Skip to content

feat: group the board by host and paint it at once - #9

Draft
tensorcopy wants to merge 12 commits into
alysnnix:mainfrom
tensorcopy:fresh-board
Draft

tensorcopy wants to merge 12 commits into
alysnnix:mainfrom
tensorcopy:fresh-board

Conversation

@tensorcopy

@tensorcopy tensorcopy commented Sep 28, 2026 •

Copy link
Copy Markdown

Read the diff as the last six commits. This pull request is stacked on #6, #7 and #8. Until they merge, the diff above includes their commits — GitHub requires a pull request's base branch to live on this repository, so a cross-fork stack cannot be based on one another's branches. Once #8 merges, this diff shrinks to exactly its own six commits (grouping, freshness, the image allowlist, the docs, and two review fixes). Merge order for the series: #6 → #7 → #8 → this one. Draft until then so it cannot merge out of order; the code is final and ready to review now.

Why. With several hosts on one board the lists interleaved. Opening the surface waited on a full GitHub sweep. A board could sit minutes behind GitHub. And an enterprise repository's screenshots rendered as links, because the image proxy only knew github.com.

What.

  • With more than one host on the board, the list is divided into one section per host, in the order the active sort puts their first card. A single host draws no banner.
  • The board cache gained single-flight, disk persistence and stale-while-revalidate: an expired board is served at once, marked stale on the wire, and refreshed behind the surface, and the client refetches a stale answer shortly after. The TTL drops to one minute, and a sweep in which a column failed is not cached. The header says how old the board on screen is.
  • Attachments on every authenticated host are proxied, each fetched with that host's own token (gh auth token --hostname). The allowlist names no host itself: github.com plus the hosts gh auth status reports, all under /user-attachments/ only. The githubusercontent CDNs carry the github.com token — those CDNs being github.com's own image hosting — and a hop the allowlist refuses, such as the signed redirect leg, carries no header at all: a presigned URL answers 400 to a request that also carries an Authorization header, verified against a live attachment. An enterprise token never leaves its own host.
  • The host override outside an item's context is GH_HOST alone: a settings-file hostname key was read but never written or documented, and the next settings save silently erased it.
  • CHANGELOG entries under [Unreleased], and the README paragraphs and limitation updates that match.

How. client/board/host-sections.ts groups already-sorted rows without disturbing the order within a group; the Cache class in server/cache/ gained revalidate, shouldCache and patchAll; shared/image-host.ts takes the authenticated hosts as a parameter and both halves pass the same list — the daemon from its accounts, the client from the board answer's imageHosts field.

Test. 14 suites, 70 tests at this tip, covering the cache revalidation and freshness, the host sections, the allowlist and the per-host token mapping. Typecheck and lint are clean, and every commit in the stack builds and passes its tests on its own.

- the lock still said 0.5.0 while package.json says 1.0.1
- a shared budget went to whichever relation held the newest items, so a full review queue pushed the viewer's own work off the board
- nodes(ids:) caps at 100 ids; ask in batches of that size so a longer board keeps its checks
- match the pull request each active or retained workspace tracks to the first agent created there, the originating conversation
- an action on the row and in the panel jumps straight to that chat
- resolve the hostname from GH_HOST or the plugin's settings file and set it on every gh subprocess
- gh auth status names every authenticated host and its active account
- item ids carry their host, so reads and actions reach the host that owns the item
- the sweep unions every host's columns and keeps each host's failure in the column error
- one section per host when more than one host contributed, in the order the sort puts their first card
- an expired login on one host no longer blanks the board for the hosts that are fine
- an expired board is served immediately, marked stale, and refreshed behind the surface
- the board ttl drops to one minute, a sweep with a failed column is not cached, and the client refetches a stale answer
- the allowlist names no host itself: github.com plus the hosts gh auth status reports, all under /user-attachments/ only
- an enterprise attachment is fetched with that host's own token via gh auth token --hostname
- the githubusercontent CDNs carry the github.com token, never an enterprise one, and the signed redirect leg carries no header at all
- the host list rides the board answer, so the client knows which urls the daemon will fetch
- changelog entries under unreleased for the ported features and fixes
- readme gains the host, chat and freshness paragraphs, and the image limitation names the hosts the daemon will fetch for
- the settings-file hostname key was read but never written or documented, and the next settings save silently erased it
- GH_HOST in the daemon environment is the documented override, and the sweep itself sets each host's context
- a refused hop carries no header; a githubusercontent hop carries the github.com token, those CDNs being github.com's own image hosting
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant