Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
309 commits
Select commit Hold shift + click to select a range
cc9c8a0
test: require service URL in review draft
seonghobae Sep 2, 2026
815bec3
fix: project service URL into review draft
seonghobae Sep 2, 2026
4ceaf82
docs: record service URL review projection
seonghobae Sep 2, 2026
01d661a
docs: reconcile service URL projection repair
seonghobae Sep 2, 2026
f21c65a
test: prevent dead pre-release affordances
seonghobae Sep 2, 2026
f00a6ad
fix: make unshipped affordances non-deceptive
seonghobae Sep 2, 2026
8c9eaa3
docs: record non-deceptive pre-release affordances
seonghobae Sep 2, 2026
ae947ac
docs: reconcile pre-release affordance repair
seonghobae Sep 2, 2026
8233fe0
test: prevent inert document selector affordance
seonghobae Sep 2, 2026
c385196
fix: render document title as non-interactive status
seonghobae Sep 2, 2026
2d4f1de
docs: record document title affordance repair
seonghobae Sep 2, 2026
8ddb45d
docs: reconcile document-title affordance repair
seonghobae Sep 2, 2026
37c5c49
test: reject inferred customer policy facts
seonghobae Sep 2, 2026
b12052b
fix: require operator-confirmed policy facts
seonghobae Sep 2, 2026
8e24284
docs: align fact-authority commercialization contract
seonghobae Sep 2, 2026
1e77d44
test: require all seven authoring facts
seonghobae Sep 2, 2026
cbe3a74
fix: require complete seven-step authoring facts
seonghobae Sep 2, 2026
36b1623
docs: align seven-step readiness contract
seonghobae Sep 2, 2026
61220e8
test: reject malformed policy contact facts
seonghobae Sep 2, 2026
bcabe96
fix: validate policy contact fact syntax
seonghobae Sep 2, 2026
0b2c8a5
test: require collection path evidence
seonghobae Sep 2, 2026
7b843ef
feat: require collection path evidence for readiness
seonghobae Sep 2, 2026
aa3be87
docs: reconcile collection path readiness contract
seonghobae Sep 2, 2026
97063fc
test: specify explicit no-collection attestation
seonghobae Sep 2, 2026
e73eb83
feat: support explicit no-collection attestation
seonghobae Sep 2, 2026
6a071de
docs: model explicit no-collection authority
seonghobae Sep 2, 2026
e5b77f1
test(a11y): require high-contrast keyboard focus indicators
seonghobae Sep 2, 2026
e9e7dcc
fix(a11y): increase authored keyboard focus contrast
seonghobae Sep 2, 2026
ee73bc2
test(a11y): verify focus token contrast ratio
seonghobae Sep 2, 2026
d050b1e
docs(a11y): trace WCAG focus contrast evidence
seonghobae Sep 2, 2026
27364e3
docs(changelog): record focus contrast repair
seonghobae Sep 2, 2026
aa194db
docs(gap): record focus contrast repair and remaining browser evidence
seonghobae Sep 2, 2026
e9ff9cd
test: specify authoring focus transfer
seonghobae Sep 2, 2026
960432e
feat: preserve focus across authoring steps
seonghobae Sep 2, 2026
2ec1e10
feat: activate authoring focus transfer
seonghobae Sep 2, 2026
cc87e9c
docs: record authoring focus transition
seonghobae Sep 2, 2026
67b7f66
docs: specify logical focus order contract
seonghobae Sep 2, 2026
7e37ead
docs: trace focus order evidence
seonghobae Sep 2, 2026
260de02
docs: reconcile focus accessibility gap
seonghobae Sep 2, 2026
ed9f907
docs: align focus interaction architecture
seonghobae Sep 2, 2026
91ba897
test: start fresh workspace at first responsibility
seonghobae Sep 2, 2026
a892bbd
fix: start fresh workspace at service information
seonghobae Sep 2, 2026
4657b3e
docs: require first unresolved step on startup
seonghobae Sep 2, 2026
26c55ee
docs: align fresh-workspace start contract
seonghobae Sep 2, 2026
e98cfd0
docs: record truthful fresh-workspace progress
seonghobae Sep 2, 2026
89e4571
docs: reconcile truthful startup gap
seonghobae Sep 2, 2026
74991d5
test: prevent navigation from faking completion
seonghobae Sep 2, 2026
9348739
test: distinguish completion from navigation
seonghobae Sep 2, 2026
bd5b20a
test: tie progress to verified completion
seonghobae Sep 2, 2026
08d4a23
feat: derive completion from verified facts
seonghobae Sep 2, 2026
970ec4e
fix: derive progress from completed responsibilities
seonghobae Sep 2, 2026
fd48659
docs: define evidence-backed authoring progress
seonghobae Sep 2, 2026
01ff054
test: make no-collection retention inapplicable
seonghobae Sep 2, 2026
5ad05c6
fix: make no-collection retention inapplicable
seonghobae Sep 2, 2026
fc35f8c
fix: project no-collection retention truthfully
seonghobae Sep 2, 2026
ddd24ea
docs: define no-collection retention applicability
seonghobae Sep 2, 2026
773ecb3
docs: align retention applicability contract
seonghobae Sep 2, 2026
b3ab6b4
docs: record truthful no-collection retention
seonghobae Sep 2, 2026
1d32e78
docs: reconcile no-collection retention gap
seonghobae Sep 2, 2026
734a3d6
test: require explicit retention applicability
seonghobae Sep 2, 2026
dc4f9ad
test: separate retention authority from collection
seonghobae Sep 2, 2026
e0f25c0
test: make retention status explicit in buyer flow
seonghobae Sep 2, 2026
6207729
fix: require explicit retention applicability
seonghobae Sep 2, 2026
25a75ad
fix: separate retention status from collection state
seonghobae Sep 2, 2026
1372763
docs: bind retention authority to PIPC terminology
seonghobae Sep 2, 2026
35e462f
docs: require explicit retention authority
seonghobae Sep 2, 2026
73ed5f3
docs: separate retention and collection contracts
seonghobae Sep 2, 2026
20354c4
docs: record independent retention authority
seonghobae Sep 2, 2026
b0a1825
docs: reconcile independent retention authority
seonghobae Sep 2, 2026
8843fbe
ci(actions): restamp current head after startup failure
seonghobae Sep 4, 2026
ee95740
chore: refresh head after Actions startup failure
seonghobae Sep 4, 2026
cf559fd
fix(ci): restore truthful workflow verification
seonghobae Sep 6, 2026
f1b6f57
docs: align retention ADR and proposal state
seonghobae Sep 6, 2026
f3c3f1c
fix: reject credential-bearing service URLs
seonghobae Sep 7, 2026
75262a3
test: add exact-head browser accessibility evidence
seonghobae Sep 7, 2026
df8e860
fix: restore UTF-8 dependency lockfile
seonghobae Sep 7, 2026
2905d87
fix: raise muted text contrast
seonghobae Sep 7, 2026
2ad3d9c
test: expose offscreen warning focus
seonghobae Sep 7, 2026
97140b1
test: target the specific service warning
seonghobae Sep 7, 2026
d9ef1f8
fix: reveal focused authoring headings
seonghobae Sep 7, 2026
b38204b
docs: reconcile exact-head browser evidence
seonghobae Sep 7, 2026
19a22c9
test: verify retention evidence invalidation
seonghobae Sep 7, 2026
53f109a
test: scope retention navigation to the rail
seonghobae Sep 7, 2026
1b3d34b
docs: record retention browser evidence
seonghobae Sep 7, 2026
c2934b6
test: specify 200 percent rendered-scale reflow
seonghobae Sep 7, 2026
a2cc136
test: model browser zoom through layout viewport
seonghobae Sep 7, 2026
5842998
docs: record bounded browser zoom evidence
seonghobae Sep 7, 2026
58741e7
docs: bind zoom ledger to exact head evidence
seonghobae Sep 7, 2026
70c52d8
test: require policy revision schema
seonghobae Sep 7, 2026
afda644
feat: define policy revision schema
seonghobae Sep 7, 2026
cb58715
test: require serialized fact constraints
seonghobae Sep 7, 2026
d790def
fix: serialize policy fact constraints
seonghobae Sep 7, 2026
572470b
docs: record proposed persistence boundary
seonghobae Sep 7, 2026
b26d6ea
test: cover revision fact concurrency
seonghobae Sep 7, 2026
2e9fe56
fix: preserve revision fact ownership
seonghobae Sep 7, 2026
a852dde
chore: ignore browser test output
seonghobae Sep 7, 2026
8bb50dc
docs: record persistence review repair
seonghobae Sep 7, 2026
eb089ec
docs: record persistence lock contract
seonghobae Sep 7, 2026
7ed2955
test: cover every revision fact owner
seonghobae Sep 7, 2026
c8ca4d1
fix: protect all revision fact owners
seonghobae Sep 7, 2026
9316f0a
docs: add proposed policy revision ERD
seonghobae Sep 7, 2026
21e2529
ci: upgrade action runtimes to Node 24
seonghobae Sep 7, 2026
5d4d11d
fix(ci): move checkout to Node 24 action runtime
seonghobae Sep 7, 2026
1cfd320
docs(release): record checkout Node 24 action runtime
seonghobae Sep 7, 2026
02d9439
docs(gap): bind checkout runtime warning RED to exact repair
seonghobae Sep 7, 2026
23b3a1c
docs(gap): keep exact-head gate state timeless
seonghobae Sep 8, 2026
971241f
test: require explicit retention transition transaction
seonghobae Sep 8, 2026
95b5dfb
docs: clarify retention transition transaction
seonghobae Sep 8, 2026
fba59b8
merge: restack action runtime repair on persistence fix
seonghobae Sep 8, 2026
cbfbdae
test(docs): reject recursive action evidence claims
seonghobae Sep 8, 2026
fd2d6d2
docs(ci): bind action evidence to immutable heads
seonghobae Sep 8, 2026
3d576aa
docs(ci): preserve canonical artifact digests
seonghobae Sep 8, 2026
7dd5c24
docs(test): reconcile evidence regression count
seonghobae Sep 8, 2026
bdaf5e8
test(ci): require stale-head cancellation
seonghobae Sep 8, 2026
ce6d5d5
fix(ci): cancel superseded repository heads
seonghobae Sep 8, 2026
7de8043
test(db): require PostgreSQL runtime evidence
seonghobae Sep 8, 2026
f106173
test: bind both immutable evidence tuples
seonghobae Sep 8, 2026
2a287b6
fix(test): preserve regex escapes across contents API
seonghobae Sep 8, 2026
9eaa3a5
fix(test): retain constructor regex escaping
seonghobae Sep 8, 2026
9030a07
test(db): execute PostgreSQL migration contract
seonghobae Sep 8, 2026
9ebc735
test(db): bind failures to domain errors
seonghobae Sep 8, 2026
7da8529
test(db): require concurrent writer evidence
seonghobae Sep 8, 2026
7d2cc35
test(db): verify concurrent writer serialization
seonghobae Sep 8, 2026
6f12bb5
test(db): verify complete UPSERT values
seonghobae Sep 8, 2026
f756f05
test(db): bind full UPSERT regression contract
seonghobae Sep 8, 2026
761125b
merge: restack concurrency evidence on UPSERT repair
seonghobae Sep 8, 2026
f97ab69
test: require PostgreSQL restore evidence
seonghobae Sep 8, 2026
2e0774e
test(db): verify policy revision dump restore
seonghobae Sep 8, 2026
e9f833a
docs: record restart and restore evidence
seonghobae Sep 8, 2026
3d633ee
test: require complete concurrent UPSERT values
seonghobae Sep 8, 2026
227e089
fix: verify complete concurrent UPSERT values
seonghobae Sep 8, 2026
a7d1416
docs: record complete concurrent UPSERT evidence
seonghobae Sep 8, 2026
735f0ad
docs: bind concurrent UPSERT evidence to persisted values
seonghobae Sep 8, 2026
91e2017
docs: clarify concurrent UPSERT value contract
seonghobae Sep 8, 2026
c031570
merge: preserve complete concurrent UPSERT evidence
seonghobae Sep 8, 2026
e9d5631
fix: seed restore facts atomically
seonghobae Sep 8, 2026
c756811
test: require NULL-safe concurrent UPSERT checks
seonghobae Sep 8, 2026
fbfa5e6
fix: fail closed on NULL concurrent UPSERT values
seonghobae Sep 8, 2026
946338b
docs: record NULL-safe concurrency evidence
seonghobae Sep 8, 2026
a0bb446
docs: explain NULL-safe persistence assertion
seonghobae Sep 8, 2026
e315e5e
docs: reconcile NULL-safe concurrency gap
seonghobae Sep 8, 2026
9219b06
merge: restack restore evidence on NULL-safe concurrency
seonghobae Sep 8, 2026
ce0f316
test: require complete restored collection-item values
seonghobae Sep 8, 2026
0430469
fix: verify complete restored collection-item values
seonghobae Sep 8, 2026
a0a26c9
docs: record complete restore evidence
seonghobae Sep 8, 2026
991ecaa
docs: bind complete restore assertions
seonghobae Sep 8, 2026
e28415c
docs: reconcile complete restore gap
seonghobae Sep 8, 2026
9678ee7
docs: align architecture with PostgreSQL CI evidence
seonghobae Sep 8, 2026
6f8abb0
docs: align TRD with PostgreSQL CI evidence
seonghobae Sep 8, 2026
d8fdd01
merge: restack restore evidence on reconciled architecture
seonghobae Sep 8, 2026
5950a74
test: require transactional applies retention seed
seonghobae Sep 8, 2026
45fc63d
fix(db): seed applies retention in one transaction
seonghobae Sep 8, 2026
d2eea3c
merge: restack restore evidence on concurrent UPSERT values
seonghobae Sep 8, 2026
a5342b1
docs: record deferred applies seed contract
seonghobae Sep 8, 2026
a1539c5
merge: integrate concurrent restore restack
seonghobae Sep 8, 2026
5e54834
test: require independent retention state after restore
seonghobae Sep 8, 2026
202e69d
test: prove restored policy fact independence
seonghobae Sep 8, 2026
2b1205f
docs: record complete restore invariants
seonghobae Sep 8, 2026
92a1e11
docs: bind restored fact independence evidence
seonghobae Sep 8, 2026
e1b94ee
docs: reconcile restore RCA and evidence
seonghobae Sep 8, 2026
aaef3b5
test: detect restored service URL loss
seonghobae Sep 8, 2026
57732c6
test: preserve restored service URL evidence
seonghobae Sep 8, 2026
bfdaee2
docs: record restored service URL RCA
seonghobae Sep 8, 2026
ea9f186
docs: separate CI restore from operations
seonghobae Sep 8, 2026
5309a61
merge: restore evidence into concurrent writer stack
seonghobae Sep 8, 2026
878d0ce
test: bind restored URL and independence contract
seonghobae Sep 8, 2026
ad07bcd
test: specify deterministic policy JSON export
seonghobae Sep 8, 2026
d82485a
test: require browser JSON download
seonghobae Sep 8, 2026
e834aa7
test: prevent credential URL export
seonghobae Sep 8, 2026
553c1a6
test: keep export cases independently runnable
seonghobae Sep 8, 2026
856958a
feat: project deterministic policy draft export
seonghobae Sep 8, 2026
d883d16
feat: download policy draft JSON locally
seonghobae Sep 8, 2026
384c337
test: type the exported Blob mock argument
seonghobae Sep 8, 2026
2a4249c
docs: define local draft export boundary
seonghobae Sep 8, 2026
e386140
test: expose export portability edge cases
seonghobae Sep 8, 2026
eaf18cb
fix: preserve portable export semantics
seonghobae Sep 8, 2026
b72ce67
docs: record export review repairs
seonghobae Sep 8, 2026
0f1a608
test: expose export data and mock leaks
seonghobae Sep 8, 2026
5c803b1
fix(export): strip query credentials from service URL
seonghobae Sep 8, 2026
90a3d68
test(export): restore browser URL spies
seonghobae Sep 8, 2026
2833391
docs: record export disclosure controls
seonghobae Sep 8, 2026
0e9a349
test(export): reject UI status sentinels in schema types
seonghobae Sep 8, 2026
f3f0f9e
fix(export): narrow portable status schema types
seonghobae Sep 8, 2026
7be6d36
test: verify policy draft browser download
seonghobae Sep 8, 2026
35b9fbd
docs: record browser download evidence
seonghobae Sep 8, 2026
b731c01
docs: preserve non-recursive evidence wording
seonghobae Sep 8, 2026
798f2c4
test: cover JSON export interactions
seonghobae Sep 8, 2026
b9507d9
docs: record JSON export interaction evidence
seonghobae Sep 8, 2026
4d57f60
test: bind revoked URLs to created downloads
seonghobae Sep 8, 2026
bc4c7f1
test: specify download activation failure recovery
seonghobae Sep 8, 2026
d8117e2
fix: report local export activation failures
seonghobae Sep 8, 2026
f7c3ee2
docs: record export activation failure recovery
seonghobae Sep 8, 2026
01ab876
test: fail closed on lossy service URL export
seonghobae Sep 8, 2026
3f16e06
fix: reject lossy service URL export
seonghobae Sep 8, 2026
c2f4887
test: preserve service URL destination semantics
seonghobae Sep 8, 2026
71ef187
docs: align service URL authority contract
seonghobae Sep 8, 2026
170a658
test: preserve complete service URL rejection matrix
seonghobae Sep 8, 2026
bc539d7
docs: preserve service URL rejection lineage
seonghobae Sep 8, 2026
0580f46
test: reject empty service URL delimiters
seonghobae Sep 8, 2026
9d92a9e
fix: reject empty service URL delimiters
seonghobae Sep 8, 2026
6032102
docs: record empty URL delimiter repair evidence
seonghobae Sep 8, 2026
a6cf635
test: preserve encoded service URL path data
seonghobae Sep 8, 2026
a7cac94
docs: bind encoded URL path regression
seonghobae Sep 8, 2026
83f189e
test: expose pre-activation export failure
seonghobae Sep 8, 2026
8d637f9
fix: contain export preparation failures
seonghobae Sep 8, 2026
751e3d5
docs: record export preparation recovery
seonghobae Sep 8, 2026
6529617
docs: define export preparation failure boundary
seonghobae Sep 8, 2026
fd44c84
docs: align export error contract
seonghobae Sep 8, 2026
9edb24f
docs: bind export preparation RED and GREEN
seonghobae Sep 8, 2026
becfd95
docs: document authoring helper invariants
seonghobae Sep 8, 2026
e3f8c6b
docs: correct product readiness and license boundary
seonghobae Sep 8, 2026
4c74e5d
docs: document policy helper contracts
seonghobae Sep 8, 2026
b8171c9
docs: restack protected integration truth
seonghobae Sep 8, 2026
80b69d6
test(deps): reject mutable direct dependency specs
seonghobae Sep 8, 2026
cd9144f
build(deps): pin reviewed versions and isolate tooling
seonghobae Sep 8, 2026
f6bbf9d
test(ci): require exact-head CycloneDX evidence
seonghobae Sep 8, 2026
a3592da
ci(deps): publish exact-head CycloneDX evidence
seonghobae Sep 8, 2026
c0c2b0a
docs(deps): bind supply-chain evidence and gaps
seonghobae Sep 8, 2026
3c8ac64
test(ci): isolate dependency evidence artifact
seonghobae Sep 8, 2026
00b89fb
ci(deps): isolate CycloneDX artifact
seonghobae Sep 8, 2026
71fe275
docs(deps): record artifact isolation evidence
seonghobae Sep 8, 2026
eff7ec1
test(deps): close exact-head review gaps
seonghobae Sep 8, 2026
8d85635
Merge pull request #2 from ContextualWisdomLab/codex/policyweave-focu…
seonghobae Sep 9, 2026
d0da193
test: bind cross-state seed and query predicates
seonghobae Sep 9, 2026
bbea5c9
Merge pull request #13 from ContextualWisdomLab/codex/pin-direct-depe…
seonghobae Sep 9, 2026
df9eef5
Merge pull request #14 from ContextualWisdomLab/codex/policyweave-res…
seonghobae Sep 9, 2026
369cfe2
docs: record 2026-09-09 stack-collapse merge ledger
seonghobae Sep 9, 2026
111400a
Merge pull request #15 from ContextualWisdomLab/docs/policyweave-merg…
seonghobae Sep 9, 2026
7bf0fa9
Merge pull request #16 from ContextualWisdomLab/codex/policyweave-con…
seonghobae Sep 9, 2026
cef8c0b
merge: restack export stack on full writer-stack tip
seonghobae Sep 9, 2026
e67c34c
merge: restack readiness docs on restacked export head
seonghobae Sep 9, 2026
29f91f9
docs: record PR16 landing plus side-chain restacks
seonghobae Sep 9, 2026
8178ba6
Merge pull request #17 from ContextualWisdomLab/docs/policyweave-rest…
seonghobae Sep 9, 2026
77bf3c2
docs: align PR11 scope sentence with dependency-governance delta
seonghobae Sep 9, 2026
83fb9f8
Merge pull request #11 from ContextualWisdomLab/docs/product-readines…
seonghobae Sep 9, 2026
828ecf1
merge: land export plus dependency-governance side chain into develop…
seonghobae Sep 9, 2026
e1c588f
Merge pull request #18 from ContextualWisdomLab/codex/policyweave-sid…
seonghobae Sep 9, 2026
ea30067
docs: record side-chain landing plus merge know-how
seonghobae Sep 9, 2026
852c6ba
docs: record PR1 exact-head failures on pinned develop tip
seonghobae Sep 9, 2026
632a08e
Merge pull request #19 from ContextualWisdomLab/docs/policyweave-land…
seonghobae Sep 9, 2026
198fbe0
docs: cover remaining exported policy symbols with JSDoc
seonghobae Sep 9, 2026
82ac08d
docs: record PIPA amendment re-verification ahead of effective date
seonghobae Sep 9, 2026
77f3331
Merge pull request #20 from ContextualWisdomLab/docs/policyweave-docs…
seonghobae Sep 9, 2026
062299b
Merge pull request #21 from ContextualWisdomLab/docs/policyweave-sour…
seonghobae Sep 9, 2026
82e556c
docs: record docstring and re-verification turn in ledger
seonghobae Sep 9, 2026
2d4928d
Merge pull request #22 from ContextualWisdomLab/docs/policyweave-turn…
seonghobae Sep 9, 2026
c57ebc7
test: pin policy boundary contracts for URL, contradiction, and email…
seonghobae Sep 9, 2026
82e7826
Merge pull request #23 from ContextualWisdomLab/test/policy-boundary-…
seonghobae Sep 9, 2026
c8f8510
docs: record boundary-contract turn and PR1 tracking state
seonghobae Sep 9, 2026
a2f48f9
Merge pull request #24 from ContextualWisdomLab/docs/policyweave-boun…
seonghobae Sep 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
83 changes: 83 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
name: CI
on:
pull_request:
push:
branches: [main, develop]
concurrency:
group: policyweave-ci-${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
verify:
runs-on: ubuntu-latest
services:
postgres:
image: postgres@sha256:d3e1620b530c944afa6e887d22eb899824da68e19c52024bf98f5220c88a65b2 # 18.6-alpine3.24
env:
POSTGRES_DB: policyweave_test
POSTGRES_USER: policyweave_ci
POSTGRES_PASSWORD: policyweave_ci_password
ports:
- 5432:5432
options: >-
--health-cmd "pg_isready -U policyweave_ci -d policyweave_test"
--health-interval 5s
--health-timeout 5s
--health-retries 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
cache: npm
- run: npm ci
- name: Generate exact-head dependency SBOM
run: |
mkdir -p dependency-evidence
npm sbom --sbom-format cyclonedx > dependency-evidence/policyweave-dependency-sbom.cdx.json
- run: npm run lint
- run: npm test
- run: npm run build
- name: Verify PostgreSQL policy revision migration
env:
PGHOST: 127.0.0.1
PGPORT: 5432
PGUSER: policyweave_ci
PGDATABASE: policyweave_test
PGPASSWORD: policyweave_ci_password
run: sh db/tests/policy_revision_runtime.sh
- name: Verify PostgreSQL concurrent policy writers
env:
PGHOST: 127.0.0.1
PGPORT: 5432
PGUSER: policyweave_ci
PGDATABASE: policyweave_test
PGPASSWORD: policyweave_ci_password
run: sh db/tests/policy_revision_concurrency.sh
- name: Verify PostgreSQL policy revision restore
env:
PGHOST: 127.0.0.1
PGPORT: 5432
PGUSER: policyweave_ci
PGDATABASE: policyweave_test
PGPASSWORD: policyweave_ci_password
run: sh db/tests/policy_revision_restore.sh
- run: npx playwright install --with-deps chromium
- run: npm run test:e2e
- name: Upload exact-head browser evidence
if: ${{ !cancelled() }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: policyweave-browser-evidence
path: test-results
if-no-files-found: warn
- name: Upload exact-head dependency SBOM
if: ${{ !cancelled() }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: policyweave-dependency-sbom
path: dependency-evidence/policyweave-dependency-sbom.cdx.json
if-no-files-found: error
8 changes: 8 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
node_modules
dist
.env
coverage
playwright-report
test-results/
*.tsbuildinfo
.codegraph/
24 changes: 24 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# AGENTS.md

## Product responsibility
PolicyWeave is a local-first privacy-policy fact-authoring workspace. It structures facts supplied by a service operator, detects missing or contradictory inputs, and renders a review draft. It does not provide legal advice, certify compliance, or infer facts that the operator has not established.

## Development contract
- Treat structured policy facts as the source of truth; rendered policy prose is a deterministic projection.
- Preserve the seven authoring steps in `docs/PRD.md`: service information, collection items, purposes, retention, third-party transfer, international transfer, and privacy contact.
- Behavior changes require regression or edge-case tests first. Do not resolve a review finding until the exact current head proves the finding obsolete or fixed.
- Re-fetch the PR head before every commit/push. Never force-push or weaken branch/ruleset protections to merge.
- Keep `ARCHITECTURE.md`, `docs/TRD.md`, ADRs, `docs/research-traceability.md`, `CHANGELOG.md`, and `docs/product-technical-gap-baseline.md` aligned with implementation.
- Do not encode legal conclusions from memory. Every legal/rule/template decision needs an authoritative source, effective date, source revision, and implementation/test trace.
- Do not commit identifying customer, individual, or real operational-organization data in tests, examples, fixtures, or product documentation. Publicly documented legal authorities, official document titles, standards bodies, source publishers, and the repository owner may be named when required for accurate provenance and citation. Production must not consume synthetic demo data.
- Keep persistence objects semantically named with at least two words and `snake_case` unless a framework contract requires another convention. Avoid generic named persistence objects such as a standalone `id` table/collection.
- Hosted persistence/publication must be introduced only behind explicit tenant, authorization, audit, encryption, immutable revision, and supersession contracts. CI PostgreSQL restart and dump/restore evidence lives in `db/tests/policy_revision_restore.sh` and does not enable a hosted adapter. Seed `retention_status = applies` only in the same transaction as its `retention_rule`; autocommit fails the deferred fact contract.
- GitHub Actions dependencies stay SHA pinned and checkout credentials must not persist.
- Direct npm dependencies stay pinned to their reviewed lock resolutions. Compiler and bundler packages belong in `devDependencies`, and exact-head CI publishes a CycloneDX dependency SBOM without treating license metadata as legal approval.

## Verification
The minimum exact-head gate is `npm run lint`, `npm test`, and `npm run build`, plus every live organization-required workflow, independent approval, and resolved review thread. Queued, skipped, predecessor-head, or stale results are not passing evidence.

## Know-how
- Draft PRs cannot merge through the API: mark ready (`gh pr ready`), re-confirm exact-head CLEAN/MERGEABLE/verify GREEN with zero unresolved threads, then ordinary `--merge` without branch deletion or force-push.
- Slow local executors flake Vitest's default 5s per-test timeout on full-workflow UI tests while exact-head CI stays GREEN. Use `npx vitest run --testTimeout=60000` for the local signal; CI `verify` is authoritative. Detail: `CLAUDE.md`.
46 changes: 46 additions & 0 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
# Architecture

## Product boundary
PolicyWeave owns the authoring and review of structured privacy-processing facts and the deterministic generation of a review draft. It does not own legal advice, identity-provider data, payment processing, or a customer's source systems. Hosted publication and durable storage are future supporting capabilities, not authority to invent or reinterpret processing facts.

## Domain-driven design
The core subdomain is **Policy Fact Authoring**. Supporting subdomains are **Review & Publication** and **Legal Source Registry**. Browser/storage frameworks, authentication infrastructure, observability, and deployment are generic subdomains.

### Bounded contexts
- **Policy Fact Authoring**: captures `service_profile`, collection presence/no-collection attestation, `collection_item`, `processing_purpose`, `retention_rule`, `third_party_transfer`, `international_transfer`, and `privacy_contact` facts.
- **Review & Publication**: derives `review_finding`, controls `policy_revision` review state, and will create immutable `publication_revision` artifacts only after explicit authorization.
- **Legal Source Registry**: versions authoritative sources, effective dates, rule/template revisions, and citations. It is an anti-corruption layer between changing external law/guidance and already-published revisions.

### Context map
`Policy Fact Authoring -> Review & Publication` is a customer/supplier relationship through a versioned policy-fact contract. `Legal Source Registry -> Review & Publication` supplies versioned rule evidence; source updates cannot silently mutate historical policy revisions. External customer systems remain behind adapters and must not be queried or mutated through hidden coupling.

## Ubiquitous language and model
A future `policy_revision` is the minimal aggregate root and transaction boundary. `service_profile`, collection presence/no-collection attestation, `collection_item`, `processing_purpose`, `retention_rule`, `third_party_transfer`, `international_transfer`, and `privacy_contact` are revision-owned facts/value objects unless later evidence requires independent lifecycles. `review_finding` is derived evidence. `publication_revision` is an immutable release receipt, not a mutable policy row. Rendered prose is a projection and never the source of truth.

Core invariants:
1. A fresh workspace contains no inferred customer operational facts; blank means unresolved rather than `none`.
2. Collection presence is established by either at least one selected collection item or an explicit no-collection attestation. Empty selection alone remains unresolved. The no-collection attestation and selected items are mutually exclusive; contradictory state fails closed.
3. Turning on the no-collection attestation invalidates all selected-item collection mode, processing purpose, and collection-path evidence. Turning the attestation off cannot revive those stale facts.
4. Selecting a collection item without confirming its collection mode, processing purpose, or collection-path evidence creates independent blocking review findings.
5. Service identity, retention, third-party provision status, international-transfer status, and privacy contact remain blocking authoring responsibilities until explicitly established; service URL and contact-email syntax checks prove only usable field shape, not endpoint/mailbox ownership.
6. Third-party provision and international transfer distinguish unresolved, yes, and no. A `yes` status requires dependent facts; a transition away from yes invalidates dependent details so stale facts cannot revive silently.
7. Disabling a collection item invalidates its dependent collection-mode, processing-purpose, and collection-path evidence; re-enabling requires renewed confirmation.
8. Review findings navigate to the fact that caused them.
9. Publication must never upgrade an unreviewed or incomplete draft to a reviewed/authoritative state.
10. A published revision remains reproducible from its policy facts plus rule/template/source versions.
11. External legal-source updates produce explicit re-evaluation, not silent rewriting.

## Current implementation
The active MVP is a React/Vite browser workspace. State is in memory and there is no production persistence or publication backend. The browser can download a deterministic versioned JSON draft containing normalized operator-authored facts and readiness finding codes; this local portability projection is not publication, persistence, or legal approval. The seven PRD steps are routed to distinct editing surfaces. The collection taxonomy is metadata only. `src/policy.ts` owns deterministic collection-selection/no-collection/mode/purpose/path and non-collection authoring-completeness findings; `src/App.tsx` owns browser orchestration, explicit no-collection and transfer-status capture, warning-to-source navigation, stale dependent-fact invalidation, and deterministic preview rendering. `src/AuthoringFocusController.tsx` is a browser interaction adapter: after explicit rail, previous/next, or review-warning navigation changes the active editing surface, it moves programmatic focus to that surface's heading without changing domain state, intercepting ordinary field interaction, or overriding the separate preview-focus shortcut.

Authoring completeness is deliberately separate from legal sufficiency. Current readiness rules prove that product-defined fact responsibilities were explicitly addressed; they do not assert that a policy complies with law. Source/effective-date-bound legal validation belongs to the Legal Source Registry -> Review & Publication boundary.

## Persistence boundary (Proposed schema; CI-only runtime)
ADR-0003 and `db/migrations/0001_policy_revision.sql` propose the first PostgreSQL contract. The 3NF write model uses `policy_revision` as aggregate root; `service_profile`, `collection_item`, `processing_purpose`, and `retention_rule` are revision-owned facts. `(tenant_account_id, revision_number)` identifies a version, while `(policy_revision_id, collection_item_key)` is the item-level UPSERT/idempotency key. Deferred database constraints lock the owning revision row, reject collection items under explicit no-collection, and reject retention-rule/status contradictions at transaction commit.

Exact-head CI executes that migration against digest-pinned PostgreSQL 18, including rollback, two-session locks with NULL-safe complete-value assertions, process restart, and custom-format dump/restore of complete collection-item plus independent collection and retention facts. This is not an active datastore, released API, or hosted adapter. Hosted tenant authorization, immutable audit events, encryption, deletion, operational backup/restore, and production-scale contention remain open. Publication remains append-only/immutable with explicit supersession; writes across unrelated aggregates must not share a transaction merely for convenience. Named database/schema/persistence objects use at least two semantic words and `snake_case`, for example `policy_revision`, `collection_item`, `processing_purpose`, `review_finding`, `publication_revision`, and `legal_source_revision`.

Separate write-side draft commands from read-side rendered/review projections once hosted traffic justifies it. Account for revision hot spots and optimistic/constrained writes before adding collaborative editing. Keep source/customer integrations behind ACLs; do not form a shared kernel with unrelated ContextualWisdomLab products without demonstrated reuse.

## Deployment and operability direction
The browser-only MVP needs no service mesh. A hosted backend should be compose-deployable across Docker/Podman/Colima before Kubernetes migration, expose asynchronous/non-blocking request handling, and add realistic k6 evidence for network surfaces before latency claims. No code may depend on an optional `close_connection` instance attribute existing unless the adapter contract guarantees it.
Loading
Loading