Repository navigation
Integrate Slide Maker with institutional identity and Gateway - #14
Conversation
|
Root review completed at 5e0d77a. The example issuer defect found during review is fixed: the shipped configuration now uses the canonical /cail-sso issuer, and its test verifies actual signed tokens against that value. Latest hosted CI passed (34181931289). Reviewed the production identity boundary, explicit additive account mapping, preserved local roles/sharing and CUID file paths, Gateway transport and quota display, stream completion/cancellation, UI sign-out, dependency removal and release documentation. No remaining blocking source findings. Independently ran all eight actual Slide Hono/cail-client → pinned Gateway f3a8b3c receiver tests. They passed, covering identity mismatch rejection, catalog/quota, correlated chat, refusal without retry, trailing stream error, cancellation, planning and plan refusal. The Gateway runs under Node with its unused WorkerEntrypoint shimmed; provider, Registry and analytics are fixtures. The owner's mounted Chromium check exercises the actual UI/Hono/SQLite with a controlled edge and Gateway fixture. Neither is a live SSO or paid-provider acceptance claim. This remains PR-only for the repository maintainer. Private Node ingress, verified account linking, backup/migration rehearsal, CI release implementation and deployed sign-in/model/export checks remain explicit rollout requirements. |
Slide Maker currently owns local password sessions and direct provider transports, so it cannot receive CUNY identity or charge model use through the shared Gateway. This change makes the existing Node/Hono application a fleet receiver while preserving its local deck, role, sharing, upload, and normalized mutation behavior.
The source change:
cail:slide-makerand a separate same-subjectcail:gatewayleg, then maps the canonical subject to an operator-verified existing local user ID;@cuny-ai-lab/cail-clientGateway transport for catalog, quota, chat, and planning;Validation on exact head
5e0d77ae1f71236047ae831a52028203921a2f85:bun run check: 720 assertions passed; eight explicit receiver opt-in skips; API/web builds and shell checks passed; Svelte reported 0 errors and 10 existing warnings.f3a8b3cc4b6b8bc99125771da6a907dffbdb07c3: 8/8 tests passed, covering identity mismatches, catalog/quota, chat and planning, refusal without retry, trailing stream failure, correlation, cancellation, and normalized plan application.34181931289passed at the exact PR head, including package installation, tests, and builds.Registry, provider, and browser edge responses are synthetic; the receiver harness uses the actual Gateway source and client but is not a deployed-path test. A supported private transport to the loopback-bound Node process, deployment, live CUNY sign-in/model use, backup/restoration, and mounted DNS/access checks remain release prerequisites.
This is a source-only PR for the Slide Maker maintainer. It does not deploy, mount, migrate production data, alter account access, or make paid provider calls. The existing design reconciliation PR #13 remains separate and unchanged.