Implement approved specification #32 and tickets #33-#37. Keep host authentication server-verified and pin session interaction language. Compile scoped base selectors for browser compatibility and retain full gutters during CSS pruning.
Add PostgreSQL-backed memory, editable evidence with source review and activation, and human-approved archive repairs across the harness, API, and UI. Include migrations, deployment support, regression coverage, and validation documentation.
Refresh permissions from validated session roles so existing administrator logins can access newly deployed archive management features.
Two fixes:
1. Revert tool_execution_* forwarding: these cluttered the UI with raw
bash/read output the user never asked for. Only text_delta, system_event
and ui_request are forwarded, as before.
2. tht ignores THT_CONFIG env var and always looks for config/tht.yaml
relative to CWD. Create a symlink so the PI agent can run tht commands
without -c flag.
- restore COPY harness/ (perso durante edit) -> /app/harness esiste
- cp workflow.yaml in site-packages: tht lo carica module-relative
(parent.parent del package); non-editable install non lo includeva
-> session show 500 (FileNotFoundError). pip install -e non accettato da pip.
- cd /app/harness && pip install . : pip 26.1.2 rifiuta il path bare /app/harness
- compose: THT_MODEL_API_KEY_FILE per buildPiChildEnv (codex) -> session create
prima 500 'model provider credential is unavailable'
Verificato: session show 200 (phase 1), create 200, Pi+model+SSE OK.
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
Il caso 'server)' era stato eliminato inavvertitamente: CMD [server]
cadeva nel *) exec $@ -> 'server: not found' (exit 127).
Smoke standalone ora verde: health + config check + db ping (read-only).