Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
81 commits
Select commit Hold shift + click to select a range
a623f16
feat: handle Summon wallets with capability-based metadata
kanyuku Mar 3, 2026
b1c8edc
fix(wallet): address PR feedback on legacy Summon wallet CBOR preserv…
kanyuku Mar 28, 2026
a02ad79
feat: agent onboarding, governance overview, wallet transfer, ballot UX
QSchlegel May 11, 2026
e2d21b7
docs(roadmap): MRP task mapping, April–July delivery window, drop tea…
QSchlegel Aug 7, 2026
a226429
feat(documents): Document Sign-Off MVP — data model, routes, CIP-8 si…
QSchlegel Aug 7, 2026
cea05c6
feat(proxy): manage proxy access in-app and explain the on-chain flow
QSchlegel Aug 13, 2026
1703499
docs(mcp): setup instructions that work for GUI clients
QSchlegel Aug 14, 2026
70160f6
Merge pull request #370 from MeshJS/claude/mcp-gui-setup
QSchlegel Aug 14, 2026
12650c4
Merge pull request #364 from MeshJS/claude/proxy-user-management-ux-6…
QSchlegel Aug 14, 2026
5666995
feat: update roadmap for September and October 2026 with new focus ar…
Andre-Diamond Aug 18, 2026
fbb9b9c
Merge origin/preprod into claude/document-signoff-mvp
QSchlegel Aug 19, 2026
36f6ec5
feat(seo): a social card per route, not one card for the whole site
QSchlegel Aug 19, 2026
f745042
Merge pull request #356 from MeshJS/claude/document-signoff-mvp
QSchlegel Aug 21, 2026
afc2eb0
Merge branch 'preprod' into claude/happy-bhabha-fa7fd2
QSchlegel Aug 21, 2026
157340a
Merge preprod into feature/issue-204-summon-api-routes + address review
QSchlegel Aug 21, 2026
ec26d70
Merge pull request #254 from MeshJS/claude/happy-bhabha-fa7fd2
QSchlegel Aug 21, 2026
4499525
Merge preprod (now including #254) into the Summon capability branch
QSchlegel Aug 21, 2026
7209692
Merge pull request #371 from MeshJS/contrib/issue-204-summon-capabili…
QSchlegel Aug 21, 2026
371688b
feat: shielded sign-off — hash-linked vault trust graph and selective…
Aug 21, 2026
4c7071e
feat: vault browser with the trust graph as an overlay
Aug 21, 2026
90354eb
feat(vault): interactive knowledge graph, rendered notes, public route
QSchlegel Aug 21, 2026
43383ae
feat(seo): give /vault its own metadata, social card and sitemap entry
QSchlegel Aug 21, 2026
f5f7074
feat(vault): link /vault from the footer and the crawler fallback
QSchlegel Aug 21, 2026
5254a39
fix: Document Sign-Off shipped with no way to reach it
Aug 21, 2026
7c437db
fix(signing): sign() rejected every valid signature
QSchlegel Aug 21, 2026
6348995
fix(vault): bind document identity into the commitment, and 6 other d…
QSchlegel Aug 21, 2026
d694ca2
feat(documents): platform attestation — signed, chained version history
QSchlegel Aug 21, 2026
6c0ca2f
feat(mcp): read-only document tools, on a new v1 REST surface
QSchlegel Aug 21, 2026
2757278
Merge pull request #372 from MeshJS/claude/fix-signdata-verification
QSchlegel Aug 21, 2026
67d0afb
Merge pull request #373 from MeshJS/claude/documents-nav-entry
QSchlegel Aug 21, 2026
937d5e3
Merge pull request #374 from MeshJS/claude/vault-view
QSchlegel Aug 21, 2026
02ac01a
Merge pull request #375 from MeshJS/claude/document-attestation
QSchlegel Aug 21, 2026
32c19c7
Merge pull request #376 from MeshJS/claude/mcp-documents
QSchlegel Aug 21, 2026
1293046
feat(documents): preview shielded sign-off inside the Documents section
QSchlegel Aug 21, 2026
8e4b040
Merge pull request #377 from MeshJS/claude/documents-vault-preview
QSchlegel Aug 22, 2026
18c7dda
fix(security): unaccepted invitations are a count, not attacker-chose…
QSchlegel Aug 22, 2026
3278535
feat(documents): DocumentDraft — a mutable body that cannot be signed
QSchlegel Aug 22, 2026
4334bfb
Merge pull request #379 from MeshJS/claude/wallet-invite-count
QSchlegel Aug 22, 2026
c339150
Merge pull request #380 from MeshJS/claude/document-draft-layer
QSchlegel Aug 22, 2026
ad2f119
feat(documents): a wallet's own vault, built from the database
QSchlegel Aug 22, 2026
0da6532
Merge pull request #381 from MeshJS/claude/wallet-vault-view
QSchlegel Aug 22, 2026
17d61e0
feat(documents): real upload control, and archive / delete actions
QSchlegel Aug 22, 2026
08f595f
Merge pull request #378 from MeshJS/claude/documents-detail-actions
QSchlegel Aug 22, 2026
7291ccf
feat(documents): draft editor with live preview and honest collaboration
QSchlegel Aug 22, 2026
654c018
Merge pull request #382 from MeshJS/claude/document-editor
QSchlegel Aug 22, 2026
1911d5e
docs(vault): a how-to for shielded sign-off, linked from both vaults
QSchlegel Aug 23, 2026
3cae58e
fix(security): RLS for DocumentDraft and DocumentAttestation
QSchlegel Aug 23, 2026
c1a103a
test(documents): end-to-end sign-off against a real database and real…
QSchlegel Aug 23, 2026
a5e2464
Merge pull request #383 from MeshJS/claude/shielded-signoff-guide
QSchlegel Aug 23, 2026
429b231
Merge pull request #384 from MeshJS/claude/rls-document-tables
QSchlegel Aug 23, 2026
2dead16
Merge pull request #386 from MeshJS/claude/document-e2e
QSchlegel Aug 23, 2026
aa45c22
feat(documents): contract parties, roles, optional parties and dual r…
QSchlegel Aug 23, 2026
5739ddd
Merge pull request #387 from MeshJS/claude/contract-model-v2
QSchlegel Aug 23, 2026
5402943
feat(documents): let a named contract party reach the contract
QSchlegel Aug 23, 2026
5207810
Merge pull request #388 from MeshJS/claude/contract-access
QSchlegel Aug 23, 2026
b6f5e17
feat(roadmap): add project task board with multisig payouts to roadmap
Andre-Diamond Aug 24, 2026
80b9656
feat: enhance transaction building with metadata support and change h…
Andre-Diamond Aug 26, 2026
3958b1f
feat(tx-draft): introduce funding source management for transaction d…
Andre-Diamond Aug 27, 2026
7f4bc1f
feat(notifications): implement ballot deadline reminders and threshol…
Andre-Diamond Aug 27, 2026
e57681c
feat: add participantsInclude function for key hash matching in regis…
Andre-Diamond Aug 31, 2026
212e0ac
Merge pull request #391 from MeshJS/feat/sign-off-tx-visualization
Andre-Diamond Aug 31, 2026
f372383
fix(vault): escape square brackets correctly in markdown links
Andre-Diamond Aug 31, 2026
533e38f
feat(tx-review): implement transaction proposal and review functional…
Andre-Diamond Sep 7, 2026
958cfb2
feat: implement review card MCP App with inline rendering and server …
Andre-Diamond Sep 8, 2026
e1ffcdd
feat: enhance stake account handling in transaction review pipeline
Andre-Diamond Sep 8, 2026
cb6e011
feat: implement DRep registration checks in transaction pipeline and …
Andre-Diamond Sep 8, 2026
46fd80a
feat(task-payout): implement task payout functionality
Andre-Diamond Sep 10, 2026
27226e1
refactor: improve payout dialog and task management UI
Andre-Diamond Sep 11, 2026
6f28cf3
feat: introduce card delivery modes for transaction previews and prop…
Andre-Diamond Sep 12, 2026
5900a7c
feat(documents): a public proof verifier, and the proof as a PDF
QSchlegel Sep 17, 2026
074ce67
Merge pull request #397 from MeshJS/claude/signoff-verify-and-pdf
QSchlegel Sep 17, 2026
4c45488
fix(verify): the proof verifier showed visitors the homepage
QSchlegel Sep 17, 2026
d0c95a4
Merge pull request #398 from MeshJS/claude/verify-public-route
QSchlegel Sep 17, 2026
f702000
feat(task-board): enhance task management and payout functionality
Andre-Diamond Sep 22, 2026
f58d53c
feat(tasks): enhance payout functionality and UI
Andre-Diamond Sep 23, 2026
6481eb9
refactor(task-payout): remove unused MCP tools and related functions
Andre-Diamond Sep 24, 2026
aa11193
refactor(task-payout): remove unused MCP tools and related functions
Andre-Diamond Sep 24, 2026
7755f5e
Merge pull request #399 from MeshJS/feat/mcp-unsigned-tx-creation
Andre-Diamond Oct 5, 2026
4e3fe38
feat(bot-setup): implement bot setup guide and related API enhancements
Andre-Diamond Oct 5, 2026
488e349
chore: add dotenv package for environment variable management
Andre-Diamond Oct 5, 2026
e991899
feat: add TypeScript types for three.js and update modern request hea…
Andre-Diamond Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
29 changes: 23 additions & 6 deletions .agents/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,15 +41,32 @@ Specs live in the vault, not this repo. The maintainer keeps a document-driven d

- **Endpoint**: `POST /api/mcp` — a stateless Model Context Protocol server built on
`@modelcontextprotocol/server` v2. Docs: `src/pages/api/mcp/README.md`.
- **Surface**: read-only plus governance ballot drafts. It cannot sign, spend or
broadcast, and that boundary is enforced by a test (`src/__tests__/mcpTools.test.ts`) —
adding a write tool must be a deliberate decision, not a registry addition.
- **Surface**: read-only, governance ballot drafts, and — under the opt-in
`transactions:write` scope — unsigned transaction drafts in two steps
(`transaction_preview` returns a review-card PNG plus a signed draft token;
`transaction_propose` takes only that token and creates the pending transaction with
zero signatures). It cannot sign, spend or broadcast, and that boundary is enforced by
a test (`src/__tests__/mcpTools.test.ts`) — adding a write tool must be a deliberate
decision, not a registry addition.
- **Tools wrap the existing v1 handlers in-process** via `src/lib/mcp/invokeV1.ts`, so
authorization and validation stay defined once. Handler imports in
`src/lib/mcp/tools.ts` must stay **lazy** or the Mesh/whisky WASM lands in the route's
cold path.
authorization and validation stay defined once — including the dual identity (human
signer JWT vs. bot key with a WalletBotAccess grant), which a tool body calling a
tRPC router directly would not reproduce. A tool that needs an operation with no REST
route gets a new v1 handler first (`tasks.ts` / `taskUpsert.ts` are the model). The
transaction review tools are the exception: they live in `src/lib/tx-review/` and
reuse the canvas builder's `src/lib/tx-draft/` pipeline server-side, and even they
take their UTxOs from `freeUtxos.ts` through `freeUtxosFetcher` in `tools.ts`. Handler
imports in `src/lib/mcp/tools.ts` must stay **lazy** or the Mesh/whisky WASM (and the
`next/og` renderer) lands in the route's cold path.
- **Auth**: an OAuth 2.1 access token, or an existing v1 bearer token. The authorization
server lives under `src/pages/api/oauth/` — see `src/pages/api/oauth/README.md`.
- **Inline card (MCP App)**: the review tools point at `ui://mesh-multisig/review-card`
(`src/lib/mcp/apps/review-card.ts`), a self-contained HTML view the Claude app renders
inline with a Confirm button. Keep it dependency-free (default CSP: no fetch, no external
assets) and keep the `ui/initialize` handshake — the host hides the frame until it completes.
- **Server instructions** (`MCP_SERVER_INSTRUCTIONS`, `src/lib/mcp/server.ts`) are sent
at initialize and land in the model's context for every conversation: keep them short
and behavioural (what to do with tool results), never a feature list.

## Docs to keep in sync

Expand Down
6 changes: 3 additions & 3 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -40,9 +40,9 @@ NEXT_PUBLIC_BLOCKFROST_API_KEY_PREPROD="your-blockfrost-preprod-api-key"
# SNAPSHOT_AUTH_TOKEN="your-snapshot-auth-token"

# Canonical public URL of the deployment.
# Used for SEO: canonical tags, Open Graph / Twitter URLs, robots.txt and the
# sitemap. Defaults to the production domain when unset; set this on preview or
# self-hosted environments so links point at the right origin.
# Used for bot setup guide URLs and SEO: canonical tags, Open Graph / Twitter
# URLs, robots.txt and the sitemap. Defaults to the production domain when unset;
# set this on local, preview or self-hosted environments so links point at the right origin.
# NEXT_PUBLIC_SITE_URL="https://multisig.meshjs.dev"

# Optional: Skip environment validation during builds
Expand Down
50 changes: 50 additions & 0 deletions .github/workflows/ballot-deadline-reminders.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
name: Ballot Deadline Reminders

# Enqueues 48h/24h ballot-deadline reminder emails (derived from on-chain
# proposal expiration epochs) and drains the outbox, by calling the
# authenticated reminder endpoint. Shares NOTIFICATION_DRAIN_SECRET with the
# outbox drain workflow; until it is set both here and on the deployment, runs
# are graceful no-ops.

on:
schedule:
# Hourly; reminder windows are 24h wide so this is ample resolution.
- cron: '17 * * * *'
# Allow manual triggering for testing
workflow_dispatch:

jobs:
remind:
runs-on: ubuntu-latest
timeout-minutes: 5

steps:
- name: Scan ballots and enqueue deadline reminders
env:
API_BASE_URL: 'https://multisig.meshjs.dev'
DRAIN_SECRET: ${{ secrets.NOTIFICATION_DRAIN_SECRET }}
run: |
if [ -z "$DRAIN_SECRET" ]; then
echo "NOTIFICATION_DRAIN_SECRET repo secret is not set; skipping."
exit 0
fi

status=$(curl -s -o response.json -w "%{http_code}" -X POST \
"$API_BASE_URL/api/notifications/ballot-deadlines" \
-H "Authorization: Bearer $DRAIN_SECRET")

echo "HTTP $status"
cat response.json || true
echo

case "$status" in
200)
;;
503)
echo "Endpoint reports NOTIFICATION_DRAIN_SECRET is not configured on the deployment; skipping."
;;
*)
echo "Ballot deadline reminder request failed."
exit 1
;;
esac
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -347,7 +347,8 @@ The application provides comprehensive API documentation through Swagger UI:
- `GET /api/v1/walletIds` - Get user's wallet IDs
- `POST /api/v1/addTransaction` - Create new transaction
- `POST /api/v1/authSigner` - Authenticate signer
- `GET /api/v1/lookupMultisigWallet` - Lookup multisig wallet
- `GET /api/v1/lookupMultisigWallet` - Lookup multisig wallet registrations by signer key hash
- `GET /api/v1/resolveScript` - Resolve a native script (policy id or wallet address) to its signer key hashes
- `POST /api/discord/send-message` - Send Discord notifications

> 💡 **Tip**: The Swagger UI provides interactive API testing. Start the dev server and visit `/api-docs` to explore all available endpoints.
Expand Down
Loading
Loading