docs: post-convoy cleanup for drop-public-setup #14

Merged
varutasu merged 1 commit from docs/drop-public-setup-cleanup into main 2026-05-23 18:06:35 -04:00
varutasu commented 2026-05-23 18:04:59 -04:00 (Migrated from github.com)

Summary

Post-merge documentation cleanup for the just-shipped drop-public-setup convoy (PR #13, P0 #3). Small focused pass; no behavior changes.

3 files, +13/-5 lines:

  • AGENTS.md
    • § 1 auth bullet — replace "seed admin row still ships in setup-neon-db.js" with the new env-var-gated reality + R1 operator-rotation caveat
    • § 4 Gotcha #4 — mark RESOLVED with commit refs (ff80753 + b63b509), document as-shipped behavior, Brief 2's CJS→ESM Node 22.x fix, and the R1 operator caveat. Entry kept (not renumbered) per the same convention used for resolved gotchas #2, #3, #5.
    • § 5 Running locally — add ADMIN_INITIAL_PASSWORD to env-var template list with a note that setup-db exits 1 if it's unset
  • .convoys/ship-readiness.md
    • P0 #3 — mark RESOLVED 2026-05-23 with commit refs, document full as-shipped behavior including Brief 2's CJS→ESM bonus, R1 caveat (Decision A — going-forward only), and deferred sibling weak-cred references queued for purge-weak-creds-from-helpers
  • .cursor/rules/no-go-zones.mdc
    • Editing rules of thumb — clarify the schema-vs-operational distinction for scripts/setup-neon-db.js. drop-public-setup set the precedent that operational changes (env-var gating, pre-flight validation, module-system fixes) are allowed in place, while DDL changes still need a separate migration script. Future agents shouldn't have the same Decision-B confusion the architect did.

What did NOT change

  • package.json, package-lock.json
  • lib/**, pages/**, components/**, scripts/**
  • .github/**
  • README.md — already updated in PR #13
  • .cursor/rules/auth-and-permissions.mdc, .cursor/rules/api-routes.mdc — these were updated in the fix-auth-bypass doc-writer pass (PR #12); nothing new for drop-public-setup to add there
  • .cursor/rules/db-and-schema.mdc — its mention of setup-neon-db.js ("bootstrap DDL — idempotent") is still accurate; no change

Test plan

  • Read AGENTS.md rendering on GitHub — confirm Gotcha #4's RESOLVED block reads cleanly alongside the existing #2/#3/#5 entries
  • Read .convoys/ship-readiness.md P0 #3 — confirm RESOLVED block + R1 caveat are visible
  • Confirm .cursor/rules/no-go-zones.mdc schema-vs-operational distinction is clear

🤖 Generated with Cursor

Made with Cursor

## Summary Post-merge documentation cleanup for the just-shipped `drop-public-setup` convoy (PR #13, P0 #3). Small focused pass; no behavior changes. **3 files, +13/-5 lines:** - **`AGENTS.md`** - § 1 auth bullet — replace "seed admin row still ships in setup-neon-db.js" with the new env-var-gated reality + R1 operator-rotation caveat - § 4 Gotcha #4 — mark **RESOLVED** with commit refs (`ff80753` + `b63b509`), document as-shipped behavior, Brief 2's CJS→ESM Node 22.x fix, and the R1 operator caveat. Entry kept (not renumbered) per the same convention used for resolved gotchas #2, #3, #5. - § 5 Running locally — add `ADMIN_INITIAL_PASSWORD` to env-var template list with a note that setup-db exits 1 if it's unset - **`.convoys/ship-readiness.md`** - P0 #3 — mark **RESOLVED 2026-05-23** with commit refs, document full as-shipped behavior including Brief 2's CJS→ESM bonus, R1 caveat (Decision A — going-forward only), and deferred sibling weak-cred references queued for `purge-weak-creds-from-helpers` - **`.cursor/rules/no-go-zones.mdc`** - Editing rules of thumb — clarify the schema-vs-operational distinction for `scripts/setup-neon-db.js`. `drop-public-setup` set the precedent that operational changes (env-var gating, pre-flight validation, module-system fixes) are allowed in place, while DDL changes still need a separate migration script. Future agents shouldn't have the same Decision-B confusion the architect did. ## What did NOT change - `package.json`, `package-lock.json` - `lib/**`, `pages/**`, `components/**`, `scripts/**` - `.github/**` - `README.md` — already updated in PR #13 - `.cursor/rules/auth-and-permissions.mdc`, `.cursor/rules/api-routes.mdc` — these were updated in the `fix-auth-bypass` doc-writer pass (PR #12); nothing new for `drop-public-setup` to add there - `.cursor/rules/db-and-schema.mdc` — its mention of `setup-neon-db.js` ("bootstrap DDL — idempotent") is still accurate; no change ## Test plan - [ ] Read `AGENTS.md` rendering on GitHub — confirm Gotcha #4's RESOLVED block reads cleanly alongside the existing #2/#3/#5 entries - [ ] Read `.convoys/ship-readiness.md` P0 #3 — confirm RESOLVED block + R1 caveat are visible - [ ] Confirm `.cursor/rules/no-go-zones.mdc` schema-vs-operational distinction is clear 🤖 Generated with [Cursor](https://cursor.com) Made with [Cursor](https://cursor.com)
vercel[bot] commented 2026-05-23 18:05:04 -04:00 (Migrated from github.com)

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
tcg-vault Ready Ready Preview, Comment May 23, 2026 10:05pm

Request Review

[vc]: #MUVe/zWBjZnC5gbCsgqTVARSZcyHccOC4pLLVhHBhe0=:eyJpc01vbm9yZXBvIjp0cnVlLCJ0eXBlIjoiZ2l0aHViIiwicHJvamVjdHMiOlt7Im5hbWUiOiJ0Y2ctdmF1bHQiLCJwcm9qZWN0SWQiOiJwcmpfRjZXOEVvRkd3Y0g3aWVGcnRvRlNlOXdVVkFhNSIsImxpdmVGZWVkYmFjayI6eyJyZXNvbHZlZCI6MCwidW5yZXNvbHZlZCI6MCwidG90YWwiOjAsImxpbmsiOiJ0Y2ctdmF1bHQtZ2l0LWRvY3MtZHJvcC1wdWJsLTRjMDA3Yi1yYW5kYWxsLXN0aWxsd2VsbHMtcHJvamVjdHMudmVyY2VsLmFwcCJ9LCJpbnNwZWN0b3JVcmwiOiJodHRwczovL3ZlcmNlbC5jb20vcmFuZGFsbC1zdGlsbHdlbGxzLXByb2plY3RzL3RjZy12YXVsdC80cG5BS242RG94TVE1Z3BZSmhSbzV0VkxkRFJxIiwicHJldmlld1VybCI6InRjZy12YXVsdC1naXQtZG9jcy1kcm9wLXB1YmwtNGMwMDdiLXJhbmRhbGwtc3RpbGx3ZWxscy1wcm9qZWN0cy52ZXJjZWwuYXBwIiwibmV4dENvbW1pdFN0YXR1cyI6IkRFUExPWUVEIn1dLCJyZXF1ZXN0UmV2aWV3VXJsIjoiaHR0cHM6Ly92ZXJjZWwuY29tL3ZlcmNlbC1hZ2VudC9yZXF1ZXN0LXJldmlldz9vd25lcj12YXJ1dGFzdSZyZXBvPXRjZy12YXVsdCZwcj0xNCJ9 The latest updates on your projects. Learn more about [Vercel for GitHub](https://vercel.link/github-learn-more). | Project | Deployment | Actions | Updated (UTC) | | :--- | :----- | :------ | :------ | | [tcg-vault](https://vercel.com/randall-stillwells-projects/tcg-vault) | ![Ready](https://vercel.com/static/status/ready.svg) [Ready](https://vercel.com/randall-stillwells-projects/tcg-vault/4pnAKn6DoxMQ5gpYJhRo5tVLdDRq) | [Preview](https://tcg-vault-git-docs-drop-publ-4c007b-randall-stillwells-projects.vercel.app), [Comment](https://vercel.live/open-feedback/tcg-vault-git-docs-drop-publ-4c007b-randall-stillwells-projects.vercel.app?via=pr-comment-feedback-link) | May 23, 2026 10:05pm | <a href="https://vercel.com/vercel-agent/request-review?owner=varutasu&repo=tcg-vault&pr=14" rel="noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://agents-vade-review.vercel.sh/request-review-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://agents-vade-review.vercel.sh/request-review-light.svg"><img src="https://agents-vade-review.vercel.sh/request-review-light.svg" alt="Request Review"></picture></a>
github-actions[bot] commented 2026-05-23 18:05:08 -04:00 (Migrated from github.com)

Pipeline Health

Build + CI gates

Gate Status
Vercel build (Preview) pass
CI: Lint pass
CI: Schema map fresh skipped
Preview smoke failure
Visual diff ⏭ skipped or pending

Build runs on Vercel; this CI runs lint and schema-map drift only (no duplicate build).

Role reports

Role Status
Reviewer report pending
A11y audit pending
Design system audit pending

See individual comments above for details. This rollup updates automatically.

<!-- pipeline-rollup --> ## Pipeline Health ### Build + CI gates | Gate | Status | | --- | --- | | Vercel build (Preview) | ✅ pass | | CI: Lint | ✅ pass | | CI: Schema map fresh | ❌ skipped | | Preview smoke | ❌ failure | | Visual diff | ⏭ skipped or pending | _Build runs on Vercel; this CI runs lint and schema-map drift only (no duplicate build)._ ### Role reports | Role | Status | | --- | --- | | Reviewer report | ⏳ pending | | A11y audit | ⏳ pending | | Design system audit | ⏳ pending | See individual comments above for details. This rollup updates automatically.
Sign in to join this conversation.
No description provided.