Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
71 commits
Select commit Hold shift + click to select a range
0c4fb13
fix(copilot): keep a file-preview failure from stripping a tool call'…
waleedlatif1 Aug 12, 2026
5cf60f6
fix(v2): give every collection one pagination contract and close four…
waleedlatif1 Aug 12, 2026
878856b
chore(ci): declare least-privilege permissions on the desktop e2e wor…
waleedlatif1 Aug 12, 2026
74212ef
feat(models): add grok-4.6 and make it the xAI flagship (#6624)
waleedlatif1 Aug 12, 2026
afa0293
fix(docs): include API key header in generated code samples (#6630)
TheodoreSpeaks Aug 12, 2026
9dfd9db
feat(xai): wire reasoning effort through the Grok adapter (#6627)
waleedlatif1 Aug 12, 2026
6541a22
fix(v2): tell a caller when to come back on every failure meant to be…
waleedlatif1 Aug 12, 2026
81108d5
fix(v2): serve HEAD, advertise PATCH, and document the reachable 403 …
waleedlatif1 Aug 12, 2026
3ae83b1
fix(desktop): fix desktop prod ci #6628
Sg312 Aug 12, 2026
f4ee41b
improvement(blog): simplify provenance post structure (#6631)
icecrasher321 Aug 12, 2026
c411b1d
fix(workflow): allow dual-mode blocks inside loop/parallel subflows (…
j15z Aug 12, 2026
7022e2e
fix(workflow): stop the coloured knob leaving a barb at each shoulder…
waleedlatif1 Aug 12, 2026
8a0b328
fix(blocks): give a block one tile everywhere it is listed (#6634)
waleedlatif1 Aug 12, 2026
0e65ca3
fix(copilot): surface document render failures (#6629)
j15z Aug 12, 2026
7c2ba46
fix(cmdk): keep the first result focused and the top fog stable acros…
j15z Aug 12, 2026
1b63541
fix(v2): give the keyset cursor's timestamp an explicit SQL type (#6636)
waleedlatif1 Aug 12, 2026
9aa16e3
improvement(workflow): smooth the running hatch and sit it in the slo…
waleedlatif1 Aug 12, 2026
2805a8d
feat(windchill): add document integration (#6577)
BillLeoutsakosvl346 Aug 12, 2026
128054e
fix(workflow): stop subflows resizing themselves after every load (#6…
waleedlatif1 Aug 12, 2026
1fa40b8
feat(v2): complete and align the v2 API surface (#6643)
waleedlatif1 Aug 12, 2026
c58a642
fix(workflow): stop a nested block jumping when it leaves its contain…
waleedlatif1 Aug 12, 2026
e56b288
fix(workflow): draw a highlighted edge over the ordinary ones (#6642)
waleedlatif1 Aug 12, 2026
9f8d4d1
fix(billing): checkout guard, admin panel case (#6641)
icecrasher321 Aug 12, 2026
1faac4e
fix(tools): sanitize database execution errors (#6645)
TheodoreSpeaks Aug 12, 2026
aeb77dd
fix(files): allow document compiler to read referenced images (#6647)
TheodoreSpeaks Aug 12, 2026
f890c89
improvement(emails): size the header wordmark to the landing navbar's…
waleedlatif1 Aug 12, 2026
51df824
fix(copilot): align principal lifetime with orchestration (#6649)
TheodoreSpeaks Aug 13, 2026
2da8015
fix(enrichment): require work email company domain (#6531)
TheodoreSpeaks Aug 13, 2026
738006d
fix(emails): re-export the wordmark onto its original canvas (#6651)
waleedlatif1 Aug 13, 2026
29853fb
improvement(docs): make the API reference read as code and unify its …
waleedlatif1 Aug 13, 2026
ec70c4d
improvement(nav): cut prefetch and session-recorder waste (#6656)
waleedlatif1 Aug 13, 2026
e4019fa
fix(files): preserve principals when serving generated documents (#6654)
TheodoreSpeaks Aug 13, 2026
e8d278b
fix(files): stop the collaborative editor rewriting and reflowing a d…
icecrasher321 Aug 13, 2026
c49751b
perf(prefetch): stop calling our own API over the wire during server …
waleedlatif1 Aug 13, 2026
618cee5
test(prefetch): cover the workspace-list seed, and fix two tests that…
waleedlatif1 Aug 13, 2026
0c4e674
perf(server): stop calling our own API over HTTP during render, execu…
waleedlatif1 Aug 13, 2026
1e60042
fix(tools): resolve credentials over HTTP again so token refresh keep…
waleedlatif1 Aug 13, 2026
6de8ba2
fix(v2): close the correctness gaps an end-to-end audit found (#6655)
waleedlatif1 Aug 13, 2026
bed25e2
fix(realtime): keep the file-doc store reconnecting instead of dying …
icecrasher321 Aug 13, 2026
cc7f005
feat(emails): add aug-13 what's new broadcast (#6663)
waleedlatif1 Aug 13, 2026
9c7b243
fix(sidebar): keep the right-click context menu open over the collaps…
waleedlatif1 Aug 13, 2026
8d319a4
fix(v2): close the correctness gaps the release audit found (#6671)
waleedlatif1 Aug 13, 2026
1a62c44
improvement(canvas): cancel an in-flight edge drag with Escape (#6669)
waleedlatif1 Aug 13, 2026
85c8451
fix(blocks): give the detail headers the same tile as everything else…
waleedlatif1 Aug 13, 2026
2da8855
test(realtime): wait for the idle read the streak test depends on (#6…
icecrasher321 Aug 13, 2026
86dbd0a
improvement(search): make overlap dedupe linear in match count (#6640)
mzxchandra Aug 13, 2026
49ec9a9
fix(loading): debounce selector search, fix two row-cache snapshots, …
waleedlatif1 Aug 13, 2026
0758df3
perf(workspace): stop the sidebar fetching palette data on every rout…
waleedlatif1 Aug 13, 2026
e2b7335
fix(v2): stop telling callers something the server did not do (#6676)
waleedlatif1 Aug 13, 2026
c155a57
fix(desktop): move prereleases to release repo (#6674)
TheodoreSpeaks Aug 13, 2026
58b5ee9
feat(logrocket): add LogRocket integration (#6678)
waleedlatif1 Aug 13, 2026
046302a
fix(sidebar): stop bubbled dragleave events cancelling an in-progress…
waleedlatif1 Aug 13, 2026
1424809
feat(netsuite): add Oracle NetSuite integration (#6476)
BillLeoutsakosvl346 Aug 13, 2026
44524d1
fix(autolayout): rescue new notes from blocks they were created on to…
j15z Aug 13, 2026
ab8a64f
fix(v2): close the defects live probing found (#6681)
waleedlatif1 Aug 13, 2026
4ff339e
fix(chat): focus the composer when opening a new or existing chat (#6…
waleedlatif1 Aug 13, 2026
9fc6586
fix(v2): hold create to the rules update enforces, and bind the last …
waleedlatif1 Aug 14, 2026
264d4f3
feat(canvas): add a setting to turn off auto-focus when clicking bloc…
waleedlatif1 Aug 14, 2026
9436a93
feat(library): How to Turn a Workflow Into a Reusable MCP Tool (Sim v…
icecrasher321 Aug 14, 2026
b9b9c9c
fix(canvas): stop phantom ports and a latched-open action bar (#6688)
waleedlatif1 Aug 14, 2026
009f5fe
fix(logs): record how long a cancelled run had been going (#6686)
waleedlatif1 Aug 14, 2026
fa394e5
fix(execution): resolve secrets against the acting principal, not the…
icecrasher321 Aug 14, 2026
9aa36a4
fix(icons): match folder icon optical size to sibling resource icons …
waleedlatif1 Aug 14, 2026
c6047ef
fix(sidebar): align credits chip with panel toggle and square the col…
j15z Aug 14, 2026
b9a70e4
fix(execution): give a cancelled async run its terminal metadata (#6693)
waleedlatif1 Aug 14, 2026
b2b6e55
fix(tables): stop every table paginating forever on a null totalCount…
waleedlatif1 Aug 14, 2026
0239db8
fix(desktop): report a stock Chrome user agent in the browser tab (#6…
waleedlatif1 Aug 14, 2026
0650eab
fix(desktop): let sites copy to the clipboard in the browser tab (#6696)
waleedlatif1 Aug 14, 2026
4181912
fix(search): stop cmd+k boosts from lifting weaker matches over stron…
j15z Aug 14, 2026
7f64d5e
perf(tables): stop a table write refetching every loaded page in the …
waleedlatif1 Aug 14, 2026
3051954
fix(agent): show files in tool picker (#6666)
j15z Aug 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
10 changes: 10 additions & 0 deletions .agents/skills/ship/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -100,6 +100,16 @@ improvement(scope): description for enhancements
chore(scope): description for maintenance
```

## What to Omit

The repo is public. Keep the title and description to the code change and its reasoning — never:

- Customer, company, or user names; workspace/user/org IDs; email addresses
- Prod or staging operational data: log lines, DB rows, metrics, timestamps, incident details, canary/alert output
- Infrastructure specifics: hostnames, ARNs, internal URLs, env var values, secret names

Describe the bug by its mechanism, not by how you found it. "Expired OAuth credentials fail to refresh in the worker" — not "the Sheets canary failed at 16:31Z for workspace abc-123".

## PR Description Format

Use this exact template in the user's voice (concise, bullet points):
Expand Down
4 changes: 4 additions & 0 deletions .agents/skills/tool-registry-boundary/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,10 @@ If it fails, do not add the entry to an allowlist — there isn't one. Find the

Run it with `--verbose` to print per-route module counts, which is also the quickest way to see whether a change moved the graph.

The same command also ratchets those counts against `check-tool-registry-boundary.baseline.json`. `--check` (what CI runs) fails when an entry exceeds its baseline by more than `max(25 modules, 2%)`, naming the import chain responsible. This catches bloat the registry rule misses — a prefetch importing `listTables` cost the Tables page 444 modules without ever touching `@/tools/registry`.

Re-record with `--update-baseline` and commit the JSON when growth is deliberate. A *shrink* passes but is reported — re-record then too, or the win is silently spendable again.

## How to verify an edge actually got cut

Do not eyeball imports — the registry is reached through several redundant paths, so cutting one buys nothing while another survives. Walk the graph:
Expand Down
233 changes: 233 additions & 0 deletions .agents/skills/v2-api-conventions/SKILL.md

Large diffs are not rendered by default.

10 changes: 10 additions & 0 deletions .claude/commands/ship.md
Original file line number Diff line number Diff line change
Expand Up @@ -99,6 +99,16 @@ improvement(scope): description for enhancements
chore(scope): description for maintenance
```

## What to Omit

The repo is public. Keep the title and description to the code change and its reasoning — never:

- Customer, company, or user names; workspace/user/org IDs; email addresses
- Prod or staging operational data: log lines, DB rows, metrics, timestamps, incident details, canary/alert output
- Infrastructure specifics: hostnames, ARNs, internal URLs, env var values, secret names

Describe the bug by its mechanism, not by how you found it. "Expired OAuth credentials fail to refresh in the worker" — not "the Sheets canary failed at 16:31Z for workspace abc-123".

## PR Description Format

Use this exact template in the user's voice (concise, bullet points):
Expand Down
4 changes: 4 additions & 0 deletions .claude/commands/tool-registry-boundary.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,10 @@ If it fails, do not add the entry to an allowlist — there isn't one. Find the

Run it with `--verbose` to print per-route module counts, which is also the quickest way to see whether a change moved the graph.

The same command also ratchets those counts against `check-tool-registry-boundary.baseline.json`. `--check` (what CI runs) fails when an entry exceeds its baseline by more than `max(25 modules, 2%)`, naming the import chain responsible. This catches bloat the registry rule misses — a prefetch importing `listTables` cost the Tables page 444 modules without ever touching `@/tools/registry`.

Re-record with `--update-baseline` and commit the JSON when growth is deliberate. A *shrink* passes but is reported — re-record then too, or the win is silently spendable again.

## How to verify an edge actually got cut

Do not eyeball imports — the registry is reached through several redundant paths, so cutting one buys nothing while another survives. Walk the graph:
Expand Down
232 changes: 232 additions & 0 deletions .claude/commands/v2-api-conventions.md

Large diffs are not rendered by default.

21 changes: 21 additions & 0 deletions .claude/rules/sim-architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,27 @@ Use the `migrate-application-operation` skill before creating or migrating a pro

Every export of a `'use client'` module becomes a *client reference* on the server — server-evaluated code (RSC pages/layouts, `prefetch.ts`, route handlers, block definitions, triggers) can only *render* it as a component or pass it as a prop, never *call* it (doing so throws at runtime, e.g. `tableKeys.list is not a function`; `next build` does not catch it). Keep server-importable query primitives (key factories, fetchers, mappers, constants) in non-`'use client'` modules — see `.claude/rules/sim-queries.md`. Enforced by `scripts/check-client-boundary-imports.ts`.

## The app/worker runtime boundary

Server code runs in two runtimes with **different environments**. The app container loads the
full env from `SIM_ENV_SECRET_ID` (Secrets Manager). Trigger.dev workers — which execute
workflows, so every block handler and every tool call — get their env from the Trigger.dev
dashboard, and `trigger.config.ts` syncs only `DB_APP_NAME`. The repo cannot see what the
dashboard holds.

So before replacing a worker's HTTP call to our own API with an in-process call, ask what env
that work reads *on the app side*. Anything gated by a `require*Capability` helper is the sharp
case: those **throw** when the variable is absent (`requireOAuthClientCapability` →
`EnvCapabilityConfigurationError`), and the throw may be caught and reported as something
unrelated. OAuth token refresh is the known example — moving it into the worker turns every
expired credential into `Failed to refresh access token`, while a still-valid token hides the
bug entirely, so it surfaces hours later and only for whoever's token lapsed first.

An in-process conversion is safe when the same work already runs in that runtime (the agent
block has always called `executeProviderRequest` in-process, so router and evaluator joining it
is proven), or when the caller and the callee are both the app (a route calling a lib module, an
RSC prefetch reading the data layer). It is not safe on reasoning alone.

## Feature Organization

Features live under `app/workspace/[workspaceId]/`:
Expand Down
16 changes: 16 additions & 0 deletions .claude/rules/sim-queries.md
Original file line number Diff line number Diff line change
Expand Up @@ -143,6 +143,22 @@ const handler = useCallback(() => {
}, [data])
```

## Server prefetching

A server prefetch fills the *same* cache key a client hook fills, so it must be indistinguishable from a client fetch. Five rules:

1. **Read the data layer, never our own API over HTTP.** A server-to-server call to `/api/...` costs a round trip and a second authentication for data the process can already read. Where the route runs an application use case, call that same use case with a principal from the same auth policy the route declares — not a manager underneath it.
2. **Match the wire shape the hook caches.** The hook's data is whatever `requestJson(contract, …)` produced, so the seed must equal it. Two traps: a contract field declared `z.coerce.date()` means the hook holds a `Date` where raw route JSON holds a string; a passthrough response schema (`z.custom`) means the hook caches route JSON *verbatim*, so seeding raw rows leaks `Date`s and server-only fields. When the route projects before responding, share that projection — have the route and the prefetch call one function.
3. **Prove the viewer.** Data-layer reads carry no authorization; the route used to provide it. Resolve the viewer (`getWorkspaceHostContextForViewer`, already `cache`d by the layout so it costs nothing) and return early on failure, caching nothing — the client fetch then reaches the route for the real 403. Never widen what a viewer can see.
4. **Always `await`.** Only a settled query is dehydrated, so an unawaited prefetch is silently dropped from the payload and the pane waterfalls anyway.
5. **Don't repeat what the layout already seeded.** `getQueryClient()` builds a new client per server call, so a page re-seeding a layout key is a genuine second read — and `HydrationBoundary` defers an already-seen query to an effect, which SSR never runs, so it never reaches the server render either.

Reuse the hook's exported `staleTime` constant and its key factory; `dehydrate` carries neither options nor `staleTime`, and freshness is per-observer.

Seed with `setQueryData` only when the prefetch must be able to *decline* to create an entry (an empty list that has to fall through to a route's creation path). `prefetchQuery` and `ensureQueryData` always create one.

Keep prefetch imports light. A page prefetch's imports land in that route's server graph, so pulling a barrel to reach one function can drag thousands of modules behind it — `bun run check:tool-registry-boundary` gates this per page.

## Boundary Types

- Hooks import named type aliases from `@/lib/api/contracts/**` (e.g., `import { listEntitiesContract, type EntityList } from '@/lib/api/contracts/entities'`). Never write `z.input<...>` / `z.output<...>` in hooks, and never `import { z } from 'zod'` in client code.
Expand Down
10 changes: 10 additions & 0 deletions .cursor/commands/ship.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,16 @@ improvement(scope): description for enhancements
chore(scope): description for maintenance
```

## What to Omit

The repo is public. Keep the title and description to the code change and its reasoning — never:

- Customer, company, or user names; workspace/user/org IDs; email addresses
- Prod or staging operational data: log lines, DB rows, metrics, timestamps, incident details, canary/alert output
- Infrastructure specifics: hostnames, ARNs, internal URLs, env var values, secret names

Describe the bug by its mechanism, not by how you found it. "Expired OAuth credentials fail to refresh in the worker" — not "the Sheets canary failed at 16:31Z for workspace abc-123".

## PR Description Format

Use this exact template in the user's voice (concise, bullet points):
Expand Down
4 changes: 4 additions & 0 deletions .cursor/commands/tool-registry-boundary.md
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,10 @@ If it fails, do not add the entry to an allowlist — there isn't one. Find the

Run it with `--verbose` to print per-route module counts, which is also the quickest way to see whether a change moved the graph.

The same command also ratchets those counts against `check-tool-registry-boundary.baseline.json`. `--check` (what CI runs) fails when an entry exceeds its baseline by more than `max(25 modules, 2%)`, naming the import chain responsible. This catches bloat the registry rule misses — a prefetch importing `listTables` cost the Tables page 444 modules without ever touching `@/tools/registry`.

Re-record with `--update-baseline` and commit the JSON when growth is deliberate. A *shrink* passes but is reported — re-record then too, or the win is silently spendable again.

## How to verify an edge actually got cut

Do not eyeball imports — the registry is reached through several redundant paths, so cutting one buys nothing while another survives. Walk the graph:
Expand Down
Loading
Loading