Repository navigation
Conversation
Adds a JSON encoder/decoder whose number formatting and string escaping match JSON.stringify exactly, so content the daemon writes is byte-identical to what deco serve writes. The tests are the spec. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Maps block keys to file names with encodeURIComponent parity and resolves the spellings a key may have on disk; adds the protocol's error codes. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
A content store over the sandbox working tree: contained to the tree, writes under a commit lock, durable writes and rollback on failure. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
…escer Moves regenerateGenArtifact and decofileCommitMessage out of commit-coalescer.ts into decofile/gen-artifact.ts so the hosted publish path (later in this stack) can reuse them. No behavior change. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Adds `@decocms/[email protected]` to apps/api (the hosted path uses its decofile/release helpers). The Dockerfile and the tarball smoke test now start Studio by the path of its CLI, and a test pins the v7 secret-loader exemption. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Refuses plaintext in v8 Secret fields and validates ciphertext shape; the v7 secret loader stays exempt. Its unit tests (secrets_test.go) land in the next PR, because they also cover servablePublicKey from methods.go. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
…, blocks.apply) The content-protocol JSON-RPC handler: envelope and batch handling, the four methods, blocks.apply ifMatch and retry, and request body limits. Also adds secrets_test.go (the secret guard from the previous PR plus describe's servablePublicKey). Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Asset uploads with name sanitizing, plus HTTP-level tests for the store, secrets, RPC and uploads. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Mounts the content protocol and asset uploads on the daemon behind its auth, and adds worktree.Lock.AcquireWithin so a write never lands after its client gave up. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Adds the hosted delivery bucket settings (R2/S3), `deliveryStore` (read/write release objects with ETag handling) and `deliveryPurge` (CDN purge with one retry), plus shared test helpers. Nothing calls them yet; the routes land in #10/#11. A temporary knip `ignoreIssues` entry for `apps/api/src/hosted/*.ts` (unused exports only) is removed in PR 11 of this track. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Adds the CDN draft store and a content storage that layers the draft over the repo main branch (read-only repo storage underneath), so a hosted v8 project can be edited without a running sandbox. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Runs the published @decocms/blocks content-protocol conformance suite against the real Go daemon (its /_sandbox/rpc and /assets routes), and adds @decocms/blocks as a sandbox devDependency for it. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Adds release objects and `publishDraft`: commits the draft to main, writes the release to the CDN bucket, updates latest.json and purges it. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
…cope, draft publish status Adds the `site_editor_content_protocol` org flag (off by default; `tool-io.ts` regenerated, flag hunks only), the releases timeline, the project-to-site scope helper and the draft publish status loader. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Adds Ed25519-signed site tokens for hosted v8 sites (issue and verify). Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
When a project is created for a deco.cx site, claims that site slug for the project's org (bounded deco.cx lookup), so later hosted routes can scope by org-owns-site. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Adds an admin-only route that backfills site claims for existing projects, using the claim logic from the previous PR. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Wires the hosted modules into routes: the decofile `/rpc` endpoint, the v8 draft pointer and publish on the session routes, the hosted routes (releases, site tokens), all behind the `site_editor_content_protocol` flag and scoped to the org that owns the site. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Proxies the content protocol `/_sandbox/rpc` to the sandbox daemon with the same auth and site claim as the other sandbox routes, and reports the draft publish status. Removes the temporary knip ignore for `apps/api/src/hosted/*.ts` added in PR 3 of this track; every hosted export now has a consumer. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
The e2e specs exercise the hosted API routes, so this branch carries the API stack (plan PRs 1-11) as a normal merge. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
…e2e stack Carries the daemon stack (plan PRs 12-19) as a normal merge so the e2e branch holds all three tracks. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Adds an in-memory stand-in for the hosted Deco CMS delivery bucket/CDN and wires it into the Playwright web server env, registered as a knip entry. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
This was referenced Oct 8, 2026
This was referenced Oct 8, 2026
Closed
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds an in-memory stand-in for the hosted Deco CMS delivery bucket/CDN (
packages/e2e/fixtures/delivery-stub-server.ts), wires it into the Playwright web-server env, and registers it as a knip entry.Merge after the API, daemon and web stacks. This branch is cut from the top of the web stack (#7840) and contains the API stack (#7825) and the daemon stack (#7820) through two normal merge commits, because the e2e specs drive all three. GitHub therefore shows those stacks' changes in this PR's diff; this PR's own change is only the last commit (
test(e2e): delivery CDN stub server, 3 files, +251/-3). Once the API and daemon stacks are merged, the diff shrinks to that commit.What to look at
Stack
e2e track: previous: #7840 (web track top; also merges #7825 and #7820) · next: #7842
🤖 Generated with Claude Code
https://claude.ai/code/session_01WNwbSEePYNcY5YCgqZURig
Summary by cubic
Adds an in-memory stand-in for the hosted Deco CMS delivery bucket/CDN so the e2e specs can exercise the hosted content-protocol flows end to end.
packages/e2e/fixtures/delivery-stub-server.tsserves the S3 API Studio writes through (PUT/GET/HEAD/DELETE, list), the public origin sites read (with ETag and Cache-Control), and a__adminendpoint for assertions.This branch carries the API and daemon stacks as merges because the e2e specs drive all three; the stub server itself is the last commit and the diff shrinks to it once those merge.
Written for commit 62c6449. Summary will update on new commits.