Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions docs/PROGRESS.md
Original file line number Diff line number Diff line change
Expand Up @@ -451,6 +451,28 @@ bodies total 37,095 bytes. **This retires the Option C frozen-tail invariant by
existed only to police a boundary inside an unreviewable single line, and the append-only rule above
supersedes it. No bespoke hash is needed for future updates: the diff is the proof.

### 2026-10-07 - `docs/store/STORE_PATH.md` amended from Scan & Action's record: the build job and native sign-in are copied, not written; EU trader status is required even outside the EU; Android follows the iOS submission; three sessions to TestFlight and about nine to the first submission

**No row is edited. Outside this file: `docs/store/STORE_PATH.md` (amended in place, each correction marked "Corrected by §8", and a new §8). The owner's other app, Scan & Action (`tornidomaroc-web/scan-and-action`, same Apple team), was read only, through the GitHub API; nothing in it was changed. Nothing is built, nothing in production changed. Rows 42, 69 and 81 are not touched, and Section 7 takes no deletions.**

**WHAT SCAN & ACTION PROVES, AND WHAT IT DOES NOT.** It reached TestFlight on the owner's iPhone on 2026-09-28 (build 5) through a free `macos-26` job signed by an App Store Connect API key, after a wrong signing fix and its revert (#261, #262), a processing rejection ITMS-90683 for a missing photo-library purpose string (#263), and later Apple's cap of ten Development certificates per team (#277). It signs in to Google and Apple through one native plugin and revokes Apple tokens at deletion, proven on the phone (#258, #272). **It has never been submitted to App Review**, so it gives no evidence of what a reviewer decides on 4.2 or 3.1.3(f); its export options still carry `testFlightInternalTestingOnly`.

**CORRECTIONS TO THE PATH.** (1) Google sign-in goes through `@capgo/capacitor-social-login`'s native sheet and `signInWithIdToken`, not the system browser and a deep link. (2) The build job is Scan & Action's two-job workflow, copied and adapted, so the App Store Connect key never sits on a runner that ran npm; the owner's iPhone is already registered on the team, which removes the device dead end. (3) **EU trader status is required even outside the EU:** Apple's page, read 2026-10-07, says *"Even if you don't distribute apps in the EU, you'll still need to declare a trader status"*, which corrects `PIVOT_PLAN.md` §9's "deferred, not blocking" and the owner's brief. It is declared once per account, so one declaration covers both apps; Scan & Action's board still lists it open. (4) **Android moves after the iOS submission:** the owner has no Android device, so Android Google sign-in cannot be witnessed, and Scan & Action records that the account cannot register as a Google Play merchant. (5) The estimates fall from four to **three sessions to TestFlight** and from ten to **about nine to the first submission**.

**THE ARCHITECTURE, RE-JUDGED AND KEPT.** Capacitor's own configuration reference says of `server.url`: *"This is not intended for use in production."* That is weighed in §8.3. Scan & Action bundled its build at no extra cost because it was already a client-rendered app calling its backend with tokens; KnowFlow is server rendered with cookie sessions, so bundling costs it six to eight sessions. The deciding question is whether the native bridge reaches a page loaded from `tryknowflow.com`, and the first build answers it with a simulator launch check copied from Scan & Action; **if the bridge is absent, the plan switches to the bundled build before any later item is built.**

**REPORTED TO THE OWNER, NOT FIXED: A LIVE RISK IN SCAN & ACTION.** Its signing job runs `xcodebuild archive` on an Xcode project that arrives as an artifact from the job that ran `npm ci`, and does not check that `project.pbxproj` matches the commit. A compromised npm dependency could add a build-phase script that Xcode runs on the runner holding the team's **Admin** App Store Connect key, which also reaches KnowFlow. The suggested fix and two smaller findings are in `STORE_PATH.md` §8.5; KnowFlow's copy of the workflow carries the check from its first version, and KnowFlow gets its own key.

### 2026-10-07 - #137 PR B and PR C paused on the owner's ruling, registered and resumable; the path to the stores measured in `docs/store/STORE_PATH.md`: four sessions to TestFlight on the owner's iPhone, about ten to the first App Store submission

**No row is edited (the brief allowed Section 7 additions only). Outside this file: `docs/store/STORE_PATH.md` (new, analysis and decisions only). Nothing is built, nothing in production changed, no grant moved. Rows 42, 69 and 81 are not touched, and Section 7 takes no deletions.**

**THE PAUSE, AS THE OWNER RULED IT ON 2026-10-07.** Register #137's PR B (revoke the unused `authenticated` verbs: `knowledge_bases`, `conversations`, `messages`, `quiz_items` UPDATE and DELETE; `chunks` and `quizzes` UPDATE) and PR C (`alter default privileges for role postgres in schema public revoke insert, update, delete on tables from anon, authenticated`; `profiles` losing all three verbs with the dead signup upsert deleted; EXECUTE revoked from PUBLIC on the five functions of `docs/db-grants-audit-137.md` §1.7) are **paused, not dropped**. The owner's reasons: the core protection is live (PR A, `7265eef`, applied and proven 2026-10-07), the product has no real users yet, and the pace toward the stores is too slow. **Both stay registered under row #137 and resumable without a new audit:** PR B is six lines of the `INTENDED` matrix in `scripts/verify-public-grants.mjs` plus one migration, and the harness already exercises every verb `authenticated` keeps, so an over-reach goes red on its first run; PR C's plan is `docs/db-grants-audit-137.md` §4 and §6. **The agent agrees with the pause, with evidence (`STORE_PATH.md` §6):** every verb PR B would revoke is confined to the student's own rows by row security, so no cross-user write exists; and PR C's main purpose, catching a future table born with full API grants, is now served by `public-grants`, a required check since 2026-10-07 that fails any PR whose database holds a table outside the declared matrix. **Row #137's status cell still reads "NOT BUILT"; PR A is built and live (the two blocks below), and PR B and PR C are paused as recorded here.** The row is rewritten when #137 closes.

**THE STORE PATH, MEASURED (`docs/store/STORE_PATH.md`).** Apple's App Review Guidelines, account-deletion page, App Privacy page, TestFlight overview and upcoming-requirements page, GitHub's Actions billing and runner-image pages, Codemagic's pricing, and Google Play's testing, target-API and payments pages were read on 2026-10-07 and are cited by section. The findings that change the plan: **(1) the architecture.** The file objects to `PIVOT_PLAN.md` §5's static client bundle ("Option B") and recommends a native shell that loads `tryknowflow.com`: guideline 4.2 judges features, content and UI, not where the HTML loads from, while the signed-in app is server rendered (the dashboard layout, home, settings, subjects and ask pages, the middleware, and all 13 API routes reading the session from cookies), so a static bundle would cost about 6 to 8 sessions and a second front end. The residual risk of the hosted shell is guideline 2.5.2 (code that changes features after review), rated medium. **This is the one decision the file asks the owner to sign.** **(2) Two facts that break today's code in any shell:** Google blocks OAuth inside embedded web views (since 2021-09-30), so the Google button must go through the system browser and a deep link; and `src/lib/platform.ts`'s store flag is build-time only, so server-rendered pages would show the Upgrade links 3.1.1 forbids unless the shell marks its requests. **(3) A blocker no row tracked: guideline 5.1.2(i) now requires explicit permission before personal data is shared with third-party AI.** The privacy page names Anthropic and Voyage AI; nothing in the app asks. **(4) In-app purchase:** 3.1.3(b) lets an app honour a web purchase only if the same item is also sold through in-app purchase, so the first submission goes under 3.1.3(f) (a free companion to a paid web tool, no purchase surface), with a one-session fallback (native requests served the free tier) if App Review rejects it. **(5) Building without a Mac costs nothing:** GitHub's standard runners are free on public repositories, this repository is public, and the GA `macos-26` image meets Apple's Xcode 26 requirement of 2026-04-28; larger runners bill even here, so the label is exactly `macos-26`. **(6) Google Play:** a personal account created after 2023-11-13 must run a closed test with 12 testers for 14 days before production; whether the owner's account is one is unknown and is the owner's to read; new apps must target API 36 since 2026-08-31. **(7) Verdicts:** Phase 6, Phase 7 (B5b and B6), Phase 9 and #137 PR B and PR C all move after the first submission, with evidence per item; the file objects to `PIVOT_PLAN.md` §7's "Must merge before the mobile shell" for Phase 7, because the hosted shell adds no surface the web app does not already expose.

**THE ORDER RECOMMENDED.** To TestFlight on the owner's iPhone: T1 (the platform marker read at request time, native routing, the Google button hidden in native) → T2 (the Capacitor project, `ios/` and `android/`) → T3 (the owner: the App Store Connect app record and an API key in three GitHub secrets, about 30 minutes) → T4 (the iOS build and upload job on `macos-26`) → T5 (the owner installs through TestFlight): **about four sessions.** Then S1 (Google through the system browser, Sign in with Apple through the native sheet) → S4 (the AI consent) → S3 (a local study reminder and "Open in KnowFlow" for 4.2) → S2 (Apple token revocation on deletion) → S6/S7 (screenshots from the `/preview/*` routes, the App Store Connect forms) → S8 (the owner's reviewer account) → S9 (submit): **about ten sessions in total.** Android in parallel: its internal test starts as T2 lands and its closed test as S1 lands. **The first item to build is T1.**

### 2026-10-07 - #137 PR A applied to production after the merge and proven on the live database: the 25 grant lines flipped exactly, the six policies gone, everything else byte-identical, the definer functions and every refusal witnessed inside a transaction that rolled itself back; `public-grants` now a required check

**Row #137 is not edited: the owner's brief for this step allowed Section 7 additions only. Its text still reads "NOT BUILT", which is now true of PR B and PR C and no longer of PR A; the block below supersedes that sentence until the row is rewritten when #137 closes. Outside this file: nothing in the repository; on production, the one file `20261007_public_grants_dead_writes_and_anon.sql`, run in the SQL editor by the agent on the owner's written instruction of 2026-10-07 (the editor's "Potential issue detected" dialog for the DROP POLICY statements confirmed by the agent under that instruction); and on GitHub, `public-grants` added to the required status checks of `main`. Rows 42, 69 and 81 are not touched, and Section 7 takes no deletions.**
Expand Down
Loading
Loading