v0.2.0 — guarded browser consent milestone
Pre-release
Pre-release
Milestone 2 adds the guarded browser-side setup and disclosure path to the exact-session Host authority foundation.
What is included:
- lazy DeepSeek Harness composer control and disclosure-panel contributions
- structured non-secret route injection through the official DSH boot table
- exact live-session/workspace binding with one-shot, expiring client-attested acceptance
- post-acceptance provider configuration and credential-availability validation
- deterministic browser packaging, strict Host/browser schemas, lifecycle cleanup, and adversarial regression coverage
- honest privacy and threat-model documentation
Verification receipts:
- public PR and merged-main CI passed
- 125 tests across 15 files
- 91.92% statement / 89.72% branch / 91.36% function / 94.83% line coverage
- independent adversarial review found no release blockers
- exact attached tarball passed an official DeepSeek Harness packed-install/runtime smoke
- tarball SHA-256: A5BDF9B74E7CC04E0CFA2D00FA00DE81971C8CFBD420672DAB983D4EA5C2B821
Important boundary: this development milestone does not request microphone access, transmit audio or text, connect to Qwen, transcribe, play audio, or insert/submit a composer message. The visible acceptance path is client-attested; it is not cryptographic proof of a human and does not resist a malicious same-user local process without an external trust root.