Skip to content

Make synthetic agent preview read-only and verify legacy upgrades - #359

Merged
dinpd merged 1 commit into
mainfrom
codex/358-readonly-preview
Oct 8, 2026
Merged

dinpd merged 1 commit into
mainfrom
codex/358-readonly-preview

Conversation

@dinpd

@dinpd dinpd commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Closes #358.

Summary

  • Mark the synthetic localhost workflow preview read-only, present fixture viewer access, keep a visible desktop/mobile notice and link to the live console without synthetic workspace identifiers.
  • Disable mutations through the existing viewer UI and explain HTTP 405 responses rather than returning an empty error. Keep inspection, filters, refresh and workspace switching usable.
  • Document supported legacy runtimes and the explicit scanner upgrade path; do not delete compatibility code or unidentified live agents.
  • Prove both legacy scanner formats upgrade without changing historical evidence, carry no old activation approval forward, cancel pending trials without tool/model/delivery effects, and require a fresh successful trial before reactivation.

Acceptance And Security Evidence

  • Console suite: 341 passing tests; final extended legacy upgrade case: all 26 research tests pass.
  • Workflow-inspector browser acceptance passes twice on installed Chrome, desktop 1440x1050 and mobile 390x844; viewport screenshots inspected. Covers read-only labeling, disabled mutations, retained inspection, tenant switching, keyboard access, legacy gaps, zero inspection writes, and descriptive direct-POST rejection.
  • Existing research browser acceptance passes (save/reload, connection consent, approvals, reports, activation, pause, mobile).
  • Console Wrangler dry run passes; production dependency audit reports zero vulnerabilities; git diff --check passes.
  • Reviewed all changes for credentials, accidental live data, permissions, fixture isolation and CSP. Preview styling is appended to the same-origin test stylesheet, without weakening production CSP. No production runtime/UI/auth/schema, dependencies or live workspace records changed. No human acceptance required for these programmatically proven criteria; no live trial was attempted.

Release Impact

No release: test-only synthetic preview and compatibility regression coverage plus documentation. The supported production surface is unchanged; v0.48.0-rc.1 remains the product version.

Operational Follow-Up

Restart the owned localhost preview on port 8794 after merge so existing tabs receive the updated fixture. Live legacy cleanup is not performed: identify exact affected agents and their failure first, prefer reversible pause, and preserve retained run evidence.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T16:10:09.647200Z ee2af3d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@dinpd
dinpd merged commit dd2cabc into main Oct 8, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Make synthetic agent preview explicitly read-only and verify legacy upgrade preservation

1 participant