F∆I Studio — desktop GUI for the F∆I hub
Find a file
flemming-it ebc668d28d feat(approvals,audit): record the reviewer as the unchecked claim it is
The hub copies the reviewer string a client sends straight into
decided_by (DecideApproval, ClearEventLog); nothing on the wire ties
it to the authenticated caller. Studio filled it from the OS account,
so an export read like non-repudiation while being an arbitrary
client claim — the legal finding of the 2026-07-26 usertest panel.

The real fix is hub-side (derive decided_by from CALLER_IDENTITY);
that contract is written down in docs/reviewer-identity.md and needs
a hub release. Until then Studio does the one thing it can do
honestly and marks its own claim as a claim, inside the record:

- data/reviewer_identity.dart is the single place that produces and
  reads the value; wire() is idempotent, so page and HubService may
  both normalise. Every write path funnels through HubService, so no
  surface can send a bare handle.
- The inbox states before the decision who will be recorded, what
  that attribution is worth on this hub (from AuthStatus), and the
  literal string that lands in decided_by. An unreadable auth policy
  stays unreadable — never optimistic.
- Reading back: a marked value shows its plain name plus an
  unchecked flag; an unmarked one (legacy row, CLI decision, or a
  future hub-derived identity) is not classified either way.
- The audit wipe seeds the same kind of marked attribution into its
  chain.reset marker.

When the hub starts deriving the value it overwrites the field and
the prefix disappears by itself — no Studio release needed.

Guards: reviewer_identity_test (the value) and
approvals_reviewer_identity_test (every surface that writes or
renders it, against the hermetic fake hub). Visual proof for both
themes via the dialog-shot harness.

Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
2026-08-03 23:50:34 +02:00
.forgejo/workflows ci(security): add self-test harness (mirror of fai/platform) 2026-05-10 21:41:23 +02:00
.githooks docs: old product name F∆I Platform -> Ch∆In + contact chain@flemming.ai 2026-06-16 10:14:30 +02:00
assets feat(approvals,runs): explain approvals in place + one-click hub update (0.81.0) 2026-07-26 15:50:41 +02:00
docs feat(approvals,audit): record the reviewer as the unchecked claim it is 2026-08-03 23:50:34 +02:00
integration_test feat(approvals,audit): record the reviewer as the unchecked claim it is 2026-08-03 23:50:34 +02:00
lib feat(approvals,audit): record the reviewer as the unchecked claim it is 2026-08-03 23:50:34 +02:00
linux fix(ui): window title Ch∆In Studio (was F∆I); de-dup federation add-satellite 2026-06-18 12:53:35 +02:00
macos chore: Pfade auf ~/Developer umgestellt 2026-07-28 00:40:09 +02:00
test feat(approvals,audit): record the reviewer as the unchecked claim it is 2026-08-03 23:50:34 +02:00
tools feat(settings): hub auth-policy panel — T4/T5 security parity in the GUI 2026-07-15 03:19:33 +02:00
windows refactor: rename app fai_studio -> chain_studio 2026-06-16 17:48:11 +02:00
.gitignore feat: F∆I Studio MVP scaffold (Tier-2 desktop GUI) 2026-05-05 14:19:39 +02:00
.metadata feat: F∆I Studio MVP scaffold (Tier-2 desktop GUI) 2026-05-05 14:19:39 +02:00
.security-allow ci(hooks): pre-commit security check (mirror of fai/platform) 2026-05-09 13:32:26 +02:00
analysis_options.yaml feat: F∆I Studio MVP scaffold (Tier-2 desktop GUI) 2026-05-05 14:19:39 +02:00
CHANGELOG.md feat(approvals,audit): record the reviewer as the unchecked claim it is 2026-08-03 23:50:34 +02:00
CLAUDE.md docs: add CLAUDE.md with UI verification gate (screenshot light+dark, click-flow) 2026-07-13 14:10:14 +02:00
l10n.yaml feat(studio): app-wide i18n via flutter_localizations (v0.24.0) 2026-05-08 01:19:32 +02:00
pubspec.lock fix(flows): only offer install for capabilities the store resolves 2026-07-22 13:46:08 +02:00
pubspec.yaml feat(approvals,runs): explain approvals in place + one-click hub update (0.81.0) 2026-07-26 15:50:41 +02:00
README.md docs: replace stale MVP-scaffold README with the current v0.70 reality 2026-07-07 13:44:40 +02:00

Ch∆In Studio

Desktop GUI client for the Ch∆In Platform hub. Tier-2 generic platform client per docs/architecture/client.md in the platform repo. Connects to a local or remote chain serve over gRPC / gRPC-Web.

Status: live product (v0.70+). Every page talks to the hub through chain_client_sdk; there is no mock data. End users launch Studio via chain studio, which downloads and verifies a prebuilt bundle from the release mirror (sha256 + signature) or rebuilds from source when a dev workspace is configured.

Pages

  1. Welcome — onboarding checklist, guided setup wizard, bundled documentation reader.
  2. Store — browse/search/install modules across multiple stores (pinned publisher keys, private sources, AI AskBar); installed modules live here as a filter.
  3. Flows — graph + text flow editor with a live Run tab (streamed step events, inline approvals). Editor ships as the chain_studio_flow_editor package.
  4. Audit — live event stream (StreamEvents) with filters, hash-chain verification, gated log reset.
  5. Approvals — pending system.approval@^0 reviews with approve / reject and payload disclosure.
  6. Doctor — diagnostics, daemon lifecycle, binary recovery.
  7. Föderation — satellite list, bootstrap-token enrolment, revocation.

Plus: settings dialog (System-AI, integrations/MCP/n8n, security, maintenance), Cmd+K palette, release-channel switcher.

Stack

  • Flutter 3.40+ (Desktop: macOS, Linux, Windows)
  • gRPC client via chain_client_sdk (sibling repo; pinned by relative path during development)
  • No external runtime dependencies; bundles its own Dart VM

Run locally

flutter run -d macos      # or -d linux / -d windows
flutter test

chain studio prefers a configured dev workspace and will flutter run from source when one resolves — see crates/chain_runtime_mgmt in the platform repo.

Repo placement

Published as fai/chain-studio on Forgejo (git.flemming.ai). The local directory follows the established fai_chain_* layout convention.

Why "Studio" and not "Stage"

"Stage" collided too easily with "staging environment" in developer English. "Studio" is the established industry pattern for creator-tools (Visual Studio, Android Studio, RStudio) and matches the GUI's audience of module developers, operators, and power users.