Skip to content

feat: reins key — TypeSafe key storage and popup setup for reins do (1/3) - #41

Open
karngyan wants to merge 13 commits into
mainfrom
feat/reins-do
Open

karngyan wants to merge 13 commits into
mainfrom
feat/reins-do

Conversation

@karngyan

@karngyan karngyan commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Part 1 of 3 for reins do (stacked: this → #42 → #43). Merge in order.

Why

reins do "<goal>" hands a whole browsing goal to TypeSafe's Jev model and returns when it's done or needs a decision. Jev is opt-in and uses the user's own TypeSafe key, so the key needs a home first: one file on the machine, shared by every browser, settable from the CLI or the extension popup.

What

  • Key file: ~/.reins/credentials.json (0600, atomic write). Only the daemon reads it; the extension never stores the key.
  • reins key set|status|clear: hidden prompt (or stdin), validated against TypeSafe before saving. status shows only the last 4 characters (typesafe: set (••••e876)).
  • Protocol: a new call frame lets the extension call the daemon (key_set / key_status / key_clear only; anything else gets METHOD_NOT_ALLOWED).
  • Popup: a Jev section with a short pitch for reins do, plus Save / Replace / Cancel / Remove. The input is disabled with "Start reins to save a key" when the daemon is offline, and key_set gets a 20s timeout.
  • Jev client: built on the official @typesafe-ai/sdk 0.6.0 (pinned exact), with strict validation of choices and probabilities.
  • Audit: key_set logs the key as [redacted].
  • Docs: PRIVACY.md, SECURITY.md, the Chrome Web Store copy and the web privacy/security/FAQ pages say what reins do sends to TypeSafe and what it never sends. The "nothing leaves your machine" claims are now scoped to "unless you opt in to reins do".
  • Changeset: @karnstack/reins and @reins/extension minor.
  • Design: spec docs/superpowers/specs/2026-09-27-reins-do-design.md, plan docs/superpowers/plans/2026-09-27-reins-do.md.

Testing

  • Unit tests cover the credentials file (atomic write, mode), SDK error mapping and choice validation, the key service, daemon call frames, audit redaction, and the popup view states.
  • Checked by hand on the maintainer's Chrome: reins key status read the real key file (the key itself was never printed).

🤖 Generated with Claude Code

karngyan and others added 12 commits September 27, 2026 02:27
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Reads the key without echo (raw-mode TTY or piped stdin), saves it via
the daemon's key_set RPC, and prints a status line plus what reins do
will send. Key parameter parse failures now surface as a plain one-line
error (the first zod issue's message) instead of a ZodError dump.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- Save's finally restores only the label; disabled state comes from the
  renderer (re-run from live connectivity after a failed save/remove) so a
  daemon drop mid-save can't leave Save enabled on an offline form
- Cancel button + Escape leave Replace mode
- generation counter drops superseded renderJev results
- reins:call carries an optional timeoutMs; key_set sends 20 s so a slow
  TypeSafe validation isn't reported as an outdated daemon
- primary Save button, :disabled styles for buttons and inputs
- pure jevViewFlags() with tests for offline / unset / set / replacing

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The protocol-guard CI job requires it: this PR changes packages/protocol.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@karngyan
karngyan added this pull request to stack #44 September 27, 2026 08:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant