Skip to content

docs(screenshots): document permanent PR image publishing - #13

Merged
davidvornholt merged 5 commits into
mainfrom
chore/screenshot-publishing
Sep 13, 2026
Merged

docs(screenshots): document permanent PR image publishing#13
davidvornholt merged 5 commits into
mainfrom
chore/screenshot-publishing

Conversation

@davidvornholt

@davidvornholt davidvornholt commented Sep 13, 2026

Copy link
Copy Markdown
Owner

Before. PaperSync's screenshot publisher is configured, but the root development guide does not explain how contributors can publish permanent visual evidence for a pull request.

Now. The README gives the publishing command and links directly to the bucket configuration and screenshot conventions, including the requirement to use demo data for public, permanent images.

Verification

Completed checks

  • bun run check:fix at b854103: 25/25 tasks passed in 17.451 seconds.
  • Six matched demo images were published through the configured service for fix(scanner): resolve printed dates and filter saved homework before review #12; anonymous downloads matched their SHA-256 content addresses.
  • The publishing configuration and encrypted credential are already present on main at 43fbb86 and were reviewed by two Astra high lenses without blockers. This final diff contains only the four-line README addition.

Check it yourself

Run gh pr checkout chore/screenshot-publishing and follow the README's “PR screenshots” instructions with a demo image and an authorized existing SOPS identity. The command prints permanent Markdown image links.

@davidvornholt

Copy link
Copy Markdown
Owner Author

Review-fix scope: enable PaperSync to publish permanent public PR screenshots through the existing personal-infra service. Threat model: publishing must use the intended EU bucket and PaperSync's own scoped credential, preserve encryption/recipient boundaries, and avoid exposing secrets in configuration or screenshots. No changes to runtime deployment or infrastructure resources.

Model: GPT-6 Astra high, as requested. Two read-only lenses review base a4530e3 → initial head f2e6eaa in the dedicated /home/david/dev/papersync-screenshots worktree:

  1. Behavior/invariants: screenshot CLI configuration, endpoint/bucket/jurisdiction contract, usage and renewal documentation, and correspondence with live upload/public-read evidence. Excludes SOPS recipients and credential scope/security.
  2. Security/integration: SOPS target/recipients, secret/plain separation, credential ownership/scope and runtime/CI exposure. Excludes CLI presentation and screenshot appearance.

Baseline: bun run check:fix passed 25/25 tasks in 2.607 seconds. The initial attempt encountered a stopped shared development database; starting that existing database restored the gate. Six demo images published successfully and their anonymous curl downloads matched SHA-256 content addresses. Broker plan reports one healthy PaperSync token and zero actions/findings. Do not decrypt secrets for review.

@davidvornholt

Copy link
Copy Markdown
Owner Author
Phase Scope Model / lenses Findings Outcome Duration
Baseline gate f2e6eaa deterministic reused: 25/25 tasks passed 2.607 s
Review a4530e3f2e6eaa GPT-6 Astra high × 2 0 block, 0 ask, 0 defer; 1 discarded observation clean about 2 min
Fix verification no fix delta — × 0 skipped
Repair verification no repair delta — × 0 skipped
Final gate unchanged f2e6eaa deterministic reused successful equivalent exact-head gate

Both lenses completed. Behavior validated the canonical config loader and EU endpoint generation, matched the existing Portfolio and personal-infra contracts, and checked the issuance/renewal instructions against CLI behavior. Security/integration verified encrypted recipients, the dedicated target, public/secret separation, ownership/scope evidence, and Docker/CI boundaries. The encrypted target is excluded from application images and from the CI identity.

The initial Python urllib 403 was discarded: all six intended public URLs downloaded anonymously with curl and matched their SHA-256 content addresses. No material publication failure was demonstrated.

No fixes, tests, or new test machinery were needed. No secrets were decrypted during review. Existing shared-bucket scope and 90-day broker renewal follow the established personal-project pattern. The shared development database was restarted before the successful baseline gate. Review cycle complete; merge follows the user's existing authorization after GitHub checks pass.

@davidvornholt
davidvornholt marked this pull request as ready for review September 13, 2026 08:41
@davidvornholt

Copy link
Copy Markdown
Owner Author

Merged the now-reviewed and merged #12 into this branch because the repository requires an up-to-date base. The PR diff remains the same four screenshot configuration/credential files; there were no conflicts or new implementation changes. The combined head 26337e3 passed bun run check:fix: 25/25 tasks in 19.46 seconds. Existing review coverage applies to both component changes; GitHub is checking the updated merge candidate.

@davidvornholt
davidvornholt enabled auto-merge (squash) September 13, 2026 08:43
@davidvornholt davidvornholt changed the title chore(screenshots): enable permanent PR image publishing docs(screenshots): document permanent PR image publishing Sep 13, 2026
@davidvornholt

Copy link
Copy Markdown
Owner Author

Release-state recovery: GitHub exposed the reviewed screenshot setup on main as 43fbb86 while this PR remained open and no push checks were created for that commit. Its tree exactly matches the previously reviewed combined head. No main history was rewritten.

The branch now includes that existing main commit and adds a four-line README publishing guide (d753899). The final diff is documentation only, so the review-fix skill permits skipping fresh review. All 25 checks passed again in 2.58 seconds. Auto-merge is disabled; I will explicitly complete the PR after GitHub checks pass, so its push can enter the normal release gate.

@davidvornholt

davidvornholt commented Sep 13, 2026

Copy link
Copy Markdown
Owner Author

The screenshot configuration and encrypted credential are already committed on main at 43fbb86fed870b06eab1535d47bc553e9c99c3af. GitHub still reports this PR open and repeatedly fails normal GraphQL/REST merge requests with server errors; no push release checks exist for that commit.

Recovery was attempted with the same four-line publishing guide on branch fix/screenshot-release-record (128fcca). Both GraphQL and REST replacement-PR creation failed, so no replacement PR number exists. Closing this PR also failed. No main history or quality gate was rewritten.

Current state: the scan fix and screenshot setup are present on main; this PR remains open with the README addition and successful checks. Deployment is incomplete because the normal exact-commit release pipeline could not start. Astra review and six successful public image byte checks remain recorded above.

@davidvornholt

Copy link
Copy Markdown
Owner Author

GitHub operations are responding again. Updated this branch to the current main (ff486a4) and resolved the README conflict by preserving the consolidated setup guide and adding only the screenshot publishing paragraph. The final diff remains four documentation lines. bun run check:fix at b854103 passed all 25 tasks in 17.451 seconds; this prose-only resolution needs no additional code review. The existing release build already includes the scan fixes and screenshot configuration, and personal-infra #360 is being validated for deployment.

@davidvornholt
davidvornholt merged commit 757da41 into main Sep 13, 2026
7 checks passed
@davidvornholt
davidvornholt deleted the chore/screenshot-publishing branch September 13, 2026 11:11
@davidvornholt

Copy link
Copy Markdown
Owner Author

Retry succeeded: GitHub recorded the merge as 757da415e05183b259072a58f50862b43d177a86 and closed this PR. The current documentation preserves the consolidated setup guide plus the screenshot publishing instructions. The replacement branch was never needed.

The application fixes and screenshot configuration are included in source ff486a4, whose reviewed promotion is personal-infra #360. That promotion has merged and is running the trusted production deployment; its completion is tracked there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant