84 lines
8.4 KiB
Markdown
84 lines
8.4 KiB
Markdown
# HANDOFF
|
||
|
||
## Current state
|
||
Implementation is in progress in `/Users/kunthawat/Gitea/Chatwoot`; source changes are present and remain unpushed.
|
||
|
||
### Latest handoff — 2026-08-16 03:04 +0700
|
||
- `19dc449` — SM-07 local-only observability: Sentry/APM packages and boot paths removed; exception tracking remains local-only; exact post-commit review for `372f316..19dc449` passed with empty blocking arrays.
|
||
- `364e72f` — SM-08 dashboard arbitrary-script injection removal: `DASHBOARD_SCRIPTS` reader/config/sink removed; exact post-commit review passed with empty blocking arrays; Vite production build exited 0.
|
||
- Code checkpoint remains `364e72f`; current repository `HEAD` includes this docs handoff commit `9a4e78a`. No push, deploy, HTTP request, DNS lookup, or credential use occurred.
|
||
- Residual Hub cleanup is implemented in the worktree but **not committed**: fixed Hub URL/push relay/Hub changelog are removed, Enterprise shared billing callers are preserved behind validated `CHATWOOT_BILLING_URL`, and privacy audit findings are zero. The residual Vite production build completed successfully (`4,736 modules transformed`, `✓ built in 3m 49s`, exit code 0); only Browserslist/chunk-size warnings remain. Commit is blocked because fresh delegated reviewers timed out/incomplete and therefore produced no valid approval verdict.
|
||
|
||
### Verified checkpoints
|
||
- `8ebb320` — privacy/branding audit harness.
|
||
- `832a7fd` — Hub sync/registration/telemetry removal.
|
||
- `1a3697f` — restored only the compatibility APIs required by direct push/billing callers.
|
||
- `8b1a033` — removed the Chatwoot Hub push relay; exact post-commit independent review passed.
|
||
- `3458272` — removed cwctl telemetry from the installer; exact post-commit independent review passed.
|
||
- `d9bf4c4` — removed community signup/onboarding website-branding enrichment; split exact post-commit reviews `deleg_5e2578c5` (backend) and `deleg_ee3e217f` (frontend) passed with empty blocking arrays.
|
||
- `ced77af` — SM-06 Product Analytics removal and dashboard config allowlist remediation; pre-commit review `deleg_f9644984` and exact post-commit review `deleg_9b0a2f63` passed with empty security/logic arrays.
|
||
|
||
### Current work / uncheckpointed work
|
||
- SM-05 community signup enrichment removal is checkpointed at `d9bf4c4`; pre-commit review, commit hooks, and split exact post-commit reviews passed. The enterprise service/spec remain unchanged and fail with `NameError: uninitialized constant WebsiteBrandingService`. This remains an explicit architecture/legal blocker; do not add a dummy service or restore remote enrichment.
|
||
- SM-06 is verified at `ced77af`. Its follow-up fix applies `.slice(*GLOBAL_CONFIG_KEYS)` before merging `app_config`, preventing stale/unrequested values such as `CLOUD_ANALYTICS_TOKEN` from reaching serialized `window.globalConfig`. SM-07 local-only observability and the remaining SM-08 dashboard/config script-injection work are still uncheckpointed. The community Help Center SM-08 correction is committed as `5619cc3`: remove GTM remote-container execution, reject/remove legacy GTM config, and retain only fixed allow-listed provider snippets for explicit admin configuration. Exact post-commit review `deleg_dd3db5b7` passed with empty blocking arrays. Enterprise marketing conversion tracking remains outside this community scope pending legal/compatibility review.
|
||
|
||
### Evidence and blockers
|
||
- SM-03 exact post-commit review passed for `1a3697f..8b1a033`; reviewer suggestions are to add explicit missing/blank/partial Firebase negative coverage and clarify legacy FCM configuration names in `.env.example`.
|
||
- SM-04 exact post-commit review passed for `1a3697f..3458272`; Bash 3.2 compatibility and fail-closed privacy-test behavior were verified.
|
||
- SM-05 exact committed range `3458272..d9bf4c4` passed split independent reviews: backend `deleg_5e2578c5` and frontend `deleg_ee3e217f`; both returned complete five-key verdicts with empty security and logic arrays. Frontend targeted run passed 9 suites/8 tests. Backend RSpec rerun is environment-blocked because Ruby 3.4.4 is required but only 3.4.10 is installed and the bundle has no usable `rspec` executable.
|
||
- SM-06 exact committed range `a96b977..ced77af` changed one controller line and passed fresh pre-commit/post-commit independent review. Raw merge leaked a stubbed analytics token; the allowlist slice now removes unrequested keys before layout serialization. Committed Ruby syntax, diff check, and security scan passed. Rails RSpec/RuboCop remain blocked because the active Ruby is 2.6.10 and Bundler 2.5.16 is unavailable.
|
||
- SM-08 exact post-commit review `deleg_dd3db5b7` passed for `d9bf4c4..5619cc3`; 57 portal model/controller examples, GTM regression 3/3, Ruby/ERB syntax, RuboCop, ESLint/Prettier, Vite build and privacy-audit harness passed. Full Vitest remains 407 passed/15 failed in six unrelated date/time/report-snapshot tests.
|
||
- No push or deploy has occurred.
|
||
- Approved product name, domains, logos/icons and sender/legal values are still missing; stop before SM-09/10.
|
||
- Full Rails/frontend suites, production-like DB checks, HTTP/DNS egress capture, `git fetch --unshallow`, and upstream merge rehearsal remain outstanding. Current full Vitest baseline has 407 passed/15 failed in six unrelated date/time and report-snapshot tests; do not report it as a clean suite until those baseline failures are resolved or formally waived.
|
||
- Temporary test services/configuration stay under `/tmp`; never commit them or secrets.
|
||
|
||
### Repository baseline
|
||
- Path: `/Users/kunthawat/Gitea/Chatwoot`
|
||
- Origin: `https://github.com/chatwoot/chatwoot.git`
|
||
- Branch: `develop`
|
||
- Initial baseline commit: `9a73c1473ffa0ae6a9c7725046b8ca17922dcc83`
|
||
- Latest checkpoint: `ced77af` (SM-06 Product Analytics plus dashboard config allowlist remediation; exact post-commit review `deleg_9b0a2f63` passed). SM-08 Help Center remains separately verified at `5619cc3`.
|
||
- Clone is shallow; fetch full upstream history before merge/rebase rehearsal.
|
||
|
||
### Primary deliverable
|
||
- `.hermes/plans/2026-08-15_092534-chatwoot-private-rebrand.md`
|
||
- Small-model execution index: `.hermes/plans/chatwoot-private/README.md`
|
||
- The execution package contains `00-execution-contract.md` plus runbooks `01`–`12` with 58 unique `SM-*` tasks. Send only one task at a time and review its exact diff/test evidence before advancing.
|
||
|
||
### Most important finding
|
||
`DISABLE_TELEMETRY=true` is not a complete opt-out. `lib/chatwoot_hub.rb` still posts `instance_config` to the Hub; it only omits `instance_metrics`. The corresponding behavior is asserted in `spec/lib/chatwoot_hub_spec.rb`.
|
||
|
||
### Other unsolicited/vendor-controlled egress to remove
|
||
- Chatwoot Hub daily sync and onboarding registration
|
||
- Chatwoot Hub `/send_push` relay fallback
|
||
- Hub-hosted changelog fetch
|
||
- silent cwctl command reporting to the Hub
|
||
- automatic signup email-domain website/DNS branding enrichment
|
||
- Amplitude browser analytics
|
||
- Sentry/frontend/backend remote error reporting
|
||
- optional remote APM agents
|
||
- arbitrary dashboard scripts and remote GTM container execution
|
||
- enterprise marketing conversion tracking (proprietary/cloud-only; pending separate legal/compatibility decision)
|
||
|
||
### Implementation order
|
||
1. Follow dependency order in `.hermes/plans/chatwoot-private/README.md`.
|
||
2. Establish the baseline and privacy audit harness before behavior changes.
|
||
3. Remove Hub sync/registration/manual refresh, push relay, cwctl telemetry, signup-domain enrichment and remote changelog.
|
||
4. Neutralize/remove analytics, remote error reporting/APM and script injection.
|
||
5. Stop at the Runbook 09 input gate until approved brand values/assets are supplied.
|
||
6. Add central brand defaults and replace visible assets/copy without renaming compatibility APIs.
|
||
7. Run static and isolated dynamic egress gates, positive feature-traffic tests, full review and visual QA.
|
||
8. Complete upstream-history and merge-rehearsal workflow; never mix upstream merge with customization commits.
|
||
|
||
### User decisions required before implementation
|
||
- Product name, canonical/support/docs domains, logos/icons and email sender name
|
||
- Private Gitea repository name
|
||
- Whether to keep deprecated widget API aliases (recommended: yes)
|
||
- Whether local-only logs are sufficient or a self-hosted observability endpoint is required
|
||
- Push notification plan and own FCM/VAPID credentials
|
||
|
||
### Safety/legal notes
|
||
- Root is MIT, but `enterprise/` is proprietary; do not ship enterprise features without a separate license.
|
||
- No remote repository was created, no files were pushed and no deployment was performed.
|