence without committing or publishing it."""
root = _canonical_worktree(workspace_root)
skill_path = Path(__file__).resolve().parents[2] / ".pi" / "skills" / "tht-evidence-authoring" / "SKILL.md"
from tht.evidence.authoring import authoring_skill_path
skill_path = authoring_skill_path()
restructurer = PiEvidenceRestructurer(os.environ.get("THT_PI_EXECUTABLE", "pi"), skill_path)
try:
try:
@@ -180,7 +221,7 @@ def migrate_cmd(
workspace_root: Path,
json_output: Annotated[bool, typer.Option("--json", help="Write machine JSON to stdout.")] = False,
) -> None:
"""Rewrite legacy Curated units as table-free v3 Markdown without model calls."""
"""Convert legacy units to editable v4 Markdown and establish a local baseline."""
root = _canonical_worktree(workspace_root)
try:
report = migrate_workspace_evidence(root)