54 Commits
Author SHA1 Message Date
Codex d8a29bfbdd Add full shell, replaceable Omics adapter and bilingual interaction
Implement approved specification #32 and tickets #33-#37. Keep host authentication server-verified and pin session interaction language. Compile scoped base selectors for browser compatibility and retain full gutters during CSS pruning.
2026-09-13 14:26:39 +02:00
Codex 82e2c91f42 feat: implement memory and evidence administration with guided repairs
Publish documentation / publish (push) Successful in 1m27s
Add PostgreSQL-backed memory, editable evidence with source review and activation, and human-approved archive repairs across the harness, API, and UI. Include migrations, deployment support, regression coverage, and validation documentation.

Refresh permissions from validated session roles so existing administrator logins can access newly deployed archive management features.
2026-09-10 10:31:34 +02:00
User 28db30bd78 fix(ops): make server diagnostics release-safe 2026-09-07 01:15:28 +02:00
Codex f114d0065a feat: classify sensitive columns locally 2026-09-03 02:11:13 +02:00
Codex 7b7927bfe5 feat: unify installation model catalog 2026-09-02 18:45:33 +02:00
Codex 79c4c925b5 feat: implement metadata catalog database management 2026-08-27 22:43:54 +02:00
marcopan 3e106d5262 fix(ci): restore deployment release gates 2026-08-25 16:45:56 +02:00
User 3fdc278e7a fix(frontend): prevent stale bundle white screens 2026-08-22 21:14:48 +02:00
User 120816d81c fix(docker): preserve frontend script executability 2026-08-22 20:53:02 +02:00
User 87606c73c1 build: package standalone DWH authentication service 2026-08-21 02:32:26 +02:00
marcopan 7e52df2702 fix(auth): address Task 13 deployment review findings 2026-08-17 21:31:25 +02:00
marcopan d464f3a982 build: align authentication runtime on Node 24 2026-08-16 17:13:55 +02:00
marcopan 3e0c864c85 fix(pi): isolate resolved package builds 2026-08-16 00:20:30 +02:00
marcopan aa8a2e9278 refactor(cli): rename operator command to tht 2026-08-15 21:56:40 +02:00
marcopan 9414a4b4dd fix: initialize workspace secret volume for runtime 2026-08-14 18:13:52 +02:00
marcopan c5f65d0f15 feat: profile-gated workspace-maintenance service and connector override generator (P2) 2026-08-11 18:40:11 +02:00
marcopan 320d9ea74e feat: run qdrant and ollama inside thothii 2026-08-08 18:38:42 +02:00
marcopan 5d037e97c4 refactor: remove portal deployment coupling 2026-08-05 06:58:19 +02:00
marcopan 55926c75f8 fix: harden pi management verification 2026-08-05 01:00:13 +02:00
marcopan 935bb1db0e fix: harden embedded Pi lifecycle recovery 2026-08-04 23:14:47 +02:00
marcopan 4158990c10 fix: harden thothctl diagnostics 2026-08-04 17:00:05 +02:00
marcopan 853a151796 feat: add cross-platform thothctl 2026-08-04 16:48:40 +02:00
marcopan e2264ee295 build: harden image build inputs 2026-08-04 16:33:39 +02:00
marcopan d42fdf4b71 build: make embedded pi images reproducible 2026-08-04 16:19:04 +02:00
marcopan a248fb46d0 fix(deploy): reject ambiguous frontend upstream paths 2026-08-04 16:02:25 +02:00
marcopan 87b0fda3f6 fix(dev): proxy local API and restrict frontend upstream 2026-08-04 15:58:13 +02:00
marcopan 8ffcaf3db9 deploy: route frontend and core through one origin 2026-08-04 15:48:15 +02:00
marcopan ad07a75490 build: enforce portable line endings 2026-08-04 14:33:45 +02:00
marcopan f71feecaea feat: deploy portable workspace registry 2026-08-04 07:26:45 +02:00
marcopan ff795d1c91 feat: diagnose workspace connector bindings 2026-08-03 22:52:29 +02:00
marcopan 801f847ec4 fix: use Pi user auth and handle startup failures 2026-07-21 14:01:47 +02:00
marcopan 0cf09777f2 Fix session resume and PSD container configuration 2026-07-20 20:22:47 +02:00
User 7a65fc80a2 fix(deploy): validate session migrator TLS mode 2026-07-16 19:07:53 +02:00
User cadc4c6947 docs(deploy): document user-owned session cutover 2026-07-16 19:02:58 +02:00
User 6dbf93fff9 feat: harden runtime readiness and session workflow 2026-07-14 10:27:25 +02:00
User 664d392859 fix: remove verbose tool logs from UI + symlink config/tht.yaml
Two fixes:
1. Revert tool_execution_* forwarding: these cluttered the UI with raw
   bash/read output the user never asked for. Only text_delta, system_event
   and ui_request are forwarded, as before.

2. tht ignores THT_CONFIG env var and always looks for config/tht.yaml
   relative to CWD. Create a symlink so the PI agent can run tht commands
   without -c flag.
2026-07-13 00:29:28 +02:00
User ac333f99ac fix(docker): chown .pi to thoth so Pi locks survive rebuilds 2026-07-13 00:14:37 +02:00
User 122cbfd50d fix(docker): post-merge fixes for codex backend compatibility
- restore COPY harness/ (perso durante edit) -> /app/harness esiste
- cp workflow.yaml in site-packages: tht lo carica module-relative
  (parent.parent del package); non-editable install non lo includeva
  -> session show 500 (FileNotFoundError). pip install -e non accettato da pip.
- cd /app/harness && pip install . : pip 26.1.2 rifiuta il path bare /app/harness
- compose: THT_MODEL_API_KEY_FILE per buildPiChildEnv (codex) -> session create
  prima 500 'model provider credential is unavailable'
Verificato: session show 200 (phase 1), create 200, Pi+model+SSE OK.
2026-07-12 21:30:49 +02:00
User 2bd2f72356 Merge origin/codex/portable-deployment into feat/docker-local-deploy
Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream,
security hardening, CI multiarch) mantenendo le fix portal-specific:
- backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream'
- Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g)
  perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello
  secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro.
- config.test.ts: preso Codex (superset)
Verificato: tsc clean, 132/132 vitest.
2026-07-12 21:13:20 +02:00
marcopan 7628eaa579 fix(docker): run real questions through trusted Pi gate 2026-07-12 19:20:10 +02:00
User 5f6647e77a fix(entrypoint): restore server case (lost during doctor->check refactor)
Il caso 'server)' era stato eliminato inavvertitamente: CMD [server]
cadeva nel *) exec $@ -> 'server: not found' (exit 127).
Smoke standalone ora verde: health + config check + db ping (read-only).
2026-07-12 17:17:24 +02:00
User 67d030b24d feat(deploy): docker images, compose, roles SQL, local workspace
- core.Dockerfile: python:3.12-slim + node 22 copied (same bookworm glibc), non-root, tht+pi
- frontend.Dockerfile: vite build (env-driven base/assetsDir) + nginx-unprivileged
- compose.yaml (embedded, omics_network ext, zero host ports) + docker-compose.dev.yml (standalone)
- deploy/sql: thoth_dwh_reader (ro) + thoth_vector_rw (rw) roles
- deploy/thothii.env.example + harness/workspaces/local.yaml (direct DWH+vector, 5438)
- scripts/docker-smoke.sh; .dockerignore; gitignore deploy secrets
- verified: both images build, core health {ok}, config check validates local.yaml
2026-07-12 16:49:03 +02:00
marcopan f67d2c97d8 fix(security): reject invalid optional bundle values 2026-07-12 11:53:15 +02:00
marcopan 449a333365 fix(security): validate bundle and clean runtime secrets 2026-07-12 11:52:02 +02:00
marcopan 70a19f290d feat(compose): use one secret bundle for local services 2026-07-12 11:30:43 +02:00
marcopan e40a9d9a56 fix(backend): inject provider credentials from file 2026-07-12 07:53:22 +02:00
marcopan 4028ef7821 feat(preprocess): add deployment jobs and S3 source 2026-07-12 05:42:07 +02:00
marcopan 3588a7749b fix(vector): harden packaged migrations 2026-07-12 01:32:33 +02:00
marcopan ebdd3aa2c5 fix(deploy): unify backend URL policy 2026-07-12 00:54:39 +02:00
marcopan a3a266fd81 fix(deploy): close container final review 2026-07-12 00:44:39 +02:00