Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1013 commits
Select commit Hold shift + click to select a range
5df58a7
merge: propagate current protected board base
seonghobae Aug 20, 2026
b70e17e
merge: propagate current protected board base
seonghobae Aug 20, 2026
335dd08
fix: keep Weekly VOC test option typed
seonghobae Aug 20, 2026
4a05a91
merge: propagate current board branch head
seonghobae Aug 20, 2026
b03cec1
merge: propagate current board branch head
seonghobae Aug 20, 2026
f70a659
merge: propagate current board branch head
seonghobae Aug 20, 2026
993b693
merge: propagate current board branch head
seonghobae Aug 20, 2026
8febf13
merge: retain concurrent project-history updates
seonghobae Aug 20, 2026
93537f8
merge: propagate current Event Lineage branch head
seonghobae Aug 20, 2026
f8d2fa9
fix: preserve semantic source unit boundaries
seonghobae Aug 20, 2026
9b61751
merge: retain concurrent Weekly VOC parent sync
seonghobae Aug 20, 2026
dfd95d9
merge: propagate current semantic-source parent
seonghobae Aug 20, 2026
bd1b4d2
merge: propagate current semantic-source parent
seonghobae Aug 20, 2026
80445b8
merge: propagate current semantic-source parent
seonghobae Aug 20, 2026
d670acd
merge: propagate current semantic-source parent
seonghobae Aug 20, 2026
d5dbdf7
merge: propagate current semantic-source parent
seonghobae Aug 20, 2026
76af029
merge: propagate current semantic-source Event Lineage base
seonghobae Aug 20, 2026
4eaeb23
ci: export exact project history source for local verification
seonghobae Aug 20, 2026
b77bea4
ci: move source export off the saturated Linux queue
seonghobae Aug 20, 2026
654faa3
test(projects): expose truth and identity boundary gaps
seonghobae Aug 20, 2026
eac418a
fix(projects): preserve identity and evidence truth boundaries
seonghobae Aug 20, 2026
7c9e2b2
fix(projects): enforce exact identity and evidence truth at the read …
seonghobae Aug 20, 2026
13b869e
fix(projects): render observed and inferred responsibility evidence h…
seonghobae Aug 20, 2026
cbb959c
fix(projects): expose per-evidence truth in the timeline
seonghobae Aug 20, 2026
c7f49af
feat(projects): wire authorized history into buyer surfaces
seonghobae Aug 20, 2026
de07aad
test(projects): distinguish observed and inferred responsibility evid…
seonghobae Aug 20, 2026
ba1de00
docs(storybook): show project-history truth states
seonghobae Aug 20, 2026
9a4ca86
merge: retain concurrent project-history truth fixes
seonghobae Aug 20, 2026
6004a7a
fix(projects): keep timeline compatible with persisted evidence
seonghobae Aug 20, 2026
367c40a
Merge remote-tracking branch 'origin/pr-285-head' into codex/integrat…
seonghobae Aug 20, 2026
0a76b25
fix(projects): focus timeline on opened source post
seonghobae Aug 20, 2026
8a01449
test: type latest VOC backend fixture input
seonghobae Aug 20, 2026
ef7189e
Merge remote-tracking branch 'origin/feat/customer-master-open-focus-…
seonghobae Aug 20, 2026
30dae74
fix(project-history): preserve exact identity and isolate matches
seonghobae Aug 20, 2026
5d0e412
docs: refresh project gap exact-head checkpoint
seonghobae Aug 20, 2026
0beabed
merge: restack GNB focus onto current Ask Agent base
seonghobae Aug 20, 2026
d925f53
Merge remote-tracking branch 'origin/feat/event-lineage-node-keeps-gn…
seonghobae Aug 20, 2026
18dfddf
fix(ontology): align person mention direction with KG triples
seonghobae Aug 20, 2026
7b5c1e9
Merge branch 'feat/analysis-run-name-evidence-lineage' of https://git…
seonghobae Aug 20, 2026
9648110
docs: record audited safe SQL gate
seonghobae Aug 20, 2026
848ff4c
Merge branch 'feat/board-weekly-voc-open-event-lineage-v2130' of http…
seonghobae Aug 20, 2026
5fcfbea
Merge branch 'feat/calendar-open-focus-event-lineage-v2140' of https:…
seonghobae Aug 20, 2026
c264674
Merge remote-tracking branch 'origin/feat/project-lifecycle-history' …
seonghobae Aug 20, 2026
e573875
fix(board): keep weekly VOC filters complete
seonghobae Aug 20, 2026
8268b14
fix(board): fetch posts for selected ISO week
seonghobae Aug 20, 2026
6f31284
test(api): prove ISO week scope excludes other corps
seonghobae Aug 20, 2026
a71b8a6
Merge remote-tracking branch 'origin/feat/board-weekly-voc-open-event…
seonghobae Aug 20, 2026
221cc94
fix(calendar): keep home commitment opens neutral
seonghobae Aug 20, 2026
d061571
Merge remote-tracking branch 'origin/feat/calendar-open-focus-event-l…
seonghobae Aug 20, 2026
9ffe3b6
Merge remote-tracking branch 'origin/feat/customer-master-open-focus-…
seonghobae Aug 20, 2026
3ed21fe
Merge remote-tracking branch 'origin/feat/ask-agent-open-focus-event-…
seonghobae Aug 20, 2026
49804b0
Merge branch 'main' into feat/analysis-run-name-evidence-lineage
github-actions[bot] Aug 20, 2026
b83be70
style: normalize merged branch whitespace
seonghobae Aug 20, 2026
c92c5d1
chore: remove completed project history bootstrap
seonghobae Aug 20, 2026
cfc125c
chore: align project history release version
seonghobae Aug 20, 2026
d1d4930
Merge current main into feat/analysis-run-name-evidence-lineage
seonghobae Aug 20, 2026
1f905a3
merge current analysis-run parent into weekly VOC stack
seonghobae Aug 20, 2026
ee52819
merge: sync buyer evidence branch with main
seonghobae Aug 20, 2026
dcbd4c1
merge: preserve concurrent main synchronization
seonghobae Aug 20, 2026
b2d4c10
fix: restrict synthetic cleanup to demo scopes
seonghobae Aug 20, 2026
41036e2
test: cover empty synthetic cleanup
seonghobae Aug 20, 2026
f1ff05c
test: specify recovered TEPP project-history boundary
seonghobae Aug 21, 2026
93873f7
test: specify TEPP project-history buyer evidence
seonghobae Aug 21, 2026
565e531
feat: recover strict TEPP project-history client
seonghobae Aug 21, 2026
8281e6a
feat: map canonical project history into TEPP contract
seonghobae Aug 21, 2026
5c81a5e
feat: render TEPP validation beside canonical history
seonghobae Aug 21, 2026
aeb0d93
Merge current analysis-run base into weekly VOC stack
seonghobae Aug 21, 2026
889bddb
style: add TEPP project-history evidence panel
seonghobae Aug 21, 2026
2a2a1a7
docs: add TEPP project-history Storybook states
seonghobae Aug 21, 2026
31c2016
chore: stage one-shot TEPP project-history recovery
seonghobae Aug 21, 2026
0b03ad5
docs: record recovered TEPP project-history boundary
seonghobae Aug 21, 2026
26b83f0
ci: execute verified TEPP project-history recovery
seonghobae Aug 21, 2026
4bb2344
docs: align orchestrator runtime pin
seonghobae Aug 21, 2026
9bfa181
Merge remote-tracking branch 'origin/feat/event-lineage-node-keeps-gn…
seonghobae Aug 21, 2026
9bb02fa
Merge remote-tracking branch 'origin/feat/board-weekly-voc-open-event…
seonghobae Aug 21, 2026
19747b6
fix(i18n): cover Vietnamese TEPP project-history copy
seonghobae Aug 21, 2026
294fe99
ci: remove completed Global Ask repair workflow
seonghobae Aug 21, 2026
c518058
Merge remote-tracking branch 'origin/feat/analysis-run-name-evidence-…
seonghobae Aug 21, 2026
33baae5
test(frontend): specify customer master tree hardening
seonghobae Aug 21, 2026
c1d340f
Merge remote-tracking branch 'origin/feat/board-weekly-voc-open-event…
seonghobae Aug 21, 2026
90412ed
Merge remote-tracking branch 'origin/feat/calendar-open-focus-event-l…
seonghobae Aug 21, 2026
065f962
test(red): require TEPP evidence on canonical timeline
seonghobae Aug 21, 2026
7d2fea8
fix(ci): make TEPP recovery red gate integration-specific
seonghobae Aug 21, 2026
6e18cf4
Merge remote-tracking branch 'origin/feat/customer-master-open-focus-…
seonghobae Aug 21, 2026
3fd75b0
fix(ui): harden TEPP evidence semantics and accessibility
seonghobae Aug 21, 2026
f8b5826
test(ui): cover TEPP evidence labels and unique regions
seonghobae Aug 21, 2026
2ff8826
Merge remote-tracking branch 'origin/feat/ask-agent-open-focus-event-…
seonghobae Aug 21, 2026
a1b117f
test(red): reject unrecognized TEPP findings and invalid responses
seonghobae Aug 21, 2026
704215a
fix(ci): apply complete strict TEPP recovery contract
seonghobae Aug 21, 2026
32e24c1
ci: format and lint TEPP recovery before commit
seonghobae Aug 21, 2026
8d69a34
docs(adr): close TEPP finding vocabulary and response boundary
seonghobae Aug 21, 2026
1875e65
fix(a11y): separate customer tree from evidence panel
seonghobae Aug 21, 2026
69f0a3d
fix(ci): cancel stale TEPP recovery attempts
seonghobae Aug 21, 2026
67e39c9
test: expose ORG and SKOS ontology boundary gaps
seonghobae Aug 21, 2026
cb30c24
feat: materialize TEPP project history recovery
seonghobae Aug 21, 2026
337691a
test: keep TEPP evidence type-safe
seonghobae Aug 21, 2026
065d582
fix: fail closed on unknown TEPP findings
seonghobae Aug 21, 2026
c7ecfa8
fix: separate organizations from SKOS classifications
seonghobae Aug 21, 2026
865ec0d
feat: publish core ontology SHACL constraints
seonghobae Aug 21, 2026
a9c0385
docs: amend ontology ADR for ORG SKOS and SHACL boundaries
seonghobae Aug 21, 2026
68ca6cb
Merge remote-tracking branch 'origin/feat/event-lineage-node-keeps-gn…
seonghobae Aug 21, 2026
996db8c
docs: align ontology loader with ORG and SHACL contracts
seonghobae Aug 21, 2026
19bd247
docs: record organization ontology interoperability fix
seonghobae Aug 21, 2026
cccf80c
fix(frontend): integrate customer master tree safely
seonghobae Aug 21, 2026
4228c48
merge: preserve concurrent customer-master updates
seonghobae Aug 21, 2026
21074cf
fix(a11y): make customer tree ownership explicit
seonghobae Aug 21, 2026
ca1ee63
ci: verify customer hierarchy finalization
seonghobae Aug 21, 2026
2b77e3d
docs: finalize customer hierarchy evidence
seonghobae Aug 21, 2026
be4c254
ci: remove stale cross-branch pnpm repair workflow
seonghobae Aug 21, 2026
de9a9cf
Merge remote-tracking branch 'origin/feat/analysis-run-name-evidence-…
seonghobae Aug 21, 2026
8ef98a0
Merge remote-tracking branch 'origin/feat/analysis-run-name-evidence-…
seonghobae Aug 21, 2026
3532062
docs: finalize customer hierarchy evidence
seonghobae Aug 21, 2026
9924465
merge: preserve exact customer hierarchy evidence
seonghobae Aug 21, 2026
b7625c3
Merge remote-tracking branch 'origin/feat/analysis-run-name-evidence-…
seonghobae Aug 21, 2026
6c4d48d
Merge remote-tracking branch 'origin/feat/board-weekly-voc-open-event…
seonghobae Aug 21, 2026
13a3430
fix(http): let strict contracts suppress LLM metadata
seonghobae Aug 21, 2026
6dfb5d9
fix(tepp): keep contextual metadata out of strict payloads
seonghobae Aug 21, 2026
1703bf7
test(tepp): prove strict payloads suppress LLM metadata
seonghobae Aug 21, 2026
cc0a890
Merge remote-tracking branch 'origin/feat/calendar-open-focus-event-l…
seonghobae Aug 21, 2026
457e7e1
Merge remote-tracking branch 'origin/feat/customer-master-open-focus-…
seonghobae Aug 21, 2026
8baf402
fix(tepp): preserve strict validation while suppressing metadata
seonghobae Aug 21, 2026
d207b62
Merge remote-tracking branch 'origin/feat/ask-agent-open-focus-event-…
seonghobae Aug 21, 2026
bcdc459
fix: recover expired ask sessions and localize timeline
seonghobae Aug 21, 2026
43262dc
fix(tepp): normalize unexpected provider failures
seonghobae Aug 21, 2026
0c8e8d0
fix: preserve project history evidence truth in buyer UI
seonghobae Aug 21, 2026
f754c36
Merge remote-tracking branch 'refs/remotes/origin/feat/event-lineage-…
seonghobae Aug 21, 2026
0d827fc
fix: keep provider errors behind product boundaries
seonghobae Aug 21, 2026
8832216
fix: localize event lineage post actions
seonghobae Aug 21, 2026
6a35ca8
fix: bound and explain project history loading
seonghobae Aug 21, 2026
d58edc8
fix: close provider error leaks at write endpoints
seonghobae Aug 21, 2026
f365821
Merge remote-tracking branch 'refs/remotes/origin/feat/project-histor…
seonghobae Aug 21, 2026
12f92e9
Merge remote-tracking branch 'refs/remotes/origin/feat/event-lineage-…
seonghobae Aug 21, 2026
ccaeaa1
test: align project history document clock copy
seonghobae Aug 21, 2026
711f027
merge current main into #258
seonghobae Aug 21, 2026
1df9d83
Merge remote-tracking branch 'refs/remotes/origin/feat/project-histor…
seonghobae Aug 21, 2026
678df0d
fix: keep unauthenticated admin controls out of login
seonghobae Aug 21, 2026
abb99aa
merge concurrent provider error boundary fix
seonghobae Aug 21, 2026
87c1b01
fix: enforce TEPP project history byte limits
seonghobae Aug 21, 2026
44e8dcf
fix: normalize unexpected provider failures
seonghobae Aug 21, 2026
5158934
fix: normalize summary enrichment failures
seonghobae Aug 21, 2026
6a4dbe7
fix: order TEPP history events by timestamp
seonghobae Aug 21, 2026
d58651e
Merge remote-tracking branch 'origin/feat/analysis-run-name-evidence-…
seonghobae Aug 21, 2026
643338a
fix: remove unused locale return imports
seonghobae Aug 21, 2026
8cd94b2
Merge remote-tracking branch 'origin/feat/board-weekly-voc-open-event…
seonghobae Aug 21, 2026
e3f4561
Merge current calendar stack and wire customer tree
seonghobae Aug 21, 2026
76964c0
fix: sanitize TEPP transport provider errors
seonghobae Aug 21, 2026
5bd176c
Merge remote-tracking branch 'origin/feat/customer-master-open-focus-…
seonghobae Aug 21, 2026
8d12743
docs: record TEPP provider error boundary
seonghobae Aug 21, 2026
39f2126
Merge remote-tracking branch 'origin/feat/ask-agent-open-focus-event-…
seonghobae Aug 21, 2026
1803ab3
feat: redesign Customer Master around three-pane relationships
seonghobae Aug 21, 2026
df5c36e
Merge remote-tracking branch 'origin/feat/event-lineage-node-keeps-gn…
seonghobae Aug 21, 2026
7093c8b
fix: align core ontology with ORG and SHACL contract
seonghobae Aug 21, 2026
f5e23b5
fix: close remaining provider error leaks
seonghobae Aug 21, 2026
59d687e
Merge latest project history timeline into TEPP recovery
seonghobae Aug 21, 2026
8314f3c
ci: verify and repair OIDC return fallback
seonghobae Aug 21, 2026
2c84824
fix: validate provider chat response envelopes
seonghobae Aug 21, 2026
c8dcc27
Merge remote-tracking branch 'refs/remotes/origin/feat/analysis-run-n…
seonghobae Aug 21, 2026
7f4a5c9
ci: expose PR 258 repair as a visible exact-head check
seonghobae Aug 21, 2026
e175ecd
ci: run the PR 258 repair through the recognized test workflow
seonghobae Aug 21, 2026
c48d88b
ci: remove completed self-modifying repair workflows
seonghobae Aug 21, 2026
899b44a
Merge branch 'feat/analysis-run-name-evidence-lineage' of https://git…
seonghobae Aug 21, 2026
c135c41
ci: keep tests workflow read-only
seonghobae Aug 21, 2026
a838559
fix: persist OIDC buyer return URL before redirect
seonghobae Aug 21, 2026
6a1177d
Merge commit 'a8385597030de92f6d771b61f13edbdc9c3dca2d' into codex/re…
seonghobae Aug 21, 2026
0ff8643
Merge commit '6a1177df' into codex/review-pr261-current
seonghobae Aug 21, 2026
5e706b7
fix: keep malformed customer parents unresolved
seonghobae Aug 21, 2026
349d559
Merge remote-tracking branch 'origin/feat/customer-master-open-focus-…
seonghobae Aug 21, 2026
f970b21
Merge remote-tracking branch 'origin/feat/ask-agent-open-focus-event-…
seonghobae Aug 21, 2026
7ff36d4
fix: preserve semantic image and summary boundaries
seonghobae Aug 21, 2026
9f24b68
fix: keep ADR numbers unique
seonghobae Aug 21, 2026
326f7ea
chore: restack project history on current parent
seonghobae Aug 21, 2026
8bddedf
fix: preserve OIDC deep links across callback storage (#306)
seonghobae Aug 21, 2026
aaad6f1
feat: make Event Lineage directional and evidence-readable (#330)
seonghobae Aug 21, 2026
b3d803a
feat: connect Ask answers to canonical project histories (v2.20.0) (#…
seonghobae Aug 21, 2026
f9f5227
fix: reject blank OCR table separators
seonghobae Aug 21, 2026
a9d0462
Merge current PR #258 head into PR #260
seonghobae Aug 21, 2026
4dba417
fix: require complete organization token corroboration (#327)
seonghobae Aug 21, 2026
7e2982b
feat: name Weekly VOC and focus Event Lineage (v2.13.0) (#260)
seonghobae Aug 21, 2026
b141ffc
Merge current PR #260 head into PR #261
seonghobae Aug 21, 2026
aba991f
feat: open Calendar commitments onto Event Lineage (v2.14.0) (#261)
seonghobae Aug 21, 2026
427a7a1
Merge current PR #261 head into PR #262
seonghobae Aug 21, 2026
b8e1b30
feat: open Ask Agent cited posts onto Event Lineage (v2.16.0) (#263)
seonghobae Aug 21, 2026
125a806
feat: publish external email and project lineage contract (#343)
seonghobae Aug 21, 2026
63d12af
fix: keep ADR numbers unique after customer master restack
seonghobae Aug 21, 2026
1ae3c40
Merge concurrent PR #263 updates into PR #262
seonghobae Aug 21, 2026
a2a0ad8
feat: keep GNB Event Lineage focus on a linked DAG node (v2.17.0) (#264)
seonghobae Aug 21, 2026
c2d7207
feat: publish bounded lineage provider contract (#340)
seonghobae Aug 21, 2026
b521812
fix: expose Ask Agent next actions
seonghobae Aug 21, 2026
d5d45f0
feat: expose authenticated MCP Global Ask (#270)
seonghobae Aug 21, 2026
b450c3e
Merge branch 'feat/project-history-timeline-v2184-r3' of https://gith…
seonghobae Aug 21, 2026
4f36013
fix: preserve project history focus across key normalization
seonghobae Aug 21, 2026
041aa4c
fix: preserve semantic document evidence units (#302)
seonghobae Aug 21, 2026
9235807
docs: assign unique ADR numbers after stack merge
seonghobae Aug 21, 2026
a8f56d0
feat: recover TEPP validation on canonical Project history (v2.19.0) …
seonghobae Aug 21, 2026
9e69bdb
Merge branch 'feat/project-history-timeline-v2184-r3' of https://gith…
seonghobae Aug 21, 2026
1a2ad15
fix: keep ADR identifiers unique and references consistent
seonghobae Aug 21, 2026
62bcd71
chore: restack customer master on current parent #258
seonghobae Aug 21, 2026
e7f0e01
feat: add evidence-honest Global Ask knowledge cutoff (v2.23.0) (#301)
seonghobae Aug 21, 2026
efcc3c6
fix: enforce TEPP request and search evidence boundaries (#323)
seonghobae Aug 21, 2026
4e24688
chore: restack customer master on latest parent
seonghobae Aug 21, 2026
910cf0e
feat: rebuild Ask Agent as an evidence workspace (v2.18.0) (#353)
seonghobae Aug 21, 2026
6c39a0d
fix: disclose unused and malformed lineage LLM paths
seonghobae Aug 21, 2026
3f9a0cf
fix: harden pr258 buyer board and lineage fallback
seonghobae Aug 21, 2026
cda7d48
fix: harden external lineage contract boundaries
seonghobae Aug 21, 2026
be7255d
fix: harden customer master contract delivery
seonghobae Aug 21, 2026
b153716
Merge remote-tracking branch 'refs/remotes/origin/pr258-current' into…
seonghobae Aug 21, 2026
aba828e
feat(ui): make plural affiliation chips actionable and multilingual (…
seonghobae Aug 21, 2026
2a3a464
Merge remote-tracking branch 'refs/remotes/origin/pr258-current' into…
seonghobae Aug 21, 2026
481bdb6
fix: remove privileged repair workflow
seonghobae Aug 21, 2026
fcb9bd3
fix: publish not-invoked lineage status
seonghobae Aug 21, 2026
23a5c13
Merge remote-tracking branch 'refs/remotes/origin/pr258-current' into…
seonghobae Aug 21, 2026
d0c7dec
fix: preserve buyer control typography
seonghobae Aug 21, 2026
073e5e2
Merge base event-lineage stack into project history
seonghobae Aug 21, 2026
2c827ea
feat: add Buyer Project history destination (v2.18.0) (#285)
seonghobae Aug 21, 2026
8b356a8
Merge pull request #385 from seonghobae/repair/pr258-review-hardening…
seonghobae Aug 21, 2026
6bf7599
Merge pull request #262 from ContextualWisdomLab/feat/customer-master…
seonghobae Aug 21, 2026
53ce1a5
test: preserve duplicate chunking coverage
seonghobae Aug 21, 2026
3488669
fix(frontend): preserve images in markdown fallback
seonghobae Aug 21, 2026
a3cf51e
fix: rebuild lineage group after llm channel failure
seonghobae Aug 21, 2026
6621eb1
docs: correct buyer terminology ADR reference
seonghobae Aug 21, 2026
6dc040c
fix: consolidate lineage product contracts
seonghobae Aug 21, 2026
d1ab7ca
fix: reuse authorized entity ids on Global Ask cutoff query (v2.20.1)…
seonghobae Aug 21, 2026
0407480
perf: batch persisted Ask reauthorization (#401)
seonghobae Aug 21, 2026
502d3c7
Merge pull request #402 from ContextualWisdomLab/reconcile/ask-histor…
seonghobae Aug 21, 2026
5975fe3
merge: reconcile Ask history with current Project timeline
seonghobae Aug 21, 2026
cc6cabd
Merge pull request #406 from ContextualWisdomLab/reconcile/ask-histor…
seonghobae Aug 21, 2026
61c6413
chore: nudge CI re-review (opencode-agent's prior REQUEST_CHANGES was…
seonghobae Aug 23, 2026
35bd32b
fix: resolve ADR 0119 collision and finish buyer->reader terminology …
seonghobae Aug 23, 2026
a1a8d86
docs: use workspace reader terminology
seonghobae Aug 23, 2026
bcfb67f
fix(frontend): restore Weekly VOC history focus
seonghobae Aug 23, 2026
d927cc4
Merge commit 'cc6cabddd6247dea0deabf5ad26600107b202340' into HEAD
seonghobae Aug 23, 2026
0f5b88d
Merge remote-tracking branch 'origin/feat/event-lineage-node-keeps-gn…
seonghobae Aug 23, 2026
56b899f
Merge remote-tracking branch 'origin/feat/ask-agent-open-focus-event-…
seonghobae Aug 23, 2026
1a238d4
Merge remote-tracking branch 'origin/feat/customer-master-open-focus-…
seonghobae Aug 23, 2026
9f7ac9f
Merge remote-tracking branch 'origin/feat/calendar-open-focus-event-l…
seonghobae Aug 23, 2026
cff2aa3
Merge remote-tracking branch 'origin/feat/board-weekly-voc-open-event…
seonghobae Aug 23, 2026
32deb9d
fix(security): document safe post chat SQL sinks
seonghobae Aug 23, 2026
ea14374
fix: preserve project history validation contracts
seonghobae Aug 23, 2026
af5a804
feat: show project-history lineage counts (#487)
seonghobae Aug 23, 2026
e05cf99
feat(mcp): enforce distributed account quota
seonghobae Aug 23, 2026
83ad578
fix(mcp): make browser admission exact and byte-bounded (#286)
seonghobae Aug 21, 2026
646e2a7
refactor(mcp): centralize quota settings
seonghobae Aug 23, 2026
f6ed5ef
fix(mcp): expose standards-safe quota retry metadata
seonghobae Aug 23, 2026
d26c4c5
fix(mcp): expose quota retry header to browsers
seonghobae Aug 23, 2026
d78ab1a
docs: renumber MCP rate-limit ADR to 0144
seonghobae Aug 23, 2026
2e2ddd1
docs(adr): assign MCP rate limit ADR 0146
seonghobae Aug 23, 2026
f4ebfc6
docs: align MCP quota reference with ADR 0146
seonghobae Aug 23, 2026
52deb37
feat(project-history): consume TEPP topic lineage (#495)
seonghobae Aug 23, 2026
3754e93
docs: refresh project history delivery evidence
seonghobae Aug 23, 2026
f0b5234
fix(mcp): close partial startup resources
seonghobae Aug 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
14 changes: 14 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,20 @@ OIDC_AUDIENCE=lineageweave-api

BACKEND_PORT=18420

# Dedicated authenticated Streamable HTTP MCP resource server (ADR 0031).
# A browser client requires an exact Origin; leave empty for non-browser
# clients such as Codex. Never use `*` and never include a path.
MCP_PORT=18001
MCP_REQUIRED_SCOPES=
MCP_ALLOWED_ORIGINS=
# The server counts actual streamed bytes before OAuth or SDK JSON parsing.
# Valid range: 8192..1048576; default: 65536 bytes (ADR 0119).
MCP_MAX_REQUEST_BYTES=65536
# Shared Valkey quota for provisioned MCP accounts (ADR 0146).
# Requests: 1..10000; window seconds: 1..3600.
MCP_RATE_LIMIT_REQUESTS=30
MCP_RATE_LIMIT_WINDOW_SECONDS=60

# Optional. Empty = every LLM/vision channel is unavailable (Null client,
# dropped and renormalized -- never a placeholder score). Point these at a
# running contextual-orchestrator to turn the channels on.
Expand Down
80 changes: 0 additions & 80 deletions .github/workflows/repair-global-ask-pnpm-v2.yml

This file was deleted.

20 changes: 20 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -170,6 +170,26 @@ adjudication does -- never a raw LLM API. Demo TEPP seed goes through
envelope is Failed (`tepp_not_available` / `tepp_result_not_persisted`),
never a fabricated theta or a local psychometric substitute.

Workspace **Weekly VOC** is an ISO-8601 week list filter (ADR 0092).
Opening that filtered post focuses Event Lineage (ADR 0093). Do not
invent a week, a theta, or a cutoff body.
Opening a Calendar commitment uses the same focus path (ADR 0094). Do not
invent a week, a theta, a cutoff body, or a CalDAV event.
Opening a Customer master related post uses the same focus path (ADR 0095).
Do not invent a week, a theta, a cutoff body, a CalDAV event, or a customer.
Opening an Ask Agent cited post uses the same focus path (ADR 0096).
Do not invent a cited post.
A linked Event Lineage node opened from that focused popup keeps the
originating flags (ADR 0097). That open then focuses Keyman as the named
next read (ADR 0100). Do not invent a week, a theta, a cutoff body,
a CalDAV event, a customer, or a cited post.

Ask Agent accepts an optional knowledge cutoff (ADR 0135). A dated
question uses retained revisions and never substitutes a live body. A
live query is never labeled as-of. Do not invent a cutoff body or a
TEPP theta.


## Tests

```bash
Expand Down
50 changes: 36 additions & 14 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ flowchart LR

subgraph External services, all optional
EMB[Embedding provider<br/>swap in for the text channel]
ORC[contextual-orchestrator<br/>mode=verify, llm channel]
ORC[contextual-orchestrator<br/>mode=auto, llm and vision channels]
TEPP[TEPP<br/>AnalysisRunRequest v1,<br/>calibrated measurement]
end

Expand All @@ -69,6 +69,8 @@ flowchart LR
| `rankweave_client.py` | Fail-closed RankWeave ranking port (`weighted_reciprocal_rank_fuse` in-process; never invent a fused score or a theta) |
| `reconstruct.py` | The pipeline: group → candidate window → score → fuse → thread |
| `lineage_persistence.py` | Flattens reconstruct trees into `post_lineage_edge` row specs (parent, child, fused_score) |
| `external_lineage_contract.py` | Sole versioned, store-agnostic external boundary for bounded authorized evidence and opaque-reference results (ADR 0133) |
| `external_lineage_analysis.py` | Adapts the external contract to the existing reconstruction kernel without database or provider authority |
| `knowledge_graph.py` | Random-walk-with-restart relevance + per-node adaptive related-node cutoff (Tong et al., 2006) -- pure graph math, no Postgres |
| `keyman_extraction.py` | Pluggable LLM extraction of two-sided (our-side/counterparty) person mentions + N:N org affiliations from a post |
| `entity_relationship_classification.py` | Pluggable LLM classification of a named organization's relationship to the post author (`rel_voc`/`rel_vom`/`rel_vop`/`rel_vocc`/`rel_voco`/`rel_vos`) |
Expand All @@ -82,19 +84,15 @@ flowchart LR
| `period_report.py` | Fit GRM/GPCM on persisted IRT rows, FIPC-select, EAP-score a period (ADR 0003 slice 3; Bock & Mislevy, 1982) |
| `fixtures.py` | Synthetic demo dataset -- no real data ships in this repo |
| `server.py` | Legacy stdlib HTTP server for the library-level synthetic fixture demo; production uses FastAPI/PostgreSQL |
| `backend/app/mcp_server.py` | OAuth-protected Streamable HTTP MCP resource server exposing read-only, evidence-grounded Global Ask |
| `web/index.html` | Legacy self-contained SVG DAG viewer; production UI is the React/Vite frontend |

> **Known local-test-environment limitation:** `adjudication_client.py`'s
> `mode="verify"` call depends on contextual-orchestrator's
> `TaskOrchestrator.route_and_verify`, which as of this writing is still
> an open, unmerged upstream PR
> (`ContextualWisdomLab/contextual-orchestrator#149`). Until it merges,
> the four adjudication/chat tests that exercise `mode="verify"` against
> a real orchestrator fail with `invalid_mode` (the deployed `main` only
> accepts `auto`/`route`/`conduct`) -- confirmed by reproducing the same
> `400` directly against the orchestrator's own `/v1/chat/completions`,
> not caused by anything in this repo. `mode="route"` (every other
> pluggable client) is unaffected.
> **Contextual-orchestrator contract:** Post Ask and MCP Global Ask use
> `mode="auto"` and `reasoning_effort="auto"`; the gateway owns model
> discovery, provider protocol, and multi-agent reasoning. Requests carry a
> stable post-scoped session id and non-secret evidence metadata. Structured
> responses use `json_schema`. LineageWeave never calls a provider directly
> or falls back to the rejected legacy `verify` mode.

## Design decisions worth naming

Expand Down Expand Up @@ -260,6 +258,11 @@ raw HTTP status. After that 503 the free-text Ask box is hidden and
only seeded question chips remain -- never a fabricated answer. Evaluate, Extract
Keymen, Derive commitment, and Verify use the same 503 empty-state
pattern and then hide the action button so it cannot 503 again.
Persisted Ask-history reads are bounded to 64 exchanges and 256 citation
occurrences (ADR 0131). One query loads the ordered history and one query
reauthorizes every citation against tenant ABAC, publication eligibility, and
its exchange-specific knowledge cutoff. An over-budget history is withheld
rather than partially returned.
`find_linked_post_ids` first expands to every post
sharing a mentioned person before calling
`backend/app/knowledge_graph.py::load_visible_subgraph` -- that function
Expand All @@ -280,7 +283,17 @@ Keycloak (`src/main.tsx`'s `AuthProvider`) -- no mocked auth, no static
HTML. `src/api.ts` calls the FastAPI backend directly with the token
Keycloak issued; `src/App.tsx` renders a git-branch SVG of
`GET /api/lineage` (click a node to open that post; `post_admin` can
rebuild), the post list, and a full detail popup: Korean
rebuild), the post list with a named Weekly VOC ISO-8601 week filter
(ADR 0092; opening that filtered post focuses Event Lineage, ADR 0093).
Calendar commitments use the same Event Lineage focus path (ADR 0094).
Customer master related posts use the same Event Lineage focus path
(ADR 0095). Ask Agent cited posts use the same Event Lineage focus path
(ADR 0096). A linked Event Lineage node opened from a focused popup keeps
those flags (ADR 0097). Ask Agent accepts an optional knowledge cutoff
and uses retained `source_post_revision` bodies for that clock (ADR 0135);
a live query is never labeled as-of. The full detail popup includes Korean
and focuses Keyman as the named next read (ADR 0100). The full detail
popup includes Korean
summary/key-events/R&R, VOC evidence excerpts, an Event Lineage panel
(direct vs. indirect links; a link opens that post), the Keyman
affiliate tree (resolved ancestors plus unresolved org roots), Keyman +
Expand Down Expand Up @@ -336,6 +349,13 @@ Keyman sides are labeled from `common_lookup_value` (`Our side`,
codes when a label exists. Related-node person chips use the same
side lookup label (for example, `Our side` or `Counterparty`) rather
than exposing the generic PROV-O `Person` class as business context.
When a person has several distinct affiliation identities, the API emits
`affiliation_ambiguous` and the reusable `RelatedNodeChip` says
`multiple organizations`; it never chooses the first row as a primary.
When exactly one identity remains, the chip includes that organization.
Organization chips use the cataloged entity-level label and post chips use
the source title only. The full N:N list stays visible on the Keyman panel,
which names the next action before the reader continues the walk.

`GET /api/posts` and `GET /api/posts/{post_id}` include
`voc_type_label` / `visibility_label` from `common_lookup_value` so
Expand Down Expand Up @@ -367,7 +387,9 @@ close the one product-brief item with a schema table (`issue_ticket`)
but no implementation through Phase 4. Deliberately plain CRUD, not a
pluggable-LLM channel like `keyman_ingestion.py` -- ticket status is a
closed enum in `common_lookup_value`, and opening or updating a ticket
is a direct user action, not something extracted from text.
is a direct user action, not something extracted from text. Ticket writes
also require `post_admin` plus authorship or corporate affiliation with the
owning post; public visibility is read access only (ADR 0122).
`frontend/src/App.tsx`'s `IssueTicketPanel` is the popup's real
list/create/status-update UI for it. Status options show
`common_lookup_value` labels (`Open` / `In progress` / `Closed`)
Expand Down
5 changes: 5 additions & 0 deletions CHANGELOG.d/2.12.0-weekly-voc-iso-week.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# 2.12.0 Weekly VOC ISO-week list filter

Weekly VOC on Board keeps Voice of Customer posts for the latest ISO-8601
week (UTC Thursday rule). Other VOC types and older weeks drop out. The
Board names Event Lineage as the next read. No TEPP theta is invented.
3 changes: 3 additions & 0 deletions CHANGELOG.d/2.12.6-frontend-build-gate.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
## Fixed

- Keep the unauthenticated login surface free of authenticated admin controls and remove unused OIDC imports so TypeScript production builds pass.
7 changes: 7 additions & 0 deletions CHANGELOG.d/2.12.6-oidc-return-storage.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# 2.12.6 — Preserve Buyer deep links during OIDC redirect

## Fixed

- Save the bounded Buyer return URL before SSO redirect so a provider that
omits the OIDC state payload can still return the member to the requested
evidence page.
5 changes: 5 additions & 0 deletions CHANGELOG.d/2.12.6-provider-error-boundary.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
## Fixed

- Keep contextual-orchestrator, OIDC, RankWeave, TEPP, and durable-ingestion diagnostics behind stable product error boundaries while retaining the original exception for server-side chaining.
- Route browser transport and tenant-settings failures through the same boundary so 5xx provider details never reach buyer-facing error text.
- Keep browser 5xx and transport failures behind the same stable client error boundary.
5 changes: 5 additions & 0 deletions CHANGELOG.d/2.12.6-remove-self-modifying-repair-workflows.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
## Fixed

- Removed completed repair-only GitHub Actions that could write to feature
branches. Product fixes now require ordinary reviewed commits and the normal
protected Checks path.
7 changes: 7 additions & 0 deletions CHANGELOG.d/2.12.7-korean-search-boundary.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# 2.12.7 — Preserve Korean search corroboration boundaries

## Fixed

- Accept a Korean organization token followed by a grammatical particle in a
natural Searxng snippet while still rejecting the token inside a longer
unrelated Hangul word.
8 changes: 8 additions & 0 deletions CHANGELOG.d/2.12.7-lineage-dag-evidence.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
### Changed

- Made the buyer Event Lineage DAG explicitly directional with parent-to-child arrowheads whose paths stop outside node circles.
- Preserved authored graph width behind a keyboard-focusable horizontal scroll region instead of shrinking deep lineages.
- Added visible event dates, a redundant visual/text legend, and an accessible exact-value evidence table for lineage relations, dates, and fused scores.
- Added five-locale buyer copy stating that reconstructed continuation edges do not prove causality or authoritative fact.
- Replaced the internal "seed posts" empty-state language with an actionable five-locale instruction to add eligible source records and rebuild Event Lineage.
- Added synthetic Storybook states for branching, selected-root, isolated-root, and empty lineage surfaces.
13 changes: 13 additions & 0 deletions CHANGELOG.d/2.12.8-ontology-org-shacl.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# 2.12.8 Organization ontology and SHACL boundaries

The core Knowledge Graph ontology now distinguishes real organizations from
the concepts used to classify them. `CorporateEntity` and `Team` reuse W3C ORG
organization, organizational-unit, containment, and unit-membership semantics;
SKOS remains responsible for Group, Company, and Plant level concepts and
canonical/alternative labels.

The ontology now publishes stable version/import metadata and a companion
versioned SHACL graph. Regression tests cover the ORG/SKOS boundary, direct
parent and team-owner cardinalities, and the continued relational lookup-code
round trip. PostgreSQL remains authoritative and ontology imports are never
network-dereferenced at runtime.
6 changes: 6 additions & 0 deletions CHANGELOG.d/2.13.0-weekly-voc-open-event-lineage.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
# 2.13.0 Opening Weekly VOC focuses Event Lineage

Open a Voice of Customer post from an active Weekly VOC filter and the
popup Event Lineage heading takes focus. The popup names that post as
current and to read Keyman and evaluation next. Home-list opens do not.
No TEPP theta is invented.
23 changes: 23 additions & 0 deletions CHANGELOG.d/2.13.1-mcp-browser-admission.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
# 2.13.1 — MCP browser and request-byte admission

## Fixed

- Browser MCP clients can complete an exact-Origin CORS preflight before OAuth
while wildcard, prefix, suffix, `null`, and unrelated Origins fail closed.
- Unsafe configured Origins now prevent startup instead of weakening the exact
allowlist into wildcard, credential-bearing, or path-bearing CORS.
- Origin-sensitive MCP responses vary by Origin and expose only the protocol,
session, and `WWW-Authenticate` headers needed for Streamable HTTP and OAuth
protected-resource discovery.
- MCP POST bodies are bounded by actual streamed bytes before OAuth and SDK JSON
decoding. Ambiguous framing, declared/actual mismatches, malformed body
streams, and over-limit requests return stable no-store errors without
echoing request content.
- Non-browser MCP clients may continue to omit `Origin`.

## Operations

- Added `MCP_MAX_REQUEST_BYTES` with a 65,536-byte default and an explicit
8,192–1,048,576-byte startup-validated range.
- Docker Compose, `.env.example`, integration guidance, ADR 0119, and MCP
standards traceability now share the same browser and body-admission contract.
5 changes: 5 additions & 0 deletions CHANGELOG.d/2.14.0-calendar-open-event-lineage.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# 2.14.0 Opening a Calendar commitment focuses Event Lineage

Calendar names authorized commitments as current and to open one to read
Event Lineage. That open focuses the popup Event Lineage heading. Home-list
opens do not. No TEPP theta is invented.
7 changes: 7 additions & 0 deletions CHANGELOG.d/2.15.0-customer-hierarchy-boundary.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# 2.15.0 — Keep unresolved customer parents non-authoritative

## Fixed

- A self-parent or cyclic customer relation now remains visibly unresolved in
the focus workspace instead of being presented as a valid parent. Review the
source hierarchy before using that relationship for navigation.
11 changes: 11 additions & 0 deletions CHANGELOG.d/2.15.0-customer-master-open-event-lineage.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# 2.15.0 Opening a Customer master related post focuses Event Lineage

Customer master names authorized customer entities as current and to open a
related post to read Event Lineage. That open focuses the popup Event Lineage
heading. Home-list opens do not. No TEPP theta is invented.

Customer Master now keeps one customer at the center of a responsive three-pane
workspace: authorized hierarchy, visible parent/direct-child relationships, and
source-backed linked evidence. Closing evidence no longer loses the selected
customer context. Desktop, tablet, and phone layouts use the shared UI tokens
and the 1024 px / 768 px responsive boundaries.
5 changes: 5 additions & 0 deletions CHANGELOG.d/2.16.0-ask-agent-open-event-lineage.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
# 2.16.0 Opening an Ask Agent cited post focuses Event Lineage

Ask Agent names authorized cited posts as current after an answer and to
open one to read Event Lineage. That open focuses the popup Event Lineage
heading. Home-list opens do not. No TEPP theta is invented.
6 changes: 6 additions & 0 deletions CHANGELOG.d/2.16.0-pr262-hardening.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
### Fixed

- Keep embedded source images visible when a post also contains a Markdown
table, and remove the privileged self-modifying contract-repair workflow.
- Align the Python package version and ontology ADR reference with the 2.16.0
release.
9 changes: 9 additions & 0 deletions CHANGELOG.d/2.17.0-event-lineage-node-keeps-gnb-focus.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# 2.17.0 A linked Event Lineage node keeps GNB focus

Opening a linked Event Lineage DAG node from a GNB-focused popup keeps
Event Lineage focused and names Keyman and evaluation next. A home-list
DAG walk does not. No TEPP theta is invented.

Ask Agent now replaces an expired saved session once, then stores the new
session. The Event Lineage timeline heading, list, and post-button
accessibility labels are translated in the supported locales.
8 changes: 8 additions & 0 deletions CHANGELOG.d/2.17.0-image-and-summary-boundaries.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
# 2.17.0 — Preserve table image boundaries and avoid duplicate summaries

## Fixed

- Inline or invalid images no longer split a table row or surrounding
paragraph into disconnected semantic units.
- Opening a post requests its summary once; the explicit retry action remains
the only path that requests another summary.
Loading
Loading