Files
moreminimore-chat/HANDOFF.md
2026-08-16 03:36:08 +07:00

84 lines
8.4 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# HANDOFF
## Current state
Implementation is in progress in `/Users/kunthawat/Gitea/Chatwoot`; source changes are present and remain unpushed.
### Latest handoff — 2026-08-16 03:04 +0700
- `19dc449` — SM-07 local-only observability: Sentry/APM packages and boot paths removed; exception tracking remains local-only; exact post-commit review for `372f316..19dc449` passed with empty blocking arrays.
- `364e72f` — SM-08 dashboard arbitrary-script injection removal: `DASHBOARD_SCRIPTS` reader/config/sink removed; exact post-commit review passed with empty blocking arrays; Vite production build exited 0.
- Code checkpoint remains `364e72f`; current repository `HEAD` includes this docs handoff commit `9a4e78a`. No push, deploy, HTTP request, DNS lookup, or credential use occurred.
- Residual Hub cleanup is implemented in the worktree but **not committed**: fixed Hub URL/push relay/Hub changelog are removed, Enterprise shared billing callers are preserved behind validated `CHATWOOT_BILLING_URL`, and privacy audit findings are zero. The residual Vite production build completed successfully (`4,736 modules transformed`, `✓ built in 3m 49s`, exit code 0); only Browserslist/chunk-size warnings remain. Commit is blocked because fresh delegated reviewers timed out/incomplete and therefore produced no valid approval verdict.
### Verified checkpoints
- `8ebb320` — privacy/branding audit harness.
- `832a7fd` — Hub sync/registration/telemetry removal.
- `1a3697f` — restored only the compatibility APIs required by direct push/billing callers.
- `8b1a033` — removed the Chatwoot Hub push relay; exact post-commit independent review passed.
- `3458272` — removed cwctl telemetry from the installer; exact post-commit independent review passed.
- `d9bf4c4` — removed community signup/onboarding website-branding enrichment; split exact post-commit reviews `deleg_5e2578c5` (backend) and `deleg_ee3e217f` (frontend) passed with empty blocking arrays.
- `ced77af` — SM-06 Product Analytics removal and dashboard config allowlist remediation; pre-commit review `deleg_f9644984` and exact post-commit review `deleg_9b0a2f63` passed with empty security/logic arrays.
### Current work / uncheckpointed work
- SM-05 community signup enrichment removal is checkpointed at `d9bf4c4`; pre-commit review, commit hooks, and split exact post-commit reviews passed. The enterprise service/spec remain unchanged and fail with `NameError: uninitialized constant WebsiteBrandingService`. This remains an explicit architecture/legal blocker; do not add a dummy service or restore remote enrichment.
- SM-06 is verified at `ced77af`. Its follow-up fix applies `.slice(*GLOBAL_CONFIG_KEYS)` before merging `app_config`, preventing stale/unrequested values such as `CLOUD_ANALYTICS_TOKEN` from reaching serialized `window.globalConfig`. SM-07 local-only observability and the remaining SM-08 dashboard/config script-injection work are still uncheckpointed. The community Help Center SM-08 correction is committed as `5619cc3`: remove GTM remote-container execution, reject/remove legacy GTM config, and retain only fixed allow-listed provider snippets for explicit admin configuration. Exact post-commit review `deleg_dd3db5b7` passed with empty blocking arrays. Enterprise marketing conversion tracking remains outside this community scope pending legal/compatibility review.
### Evidence and blockers
- SM-03 exact post-commit review passed for `1a3697f..8b1a033`; reviewer suggestions are to add explicit missing/blank/partial Firebase negative coverage and clarify legacy FCM configuration names in `.env.example`.
- SM-04 exact post-commit review passed for `1a3697f..3458272`; Bash 3.2 compatibility and fail-closed privacy-test behavior were verified.
- SM-05 exact committed range `3458272..d9bf4c4` passed split independent reviews: backend `deleg_5e2578c5` and frontend `deleg_ee3e217f`; both returned complete five-key verdicts with empty security and logic arrays. Frontend targeted run passed 9 suites/8 tests. Backend RSpec rerun is environment-blocked because Ruby 3.4.4 is required but only 3.4.10 is installed and the bundle has no usable `rspec` executable.
- SM-06 exact committed range `a96b977..ced77af` changed one controller line and passed fresh pre-commit/post-commit independent review. Raw merge leaked a stubbed analytics token; the allowlist slice now removes unrequested keys before layout serialization. Committed Ruby syntax, diff check, and security scan passed. Rails RSpec/RuboCop remain blocked because the active Ruby is 2.6.10 and Bundler 2.5.16 is unavailable.
- SM-08 exact post-commit review `deleg_dd3db5b7` passed for `d9bf4c4..5619cc3`; 57 portal model/controller examples, GTM regression 3/3, Ruby/ERB syntax, RuboCop, ESLint/Prettier, Vite build and privacy-audit harness passed. Full Vitest remains 407 passed/15 failed in six unrelated date/time/report-snapshot tests.
- No push or deploy has occurred.
- Approved product name, domains, logos/icons and sender/legal values are still missing; stop before SM-09/10.
- Full Rails/frontend suites, production-like DB checks, HTTP/DNS egress capture, `git fetch --unshallow`, and upstream merge rehearsal remain outstanding. Current full Vitest baseline has 407 passed/15 failed in six unrelated date/time and report-snapshot tests; do not report it as a clean suite until those baseline failures are resolved or formally waived.
- Temporary test services/configuration stay under `/tmp`; never commit them or secrets.
### Repository baseline
- Path: `/Users/kunthawat/Gitea/Chatwoot`
- Origin: `https://github.com/chatwoot/chatwoot.git`
- Branch: `develop`
- Initial baseline commit: `9a73c1473ffa0ae6a9c7725046b8ca17922dcc83`
- Latest checkpoint: `ced77af` (SM-06 Product Analytics plus dashboard config allowlist remediation; exact post-commit review `deleg_9b0a2f63` passed). SM-08 Help Center remains separately verified at `5619cc3`.
- Clone is shallow; fetch full upstream history before merge/rebase rehearsal.
### Primary deliverable
- `.hermes/plans/2026-08-15_092534-chatwoot-private-rebrand.md`
- Small-model execution index: `.hermes/plans/chatwoot-private/README.md`
- The execution package contains `00-execution-contract.md` plus runbooks `01``12` with 58 unique `SM-*` tasks. Send only one task at a time and review its exact diff/test evidence before advancing.
### Most important finding
`DISABLE_TELEMETRY=true` is not a complete opt-out. `lib/chatwoot_hub.rb` still posts `instance_config` to the Hub; it only omits `instance_metrics`. The corresponding behavior is asserted in `spec/lib/chatwoot_hub_spec.rb`.
### Other unsolicited/vendor-controlled egress to remove
- Chatwoot Hub daily sync and onboarding registration
- Chatwoot Hub `/send_push` relay fallback
- Hub-hosted changelog fetch
- silent cwctl command reporting to the Hub
- automatic signup email-domain website/DNS branding enrichment
- Amplitude browser analytics
- Sentry/frontend/backend remote error reporting
- optional remote APM agents
- arbitrary dashboard scripts and remote GTM container execution
- enterprise marketing conversion tracking (proprietary/cloud-only; pending separate legal/compatibility decision)
### Implementation order
1. Follow dependency order in `.hermes/plans/chatwoot-private/README.md`.
2. Establish the baseline and privacy audit harness before behavior changes.
3. Remove Hub sync/registration/manual refresh, push relay, cwctl telemetry, signup-domain enrichment and remote changelog.
4. Neutralize/remove analytics, remote error reporting/APM and script injection.
5. Stop at the Runbook 09 input gate until approved brand values/assets are supplied.
6. Add central brand defaults and replace visible assets/copy without renaming compatibility APIs.
7. Run static and isolated dynamic egress gates, positive feature-traffic tests, full review and visual QA.
8. Complete upstream-history and merge-rehearsal workflow; never mix upstream merge with customization commits.
### User decisions required before implementation
- Product name, canonical/support/docs domains, logos/icons and email sender name
- Private Gitea repository name
- Whether to keep deprecated widget API aliases (recommended: yes)
- Whether local-only logs are sufficient or a self-hosted observability endpoint is required
- Push notification plan and own FCM/VAPID credentials
### Safety/legal notes
- Root is MIT, but `enterprise/` is proprietary; do not ship enterprise features without a separate license.
- No remote repository was created, no files were pushed and no deployment was performed.