From the first agent-conversation e2e against a live hub:
- install.md: git handoff for tracked knowledge folders (one transport per
folder), .bdrive//.bdriveignore git guidance, Hermes per-user hook warning,
drop stale share--list aside
- SKILL.md: .bdriveignore is local-only on --shared mounts (root file sits
outside the include list) — doc now matches behavior
- new project skill .claude/skills/onboarding-e2e: reusable procedure to
re-run the conversation-level e2e (staging, instruction materialization,
agent prompt contract, verification, pass bar)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
bdrive log preferred Op.Author (git/OS identity) even when the op carried the
hub account (Op.User/UserName), so team history showed local git emails.
Found by the agent-onboarding live e2e: device signed in as e2e-bot showed
snow@runbear.io in log. Now: UserName → User → Author. bdrive status likewise
shows 'signed in as Name <email>' when a session exists.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
- login copy across README/skill/commands: bare `bdrive login` (BearDrive
Cloud) is the default; signup auto-creates a free personal workspace,
pending invites route into the team; self-hosted hubs pass a URL
- init flows propose a detected knowledge folder (wiki/docs/notes/handbook/
vault) as --shared instead of asking open-endedly; repo-root rule restated
- install always ends by handing the user a `bdrive url` link to a
representative page — the activation moment
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
Two viewer features plus the security fix the second one surfaced:
- Missing file/folder paths now get a not-found view: the path, and the
hint that a just-created file may still be uploading or syncing from a
teammate's device — the tree polls every few seconds so it appears on
its own, plus a Check again button that refetches immediately. The
topbar's share/download actions no longer show for nonexistent files.
- Opening an .html file renders it as a page (sandboxed iframe,
allow-scripts only) instead of showing source text.
- SECURITY: /api/file was already serving synced HTML inline as
text/html on the hub origin with session cookies — a stored-XSS
surface reachable by direct navigation, previously masked only by the
viewer showing HTML as text. Inline HTML and SVG responses now carry
'Content-Security-Policy: sandbox allow-scripts' (the same wall as
/s/* share pages); downloads are exempt (attachments never execute in
the hub origin).
Tests: Go CSP-header matrix (html/svg sandboxed, md clean, download
exempt); e2e: sandboxed-iframe rendering incl. in-frame content + CSP
assertion, and the not-found → late-upload → Check again flow. 44 specs
green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Field report follow-up: an agent with a stale skill copy couldn't find
the gated URL after creating a file. Instructions rot; hook output is
computed fresh from the binary every turn. Claude Code's turn-start
pull hook now runs 'bdrive sync --hook claude-code', which:
- pulls as before, and stamps the session note from the event JSON
(replacing the sh/sed pipeline for the pull leg)
- emits the project's gated-link formula as UserPromptSubmit
additionalContext: whenever the agent mentions a synced file path in
prose, it appends the hub link on an emoji — `<path>` [🔗](<url>) —
path plain (it's the local path), hyperlink on the emoji only; code
blocks stay plain; bdrive share stays explicit-opt-in-public
Blind-tested: an agent given only the injected context decorated every
path mention correctly, kept the code-block command plain, and checked
files were synced before linking.
- hooks install now CONVERGES marker-identified groups to the current
shape (command/matcher/flags), so improvements reach existing
projects on reinstall instead of being frozen by the idempotency
marker; hermes same
- plugin: UserPromptSubmit → beardrive-pull.sh (stdout passes through);
version 0.3.0
- SKILL 'Share what you make' generalized to 'Link what you mention'
(URL formula documented for non-Claude platforms); install.md pointer
template updated
Never fails the turn: every error path in --hook mode is a silent
successful exit; offline still emits (links serve online teammates).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
A leading YAML frontmatter block used to render as goldmark's
thematic-break soup (hr + stray text). It now renders as a compact
table: keys in the author's order (yaml.Node, not a map), flat lists
comma-joined, nested values as compact YAML in <code>, everything
HTML-escaped. Anything that isn't a well-formed YAML mapping — mid-doc
fences, unclosed fences, list-shaped or invalid YAML — falls through
and renders exactly as before; empty frontmatter is simply hidden.
Applies everywhere the server renders markdown: the hub viewer and
public share pages, each with theme-matched styling. Matters most for
OKF/gbrain-style frontmattered knowledge bases.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
'Share with the team' must show the product's actual default: the
permission-walled bdrive url viewer link (sign-in + membership), with
the public /s/ link as an explicit opt-in — matching the skill's
'Share what you make' rule shipped in v0.7.0. The old mockup had Claude
minting a public link unasked, contradicting the shipped behavior.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
From the reviewer's focused 'good enough to grow?' pass:
- og:image now points at raw.githubusercontent (resolves today;
beardrive.ai doesn't yet) with width/height so link-preview cards —
the top of a reshare-driven funnel — actually render
- the two real, previously-unused screenshots are embedded: browse.png
(read heat + change feed) under the how-it-works architecture card,
share.png inside the Share-by-URL step — real proof next to the
stylized mockups
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Rounds 5 and 6 both scored 9/8/9/9/8/9 with zero repo-fixable
blocker/major findings — the exit bar (two consecutive passes) is met.
Round 6 truth-verified the loop's copy against the code (commands,
Insights sections, hook platforms, url format — all accurate; zero
fabricated proof). Post-exit optional minors applied: og:image +
twitter card meta on the site, SKILL login-cell waitlist parity.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Zero repo-fixable blockers/majors; all four round-4 surfaces verified
fixed. The two optional minors applied: the README command-table login
cell and SKILL's init cell now carry the waitlist-only caveat inline.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Reviewer round 4 (9/6/9/9/7/9) caught that round 3 only fixed the
Quick start: the bare-login default survived in the four highest-
traffic surfaces. All inverted to self-host-first:
- README HERO code block (+ the other-machine one-liner and the
every-other-device shorthand): bdrive login https://your-hub, with
Cloud as a clearly-labeled waitlist callout
- plugin/commands/install.md + init.md step 2: ask for the team's hub
URL; bare 'bdrive login' explicitly flagged as targeting the
not-yet-open Cloud
- SKILL.md walkthrough step 1 + the hub-example comment
- website hero terminal animation: 'syncing → your team's hub', share
URL on a neutral acme-hub.example host (og:url and the coming-soon
card untouched — those are honest)
- README's login reference sentence now says the beardrive.ai default
is waitlist-only
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Reviewer round 3 (9/7/9/8/7/9) caught the sharpest truth bug yet: the
README quickstart's bare 'bdrive login' defaults to beardrive.ai, which
is waitlist-only and not accepting logins — a launch-day visitor's
first command would fail silently. Fixes:
- quickstart step 1 now routes to self-hosting ('bdrive login
https://your-hub', ~10-minute guide linked) with Cloud honestly
framed as waitlist; website closer promises 'Self-host in one
binary' instead of 'under a minute, done'
- handoff gains a P0 gate: verify the FULL first run (login → init →
edit → log) against a working hub before any launch; bare 'bdrive
login' must not be advertised until Cloud accepts logins
- handoff: seed 3-5 good-first-issues (CONTRIBUTING promises them);
replace the mailto waitlist with a real form before Product Hunt
- README trimmed 583→524 lines: the Authentication and Choosing-a-
database operator reference moved verbatim into docs/self-hosting.md
with a compact pointer left behind
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Reviewer round 2 scored 8/7/9/8/8/8 with one repo-fixable major left:
three deeper website spots (storage strip, architecture card, bring-
your-own-storage card) still implied a hub-less direct-to-bucket mode
that v0.3.0 removed — all rewritten to the hub-on-your-storage reality;
themes-preview.html's five retracted 'no server required' strings fixed.
Also: install-path verification added to the handoff P0 and the launch
prep checklist (a 404 brew tap on launch day is fatal); README
credentials table now says the s3/gs/file rows are hub-operator storage,
never client remotes; the agent promise now leads on both README and
website (people-sharing supports it); share.png re-captured against a
real rendered runbook (headings/table/code) instead of a one-line stub.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
GTM reviewer round 1 (baseline: positioning 6, funnel 4, open-paid 8,
community 3, launch 3, metrics 2; 3 blockers + 3 majors, all repo-fixable):
- TRUTH: removed the false 'no server required' claim (x3 on the
website) and stale 'S3/GCS directly' sync claims in both plugin
manifests — hub-only since v0.3.0
- POSITIONING: one line everywhere ('the open-source Google Drive for
AI agents' + the attribution/read-analytics wedge) across README,
website, marketplace.json, plugin.json, SKILL.md; third 'Why' card
and AGPL-why rationale; nav CTA → Star on GitHub
- COMMUNITY: CONTRIBUTING.md, issue forms + PR template, public dated
ROADMAP.md, CHANGELOG.md seeded from all 8 releases
- DEMO ASSETS: real product screenshots captured from the seeded demo
hub (Insights treemap, browse-with-heat, public share page) embedded
in README + website — no fabricated content anywhere
- DOCS: self-hosting quickstart, metrics plan (north star: active
shared brains), launch-plan drafts (Show HN/PH/launch week), and
docs/gtm-handoff.md — the prioritized external-action checklist
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Web-researched persona: a maintainer-turned-managed-cloud-GM grounded in
the a16z three-fits framework (project-community -> product-market ->
value-market), the Supabase/PostHog-era playbooks (positioning-as-
unlock, launch weeks, generous-free-tier PLG, docs-as-marketing), and
COSS failure modes (rug-pull relicensing, resented open-core lines).
Reviews README/website/plugin/docs as funnel surfaces plus the AGPL +
managed-service line, scores six dimensions with evidence, and returns
a stage verdict, replacement copy, and a 30/60/90 plan.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
New command printing a file's hub viewer URL: sign-in + project-org
membership required to open (the internal counterpart to bdrive share's
public links). Computed locally from the mount config — hub origin +
project id from the remote, path segments percent-encoded with literal
slashes; unsynced paths (ignored, or outside a --shared scope) are
refused so nobody gets handed a 404. --sync pushes first so a
just-created file's link resolves immediately; no arg = project home.
The plugin docs now instruct agents to include this link in their reply
whenever they create a shareable artifact (.md/.html/.csv/...) in the
shared folder, reserving bdrive share for people outside the hub:
SKILL.md command map + 'Share what you make' guidance, install.md root
pointer template + payoff step, README, CLAUDE.md.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Desktop right-aligns Search/Share/⋯ via #meta's flex:1 spacer, but the
mobile styles hide #meta — nothing absorbed the middle space, so the
buttons sat next to the breadcrumb mid-bar (user-reported). On <=900px
the crumb is now the spacer. Verified at 390px: ⋯ right edge at 382/390.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Rounds 4 and 5 both scored every category >=8 with zero high-severity
findings — the exit bar (two consecutive passing designer rounds) is
met. Post-exit cleanup: restore id=search-btn dropped in the React port
so the existing mobile rule hiding the ⌘K badge matches again. Two
remaining observations recorded as won't-fix in the spec with reasons.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Designer round 4: all categories >=8, zero high or medium findings, all
seven round-3 fixes confirmed with measurements. Residual lows fixed for
the confirmation round: insights lens chips, guide tabs, and modal text
inputs to 44px on mobile; at <=430px the share dialog's destructive
Revoke takes its own row instead of sitting 9px from Done.
All responsive CSS on the same URLs — no mobile-specific routes.
42 e2e specs green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Designer round 3 FAILED the bar (6/6/7/9/6, one high) — it caught a
regression my round-2 fix introduced: .ai-main { overflow-wrap:anywhere }
let flex min-content collapse invite/share URL rows to one character per
line at 360/390 (496px-tall rows). Streak reset. Fixes:
- H1: on mobile the admin row's name/URL takes the full row
(flex-basis 100%; controls drop below) and break-word replaces
anywhere, so URLs wrap readably at natural break points
- M1: onboarding inputs collapsed to 18px (.ob-row goes column on
mobile, so flex:1 became flex-basis:0) — now flex:none, 44px
- L1: overflow-menu items 44px; L2: server auth pages get 44px
inputs/buttons at <=900px; L4: .markdown gets width:100% so short
docs stop shrink-to-content floating; L5: .hmeta centers so the
size stays attached when the author line wraps
go build/vet/test green; 42 e2e specs green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Designer round 2: layout 9 / readability 8 / tap-targets 8 /
navigation 9 / polish 8, zero high or medium findings; every round-1
fix confirmed with measurements (no page-level horizontal scroll on any
of the 24 surface x viewport combinations; desktop 1360 unaffected by
the 900px breakpoint).
Remaining low cosmetics fixed for the confirmation round:
- .hsize never wraps ('67 B' split across lines at 360)
- guide Copy button is a real 44px touch target (code blocks get the
height to hold it), admin selects/buttons 40 -> 44px
- truncated emails/URLs wrap on touch instead of dead-end ellipsis
- history timestamps 12px (11px was borderline on small phones)
42 e2e specs green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Designer round 1 scored layout 5 / readability 7 / tap-targets 6 /
navigation 8 / polish 7, one high finding:
- HIGH: tablet 768 and phone-landscape 844 fell between breakpoints —
full desktop topbar + fixed 264px sidebar overflowed the page
(scrollWidth 849 vs 768). The mobile media query now covers
max-width 900px, giving those widths the off-canvas sidebar and
collapsed topbar.
- MED: admin-row selects (28px) and .ai-btn/.ai-del (27px) bumped to
40px targets on mobile, rows wrap; modal buttons to 44px; share
dialog's destructive Revoke pushed away from Done; Escape now
dismisses the share dialog.
- MED: <=430px drops the verbose .dl-meta so filenames stop truncating.
- LOW: gd-copy gets an opaque backing over scrolling code; compact
nowrap history timestamps; invite/pbtn/palette rows to 44px.
42 e2e specs green.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Field report: an agent session read a dozen-plus files via Bash
(grep/cat/tail/find) and Grep, but read heat showed almost nothing —
the read-log hook only matched the native Read tool.
- matchers broadened per platform: claude Read|Grep|Bash, codex
read_file|shell, gemini +search_file_content|run_shell_command,
hermes read_file|grep|bash; plugin hooks.json matches Read|Grep|Bash
- read-log is now tool-aware: shell events mine the command line for
existing files it names (redirect targets and flags excluded), grep
events mine the response for the files the matches came from
(content lines and filename lists), and listing tools (Glob, ls) are
deliberately ignored — seeing a file's name is not reading it
- hooks install upgrades a registered hook's stale matcher in place, so
re-running it after a binary upgrade rolls coverage out to existing
projects instead of being skipped by the idempotency marker
- docs: SKILL.md platform table + read-heat wording, install/init
commands, README command table
Note from the same report, verified not a bug: read-log resolves the
mount via the folder's own .bdrive/config.json (config.ResolveMount),
so a stale duplicate registry entry cannot swallow reads.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
- #root { display: contents } so body's flex layout sees through the
React mount point (main pane was stuck at content width)
- README: Web frontend development section; CLAUDE.md: commands +
webapp description rewritten for the React/Vite reality (committed
dist, check-dist pre-release step, the no-router-library and
no-post-commit-DOM-patching lessons)
- verified: clean git-archive checkout builds with no Node and serves
the React app; visual parity pass across desktop + mobile surfaces;
42 e2e specs green; plugin docs untouched (no frontend internals)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
- org admin: rename, member roles/removal (self marked), project
rename/delete, invite links (create/copy/revoke, uses + expiry),
org-wide public-share audit with revoke; members get a read-only view
- hub settings: verification/approval policy toggles (verification
disabled without SMTP), read-only domains/self-signup/admins, pending
signup queue with approve/deny (count feeds the admin bar)
- panels replace the content pane without becoming routes (classic-app
parity): Browser takes a panel prop, HubApp owns the state and any
navigation closes it
- e2e: 8 admin specs, all mutations self-reverting (42 total green)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
- project home at /<pid>: connect-an-agent guide (Claude plugin flow,
Hermes/Codex CLI tabs, persisted choice, copy buttons, real hub origin
+ project id), with Insights embedded below for admins/org-owners
- Insights: squarified treemap, reads×freshness scatter with danger
quadrant, hot-path list, agent coverage matrix — classic math ported
verbatim into JSX SVG; dedicated /insights route
- history views: whole-project / subtree / per-file feeds with kind tags,
device attribution, expandable linkified session notes
- REPLACED react-router-dom with src/nav.ts (~40-line synchronous history
router): v7 wraps navigation in startTransition, which left the old
view on screen for seconds after the URL changed (flaky navigations,
35KB heavier bundle). Routing semantics are unchanged.
- e2e: 12 new specs porting the original 17 parity checks (34 total,
~13s, stable across repeated runs)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
- FileTree with fold state, lone-root auto-open, reveal-on-deep-link;
folder listings with heat dots and the journals-backed change feed
- FileView: markdown (HTML transformed BEFORE render, link clicks
delegated — React re-applies dangerouslySetInnerHTML markup on
unrelated updates, so post-commit DOM patching loses handlers),
images, text, download card
- breadcrumbs, per-route scroll restoration (location.key memo)
- topbar actions: share dialog (mint/copy/open/revoke), history/upload/
download buttons, ⋯ overflow menu; upload via upload/init direct or
relay path, then tree refresh + open
- ⌘K command palette: fuzzy files/projects/actions with stemming
- e2e: 11 new browse specs (22 total green in ~12s); helpers cache one
session cookie per identity to stay under the 10/min auth rate limit
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
- URL as source of truth: parseRoute/urlForPath/urlForView ported verbatim
(src/router.ts), single catch-all route so encoded slashes survive
- hub shell: project nav with color chips, org bar, admin bar with pending
count, sign-out per session flags; volume shell renders too
- empty-state onboarding (invite paste + create project), /join/<token>
invite accept that survives the login redirect
- toast + modal prompt/confirm primitives (imperative promise API over a
React host, matching the classic behavior)
- e2e: 7 new hub specs (11 total green); harness gains a no-org 'solo'
account to reach the empty state
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
- Vite+React+TypeScript workspace at internal/webapp/frontend; vite build
emits committed assets into internal/webapp/static (the go:embed target),
so plain 'go build' still needs no Node
- style.css and the SVG sprite ported verbatim; boot layer (api/config,
401->login redirect) ported so the auth flow works end to end
- frontend(): content-hashed assets/* now served immutable; index.html
stays no-cache (TestFrontendSPAFallback covers both)
- committed e2e harness (BDRIVE_E2E_SERVE=1, deterministic seeded hub on
:8993) wired as Playwright webServer; 4 shell specs green
- check-dist.sh guards against stale committed build output
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
Replace the old "append conventions to CLAUDE.md" step with a two-file
pattern for teaching agents a newly mounted shared folder:
- <shared>/AGENTS.md (synced): the team's single source of truth for the
folder's structure and conventions — scaffolded once by the project
creator, read (never rewritten) by joiners.
- A repo-root AGENTS.md/CLAUDE.md pointer (per machine, not synced): the
awareness/routing layer. Required because discovery differs by
platform — Claude Code and Hermes load nested instruction files lazily
(only after entering the folder), and Codex never discovers them at
all (root→cwd path only).
SKILL.md gains a "Teaching agents the folder" section with the platform
discovery table and a first-contact orientation ritual; /beardrive:install
step 4 and /beardrive:init step 6 now offer both files as separate
consents; install.md step 3 gains the same never-sync-a-repo-root hard
rule init.md already had; README/CLAUDE.md descriptions updated.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt