Unisce gli internals di Codex (secret-bundle, provider-credentials, auth upstream, security hardening, CI multiarch) mantenendo le fix portal-specific: - backend: configPath da THT_CONFIG (fix sessioni) + dataRoot di Codex; authMode 'upstream' - Docker/compose: TENUTO il mio (verificato live: omics_network+alias, env_file, pi npm-g) perche' il compose/Dockerfile/entrypoint di Codex sono accoppiati al suo modello secret-bundle (tht doctor inesistente, secret-policy.sh). Adottabile in futuro. - config.test.ts: preso Codex (superset) Verificato: tsc clean, 132/132 vitest.
69 lines
1.1 KiB
Plaintext
69 lines
1.1 KiB
Plaintext
# === macOS ===
|
|
.DS_Store
|
|
|
|
# === Reference / consultation material (local-only, NOT ThothII deliverables) ===
|
|
ChironeWp3/
|
|
Thoth/
|
|
|
|
# === Visual companion brainstorming artifacts (local-only) ===
|
|
.superpowers/
|
|
.worktrees/
|
|
|
|
# === Python ===
|
|
__pycache__/
|
|
*.pyc
|
|
*.pyo
|
|
.venv/
|
|
venv/
|
|
*.egg-info/
|
|
dist/
|
|
build/
|
|
|
|
# === Node ===
|
|
node_modules/
|
|
|
|
# === Replay bundle (built artifact, like dist/) ===
|
|
tools/replay/web/
|
|
|
|
# === Secrets — NEVER commit ===
|
|
.env
|
|
harness/.env
|
|
deploy/thothii.env
|
|
*.pem
|
|
ca-chain.pem
|
|
config/ca-chain.pem
|
|
|
|
# ThothII deployment configuration and secret values (keep only the README tracked)
|
|
deploy/.env
|
|
deploy/compose.psd-local.yaml
|
|
deploy/workspaces/psd.yaml
|
|
deploy/secrets/*
|
|
!deploy/secrets/README.md
|
|
!deploy/secrets/*.example
|
|
|
|
# === Runtime data (sessions contain PII; indexes are derived) ===
|
|
harness/sessions/
|
|
harness/indexes/
|
|
backend/sessions/
|
|
backend/indexes/
|
|
|
|
# === Test artifacts ===
|
|
.pytest_cache/
|
|
.ruff_cache/
|
|
.coverage
|
|
htmlcov/
|
|
|
|
# === Editor ===
|
|
.vscode/
|
|
.idea/
|
|
*.swp
|
|
|
|
# Playwright MCP run artifacts
|
|
.playwright-mcp/
|
|
|
|
# === MkDocs build output ===
|
|
site/
|
|
|
|
# Generated container inventory / SBOM-equivalent verification artifacts
|
|
.artifacts/
|