Two new tabs in the Studio Notebook:
- 📚 Classes: a binder for courses, workshops, books, and video series.
Each class has a subject, source, link, status (taking / want / done),
a what-it's-about note, photos, handout files, and dated pages of
class notes that can be edited in place.
- 💭 Mind Dump: idea capture filed by category (things to make — with a
medium: clay / wood / silver / metal / mixed — marketing, packaging,
display & booth, shop & site, other) with spark / trying / did it /
parked status, sketch photos, one-tap 'make it a to-do', and filters.
The Today jot box gains a 💭 idea chip; those land as 'unsorted' to
file later.
Schema: Course, CoursePage, Idea (additive; prisma db push at boot).
Files tab now labels attachments that belong to a class.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Three new doors, all wire-contract ports of the shared @otm/account-panel
factories (this backbone is plain Node — the Next factories can't mount):
- GET /api/auth/operator-magic — OTM 'Log in as admin'. HS256 verify against
OPERATOR_SHARED_SECRET (alg allowlist, constant-time, action-claim rejected
for flow separation), single-use jti via OperatorMagicConsumed (+ who/when
audit), 1-HOUR session with cookie Max-Age derived from the payload, 🔑
support-session banner in the app, every failure a 302 reason redirect.
- GET /api/auth/otm-sso — the OTM /account tile. Stricter sso-ticket verify
(exp mandatory, audience compared), email-then-role actor mapping, safeNext.
- 💡 suggestion jot chip — files a Gitea issue (shared attribution footer,
8k cap, 10s timeout); on any failure the jot is kept as a note instead.
Success also leaves a '#N — …' note so she has her own record.
- Footer version chip + one-tap self-update (HMAC-signed OTM proxy with
explicit field picking — foreign JSON can never reach the _setSession/_redirect
control keys), owner-gated, 10-min sessionStorage cache on the check.
Hardening that rode along: session key now derived from OPERATOR_SHARED_SECRET
(managed boot REFUSES the old derivable DATABASE_URL fallback), 1MB JSON body
cap, login.html prototype-lookup fix. NOTE: server.mjs previously contained a
literal NUL byte that made git treat it as binary — this commit re-encodes it
as an escape (behavior identical) and adds .gitattributes so source diffs can
never go blind again.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SmybqyQmZWfcqA1vMP4jbQ
Prototype stays untouched (Bonna's laptop daily driver until cutover).
app/ is the deployable bms-backbone: same routes/frontend, Prisma models
replacing node:sqlite, session-cookie login backed by a User table seeded
via the platform SEED_OWNER_* convention (bcryptjs), /api/health with
APP_VERSION, photos/files under DATA_DIR (/app/data uploads mount),
Dockerfile + entrypoint (prisma db push + owner seed + serve), and a
one-shot sqlite→postgres migration script for Bonna's existing data.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>