Skip to content

CodeMower.com: implement the frozen Slack telemetry contract and fresh views #978

Description

@jeffhuber

Part of Slack epic #903 and roadmap #900. This is the hosted counterpart to #921, keeping one independently reviewable PR per repository boundary.

Scope / PR mapping

One PR in the authorized CodeMower.com repository: implement hosted validation, ingest, aggregation/dashboard mapping, and export/deletion/retention for the exact versioned Slack telemetry contract frozen by OSS #921. Preserve old client behavior. Publish only a sanitized cross-repository status in this public tracker; private repository/PR bindings and operational data stay in the authorized private record.

#921 owns the closed schema, OSS emitters/local Slack-to-Board mapping, and shared fixtures. This issue owns the server implementation and deployment. New hosted fields must be accepted here before production emission is enabled; server rollout precedes client emission. Board v1.4.2 adds no cloud fields.

Acceptance criteria

  • Hosted validators pass the same approved contract fixtures as Slack: freeze telemetry contract and implement OSS Board/cloud emitters #921 and reject unknown/disallowed fields without logging private input.
  • Old clients remain compatible, new client emission is capability/version gated, and rollback does not lose accepted metadata or widen the schema.
  • A canary receipt confirms storage separately from a freshly observed authenticated aggregate/dashboard view.
  • Export, deletion, retention, revocation, and tenant isolation cover the new metadata with no private Slack/provider/task content.
  • No task, answer, source, diff, prompt, message, response URL, Slack identity, provider reference, token, personal path, or graph/context data is accepted as telemetry.
  • Exact hosted PR/head, independent review, CI/gate equivalent, deployment revision, and sanitized canary evidence are linked in the epic; public/private provenance follows repository policy.

Dependencies and target

Requires the #921 contract and fixtures. Existing-event aggregate diagnosis #974 informs verification; this issue does not duplicate that diagnosis. Required before #922 and final #923. Code Mower OSS and hosted mutations are separate PRs and separately reviewed.

Planned builder: Code Mower Claude. Planned independent reviewer: Code Mower Codex, subject to actual contributor exclusion.

Delivery and evidence

One independently reviewable implementation PR in the repository named below; one named Code Mower builder and one writer per branch. Record the PR, exact head, contributing builder lineage, independent eligible reviewer verdict, focused and relevant regression tests, CI, authoritative code-mower/gate, and outcome. Resolve all P0/P1/P2 findings before merge. Re-review every changed head. An implementation provider never acquires orchestration or merge authority by being selectable. Keep source, diffs, prompts, messages, private context, identities, provider references, raw output, credentials, and personal paths out of public evidence and cloud reporting.

Planned builder assignments are scheduling proposals, not active sessions. Paid canaries require an explicit campaign-wide cap and stable private bindings; no uncertain automatic retry and no new recovery allowance is implied by this issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions