Skip to content

Prevent stale evidence links from restoring changed audits; release 0.10.2 - #15

Merged
noteflowai merged 1 commit into
mainfrom
codex/evidence-ux-20260915
Sep 15, 2026
Merged

noteflowai merged 1 commit into
mainfrom
codex/evidence-ux-20260915

Conversation

@noteflowai

Copy link
Copy Markdown
Owner

A shared case URL could silently show another recording after audit bytes changed while task/case coordinates stayed the same. Version 2 links now include SHA-256 of the actual fetched audit bytes; a mismatch leaves the current view in place with an actionable explanation. Display the loaded fingerprint, disclose legacy links' missing identity and reject duplicate parameters.

Keep reports and downloads usable when browser hashing is unavailable. Synchronize the Python and private site package versions and bilingual documentation for 0.10.2. Task contracts, scoring and historical records are unchanged.

Validation: 308 Python tests; Ruff checks; browser flows at 1440, 390 and 320 px including clipboard fallback, partial task retries, changed audit bytes under an unchanged manifest, fresh links, legacy notices, duplicate hashes and unavailable Web Crypto.

@noteflowai
noteflowai merged commit 3a855b1 into main Sep 15, 2026
12 checks passed
@noteflowai
noteflowai deleted the codex/evidence-ux-20260915 branch September 15, 2026 15:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant