feat: package focused private Huddle portfolio demo - #7
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Finish Huddle as a focused, polished, private, resettable, synthetic-only TSA Junior Software Engineer portfolio demo whose teacher golden path is sign in, upload the fixed CSV, validate and commit, refresh, see the ranked Evidence Desk, open exact evidence, observe Seen acknowledgment, and verify deterministic fallback. The recovery pass must simplify the teacher-facing UI to match the accepted prototype by removing nonessential controls, explanatory chrome, visual density, unnecessary states, and excess code rather than restyling the same complexity. Preserve authentication, server-side Supabase/PostgreSQL boundaries with no browser-held service credential, synthetic-only enforcement, trust-boundary validation, accessibility, responsive desktop/narrow behavior, exact dominant and additional evidence, priority and confidence, acknowledgment, deterministic behavior, reviewed zero-model-call evaluation artifacts, explicit no-accuracy-claim posture, reproducible local/reset/deploy/hosted-smoke commands, and private Vercel plus Supabase reviewer packaging. Reuse the merged Operations and Evidence Desk implementations and existing dependencies; do not add speculative infrastructure, tenancy, model providers, portals, notifications, simulator breadth, or a broader evaluation platform. The captain will perform the final manual walkthrough; validation should focus on the real golden path and produce a PR with green CI.
What Changed
Risk Assessment
✅ Low: The Vercel protection fix is well-bounded, rejects the previously reachable ordinary-redirect false positive, and introduces no substantiated source or intent regressions.
Testing
Prior baseline visual artifacts showed the sign-in, ranked Evidence Desk, Seen state, fallback posture, and exact evidence; this round proved the previous clean-quickstart failure fixed by rebuilding from absent package outputs, reran the focused credential-free checks, exercised live routes and CSV delivery, and cleaned the transient Next.js output, with the credentialed walkthrough correctly left to the captain.
/var/folders/nt/rdk7cjs538l8zphln24q2k900000gn/T/no-mistakes-evidence/01KYRRD7ZDKXJRX44DN3K3ES19/login-rendered.html.png)/var/folders/nt/rdk7cjs538l8zphln24q2k900000gn/T/no-mistakes-evidence/01KYRRD7ZDKXJRX44DN3K3ES19/evidence-desk-rendered.html.png)/var/folders/nt/rdk7cjs538l8zphln24q2k900000gn/T/no-mistakes-evidence/01KYRRD7ZDKXJRX44DN3K3ES19/exact-evidence-rendered.html.png)Evidence: Anonymous board fails closed after clean install
Evidence: Live health and policy response
{"ok":true,"service":"huddle","dataPolicy":"synthetic-only","decisionSupport":"deterministic","accuracyClaim":"none"}Evidence: Zero-model deterministic portfolio report
Evidence: Clean installation recreating all workspace outputs
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
🔧 **Review** - 5 issues found → auto-fixed (3) ✅
apps/web/app/board/evidence-desk.tsx:414- The required report progression is reversed: the report header omits the dominant cause, while exact attempts render before prerequisite/conflict details inside the shared EvidenceDetails component. This contradicts the required preservation of dominant/additional evidence and the Evidence Desk contract’s cause → comparison/prerequisite/conflict → exact-record order. Surface the cause in the report header and restore that ordering for dominant and additional findings.apps/web/app/board/evidence-desk.tsx:442- The visible trust label says only “Deterministic fallback”; the required degraded status and reason are hidden under collapsed Technical provenance. This also contradicts the README walkthrough’s promised “Deterministic fallback · degraded” state. Confirm whether hiding the reason was intentional, or surface it without expansion..github/workflows/ci.yml:45- CI uploads artifacts/portfolio-eval-report.json, but verify:quickstart writes the report to /tmp/huddle-portfolio-eval-report.json. The upload therefore retains no report and only warns. Align the paths and set if-no-files-found: error.apps/web/app/board/evidence/[entry_id]/page.tsx:11- The legacy page still imports a low-level DB helper directly, contradicting FR-058’s requirement that pages use the application interfaces rather than repositories. Route this lookup through an application-owned boundary or explicitly retire the legacy route.README.md:111- The required “reproducible ... deploy” and “private Vercel” packaging is incomplete: no deployment command is documented, and Deployment Protection is described as optional (“when ... enabled”). Require and document the private deployment/protection workflow and reviewer access, or explicitly approve Supabase-auth-only containment.🔧 Fix: Restore report trust and private deployment guarantees
2 errors still open:
apps/web/app/board/evidence-desk.tsx:414- The required evidence progression remains incomplete: prerequisite and conflict facts are inside the collapsed “Show exact contributing evidence” disclosure and a second collapsed “Rule and quality details” disclosure. Opening the exact-evidence section therefore exposes attempts while these level-2 facts remain hidden, contrary to the required comparison/prerequisite/conflict → exact-record sequence. Move a compact prerequisite/conflict presentation before the exact-record disclosure.scripts/smoke-hosted.ts:22- The change claims to guarantee “private Vercel plus Supabase reviewer packaging,” but the hosted smoke still makes VERCEL_PROTECTION_BYPASS optional and only checks bypassed application responses. A public deployment can therefore pass and print success. For hosted URLs, require the bypass and first verify that an unbypassed request is stopped by Deployment Protection before running application checks with the bypass.🔧 Fix: Expose evidence context and enforce hosted protection
1 error still open:
scripts/smoke-hosted.ts:36- The required “private Vercel plus Supabase reviewer packaging” invariant remains bypassable: the changed hunk accepts any 3xx response with a Location header as Deployment Protection. A public alias that redirects to its canonical deployment passes this probe, after which the application checks follow that ordinary redirect and can report success. Validate a Vercel-authentication-specific challenge marker and cover an ordinary public redirect in the smoke test. See Vercel Deployment Protection.🔧 Fix: Require Vercel-specific authentication challenge
✅ Re-checked - no issues remain.
🔧 **Test** - 2 issues found → auto-fixed ✅
README.md:53- The documented clean quickstart is not reproducible immediately afternpm ci.npm run devreturns HTTP 500 for/boardbecause@huddle/db/scoped.jspoints to an absent generateddistfile;npm run eval:portfoliolikewise cannot resolve@huddle/narrator/dist/src/catalog.js. Building the relevant workspaces first unblocks both, but README does not document this prerequisite and the root commands do not ensure it..env, Supabase reviewer credentials, or database connection. Reviewer-visible component renders and focused boundary tests cover these surfaces, but they do not replace a credentialed walkthrough. Decide whether to supply a reviewer environment for automated evidence or retain this as the captain-owned final walkthrough.Inspecteda61db956f7df275dff7b5dc1727a575c8bed8b3a..0c5ead7241d642f878d9ac07d9869c52ba1d936f, the implementation plan, constitution, README, and golden-path scripts/tests.npm exec vitest run packages/ingest/test/portfolio-csv.test.ts packages/eval/test/portfolio-gate.test.ts apps/web/test/demo-config.test.ts apps/web/test/import-actions-fail-closed.test.ts apps/web/test/quick-demo-access.test.ts apps/web/test/evidence-desk-rendering.test.ts apps/web/test/evidence-desk-state.test.ts apps/web/test/acknowledgment-tokens.test.ts apps/web/test/report-reveal-server-action.test.ts apps/web/test/health-route.test.ts scripts/smoke-hosted.test.ts packages/db/test/evidence-persistence.test.ts packages/db/test/evidence-acknowledgment-migration.test.ts(initially exposed missing workspace outputs; completed assertions passed).npm run build -w @huddle/narratorfollowed bynpm exec vitest run apps/web/test/quick-demo-access.test.tsto repair and verify test setup.env -u ANTHROPIC_API_KEY npm run eval:portfolio -- --out /var/folders/nt/rdk7cjs538l8zphln24q2k900000gn/T/no-mistakes-evidence/01KYRRD7ZDKXJRX44DN3K3ES19/portfolio-eval-report.json(initial clean-output attempt failed; retry after workspace generation passed).npm run db:migrate -- --help,npm run demo:seed -- --help,npm run demo:reset -- --help, andnpm run smoke:hosted -- --help.Started the real Next.js app and rannpm run smoke:hosted -- --base-url http://127.0.0.1:3107from a clean generated-output state;/boardfailed with HTTP 500 due unresolved@huddle/db/scoped.js.npm run build -w @huddle/db, restarted Next.js, then rerannpm run smoke:hosted -- --base-url http://127.0.0.1:3107; health, login, fixed CSV, and anonymous fail-closed board behavior passed.Fetched/healthand verified anonymous/boardrenderedGuide workspace unavailablewithout synthetic roster names.Rendered and visually inspected the live/loginresponse plus actualEvidenceDesk,ReportHeading,NarrationTrust, andEvidenceRecordDisclosurecomponents with synthetic fixtures.Removed generated.nextand workspacedistdirectories; finalgit status --shortwas clean.🔧 Fix: Build workspace outputs during dependency installation
✅ Re-checked - no issues remain.
Removed the eight ignoredpackages/*/distdirectories, rannpm ci, and verified all eight workspace outputs were recreated, includingpackages/db/dist/src/scoped.jsandpackages/narrator/dist/src/catalog.js.Ranenv -u ANTHROPIC_API_KEY npm run eval:portfolio -- --out …/portfolio-eval-after-clean-install.json.Ranenv -u ANTHROPIC_API_KEY npm run verify:quickstart, covering determinism, strict portfolio CSV, demo configuration, Evidence Desk rendering, health policy, reveal action, and hosted-protection behavior.Started the real application withnpm run devafter the clean install and requested/login,/board,/import,/health, and/synthetic-huddle-sample.csv.Verified/loginrendered, anonymous/boardand/importshowed the private-guide denial state,/healthdeclared synthetic-only/deterministic/no-accuracy-claim policy, and the fixed CSV contained 53 lines.Inspected the retained reviewer-visible sign-in, ranked Evidence Desk, Seen acknowledgment, deterministic fallback, and exact-evidence screenshots.The initial evaluator attempt setANTHROPIC_API_KEYto an empty string and was rejected by configuration validation; retrying with the variable genuinely unset matched the documented workflow and passed.✅ **Document** - passed
✅ No issues found.
🔧 **Lint** - 1 issue found → auto-fixed ✅
scripts/smoke-hosted.test.ts:75-npm run typecheckfails becauseprotectedDeployment(): HostedSmokeFetcherases Vitest mock metadata, leavingfetcher.mockuntyped at lines 75 and 78. The mechanical fix requires changing a test, which this phase forbids.🔧 Fix: Preserve Vitest mock typing
✅ Re-checked - no issues remain.
✅ **Push** - passed
✅ No issues found.