Skip to content

docs(security): reconcile assistant and threat contracts - #5963

Draft
RaresKeY wants to merge 1 commit into
odysseus-dev:devfrom
RaresKeY:docs/current-runtime-contracts
Draft

docs(security): reconcile assistant and threat contracts#5963
RaresKeY wants to merge 1 commit into
odysseus-dev:devfrom
RaresKeY:docs/current-runtime-contracts

Conversation

@RaresKeY

@RaresKeY RaresKeY commented Aug 8, 2026

Copy link
Copy Markdown
Member

Summary

Reconcile the assistant/task documentation and threat-model contracts with current implementation behavior. The updated text records that check-ins are not seeded automatically, token URLs are validated, task scope families are explicit, and search compatibility shims delegate to the canonical implementation. This change does not alter runtime behavior.

Refresh the documentation against the final dev landing set immediately before opening this PR if the branch has moved.

Target branch

  • This PR targets dev, not main. All PRs land in dev; main is curated by the maintainer at each release. If your PR is on main by accident, click "Edit" on this PR and change the base.

Linked Issue

Fixes #5952

Related: #5794

Type of Change

  • Bug fix (non-breaking — fixes a confirmed issue)
  • New feature (non-breaking — adds new behaviour)
  • Breaking change (changes or removes existing behaviour)
  • Refactor / cleanup (behaviour unchanged)
  • Documentation only
  • CI / tooling / configuration

Checklist

  • I searched open issues and open PRs — this is not a duplicate.
  • This PR targets dev
  • My changes are limited to the scope described above — no unrelated refactors or whitespace changes mixed in.
  • I actually ran the app (docker compose up or uvicorn app:app) and verified the change works end-to-end. Type-checks and unit tests are not enough.

The focused documentation-contract tests passed; the application was not run because this change does not modify runtime behavior.

How to Test

  1. Run pytest -q tests/test_current_assistant_security_docs.py; the validated head reports 3 passing tests.
  2. Verify the assistant documentation states that check-ins are not seeded automatically.
  3. Verify the task documentation describes token-URL validation and the current scope families.
  4. Verify the threat/search documentation describes the compatibility shims as delegating to the canonical implementation.
  5. Recompare these statements with the final dev source immediately before publication.

Visual / UI changes — REQUIRED if you touched anything that renders

Anything that changes what the UI looks like — buttons, icons, padding, colors, fonts, spacing, layout, CSS, HTML, SVG, or any static/js/ module that draws to the DOM — needs all of the following. PRs that change rendering without these WILL be closed.

N/A — this is a documentation-only change with no rendered UI changes.

  • Screenshot or short clip of the change in the running app, attached below. Mobile screenshot too if the change affects mobile.
  • Style match: the change uses Odysseus's existing visual language. Specifically:
    • Reuse existing CSS variables (--red, --fg, --bg, --card, --border, etc.) — do not introduce new color values, font sizes, or spacing units.
    • Reuse existing button/input/card/border classes. Don't invent parallel styling.
    • No Unicode emoji in UI or code. Use inline SVG (matching the monochrome icon style already in static/index.html) or plain text.
    • Monospaced font (Fira Code) for primary UI text. Don't override.
    • Dark theme is the default; any light-mode work must be wired through the existing theme system, not hard-coded.
  • No new component patterns. If a similar widget already exists in the app, extend it instead of writing a parallel one.
  • I am not an LLM agent submitting a bulk PR. If you are, please open an issue describing the problem first — bulk auto-generated PRs that don't match the project's visual style are closed on sight, even when the underlying fix is correct.

Screenshots / clips

N/A — no rendered UI files changed.

@github-actions github-actions Bot added the ready for review Description complete — ready for maintainer review label Aug 8, 2026
@RaresKeY
RaresKeY force-pushed the docs/current-runtime-contracts branch from 7f1a6f6 to 8b11ef5 Compare August 9, 2026 00:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready for review Description complete — ready for maintainer review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Assistant and threat documentation has drifted from runtime behavior

1 participant