Files
ThothII/.superpowers/sdd/2026-08-03-git-workspace-registry/task-7-report.md
T

3.6 KiB

Task 7 report — revision-pinned sessions

Delivered

  • New-session requests may carry workspaceId, provider, model, and thinking. The backend resolves the active operational registry revision, enforces its LLM policy, and persists the workspace ID/revision with the selected LLM settings.
  • The harness manifest and tht session new support the optional, backward-compatible workspace_id and workspace_revision fields.
  • Resume resolves the manifest's retained snapshot, including after later registry publication. A missing retained revision returns a sanitized workspace_revision_unavailable response. Legacy manifests retain the prior workspace behavior and are marked with a visible warning on GET /sessions/:id.
  • /settings is now a non-mutating compatibility endpoint: installation defaults remain readable, while anonymous workspace/provider/model/thinking selections are no longer written to backend settings or principal preferences.

TDD evidence

  • RED: npx vitest run test/routes-sessions.test.ts test/routes-settings.test.ts failed for the new immutable-snapshot and no-settings-mutation assertions; the manifest test failed because new_session_manifest did not accept workspace revision fields.
  • GREEN: npx vitest run test/tht-runner.test.ts test/routes-sessions.test.ts test/routes-settings.test.ts && npx tsc --noEmit -p . completed with 97 passing tests and a clean type check.
  • GREEN: THT_HOME=/private/tmp/thothii-task7-home .venv/bin/pytest tests/test_session_documents.py tests/test_session_mutations.py -q completed with 22 passing tests.
  • git diff --check completed cleanly.

Verification note

The unscoped backend suite was also run. The Task 7 code regressions in test/tht-runner.test.ts were fixed; the remaining failures were existing sandbox restrictions on tests that listen on 127.0.0.1 (listen EPERM: operation not permitted in SSE/e2e health tests), not application assertions.

Review fixes — round 1

  • Every new session now resolves workspaceId through the registry; an omitted value uses the configured installation default and persists both the resolved ID and revision. Callers cannot bypass revision pinning by supplying a workspace ID.
  • Browser-local preferences now migrate once from the read-only legacy settings response and hold workspace, provider, model, and thinking. Session creation includes those selections, including direct entry points that run before the composer mounts. The frontend no longer PUTs shared settings.
  • The settings compatibility endpoint honors a stored installation workspace before falling back to the first workspace configuration.
  • Resume rejects finalized and archived sessions before looking up any pinned snapshot, preserving the read-only response even when a historical snapshot is unavailable.

Review verification

  • RED: the added backend tests failed for omitted-default pinning, read-only resume ordering, and stored-default precedence; the added frontend preference tests failed because preferences were neither stored nor included in session requests.
  • GREEN: npx vitest run test/tht-runner.test.ts test/routes-sessions.test.ts test/routes-settings.test.ts && npx tsc --noEmit -p . — 100 tests passed with a clean type check.
  • GREEN: npx vitest run && npx tsc -b — 332 frontend tests passed with a clean type check.
  • GREEN: THT_HOME=/private/tmp/thothii-task7-home .venv/bin/pytest tests/test_session_documents.py tests/test_session_mutations.py -q — 22 tests passed (one existing testcontainers deprecation warning).
  • git diff --check completed cleanly.