Batch of red-team r3 fixes that were in the working tree before the
2026-09-28 design overhaul, committed as one unit with their tests.
- desktop main: STT timeouts and sidecar, voice recording store, sync
(credentials, audio, knowledge reindex, push gates), runtime
provisioner, update policy, AltGr keybindings, voice-command policy,
dictionary file codec/limits, meeting transcript condensing and a
local recording ledger so interrupted-session recovery only closes
meetings this device recorded (a phone's live meeting is left alone).
- mobile: login CSRF via implicit token callbacks rejected, account
deletion/retention, durable queue retention, knowledge realtime
without unfiltered DELETE, meeting re-record failure paths, cloud STT
client, preferences store/resync.
- core: text chunking splits long unbroken transcripts to fit, template
field policy, dictionary limits, meeting markdown inline handling.
- server: payple webhook policy and cancellation order scope, meeting
document generation quota, team RPC null-role guard, unified LLM
quota in-flight accounting, knowledge chunk vector index, meeting
re-record failure paths (migrations 20260929*).
- ci: portable/runtime feed gates, update-policy schema, Forgejo file
delete and alias planning.
Four older tests are updated to the new contracts rather than the old
behavior: token-pair auth callbacks are rejected, knowledge realtime no
longer subscribes to DELETE, long transcript lines are split, and
meeting recovery requires the local recording ledger for empty rows.
With a 100 ms trigger left in the installed config, generation started in the
gaps between keystrokes; the next key ended the session silently, and that
session still counted against the 5 s minimum interval, so the moment the
user actually paused nothing came (rate-limited). The log showed a
generate-then-vanish cycle every 5-6 s.
The trigger delay now has a 500 ms floor and settings revision 6 resets a
stored value below it to 600 ms. A session ended because the user kept typing
no longer blocks the next request by the minimum interval (per-minute and
daily caps still apply), and that dismissal is logged.
A candidate list was cleared about two seconds after it appeared: once typing
paused, the not-typing rule dismissed the visible overlay, so a click or
Ctrl+Alt+Enter found nothing to insert. The rule now only stops new
requests; a visible overlay stays until it is accepted, dismissed or goes
stale.
Terminals were excluded from suggestions because the whole screen buffer
reads as the input and the last line is usually a status bar. The input line
is now extracted (Claude Code/Codex >, starship, PowerShell, cmd and POSIX
prompts, wrapped continuation lines) and used as the prefix; no prompt means
no suggestion. Terminals stay out of phrase learning. Accepting with nothing
shown and successful inserts are now logged.
Desktop transcript edits, auto-polish and speaker labels now reach the phone,
which draws meetings from transcript segments, and prompt edits of the four
shared preset commands are used by the phone's commands.
Bumps the product version to 1.9.0 (Android/iOS build 1090000).
The phone draws a meeting from its transcript segments before the edited
transcript, so desktop edits, auto-polish and diarization never showed there.
Every desktop transcript change now rebuilds the meeting's segments from its
[MM:SS] [speaker] lines and trims the rest; the line parser moves to
@d3ro/core/meeting-transcript and the meeting view uses it too.
Prompt edits of the four desktop presets that exist on the phone update the
server preset row (a reset restores its default; {{targetLanguage}} is sent
as English, the only target on both sides), and edits made on another desktop
come back. The free-prompt preset has no phone counterpart and stays local.
Knowledge documents move between desktop, phone and web as source text and
are indexed on each device; desktop recordings upload to the shared storage
and any recording plays from the history card; language, theme, auto-polish
and the active command follow the phone. Document text survives a missing
embedding model so it can be indexed later.
Bumps the product version to 1.8.0 (Android/iOS build 1080000).