Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
166 commits
Select commit Hold shift + click to select a range
4c894a1
docs: pivot design from Next.js to Express + React
YonatanHen Jul 16, 2026
3f118cd
docs: P1 implementation plan for the Express API foundation
YonatanHen Jul 16, 2026
abeb07c
chore: re-establish workspace config and correct shared package for t…
YonatanHen Jul 16, 2026
b103245
chore: gitignore compose.override.yaml (holds the machine's CA cert)
YonatanHen Jul 19, 2026
562ed06
feat(api): express app skeleton with asserted middleware order
YonatanHen Jul 19, 2026
cedd8ee
feat(api): session middleware on redis with a hardened cookie policy
YonatanHen Jul 19, 2026
3309f3e
feat(api): requireAuth and requireOwner guards
YonatanHen Jul 19, 2026
8f92152
feat(api): validate middleware and userService
YonatanHen Jul 19, 2026
b1d81fa
feat(api): postService with gating at the serialization boundary
YonatanHen Jul 19, 2026
ee2f0b0
docs: fix mock.calls[0][0] typing under noUncheckedIndexedAccess, cor…
YonatanHen Jul 19, 2026
f07150b
feat(api): auth routes (signup, login, logout, me)
YonatanHen Jul 20, 2026
15ed894
feat(api): posts CRUD with owner-enforced authorization
YonatanHen Jul 20, 2026
532b32a
feat(api): user profile routes — closes the account-takeover hole
YonatanHen Jul 20, 2026
1e827cb
docs: fix set-cookie[0] typing under noUncheckedIndexedAccess, record…
YonatanHen Jul 20, 2026
221ce8d
feat(api): idempotent like/unlike as PUT/DELETE
YonatanHen Jul 20, 2026
595793d
docs: record the requireAuth + :slug param-inference landmine and its…
YonatanHen Jul 20, 2026
a6f4ac3
feat(api): composition root and SPA catch-all
YonatanHen Jul 20, 2026
95d3e77
docs: record the /*splat root-match and mongoose-bundling landmines (…
YonatanHen Jul 20, 2026
c61de5f
build: multi-stage Dockerfile and dev/e2e compose stacks
YonatanHen Jul 20, 2026
5f07631
fix(security): gitignore secret files, commit .example templates instead
YonatanHen Jul 20, 2026
d339c8f
docs: record Task 12 deviations - prod-deps stage, session-secret-onl…
YonatanHen Jul 20, 2026
1f46d44
feat(api): seed script with a demo account
YonatanHen Jul 21, 2026
05c9c89
docs: mark Task 13 complete; codify one-branch-per-feature rule
YonatanHen Jul 21, 2026
9b463e2
ci: three-workflow pipeline with branch-protection gates
YonatanHen Jul 21, 2026
cb24be3
docs: record Task 14 deviations - three workflows over one env-gated …
YonatanHen Jul 21, 2026
223f534
Merge pull request #9 from YonatanHen/dev/ci-cd-pipeline
YonatanHen Jul 21, 2026
9e55790
Merge pull request #10 from YonatanHen/dev/express-api-foundation
YonatanHen Jul 21, 2026
479d732
ci: fix workflow-triggering gaps in the release-PR path
YonatanHen Jul 21, 2026
493031d
Merge pull request #12 from YonatanHen/dev/fix-pr-to-master-trigger
YonatanHen Jul 21, 2026
999a555
docs: render.yaml, README quick start, architecture status
YonatanHen Jul 22, 2026
a15c318
docs: trim P1 plan to a completion log, fix stale spec references
YonatanHen Jul 22, 2026
ef11dbb
Merge pull request #14 from YonatanHen/dev/trim-plan-docs
YonatanHen Jul 22, 2026
b233c2f
docs: draft P2 react-client implementation plan
YonatanHen Jul 22, 2026
00c426a
docs: fix AutoForm's ZodDefault unwrap bug found in plan pre-flight r…
YonatanHen Jul 22, 2026
4eda2de
feat(client): Vite + React + Tailwind v4 scaffold with dev proxy
YonatanHen Jul 22, 2026
9f2fd1d
fix(client): stop tsc -b from emitting stray .js/.d.ts into src
YonatanHen Jul 22, 2026
54cb865
chore(client): remove stray build artifacts committed in the scaffold
YonatanHen Jul 22, 2026
1fa6302
refactor: rename apps/api to apps/server, split packages/shared, move…
YonatanHen Jul 22, 2026
f8ce1e9
fix: regenerate package-lock.json to purge stale apps/api / packages/…
YonatanHen Jul 22, 2026
c37be69
Merge pull request #15 from YonatanHen/dev/react-client
YonatanHen Jul 22, 2026
b322c6d
fix: regenerate package-lock.json to include all rolldown platform bi…
YonatanHen Jul 22, 2026
fa3daf3
Merge pull request #16 from YonatanHen/dev/server-client-restructure
YonatanHen Jul 22, 2026
2891108
feat(client): ui primitives (Button, Input, Label, Textarea, Card, Sk…
YonatanHen Jul 23, 2026
7f2ed26
feat(client): api client layer with typed wrappers
YonatanHen Jul 23, 2026
1c87f2e
feat(client): query client, router, page shell and page stubs
YonatanHen Jul 23, 2026
45c185e
Merge pull request #17 from YonatanHen/dev/api-client-layer
YonatanHen Jul 23, 2026
59f9d8b
Merge branch 'staging' into dev/task-4-query-setup
YonatanHen Jul 23, 2026
58c87d0
Merge pull request #18 from YonatanHen/dev/task-4-query-setup
YonatanHen Jul 23, 2026
89fd5e1
feat(client): auth pages, hooks, and route guard
YonatanHen Jul 23, 2026
5febaa7
chore: configure vitest for client .test.tsx files and update CLAUDE.…
YonatanHen Jul 23, 2026
90abf6e
fix(client): send Content-Type header so API bodies parse correctly
YonatanHen Jul 23, 2026
72d84b0
Merge pull request #19 from YonatanHen/dev/auth-pages
YonatanHen Jul 23, 2026
b0676c7
feat(api)!: gate content per reader, drop the premium flag
YonatanHen Jul 25, 2026
c203efd
feat(client): blog feed with PostCard and gating prompt
YonatanHen Jul 25, 2026
ed8f582
Merge pull request #20 from YonatanHen/dev/simplify-gating
YonatanHen Jul 25, 2026
b91c05d
Merge pull request #21 from YonatanHen/dev/blog-feed
YonatanHen Jul 25, 2026
8d02f28
feat(client): post detail page with server-driven gating UI
YonatanHen Jul 26, 2026
4265036
feat(client): schema-driven AutoForm and the post editor
YonatanHen Jul 26, 2026
d3fcfc1
build: bake the client build into the api image; add a client dev con…
YonatanHen Jul 26, 2026
d5ac83e
fix(client): guard usePost against an empty slug
YonatanHen Jul 26, 2026
9d1f6a4
fix(server): scope the runner's prod install to the server workspace
YonatanHen Jul 26, 2026
9094eff
Merge pull request #22 from YonatanHen/dev/post-detail-page
YonatanHen Jul 26, 2026
af6f7c0
Merge remote-tracking branch 'origin/staging' into dev/client-docker-…
YonatanHen Jul 26, 2026
a9845e7
Merge pull request #23 from YonatanHen/dev/client-docker-build
YonatanHen Jul 26, 2026
4bad4e7
Merge remote-tracking branch 'origin/staging' into dev/post-editor-form
YonatanHen Jul 26, 2026
a3ea7a2
Merge pull request #24 from YonatanHen/dev/post-editor-form
YonatanHen Jul 26, 2026
02f454c
docs: demo caps, rate limiting and DB hardening design spec
YonatanHen Jul 26, 2026
f1ff71d
docs: add P2 Task 14 (demo caps, rate limiting, DB hardening) and ref…
YonatanHen Jul 26, 2026
c46fb0f
chore(lint): ignore the .remember scratch dir
YonatanHen Jul 26, 2026
e709ce3
feat(client): delete post — invalidate rather than optimistically remove
YonatanHen Jul 26, 2026
e4f0a89
feat(client): likes with optimistic UI and rollback on failure
YonatanHen Jul 26, 2026
1f86cef
fix(client): log out through the API instead of navigating to a dead …
YonatanHen Jul 26, 2026
0930520
test(e2e): Playwright coverage for auth+posts+likes and the gating bo…
YonatanHen Jul 26, 2026
38f0880
Merge pull request #25 from YonatanHen/dev/delete-post
YonatanHen Jul 26, 2026
6863626
Merge pull request #26 from YonatanHen/dev/likes-optimistic-ui
YonatanHen Jul 26, 2026
5426845
Merge pull request #27 from YonatanHen/dev/playwright-e2e
YonatanHen Jul 26, 2026
acd1b52
Merge branch 'staging' into dev/plan-task-14-and-docs
YonatanHen Jul 26, 2026
3a9e7c7
Merge pull request #28 from YonatanHen/dev/plan-task-14-and-docs
YonatanHen Jul 26, 2026
1ea6702
Replace comma-separated tags box with a chip input
YonatanHen Jul 26, 2026
fc04ec4
Merge pull request #29 from YonatanHen/dev/tags-chip-input
YonatanHen Jul 26, 2026
9792cc0
docs: close out P2 with the final gate (README, deployment architectu…
YonatanHen Jul 28, 2026
7d04c1a
docs: note these two P2 checklist items are structural guarantees, no…
YonatanHen Jul 28, 2026
b62dd9a
Merge pull request #30 from YonatanHen/dev/p2-final-docs
YonatanHen Jul 28, 2026
f927c45
Add full-text post search over the Mongo text index
YonatanHen Jul 28, 2026
82a2614
feat(comments): threaded comments with a Markdown editor and preview
YonatanHen Jul 28, 2026
ab4138d
Address code review on search
YonatanHen Jul 28, 2026
85b97ad
fix(comments): scope mutations to the post, cap reply depth, keep fai…
YonatanHen Jul 28, 2026
0766d7c
Merge pull request #31 from YonatanHen/dev/media-and-search
YonatanHen Jul 28, 2026
04b4217
Merge remote-tracking branch 'origin/staging' into dev/comments-markdown
YonatanHen Jul 28, 2026
4987e60
Merge pull request #32 from YonatanHen/dev/comments-markdown
YonatanHen Jul 28, 2026
7aaff73
fix(search): stop the search box from dropping keystrokes typed at no…
YonatanHen Jul 28, 2026
6eece76
Merge pull request #33 from YonatanHen/dev/search-input-race-fix
YonatanHen Jul 28, 2026
095d78b
docs: explain the search box's whole-word $text semantics
YonatanHen Jul 28, 2026
7ae61dc
docs: document the README-direct-push exception to the PR-only rule
YonatanHen Jul 29, 2026
0c97b1d
Merge pull request #35 from YonatanHen/dev/readme-direct-push-policy
YonatanHen Jul 29, 2026
50aac54
docs: rewrite README as the rebuild's baseline (architecture, flows, …
YonatanHen Jul 29, 2026
b187a95
feat: add readme-maintenance skill, un-ignore .claude/skills/
YonatanHen Jul 29, 2026
d50c9d4
Merge pull request #36 from YonatanHen/dev/readme-maintenance-skill
YonatanHen Jul 29, 2026
d8e274a
docs: bring demo-caps spec in scope with comments (caps, limiter, res…
YonatanHen Jul 29, 2026
7c28ffb
feat(client): confirm password on signup, validated before the request
YonatanHen Jul 29, 2026
3a6c0e7
chore: ignore .playwright-mcp scratch output
YonatanHen Jul 29, 2026
ba8509c
fix(security): stop logging plaintext passwords on the auth paths
YonatanHen Jul 29, 2026
df543fe
docs: rescope demo caps per-owner (20/2/10) and drop rate limiting
YonatanHen Jul 29, 2026
b02dd12
test(e2e): disambiguate the password locator after adding confirmation
YonatanHen Jul 29, 2026
07e8dc5
Merge pull request #37 from YonatanHen/dev/gitignore-playwright-mcp
YonatanHen Jul 29, 2026
200cbe0
Merge pull request #38 from YonatanHen/dev/redact-credential-logging
YonatanHen Jul 29, 2026
5a066b0
Merge pull request #40 from YonatanHen/dev/demo-caps-and-hardening
YonatanHen Jul 29, 2026
17aeea5
Merge pull request #39 from YonatanHen/dev/signup-password-confirmation
YonatanHen Jul 29, 2026
3098ad9
docs: P4 realtime chat design — Socket.io inside apps/server
YonatanHen Jul 29, 2026
10f7e04
docs: retire apps/realtime across the spec, CLAUDE.md and README
YonatanHen Jul 29, 2026
50b87fc
docs: P4 realtime chat implementation plan
YonatanHen Jul 29, 2026
6466a91
refactor(server): build the session middleware at the entry point
YonatanHen Jul 29, 2026
ea49b3b
feat(shared): ChatMessageSchema — body only, author is server-derived
YonatanHen Jul 29, 2026
fc0c59e
feat(api): chat message buffer on a capped Redis list
YonatanHen Jul 29, 2026
b9052a0
feat(api): GET /chat/messages returns the recent buffer, auth required
YonatanHen Jul 29, 2026
23b93b6
feat(api): Socket.io on the app server, authenticated by the session
YonatanHen Jul 29, 2026
e6d4ebb
fix(api): guard chat append against unhandled rejection, fix socket.d…
YonatanHen Jul 29, 2026
669d9d4
test(api): cover the failed-append path in realtime chat
YonatanHen Jul 29, 2026
93e3741
feat(api): in-memory presence, typing relay, and logout disconnects s…
YonatanHen Jul 29, 2026
dc2871b
feat(client): useChat — socket created once, every listener cleaned up
YonatanHen Jul 29, 2026
e24e27b
feat(client): chat page, guarded route, and nav link
YonatanHen Jul 29, 2026
b5b0122
fix(client): move RequireAuth into ChatPage, add ChatPage tests
YonatanHen Jul 29, 2026
82d469c
fix(client): split ChatRoom out of ChatPage so useChat cannot run bef…
YonatanHen Jul 29, 2026
b00bbf5
build(client): proxy the socket.io upgrade to the API in dev
YonatanHen Jul 29, 2026
f88b3ea
test(e2e): a message crosses the server between two browser contexts
YonatanHen Jul 29, 2026
732497e
feat(client): load chat history buffer before subscribing to live mes…
YonatanHen Jul 29, 2026
ad79b97
fix(client): pin the chat history buffer as a mount-time snapshot
YonatanHen Jul 29, 2026
c7dc5cb
test(client): replace decorative refetch guard with one that actually…
YonatanHen Jul 29, 2026
077e41e
test(e2e): fix the readiness wait and cover the buffered history
YonatanHen Jul 29, 2026
a9989df
docs: chat is built - tick the section 14 chat items and update the R…
YonatanHen Jul 29, 2026
e9b0561
docs: correct two stale references to the retired apps/realtime design
YonatanHen Jul 29, 2026
e11e82b
fix(chat): apply final review fix wave before PR
YonatanHen Jul 30, 2026
bfda167
docs: how to try the chat locally, plus the rebuild and CA caveats
YonatanHen Jul 30, 2026
207654a
style: shorten comments added in the chat fix wave
YonatanHen Jul 30, 2026
cd4b923
docs: document the raw docker compose commands
YonatanHen Jul 30, 2026
c06a0f5
fix(client): add sendError to the useChat mock in ChatPage.test
YonatanHen Jul 30, 2026
184b9eb
Merge pull request #41 from YonatanHen/dev/realtime-chat
YonatanHen Jul 30, 2026
18bf0e6
feat(client): editorial feed redesign with generated cover art
YonatanHen Jul 30, 2026
3516ffc
feat: optional cover images via signed Cloudinary uploads
YonatanHen Jul 30, 2026
dd2f54d
refactor(uploads): use the Cloudinary SDK and discrete credential vars
YonatanHen Jul 30, 2026
d5b789b
docs: cover uploads have shipped - correct the README's not-yet-built…
YonatanHen Jul 30, 2026
296ff6b
feat(auth): Google and Facebook sign-in via Passport
YonatanHen Jul 30, 2026
17e943b
docs: google sign-in has shipped - update the README's feature list a…
YonatanHen Jul 30, 2026
e4fda8a
fix(auth): resolve PUBLIC_ORIGIN from RENDER_EXTERNAL_URL when unset
YonatanHen Jul 30, 2026
ed6a8ff
chore(render): drop the Facebook env keys - only Google is wired up
YonatanHen Jul 30, 2026
139d078
fix(client): satisfy noUncheckedIndexedAccess in PostTile
YonatanHen Jul 30, 2026
0c8c015
Merge branch 'dev/feed-redesign' into dev/media-uploads
YonatanHen Jul 30, 2026
6ff32ff
Merge branch 'dev/media-uploads' into dev/oauth-login
YonatanHen Jul 30, 2026
a2042a0
changed blog secondary header
YonatanHen Jul 30, 2026
911e6f4
test(e2e): match the redesigned nav's copy
YonatanHen Jul 30, 2026
a9b5591
Merge branch 'dev/feed-redesign' into dev/media-uploads
YonatanHen Jul 30, 2026
5d690b6
Merge branch 'dev/media-uploads' into dev/oauth-login
YonatanHen Jul 30, 2026
0c3e272
Merge pull request #42 from YonatanHen/dev/feed-redesign
YonatanHen Jul 30, 2026
0c7e997
Merge pull request #43 from YonatanHen/dev/media-uploads
YonatanHen Jul 30, 2026
44d5a64
Merge pull request #44 from YonatanHen/dev/oauth-login
YonatanHen Jul 30, 2026
fe5b0d6
feat: demo capacity caps
YonatanHen Jul 30, 2026
5df30f2
docs: document the demo capacity caps in the README
YonatanHen Jul 30, 2026
4f9bcb0
feat(seed): gate production seeding behind an explicit prod argument
YonatanHen Jul 30, 2026
fbbe21a
chore(render): name the existing production service and pin master
YonatanHen Jul 30, 2026
32830e0
chore(render): move the Blueprint to the repo root
YonatanHen Jul 30, 2026
fa37053
Merge pull request #45 from YonatanHen/dev/demo-caps
YonatanHen Jul 30, 2026
538708b
fix(auth): stop auto-linking OAuth identities to unverified local acc…
YonatanHen Jul 30, 2026
3c1270d
Merge pull request #46 from YonatanHen/dev/oauth-linking-security-fix
YonatanHen Jul 30, 2026
86dba54
fix(client): sync the feed's cached like count after liking a post
YonatanHen Jul 30, 2026
d3c665d
Merge pull request #47 from YonatanHen/dev/like-count-cache-fix
YonatanHen Jul 30, 2026
cff2d32
Merge branch 'master' into staging (reconcile, no content change)
YonatanHen Jul 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
61 changes: 61 additions & 0 deletions .claude/skills/docker-compose-rebuild/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
---
name: docker-compose-rebuild
description: >-
Use on the Blog-Chat-app repo whenever a code edit (bug fix or new feature) does not show up in the
running app, or as the FIRST troubleshooting step when the user says a fix "didn't work," they "don't
see the change," or the UI/API still shows old behavior after edits. Docker containers here bake source
at build time and serve stale code, so this skill asks permission and then rebuilds the compose stack so
the edits actually take effect. Trigger it before debugging the code itself when changes seem to have no visible effect.
---

# Docker Compose Rebuild

## Why this exists

On this repo the dev stack runs in Docker. A container started with `up -d` **freezes the app code at
image-build time** — editing a file afterward and running `restart` keeps serving the code baked into the
image (see the `docker-compose-dev-sync-gotcha` project memory, confirmed during P2 signup debugging). So
when a bug fix or new feature "doesn't work," the most common cause is not the code — it's that the running
container never picked up the edit.

**Rule of thumb:** if the user just changed code and the change isn't visible, suspect a stale container
*before* you re-read the logic. Rebuilding is the cheap first move; debugging code that's correct but not
running is wasted effort.

## When to trigger

- The user reports that a recent bug fix or new feature has no visible effect.
- "I don't see my changes," "the fix didn't work," "still shows the old behavior," "nothing changed."
- Right after you (or the user) edit source while the stack is already running.
- As the **first** step of troubleshooting a "my change isn't showing" symptom, before diving into the code.

## What to do

1. **Ask for permission first.** A full `--no-cache` rebuild is slow, and `up --watch` runs in the
foreground and takes over the terminal. Never rebuild silently — confirm with the user, e.g.:
> "Your change may not be showing because the container is serving stale code. Want me to rebuild the
> compose stack? This does a clean `--no-cache` build and can take a few minutes."

2. **Only after they agree**, run these two commands from the **repo root** (not from `infra/`):

```bash
docker compose --project-directory . -f infra/compose.yaml build --no-cache
docker compose --project-directory . -f infra/compose.yaml up --watch
```

- `--project-directory .` is mandatory — the compose file lives in `infra/` but its `context` /
`develop.watch` / secrets paths are written relative to the repo root; Compose resolves them wrong
without it.
- `up --watch` is long-running and blocks the terminal (it keeps syncing edits live). Run it in the
background if you need the terminal back, and tell the user it stays running.

3. If the user only wants the change picked up (not a full clean rebuild), a lighter option is a targeted
rebuild of the one changed service — `docker compose --project-directory . -f infra/compose.yaml up -d --build <service>`
— or just `docker compose watch` (what `npm run dev` does), which syncs edits live without the slow
`--no-cache` pass. Offer this when a full clean rebuild is overkill.

## After rebuilding

Confirm the change is actually present before assuming success — e.g. reload the page, hit the endpoint, or
`docker compose exec <service> grep` for the edited string inside the container. Don't declare it fixed until
you've seen the new behavior.
126 changes: 126 additions & 0 deletions .claude/skills/plan-status/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,126 @@
---
name: plan-status
description: >-
Use on the Blog-Chat-app repo whenever the question is "where are we?" or "what's next?" — status of the
current phase plan, which tasks are done, what task to pick up, what's left before a phase ships, or
orienting at the start of a session after time away. Reads docs/superpowers/plans/ and derives real
status from git and the code rather than the plan's checkboxes (which are never ticked and always read
0% done). Trigger it on "what's the status", "where did we leave off", "what should I work on next",
"what's left in P2", "catch me up", "is task N done", or before starting any new task on this project —
even when the user doesn't name the plan.
---

# Plan Status

## Why this exists

Phase plans live in `docs/superpowers/plans/`. They are long (P2 is ~2,200 lines) and they track steps with
`- [ ]` checkboxes — **but nobody ever ticks them.** P2 is 0-of-75 checked while Tasks 1–6 are merged to
`staging`. So the two obvious ways to answer "where are we" both fail: reading the checkboxes reports 0%
and sends you to redo Task 1, and reading the whole plan burns thousands of tokens to reach the same wrong
answer.

The plan is the **specification**; git and the working tree are the **record of what shipped**. This skill
reads the plan for *what the work is* and reads the repo for *what's done*, then reports the join.

## Step 1 — Scan

```bash
python .claude/skills/plan-status/scripts/scan_plan.py
```

Add `--plan <path>` for a specific phase, `--base <branch>` to change what counts as already-merged
(default `master`). The script picks the newest plan not marked complete, and emits JSON with: the task
ledger (number, title, line number, declared files, `Produces` interfaces, planned commit message),
per-task evidence, amendment blocks, and git position.

**Do not read the plan file top-to-bottom.** The scan plus a targeted read of the next task's line range is
the whole job; reading 2,000 lines to report six facts is the failure mode this skill exists to prevent.

Each task carries a `signal` built from two independent axes — do its declared files exist, and did a
commit matching its planned message land:

| signal | meaning | what to do |
|---|---|---|
| `LIKELY_DONE` | files present **and** a matching commit | trust it |
| `NOT_STARTED` | declared files absent, nothing shipped | trust it |
| `NEEDS_CHECK` | the axes disagree | resolve it in Step 2 |
| `NO_EVIDENCE` | task declares no files (docs/gate tasks) | resolve it in Step 2 |

## Step 2 — Resolve the frontier

Only resolve tasks the scan left uncertain, and usually only the first one or two — a `NEEDS_CHECK` at
Task 11 doesn't matter when Task 7 is the frontier. Two things routinely make the mechanical signals
disagree, and both need judgment:

**Commit messages drift.** The plan prescribes `feat(client): typed API wrappers (client.ts + auth/posts/users)`;
the commit that actually shipped it says `feat(client): api client layer with typed wrappers`. Token
matching misses this, so a done task shows `NEEDS_CHECK` with no evidence. Scan `git log --oneline -40`
yourself for a commit that plainly covers the task's subject.

**Files exist as stubs.** Earlier tasks create placeholder pages so the app compiles — `PostPage.tsx`
exists from Task 5, but Task 7 is what fills it in. Existence proves nothing here; the plan itself says
"replace the Task 5 stub". This is what the task's **`Produces`** line is for: it names the exact symbols
the task must yield (`usePost(slug)`, `<LikeButton />`, `AutoForm`). Grep for those:

```bash
grep -rn "export function usePost\b" apps/client/src/hooks/
```

Present and substantive → done. Absent, or the file is a few lines returning a heading → not done. When
still genuinely ambiguous after that, say so in the report rather than picking a side; a wrong "done"
costs more than an honest question.

## Step 3 — Report

Lead with this block. It is deliberately compact — the user asked where things stand, not for a recital of
the plan. Task count, titles, and line numbers all come from the scan; never assume a phase's task count
from memory.

```
P2 — React Client · 6/13 tasks shipped
Branch: staging (clean, up to date with origin)

✅ 1 Vite scaffold ✅ 4 Query/router/shell
✅ 2 UI primitives ✅ 5 Auth pages
✅ 3 API client layer ✅ 6 Blog feed
▶ 7 Post detail page (gating UI)
○ 8 AutoForm ○ 9 Delete ○ 10 Likes
○ 11 Docker ○ 12 E2E ○ 13 Final gate

⚠ Amendment 2026-07-25: `premium` is gone — ignore that
line in the Tasks 8/10/12 snippets.

Next: Task 7 (plan L1284)
hooks/use-posts.ts + usePost
pages/PostPage.tsx replace the Task-5 stub
git checkout -b dev/post-detail-page
```

Rules for the block:

- **Surface amendments.** Plans get amended in place (`> **Amendment ...**`) and those notes supersede the
code snippets below them. Someone following an amended snippet reintroduces work that was deliberately
removed — that's why this gets a line of its own rather than a footnote.
- **Flag git position honestly.** Uncommitted changes, a `dev/*` branch with unmerged work, or local
`staging` behind `origin/staging` all change what "next" means. CLAUDE.md requires feature branches off
an up-to-date `staging`, so a stale `staging` is a blocker to state, not a detail to skip.
- **Propose the branch, don't create it.** Name it after the feature, never the task number
(`dev/post-detail-page`, not `dev/task-7`) — a CLAUDE.md rule. Give the command; let the user run it.
- Keep to the shipped/next/remaining shape. Offer the detail ("want the full step list for Task 7?")
instead of pre-emptying it into the reply.

## Scope

This skill reports; it doesn't act. It never edits the plan (the checkboxes stay untouched — deriving
status fresh each time can't go stale, and a wrong verdict written into a doc outlives the mistake), never
creates branches, and never starts the next task. When the user then says "go", that's implementation
work — hand off to `superpowers:subagent-driven-development` or `superpowers:executing-plans`, which is
what the plan's own header asks for.

**Completed plans** announce themselves — `(COMPLETE)` in the title or a `**Status:** all N tasks shipped`
line — and record their history in a prose "Completion log" rather than checkbox tasks. The scan flags
them in `plans[].complete`. Summarize from the Status line; don't build a ledger for a phase that's done.

If the user asks about a phase with no plan file yet (P3–P6), say so plainly and point at spec §13, which
is where the phase table lives.
Loading
Loading