You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: DEMO-SCRIPT.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -33,7 +33,7 @@ The rules require a 1–3 minute public video, explicit explanation of the YouCa
33
33
34
34
### 0:38–0:59 — private intake and quality gate
35
35
36
-
**Picture:**sign in; start a Cut Card; select the synthetic customer and garment images; show consent and rights confirmations. Briefly select the poor body fixture and show the local rejection, then restore the clean fixture.
36
+
**Picture:**from `/create`, choose **Create with my photos**; the isolated guest workspace opens without login. Select the synthetic customer and garment images; show consent and rights confirmations. Briefly select the poor body fixture and show the local rejection, then restore the clean fixture.
Copy file name to clipboardExpand all lines: JUDGING.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,25 +1,25 @@
1
1
# PatternProof judge guide
2
2
3
-
Replace only the bracketed deployment fields after the final hosted acceptance run.
3
+
Production judge path for the public PatternProof deployment. No account or credentials are required.
4
4
5
5
## 45-second guided path
6
6
7
-
1. Open `[FINAL_HTTPS_ORIGIN]/create`.
7
+
1. Open [https://patternproof-nu.vercel.app/create](https://patternproof-nu.vercel.app/create).
8
8
2. Use **Next** to see the recorded YouCam result and byte-identical repeat evidence.
9
9
3. Confirm that a human **Not feasible** decision changes Cut Readiness to blocked.
10
10
4. Continue to see a customer veto become a traceable V1 → V2 revision rather than an editable approval.
11
-
5. Watch three independent keys—YouCam evidence, tailor judgment, and customer consent—bind to one Expectation Checksum and change **DO NOT CUT** to **CUT RELEASED**.
11
+
5. Watch three independent keys—YouCam evidence, tailor judgment, and customer consent—bind to one Expectation Checksum and change **DO NOT CUT** to **CUT RELEASED**.
12
12
6. End on the privacy-exit state, then open the immutable public record.
13
13
14
-
Choose **Use sample photos** for the rights-cleared, no-write journey. Move through preview, human veto, revision replay, consent, and privacy exit. Choose **Use my photos**only for the authenticated, consent-bound live intake. `/s/demo-olive` is the byte-pinned, read-only frozen record.
14
+
The sample opens immediately and never writes a customer record. Choose **Create with my photos**to open an isolated, consent-bound guest workspace without an email or password. `/s/demo-olive` is the byte-pinned, read-only frozen record.
15
15
16
16
The zero-login examples use byte-pinned synthetic assets and cannot write customer or database records. They demonstrate product logic and recorded provider evidence, not a new live YouCam call.
17
17
18
18
## Full hosted path
19
19
20
-
Use the invited account described in the private Devpost testing field: `[ADD INVITED TEST EMAIL OR MAGIC-LINK PROCEDURE]`.
20
+
No invited account is required.
21
21
22
-
1.Sign in and create a brief with the provided rights-cleared fixtures.
22
+
1.Open `/create`, choose **Create with my photos**, and create a brief with the provided rights-cleared fixtures.
23
23
2. Confirm the poor-body fixture is rejected before a billable request.
24
24
3. Create a valid brief and generate the YouCam Clothes Virtual Try-On V3 preview.
25
25
4. Complete the human feasibility gate and create the 14-day customer link.
Copy file name to clipboardExpand all lines: README.md
+23-21Lines changed: 23 additions & 21 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,15 +6,15 @@ The central product promise is narrow: the shop and customer approve the same fr
6
6
7
7
## Release status
8
8
9
-
The repository contains the complete private intake, normalization, rendering, feasibility, frozen review, approval, and audited body-photo-erasure paths. The production deployment is [patternproof-nu.vercel.app](https://patternproof-nu.vercel.app). Real-customer onboarding remains blocked until every item in [Live release acceptance](#live-release-acceptance) is recorded against the real Supabase, YouCam, and Vercel environments.
9
+
The repository contains the complete private intake, normalization, rendering, feasibility, frozen review, approval, and audited body-photo-erasure paths. The production deployment is [patternproof-nu.vercel.app](https://patternproof-nu.vercel.app). The final hosted acceptance evidence is recorded in [RELEASE-ACCEPTANCE.md](RELEASE-ACCEPTANCE.md).
10
10
11
-
Current evidence: YouCam T0 and T2 passed; T3 passed 3/3; the application-side T4 quality gate rejects the poor live input before provider spend; authenticated T5 evidence confirms two units per successful Clothes VTO V3 result; live Supabase signed-URL T6 passed; the controlled repeated-input T7 check passed; the release credential was rotated; and Vercel health, unified sample/private boundaries, private-workspace redirect, cache policy, and exact demo-token isolation passed over HTTPS on August 13, 2026. Hosted authentication and a fresh production write-path run remain release gates. Do not invite real customers until every remaining gate passes.
11
+
Current evidence: YouCam T0 and T2 passed; T3 passed 3/3; the application-side T4 quality gate rejects poor live input before provider spend; T5 confirms two units per successful Clothes VTO V3 result; live signed-URL T6 passed; controlled repeated-input T7 produced byte-identical output; the exposed credential was rotated; and the zero-account production journey passed from consent-bound intake through private V3 generation, human feasibility, frozen customer review, approval, immutable owner readback, and explicit draft cleanup on August 14, 2026. This is production acceptance evidence, not a claim of measured customer outcomes; prospective impact validation remains governed by [VALIDATION-PROTOCOL.md](VALIDATION-PROTOCOL.md).
12
12
13
-
Formative problem evidence is documented in [RESEARCH.md](RESEARCH.md): 108 manually screened 1.0–2.0 public tailoring complaints across 41 de-identified businesses and three city samples. It is a purposive negative-review study—not a prevalence estimate, user validation, or proof of product impact—and it explicitly reports the failure categories PatternProof does not solve.
13
+
Formative problem evidence is documented in [RESEARCH.md](RESEARCH.md): 108 manually screened 1.0–2.0 public tailoring complaints across 41 de-identified businesses and three city samples. It is a purposive negative-review study—not a prevalence estimate, user validation, or proof of product impact—and it explicitly reports the failure categories PatternProof does not solve.
14
14
15
15
## Product flow
16
16
17
-
1. A tailor signs in by Supabase magic link.
17
+
1. A visitor opens an isolated Supabase anonymous session with one click. No email or password is required; an optional magic link can still identify a returning pilot owner.
18
18
2. The browser receives single-purpose private upload grants. The server validates each JPG/PNG, limits pixels and bytes, rotates orientation, converts to sRGB JPEG, strips embedded metadata, and records SHA-256 digests.
19
19
3. A server-only YouCam request uses short-lived signed input URLs. The returned image is allowlisted, downloaded, validated, normalized, and stored in the private bucket.
20
20
4. The tailor records each non-negotiable and an explicit feasibility decision. `not_feasible` blocks customer review; an adjustment requires a customer-visible note.
@@ -26,7 +26,7 @@ Formative problem evidence is documented in [RESEARCH.md](RESEARCH.md): 108 manu
26
26
## Architecture and trust boundaries
27
27
28
28
- Next.js 15 App Router and React 19 provide the application and server routes.
29
-
- Supabase provides magic-link authentication, PostgreSQL, row-level security, RPC transactions, and the private `brief-images` bucket.
29
+
- Supabase provides isolated anonymous sessions, optional magic-link authentication, PostgreSQL, row-level security, RPC transactions, and the private `brief-images` bucket.
30
30
- Perfect Corp YouCam Clothes VTO creates the visual-intent preview.
31
31
- Vercel hosts the reference deployment and invokes one authenticated daily maintenance job.
32
32
- Browsers are untrusted. They never receive the YouCam key or Supabase service-role key.
@@ -46,7 +46,7 @@ npm run dev
46
46
47
47
Visit `http://localhost:3000`. Because the parent workspace path contains `&`, use the npm scripts or direct Node command rather than wrapping the path in an unquoted shell string.
48
48
49
-
The unified Cut Card entry is at `/create`: visitors can explore a rights-cleared, no-write sample or continue to consent-bound private intake. The deterministic immutable record is at `/s/demo-olive`. Legacy `/judge` and `/demo` links redirect into the sample workspace. Live intake requires Supabase configuration.
49
+
The unified Cut Card entry is at `/create`: visitors immediately explore a rights-cleared, no-write sample, then can create a separate private Cut Card with their own consent-bound photos in an isolated guest workspace. The deterministic immutable record is at `/s/demo-olive`. Legacy `/judge` and `/demo` links redirect into the sample workspace. Live intake requires Supabase configuration, including anonymous sign-ins.
50
50
51
51
Judges can follow the bounded zero-login and hosted paths in [JUDGING.md](JUDGING.md). The pre-results usability and prospective-order protocol is in [VALIDATION-PROTOCOL.md](VALIDATION-PROTOCOL.md); `npm run pilot:report -- <de-identified-pilot.json>` validates and summarizes pilot records without accepting personal-data fields.
52
52
@@ -107,23 +107,25 @@ Use a new, empty Supabase project for the pilot. Apply each file once in the SQL
107
107
| 017 |`supabase/migrations/20260812002100_body_photo_erasure_claim_fix.sql`| Forward fix for the unambiguous, retryable body-photo erasure claim. |
108
108
| 018 |`supabase/migrations/20260812002200_spatial_agreement_notes.sql`| Tenant-scoped spatial notes that freeze into customer approval. |
| 020 |`supabase/migrations/20260813000100_customer_change_requests.sql`| Snapshot-bound customer veto, approval race guard, and traceable revision replay; final health sentinel. Run last. |
110
+
| 020 |`supabase/migrations/20260813000100_customer_change_requests.sql`| Snapshot-bound customer veto, approval race guard, and traceable revision replay; health sentinel 20. |
111
+
| 021 |`supabase/migrations/20260813000200_guest_render_ceiling.sql`| Zero-login isolated workspaces, exact retry idempotency, and a two-attempt lifetime YouCam ceiling for anonymous users. |
112
+
| 022 |`supabase/migrations/20260814000100_draft_discard_consent_cascade.sql`| Forward fix for safe consent cascade and deterministic cleanup-manifest return during incomplete-draft discard. |
111
113
112
114
After applying SQL:
113
115
114
116
1. Confirm `brief-images` is private, limited to 10 MB, and accepts only `image/jpeg` and `image/png`. Do not switch it public.
115
117
2. In Supabase Auth URL Configuration, set Site URL to `APP_URL` and add `APP_URL/auth/callback` to the redirect allowlist.
116
-
3. Enable email magic links, restrict pilot onboarding, and configure provider email/rate limits before invitations.
118
+
3. Enable anonymous sign-ins for zero-login judging. Keep Supabase Auth attack protection, deployment monitoring, and provider abuse controls enabled; anonymous users are additionally fenced to two lifetime YouCam attempts in PostgreSQL. Add CAPTCHA only when the client supplies and verifies the provider token end to end. Configure email magic links only if returning pilot owners need durable cross-device access.
117
119
4. Run the two-user isolation and service-function tests listed in [supabase/README.md](supabase/README.md). Never treat the service-role key as an RLS test client.
118
-
5. Verify this query returns migration `18` before deployment:
120
+
5. Verify this query returns migration `22` before deployment:
119
121
120
122
```sql
121
123
select migration, installed_at
122
124
frompublic.patternproof_release
123
125
where singleton = true;
124
126
```
125
127
126
-
Do not reorder, partially rerun, or apply these files to an unknown legacy schema. Database rollback is not automatic; restore from a tested backup or apply a reviewed forward migration. On an upgrade with live render traffic, pause render admissions and workers until migration 015 commits so no transaction can resume the retired one-unit function body; a fresh empty deployment is unaffected. Apply 016 through 020 as complete transactions before deploying code that expects sentinel 20, and keep traffic disabled until the post-migration Auth/RLS/Storage checks pass.
128
+
Do not reorder, partially rerun, or apply these files to an unknown legacy schema. Database rollback is not automatic; restore from a tested backup or apply a reviewed forward migration. On an upgrade with live render traffic, pause render admissions and workers until migration 015 commits so no transaction can resume the retired one-unit function body; a fresh empty deployment is unaffected. Apply 016 through 022 as complete transactions before deploying code that expects sentinel 22, and keep traffic disabled until the post-migration Auth/RLS/Storage checks pass.
127
129
128
130
## YouCam release configuration
129
131
@@ -140,7 +142,7 @@ Do not reorder, partially rerun, or apply these files to an unknown legacy schem
140
142
3. Set `APP_URL` to the final custom HTTPS origin, update the Supabase Site URL/redirect allowlist, and redeploy.
141
143
4. Deploy [vercel.json](vercel.json). It schedules `GET /api/maintenance/intake-cleanup` at `0 3 * * *` (once daily at approximately 03:00 UTC). This is compatible with Vercel Hobby's daily cron restriction.
142
144
5. Vercel automatically sends `CRON_SECRET` as the bearer authorization header. Confirm the cron appears under Project Settings > Cron Jobs and inspect its first invocation log.
143
-
6. Request `GET /api/health`. A ready release returns HTTP 200 with `{"status":"ok"}`. Missing configuration, the private bucket, or migration 020 returns HTTP 503.
145
+
6. Request `GET /api/health`. A ready release returns HTTP 200 with `{"status":"ok"}`. Missing configuration, the private bucket, or migration 022 returns HTTP 503.
144
146
145
147
Official references: [Vercel cron security and Hobby scheduling](https://vercel.com/docs/cron-jobs/manage-cron-jobs) and [Supabase private bucket behavior](https://supabase.com/docs/guides/storage/buckets/fundamentals).
146
148
@@ -233,13 +235,13 @@ The user-facing notice is at `/privacy` and is linked from every page. It descri
233
235
234
236
## Repository map
235
237
236
-
-`app/`— pages, components, server routes, health, and maintenance
0 commit comments