fix(curation): kill dev-artefact leak + rename agent honestly

Oracle remediation batch 1 — closing gaps #1 (agent overclaim), #4
(demo-data leak), #5 (raw-ID exposure):

- src/lib/flowCuration.ts: shared isDevArtefact + curatedPublishedFlows
  filter for the whole codebase. Patterns drop rv_/orphan/Atlas F1/MCP
  SDX/Codex Test/sidekick/process_<ts>/backfill/smoke/probe/fixture and
  the EA2_* internal source_contexts.
- src/scenes/Hub.tsx: loadPublishedFlows uses the shared curator
- src/lib/agentTools.ts: list_processes and start_process both use the
  shared curator; raw transaction_id no longer in start reply
- src/state/store.ts: snapshot + live merges curated; resolveDefaultStepId
  guards against scenarios whose defaultStepId references a stale step
- src/scenes/Wizard.tsx: 'Process definition <hex>' confirmation replaced
  with the user-facing process name
- src/scenes/Hub.tsx: start toast no longer shows transaction_id prefix
- src/scenes/Agent.tsx + App.tsx + Landing.tsx: rename Pi -> FlowMaster
  Command Assistant. Welcome message says explicitly that this is a
  deterministic router and the LLM agent + tenant memory are on the
  roadmap. Tab label, hub chip, turn author all rebranded.
- src/scenes/GeoAttendance.tsx: scene re-titled to 'Attendance map ·
  preview' with honest copy explaining the dataset is illustrative until
  the EA2 attendance feed is wired in.
- src/data/synthetic.ts: orphaned from runtime (kept in tree for tests).
  Snapshot now sources only the live-cached EA2 read (scenarios.json),
  filtered through the same curator.

29/29 tests green. No more 'rv test flow 0' / 'orphan' / 'Atlas F1' / raw
32-char hex IDs visible to a buyer.
This commit is contained in:
2026-06-14 13:11:54 +04:00
parent 7ceb5c05bb
commit 8933148719
9 changed files with 109 additions and 48 deletions
+58
View File
@@ -0,0 +1,58 @@
export interface RawFlow {
_key: string;
display_name?: string;
name?: string;
description?: string;
source_context?: string;
status?: string;
kind?: string;
}
const DEV_ARTEFACT_PATTERNS = [
/^rv[_\s]/i,
/^orphan/i,
/^atlas[_\s]?f1/i,
/\batlas-f1-fresh\b/i,
/mcp[_\s]?sdx[_\s]?smoke/i,
/\bcodex[_\s]?test\b/i,
/\bsidekick\b/i,
/^process_\d{10,}$/i,
/\bbackfill\b/i,
/\bsmoke[_\s]?test\b/i,
/\bprobe\b/i,
/\bfixture\b/i,
];
const NON_BUSINESS_SOURCE_CONTEXTS = new Set([
"EA2_CHAT_THREAD",
"EA2_CHAT_MSG",
"EA2_WIZARD_STEP",
"EA2_DRAFT_PROCESS:process_creation",
]);
const HEX32 = /[a-f0-9]{32}/gi;
const HEX_SUFFIX = /[_-][a-f0-9]{8,}$/i;
export function isDevArtefact(f: RawFlow): boolean {
if (f.source_context && NON_BUSINESS_SOURCE_CONTEXTS.has(f.source_context)) return true;
const haystack = `${f.display_name || ""} ${f.name || ""} ${f.description || ""}`;
return DEV_ARTEFACT_PATTERNS.some((p) => p.test(haystack));
}
export function curatedPublishedFlows<T extends RawFlow>(items: T[]): T[] {
return items.filter(
(it) => it.status === "published" && it.kind === "definition" && !!it.display_name && !isDevArtefact(it)
);
}
export function friendlyShortId(id: string | undefined | null): string {
if (!id) return "";
const trimmed = id.replace(HEX_SUFFIX, "");
if (trimmed.length < id.length && trimmed.length > 0) return trimmed;
if (HEX32.test(id)) return `ref-${id.slice(0, 4)}`;
return id;
}
export function scrubIdsFromText(text: string): string {
return text.replace(HEX32, "");
}