Commit Graph

25 Commits

Author SHA1 Message Date
Den
2652cc2ca9 docs(playstore): record v0.4.14 production rollout (versionCode 151) (#171)
Tag pushes only reach the internal track; production is a separate manual
workflow_dispatch that rebuilds and gets its own versionCode. Document that
path and start a release-history table so the AGE-105 Sentry measurement
window has a real rollout date to anchor on.

v0.4.14: internal versionCode 150 (run 50), production versionCode 151
(run 51), submitted to the production track 2026-08-14 14:22 UTC.

Co-authored-by: engineer <engineer@macbookpro.lan>
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-08-14 07:39:21 -07:00
Den
61f4b1177b fix(diagnostics): classify 401/403 as auth-failed so a wrong password stops the retry loop (#170)
AGE-107. The 498 `API Error: 401` events from one device were not a client
token-refresh loop. Sentry breadcrumbs on the surviving events show a `touch`
event immediately before every capture, at irregular human-paced intervals
(87s, 199s, 69s, 5s, 61s, 66s) — a person re-tapping Connect, not a backoff
timer. The app's automated loops were already correct: events.ts terminates
the SSE reconnect loop on ApiAuthError (issue #76).

What actually drove it: in v0.4.4 the connection probe counted any HTTP
response as a successful health check, so a 401 was classified `ok` and shown
to the user as "Health endpoint responded — connection actually works now"
while their password was wrong. The user retried for two months. `requireOk`
(#114, v0.4.8) stopped the false success, but 401 then fell into the generic
`health-failed` bucket — "Likely wrong path, auth, or an old server version" —
which still doesn't tell anyone to fix their password.

- New `auth-failed` classification: a 401/403 from /global/health means the
  server is up and reachable and rejected the credentials. Its summary names
  the status, points at the password and OPENCODE_SERVER_USERNAME, and says
  the server is fine. It flows straight into the existing failure Alert on
  both the add and edit connection screens — which is where the password
  field is, i.e. the re-auth prompt.
- It short-circuits before the root/internet probes can downgrade it: a 401
  already proves the server answered.
- `health-failed` copy no longer blames auth.
- `connect auth-failed` joins the noise-gate drop-list. A wrong password is
  user config, unactionable server-side, already visible in the UI and
  already trended in PostHog as connection_failed{error_class:"unauthorized"}.
  `health-failed` and `tls-error` still report.

Tests: 6 new (401/403 -> auth-failed, message content, root-unreachable does
not override, 404/500/502 stay health-failed, health-failed copy drops "auth",
noise gate drops `connect auth-failed` but not a raw `API Error: 401`).
263 pass, tsc --noEmit clean.

Co-authored-by: engineer <engineer@macbookpro.lan>
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-08-14 07:14:36 -07:00
Den
7c8bc7d317 fix(sentry): gate non-actionable client noise before it leaves the device (#169)
opencode-mobile is now the org's #1 Sentry volume source (~4,500 events/mo
against a 3,500/mo org quota, AGE-105). ~1,100 of those events are three
non-defects: `connect timeout` (462), `connect server-unreachable` (157), and
one device's `API Error: 401` token-refresh loop firing 498 times.

Adds a pure, unit-tested noise gate (src/lib/sentry-noise.ts) wired into
`beforeSend`, applying three layers cheapest-first:

  1. Always-send allowlist — OOM/ANR/native/fatal crash classes bypass every
     limit. Quota is worthless if it silences real crashes.
  2. Transport drop-list — hard drop for client-side network conditions. Hard,
     not sampled: the gate runs per-install, so "1 per device per day" would
     multiply by the install base straight back into thousands per month.
  3. Dedup + rate cap — 6h per-fingerprint cooldown, ≤6 new fingerprints/h,
     ≤10 events/h, mirroring the openclaw-box-bot shim (AGE-55).

Nothing is lost by the transport drop: those failures are already user-visible
as connection UI and already trended, PII-free, as the PostHog
`connection_failed{error_class}` event. captureDiagnostic() also short-circuits
for those classifications so the event is never even built. Drops are auditable
— the count since the last delivered event rides along as a
`noise.dropped_since_last` tag.

Replaying the observed 1,126-event hour through the gate yields 5 delivered
events (1 auth report + 4 real OOMs).

Tests: 18 new, 257 total passing; tsc --noEmit clean.

Co-authored-by: engineer <engineer@macbookpro.lan>
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-08-14 06:35:27 -07:00
Den
929f55b850 docs: data safety audit for Email Address (Play rejection versionCode 142) (#149)
Co-authored-by: engineer <engineer@gray-knight-m1.local>
2026-07-24 07:45:16 -07:00
Den
d6e24e9f99 fix(compliance): disclose email collection in Play Data Safety + align privacy docs (#146)
* fix(compliance): disclose email collection in Play Data Safety + align privacy docs (closes #143)

Google Play rejected cc.agentlabs.opencode (2026-07-22) because the Data
Safety declaration did not disclose collection of Email Address. Root
cause: the optional "OpenCode Connect" waitlist card on the Connect
screen (app/connection/add.tsx -> src/lib/waitlist.ts) collects an email
and forwards it to Brevo (email marketing/CRM) via the beta-signup
backend.

Audited all other PII surfaces and confirmed no other undisclosed
collection: Chatwoot support reports stay anonymous (no email/name),
Sentry strips URLs/tokens and sends no default PII, and PostHog
analytics uses only a random anonymous ID with coarse event properties.

Updates:
- distribution/play-listing.md: Data Safety table now declares
  Personal info / Email address (collected, shared with Brevo,
  optional, purpose account management); embedded privacy-policy draft
  and app description updated to match.
- distribution/privacy-policy.md/.html + docs/privacy/index.html: new
  section 3c discloses the waitlist email collection, third-party
  services list adds Brevo, retention/rights sections and the Apple
  Privacy Nutrition Label table updated accordingly.
- docs/playstore.md: checklist entry documents the rejection and points
  to the fix.
- PUBLISHING.md: adds exact Play Console resubmission steps (Data
  types -> Personal info -> Email address -> collected/shared/purpose)
  plus a note on the earlier unrelated "Missing sign-in details" App
  access blocker in case it resurfaces.

No app code changed; npm test (209 pass) and tsc --noEmit are clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(ci): run required checks on docs-only PRs (unblock branch protection)

ios-ci.yml (which emits the required 'Typecheck and unit tests' check) had
paths-ignore for docs/**, docs-site/**, distribution/**, **/*.md. A required
status check that is path-filtered never runs on docs-only PRs, so those PRs
sit permanently in mergeStateStatus=BLOCKED (missing required check). Remove the
paths-ignore so required checks always run.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: test <test@test.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 15:01:48 -07:00
Den
1ea84f8236 chore(launch): reconcile README/store live-status + add demo-funnel analytics (#111)
Two scoped changes for the no-spend growth launch (Growth Launch Kit,
Notion page 3a1ac25eb49f81099cc9f3a4286c8ec4):

1. README.md and distribution/play-listing.md said Google Play was
   "coming soon" / internal-testing-only, while distribution/retention-analysis.md
   and the live play.google.com listing show it's actually public with 1K+
   installs. Fixed the contradiction, added Google Play as a third install
   channel, and added an accurate mention of the new offline demo mode
   ("Try a Demo" — reasoning, grep, diff, permission prompt, ~30s, no server)
   matching what app/demo.tsx + src/lib/demo-script.ts actually render.
   play-listing.md's stale pre-launch checklists are marked historical
   instead of rewritten, so #83's ASO copy/keyword work is untouched.

2. Added the demo funnel's key metric (demo-completion, per the launch
   kit) as four consent-gated PostHog events: demo_started,
   demo_step_advanced, demo_completed, demo_exited_to_connect. Pure
   property-derivation logic lives in src/lib/demo-analytics.ts (no
   RN/PostHog imports, unit-tested with node --test, same pattern as
   analytics-classify.ts) and is wired into app/demo.tsx's lifecycle.
   Updated docs/analytics.md's event table and the privacy policy's event
   list (distribution/privacy-policy.md + its two HTML mirrors) per the
   repo's "new event requires a policy update" convention.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 19:49:47 -07:00
Den
63f3ec3c7e docs+consent: disclose activation analytics honestly across consent modal, privacy policy, and store docs (#81)
The app ships PostHog activation-funnel analytics gated behind the same
consent flag as Sentry, but the consent modal, Settings toggle, privacy
policy, and Play Data safety draft only mentioned crash reporting. Fix
the disclosure everywhere:

- TelemetryConsentModal: body + bullets + a11y labels now cover anonymous
  usage analytics (PostHog EU) alongside crash reports
- Settings: toggle renamed 'Crash Reports & Usage Analytics', description
  names both Sentry and PostHog
- Privacy policy (md + html + live gh-pages mirror): new section 3a with
  the full event/property table, PostHog EU destination, anonymous-ID
  statement, decline/revoke (drop-on-revoke) semantics; sections 4-7, 9
  and the Apple nutrition-label addendum updated for analytics
- play-listing.md: Data safety draft declares App interactions + Device
  or other IDs (opt-in, default OFF, shared with PostHog/Sentry)
- docs/playstore.md: Data safety row flipped to re-verify with pointer
  to the new design record
- docs/analytics.md: new design record — event schema, consent gating
  incl. buffered-event drop on revoke, disclosure surfaces to keep in
  sync, verification checklist (all TODO)
- website privacy page metadata mentions analytics opt-in

Closes #63


Claude-Session: https://claude.ai/code/session_01NJKAQ6HAikWGQK7PGZ5Y4E

Co-authored-by: engineer <engineer@gray-knight-m1.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 03:28:00 -07:00
Den
142518866b fix(metrics): repair review triage — correct secret wiring, privacy-safe aggregated issues. Closes #61. Refs #60. (#78)
* fix(metrics): repair review triage — correct secret wiring, privacy-safe aggregated issues

- triage-reviews.yml read secrets.GOOGLE_SERVICE_ACCOUNT_JSON, which doesn't
  exist; map the real PLAY_STORE_SERVICE_ACCOUNT_JSON secret onto the env var
  the script expects.
- triage-reviews.py rewritten to maintain a single sanitized, deduped
  "Play Store Review Triage" issue instead of one public issue per review.
  The old version leaked reviewer full names and verbatim review text into
  public GitHub issues and spammed the tracker. The new version aggregates
  actionable (<=3 star) reviews into one issue with rating counts, a
  word-frequency theme summary (no quoted sentences), and opaque review_id
  references for Play Console lookup. An embedded HTML comment marker
  (matching the product-intelligence.mjs pattern) holds the current
  actionable review_id set so runs update in place and skip entirely when
  nothing changed.
- product-intelligence.yml referenced the nonexistent
  SENTRY_PRODUCT_INTELLIGENCE_TOKEN secret, causing the daily cron to fail
  silently (#60). Fall back to SENTRY_AUTH_TOKEN when the dedicated
  read-only token isn't configured.
- docs/playstore.md: document that Play Console is still the only trusted
  source for acquisition/uninstall metrics (product-intelligence.mjs defers
  this), and that review-based signals are sourced via the Android
  Publisher API through PLAY_STORE_SERVICE_ACCOUNT_JSON.

Closes #61. Refs #60.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NJKAQ6HAikWGQK7PGZ5Y4E

* fix(triage): fail visibly when GOOGLE_SERVICE_ACCOUNT_JSON is missing

Review finding on PR #78: env_client() exited 0 on missing credentials,
so the scheduled workflow would report success while silently doing
nothing — contradicting issue #61's 'missing credentials fail visibly'
done-criteria.

---------

Co-authored-by: engineer <engineer@gray-knight-m1.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 18:00:41 -07:00
Den
5c14ce0a5d feat: add daily product intelligence and versioned site assets (#64)
Adds privacy-safe aggregate product intelligence, reviewed/versioned website assets, and a dispatch-only rollout until the dedicated Sentry token is verified. Independent review blockers were fixed in 8bc47e4; app checks, website production build, Android CI, and iOS CI are green.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-07-15 11:59:40 -07:00
Dennis V
d1071b2a44 fix(ios): close final release review blockers
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-07-14 17:49:53 +00:00
Dennis V
791588647b feat(ios): add native build and TestFlight automation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-07-14 06:16:36 +00:00
Dennis V
e29f381aab docs(tdd): correct stale references — clarify path.get()/serverHome, add speech.ts, fix version note
- §4: path.get() is still live (feeds serverHome → directory switcher ~ expansion);
  only the dead session-scoping plumbing (sessionScope.ts) was removed in 472ff8d.
  Clarify rather than delete, since the call site is not dead.
- §2: document src/lib/speech.ts (experimental voice input; PRD §7 scope caveat).
- §7: app.json and package.json versions are kept in sync since v0.4.6 (both 0.4.6).

Refs #43

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-06-23 15:36:35 +00:00
Dennis V
9498b19457 fix(pages): replace vibebrowser.app with agentlabs.cc across all pages
Replace stale opencode.vibebrowser.app / www.vibebrowser.app domain refs
with the current agentlabs.cc/opencode branding, and update the privacy
policy package id ai.opencode.mobile -> cc.agentlabs.opencode.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-06-23 05:18:12 +00:00
Dennis V
1f476f1eab fix(support): update contact email to support@agentlabs.cc
Replace all @vibebrowser.app email addresses with @agentlabs.cc across
22 files including privacy policy, Play/App Store listings, fastlane
metadata, docs, README, CONTRIBUTING, eas.json, and in-app mailto links.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-06-23 00:17:06 +00:00
engineer
92a022cfd1 qa: HEAD release build verified on-device — Quick Connect now succeeds (auth fix confirmed)
Built the actual release APK from HEAD (auth + UI fixes, BUILD SUCCESSFUL 11m48s) and
installed on the emulator. Same Quick Connect path that gave 401 on the CI APK now
CONNECTS and loads the sessions list. Definitive on-device proof of the fix on the
shipping build. Screenshots 07-08.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-08 09:13:28 -07:00
engineer
2476d4def5 qa: on-device GUI verification — connect+reply flow GREEN, auth bug reproduced
Ran a native arm64 emulator against the live opencode server, driven via adb (free
model, no LLM). Verified on real device: telemetry consent, empty state, Quick Connect
401 auth bug REPRODUCED, Advanced+username=opencode connects + loads sessions, chat
renders (bubbles/thinking/tokens), and LIVE send -> streaming reply. Screenshots +
writeup under docs/qa/. Closes the pre-posting test-gate pixel-GUI residual for the
connect->session->reply journey.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-08 08:51:07 -07:00
engineer
108260cec7 release: bump versionCode 5->6 for v0.4.4 + add changelog 6.txt
v0.4.3 already shipped as versionCode 5; a duplicate code would be rejected by Play and ignored by F-Droid. Bump to 6 unblocks the v0.4.4 release. QA gate passed (units + on-device E2E + visual render check screenshots in docs/qa/render-check/).
2026-06-08 08:36:53 -07:00
engineer
b0b30ea203 docs(qa): visual render-check evidence — real Gemini reply renders bug-free
Clears the owner's hard visual gate: a real gemini-2.5-flash reply rendered
through the actual app components (MessageBubble→Markdown/CodeBlock, DiffView)
via Expo web export, screenshotted in a real browser.

Per-surface verdict (all PASS, no app code changes needed):
- markdown: heading+bullets, high contrast light & dark
- code block: 430-char single line horizontally scrolls (scrolled-right reveals
  the line END), not truncated/wrapped
- diff: fenced ```diff + native DiffView render +/- coloring and scroll

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-08 08:33:50 -07:00
engineer
e39cec3847 fix(launch): Expo SDK 52->54 in HN/Reddit copy; add reply-flow E2E evidence; version refs
- Launch posts claimed Expo SDK 52 but app is on SDK 54 (factual accuracy
  before public posting — HN/Reddit devs check this)
- docs/qa/REPLY-FLOW-E2E-2026-06-08.md: verified send->streaming reply works
  against the live opencode server via app-identical sdk.ts calls (free model);
  closes the 'opencode can't reply in CI' residual at the data-contract level
- owner-submissions.md: 0.4.3 -> 0.4.4

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-08 07:42:19 -07:00
engineer
6563f5ef53 fix(ui): correct mirrored chat empty-state + clipped IP placeholder; add readiness-check skill; privacy page nav/meta
- app/session/[id].tsx: chat empty-state rendered mirrored on Android (inverted FlatList) — now an untransformed overlay
- app/connection/add.tsx: shortened clipped host placeholder
- .agents/skills/readiness-check: production-readiness gate (Play+F-Droid published, app+site health)
- docs/privacy: back-nav + canonical/theme-color/description meta
Verified: tsc clean, CUA smoke green (run 26814702062)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-03 06:16:22 -07:00
engineer
dc7cc749c2 docs(distribution): cite live GitHub Pages privacy URL for store submissions (unblocks Play/IzzyOnDroid)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-02 17:11:39 -07:00
Den
c9a57901c4 fix(ci): CUA smoke true-E2E with local opencode server (#15) (#18)
* chore: repoint OpenCode links to agentlabs.cc/opencode

agentlabs.cc/opencode and /opencode/privacy are now live (200). Repoint
README, distribution listings (Play/App Store/F-Droid/IzzyOnDroid/iOS),
docs, and in-app privacy links (settings + telemetry consent) from
www.vibebrowser.app/opencode to the canonical agentlabs.cc hub.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(ci): run local opencode server for CUA smoke true-E2E (#15)

GitHub-hosted runners can't reach the Tailscale dev server
(100.108.64.76:4096), so the CUA smoke always failed at session creation.

- Install opencode-ai and run `opencode serve` on the runner host; the
  Android emulator reaches it via 10.0.2.2. OPENCODE_URL now points there.
- Healthcheck /global/health before launching the app; dump server log on
  failure for diagnosis.
- Add --only-connect-scenario to the smoke script and run just the
  connect-and-verify-sessions path in CI: deterministic, needs no model
  backend. The scenario now creates a session if the list is empty, so a
  fresh server still yields a non-empty list.

This makes the smoke a true E2E and also exercises the #10 sessions-list
rendering path against a real server.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(ci): emulator smoke script is dash, not bash — drop brace-group healthcheck

android-emulator-runner runs the script: block under /usr/bin/sh (dash). The
multi-line `|| { ...; }` healthcheck was a dash syntax error (end of file
unexpected), failing the step before the smoke ran. Replace with a non-fatal
one-line re-check; the server was already health-gated in the prior step.

* docs(tasks): record smoke CI round 1 failure + dash fix

---------

Co-authored-by: engineer <engineer@opencode.ai>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-01 15:32:06 -07:00
engineer
c667331593 docs(privacy): publish privacy policy via GitHub Pages (cc.agentlabs.opencode)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-05-30 13:14:15 -07:00
Dennis V
b8fb390f5c feat(release): production signing in build.yml + F-Droid metadata filled
- build.yml: use production keystore (KEYSTORE_BASE64) on tag pushes,
  fall back to debug key for PRs/branch builds — build.gradle already
  reads RELEASE_STORE_FILE env var so no Gradle changes needed
- distribution/fdroid-submission/metadata.yml: filled
  AllowedAPKSigningKeys with actual SHA-256 fingerprint, commit tag
  updated to v0.3.1, version bumped to 0.3.1
- app.json: bump version 0.2.3 → 0.3.1, versionCode 1 → 2
- Add eas.json + EAS README for iOS App Store builds
- Add fastlane/metadata/android for Play Store / F-Droid graphics
- Add distribution docs: applestore, fdroid, market, playstore,
  security, threat-model, opencode-site-deploy

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-26 01:26:35 +00:00
Dennis V
24667ee4f4 feat(crash): comprehensive crash + error reporting for v0.2.3
Adds full-stack crash capture so any unexpected failure — React render,
uncaught JS exception, unhandled promise rejection, or native — is
reported to Sentry with rich, scrubbed context. Expected operational
errors (timeouts, biometric cancel, etc.) stay local to preserve signal.

Changes:
- src/lib/sentry.ts: explicit native crash handlers, release/dist tags
  from app.json, beforeSend/beforeBreadcrumb URL+secret scrubbing,
  addBreadcrumb/captureException helpers, ErrorUtils + onunhandledrejection
  wrappers that always feed the in-memory log buffer (so offline Share
  Report includes the crash too).
- src/components/ErrorBoundary.tsx: new app-wide React boundary with a
  dark recovery screen — error message, top stack/component frames,
  Share Report (clipboard + native share sheet) and Try Again.
- src/lib/diagnostics.ts: buildCrashReport() reuses the existing
  DiagnosticReport pipeline so crashes and connect failures share one
  UI and one transport.
- _layout.tsx: wraps app in ErrorBoundary; emits app.lifecycle
  breadcrumb at startup.
- stores/{connections,events,sessions}.ts: high-signal breadcrumbs at
  connect, SSE connect/disconnect/reconnect, and session select.
- (tabs)/settings.tsx: fix unhandled promise on notificationsGranted().
- app.json: bump expo.version to 0.2.3.
- docs/prd.md, docs/tdd.md: new product + technical design docs.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-23 09:00:26 +00:00