Conversation
Entry 16 removed the browser client's audience: with no hosted relay, only someone self-hosting the full-stack image could reach it. It had also never been exercised by a browser, and every wire change planned for 0.4.0 would have had to be carried through it untested. Gone: `web/`, `crypto-wasm/`, the relay's `/` and `/assets` routes, CORS and `DROP_ALLOWED_ORIGINS`, `Dockerfile.fullstack`, the `web` CI job, npm in dependabot, and `.cargo/config.toml`'s wasm rustflag. `GET /` now answers 404 with one line saying what the host is. CodeQL analyses Rust instead of the TypeScript that no longer exists. The relay stays. `--transport relay` is what works on a network that lets no UDP out, and netlab covers that. The rules about what a browser transfer may be called stay too, marked dormant, since they bind any future browser client. Found on the way: `Dockerfile` has not built since the envelope moved into its own crate. It copied the CLI's manifest but not `crypto/`, so cargo could not load the workspace. Reproduced by copying exactly the Dockerfile's files into a scratch directory, and fixed there with `--release --locked`. Recorded as decisions entry 17; entry 11 is marked superseded. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G7Fy45hUvna94cd79WKG8S
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
It does not. The relay repeats the few envelope constants it enforces, and cli/tests/protocol.rs fails if a copy drifts. architecture.md said otherwise, and the removal carried that claim into the Dockerfile, two manifest comments, lib.rs and decisions entry 17. The Dockerfile change itself stands: cargo needs crypto/ because it is a workspace member and the CLI's path dependency. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G7Fy45hUvna94cd79WKG8S
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01G7Fy45hUvna94cd79WKG8S
This was referenced Sep 15, 2026
Merged
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Browser client removal, phases 1–4, recorded as
decisions.mdentry 17. Stacked on #68. This needs your review, and two repository settings changes when it merges (below).Removed
web/andcrypto-wasm/(about 4,500 lines), plus the workspace member and.cargo/config.toml's wasm rustflag./and/assetsroutes.GET /now answers 404 with one plain-text line naming the project and the repository.DROP_ALLOWED_ORIGINS(open question 1, answered "remove").Dockerfile.fullstack.docker-compose.ymlnow buildsDockerfile.webCI job, and npm in dependabot.Kept
--transport relayis what works where no UDP gets out, and netlab covers that case.AGENTS.mdandsecurity.md, reworded as dormant (open question 3). They bind any future browser client.crypto/crate boundary. Entry 11 is marked superseded, not deleted.Found along the way
Dockerfilehas not built since the envelope got its own crate. It never copiedcrypto/, so cargo could not load the workspace. Reproduced by copying exactly the Dockerfile's files into a scratch directory (cargo metadatafails ondrop-crypto). WithCOPY crypto ./cryptoadded,cargo build --release --locked --package apisucceeds there. I could not build the image itself: Docker isn't installed on this machine.k8s/README.mdclaimed the message cap is 256 KiB, justified by a browser chunk size. It is 1 MiB + 64 KiB, andRELAY_BUDGET_BYTESis what actually bounds memory.AGENTS.mdsaid "every transfer today crosses the relay", which has been false since v0.2.0.Branch protection on
mainrequires these checks:Web: the job is deleted, so the check never reports. Remove it from required checks.Analyze JavaScript and TypeScript: renamed toAnalyze Rust. Swap it in required checks.While you're there,
Rust (macos-14)andRust (windows-2025)from #67 can be added as required once they're green on this stack.Verified
cargo fmt --check,clippy -D warnings, andcargo test --workspace --all-targetspass: 193 tests. The removed index test is replaced bythe_root_explains_what_this_host_is.scripts/check-secrets.shpasses andgit diff --checkis clean.git grepfinds noweb/,svelte,wasm-pack,viteornpmoutside plans, decisions and checklist history.docker compose up --build(no Docker here) and netlab (the relay code it drives only lost the removed routes and CORS). The Kubernetes render is covered by CI.🤖 Generated with Claude Code
https://claude.ai/code/session_01G7Fy45hUvna94cd79WKG8S