#steering-toggle (the header 'Tuning' button) shipped visible in all six pages and was only removed after /api/whoami resolved, so anonymous visitors saw it flash for the whole round-trip (TODO.md L3). It now ships hidden on every page and initSharedHeader unhides it only for admin — the same ship-hidden / reveal-for-admin contract as the admin-only nav links; the anonymous end-state (removed from the DOM, phase-16 'absent, not hidden') is unchanged. Adds the story E2E suite (MutationObserver proves zero visible frames for anonymous on every page, admin reveal + panel + count badge, nav-contract regression) and the source-level unit pins. Also fixes test_steering.py's BASE_SCRIPT_COUNT (2 → 3: brand.js + markdown.js + app.js, since phase 39).
166 lines
10 KiB
HTML
166 lines
10 KiB
HTML
<!doctype html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="utf-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover">
|
|
<meta name="description" content="Read a document indexed in Brain of Reese.">
|
|
<title>Document · Brain of Reese</title>
|
|
<link rel="icon" href="data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%2064%2064%22%3E%3Cpath%20d=%22M32%204%2055%2018v28L32%2060%209%2046V18Z%22%20fill=%22%23121a2e%22%20stroke=%22%236d78f2%22%20stroke-width=%224%22%20stroke-linejoin=%22round%22/%3E%3Ccircle%20cx=%2232%22%20cy=%2232%22%20r=%226.5%22%20fill=%22%236d78f2%22/%3E%3Cpath%20d=%22M32%2025.5V16M32%2048v-9.5M25.5%2032H16M48%2032h-9.5%22%20stroke=%22%2322d3ee%22%20stroke-width=%223%22%20stroke-linecap=%22round%22/%3E%3C/svg%3E">
|
|
<link rel="stylesheet" href="/assets/styles.css">
|
|
</head>
|
|
<body>
|
|
<a class="skip-link" href="#main">Skip to content</a>
|
|
|
|
<!-- Phase 34 (owner confirmation 2026-08-26): the viewer carries the
|
|
SAME standard bar as every other page — row 1 is the shared
|
|
.app-header / .header-inner block (byte-identical controls), and
|
|
the back link + title + meta survive in a second .doc-titlebar
|
|
row inside the same <header> (the phase-19 single-row viewer bar
|
|
is superseded — this phase records the revision, PLAN.md §7.1
|
|
unchanged). No nav link is "current" here: a document is a
|
|
detail view reachable from chat or Sources, and the phase-13
|
|
back link carries the return affordance. -->
|
|
<header class="doc-header">
|
|
<div class="app-header">
|
|
<div class="container header-inner">
|
|
<span class="brand">
|
|
<svg class="brand-mark" aria-hidden="true" viewBox="0 0 64 64"><path d="M32 4 55 18v28L32 60 9 46V18Z" fill="#121a2e" stroke="#6d78f2" stroke-width="4" stroke-linejoin="round"/><circle cx="32" cy="32" r="6.5" fill="#6d78f2"/><path d="M32 25.5V16M32 48v-9.5M25.5 32H16M48 32h-9.5" stroke="#22d3ee" stroke-width="3" stroke-linecap="round"/></svg>
|
|
<span class="brand-text">Brain of <strong>Reese</strong></span>
|
|
</span>
|
|
<nav class="app-nav" aria-label="Primary">
|
|
<a href="/" class="nav-link">Chat</a>
|
|
<!-- Phase 19 (now every page — phase 34, owner confirmation
|
|
2026-08-26): the Sources link is admin-only (owner
|
|
permission 2026-08-23) — hidden by default, header.js
|
|
reveals it once whoami says admin. The soft-gated page
|
|
itself is unchanged. -->
|
|
<a href="/sources.html" class="nav-link" id="nav-sources" hidden>Sources</a>
|
|
<!-- Phase 35 (owner permission 2026-08-26): the Git sources
|
|
link is admin-only — hidden by default, header.js
|
|
reveals it once whoami says admin, exactly like the
|
|
Sources link above. -->
|
|
<a href="/git-sources.html" class="nav-link" id="nav-git-sources" hidden>Git sources</a>
|
|
<!-- Phase 29 (now every page — phase 34, owner confirmation
|
|
2026-08-26): the Global Tuning link is admin-only (owner
|
|
permission 2026-08-25) — hidden by default, header.js
|
|
reveals it once whoami says admin, exactly like the
|
|
Sources link above. -->
|
|
<a href="/tuning.html" class="nav-link" id="nav-tuning" hidden>Tuning</a>
|
|
</nav>
|
|
<!-- Phase 15 (now every page — phase 34, owner confirmation
|
|
2026-08-26): open the tuning-notes panel (stored in
|
|
Postgres, read into every system prompt). The behavior is
|
|
owned by the shared header module (assets/header.js); the
|
|
#steering-panel section ships in every page's <main>. -->
|
|
<button type="button" class="steering-toggle" id="steering-toggle" hidden
|
|
aria-expanded="false" aria-controls="steering-panel">
|
|
<svg aria-hidden="true" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round"><path d="M4 7h10M18 7h2M4 17h4M12 17h8"/><circle cx="15.5" cy="7" r="2.2"/><circle cx="9.5" cy="17" r="2.2"/></svg>
|
|
<span class="steering-label">Tuning</span>
|
|
<span class="steering-count" id="steering-count">0</span>
|
|
</button>
|
|
<!-- Phase 32 (now every page — phase 34, owner confirmation
|
|
2026-08-26): the admin-only "Sync sources" button — SHIPS
|
|
hidden (anonymous-safe), header.js reveals it for the admin
|
|
on the SAME cached whoami that reveals #nav-sources /
|
|
#nav-tuning. The §7.4 "never stale" lifecycle is
|
|
module-owned (assets/header.js); the Sources page's
|
|
#sync-result line + #sync-error-banner render off the
|
|
module's "bor:sync-status" event. -->
|
|
<button type="button" class="sync-btn" id="sync-btn" hidden aria-label="Sync sources">
|
|
<svg class="sync-icon" aria-hidden="true" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round"><path d="M21 12a9 9 0 1 1-9-9c2.52 0 4.93 1 6.74 2.74L21 8"/><path d="M21 3v5h-5"/></svg>
|
|
<span class="sync-label" id="sync-label">Sync sources</span>
|
|
</button>
|
|
<!-- Phase 14 (now every page — phase 34, owner confirmation
|
|
2026-08-26; module-owned since phase 34 task 02): on the
|
|
chat page "New chat" resets the local (localStorage)
|
|
conversation; on every other page it means "go to the
|
|
chat, fresh" (the module clears the key + navigates). -->
|
|
<button type="button" class="new-chat-btn" id="new-chat-btn" aria-label="New chat">
|
|
<svg aria-hidden="true" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round"><path d="M12 5v14M5 12h14"/></svg>
|
|
<span class="new-chat-label">New chat</span>
|
|
</button>
|
|
<!-- Phase 16: single-admin auth — exactly one of Sign in / Sign
|
|
out is visible; /api/whoami decides at load (the shared
|
|
header module). Icon-only below 640px (aria-labels keep the
|
|
accessible names). -->
|
|
<a href="/login.html?next=/document.html" class="auth-link" id="sign-in-link" hidden>
|
|
<svg aria-hidden="true" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round"><path d="M10 4h8a2 2 0 0 1 2 2v12a2 2 0 0 1-2 2h-8"/><path d="M4 12h11"/><path d="m12 9 3 3-3 3"/></svg>
|
|
<span class="auth-label">Sign in</span>
|
|
</a>
|
|
<button type="button" class="auth-link" id="sign-out-btn" aria-label="Sign out" hidden>
|
|
<svg aria-hidden="true" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.7" stroke-linecap="round" stroke-linejoin="round"><path d="M14 4H6a2 2 0 0 0-2 2v12a2 2 0 0 0 2 2h8"/><path d="M9 12h11"/><path d="m17 9 3 3-3 3"/></svg>
|
|
<span class="auth-label">Sign out</span>
|
|
</button>
|
|
</div>
|
|
</div>
|
|
<!-- Row 2: the viewer titlebar — the phase-10 back link + title +
|
|
meta row, markup otherwise unchanged (document.js addresses
|
|
them by id). -->
|
|
<div class="doc-titlebar">
|
|
<div class="container">
|
|
<a class="doc-back" id="doc-back" href="/sources.html">
|
|
<svg aria-hidden="true" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"><path d="M19 12H5"/><path d="m12 19-7-7 7-7"/></svg>
|
|
<span>Sources</span>
|
|
</a>
|
|
<div class="doc-title-block">
|
|
<h1 id="doc-title">Loading…</h1>
|
|
<div id="doc-meta" class="doc-meta"></div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</header>
|
|
|
|
<main id="main" class="app-main" tabindex="-1">
|
|
<!-- Phase 15 (now every page — phase 34, owner confirmation
|
|
2026-08-26): the tuning-notes panel (stored notes, newest
|
|
first) — rendered + driven by assets/header.js (shared), not
|
|
the page script. First child of <main> on the non-chat pages;
|
|
the chat page keeps it after #kb-banner. -->
|
|
<section class="steering-panel" id="steering-panel" role="region"
|
|
aria-label="Tuning notes" hidden>
|
|
<div class="steering-panel-head">
|
|
<h2 class="steering-panel-title">Tuning notes</h2>
|
|
<p class="steering-panel-sub">Every note below steers all future answers.</p>
|
|
</div>
|
|
<ul class="steering-list" id="steering-list"></ul>
|
|
<p class="steering-empty" id="steering-empty">No tuning notes yet — press “Tune” under any answer to add one.</p>
|
|
</section>
|
|
<p class="visually-hidden" id="steering-announcer" role="status" aria-live="polite" aria-atomic="true"></p>
|
|
<!-- aria-live wraps the load → content swap so screen readers hear the
|
|
document land (phase 10 a11y contract). -->
|
|
<div class="container doc-shell" aria-live="polite">
|
|
<div id="doc-content">
|
|
<p class="doc-loading" role="status">Loading document…</p>
|
|
</div>
|
|
|
|
<div class="doc-not-found" id="doc-not-found" hidden>
|
|
<div class="doc-not-found-glyph" aria-hidden="true">
|
|
<svg viewBox="0 0 48 48" fill="none" stroke="currentColor" stroke-width="2.4" stroke-linecap="round" stroke-linejoin="round"><path d="M12 4h16l8 8v28a4 4 0 0 1-4 4H12a4 4 0 0 1-4-4V8a4 4 0 0 1 4-4Z"/><path d="M28 4v8h8"/><path d="m19 22 10 10M29 22l-10 10"/></svg>
|
|
</div>
|
|
<h2>Document not found</h2>
|
|
<p class="doc-not-found-sub">
|
|
This document isn't in the knowledge base — it may have been removed
|
|
from the index, or the notes were re-imported.
|
|
</p>
|
|
<a class="doc-open-sources" href="/sources.html">Open Sources</a>
|
|
</div>
|
|
</div>
|
|
</main>
|
|
|
|
<footer class="app-footer">
|
|
<div class="container footer-inner">
|
|
<span>Powered by Reese's self-hosted models</span>
|
|
</div>
|
|
</footer>
|
|
|
|
<!-- Phase 39: the brand layer — classic script, first on the page:
|
|
window.BOR_BRAND at parse time, refreshed from /api/config. -->
|
|
<script src="assets/brand.js"></script>
|
|
<script src="assets/markdown.js"></script>
|
|
<!-- Phase 19: the shared header module loads through the page script's
|
|
own `import "./header.js"` — a hoisted import that is evaluated
|
|
before the page script body calls initSharedHeader() at boot. -->
|
|
<script type="module" src="assets/document.js"></script>
|
|
</body>
|
|
</html>
|