feat/discovery
needs attentionviewing older commit4bdb2c9 · incrementalPR #305reviewed 2026-07-21 23:22 UTC1H · 3M · 5L · 5I- Purpose
- Feature Discovery v1 — ambient spotlights + Descubre hub + first-run guided product tour for existing users, flag-gated (feature-discovery-spotlights, OFF by default).
- Goal
- Contextual coachmarks for unused capabilities, self-serve Descubre hub, 5-step first-run product tour. FCIS-compliant, RLS-enforced, PostHog analytics.
- Sub-goals
- Ambient spotlight computation (pure decision, rolling-day pacing)
- Descubre hub (header badge + gap list)
- First-run product tour (5 steps, dimmed scrim)
- discovery_state table (profile-scoped RLS, migration 0063)
- Adversarial review + fixes applied (Host→VERCEL_ENV, spotlight latch, atomic upsert)
- What
- Merge from main: renumber discovery_state migration 0062→0063, bring in energia findings API (finding.contract/handler/schemas), add energia sidebar nav, add prod Supabase MCP server.
- Why
- Main's migration 0062 (sloppy_ma_gnuci) conflicted with this branch's; resolved by renaming to 0063.
- Areas
- apps/platform+2542−52domains/cross-domain+1604−0domains/core+498−0packages/secrets+152−12packages/database+138−1packages/api+103−0packages/analytics+98−0e2e/platform+61−0
- Blast
- 65 files +5232/-66 cumulative. Flag-gated — zero user impact until PostHog flag created.
Findings · 15
correctness3
Migration renamed 0062→0063 via git mv, not drizzle-kit regeneration
packages/database/drizzle/0063_discovery_state.sql
Zero lines changed. Bare CREATE POLICY statements not idempotency-wrapped — double-apply would abort mid-file.
Bare CREATE POLICY statements not idempotency-wrapped
packages/database/drizzle/0063_discovery_state.sql
Wrap in DO $$ BEGIN ... EXCEPTION WHEN duplicate_object THEN null; END $$; per migrations.md.
list contract declares 404 but handler never returns it
apps/platform/src/api/contracts/finding.contract.ts
Dead 404 misleads ts-rest client type inference.
security3
.mcp.json git-tracked — prod Supabase project ref in repo history
.mcp.json
Force-added file commits prod project_ref (tljxdspuxeyscdhbbzkn) to history. read_only=true is advisory server-side only. Fix: git rm --cached, move to .env.local.
discovery_state: no DELETE for authenticated — intentional
packages/database/drizzle/0063_discovery_state.sql
Platform admin bypass is JWT-grounded and intentional
apps/platform/src/api/handlers/finding.handler.ts
conventions5
finding.contract missing 500 response declaration
apps/platform/src/api/contracts/finding.contract.ts:40
Declares 200/400/401/403/404 but no 500. ts-rest collapses undeclared codes. Add JSendFailSchema(['INTERNAL_ERROR']).
Handler calls queries directly (SG-19 justified)
apps/platform/src/api/handlers/finding.handler.ts:58
Canonical rule deviation; documented SG-19 exception for contract-anchored tables with no org_id.
fnd_ prefix not in utility CLAUDE.md or ontology
domains/utility/CLAUDE.md
FCIS entity structure fully compliant
domains/utility/src/finding/
Static/parametric route ordering correct
apps/platform/src/app/api/[...ts-rest]/route.ts
tests2
No handler-level test for 403 path (ensureModuleEntitled rejection)
apps/platform/src/api/handlers/finding.handler.ts
Test coverage solid: finding integration, contract, energia nav, discovery_state
improvement2
Missing trailing newlines in .mcp.json and 0063_discovery_state.sql
.mcp.json
disabled prop evaluates to false not undefined for non-greyed nav items
apps/platform/src/components/DashboardSidebar.tsx
History · 36 commits
- c1fe7b7needs attentionincremental3H · 4M · 3L2026-07-27 06:02
- 414db56safeincremental0H · 0M · 2L2026-07-23 00:52
- ea68968needs attentionincremental0H · 4M · 7L2026-07-22 23:01
- 4bdb2c9needs attentionincremental1H · 3M · 5L2026-07-21 23:22current
- 6e3f255safeincremental0H · 0M · 0L2026-07-20 16:46
- cc41079blockedincremental5H · 5M · 3L2026-07-20 16:25
- 2451ee0needs attentionincremental0H · 5M · 6L2026-07-20 16:09
- ab7c103needs attentionincremental0H · 1M · 6L2026-07-20 15:52
- 7eff611needs attentionincremental0H · 1M · 2L2026-07-18 00:41
- 246c67csafeincremental0H · 0M · 0L2026-07-17 23:58
- 7521b17safeincremental0H · 0M · 0L2026-07-17 23:35
- 1847ec8needs attentionincremental0H · 2M · 4L2026-07-17 23:28
- 5d3175cneeds attentionincremental3H · 6M · 4L2026-07-17 19:31
- d3f875dneeds attentionincremental1H · 2M · 4L2026-07-17 18:01
- 47d25faneeds attentionincremental1H · 1M · 2L2026-07-17 00:46
- 440d838needs attentionincremental4H · 9M · 9L2026-07-17 00:27
- 7466f97needs attentionincremental0H · 1M · 5L2026-07-16 23:20
- b686d58needs attentionincremental0H · 2M · 2L2026-07-16 14:24
- 9ea1446blockedincremental2H · 7M · 10L2026-07-16 13:44
- 6f39bb9needs attentionincremental0H · 2M · 7L2026-07-14 21:53
- 2eadf2aneeds attentionincremental0H · 1M · 2L2026-07-14 20:12
- 97bd08fneeds attentionincremental0H · 2M · 5L2026-07-14 19:40
- a48e3ffneeds attentionincremental5H · 8M · 6L2026-07-14 18:22
- 69473b7needs attentionincremental2H · 5M · 3L2026-07-14 01:34
- 92e4235needs attentionincremental2H · 1M · 3L2026-07-14 01:04
- 6be8018safeincremental0H · 0M · 3L2026-07-14 00:15
- 090b4daneeds attentionincremental1H · 3M · 5L2026-07-13 23:50
- fa7683bneeds attentionincremental1H · 4M · 3L2026-07-13 18:55
- d64cd72needs attentionincremental2H · 3M · 2L2026-07-13 16:27
- c1f337bneeds attentionincremental3H · 7M · 14L2026-07-13 13:30
- 46e32b2safeincremental0H · 0M · 3L2026-07-11 02:54
- 3b30949needs attentionincremental0H · 2M · 3L2026-07-11 02:39
- 9f8dbdfneeds attentionincremental3H · 5M · 5L2026-07-11 02:32
- 23191eeneeds attentionincremental5H · 12M · 7L2026-07-11 02:18
- fa9b88fneeds attentionincremental0H · 1M · 2L2026-07-11 01:30
- 6a8bf42blockedfull8H · 11M · 8L2026-07-11 01:08