Production /login rendered a blank page (browser console: SyntaxError: 10 through the vue-i18n parser). Root cause proved with a RED regression (RES: vue-i18n public API reproduces 'Invalid linked format' code 10) plus an independent reviewer: auth.emailPlaceholder="name@company.com" is invalid vue-i18n linked-message syntax, so createI18n() throws a message-compilation SyntaxError while LoginView renders t('auth.emailPlaceholder'). Fix: escape the literal at-sign as name{'@'}company.com in th and en so the message compiles and the visible label is unchanged (name@company.com). Add an all-translations regression that translates every string in th/en (objects and arrays) through vue-i18n's public createI18n/global.t API and asserts the visible placeholder value. Verification: - RED test failed at th:auth.emailPlaceholder (code 10) before the fix. - Independent reviewer verified reproduction + fix, finished PASS. - Frontend tests 11 passed; production build passed (index-B4oVHpLg.js). - Chrome headless rendered the login card, Thai heading, and name@company.com from the production dist. Artifact checksum hash 3621155075b3d9245d2d05511aaf39b1b0cbcaeea local vs server.
5.2 KiB
5.2 KiB
Engineering Log
Current status
| Milestone | Status | Last verified | Evidence | Next action |
|---|---|---|---|---|
| Baseline architecture study | complete | 2026-08-23 | npm run build passed; compileall passed; git diff --check passed; source inventory completed |
Review MiroFish SaaS plan and lock M0 decisions |
| Thai/English frontend hardening | production login root cause fixed; redeploy pending | 2026-09-01 | Root cause of /login white screen proved with a RED vue-i18n compiler test: auth.emailPlaceholder = "name@company.com" is invalid linked-message syntax and throws compiler code 10 (Invalid linked format) while LoginView renders. Escaped as name{'@'}company.com in th/en. Recursive compiler regression covers every translation; frontend tests 11 passed, production build passed (index-B4oVHpLg.js), Chrome rendered DOM contains login-card, Thai heading, and rendered name@company.com; screenshot analysis unavailable because vision provider returned 401 |
Complete fresh reviewer gate, then commit/push/redeploy and verify live /login |
| Zep replacement | bounded local E2E slice | 2026-08-24 | Local graph → profile → simulation config → report tools → persisted report regression passed; default remains Zep; no full consumer cutover or semantic parity claim | Cut over remaining consumers and close semantic/E2E gaps |
| Auth/tenant/roles | bounded foundation | 2026-08-24 | Identity/session/roles/CSRF/CORS/idempotency/resource guards covered by focused tests; durable task app-state leak fixed; task query filters now push tenant predicates into SQL | Complete broader tenant matrix, admin UI, rate limits, audit/usage policy |
| SaaS foundation batch | in progress | 2026-08-24 | Backend full suite 193 passed after app/factory isolation, SQLite-FK, auxiliary API auth/CSRF/idempotency, cross-route/multipart idempotency, local consumer-boundary fixes, durable product-resource schema/repository, tenant-scoped ArtifactStore, durable JobQueue+worker.py, versioned redacted PlatformSettings, durable RateLimiter (wired to login), durable LLM UsageService, durable redacted AuditService, and durable single-use PasswordResetService + endpoints (also covers invite-pending setup); schema/TaskManager regression 16 passed; auxiliary security 8 passed; idempotency API 5 passed; local import-boundary regression 9 fresh-import tests; product-resource persistence 21 tests; artifact store 12 tests; job queue/worker 10 tests; settings service 4 tests; rate limiter 6 tests; usage service 4 tests; audit service 3 tests; password reset 6 tests; frontend gates passed; bounded reviewers passed their exact slices; hardened bases ready; remaining: resource authz matrix completion, admin/bootstrap UI, and deploy topology; ruff unavailable; no commit/push/deploy |
Complete admin UI, authz matrix, then deploy topology; do not claim full-system approval |
| Admin/super-admin UI | bounded foundation | 2026-08-24 | Backend: GET/POST/PATCH /api/admin/users + GET/PUT /api/admin/settings (super-admin only, masked/encrypted secret via SettingsService); Frontend: AdminView.vue (user mgmt) + SettingsView.vue (LLM settings form) routed at /admin + /admin/settings with admin/super-admin role guards, th/en i18n identical; build + 10 frontend tests pass; backend 197 passed |
Add invite self-setup UX, connection-test endpoint, then full i18n/mobile review |
| Production worker/deployment | production topology drafted, locally smoke-tested | 2026-08-24 | Dockerfile rebuilt as multi-stage production (frontend build + python-gunicorn + nginx-SPA-proxy + supervisord worker); backend/wsgi.py gunicorn entry + gunicorn>=21 added; local smoke test: gunicorn wsgi:app started, /health OK, /api/auth/login 401, built SPA assets served 200; backend 197 passed |
Build in EasyPanel container to verify nginx SPA-fallback + /api proxy + worker poll; choose broker (Redis vs durable-poll) + object storage for full readiness |
Guardrails
- No production implementation was changed during the architecture study.
- Keep exactly three role identifiers:
super_admin,admin,user. - Never expose LLM/API secrets to the browser or commit them to docs/logs.
- Backend authorization and tenant scope are authoritative; frontend visibility is not security.
- Do not claim LLM/Zep semantic parity without golden-fixture evidence.
Entry index
docs/engineering-log/2026-08-23-architecture-study.mddocs/test-evidence/2026-08-23-baseline.md.hermes/plans/2026-08-23_110451-mirofish-saas-migration.mddocs/engineering-log/2026-08-24-simulation-memory-fallback.md- Independent SaaS audit findings were incorporated after the initial plan: raw log redaction, ID/path confinement, idempotency, upload drafts and API contract tests.
- Safe-error audit now covers API response/persisted task state paths; raw exception/traceback values are replaced with generic localized errors and error-type-only server logs.
docs/engineering-log/2026-08-24-memory-parity-panorama-insight.mdrecords the bounded parity implementation, verification evidence, review verdict, and remaining semantic/E2E boundary.docs/engineering-log/2026-08-24-saas-foundation-verification.md