Skip to content

feat(queen): the ALL board -- CRM, mail, code and the agent's browser by whose move it is - #1199

Open
gHashTag wants to merge 1 commit into
mainfrom
feat/kanban-ball-lane
Open

gHashTag wants to merge 1 commit into
mainfrom
feat/kanban-ball-lane

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 1, 2026

Copy link
Copy Markdown
Owner

What

A third board on /game/kanban -- ALL -- beside TASKS and CLIENTS. It shows every open thing the signed-in person is part of: their CRM matters, mail threads, GitHub work and their own AI-browser session, grouped by whose move it is (OUR MOVE / DUE / THEIR MOVE / NOBODY'S).

  • Spec of record: t27 specs/automation/ball-board.t27 (feat(automation): ball-board v2 -- refuse shared-domain links, title links, card specs t27#5375). Host: render ball_board (gHashTag/999-multibots-telegraf, branch feat/ball-board-v2).
  • Every card names its .t27 spec and opens it in the specs view; unspecced cards are labelled and counted, never given one.
  • The browser card plus a head chip "open the AI browser" go to the app's own /game/browser, so the person can watch the agent and step in at any time.

Privacy and safety

New gate check:ball-board (66 checks, wired into website-checks.yml) feeds the reader a hostile answer:

Property Held by
No credential in the module; one tool, no arguments BALL_BOARD_TOOL: PlayerTool, loadBallBoard
Links only https to github.com / t27.ai, or exactly /game/browser safeLink -- dropped, never rewritten
A browser card carries no stream URL, view token or endpoint readCard keeps 8 named fields only
Spec paths cannot climb out of specs/ specPath
Nothing fetched directly, stored in the browser, or logged source scan
Private lane never default, drawn only behind the clients guard hive-board / clients-filter contracts, now component-aware

Known limit, stated not hidden

The render's GAME_TOKEN_TOOLS refuses hive_board/ball_board to a bare game token, so on t27.ai both private lanes answer "refused" and draw nothing. They work on app.t27.ai, where the token is the app session's. Fail-closed and intended; the PLAYER_TOOLS doc comment now says so.

Checks run locally

  • check:hive-board 65, check:clients-filter 56, check:ball-board 66, check:queen-direction 92 -- all PASS.
  • tsc -b: no errors in changed files (179 pre-existing errors elsewhere, unchanged).
  • queen-viewport skipped locally (no Chrome on this machine); CI runs it.

Do not merge before the render side (ball_board v3) is deployed, or the lane answers "refused".

🤖 Generated with Claude Code

… by whose move it is

A third board on /game/kanban beside TASKS and CLIENTS: every open thing the
signed-in person is part of, grouped into OUR MOVE / DUE / THEIR MOVE /
NOBODY'S, read from the render's ball_board tool (spec of record: t27
specs/automation/ball-board.t27, gHashTag/t27#5375).

- Every card names the .t27 spec it stands on and opens it in the specs view;
  a card with none says so ("no .t27 spec") and the head counts them.
- The caller's own AI-browser session is a card. "Open the AI browser" goes to
  the app's own /game/browser view, so the person can watch the agent and step
  in at any moment.

Privacy and safety, held by a new gate (check:ball-board, 66 checks):
- lib/ballBoard.ts holds no credential; it names a PlayerTool and triIdentity
  makes the call with no arguments, so identity is the token's, not the page's.
- A link is drawn only as https to github.com / t27.ai or exactly
  /game/browser. Anything else is dropped, not rewritten.
- A browser card cannot carry a stream URL, a view token or an endpoint,
  whatever the host sends; a spec path cannot climb out of specs/.
- Nothing is fetched directly, stored in the browser or logged.
- The board is private: never the default, drawn only behind the clients
  guard (hive-board and clients-filter contracts made component-aware).

triIdentity's PLAYER_TOOLS comment now says the plain truth: being on the list
is necessary, not sufficient -- the render's GAME_TOKEN_TOOLS refuses both
private boards to a bare game token, so they answer on app.t27.ai only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added the status:in-progress 🔵 Agent working label Oct 1, 2026
@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Reviewer bee Y: not merged. (1) CONFLICTING with main. (2) Required status 'T27 work report' = FAILURE. (3) It edits .github/workflows/website-checks.yml, so it needs the owner's workflow scope anyway. (4) It is a second, diverging implementation of the same ball board as #1202: both rewrite apps/website/src/lib/ballBoard.ts, qa/ball-board-contract.mjs, Queen.tsx/Queen.css, triIdentity.ts (diff between the two heads: 10 files, +726/-541), and neither contains the other. Only one can land; the owner/author should pick one and close the other before anyone reviews further.

@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

bee review: left open -- CONFLICTING with main (head 0781b36). Conflicts in Queen.tsx, Queen.css, queen-viewport-contract.mjs and website-checks.yml, all moved on main (#1236, #1239, #1221). No credentials. Note the overlap with #1202 (mail lane, same ball-board idea): the author should decide which one survives before rebasing.

@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Bee review: #1199, not merged (head 0781b36d9c16538b65c8f8d33b30a7c4d0e5a638)

This PR was already CONFLICTING/DIRTY against main. #1202 has now merged (92e1d48d) with the narrower mail lane: it adds the same apps/website/src/lib/ballBoard.ts and qa/ball-board-contract.mjs, the same check:ball-board script and workflow step, and edits the same Queen.tsx, Queen.css, triIdentity.ts, hive-board and clients-filter contracts. Every one of those is now an add/add or content conflict.

If the ALL board (CRM, code and browser cards, spec links) is still wanted, it needs a rebase on top of #1202's ballBoard.ts, extending it rather than replacing it. Its own description also says not to merge before render ball_board v3 is deployed, and that has not been confirmed here. If the ALL board is not wanted, close this PR as superseded by #1202.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status:in-progress 🔵 Agent working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant