Skip to content
This repository was archived by the owner on Aug 17, 2026. It is now read-only.

Electric: brand and constrain the evaOS Teams managed desktop - #24

Closed
100yenadmin wants to merge 2 commits into
feature/5-one-way-supabase-authorityfrom
feature/8-evaos-teams-branding
Closed

Electric: brand and constrain the evaOS Teams managed desktop#24
100yenadmin wants to merge 2 commits into
feature/5-one-way-supabase-authorityfrom
feature/8-evaos-teams-branding

Conversation

@100yenadmin

@100yenadmin 100yenadmin commented Jul 24, 2026

Copy link
Copy Markdown
Member

Closes #8 when merged.

Stacked on #22 (feature/5-one-way-supabase-authority) because merge authority is outside this implementation program. Retarget to main after #22 merges.

What changed

  • pins the managed product contract to evaOS Teams 0.4.23-es.1, com.electricsheephq.evaos.teams, evaos-teams://, managed-beta, evaOS-Teams-0.4.23-es.1-arm64.dmg, and the evaOS Teams executable name
  • adds the managed icon, DMG background, Info.plist, build entrypoint, Apache license resource, and origin notice
  • makes the backend product contract the renderer authority for managed branding and authentication gates
  • removes native/upstream branding and management surfaces from reachable managed UI while retaining required Apache origin attribution
  • disables the upstream updater plugin and UI actions, rejects updater build configuration, and blocks Builderlab before I/O
  • permits only the active product's message deep-link scheme; authority-changing native deep links remain unavailable
  • keeps native Buzz behavior and user-selected relay/media/provider/model destinations outside this endpoint audit

Local proof on 23c6cb4c745667c4aaf117cbef519368ff856a34

  • 75 focused product/package/message/markdown/notification/feedback/update tests: passed
  • managed Rust contract tests: 4 passed; focused Builderlab, scheme, action, message-link, and product-policy tests: passed
  • pnpm typecheck, changed-file Biome checks, cargo fmt --check, node --check, and git diff --check: passed
  • managed E2E smoke: 3 passed across active dark mode, signed-out light mode, and Keychain-locked light mode; no forbidden upstream host requests or updater/Builderlab commands
  • injected BUZZ_UPDATER_ENDPOINT build guard: rejected before build

Independent review dispositions

  • P1 executable name gap: fixed by hard-pinning mainBinaryName in both managed configuration sources and tests
  • P2 reachable managed Buzz copy: fixed in camera-permission and storage-quota errors
  • P2 cross-product message-link acceptance: fixed; native accepts only buzz://message and managed accepts only evaos-teams://message
  • P3 endpoint-spy coverage: exact and subdomain host matching fixed; native runtime network instrumentation remains an explicit Release: signed evaOS Teams 0.4.23-es.1 macOS internal canary #10 proof boundary

Asset and proof boundary

The canary icon is derived from the current Electric Sheep dashboard favicon. Its 256 px source is suitable for this internal canary but is not final public-brand approval.

This PR proves source and package configuration only. It does not claim a signed DMG, merge, release, deployment, runtime, or customer proof; signed artifact inspection belongs to #10.

@coderabbitai

coderabbitai Bot commented Jul 24, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d9467588-1b8d-4b24-9267-3758e8ca20f9

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feature/8-evaos-teams-branding

Comment @coderabbitai help to get the list of available commands.

@100yenadmin

Copy link
Copy Markdown
Member Author

This pre-reset staging PR is closed as superseded by merged upstream-first reset PR #37 and the current thin-adapter tracker #1/#36.

No code is being deleted. The branch and review history remain available. Retained behavior was replayed narrowly in #37; dropped managed brokers, blanket guards, duplicate UI, and control-signed routine collaboration must not be revived from this PR.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant