Skip to content

feat(code-context): test-state sweep and browser storage key anchors (0.2.11) - #30

Merged
alphali merged 1 commit into
mainfrom
claude/state-anchors-and-sweep
Oct 7, 2026
Merged

alphali merged 1 commit into
mainfrom
claude/state-anchors-and-sweep

Conversation

@alphali

@alphali alphali commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

Summary

Release 0.2.11 of doable-code-context.

  • Test-state sweep on base investigations. The agent lists, in its local ledger:

    • browser storage keys the feature reads or writes;
    • operations that change persistent state;
    • role, plan, permission and quota gates;
    • one-time states;
    • external services.

    Each item is marked included or out-of-scope. Every included item must close with either a grounded finding or an unknown that names an outside-repository or configuration reason. "Not inspected yet" does not close an item in a mapped repository. Items are named by product purpose, never by generated labels or numbers.

  • New observable anchors. An anchor may be a URL path, or a browser storage key written as localStorage:<key>, sessionStorage:<key>, cookie:<name> or indexedDB:<database>. The helper accepts such an anchor even when the key equals a local evidence symbol.

Why: tests fail most often on state the test spec never named. In offline scoring, the existing rules could not cite browser-persisted state at all, for example a locale or a tour-shown flag. Most missed state items were never surfaced.

Pairs with getdoable/trd branch claude/code-context-state-sweep (change set code-context-state-sweep). That branch adds the same state list to the base question, so the GitHub runner gets it as well.

Privacy and compatibility

  • This changes the public privacy contract, with owner approval. Route paths and names of browser storage keys may now be sent as anchors. A tester can see both in their own browser. Storage values, server-side field names, and code identifiers (functions, classes, handlers) are still never sent. PRIVACY.md is updated to list this.
  • Plugin with an older trd: compatible. The sweep comes from the Skill text and uses existing submission fields.
  • Older plugin with the new trd: compatible. The older plugin keeps storage facts local.
  • No manifest shape, authentication, or MCP changes; only version numbers were bumped.

Verification

  • npm test. This covers release verify for 0.2.11, the GitHub workflow verify, and the 4 node test suites. New helper tests check that:
    • localStorage:has_onboarding_shown is accepted even when it equals the evidence symbol;
    • the bare symbol is still rejected;
    • a callable-shaped anchor under an unknown store prefix is still rejected.
  • No credentials, customer data, private URLs, local paths, or .doable/ state included.
  • Documentation and manifests updated: PRIVACY, CHANGELOG, TESTING scenario 26, README, all three host manifests.
  • claude plugin validate ./plugins/doable-code-context: not run; the CLI was not executable in this environment.
  • Fresh-session checks from TESTING.md, including the new scenario 26: not run.

🤖 Generated with Claude Code

…(0.2.11)

Base investigations now run a local test-state sweep. They enumerate browser
storage keys, state-changing operations, role/plan/permission/quota gates,
one-time states and external services, and close every included item with a
grounded finding or an unknown that says why the workspace cannot establish it.
"Not inspected yet" does not close an item. Items are named by product purpose.

Observable anchors may now be a URL path or a browser storage key written as
localStorage:<key>, sessionStorage:<key>, cookie:<name> or indexedDB:<database>.
The helper accepts such an anchor even when it equals a local evidence symbol.
Server-side fields and code identifiers stay rejected. PRIVACY.md lists the new
remote data.

Pairs with getdoable/trd change set code-context-state-sweep.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@alphali
alphali merged commit 4d53343 into main Oct 7, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant