Skip to content

Integrate Slide Maker with institutional identity and Gateway - #14

Merged
szweibel merged 2 commits into
mainfrom
codex/slide-maker-fleet-integration-20260908
Sep 24, 2026
Merged

szweibel merged 2 commits into
mainfrom
codex/slide-maker-fleet-integration-20260908

Conversation

@szweibel

@szweibel szweibel commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Slide Maker currently owns local password sessions and direct provider transports, so it cannot receive CUNY identity or charge model use through the shared Gateway. This change makes the existing Node/Hono application a fleet receiver while preserving its local deck, role, sharing, upload, and normalized mutation behavior.

The source change:

  • verifies an app identity for cail:slide-maker and a separate same-subject cail:gateway leg, then maps the canonical subject to an operator-verified existing local user ID;
  • disables password authentication in production, keeps it for local development, and sends production sign-out through Doorway;
  • replaces direct Anthropic, Bedrock, and OpenRouter calls with the pinned @cuny-ai-lab/cail-client Gateway transport for catalog, quota, chat, and planning;
  • makes one model attempt, propagates cancellation and correlation, consumes streams through clean EOF including trailing usage/error frames, and displays safe support IDs;
  • retains local product roles, sharing, existing CUID upload paths, SQLite data, and historical usage records without using them to authorize current model work;
  • adds private readiness, additive identity-mapping scripts, mounted-path support, and a release proposal for the unresolved private Node transport.

Validation on exact head 5e0d77ae1f71236047ae831a52028203921a2f85:

  • bun run check: 720 assertions passed; eight explicit receiver opt-in skips; API/web builds and shell checks passed; Svelte reported 0 errors and 10 existing warnings.
  • Actual Hono caller → frozen CAIL Gateway f3a8b3cc4b6b8bc99125771da6a907dffbdb07c3: 8/8 tests passed, covering identity mismatches, catalog/quota, chat and planning, refusal without retry, trailing stream failure, correlation, cancellation, and normalized plan application.
  • Mounted Chromium scenario: passed sign-in, existing deck/file/thumbnail access, persisted editing, catalog/quota display, refusal support ID, cancellation, and institutional logout against the actual UI/Hono/SQLite application with controlled edge and Gateway fixtures.
  • Independent final review found no actionable issues and confirmed both earlier findings were fixed.
  • Hosted CI run 34181931289 passed at the exact PR head, including package installation, tests, and builds.

Registry, provider, and browser edge responses are synthetic; the receiver harness uses the actual Gateway source and client but is not a deployed-path test. A supported private transport to the loopback-bound Node process, deployment, live CUNY sign-in/model use, backup/restoration, and mounted DNS/access checks remain release prerequisites.

This is a source-only PR for the Slide Maker maintainer. It does not deploy, mount, migrate production data, alter account access, or make paid provider calls. The existing design reconciliation PR #13 remains separate and unchanged.

@szweibel

szweibel commented Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

Root review completed at 5e0d77a. The example issuer defect found during review is fixed: the shipped configuration now uses the canonical /cail-sso issuer, and its test verifies actual signed tokens against that value. Latest hosted CI passed (34181931289).

Reviewed the production identity boundary, explicit additive account mapping, preserved local roles/sharing and CUID file paths, Gateway transport and quota display, stream completion/cancellation, UI sign-out, dependency removal and release documentation. No remaining blocking source findings.

Independently ran all eight actual Slide Hono/cail-client → pinned Gateway f3a8b3c receiver tests. They passed, covering identity mismatch rejection, catalog/quota, correlated chat, refusal without retry, trailing stream error, cancellation, planning and plan refusal. The Gateway runs under Node with its unused WorkerEntrypoint shimmed; provider, Registry and analytics are fixtures. The owner's mounted Chromium check exercises the actual UI/Hono/SQLite with a controlled edge and Gateway fixture. Neither is a live SSO or paid-provider acceptance claim.

This remains PR-only for the repository maintainer. Private Node ingress, verified account linking, backup/migration rehearsal, CI release implementation and deployed sign-in/model/export checks remain explicit rollout requirements.

@szweibel
szweibel merged commit 63e9e6e into main Sep 24, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant