48c31dc1b3
Ten git worktrees each carried their own 225 MB node_modules (1.1 GB across five) and paid 11s per `npm ci`. pnpm hardlinks from a shared store: the same five worktrees cost ~250 MB total, and a fresh install is 4s. What changed beyond the mechanical rename: - `overrides` moved to `pnpm-workspace.yaml`. pnpm 11 does not read the `pnpm` field in package.json *or* npm's top-level `overrides`, and it fails silently — the vite/defu/language-server pins would have quietly stopped applying. - Build scripts are blocked by default in pnpm; esbuild and sharp are allowed explicitly via `allowBuilds` (renamed from `onlyBuiltDependencies` in 11). - `packageManager` + `engines` pin the toolchain. - gate.sh rejects a package-lock.json/yarn.lock/bun.lock outright, so an agent running `npm install` out of habit fails loudly instead of building a second, divergent dependency tree. - CI bootstraps pnpm with `npm install --global pnpm@11.25.0` rather than corepack (unbundled as of Node 25) or pnpm/action-setup (this self-hosted act-runner has never run a job; fetching a third-party action is not something to discover on the first one). Two pre-existing CI bugs fixed while in the file: - the gate installed with `npm install --package-lock=false`, which discarded the lockfile the previous session had just fixed. - the visual-regression step imported `playwright`, which is not a dependency, and `visual-regression.mjs` has no compare mode anyway — in CI it overwrote its own baselines and passed unconditionally. Removed with a comment; it comes back when it can diff. The `publish` job is now manual (`workflow_dispatch`). During the migration dist/ holds three HTML files against the live pages branch's ten, so publishing on every push to main would take the site down to a stub. Restore at task 20. HANDOVER.md's incident log still says npm where it describes what happened at the time; that is history, not a missed rename. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
65 lines
2.6 KiB
Markdown
65 lines
2.6 KiB
Markdown
# Task 16 — Review desk
|
|
|
|
**Agent**: `page-migrator` · **Model**: **Codex** — highest defect risk
|
|
**Depends on**: 06, 11, 13 · **Parallel with**: 15 **Worktree**:
|
|
`.agents/scripts/worktree.sh start 16 page-review-desk`
|
|
|
|
## Goal
|
|
|
|
`/skills-review/` → Astro. The most interactive page: search, filtering, lazy
|
|
file fetching, markdown rendering, a client-side diff view, six URL params, and
|
|
a live API call to `vote-service/`.
|
|
|
|
## The six query params are a public contract
|
|
|
|
`?author=`, `?skill=`, `?view=`, `?file=`, `?compare=`, `?render=` — documented
|
|
in the page footer and shared externally. All six must round-trip, and browser
|
|
back/forward must restore state (`syncUrl` / `selectFromUrl` today).
|
|
|
|
**Test every one manually.** A snapshot diff cannot catch a broken deep link.
|
|
|
|
## Islands
|
|
|
|
The catalog + detail pane is genuinely interactive: `client:load` is justified
|
|
here. The vote widget is `client:visible`. Everything else server-renders.
|
|
|
|
## vote-service integration
|
|
|
|
`window.SKILLS_REVIEW_VOTE_API = 'https://ai-for-dummies-vote.marcospaulo.dev.br'`
|
|
is set inline in `index.html` today. Either keep the global or move it to
|
|
`PUBLIC_VOTE_API` — **if you move it, update `vote-service/README.md` in the
|
|
same change**, since it documents the coupling.
|
|
|
|
`ALLOWED_ORIGIN` on the deployed service is
|
|
`https://netcracker.pages.marcospaulo.dev.br`. If the site's origin changes, the
|
|
vote API breaks with a CORS error. It does not change in this plan — but verify
|
|
after cutover.
|
|
|
|
## Asserted by verify.mjs
|
|
|
|
Interaction tokens: `from './catalog.js'`, `from './files.js'`, `renderList`,
|
|
`renderDetail`, `selectSkill`, `packageSummary`, `markdownHeadings`,
|
|
`markdownToc`, `loadSelectedFile`, `schedulePackageSearch`, `fetchSource`,
|
|
`packageSearchText`, `diffMarkup`, `diffRows`, `searchParams.set('compare')`,
|
|
`markdownMarkup`, `syncUrl`, `selectFromUrl`, `URLSearchParams`,
|
|
`navigator.clipboard`, `document.execCommand`.
|
|
|
|
Plus the catalog count: `id:'` occurrences across both catalogs **must equal
|
|
24**.
|
|
|
|
Same rule as task 15 — re-point with task 19, never delete.
|
|
|
|
## Watch for
|
|
|
|
The markdown renderer is hand-rolled (`markdownMarkup`, `markdownHeadings`,
|
|
`markdownToc`). Task 06 moves rendering to build time — but the **diff view
|
|
needs raw source text**, not rendered HTML. Keep both available.
|
|
|
|
## Done when
|
|
|
|
- [ ] All six query params round-trip; back/forward restores state
|
|
- [ ] Search, filter, file tabs, preview, change lens, download, copy all work
|
|
- [ ] Vote widget reaches the live API; CORS preflight succeeds
|
|
- [ ] Snapshot diff empty; screenshots match; checklist complete
|
|
- [ ] `pnpm run gate` green
|