chore: hygiene pass — ruff clean, docs storage-model truth, replay /me, failSession log

Audit findings 6.1-6.4 + the audit's remediation plan itself
(docs/superpowers/plans/2026-07-20-full-audit-remediation-plan.md).

- ruff: 34 → 0 (unused imports/f-strings auto-fixed; E702 semicolon lines
  split in test files; one unused local dropped). Suite still 819 green.
- CLAUDE.md + PROJECT_STATE.md no longer claim "no database / settings in
  settings.json": the harness selects filesystem OR PostgreSQL session
  storage (repository.py, server mode), and settings flow through harness
  preferences with the JSON file as fallback only.
- tools/replay: stub /me (SPA boot was parsing the SPA's own HTML as JSON)
  and /runtime/prewarm.
- failSession best-effort persistence now logs its failure server-side
  instead of vanishing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-20 01:55:41 +02:00
co-authored by Claude Fable 5
parent 1ab0015460
commit c4951e2aa5
21 changed files with 283 additions and 43 deletions
+11
View File
@@ -334,6 +334,17 @@ const server = createServer(async (req, res) => {
}
// --- REST stubs the SPA needs to boot -----------------------------------
// The SPA queries /me at boot (principal for session scoping/admin UI). Falling
// through to the static handler served HTML that apiFetch tried to parse as JSON.
if (method === "GET" && path === "/me") {
return sendJson(res, 200, {
issuer: "replay", subject: "reviewer@replay", displayName: "Replay reviewer", isAdmin: true,
});
}
// Boot-time best-effort warmup: a no-op in replay (no Pi runtime exists).
if (method === "POST" && path === "/runtime/prewarm") {
return sendNoContent(res);
}
if (method === "GET" && path === "/health") {
return sendJson(res, 200, { ok: true, replay: true, gates: GATES.length });
}