Skip to content

jj - #10

Open
dsactivi-2 wants to merge 151 commits into
devshift-stack:mainfrom
dsactivi-2:main
Open

jj#10
dsactivi-2 wants to merge 151 commits into
devshift-stack:mainfrom
dsactivi-2:main

Conversation

@dsactivi-2

Copy link
Copy Markdown

bkmmm

claude and others added 30 commits December 23, 2025 15:50
- Fix critical bugs: add missing sample_call_log.json, implement error
  handling and input validation, remove unused datetime import
- Add YAML config loader to use flow_validator_checklist.yaml
- Implement risk level mapping (LOW/MEDIUM/HIGH/CRITICAL) matching
  supervisor dashboard expectations
- Include placeholder_used in risk calculation formula
- Extend keyword lists for price and legal detection (German/multi-currency)
- Add comprehensive pytest test suite with 33 tests covering all edge cases
- Add requirements.txt with PyYAML and pytest dependencies
- Expand README with installation, usage, API docs, and examples
- Fix YAML parsing issue with quoted strings
Major enhancements to agent log scorer:
- Refactored to OOP architecture with dataclasses
- Added AgentLogScorer class with batch processing support
- Implemented async batch processing for better performance
- Added ScoringConfig class loading keywords from YAML
- Added ReportGenerator for JSON/CSV/HTML exports
- Added DashboardGenerator for live supervisor dashboard
- Added AlertSystem for critical incident warnings
- Added AgentStatistics for per-agent performance tracking
- Added RiskLevel enum with comparison operators
- Extended CLI with new options: --batch, --html, --csv, --dashboard, --stats, --async
- Added GitHub Actions CI/CD pipeline with test matrix
- Added pre-commit hooks configuration
- Created test input logs for integration testing
- Extended test suite to 39 tests covering all new features
- Updated README with comprehensive documentation
- Maintained backward compatibility with legacy functions
…ments-804M2

Analyze repository for improvements and bugs
New documentation files:
- docs/DESIGN_SPECIFICATION.md: Complete UI/UX design guide
  - Color palette with risk-level colors
  - Typography scale and hierarchy
  - Component library specifications (badges, cards, alerts, tables)
  - Page layouts (dashboard, agents, alerts, reports)
  - Interaction patterns and animations
  - Responsive design breakpoints
  - Accessibility guidelines (A11Y)
  - Dark mode support
  - Icon set recommendations

- docs/FRONTEND_IMPLEMENTATION.md: Technical implementation guide
  - Recommended tech stack (Next.js, TypeScript, Tailwind)
  - Project structure
  - TypeScript type definitions
  - Component implementations (React/TSX)
  - Layout components (sidebar, header)
  - State management with Zustand
  - TanStack Query hooks
  - WebSocket integration for real-time updates
  - API client setup
  - Tailwind configuration

This documentation enables design and frontend agents to create
a consistent, accessible, and performant dashboard UI.
Implements a complete supervised AI system with:
- Engineering Lead Supervisor (plan, delegate, verify, STOP)
- Cloud Assistant (execute under supervision with evidence)
- Meta Supervisor (routing and monitoring)
- STOP scoring system with configurable thresholds
- Minimal Node/TS API service with Express
- SQLite persistence with in-memory fallback
- In-memory queue adapter (BullMQ scaffold)
- Integration stubs (WhatsApp, Voice, Google, iCloud, Pinecone)
- Docker Compose setup with optional Redis
- Comprehensive documentation (prompts, policies, runbooks, architecture)

All integrations are stubs - no live connections without explicit approval.
Pricing and legal facts marked as UNKNOWN per policy.
Implements ChatGPT's recommended improvements:

1. HARD GATE ENFORCEMENT
   - EnforcementGate class blocks tasks when STOP_REQUIRED
   - No task proceeds without explicit human approval
   - All decisions are audited

2. HUMAN APPROVAL FLOW
   - POST /api/enforcement/approve/:taskId - requires:
     * approver identity
     * reason (min 10 chars)
     * acknowledged_risks array
   - POST /api/enforcement/reject/:taskId - permanent stop
   - GET /api/enforcement/blocked - list blocked tasks

3. CLAIM-ARTEFACT VERIFICATION
   - Detects lies: "scraped 10 URLs" but only 1 file → STOP
   - Pattern matching for common claims
   - Generates verification reports

4. API INTEGRATION
   - Task creation evaluates content through gate
   - Work submission triggers enforcement check
   - Task GET shows enforcement status

Key difference from previous version:
- STOP is now BLOCKING, not just a status
- No automation can override STOP
- Human must explicitly approve with accountability
Features:
- Dashboard overview with live stats
- Task creation form
- Blocked tasks management (approve/reject)
- Audit log viewer
- Settings page with STOP score thresholds
- Auto-refresh every 5 seconds
- Toast notifications
- Dark theme (GitHub-style)

Endpoints now serve:
- / → Dashboard (HTML)
- /api → API info (JSON)
- /health → Health check
- /api/* → All API endpoints
…ments-804M2

Add comprehensive design and frontend implementation documentation
…-wsYBQ

Claude/analyze and optimize ws ybq
- Vite + React + TypeScript setup
- shadcn/ui components
- AgentCard, StatsCard, ActivityLog, SettingsPanel components
- CreateAgentDialog for new agent creation

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
- tailwind.config.js with shadcn/ui setup
- postcss.config.js for Tailwind processing
- tsconfig.json for React JSX support
- tsconfig.node.json for Vite config
- Added missing devDependencies (@types/react, tailwindcss, etc.)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
- Fixed sonner import (removed version suffix)
- Added Dialog for agent-specific settings
- Settings include: Auto Restart, Log Level, Max Retries, Timeout

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
- Added electron/main.js for desktop wrapper
- Configured electron-builder for DMG/ZIP builds
- Updated package.json with electron scripts and build config
- Removed unused backend dependencies (better-sqlite3, express)
- Updated .gitignore for build artifacts

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
- Add CLAUDE.md with global coding standards (TypeScript strict, naming conventions, security rules)
- Add slash commands: /review, /search, /implement, /fix, /agent-status
- Configure supervisor system rules (STOP-Score, Evidence-Based Verification)
- No lies, no hallucinations
- Work fast, don't wait unnecessarily
- Active thinking: plan, check errors, test
- Never forget: Frontend ↔ Backend integration, Security
- Less talking, more coding
- Create data/ directory with .gitkeep for SQLite database
- Add better-sqlite3 dependency (required by src/db/database.ts)
- Add @types/better-sqlite3 for TypeScript support
- Add @types/express for TypeScript support
- Add SETUP_ISSUES.md documenting all setup problems
- Add AGENT_A2_REPORT.md with complete task report

Backend now starts successfully. Frontend works. Tests still fail due to architectural issue (need separate backend/frontend tsconfig or tsx for tests).
Backend Fixes:
- Fix better-sqlite3 ESM import (BetterSqlite3 → Database)
- Fix test imports (.js → .ts for tsx compatibility)
- Update package.json test script to use tsx

Webhooks Module:
- Webhook registration and management
- Automatic retry with exponential backoff
- HMAC-SHA256 signature verification
- Delivery history tracking
- Event-based triggers (task.*, stop_score.*, enforcement.*)

Billing & Cost Tracking:
- Track API costs per model/user/repo/task (USD/EUR)
- User monthly limits with admin controls
- Automatic model selection by supervisor (Haiku/Sonnet/Opus)
- Cost analysis and reporting
- Pricing for Anthropic/OpenAI/xAI/Ollama models

Module Status System:
- Visual status indicators (🟢 ready, 🟡 buggy, 🔴 in-progress, ⚫ not-started)
- Module registry with 25+ tracked modules
- Test status tracking
- Known issues documentation

API Endpoints Added:
- POST /api/webhooks - Register webhook
- GET /api/webhooks - List webhooks
- POST /api/webhooks/incoming - Receive incoming webhooks
- GET /api/billing/summary - Cost summary
- POST /api/billing/limits - Set user limits (Admin)
- POST /api/billing/model-select - Get model recommendation
- GET /api/modules - List all modules
- GET /api/modules/report - Module status report

Tests:
- 14/15 tests passing (1 assertion mismatch)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <[email protected]>
Cloud Agents Bot and others added 27 commits December 31, 2025 04:34
- Move /status/all route before /:id to prevent path conflicts
- Re-add agent system imports after git rebase

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
- Daily cron job at 6:00 AM
- Slack notifications on WARN/FAIL
- Checks: PM2, ports, API, disk, RAM, logs

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
- Add log object with info, warn, error, debug helpers
- Add metrics object with count, gauge, distribution, set, timing
- Update ecosystem.config.cjs with optimized PM2 settings
- Fix unused variable in task-queue.ts

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
Admin dashboard expects backend on port 3000

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
When Claude (Anthropic) fails with 429 rate limit, automatically
tries OpenAI (gpt-4o) as fallback, then Gemini if available.

- getProviderOrder() determines fallback sequence
- Logs rate limit warnings to Sentry
- Tries all available providers before failing

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
Phase-1 Hardening - All critical routes now require authentication:

- agent-control.ts: requireAdmin (agent start/stop/control)
- agent-tasks.ts: requireAuth (task management)
- modules.ts: requireAuth (module status)
- settings.ts: requireAuth + owner check (user settings)
- tasks.ts: requireAuth (task CRUD)
- memory.ts: requireAuth (chat/message CRUD)

Security improvements:
- Users can only access their own settings (owner check)
- Admins can access all settings
- All agent control restricted to admins only

Also fixes TypeScript errors in sentry.ts

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
Phase-1 Hardening - Webhook signature verification is now MANDATORY:

- GitHub webhooks: GITHUB_WEBHOOK_SECRET must be configured
- Linear webhooks: LINEAR_WEBHOOK_SECRET must be configured
- Without configured secrets, webhooks return 500 (not silently accepted)
- Invalid signatures return 401

This prevents accepting unverified webhooks when secrets are not set.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
…d/messages)

- GET /api/chat/threads - list user threads
- POST /api/chat/threads - create new thread
- GET /api/chat/threads/:id/messages - get thread messages
- Add createChat method to ChatManager

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
Backend Tasks:
- GET /api/agents/status: Returns status overview for MCP tools
- GET /api/tasks?state=: Filter by running|failed|done|pending
- seedDefaultAdmin(): Auto-creates admin on first startup
- Tests: 14 new tests (4 agents/status, 10 tasks filter)
- docs/API_CURL_EXAMPLES.md: curl examples for all endpoints

ENV variables:
- SEED_ADMIN_EMAIL, SEED_ADMIN_PASSWORD, SEED_ADMIN_NAME

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
Backend:
- Add brain DB tables (brain_docs, brain_chunks, brain_embeddings)
- Implement BrainManager for document ingestion and CRUD
- Implement BrainSearch with semantic, keyword, and hybrid search
- Add Brain API endpoints (ingest, search, docs, stats, link)

Frontend:
- Add BrainMemoryPage component with search and ingest UI
- Add Brain tab to main navigation
- Include all required data-testid attributes

Tools:
- Add /brain slash command
- Add brain-cli.ts CLI tool

Tests:
- Add 24 comprehensive tests for BrainManager (all passing)

Also fixes unused variable in chat.ts

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
The auth middleware sets req.userId directly, not req.user.userId.
This fix aligns brain.ts with the actual middleware behavior.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
Phase 2 auth standardization:
- requireAuth() now extracts userId from JWT token
- requireAdmin() extracts userId + role from JWT
- optionalAuth() supports optional JWT parsing
- Removed x-user-id header dependency
- Added extractJwtPayload() helper function

Breaking change: x-user-id header no longer used

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
- Fix date-fns version (^3.6.0) for react-day-picker compatibility
- Regenerate clean package-lock.json
- Update .env.example with all environment variables
- Add scripts/deploy.sh for clean deployments using npm ci

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
tsx is required at runtime for backend:prod script.
Moved from devDependencies to dependencies.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
dotenv was being used but not listed in package.json.
Required for production builds.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
- src/db/audit-events.ts: Event table + AuditService
- src/lib/events.ts: Global recordEvent() helper
- Task lifecycle: created, started, finished, failed
- Chat events: message sent
- Auth events: login, logout
- Events persisted to SQLite, survive restarts

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
feat: Add persistent event logging (audit_events)
- Extended /api/audit with events endpoints (POST/GET/stats/cleanup)
- Added audit logging to brain service (ingest, search)
- Integrated AuditService into database module
- Support for filtering events by kind, severity, userId

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
* feat: Add Ops Dashboard API endpoints

Backend:
- GET /api/ops/events - Unified event stream from tasks & audit
- GET /api/ops/tasks/history - Task history with duration & audit data
- GET /api/ops/stats - Aggregated statistics (Admin only)

Features:
- Filter events by since, limit, agentId, type
- Filter task history by status, assignee, includeAudit
- Aggregate stats per agent with completion/stop rates

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>

* style: auto-fix linting and formatting

🤖 Auto-fixed by GitHub Actions

---------

Co-authored-by: devshift-stack <[email protected]>
Co-authored-by: Claude Opus 4.5 <[email protected]>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
- Support both port 4000 and 3002 for backend
- Use correct /health endpoint instead of /api/health
- Check for SQLite instead of PostgreSQL
- Accept 307/308 redirects for Next.js dashboard
- Dynamic port detection for API endpoint tests

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>
- Add brain-proxy.ts: HTTP proxy to Brain Server (49.13.158.176:5001)
- Add brain/client.ts: BrainClient HTTP adapter
- Update index.ts: Conditional proxy mode via BRAIN_SERVER_URL env
- Update ecosystem.config.cjs: Add BRAIN_SERVER_URL config
- Add start-backend.sh: Wrapper script with env vars for PM2

Architecture:
- Cloud-Agents (178.156.178.70:3001) proxies /api/brain/* to Brain-Server
- Brain-Server (49.13.158.176:5001) stores all knowledge base data centrally
- Fallback to local mode if BRAIN_SERVER_URL not set

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Deploy Bot <[email protected]>
Co-authored-by: Claude <[email protected]>
* feat: Add Core Brain integration for central knowledge base

- Add core-brain.ts client for connecting to brain-core API (49.13.158.176:5001)
- Implement Pre-Recall: Search core brain before AI response for context
- Implement Writeback: Store Q&A pairs in core brain (append-only)
- User mapping: Pass real userId to brain-core (auto-created if not exists)

Features:
- coreBrainSearch(): Search central knowledge base
- coreBrainStore(): Store memories (append-only, no overwrites)
- coreBrainRecent(): Get recent memories
- buildCoreBrainContext(): Build context string for prompt injection

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>

* style: auto-fix linting and formatting

🤖 Auto-fixed by GitHub Actions

* feat(auth): Add admin password reset endpoint

- POST /api/auth/reset-password (admin only)
- Validates password length (min 8 chars)
- Logs password_reset event to audit log
- Added new audit event types: password_reset, user_created, user_deleted

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>

* style: auto-fix linting and formatting

🤖 Auto-fixed by GitHub Actions

* feat(frontend): Add full API client and admin pages

- src/lib/api.ts: Complete API client with all 178 backend endpoints
  - Auth, Users, Agents, Tasks, Chat, Audit, Ops, Brain, Memory
  - Settings, Enforcement, GitHub, Linear, Webhooks, Modules, Billing
  - Full TypeScript types for all API responses

- src/components/UsersPage.tsx: User management (CRUD)
  - List, create, edit, delete users
  - Password reset functionality
  - Role management (admin/user/demo)
  - User stats dashboard

- src/components/AuditPage.tsx: Audit & Ops dashboard
  - Event log with filtering
  - Blocked tasks management (approve/reject)
  - Operations statistics
  - STOP-Score monitoring

- src/components/IntegrationsPage.tsx: External integrations
  - GitHub repos and issues
  - Linear teams and issues
  - Webhook management (CRUD, test)

- Updated App.tsx with new navigation tabs

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>

* style: auto-fix linting and formatting

🤖 Auto-fixed by GitHub Actions

---------

Co-authored-by: devshift-stack <[email protected]>
Co-authored-by: Claude Opus 4.5 <[email protected]>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
* feat: merge PR features with test-IDs from Optimizecodecloudagents

Components (with test-IDs):
- NEW: ThemeProvider.tsx - dark/light/system theme switching
- NEW: ThemeToggle.tsx - theme toggle dropdown button
- MERGED: AgentCard.tsx - added spokenLanguage, agentType, contentAutonomy
- MERGED: CreateAgentDialog.tsx - added influencer type, spoken language selector

Documentation:
- NEW: docs/AGENT_CONTROL.md - Agent Control API documentation

Fix:
- Fixed unused parameter warning in brain-proxy.ts

Features merged from PRs:
- PR #2: ThemeProvider, ThemeToggle
- PR #4: Influencer agent type, Serbian language support, content autonomy
- PR #7: AGENT_CONTROL.md API documentation

All components include data-testid attributes following naming convention:
cloudagents.{component}.{element}.{action}

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>

* style: auto-fix linting and formatting

🤖 Auto-fixed by GitHub Actions

* feat: Add test-IDs to UI components for E2E testing

Components updated:
- ActivityLog.tsx: cloudagents.activitylog.* test-IDs
- DemoDashboard.tsx: cloudagents.demodashboard.* test-IDs
- DemoPage.tsx: cloudagents.demopage.* test-IDs
- StatsCard.tsx: cloudagents.statscard.* test-IDs
- StatusDashboard.tsx: cloudagents.statusdashboard.* test-IDs
- TeamAgentCard.tsx: cloudagents.teamagent.* test-IDs
- TeamAgentList.tsx: cloudagents.teamagentlist.* test-IDs

All test-IDs follow the naming convention: cloudagents.{component}.{element}

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <[email protected]>

* style: auto-fix linting and formatting

🤖 Auto-fixed by GitHub Actions

---------

Co-authored-by: devshift-stack <[email protected]>
Co-authored-by: Claude Opus 4.5 <[email protected]>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Jan 1, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 298 files, which is 148 over the limit of 150.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment

Tip

Issue Planner is now in beta. Read the docs and try it out! Share your feedback on Discord.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@gitguardian

gitguardian Bot commented Jan 1, 2026 •

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 3 secrets following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

Since your pull request originates from a forked repository, GitGuardian is not able to associate the secrets uncovered with secret incidents on your GitGuardian dashboard.
Skipping this check run and merging your pull request will create secret incidents on your GitGuardian dashboard.

🔎 Detected hardcoded secrets in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
- - Company Email Password 1b6c78c send-access-email.js View secret
- - Generic Password 1de297d tests/password-hashing.test.ts View secret
23405797 Triggered Generic Password 963b819 tests/auth-improvements.test.ts View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants