Repository navigation
feat(website): the mail lane on /game/kanban -- the owner's, or granted - #1202
Conversation
Owner, 2026-10-01: every task from the mail visible to him when signed in, and to others only if he allowed it. - lib/ballBoard.ts reads the ball_board tool through the player's identity (one Authorization header, credentials omitted, no arguments). Links pass safeLink (https only); no counts from the server survive the reader. - The MAIL lane is drawn only when the server sent the mail source. A not_yours, unknown or missing status draws nothing -- no lane, no chip, no hint that a lane exists. Signed out sends no request. - Columns by whose move it is (ours / due / theirs / none); cards carry the client, the source, the title, why, and days waiting. - qa/ball-board-contract.mjs (59 checks) gates the wire, the refusals and the page structure; hive-board and clients-filter contracts learn the second private lane. Wired into website-checks. Server side: gHashTag/999-multibots-telegraf#3204, spec gHashTag/t27#5411. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Reviewer bee Y: not merged. (1) Required status 'T27 work report' = FAILURE. (2) Edits .github/workflows/website-checks.yml -> needs the owner's |
|
bee review: not merged. Head 0468de8, MERGEABLE but BLOCKED: the required status |
|
Bee review evidence: #1202 (head Contracts. I applied the diff on current main (
Privacy and safety, read from the code.
Server side is merged. 999-multibots-telegraf#3204 merged 2026-10-02, and t27#5411 (ball-grants) is merged. Checks. Overlap with #1199. #1199 adds the same |
feat(website): the mail lane on /game/kanban -- the owner's, or granted (#1202) Owner, 2026-10-01: every task from the mail visible to him when signed in, and to others only if he allowed it. - lib/ballBoard.ts reads the ball_board tool through the player's identity (one Authorization header, credentials omitted, no arguments). Links pass safeLink (https only); no counts from the server survive the reader. - The MAIL lane is drawn only when the server sent the mail source. A not_yours, unknown or missing status draws nothing -- no lane, no chip, no hint that a lane exists. Signed out sends no request. - Columns by whose move it is (ours / due / theirs / none); cards carry the client, the source, the title, why, and days waiting. - qa/ball-board-contract.mjs (59 checks) gates the wire, the refusals and the page structure; hive-board and clients-filter contracts learn the second private lane. Wired into website-checks. Server side: gHashTag/999-multibots-telegraf#3204, spec gHashTag/t27#5411. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Owner, 2026-10-01: every task from the mail visible to him when signed in,
and to others only if he allowed it.
(one Authorization header, credentials omitted, no arguments). Links pass
safeLink (https only); no counts from the server survive the reader.
not_yours, unknown or missing status draws nothing -- no lane, no chip,
no hint that a lane exists. Signed out sends no request.
client, the source, the title, why, and days waiting.
the page structure; hive-board and clients-filter contracts learn the
second private lane. Wired into website-checks.
Server side: gHashTag/999-multibots-telegraf#3204, spec gHashTag/t27#5411.
Checks
Release: after merge, a release(board) PR in 999 pins QUEEN_REF.
🤖 Generated with Claude Code
{ "version": 1, "head_sha": "0468de86360d3d23fb6fdef0c0b7c21f21e21efd", "summary": "The /game/kanban board gains a MAIL lane read from the ball_board tool through the signed-in player's identity, drawn only when the server returned the mail source, with columns by whose move it is.", "changes": [ "New apps/website/src/lib/ballBoard.ts reads the ball_board tool with one Authorization header and credentials omitted, passes links through safeLink (https only), and sends no request when signed out.", "Queen.tsx draws the MAIL lane only when the server sent the mail source; not_yours, unknown or missing status draws no lane, chip or hint. Cards carry client, source, title, reason and days waiting, in columns ours, due, theirs and none.", "New qa/ball-board-contract.mjs gates the wire, the refusals and the page structure; hive-board and clients-filter contracts learn the second private lane; check:ball-board is wired into website-checks.yml.", "triIdentity.ts and Queen.css receive small supporting edits." ], "tests": [ { "command": "npm run check:ball-board, check:hive-board, check:clients-filter", "result": "Author reports 59, 63 and 56 checks passing respectively.", "status": "passed", "evidence": "Author-reported in the Checks section of this PR body; not rerun for this report." }, { "command": "typecheck ratchet in apps/website", "result": "Author reports 179 errors across 26 files, equal to the baseline, with no file gaining errors.", "status": "passed", "evidence": "Author-reported in the Checks section of this PR body." }, { "command": "Website checks workflow, job checks, on head 0468de86", "result": "The job completed successfully on the PR head commit, which wires in check:ball-board.", "status": "passed", "evidence": "https://github.com/gHashTag/trinity/actions/runs/36856722398" } ], "limitations": [ "The server side lives in gHashTag/999-multibots-telegraf#3204 with spec gHashTag/t27#5411; the lane shows nothing until that server returns the mail source.", "The board reaches users only after a release(board) PR in 999-multibots-telegraf pins QUEEN_REF to the merge." ], "tags": [ "website", "kanban", "privacy" ], "blog": { "title": "The mail lane on the kanban board is private by default", "summary": "Tasks from the owner's mail appear on /game/kanban only for him or for people he allowed; for anyone else the page shows no lane and no hint that one exists.", "outline": [ "The owner asked that every task from his mail be visible to him when signed in, and to other people only when he has granted them access.", "The site reads the ball_board tool with the player's own identity and draws the MAIL lane only when the server returns the mail source, grouping cards by whose move it is.", "A contract with fifty-nine checks gates the request, the refusals and the page structure, and the lane depends on a separate server change and a later board release." ] } }