Commit Graph
199 Commits
Author SHA1 Message Date
marcopan f6e4dbcae2 feat(auth): add safe Argon2id local user registry 2026-08-16 18:24:20 +02:00
marcopan f99bddcdf0 fix(auth): restore permission boundary safeguards 2026-08-16 18:03:36 +02:00
marcopan 2e0489ce22 feat(auth): centralize ThothII permission enforcement 2026-08-16 17:52:03 +02:00
marcopan 23ac75ce1d fix(auth): declare local development environment 2026-08-16 17:36:42 +02:00
marcopan e54ce15426 fix(auth): fail closed configuration compatibility 2026-08-16 17:35:40 +02:00
marcopan a66ef58766 feat(auth): define strict installation authentication config 2026-08-16 17:26:31 +02:00
marcopan d464f3a982 build: align authentication runtime on Node 24 2026-08-16 17:13:55 +02:00
marcopan bd42aa5934 test: verify read-only workspace secret flow 2026-08-14 18:05:28 +02:00
marcopan a94df262f4 fix: preserve deterministic runtime secret leases 2026-08-14 17:47:17 +02:00
marcopan 87cefd120c feat: configure workspace runtime secrets through API 2026-08-14 17:30:35 +02:00
marcopan 2114c94704 feat: derive workspace runtime secret requirements 2026-08-14 17:26:39 +02:00
marcopan e4999c8420 feat: add encrypted workspace secret store 2026-08-14 17:23:23 +02:00
marcopan 747020a330 feat: declare workspace repository in installation config 2026-08-14 16:32:58 +02:00
marcopan 9db4463a83 refactor: remove workspace publishing and bundles 2026-08-14 16:28:01 +02:00
marcopan 42e02f8b1c refactor: make workspace repository strictly read only 2026-08-14 16:20:08 +02:00
marcopan db1a81cfa6 fix: surface reviewer response failures 2026-08-14 12:06:25 +02:00
marcopan 9d7e9a05b7 fix: resolve diagnostic paths under the base path prefix and tolerate health-style ping responses 2026-08-13 20:58:10 +02:00
marcopan f31b1e61ac fix: upsert in bounded chunks, recreate Qdrant indexes on rebuild, larger maintenance tmpfs 2026-08-13 19:02:52 +02:00
marcopan f09ab2b8c6 test: expect filesystem Evidence materialization in the canonical snapshot 2026-08-13 12:38:53 +02:00
marcopan 871de800f0 feat: make filesystem Evidence operational after materialization (P6) 2026-08-13 12:35:25 +02:00
marcopan bb2eabceb6 feat: activate commit-addressed Evidence materialization with an integrity chain (P6) 2026-08-13 12:34:56 +02:00
marcopan 0c9e614100 feat: bounded Evidence materializer with manifest and atomic publication (P6) 2026-08-13 12:31:12 +02:00
marcopan 0c1033889a feat: safe Evidence tree enumeration and bounded blob streaming (P6) 2026-08-13 12:28:49 +02:00
marcopan d751188db7 feat: gate FK review on the accepted revision blob (P5) 2026-08-13 05:08:19 +02:00
marcopan 0459a6cd3e feat: operator schema accept command for curated FK review (P5) 2026-08-13 05:06:23 +02:00
marcopan 5249798c03 feat: revision-qualified annotations root for pinned runtimes (P5) 2026-08-13 05:02:19 +02:00
marcopan 259d5a0374 feat: atomic revision-qualified annotations sync with ownership manifest (P5) 2026-08-13 04:58:56 +02:00
marcopan b00b7f17c9 feat: read and validate curated FK annotations at the pinned commit (P5) 2026-08-13 04:56:03 +02:00
marcopan e056c19e62 feat: P4 qdrant collection lifecycle (self-heal + guarded rebuild)
- shared TS collection manager: self-heal creates missing collection (1024/cosine)
  and missing keyword payload indexes; never mutates incompatible contracts
  (semantic_index_incompatible); async index visibility polled with bounded deadline
- session admission (qdrantEnsure) uses the manager in self-heal mode; operator path
  keeps require_existing semantics
- runtime lease exposes semanticQdrantUrl to the operator
- operator commands vector-inspect/vector-rebuild with exact confirmation guards
- thothctl workspace vector inspect|rebuild (Go) with --collection/--confirm/--destroy
- p4 acceptance runner: real Qdrant (v1.18.2) lifecycle checks, 11/11 PASS
- docs: CLI contract, manual walkthrough P4 (PENDING), PROJECT_STATE
2026-08-12 20:00:14 +02:00
marcopan e23e526966 feat: P3 effective configuration, memory root, and revision-scoped records 2026-08-12 16:01:25 +02:00
marcopan ad3c3125a8 fix: expose catalog identity as a sha256 content digest 2026-08-11 19:25:04 +02:00
marcopan 82b5453c88 fix: use sha256 descriptor digest and keep operator errors fully sanitized 2026-08-11 19:24:15 +02:00
marcopan f7c2b69837 feat: P2 operator, preprocessing state/service, and runtime config lease 2026-08-11 18:40:11 +02:00
marcopan 7ce25894a2 feat: reconcile generated docs on explicit registry pull 2026-08-11 16:19:10 +02:00
marcopan 5446885006 test: cover the P1.1 registry deployment contract 2026-08-11 15:11:48 +02:00
marcopan 25ec236f1f feat: activate workspaces from the root catalog and bootstrap-only publication 2026-08-11 14:49:46 +02:00
marcopan 86af45acb4 refactor: enforce P1.1 registry path ownership 2026-08-11 14:29:00 +02:00
marcopan 7356d6794b docs: add P1.1 workspace directory plan 2026-08-11 14:22:28 +02:00
marcopan edef085fea test: replace legacy workspace deployment fixtures 2026-08-10 23:21:27 +02:00
marcopan fa24f43fd4 refactor: remove workspace migration utilities 2026-08-10 21:32:01 +02:00
marcopan c2f9b03973 refactor: remove legacy workspace runtime branches 2026-08-10 21:28:08 +02:00
marcopan f102629cee refactor: remove workspace revision state 2026-08-10 20:54:40 +02:00
marcopan 512b0261b1 refactor: make workspace descriptors schema v3 only 2026-08-10 20:21:20 +02:00
marcopan 4d6e91526d test: prove P1 configuration process end to end 2026-08-09 20:51:20 +02:00
marcopan 4b329b4b2c test: expect canonical secret binding paths 2026-08-09 20:50:53 +02:00
marcopan ba7596c2dd fix: tighten evidence artifact guarantees 2026-08-09 20:12:42 +02:00
marcopan 212c973e3b feat: preserve evidence in workspace artifacts 2026-08-09 20:03:28 +02:00
marcopan 64b778ade9 test: strengthen evidence runtime handoff coverage 2026-08-09 19:46:47 +02:00
marcopan 36fbd58277 feat: render revision-bound evidence configuration 2026-08-09 19:39:03 +02:00
marcopan 3b9681a63a fix: harden evidence secret file handoff 2026-08-09 19:27:52 +02:00