Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
70 commits
Select commit Hold shift + click to select a range
6f90f55
docs: WR Handshake gap analysis deliverables (findings report, gap ma…
Jul 24, 2026
c13c942
refactor(handshake): Phase 1 - hygiene and guards (full-claim identit…
Jul 24, 2026
53ac2ab
refactor(handshake): Phase 2 - canonical core (full-coverage signing,…
Jul 24, 2026
cdf45fd
Phase 3: profile registry with fail-closed dispatch, core store split…
Jul 24, 2026
0ed2443
refactor(handshake): Phase 4 - one formation pipeline (Connect-offer …
Jul 24, 2026
617ff66
refactor(handshake): Phase 5 - grants & evidence (grant objects, per-…
Jul 24, 2026
b9a4b83
chore: build045 stamp (phase 5 grants/evidence)
Jul 24, 2026
8c506d4
art50: WP1 core AiProvenance module and generation log
Aug 1, 2026
83847d0
art50: WP2 instrument generation points with AiProvenance
Aug 1, 2026
c425fd3
art50: WP3 propagate provenance on wire and HTTP envelopes
Aug 1, 2026
5fe3f9c
art50: WP4 outbound MIME headers and BEAP content_provenance
Aug 1, 2026
ff79481
art50: WP5 first-interaction AI disclosure component and mounts
Aug 1, 2026
d75e256
art50: WP6 draft origin tracking and send-time AI labelling
Aug 1, 2026
4c3bddc
art50: WP7 clipboard export and field-apply chain-of-custody
Aug 1, 2026
d66e275
art50: WP8 stop stripping AI self-disclosure boilerplate
Aug 1, 2026
15ac103
art50: WP9 verification tests for marking and disclosure contracts
Aug 1, 2026
7f34656
art50: WP3 attach provenance on chatWithContext IPC results
Aug 1, 2026
7c937fa
art50-fix: phase1 Layer B non-dismissible disclosure and editorial re…
Aug 1, 2026
507cc5b
art50-fix: phase2 once-at-generation provenance and IPC propagation
Aug 1, 2026
9ff18b9
art50-fix: phase3 carrier honesty for clipboard export and Zoho Layer A
Aug 1, 2026
b7e72f4
art50-fix: phase4 integration tests and createProvenance invariant grep
Aug 1, 2026
188c327
art50-fix: phase2 persist stream-analyze provenance into ai_analysis_…
Aug 1, 2026
7a9921c
phase 1: baseline code module + CPR + trust-signal hygiene; spec v1.4…
Aug 7, 2026
b848b27
phase 1 correction: retire wrcode_valid condition; fix zoho aiProvena…
Aug 7, 2026
3152f0f
merge main into wr-code-email-e2e-phase-1 for integration testing
cursoragent Aug 7, 2026
560d005
docs(spec): track Refactor Order Delta v1.1 (Annex XIV 5.5 + Annex XV…
cursoragent Aug 8, 2026
0690a93
docs: add Annex XVII - WR Entries and the Publisher Console v1.0 (7 A…
cursoragent Aug 8, 2026
e5d3b67
docs(spec): add A6 to Delta v1.1 - suspension triple ruled
cursoragent Aug 8, 2026
e404d32
docs(spec): replace Delta v1.1 Phase 4 status bullet with author text
cursoragent Aug 8, 2026
93289fd
merge origin/main into wr-code-email-e2e-phase-2
cursoragent Aug 8, 2026
06753a9
phase 2 (2A.1): provenance gates BEAP detection on the inline path
cursoragent Aug 8, 2026
8b2a18e
phase 2 (2A.2): close all three fail-open degradations on the inline …
cursoragent Aug 8, 2026
a181aae
phase 2 (2A.3): source-walking guard tests for the provenance gate
cursoragent Aug 8, 2026
a155e09
phase 2 (2B.1): shared rule-8 provenance alert + extension wiring
cursoragent Aug 8, 2026
e1e993c
chore(graphify): add code/ knowledge graph (AST-only, no PDFs/docs)
cursoragent Aug 8, 2026
3442b5b
fix(handshake): close three Host-AI / IPC authorization gaps
cursoragent Aug 8, 2026
a38e8cd
merge: integrate refactor/wr-code-email-e2e-phase-2 into consolidation
cursoragent Aug 8, 2026
dffec03
merge: integrate cursor/graphify-knowledge-graph-c56a (#7)
cursoragent Aug 8, 2026
2a24cdb
test: align #7 regression fixtures with Phase-2 same_principal gate
cursoragent Aug 8, 2026
1f13880
fix(ci): use pnpm in WebMCP Release Gate workflow
Jun 21, 2026
123adba
chore(graphify): stop committing generated graphify-out artifacts
cursoragent Aug 8, 2026
f42ba48
fix(deps): sync pnpm lockfile for extension @repo/shared-beap-ui
cursoragent Aug 8, 2026
d856175
chore: remove accidental vitest dump phase2-before-native.json
cursoragent Aug 8, 2026
743fd75
chore: ignore .cursor/ tooling artefacts
cursoragent Aug 8, 2026
0c8466a
phase 2 (2B Option 2): wire shared CPR alert; defer extension sync pl…
cursoragent Aug 8, 2026
5f5d06a
chore: keep the Cursor/Graphify integration visible in .gitignore
cursoragent Aug 8, 2026
8089bb4
phase 2 (2C): CPR as a declared, typed input to local scam analysis
cursoragent Aug 8, 2026
a310cb9
docs(phase 2): report — consolidation, 2A/2B/2C, and the do-not-regre…
cursoragent Aug 8, 2026
2c2e007
docs: diagnosis-only pass on the consolidation-inherited failures
cursoragent Aug 8, 2026
20794bf
docs(spec): WRC Registry API Contract v1.0 (author document drop)
cursoragent Aug 8, 2026
892bacf
test(harness): add validated_at / validation_reason to createHarnessDb
cursoragent Aug 8, 2026
a5ad04b
test: align clone-prepare fixtures with coordination-device-id role d…
cursoragent Aug 8, 2026
3299671
test(seal-gate): assert the contract these four cases actually have
cursoragent Aug 8, 2026
c5447a4
test(coordination): pin the retired-relay refusal and stop reading am…
cursoragent Aug 8, 2026
b46680a
docs: consolidation-inherited remediation acceptance
cursoragent Aug 8, 2026
4a3695b
docs: record author dispositions for the three carried-forward items
cursoragent Aug 8, 2026
58aa71c
phase 3 (3A/3B/3C/3D/3E/3F): WRC resolution client, contract-first
cursoragent Aug 8, 2026
ef87c6b
phase 3: exit-criteria tests — hardening, divergence matrix, r7 align…
cursoragent Aug 8, 2026
1c1cb3e
docs(phase 3): report — resolution infrastructure
cursoragent Aug 8, 2026
d8ac21b
phase 3 addendum (3G): contract v1.1 — delegation travels in the head
cursoragent Aug 9, 2026
de25492
docs(phase 3): 3G addendum + codified standing rules
cursoragent Aug 9, 2026
3a77709
pre-phase-4 (i): split the conflated inbox-read error code
cursoragent Aug 9, 2026
49022f0
pre-phase-4 (iii): move the anti-rollback epoch floor into the native DB
cursoragent Aug 9, 2026
74e6f70
pre-phase-4 (ii): seal-key-source policy findings — diagnosis only
cursoragent Aug 9, 2026
df3dcdf
test(wrc): the floor survives eviction because of where it lives now
cursoragent Aug 9, 2026
97cb52a
docs: pre-Phase-4 block acceptance report
cursoragent Aug 9, 2026
56dbf7c
docs: pin the pre-block tip hash in the report
cursoragent Aug 9, 2026
3af4af8
phase 4 (4A/4B): A6 status composition and the resolution-bearing offer
cursoragent Aug 9, 2026
485880c
phase 4: keep the staged-offer table to its one owning module
cursoragent Aug 9, 2026
0a7ca3a
docs(phase 4): report — entry lifecycle and offer schema
cursoragent Aug 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
21 changes: 21 additions & 0 deletions .cursor/rules/graphify.mdc
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
---
description: graphify knowledge graph context
alwaysApply: true
---

This project can build a Graphify knowledge graph under `graphify-out/` (generated locally; not committed). Scope/exclusions: `.graphifyignore` and `code/.graphifyignore`.

**When exploring architecture, prefer Graphify if a local graph exists:**
- `graphify query "<question>"` — scoped subgraph for codebase or architecture questions
- `graphify path "<A>" "<B>"` — dependency path between two symbols
- `graphify explain "<concept>"` — nodes related to a concept

If `graphify-out/graph.json` is missing, regenerate with AST-only Graphify against `code/` (respect `.graphifyignore`; do not ingest PDFs), then query. Treat Graphify edges as hints — always source-verify before concluding.

Only use Read/Grep/Glob directly when:
1. Graphify has already oriented you and you need specific lines
2. Graphify is unavailable and regeneration is not practical

- If `graphify-out/wiki/index.md` exists, navigate it instead of reading raw files
- Read `graphify-out/GRAPH_REPORT.md` only for broad architecture review when query/path/explain are insufficient
- After substantial code changes, run `graphify update .` locally to refresh the graph (AST-only)
82 changes: 48 additions & 34 deletions .github/workflows/webmcp-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,79 +20,93 @@ jobs:
webmcp-release-gate:
name: "WebMCP Gate (build + unit tests)"
runs-on: ubuntu-latest
defaults:
run:
working-directory: code
steps:
- uses: actions/checkout@v4

- uses: actions/setup-node@v4
- name: Setup pnpm
uses: pnpm/action-setup@v4
with:
node-version: 20
cache: npm
version: 10.28.2

- name: Install root dependencies
run: npm ci
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: 22
cache: pnpm
cache-dependency-path: code/pnpm-lock.yaml

- name: Install extension dependencies
run: npm ci
working-directory: code/apps/extension-chromium
- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Build extension
run: npm run build
working-directory: code/apps/extension-chromium
run: pnpm --filter @optimandoai/extension-chromium run build

- name: Run WebMCP unit + sender-gate tests
run: npm run test:webmcp:ci
working-directory: code
run: pnpm run test:webmcp:ci

quarantine-monitor:
name: "Quarantine (pre-existing failures, non-blocking)"
runs-on: ubuntu-latest
continue-on-error: true
defaults:
run:
working-directory: code
steps:
- uses: actions/checkout@v4

- uses: actions/setup-node@v4
- name: Setup pnpm
uses: pnpm/action-setup@v4
with:
node-version: 20
cache: npm
version: 10.28.2

- name: Install root dependencies
run: npm ci
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: 22
cache: pnpm
cache-dependency-path: code/pnpm-lock.yaml

- name: Install extension dependencies
run: npm ci
working-directory: code/apps/extension-chromium
- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Run quarantined tests (informational)
run: npm run test:quarantine || true
working-directory: code
run: pnpm run test:quarantine || true

webmcp-e2e-smoke:
name: "WebMCP E2E Smoke (opt-in)"
runs-on: ubuntu-latest
if: ${{ github.event_name == 'workflow_dispatch' && inputs.run_e2e == true }}
defaults:
run:
working-directory: code
steps:
- uses: actions/checkout@v4

- uses: actions/setup-node@v4
- name: Setup pnpm
uses: pnpm/action-setup@v4
with:
node-version: 20
cache: npm
version: 10.28.2

- name: Install root dependencies
run: npm ci
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: 22
cache: pnpm
cache-dependency-path: code/pnpm-lock.yaml

- name: Install extension dependencies
run: npm ci
working-directory: code/apps/extension-chromium
- name: Install dependencies
run: pnpm install --frozen-lockfile

- name: Install Playwright browsers
run: npx playwright install --with-deps chromium
run: pnpm exec playwright install --with-deps chromium
working-directory: code/apps/extension-chromium

- name: Build extension
run: npm run build
working-directory: code/apps/extension-chromium
run: pnpm --filter @optimandoai/extension-chromium run build

- name: Run WebMCP E2E smoke
run: npm run test:e2e:webmcp
run: pnpm run test:e2e:webmcp
working-directory: code/apps/extension-chromium
15 changes: 15 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -40,3 +40,18 @@ code/packages/ingestion-core/src/*.js

# Chromium extension Vite outDir (versioned per release, e.g. build55647)
code/apps/extension-chromium/build*/

# graphify generated outputs + caches (regenerate with `graphify` / graphifyy)
# Keep hand-authored: .graphifyignore, code/.graphifyignore, .cursor/rules/graphify.mdc
graphify-out/
code/graphify-out/

# Cursor tooling artefacts (agent state, dumps). The Graphify↔Cursor
# integration is hand-authored and must stay visible: the always-on rule in
# .cursor/rules/ and, when used, .cursor/mcp.json.
.cursor/*
!.cursor/rules/
!.cursor/mcp.json

# Accidental vitest JSON dumps (not source)
code/phase2-before-native.json
34 changes: 34 additions & 0 deletions .graphifyignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
# Initial graphify pass: codebase AST only.
# PDFs and documentation are excluded; add selectively later with /graphify --update.
*.pdf
**/*.pdf
*.md
**/*.md
*.mdx
**/*.mdx
*.txt
**/*.txt
*.html
**/*.html
*.rst
**/*.rst
*.qmd
**/*.qmd
*.yaml
**/*.yaml
*.yml
**/*.yml
*.png
**/*.png
*.jpg
**/*.jpg
*.jpeg
**/*.jpeg
*.webp
**/*.webp
*.gif
**/*.gif
*.svg
**/*.svg
**/THIRD_PARTY_LICENSES/**
**/docs/**
4 changes: 4 additions & 0 deletions code/.gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -338,3 +338,7 @@ apps/extension-chromium/build179/
apps/extension-chromium/build180/
apps/extension-chromium/build181/
apps/extension-chromium/build182/

# Accidental vitest JSON dumps (not source)
phase2-before-native.json
*-before-native.json
34 changes: 34 additions & 0 deletions code/.graphifyignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
# Initial graphify pass: codebase AST only.
# PDFs and documentation are excluded; add selectively later with /graphify --update.
*.pdf
**/*.pdf
*.md
**/*.md
*.mdx
**/*.mdx
*.txt
**/*.txt
*.html
**/*.html
*.rst
**/*.rst
*.qmd
**/*.qmd
*.yaml
**/*.yaml
*.yml
**/*.yml
*.png
**/*.png
*.jpg
**/*.jpg
*.jpeg
**/*.jpeg
*.webp
**/*.webp
*.gif
**/*.gif
*.svg
**/*.svg
**/THIRD_PARTY_LICENSES/**
**/docs/**
4 changes: 2 additions & 2 deletions code/apps/electron-vite-project/electron-builder.config.cjs
Original file line number Diff line number Diff line change
Expand Up @@ -7,10 +7,10 @@ const appDir = __dirname

/**
* Parsed by scripts/kill-wr-desk.cjs — must contain a line matching:
* return 'C:\\build-output\\build044'
* return 'C:\\build-output\\build046'
*/
function windowsOutputDirMarker() {
return 'C:\\build-output\\build044'
return 'C:\\build-output\\build046'
}

const workspaceRoot = path.resolve(appDir, '../..')
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
/**
* Pure builder for `handshake:accept` IPC options — shared with preload tests.
* Forwards an explicit allowlist only (no pass-through of arbitrary objects).
* Internal vs normal and X25519 requirements are decided in main using persisted
* `record.handshake_type` — this module does not use `device_role` as proof of internal.
* Internal vs normal and X25519 requirements are decided in main using the persisted
* `record.same_principal` flag — this module does not use `device_role` as proof of internal.
*/

const MAX_B64 = 8192
Expand Down
Loading
Loading