Skip to content

Latest commit

 

History

History
149 lines (141 loc) · 28.7 KB

File metadata and controls

149 lines (141 loc) · 28.7 KB

Orchestration Progress

Last updated: 2026-07-24

Method

Each lifecycle slice follows: gather context → take one typed action → verify provider truth/invariants → persist → repeat. Fireworks drafts and classifies; deterministic code alone confirms payment, proof, deployment, and delivery.

Checkpoints

Checkpoint Status Verification
Repository/spec audit Complete Existing proof boundary, Stripe conflict, preview safety, and missing orchestration interfaces mapped.
Sourced contract compiler Complete Exact transcript/research citations accepted; unsupported facts fail closed (2 tests).
PII minimization Complete Email/phone + Fireworks spans removed while source offsets remain stable (2 tests).
Fireworks orchestration reasoner Complete Typed intake/proposal/change tool outputs fail closed when missing or malformed (2 tests + typecheck).
Proven-winner policy Complete Current project/contract only; pinned Braintrust policy + deterministic tuple fail closed (69 focused tests).
Customer email sequence Complete Proposal/payment, receipt, proven preview/steering, and final delivery copy (2 tests + typecheck).
Voice/email ownership boundary Backend complete Voice intake cannot assert email ownership; the normalized boundary accepts dictated contact capture without a verification claim, while durable pre-proposal mail sends a scanner-safe 15-minute project/email-bound verification link. Spoken interaction behavior remains the voice layer's responsibility.
Passwordless dashboard access Backend complete Fragment token, inert GET exchange page, POST-only verification, atomic one-time digest consumption with ownership event, generic replay failure, and seven-day signed project session are implemented.
Bounded access-link reissue Backend complete Generic POST .../access/requests accepts only a signed active or at-most-30-days-expired fragment capability, rechecks protected project/email identity, mails only the stored address, applies a durable one-minute per-project send floor, and rotates unsent 15-minute capability generations.
Customer dashboard REST + steering Backend complete Project/email-bound project and bounded event reads plus session-derived double-submit CSRF, stable idempotency key, expected revision/proposal coordinates, and shared-orchestrator steering are implemented under /v1/orchestration/customer-dashboard/....
Sanitized build observation Backend complete Internal per-run observation exposes allowlisted status/stage/slot/tool/proof/timeline fields; raw Daytona surfaces and logs never cross it, and the schema remains explicitly customerRenderable: false.
Customer dashboard UI + live visual UI complete; producer open Next.js/CopilotKit workspace, opaque aliases, and resumable Last-Event-ID SSE ship in apps/dashboard; the raster gateway has a consumer but no producer. Typed-email requests, server-side revocation/renewal, and edge rate limits stay open. See the audit below.
Provider-backed dashboard E2E Pending Real Resend link delivery/consumption, browser session, live project read, steering revision, build observation, proven preview, and production handoff have not yet been verified together with configured providers.
Secure email-thread routing Complete Opaque HMAC-protected project reply addresses reject tampering/wrong domains (2 tests).
Sourced proposal versions Complete Fireworks plans bind to exact intake/research evidence, quote, contract, strategies, and immutable digests (2 tests).
Build handoff compiler Complete Distinct 1–4 assignments share one exact contract and exclude protected contact PII (1 integration test + typecheck).
Encrypted durable project state Complete AES-256-GCM aggregate, immutable redacted events, optimistic revisions, effects, and webhook replay protection (6 tests).
Stripe, Resend, safe research adapters Complete Signed webhooks, exact Checkout verification, idempotent mail, and consent/SSRF-guarded research (20 tests).
Lifecycle engine: intake → paid build Complete Revised proposal expires old Checkout; exact paid vN sends confirmation and fans out PII-minimized builds (integration test + typecheck).
Frozen proven-preview boundary Complete Snapshot-restored private clone, signed-URL readiness/marker probe, identity/TTL checks, cleanup, and idempotent ACK (36 focused tests + lint).
Proof → preview → deploy engine Complete Current-contract proof ingestion, deterministic winner, durable preview email, review window, exact artifact deploy, health-gated final email (18 focused lifecycle/state/HTTP tests).
Paid steering + clarification Complete No-op/in-scope/re-quote branches, paid commercial ancestry, cumulative hard requirements, clarification email/reply, and fresh proof fan-out (focused integration tests).
Crash recovery + races Complete Intake-before-model, clarification-mail replay, paid-revision replay, partial fan-out, proven-event ACK loss, and payment/edit arbitration pass focused lifecycle tests (13/13).
HTTP/webhook runtime Complete Raw-body Stripe/Resend verification, secure reply routing, authenticated intake/reconcile, strict schemas, and minimized responses (9 tests).
Email thread + delivery truth Complete Raw-message aligned DKIM, deterministic RFC threading, exact delivery receipts, bounce attention, and stale-version fencing (focused provider/HTTP/lifecycle tests).
Fly first-app provisioning Complete Exact app/org lookup, idempotent create/race recovery, pre-provisioned app-token path, and fail-closed release fencing (31 focused deploy/runtime tests).
Evidence + approval integrity Complete Per-item extractive citations, quote rejection checks, deterministic build prompt, and asset clarification pass 18 focused tests.
Payment reconciliation Complete Lost webhook, exact Checkout/PI polling, edit race, replay, expiration, and replacement-link paths pass 59 focused tests.
Ordered edits + paid-work delivery Complete Concurrent cumulative replies cannot bypass re-quote; any pending authenticated vN+1 edit fences customer-visible vN delivery (focused tests).
Preview freshness Complete Stored links refresh before mail unless they cover the full review window plus safety margin.
Earlier adversarial audit Superseded A later reliability re-audit found additional deadline, effect-attribution, and provider-hang gaps; those are tracked below instead of hidden.
Compiler + lint checkpoint Complete Strict TypeScript and zero-warning ESLint pass on the combined tree.
Current-proof event isolation Complete Outbox polling filters to exact active run UUIDs; 45 focused backend/HTTP/adapter tests pass.
Orchestration decision tracing Complete Fireworks intake, proposal, and edit decisions fail closed through redacted Braintrust traces.
Real-provider composition Complete Production uses concrete provider adapters only; live Stripe and real domains are mandatory.
Provider readiness Code complete; live pending Read-only probes cover all providers, webhook registrations, backend identity, and snapshot; credential smoke awaits API keys.
Production startup Complete One supervisor starts/stops both backends; individual service commands remain available.
Integrated repository suite Complete npm run check passes formatting, lint, strict typecheck, production build, coverage thresholds, 56 test files, and 676 tests.
Docs + GitHub handoff Documentation updated README, CLAUDE, product/dashboard/runtime, and progress documents describe all four services (build backend, orchestrator, dashboard, voice intake) and distinguish the implemented slices from the pending WIP frame producer, session operations, and provider-backed E2E.
Transactional provider inbox Complete Verified inbox receipt + aggregate CAS commit/rollback are atomic; duplicate/conflict and lifecycle integration pass.
Bounded effect recovery Complete Persisted exponential retry, capped attempts, safe errors, stable idempotency, and dead-letter/operator-attention paths pass focused tests.
Preview delivery gate Complete Lost Resend webhooks reconcile through authoritative provider status; deployment waits for actual preview delivery and starts its review clock there.
Reliability re-audit checkpoint Complete Node 24 strict typecheck plus 5 focused files / 84 tests pass after re-checking the original lifecycle requirements.
Terminal attention boundary Complete Authenticated customer mail is retained/inboxed but cannot bypass a dead-lettered or verification-failed project (4/4 retry tests).
Fly last-known-good rollout Complete Trusted blue/green strategy + service health check keep the prior healthy Machines serving until replacement readiness (30/30 deploy tests).
Stripe mutation response recovery Complete Authoritative already-expired Checkout evidence completes the same durable effect without a second mutation or duplicate replacement link (28 focused tests).
Exact retry attribution Complete Only the effect immediately bound to a failing provider call spends retry budget; unrelated pending work stays unchanged (5/5 retry tests, 24/24 lifecycle tests).
Build/proof liveness Complete Persisted build and proof-event deadlines cancel stalled peers, rank available proven work, or stop in no-proven; legacy batches backfill safely (28/28 lifecycle tests).
Hung-operation containment Complete Per-project worker deadlines keep later projects/cycles moving, and Braintrust trace flushes fail closed within a bound (13 runtime + 10 trace tests).
Required-mail liveness Complete Persisted delivery deadline stops unverifiable preview/final mail; API/webhook races terminalize one exact effect atomically (42 focused lifecycle/runtime tests).
Build mutation recovery Complete Per-run cancellation and per-proof ACK effects recover lost responses with stable backend idempotency and bounded dead-lettering (31 lifecycle tests).
Latest-version delivery fence Complete Authenticated edits/clarifications fence older paid work from preview, Fly deploy, and final email; only the latest settled contract can become customer-visible (31 lifecycle tests).
Provider-deadline accounting Complete Operation-specific artifact/preview/Fly ceilings fit inside a 32-minute worker bound; aborted attempts spend the exact effect retry (focused runtime/deploy tests).
Stripe verification recovery Complete Checkout/PaymentIntent reconciliation has a durable effect, explicit verification-failed state, and normalized authoritative settlement receipt (41 focused lifecycle/store tests).
Deadline evidence outage Complete Build/status outbox outages cannot bypass stored build/proof ceilings; trusted stored evidence retires or fails closed with an explicit receipt (34 lifecycle tests).
Project action linearization Complete One active orchestrator serializes inbound edits, reconciliation, payment, and mail receipts per project across customer-visible provider calls (52 lifecycle/HTTP tests).
Frozen-preview replay safety Complete POST idempotency, deterministic Daytona name/labels, provider recovery, serialized replay, TTL refresh, and exact proof identity pass 48 focused tests.
Research + paid-scope grounding Complete Owned-domain authority, provisional research confirmation, ISO quote evidence, hard proof coverage, and bounded paid change briefs pass 88 focused tests + lint.
One-time quote integrity Complete Recurring, staged-payment, tax, and fee qualifiers fail closed before one-time Stripe Checkout; focused policy and lifecycle tests pass.
Signed inbound-mail recovery Complete Minimal signed envelopes persist before enrichment; bounded retry, operator recovery, attachment/oversize rejection, and release fences pass 76 focused tests + lint.
Rejected-webhook security audit Complete Missing/invalid Stripe and Resend signatures produce immutable digest-only receipts, bounded overflow summaries, and a protected count-only view (34 focused tests + lint).
Operator evidence + proof summary Complete Internal evidence is paginated; final mail is bound to an encrypted immutable proof snapshot with crash recovery, revocation, bounded capability reads, uniform failures, and fail-closed PII/secret publication checks (91 focused tests + typecheck).

Original-request audit

  • Intake from transcript/email/text, name + PII: complete through the core lifecycle; voice-surface dictation UX remains outside this backend
  • Passwordless email ownership: backend complete with durable verification mail, fragment-only 15-minute capability, scanner-safe GET, atomic POST consumption/ownership event, and project/email-bound seven-day signed session.
  • Bounded link reissue: backend complete for signed active/recently-expired capability proof, 30-day grace, generic 202, protected identity recheck, stored-address-only delivery, durable one-minute per-project send floor, and unsent-capability generation rotation. Typed-email requests and edge-wide rate limiting remain open.
  • Post-payment dashboard access: backend complete with one durable send_dashboard_access effect after the exact requested build batch is fully dispatched.
  • Customer dashboard reads and steering: backend complete for project snapshot, bounded REST events, safe build-observation join, last-known-good preview/production retention, and CSRF/idempotency/version-bound steering.
  • Customer dashboard experience: complete for the Next.js/CopilotKit frontend (apps/dashboard/app/dashboard/projects/[projectAlias], app/api/copilotkit/*), opaque prj_/bld_/frm_ aliases sealed into a session-bound cookie (apps/dashboard/lib/server/aliases.ts), and resumable Last-Event-ID SSE that fans the orchestrator's bounded event window out as text/event-stream (apps/dashboard/lib/server/customer-stream.ts with apps/dashboard/components/use-customer-project.ts; 9 focused tests in apps/dashboard/tests/customer-sse.test.ts).
  • Customer-renderable raster WIP gateway: consumer only. The dashboard accepts, sanitizes to a blurred layout-only PNG, watermarks, and serves frames (apps/dashboard/lib/server/wip-raster.ts), but every ingest requires a sanitizationPolicyDigest plus an HMAC sanitization receipt, and nothing in src/ produces one — no builder or controller captures or attests a frame. The build backend's projection is still schema-pinned to customerRenderable: false, so no customer can receive a frame today. The producer side is the remaining work.
  • Remaining dashboard gaps: open for the typed-email public link request (no email-entry surface exists), server-side session revocation and renewal — logout clears the dashboard-origin cookies and projection state but returns globalRevocation: false, leaving the orchestrator-signed session valid until it expires — and edge-wide dashboard rate limits.
  • Caller-provided, consented own-business URL research with citations: complete for explicitly owned/authorized URLs; findings stay provisional until customer-confirmed; business-name discovery/assets remain open
  • Versioned summary + Stripe link + pre-payment email edits: complete
  • Verified payment + confirmation email: complete
  • End-to-end prompt + free-slot build dispatch: complete
  • Proven preview + email steering loop: complete
  • Proof-gated Fly.io deploy + final email: complete in the lifecycle engine
  • Concrete Fireworks/Braintrust/Stripe/Resend/Daytona/CodeRabbit/Fly wiring: complete; configured-provider smoke and dashboard end-to-end verification remain pending
  • Durable tracking, fixed-interval recovery, idempotency, and failure states: complete for the implemented lifecycle, including retry/dead-letter, build/proof/mail deadlines, exact effect attribution, healthy provider poll cadence, all required-mail reconciliation, and signed inbound recovery
  • Protected operator evidence and customer-readable, exact-deployment proof summary: complete
  • Invalid provider signatures fail closed with bounded, minimized durable security-audit receipts and a protected summary; repository-wide retention policy remains open.
  • Field-approved customer contact content for generated sites: open; all customer contact PII currently stays out of builders
  • Patch Model dataset/RFT/evaluation/promotion pipeline: open; the current runtime uses the configured base Fireworks model

Safety decision: raw work-in-progress Daytona builds remain operator-only. An authenticated customer may receive only the implemented, allowlisted structured observation, currently with customerRenderable: false. The dashboard can already serve watermarked, layout-only raster frames, but only for frames posted through its attested internal ingest; until a builder-side producer exists, no frame is ever available and the customer surface stays non-renderable. Customer review links remain frozen proven revisions; every requested edit creates a new contract revision and must pass the complete proof gate again.