Commit Graph
100 Commits
Author SHA1 Message Date
marcopanandClaude Opus 4.8 f979ada5e7 feat(frontend): open a live session straight to its pending gate
Opening an in-progress session that has a live Pi runtime now reconnects to
its pending gate instead of the empty landing screen that read as "stopped".
Cold/completed sessions keep the read-only documents panel with its explicit
Resume, so a mere click never spawns a runtime. Backend GET /sessions now
reports a per-session `active` flag (live runtime bound) to drive this.

Also:
- "New session" now closes any open session detail panel (left box).
- The model-activity separator can be dragged to a full 50/50 split
  (was capped at 576px); central-min still guards narrow viewports.

Test fixes uncovered along the way:
- Node 25 ships an experimental global localStorage that shadows jsdom's and
  lacks clear(), failing every jsdom test at setup; install a spec-compliant
  in-memory Storage (feature-detected, inert on CI/LTS).
- Fix 4 pre-existing session-mgmt tests that used an ambiguous getByText for a
  session shown in both nav and header; target the nav item by test id.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-17 22:56:12 +02:00
marcopan 6274bf2da0 Merge branch 'feat/per-provider-model-credentials' 2026-07-17 19:31:06 +02:00
marcopanandClaude Opus 4.8 c5fd03ed84 feat(backend): let pi self-authenticate providers from its own auth store
The backend injects a single managed model key (THT_MODEL_API_KEY[_FILE]) as
the selected provider's env var, but that key belongs to one provider — so
selecting a second cloud provider (e.g. DeepSeek while the managed key is zai's)
forced the wrong key onto it and failed auth. This is why the model could not be
switched to DeepSeek.

When the selected provider is present in pi's own auth store
(~/.pi/agent/auth.json), skip injection and let pi resolve that provider's key
itself. Deployments without an auth store (containers) yield an empty set, so the
managed-key injection stays authoritative and fail-fast there. authProviders is
injectable into PiProcessManager for deterministic tests.

Verified live: GLM 5.2, DeepSeek V4 Flash, and aritmolab Qwen3.6 all operate through the ThothII model selector.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-17 18:26:18 +02:00
marcopanandClaude Opus 4.8 c252c95c5f fix(frontend): pin the question as a stable first line during processing
The central column was top-anchored with no fixed header, so the user's
question was never shown while the model worked and the activity/gate
content drifted upward. Render the active session's question as a sticky,
always-present first row of the central area so it stays evident and
anchored at the top of the form.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-17 16:30:18 +02:00
marcopan 7628eaa579 fix(docker): run real questions through trusted Pi gate 2026-07-12 19:20:10 +02:00
marcopan c446d40e1f docs: define local and server Docker deployment 2026-07-12 16:27:05 +02:00
marcopan 08f0029793 fix: finalize session after memory promotion 2026-07-12 14:26:48 +02:00
marcopan f67d2c97d8 fix(security): reject invalid optional bundle values 2026-07-12 11:53:15 +02:00
marcopan 449a333365 fix(security): validate bundle and clean runtime secrets 2026-07-12 11:52:02 +02:00
marcopan 385646d574 docs: complete Docker context settings 2026-07-12 11:50:12 +02:00
marcopan 10465917a5 test(compose): validate bundle deployment contract 2026-07-12 11:48:43 +02:00
marcopan 07967bf589 docs: document one-command Docker installation 2026-07-12 11:44:00 +02:00
marcopan 2ab91b7c0d docs(sdd): record secret scrub review fixes 2026-07-12 11:34:52 +02:00
marcopan 8518a73685 fix(security): scrub raw deployment secret values 2026-07-12 11:34:32 +02:00
marcopan d500563963 fix(security): scrub deployment secrets from Pi child 2026-07-12 11:33:13 +02:00
marcopan 70a19f290d feat(compose): use one secret bundle for local services 2026-07-12 11:30:43 +02:00
marcopan 32a2b71687 build(compose): make root startup the default 2026-07-12 11:14:36 +02:00
marcopan 3807c65a41 test(config): cover secret bundle inode races 2026-07-12 11:09:09 +02:00
marcopan 390cfd24b5 fix(config): accept raw environment secret lookup 2026-07-12 11:07:22 +02:00
marcopan 5fe74612fb feat(config): load one validated secret bundle 2026-07-12 11:06:19 +02:00
marcopan b539303002 docs: plan simplified Docker configuration implementation 2026-07-12 10:59:31 +02:00
marcopan a6b195b8ae docs: design simplified Docker configuration 2026-07-12 10:54:42 +02:00
marcopan 0b65135153 docs: explain loading deploy environment 2026-07-12 10:46:50 +02:00
marcopan 7f8346ff58 docs: keep installation configuration inside ThothII 2026-07-12 10:21:53 +02:00
marcopan e81a250b47 docs: define secret paths before file creation 2026-07-12 10:13:31 +02:00
marcopan 5e345c5567 docs: clarify host and container secret paths 2026-07-12 10:07:39 +02:00
marcopan 7e829a8414 docs: clarify Docker secrets and workspace configuration 2026-07-12 10:04:41 +02:00
marcopan b07f422bb3 docs: add Docker installation guide for four contexts 2026-07-12 09:49:09 +02:00
marcopan 2302286ea1 fix(backend): reject compound provider credentials 2026-07-12 08:10:47 +02:00
marcopan f064daef09 fix(backend): harden provider credential isolation 2026-07-12 08:05:51 +02:00
marcopan 32e73d66b5 docs(preprocess): restore local startup commands 2026-07-12 07:57:17 +02:00
marcopan 72bc50ab2e fix(preprocess): enforce local vector startup chain 2026-07-12 07:54:09 +02:00
marcopan e40a9d9a56 fix(backend): inject provider credentials from file 2026-07-12 07:53:22 +02:00
marcopan ee92ef45ab fix(vector): track packaged migrations in restore smoke 2026-07-12 07:49:58 +02:00
marcopan 09d50ac9bb fix(dwh): release snapshots before job startup 2026-07-12 07:34:56 +02:00
marcopan 4aae6c433d fix(dwh): bind snapshots to validated bytes 2026-07-12 07:31:46 +02:00
marcopan 2f6daaaea6 fix(dwh): anchor generation operations to lease fd 2026-07-12 07:26:10 +02:00
marcopan 24e61d5713 fix(preprocess): retain DWH root fd through lease 2026-07-12 07:12:28 +02:00
marcopan 4cf0adbdd2 fix(preprocess): initialize fresh DWH writers safely 2026-07-12 07:07:31 +02:00
marcopan 22e806a41b fix(preprocess): restrict DWH root claims to writers 2026-07-12 07:00:51 +02:00
marcopan c4dd6c8900 fix(preprocess): claim DWH roots atomically 2026-07-12 06:51:46 +02:00
marcopan 8110793f61 fix(evidence): make result summaries safe 2026-07-12 06:50:23 +02:00
marcopan b43075289e fix(preprocess): bind DWH artifacts to workspace 2026-07-12 06:46:06 +02:00
marcopan 0a2421c513 fix(evidence): bound reports and fail failed jobs 2026-07-12 06:45:19 +02:00
marcopan 03ee3ffda8 fix(evidence): validate active corpus artifacts 2026-07-12 06:35:27 +02:00
marcopan 5cc023f390 fix(evidence): harden unchanged job snapshot 2026-07-12 06:29:31 +02:00
marcopan 7d41c4cefc fix(preprocess): verify canonical generations and cleanup 2026-07-12 06:18:18 +02:00
marcopan 4a29086fe4 fix(preprocess): anchor DWH retention validation 2026-07-12 06:15:27 +02:00
marcopan 27697e5db2 fix(preprocess): ignore corrupt DWH retention entries 2026-07-12 06:11:40 +02:00
marcopan e6d44ba082 fix(evidence): close S3 and smoke safety gaps 2026-07-12 06:09:15 +02:00
marcopan efcb0deb31 fix(evidence): lock GC and preflight search ownership 2026-07-12 06:07:30 +02:00
marcopan d21aac9151 fix(evidence): validate ownership before all searches 2026-07-12 06:04:00 +02:00
marcopan c6966f3d15 fix(preprocess): harden S3 and real Compose jobs 2026-07-12 06:01:06 +02:00
marcopan 950f88f23e fix(evidence): distinguish implicit corpus ownership 2026-07-12 05:59:13 +02:00
marcopan 6bb158233f fix(preprocess): lease DWH generation reads 2026-07-12 05:58:12 +02:00
marcopan db35ddb041 fix(evidence): bind corpus to workspace identity 2026-07-12 05:57:23 +02:00
marcopan 78ff360882 fix(preprocess): reconcile durable DWH generations 2026-07-12 05:51:49 +02:00
marcopan 05accc1443 fix(evidence): isolate vectors by workspace 2026-07-12 05:50:59 +02:00
marcopan 24f6a5daa6 fix(preprocess): publish DWH artifacts atomically 2026-07-12 05:43:57 +02:00
marcopan 4028ef7821 feat(preprocess): add deployment jobs and S3 source 2026-07-12 05:42:07 +02:00
marcopan 6656a69630 fix(evidence): filter active data in every search 2026-07-12 05:40:45 +02:00
marcopan 92b1d3ccc3 fix(evidence): retain referenced vector generations 2026-07-12 05:34:47 +02:00
marcopan 3a9808f126 feat(preprocess): add resumable DWH jobs 2026-07-12 05:34:38 +02:00
marcopan 2624d1d342 test: assert removed evidence stays hidden 2026-07-12 05:26:11 +02:00
marcopan 9a9acbd122 test: gate real pgvector corpus lifecycle 2026-07-12 05:22:30 +02:00
marcopan 9e21cce036 test(evidence): harden generation lifecycle boundaries 2026-07-12 05:15:30 +02:00
marcopan 459ffa0bcd fix(evidence): reconcile generations safely 2026-07-12 05:10:19 +02:00
marcopan f3b49f41c8 feat(evidence): add safe retention and materialized reads 2026-07-12 05:02:47 +02:00
marcopan b6a52995ae fix(jobs): bind completed effects to checkpoints 2026-07-12 04:54:00 +02:00
marcopan c964920f16 fix(preprocess): harden crash recovery integrity 2026-07-12 04:49:15 +02:00
marcopan 1d5f8c76a7 feat(preprocess): resume evidence jobs by run id 2026-07-12 04:39:32 +02:00
marcopan 981b149249 fix(evidence): enforce active vector generations 2026-07-12 04:33:07 +02:00
marcopan b96d4f13b9 feat(preprocess): publish incremental Evidence corpus 2026-07-12 04:26:24 +02:00
marcopan 16a8bd9df6 fix(jobs): validate resume checkpoints before allocation 2026-07-12 04:17:34 +02:00
marcopan 9f069cdd5b fix(jobs): harden resume locks and durability 2026-07-12 04:05:43 +02:00
marcopan a4acee4c70 feat(jobs): add resumable preprocessing envelope 2026-07-12 03:58:37 +02:00
marcopan 11e7ee9ea6 fix(corpus): harden canonical chunk and frontmatter invariants 2026-07-12 03:50:32 +02:00
marcopan 015715d092 feat(corpus): add deterministic normalization and chunking 2026-07-12 03:44:54 +02:00
marcopan d1fdf7d9f5 fix(evidence): bind HTTP validators to final URL 2026-07-12 03:38:11 +02:00
marcopan 81ff1810d1 fix(evidence): harden source acquisition 2026-07-12 03:32:18 +02:00
marcopan ffd683c587 feat(evidence): add filesystem and HTTP sources 2026-07-12 03:23:42 +02:00
marcopan 293d96e1a6 fix(evidence): close canonical contract gaps 2026-07-12 03:15:17 +02:00
marcopan 4424fd3d90 fix(evidence): harden canonical corpus contracts 2026-07-12 03:10:30 +02:00
marcopan d702aad93d feat(evidence): define source and corpus contracts 2026-07-12 03:02:10 +02:00
marcopan 532073d550 fix(deploy): isolate local vector compose secrets 2026-07-12 02:56:00 +02:00
marcopan 6c67235caf fix(vector): close local pgvector final review 2026-07-12 02:48:10 +02:00
marcopan 407c4a6faf fix(vector): publish backups without replacement 2026-07-12 02:32:32 +02:00
marcopan 015c496bda fix(vector): harden backup restore parity gates 2026-07-12 02:29:53 +02:00
marcopan e4db2ea5e1 docs(vector): add local backup restore and parity gate 2026-07-12 02:18:29 +02:00
marcopan 1145ae20bc fix(deploy): align vector bootstrap identity policy 2026-07-12 02:04:57 +02:00
marcopan 144acf2093 fix(deploy): support bootstrap password rotation 2026-07-12 01:57:33 +02:00
marcopan 62e0ff1f12 fix(deploy): reconcile local vector credentials safely 2026-07-12 01:50:42 +02:00
marcopan 0ca9783f61 feat(deploy): add optional local pgvector profile 2026-07-12 01:42:37 +02:00
marcopan 3588a7749b fix(vector): harden packaged migrations 2026-07-12 01:32:33 +02:00
marcopan c0d50e9b08 feat(vector): version pgvector schema 2026-07-12 01:21:29 +02:00
marcopan 409f806aae fix(vector): verify writer sequence privileges 2026-07-12 01:13:56 +02:00
marcopan e7e948c77c fix(vector): harden direct pgvector parity 2026-07-12 01:09:24 +02:00
marcopan b09341f07e feat(vector): add direct pgvector adapter 2026-07-12 01:01:15 +02:00
marcopan ebdd3aa2c5 fix(deploy): unify backend URL policy 2026-07-12 00:54:39 +02:00
marcopan a3a266fd81 fix(deploy): close container final review 2026-07-12 00:44:39 +02:00