You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Files Changed: adopt app and extension user mutation routes
Important
Problem - Sidebar, Preview, and Files Changed editing can currently mutate through client or extension paths that have weaker session identity and fallback guarantees than the proposed ledger contract. Approach - Make user-initiated file operations host-mediated mutation intents. Use the negotiated capability to create registered operation groups; preserve clearly labelled legacy behavior only when protocol discovery selects legacy. Scope - in: Sidebar leaf, move, Trash, restore, directory, and recursive operations; Preview and review editing; panel ownership; opaque host transport; and watcher revalidation. out: engine tool adoption and plugin/runner records. Assumptions - The mutation gate and privacy policy are available. Existing #976 remains the v1 foundation pending its release and pin gate.
Acceptance Criteria
User-initiated file operations bind to the initiating panel and active session before storage work begins.
Sidebar create, move, Trash, restore, directory, and recursive operations use registered contexts or deny before mutation in full-provenance mode.
Preview and Files Changed editing cannot bypass host-mediated context validation.
A capability-discovery legacy result preserves existing behavior with a visible legacy label; an invalid mutation context never falls back to untracked mutation.
Watchers only revalidate server-owned receipts and cannot determine ownership or lifecycle locally.
User-originated receipts remain distinguishable from agent, child-agent, and system receipts.
The browser sends a display-safe MutationIntent containing operation, user-selected display target, and idempotency key. The extension host resolves resource identity, snapshots the active panel and session before input or confirmation, obtains the context, and returns only a display-safe operation result.
Capability discovery has full, partial, legacy, and unavailable outcomes. Only legacy selects existing behavior; partial uses a labelled partial epoch, while invalid or expired mutation contexts deny without fallback.
Watchers receive only receipt references and assessment revisions, emit invalidation, and never receive or derive ownership, lifecycle, canonical paths, hashes, or evidence.
Files Changed: adopt app and extension user mutation routes
Important
Problem - Sidebar, Preview, and Files Changed editing can currently mutate through client or extension paths that have weaker session identity and fallback guarantees than the proposed ledger contract.
Approach - Make user-initiated file operations host-mediated mutation intents. Use the negotiated capability to create registered operation groups; preserve clearly labelled legacy behavior only when protocol discovery selects legacy.
Scope - in: Sidebar leaf, move, Trash, restore, directory, and recursive operations; Preview and review editing; panel ownership; opaque host transport; and watcher revalidation. out: engine tool adoption and plugin/runner records.
Assumptions - The mutation gate and privacy policy are available. Existing #976 remains the v1 foundation pending its release and pin gate.
Acceptance Criteria
Testing Decisions
Key Decisions
Constraints & Invariants
Prior Art
Deliberation Resolution
MutationIntentcontaining operation, user-selected display target, and idempotency key. The extension host resolves resource identity, snapshots the active panel and session before input or confirmation, obtains the context, and returns only a display-safe operation result.full,partial,legacy, andunavailableoutcomes. Onlylegacyselects existing behavior;partialuses a labelled partial epoch, while invalid or expired mutation contexts deny without fallback.Source
Part of #972. Blocked by #976, #1077, and #1078.