BREAKING main #1 / 74
aaronrene · 10 days ago · Jul 13, 2026 · Diff

mirror: GitHub Phase A durable MCP OAuth (#270)

sha256:b5f647cb9c409f563d4671fe3fc05ddea01fabfed9b41fc11cb923588e1c1baf sha
+113 ~35 −4 symbols
1155 changed · 1155 in snapshot files
sha256:98e654479188e68fb745a472d2a27d5b5ec56bb7134f0084650dd87344fe8886 snapshot
+113
symbols added
~35
symbols modified
−4
symbols removed
1155
files changed
1155
files in snapshot
0
dead code introduced
Semantic Changes 152 symbols
~ docs/DURABLE-AGENT-AUTH-ROADMAP.md .md 21 symbols added
+ Durable agent auth — roadmap section Durable agent auth — roadmap L1–141
+ Build status table section Build status table L131–141
+ table section table L133–141
+ Phase 0 — Thinking freeze section Phase 0 — Thinking freeze L23–30
+ Phase A — Durable MCP OAuth refresh + Hermes spike section Phase A — Durable MCP OAuth refresh + Hermes spike L30–74
+ DoD checklist section DoD checklist L52–61
+ Frozen interfaces (Build) — implemented section Frozen interfaces (Build) — implemented L42–52
+ Spike (HARD GATE — completed) section Spike (HARD GATE — completed) L35–42
+ Test tiers section Test tiers L61–74
+ table section table L63–71
+ Phase B — Hub “Connect cloud agent” section Phase B — Hub “Connect cloud agent” L74–97
+ DoD section DoD L83–91
+ Frozen product goal section Frozen product goal L79–83
+ Test tiers section Test tiers L91–97
+ Phase C — Scoped agent credentials (REST) section Phase C — Scoped agent credentials (REST) L97–115
+ DoD section DoD L107–115
+ Frozen invariants section Frozen invariants L101–107
+ Phase D — Propose-only + path prefix section Phase D — Propose-only + path prefix L115–125
+ Phase E — Marketing honesty section Phase E — Marketing honesty L125–131
+ Phase routing section Phase routing L8–23
+ table section table L10–18
~ docs/DURABLE-AGENT-AUTH-SPEC.md .md 28 symbols added
+ Durable agent / MCP auth for remote co-founders — frozen decision section Durable agent / MCP auth for remote co-founders — frozen decision L1–223
+ Incident (truth vs claims) section 1. Incident (truth vs claims) L20–38
+ table section table L22–35
+ env users) section 10. Migration message (existing Copy-Hub → .env users) L170–179
+ Doc / marketing edits list (when approved) section 11. Doc / marketing edits list (when approved) L179–192
+ Interim Born Free runbook (≤10 lines) section 12. Interim Born Free runbook (≤10 lines) L192–204
+ Evidence index (files read) section 13. Evidence index (files read) L204–215
+ Offline-lock interaction (Phase 8) section 14. Offline-lock interaction (Phase 8) L215–223
+ Verdict (1 paragraph) section 2. Verdict (1 paragraph) L38–44
+ Personas — shipped vs promised section 3. Personas — shipped vs promised L44–55
+ table section table L46–52
+ Claims audit — overstatement + honest copy section 4. Claims audit — overstatement + honest copy L55–69
+ table section table L57–66
+ Recommended end-state architecture section 5. Recommended end-state architecture L69–109
+ Explicitly not primary section Explicitly not primary L98–109
+ table section table L100–106
+ Fallback (freeze) section Fallback (freeze) L83–98
+ Primary (freeze) section Primary (freeze) L71–83
+ Options ranking (security × UX) section 6. Options ranking (security × UX) L109–122
+ table section table L111–119
+ Refresh token delivery threat model section 7. Refresh token delivery threat model L122–141
+ table section table L128–136
+ MCP URL vs REST for always-on agents section 8. MCP URL vs REST for always-on agents L141–159
+ table section table L143–147
+ Scopes / roles for Born Free marketing agents section 9. Scopes / roles for Born Free marketing agents L159–170
+ table section table L161–167
+ Simple summary section Simple summary L10–14
+ Technical summary section Technical summary L14–20
+ Hermes MCP OAuth spike — Hostinger Managed (Phase A hard gate) section Hermes MCP OAuth spike — Hostinger Managed (Phase A hard gate) L1–53
+ Operator follow-up (no secrets) section Operator follow-up (no secrets) L29–50
+ code[bash] variable variable code[bash] L33–38
+ code[yaml] variable variable code[yaml] L41–47
+ Rank swap (frozen contingency) section Rank swap (frozen contingency) L22–29
+ Secrets policy section Secrets policy L50–53
+ Simple summary section Simple summary L7–11
+ Technical summary section Technical summary L11–22
+ table section table L13–21
+ Issue draft — muse clone stuck on fetch/mpack “server busy” (pack never ready) section Issue draft — muse clone stuck on fetch/mpack “server busy” (pack never ready) L1–83
+ Ask section Ask L67–73
+ Client transport note (likely related) section Client transport note (likely related) L51–63
+ Expected section Expected L63–67
+ Non-goals / not the cause section Non-goals / not the cause L73–79
+ Summary section Summary L9–15
+ What fails section What fails L24–51
+ code[text]@L26 variable variable code[text]@L26 L26–30
+ code[text]@L33 variable variable code[text]@L33 L33–39
+ code[text]@L42 variable variable code[text]@L42 L42–46
+ What works section What works L15–24
+ table section table L17–23
+ Workarounds for operators (until fixed) section Workarounds for operators (until fixed) L79–83
~ hub/gateway/access-token-authz.mjs .mjs 4 symbols added
+ isSafeHttpMethod method function isSafeHttpMethod L15–18
+ mcpScopesPermitMethod method function mcpScopesPermitMethod L26–34
+ shouldMountDurableAgentAuth function function shouldMountDurableAgentAuth L63–65
+ subFromVerifiedPayload function function subFromVerifiedPayload L45–53
+ get method async_method get L65–65
+ setJSON method async_method setJSON L66–66
+ cleanup method async_method cleanup L27–31
+ createDurableMcpProvider function async_function createDurableMcpProvider L39–48
+ createTempStrongStore function async_function createTempStrongStore L17–33
+ json method method json L75–75
+ mintMcpTokens function async_function mintMcpTokens L55–80
+ redirect method method redirect L74–74
+ status method method status L75–75
~ docs/AGENT-INTEGRATION.md .md 3 symbols added, 7 symbols modified
+ Always-on cloud agents (Hermes / VPS) — do not paste Hub JWT as durable auth section Always-on cloud agents (Hermes / VPS) — do not paste Hub JWT as durable auth L169–192
+ code[yaml] variable variable code[yaml] L181–187
+ table section table L173–178
~ )
~ docs/FLOW-STORE-CONTRACT-7A-10.md .md 6 symbols added, 2 symbols modified
+ P-FLOW extension — flow_run/v0 read store (7A-10c / P-FLOW) section 11. P-FLOW extension — flow_run/v0 read store (7A-10c / P-FLOW) L552–584
+ 1 Read operations (always-on; no write gate) section 11.1 Read operations (always-on; no write gate) L557–567
+ table section table L559–563
+ 2 Portable run_ref pointer section 11.2 Portable run_ref pointer L567–573
+ 3 Triple-surface parity (read paths) section 11.3 Triple-surface parity (read paths) L573–580
+ 4 Seven-tier tests section 11.4 Seven-tier tests L580–584
~ docs/OVERSEER-HANDOVER.md .md 5 symbols added, 1 symbol removed, 5 symbols modified
NEXT SESSION — same as Scooling PRIMARY section NEXT SESSION — same as Scooling PRIMARY L10–20
+ NEXT SESSION — Durable agent auth Phase B (Thinking → Auto) section NEXT SESSION — Durable agent auth Phase B (Thinking → Auto) L11–53
+ Interim ops (Born Free) section Interim ops (Born Free) L47–53
+ Phase B prompt (draft) section Phase B prompt (draft) L31–47
+ code variable variable code L33–46
+ Shared context (prepend to phase prompt) section Shared context (prepend to phase prompt) L24–31
~ table
~ table
~ hub/gateway/mcp-oauth-provider.mjs .mjs 2 symbols added, 1 symbol removed, 6 symbols modified
_sweepExpiredRefreshTokens method method _sweepExpiredRefreshTokens L295–300
+ refreshFailureError function function refreshFailureError L91–102
+ resolveMcpAgentLabel function function resolveMcpAgentLabel L79–84
~ hub/gateway/refresh-token-store.mjs .mjs 2 symbols added, 1 symbol modified
+ load function async_function load L226–229
+ save function async_function save L231–237
~ hub/gateway/server.mjs .mjs 3 symbols modified
~ hub/lib/refresh-token-core.mjs .mjs 1 symbol added, 2 symbols modified
+ mergeMeta function function mergeMeta L198–203
~ lib/flow/flow-execution.mjs .mjs 2 symbols removed, 3 symbols modified
findVisibleRun function function findVisibleRun L382–388
runForClient function function runForClient L191–215
~ lib/flow/flow-store.mjs .mjs 10 symbols added
+ buildDefaultRunRef function function buildDefaultRunRef L821–823
+ ensureRunSeed function function ensureRunSeed L969–971
+ findRunInVault function function findRunInVault L842–852
+ findVisibleRun function function findVisibleRun L860–865
+ getFlowRun function function getFlowRun L1036–1054
+ isValidRunLookupKey function function isValidRunLookupKey L829–833
+ listFlowRuns function function listFlowRuns L987–1025
+ persistFlowRun function function persistFlowRun L1065–1098
+ runForClient function function runForClient L873–898
+ seedOverseerAnchorRun function function seedOverseerAnchorRun L907–961
~ lib/task/task-store.mjs .mjs 1 symbol modified
~ test/gateway-refresh-token-store.test.mjs .mjs 2 symbols modified
~ get
Files Changed
+1155
1155 in snapshot
+ .env.example .example
+ .gitignore .gitignore
+ .gitleaks.toml .toml
+ .museattributes .museattributes
+ .museignore .museignore
+ .nvmrc .nvmrc
+ AGENTS.md .md
+ README.md .md
+ backups/.gitignore .gitignore
+ cli/index.mjs .mjs
+ docs/SPEC.md .md
+ hub/roles.mjs .mjs
+ lib/air.mjs .mjs
+ lib/chunk.mjs .mjs
+ lib/vault.mjs .mjs
+ lib/write.mjs .mjs
+ netlify.toml .toml
+ package.json .json
+ public/.gitkeep .gitkeep
+ vault/meta/.gitkeep .gitkeep
+ web/index.html .html

0 comments

No comments yet. Be the first to start the discussion.

To add a comment, use the Muse CLI: muse hub commit comment sha256:b5f647cb9c409f563d4671fe3fc05ddea01fabfed9b41fc11cb923588e1c1baf --body "your comment"