Embedded CodeProject.AI node operations
An open, education-first home for research, projects, teaching work, and the people who make them.
Publish with context. Learn in public. Keep discovery free.
Public pre-alpha · Privacy · Feedback
Attribution: Jean-Sebastien Beaulieu · ORCID 0009-0007-2904-0443 · SecuredMe · Scholarium
Gateway support acknowledgement. E2B audit support and Datadog observability are routed through the shared SecuredMe gateway when configured. This repository does not claim a direct E2B or Datadog runtime dependency by default, and no secret is stored in this README.
Maintainer intake during active finishing week. This repository is maintained directly on
mainby the SecuredMe maintainer. Public issues are open for bug reports, documentation corrections, security-safe observations, and reproducible feedback, but opening an issue does not promise a response or a delivery date. Pull requests are not accepted during the active code-finishing week; use issues only until this notice is replaced.
Important
Pre-alpha — active public development. Scholarium is being built in public, but it is not yet a production social network. The public preview is for product validation. PayPal checkout now fails closed unless dedicated live credentials and a live webhook ID are configured; provider review, public moderation operations, and youth-flow legal review remain gated.
Scholarium is a professional, free-first social platform for people who learn, teach, research, maintain open-source work, and build in public. It combines readable social discovery with the discipline of academic context:
- a research note can live next to its sources, files, version history, and license;
- a teacher can celebrate a student project without turning it into a popularity contest;
- a maintainer can show an open project without accepting code changes in the social feed;
- a beginner can use structure without being punished for not knowing formal writing conventions.
- No pay-to-rank. Subscription tier, contribution amount, and paid tools never change feed reach.
- Free core publishing. A person can share and discover work without buying visibility.
- Provenance, not legal overclaiming. Scholarium creates a timestamped publication receipt; it does not replace copyright registration, DOI, ISBN, or legal advice.
- Human review stays human. AI can structure, explain, and trace work. It does not become a proof authority, taxonomic authority, moderator of last resort, or scientific authority.
- Privacy by default. Local activity insights are off by default, stay in the browser when enabled, and exclude post text, files, contacts, location, and provider tokens.
| Surface | Current capability |
|---|---|
| Signal | Professional research/education feed, search, followed topics, transparent ranking controls, and chronological option. |
| Publishing | Research notes, white papers, project updates, short videos, and teaching artifacts with a processing status and provenance receipt contract. |
| Files | Typed upload contract, SHA-256 hashing, and R2 metadata shape for supported documents, data files, archives, and video. |
| QuaNthoR | A non-blocking formalization coach for articles, white papers, chapters, presentations, project briefs, videos, life-science protocols, and Mizar-proof handoff. |
| Profiles | Avatar/banner preview, themes, accent colour, badges, local-only insight preference, and consent-first tool connections. |
| Identity | ChatGPT WebAuth plus separate Google, GitHub, and PayPal entry routes. Each provider identity remains separate until an explicit future account-linking flow is reviewed. The twelve-tool Gateway adapter policy is shared, but deployed login acceptance remains application-specific. PayPal is sandbox-configured; Google and GitHub await their own provider credentials. |
| Verified contribution | Fixed-price verified contributor plan metadata, verification-gated preparation, server-side PayPal order creation, and server-side capture return path with no ranking effect. |
| Integrations | Consent preparation contracts for ORCID, GitHub, Zenodo, Google Drive, QuaNthoR, Synthia, SecuredMe Blog, Codex/OpenAI, Antigravity/Gemini, and life-science discovery. |
| Education toolchain | A learner-visible directory for Scholarium Teach, AlgoQuest, Algorithm Builder, FfeD-QLC, and the shared Gateway contract. |
Scholarium Teach now has a deterministic syllable-engine core, versioned language blocks, synthetic D1 proof, and explicit non-diagnostic audio, image, mastery, and provenance boundaries. Its execution ledger records 161 of 163 actions complete. The remaining gates are material: real-student pilots are prohibited until qualified Quebec and France/EU legal review is signed, and remote VS Code tunnel authentication is unavailable while local development remains usable. This is a strong pre-alpha mechanism, not a certified teaching method or an open child pilot.
The web application also exposes the current Education journey without collapsing responsibilities:
AlgoQuest mission -> Algorithm Builder artifact -> Colab execution evidence -> AlgoQuest progression
FfeD-QLC is the supervised geometric-cryptography path, with Vigil organizing evidence and a professor retaining the final decision. The Gateway audits the twelve shared WebAuth adapter contracts and rejects secret material; it is not a hosted identity provider and does not make every product login live by itself.
QuaNthoR is deliberately a coach, not a gatekeeper. It helps a person make the structure of their work clearer so formats remain understandable across the community. It never blocks publishing because a source, section, or title is still incomplete.
For formal mathematics, it can prepare a Mizar-oriented plan and hand the draft to QuaNthoR/Mizar. A guide is never represented as a verified proof until the separate formal verifier accepts it.
For life-science work, it can prepare a source-aware protocol outline. This is not clinical advice, ethics approval, biosafety approval, or a scientific conclusion.
Official AI-assisted school routes are Codex/OpenAI and Antigravity/Gemini only. Scholarium uses the provider's own browser/WebAuth session where available; it does not request or store a raw provider token in student or teacher flows.
Tool attachments are consent-first. A connection can be prepared in a profile, but it must be explicitly approved before a provider redirect or any external write occurs. GitHub collaboration remains on GitHub: Scholarium can show attribution and project context but is not a replacement code editor.
The optional Privacy monitor is intentionally device-local. Datadog is a platform reliability lane, not a per-user container and not a destination for personal content or behavioral profiles.
apps/web/
app/ React/Vinext interface and API routes
db/ Drizzle D1 schema and migrations
drizzle/ Generated migration history
lib/ Provenance, identity, policy, integration, and privacy contracts
tests/ Rendered-interface and safety-contract checks
worker/ Worker entry point
The app is a Vinext/React application designed for Cloudflare Workers. Logical D1 (DB) and R2 (MEDIA) bindings are declared in apps/web/.openai/hosting.json. Files and records are only durable when those bindings are provided by the deployment environment.
Prerequisite: Node.js 22.13 or later.
cd apps/web
npm install
npm run devThen open the local address printed by Vinext (normally http://localhost:3000).
cd apps/web
npm testThe suite builds the Worker-compatible application and checks the rendered product contract: anti-pay-to-rank, provenance, QuaNthoR's non-blocking role, local-only insights, WebAuth binding, and consent-first profile connections.
The canonical public resource API lives under /api/v1, with the schema published at /api/v1/openapi.json. Existing unversioned resource routes are compatibility aliases only during pre-alpha migration. See docs/API-VERSIONING.md.
To regenerate Drizzle SQL after a schema change:
npm run db:generateThis repository contains the public-safe Scholarium source. Credentials, cPanel details, deployment secrets, identity documents, biometric templates, private correspondence, and unpublished research stay outside this repository.
Community feedback is welcome through GitHub Issues, without any promised response or delivery date. The maintained school-tool route is still pre-alpha, and pull requests are not accepted during the active code-finishing week. Do not submit secrets, personal identity documents, private student data, or unsupported provider integrations.
- live PayPal provider review and launch credentials;
- payment-provider checkout for the fixed 0.99 USD/month verified-contributor contribution;
- Google and GitHub provider credentials, redirect registration, and launch validation;
- production moderation operation, appeals, and legal review for youth flows;
- resumable uploads, malware scanning, document extraction, video transcoding, and Live infrastructure;
- full external service execution for Drive, GitHub, email, calendar, contacts, DOI, and life-science sources.
These are intentional launch gates, not features silently represented as complete.
Official school governance. Scholarium follows the SecuredMe Education boundary: Codex/OpenAI and Antigravity/Gemini are the only official AI-assisted school routes. Do not add Ollama Cloud, uncensored local models, raw-token student flows, or unknown provider routes. See SCHOOL_TOOL_GOVERNANCE.md and AGENTS.md.
License. This project uses the Secured Educational License 2.0 (SEL-2.0). It is provided for education, research, simulation, classroom training, and supervised learning. See LICENSE, NOTICE, DISCLAIMER, and SAFETY.md.