DUNIN7 · LOOMWORKS · RECORD
record.dunin7.com
Status Current
Path change-requests/cr-2026-193-loomworks-b47-credential-surface-v0_1.md

DUNIN7-M4 — INFRASTRUCTURE CHANGE REQUEST

CR-2026-193 — B-47: the contributor credential surface (v0.1)

Version. 0.1 · Date. 2026-08-08 · Author. Claude.ai (drafting) / Marvin Percival (approving). Target. /Users/dunin7/loomworks, branch main. Baseline. Surface c5919b4, engine ae58d34. CC confirms both at Step 0. Companion to. completion-records/loomworks-cr-2026-188-b47-halted-with-findings-v0_1.md — CR-2026-188 halted at Step 1 because it described adding controls to a list that does not exist. This CR replaces it. Supersedes CR-2026-188 in intent; that CR stays filed as halted. Charter. Autonomous regime. Status. Ready for CC execution.


1. Summary

The engine pathway is complete and has never had a screen. This CR builds one.

What is settled and not reopened:

What the precedent does not settle, and this CR must: SeedViewer only reads. This panel acts — it issues and revokes write access. Issue and revoke need their own care and must not inherit SeedViewer's weight.


2. What Step 1 confirms before building

Sourced from CR-2026-188's Step 1 report and cited as such rather than restated as fact. CC verifies each against the code:

Not established and Step 1 must report: what fields the list response actually carries (label, issued-at, expiry, revoked state, claimed state?), and whether a revoked or expired credential is distinguishable from an active one in that response. The list cannot show a state the wire does not carry — if it can't distinguish, report it rather than inventing a display.


3. Scope

3.1 The panel

Opened from a header control on the engagement surface. Renders below the header in the main column, per precedent.

The header control's wording carries weight. It sits beside "view seed," a passive action. Whatever it says should make clear that what lies behind it grants access — not "Credentials" alone if that reads as a settings shelf. CC proposes wording and states its reasoning; strings live in strings.ts per the brand-strings discipline.

3.2 The list

What exists, per §2's findings. Plain terms throughout. Only-show-what-is-available: no disabled rows, no greyed controls. A revoked credential either shows as revoked or does not appear — CC decides from what the wire carries and states which.

3.3 Issuance

Form: recipient label (optional), expiry (required, dated field, sensible default the Operator can change).

The form states what it is about to grant — unmoderated write access to this engagement's Memory — in plain terms, before submission, not after. The person should not have to infer the stakes from the word "credential."

3.4 The reveal

Shown once. Copy-to-clipboard. No path back — not by reload, navigation, browser history, or the list.

Never logged. Never in a URL or query string. Never persisted client-side — not in local storage, session storage, or a cache the issuance response could be re-read from.

The screen says plainly that this is the only showing.

3.5 Revoke

On the list. Confirmation before it fires — revoking is not recoverable and should not be one click from a row.

3.6 Operator authority

Issuance and revocation are Operator acts. Nothing here transitions automatically.


4. Out of scope


5. Seed-mutability impact

B-69 applies. Credentials are engagement-scoped; if issuance, the claim link, or revocation reads or derives from seed state, record the contact point with its Kind label. Likely Kind C — record it as one if so.


6. Build steps

| Step | What | Mode | |---|---|---| | 0 | Pre-flight. | Auto | | 1 | Verify §2 and report the list response's actual fields. Halt if an engine change is needed. | Auto, conditional halt | | 2 | Panel shell + header control + tests. | Auto | | 3 | List + tests. | Auto | | 4 | Issuance form + tests. | Auto | | 5 | Reveal + tests, including §3.4's no-path-back assertions. | Auto | | 6 | Revoke + confirmation + tests. | Auto | | 7 | Surface sweep — lint, tsc, build, vitest. | Auto | | A | Checkpoint. | Checkpoint | | 8 | Tag cr-2026-193-b47-credential-surface. Push. | Auto |


7. Acceptance gate

  1. A credential can be issued, is shown exactly once, and is unreachable afterward by any route — tested, not asserted.
  2. The issuance form states what it grants, in plain terms, before submission.
  3. Verified explicitly that the token appears in no log, URL, query string, or client-side store. This is the failure that would not surface in a test of normal behaviour, so it needs its own check rather than an assumption.
  4. Revoke exists, requires confirmation, works.
  5. No control appears for a state the wire cannot express.
  6. Surface sweep clean. Seed-mutability check recorded, including as a null finding.

8. Kickoff prompt


Execute CR-2026-193 v0.1 at ~/Downloads/cr-2026-193-loomworks-b47-
credential-surface-v0_1.md. Confirm the CR number against the ledger
first.

This replaces CR-2026-188, which halted because it described adding
controls to a credentials list that does not exist. Placement is now
settled from your own survey: a header-opened panel following the
SeedViewer / VoiceListeningPanel precedent. Don't reopen it.

The thing the precedent does NOT settle: SeedViewer only reads. This
panel acts — it issues and revokes write access. Don't let the issue
and revoke affordances inherit SeedViewer's weight.

Step 1 verifies the three routes and the response models against the
code rather than trusting my §2, which is sourced from your own earlier
report. What's genuinely unknown: what fields the list response carries,
and whether a revoked or expired credential is distinguishable from an
active one. The list cannot show a state the wire doesn't carry — if it
can't distinguish, report it, don't invent a display.

HALT if the surface can't do its job without an engine change.

Gate item 3 is the one that won't surface in ordinary testing: verify
explicitly that the token reaches no log, no URL, no query string, and
no client-side store — including that the issuance response isn't
cached anywhere it could be re-read. Check it rather than assume it.

§3.1: propose the header control's wording and state your reasoning. It
sits beside "view seed," which is passive; this one grants access.

Note migration 0103 is now applied to playground_dev, so these routes
are live there.

DUNIN7 — Done In Seven LLC — Miami, Florida CR-2026-193 — B-47 credential surface — v0.1 — 2026-08-08