pastilhasandClaude Opus 5 e2b0d5c06b edit any text file, and make new ones from the empty panel
Two things, both asked for.

── Open in editor now covers text ──

It was markdown and code only, because `text` is `getFileType`'s FALLBACK and so
also catches binaries. That was the wrong trade: media, archives and pdf are
already claimed by earlier branches, so what actually lands in the fallback is
.txt, .log, .csv, .conf, dotfiles, Makefile-likes and anything with an extension
the platform has never heard of. Refusing all of that to avoid one bad case cost
far more than it saved.

The bad case is named instead of guessed at — a ~40-entry list of extensions that
reach the fallback but are not text (.exe .so .sqlite .docx .woff …). A denylist
that is too short costs one bad render; a `text` test that is too strict costs
the feature. Not a security control: `/file-browser/read` is UTF-8 and capped at
5 MB, so the worst outcome is mojibake.

Checked against 18 names: notes.txt, server.log, data.csv, nginx.conf, .env,
Makefile, script.sh, and an extensionless file all offer it; jpg, mp3, zip, pdf,
exe, so, sqlite and docx all do not.

── New file, from the empty panel ──

Right-click → New file takes a name WHOLE, extension included, creates it empty
and opens it in the editor. The extension is what the editor uses to pick a
language, so guessing one would be wrong more often than not; no extension is
fine and opens as plain text.

It refuses to clobber. `/write` is an overwrite, so creating over an existing
name would silently empty it — the one outcome nobody wants from a menu item
called "New file". There is no stat endpoint, so the check is a read that is
expected to fail.

`prompt()` to match New folder directly above it. Both deserve a real dialog and
neither has one; making this one different would just be inconsistent.

── Verified rather than assumed ──

`getActiveFile()` only matches ALREADY-OPEN files, so a path arriving in the URL
could have landed on an empty editor — the exact silent failure this whole audit
keeps turning up. It does not: CodeEditor.tsx:60-76 fetches and opens an unopened
`?file=`, with an `unreadable` set guarding the retry loop. Confirmed
/code-editor renders with `urlState`, without which the param is ignored entirely.

The param is imported as `EDITOR_FILE_PARAM` rather than written as 'file' twice,
so renaming it cannot leave this behind.

tsgo clean, frontend builds, 808 pass / 7 fail unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-15 19:15:05 +00:00
2026-02-16 19:34:35 +00:00
2026-02-16 19:34:35 +00:00
2026-02-16 19:34:35 +00:00
2026-02-22 03:35:26 +00:00
2026-02-16 19:34:35 +00:00
2026-02-16 19:34:35 +00:00

The documentation, triaged

2026-08-13. A map of what is in here, what it is for, and what should happen to it. Made because there are 42 documents and 13,000 lines, and no way to tell from the filenames which describe the system as it is and which are a record of an afternoon in July.

How much I verified: the classifications below are from filenames, status lines, and greps for things that changed on 2026-08-13. Where I actually read the document or checked the code, it says so. The rest is a starting point for a conversation, not a verdict.


Living — these describe the system and must stay true

doc state
working-on-officer.md updated 2026-08-13. Operational guide.
secret-store.md updated 2026-08-13. Built; rotation still open.
install-variants.md new. The branch tree, for discussion.
http-secure-context-audit.md new. What breaks over plain http.
install-container-testing.md new. First container pass and its findings.
per-user-linux-accounts.md partly updated. OFFICER_OS_USERS is gone; check the rest.
navigation-audit.md authoritative on routing. Unverified against tonight's route removals.
workspace-panels.md + workspace-panel-todo.md the panel framework. 1,300 lines combined — likely the biggest cleanup here.
agent-coordination.md the north star for panel work.
deprovision-os-account.md implemented; the 'disabled' stage it may mention was deleted tonight.

Stale — describe things that changed on 2026-08-13

Each of these references something that no longer exists. Not yet corrected.

  • sidecar-topology.md — "ecosystem.config.cjs is the source of truth". It is generated now, and holds six processes.
  • sidecar-app-store.md — derives the catalogue from full light. Those files are gone, and catalogue.test.ts was rewritten.
  • sidecar-bootstrapping.md — "20 PM2 entries, 18 sidecar dirs". Six entries now.
  • mobile-api-keys.md — partly corrected; recheck the origin-checking claims.
  • wallet-key-custody.mdVAULT_STORE_KEY is now the per-purpose wallet key.
  • push-notifications.md — "agreed design, 2026-07-31". Notify is a plugin and unmounted.
  • chat-session-lifetime.md, chat-ui-walkthrough.md — reference officer-agent, renamed.

Historical — a record of a moment, and should stay one

Do not rewrite these to match today's code. They document how a decision was reached, and editing them destroys the reasoning. If they mislead, add a dated header pointing forward.

  • sidecar-audit-2026-07.md (1,377 lines)
  • claude-sidecar-isolation.md — records the officer-claudeofficer-agent rename that preceded tonight's officer-agentofficer-claude-code
  • open-threads-after-per-user-claude.md
  • two-agent-field-report-2026-08-12.md
  • api-method-changes-2026-08-06.md

The opencode cluster — nine documents for one migration

opencode-fork-decision · -parity · -api-2-assessment · -phase0-review · -phase1-report · -phase1-review · -serve-migration-plan · -serve-path · -testing-checklist

The migration landedopencode serve is in the sidecar, verified. So opencode-serve-migration-plan.md saying "Nothing here is implemented" is false.

This is the clearest consolidation candidate in the whole directory: one document recording what was decided and what shipped, replacing nine that describe stages of getting there. I did not do it because it needs reading all nine, and deleting documents unread is not a thing to do at 4am.

The mobile-dav thread — three documents, one conversation

mobile-dav-provisioning · -feedback · -reply. A correspondence. Almost certainly one document.

Unclassified — I have not looked

design-language-interface · file-sync · jobs-unification · mobile-photo-sync-api · nextcloud-replacement · agent-git-identity


The plugin split, which affects most of the above

A core install is six processes. Everything else is a plugin, switched off tonight but present on disk. Most documents here were written when the estate was twenty processes and every one of them was simply "there", so they describe availability that no longer holds.

The useful rewrite is usually one line, not a rewrite: say whether the thing described is core or a plugin, and if a plugin, that it is not mounted on a fresh install.

S
Description
No description provided
Readme
42 MiB
Languages
TypeScript 90.6%
Shell 4.9%
JavaScript 4.2%
CSS 0.2%
HTML 0.1%