Skip to content

C05: frontend recovery timeline and evidence history - #31

Merged
SuPuHe merged 1 commit into
developfrom
milestone/c05-frontend-recovery
Sep 8, 2026
Merged

SuPuHe merged 1 commit into
developfrom
milestone/c05-frontend-recovery

Conversation

@SuPuHe

@SuPuHe SuPuHe commented Sep 8, 2026 •

Copy link
Copy Markdown
Member

Summary

Adds C05 as an independently composable React/Vite recovery timeline with a frozen sanitized mock boundary, provenance-aware evidence history, Graph/MCP diagnostics, bounded advisor/core decisions, and safe UNKNOWN handling.

Scope and acceptance criteria

  • Change is limited to C05 and its workspace wiring.
  • Ordered, paginated, deduplicated timeline handles clock ambiguity.
  • Authority, evidence provenance, Graph/MCP, LLM advice, and deterministic core remain visually separate.
  • UNKNOWN blocks settlement; only refresh, escalation, and load-earlier actions exist.
  • Required fixture, component, accessibility, keyboard, responsive, lint, type, test, and build evidence passes.
  • No unrelated cleanup included.

Product and security invariants

  • Tenant isolation remains fail-closed.
  • Sponsor authorization, auditability, and daily caps remain enforced where applicable.
  • Recipients cannot modify sponsor controls or access sponsor-only data.
  • No secret, token, production identifier, or personal data is committed or pasted into review prompts.

Invariant notes: UI is read/escalate-only and has no settlement, signing, retry, payment, or sponsor-control path. Sanitized parser rejects forbidden raw-provider keys and secret-shaped strings before render.

Validation

pnpm install --frozen-lockfile: PASS
pnpm --filter @oneshot/recovery-ui run verify: PASS (50 tests, lint/type/build)
pnpm lint / typecheck / check:generated / validate:fixtures: PASS
pnpm test rerun: PASS (560 tests)
markdownlint new docs: PASS
visual desktop + 390px inspection: PASS, no horizontal overflow
root format:check: known baseline failure on 122 untouched Windows CRLF files
Docker integration: unavailable; C05 adds no database/runtime integration path

Independent review evidence

Gate A — exact candidate tree before push

  • Base commit SHA: 25a17d8

  • Candidate tree SHA: be0640868862080bc452bf966bffd32053465f5d

  • Candidate commit SHA: cf0b79b

  • Reviewer tool: free-pi-cli

  • Reviewer model: free-pi/glm-5.3-flash (CLI selected; verdict reported model not exposed by platform)

  • Verdict: VERDICT: PASS

  • Findings: four non-blocking hardening notes (load-more error surfacing, malformed dev-mock URI, axe contrast follow-up at P5, refresh history reset).

  • Reviewed tree equals committed tree.

Gate B — exact remote PR head

  • Pending required CI and fresh exact-head review.

Risk and rollback

  • Residual risks: Gate P5 must preserve authority separation and safe-action boundary; Docker/live network behavior belongs to later integration gates.
  • Rollback: revert cf0b79b.

Human merge

  • Human owner reviews evidence and performs merge.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
oneshot cf0b79b Sep 08 2026, 07:24 AM

@SuPuHe
SuPuHe marked this pull request as ready for review September 8, 2026 11:17
@SuPuHe
SuPuHe merged commit 1250dec into develop Sep 8, 2026
4 checks passed
@SuPuHe
SuPuHe deleted the milestone/c05-frontend-recovery branch September 8, 2026 22:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant