Mirror to GitHub / mirror (push) Canceled after 0s
- session store + requireSession middleware (signup persists session) - PairingService (8-char code, 5-min TTL, 5-attempt lockout, single-use, https check) - POST /sites/pair, /sites/redeem, /sites/:id/confirm, GET /sites/:id - PluginClient signs HMAC (timestamp+method+path+body-hash), token in Authorization - ADR 0016; 58 api tests green
Architecture Decision Records
Wursor records significant technical and product decisions as ADRs. This directory is the source of truth; PRD §14 holds the product-level "locked decisions", while these records capture the engineering choices and tradeoffs behind them.
Each ADR is a single file following the Nygard format: Status, Context, Decision, Consequences. "Options considered" and "Rejected" are kept explicit to honor the wursor-decision-log skill.
Status legend
- Accepted — agreed; in force.
- Proposed — under discussion, not yet binding.
- Superseded — replaced by a later ADR; see the link.
Index
| ADR | Title | Status |
|---|---|---|
| 0001 | MVP is the content-change loop, not the full P0 feature list | Accepted |
| 0002 | Phase 0 spikes gate the scaffold | Accepted |
| 0003 | Wursor generates the pairing code, not the plugin | Accepted |
| 0004 | Plugin install is a 40-slug allowlist, fail-closed | Accepted |
| 0005 | Golden harness scores slot-fill tool calls against JSON fixtures | Accepted |
| 0006 | Builder detection uses slugs + post meta with a priority order | Accepted |
| 0007 | Sandboxes proxy uploads; never copy the media library | Accepted |
| 0008 | Workspace ships empty packages, not placeholder source | Accepted |
| 0009 | Repository renamed originmain → wursor | Accepted |
| 0010 | Golden harness scores live runs through a provider-agnostic LLM client (OpenRouter first) | Accepted |
| 0011 | Fastify is the API server; React + Vite is the web shell | Accepted |
| 0012 | In-memory user store behind a UserStore interface; Postgres deferred | Accepted |
| 0013 | Sandbox orchestration mocks the Docker boundary; real daemon client deferred | Accepted |
| 0014 | Postgres user store via a Queryable boundary; schema in SQL migrations | Accepted |
| 0015 | Docker daemon client via dockerode behind an injected engine; sandbox gated by env | Accepted |
| 0016 | Pairing-code TTL/lockout lives on the Wursor API; the plugin enforces token/HMAC/scope | Accepted |
How to add one
- Copy the previous number + 1.
- Write Status / Context / Decision (with options + rejected) / Consequences.
- Add a row to this index.