Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
102 commits
Select commit Hold shift + click to select a range
d3d91c8
docs: add canonical Inkspan product requirements
seonghobae Aug 9, 2026
b8c2c3d
docs: add canonical Inkspan technical requirements
seonghobae Aug 9, 2026
6550b63
docs: add Inkspan conceptual data model
seonghobae Aug 9, 2026
302e4a0
docs: add Inkspan ADR index
seonghobae Aug 9, 2026
5d5b8c6
docs: add Inkspan runtime diagrams
seonghobae Aug 9, 2026
8814c00
test(docs): require acquisition-complete canonical spine
seonghobae Aug 9, 2026
4ffca86
docs(security): define canonical Inkspan threat model
seonghobae Aug 9, 2026
3982f59
docs(test): define canonical Inkspan test strategy
seonghobae Aug 9, 2026
537d315
docs(ops): define Inkspan operability and recovery
seonghobae Aug 9, 2026
d8be3e2
docs(trace): add standards and evidence traceability
seonghobae Aug 9, 2026
900550c
docs(adr): record product and host authority boundary
seonghobae Aug 9, 2026
faa2ce4
docs(adr): record document and revision authority
seonghobae Aug 9, 2026
e46fe8e
docs(adr): record safe rich clipboard boundary
seonghobae Aug 9, 2026
494eef7
docs(adr): record durable validator autosave boundary
seonghobae Aug 9, 2026
7848316
docs(adr): record revision-scoped review evidence
seonghobae Aug 9, 2026
df0a4f3
docs(adr): record SSR and native form boundary
seonghobae Aug 9, 2026
a0d1e26
docs(adr): record provider-neutral collaboration boundary
seonghobae Aug 9, 2026
a660358
docs(adr): record deterministic Office rendering boundary
seonghobae Aug 9, 2026
897e824
docs(adr): record naruon modular composition
seonghobae Aug 9, 2026
4f8b8f8
docs(adr): record release evidence authority
seonghobae Aug 9, 2026
e6b28b9
docs(adr): index detailed canonical decisions
seonghobae Aug 9, 2026
a6ad45a
docs(changelog): record canonical acquisition documentation
seonghobae Aug 9, 2026
a528f75
test(docs): require conversation-complete product contracts
seonghobae Aug 9, 2026
872b468
docs(product): complete canonical Inkspan product requirements
seonghobae Aug 9, 2026
9692105
docs(tech): complete canonical Inkspan technical requirements
seonghobae Aug 9, 2026
60802e5
docs(uml): complete Inkspan runtime and deployment diagrams
seonghobae Aug 9, 2026
1701d8c
docs(model): complete conceptual Inkspan evidence model
seonghobae Aug 9, 2026
6e3e172
test(docs): require canonical interface contracts
seonghobae Aug 9, 2026
99847fc
docs: add canonical interface contract index
seonghobae Aug 9, 2026
3fc2f3d
test(docs): bind contributor guidance to canonical graph
seonghobae Aug 9, 2026
fea77f2
docs: add canonical documentation index
seonghobae Aug 9, 2026
cbae8c7
docs: align Claude guidance with canonical architecture
seonghobae Aug 9, 2026
fdd5568
docs: align agent guidance with canonical product graph
seonghobae Aug 9, 2026
728f4e7
test(docs): require complete ADR decision records
seonghobae Aug 9, 2026
5d40d60
docs(adr): complete host-authority decision record
seonghobae Aug 9, 2026
bedb234
docs(adr): complete document-authority decision record
seonghobae Aug 9, 2026
3566061
docs(adr): complete clipboard-security decision record
seonghobae Aug 9, 2026
efd8d26
docs(adr): complete autosave decision record
seonghobae Aug 9, 2026
357d8f3
docs(adr): complete revision-evidence decision record
seonghobae Aug 9, 2026
b67f8d1
docs(adr): complete SSR form decision record
seonghobae Aug 9, 2026
603d14d
docs(adr): complete collaboration decision record
seonghobae Aug 9, 2026
aad566d
docs(adr): complete Office-renderer decision record
seonghobae Aug 9, 2026
1312f58
docs(adr): complete naruon composition decision record
seonghobae Aug 9, 2026
5d28d35
docs(adr): complete release-evidence decision record
seonghobae Aug 9, 2026
ca47d58
test(docs): require remaining minimum architecture decisions
seonghobae Aug 9, 2026
2aca72d
docs(adr): separate deterministic and model-assisted authority
seonghobae Aug 9, 2026
fe5da88
docs(adr): define spreadsheet formula safety authority
seonghobae Aug 9, 2026
1a94839
docs(adr): define atomic file publication semantics
seonghobae Aug 9, 2026
979e4ce
docs(adr): define offline font asset and licensing boundary
seonghobae Aug 9, 2026
7896c9a
docs(adr): index complete minimum decision set
seonghobae Aug 9, 2026
e26fd00
test(docs): bind offline font provenance and egress contract
seonghobae Aug 9, 2026
598e389
docs: align changelog with canonical architecture graph
seonghobae Aug 9, 2026
12f7046
test(docs): require product-definition status discipline
seonghobae Aug 9, 2026
084e1f4
docs(prd): separate proposed requirements from shipped claims
seonghobae Aug 9, 2026
85629eb
test(docs): require documentation fitness matrix
seonghobae Aug 9, 2026
ab33189
docs: record canonical documentation fitness
seonghobae Aug 9, 2026
d7098d0
docs: index documentation fitness matrix
seonghobae Aug 9, 2026
4cacb3c
test(docs): require migration and browser assurance decisions
seonghobae Aug 9, 2026
09c8c5b
docs(adr): define envelope migration routing authority
seonghobae Aug 9, 2026
8393842
docs(adr): define cross-engine clipboard release assurance
seonghobae Aug 9, 2026
2edf838
docs(adr): index migration and browser assurance decisions
seonghobae Aug 9, 2026
c75f51a
docs: reconcile migration and browser assurance fitness
seonghobae Aug 9, 2026
0710152
docs(uml): diagram migration routing and browser assurance
seonghobae Aug 9, 2026
2ee50d1
docs: trace migration routing and browser release assurance
seonghobae Aug 9, 2026
6532c53
test(docs): require evidence-model coverage for planned decisions
seonghobae Aug 9, 2026
ec209f0
docs(erd): model planned migration and browser evidence
seonghobae Aug 9, 2026
0c5720c
docs(changelog): record canonical decision coverage
seonghobae Aug 9, 2026
971196a
test(docs): require work-conserving maintenance guidance
seonghobae Aug 9, 2026
4097193
docs(agents): preserve work-conserving maintenance discipline
seonghobae Aug 9, 2026
21d772b
docs(agents): make autonomous execution work-conserving
seonghobae Aug 9, 2026
cf4a6d6
docs: classify autonomous maintenance governance
seonghobae Aug 9, 2026
1160eb2
docs: record work-conserving maintainer governance
seonghobae Aug 9, 2026
e97b51e
chore(docs): reconcile protected release gate
seonghobae Aug 9, 2026
3ad45fa
Merge branch 'main' into docs/canonical-product-architecture
opencode-agent[bot] Aug 9, 2026
04cbd52
test(docs): require protected security disclosure decision
seonghobae Aug 9, 2026
053f6c1
docs(adr): capture protected security disclosure lifecycle
seonghobae Aug 9, 2026
af7ac05
docs(adr): index security disclosure lifecycle
seonghobae Aug 9, 2026
93021e3
docs(fitness): recognize protected security disclosure policy
seonghobae Aug 9, 2026
70c6e30
docs(trd): reconcile protected security disclosure authority
seonghobae Aug 9, 2026
f56cbbf
docs(prd): reconcile protected security disclosure lifecycle
seonghobae Aug 9, 2026
c859793
docs(index): recognize protected security disclosure authority
seonghobae Aug 9, 2026
7d6b7c8
chore(docs): reconcile protected security policy
seonghobae Aug 9, 2026
8613eab
test(docs): require integrated security authority in canonical graph
seonghobae Aug 9, 2026
4274d9e
docs(adr): align autosave snapshot validator privacy contract
seonghobae Aug 9, 2026
4ad9a2b
docs(contracts): bind exact release draft inventory and digest gate
seonghobae Aug 9, 2026
ecea0aa
docs(operability): bind exact release inventory and private observabi…
seonghobae Aug 9, 2026
33e58f4
docs(test): align coverage and release gates with protected CI
seonghobae Aug 9, 2026
e5df2e7
docs(data): fail closed on public telemetry metadata
seonghobae Aug 9, 2026
f8788a4
test(docs): bind merged autosave lifecycle status
seonghobae Aug 9, 2026
0d56877
docs(prd): mark autosave lifecycle observation protected
seonghobae Aug 9, 2026
3c88000
docs(trd): mark autosave lifecycle observation protected
seonghobae Aug 9, 2026
5f92659
docs(fitness): reconcile protected autosave lifecycle
seonghobae Aug 9, 2026
331eb17
docs(fitness): reconcile protected SSR and accessibility integration
seonghobae Aug 9, 2026
94daef6
docs(prd): reconcile protected SSR and accessibility capabilities
seonghobae Aug 9, 2026
cf2ab64
docs(trd): reconcile protected SSR and accessibility capabilities
seonghobae Aug 9, 2026
1bf49f8
test(docs): harden canonical authority contracts
seonghobae Aug 9, 2026
68e6625
docs(uml): mark control plane as non-runtime
seonghobae Aug 9, 2026
82df41f
docs(product): reconcile merged evidence capabilities
seonghobae Aug 9, 2026
def86ab
docs(technical): reconcile merged evidence capabilities
seonghobae Aug 9, 2026
86d8d17
docs(fitness): reconcile protected evidence maturity
seonghobae Aug 9, 2026
6701509
test(docs): preserve active-vs-shipped wording contract
seonghobae Aug 9, 2026
b00695e
docs: reconcile canonical changelog with protected main
seonghobae Aug 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,21 @@
# AGENTS.md

## Canonical product and architecture authority

Protected `main` is Inkspan's implementation authority. Before changing product behavior, public contracts, architecture, security boundaries, tests, release behavior, or integration guidance, start from `docs/README.md` and keep `docs/PRD.md`, `docs/TRD.md`, and `docs/CONTRACTS.md` aligned with the current implementation and accepted ADRs.

Inkspan owns deterministic editor/conversion behavior, versioned document/evidence contracts, local autosave coordination, accessibility metadata, package behavior, and provider-neutral adapters. Hosts retain transport, authentication, authorization, tenant isolation, durable persistence, credentials, migration execution, retention, deployment, durable audit, collaboration-provider authority, and model-use policy unless an accepted versioned contract explicitly changes that boundary.

Do not infer shipped behavior from conversation history, PR bodies, model output, or predecessor-head evidence. Keep Proposed/Active-PR behavior distinct from implementation on Protected `main`, preserve fail-closed security and deterministic conversion boundaries, and update the smallest affected canonical documents plus tests when a durable contract changes.

## Autonomous maintenance execution discipline

When an external scheduler or autonomous maintainer is operating on Inkspan, repository work is **work-conserving**: after every mutation, proof, merge, closure, review/check observation, or defer decision, select the next highest-value safe Inkspan action while practical execution budget remains. A blocked PR blocks only that lane; queued CI, reviewer latency, provider cooldown, a read-only dependency, or missing approval must not freeze unrelated work.

A status report, prompt update, documentation assessment, green check, PR creation, review request, or one completed product slice is an intermediate result rather than repository completion while another safe action exists. Before ending an autonomous run, re-scan open PRs/issues, protected `main`, changed branches, reviews/checks/security findings, documentation fitness, release evidence, and buyer-visible gaps; continue if any executable item remains.

The external scheduler remains the execution authority for cadence and run continuation. These repository instructions define Inkspan-specific writer, evidence, product, and safety discipline only; they do not make scheduling or autonomous orchestration an Inkspan runtime capability.

## Code-owner review gates — disabled (on hold)

As of 2026-08-04, code-owner review requirements (`require_code_owner_reviews` in branch
Expand Down
34 changes: 34 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,17 +6,51 @@ Historical release entries from **0.1.0 through 0.5.27** are preserved verbatim

## [Unreleased]

### Fixed
- Added the selected standalone Markdown or HTML value to an explicitly configured SSR native form field, preserving controlled-value precedence, external form association, React attribute escaping, and the synchronous post-hydration TipTap transaction mirror

### Security
- Added a fail-closed draft release asset inventory gate that requires exactly one npm tarball, one Office wheel, and `SHA256SUMS`, rejects stale or unexpected draft assets before immutable publication, and verifies every GitHub-reported `sha256:` asset digest against the transferred local file
- Kept SSR document disclosure opt-in through `formFieldName`; hidden-field values remain client-controlled submission data and do not replace host authentication, authorization, tenant isolation, CSRF defenses, server validation, durable concurrency, or persistence controls
- Kept collaborative Yjs document content out of server markup until the host-owned client collaboration lifecycle is bound

### Added
- Added one optional construction-time `onSnapshotChange` callback to the framework-free autosave queue and durable autosave session so hosts can observe saving, pending, blocked, recovery, idle, and shutdown state without polling or introducing a subscriber collection
- Added privacy-minimized revision-scoped selection evidence through `getSelectionRevisionEvidence()`, binding frozen ProseMirror coordinates to the SHA-256 strong revision of the exact same immutable editor state before asynchronous hashing begins
- Added privacy-minimized document transition evidence for validated previous and resulting canonical revisions through the framework-independent `revision-evidence` subpath, with object/JSON and strict UTF-8 entry points, deterministic previous-then-resulting SHA-256 derivation, frozen revision-only results, and no document body, actor, tenant, time, authorization, signature, transport, model, or durable-write claim

### Reliability
- Lifecycle observers receive only distinct frozen document-free snapshots; observer exceptions cannot alter save ordering, conflict/failure recovery, queue outcomes, or durable-validator handoff
- Durable-session notifications expose a newly committed server validator only after it is coherent with the emitted lifecycle state, preserving host-owned atomic RFC 9110 `If-Match` semantics

### Accessibility
- Added programmatic toolbar shortcut discoverability with WAI-ARIA `aria-keyshortcuts` for the implemented bold, italic, link, undo, and redo commands, preserving the same native-button behavior, visible labels, roving focus model, and host-owned shortcut-conflict policy
- Completed redo shortcut metadata with `Control+Shift+Z Meta+Shift+Z Control+Y Meta+Y`, matching the configured Tiptap history and collaboration behavior and exposing both `Ctrl/Cmd+Shift+Z` and `Ctrl/Cmd+Y` alternatives without adding new key handling
- Corrected extension-scoped review evidence after exact-head repository review found the existing editor-surface `Ctrl/Cmd+K` link binding in `EditorFrame`; the link button now truthfully exposes `Control+K Meta+K` while the Tiptap Link extension itself remains documented as having no default shortcut
- Preserved buyer-facing README guidance within the same validated safe-link command boundary and moved the shortcut-specific behavior contract to the authoritative accessibility and doctoring records so it is not misattributed to Tiptap
- Added deterministic regression and documentation contracts plus APA 7th doctoring for exact `Control`/`Meta` shortcut alternatives, the descriptive-only accessibility boundary, repository-level shortcut verification, and omission of unsupported shortcut claims

### Tests
- Added test-first Node `renderToString` evidence for the missing SSR native value, controlled-over-default selection, escaping, external form ownership, no ProseMirror server construction, and opt-out non-disclosure
- Added browser-DOM handoff tests proving the field retains and updates the selected value before TipTap exists while reset-only unnamed fields remain empty

### Documentation
- Added a canonical acquisition documentation spine covering product requirements, technical requirements, public interface/integration contracts, Mermaid UML, a conceptual data/evidence model, a threat model, test strategy, operability/recovery, standards/evidence traceability, and seventeen linked architecture decision records without inventing Inkspan-owned persistence or host authority; the newest decisions make envelope schema identity/host-owned migration routing, cross-engine browser-semantic release assurance, and the protected security-disclosure lifecycle first-class while keeping unimplemented capabilities explicitly planned
- Added machine-checkable canonical-documentation decision coverage that keeps required files, ADR index links and completeness, migration-routing and browser-assurance UML/data-model/traceability evidence, physical-ERD non-applicability, browser-security evidence, offline font provenance/no-runtime-font-egress, standards references, rollback sections, host-vs-Inkspan authority boundaries, implemented-vs-active-PR status, and work-conserving autonomous-maintenance guidance synchronized
- Documented work-conserving autonomous-maintenance governance in `AGENTS.md` and `CLAUDE.md`: a blocked PR blocks only its lane, status/report/prompt/documentation milestones are intermediate while safe work remains, and the external scheduler owns cadence rather than becoming an Inkspan runtime capability
- Added a repository-native security disclosure and vulnerability-handling policy with supported pre-1.0 release lines, private GitHub Security Advisory routing and safe public fallback, minimized evidence guidance, explicit Inkspan-versus-host ownership boundaries, no-SLA and non-conformance claim limits, deterministic documentation tests, and APA 7th doctoring grounded in current ISO/IEC 29147:2018, ISO/IEC 30111:2019, final NIST SP 800-218 SSDF 1.1, the draft-status boundary for SSDF 1.2, and GitHub primary documentation
- Documented that revision-scoped selection evidence contains no selected text or complete document envelope, remains valid only for its exact document revision, is not a W3C `TextPositionSelector`, and leaves durable comments, authorization, persistence, collaborative anchoring, and cross-revision re-anchoring to the host
- Added an APA 7th doctoring record for the selection/revision atomicity, privacy, rollback, and interoperability boundaries grounded in ProseMirror, RFC 9110, and the W3C Web Annotation Data Model
- Added transition-evidence operator guidance and APA 7th doctoring for content minimization, W3C PROV occurrence-provenance limits, RFC 8785 canonicalization, RFC 9110 durable-validator separation, SHA-256 lifecycle evidence, framework-free packaging, rollback, and host-owned authenticated audit semantics
- Added an authoritative standalone and modular MSA architecture contract with reviewable deployment, optimistic-concurrency, data-ownership, security, and acquisition-evidence diagrams and tables
- Added a beginner-readable naruon compose and ui.panel integration guide covering narrow client hydration, server-selected strong validators, accessible conflict handling, host-owned Yjs lifecycle, contextual-orchestrator boundaries, and local-versus-shareable evidence
- Added an opaque editing-context remount for the complete editor and autosave example, latest-generation asynchronous capture ordering, encoded document path segments, redacted recovery status, and lazy state-owned session identity to prevent cross-document state reuse
- Bounded the host save example with a fresh abort deadline, exposed authenticated conflict recovery through `session.resume(...)`, generated an instance-unique accessible heading relationship, and strengthened fenced-TSX ordering contracts
- Added stale-generation conflict recovery and operational save failure recovery through one reason-aware single-flight host workflow, so newer local edits cannot hide or duplicate recovery while retained work remains blocked; rejected or malformed resume attempts retain the same recovery surface until a valid resume succeeds or the editing context is disposed
- Added exact-head read-only CI with fixed Ubuntu 24.04 runners, immutable action pins, explicit contributor-head checkout, disabled persisted Git credentials, and a documented merge-result compatibility boundary
- Added deterministic documentation contract tests and APA 7th doctoring grounded in RFC 9110, WCAG 2.2, NIST SP 800-204, NIST SP 800-204D, OWASP ASVS 5.0.0, React, current Next.js App Router guidance, and GitHub Actions primary documentation
- Added APA 7th doctoring for the SSR native form field, including the WHATWG hidden-input/form-entry contract, React server/hydration continuity, client-controlled-data boundary, host-owned CSRF and acceptance controls, collaboration exclusion, and rollback
- Added lifecycle-observation doctoring covering bounded callback retention, local-versus-shareable evidence, durable-validator coherence, WCAG 2.2 status-message responsibilities, rollback, and APA 7 references to RFC 9110, WCAG 2.2, and optimistic concurrency research

## [0.5.29] — 2026-08-05

Expand Down
42 changes: 42 additions & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
# CLAUDE.md

## Repository authority

Protected `main` is Inkspan's implementation authority. Start architecture, product, interface, security, testing, and operability work from the canonical graph in `docs/README.md`; in particular, keep `docs/PRD.md`, `docs/TRD.md`, and `docs/CONTRACTS.md` aligned with shipped behavior and accepted ADRs rather than reconstructing product intent from conversations or pull-request prose.

## Product boundary

Inkspan owns deterministic Markdown/HTML authoring and conversion behavior, versioned document/evidence contracts, local autosave coordination, accessibility metadata, package behavior, and provider-neutral adapters. The embedding host owns authenticated transport, authorization, tenant isolation, durable persistence, credentials, migration execution, retention, deployment, durable audit, collaboration-provider authority, and model-use policy unless an accepted versioned contract explicitly changes that boundary.

Keep deterministic conversion separate from model-assisted authoring. Model output is an untrusted proposal and cannot bypass editor/document/clipboard/Office validation, host authorization, user approval, or durable concurrency controls.

## Security and reliability invariants

- Preserve strict fail-closed handling for untrusted clipboard HTML, links, image sources, document envelopes, Office structures, host callbacks, collaboration updates, and model proposals.
- Office rendering remains network-free, macro-free, model-free, Desktop-Office-free, bounded, formula-injection-safe, and race-safe at publication.
- Local SHA-256 document revisions are equality evidence, not authorization, signatures, tenant identity, server time, or durable-write receipts.
- Host/server-selected strong validators remain the durable compare-and-swap authority.
- Do not place credentials, complete document bodies, tenant identifiers, prompts/model output, durable validators, or private exception causes into generic diagnostics or telemetry.
- Do not move transport, persistence, tenancy, credential, retention, provider, or deployment ownership into Inkspan merely to make a local feature or test easier.

## Change and evidence discipline

Use test-first changes for product behavior and permanent contracts where practical. Preserve exact owned production statement/branch/function/line coverage and public-docstring requirements enforced by repository CI. Validate public package behavior from packed artifacts, not source imports alone.

For architectural changes, update the smallest affected canonical records and ADRs. Keep status language explicit: implemented on protected main, active PR/proposed, accepted architecture, planned, research only, superseded, or out of scope.

A queued, pending, cancelled, skipped-required, stale-head, predecessor-head, status-only, comment-only, author-only, or synthetic-merge result is not acceptance evidence. Formal review, automated review, repository checks, host authorization, and release evidence remain distinct authorities.

## Autonomous maintenance execution discipline

When an external scheduler or autonomous maintainer drives Inkspan work, execution is **work-conserving**. After each mutation, proof, merge, closure, review/check observation, or defer decision, choose the next highest-value safe Inkspan item while practical execution budget remains. A blocked PR blocks only that lane; do not let queued CI, reviewer latency, provider cooldown, a read-only dependency, or missing approval freeze unrelated source, documentation, operability, or product work.

Do not use a status report, prompt update, documentation assessment, green check, PR creation, review request, or one completed product slice as a stopping condition while another safe action exists. Before ending an autonomous run, re-scan open PRs/issues, protected `main`, changed branches, review/check/security evidence, canonical-document fitness, release readiness, and buyer-visible gaps; continue when an executable item remains.

The external scheduler remains the execution authority for cadence and continuation. This file constrains repository-specific writer/evidence/product/safety behavior and does not make scheduling or autonomous orchestration part of Inkspan runtime architecture.

## Integration discipline

Inkspan must remain independently usable. naruon and other CWL hosts compose it through narrow host-owned boundaries; they are not required runtime dependencies. Central `.github`, contextual-orchestrator, and other repositories are external bounded contexts and must not be locally patched around when they own a shared control-plane defect.

Before changing public behavior, inspect `docs/README.md`, `docs/PRD.md`, `docs/TRD.md`, `docs/CONTRACTS.md`, `ARCHITECTURE.md`, the relevant ADRs, and current tests. Prefer the smallest root-cause-changing change with explicit rollback and compatibility evidence.
Loading
Loading