Commit Graph
91 Commits
Author SHA1 Message Date
Snow LeeandClaude Fable 5 623da892d2 fix(auth): first-account bootstrap — admin emails activate on signup; add CI
A fresh hub following docs/self-hosting.md was a locked room: invite-only
(the default) showed "Sign up disabled" with nobody to mint an invite, and
the approval-gated posture stranded the first admin as pending forever.

Emails on the config's admin list are operator-vetted, so they now
activate immediately on signup (any posture), and while the hub has zero
accounts they may sign up even on an invite-only hub. Strangers still
can't take the bootstrap slot, and the door closes after the first
account. Validated end to end from scratch: hub boot → admin signup →
device-code login × 2 devices → init → bidirectional sync → hooks install.

Also adds the missing GitHub Actions CI workflow (build/vet/test on
ubuntu + macos) — the repo previously had no CI at all.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-21 23:24:25 -07:00
Snow Lee dfef5720df webapp: organizations behind a Directory seam
The hub already abstracted authentication — AuthProvider, with BuiltinAuth
as the built-in implementation — and then reached around that seam three
times: Accounts() was declared on neither interface, admin.go type-asserted
*BuiltinAuth (five handlers silently degraded to 404/empty under any other
provider), and organizations were not on the seam at all.

That last gap had teeth. A deployment whose identities come from elsewhere
had no way to own its orgs, so the code that did own them wrote into the
hub's OrgDB from the side — and nothing stopped the hub from inventing an
org that the identity system had never heard of. One did: a hub-created org
held every project while the mirrored one sat empty, and no sync path could
see the difference.

Directory (directory.go) is where organizations live now. LocalDirectory
wraps today's OrgDB unchanged — same last-owner protection, same normEmail,
same "o-"+randHex(4) ids, same file/SQL persistence — so a self-hosted hub
behaves exactly as before. A deployment whose orgs are owned elsewhere
implements the same interface, returns ErrManagedElsewhere from the write
half, and the handlers answer 409 with ManageURL. The hub never learns why
a write was refused, only where to send the user.

Two rules shape the interface. Reads are on the request path: Role runs on
every project request, including the /store/* endpoints a device hits every
few seconds with a token that carries no identity claims, so an
implementation backed by a remote system answers from its own cache — and
that cache is its business, not the hub's. Writes are optional, because
"this hub owns its orgs" is a deployment fact, not a code path.

- Server.Orgs *OrgDB becomes Server.Dir Directory: 28 call sites, 8
  nil-checks, one writeDirErr helper for the 409 translation.
- /api/orgs gains manage_url per org — the destination of the account
  menu's Settings entry. The client follows a link and never branches on
  which kind of hub it is talking to.
- Org administration becomes a real route, /orgs/<id>, retiring one of the
  two URL-less panels CLAUDE.md grandfathers. When a directory's ManageURL
  is not hub-local, the SPA fallback redirects there instead — so a hub that
  cannot administer its orgs cannot paint a console whose every control 409s.
- Accounts() moves onto AuthProvider. admin.go's type assertion becomes an
  optional AccountApprover, and a provider without one now answers 503
  rather than an empty approval queue: "no queue here" and "queue is empty"
  are different answers and only one of them was true.

Two reviews drove the rest. The architecture review caught a browser page
load that could delete org members (a display read ran the full membership
reconcile, and a 200 with an empty user list evicted everyone), one write
site that escaped the 409 translation, and a webhook that could wedge an
event stream behind an unappliable event. The design review, over eight
rounds, caught the org page rendering live controls on a hub that cannot
use them, a share link made unrevokable by a long filename, nine keyboard
tab stops parked off-screen behind a closed drawer, and — five separate
times — a fix of mine that looked right in the source and did nothing in
the browser.

Conformance tests run both a writable and a read-only implementation against
one contract; the seat, prune, and out-of-order regressions each have a test
written to fail against the old code.
2026-07-20 03:06:19 -07:00
Snow LeeandClaude Opus 4.8 25f890c03f feat(brand): the Stack mark and Jersey 10 across app, auth, and docs
Replaces the 🐻 emoji standing in for a logo everywhere. The mark is the
letter B built from three rectangles — a rail and two blocks, the same
shape as the product (a spine with volumes hanging off it). One fill, so
`currentColor` themes it in the sidebar, the favicon, and flat ink.

- Web app: <Mark> in shell.tsx replaces the emoji-in-a-gradient-tile
  badge; the mark takes the honey and the wordmark takes text colour, so
  the accent lands once. #vault-name sets in Jersey 10 at 18px — the face
  is condensed, so that measures like 13px of the UI face.
- Auth pages (authlocal.go): server-rendered, so they had their own emoji
  logo. Same mark, inline.
- Docs: bear.svg becomes the mark (fixed honey fill — Starlight renders
  the logo as <img>, which can't inherit currentColor), and .site-title
  sets in Jersey 10. Starlight tints that title with the accent by
  default, which put honey on white in light mode and failed contrast;
  it now takes --sl-color-white, matching the app.
- Favicon: the mark, as a data URI.

Jersey 10 is SIL OFL and self-hosted in both trees — Vite fingerprints
the app's copy into static/assets/, the docs serve theirs from public/ —
so no surface makes a third-party font request. Licence ships beside each
file. It is deliberately not a design token: tw.css's @theme block is
mirrored by the cloud landing's tokens.css and a drift check fails the
build if they diverge, so the logo face lives in plain CSS.

The cloud landing page carries the same mark and face (separate repo).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-19 19:38:42 -07:00
Snow LeeandClaude Fable 5 3f9e465463 refactor(web): one md-width column for app views; read is for rendered files only
- --page-read and --page-app both resolve to 768px (Tailwind md)
- History, folder listings, and the onboarding empty state move to the
  default app column; Insights already sat there. Only rendered markdown
  keeps read (HTML files keep their wide frame).
- layout.spec.ts repinned first (test-first); 59/59 e2e green
- shell.tsx docstring and stale style.css width comments updated

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-19 16:37:40 -07:00
Snow LeeandClaude Opus 4.8 1b5a422af2 webapp: eight agents in the demo seed, and far less staleness
Two changes to the demo data, both driven by how the screenshots read.

Warning triangles were on roughly half the files, which stops meaning
"look here" and starts meaning nothing. Staleness is now ~15% overall, and
correlated with reads rather than uniform: a heavily-read file is far
likelier to be stale, because it's the one everybody trusts and nobody
owns. That puts the red on big cells in the treemap and in the top-right
of the scatter — where the story is — instead of scattering it across a
hundred files nobody opens. Fewer warnings, and the ones left are the ones
worth reading.

The agent fleet goes from four to eight: one per teammate plus shared CI,
which is what a team's coverage matrix actually looks like once everyone
runs their own. Each has a bias (agentBias) toward particular areas, so
the matrix shows agents specialising instead of eight identical rows.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RA5pQH92cxk5SfiYJeTUjK
2026-07-19 16:29:41 -07:00
Snow LeeandClaude Opus 4.8 52f595efc0 webapp: seed the demo hub with a realistic wiki
The demo harness generated files named run-015.md, des-031.md and so on,
with one-line bodies. Screenshots taken from it end up on the website, and
"des-031.md" in a treemap tells a visitor nothing about what BearDrive is
for.

Replaced the generator with a wiki a company would actually have: runbooks,
ADRs with real slugs, dated meeting notes, product and research docs, and
three hand-written documents (q3-findings, incident-response, first-week)
whose markdown renders with headings, tables, code and lists so the file
view is worth screenshotting. Read-heat shaping is unchanged — runbooks are
what the on-call agents live in, research notes are written for humans and
barely read by anything — so the insights views still light up.

Project renamed proj -> acme-wiki to match.

Also dropped the "must never be committed" note: the file has been in the
tree for a while and is genuinely useful for exploring the UI and taking
product screenshots. It still only runs under BDRIVE_MANUAL_SERVE=1.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RA5pQH92cxk5SfiYJeTUjK
2026-07-19 15:28:45 -07:00
Snow LeeandClaude Opus 4.8 afac6bef65 fix(web): design-review fixes to the column system
A design pass over the new tiers found four problems, two of them
introduced by the refactor itself:

- Insights was assigned `wide`, but its charts are viewBox="0 0 720 …"
  SVGs at width:100% — a wider column didn't show more, it magnified:
  measured 1.67x at 1600px, painting a 10.5px treemap label at 21px,
  larger than the page h1. Insights moves back to `app` and .in-chart
  caps at its 760px design width. Widening a column must never mean
  scaling content up; that line is now written into shell.tsx.
- /install rendered the same ConnectGuide as the project home, but
  wrapped in the .onboard card: x=652 w=560 top=186 against home's
  x=492 w=880 top=96 — two sidebar items apart, same component, three
  different numbers. It renders directly now. .onboard stays what it
  is, the empty-state hero card.
- History was `app`, so `.htime { margin-left: auto }` stranded each
  timestamp ~600px from its path. It's a listing — same rows as the
  folder view — so it belongs in `read` alongside it.
- --hero-top: 10vh is viewport-relative in the wrong direction: 84px on
  a 390x844 phone against 80px on a 1280x800 desktop, i.e. the smallest
  screen paid the most. Now clamp(32px, 8vh, 88px).

Also fixes the Copy button in the guide's code blocks: it was absolutely
positioned over a scrolling box, so its 72px of reserved padding
scrolled away with the content and the button landed on top of the
command (visible mid-token at 560px and on mobile). The block is a grid
now — code scrolls in its own track, the button can't overlap it.

layout.spec.ts gains three assertions: /install and home render the
guide identically, no chart scales past ~1.0x at 1600, and the tier map
matches the new assignments.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-19 15:08:30 -07:00
Snow LeeandClaude Opus 4.8 6cc61292ee refactor(web): one column system for every view
Every route invented its own content column: widths ran 560px to
unbounded (704 / 760 / 860 / 936 / 560), half of them uncentered because
they set max-width with no auto margins, and markdown pages carried the
constraint on #content itself so the 40px gutter came out of the reading
measure — .md text ran 624px against the folder listing's 704px directly
beside it in the tree.

Now there is exactly one primitive:

- #content owns scrolling and the page gutter, never a width.
- <Page width="read|app|wide"> (shell.tsx) owns width and centering, one
  per view, driven by CSS tokens --page-read/-app/-wide (704/880/1200).
  read = prose + listings, app = structured views, wide = data-dense.
- .markdown goes back to being typography only; the column around it is
  .page.read, which also retires the #content.markdown min-width hack.
- Views declare no layout: .guide/.insights/.history/.admin/.dirlist/
  .markdown lost their max-widths, Browser picks the width per route.
- Short centered states (empty, loading, not-found, no-preview, onboard)
  shared one --hero-top instead of 8/12/15/22vh apiece.

Insights moves to wide — its treemap and coverage matrix were cramped at
760. Everything else lines up: app pages at 880, read pages at 704, same
edges on every route.

e2e/layout.spec.ts locks it in: one .page per route, widths resolve to
the tokens, same-width routes share edges, #content never constrains
width, and no view re-declares a column inside .page.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-19 14:50:38 -07:00
Snow LeeandClaude Opus 4.8 5c6099177b feat: bdrive skill install + one-paste Codex/Hermes setup guide
The hub's install guide told Codex and Hermes users to run four CLI
commands by hand, and the one people skipped — `bdrive hooks install` —
is exactly the one that makes files sync at turn boundaries. Hand the
setup to the agent instead, the way the Claude tab hands it to the
plugin.

- `bdrive skill install` (internal/agentskills, plugin/embed.go): the
  binary now carries the beardrive skill and writes it to any agent that
  reads SKILL.md — ~/.{claude,codex,gemini,hermes}/skills/beardrive/.
  User-level on purpose: the skill is about the CLI, not one folder, and
  a synced project folder should never carry it. Idempotent; refreshes a
  stale copy after a CLI upgrade. Bare `bdrive skill` prints the table,
  mirroring `bdrive hooks`.
- Guide's Codex/Hermes tabs are now a single paste, no terminal: the
  prompt has the agent install the CLI, keep the skill, sign in, init,
  and register hooks. The commands ride inside the prompt because these
  agents ship no BearDrive knowledge (Claude's tab is terse only because
  the plugin carries it). `login --device` there — a browser-callback
  sign-in is invisible to an agent mid-turn, while the device flow gives
  it a code and URL to relay. Plain commands live on in an "or run it
  yourself" fallback.
- Docs realigned: README, SKILL.md, /beardrive:install, self-hosting.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-19 14:30:06 -07:00
Snow LeeandClaude Fable 5 7f17c1be98 fix(web): design round-2 polish — mobile 44px vault buttons, uncapped mobile nav, faint informational text, centered mobile Revoke
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 13:49:30 -07:00
Snow LeeandClaude Fable 5 e5aeca675b fix(web): design-review round 1 — overlay double-centering, tree file/dir classes, palette chrome, table cards, AA labels, mobile targets
- translate:none on .modal/#palette (Tailwind v4 translate utility stacked on
  the house transform, shifting every overlay and clipping the palette input)
- virtualized tree rows regain dir/file classes (file rows had fold chevrons)
- palette input: single icon, no shadcn border/ring leak
- members/shares tables wrapped in the .admin-list card vocabulary
- section labels ghost→faint (3.6:1 → 5.75:1 AA); mobile 44px icon buttons,
  projects-section clipping; switcher opens below trigger (popper)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 13:35:11 -07:00
Snow LeeandClaude Fable 5 389c4ba550 fix: drop stray worktree gitlink (gitignore .claude/worktrees/); sonner radius token
CTO review findings 1+4: the agent-worktree gitlink re-staged by add -A would
break --recurse-submodules clones; sonner referenced undefined --radius.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 13:21:09 -07:00
Snow LeeandClaude Fable 5 fad9ae4f6b feat(web): react-table admin tables + RHF/zod forms; docs reflect the Stack A dependency set
Members and shares-audit render through @tanstack/react-table (sortable,
spec-first); org rename, hub signup policy, and onboarding create/join are
react-hook-form + zod with inline errors replacing toast-on-typo. 55/55.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 13:15:24 -07:00
Snow LeeandClaude Fable 5 2e835d266d feat(web): file tree virtualized with @tanstack/react-virtual
Only the visible window renders (collapsed subtrees not at all — the ~5k-file
DOM cliff from the CTO review is gone). Flat rows keep data-path/.active
contract, nesting guide lines, mobile 44px rows; scroll-into-view moves into
FileTree via scrollToIndex. Fold behavior pinned by spec first. 54/54.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 13:08:39 -07:00
Snow LeeandClaude Fable 5 2993049bf4 feat(web): buttons on shadcn Button — house variants (primary/danger/subtle/toolbar) keep the exact look
cva variants map to the existing .pbtn/.danger-btn/.ai-btn/.btn classes, so
style.css owns appearance while shadcn adds focus-ring/disabled plumbing.
Migrated: modals, ShareDialog, EmptyState, Browser topbar. 53/53.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 13:05:13 -07:00
Snow LeeandClaude Fable 5 b7ce76b72e feat(web): palette on cmdk in a Radix Dialog — house fuzzy scorer kept (shouldFilter=false)
cmdk owns keyboard nav/selection/aria; matching, stemming, highlighting and
ordering unchanged. Specs target #palette input (cmdk owns the input id).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 12:57:08 -07:00
Snow LeeandClaude Fable 5 4a4e13f14c feat(web): modals on Radix Dialog — same imperative API, same classes, Radix-owned dismissal
modalPrompt/modalConfirm/ShareDialog render in DialogContent (.modal kept for
specs/styling); Escape pinned by spec first.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 12:51:59 -07:00
Snow LeeandClaude Fable 5 cb06737af7 feat(web): project switcher on shadcn Select — specs moved to behavioral contract first
Trigger keeps #project-select + proj-mark; items portal'd with keyboard nav
from Radix; picking navigates (spec: open, both projects listed, pick → URL).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 12:49:19 -07:00
Snow LeeandClaude Fable 5 c1db12e75e feat(web): account menu on Radix DropdownMenu (non-modal for legacy click-through parity)
Ids preserved (#account-btn/#account-menu/#menu-*/#signout); Radix owns
Escape/outside dismissal + focus; dismissal behavior pinned by spec first.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 12:47:47 -07:00
Snow LeeandClaude Fable 5 fe8911861c feat(web): search tooltip on Radix (shadcn) — portal'd, house-styled tipcard; provider at root
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 12:39:33 -07:00
Snow LeeandClaude Fable 5 65c4a29bf8 feat(web): toasts on sonner behind the same toast() API; specs pin behavior via expectToast
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 12:37:46 -07:00
Snow LeeandClaude Fable 5 407c443a40 feat(web): Stack A foundation — Tailwind v4 + shadcn/ui wired, zero visual change
Tailwind v4 via @tailwindcss/vite, theme+utilities only (no preflight) so
legacy style.css keeps owning base styles during migration; BearDrive tokens
mapped into @theme incl. shadcn semantic slots (primary=honey, popover=raise…).
shadcn components copied in (button, tooltip, dropdown-menu, dialog, select,
command, sonner, input, label, form, table) with radix-ui/cmdk/sonner/cva;
sonner pinned dark (next-themes dropped). Stack A libs installed:
react-virtual, react-table, react-hook-form + zod. 50/50 e2e unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 12:34:52 -07:00
Snow LeeandClaude Fable 5 4c59bbc794 fix(web): search tooltip painted under the section border — lift the header's stacking context
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 11:44:59 -07:00
Snow LeeandClaude Fable 5 7ddb211fcf feat(web): scoped insights/history keep the file or folder selected in the tree
On /insights/<path> and /history/<path> the tree highlights (and unfolds to)
the target; Dashboard/History menu items light up only for their root,
project-wide views. 50/50 e2e.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 11:41:35 -07:00
Snow LeeandClaude Fable 5 d18ad1fa91 test(web): regression specs — ⋯ Insights scopes to the open file and selected folder
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 11:36:56 -07:00
Snow LeeandClaude Fable 5 288b426e82 fix(web): search tooltip clipped by the sidebar edge — right-align it
#sidebar is overflow:hidden; the centered card poked past its right edge.
The tooltip now grows leftward from the button, arrow anchored beneath it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 11:27:01 -07:00
Snow LeeandClaude Fable 5 3f974d96e4 feat(web): search moves beside the brand in the sidebar header, with a ⌘K hover tooltip
Icon-only trigger in the vault header (Linear-style); a tiny search.ts
emitter asks Browser's palette to open — no plumbing through the shell.
Custom tooltip card (label + kbd chip, arrow) on hover/focus. Topbar search
and its centered styles removed. 47/47 e2e incl. header-trigger spec.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 11:24:07 -07:00
Snow LeeandClaude Fable 5 75f2b0bfe9 feat(web): topbar cleanup — centered 2x search, icon-only Share, History/Download into the ⋯ menu
- search control sits centered in the topbar at ~2x width, kbd right-aligned
  (static again on mobile)
- Share is icon-only
- History button shows only on the project home: gone from dashboard/history
  (and other view routes) and whenever a file/folder is selected — the ⋯
  menu and sidebar carry it
- Download is ⋯-menu-only; a hidden anchor keeps the browser download flow
46/46 e2e.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 11:16:50 -07:00
Snow LeeandClaude Fable 5 317045cecb feat(web): History in the project menu, after Installation
Navigates to the existing /history route; active state follows the URL.
46/46 e2e.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 11:07:14 -07:00
Snow LeeandClaude Fable 5 bacb528de6 feat(web): Installation and Settings are real routes; every page owns a URL
/<pid>/install and /<pid>/settings join /insights and /history as view
routes — deep links, reload, and back/forward work; the sidebar menu
navigates instead of toggling panel state. Rule recorded in CLAUDE.md:
new surfaces are view routes, never URL-less panels (org/hub admin panels
are the legacy exceptions). 46/46 e2e incl. deep-link spec.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 10:51:25 -07:00
Snow LeeandClaude Fable 5 e894f4ced9 fix(web): Dashboard menu dead after opening a panel on the insights route
Panels are not routes: navigating to the already-current /insights URL never
changes pathname, so the route-change effect couldn't close the open panel.
Menu Dashboard (and the ⋯ Insights entry) now close the panel explicitly.
Regression spec added; 46/46.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 10:47:23 -07:00
Snow LeeandClaude Fable 5 7a41a9e5b6 feat(web): project menu in the sidebar — Dashboard, Installation, Settings
Under the project dropdown: Dashboard (project insights), Installation
(connect guide, moved out of Settings), Settings (project facts). Active
states follow the open view/panel; the inline gear next to the dropdown is
gone. 46/46 e2e.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 09:58:48 -07:00
Snow LeeandClaude Fable 5 3698d70f68 feat(web): insights scoped to the selected file or folder
The ⋯ menu's Insights opens /insights/<current path>: a folder scopes the
treemap/scatter/hot-path/agent-coverage to its subtree, a file to itself;
crumb and title show the scope. urlForView now carries targets for insights
like it did for history. 45/45 e2e.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 09:51:07 -07:00
Snow LeeandClaude Fable 5 51ce477b07 feat(web): remove browser upload UI — content enters via local sync only (for now)
Topbar button, ⋯ menu entry, palette action, hidden file input, and the
upload plumbing (upload.ts) are gone; the server upload API stays (devices
and the store proxy depend on it). Spec reworked to seed via API and assert
the affordance is absent. 44/44 green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 09:48:17 -07:00
Snow LeeandClaude Fable 5 40a0b19aa4 feat(web): PropelAuth-style sidebar layout — brand header, project dropdown, account menu
- header is the brand only (BearDrive), linking home
- Projects section is a dropdown (native select, styled) with the project
  mark, plus the project-settings gear beside it and + to create
- sidebar footer is the account row (avatar, name, email) opening a popover:
  Organization → <org> Settings, Hub → Signup & access (admins), Account →
  Log out (danger red)
- volume mode unchanged (sign-out stays in its header)
- Playwright suite reworked for the new layout — 44/44 green; static rebuilt

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 09:42:30 -07:00
Snow LeeandClaude Fable 5 77735660c9 feat(web): nav redesign — lucide icons; project settings in header, workspace gear + sign-out in org bar
Design feedback applied:
- icons are lucide-react (lucide.dev) behind the existing <Icon name> API;
  the inline SVG sprite is gone
- org bar (sidebar footer): the Manage text button is a gear icon opening
  the org admin panel; sign-out moved here, after the gear
- header: the org-manage (people) button is removed; the header gear now
  opens a new per-PROJECT settings panel (identity facts + connect guide);
  sign-out stays in the header only when no project/org bar is present
  (volume mode, loading, empty state)

Playwright suite updated and green (44/44); static/ rebuilt.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VbiaaVM2ACxeRi8ySG9ybc
2026-07-19 09:25:22 -07:00
Snow LeeandClaude Fable 5 cb621c153e feat(web): friendly 404 for missing paths; HTML files render as sandboxed pages
Two viewer features plus the security fix the second one surfaced:

- Missing file/folder paths now get a not-found view: the path, and the
  hint that a just-created file may still be uploading or syncing from a
  teammate's device — the tree polls every few seconds so it appears on
  its own, plus a Check again button that refetches immediately. The
  topbar's share/download actions no longer show for nonexistent files.

- Opening an .html file renders it as a page (sandboxed iframe,
  allow-scripts only) instead of showing source text.

- SECURITY: /api/file was already serving synced HTML inline as
  text/html on the hub origin with session cookies — a stored-XSS
  surface reachable by direct navigation, previously masked only by the
  viewer showing HTML as text. Inline HTML and SVG responses now carry
  'Content-Security-Policy: sandbox allow-scripts' (the same wall as
  /s/* share pages); downloads are exempt (attachments never execute in
  the hub origin).

Tests: Go CSP-header matrix (html/svg sandboxed, md clean, download
exempt); e2e: sandboxed-iframe rendering incl. in-frame content + CSP
assertion, and the not-found → late-upload → Check again flow. 44 specs
green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-16 11:01:38 -07:00
Snow LeeandClaude Fable 5 644caff70e feat(hooks): every mentioned file path gets a gated hub link — formula injected each turn
Field report follow-up: an agent with a stale skill copy couldn't find
the gated URL after creating a file. Instructions rot; hook output is
computed fresh from the binary every turn. Claude Code's turn-start
pull hook now runs 'bdrive sync --hook claude-code', which:

- pulls as before, and stamps the session note from the event JSON
  (replacing the sh/sed pipeline for the pull leg)
- emits the project's gated-link formula as UserPromptSubmit
  additionalContext: whenever the agent mentions a synced file path in
  prose, it appends the hub link on an emoji — `<path>` [🔗](<url>) —
  path plain (it's the local path), hyperlink on the emoji only; code
  blocks stay plain; bdrive share stays explicit-opt-in-public

Blind-tested: an agent given only the injected context decorated every
path mention correctly, kept the code-block command plain, and checked
files were synced before linking.

- hooks install now CONVERGES marker-identified groups to the current
  shape (command/matcher/flags), so improvements reach existing
  projects on reinstall instead of being frozen by the idempotency
  marker; hermes same
- plugin: UserPromptSubmit → beardrive-pull.sh (stdout passes through);
  version 0.3.0
- SKILL 'Share what you make' generalized to 'Link what you mention'
  (URL formula documented for non-Claude platforms); install.md pointer
  template updated

Never fails the turn: every error path in --hook mode is a silent
successful exit; offline still emits (links serve online teammates).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-16 10:25:07 -07:00
Snow LeeandClaude Fable 5 364ba187a2 feat(web): render markdown frontmatter as a key/value table
A leading YAML frontmatter block used to render as goldmark's
thematic-break soup (hr + stray text). It now renders as a compact
table: keys in the author's order (yaml.Node, not a map), flat lists
comma-joined, nested values as compact YAML in <code>, everything
HTML-escaped. Anything that isn't a well-formed YAML mapping — mid-doc
fences, unclosed fences, list-shaped or invalid YAML — falls through
and renders exactly as before; empty frontmatter is simply hidden.

Applies everywhere the server renders markdown: the hub viewer and
public share pages, each with theme-matched styling. Matters most for
OKF/gbrain-style frontmattered knowledge bases.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-15 16:17:08 -07:00
Snow LeeandClaude Fable 5 da4157cc34 fix(webapp): [mobile] pin topbar actions to the top-right corner
Desktop right-aligns Search/Share/⋯ via #meta's flex:1 spacer, but the
mobile styles hide #meta — nothing absorbed the middle space, so the
buttons sat next to the breadcrumb mid-bar (user-reported). On <=900px
the crumb is now the spacer. Verified at 390px: ⋯ right edge at 382/390.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-13 21:57:27 -07:00
Snow LeeandClaude Fable 5 e26a15d4b4 feat(webapp): [mobile] round 5 — confirmation pass (9/9/9/9/8), goal complete
Rounds 4 and 5 both scored every category >=8 with zero high-severity
findings — the exit bar (two consecutive passing designer rounds) is
met. Post-exit cleanup: restore id=search-btn dropped in the React port
so the existing mobile rule hiding the ⌘K badge matches again. Two
remaining observations recorded as won't-fix in the spec with reasons.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-13 21:49:40 -07:00
Snow LeeandClaude Fable 5 9ea07281f8 feat(webapp): [mobile] round 4 — pass (9/9/8/9/8), touch-size the last small controls
Designer round 4: all categories >=8, zero high or medium findings, all
seven round-3 fixes confirmed with measurements. Residual lows fixed for
the confirmation round: insights lens chips, guide tabs, and modal text
inputs to 44px on mobile; at <=430px the share dialog's destructive
Revoke takes its own row instead of sitting 9px from Done.

All responsive CSS on the same URLs — no mobile-specific routes.
42 e2e specs green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-13 21:34:39 -07:00
Snow LeeandClaude Fable 5 3161fc73c9 feat(webapp): [mobile] round 3 — repair the wrap regression, onboarding inputs, auth controls
Designer round 3 FAILED the bar (6/6/7/9/6, one high) — it caught a
regression my round-2 fix introduced: .ai-main { overflow-wrap:anywhere }
let flex min-content collapse invite/share URL rows to one character per
line at 360/390 (496px-tall rows). Streak reset. Fixes:

- H1: on mobile the admin row's name/URL takes the full row
  (flex-basis 100%; controls drop below) and break-word replaces
  anywhere, so URLs wrap readably at natural break points
- M1: onboarding inputs collapsed to 18px (.ob-row goes column on
  mobile, so flex:1 became flex-basis:0) — now flex:none, 44px
- L1: overflow-menu items 44px; L2: server auth pages get 44px
  inputs/buttons at <=900px; L4: .markdown gets width:100% so short
  docs stop shrink-to-content floating; L5: .hmeta centers so the
  size stays attached when the author line wraps

go build/vet/test green; 42 e2e specs green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-13 21:23:04 -07:00
Snow LeeandClaude Fable 5 445ee1683d feat(webapp): [mobile] round 2 — all categories >=8, polish the five low findings
Designer round 2: layout 9 / readability 8 / tap-targets 8 /
navigation 9 / polish 8, zero high or medium findings; every round-1
fix confirmed with measurements (no page-level horizontal scroll on any
of the 24 surface x viewport combinations; desktop 1360 unaffected by
the 900px breakpoint).

Remaining low cosmetics fixed for the confirmation round:
- .hsize never wraps ('67 B' split across lines at 360)
- guide Copy button is a real 44px touch target (code blocks get the
  height to hold it), admin selects/buttons 40 -> 44px
- truncated emails/URLs wrap on touch instead of dead-end ellipsis
- history timestamps 12px (11px was borderline on small phones)

42 e2e specs green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-13 21:07:59 -07:00
Snow LeeandClaude Fable 5 036faa149c feat(webapp): [mobile] round 1 — close the 761-900px breakpoint gap, touch-size controls
Designer round 1 scored layout 5 / readability 7 / tap-targets 6 /
navigation 8 / polish 7, one high finding:

- HIGH: tablet 768 and phone-landscape 844 fell between breakpoints —
  full desktop topbar + fixed 264px sidebar overflowed the page
  (scrollWidth 849 vs 768). The mobile media query now covers
  max-width 900px, giving those widths the off-canvas sidebar and
  collapsed topbar.
- MED: admin-row selects (28px) and .ai-btn/.ai-del (27px) bumped to
  40px targets on mobile, rows wrap; modal buttons to 44px; share
  dialog's destructive Revoke pushed away from Done; Escape now
  dismisses the share dialog.
- MED: <=430px drops the verbose .dl-meta so filenames stop truncating.
- LOW: gd-copy gets an opaque backing over scrolling code; compact
  nowrap history timestamps; invite/pbtn/palette rows to 44px.

42 e2e specs green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-13 20:46:02 -07:00
Snow LeeandClaude Fable 5 476113ebdc fix(hooks): read heat captures grep matches and shell-command reads, not just Read
Field report: an agent session read a dozen-plus files via Bash
(grep/cat/tail/find) and Grep, but read heat showed almost nothing —
the read-log hook only matched the native Read tool.

- matchers broadened per platform: claude Read|Grep|Bash, codex
  read_file|shell, gemini +search_file_content|run_shell_command,
  hermes read_file|grep|bash; plugin hooks.json matches Read|Grep|Bash
- read-log is now tool-aware: shell events mine the command line for
  existing files it names (redirect targets and flags excluded), grep
  events mine the response for the files the matches came from
  (content lines and filename lists), and listing tools (Glob, ls) are
  deliberately ignored — seeing a file's name is not reading it
- hooks install upgrades a registered hook's stale matcher in place, so
  re-running it after a binary upgrade rolls coverage out to existing
  projects instead of being skipped by the idempotency marker
- docs: SKILL.md platform table + read-heat wording, install/init
  commands, README command table

Note from the same report, verified not a bug: read-log resolves the
mount via the folder's own .bdrive/config.json (config.ResolveMount),
so a stale duplicate registry entry cannot swallow reads.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-13 15:05:05 -07:00
Snow LeeandClaude Fable 5 2590181f84 chore(webapp): drop stray screenshot script from frontend/
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-13 10:57:36 -07:00
Snow LeeandClaude Fable 5 d9a5ab3fd6 feat(webapp): [phase 5] parity gate — docs, layout fix, migration complete
- #root { display: contents } so body's flex layout sees through the
  React mount point (main pane was stuck at content width)
- README: Web frontend development section; CLAUDE.md: commands +
  webapp description rewritten for the React/Vite reality (committed
  dist, check-dist pre-release step, the no-router-library and
  no-post-commit-DOM-patching lessons)
- verified: clean git-archive checkout builds with no Node and serves
  the React app; visual parity pass across desktop + mobile surfaces;
  42 e2e specs green; plugin docs untouched (no frontend internals)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-13 10:57:21 -07:00
Snow LeeandClaude Fable 5 f60be366e7 feat(webapp): [phase 4] admin surfaces — org admin panel + hub settings
- org admin: rename, member roles/removal (self marked), project
  rename/delete, invite links (create/copy/revoke, uses + expiry),
  org-wide public-share audit with revoke; members get a read-only view
- hub settings: verification/approval policy toggles (verification
  disabled without SMTP), read-only domains/self-signup/admins, pending
  signup queue with approve/deny (count feeds the admin bar)
- panels replace the content pane without becoming routes (classic-app
  parity): Browser takes a panel prop, HubApp owns the state and any
  navigation closes it
- e2e: 8 admin specs, all mutations self-reverting (42 total green)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-13 10:51:01 -07:00
Snow LeeandClaude Fable 5 44b95143b0 feat(webapp): [phase 3] project home guide, insights, history — and a synchronous router
- project home at /<pid>: connect-an-agent guide (Claude plugin flow,
  Hermes/Codex CLI tabs, persisted choice, copy buttons, real hub origin
  + project id), with Insights embedded below for admins/org-owners
- Insights: squarified treemap, reads×freshness scatter with danger
  quadrant, hot-path list, agent coverage matrix — classic math ported
  verbatim into JSX SVG; dedicated /insights route
- history views: whole-project / subtree / per-file feeds with kind tags,
  device attribution, expandable linkified session notes
- REPLACED react-router-dom with src/nav.ts (~40-line synchronous history
  router): v7 wraps navigation in startTransition, which left the old
  view on screen for seconds after the URL changed (flaky navigations,
  35KB heavier bundle). Routing semantics are unchanged.
- e2e: 12 new specs porting the original 17 parity checks (34 total,
  ~13s, stable across repeated runs)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5cxPQdSGJnjXCYY9GeWXt
2026-07-13 10:45:19 -07:00