Conversation
…Nexora into impl/m01-s00-scaffold
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current handoff — code-only local Release 1 continuation
PR #4 remains open and unmerged on
impl/m01-s00-scaffoldtargetingmain.99db64e2ab07a202ddd4fde1d5ce2b756879a2d8(handoff documentation commit).e42516e2360ad2afd7d8a0144412a15086770983.a3a0a7b84a124a8a9063d35d65641119e2824718; commits after it are documentation-only.DEC-20260909-014permits slice-by-slice local implementation. Production deployment, public launch, real providers/OAuth/secrets/user data, paid services and external destructive actions remain disabled.Read the continuation handoff first when resuming.
Completed blocker and contract fixes
[identity].[MfaCredential]; MFA-enabled reset fails closed asMfaRecoveryRequiredbefore password, security-stamp or session mutation.apiFetchcapturesX-CSRF-Tokenfrom every successful response, preserving login CSRF rotation for the next mutation.Idempotency-Keythrough the existing JSON mutation headers; global CSRF/idempotency filters remain enabled./health/liveis process-only;/health/readyrequires SQL, migration journal, required migrations through0020, and bootstrap/security invariant, with coarse non-secret failure responses.NEXORA_IDEMPOTENCY_SECRET, account/securityNOLOCKremoval and stale catalog wording were hardened.20260910_0019_productivity_contract_alignment.sqland20260910_0020_task_calendar_projection.sqlare included.Traceability and evidence
The matrix distinguishes documented catalog, locally implemented, runtime-available, partial, not implemented, blocked, paused and not-run evidence. Documentation/action contracts are not runtime proof.
Verification
Pass
34508111597/ run149, passed:bash scripts/dev/verify.shdotnet build src/Nexora.Api/Nexora.Api.csproj --configuration Releasedotnet build src/Nexora.Bootstrap/Nexora.Bootstrap.csproj --configuration Releasedotnet run --project tests/Nexora.UnitTests/Nexora.UnitTests.csproj --configuration Release— 24 tests, 0 failednpm ci --prefix web/Nexora.Webnpm run build --prefix web/Nexora.Web34508111463/ run166: Pass.git diff --check: Pass.Not run / not claimed
bash scripts/dev/verify.sh: Not run because Windows WSL/Bash creation returnedE_ACCESSDENIED; CI command passed.NEXORA_TEST_SQL_CONNECTION, readiness runtime and SQL isolation/lifecycle checks: Not run.Remaining status
The matrix remains Partial, Not implemented, Blocked, Paused or Not run for many committed R1 areas. Sharing/support/emergency, files/import-export/backup, reminders/planner/habits/time tracking/Pomodoro, advanced document hierarchy/import-export/version restore, advanced finance/Vault, News/shopping/GitHub/monitoring/assets/career/learning and other vertical slices still require contracted implementation. FX30/FX34/FX35 remain provider-gated. FX11–FX13 still need SQL/browser evidence and remaining ICS, DST/all-day and aggregate-restore coverage.
Do not label this PR “R1 complete”, “Accepted”, “Runtime verified” or production-ready. Do not merge PR #4 in this continuation.