deepseek-harness/docs
Yichen Jiang 9eaaeaeb96 fix(credentials,authorization,llm-pi-ai): harden the auth seams per review
Review findings on #2509, all confirmed:

- Every writer of .credentials.yaml now waits out the record-mutation
  lock (DOCUMENT_LOCK_WAIT_MS): refs and records share one file and one
  lock, so a reference write or record delete contending with an OAuth
  refresh must not fail at the 2s file-work default.
- api-key records are admitted before they are rendered: an empty key,
  a non-POSIX env name, or an empty env value is refused at the write
  instead of persisting a document the next boot rejects wholesale.
- llm-pi-ai no longer lets the credential-key grammar reject legal
  route ids: reads answer "nothing stored" via isCredentialKeySegment
  (new dsh-credentials export), deletes have nothing to remove, and only
  a write refuses, as LlmError UNSTORABLE_PROVIDER_ID; flow registration
  skips a future catalog id outside the grammar instead of failing the
  mount.
- authorization/settled fans out with contained listener failures on
  the credentials seam's terms (INVARIANT still rethrows), so a broken
  watcher can never turn a finished attempt into a failure.
- notify() is fire-and-forget at the seam: a surface that cannot render
  a notice loses the notice, never the attempt.
- A declined prompt is an outcome: interactions reject with the new
  AuthorizationDeclinedError and the attempt settles cancelled instead
  of failed.
- NOT_COMMITTED now confirms a commit observed during the attempt
  (credentials/record-updated for the flow's key), so a re-auth cannot
  pass a stale record off as fresh; a flow that deletes its record is
  refused on the same code.

READMEs, the subsystem/event/config catalogs, and the Agent Note follow
the shipped behavior; memory.ts carries the dedup TODO.
2026-08-20 17:58:38 +08:00
..
cookbook Merge remote-tracking branch 'origin/master' into feat/plugin-owned-settings-surface 2026-08-14 15:46:01 +08:00
cordis-api fix: test/docs 2026-08-13 01:30:49 +08:00
cordis-tutorial docs: fix release smoke test failures 2026-08-13 14:20:09 +08:00
i18n docs: split brand guidelines into bilingual pair 2026-08-19 21:01:18 +08:00
postmortem refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
subsystems fix(credentials,authorization,llm-pi-ai): harden the auth seams per review 2026-08-20 17:58:38 +08:00
user docs(user): point the provider guide at the adapter's catalog section 2026-08-19 13:46:39 +08:00
agent-lifecycle.i18n.yaml refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
agent-lifecycle.md refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
agent-lifecycle.zh.md refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
AGENTS.md update architeture.md 2026-08-12 21:01:11 +08:00
api-gateway.i18n.yaml refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
api-gateway.md refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
api-gateway.zh.md refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
architecture.i18n.yaml docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
architecture.md docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
architecture.zh.md docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
capability-seams.i18n.yaml feat(authorization): obtain a credential by asking the human 2026-08-20 17:58:38 +08:00
capability-seams.md feat(authorization): obtain a credential by asking the human 2026-08-20 17:58:38 +08:00
capability-seams.zh.md feat(authorization): obtain a credential by asking the human 2026-08-20 17:58:38 +08:00
config-catalog.i18n.yaml fix(credentials,authorization,llm-pi-ai): harden the auth seams per review 2026-08-20 17:58:38 +08:00
config-catalog.md fix(credentials,authorization,llm-pi-ai): harden the auth seams per review 2026-08-20 17:58:38 +08:00
config-catalog.zh.md fix(credentials,authorization,llm-pi-ai): harden the auth seams per review 2026-08-20 17:58:38 +08:00
cordis-primer.i18n.yaml docs: fix release smoke test failures 2026-08-13 14:20:09 +08:00
cordis-primer.md refactor: apply repository naming contract 2026-08-13 00:54:38 +08:00
cordis-primer.zh.md docs: fix release smoke test failures 2026-08-13 14:20:09 +08:00
defensive-patterns.i18n.yaml docs: add junction-safe unlink rule to defensive patterns 2026-08-13 15:16:12 +08:00
defensive-patterns.md docs: add junction-safe unlink rule to defensive patterns 2026-08-13 15:16:12 +08:00
defensive-patterns.zh.md docs: add junction-safe unlink rule to defensive patterns 2026-08-13 15:16:12 +08:00
development.i18n.yaml feat(build): bind client artifacts to build profiles 2026-08-19 18:21:27 +08:00
development.md feat(build): bind client artifacts to build profiles 2026-08-19 18:21:27 +08:00
development.zh.md feat(build): bind client artifacts to build profiles 2026-08-19 18:21:27 +08:00
event-producer-consumer.i18n.yaml fix(credentials,authorization,llm-pi-ai): harden the auth seams per review 2026-08-20 17:58:38 +08:00
event-producer-consumer.md fix(credentials,authorization,llm-pi-ai): harden the auth seams per review 2026-08-20 17:58:38 +08:00
event-producer-consumer.zh.md fix(credentials,authorization,llm-pi-ai): harden the auth seams per review 2026-08-20 17:58:38 +08:00
glossary.i18n.yaml docs: capitalize Service Provider across repository 2026-08-13 13:31:30 +08:00
glossary.md docs: capitalize Service Provider across repository 2026-08-13 13:31:30 +08:00
glossary.zh.md docs: capitalize Service Provider across repository 2026-08-13 13:31:30 +08:00
graph-atlas.i18n.yaml refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
graph-atlas.md refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
graph-atlas.zh.md docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
module-graph.i18n.yaml test: sync permission origin artifacts 2026-08-20 00:01:28 +08:00
module-graph.md test: sync permission origin artifacts 2026-08-20 00:01:28 +08:00
module-graph.zh.md test: sync permission origin artifacts 2026-08-20 00:01:28 +08:00
persistence-catalog.i18n.yaml Merge remote-tracking branch 'origin/master' into xtr/projection-state-schema 2026-08-20 13:21:03 +08:00
persistence-catalog.md Merge remote-tracking branch 'origin/master' into xtr/projection-state-schema 2026-08-20 13:21:03 +08:00
persistence-catalog.zh.md Merge remote-tracking branch 'origin/master' into xtr/projection-state-schema 2026-08-20 13:21:03 +08:00
rescope.i18n.yaml build(vendor): add the @deepseek-ai rescope codemod, its mapping doc, and its Agent Note 2026-08-10 22:04:10 +08:00
rescope.md build(vendor): add the @deepseek-ai rescope codemod, its mapping doc, and its Agent Note 2026-08-10 22:04:10 +08:00
rescope.zh.md build(vendor): add the @deepseek-ai rescope codemod, its mapping doc, and its Agent Note 2026-08-10 22:04:10 +08:00
testing.i18n.yaml test(python): pin the minimal composition's model-visible surface 2026-08-17 16:49:14 +08:00
testing.md test(python): pin the minimal composition's model-visible surface 2026-08-17 16:49:14 +08:00
testing.zh.md test(python): pin the minimal composition's model-visible surface 2026-08-17 16:49:14 +08:00
tool-catalog.i18n.yaml docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
tool-catalog.md docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
tool-catalog.zh.md docs: refresh Agent Teams catalogs 2026-08-19 22:44:23 +08:00
tool-execution-pipeline.i18n.yaml refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
tool-execution-pipeline.md refactor: replace overloaded surface terminology 2026-08-11 15:23:05 +08:00
tool-execution-pipeline.zh.md docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
web-styling.i18n.yaml docs: make technical prose concrete 2026-08-10 16:34:20 +08:00
web-styling.md
web-styling.zh.md docs: make technical prose concrete 2026-08-10 16:34:20 +08:00