From a074b06e6cf4ca18616c1f4db66fc20558686b32 Mon Sep 17 00:00:00 2001 From: "quality-runtime[bot]" <330432719+quality-runtime[bot]@users.noreply.github.com> Date: Sat, 19 Sep 2026 19:21:18 +0200 Subject: [PATCH 1/3] docs: record that bot commits carry no sign-off A DCO sign-off is a personal certification the project bot cannot make, so commits authored as quality-runtime[bot] omit it; pull requests the bot opens are already exempt from the dco check. --- AGENTS.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/AGENTS.md b/AGENTS.md index 2f77d0c..82efce5 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -41,7 +41,7 @@ Apps go in `apps/`, shared code in `packages/` — extract a package only when t - Add or update tests for important behavior. - Never weaken tenant isolation, authorization, auditability, or data integrity for convenience. - Never modify an existing applied database migration; add a new one. -- Sign off commits with `git commit -s` (Developer Certificate of Origin); pull requests opened by `quality-runtime[bot]` are exempt. +- Sign off commits with `git commit -s` (Developer Certificate of Origin). Commits authored as `quality-runtime[bot]` are not signed off — a bot cannot make the certification — and pull requests it opens are exempt from the check. ## Licensing From 69fa4c1261692760c757d69eeb1156ba9c00e856 Mon Sep 17 00:00:00 2001 From: "quality-runtime[bot]" <330432719+quality-runtime[bot]@users.noreply.github.com> Date: Sat, 19 Sep 2026 19:40:37 +0200 Subject: [PATCH 2/3] chore: load local agent instructions and keep them out of git CLAUDE.md imports CLAUDE.local.md for per-developer notes, and .gitignore keeps that file from being committed to this public repository. --- .gitignore | 1 + CLAUDE.md | 1 + 2 files changed, 2 insertions(+) diff --git a/.gitignore b/.gitignore index 3ce9c40..a78c22c 100644 --- a/.gitignore +++ b/.gitignore @@ -3,4 +3,5 @@ node_modules/ .env .env.local .env.*.local +CLAUDE.local.md .DS_Store diff --git a/CLAUDE.md b/CLAUDE.md index 43c994c..c8c3431 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -1 +1,2 @@ @AGENTS.md +@CLAUDE.local.md From 3f80a3bcfc0499f39333c930032cf755661078cc Mon Sep 17 00:00:00 2001 From: "quality-runtime[bot]" <330432719+quality-runtime[bot]@users.noreply.github.com> Date: Sat, 19 Sep 2026 19:46:52 +0200 Subject: [PATCH 3/3] docs: keep public pages on a separate, session-free origin Hostnames stay deployment configuration. Public pages, when they exist, are answered only on their own origin so nothing there can use a session, and render structured records rather than tenant-supplied markup; anything that needs a sign-in, an auditor's access included, stays on the application's origin. --- ARCHITECTURE.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/ARCHITECTURE.md b/ARCHITECTURE.md index 7d5a88b..d24a362 100644 --- a/ARCHITECTURE.md +++ b/ARCHITECTURE.md @@ -198,6 +198,12 @@ Additional services must not become mandatory without strong operational justifi Cloud-provider-specific implementations live in deployment adapters, and the application must remain portable to other environments. +Hostnames are configuration. The runtime assumes no hosted service's domains; custom domains and their certificates belong to the deployment in front of it. + +Public pages, when they exist, are server-rendered routes in `apps/server` answered only on a separate public origin the deployment configures, so nothing served there can use a session: they need no sign-in, set no session cookies, and render structured records, never tenant-supplied HTML or scripts. Printed addresses use immutable identifiers, so they survive a record's rename. + +Anything that needs a sign-in, including an outside reviewer's read access, stays on the application's origin; a public page may link to it. + ## Hosted product boundary The public runtime contains functionality generally useful to anyone operating Quality Runtime themselves. Hosted-service concerns (billing, subscriptions, provisioning, usage metering, entitlements, internal cloud operations) stay outside it.