Member invites, gallery resync, content and operator docs

- Invite flow: admin issue/revoke on join requests, public single-use
  claim links (hash-only tokens, 7-day expiry, no state reveal), claim
  creates the Member account and marks the request accepted
- Gallery: admin status page plus resync endpoint; sync refreshes
  thumbnails whose content changed; tools/gallery contract and checker
- Docs: public content page, admin-only operator runbook, api.md
  invite/gallery sections, all routes in the live API docs, docs
  reachability gate test
- Screenshots cover the new pages; version 1.0.18
This commit is contained in:
2026-10-06 02:56:08 +02:00
parent e512556703
commit 9fb4d65787
36 changed files with 1147 additions and 19 deletions
+42
View File
@@ -384,3 +384,45 @@ environments, docker, env-files, serving, gallery, test, git, code,
docs, and handover laws are preserved as dated `muse-spark` entries
above. New teachings use the skeleton under [Lesson format](#lesson-format).
No lesson content may be deleted when the format evolves.
### L-2026-10-05-13: Restart reload-based dev servers after every pull
| Field | Value |
|--------------|-------|
| date | 2026-10-05 |
| agent | muse-spark |
| status | proposed |
| dpp_template | no |
| dpp_reason | proposed; Grok folds into template deploy section |
File-watching dev servers restart on the first changed file they notice.
A version-control update writes files one by one, so the restart can
fire mid-checkout and boot workers from a mixed old/new tree with no
further restart once the checkout completes (observed: health reported
the previous version while new code was partially loaded).
After every pull or checkout on a host running reload-based servers,
restart those servers (or their containers) and verify the reported
version matches the checked-out tree before declaring the deploy done.
Production targets without reload are unaffected but still verify.
### L-2026-10-05-14: Autonomous development rule
| Field | Value |
|--------------|-------|
| date | 2026-10-05 |
| agent | muse-spark |
| status | proposed |
| dpp_template | no |
| dpp_reason | proposed; agent operating rule, Grok decides the template fold |
Standing instruction from retoor, recorded as a clear rule:
- Move one way only: forward. Do the maximum-effort option that adds
no degradation and deletes no functionality.
- Whatever is unclear after the user's answers is resolved by online
deep research first; the agent then picks the research-backed option
and continues autonomously instead of stalling on questions.
- Research grounds the choice (example: invite tokens use hash-only
storage, single use and expiry per current security practice), it
never replaces verification against the repo's own code and tests.