Changes touching this path
- the Tickets view on the private workbench, verdict E of #2411 (ADR 0094, ADR 0098 §1): a view module, its VIEWS line, routes for tickets, tickets/<id> and tickets/q/<query>, and a read route, /api/private/tickets, that answers the files the forge head holds under tickets/ as paths and addresses and each ticket path first touch in the head history with its generation. the browser fetches the objects from the forge by address, opens them with the session keys and folds them in wasm with loot_ticket::fold, the fold loot ticket now folds through too, moved out of loot-cli (ticket_read.rs: readTickets, ticketWants, ticketKinds), so the web reads a ticket as the CLI does and in the same causal order. the page is the conversation page for every ticket and map, a timeline ending in the resolution card, a comment and resolve composer and a right rail; the panel with search, saved views, maps, labels and kinds; and on a map a Conversation and Board switch whose board lays out Waiting, Frontier, In a lane and Resolved under the decisions so far, where a drop onto a card is a wait-on. sealed tickets are withheld rows, and each control names its loot ticket command. a write publishes one change through the SDK publish, now publishTicketWith over an injected core (sdk/src/ticket-publish.ts, assertStowAccepted moved to stow.ts); the pending bar holds writes in flight, and a collision shows both versions and asks. a session whose key is not the namespace owner reads, and lanes, which the web cannot see, are said to be so. connect-src is not widened, since the forge origin it names covers the repo endpoints, pinned by a CSP test, and a built private route loaded in headless Chrome under the enforced policy loaded the view and the wasm core with no violation but the control fetch meant to be refused. public surfaces grow by 229 to 236 B gzip, the route definitions. red under ten named mutations, each restored: the least touch taken as the latest (0 passed and 1 failed), the timeline ordered by name (0 and 1), waiting ignoring closure (0 and 1), the shared fold ignoring a label removal (0 and 2, the CLI label test and the browser read test), a touch outside the head history kept (1 failed and 2 passed), a generation counting a parent never sent (1 and 2), the board waiting column taking the frontier (1 failed and 7 passed), any session writing (1 and 7), an own key held without unsealing (1 failed and 16 passed), and the parent edges swapped in the read route SQL (1 failed and 78 passed over the live Postgres suites). cargo test green, 4739 passed over 145 binaries with 13 ignored, the site gate green at 856 passed, the live Postgres suites at 79 passed, and the SDK suite at 153 passed. owes a site deploy (#2432)
94447d12 · dbf3dbe6… - review sweep 4 fix-up over the live Tickets view (#2432) and the web ticket write (#2479, #2481), map #2422: no document key, href or URL of the view carries decrypted text any more, where a label in the panel opened a query whose URL held the label. a query is its own URL only when addressOnly finds every term an address, and any other, a label, a kind the ticket format does not name or a word typed into the search, is a search held in the workbench cache under a random handle that its key and URL carry instead (route tickets/s/<handle>), pinned by a render of the panel navigation, the lists, every ticket page and the board over a marked fold whose links and asked-for documents are scanned for the mark. an /ingest whose answer is lost, a thrown request or a 5xx, is settled by asking instead of read as not published: the SDK publish re-reads /ref, calls it published when the head is the change, sends the same built change again while the head is at the generation it was built on, and when the head moved asks an unbounded /fetch past its base whether the forge holds the change, which it does only when an ingest of it committed, building again only when not. until then the write reads unknown, the site asks until it knows, and an UnsettledIngestError names the change when the checks run out. the page asks before it unloads while a write has not settled. the board gains verdict E Take, which copies loot lane new --ticket <id>, on each frontier card and on a next in causal order callout. AGENTS.md states what the site build reads outside site/ as a property, site-main.yml paths gain sdk/src, loot-hygiene, loot-ticket and Cargo.toml, CONTEXT.md Stow-first publish and ADR 0098 §1 and §5 say what is true now, the member tier read of /api/private/tickets is pinned through forge_member_*, the keyring wait is Keyring.keyForSettled, data.ts uses lib/identity/bytes.ts, and the map kind is MAP_KIND. red under named mutations, each restored: a label opened as a query (1 failed and 6 passed), a label term taken as an address (3 and 4), unknown counted as settled (2 and 5), no beforeunload listener (1 and 6), no callout (1 and 6), no Take on a card (1 and 6), a lost answer read as a refusal (4 failed and 4 passed over the fake-transport suite, 3 and 5 against a real forge), a head at its generation rebuilt instead of resent (2 and 6), a moved head always taken as holding the change (1 and 7) and never (1 and 7 against a real forge), the keyring answering a lock without waiting (1 and 10), and the member read through the owner relation (1 failed and 79 passed over the live Postgres suites). the site gate green at 863 passed, the live Postgres suites at 80 passed, the SDK suite at 161 passed, and a CSP-enforced headless Chrome load of the built search, query and ticket routes met no violation but the control fetch. no Rust changed. owes a site deploy (#2486)
016ab4c2 · dbf3dbe6…diff - the Tickets view asks the consent a web write needs, and moves, attaches and shows attachments (map ztrnpqko): a write the core builds only with consent waits in the pending list while a sheet asks, publish naming each file that becomes world-readable for good beside a per-device do not show this again, which a notice above the view turns back on, demote naming who gains access and reveal refusing a secret-shaped name with an override, neither of which can be silenced, and a silenced device gives publish consent itself once per write; a composer on a public ticket shows a public badge either way. the rail moves a ticket to the spaces the head rules define, read by loot_wasm::ticket::spaces with the rule deciding each, and when they define none but internal it says so with the lines to add. the conversation takes a dropped or picked file, refused over ATTACHMENT_CAP before it is read, and an attachment opens through ticket_read::attachment: an image by its byte signature as a blob: URL in an img, the private CSP img-src widened by blob: alone, text by its declared extension escaped in a pre, and anything else a download of application/octet-stream. the filter term frontier becomes unblocked, frontier:<map> is the map frontier the core read, and a query holding the bare word redirects 301, /tickets/q/frontier to unblocked. ADR 0098 §11, the spec and CONTEXT.md record it. pinned natively (the spaces offered, a lockout group left out, internal alone with the lines to add, the attachment bytes the browser opens) and in the site. red under named mutations, each restored: img-src without blob: (41 passed and 2 failed), a quiet device dropping the demote question (42 and 1), the reveal question silenced (42 and 1), do not show this again beside every question (42 and 1), svg shown as text (42 and 1), an image judged by its name (42 and 1), a download typed text/html (42 and 1), an iframe preview (41 and 2), frontier:<map> read as map:<map> (42 and 1), no redirect (42 and 1), the badge off a public ticket (42 and 1), the internal-only note never shown (42 and 1), a lockout group offered (0 and 1), only the current space offered (0 and 1), the whole a/ file answered as the attachment (0 and 1). cargo test green, 4758 passed over 144 binaries with 13 ignored, the site gate green at 877 passed, and a CSP-enforced headless Chrome load of the built tickets routes with no violation, a blob: image loaded and a foreign image refused. owes a site deploy (vsropolo)
75a3eeb3 · dbf3dbe6…diff
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.