Skip to content

Add staged Care Plan prototype through Personal Safety Plans - #2274

Merged
BigSimmo merged 57 commits into
mainfrom
claude/ed-care-plans-impl-7f44cd
Aug 22, 2026
Merged

Add staged Care Plan prototype through Personal Safety Plans#2274
BigSimmo merged 57 commits into
mainfrom
claude/ed-care-plans-impl-7f44cd

Conversation

@BigSimmo

@BigSimmo BigSimmo commented Aug 22, 2026

Copy link
Copy Markdown
Owner

Summary

  • Adds a linked, fully synthetic and memory-only Care Plan prototype through Management Plan authoring, ED Presentation continuity, and Personal Safety Plans (implementation-plan Tasks 1–8).
  • Patient Plan plus the operational Reviews, Team, Governance, and History work (Tasks 9–11) remain route specimens. The Developer Hub labels the work as Stage B in progress rather than presenting those routes as complete.
  • Fixes two review defects: shell searches now seed the Patients directory without putting the term in the URL, and permission/version-conflict states cannot invoke browser printing.
  • Fits the prototype into current main by restoring Care Plan as a first-class, tested Developer Hub panel after the new hub replaced the old development index.
  • Removes seven stale session/transcript/handoff artefacts, resolves the historical Gitleaks false positive by exact fingerprint, and replaces the raw print margin literal with the shared print token.
  • Refreshes the deliberately stale bundle baseline from a fresh production build. Before refresh, production was +8.6% and still within its 10% guard; the developer-only mockup bucket was +33.8% and legitimately exceeded its 25% hygiene ceiling.

Verification

  • npm run verify:pr-local
  • Final wrapper not rerun: the repaired, merge-synced head was covered by the focused behavioral, type, design, bundle, and production-build gates below; CI remains the broad PR authority.
  • npm run test -- tests/care-plan-linked-routes.dom.test.tsx tests/developer-hub-panels.test.ts tests/developer-hub-page.dom.test.tsx --pool=threads — 235/235 passed.
  • npm run typecheck — passed.
  • npm run check:design-system-contract — passed.
  • npm run check:gitleaks-pinned — passed.
  • npm run build — passed from a freshly removed .next; Next 16 compiled, typechecked, generated 1,969 pages, and passed the client-bundle secret check.
  • npm run check:bundle-budget — passed from that exact build after the deliberate baseline refresh.
  • npm run format — completed on the final tree.
  • npm run verify:ui
  • UI verification not run on the final head: focused DOM coverage and the production build passed; CI is the complete Chromium authority.
  • npm run verify:release
  • Release gate not run: no release-confidence claim is made.
  • npm run check:production-readiness — run; source/runtime checks passed, while provider configuration was environment-gated in the isolated worktree because Supabase/OpenAI secrets were intentionally absent.

Risk and rollout

  • Risk: Medium. This is a large developer-only prototype surface with clinical language, but it remains signed-in-administrator gated, synthetic, deterministic, memory-only, and explicitly not validated clinical decision support.
  • Rollback: Revert this PR and its bundle-baseline update. There is no migration, provider state, or persisted prototype data to unwind.
  • Provider or production effects: None.
  • RAG impact: none.

Clinical Governance Preflight

  • Source-backed claims still require linked source verification before clinical use
  • No patient-identifiable document workflow was introduced or expanded without explicit governance approval
  • Supabase target remains Clinical KB Database (sjrfecxgysukkwxsowpy)
  • Service-role keys and private document access remain server-only
  • Demo/synthetic content remains clearly separated from real clinical sources
  • Source metadata, review status, and outdated/unknown-source behavior remain conservative
  • Deployment classification/TGA SaMD impact was checked when clinical decision-support behavior changed

Notes

  • Implemented scope is Tasks 1–8 only. Tasks 9–11 remain visible route specimens so the navigation contract can be reviewed without claiming those workflows are built.
  • The branch is merge-synced with current main; no history rewrite or force-push is used.

BigSimmo and others added 30 commits August 21, 2026 01:29
Brings the ED Care Plans design specification, domain glossary, nine-task
implementation plan and handover documents into this worktree, and applies
the four decisions the user made on 21 August 2026:

- Build the synthetic prototype now, but keep the domain shaped so real
  persistence could be added later without redesigning it. Recorded as a
  Global Constraint (pure reducer, serialisable state, caller-allocated
  IDs, single dispatch path) and as decision 9 in the specification. No
  storage layer, adapter or migration scaffolding is built now.
- Keep the full multi-service workflow, including named senior-clinician
  approval. No change to the specification.
- Deliver Tasks 1-5 as Stage A, stop at a mandatory checkpoint for user
  review, then Tasks 6-9 as Stage B. Added a Delivery Stages section and
  a Stage A Checkpoint with its own evidence steps.
- Local task commits authorised; nothing pushed. Replaced the nine
  "after explicit local-commit permission" steps accordingly.

Also corrected three stale facts in the plan: the target worktree and
branch (now this worktree, based on current main), the "task-start
preflight has already run" line, and the import homes of the twelve
shared UI primitives (InlineNotice and EmptyState live in
src/components/ui-primitives.tsx, not src/components/ui/). All twelve
export paths were verified against this worktree.

No application code exists yet. No test, typecheck, lint, build or
browser gate has run for this feature.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Five decisions from a proper brainstorming pass with the user, which the
first Claude pass skipped by treating the Codex handover's "brainstorming
is complete" note as binding. It was not; it was a prior agent's note.

1. Management Plan content cut from nineteen fields to eleven, in two
   tiers. Four field pairs said the same thing twice (helps/helpful,
   worse/unhelpful, engagement/agreed-approach, pattern/triggers), which
   would leave an author unsure where a sentence belongs and a reader
   seeing the same guidance twice. Nineteen required fields is also an
   authoring burden heavy enough that plans do not get written.

2. The first-minute summary is exactly five sections: how to approach,
   what helps, what makes it worse, what we have agreed to do, and what
   would make this presentation different. The last two were previously
   below the fold in the full plan despite being the safety-critical
   ones. whatWouldMakeThisDifferent is never collapsed, truncated or
   clipped, at any viewport or in print, and has its own acceptance
   criterion.

3. An ED Presentation now requires only site, disposition, plan
   availability, plan use, plan helpfulness and a free-text note, with
   the richer fields behind a disclosure. The previous fifteen-field
   record was two to three minutes of typing at shift end in a second
   system; unfilled, it would have left the Review Suggested queue
   permanently empty and made a third of the app scaffolding for a loop
   that never runs.

4. The review clock was a genuine hole: the spec defined within_review,
   due_soon and overdue but never their durations. Now a 12-month
   editable per-version default with a 28-day amber window, shared by
   both plan types. Deliberately unlike the identification threshold,
   which stays null and pending governance.

5. Identification Reviews can now be closed. Previously they could be
   opened but never closed, so the queue would have filled permanently
   and become useless. Closing records one of proceed_to_plan,
   not_needed_now or revisit_later plus a reason, and creates no plan on
   any decision.

Adds IdentificationDecision, close-identification-review,
identification_review_closed, MANAGEMENT_PLAN_REQUIRED_CONTENT_KEYS,
FIRST_MINUTE_CONTENT_KEYS, REVIEW_INTERVAL_MONTHS, REVIEW_DUE_SOON_DAYS
and deriveReviewState, and updates Tasks 1, 2, 5, 6 and 8 to match.
Checked for stale references to the seventeen removed content keys:
none remain in either document.

Still no application code. No test, typecheck, lint, build or browser
gate has run for this feature.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Renames ED Care Plans to Care Plan across every path, identifier and
document, and records the decisions from the grilling round. Nothing is
built yet, so the rename is free today and irritating in a month.

Ordering principle, from the user: "the plan is for clinicians to look up
and see the management plan; it is rarely for changing or updating."
Read primacy is now written into the spec as a rule — where reading and
authoring compete for space, navigation depth, attention or effort,
reading wins — and it reorders the build. The old Task 5 splits: the
complete reading surface, including the pinned safety boundary and a
clinician print view, now closes Stage A, and every authoring surface
moves to Stage B. The plan is eleven tasks and twenty-one routes.

Decisions applied:

- Admission wording. agreedEdApproach must name who agreed the position
  and when, read as an agreed default rather than a ceiling on care, and
  never use a prohibitive construction. BANNED_ADMISSION_CONSTRUCTIONS is
  checked at the form boundary and by a fixture scan. Refusing to record
  the decision would not undo it, only make it unaccountable.
- The safety boundary is pinned above all plan content as well as sitting
  in its numbered place, because on a phone the five sections are a long
  card and a hurried reader stops before the end.
- whatMakesItWorse is written about what the service does, not what the
  person does. Fixtures model it, because fixtures are what real plans
  written in this tool will imitate.
- A version may be approved at any participation state, but declined and
  patient_unavailable carry a permanent "written without this person's
  involvement" marker and raise a Review Trigger.
- Withdrawal is senior-clinician only and renders distinctly from a
  patient who never had a plan.
- Any clinical role may author a Personal Safety Plan, including an ED
  clinician mid-shift. Only the non-clinical coordinator cannot.
- Sort-by-count exists only inside the Identification Review workflow.
  The activity view gains per-site breakdown and a one-line account per
  presentation.
- Amendment extends to the one-line account and the plan-use answers.
- The route family is gated in production so it works on the live site
  for a signed-in administrator, as Caring Contacts already is.
- The required presentation note becomes "In one line: why they came and
  what happened", doing the work the optional indication and outcome
  fields would otherwise do.

New Task 9, the Patient Plan. A deterministic offline transformation of
an approved Management Plan Version into a patient-facing edition:
eleven known fields to eight patient-voice headings through a curated
dictionary. It emits a visible gap wherever it cannot convert
confidently and never guesses, and it never auto-converts the agreed-ED-
approach section under any circumstances — that is where a wording slip
does the most harm. A clinician (any clinical role, not only a senior
one) must approve before the patient receives it, and cannot approve
while a gap is unfilled. Resources are typed and include housing,
financial and transport categories, because those are frequently the
actual reason someone keeps presenting. When a newer Management Plan
Version is approved the patient copy is marked as needing updating and
stays readable rather than regenerating or hiding, since the person may
be holding a printed copy. No language model, network call or provider
is involved; the pure-function shape means a model-backed version later
is a swap, not a redesign.

Both print views are built on the shared PrintOutput primitive, with
genuinely general capabilities added there and consumed, not
reimplemented locally.

This branch's worktree was deleted by external tooling mid-session
before this work was committed; the two prior commits survived and this
change is a replay of the lost uncommitted work.

Still no application code. No test, typecheck, lint, build or browser
gate has run for this feature.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Rename the CMHT contact subject to "Care Plan - team contact request",
widen PresentationAmendment.field to the spec's amendable set via a new
AmendableField union, and use the verified Rurallink source URL. Adds a
plan-use amendment fixture and a covering test so the widened union is
exercised at runtime, not only in types.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
All four are controller mistakes in the planning documents, not in the
implementation. The implementer followed the plan verbatim, which is why
they showed up as working code rather than as questions.

1. The product rename missed the URL-encoded form. Replacing "ED Care
   Plans" and "ed-care-plans" left "ED+Care+Plans" untouched inside a
   mailto subject that Task 1's brief pinned in a verbatim test. The
   generic contact subject is now "Care Plan - team contact request".

2. PresentationAmendment.field contradicted the spec. The grilling round
   widened the amendable set to disposition, assessment outcome, the
   one-line account and the three plan-use answers, but the canonical
   type still allowed only the first two. Adds AmendableField with all
   six values; the two amend-presentation action variants collapse to
   one carrying a string replacement, and the reducer will validate that
   a disposition replacement parses. The plan-use answers group in the
   UI at Task 7, but each changed answer still records its own
   attributed amendment, so stored evidence stays one field per record.

3. The rename over-reached and rewrote real identifiers. It rewrote this
   worktree's path, this branch name, the superseded Codex worktree path
   and codex/ed-care-plans, so the plan's first Global Constraint sent a
   future implementer to a directory that does not exist. Restored, and
   every src/, tests/ and scripts/ path named in the plan and spec was
   swept against the filesystem - all present except the two SDD skill
   scripts, which correctly live in the skill directory.

4. CLAUDE-START-HERE.md carried a stale copy/paste prompt naming nine
   tasks and the superseded Codex branch. Replaced with a resume prompt
   that points at the SDD ledger and states the eleven-task shape and
   the Stage A checkpoint.

Also records two verified WA crisis source deep links, and pins the ACMA
range reserved for fiction so no later task renumbers it to something
that looks more fictional but is really allocatable.

No application behaviour changes here; Task 1's matching code changes
are committed separately.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Renumber the six CMHT telephone numbers and the three personal-support
contacts into 0491 570 006-156, the ACMA range reserved for fiction, using
the allocation that also satisfies Task 4's pinned duty number. Rewrite the
three after-hours labels so a fictional mobile is no longer presented under
the name of a real crisis service; the verified public crisis lines are
unchanged. Replace the literal-list number test with a numeric range
assertion so a number added later cannot sit outside the reserved span.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The CMHT after-hours pathway is the public crisis service, not a fictional
team line: a reader dialling it from a printed safety plan must reach a real
service. Restore MHERL, MHERL Peel, and Rurallink with their real numbers
and names, each keeping the not-an-emergency-service caveat, the 000
pointer, and Rurallink's hours. Duty numbers and personal supports stay in
the reserved fiction range.

Split the number test into two rules: every Australian mobile must sit
inside 0491 570 006-156, checked numerically, and every other number must
appear in an explicit four-entry public allowlist. Also pins that the three
dialable crisis lines are still present, and guards the mobile sweep against
passing vacuously.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Task review round 1. Fixture prose claimed episode counts the records did
not support: add the two missing left-before-completion episodes for Jordan
and Alex, move Alex's episode before the referral that cites it, and drop an
unverifiable time-scoped count from Evelyn's referral. Add a test deriving
each patient's counts from the episode records and checking no prose
contradicts them.

Rebuild the service-facing, concrete-findings and agreed-and-when guards as
predicates with negative controls, each proven to reject the sentence that
previously slipped through, and run them over every version rather than only
the current ones. Replace the glossary-banned ED Presentation synonyms and
test for them.

Remove stored reviewState from both version types so it cannot drift from
the date it describes; review state is always derived. Return overdue from
deriveReviewState for an unreadable date, so failure degrades conservatively
rather than showing the most reassuring state.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Task 1 review found ManagementPlanVersion.reviewState and
PersonalSafetyPlanVersion.reviewState restating what
deriveReviewState(reviewDueAt, now) computes, with a consistency test
covering only the first of the two. A stored copy of a currency
indicator can drift from the date it claims to describe, and this one
is read to decide whether a clinical plan is still trustworthy.

Removes both fields from the canonical block rather than adding the
missing test, since nothing consumes them yet. Records that an
unparseable date derives overdue, so a malformed value surfaces
rather than reassuring the reader.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Task review round 2. Evelyn's referral claimed she had presented since her
plan was withdrawn, but it was written seven days after the withdrawal and
24 days before the only post-withdrawal presentation. Move the referral to
two days after that presentation, so the sentence is true and the referral
follows the event that prompted it.

Add a chronology guard over IdentificationReview.reason and
ManagementPlanVersion.withdrawalReason: a reason citing a presentation must
have at least one that falls before the record's own timestamp, and a reason
saying "since" a withdrawal must have one between the two. Proven by
reverting the date and watching it fail.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
One pure reducer now enforces the whole Management Plan, Personal Safety
Plan, ED Presentation, and Identification Review lifecycle, and one
layout-scoped provider shares that state across every route.

The reducer is a plain (state, action) => state function: no clock,
network, storage, browser API, randomness, or module-level mutable state.
Timestamps derive from PROTOTYPE_NOW and identifiers from the identifiers
already in state, so an action sequence reproduces byte for byte.

Permission and degraded-state checks share one funnel, so no transition
can reach a clinical record without being rechecked against
canPerformAction. Approval is atomic and leaves exactly one Current Plan;
withdrawal leaves none and restores nothing; ED Presentations stay
append-only with attributed corrections beside them; contact and print
actions record an intent and never claim an outcome.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
All three are controller mistakes in the plan, not implementation faults.

1. ReviewTrigger.source could not express the participation trigger the
   Global Constraints require. Approving a version at declined or
   patient_unavailable participation is supposed to raise an open trigger
   so involving the person stays on somebody list, but the canonical union
   had no value for it and redefining canonical types is forbidden. Adds
   a participation source. The on-screen marker is not a substitute: a
   marker is read only by whoever opens that plan, while a trigger reaches
   the Reviews queue where somebody owns it.

2. The plan told Task 2 to add an online/offline listener. The spec is
   binding and says the offline state exists only in the dedicated
   specimen scenario. Nothing in a memory-only prototype depends on the
   network, so a real connectivity event must not change state, and
   driving it through apply-scenario reconstructs fixtures and discards
   whatever the user was working on because their wifi blipped.
   Instruction removed with the reasoning recorded.

3. Task 2 example test named fixtures that predate Task 1. The shipped
   identifier is SYN-MGMT-PLAN-002, getOpenManagementDraft takes
   (versions, planId), and Mira former Current is version 1. Snippet
   corrected so it no longer misleads a later reader.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…listener

Fix round 1 against plan 9600e12.

ReviewTrigger.source gains "participation" from the corrected canonical
block, and approving a version whose participationState is declined or
patient_unavailable now raises one open trigger with that source, keyed
to the approved version and deduplicated against an open participation
trigger already on the plan. Participation still never blocks approval;
what it does is put going through the plan with the person into the
Reviews queue, where somebody owns it. A marker on the plan is read only
by whoever opens that plan. Approval still appends exactly one audit
event, and the two reasons are worded separately so neither declining
nor being unavailable reads as blame.

The provider loses its online/offline listener, ref and effect. Nothing
in a memory-only prototype depends on the network, so a real
connectivity event must not change state, and routing it through
apply-scenario rebuilt the fixtures and discarded whatever the user was
working on. connectivity.online is a specimen flag now set from the
System states route alone; the reasoning is recorded in the file so it
is not re-added.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1. Review Triggers must reach the withdrawn-plan cohort. The reducer
   gated trigger creation on a live Current version, so a person whose
   plan was withdrawn who then presents and is admitted produced nothing
   for the Reviews queue. That is the cohort the queue most exists for.
   The line is now has-ever-had-a-version, not has-a-current-version;
   only a patient who never had one raises none, and for them the
   pathway is Identification Review rather than plan review.

2. Approval requires a non-empty revisionReason. A version must not
   become the Current Plan with no stated reason for existing, and the
   reducer is the final guard rather than the form.

3. Printing the Personal Safety Plan is exempt from the offline block.
   It is the one action you most want when systems are down and it
   appends an audit event rather than changing a clinical record.
   Identity uncertainty still blocks it, because printing the wrong
   persons safety plan is a real harm.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…save

Fix round 2 against the Task 2 review and rulings bdcf2f0.

A Review Trigger was gated on a live Current version, so someone whose
plan had been withdrawn, who then presented and was admitted, produced
nothing for the Reviews queue. The line is now whether the patient has
ever had a Management Plan version. Only a patient who has never had one
raises none, because for them the pathway is Identification Review
rather than plan review. Jordan and Evelyn are now separate pinned tests
rather than one test and an untested consequence.

save-safety-plan-draft was dispatched by no test at all. Its state
guard, its unparseable review date refusal and its content copy now have
three, and mutations redden each of them.

Approval additionally requires a non-empty revisionReason: a version
must not become the Current Plan with no stated reason for existing, and
the reducer is the final guard rather than the form.

record-safety-plan-print-intent is exempt from the connectivity block
alone. Printing the person's own safety plan is what you most want when
systems are down, and it appends an audit event rather than changing a
record; identity uncertainty, permission and version conflict still
block it, because printing the wrong person's safety plan is a real
harm.

The participation trigger reason no longer asserts that an unavailable
person was absent. A new draft starts at that state before anybody
records anything, so it now says only that no involvement is recorded.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The worktree at .claude/worktrees/ed-care-plans-impl-7f44cd was destroyed
for the third time today, mid-task, through an explicit git worktree
lock. Nothing committed was lost - every recovery was one git worktree
add - but the git-ignored SDD workspace died with it, taking the ledger,
briefs, reports and review packages.

So the ledger is now a tracked file. The superpowers skill puts it in
git-ignored scratch, which is right when scratch is safe; it is not safe
here. Reconstructed from the controlling session's context and the commit
history, which agree.

Adds:

- docs/care-plan/sdd-ledger.md - progress, all 25 controller rulings with
  what each costs if wrong, 19 deferred minors for the whole-branch
  review, and four systemic lessons (shell layers corrupting source,
  guards that cannot fail, inaccurate reports, commit every task).
- docs/care-plan/session-handoff-2026-08-21.md - state, the thirteen
  binding product decisions, the environment hazard, the prompt to start
  the next session, and the authorisation boundary.

Rewrites CLAUDE-START-HERE.md to point at both and at the relocated
worktree.

Work has moved to D:\Worktrees\Database\care-plan. That parent directory
has been untouched all day and a sibling worktree there survived all
three destructions. Do not recreate a worktree under .claude/worktrees/.

State: Tasks 1 and 2 complete, reviewed and committed - 121 tests
passing, typecheck and lint clean at last run. Task 3 not started, no
partial work. Nothing pushed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Re-running the suites after relocation gave Test Files 2 passed (2) /
Tests 121 passed (121), so the recovery is sound.

But npm run typecheck fails there, and the handoff must not imply
otherwise. The failures are three unrelated pre-existing files -
universal-search and two use-in-page-section-nav DOM tests - with
module-resolution errors typical of a half-finished install, and there
are zero errors in any care-plan source or test file. Typecheck exited 0
in the previous worktree at the same commit. The npm ci was backgrounded
and never reported completion.

Records all of that so the next session re-runs the install to completion
before reporting any gate as green, rather than either trusting a stale
clean result or mistaking an install artefact for a regression.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
A single chronological record of everything done on Care Plan across both
sessions - the Codex design session and the Claude build session - with
every artefact, every commit and its time, every decision and where it
came from, the current state, and an explicit list of what has NOT been
done so no later reader infers coverage that does not exist.

The three existing documents each answer a different question and this
adds the fourth:

- complete-work-ledger.md  - what happened, in order (this file)
- sdd-ledger.md            - decisions taken, with what each costs if wrong
- session-handoff-2026-08-21.md - where to pick up, and the prompt to do it
- CLAUDE-START-HERE.md     - orientation, pointing at the other three

Records that no UI exists yet, so no browser, accessibility, responsive,
print, build or bundle check has ever run for this feature, and that the
current typecheck failure in the relocated worktree is an unfinished
dependency install rather than a regression.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Written while Prettier was unavailable in the relocated worktree, so
never formatted. The pre-push guard caught it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…tion

I advised moving the work to D:\Worktrees\Database\care-plan because that
parent had been untouched all day. It was destroyed there too, within the
hour, by the same method: .git pointer first, then 1,301 files.

So the advice was wrong and the documents said so. No directory on this
machine is safe. The only thing that has ever protected this work is
committing and pushing, which is now done - origin/claude/ed-care-plans-impl-7f44cd
is the authoritative copy.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
… fixed

The three handover documents said the cause was not conclusively
identified. That was wrong, and the answer was in front of me the whole
time - both fixes are already on main and this branch predates them:

  a04330e  harden(guard-push): never force-delete a scratch checkout
             that still holds a borrowed node_modules link (#2244)
  cdfcbac  fix(worktrees): stop silent worktree wipes and misdirected
             commands (#2240)

The old scripts/guard-push.mjs linked a borrowed worktree's real
node_modules into a scratch checkout as a Windows junction, then
force-deleted that checkout recursively. A git worktree lock cannot stop
it because it is a filesystem delete, not a git worktree operation - which
is exactly why the third destruction went through a lock. Any concurrent
session pushing from a stale base ran it against whichever worktree it
had borrowed from.

This branch is 122 commits behind origin/main and has neither fix, so the
tooling in this worktree - and in the other stale worktrees running
alongside it - predated its own fix. scripts/clean-worktree.mjs was
investigated and cleared: it contains no filesystem deletion at all.

The remedy is to merge origin/main before any further build work, and the
documents now say so.

Also corrects two claims that went stale: the branch is no longer unpushed,
and the authorisation boundary now records that the push happened with the
user's explicit agreement after they were told the repository is public.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The merge landed with zero conflicts and both worktree-safety fixes
(a04330e, cdfcbac) are now ancestors of HEAD, so this checkout runs
the hardened guard-push. 121/121 tests and typecheck are green after it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Task 3 complete at 209/209 with one fix round and a clean scoped
re-review. Records the glossary-scope ruling that kept the spec's own
route copy, and the accepted removal of the duplicate live region.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
BigSimmo and others added 8 commits August 22, 2026 10:11
Two Critical findings that reached the user and that no gate could see: a
rebound selector list stripping the pinned safety boundary's link, and a
change table telling an approving senior nothing had changed on a first
plan. Records the ruling that wired the URL to the reducer, which three
tasks of refusals had been unreachable without.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Records the append-only ruling that corrected two fixtures against the
reducer, the accepted trade to refuse a correction whole rather than in
part, and the seventh guard-that-cannot-fail. Flags the new chain
invariant's unexercised half for the whole-branch review.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@supabase

supabase Bot commented Aug 22, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project sjrfecxgysukkwxsowpy because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@coderabbitai

coderabbitai Bot commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your current included review allowance is based on your included PR review attempts over the past 7 days.

Next review available in: 59 minutes

Limit details: You’ve used the included review currently available. Your 90 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

How can I continue?

Wait for the limit to reset, then comment @coderabbitai review or push new commits to the PR.

An organization admin can change what happens after included review limits in Billing.

How do review limits work?

CodeRabbit enforces per-developer PR review limits within each organization.

For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 5aa7b14e-bffb-4f29-8f36-3329b07646df

📥 Commits

Reviewing files that changed from the base of the PR and between 83a8ffb and b7c33d4.

📒 Files selected for processing (72)
  • .gitleaksignore
  • bundle-budget.json
  • docs/branch-review-records/ef78ebe56daf193a014a7dfbfef22f40583112c104084f3adbfcc4e9439bb1e5.record.md
  • docs/care-plan-context.md
  • docs/design-system/adoption-manifest.json
  • docs/site-map.md
  • docs/superpowers/plans/2026-08-20-care-plan-implementation.md
  • docs/superpowers/specs/2026-08-20-care-plan-design.md
  • src/app/globals.css
  • src/app/mockups/care-plan/governance/page.tsx
  • src/app/mockups/care-plan/layout.tsx
  • src/app/mockups/care-plan/loading.tsx
  • src/app/mockups/care-plan/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/history/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/management-plan/edit/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/management-plan/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/management-plan/print/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/management-plan/review/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/patient-plan/edit/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/patient-plan/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/patient-plan/print/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/presentations/[presentationId]/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/presentations/new/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/presentations/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/safety-plan/edit/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/safety-plan/page.tsx
  • src/app/mockups/care-plan/patients/[patientId]/safety-plan/print/page.tsx
  • src/app/mockups/care-plan/patients/page.tsx
  • src/app/mockups/care-plan/reviews/page.tsx
  • src/app/mockups/care-plan/route-page.tsx
  • src/app/mockups/care-plan/system-states/page.tsx
  • src/app/mockups/care-plan/team/page.tsx
  • src/app/mockups/mockups-layout-client.tsx
  • src/components/care-plan/mockups/care-plan-error-boundary.tsx
  • src/components/care-plan/mockups/care-plan-shell-frame.tsx
  • src/components/care-plan/mockups/care-plan.module.css
  • src/components/care-plan/mockups/clinical-snapshot-page.tsx
  • src/components/care-plan/mockups/contact-actions.tsx
  • src/components/care-plan/mockups/domain.ts
  • src/components/care-plan/mockups/fixtures.ts
  • src/components/care-plan/mockups/index.ts
  • src/components/care-plan/mockups/management-plan-diff.tsx
  • src/components/care-plan/mockups/management-plan-form.tsx
  • src/components/care-plan/mockups/management-plan-print.tsx
  • src/components/care-plan/mockups/management-plan-read.tsx
  • src/components/care-plan/mockups/management-plan-review.tsx
  • src/components/care-plan/mockups/patient-directory.tsx
  • src/components/care-plan/mockups/patient-navigation.tsx
  • src/components/care-plan/mockups/patient-workspace.tsx
  • src/components/care-plan/mockups/presentation-form.tsx
  • src/components/care-plan/mockups/presentation-pages.tsx
  • src/components/care-plan/mockups/presentation-timeline.tsx
  • src/components/care-plan/mockups/prototype-provider.tsx
  • src/components/care-plan/mockups/prototype-state.ts
  • src/components/care-plan/mockups/prototype-ui.tsx
  • src/components/care-plan/mockups/routable-suite.tsx
  • src/components/care-plan/mockups/routes.ts
  • src/components/care-plan/mockups/safety-plan-form.tsx
  • src/components/care-plan/mockups/safety-plan-pages.tsx
  • src/components/care-plan/mockups/types.ts
  • src/components/ui/print-output.tsx
  • src/lib/developer-area/headers.ts
  • src/lib/developer-area/hub-panels.ts
  • src/proxy.ts
  • tests/care-plan-domain.test.ts
  • tests/care-plan-linked-routes.dom.test.tsx
  • tests/care-plan-prototype-state.test.ts
  • tests/care-plan-route-files.test.ts
  • tests/developer-hub-panels.test.ts
  • tests/print-output-capabilities.dom.test.tsx
  • tests/proxy.test.ts

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

CI triage

CI failed on this PR. Automated classification of the 2 failed job(s):

  • Unit coverageneeds investigation: inspect the failing step and uploaded diagnostics; rerun only after classifying the cause.
  • PR requiredneeds investigation: inspect the failing step and uploaded diagnostics; rerun only after classifying the cause.

Compared with main CI run #13149 (failure).

Classification is evidence routing, not permission to ignore a failure. Exact quarantined Playwright identities remain governed by the flake ledger.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 87b28b3acc

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/components/care-plan/mockups/routable-suite.tsx Outdated
Comment thread src/components/care-plan/mockups/management-plan-print.tsx Outdated
@BigSimmo

Copy link
Copy Markdown
Owner Author

@codex resolve actionable Codex review findings for this pull request and current head using the repository instructions. This is the pull request's single automatic repair pass: do not perform a fresh review, create new standalone findings, or request another review. Work only the existing unresolved Codex threads on the current head. The only repository destination is BigSimmo/Database, and the only branch destination is the pull request head branch claude/ed-care-plans-impl-7f44cd at starting commit 79cfa97; never publish fixes to a detached or synthetic work branch and never create a stacked pull request. Use the authenticated GitHub connector to commit each approved fix to BigSimmo/Database:claude/ed-care-plans-impl-7f44cd, then verify that the pull request head contains the published commit before reporting success. Always fix P0 and P1 findings. For P2 and lower findings, fix only clear, scoped, low-risk issues; otherwise disposition them with a concise reason. For a fixed thread, reply with as the first line and as the second line. For a no-code disposition, use followed by . These result markers authorize the workflow to close that exact thread only after it verifies a fixed commit is the pull request head; a local-only commit is not a fix. If publication or verification fails, do not use either result marker, do not claim success, and leave the thread open with the blocker. If human input or new authorization is required, do the same. Finish only after every actionable thread is fixed or dispositioned and closed, or explicitly left open for a human decision. Do not update the branch from main, address unrelated reviews, broaden scope, or create more than one scoped fix commit. Do not use external APIs, paid services, credentials, dependency changes, or broad refactors unless explicitly authorized. Add targeted tests where behavior changes and run the narrowest relevant validation.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

Reviewed commit: 79cfa97b3e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@BigSimmo
BigSimmo enabled auto-merge (squash) August 22, 2026 08:06
@BigSimmo BigSimmo changed the title Claude/ed care plans impl 7f44cd Add staged Care Plan prototype through Personal Safety Plans Aug 22, 2026
@BigSimmo
BigSimmo merged commit 7f29952 into main Aug 22, 2026
25 of 26 checks passed
@BigSimmo
BigSimmo deleted the claude/ed-care-plans-impl-7f44cd branch August 22, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant