Commit Graph
20 Commits
Author SHA1 Message Date
AIOSAIandClaude Opus 4.8 0096aef1d2 feat(telegram): port wave-1 fixes + @api set_secret write-door (DPLAN-0220)
Surfaced by a full completeness audit of the telegram skill against
TELEGRAM_PORT_MAP.md (366 tags, ~83% ported, 452/452 tests green).

@api — in-process set_secret(provider, slug, value, *, as_json) writer
mirroring get_secret (0o600 files / 0o700 dirs, no stdout echo). The store
was read-only; this is the GAP1 enabler the telegram mother-bot needs to
persist a created bot's config. 515 @api tests, seedgo 100%.

@skills telegram wave-1 (fix-forward, no deletions):
- GAP2: bot_factory + telegram-bot@.service launched a non-existent
  ~/.venv/bin/python3; now sys.executable -m ...base_bot (+ lib/__init__.py
  and lib/telegram/__init__.py for package resolution).
- Reboot survival: enable_service now installs the unit to
  ~/.config/systemd/user/ + daemon-reload (was never installed).
- GAP9: gitignore lib/telegram/.local/ so runtime state stops leaking to git.
- prax-monitor: log_streamer now resolves repo-root system_logs (honoring
  AIPASS_TEST_LOG_DIR) instead of a hardcoded ~/system_logs.

Verified: telegram 452/452 green (twice), base_bot imports via -m.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QEQZXCtgnF3NQtcttTErpq
2026-06-24 16:39:08 -07:00
AIOSAIandClaude Opus 4.8 a75910a4e6 fix(api,skills): harden secrets door — no secret value to stdout (DPLAN-0211, clears CodeQL #86-88)
PR #640's only failing required check was Code scanning/CodeQL: 3 HIGH
py/clear-text-logging-sensitive-data alerts where get-secret printed raw secret
values to stdout. Research (OWASP, CodeQL rule source, secret-CLI survey)
confirmed a real exposure — acute for AIPass since it runs inside Claude Code,
which captures command stdout into model context, and the telegram skill
shelled out to get-secret and parsed the token from stdout.

@api (P1):
- NEW apps/modules/secrets.py — in-process cross-branch door (get_secret,
  list_secrets) wrapping the auth handler; consumers import this, not the CLI.
- get_secret_cmd rewritten: masked summary by default ('slug: set (N chars)'),
  --out FILE writes the raw value 0o600 and prints only the path, --list shows
  slug names via console.print. All 3 raw-value print() sinks removed.
- bypass.json reasoning + README + help updated.

@skills (P2):
- telegram config._get_secret / list_bot_configs rewired from subprocess+stdout
  parse to the in-process aipass.api.apps.modules.secrets API; subprocess/json
  imports dropped. Tests + SKILL.md updated.

Also: seedgo test_checkers_batch2.py — comment the synthetic sk-or-v1 fixture
keys as FAKE (not real credentials).

Verified: @api 504 tests + seedgo 100%; telegram 452/452; skills 252/252; no
secret reaches stdout by any path.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 23:45:46 -07:00
AIOSAIandClaude Opus 4.8 392f5d83b0 feat(skills): port Dev-Pass Telegram bridge as self-contained AIPass skill (FPLAN-0277 P1-P3)
P1 @api: get-secret command + auth/secrets.py (reads ~/.secrets/aipass/).
P2 @skills: 14-file bridge (~5300L) + ~424 tests ported to .aipass/skills/telegram/, seams rewired to services (prax logging, @api secrets).
P3 @hooks: telegram_response.py Stop hook (3-layer SubagentStop/sidechain/cursor defense) registered via the hooks engine.
P5 audit (TELEGRAM_PORT_MAP.md, 366 tags): 288 verified, 23 gaps (top conftest log-isolation fixture fixed), 55 live-deferred.
Lint: 5 F841 unused-var autofixes in ported tests. Known gaps + live bring-up (creds, systemd, telethon, round-trip) pending. CI red unrelated; land-only, no merge.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 06:50:15 -07:00
AIOSAI 6da94f8767 docs: update cli, api, memory READMEs with accurate state 2026-05-16 16:57:50 -07:00
AIOSAIandClaude Opus 4.6 f42039dae7 docs(api): comprehensive README update — current state, architecture, contracts
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-04-22 21:23:02 -07:00
AIOSAIand@seedgo 541e5c142a feat(system): feat(seedgo): hook bridge installer — install/uninstall AIPass hooks in settings.json (DPLAN-0141 Phase 2)
Co-Authored-By: @seedgo <seedgo@aipass>
2026-04-22 10:00:27 -07:00
AIOSAIand@devpulse 16b33a6d36 feat(system): S86: APLAN fix sweep — 11 CRITICALs resolved, 35+ BUGs fixed, catch-all loggers, README update
Co-Authored-By: @devpulse <devpulse@aipass>
2026-04-10 14:06:52 -07:00
AIPassand@devpulse 040611d098 feat(system): S85: Restore api branch + gitleaks config (merge sync) (#228)
* feat(system): SECURITY: gitleaks config + pre-commit for API key leak prevention

Co-Authored-By: @devpulse <devpulse@aipass>

* feat(system): S84: Restore api branch to repo — normal branch, gitleaks protection, no real keys outside .secrets

Co-Authored-By: @devpulse <devpulse@aipass>

---------

Co-authored-by: @devpulse <devpulse@aipass>
2026-04-10 10:22:28 -07:00
AIPassand@devpulse 2918960dd1 feat(system): SECURITY: Remove api/ from public repo — key handling test patterns (#223)
Co-authored-by: @devpulse <devpulse@aipass>
2026-04-10 03:43:38 -07:00
AIOSAIand@devpulse 316345a130 feat(devpulse): API branch reinstate.
Co-Authored-By: @devpulse <devpulse@aipass>
2026-04-10 00:39:01 -07:00
AIPassand@devpulse 8471c4c732 feat(system): feat(system): S82: core 10 split — remove daemon/commons/skills, README 10 agents, Herald updated, spawn CWD-aware sync (#207)
Co-authored-by: @devpulse <devpulse@aipass>
2026-04-09 18:34:13 -07:00
AIOSAIand@devpulse 9b5b7f1cc8 feat(system): S80: 14-branch state audit + README Round 7 (flow/memory lifecycle, transparency) + dist/ gitignore
Co-Authored-By: @devpulse <devpulse@aipass>
2026-04-08 01:32:40 -07:00
AIOSAIand@devpulse 289c0df5ff feat(system): Nav links across 15 branch READMEs, CONTRIBUTING.md, devpulse branch prompt update
Co-Authored-By: @devpulse <devpulse@aipass>
2026-04-06 14:52:06 -07:00
AIPassand@devpulse 3b4126b0bb feat(system): Issue templates: simplified bug report + new feedback form (#196)
Co-authored-by: @devpulse <devpulse@aipass>
2026-04-06 11:37:39 -07:00
AIPassand@devpulse 6194c751dc feat(system): README overhaul + HERALD update + S73 test files (#182)
* feat(system): feat(system): FPLAN-0164 dispatch safety net + morning briefing timeout fix

Co-Authored-By: @devpulse <devpulse@aipass>

* feat(system): fix(drone+backup): resolver BranchNotFoundError handling + backup snapshot quick-check

Co-Authored-By: @devpulse <devpulse@aipass>

* feat(system): fix(ai_mail): test fix for JSONL-based startup detection in dispatch_monitor

Co-Authored-By: @devpulse <devpulse@aipass>

* feat(system): feat(daemon): expand test coverage from 12% — 74 new tests for scheduler_cron and actions

Co-Authored-By: @devpulse <devpulse@aipass>

* feat(system): S73 night shift: test coverage push to 100% + seedgo test depth fixes

Co-Authored-By: @devpulse <devpulse@aipass>

* feat(system): README overhaul + HERALD update + S73 test files

Co-Authored-By: @devpulse <devpulse@aipass>

---------

Co-authored-by: @devpulse <devpulse@aipass>
2026-04-05 11:36:21 -07:00
b72e720f00 feat: seedgo cert sprint — 10 branches, drone introspection rebuilt (#118)
* feat(seedgo): deep nesting bypasses, dead code cleanup, json structure compliance

Co-Authored-By: @seedgo <seedgo@aipass>

* feat(memory): seedgo certification: introspection fixes, subprocess bypasses, silent catch cleanup

Co-Authored-By: @memory <memory@aipass>

* feat(api): seedgo certification: 94%→97%, 31/33 standards at 100%

Co-Authored-By: @api <api@aipass>

* feat(seedgo): deep nesting 100%, limit 3→4, checker refactors, @ validation, bypass cleanup

Co-Authored-By: @seedgo <seedgo@aipass>

* feat: seedgo cert sprint — 10 branches dispatched, drone introspection rebuilt, system-wide compliance push

Session 49-50 cert sprint results:
- drone: introspection rebuilt (proper auto-discovery), silent_catch 92%→100%, overall 97%
- api: 94%→97%, json_handler fixed, PR #116
- backup: 93%→94%, json_handler load_template→inline
- memory: 88%→91%, introspection 79%→100%, 10 bypasses for subprocess files
- skills: 97%, json_structure→100%, introspection→100%
- spawn: 97%→99%, 32/34 standards at 100%
- ai_mail: 95%→97%, 12 unused functions removed, 32/34 at 100%
- seedgo: checker improvements (deep_nesting threshold 3→4, various fixes)
- drone: removed from _MODULE_REGISTRY (DPLAN-0053 consensus)
- commons: introspection bypasses (22 entries), python3→drone refs fixed
- trigger/cli/prax/daemon/flow/backup: various cert fixes

New DPLANs: 0053 (drone audit), 0054 (bypass tracker), 0055 (persistent git branches)
New FPLAN: 0134 (persistent citizen git branches — drone build)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: @seedgo <seedgo@aipass>
Co-authored-by: @memory <memory@aipass>
Co-authored-by: @api <api@aipass>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-24 01:31:56 -07:00
AIPassand@api 9ab96013e7 feat(api): Google provider module — centralized external API gateway (#43)
Add Google API authentication and service factory as the first
non-LLM provider in API's evolution to centralized external service
gateway (DPLAN-0036).

New handlers: google/auth.py (OAuth2 lifecycle), google/service_factory.py
(single + thread-safe service objects), google/retry.py (SSL retry).
New module: google_client.py with get_drive_service(), get_google_service(),
validate_google(), reauth_google() public API.

New commands: drone @api validate google, drone @api reauth google.
Credentials at ~/.secrets/aipass/ (cross-platform standard).

Co-authored-by: @api <api@aipass>
2026-03-14 23:07:00 -07:00
AIOSAIandClaude Opus 4.6 babedd9c64 feat(system): seedgo v2 operational, full system audit, 14/15 branches at 99%
Three days of intensive work bringing seedgo to full operational status
and driving all branches through comprehensive standards compliance.

Seedgo v2.0.0:
- 22 checkers active (up from 20), standards pack fully operational
- New introspection standard researched from Dev-Pass, FPLAN-0017 open
- Bypass system for false positives (.seedgo config)
- Standards query and audit commands fully functional

System-wide audit (FPLAN-0016):
- All 14 auditable branches at 99%+ compliance
- CLI imports standardized across all branches (console from cli.apps.modules)
- handle_command(command, args) → bool contract added to all modules
- print_help() function naming fixed for checker pattern matching
- Handler extraction: large modules split, file I/O moved to handler layer
- New handlers created across ai_mail, backup, daemon, flow, skills, spawn, seedgo

Branch-specific highlights:
- ai_mail: email.py split 840→420 lines, 4 new handlers
- flow: dplan_flow.py 688→591 lines, 4 new handlers
- seedgo: massive restructure — standards moved to handlers/aipass_standards/,
  old standards/ tree removed, bypass system added, diagnostics module
- commons: database module added, CLI imports fixed
- skills: 5 handle_commands added, help function renamed
- trigger: error reporter handler, handle_command routing
- All branches: consistent architecture, clean drone routing

Culture doc (CLAUDE.md) added — documents AIPass philosophy, identity,
memory system, and collaboration principles.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-10 01:26:42 -07:00
AIOSAIandClaude Opus 4.6 3b45824dc6 FPLAN-0410 repo cleanup + integration test bug fixes
VERA cleanup (FPLAN-0410):
- Remove all /home/aipass hardcoded paths (portability)
- Remove internal Telegram bot code from public repo (6k+ lines)
- Remove runtime logs, .claude/settings.local.json, stale files
- Clean READMEs across all branches
- Restructure spawn handlers into proper 3-layer architecture
- Add __init__.py files for proper package imports
- Update seedgo standards for public repo context
- Add log_structure standard to seedgo

Integration test bug fixes:
- Fix double @@ display in drone introspection output
- Fix spawn registry resolving to wrong file (walk up from package root)
- Fix email sender identity always showing as @ai_mail (pass AIPASS_CALLER_CWD)
- Fix branch_detection.py relative path resolution against CWD instead of registry dir
- Add .trinity/passport.json detection for spawned agents
- Archive duplicate json_ops.py, update imports to canonical json_handler
- Update .gitignore for runtime logs and .claude/ dirs

Tested end-to-end in Docker container (aipass-test:latest):
- Spawn → register → send email → receive → reply all verified working

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-06 15:29:16 -08:00
AIOSAI 019a69141e update 1 file, create 421 files and delete 4 files 2026-03-05 15:22:59 -08:00