Outcome
Harden the ChatGPT export importer with schema probes, privacy gates, idempotency, and synthetic regression fixtures.
This should land with or immediately after #185 so imported archives are safe to preview and repeat.
Acceptance
- Add schema detection for the expected conversations payload.
- Fail with a clear error when the export shape is unknown.
- Never log raw message content on parse errors.
- Reuse existing content screening before any visible turn is stored.
- Reject or redact secrets using the same policy path as
/v1/turns.
- Reject unsupported message roles by default.
- Preserve enough metadata for provenance without storing unrelated account data.
- Stable idempotency keys prevent duplicate turns across repeated applies.
- Add synthetic fixtures for:
- normal two-turn conversation
- conversation with missing title
- unsupported role
- secret-like content rejection
- duplicate apply
- malformed export
- Tests must prove preview writes nothing.
Non-goals
- No real ChatGPT user export fixture in the repo.
- No raw private conversation data in tests.
- No hidden/internal message preservation.
Outcome
Harden the ChatGPT export importer with schema probes, privacy gates, idempotency, and synthetic regression fixtures.
This should land with or immediately after #185 so imported archives are safe to preview and repeat.
Acceptance
/v1/turns.Non-goals