3c99e3ca77
feat(dashboard-testing): add chart health diagnostics and per-tab evidence
...
Focused matrix and cleanup checks pass. Native Superset error/recovery acceptance and final semantic freeze remain open; this is not release GO.
2026-10-02 16:23:22 +03:00
54bdbcc403
refactor(semantics): close dashboard testing protocol audit
2026-10-02 12:47:12 +03:00
bcc69f4bbe
feat(dashboard-testing): add sampled traversal and ClickHouse test lab
...
Add versioned metric graph authority, owned browser evidence, paginated and all-tab traversal, deterministic sampling policies, and analyst-facing run inspection.
Provision the DEV/PREPROD/PROD Superset, Gitea and million-row ClickHouse lab; retain reproducible lifecycle evidence and explicit incomplete-traversal limits.
2026-10-02 10:54:42 +03:00
e99306eb54
fix(dashboard-testing): bind launches to published baselines
2026-09-28 19:43:57 +03:00
354c6684d8
feat(dashboard-testing): pin published baselines in schedules
2026-09-25 11:44:44 +03:00
e7bac04e98
feat(dashboard-testing): add reference URL baseline workflow and analyst UX
...
Discover dashboard filters, datasets and metrics from a parsed reference URL; capture and review baseline candidates with source provenance. Improve scenario DAG and run result views, add isolated browser coverage, and align contracts and ADRs.
2026-09-25 10:36:37 +03:00
9acd9badab
feat(frontend): improve investigation analyst UX
2026-09-24 11:09:41 +03:00
6d58bb97d0
fix(dashboard-testing): authenticate browser SSE run stream via query token
2026-09-24 09:39:49 +03:00
d8b0bd58ad
fix(dashboard-testing): enforce run/case object ACLs and recurrence guards
2026-09-24 09:32:58 +03:00
05072f8547
feat(frontend): update maintenance settings and UI contracts
2026-09-24 00:33:04 +03:00
fc3697f35f
feat(dashboard-testing): complete analyst workflows
2026-09-24 00:31:22 +03:00
c4d6faa0f4
feat(frontend,automation): quarantine recovery UI, run-monitor reload/reconnect, disposition e2e spec
...
Wave UI (G-DLQ-SOAK operator recovery, G-MONITOR reload/reconnect, G-INVESTIGATION-UI spec):
- AutomationQuarantineModel (FSM, CAS-release of displayed version, 409->reload+stale_version,
404->reload+already_released) + QuarantinePanel mounted on automation page, i18n ru/en
- RunMonitorModel reload/reconnect L1 vectors (waiting_human restore without duplicate checkpoint,
repeated bindEvents closes previous EventSource)
- scenario-disposition.e2e.js spec (queue->case->disposition + STALE_CASE CAS vector; skips with
explicit reason until the isolated stand has a queue-seeding path)
- Matrix/traceability/WORKSTATE accounting for the UI wave; handoff docs + safety patch
Verified: frontend vitest 3425 passed (220 files); npm run build ok
2026-09-23 16:11:09 +03:00
300c2a2954
feat(maintenance): add dashboard-targeted banners and template library
2026-09-22 21:18:15 +03:00
f0d7b79523
fix(rbac): single admin authority, gate privileged surfaces, enforce session on dual-auth
...
- is_admin flag is the sole admin authority; remove role-name fallbacks (dependencies, reports, tasks, agent lifecycle, security badge, frontend)
- normalize (resource, ACTION) across REST/MCP/catalog; strict admin role/permission parsing (400 on unknown)
- gate LLM provider CRUD/status/test on admin:settings; require auth on agent llm-status; quarantine listing requires scenario:automation MANAGE
- enforce logical-session revocation/idle in require_api_key_or_jwt
- last-admin lockout guards for user/role CRUD; block non-admin from granting is_admin
- frontend: flag-only admin, route permission map from the nav registry, write-control gating, 403 dedupe
- tests: orthogonal edge coverage (flag-only admin, lockout boundaries, session states, normalization)
2026-09-22 21:14:35 +03:00
a4db469077
fix(translate): typed temporal transfer, language arbitration, MERGE key
...
- sql_generator: normalize ISO/epoch values only against a resolved target type
(Nullable/LowCardinality unwrapped); untyped epoch-looking strings are preserved and
unparseable temporal values raise instead of coercing. Removes the heuristic that
wrote sentinel dates (2106-02-07 = UInt32 max) into business date columns.
- sql_generator: ClickHouse string-literal escaping — backslash, quote and control
characters escaped; ANSI '' doubling alone silently rewrote paths and tabs on insert.
- service_target_schema: one fetch_target_column_types resolver for both direct_db and
SQL Lab insert paths (300s cache) plus a single column-catalog SQL builder; EXPLORE
trace when the catalog is unreachable/empty instead of a silent untyped fallback.
- _lang_detect: script-conflict downgrade no longer depends on the target language list;
letterless text becomes und; short/number-heavy Cyrillic cannot survive as a Latin
language; sanitize_detected_language validates the LLM arbitration answer by script.
- _batch_proc/_utils: und rows actually reach LLM arbitration (same-language, cache and
preview short-circuits blocked) and trust a cache entry only when its stored source
language is confirmed; detector version bumped to invalidate the v2 cache.
- _key_mapping: single source->target key mapping; MERGE with target_language_column
absent from target_key_cols rejected in preflight before any fetch/LLM; lang_code is a
target-only discriminator (no fictitious source key). Removes 5 divergent copies.
- frontend: global run indicator elapsed timer (1s tick, server started_at, cleanup)
reusing formatDuration; MERGE-key inline validation with en/ru i18n keys; UX contract
and decision-memory updates.
- tests: real ClickHouse testcontainers coverage on dm.debt_comment_translations
(Date32/DateTime transfer, epoch/millis/sentinel/boundaries, NULL semantics, text
escaping round-trip, MERGE language discriminator, chunked batch, production
projection); unit coverage for typed normalization, escaping, key mapping and the
arbitration cache. Existing integration module had a stale untyped-epoch expectation.
2026-09-22 11:36:44 +03:00
e7925d0e26
feat(analytics): investigation queue findability, case index, linked runs and evidence refs in workspace
2026-09-18 10:48:19 +03:00
6fcc861677
feat(analytics): start investigation queue refresh
2026-09-17 21:26:27 +03:00
4746af2f3e
fix(health): address consolidation review findings
2026-09-16 16:11:02 +03:00
3de0756d4f
refactor(validation): remove legacy LLM dashboard validation mechanism
...
Scenario-based dashboard testing (042/044) and scenario automation (046)
replace the legacy policy/run based validation surface.
- drop backend validation routes, service, schemas and DashboardValidationPlugin
- add migration 0025_drop_legacy_validation removing legacy tables
- redirect legacy settings/automation page to scenario automation surface
- remove frontend validation models, routes, components and i18n bundles
- repair dangling semantic relations and dead plugin-id fixtures
2026-09-16 11:13:50 +03:00
8522a2ee3c
feat(scenario): complete dashboard testing UX flow
2026-09-15 10:12:17 +03:00
71135c0822
fix(maintenance): single-banner multi-event render and per-env end-all
...
- multi-event builds exactly one banner (dedup messages <br>, min-start/max-end
envelope, open-ended keeps 'уточняется') instead of nested invalid HTML
- event.environment_id is authoritative for states/banner rows (settings target
only legacy fallback)
- end_all resolves a SupersetClient per event environment via memoized factory
- structured reason/explore logging for fan-out target resolution
- suppress toast for unconfigured /maintenance/settings 404
2026-09-11 17:27:39 +03:00
1d48625b10
test(maintenance): fix 5s first-test timeout flake — static import + vi.hoisted mocks
...
Module load of maintenance.svelte.js happened inside the first test via
dynamic import and exceeded the 5000ms testTimeout under full-suite
parallel load. Move to a single hoisted static import (mock factories
now resolve vi.fn()s created via vi.hoisted) and drop a dead no-op
placeholder test. 39/39 in isolation, 3563/3563 full suite.
2026-09-11 09:49:52 +03:00
bac002bcbc
feat(settings): derive project-sections toggles from sidebar nav registry
...
- sidebarNavigation.ts: static SIDEBAR_SECTIONS registry (i18n labelKey) + getTogglableFeatureNodes() with per-flag dedup
- projectSections.json: shared feature-id manifest; vitest guard pins nav ids to it, pytest guard pins it to FeaturesConfig fields
- FeaturesSettings: toggles derived and grouped by sidebar section/category, extra block for non-nav flags
- features.svelte.ts: reactive flags store; sidebar rebuilds live after settings save, untracked health polling
2026-09-11 07:35:26 +03:00
2532702478
feat(migration): localized risk messages, advanced options collapse, names over UUIDs
...
Iteration 2 of the migration UX plan:
Risk message localization (params + frontend templates):
- MigrationRiskItem.params (additive) populated at all 13 emission sites
(orchestrator, dashboard_outcomes, risk_assessor); English message kept
for assistant/logs backward compatibility
- migration.riskMessages.ts renders risk_msg_* en/ru templates with
drift details (schema: «marts» → «public») and graceful fallback
Names over UUIDs:
- _read_target_databases caches uuid->name map; drift/missing-datasource
messages and params carry dataset titles (table_name) and DB names
- compare_dataset_contracts: live None = no evidence, never drift
(fixes false positives where target LIST omits database_uuid)
- UUID rendered as ds:{8-char} chip with full UUID in title tooltip
Step 2 UX:
- sed rule, composite keys (+mutation server), rescan IDs moved into
collapsed Advanced options; selected-count chip near Dry Run CTA;
target-mutation hint + SOURCE-mutation warning
P0 hygiene:
- task view Cancel -> Close view + background-continues hint; own i18n
keys for Dry Run/step labels; dead Quick Actions block removed;
PasswordPrompt alert() -> inline validationError
Decomposition (no behavior change):
- run() 330 -> ~55 lines via _process_dashboard/_resolve_effective_
mapping/_transform_with_fallback/_assemble_report
- MigrationReviewPanel 303 -> 151 lines via MigrationOutcomeList +
MigrationRiskAssessment
Tests: params assertions + None-skip case (backend), 5 riskMessages
cases (frontend). 116 pytest + 270 vitest passed, lint/build clean.
2026-09-10 20:13:45 +03:00
befa03e34f
feat(migration): dashboard-first dry-run review, compact logs, second timestamps
...
Backend:
- dashboard_outcomes module: per-dashboard new/overwrite/identical outcome,
composite-key drift prediction with desired-vs-live values, read-only
- dry-run: single cached live dataset-contract fetch (was O(dashboards)),
literal_find/literal_replace reach every transform_zip call
- catalog read failures degrade to warnings (target_database/dataset_catalog_
unavailable, risk_analysis_unavailable) instead of fabricated blockers
- MigrationDryRunResult + dashboards[]; MigrationRiskItem + dataset_uuid
Frontend:
- MigrationReviewPanel: sorted outcomes (blocked -> overwrite -> new ->
identical), show-all toggle, risk assessment separated from technical
details, full en/ru localization
- execute failure preserves dry-run and returns to step 3; submit guard
hides Back while POST is in flight; confirm dialog before migration start
- task logs: dense one-line rows with expand chevron, compact toolbar
(filters/debug/errors/autoscroll/count in one row)
- migration dashboard grid timestamps truncated to seconds via
formatDateTimeSeconds
Tests: +6 backend regression (literal kwargs, outcomes, drift severity,
missing-db blocker, catalog degradation, single live fetch), +4 frontend
(sorting, legacy fallback, execute recovery). 116 pytest + 261 vitest passed.
2026-09-10 16:34:02 +03:00
e1dcf7cf90
fix(maintenance): INV_7 routes decomposition, UX contract-drift repair, RBAC/L2 test gaps closed
...
- decompose _routes.py (947 lines) into a 27-line facade + 5 handler modules (events/preview/start/end/settings), all <=400; extract _chart_layout from _chart_manager (441->381+78); contract IDs preserved verbatim, 9 routes registered in original order
- close RBAC FR-015 invariant gap: tests/api/test_maintenance_routes_rbac.py — 403 denied + 401 unauth on all 9 endpoints with exact guards (root cause of the blind spot: conftest MaintenanceRouteEnv overrode permission closures with lambda: None)
- repair 4 UX contract drifts: EventsTable empty-state + expandedEventIds invariant aligned to implementation (backend terminal-events expansion is intended per MaintenanceEventStateStatuses @POST); Badge phantom loading state removed (INV_9); SettingsPanel fields disabled during Saving implemented per contract
- add 34 L2 component tests (EventsTable/Badge/SettingsPanel) covering declared @UX_STATE/@UX_TEST/@UX_RECOVERY
- split oversized test files (709/686/624 -> all <=520, collected counts identical)
- test hygiene: RootTransaction is_active guard removes SAWarning in shared postgres fixture; AsyncMock create_task coroutine leak fixed in scheduler tests (zero RuntimeWarnings)
- examples/maintenance actualized against current API: optional environment_id with PROD fan-out (batch response), 422 no-PROD-target, GET events/{id}/dashboards, settings field list
Verified: isolated worktree (HEAD + this diff) 729 backend tests passed; frontend 109 passed; ruff clean; anchors balanced; index rebuilt (0 warnings)
2026-09-10 10:57:18 +03:00
9c1a1e093c
feat(mcp): Phase 2d field-run remediation — ADR-0024 agent-run surface, derived capabilities, disposition clarity
...
Source: live external MCP run against ss-prod Sales Dashboard (docs/2026-09-07-sales-prod-mcp-run.md) proved the initial-bootstrap chain externally unreachable: register_draft_pack requires a principal-owned AgentRun but no MCP operation created one after the chat decommission; the vertical E2E masked the gap with a raw-ORM prerequisite seed.
T029i: MCP create_agent_run/get_agent_run (mcp_server/tools_agent_run.py) over Services.AgentRuns.Service.Create — REST-parity EXECUTE/READ permissions, human-only, server-pinned UIContext, idempotency-key replay; catalog 2.1.0->2.2.0; MCPX-FR-027 external-reachability invariant pinned; initial-scenario E2E converted to the fully external chain (zero non-MCP seeding); strict-xfail pin flipped as designed, unmarked and hardened (E2E-EXT-001 CLOSED).
T029k: ScenarioGraph.CapabilityAuthority — truthful capability facts derived from the authoritative DashboardQueryModel (mutation-context capabilities never derived), derived-wins merge over caller declarations, single choke point wired into MCP inspect_scenario / inspect_dashboard_context and REST api_compile_scenario; CAP-001 classification-fix test on the sales-shape fixture (B02-B04/T01-T03 automated, C04-C06 unsupported, unsafe-mutation cases legitimately human).
T029l: disposition vocabulary clarity — RU/EN labels name the persisted outcome (confirm->passed), confirm restyled bg-destructive->bg-primary, decide_checkpoint description carries the immutable outcome table; lifecycle mapping and API vocabulary unchanged (DISP-001 CLOSED).
Decision memory: ADR-0024 (IMPLEMENTED, 4 rejected alternatives incl. no-AgentRun boundary and implicit auto-create) + README registry; 050 MCPX-FR-027/028/029 + release-gate rows + Clarifications session 2026-09-07; 038/044/045 field-run amendments -> IMPLEMENTED; WORKSTATE checkpoints (plan round + execution round).
Pre-existing HEAD regressions surfaced by the first full-suite rerun since 4d5ef6be/58c5ae39 and fixed: (1) stale SC-007 resource pin — canonical identifier is the post-redirect /mcp/ (code + twin pin aligned since the batches; test_mcp_client_flow_http pin updated with rationale); (2) app-lifespan tests re-entered the run-once StreamableHTTPSessionManager module singleton — autouse fresh-transport-app fixture (production lifespan runs once per process; singleton stays correct there).
Gates: full backend suite 11357 passed / 243 skipped / 1 xpassed / 0 failed (first green full run since the batches); MCP+catalog slice 70 passed; capability slice 67 passed; frontend vitest 3507 passed (206 files), lint 0 errors (364 baseline warnings), build OK; ruff/compileall clean; anchors balanced; scoped git diff --check clean. INV_7 watch: tools_scenario.py 508 LOC and routes scenario.py 442 LOC flagged for the next decomposition pass (new code lives in new modules 155/236 LOC).
OPEN: T029m / E2E-EXT-002 — live-stand replay of the sales scenario through the full external chain. Not included (foreign uncommitted workstream): translate/migration integration tests, _job_routes.py, .kilo/agent-manager.json, specs-036-050-20260907-111314.md.
2026-09-07 16:52:38 +03:00
58c5ae39cb
feat(scenario): server-owned handle pipeline T029d–h + MCP bootstrap/automation + UI launch/approval
...
Backend (Phase 2c, closes ADR-0023):
- T029b/c: 9 automation MCP tools (REST-parity RBAC, scheduler registration, idempotency), migration 0018; fresh-DB MCP E2E.
- Guard BOOTSTRAP_REVISION_NOT_RUNNABLE in derive_runner_plan (provenance-only revisions never queue a vacuous zero-step PASS); demoted to defense-in-depth after materialization landed.
- T029d: CompiledScenarioHandle/ValidationResultHandle/DraftPackHandle (immutable, owner-bound, content-addressed canonical-bytes store), migrations 0019/0021; minting at REST compile/validate/resolve/draft-pack boundaries; single consumption under SELECT...FOR UPDATE + populate_existing, proven on PostgreSQL (Testcontainers).
- T029e: handle-first create_scenario/create_initial materialize canonical graph_snapshot (+ server-owned action_registry identity) in-transaction; OutboxEvent + RevisionMaterialization (0020) with idempotent worker wired into the scheduler poll loop (30s tick).
- T029f: MCP register_draft_pack write tool; bootstrap accepts only stored handle ids (transitional compile:{run}:{digest} removed); legacy REST POST /scenarios/{id}/revisions retired -> 410; catalog 2.0.0 (pinned-major ritual); ActionRegistry 038.2.0 — generate_report reclassified non-mutating (local draft write), register_artifact/row_edit/bulk_edit stay mutating.
- T029h (hybrid C+X1): inspect_dashboard_context MCP tool (live DashboardQueryModel resolver); context_authority evaluation — server recomputes client-context fingerprint (claimed values ignored), sentinel fingerprints never verify, unreachable env fails open to unverified, live-env mismatches reject typed with zero rows; marker persists on DraftPackHandle, materializes into graph_snapshot; PROD start refuses explicit non-verified (CONTEXT_AUTHORITY_REQUIRED_FOR_PROD); validator recursively rejects query_context/SQL smuggling in dashboard_context; catalog 2.1.0. 043 editor path provably inherits the marker.
Frontend:
- D2: scenario detail route scenarios/[id] — first production host of RunConfigurationPanel (typed 044 launch + Idempotency-Key + redirect to run monitor); ROUTES.scenarioDetail SSOT; registry index links to detail (launch stays off the index).
- D4: ApprovalDecisionPanel + RunMonitorModel.decideApproval — PROD gates decidable from the web UI (run-detail aside on pending_approval).
- Pre-existing suite repairs: oauth-consent raw goto -> ROUTES.login(); InvestigationModels stale dispose signature; settings mcp_oauth_* bind:value undefined crash (backend defaults 15/30/90).
- i18n: approval_* + scenario_detail_* keys in en+ru.
Specs/docs (amendments 2026-09-06/07):
- 038: PackCompiler.Generate contract corrected (pure manifest); ServerOwnedPipeline handle-persistence amendment; verification-program reconciliation (implemented vs PROPOSED IR entities).
- 042: synchronous graph materialization + outbox scope; CreateInitial amendments; RevisionChain @REJECTED for raw client graph_snapshot.
- 050: stage-table implementation-status note, handle-rules status, T029–T029h evidence; WORKSTATE checkpoints; ADR-0023 -> IMPLEMENTED.
Gates: backend full regression 3360 passed (+ PostgreSQL integration green), alembic single head 0021; frontend vitest 3506 passed, lint 0 errors, build OK.
2026-09-07 11:26:34 +03:00
4d5ef6bed0
feat: dashboard-testing UX remediation + admin MCP governance + i18n sweep
...
- UX audit Fix 1-5: actionable MCP HandoffSurface (endpoint/discovery/onboarding), reachable
approval loop (sidebar section + waiting-for-me badge), honest MCP entry labels, ROUTES SSOT
for dashboard-testing/load-testing (+ link-integrity coverage)
- scenario registry hub (/dashboard-testing/scenarios) built on ScenarioRegistryModel
- admin MCP governance: read-only GET /api/admin/mcp/catalog (catalog x roles + DCR clients) +
/admin/mcp page/model/api + ROUTES.admin.mcp + sidebar entry
- full i18n sweep of dashboard-testing routes and scenario-* component trees (ru/en)
- accumulated workspace: MCP OAuth/DCR, automation idempotency migration, docker/nginx, specs
2026-09-05 20:16:26 +03:00
65121cac6b
feat(logging): self-diagnosing EXPLORE + shared/ absorption + belief analytics (ADR-0021/0022)
...
T0: absorb shared/ into backend — cot_logger→src/core, CotJsonFormatter→src/core/cot_formatter.py, _llm_http/_llm_health/ssl→src/core/utils; imports rewritten (26 prod + tests, patch targets); run.sh/backend.Dockerfile/requirements/.axiom source_dirs/semantic_health/AGENTS/INSTALL cleaned; ADR-0022 supersedes ADR-0015; fixed latent CI defects (ss_tools ImportError, record.message in logger tests, same-name test-module collision).
ADR-0021 wire enrichment (additive): contract_id/claim/error_code/loc fields; _contract_id ContextVar + resolve_contract_id (explicit > belief_scope > declared-src mirror, derived src never mirrors); EXPLORE auto-loc via single frame walk; facade error auto-fill; 2KB payload cap with payload_truncated/payload_bytes markers; migrated 85 error="CODE" sites to error_code= (12 files); pilot editor/load.py; superset preview payload-bomb inlined bodies removed.
Analytics SSOT src/core/log_stats.py (bond transition matrix, orphan-EXPLORE ratio, REFLECT pairing, intent families, coverage, insufficient-sample flag); pretty_cot.py --stats/--digest/--trajectory/--story over one engine; log_gap_service three-tier ground-truth triangulation (FAILED w/o EXPLORE etc.) + GET /api/reports/log-stats|task-log-gaps (polling-suppressed); scripts/cot_audit.py CLI; enriched fields persisted into task_logs.payload for tier queries.
Frontend: ReportsAnalyticsModel + AnalyticsStatsPanel (Logs tab) + TaskGapPanel and per-row T1/T2/T3 gap badges (Tasks tab); cot-logger.ts ADR-0021 opts; i18n en/ru. Scheduler console spam fixed: apscheduler logger demoted to WARNING via LoggingConfig.scheduler_log_level. .axiom belief patterns -> $OBJ.* (alias undercount). molecular-cot-logging skill updated (fields, decision rules, tie-break, CLI) and synced.
Reviewed orthogonally: F1 cot_span contract pollution, F2 cap boundary accounting, F3 digest over-dedup, F4 trace-state bound, F5 tier metadata — fixed with regression tests. Validation: backend 11287 passed + ruff + compileall; frontend 3446 passed + lint + build; CLI smoke on live app.log.
2026-09-04 20:56:41 +03:00
4c57789218
fix(mcp): closure-gate remediation rounds 2-5 — unified CoT logging, server.py decomposition, 050 P2 queue closed
...
Round 2 — P1 MCL + GRACE:
- logger intent-drop repaired across 182 call sites; logging unified repo-wide on the
intent-first facade (211 direct SSOT log() sites migrated); facade level= support;
molecular-cot-logging skill synced with the module (.agents -> .kilo).
- EXPLORE/REASON-REFLECT gaps closed: poll-dispatch failure path, exploration fail-closed
choke point in _finish(), 9 silent mcp_ops_dispatch adapters.
- INV_6: dead agent/app.py edge removed (_llm_health); specs 033/035/036/039 sweep ->
0 dead edges (5 retargeted to live IDs, 15 tombstoned with successors).
- INV_9 dedupes (TaskDrawer BINDS_TO, vestigial assistantOffset, duplicated @SIDE_EFFECT);
INV_1: migrations 0014-0016 anchored, exploration_sandbox module-region span fixed.
- Full-suite defect root-caused: leaked DI singleton mocks from test_dependencies_unit ->
autouse restore fixture + get_session_idle_timeout_minutes hardening (int validation,
EXPLORE fallback SESSION_POLICY_CONFIG_INVALID).
- Executable pins: tests/test_core/test_logger_wire_format.py (wire fields, misuse proof,
repo-wide AST sweeps over both forbidden shapes).
Round 3 — server.py decomposition EXECUTED per the binding gate plan
(specs/050-mcp-interface/plans/server-decomposition-gate.md, execution log included):
- 1571 -> 177 LOC: scenario_inputs.py (268), auth.py (238, single _access_token_context
site), rbac_server.py (393), tools_authoring.py (367), tools_scenario.py (373).
- Addendum E: pre-existing ops_tools.py INV_7 offender split 420 -> 215 + tools_review.py (253).
- Contract IDs frozen, import surface frozen, registration order frozen; monkeypatch seams
relocated to owning modules (recorded); zero behavior diff.
Round 4 — P2 queue closed:
- Story 5 AC2: HandoffSurface copyable prompt parameterized with dashboard context
(/agent route forwards objectType/objectId/objectName/envId/route/intent; i18n
handoff_context_label ru/en; contract + render tests).
- E6 / MCPX-FR-007a: McpTransportGuard enforces server-owned JSON-depth bound (typed
400 json_depth_exceeded pre-dispatch, iterative fail-closed walker) and per-session
sliding-window rate limit (typed 429 rate_limited + standard Retry-After); rejections
create no mutable state. Limits live in McpServerConfiguration.
- SC-005 remnants CLOSED: /api/assistant router unmounted (package retained as MCP parity
provenance, header records rationale); /api/agent/llm-config REMOVED with in-place
Tombstone + dead strict service DI deleted; assistant.ts deleted (inbound edge removed
first); SystemSettings assistant-retention UI + 16 i18n keys removed; .env.example
7860/GRADIO vars removed (zero consumers verified repo-wide).
- SC-004 + SC-009: exact RBAC catalog pins (admin 47 / analyst 21 / viewer 15 derived from
the live catalog); mid-flow role revocation hides tools in the next tools/list AND denies
cached-catalog calls by name on the same identity-only token; mid-flow grant exposes the
approvals surface without new consent.
- Browser cookie-consent decision recorded (tasks.md T008): not built in 050.
Round 5 — last 050 task + FR-010:
- T008b: Core.EndpointLocality deny-by-default perimeter guard for LLM/VLM provider base_url
at the create/update choke points (private ranges, enterprise DNS suffixes, all-private
resolution; fail closed; anti-substring-spoofing; empty URL denied); typed 400
endpoint_not_local:<reason> pre-persistence; EXPLORE audit line on every denial; env
escape hatches documented (INSTALL.md "Локальный периметр").
- MCPX-FR-010: MCP_CATALOG_VERSION published as serverInfo.version at initialize;
deprecated/deprecation_note on McpToolDefinition; [DEPRECATED] marker at the single
list_tools choke point (entry stays listed/callable one minor cycle); deliberate
major-bump ritual pinned by test.
Evidence: full backend suite 11243 passed / 240 skipped / 1 xpassed / 0 failed;
frontend vitest 3435 passed / lint 0 errors; MCP slice 103; locality slice 107;
anchor+AST sweeps ALL BALANCED over 138 touched files; 050 tasks.md fully [x] with proof.
2026-09-04 13:07:08 +03:00
731aaaa8df
feat(mcp): 050 unified MCP interface — parity tools, durable gates, authoring E2E, assistant decommission
...
044 provider runtime completion (pre-staged workstream): capacity/operator
stores, provider ops/protocol/reconciler/dispatch revalidation, exploration
sandbox runtime, alembic 0014-0016, live canary evidence (browser provider
6/6 against the live stand).
050 Phases 0-2: RBAC FastMCP server with a 45-tool explicit catalog,
OAuth/DCR transport guards with bounded bodies, per-call provenance
(McpToolInvocationRecord), durable ActionApprovalGate + CAS decide +
leased/fenced poller, authoring workspace ops, bounded-response discipline,
hidden-vs-gated matrices.
Parity domains (T012-T014): gated git/deploy/migration/backup/llm tools with
reviewed dispatch adapters in explicit poll chains; Superset reads/writes with
a dedicated plugin:superset_sql risk class (terminal PROD denial via the
canonical execution-policy criterion, hardened danger-SQL guard covering
INTO/CALL/SET/REFRESH/file primitives/multi-statement); baseline 037 tools
over the shared REST-surface services.
Evidence (T016/T023/T028): REST-vs-MCP field parity on shared 037 fixtures;
vertical E2E from tools/list through registry revision activation with real
scenario:EDIT RBAC; sandbox-to-revision promotion E2E with unsafe-payload and
caller-digest rejection; dispatcher soak (three poll cycles, exactly-once).
Orthogonal QA+security audit hardening: enforced response_limit fail-closed
envelope, poisoned-exploration fail-closed (EXPLORATION_TARGET_UNRESOLVED),
sha256 exploration evidence digests, actor-UUID task ownership, is_active
guard on baseline consume, 038 resolver description=None selector fix.
Phase 3/4 decommission: HandoffSurface behind the MCP_DECOMMISSION flag,
then unconditional removal — agent/ service tree, chat components/models/
stores/types, gradio proxies (vite + nginx), agent service in run.sh,
docker-compose profiles, build.sh bundles; /agent renders the handoff only.
Docs: AGENTS.md/INSTALL.md two-service rewrite; 036-047 drift amendments
marked done; WORKSTATE checkpoints with all evidence.
Suites: backend 11199 passed / 240 skipped / 1 xpassed; frontend 3454 passed
(197 files), lint 0 errors, build OK; browser E2E login+handoff 6/6 twice on
the isolated compose stack (no 7860); ruff/compileall clean.
Misc: gitignore hardening (tmp/, tool model cache); E2E selector repairs
(nav strict-mode, invalid-credentials passthrough detail).
2026-09-03 07:37:14 +03:00
341d54399a
fix(semantics): repair GRACE-Poly anchors, relations, and metadata
...
Repair broken/unclosed semantic-protocol markup across the codebase:
- INV_3 region pairing: restore 87 bare '# #endregion' (6 test_structure_*
files) and 321 bare '// #endregion' (13 frontend test files) with their
matching IDs; hand-fix 26 Python + 12 frontend + 2 E2E files with
mismatched/missing/premature/duplicate closes; fully migrate
test_orthogonal_fixes.py from single- to double-hash anchors.
Workspace-wide stack-pair scan now passes 6569 code files with 0 problems.
- Relations: normalize legacy predicates USES/CONTAINS/BELONGS_TO to
canonical DEPENDS_ON/BINDS_TO (28 edits).
- Metadata: normalize @LAYER and [TYPE] enum values to the canonical
vocabulary (App->Application, lib->Infra, Service/Route/Checklist/
Declaration/Decorator/Functions -> Module/Function/Block, etc.).
- Config: extend tags.LAYER.enum; fix tools.py prose '#region' phantom that
broke anchor nesting.
- Remove dead scratch scripts backend/_convert_defs.py, _batch_convert_defs.py.
Index refresh: contract count 9576 -> 10821; schema_unclosed_anchor
1179 -> 729 (remaining 729 are markdown legacy [DEF:]/brace anchors, a
separate migration phase).
2026-09-01 12:24:42 +03:00
7a14a4d947
feat: add MCP authoring workspace foundations
2026-08-28 19:01:42 +03:00
e14524d22a
fix: resolve test and lint gate failures
2026-08-26 18:56:57 +03:00
0415a2ed7d
chore: accumulate uncommitted workspace changes
2026-08-26 17:03:22 +03:00
6cfd9135bb
fix: resolve production log errors — profile, datasets, migration recovery, mapper validation, reencrypt
...
- AuthRepository: add missing save_user_dashboard_preference (PATCH
/api/profile/preferences returned 500)
- DatasetItem.schema_name nullable — GET /api/datasets no longer 503s on
Superset datasets with null schema
- migration: TaskLogger calls used extra= kwarg which raised TypeError and
killed the composite-key recovery branch, leaving the target server
unrepaired after failed dashboard imports (e.g. PR-0160); switched to
metadata=
- maintenance settings: lazy-create singleton with IntegrityError race guard
instead of permanent 404
- mapper upload-xlsx: structured 400 detail (expected vs actual columns);
MapperTool shows inline error panel instead of toast; i18n ru/en
- connection_service: eager re-encryption of legacy plaintext passwords in
get_connection; returns a copy so live config never holds plaintext
- check_target_schema: log exception type/repr/traceback (was empty error)
- scheduler/maintenance auto-end: skip empty-tick INFO logs; suppress HTTP
framing for GET polling endpoints
- reencrypt script: repair broken merge artifact, JSON-serialize payload on
save, fix failed-count arithmetic
2026-08-26 12:50:03 +03:00
4b9619e229
refactor(deploy): standardize enterprise environment file
2026-08-25 15:30:10 +03:00
5bc1b62bd0
refactor: unify initialization and reset migration baseline
2026-08-25 11:42:31 +03:00
0c895cf416
feat(logging): unify canonical task CoT events
2026-08-24 17:00:17 +03:00
511219e3e0
fix(git): remove guided tour
2026-08-24 16:01:03 +03:00
fa4a75ce1e
feat(frontend): unify Superset Tools visual system
2026-08-24 14:16:35 +03:00
1a5c14739e
feat(auth): refresh login experience
2026-08-21 16:17:23 +03:00
ffa4d6a85b
feat(scenarios): implement execution engine contracts
2026-08-21 16:15:40 +03:00
adbea9db18
fix(translate): fail-closed source handling, double insert, retry recount, scheduler races, LLM parse safety, and improved BI-analyst error UX
2026-08-20 17:34:39 +03:00
585a00c537
semantic-curation: fix anchors, metadata, and relations across backend + specs
...
- Replace legacy @PURPOSE with @BRIEF across 241 files
- Add missing [C:N] complexity tiers to function contracts in core modules
- Fix tombstone contracts: add @STATUS DEPRECATED to 5 deprecated anchors
- Resolve 7 unresolved @RELATION edges in executor.py (DictionaryManager, TranslationPreview, etc.)
- Fix flat hierarchical IDs in 4 test files (22 test functions)
- Fix invalid tags/relations in logger.py (@ADR, @CONSEQUENCES, DISABLED_BY)
- Rebuild semantic index: 9,576 contracts, 4,742 edges, 0 parse warnings
2026-08-20 11:45:15 +03:00
82a519a347
feat(scenarios): complete editor execution and analytics
2026-08-20 11:32:26 +03:00
e291ba757f
fix(agent): full-catalog dashboard search and working LLM retry
...
- search_dashboards: call /api/dashboards with page_context=other and
page_size=100 so the profile 'My Dashboards Only' filter can no longer
hide the whole catalog; parse available_total/effective_profile_filter
and report hidden-by-filter instead of a false 'no dashboards' answer
- prefetch_dashboards: same full-catalog context; fix dead code where
data=resp.json() sat after return '' inside the error branch, making
every 200 response raise NameError and the prefetch always return ''
- llm-status: ?force=1 bypasses the 30s health cache so the 'Retry now'
button performs a fresh probe instead of re-reading the stale status;
frontend keeps a single retry interval (previously stacked intervals
decayed the countdown faster than 1/s and fired duplicate probes)
- tests: agent tool/prefetch, backend route bypass + force param,
frontend retry/force coverage
2026-08-19 19:21:00 +03:00
dd9df0fc5e
feat(env-widget): dashboard stats widget with per-env counts, health probe and profile-filter reference info
...
- Replace the global env <select> in TopNavbar with an expandable
EnvironmentStatsWidget showing per-env total/mine/published/drafts
and health status (latency, unreachable), preserving env switching.
- Add GET /api/environments/stats: per-env counts (profile-actor matched)
+ lightweight health probe, gathered concurrently with an 8s probe
timeout and a process-local TTL cache (30s, coalescing) so the full
Superset dashboard catalog is not re-fetched on every dropdown open.
- Add available_total to GET /api/dashboards so grids can show how many
dashboards exist when the profile-default filter hides everything.
- Share ProfileFilterBanner across the dashboards hub and validation
task form: 'showing X of Y' reference info + explicit Show all /
Restore filter actions.
- Russian plural forms for dashboard counts (pluralRu helper) and
compact 'Опубл.' label; i18n keys en/ru.
- Ignore :memory:test_* SQLite test artifacts and drop them from the index.
- Tests: env stats endpoint (incl. caching), widget, model fallback,
plural helper, api client, integration.
2026-08-19 14:40:14 +03:00
a571ff8175
fix(search): global search queries with envId and bypasses profile filter
...
- handleSearchInput now receives the selected envId, so the debounced
search actually fires API requests instead of hitting the !envId guard
and clearing results immediately.
- The dashboard section of the global search sends page_context=other,
apply_profile_default=false, override_show_all=true (same pattern as
DashboardHubModel.loadDashboardSearchOptions), so the "show only my
dashboards" profile filter no longer zeroes out dashboards that lack
owner metadata.
- Updated unit tests: debounce now asserts API calls + profile-off flags.
2026-08-19 11:00:33 +03:00