Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
469 commits
Select commit Hold shift + click to select a range
78ccb69
Align contract tests with checkout crash and shared order data coverage
bradleyshep Sep 17, 2026
936f348
Keep the active capacity test blocked until the next attempt starts
bradleyshep Sep 17, 2026
750522c
Bind qualified L3 checkout crash reference and defect evidence
bradleyshep Sep 17, 2026
e2715c6
Classify guarantees blocked by failed prerequisites in score reports
bradleyshep Sep 17, 2026
b348216
Add draft stored-review script diagnostic and persistent browser obse…
bradleyshep Sep 17, 2026
2b5ec8e
Score stored review script safety under the reviews feature
bradleyshep Sep 17, 2026
7cd96d0
Bound optional review setup navigation wait
bradleyshep Sep 17, 2026
7e3f3b9
Qualify L3 stored review script safety across all stacks
bradleyshep Sep 17, 2026
70aac0f
Add bounded review owner forgery diagnostic
bradleyshep Sep 18, 2026
e804c13
Extend review eligibility checks to reject forged ownership
bradleyshep Sep 18, 2026
b104d39
Reuse unchanged qualification evidence with validated check slices
bradleyshep Sep 18, 2026
bf7650f
Add bounded full-password verification diagnostic
bradleyshep Sep 18, 2026
fa4307c
Add draft opt-in identity service and browser account grading
bradleyshep Sep 18, 2026
f9add93
Use local password procedures in the SpacetimeDB reference
bradleyshep Sep 18, 2026
5c3df93
Refresh draft qualification bindings for local authentication
bradleyshep Sep 18, 2026
7497114
Add a pinned Convex native integration slice
bradleyshep Sep 18, 2026
d1d4308
Keep account recovery mutation past authentication setup
bradleyshep Sep 18, 2026
a098067
Refresh the accounts qualification runtime budget
bradleyshep Sep 18, 2026
c5dd2ea
Scope qualification reuse to the measured reference stack
bradleyshep Sep 18, 2026
9d5c0f6
Remove the unused external authentication provider
bradleyshep Sep 18, 2026
b567fe7
Prove local Convex accounts and atomic signup refusal
bradleyshep Sep 18, 2026
f6b3ab6
Prove Convex local restart and clean reset behavior
bradleyshep Sep 18, 2026
f959882
Require full password verification and strengthen reference hashing
bradleyshep Sep 18, 2026
1742062
Prove Convex launch through owned runtime lifecycle
bradleyshep Sep 18, 2026
7403837
Record reasons for incomplete transport evidence
bradleyshep Sep 18, 2026
6ba6e92
Preserve captured HTTP bodies across app reloads
bradleyshep Sep 18, 2026
e1b057c
Prove owned Convex restart and state reset
bradleyshep Sep 18, 2026
cb0463c
Verify Convex attempt isolation and interrupted startup cleanup
bradleyshep Sep 18, 2026
564f1fa
Keep credentials out of reference request-error logs
bradleyshep Sep 18, 2026
2ccb2df
Prove Convex deployment through the owned coding container
bradleyshep Sep 18, 2026
f7f8c5f
Add native Convex ecommerce support and qualification controls
bradleyshep Sep 19, 2026
7dee6df
Correct Convex defect controls to exercise their declared checks
bradleyshep Sep 19, 2026
f027191
Narrow Convex cart and signed-out purchase defect controls
bradleyshep Sep 19, 2026
d66236c
Exclude local reference builds from source inspection
bradleyshep Sep 19, 2026
e38c0f2
Add bounded session tampering diagnostic
bradleyshep Sep 19, 2026
c6fe1bd
Integrate session tampering into purchase authorization check
bradleyshep Sep 19, 2026
1d147c9
Prove isolated bearer access before session tampering
bradleyshep Sep 19, 2026
2170999
Test submitted administrator claims on restock writes
bradleyshep Sep 19, 2026
74aea51
Validate stored purchase effects under client price claims
bradleyshep Sep 19, 2026
3aecb76
test(stack-bench): check order privacy across account switches
bradleyshep Sep 19, 2026
9f4f6dd
test(stack-bench): reconcile checkout price claims with stored effects
bradleyshep Sep 19, 2026
c32e836
Validate every product in checkout orders and refusals
bradleyshep Sep 19, 2026
3e494a0
Extend checkout crash checks to two-product orders
bradleyshep Sep 19, 2026
4eb258d
Retain item-keyed stock in native checkout observations
bradleyshep Sep 19, 2026
47cbcf1
Scope checkout crash stock reads to delivered task contracts
bradleyshep Sep 19, 2026
4c24f9a
Preserve resolved task requests in grade artifacts
bradleyshep Sep 19, 2026
77d30d1
Isolate Convex crash durability control from stock changes
bradleyshep Sep 19, 2026
83f5f8b
Add stock-only checkout crash controls for all stacks
bradleyshep Sep 19, 2026
fb58e1a
Scope stock fault control to the disconnecting account
bradleyshep Sep 19, 2026
728ecd5
Isolate checkout crash trials from lingering reservations
bradleyshep Sep 19, 2026
20f5604
Make the stock disconnect defect fire once per fixture
bradleyshep Sep 19, 2026
c317686
Keep reference drawers below the navigation header
bradleyshep Sep 19, 2026
8ef6e78
Place reference navigation before supplemental panels
bradleyshep Sep 19, 2026
43d5f71
Add native shipping versus cancellation diagnostic
bradleyshep Sep 20, 2026
4c22073
Prevent shipping cancelled orders in MongoDB reference
bradleyshep Sep 20, 2026
43d54a4
Validate shipping and cancellation under the existing queue check
bradleyshep Sep 20, 2026
1aab5f7
Validate opposing transfers in the stock conservation check
bradleyshep Sep 20, 2026
f51d216
Check cart additions that overlap checkout
bradleyshep Sep 20, 2026
6b47718
Add mixed-operation state reconciliation for coverage pilot
bradleyshep Sep 20, 2026
314b03d
Exercise mixed operation histories through the live grader
bradleyshep Sep 20, 2026
d815d92
Qualify mixed operation history in normal grading
bradleyshep Sep 20, 2026
17aa151
Add qualified lost checkout reply diagnostic
bradleyshep Sep 20, 2026
ddfaa38
Integrate lost reply recovery into duplicate checkout grading
bradleyshep Sep 20, 2026
25e1509
Qualify lost order and false checkout confirmation controls
bradleyshep Sep 20, 2026
a0f408a
Check revenue and warehouse totals across bounded order populations
bradleyshep Sep 20, 2026
c5e91a9
Verify committed catalog creation before continuing UI seeding
bradleyshep Sep 20, 2026
bc4d9d3
Grade committed catalog completeness across a bounded product population
bradleyshep Sep 20, 2026
8ce43a6
Honor selected pack budgets in grading deadlines
bradleyshep Sep 20, 2026
2ba5aac
Check shipping role claims and preserve authorized fulfillment
bradleyshep Sep 20, 2026
3b69b73
Check cancellation owner claims and preserve valid cancellation
bradleyshep Sep 20, 2026
8ec639e
Fix SpacetimeDB catalog refusal control compilation
bradleyshep Sep 20, 2026
92b6e61
Check purchases from untrusted browser origins
bradleyshep Sep 20, 2026
264b681
Check account password disclosure to other clients
bradleyshep Sep 20, 2026
666cd90
Verify purchase authority ends at browser signout
bradleyshep Sep 20, 2026
35a5831
Check public assets for account password disclosure
bradleyshep Sep 20, 2026
d7024be
Check signup claims cannot grant stock-write authority
bradleyshep Sep 20, 2026
1323d4f
Qualify bounded login input against stored purchase effects
bradleyshep Sep 20, 2026
55750d2
Check stored orders after rejected purchase access
bradleyshep Sep 20, 2026
75cfc46
Preserve authentication submission error classification
bradleyshep Sep 20, 2026
743ffa0
fix(stack-bench): size concurrency qualification budget from measured…
bradleyshep Sep 20, 2026
1a70f92
fix(stack-bench): bind mutation targets to the full recipe
bradleyshep Sep 20, 2026
9854dcb
Fix background updates erasing reference form drafts
bradleyshep Sep 21, 2026
910d81f
Fix MongoDB negative-quantity defect control
bradleyshep Sep 21, 2026
6977247
Qualify four-stack ecommerce L1-L3 production checks
bradleyshep Sep 21, 2026
93bffe3
Verify delegated Convex resource ownership
bradleyshep Sep 21, 2026
94c6dc3
Mark qualification pending after Convex runtime fix
bradleyshep Sep 21, 2026
2ece35c
Stop the previous reference app before redeployment
bradleyshep Sep 21, 2026
a3a706a
Show distribution axes before runs complete
bradleyshep Sep 21, 2026
7995336
Fix saved-source regrade for inconclusive selection summaries
bradleyshep Sep 21, 2026
f541f99
Fix Convex credential probes and session replay
bradleyshep Sep 21, 2026
2c4ea51
Register Convex session capture in qualification scope
bradleyshep Sep 21, 2026
2036015
Show standalone reference validation in the dashboard
bradleyshep Sep 21, 2026
e7d665e
Page campaign history and keep dashboard reads responsive
bradleyshep Sep 21, 2026
94a8400
Compact dashboard reference validation rows
bradleyshep Sep 21, 2026
12d2076
Bind Convex proxy sessions and record stalled navigation resources
bradleyshep Sep 21, 2026
3e26823
Preserve the saved Convex endpoint during regrading
bradleyshep Sep 21, 2026
3b4d853
Allow requested navigation through beforeunload warnings
bradleyshep Sep 21, 2026
5159c39
Do not impose a fulfilment state on basic purchase checks
bradleyshep Sep 21, 2026
3f7f391
Keep generic checkout independent of fulfilment status
bradleyshep Sep 21, 2026
9473ff6
Qualify corrected Convex grading with targeted controls and reviewed …
bradleyshep Sep 21, 2026
909d65a
Fix lazy customer identity in native order grading
bradleyshep Sep 22, 2026
0c6d8de
Retain browser errors when grading setup fails
bradleyshep Sep 22, 2026
46edd50
Trigger Convex crash controls before reconnect backoff
bradleyshep Sep 22, 2026
cbd9a3c
Retry only isolated inconclusive grading suites
bradleyshep Sep 22, 2026
0a2b4cf
Avoid duplicate Convex observer ownership checks
bradleyshep Sep 22, 2026
e0ced9d
Keep reference qualification free of automatic suite retries
bradleyshep Sep 22, 2026
a367370
Avoid duplicate waits when filling dropdowns
bradleyshep Sep 22, 2026
c5f33cc
Merge origin/master into bradley/stackbench-test
bradleyshep Sep 22, 2026
84e463b
Add a readable check guide to the local dashboard
bradleyshep Sep 22, 2026
9f89109
Reduce Convex observer transport overhead
bradleyshep Sep 22, 2026
31428c7
Clean up Stack Bench docs
bradleyshep Sep 22, 2026
3f58541
Trim duplicated rules from the study method
bradleyshep Sep 22, 2026
e2cc4bc
Sync the TypeScript server skill's plugin copy
bradleyshep Sep 22, 2026
4910bbf
Keep the codegen commit hash fresh in local builds
bradleyshep Sep 22, 2026
95498b3
Drop arbitrary length bound from TableRef diagnostic test
bradleyshep Sep 22, 2026
2632bf1
Keep operator Claude config out of sequential-upgrade agents
bradleyshep Sep 22, 2026
671f830
Align sequential-upgrade agent instructions with its access
bradleyshep Sep 22, 2026
48eb8cb
Point the grading session at GRADING.md
bradleyshep Sep 22, 2026
708f74e
Simplify dashboard navigation and the Checks page
bradleyshep Sep 22, 2026
8f05845
Remove presentation-only assertions from dashboard tests
bradleyshep Sep 22, 2026
1a24dbf
Do not write repair reports through agent-planted links
bradleyshep Sep 22, 2026
e2d24b3
Score lifecycle control faults against the app only when it is at fault
bradleyshep Sep 22, 2026
029488f
Keep harness and navigation faults out of contract lint app failures
bradleyshep Sep 22, 2026
8d26d75
Treat readiness probe timeouts as unmeasured, not app failures
bradleyshep Sep 22, 2026
4556b74
Keep checks measured before an application abort
bradleyshep Sep 22, 2026
b2ade05
Label cost-cap stops instead of reporting provider failures
bradleyshep Sep 22, 2026
653d5c3
Mark session cost unknown when an invocation leaves no result
bradleyshep Sep 22, 2026
2efe917
Make a replayed repair grant return its original continuation
bradleyshep Sep 22, 2026
9ac3c6b
Stop a Docker credential broker when its controller dies
bradleyshep Sep 22, 2026
bb4eb99
Let the stored effect decide an accepted forged write
bradleyshep Sep 22, 2026
2e6a5bc
Treat cross-origin fixture setup failures as harness faults
bradleyshep Sep 22, 2026
323b331
Count only regular files in app code metrics
bradleyshep Sep 22, 2026
1bbb464
Do not pause a continuation that inherited the paused depth
bradleyshep Sep 22, 2026
e94cfd2
Subtract every provider wait from active time, and only this execution's
bradleyshep Sep 22, 2026
ab6e5f2
Adopt a dispatched claim only after its state write succeeds
bradleyshep Sep 22, 2026
4d3b5e5
Refuse new attempt resources on a finished lease
bradleyshep Sep 22, 2026
07a5724
Measure a continued attempt's time and tokens across its chain
bradleyshep Sep 23, 2026
c96761a
Order dashboard grade history with the final grade last
bradleyshep Sep 23, 2026
df1d389
Score an early-stopping sequential attempt against every planned level
bradleyshep Sep 23, 2026
03081d4
Count ladder regressions as kept passes that later fail
bradleyshep Sep 23, 2026
1eaaa19
Keep earlier features' measured failures when the app aborts
bradleyshep Sep 23, 2026
4090eaf
Show unmeasured and excluded attempts without a completion rate
bradleyshep Sep 23, 2026
20a449c
Credit a mutation kill only when the target fails at an observation
bradleyshep Sep 23, 2026
4e51b9f
Make stock alert, recommendation and privacy checks measure their claim
bradleyshep Sep 23, 2026
3f0996c
Open stock alert settings with the shared settings sentinel
bradleyshep Sep 23, 2026
42df6e7
Run credential tampering steps unmodified on typed-argument stacks
bradleyshep Sep 23, 2026
d117ab2
Remove qualification evidence no calibration cites
bradleyshep Sep 23, 2026
1d33619
Use the launcher's build container name in smoke and fault checks
bradleyshep Sep 23, 2026
a19e9e3
Kill only the process group after a bounded child is reaped
bradleyshep Sep 23, 2026
b51853c
Signal a coding session with the agent's authority
bradleyshep Sep 23, 2026
434b910
Keep a bench lease whose release was refused at startup
bradleyshep Sep 23, 2026
5fb9602
State where a qualifying mutation must fail
bradleyshep Sep 23, 2026
bffef2d
Report an uninterceptable credential probe as unmeasured
bradleyshep Sep 23, 2026
b016a98
Classify lost container ownership as a harness failure
bradleyshep Sep 23, 2026
eefcce0
Time a continued attempt across its chain in the dashboard too
bradleyshep Sep 23, 2026
a35ef51
Report unknown tokens when a level has no token record
bradleyshep Sep 23, 2026
9287e6a
Probe credential tampering through the request the app sends
bradleyshep Sep 23, 2026
86a219b
Check L1 mutation targets against every recipe
bradleyshep Sep 23, 2026
d300e55
Pin the SpacetimeDB reference to the 2.11.0 SDK tarball
bradleyshep Sep 23, 2026
0a5ea93
Score dependency report curves with the progression's rules
bradleyshep Sep 23, 2026
ee08b28
Make going offline actually interrupt the app's live connection
bradleyshep Sep 23, 2026
5cc2cd2
Score reconnect catch-up once, through a real disconnect
bradleyshep Sep 23, 2026
3858d09
Break the two circular imports through the stack adapter registry
bradleyshep Sep 23, 2026
83ce64d
Hold the TypeScript-only rule to harness code
bradleyshep Sep 23, 2026
2a7cdb4
Give crash-diagnostic fake actors the page the credential reader uses
bradleyshep Sep 23, 2026
7d25c10
Leave the dev server's reload socket out of network interruption
bradleyshep Sep 23, 2026
0556ff3
State when a staff role change takes effect
bradleyshep Sep 23, 2026
da7fd6a
Disclose that exposed operations must complete overlapping requests
bradleyshep Sep 23, 2026
951ec3d
Give each duplicated behavior one scoring owner
bradleyshep Sep 23, 2026
d3028fe
Let in-flight requests finish before the network interruption
bradleyshep Sep 23, 2026
0e7b43c
Bring six stale test expectations up to the current definitions
bradleyshep Sep 23, 2026
66dd78b
Keep the capacity-wait test's fake attempt alive like a child process
bradleyshep Sep 23, 2026
ab4f467
Keep one scoring basis per report curve
bradleyshep Sep 23, 2026
baa3e15
Place tampered sign-up fields only where the module schema declares them
bradleyshep Sep 23, 2026
6eb5a50
Exempt only the dev server's own reload socket from the network cut
bradleyshep Sep 23, 2026
89bd785
State that a business refusal still completes an overlapping request
bradleyshep Sep 23, 2026
9e57b59
Report an auth schema the probe cannot read as unmeasured, not absent
bradleyshep Sep 23, 2026
de3b15d
Observe the ordinary signup in 103b so a reject-all app is caught at …
bradleyshep Sep 23, 2026
dd78cbc
Cut an offline actor's connections with a proxy where the browser runs
bradleyshep Sep 23, 2026
bc0c586
Wait for the interruption proxy to exit when it is disposed
bradleyshep Sep 23, 2026
c18c5d6
Name the connections that stayed open through a network interruption
bradleyshep Sep 23, 2026
dcbaffb
Forget a navigated document's sockets when proving a network cut
bradleyshep Sep 23, 2026
2f7873a
Say whether a socket left open was opened during the network cut
bradleyshep Sep 23, 2026
2138fc0
Support confirmed Convex mutation replay for grader setup
bradleyshep Sep 23, 2026
b586a0b
Speed up catalog setup with confirmed writes and safe UI fallback
bradleyshep Sep 23, 2026
be8becb
Reuse Convex HTTP mutation capture for catalog setup
bradleyshep Sep 23, 2026
4620b6e
Cut the actor's connections before emulating offline
bradleyshep Sep 23, 2026
f2889ef
State the proven network interruption coverage in the grader README
bradleyshep Sep 23, 2026
e7a40f9
Emulate offline before the cut and accept proxy closures as proof
bradleyshep Sep 23, 2026
f564937
Describe the offline order and cut proof in the grader README
bradleyshep Sep 23, 2026
8e5ecad
Reduce Convex observer container inspection overhead
bradleyshep Sep 23, 2026
6fde5cc
Reuse scoped MongoDB observer processes for fresh grading snapshots
bradleyshep Sep 23, 2026
74b9277
Restore the chat-app sequential-upgrade tool to master
bradleyshep Sep 24, 2026
31030f2
Fold the technical guide and system map into the owning docs
bradleyshep Sep 24, 2026
8f246d9
Reuse feature-scoped Convex observer credentials with fresh lease val…
bradleyshep Sep 24, 2026
9b78401
Merge duplicate runtime, stack, and lease tests
bradleyshep Sep 24, 2026
d3020f2
Merge duplicate definition and calibration tests
bradleyshep Sep 24, 2026
f58c716
Merge duplicate grading tests and refresh stale integration fixtures
bradleyshep Sep 24, 2026
de71b94
Merge duplicate orchestration tests and drop the opt-in capacity test
bradleyshep Sep 24, 2026
7920d37
Trim presentation-only assertions from reporting tests
bradleyshep Sep 24, 2026
b21ba96
Limit auth WebSocket interception to credential probes
bradleyshep Sep 24, 2026
1a755f0
Remove unused CLI flags, duplicate scripts, and unread compatibility …
bradleyshep Sep 24, 2026
21b4fbf
Keep wrong-database failures within the repair report's language
bradleyshep Sep 24, 2026
82aec2a
Remove unreachable guards, unused re-exports, and a stale reducer mes…
bradleyshep Sep 24, 2026
09a8178
Replay SpacetimeDB catalog setup writes on the active browser connection
bradleyshep Sep 24, 2026
81bd001
Give six absence checks a positive control in the same criterion
bradleyshep Sep 24, 2026
ffb98b3
Classify the same stock data the same way on every stack
bradleyshep Sep 24, 2026
98ec829
Keep campaign recovery and continuations from losing finished work
bradleyshep Sep 24, 2026
9445327
Refuse unpriced Anthropic options and pass one API key source to pref…
bradleyshep Sep 24, 2026
b726692
Keep a resumed execution's unknown spend unknown
bradleyshep Sep 24, 2026
21b0d45
Keep recovery authority after a failed repair cleanup and document a …
bradleyshep Sep 24, 2026
4c736c3
Keep the report curve and campaign state honest after rejected repairs
bradleyshep Sep 24, 2026
290b96b
Resume dashboard job campaigns with their saved settings and align th…
bradleyshep Sep 24, 2026
314496d
Make the Convex test fixtures pass lint
bradleyshep Sep 24, 2026
88ba9c6
Keep SDK dependencies out of the controller's embedded package
bradleyshep Sep 24, 2026
89fbca8
Refresh three integration fixtures to the current actor shape
bradleyshep Sep 24, 2026
c419f97
Run the offline proxy beside an unleased browser
bradleyshep Sep 24, 2026
1ed79df
Make each L1-L3 mutation fail its target at an observation
bradleyshep Sep 24, 2026
43624e2
Give 105a a mutation it observes on every stack
bradleyshep Sep 24, 2026
37afc22
Confirm the cart line before 105b drops the connection
bradleyshep Sep 24, 2026
c862e92
Observe the unpublished product and a self-reloading signout at asser…
bradleyshep Sep 24, 2026
cc8226a
ups
bradleyshep Sep 24, 2026
fd28531
Skip restock navigation waits when the form is already open
bradleyshep Sep 24, 2026
3213109
Cache compiled plans and read live transcripts incrementally
bradleyshep Sep 24, 2026
493aea3
Qualify the four-stack ecommerce L1-L3 dependency calibration
bradleyshep Sep 24, 2026
45574d7
Reserve measured startup memory instead of summed container caps
bradleyshep Sep 24, 2026
23d7105
Hash the qualification scope with Git's line endings
bradleyshep Sep 24, 2026
8b7997a
Reuse the L3 qualification across the admission and scope-hash changes
bradleyshep Sep 24, 2026
4c50d7a
Represent repeatFormWrite in the all-actions definition fixture
bradleyshep Sep 24, 2026
f99aec0
Give the backend database 2 GiB and carry the L3 reuse decision over
bradleyshep Sep 25, 2026
d06786d
Forward provider requests the broker cannot price and report their sp…
bradleyshep Sep 25, 2026
97218b8
Fix network interruption evidence and durable job resume
bradleyshep Sep 25, 2026
bdb3829
Qualify reconnect fixes with targeted evidence and validated reuse
bradleyshep Sep 25, 2026
6dfcbf8
Qualify ecommerce L3 auth and cross-origin grading fixes
bradleyshep Sep 25, 2026
6cf4bb4
Support GPT-6 Sol in account-mode broker
bradleyshep Sep 25, 2026
bd56265
stack-bench: allow provider model selection in new runs
bradleyshep Sep 25, 2026
bb161fe
Classify read-only stock views and retain Docker smoke failure details
bradleyshep Sep 25, 2026
70f0ed2
Review qualification reuse for stock and smoke changes
bradleyshep Sep 25, 2026
3fb4747
stack-bench: probe Docker host ports before campaign admission
bradleyshep Sep 25, 2026
abf8aae
stack-bench: accept leased localhost socket for auth replay
bradleyshep Sep 25, 2026
a1b3f64
stack-bench: add Supabase stack without touching other stacks' qualif…
bradleyshep Sep 25, 2026
079bfc6
Carry qualification evidence across the stack isolation change
bradleyshep Sep 25, 2026
ffce578
stack-bench: skip contract walk without lintable hooks
bradleyshep Sep 25, 2026
d096ac9
stack-bench: add Supabase mutation catalog
bradleyshep Sep 26, 2026
4dcc187
stack-bench: keep transport diagnostics from crashing grading
bradleyshep Sep 26, 2026
641c6e8
stack-bench: keep Codex refresh tokens out of model discovery
bradleyshep Sep 26, 2026
05bcb9f
stack-bench: qualify four-stack L3 candidate reuse
bradleyshep Sep 26, 2026
ff3f2d2
stack-bench: cover CORP-blocked probes, Docker port admission and evi…
bradleyshep Sep 26, 2026
b4e4745
stack-bench: restore notification test sessions and improve capture d…
bradleyshep Sep 26, 2026
fefedf8
Fix privacy response capture across cache hits and pending reads
bradleyshep Sep 26, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 3 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -2,3 +2,6 @@
**/ModuleBindings/** linguist-generated=true eol=lf
/docs/llms/** linguist-generated=true
/docs/llms/*-details.json linguist-generated=false
/tools/stack-bench/** text eol=lf
/tools/stack-bench/**/*.woff2 -text -diff
/tools/stack-bench/qualification-evidence/**/*.json -text whitespace=cr-at-eol
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -267,3 +267,6 @@ nul

# Any local file
*.local

# Local working notes and temporary builds
/local-notes/
11 changes: 5 additions & 6 deletions codex-plugin/plugins/spacetimedb/skills/cli/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,13 +43,15 @@ spacetime build --debug # faster iteration, slower runtime

# Dev mode (auto-rebuild, auto-publish, generates bindings)
spacetime dev
spacetime dev --client-lang typescript --module-bindings-path ./client/src/module_bindings
spacetime dev my-database --server local --yes --delete-data=never --client-lang typescript --module-bindings-path ./client/src/module_bindings

# Generate client bindings
spacetime generate --lang typescript|csharp|rust --out-dir ./bindings --module-path ./server
spacetime generate --lang unrealcpp --uproject-dir ./MyGame --module-path ./server --unreal-module-name MyGame
```

`dev` stays running and watches module changes. `--run "npm run dev"` starts a client command; `--server-only` omits it. `--module-path` selects the module directory when no publish targets exist in `spacetime.json`. Once targets exist, use their configured paths and omit that flag. Separate build/publish/generate commands remain useful for one-shot deployment.

### Publishing & Deployment

```bash
Expand Down Expand Up @@ -114,7 +116,7 @@ spacetime server add myserver --url https://my-spacetime.example.com
# Set default server
spacetime server set-default local

# Test connectivity
# Check connectivity
spacetime server ping local

# Start local instance
Expand Down Expand Up @@ -172,10 +174,7 @@ spacetime server ping <server>
```

### "Schema conflict"
```bash
# Clear data and republish
spacetime publish my-db --delete-data=always --yes
```
`--delete-data=never` rejects incompatible schema updates without clearing data. A compatible migration preserves existing data; `--delete-data=always` destroys it and is only appropriate for an intentional reset.

### "Build failed"
```bash
Expand Down
4 changes: 2 additions & 2 deletions codex-plugin/plugins/spacetimedb/skills/concepts/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -101,8 +101,8 @@ Lifecycle: Write → Compile → Publish (`spacetime publish`) → Hot-swap (rep

## Identity

- **Identity**: A long-lived, globally unique identifier for a user.
- **ConnectionId**: Identifies a specific client connection.
- **Identity**: A long-lived, globally unique identifier for a user, derived from the token's issuer and subject claims. The same token yields the same identity on every connection.
- **ConnectionId**: Identifies one client connection. A new connection gets a new connection ID; a disconnect ends the connection, not the identity.
- Always use `ctx.sender` / `ctx.Sender` / `ctx.sender()` for authorization.

SpacetimeDB works with many OIDC providers, including SpacetimeAuth (built-in), Auth0, Clerk, Keycloak, Google, and GitHub.
2 changes: 2 additions & 0 deletions codex-plugin/plugins/spacetimedb/skills/cpp-server/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -138,6 +138,8 @@ SPACETIMEDB_CLIENT_DISCONNECTED(on_disconnect, ReducerContext ctx) {
}
```

Connection hooks run once per connection. The same authenticated principal keeps the same identity (`ctx.sender()`) across connections, while each connection has its own connection ID (`ctx.connection_id()`). A disconnect ends one connection; it does not end the identity, which returns unchanged on the next connection with the same token. Use connection IDs for presence and other connection-scoped state.

## Authentication & Timestamps

```cpp
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -162,7 +162,9 @@ public static void OnConnect(ReducerContext ctx) { ... }
public static void OnDisconnect(ReducerContext ctx) { ... }
```

`ctx.ConnectionId` is `ConnectionId?`, including in connection lifecycle reducers. Check or unwrap it before storing it in a non-nullable column or passing it to an index accessor.
Connection hooks run once per connection. The same authenticated principal keeps the same identity (`ctx.Sender`) across connections, while each connection has its own connection ID (`ctx.ConnectionId`). A disconnect ends one connection; it does not end the identity, which returns unchanged on the next connection with the same token. Use connection IDs for presence and other connection-scoped state.

`ctx.ConnectionId` is typed `ConnectionId?`. It is present inside connection lifecycle reducers and reducers invoked over a connection, and null in `Init` and scheduled reducers. Check or unwrap it before storing it in a non-nullable column or passing it to an index accessor.

## Views

Expand Down
2 changes: 2 additions & 0 deletions codex-plugin/plugins/spacetimedb/skills/rust-server/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -150,6 +150,8 @@ pub fn on_connect(ctx: &ReducerContext) { ... }
pub fn on_disconnect(ctx: &ReducerContext) { ... }
```

Connection hooks run once per connection. The same authenticated principal keeps the same identity (`ctx.sender()`) across connections, while each connection has its own connection ID (`ctx.connection_id()`). A disconnect ends one connection; it does not end the identity, which returns unchanged on the next connection with the same token. Use connection IDs for presence and other connection-scoped state.

The current connection ID is available through `ctx.connection_id()` (not a public field) and may be absent outside connection-scoped calls.

## Views
Expand Down
32 changes: 13 additions & 19 deletions codex-plugin/plugins/spacetimedb/skills/typescript-client/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ Generated bindings convert snake_case names to camelCase, including row fields:
## React: main.tsx

```typescript
import React, { useEffect, useMemo } from 'react';
import React, { useMemo } from 'react';
import ReactDOM from 'react-dom/client';
import { SpacetimeDBProvider } from 'spacetimedb/react';
import { DbConnection } from './module_bindings';
Expand All @@ -30,6 +30,7 @@ function Root() {
DbConnection.builder()
.withUri(SPACETIMEDB_URI)
.withDatabaseName(MODULE_NAME)
// Reuse the token issued on the previous connection.
.withToken(localStorage.getItem('auth_token') || undefined),
[]
);
Expand All @@ -46,27 +47,18 @@ ReactDOM.createRoot(document.getElementById('root')!).render(<Root />);
## React: App.tsx

```typescript
import { useEffect } from 'react';
import { useTable, useSpacetimeDB } from 'spacetimedb/react';
import { DbConnection, tables } from './module_bindings';

function App() {
const { isActive, identity: myIdentity, token, getConnection } = useSpacetimeDB();
const { identity: myIdentity, token, getConnection } = useSpacetimeDB();
const conn = getConnection() as DbConnection | null;

// Save auth token
// Persist the issued token for the next page load.
useEffect(() => { if (token) localStorage.setItem('auth_token', token); }, [token]);

// Subscribe when connected. Prefer typed query builders over raw SQL
useEffect(() => {
if (!conn || !isActive) return;
conn.subscriptionBuilder()
.onApplied(() => setSubscribed(true))
.subscribe([tables.entity, tables.record]);
// Or with filters: tables.entity.where(r => r.active.eq(true))
// Or raw SQL: 'SELECT * FROM entity'
}, [conn, isActive]);

// Reactive data. Returns [rows, isReady]
// useTable owns the subscription and cleanup. Returns [rows, isReady].
const [entities, entitiesReady] = useTable(tables.entity);
const [records, recordsReady] = useTable(tables.record);

Expand All @@ -80,8 +72,8 @@ function App() {
}
);

// Call reducers with object syntax
conn?.reducers.addRecord({ data }).catch(console.error);
// A callback for a UI event; defining it does not call the reducer during render.
const addRecord = (data: string) => conn?.reducers.addRecord({ data }).catch(console.error);

// Compare identities
const isMe = row.owner.toHexString() === myIdentity?.toHexString();
Expand Down Expand Up @@ -111,7 +103,9 @@ conn.db.user.onUpdate((ctx, oldUser, newUser) => console.log('Updated:', newUser

## Gotchas

- **`useTable` rows are `readonly`.** Copy before sorting/mutating, or it fails to type-check:
- **Subscription rows have no presentation order.** A server view's array order does not
define client cache iteration order. `useTable` rows are `readonly`; a sorted copy can
express the application's display order:
`const [rows] = useTable(tables.message); const sorted = [...rows].sort(...)`.
- **bigint in JSX.** ids/counts from `t.u64()`/`t.i64()` columns are `bigint`, which React
cannot render. Wrap it: `{Number(row.id)}` or `{String(count)}`.
- **64-bit display values.** `{String(row.id)}` preserves the full `bigint` value.
Conversion to `Number` can lose precision outside JavaScript's safe integer range.
42 changes: 39 additions & 3 deletions codex-plugin/plugins/spacetimedb/skills/typescript-server/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,11 @@ Every column is a `t` builder value:

Modifiers: `.primaryKey()`, `.autoInc()`, `.unique()`, `.index('btree')`, `.default(value)`.

`.primaryKey()` and `.unique()` apply to one column. For uniqueness across
multiple columns, use a surrogate key, the multi-column index below, and a
reducer that rejects an existing index match before inserting. An index alone
does not enforce uniqueness.

Use `.default(value)` only for a newly appended migration-safe field. Do not put defaults on primary-key, unique, or auto-increment columns.

Optional columns: `nickname: t.option(t.string())`
Expand Down Expand Up @@ -130,7 +135,9 @@ export { default } from './schema'; // re-export the schema for the module ent

## Reducers

Reducers are created with `spacetimedb.reducer(...)`; the export name becomes the reducer name:
Reducers are created with `spacetimedb.reducer(...)`. An exported `signUp`
becomes `signUp` in generated clients and `sign_up` in `spacetime call` and
`describe`:

```typescript
export const createEntity = spacetimedb.reducer(
Expand Down Expand Up @@ -178,10 +185,26 @@ export const onConnect = spacetimedb.clientConnected((ctx) => { ... });
export const onDisconnect = spacetimedb.clientDisconnected((ctx) => { ... });
```

`ctx.connectionId` is `ConnectionId | null`, including in lifecycle contexts. Guard it before passing it to a helper or using it as a table key.
Connection hooks run once per connection. `ctx.connectionId` identifies that connection.
`ctx.sender` identifies the authenticated caller and stays the same when the client
reconnects with the same token.

Use connection IDs for connection state, such as presence. A reload or network loss can
cause a disconnect. A disconnect alone does not mean the user signed out or their
application login expired. Keep connection cleanup separate from session revocation.

`ctx.sender` is a SpacetimeDB identity, not necessarily an application account. Separate
identities can authenticate to the same application account.

`ctx.connectionId` is typed `ConnectionId | null`. It is present inside connection lifecycle hooks and reducers invoked over a connection, and `null` in `init` and scheduled reducers. Guard it before passing it to a helper or using it as a table key.

## Reducer Context API

Each reducer call runs in one database transaction. An error that escapes the
reducer rolls back its database changes. `ctx.sender` identifies the caller;
application roles and permissions are not inferred from that identity. Table
visibility and view filters control reads, not authorization to call reducers.

`ctx` is the only source of sender identity, time, and randomness; stdlib clocks and RNG are unavailable in modules. Let exported callbacks infer their context type. In helpers, use `ReducerCtx<InferSchema<typeof spacetimedb>>`; do not annotate a context as `any`, because that erases table row types and can make `bigint` expressions infer as `number`.

```typescript
Expand Down Expand Up @@ -282,17 +305,30 @@ const Shape = t.enum('Shape', {
A client subscribing to a view receives only the rows it returns. Use a per-user view
(keyed on `ctx.sender`) for per-viewer access control: deleting a row it depends on
(e.g. a membership row) automatically drops the rows it was exposing from that client.
Use index accessors in views. Do not scan a whole table with `.iter()` when an
indexed lookup can select the required rows.

`t.row(...)` and `t.object(...)` return schema builders, not TypeScript runtime row types. Let a view callback infer its result, or annotate a separately declared structural type such as `Array<{ sku: bigint; label: string }>`. A named output type must not reuse the generated PascalCase name of its view accessor (for example, reserve `DiscountedProduct` for a `discounted_product` view).

A view context is `ViewCtx<S>` (and `AnonymousViewCtx<S>`), both exported from
`spacetimedb/server`. It carries `sender`, a read-only `db`, and `from`; it is
not a `ReducerCtx`, so a helper shared between a reducer and a view must accept
either:

```typescript
import type { ReducerCtx, ViewCtx, InferSchema } from 'spacetimedb/server';
type S = InferSchema<typeof spacetimedb>;
function stockOf(ctx: ReducerCtx<S> | ViewCtx<S>, itemId: bigint) { ... }
```

Both `spacetimedb.view(...)` and `spacetimedb.anonymousView(...)` take three arguments: view options, the declared return schema, and the callback.

```typescript
// Anonymous view (same for all clients):
export const activeUsers = spacetimedb.anonymousView(
{ name: 'active_users', public: true },
t.array(entity.rowType),
(ctx) => [...ctx.db.entity.iter()].filter(e => e.active)
(ctx) => [...ctx.db.entity.active.filter(true)] // active: t.bool().index('btree')
);

// Per-user view (varies by ctx.sender):
Expand Down
26 changes: 14 additions & 12 deletions crates/bindings-typescript/src/lib/query.ts
Original file line number Diff line number Diff line change
Expand Up @@ -248,19 +248,21 @@ export type NamespacedQueryBuilder<SchemaDef extends UntypedSchemaDef> =
* A runtime reference to a table. This materializes the RowExpr for us.
* TODO: Maybe add the full SchemaDef to the type signature depending on how joins will work.
*/
export type TableRef<TableDef extends TypedTableDef> = Readonly<{
type: 'table';
sourceName: TableDef['sourceName'];
accessorName: string;
cols: RowExpr<TableDef>;
indexedCols: IndexedRowExpr<TableDef>;
tableDef: TableDef;
// Keep this named so TypeScript diagnostics show `TableRef` instead of its
// expanded structure.
export interface TableRef<TableDef extends TypedTableDef> {
readonly type: 'table';
readonly sourceName: TableDef['sourceName'];
readonly accessorName: string;
readonly cols: RowExpr<TableDef>;
readonly indexedCols: IndexedRowExpr<TableDef>;
readonly tableDef: TableDef;
// Delegated UntypedTableDef properties for compatibility.
columns: TableDef['columns'];
indexes: TableDef['indexes'];
rowType: TableDef['rowType'];
constraints: any;
}>;
readonly columns: TableDef['columns'];
readonly indexes: TableDef['indexes'];
readonly rowType: TableDef['rowType'];
readonly constraints: any;
}

class TableRefImpl<TableDef extends TypedTableDef>
implements TableRef<TableDef>, From<TableDef>
Expand Down
78 changes: 78 additions & 0 deletions crates/bindings-typescript/tests/table_ref_error_message.test.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,78 @@
import { mkdtempSync, rmSync, writeFileSync } from 'node:fs';
import { tmpdir } from 'node:os';
import path from 'node:path';
import { fileURLToPath } from 'node:url';
import * as ts from 'typescript';
import { describe, expect, it } from 'vitest';

const bindingsRoot = path.resolve(
path.dirname(fileURLToPath(import.meta.url)),
'..'
);

function runTypecheck(source: string) {
const tmpDir = mkdtempSync(path.join(tmpdir(), 'stdb-tableref-diag-'));
const reproPath = path.join(tmpDir, 'repro.ts');
writeFileSync(reproPath, source);

try {
const options: ts.CompilerOptions = {
target: ts.ScriptTarget.ESNext,
module: ts.ModuleKind.ESNext,
strict: true,
noEmit: true,
skipLibCheck: true,
forceConsistentCasingInFileNames: true,
allowImportingTsExtensions: true,
noImplicitAny: true,
moduleResolution: ts.ModuleResolutionKind.Bundler,
useDefineForClassFields: true,
verbatimModuleSyntax: true,
isolatedModules: true,
};

const host = ts.createCompilerHost(options);
const program = ts.createProgram(
[reproPath, path.join(bindingsRoot, 'src/server/sys.d.ts')],
options,
host
);
const diagnostics = ts.getPreEmitDiagnostics(program);
return diagnostics.map(d =>
ts.flattenDiagnosticMessageText(d.messageText, '\n')
);
} finally {
rmSync(tmpDir, { recursive: true, force: true });
}
}

describe('TableRef diagnostics', () => {
const source = `
import { t } from ${JSON.stringify(path.join(bindingsRoot, 'src/server/index.ts'))};
import { table } from ${JSON.stringify(path.join(bindingsRoot, 'src/lib/table.ts'))};
import { createTableRefFromDef } from ${JSON.stringify(path.join(bindingsRoot, 'src/lib/query.ts'))};
import type { AllUnique } from ${JSON.stringify(path.join(bindingsRoot, 'src/lib/constraints.ts'))};

const cartItem = table(
{ name: 'cart_item' },
{ id: t.u64().primaryKey().autoInc(), accountId: t.u64(), quantity: t.u32() }
);

const ref = createTableRefFromDef(cartItem as any, 'cartItem');
type Boom = AllUnique<typeof ref, ['accountId']>;
declare const b: Boom;
`;

it('names the type instead of dumping its structure', () => {
const messages = runTypecheck(source);
const constraintError = messages.find(m =>
m.includes("does not satisfy the constraint 'UntypedTableDef'")
);

expect(constraintError).toBeDefined();
// The name, not the shape.
expect(constraintError).toContain('TableRef<');
expect(constraintError).not.toContain('type: "table"');
expect(constraintError).not.toContain('accessorName');
}, 15000);
});
2 changes: 2 additions & 0 deletions crates/cli/build.rs
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ use std::process::Command;
use toml::Value;

fn main() {
println!("cargo:rerun-if-env-changed=SPACETIMEDB_NIX_BUILD_GIT_COMMIT");
let git_hash = find_git_hash();
println!("cargo:rustc-env=GIT_HASH={git_hash}");

Expand Down Expand Up @@ -110,6 +111,7 @@ fn generate_template_files() {

// Embed skill files from skills/*/SKILL.md
let skills_dir = repo_root.join("skills");
println!("cargo:rerun-if-changed={}", skills_dir.display());
let skill_names = discover_skill_names(&skills_dir);

generated_code.push_str("pub fn get_skill(name: &str) -> Option<&'static str> {\n");
Expand Down
Loading
Loading