Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
30 commits
Select commit Hold shift + click to select a range
1c5cb0f
design(admin-password): questions deck for the in-chat admin password…
itsdestin Sep 26, 2026
898a0f7
roadmap(native-harness): admin password card in design; keys and othe…
itsdestin Sep 26, 2026
2e8c06f
design(admin-password): UX tester pass 1 (5 accepted, 2 rejected) and…
itsdestin Sep 26, 2026
56f05b2
design(admin-password): record review 1 answers; round-2 deck
itsdestin Sep 26, 2026
8b6862f
design(admin-password): record round-2 answers; round-3 deck (no subt…
itsdestin Sep 26, 2026
41c44c1
design(admin-password): record round-3 answers; round-4 deck (Confirm…
itsdestin Sep 26, 2026
c0efc7c
design(admin-password): record round-4 answer (approved)
itsdestin Sep 26, 2026
93911eb
design(admin-password): confirm deck for three decisions made in chat
itsdestin Sep 26, 2026
5bae6c1
design(admin-password): record confirm answers; the 20-row contract
itsdestin Sep 26, 2026
34894b4
design(admin-password): contract signed
itsdestin Sep 26, 2026
d102840
spec(admin-password): technical design draft
itsdestin Sep 26, 2026
3b84cfd
spec(admin-password): design review 1 — 7 accepted, 2 already handled…
itsdestin Sep 26, 2026
806f60b
spec(admin-password): design review 2 — 8 accepted, 1 rejected; desig…
itsdestin Sep 26, 2026
a57787e
spec(admin-password): design review 3 — 2 accepted, 1 rejected; build…
itsdestin Sep 26, 2026
ff8e4d3
review(admin-password): task 1 and task 2 reviews triaged
itsdestin Sep 26, 2026
a861a09
spec(admin-password): handshake v2 — verify, then harden, then deliver
itsdestin Sep 26, 2026
c756a58
review(admin-password): task 3 review triaged (5 accepted, fixed in 6…
itsdestin Sep 26, 2026
262d946
review(admin-password): task 4 and 5 reviews triaged (fixed in ec1c7c…
itsdestin Sep 26, 2026
26b4ca1
review(admin-password): code review and UX review 2 triaged; file the…
itsdestin Sep 26, 2026
bc64847
design(admin-password): contract second pass — 5 review rows, R13/R15…
itsdestin Sep 26, 2026
169f9a0
design(admin-password): grader verdicts (15/15 graded rows pass) and …
itsdestin Sep 26, 2026
9f3ed77
docs(admin-password): redesign §3 item 2 — real sudo's exe/environ ar…
itsdestin Sep 26, 2026
c9c8482
spec(admin-password): keep the user's NODE_OPTIONS in commands
itsdestin Sep 26, 2026
8b99e98
docs(admin-password): add §12 Per-machine guidance and refusals
itsdestin Sep 26, 2026
2fea894
design(admin-password): round-5 deck — the refusal message and per-ma…
itsdestin Sep 26, 2026
649b8bd
design(admin-password): record round-5 answers
itsdestin Sep 26, 2026
f22b99f
design(admin-password): acceptance deck answered — all 13 accepted
itsdestin Sep 26, 2026
5707b8d
merge origin/master into session/sudo-prompt
itsdestin Sep 27, 2026
a70066a
docs(admin-password): ship — archive design, spec and reviews; close …
itsdestin Sep 27, 2026
0c2167f
test(shoot): wait for the page instead of a fixed 300 ms before readi…
itsdestin Sep 27, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -72,8 +72,8 @@ Target: `v1.3.1`
| Area | Open | Needs verify | Decisions | Parked |
|---|---|---|---|---|
| [dev-workspace](docs/roadmap/dev-workspace.md) — building the app, not the app | 101 | 32 | 4 | 9 |
| [native-harness](docs/roadmap/native-harness.md) — the app's own agent doing work | 55 | 10 | 5 | 23 |
| [user-interface](docs/roadmap/user-interface.md) — shared primitives, chrome, layout, copy | 39 | 16 | 2 | 6 |
| [native-harness](docs/roadmap/native-harness.md) — the app's own agent doing work | 57 | 10 | 5 | 25 |
| [user-interface](docs/roadmap/user-interface.md) — shared primitives, chrome, layout, copy | 40 | 16 | 2 | 6 |
| [remote-access](docs/roadmap/remote-access.md) — reaching the app from another device | 29 | 6 | 1 | 4 |
| [sync](docs/roadmap/sync.md) — moving your stuff between devices | 26 | 10 | 8 | 5 |
| [chat-data](docs/roadmap/chat-data.md) — everything kept about a chat | 22 | 7 | 2 | 2 |
Expand Down
1 change: 1 addition & 0 deletions docs/MAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ Rules live in `.claude/rules/`; depth docs are read-on-demand (`youcoded/docs/`,
| Status bar & `/usage` (what every number counts) | `youcoded/desktop/src/renderer/components/StatusBar.tsx`<br>`youcoded/desktop/src/renderer/components/UsageCard.tsx`<br>`youcoded/desktop/src/renderer/state/status-widgets.ts` (the ONE place that answers "can this session show this widget?" — bar and menu both read it)<br>`youcoded/desktop/src/renderer/state/session-totals.ts` (cumulative, specialist-inclusive; `anyFree` ≠ `anyUnpriced` ≠ absent)<br>`youcoded/desktop/src/renderer/state/usage-snapshot.ts` (pure — extracted from App so it can be tested)<br>`youcoded/desktop/src/renderer/state/cache-reuse.ts` (the ONE place "how much of the prompt came from cache" is computed — bar and Usage card both read it, after they disagreed)<br>`youcoded/desktop/src/main/harness/pricing.ts` (`costForUsage` — the ONE place tokens become dollars; cached reads AND writes leave the prompt before their own rate applies; also the provider cost self-check)<br>`youcoded/desktop/src/main/harness/harness-session.ts` (`reprojectContextUsed` — occupancy after a /compact or /clear, which run no turn; `abandonedTurnUsage` — what an interrupted or errored turn already spent)<br>`youcoded/desktop/hook-scripts/statusline.sh` (writes context REMAINING, not used) | status-bar-relevance | `docs/archive/specs/2026-08-25-status-bar-session-relevance-design.md` | `youcoded/desktop/tests/status-widgets.test.ts`<br>`youcoded/desktop/tests/session-totals.test.ts`<br>`youcoded/desktop/tests/statusbar-session-relevance.test.tsx`<br>`youcoded/desktop/tests/statusbar-widget-menu.test.tsx` (the bar/menu agreement table)<br>`youcoded/desktop/tests/usage-snapshot.test.ts`<br>`youcoded/desktop/tests/usage-card-native.test.tsx`<br>`youcoded/desktop/tests/provider-cost-check.test.ts`<br>`youcoded/desktop/tests/harness-pricing.test.ts`<br>`youcoded/desktop/tests/statusline-context-remaining.test.ts`<br>`youcoded/desktop/tests/context-gauge-after-rewrite.test.ts` (the gauge after a rewrite outside a turn; page-replay bookkeeping)<br>`youcoded/desktop/tests/abandoned-turn-usage.test.ts` |
| Status push (the 10 s status bar data) | `youcoded/desktop/src/main/status-push-gate.ts` (the audience gate: sends only while a main window is visible or a phone is connected; drops a payload identical to the last one; pushes at once on show, focus or connect)<br>`youcoded/desktop/src/main/ipc-handlers.ts` → `buildStatusData()` (the payload itself, single-flight) | performance | — | `youcoded/desktop/tests/status-push-gate.test.ts` |
| Native permissions (Always-allow grants; the per-session mode chip) | `youcoded/desktop/src/main/harness/permission-store.ts`<br>`youcoded/desktop/src/main/harness/native-session-host.ts` (revokeRule / revokeProject; `seedMode` / `setPermissionMode` — the ONLY mode writers, both push `native:permission-mode`)<br>`youcoded/desktop/src/main/harness/permission-mode-store.ts` (the chosen mode, restored on resume)<br>`youcoded/desktop/src/renderer/App.tsx` (`seedNativeMode` + the push listener — the chip)<br>`youcoded/desktop/src/shared/permission-types.ts`<br>`youcoded/desktop/src/shared/subject-glob.ts` (`ruleMatches` — the ONLY decision-path matcher)<br>`youcoded/desktop/src/shared/bash-grant-shapes.ts` (what an "Always allow" may offer)<br>`youcoded/desktop/src/main/harness/permission-engine.ts`<br>**The floors BELOW every remembered grant** (each forces an ask with no "Always allow"; a deny rule still denies; called from `harness-session.ts` step 3b): `youcoded/desktop/src/main/harness/tools/rm-target.ts` (removing the workspace, home, disk root or a system folder), `youcoded/desktop/src/main/harness/tools/bash-secret-paths.ts` (a Bash command that names a file the file tools refuse), `youcoded/desktop/src/main/harness/tools/shell-words.ts` (the one shell tokenizer both read with)<br>`youcoded/desktop/src/renderer/components/permissions/deny-list-copy.ts` (the reason line a forced card shows, worded by the floor's kind)<br>`youcoded/desktop/src/renderer/components/PermissionsSection.tsx`<br>`youcoded/desktop/src/renderer/components/permissions/describe-rule.ts`<br>`youcoded/desktop/src/renderer/components/permissions/permissions-explainer.ts`<br>IPC `permissions:list` / `permissions:remove` / `permissions:remove-project` — five surfaces, see the IPC bridge row | native-permissions<br>harness-tools (the floors) | `docs/archive/specs/2026-08-11-native-permissions-management-ui.md`<br>`youcoded/docs/native-runtime.md` → "Permission precedence" (the floors) | `youcoded/desktop/tests/permission-store.test.ts`<br>`youcoded/desktop/tests/native-session-host.test.ts`<br>`youcoded/desktop/tests/permissions-section.test.tsx`<br>`youcoded/desktop/tests/describe-rule.test.ts`<br>`youcoded/desktop/tests/subject-glob.test.ts`<br>`youcoded/desktop/tests/bash-grant-shapes.test.ts`<br>`youcoded/desktop/tests/tool-card-grant-width.test.tsx`<br>`youcoded/desktop/tests/rm-target.test.ts` · `bash-secret-paths.test.ts` · `shell-words.test.ts` (a 76-command everyday sweep through both floors) · `deny-list-copy.test.ts`<br>`youcoded/desktop/tests/ipc-channels.test.ts` |
| Admin password card (sudo from chat: approval, the in-app password prompt, what the model is told) | `youcoded/desktop/src/main/harness/tools/admin-command.ts` (the admin floor: sudo asks in every mode, never remembered; `doas`/`su`/`pkexec`/`run0` refused)<br>`youcoded/desktop/src/main/harness/askpass/askpass-server.ts` (the socket; handshake verify → harden → ask → deliver)<br>`youcoded/desktop/src/main/harness/askpass/verify.ts` (who may receive a password: kernel peer pid, exact helper exe/argv/env, genuine setuid sudo parent, registered call)<br>`youcoded/desktop/scripts/askpass/` (the helper: `env -i`, non-dumpable before it holds anything)<br>`youcoded/desktop/src/main/harness/admin-password-service.ts` (asks ↔ broker; up-front password; refusals)<br>`youcoded/desktop/src/main/harness/admin-capability.ts` + `admin-password-startup.ts` (one settled answer per machine, awaited before any session starts; drives the Bash description's sudo sentence)<br>`youcoded/desktop/src/renderer/components/permissions/AdminPasswordPrompt.tsx` · `AdminRunStrip.tsx` · `AdminRefusedNote.tsx`<br>IPC `native:submit-admin-password` — five surfaces | native-permissions | `docs/archive/specs/2026-09-26-admin-password-technical-design.md`<br>`docs/archive/design/2026-09-25-admin-password/` (decks + contract) | `youcoded/desktop/tests/admin-command.test.ts` · `askpass-verify.test.ts` · `askpass-server.test.ts` · `askpass-helper.test.ts` · `proc-info.test.ts`<br>`youcoded/desktop/tests/admin-password-service.test.ts` · `admin-password-wiring.test.ts` · `admin-capability.test.ts` · `bash-env.test.ts` · `chat-reducer-admin-password.test.ts`<br>`youcoded/desktop/tests/e2e/admin-password-docker.test.ts` (real sudo in a throwaway container; `YOUCODED_DOCKER_E2E=1`, never run yet) |
| Full Auto safety stops (outside edits, risky commands, specialists) | `youcoded/desktop/src/main/harness/permission-broker.ts` (only root Full Auto Write/Edit can grant session-wide outside edits)<br>`youcoded/desktop/src/main/harness/harness-session.ts` (memory-only grant, resets on resume; file credential guard and Bash safety floors still run)<br>`youcoded/desktop/src/main/harness/specialists/child-ask-router.ts` (specialist mode and directory boundary)<br>`youcoded/desktop/src/renderer/components/permissions/FullAutoStops.tsx` (the two-step confirmation)<br>`youcoded/desktop/src/renderer/components/ToolCard.tsx` (permission-card wiring) | native-permissions · native-specialists · react-renderer | `docs/archive/design/2026-09-22-outside-edit-consent/` (approved copy and final green confirmation) | `youcoded/desktop/tests/native-permission-broker.test.ts`<br>`youcoded/desktop/tests/harness-session-loop.test.ts`<br>`youcoded/desktop/tests/specialist-child-ask-router.test.ts`<br>`youcoded/desktop/tests/tool-card-full-auto-stop.test.tsx` |
| Harness evaluator | `youcoded/desktop/src/main/harness/eval/run-case.ts`<br>`youcoded/desktop/src/main/harness/eval/matrix.ts`<br>`youcoded/desktop/src/main/harness/eval/assertions.ts`<br>`youcoded/desktop/src/main/harness/eval/judge.ts`<br>`youcoded/desktop/src/main/harness/eval/paths.ts`<br>`youcoded/desktop/src/main/harness/eval/cases/index.ts`<br>`youcoded/desktop/test-engine/harness-eval.mjs`<br>`youcoded/desktop/test-engine/harness-eval-worker.mjs` | harness-evaluator | `youcoded/docs/harness-evaluator-internals.md` | `youcoded/desktop/tests/harness-eval-comparison-noise.test.ts`<br>`youcoded/desktop/tests/harness-eval-key-leak.test.ts`<br>`youcoded/desktop/tests/harness-eval-assertions.test.ts`<br>`youcoded/desktop/tests/harness-eval-judge.test.ts`<br>`youcoded/desktop/tests/harness-eval-matrix.test.ts`<br>`youcoded/desktop/tests/harness-eval-report.test.ts`<br>`youcoded/desktop/tests/harness-eval-orchestrator.test.ts`<br>`youcoded/desktop/tests/harness-eval-cases.test.ts`<br>`youcoded/desktop/tests/harness-eval-estimate.test.ts`<br>`youcoded/desktop/tests/harness-review-fixture.test.ts`<br>`youcoded/desktop/tests/harness-review-runner.test.ts` |
| Claude Code's own sign-in, read LIVE | `youcoded/desktop/src/main/providers/claude-account.ts` (the probe: `claude auth status`, 60s cache, one in-flight call shared by every reader)<br>`youcoded/desktop/src/shared/claude-account-types.ts` (**the FOUR states and why `unknown` never greys a model — read this before changing any of them**)<br>`youcoded/desktop/src/renderer/components/model/availability.ts` (the model menu's reader)<br>`youcoded/desktop/src/renderer/components/ModelProvidersPopup.tsx` (the Claude Code card)<br>`youcoded/app/src/main/kotlin/com/youcoded/app/runtime/DevTools.kt` (`claudeAuthStatusJson` — the Kotlin mirror of the same decision table) | none — candidate | none — the type file carries it | `youcoded/desktop/tests/claude-account.test.ts`<br>`youcoded/desktop/tests/model-availability.test.ts` (the greyed-row regression itself)<br>`youcoded/desktop/tests/ipc-channels.test.ts` (five-surface parity; also pins that no sign-in reader points at `firstRun` again)<br>`youcoded/app/src/test/kotlin/com/youcoded/app/runtime/ClaudeAuthStatusTest.kt` |
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
{
"deck": "admin-password-confirm",
"started": "2026-09-26T08:19:00.609Z",
"submitted": "2026-09-26T08:19:32Z",
"cur": 0,
"answers": {
"S-scope-order": {
"v": "yes",
"seconds": 10,
"theme": "meadow-mist"
},
"S-remote-risk": {
"v": "yes",
"seconds": 10,
"theme": "meadow-mist"
},
"S-upfront": {
"v": "yes",
"seconds": 10,
"theme": "meadow-mist"
}
}
}
Loading
Loading