Skip to content

feat(website): the mail lane on /game/kanban -- the owner's, or granted - #1202

Merged
gHashTag merged 1 commit into
mainfrom
feat/ball-board-mail-lane
Oct 2, 2026
Merged

gHashTag merged 1 commit into
mainfrom
feat/ball-board-mail-lane

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Owner, 2026-10-01: every task from the mail visible to him when signed in,
and to others only if he allowed it.

  • lib/ballBoard.ts reads the ball_board tool through the player's identity
    (one Authorization header, credentials omitted, no arguments). Links pass
    safeLink (https only); no counts from the server survive the reader.
  • The MAIL lane is drawn only when the server sent the mail source. A
    not_yours, unknown or missing status draws nothing -- no lane, no chip,
    no hint that a lane exists. Signed out sends no request.
  • Columns by whose move it is (ours / due / theirs / none); cards carry the
    client, the source, the title, why, and days waiting.
  • qa/ball-board-contract.mjs (59 checks) gates the wire, the refusals and
    the page structure; hive-board and clients-filter contracts learn the
    second private lane. Wired into website-checks.

Server side: gHashTag/999-multibots-telegraf#3204, spec gHashTag/t27#5411.

Checks

  • check:ball-board PASS (59), hive-board PASS (63), clients-filter PASS (56)
  • queen language contract PASS (390 en / 390 ru keys)
  • typecheck ratchet: 179 errors across 26 files, baseline 179 across 26 -- no file gained errors

Release: after merge, a release(board) PR in 999 pins QUEEN_REF.

🤖 Generated with Claude Code

{
  "version": 1,
  "head_sha": "0468de86360d3d23fb6fdef0c0b7c21f21e21efd",
  "summary": "The /game/kanban board gains a MAIL lane read from the ball_board tool through the signed-in player's identity, drawn only when the server returned the mail source, with columns by whose move it is.",
  "changes": [
    "New apps/website/src/lib/ballBoard.ts reads the ball_board tool with one Authorization header and credentials omitted, passes links through safeLink (https only), and sends no request when signed out.",
    "Queen.tsx draws the MAIL lane only when the server sent the mail source; not_yours, unknown or missing status draws no lane, chip or hint. Cards carry client, source, title, reason and days waiting, in columns ours, due, theirs and none.",
    "New qa/ball-board-contract.mjs gates the wire, the refusals and the page structure; hive-board and clients-filter contracts learn the second private lane; check:ball-board is wired into website-checks.yml.",
    "triIdentity.ts and Queen.css receive small supporting edits."
  ],
  "tests": [
    {
      "command": "npm run check:ball-board, check:hive-board, check:clients-filter",
      "result": "Author reports 59, 63 and 56 checks passing respectively.",
      "status": "passed",
      "evidence": "Author-reported in the Checks section of this PR body; not rerun for this report."
    },
    {
      "command": "typecheck ratchet in apps/website",
      "result": "Author reports 179 errors across 26 files, equal to the baseline, with no file gaining errors.",
      "status": "passed",
      "evidence": "Author-reported in the Checks section of this PR body."
    },
    {
      "command": "Website checks workflow, job checks, on head 0468de86",
      "result": "The job completed successfully on the PR head commit, which wires in check:ball-board.",
      "status": "passed",
      "evidence": "https://github.com/gHashTag/trinity/actions/runs/36856722398"
    }
  ],
  "limitations": [
    "The server side lives in gHashTag/999-multibots-telegraf#3204 with spec gHashTag/t27#5411; the lane shows nothing until that server returns the mail source.",
    "The board reaches users only after a release(board) PR in 999-multibots-telegraf pins QUEEN_REF to the merge."
  ],
  "tags": [
    "website",
    "kanban",
    "privacy"
  ],
  "blog": {
    "title": "The mail lane on the kanban board is private by default",
    "summary": "Tasks from the owner's mail appear on /game/kanban only for him or for people he allowed; for anyone else the page shows no lane and no hint that one exists.",
    "outline": [
      "The owner asked that every task from his mail be visible to him when signed in, and to other people only when he has granted them access.",
      "The site reads the ball_board tool with the player's own identity and draws the MAIL lane only when the server returns the mail source, grouping cards by whose move it is.",
      "A contract with fifty-nine checks gates the request, the refusals and the page structure, and the lane depends on a separate server change and a later board release."
    ]
  }
}

Owner, 2026-10-01: every task from the mail visible to him when signed in,
and to others only if he allowed it.

- lib/ballBoard.ts reads the ball_board tool through the player's identity
  (one Authorization header, credentials omitted, no arguments). Links pass
  safeLink (https only); no counts from the server survive the reader.
- The MAIL lane is drawn only when the server sent the mail source. A
  not_yours, unknown or missing status draws nothing -- no lane, no chip,
  no hint that a lane exists. Signed out sends no request.
- Columns by whose move it is (ours / due / theirs / none); cards carry the
  client, the source, the title, why, and days waiting.
- qa/ball-board-contract.mjs (59 checks) gates the wire, the refusals and
  the page structure; hive-board and clients-filter contracts learn the
  second private lane. Wired into website-checks.

Server side: gHashTag/999-multibots-telegraf#3204, spec gHashTag/t27#5411.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Reviewer bee Y: not merged. (1) Required status 'T27 work report' = FAILURE. (2) Edits .github/workflows/website-checks.yml -> needs the owner's workflow scope. (3) Overlaps #1199 (same ballBoard.ts / ball-board contract / Queen.tsx, diverging implementations, neither an ancestor of the other) -- pick one. This one is the mergeable of the two (#1199 conflicts).

@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

bee review: not merged. Head 0468de8, MERGEABLE but BLOCKED: the required status T27 work report fails -- PR body must contain exactly one <!-- t27-work-report --> … <!-- /t27-work-report --> block (run 36856722512). No credentials in the diff. Add the work report (with head_sha = current head) and this can be reviewed for merge. Red on main for every PR (not counted against this one): ⚡ Brain Health Check, 📋 Brain Health Report.

@gHashTag gHashTag added the bee-reviewed A reviewer bee reviewed and verified this PR after its head commit; required to merge label Oct 2, 2026
@gHashTag

gHashTag commented Oct 2, 2026

Copy link
Copy Markdown
Owner Author

Bee review evidence: #1202 (head 0468de86360d3d23fb6fdef0c0b7c21f21e21efd)

Contracts. I applied the diff on current main (3926f22b, after #1200) and ran each contract under Node 22 --experimental-strip-types with typescript 5.9.3:

  • check:ball-board: PASS (59 checks, no arguments, 0 counts, no lane without the mail).
  • check:hive-board: PASS (63).
  • check:clients-filter: PASS (56, with 98 hostile combinations).

Privacy and safety, read from the code.

  • ballBoard.ts holds no credential and sends no arguments. Scope belongs to the server.
  • Server-sent counts and age_h are never read.
  • Strings are length-capped and rendered as text nodes.
  • safeLink accepts only https://github.com with no userinfo. Anything else becomes null.
  • The lane is null (nothing is drawn) on not_yours, unknown, refused or signed out, and signed out sends no request.
  • PLAYER_TOOLS gains ball_board, but that is only the client's allow-list. The server still refuses it to the game token and gates it on the owner's grants.
  • The workflow change only adds one npm run check:ball-board step to website-checks.yml.

Server side is merged. 999-multibots-telegraf#3204 merged 2026-10-02, and t27#5411 (ball-grants) is merged.

Checks. checks (website), Build & Test, Build Check, GitGuardian, claude-review and T27 work report are all green. The only red checks are pr-opened (Bad credentials 401) and Brain Health, both red on main.

Overlap with #1199. #1199 adds the same ballBoard.ts and ball-board-contract.mjs and edits the same Queen/qa files. It was already CONFLICTING/DIRTY before this merge. #1202 is the narrower and later lane whose server half has shipped, so #1199 has to be rebased onto it or closed. I've noted this on #1199.

@t27-bees t27-bees Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bee review: see evidence comment

@gHashTag
gHashTag merged commit 92e1d48 into main Oct 2, 2026
34 of 40 checks passed
@github-actions github-actions Bot added status:completed Done and removed status:in-progress 🔵 Agent working labels Oct 2, 2026
github-actions Bot added a commit that referenced this pull request Oct 2, 2026
feat(website): the mail lane on /game/kanban -- the owner's, or granted (#1202)

Owner, 2026-10-01: every task from the mail visible to him when signed in,
and to others only if he allowed it.

- lib/ballBoard.ts reads the ball_board tool through the player's identity
  (one Authorization header, credentials omitted, no arguments). Links pass
  safeLink (https only); no counts from the server survive the reader.
- The MAIL lane is drawn only when the server sent the mail source. A
  not_yours, unknown or missing status draws nothing -- no lane, no chip,
  no hint that a lane exists. Signed out sends no request.
- Columns by whose move it is (ours / due / theirs / none); cards carry the
  client, the source, the title, why, and days waiting.
- qa/ball-board-contract.mjs (59 checks) gates the wire, the refusals and
  the page structure; hive-board and clients-filter contracts learn the
  second private lane. Wired into website-checks.

Server side: gHashTag/999-multibots-telegraf#3204, spec gHashTag/t27#5411.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bee-reviewed A reviewer bee reviewed and verified this PR after its head commit; required to merge status:completed Done

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant