Commit Graph
100 Commits
Author SHA1 Message Date
pastilhasandClaude Opus 5 873ccae32a record the defect the useDashboardState tests found
section 9 now carries a concrete instance of its own argument: a test found a bug that
two careful readings of the file had not, in code written three days earlier to prevent
exactly that failure. also records the two bun/testing-library harness facts that cost
more than the fix did, since both present as an unrelated file breaking for no reason.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 14:23:41 +00:00
pastilhasandClaude Opus 5 4f8046d7e9 test useDashboardState, and fix the revert it proved was inverted
the store every dashboard layout is written through had no tests. writing them found
a live defect on its rollback: the guard asked "does the cache still hold what i wrote?"
by reference, and setQueryData runs react query's structural sharing, which rebuilds an
object rather than storing the one it was handed. verified against 5.101.4 — an object
comes back !==, a string comes back ===. so the check was false for every container the
store exists to hold: every layout, every config.agentName. a refused write kept its
optimistic value while the toast said it had been rolled back, and the change vanished at
the next reload. only primitives ever reverted, which is why it went unnoticed.

replaced with a per-key write sequence, which asks the question the identity check meant
to ask — has anything written this key since — and does not depend on identity at all.

14 tests: readValue's kind guard, the optimistic write and its updater composition, and
five on revert including the object regression pin.

also moves testing-library's cleanup into test-setup. it auto-registers afterEach at
module import time, so bun attaches it to whichever file imports the library first and
every later file silently gets none. adding this test file was enough to break fourteen
assertions in DataTable.test.tsx, which does not import it. preload has no file scope, so
registering there removes the ordering from the question.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 14:22:26 +00:00
pastilhas 212903ecd4 correct a stale untested list: two of its four entries already had tests 2026-08-07 14:09:37 +00:00
pastilhas a81b7cfcde record the onSelect widening and what invoiceshelf being unconnected leaves unverified 2026-08-07 14:08:22 +00:00
pastilhas f46a603892 close the last three navigate-only menu items into links 2026-08-07 14:07:38 +00:00
pastilhas 15a960897f record the third sweep: a navigation that goes nowhere 2026-08-07 14:04:14 +00:00
pastilhas 19ba106265 make create dashboard here actually create a dashboard here 2026-08-07 13:58:28 +00:00
pastilhas f4fdc000b2 record the second sweep: opaque clicks a state grep cannot see 2026-08-07 13:21:26 +00:00
pastilhas ea1dae5280 make the invoices dashboard tiles and rows real links 2026-08-07 13:20:22 +00:00
pastilhasandClaude Opus 5 19beafa9dc delete the sidebar theme tokens nothing renders
Sixteen custom properties and eight tailwind color utilities carried over from
the shadcn starter. There is no sidebar component in the repo and no
bg-sidebar/text-sidebar-foreground/... class anywhere, in either theme block.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 13:07:26 +00:00
pastilhasandClaude Opus 5 62b5b1db6f close the navigation audit's cross-cutting section
Records the pattern that came out of the refactor (path segment vs query param
vs stays-a-button), the grep that re-checks it, and the fact that BackButton —
which this section named as a standard building block — was dead and is gone.

Also folds in the two selections the audit never listed: the email folder and
the Soulseek room/peer rails. Neither was in the findings table; both were found
by sweeping for useGlobal<//useState after the listed rows were closed, which is
worth recording as the reason the table alone was not enough.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 13:05:46 +00:00
pastilhasandClaude Opus 5 5a2ef6a0a0 put the soulseek room and chat peer in the url
The last two selections in Soulseek still held in useState. `?room=` and
`?peer=` now own them, the rails are links, and the leave/close buttons stay
siblings of the anchor.

Both rails auto-selected the first entry on load, which is the reason the
selection was local: there was nowhere to put an answer the user had not given.
The bare section is a real state now — nothing open — and both panels already
had the empty pane to say so. Rooms' pane said "Join a room to start chatting"
unconditionally, which was wrong once you could be joined to rooms with none
open, so it now distinguishes the two.

Join and "message a user" stay buttons: each writes something and *then* opens
it, which a link cannot express.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 13:04:19 +00:00
pastilhasandClaude Opus 5 33492262b5 put the email folder in the query string
The last selection still living in a global. `?folder=sent` is now the state,
the folder pills are links, and the open email carries it — a bare
`/email/:id` would have dropped the query string and snapped the list back to
inbox, so the row links and the arrow-key navigate pass it through.

The auto-switch to "all" when the inbox is empty writes with `replace`: it is
the app correcting its own default, not a place you chose to be.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 13:01:04 +00:00
pastilhasandClaude Opus 5 f3538cde25 delete the toaster that could never show a toast, and title the system settings page
`ui/toaster.tsx` was mounted in frontend.tsx and rendered a permanently empty
list: nothing anywhere imports `useToast`/`toast` from `ui/use-toast.ts`. The
app's real toaster is sonner, which is mounted beside it and has four callers.

`@radix-ui/react-toast` stays declared in the two package.json files on
purpose — installs are frozen, and dropping it means a deliberate
`bun install --no-frozen-lockfile` and a read of the lockfile diff.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 12:58:21 +00:00
pastilhasandClaude Opus 5 98636224eb close out the navigation audit's remaining decide-or-skip items
Jobs step deep-link: skipped, and measured first — selectedKey is plain
useState, not a channel, so it breaks none of this document's rules. The only
thing anchor semantics would buy is a deep link nobody asked for.

Preview slug: void, there is no Preview app.

FileBrowser widget: stays local, and M4 turned that shrug into a rule — only a
workspace guaranteed to host one browser may own the address bar.

Phases 1-4 are now closed except H4 and the New Chat button, both of which
live in the chat nucleus.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 12:52:31 +00:00
pastilhasandClaude Opus 5 bbcb041ef3 make open dashboard an anchor, and close the preview-navigate verify
Four navigates were flagged; one was real. The two ProjectPreview lines are
void — Projects was deleted in July. Of the two in DashboardPreview, the
create path writes the dashboard and then goes there, which a link cannot
express, so it stays. The Open Dashboard button in the edit form was pure
navigation and is now a link.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 12:50:59 +00:00
pastilhasandClaude Opus 5 667d622918 make the jobs back button a link, delete the backbutton nobody used
The audit said adopt the shared BackButton. It is not shared: zero importers
since the initial commit, no barrel entry, and a label-plus-underline shape
that fits none of the icon-only back controls here. Adopting it would have
redesigned the Jobs header under cover of a navigation fix.

So: a Link, matching what ScriptJobDetail and DownloadJobDetail already do,
and the dead component goes. useNavigate had no other caller in
PipelineJobDetail and goes with it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 12:48:34 +00:00
pastilhasandClaude Opus 5 39125b5028 let the router decide which nav item is active
Dock, Header and the mobile sheet were computing active state from
useLocation with two copies of the same startsWith helper. react-router's
NavLink already knows. end is set for Home only: without it NavLink treats
'/' as an ancestor of every route, and with it on the others a detail route
would lose its highlight.

Segment matching is stricter than the string prefix it replaces, which is
what was meant all along.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 12:45:59 +00:00
pastilhasandClaude Opus 5 1dc0eddde0 put the open plan in the url, and stop /api/plans reading outside its folder
/plans/:name, no redirect guard: the bare route is 'no plan open', which is a
real state, so the auto-select-first effect is deleted rather than turned into
a Navigate. The picker stays a native select — chrome for one document, not a
master list — but it navigates instead of setting state.

Reading the server route for this turned up a path traversal: hono
percent-decodes params, so GET /api/plans/..%2F..%2Fsecret reached
join(plansDir, '../../secret.md'). basename() the param.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 12:41:55 +00:00
pastilhas 32aa1e7cc3 delete the combobox instead of giving it anchor semantics
audit m7 ranked this medium because "every caller inherits the opaque click". there
are no callers. nothing has imported Combobox since the initial commit, there is no
barrel that re-exports it, and nothing anywhere sets `href` on a SelectOption — so the
navigate, the separator that only appeared for href options, and the href field on both
declarations of the type were all unreachable.

writing anchor semantics into a component that is never rendered is building, not
fixing. the Command primitives it used stay; AIHarnessesSection needs them.
2026-08-07 12:35:58 +00:00
pastilhas 990ead93b9 put the open file in the url on /code-editor
audit m5. the active file is `?file=`, tree file rows and tabs are links, and a
`?file=` naming something that is not open now opens it — which is the part that makes
a pasted link actually work rather than just describe.

the open-tab *set* stays local state and i want that on the record as a choice, not an
omission. it is a working session, not an address: it grows without bound, every entry
costs a read on load, and nobody has ever linked someone else to a tab bar.

opt-in via a prop from the screen rather than the workspace identity the file browser
uses, because /code-editor renders CodeEditorView directly inside a Widget instead of
through the panel wrapper — there is no workspace to ask. a dashboard editor is
unchanged.

tree *folder* rows stay buttons, and unlike the file browser's folders this needs
nobody's call: expanding a directory is disclosure, not navigation.

two things fixed while in here. the tab close control was a role="button" span nested
inside the tab's own button — invalid before, and a nested interactive inside an anchor
after — so it is a sibling button with an aria-label now. and closeFile picked the
next-active file inside a setFiles updater, which is the impurity react double-invokes
in development to catch.

a path that fails to read is remembered, so a broken link errors once instead of once
per render, and the address is left alone rather than rewritten.
2026-08-07 12:34:10 +00:00
pastilhas 5daa598b63 put the browsed folder in the url on /files
the file browser's currentPath was useState, so back and forward did nothing and a
folder could not be linked to. it is `?path=` now on /files, and the breadcrumbs are
real links.

opt-in, keyed on the parsed workspace identity rather than the base path: a dashboard
can hold two file browsers and one shared param would move both, while an unscoped
panel (cwd `~`) sits on dashboards too, so `basePath === '/'` would have caught the
wrong ones.

two things the audit line did not know. `?view=` is ephemeral — useFileViewerPanels
wipes it on mount — so `path` is this screen's first durable param. and four
setSearchParams({...}) calls replaced the whole query string, which would have made
opening any file silently reset the folder to home; they go through a setViewerParams
helper now that carries `path` across.

folder rows stay buttons. cmd/ctrl/shift-click is already multi-select in FileItem and
open is double-click, so anchor semantics collide with a gesture that exists. that is a
product decision, not a defect — written up for the owner rather than guessed at.
2026-08-07 12:28:49 +00:00
pastilhasandClaude Opus 5 ec4aaaae8a put the open task log and the followed run in the url
task-logs was a clean move — the detail fetch already keyed off the id, so only
its source changed. activity needed one decision: its two row kinds stream
through different query params, so the url carries the id and the screen derives
task= or path= from the registry row. the sse effect now depends on that derived
string rather than a fresh object, so the 3s poll cannot re-open the stream. an
id that has left the registry says so instead of waiting for output forever.

/activity also had no page-title rule and read 'Officer'.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 12:19:47 +00:00
pastilhasandClaude Opus 5 a55ea1882a put the open capability in the url
/tasks, /skills and /processes are one component, so one route pair each and the
rows become links. drops the auto-select-items[0] effect: the bare route is the
list with nothing open, which is a real state. editing and the just-created flag
move to ?edit=1 / ?new=1 — a link row cannot reset them on the way out, and
deriving them means navigating to another item clears them for free.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 12:16:11 +00:00
pastilhasandClaude Opus 5 aef8619c6c put the music library location in the url
/music?path=<rel> replaces the music:cwd channel. Each panel reads the param
itself through useMusicCwd(), so MusicBrowser, MusicDetail and FavoritesView
no longer tell each other where they are, and every drill-in is a <Link>:
library rows, folder rows, album/artist cards, both "up" affordances, the
favorites rows, and the dock's now-playing tile. Track rows stay buttons —
they play, which is a mutation.

A query param rather than a nested route because the location is only one of
the things this screen holds (the lyrics split and the favorites view are the
others), and a splat has to be a route's last segment.

MusicPlayerHost is mounted outside <Routes> and used to write the channel and
then navigate('/music') to make the write visible — the audit's only
navigate-with-a-side-effect. That collapses to one <Link>.

music:resync (a refresh signal) and music:favorites (a view of one panel) stay
channels, deliberately.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 12:08:04 +00:00
pastilhasandClaude Opus 5 374140d3a6 put the previewed browser tab in the url
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 11:56:45 +00:00
pastilhasandClaude Opus 5 6c47cbeb74 make the email url the selection instead of a mirror of it
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 11:51:45 +00:00
pastilhas fd923bb9be give the soulseek workspace a url
The section is /soulseek/:section — nav entries are NavLinks, the view panel reads the same
URL instead of being told, and the dashboard's tiles and recent searches are real links (a
recent search now opens that search, not the search screen's front page).

The peer went in `?user=<name>` rather than the /soulseek/users/:name the audit sketched: a
second path segment would need a nested route just to keep the nav highlight, and `?search=`
had already set the convention there. That deletes the `soulseek:user` channel and with it a
`{username, nonce}` request the Users panel consumed-once and cleared — the nonce existed so
asking for the same peer twice counted twice. A link is idempotent, so there is nothing to
consume and nothing to disambiguate.

`soulseek:refresh` stays: it is a signal, which is what channels are for.
2026-08-07 11:45:33 +00:00
pastilhas 00332e275a put the monitor scope in the url
/system-monitor/:scope, the same shape as /photos: route pair, one Navigate guard after the
hooks, scope list as react-router NavLinks, and both panels reading useParams instead of
agreeing over a `monitor:scope` channel. The Dock's isActive is a startsWith, so its
highlight survives the redirect off the bare route.
2026-08-07 11:41:16 +00:00
pastilhas 2502c33804 put the settings section in the url
Five settings pages moved from a `*_SELECTED` global to `/settings/:page/:section`. The
sidebar entry is a react-router `<NavLink>` rather than a button holding the key in its
onClick closure, so a section is linkable, cmd-clickable and gets its active state from the
router; each page renders one `SettingsRoute` guard that canonicalises both the bare route
and a section that does not exist.

Integrations needed more than the shared factory. It builds its own sidebar, and it kept the
Enterprise/Personal tab in a second global — which is why a deep link to a Personal section
could never have worked: the link set the section, the tab stayed on Enterprise, and the
content pane said "Select a section" about a section that existed. The tab is derived from
the section key now.

Also removes the `/settings/resources` menu item (audit M8) and its two locale keys: there
has never been such a route, so it bounced to the catch-all and out to `/`.
2026-08-07 11:38:21 +00:00
pastilhas 98ba61f135 record the sweep commit 2026-08-07 11:26:39 +00:00
pastilhas b419af32de sweep the dead code in section 8
Each item re-verified before deleting; three of the ten entries were stale
and are corrected in place rather than silently fixed.

- WorkspaceLayout's isMobile/mobilePanelId/onMobileBack: none of its ten
  callers set them, so the mobile collapse they fed was permanently off in
  that renderer. WorkspaceView passes the same props to WorkspaceRenderer
  itself, where they are live.
- fixedHeight on AppRegistryEntry, and getFixedHeight with it: no app has
  ever declared one, so it only contributed undefined. The flex-column
  branch it shared with fitContent stays, keyed on fitContent alone.
- getDefaults: getAllDashboardState already folds the defaults row into the
  one payload the client fetches, which is why it never got a caller.
- upsertScreen's terminals/hostTerminals: never read is right, never
  written was not — it inserted them, which is why all 15 rows hold {}.
  The columns are left in place; dropping them needs a db:push, and this
  tree holds another agent's uncommitted schema file.
- SELECTED_DASHBOARD_KEY: H2 (01365cb) replaced it with ?selected= four
  months ago and it has had no reader since.
- ui/sidebar.tsx and the stray ui/hooks/ beside it. use-mobile was not
  orphaned as claimed — the sidebar imported it — and the use-toast in
  there was a near-identical copy of the live one.
- findChildById's unreachable duplicate condition, and the doc comment that
  described the wrong behaviour rather than the code being wrong.

Left deliberately: DragOverlay/LayoutEditor (gated on 5.3, an owner
decision) and the two chat-owned channels, whose docs are fixed here even
though the publishers are not mine to delete.
2026-08-07 11:26:33 +00:00
pastilhasandClaude Opus 5 f2ae10bd36 mark 5.10 resolved
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 11:15:00 +00:00
pastilhasandClaude Opus 5 c9735580fc declare panel channels once, and fix the bump that could lose a refresh
Four channels were bare string literals repeated across files, with the payload type supplied by each
caller. Neither hole errors: a typo yields a different, empty channel — publisher publishing into nowhere,
subscriber waiting forever — and a publisher and subscriber can simply disagree about the payload with
nothing to check them. defineChannel(name, initial) returns the hook, officerdev/src/channels.ts declares
the four, and every usePanelChannel call site in the repo now passes a shared constant.

files:refresh-signal was bumped two different ways: Date.now() at the Chat sites, setSignal((n) => n + 1)
at the FileViewer ones. The increment is wrong — useGlobal's functional setter applies against the value
captured at render, so two bumps in one render window both compute snapshot + 1 and the second writes the
same number as the first. Nobody re-reads and the file that was just written stays stale. Date.now() has
the same flaw at millisecond scale, and the four FileViewer sites (save, delete, extract, transcribe) sit
close enough to hit it. useFilesRefresh's bump is a module counter that never reads React state, so it is
right however many times it is called between renders, and it is identity-stable through a ref because
useGlobal's setter is a fresh closure every render and this goes into dependency lists.

system-settings:run-command is deleted. It had a writer once — 7c0b11c wired the AI harness installer to
it — and when that install moved server-side to POST /server-settings/chat-providers/install the write
went with it, leaving a channel whose only remaining writes were clears, a terminal pane nothing could
open, and a second layout nothing could select.

PanelComponentEntry's component, header and provider are typed with { panelId: string }, which is what
PanelSlot has always rendered them with. A no-prop component is still assignable, so no screen changed.

chat:active-session and preview:refresh are declared but still have no subscriber. preview:refresh has no
plausible one — the PreviewProvider that read it is gone from the repo — but both are published by the
chat panel, and that is not this branch's to change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 11:14:55 +00:00
pastilhasandClaude Opus 5 30fcab2bd3 mark 5.6 resolved, and stop three docs claiming a channel that has no publisher
The todo entry said the file-viewer registration was dead; tracing it confirmed that and turned up the
reason it looked alive — the ephemeral file viewer is a different mounting path entirely. Recorded, with
what was checked in the database before deleting anything.

CLAUDE.md, navigation-audit.md and workspace-panels.md all listed FILE_VIEWER_CHANNEL among the
legitimate refresh/signal channels. It never had a publisher, and no longer exists.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 11:07:36 +00:00
pastilhasandClaude Opus 5 9fcc9c278a seed the registries before render, and delete the dead file-viewer app
`<AppRegistry />` and `<WidgetRegistry />` seeded through `useGlobal`'s `initialData`, which is not a
write: it applies only to whichever component reads the slot first. They worked entirely by sitting
above `<App />` in frontend.tsx — any WorkspaceView that rendered first would have created the slot as
`{}`, with no second chance, and drawn every panel on that screen as an empty box.

Both are now plain functions taking the QueryClient, called before createRoot().render(). They take the
client rather than running as a module-scope side effect because the app list imports every panel app
and every panel app imports the Workspace framework; keeping the call in frontend.tsx, the one module
that is nobody's dependency, is what stops that being an import cycle. Making useAppRegistry default to
the static list was the obvious fix and is exactly that cycle.

registerApp and registerWidget go with the components. Nothing ever called either, and a registry that
can be added to at runtime is a registry whose contents depend on what has mounted so far.

Separately: officerdev/file-viewer was a registration for a provider fed by a `file-viewer:<panelId>`
channel that nothing writes, with availableOnPanel: false so it could not be picked either. The file
viewer users actually see is an ephemeral panel from useFileViewerPanels, which supplies the body and
header itself and reads the path from the URL. No stored layout referenced the key — zero rows across
dashboards, screens, dashboard_defaults, user_state and user_settings — so the meta and its wrapper are
deleted rather than repaired.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 11:07:26 +00:00
pastilhasandClaude Opus 5 04ccb05b2c mark the effect-hygiene items resolved, and correct two of them
Two entries in 5.7 were wrong. HostTerminalWrapper was fixed in c92b51c, when
all three wrappers moved onto useTerminalSession — the item had simply not been
re-read since. And useTaskRunner does not abandon a running task: `stop` is sent
from the modal's Stop button, and closing the socket kills the process tree
server-side. Both were written from the hook alone without following the call
into the modal or the executor.

VideoPlayer and the remaining VideoPlayer-shaped case are left alone on purpose,
with the reason written down rather than the item deleted.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 10:57:10 +00:00
pastilhasandClaude Opus 5 c0fae47cc7 release what a panel was holding when it goes away
The microphone was the loud one: DictateDialog's teardown was guarded by
`if (!showDictate)`, which can never be true, because a cleanup sees the props
of the render that registered it and only the open render registers one. So it
never ran, and the mic, the AudioContext and the rAF loop stayed alive for the
life of the tab. useAudioRecording had no unmount cleanup at all — closing a
Chat panel mid-recording did the same thing, with no way to switch the
recording indicator back off. Both now release on unmount; the second is pinned
by a test that records, unmounts, and asserts the track stopped.

The rest is the same shape. Two sockets registered a listener once and held the
first render's callback forever — usePipelineRunner's carried a captured
streamingText, so a re-render mid-run would have folded every later event into
a stale buffer. PanelSlot built its default header as a component *type* inside
render, which React cannot match against the previous one. WorkspaceView handed
every panel a fresh context object on every render, including each frame of a
maximize animation.

VideoPlayer's comment claimed a dependency list that the code did not have; the
list is fine (sendReport never changes identity) and the comment now says why
that has to stay true.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 10:56:58 +00:00
pastilhas e2017cbbf2 correct 5.2: the key was never the cause 2026-08-07 10:46:31 +00:00
pastilhas 56ca411cf3 a panel is no longer remounted for stopping being second
The remount table in todo §5.2 was reasoned from the code and never observed, so
this mounts the real WorkspaceRenderer against a mount-counting probe and lets
the real layout-utils mutators produce the "after" tree. Eight cases.

It found one the reading had missed, and it is the cheapest of the lot. ChildEntry
returned `<>{children}</>` for the first child and `<><Handle/>{children}</>` for
every other, so the panel sat in fragment slot 0 when it was first and slot 1
when it was not. Remove the leftmost of three panels and the second one finds a
ResizableHandle in the slot it used to occupy — different element type, so React
unmounts a panel that nothing happened to. Scroll position, media playback, a
transcode, and for a chat panel a re-read of the durable log, all thrown away
because a neighbour was closed. Now the handle slot is always there, holding null
when it is not needed.

The other cases confirm what the doc said but for a different reason. Splitting
against the parent direction, and a two-child group collapsing, both change the
element *type* at that position — PanelSlot becomes ResizablePanelGroup, or the
reverse. React reconciles by type before it looks at keys, so the "reuse the id
so the key doesn't flip" fix the doc proposes would not have moved either one.
2026-08-07 10:45:59 +00:00
pastilhas 34b40cb094 mark preserve-sibling-sizes resolved 2026-08-07 10:41:32 +00:00
pastilhas abea7a3a3d splitting one panel no longer resets the whole row
splitInner and insertPanel both ended with `100 / newChildren.length` applied to
every sibling, so splitting any panel in a group discarded every proportion in
it. A deliberately narrow sidebar became an equal column the first time anyone
split the panel next to it — and there was no way to get it back except by
dragging the splitter again.

The new sibling now takes half of the target's size and nothing else moves. One
helper for both call sites, because the drop path (movePanel -> insertPanel) had
the identical bug and would otherwise have kept it.

Three tests. Two of them were already there asserting the even split, written
against the old behaviour on purpose; they now assert the new one. The move test
is new and documents the interaction worth knowing: removePanel renormalises the
group when the panel leaves, so a move reads as renormalise-then-halve.
2026-08-07 10:41:21 +00:00
pastilhas 4ce7839b31 mark the panel-id and registry-key items resolved 2026-08-07 10:38:59 +00:00
pastilhas 6fd60e59c4 one way to mint a panel id, and a registry that cannot silently lose an app
Two second implementations, both removed rather than fixed.

DashboardPreview minted template panel ids with its own module-level counter,
tpl-1, tpl-2, no entropy, reset every page load. Two dashboards built from
templates in the same page load held panels with identical ids — and a panel id
is not decorative any more: agent_panels addresses an agent by
(dashboardId, panelId), and terminal-conn-<panelId> and file-viewer:<panelId>
key persisted state by it. The templates now call the core uid(), which is
exported from the Workspace barrel for the first time so there is one minter.

metasToRegistry is Object.fromEntries, so two apps sharing a key means one app
stops existing and every panel holding its appType renders the other. The todo
asked for a throw in dev; a throw takes down every dashboard at runtime for a
mistake made at edit time, so this is a test over the real meta list plus a
console.error. All 44 keys are unique, and the test now says so rather than the
doc.

Getting the real list into a test needed test-setup.ts to provide localStorage:
MusicPlayer/useLyricsOpen.ts reads it at import time, so the whole app graph was
unimportable from a test. That unblocks testing anything that pulls in a panel
app.

Also deletes officerdev/src/useAppRegistry.ts — a stub returning {} with a
different shape from the real hook, imported by nothing.
2026-08-07 10:38:52 +00:00
pastilhasandClaude Opus 5 3ab57a5839 measure what a handoff actually survives
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 10:32:18 +00:00
pastilhasandClaude Opus 5 df00f6d7a5 tier b has no unblocked work left
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 10:16:09 +00:00
pastilhasandClaude Opus 5 49b635a489 drop §5.4's default-layout collapse, and say why
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 10:15:58 +00:00
pastilhasandClaude Opus 5 cd1f1616c4 stop editing a dashboard's name from resetting its panels
The edit branch of the dashboard form rebuilt the layout from the template on every submit, then wrote
it. So renaming a dashboard, or fixing a typo in its description, silently threw away however its
panels had been arranged and whichever apps were in them. The template is a seed picked once at
creation; it is not a description of the dashboard as it now stands. It is now only re-applied when
the user actually picks a different one.

A rename also dropped `ws-terminals-<id>` and `ws-host-terminals-<id>` without carrying them over, so
every shell the dashboard held was abandoned: the panels came back empty and the processes stayed
alive with nothing pointing at them. Both maps now move to the new key with the layout.

The order those keys go into the PATCH body is load-bearing and now says so — the server walks the
object in insertion order, `ws-layout-<new>` upserts the row while `ws-terminals-<new>` only updates
one, and `ws-layout-<old>: null` deletes. Written the other way round the terminals 404.

Verified against the running server rather than by reading: seeded a dashboard with a layout and both
terminal maps, sent the rename PATCH exactly as the client now builds it, and read the rows back —
layout, terminals and host terminals all arrived under the new id and the old row was gone. The
no-op case (same id, same template) now writes nothing at all instead of PATCHing the layout back to
itself.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 10:15:30 +00:00
pastilhasandClaude Opus 5 d546717676 note the unguarded screens are done too
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 10:10:32 +00:00
pastilhasandClaude Opus 5 653201f268 pin the app types on the four locked screens that had none
The allow-list existed on fourteen screens and was missing from every other one, which the previous
commit turned from fifty lines into one. These four are locked — the user cannot change what is in
the panel — so an appType that stops resolving strands them on the empty teal box in PanelSlot with
no picker and no way back.

Checked against what is actually persisted rather than against the defaults: `screens/desktop` holds
`officerdev/desktop` and `screens/files` holds `officerdev/file-browser`, both already inside the
list they are now being given. `screens/terminal` and `screens/dashboards` have no row at all — those
screens have never been opened on this machine — so they seed from the default, which also matches.
Nothing is rewritten by this.

Browser and Email stay unguarded on purpose. Their panels resolve through `components`, which
PanelSlot keys on the *panel id*, and their layouts carry `appType: null` — the app type is never
consulted, so pinning it would pin nothing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 10:10:14 +00:00
pastilhasandClaude Opus 5 99ee9dbb88 record §5.4's first item as landed
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 10:07:33 +00:00
pastilhasandClaude Opus 5 1de1d925a5 make the appType allow-list a prop instead of fourteen copies
Every locked screen shipped the same recursive normaliser: an ALLOWED_APP_TYPES set, a
normalizeLayout, a useMemo to apply it before the wrong panel could render, and a useEffect to
persist the fix. Fourteen copies, character-for-character identical except the two names — so a
fifteenth screen was a copy-paste, and a bug in the shape was a bug in fourteen places.

It is now `<WorkspaceView appTypes={{ allowed, fallback }} />`. WorkspaceView normalises before it
renders and persists the diff itself, which is the same two effects the screens were writing by hand.

One deliberate behaviour change: the framework normaliser drops `config` when it replaces an app.
The fourteen copies did `{ ...node, appType: fallback }`, keeping the old app's config on the panel
the new app now owns. That is the opposite of what `setApp` does, and a config belongs to whoever
wrote it.

Headscale keeps a local useMemo. Its check is not "is this appType allowed" but "is the server
picker present at all" — a layout saved before that panel existed is discarded for the default
wholesale. That is about a panel being missing, which the allow-list cannot see.

QrTransfer gains a persist-back it never had: it normalised on read and threw the result away every
time.

Tests: normalizeLayout is pinned on reference-identity for a no-op, null always allowed, config
dropped on replacement, rebuilding only changed branches, and idempotence — because a normaliser
that does not normalise to itself makes the persist-back an infinite write loop.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 10:06:59 +00:00
pastilhas 2c84bb34be say which shells nobody is looking at
The sidecar has always sent `clients` on each session and this list has always dropped it, so a shell
you are typing into and a shell nothing is attached to rendered identically. It is now on the type,
shown as "N attached", and a zero earns the row an orphan badge — the count only helps if you do not
have to read it to notice.

Also records §5.1 and the whole of §1 in the todo, including that the diff-the-layout implementation
§5.1 used to propose is struck and why.
2026-08-07 09:58:04 +00:00
pastilhas c92b51cacb kill a terminal's shell when its panel is actually closed
Three wrappers held three copies of the same `panelId -> sessionId` bookkeeping, and one of the three
still had the unmount cleanup the other two had removed: `HostTerminalWrapper` dropped its map entry on
every layout or route change, minted a new uuid on the way back, and left the host shell running with
nothing pointing at it. All three now share `useTerminalSession`, which forgets the session and kills
the shell from `usePanelClose` — a real close, and nothing that merely looks like one.

The kill request goes to `/terminal/_officer/sessions/:id`, which is also a fix. `RunningShells` was
asking for `/terminal/sessions`; the proxy strips `/api/terminal` and forwards the rest verbatim, and
the pty sidecar only answers under `/_officer`, so that route 404s. Verified against the live sidecar:
`/sessions` returns `{"error":"not found"}` and `/_officer/sessions` returns the list. The panel has
therefore always read "No shells running" and its kill button has always been a no-op — which is why
the orphaned shells it exists to surface were never actually visible.
2026-08-07 09:55:50 +00:00
pastilhas 198dc71137 give panels a close signal that only fires on a real close
A panel that owns something on the server — a pty, a lock — has had no way to be told it was closed.
`TerminalWrapper` says so in a comment: it cannot kill on unmount, because a drag, a swap, a mobile
panel switch and a genuine close are the same event from inside the component.

So the signal is raised where the intent is, not where the teardown is. `usePanelClose(panelId, fn)`
registers a handler; `WorkspaceView` fires it from `handleRemove` and from `handleSetApp` when the app
actually changes, and from nowhere else. Registration is deliberately never torn down — "unmounted" is
the ambiguous signal being replaced, so honouring it would reintroduce the bug — and handlers are
stamped with the workspace they were registered on so one dashboard's panel id cannot fire another's.

`findPanelApp` is what tells a real app change from re-picking the app already there, which `setApp`
treats as a no-op; without it every pick from the app menu would close a panel that never closed.

No app uses the hook yet. The terminals come next; a chat panel deliberately never will, since a chat
panel is a pointer to a server-side session and closing the window must not delete what it points at.
2026-08-07 09:52:40 +00:00
pastilhas 04371a9d99 pin why a layout diff cannot answer "what closed"
The panel-close signal (§5.1) was going to be a before/after diff of the layout tree — the todo
document says so. It cannot be. `movePanel` inserts through `newPanelFrom`, which mints a fresh
`uid()`, so a dragged panel's id is gone from the new tree while its app is still on screen; and
`swapPanels` exchanges `{appType, config}` between two ids that both stay put, so a swap reads as
two closes and two opens. Everything downstream of a close signal is destructive — a pty killed, a
session released — so a mechanism that fires on a rearrangement is worse than none.

Two tests, no production change. The signal has to be raised where the intent is known, at
`WorkspaceView`'s `handleRemove`/`handleSetApp` call sites.
2026-08-07 09:49:41 +00:00
pastilhas fed2badd28 record the close of §5.9 2026-08-07 09:43:30 +00:00
pastilhas ca046a3876 build the inert context once instead of twice
`WorkspaceLayout` and the `createContext` default each spelled out the same eleven fields — every
interaction a panel can start, switched off. Two hand-written copies of one list is a list you fall
behind: adding a field to the context type only errors at the call site if it is required, and both
copies have to be found.

Named it. `inertInteraction` is what "this tree cannot be rearranged" means, and both places spread
it. `cwd` and `root` stay out of it deliberately — they say where the workspace is rather than what
can be done to it, and the inert renderer has no answer for `root`: its consumers only read it when
`cwd` is scoped, which no caller makes it.
2026-08-07 09:42:25 +00:00
pastilhas d3922bd9d3 stop couriering a system prompt through the framework
`promptPrefix` was a workspace-context field: the email and browser screens set it, `WorkspaceView`
put it on the context, and `ChatPanelWrapper` read it back off. Only the chat app has ever understood
what the string is, so the framework was carrying an app's vocabulary between two places that both
know each other.

`components` already exists for this — a screen supplies its own component for a panel id, and
`PanelSlot` prefers it over the registry while still taking header and provider from the registry
entry, so a screen-mounted chat panel keeps its normal chrome. Both screens now do that, and pass the
prefix as a prop. `ChatPanelWrapper` is exported from the barrel for it.

Also removes the same prop from `WorkspaceLayout`, where it had no callers at all: every preview and
settings pane rendering through it was already handing its chat panels an undefined prefix.
2026-08-07 09:40:47 +00:00
pastilhas b1e0bac1e0 record the first three items of §5.9 2026-08-07 09:36:27 +00:00
pastilhas 585f234b5b take out the props the previous commit orphaned
`initialPath` and `defaultSort` reached `FileBrowserApp` from nowhere else — the panel wrapper was
their only caller, and it was passing the two context fields that had no setter. Both remaining
callers pass neither, so the whole chain below them was already running on its defaults.

That includes `isolated`, which was `!!initialPath` and therefore always false: the unscoped browser
has been mirroring its folder into `files/currentPath` unconditionally, which is what the comment
beside it describes. Same behaviour, one fewer flag that reads as if it sometimes fires.
2026-08-07 09:35:03 +00:00
pastilhas 717580f6e4 stop the framework carrying file-browser vocabulary
`initialFilePath` and `defaultFileSort` were declared on the workspace context, plumbed through
`WorkspaceView`'s props and read by exactly one panel wrapper — and set by zero callers. The sort
shape in particular (`{field: 'name'|'size'|'type'|'date', direction}`) is file-browser vocabulary
sitting in the framework's type file and re-exported from two barrels, so every app that imports the
context could see it.

Nothing changes at runtime: both were always undefined, which is what the wrapper now passes by
omitting them.
2026-08-07 09:33:33 +00:00
pastilhas dbe585fd72 stop handing apps a key to reverse-engineer
`dashboardId` in the workspace context was `workspace.key` — `ws-layout-<id>` or `screens/<name>` — and
three apps parsed its format to work out what they were mounted on. It is now `workspace`, a
`{kind, id, key}` parsed once by the framework.

The key survives on the result and is still what gets stored: `agent_panels.dashboard_id` holds it, so
the wire value is byte-identical and no named agent orphans. `kind` and `id` are for deciding.

Two behaviour changes fall out. An unrecognised key is no longer treated as a dashboard — the old
`!startsWith('screens/')` test called anything that was not a screen a dashboard, which would have let a
panel register an agent against a workspace with no row to hang it on. And `ChatPanelWrapper`'s
`dashboardId === 'email'` branch is gone: it compared against a bare id no producer ever emits, because
the only writer is `WorkspaceView` and the only other one, `WorkspaceLayout`'s `dashboardId` prop, was
passed by zero callers. That prop is deleted.

Also here because it is the same defect as b0a32ae one file over: `WorkspaceLayout`'s resize handler
computed a tree from a captured `layout` and `WorkspaceRenderer` debounces it 500 ms. Updater now.
2026-08-07 09:29:34 +00:00
pastilhas b1ec1e19a7 record the close of §4 2026-08-07 09:24:23 +00:00
pastilhas 92b89052a4 make a layout column refuse a non-layout 2026-08-07 09:24:16 +00:00
pastilhas 2efd7ffba3 record §5.5 and the close of tier a 2026-08-07 09:19:59 +00:00
pastilhasandClaude Opus 5 81ad3ef5ef let two windows onto the same dashboards agree again
The dashboard-state cache had staleTime: Infinity and there is no invalidateQueries anywhere in the
repo, so it was fetched once per page load and never again: two windows diverged permanently and neither
was ever told. It now refetches on focus — with three non-default guards, because this cache is
optimistic and a refetch that started before an in-flight PATCH landed would overwrite the value we
already showed. Never on mount (splitting a panel mounts a fresh consumer, which is exactly when a write
is in flight), never on reconnect, and on focus only after a short quiet period with nothing in flight.

The PATCH stopped assembling a full state blob it then returned to nobody — three SELECTs per splitter
release, thrown away, and a caller that did read it would be reading state assembled before whatever
concurrent write it raced.

And the last three `.catch(() => {})` in this family are gone: dashboard create, rename and delete build
their own multi-key patches and so bypass the hook. They now go through persistDashboardState, which
keeps the in-flight bookkeeping honest and, on failure, invalidates rather than reverts — there is no
single previous value to swap back once the roster has been rewritten, and a refetch is the only thing
that makes the list agree with the server. A failed delete used to leave the dashboard gone from the list
and alive on the server, reappearing at the next reload with no hint why.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 09:15:55 +00:00
pastilhasandClaude Opus 5 b0a32ae473 compose layout writes against current state, not a captured tree
Every mutation in WorkspaceView computed its new tree from the `layout` its callback closed over, and two
of the paths are not immediate: the resize debounce fires 500 ms after the drag began, and a window
resize fires onLayout on every group at once. So the later write was computed from a tree that predated
the earlier one and silently undid it — remove a panel just after dragging a splitter and it came back.

Worse now that panel identity lives in the layout: the resurrected tree carries an older `config`, so a
panel that was just given an agent's name reverts to anonymous and the agent stops being addressable
through it. All eight now pass an updater to setValue, which composes against the current cache.

The debounce timer also had no cleanup at all, so it outlived the component. It now flushes on unmount
rather than dropping — with an updater the early write is correct, and dropping would lose a splitter
drag made just before navigating away, which the no-cleanup version did at least persist.

Neither file is prettier-clean at HEAD, so neither was formatted; the new code is written to match.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 09:12:06 +00:00
pastilhasandClaude Opus 5 d24f3faa5f record §4: the boundary, validate-on-read, and the layout default
Tier A now has only §5.5 left — the resize debounce and the stale cache.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 09:09:22 +00:00
pastilhasandClaude Opus 5 ef036dfcd5 stop handing the client a layout it cannot use
The layout columns defaulted to '[]' — an empty array for a column whose only legal contents are a
LayoutNode object — and every upsert that omitted a layout wrote it. Creating a dashboard from the
dashboard list is exactly that path, so the key came back present, the client's `key in state` check
preferred it over the caller's default, and normalizeLayout called .children.map on it and threw.

Three layers, because none of them was enforcing anything:

- the columns are nullable with no default: NULL means "none stored", which is the truth
- getAllDashboardState omits the key when what is stored is not an object, so rows written before this
  are repaired by the next write rather than crashing the read
- useDashboardState checks kind-compatibility before casting jsonb to T, and falls back to the caller's
  default when it does not match. Only object-shaped defaults are guarded — a wrong primitive is a
  cosmetic surprise, a wrong container is a crash.

Verified against the live DB: creating a dashboard with no layout no longer emits a ws-layout key, and
a row hand-set back to '[]' is omitted too.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 09:08:15 +00:00
pastilhasandClaude Opus 5 64961d49f5 catch render errors instead of showing a white screen
The repo had no error boundary anywhere, so a single malformed stored layout took the whole app down
and the only recovery was a psql session. Two boundaries, because "recover" means different things:

- around the routed screen in DashboardLayout, with the dock and header deliberately left outside so
  navigating away is itself a way out, plus a two-click reset of every `screens/*` layout for when it
  fails again in the same place. Dashboards are not touched — they are user-created and hold content.
- around each panel app in PanelSlot, so one bad app leaves the rest of the workspace running. Its
  recovery is "clear this panel", offered only when the layout is the user's to edit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 09:04:03 +00:00
pastilhasandClaude Opus 5 30eef86972 record what landed: A1, A2, the tests, and what tier A has left
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 08:57:13 +00:00
pastilhasandClaude Opus 5 f4ed7401da stop the dashboard PATCH dispatcher losing writes
Four defects, one shape: a write that returns 200 and lands nowhere.

- Unknown keys were dropped by a chain of `if (match) continue` with no `else`. The three prefixes
  CommandTerminalWrapper actually writes — tmux, nvim, claude-code — were among them, so those panel
  maps lived in the React Query cache only: every reload minted a fresh uuid and abandoned a running
  pty. They now live in a `panel_state` bag on the dashboard row, and an unmatched key 400s.
- `ws-terminals-{id}: null` fell through to an upsert, writing NULL into a NOT NULL column on a live
  dashboard and re-INSERTing a deleted one. Renaming a dashboard sends exactly that, paired with
  `ws-layout-{id}: null`, so the old slug came back as a zombie row in the dashboards list.
- HostTerminalWrapper and CommandTerminalWrapper built their state key straight from `dashboardId`,
  which is a workspace *key* (`ws-layout-<id>`), while TerminalWrapper stripped the prefix. The server
  read the un-stripped form back as a dashboard id and created it. One rule now, in state-key.ts.

Verified against the live server: unknown key 400s, the three prefixes round-trip, a null on a live
dashboard is a no-op, and the rename sequence leaves no zombie.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 08:55:01 +00:00
pastilhasandClaude Opus 5 70c2f0811d stop swallowing dashboard persist failures
The optimistic cache made a refused write invisible: the UI stayed correct until the next reload, at
which point the change was simply gone. That is tolerable for a pane size and not for a chat panel's
agent name, which is the address a peer agent is delivered to.

Roll back only if the cache still holds exactly what we wrote — writes to one key overlap freely (a
window resize fires one per group) and rolling back over a later successful write would turn one
failure into two.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 08:48:44 +00:00
pastilhasandClaude Opus 5 85452d1afa test layout-utils, and stop setApp leaking one app's config to the next
47 tests, the first under any Workspace path. These functions carry a panel's
identity now, so a regression in swapPanels is two agents exchanging names,
not a cosmetic glitch.

Writing them found one: setApp preserved config whenever appType was not null,
so changing a panel from chat to terminal handed the terminal the chat's
{agentName} to read as its own settings. The comment beside it already stated
the opposite intent. Not reachable through the UI today — the picker only
appears on an empty panel, so the only route out of an app is via null, which
does clear it — but setApp is exported and its signature permits the direct
swap. Now only a same-app set keeps the config.

Also pins two things as expectations rather than folklore: a move drops zoom
and fitContent (todo 5.3, to fail the day that is fixed), and a split
redistributes sibling sizes evenly (todo 5.5).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 08:44:15 +00:00
pastilhasandClaude Opus 5 ecc7fb90d8 rank the panel defects against the objective, not against severity
The re-rank the north star deferred, done now that the MVP is built and
running — so it is ranked against what the mechanism turned out to need.

The finding is that most of the list is not on this path. The mechanism is
server-side and a panel is a pointer to it, so a remount, a re-render or a
drag costs a replay, not a session. Section 5.2 and 5.3 are large downgrades;
5.3 was on the critical path when the north star was written and is disarmed
by resolving identity by name.

What is left is small and mostly one defect wearing four hats: a write that
silently does not land. Panel identity lives in the layout jsonb now, so the
swallowed persist catch, the dispatcher's missing else and the two debounce
lost-updates each become a panel that forgets which agent it is — invisibly,
for exactly as long as nobody is looking.

Also corrects two items the MVP made stale, and promotes layout-utils tests:
e588524 put agent identity inside those mutators and shipped them untested.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 08:40:33 +00:00
pastilhas 678d29b574 refuse a duplicate agent name in the panel, not in a 500
The server's uniqueness check is the one that matters, but its 409 currently never fires
(the constraint name is on err.cause, not in the DrizzleQueryError message), so a collision
came back as "Internal Server Error". The address book is already in hand here — checking
it first turns the common case into a sentence the human can act on.

Diagnosis of the server-side bug, with the patch, is in COMMS/agent-panels-split-2026-08-07.md;
that file belongs to another agent and is still uncommitted, so it is theirs to apply.
2026-08-07 08:31:03 +00:00
pastilhas bc8208622c a chat panel can be a named agent with one session forever
The panel remembers its agent's NAME in its own layout config, not the server row's panel
id: movePanel mints a fresh id on every drag, so an id-based lookup forgets the agent the
first time the dashboard is rearranged. The name travels with the panel contents; the row
is found by name and re-anchored to wherever the panel now is.

A named panel passes the row's sessionKey to useChat instead of letting the server mint a
throwaway uuid per connection. That is the whole of continuity: the same key comes back on
every load, resume-cursor replays the durable events under it, and the claude sidecar
resumes the same transcript from its write-through map even after the session was reaped.

Its cwd comes from the row too, because deliverToAgentPanel already runs an incoming
handoff there — otherwise the same agent would work in two directories depending on
whether the human or a peer spoke to it.

Only on real dashboards. The fixed screens keep anonymous chat panels exactly as before.
2026-08-07 08:29:20 +00:00
pastilhas e58852412a give a panel its own settings, and carry them when it moves
A panel can now hold an opaque config blob that the framework stores, moves and deletes
but never reads. It lives on the layout node for the same reason zoom does: the layout is
already persisted per panel and server-side, so a panel's configuration outlives the tab
and is deleted exactly when the panel is.

swapPanels and movePanel now exchange { appType, config } as one unit. They used to carry
only the app type, which would have silently reset a configured panel to defaults on a drag.

Apps read it through usePanelConfig(panelId); PanelSlot already passes panelId to every
registry app, so nothing else in the framework had to change.
2026-08-07 08:20:24 +00:00
pastilhasandClaude Opus 5 7c99429872 write down the north star: agents coordinating with each other
docs/agent-coordination.md is the objective the workspace/panel work serves —
several agents on one dashboard handing work to each other instead of routing
every step through the human, with the human authoring the workflow at the top.
Written from the owner's own words during the 2026-08-07 conversation; where a
section records a decision, that decision is his.

It settles the questions that were blocking: sessions may be reaped and resumed
from the durable sessionKey→claudeSessionId map (no heartbeat), the address is
the human-assigned panel name rather than the panel id, roles are prompts rather
than features, and the protocol is turn-boundary-only by construction — which
routes around the mid-output restart failure instead of fixing it.

Cross-referenced from CLAUDE.md, workspace-panels.md and workspace-panel-todo.md
so it is findable from any of them. The todo is still ordered by defect severity
and now says so; the re-rank against the objective is deferred, not forgotten.

Also corrects two items dated 2026-08-08 to the day they were actually found.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 06:58:01 +00:00
pastilhasandClaude Opus 5 5bdb2474ea fold every turn but the live one
A conversation is turn-based: your message, the work, the answer, repeat. The
moment you send the next message the tool calls and running commentary that
produced the last answer stop being what you are reading and start being what you
are scrolling past. So every turn but the live one collapses to three parts —
what you asked, one summary row, and what I concluded — with the summary naming
what you gave up ("5 tool calls · 2 messages · 1 failed") so you can tell whether
you want it back. Failures are counted on the summary rather than only inside,
because a red row you have to open to find is a red row you never find.

It is a pure derivation over the message list rather than state, which is what
makes a reload render identically to a live session: no wire format, no
persistence, no server change. Dividers and compaction seams split a fold instead
of disappearing into one, because "5 tool calls" hiding a /clear misreports what
happened to the conversation rather than to the work.

A turn that ends cleanly without saying anything gets a marker row. It happens
rarely and is disproportionately confusing — the composer re-enables and nothing
appears, which is indistinguishable from a turn that died. Deliberately a seam and
never prose: words in my voice that I did not write are a lie, and the next time it
happened you would not know which kind of row you were reading.

Fold-open state lives in the list, not the fold, because rows are virtualised and
state inside one would be thrown away when it scrolled past the overscan window.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 05:10:33 +00:00
pastilhasandClaude Opus 5 969b2f3762 show compaction as it happens and open tool calls while they run
Compaction was the one thing the harness does that emitted nothing at all while it
ran, and it can run for minutes — silence that reads as a hung turn, which costs a
server restart to discover it wasn't. The sidecar now reports both ends: the start
from the PreCompact hook, the finish from the compact_boundary message with the
token count, both durable so a reload or a reconnect still sees them.

Tool rows open themselves while they run and hold for five seconds after their
result, so the inputs are on screen at the moment the call is made rather than
after the fact. The clock lives outside React, keyed by tool call id: rows are
virtualised, so unmounting is not the call ending, and a fast call can render its
start and its result together — a row that only opens when it catches the pending
state never opens for exactly the quickest calls. A click outranks the clock for
as long as the row lives. A failure behaves identically and differs only in colour,
so it stays findable by scanning and nameable in conversation.

Shell logs move off the green-on-black pre onto the shared code surface, which is
the one block that had no copy button and the one you most often want to hand to
someone else.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 05:10:22 +00:00
pastilhas ce7968ac90 document how the workspace/panel framework works 2026-08-07 04:10:36 +00:00
pastilhas 33d55121cd stop escape from un-maximizing a panel 2026-08-07 03:42:52 +00:00
pastilhas 0af4b6f4d1 keep a maximized panel legible and amber its button 2026-08-07 03:31:28 +00:00
pastilhasandClaude Opus 5 91898733a4 stop parsing request bodies on sidecar proxy routes
every multipart upload through /api/<sidecar>/* arrived corrupted. bodyParser ran on
proxy routes and called parseBody for multipart, so hono cached a FormData on the
request; when the proxy then asked for the bytes hono re-serialised them from that
cache with a NEW boundary, while the proxy still forwarded the ORIGINAL content-type
header. header and body disagreed and the far side rejected it with
"Multipart: Unexpected end of form".

bodyParser now skips prefixes owned by createSidecarProxy, which register themselves
so a new sidecar cannot forget. the proxy also forwards the body as a stream instead
of buffering it, which drops the second in-memory copy of every upload.

note the bug report proposed skipping multipart in bodyParser outright; that would
have broken /upload, /file-browser upload and /bug-report, which do read a multipart
body from ctx.get('body').

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 03:22:37 +00:00
pastilhas 50484521dd add useSessionState and persist the maximized panel per tab 2026-08-07 03:10:44 +00:00
pastilhasandClaude Opus 5 fc40beca68 make a collapsed tool row say something
Five Bash rows in a trace read `cd /home/…/platform && git status…`, `echo "=== server-side…`,
`echo "=== opencode handler…` — cut, every one of them, exactly where they started being useful. Two
things conspired. The summary showed the head of a compound command, which is usually scaffolding: a
`cd` into the repo, or an `echo` labelling output for a human. And both `slice()` and CSS `truncate`
drop the tail, which is where the identity lives — the filename that distinguishes ten Reads sharing
a directory, the target a command acts on.

So skip a leading `cd`/`echo` up to its `&&`, and pin the tail as its own non-shrinking span so the
head ellipsises and the cut lands in the middle at whatever width the panel is. Both are display
only: expanding the row, and the copy button, still give the command verbatim.

The right margin traded `done` for what the call found. Success was the loudest colour on the row
and reported the least interesting fact about it, once per row; a failure still earns its red. In its
place the count that used to cost an expand to learn — `no matches`, `12 lines`, `3 files`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 03:09:11 +00:00
pastilhasandClaude Opus 5 ba664dc5c8 per-panel content zoom for every panel
soulseek had a zoom control wired into its own panel header, persisted
under its own screens/ key. move it into the framework so every panel has
it, and drop the soulseek-specific copy (its header was then identical to
the default, so that goes too, along with the orphan db row).

the factor lives on the LayoutPanel node rather than in its own
useDashboardState key: the layout is already persisted per panel, and a
separate key would seed a server row per panel on mount. absent at 1, so
an untouched panel adds nothing to the stored layout.

uses css zoom, not transform: scale. a transform repaints at a different
size without re-laying out, so the panel keeps its 100% geometry and
anything anchored or percentage-sized lands wrong — chat's composer made
that obvious. zoom scales used lengths instead: children reflow, h-full
still resolves to the panel, and rem-based tailwind text scales with it.

@container moves onto the zoomed element so container queries respond to
the effective width, the way they would in a genuinely narrower panel.

zoomable: false opts out the terminals (xterm measures its own cell grid)
and remote desktop (novnc does its own scaling and pointer mapping).

fixes chat's virtualiser under zoom: it measured bubbles with
getBoundingClientRect (rendered px) but positions them with translateY
(layout px), so at 70% every bubble was placed too early and they stacked.
new helpers/measure-zoomed divides the element's currentCSSZoom back out.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 02:58:25 +00:00
pastilhasandClaude Opus 5 575b4a5966 add a living todo for the workspace/panel framework
the framework has no tests, no error boundaries and a handful of known
defects that keep resurfacing mid-feature. write them down once, ranked,
so they can be picked off in the context of whatever is being built.

notable: the dashboards PATCH dispatcher silently drops any key family it
has no branch for, and three in use today (tmux, nvim, claude-code, all
from Terminal's statePrefix) match nothing — so that state never persists.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 02:58:16 +00:00
pastilhasandClaude Opus 5 6d0d103c78 carry attached images through to the model
The composer already uploaded an image, split its data URL and put the bytes on the wire as
`images`. Nothing on the server read them. The `chat` ClientMessage had no such field, and the
prompt reached the sidecar as a bare string, so all the model ever saw was the client-generated
`[Attached image: …]` placeholder — a label describing a picture it was never shown.

The transport was never the obstacle: `query()` consumes an async iterable of user messages whose
`content` is an Anthropic `MessageParam`, and only `pushTurn` hardcoding a string kept it to text.
So `images` is threaded through the four hops that dropped it and turned into native image content
blocks at the end, renaming `mediaType` to the API's `media_type` at that last step.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 02:54:39 +00:00
pastilhasandClaude Opus 5 5134501a2f walkthrough: the tab-name clone check was a guess
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 02:27:12 +00:00
pastilhasandClaude Opus 5 ff5095e71f a tab name should survive coming back to the page
The clone check keyed off `navigation.type`, which only reports `reload` for F5/Ctrl-R. Every other way
back into the app — Enter in the address bar, a link, re-opening the URL after the server was down — is
`navigate`, and threw away the name you typed.

Ask instead of guess: each tab holds an id beside its name, and a copy is a tab whose id is still held
by a live tab, which the original says over a BroadcastChannel. A refresh has nobody to answer.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 02:26:37 +00:00
pastilhasandClaude Opus 5 66fca28927 retry a turn the agent restart cut off
the cut-off notice is its own event now rather than an error: nothing is broken
and nothing is lost but the turn, so the row says what happened and offers the
one action that fixes it. the conversation is already durable — the claude
session id is written through to disk and passed back as resume: — so retry
just resends the prompt on a session the fresh agent picks up with full
context. read back out of the transcript, so a second window on the same
session can offer it too.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 02:00:16 +00:00
pastilhasandClaude Opus 5 876b39b301 end a turn whose agent has gone
restarting officer-agent takes every persistent session with it and nothing
downstream notices: the browser's socket is healthy, officer's subscription is
a bus filter, and there is simply never another event. the spinner ran forever
and a refresh didn't help, because the transcript has no ending to read.

keyed off the agent *registering*, not disconnecting — a disconnect fires on
every `pm2 restart officer`, when the turn is fine. a registration socket dies
with its process, so an agent appearing on it is a new one. covers the sitting
tab; the reconnect path covers the rest, with the client now sending its belief
that a turn is in flight and officer checking it against the agent over a new
claude:is-generating. the check fails toward alive.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 01:43:01 +00:00
pastilhasandClaude Opus 5 d8ee678ec4 let members sign in to the platform, which is the entire point
signin refused any non-owner arriving through the web or mobile platform
origin: "This account can only sign in through its app." so a member could
hold a gitea grant and still never reach a page — verified as a live 403
before this change.

that rule was correct while single-user was the invariant. the only
non-owner accounts were music-app accounts, and there was no way to say
"this person may use the platform, but only these parts of it", so keeping
them out entirely was the honest answer. capabilities say exactly that now,
per feature, at both doors and on every request.

so superAdminOnly is retired rather than patched. the web origin and the
platform app get no path scoping — what their caller may reach is decided by
their role, not by their Origin. per-app path scoping stays for the
single-feature apps (music, vault, tail), where it still means something.

note this WIDENS who may sign in: any Active account can now authenticate
through the browser. that is the intended product change, and it is only
safe because the capability backstop runs on every request behind it —
which is why it lands after that, not before.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 01:36:07 +00:00
pastilhasandClaude Opus 5 f283ebcba3 code block copy button is always visible
hover-revealed means most people never find it, and touch has no hover at all.
70% white on the dark block, brightening on hover; the pre reserves right
padding so a long first line scrolls up to the button instead of under it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 01:35:50 +00:00
pastilhasandClaude Opus 5 6a682fae98 copy button on every code block
the bubble's copy button copies the whole reply, which is the wrong unit when
the reply is prose ending in one command to run. fenced blocks get their own
button; inline code doesn't. text read from textContent at click time rather
than the markdown ast, trailing newline stripped so a pasted command doesn't
run itself. the positioned wrapper takes the vertical margin, or the pre's own
margin collapses through it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 01:22:57 +00:00
pastilhasandClaude Opus 5 29fc9722c1 interrupted by user, not an error
pressing stop ended the turn with "Claude Code returned an error" — the agent
sdk reports interrupt() as an ordinary failed result, indistinguishable from a
real fault downstream. the sidecar now flags the session it interrupted and
rewrites that event to the existing durable 'stopped', which opencode already
emitted. escape stops the turn (bound to the chat subtree, not the document),
and the prompt comes back to the composer verbatim unless you've started typing
something else. history parity: claude files [Request interrupted by user] as a
user message, so the transcript reader maps those exact strings to the same
role instead of replaying them as something you typed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 01:18:57 +00:00
pastilhasandClaude Opus 5 f3a3ae3b64 capabilities: send the denied routes too
the server half of the previous commit, which belonged with it. the frontend
guard needs both lists: absence from `routes` cannot tell a route this
account lacks from a route no capability claims, so without this the guard
permits everything.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-07 01:01:01 +00:00