Panel findings against the reworked approvals page, fixed in place:
- Never fabricate the request time: ApprovalRecord.createdAt is
nullable now; a missing created_at omits the line instead of
rendering DateTime.now() (which drifted on refresh). Guard:
approvals_origin_test pins the omit-on-null invariant.
- Copyable errors on approve/reject/batch via showChainErrorSnack
(the hard project rule) — batch surfaces the first real cause.
- Reject requires a reason: ChainInlineHelp strip + confirm disabled
while empty, no more silent close-and-nothing-happens.
- Batch approve applies the same no-data confirmation as the single
path, naming how many selected requests carry no show: data.
- Plainer language: glossary "Vorgang (Flow)", history label FRAGE
(was PROMPT), no-data hint drops developer jargon.
- One-click copy of the run id; history payload pretty-prints like
the card.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Approvals: the pending card now shows its full origin — flow, step,
run id (previously dropped at the Dart mapping layer), project, and
requested-at — under an ORIGIN heading, led by a one-line intro strip
that says what the inbox is and what Approve/Reject do. Approve/Reject
buttons carry tooltips; the history dialog gains project + run id.
Fixes the approvals doc drift (title/details/reviewer ->
prompt/show/timeout_seconds). Guard: approvals_origin_test renders the
card via the hermetic fake hub and pins every origin fact.
Runs: the "hub too old" state now leads with an in-place update button
(same `chain update apply` path as the Diagnose page), the Diagnose
deeplink demoted to secondary, with a CLI-absent fallback. Guard: two
new RunsLoadErrorView widget tests.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Doctor: when the system AI uses an Ollama endpoint that no declared
host service covers (host:port match, /v1 suffix stripped), the
services panel says so in one sentence with a one-click 'declare as
host service' via the new DeclareService RPC — and states honestly
that it takes effect after a daemon restart (the restart button sits
on the same page). Pure suggestOllamaServiceEndpoint pins every
branch.
Shell: one slim, dismissible banner after connecting when the
release manifest offers a newer hub version; dismissal is persisted
per version so each release hints exactly once (pure
shouldShowUpdateHint + a widget test through the fake hub).
Deliberately manifest-based — Studio and hub versions are
independent counters, so a direct comparison would be wrong;
unreleased dev skew stays with the per-page classified states.
The probe stays inert under the test probe override: its timeout
timer leaked into hub_banner_test (the hermeticity class again).
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The detail sheet always answers 'who maintains this?': one
selectable line per maintainer from the store index's new
maintainers list, or an honest 'not specified' when the index
names nobody (StoreMaintainersSection, public for the widget
tests). The install trust gate carries the same fact when
present and stays terse otherwise. DE+EN; dialog-harness proof
captured with the maintainer row.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Store snapshot is now nullable: until the first successful store
search (or after a sealed-area connection switch) the editor gets
null and claims neither 'installable' nor 'not in store'. The
snapshot reloads after installs and on connection switches — a
sealed switch previously kept the other hub's capability offers
alive on the mounted Flows page. Editor pin 2535c28.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Mount the shared project switcher (same control as Audit, Approvals
and Runs) in the flow editor's toolbar via the editor's new
toolbarTrailing slot. The list filters by the active project with
'no key = general' display semantics, and new flows are stamped
with the active project's key. Editor pin moved to c4a39a3
(0.25.0 + project separation).
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Even with the honest install badge the hub error stays reachable
(stale store snapshot, race with a store refresh, older hub). The
friendly-error mapper now gives it its own headline plus a hint
naming the three acquisition paths — local module install, adding
the providing store, configuring the MCP/n8n integration — in EN
and DE, with the verbatim hub message kept copyable. Matcher unit
tests EN+DE guard the classification.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The capability set behind the flow editor's Install quick-fix and
the flow list's install badge ingested every store entry's
requiresCapabilities (dependencies, not provided capabilities) and
ignored entry status/kind. Clicking Install on such a capability
ended in the hub's "no store entry for '<name>'" error.
The set now mirrors the hub's install resolver (entry names only,
no planned or federated entries) via installableStoreCapabilities()
with unit tests for both classification states. Unresolvable
capabilities render the editor's 'not in store' state, which
explains the three recovery paths before any click; the editor pin
moves to 0.25.0 (commit-pinned until its tag exists) and the dialog
harness captures the badge states light+dark. Studio 0.78.0.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The doc-verifier pass over the new trust/exposure surfaces came back
PASS with five improvements, all applied:
- the store policy notice gains a 'Learn more' into the security doc
(the notice named security.require_signatures but not where it
lives)
- 'blocked' disables the trust gate's install button — an active
button contradicted the 'install would be refused' statement right
above it (guard test added)
- the unknown-exposure tooltip now says what the operator can do
(check where the name resolves)
- dead l10n key verifPillUnverified removed (unverified is the
page-level notice, never a card pill)
- stale header comment in install_verification.dart corrected
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The trust-gate dialog replaces its generic 'no per-entry status yet
(alpha)' note with the hub's classified verification statement —
pinned store key / trusted publishers (green), installs without
signature checking (amber), install would be refused (red), bridge
entry (neutral) — via one shared describeInstallVerification mapping.
Against a pre-0.23 hub the field is empty and the old honest wording
stays (pinned by test).
Information architecture: policy-off is a GLOBAL fact, so it appears
as ONE ChainInlineHelp notice above the store grid instead of a
warning pill on every card (card noise); only 'blocked' — a genuine
per-source anomaly — earns a card pill. Doctor's host services show
the hub-classified network reach per endpoint (local only / private
network / publicly reachable with a protect-it hint / reach unknown).
Verified end-to-end against the live dev hub (guide harness): the
wire field arrives, the store page shows exactly one policy notice
and quiet cards; trust-gate variants captured via the dialog
harness. Suite 123 green.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
New ChainInlineHelp (intro strip: what this is + what will happen, with
an optional 'Learn more' into the doc sheet) and ChainFieldHelp /
ChainFieldLabel (a '?' affordance per field). First applied to the
add-satellite dialog, which asked for a bare 'name' with no hint of
what a satellite is or does (usertest): it now leads with a plain
explanation + a federation 'Learn more', and the name field carries a
'?'. Both widgets are quiet by design.
Verified: field_help_test covers the widgets + that the dialog explains
itself; dialog_shots_test.dart (a reusable headed dialog-capture
harness) proved the layout in light + dark. Studio 0.76.0.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The Federation and Runs help buttons opened the architecture doc:
federation.md/runs.md existed as assets but had no _DocEntry, so
showFaiDoc resolved the unknown slug to _kDocs.first. Register both
(onWelcome: false, so they don't clutter the newcomer grid but are
reachable), split the Welcome grid onto the curated subset, and make
the unknown-slug fallback assert in debug instead of silently opening
the wrong topic.
Guard (no-bugfix-without-a-guard): doc_help_wiring_test.dart scans
lib/ for every showFaiDoc('slug') call and asserts each has a
registered entry AND both assets/docs/<slug>[_de].md files. Exposes
kKnownDocSlugs for the test.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The switcher listed sealed areas by name ('lbs', 'stromnetz') on
any glance or screenshot — but the names themselves often carry
client/mandate identity (usertest security finding). The sealed
section now renders one aggregated row ('2 sealed areas') with a
deliberate 'Show names' reveal per menu opening; selection still
pops the regular s:<slug> value. Settings -> Security gains 'list
sealed areas with their names right away' (WorkspacePrefs,
SidebarPrefs pattern, default off).
The aggregate row wraps to two lines — popup menus cap their
width and action texts must never be truncated (the first cut
showed '1 abgeschotte…' in the proof shot). Guard: switcher tests
cover aggregated-until-reveal and the Settings toggle; the old
direct-listing test now asserts the reveal contract. DE+EN.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The same single-select choice pattern appeared as four widgets:
audit's hover pills, the store's SegmentedButton, the store filter
dialog's ChoiceChips, and the approvals TabBar (usertest finding
#14 / night-log decision 'pill segment as canon'). The audit
pattern is promoted to a shared ChainSegments widget (optional
icons, hover, selected border, button+selected semantics) and all
four sites use it; approvals switches lists via IndexedStack so
both stay alive and switching does not refetch.
Guard per the no-bugfix-without-a-guard rule: widget tests for
selection + semantics, plus a canon sweep that bans
TabBar/TabBarView/TabController/SegmentedButton/ChoiceChip from
lib/ (comments exempt). Deliberately out of scope: the flow
editor's Graph/Text/Run tabs live in the separate editor package.
Studio 0.75.0; guide images regenerated, dark + light verified.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The widget suites used to talk to whatever listens on the real
endpoint — results depended on the operator's machine (a running
hub fed real data into a11y/responsive runs and its gRPC channel
timers caused the historic flake). Hardening round:
- HubService.instance is now injectable (debugSetInstance);
FakeHubService (test/support/fake_hub.dart) answers every member
the pages touch with healthy-empty defaults and scripts per-RPC
failures (UNIMPLEMENTED / UNAVAILABLE / detached gate) through a
GrpcError-shaped fake. Unimplemented members are recorded and
fail the sweep with the exact list.
- state_matrix_test.dart pins the app-wide invariants for every
sidebar page x hub condition: healthy => no unreachable claims
and no raw error text; hub gone => honest unreachable states;
UNIMPLEMENTED => never 'not reachable' while the sidebar shows
connected; detached gate => plain-language feature-off state.
- a11y + responsive sweeps now inject the fake (hermetic); the
6-minute idle-timer drain workaround is gone with the cause.
Real bugs the new sweep caught immediately:
- every data page (store, doctor, audit, approvals, federation)
folded ANY load failure into 'hub not reachable' — the runs-page
bug class; they now share HubLoadErrorView, which classifies
into unreachable / needs-newer-hub / load-failed-with-copyable-
detail (new generic DE+EN strings)
- the approvals page's hidden tab had no future listener: a load
failure there surfaced as an uncaught async error
- the audit status bar rendered the raw gRPC error wall verbatim;
it now shows the classified friendly headline (still selectable)
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Doctor findings used to be dead-end statements — 'approvals
waiting for review' left the operator to find the approvals inbox
on their own. Every finding with a dedicated surface is now one
tap away from it:
- summary tiles: modules -> store, approvals -> approvals inbox,
audit chain -> audit log (chevron affordance, tooltip + semantics
button; the services tile stays plain — no dedicated page)
- modules/approvals panel rows link the same way
- the event-log headline opens the audit page next to the
existing verify button
- host-services empty state gains a 'view the configuration'
button opening the in-Studio config viewer the hint refers to
- the update banner's release-notes URL is now an underlined,
clickable link instead of dead text
Tiles and the panel are public callback-driven widgets so the
widget tests pump them without a live hub. New DE+EN link labels.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Finally caught with a creation stack trace: when the last gRPC
stream closes, Http2ClientConnection arms the channel's 5-minute
idleTimeout timer — even on a shut-down connection — so the
test's 1-minute drain never covered it and the framework's
pending-timer invariant tripped whenever the arm landed inside
the test window (frequent while a real hub listens on 50051).
The suite now closes the channel in real-async space at the end
of the body (new @visibleForTesting HubService.debugResetChannel;
shutdown is deliberately not awaited — it wedges on a mid-connect
socket, but cancels its timers synchronously) and pumps past the
idle timeout so the timer fires inside the test. 6 consecutive
full-suite runs + 3 isolated runs green; before, roughly 1 in 3
full runs failed.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The onDone handler armed an anonymous 3 s reconnect timer that
nothing could cancel; when the stream closed right before the page
was disposed (no hub, connect ends in onDone instead of onError),
the timer outlived the tree. The a11y suite caught this as the
rare 'Timer is still pending' flake noted in the night log — the
failure reason is now captured and the timer lives in a field that
dispose() cancels.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The runs monitor folded every load failure into 'hub not reachable',
contradicting the sidebar's green connected dot whenever the hub
answered but the RPC failed — most visibly against a pre-0.22 hub
whose version predates the ListInvocations RPC (UNIMPLEMENTED).
Classify the failure instead (top-level, unit-tested):
- UNIMPLEMENTED -> 'this view needs a newer hub version' with a
doctor-page link (the update banner lives there)
- FAILED_PRECONDITION from the detached gate -> the regular
feature-off empty state with the guide button
- UNAVAILABLE / DEADLINE_EXCEEDED / socket-level failures -> the
honest 'hub not reachable' state (unchanged)
- everything else -> a load-failed state with the friendly error
and a copyable detail box
The error view is a public callback-driven widget so the tests pump
each variant without a live hub. New DE+EN strings for the too-old
and load-failed states; grpcCodeOf/grpcMessageOf exposed from the
friendly-error mapper instead of duplicating the duck-typing.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The menu so far only exported the current view (type + search
filter over the page 100-event window). A second action now fetches
the complete event history of the active project scope in one
EventLog call (the RPC has no cursor and no server-side cap) and
writes it as JSONL. Serialisation extracted to a top-level function
with unit tests; a stale comment advertising the never-shipped
"chain audit export" command now names "chain admin events --json".
Studio 0.73.0.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
- Store hero: 'TODAY' badge only for an operator-accepted story; the
rotating compiled-in fallback deck now says 'FEATURED' (no false
freshness claim). Policy as a top-level function with unit tests.
- Audit filter chips: standard label typography instead of mono —
mono stays reserved for paths and identifiers.
- DE chain wording: 'Hash-Kette geprüft' as the one confirmation term
(audit header now matches the doctor pill); 'intakt' stays the
state headline. EN was already consistent.
- Workspace switcher: contrast bump for the sealed-area 'stopped'
label.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Three doctor-page findings from the usertest panel:
- Module tile no longer counts the hub's built-in 'system'
pseudo-module — a fresh hub shows 0 modules, matching the
welcome checklist's definition of an install. Counting is a
top-level function with unit tests.
- When the audit DB lives in an OS-cleanable temp directory
(/var/folders, /tmp, Windows Temp), the daemon-files panel
says so instead of presenting the state as healthy. The
classifier is a top-level function with unit tests.
- The daemon card states who-talks-to-whom-how in one line:
endpoint, transport security (TLS / unencrypted-local /
unencrypted), and whether a bearer token is attached (length
only) — the auditor's baseline the green dot cannot answer.
Also syncs pubspec.yaml (0.70.0 -> 0.72.0) with kStudioVersion,
which had drifted to 0.71.0 while pubspec stayed behind.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
- the 'start a saved flow' checklist tick no longer unticks once
the flow.completed event scrolls out of the 100-event window —
a local sticky marker keeps it honest to its wording
- the Today carousel shows 'n/m' next to the 6-px dots so the
position is readable without aiming at them
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
'document' rendered as a raw lowercase English token next to
localized neighbours; unknown categories at least capitalize.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
- 'Mit Endpunkt verbinden' — no Endpoint/Endpunkt mix
- audit-chain lead term is 'Hash-Kette' everywhere (doctor pill);
chain detail says 'Verkettung lückenlos geprüft' instead of the
raw field name prev_event_sha256
- welcome checklist line says who refreshes what
- setup privacy note explains the local model instead of ending in
a bare model tag
- default project renders localized ('Allgemein') in the switcher;
sealed-area status pills explain run state on hover
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Text widgets render markdown backticks verbatim (usertest: reads
as typos / raw dev output) — stripped across both catalogs; code
terms stay inline in plain type. 'Zeig dem Hub' / 'Nimm das CLI'
now use the formal address; the guard test learns both stems.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
- audit type filter: 'Alle'/'All' capitalized like every other label
- settings -> setup wizard: close Settings first (one modal layer),
stronger wizard scrim
- try-out setup profile discloses the upgrade path to a regulated
profile
- store maturity pills explain themselves on hover (experimental/
published/planned)
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The empty state unconditionally claimed background runs were
switched off, even on hubs where the operator had enabled them.
The hub now reports the flag on the list RPC (detached_enabled);
the hint picks the truthful variant.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
- search field over flow/step/module/error/detail/project/id backs
the list and the export ('current view' semantics); match logic
is a top-level function with unit tests
- export writes one JSON object per line via the save dialog; the
CLI stays the canonical WORM-grade export
- the bare trash icon on the audit toolbar read as 'delete
evidence' (security-auditor finding) — the dev-only reset now
sits in a labeled overflow menu next to the export action
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Every other page carries its primary action top right (New flow,
Add store) — the lone Material FAB bottom right broke the pattern
and sat far from the empty-state text asking for exactly that
action. The empty state now offers the button in place too.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
- every daemon file row gets a copy-to-clipboard action next to
view/open so terminal users can grab the raw path
- audit stat subtitle says 'n of m events verified' instead of the
cryptic 'n/m chain'
- capability source-kind breakdown renders display names
(Bundle/MCP/System) instead of raw lowercase wire tokens
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
- 'Fähigkeiten' is the German lead term everywhere (welcome step 2,
integrations panel, federation) — English jargon only as a
parenthesized technical term on first mention
- 'Enrollment-Token' -> 'Registrierungs-Token', bootstrap label in
plain words, CA spelled out, enrollment hint now formal address
- formality guard also rejects reader-addressed imperatives
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
- approvals inbox hint explains human approval in plain words
instead of citing system.approval@^0
- doctor summary counts use ICU plurals (1 module / n modules)
- audit chain pill says 'Integrity chain verified' instead of 'v1'
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
One-click installs showed no trust signal at all (top security
finding of the usertest panel). Every install path — store card,
detail sheet, and the flow list's quick fix — now routes through
one confirmation dialog showing what the hub actually knows
before download: origin store, version, license, maturity, and
required services/capabilities, plus the sandbox model and an
honest note that per-entry signature status is not in the store
index yet (verification happens hub-side at install). Widget
tests cover content and confirm/cancel semantics.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Procurement personas found no vendor, version, license, or
support information anywhere in the app (a hard checklist fail
for regulated buyers). Settings gains an About category:
product name, Studio + running-hub version, vendor Flemming.AI,
author, Apache 2.0 license, contact address, and the docs URL —
every value selectable and one-click copyable. Studio version
constant moved to data/about_info.dart so sidebar tag and About
can never drift. Bumps Studio to 0.71.0.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The icon-only rail forced first-time users to guess (usertest:
Senior, a11y, UX personas). Three changes:
- Nav tooltips appear instantly and carry the page shortcut
(Cmd+1..9, Ctrl on non-mac — Ctrl activators added); expanded
labels show the same hint. Explicit button semantics for
screen readers on every destination.
- A visible 'Search & commands' row above the footer opens the
existing Cmd+K palette, which nothing in the UI advertised.
- Settings -> Appearance gains 'Keep the navigation expanded':
pins the rail with permanent labels (persisted preference).
Footer strip and pillar toggle made overflow-safe for the
animating rail; responsive test scrolls the by-design scrollable
destinations list.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Store search, security panel, System-AI fix hint and the
approvals payload hint addressed the operator informally while
the rest of the app uses Sie — the panel flagged the break on
every second screen. All DE strings now use the formal address,
and a guard test rejects any future informal form in app_de.arb.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The Hub/Module/Flow cards explained the basics in the very
vocabulary they were supposed to introduce (Rust binary, WASM,
YAML, hash-chained). Each card now leads with a plain-language
explanation; the technical wording moved behind a per-card
'for the technically curious' toggle. DE and EN.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The empty state explained itself in operator jargon (detach,
detached.enabled, operator config) and offered no way forward.
Now it says what background runs are in everyday language and
opens the built-in guide — which carries the exact activation
steps — via a real button. DE and EN.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Wires the editor's new onPickFile host callback to file_picker
(withData: the editor receives name + bytes, never a raw path).
Pins chain_studio_flow_editor to v0.23.0. No more typing absolute
paths to feed a flow a file.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Stefan's live findings, all four addressed at the root:
- 'In 3 Fragen loslegen' read like ad copy → the entry is now plainly
'Einrichtung starten' / 'Start setup'.
- The setup button sat permanently on the Welcome page of a running
app ('setup after the app runs is backwards' — reported twice). A
fresh install now starts INSIDE the setup: SetupGateScreen hosts
the wizard embedded as the page (new embedded/onFinished modes on
GuidedSetupDialog), with an explicit 'Später einrichten' skip.
Welcome loses the setup button entirely and stays a calm intro.
- Re-running the setup later lives in Settings → General ('Run setup
again…'), the single post-first-run home.
- 'You must grant access first and only then see what will be done':
the preview used to spawn the chain CLI, whose first run could pop
the macOS permission prompt BEFORE the plan was ever shown. The
preview now calls the new PlanSetup RPC over the live hub
connection (no subprocess, nothing granted); the CLI remains only
a fallback when no hub is reachable — and applying stays the
explicit, separate step.
Widget tests: gate hosts the wizard + skip/cancel leave it; CLI-path
tests drive the fallback through the new hub-preview test seam.
Suite 76 green, analyze clean.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
A black window on launch, no error anywhere: main() awaited
loadPersistedEndpoint before the first frame, and
SharedPreferences.getBool threw 'int is not a subtype of bool?' —
the store is writable from outside the app and hub.secure had been
written as int 0. Pref reads now go through defensive typed helpers
(int coerces to bool, wrong types fall back to defaults), and every
pre-frame restore step is failure-isolated: a broken store can cost
a preference, never the first frame. Regression tests stage the
corrupt store (the exact observed value and worse).
Also removes the CocoaPods leftovers from the macOS project
(Podfile, [CP] script phases, Pods framework references, xcconfig
includes): the project builds via Swift Package Manager, and the
dual wiring ran both dependency managers on every build — Flutter's
persistent 'removing CocoaPods will improve build time' warning.
Verified: clean profile build produces a launchable bundle (plugins
statically linked via SwiftPM), suite green, analyze clean.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Review follow-ups on the auth-status work:
- Both daemon-start paths classified an auth-rejected hub as "daemon
dead" via healthy() and showed a start-failure dialog while the
shell banner above correctly blamed the token. They now share
daemonAnswers(): only an unreachable probe counts as down.
- An auth-rejected poll now re-reads ~/.chain/hub-auth-token and
reconnects when the file changed, so a token fixed outside Studio
(CLI, editor) heals the connection without a restart — previously
the client kept the stale in-memory token forever and the banner's
own advice could not work.
- An endpoint switch resets the failure streak, so a stale in-flight
probe can no longer let the unreachable banner blame the new
endpoint for the old one's misses.
- The auth-policy panel re-queries when the hub token is saved or
cleared in the panel above (reloadTick), instead of keeping a
stale admin-denied hint; it also renders the hub's new
reload_required flag as a pending-reload warning (DE+EN).
- today-pipeline.md still documented ~/.fai/today after the rename;
the FAB theme comment now states the both-themes intent.
flutter analyze clean; 71 tests green including four new ones.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The sustained-failure banner treated every failed health poll as
'can't reach the hub'. With token auth active, a wrong or rotated
token gets UNAUTHENTICATED from a perfectly reachable hub — the
old wording sent the operator to fix the endpoint. The shell now
uses the SDK's probe() and, on auth rejection, switches the banner
to 'rejected the sign-in — check the access token' (key-off icon,
DE+EN). Two widget tests pin the wording per failure kind and the
banner clearing once the probe turns serving.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Accessibility/responsive audit pass with two new permanent test
gates (test/a11y_test.dart: WCAG text contrast + labeled tap
targets on every page in both themes; test/responsive_test.dart:
no layout overflow at 800/960/1280/1920 px). Findings fixed:
- Light theme primary/tertiary sky-500 → sky-700: white text on
the lighter accent only reached 2.8:1 (welcome CTA, active
sidebar label); sky-700 clears WCAG AA at ~5.9:1. Dark theme
unchanged (already compliant). FABs now follow the same accent
instead of Material 3's washed-out tonal default.
- Audit page: filter chips collapse into a checkmark popup menu
below 900 px window width (app bar overflowed); the live-status
bar's left text is now Expanded with ellipsis so the row can
shrink, and the disconnected state's copyable error gets the
full remaining width.
- German strings now use formal address consistently (~20 strings
still used du-forms next to Sie-forms on welcome/setup), the
audit event-type chip "Step" is "Schritt", and the doctor
page's event count pluralises correctly in both languages.
flutter analyze clean, 64 tests green. Screenshot pass light+dark
via the guide-shots harness (verified parity, no overflows).
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Settings → Security now shows the hub's effective auth policy via the
new read-only AuthStatus RPC: active token validator (static / jwt-rs256
with issuer, audience, JWKS source), anonymous-access warning, per-token
cards with scope grants, env-var presence and rate limits, plus a
localized admin-denied story for non-admin tokens. Live-reloads on
endpoint change.
Also fixes a batch of fai→chain rename leftovers this panel's
verification uncovered: hub_auth_token.dart and registry_token.dart
read/wrote ~/.fai/ while the hub reads ~/.chain/ (stored registry
tokens never reached the hub), today_story_loader + tools/today used
~/.fai/today, chain_log legacy ~/.fai/logs migration removed per the
no-legacy-recognisers decision, and UI strings still advertised the
retired .fai bundle extension.
Includes 5 widget tests for the panel, an integration-test screenshot
harness (auth_policy_shots_test.dart, guide-shots style), and DE+EN
l10n. flutter analyze clean, 58 tests green.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Field test of the setup wizard surfaced three trust breaks in one run:
an unexplained macOS Documents permission prompt, a perceived crash,
and an error message whose copy button could not be reached.
Root causes and fixes:
- chain init failures were shown as a SnackBar, which lands BEHIND the
wizard's modal barrier: dimmed, clipped, copy unreachable — and the
click aimed at it hit the barrier, dismissing the whole wizard with
all answers (the perceived crash). Errors now open a modal dialog
ABOVE the wizard via showChainErrorDialog with a copyable detail
block, and the wizard is no longer barrier-dismissible.
- When the resolved chain binary is older than Studio and rejects
--plan-json, the wizard now explains the version skew in plain
language (binary path + update path) instead of leaking a raw clap
usage error. A missing binary gets its own localized story.
- Step 3 announces which chain binary the preview will execute; when
that binary physically lives (symlinks resolved) in a TCC-protected
folder, the wizard pre-explains the macOS folder prompt.
Supporting changes: FriendlyError passes through friendlyError()
unchanged so call sites can ship precise localized stories through the
shared presentation; SystemActions gains resolvedChainBinary() plus
run/resolve test seams; ChainErrorBox hugs its content instead of
filling an unbounded dialog; the wizard's answers file is written
synchronously (the async dart:io variants never complete under the
widget-test fake-async zone).
Verified: flutter analyze clean, 53 tests green (6 new wizard error-
path tests incl. clipboard round-trip), plus a live GUI walk on macOS
in dark + light with a stale binary (skew dialog, copy verified via
clipboard) and with the real binary (TCC pre-explanation with the
resolved path, full plan preview).
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
Two settings bugs the operator hit:
1. 'Test connection' appeared to do nothing. The result/error panel
renders at the bottom of the System-AI editor's scrollable,
600px-capped form, so on a tall dialog it lands below the fold —
the footer button flickers 'Testing…' and nothing visible changes.
The editor now holds a ScrollController and animates the content
to reveal the outcome whenever a test result or error appears.
2. The welcome onboarding checklist kept 'connect System-AI'
unchecked right after saving a working config. The checklist row
opens the Settings dialog (an overlay, not a navigation), and on
close the checklist never re-probed — so it showed the stale
pre-config state. Both settings-opening rows (System-AI, MCP) now
re-probe when the dialog closes; navigation-based rows already
self-heal on return.
Studio suite green; flutter analyze clean.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>