Skip to content

feat(privacy): Quiet Signal production page with elevated processing map - #1833

Merged
BigSimmo merged 10 commits into
mainfrom
cursor/privacy-quiet-signal-adopt-bc81
Aug 12, 2026
Merged

feat(privacy): Quiet Signal production page with elevated processing map#1833
BigSimmo merged 10 commits into
mainfrom
cursor/privacy-quiet-signal-adopt-bc81

Conversation

@BigSimmo

@BigSimmo BigSimmo commented Aug 12, 2026

Copy link
Copy Markdown
Owner

Summary

  • Adopt Quiet Signal on production /privacy: sticky header + Important + processing instrument, accordion with gists, desktop Signal Index — no Live Signal phone jump chips (01 Tool / 02 Collected…).
  • Elevate the processing map to the mockup instrument strip: always three equal tone-washed cells with MapPin marks, fused under Important so Sydney / Singapore / External stay visible; never rounded-full circle/pill jump chips that clipped External.
  • Phone polish: denser accordion, Expand all control, compact sticky instrument; drop sticky when chrome exceeds the viewport (large text).
  • Design-system token alignment (tracking-kicker / tracking-display / tracking-eyebrow, min-h-tap, --e1, named Live status) and standalone shell safe-area contract.

Verification

  • ./node_modules/.bin/vitest run tests/privacy-ui.test.ts tests/search-page-shell-standalone.contract.test.ts — 7 passed
  • Browser device proof at 320 / 390 / 768 / 1440: three map cells visible, External unclipped, no jump chips, sticky map under Important
  • Verification not run: npm run verify:pr-local — Cloud VM lock drift (next installed vs locked) blocked the broad gate; focused tests above cover the changed surface
  • UI verification not run: full verify:ui not proportionate; focused Chromium screenshots taken via computer-use agent
  • Production-readiness / live provider gates not run (presentation-only privacy UI; no provider calls)

Risk and rollout

  • Risk: Privacy presentation chrome only — governance copy remains pinned by tests/privacy-ui.test.ts. Sticky chrome is taller with the fused map; oversized banners drop sticky so accordion hits stay reachable.
  • Rollback: Revert this PR / restore prior /privacy surface.
  • Provider or production effects: None

Clinical Governance Preflight

  • Source-backed claims still require linked source verification before clinical use
  • No patient-identifiable document workflow was introduced or expanded without explicit governance approval
  • Supabase target remains Clinical KB Database (sjrfecxgysukkwxsowpy)
  • Service-role keys and private document access remain server-only
  • Demo/synthetic content remains clearly separated from real clinical sources
  • Source metadata, review status, and outdated/unknown-source behavior remain conservative
  • Deployment classification/TGA SaMD impact was checked when clinical decision-support behavior changed

Notes

  • Presentation-only change to the privacy disclosure UI. Pinned governance wording in src/lib/privacy-page-content.tsx is unchanged.
Open in Web Open in Cursor 

Replace the card-stack privacy page with the Quiet Signal design:
sticky amber Important (Full/Less), processing map, accordion with
gists, and a desktop Signal Index — without phone number chips.
Keep governance copy pinned and shared for privacy-ui tests.
@supabase

supabase Bot commented Aug 12, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project sjrfecxgysukkwxsowpy because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You’ve reached a temporary PR review limit under our Fair Usage Limits Policy.

Your recent review volume is higher than typical usage, so adaptive limits are currently applied.

Next review available in: 29 minutes

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 292c1900-73d7-4e44-8f41-a1fc545e90a0

📥 Commits

Reviewing files that changed from the base of the PR and between 975c058 and 8ff4241.

📒 Files selected for processing (6)
  • docs/codebase-index.md
  • src/app/privacy/page.tsx
  • src/components/privacy-quiet-signal-page.tsx
  • src/lib/privacy-page-content.tsx
  • tests/privacy-ui.test.ts
  • tests/search-page-shell-standalone.contract.test.ts

Comment @coderabbitai help to get the list of available commands.

Drop the redundant shield beside ClinicalBadge, use a compact Full/Less
face with a tap-sized hit area, and warm the expanded Important panel so
it stays fused to the amber signal.
@github-actions

github-actions Bot commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

CI triage

CI failed on this PR. Automated classification of the 3 failed job(s):

  • Static PR checksneeds investigation: inspect the failing step and uploaded diagnostics; rerun only after classifying the cause.
  • Unit coverageneeds investigation: inspect the failing step and uploaded diagnostics; rerun only after classifying the cause.
  • PR requiredneeds investigation: inspect the failing step and uploaded diagnostics; rerun only after classifying the cause.

Compared with main CI run #9819 (cancelled).

Classification is evidence routing, not permission to ignore a failure. Exact quarantined Playwright identities remain governed by the flake ledger.

@BigSimmo
BigSimmo marked this pull request as ready for review August 12, 2026 05:59
Comment thread src/app/privacy/page.tsx
Comment thread src/components/privacy-quiet-signal-page.tsx Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 33bef1cb9b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/components/privacy-quiet-signal-page.tsx Outdated
@BigSimmo

Copy link
Copy Markdown
Owner Author

@codex resolve actionable Codex review findings for this pull request and current head using the repository instructions. This is the pull request's single automatic repair pass: do not perform a fresh review, create new standalone findings, or request another review. Work only the existing unresolved Codex threads on the current head. The only repository destination is BigSimmo/Database, and the only branch destination is the pull request head branch cursor/privacy-quiet-signal-adopt-bc81 at starting commit 33bef1c; never publish fixes to a detached or synthetic work branch and never create a stacked pull request. Use the authenticated GitHub connector to commit each approved fix to BigSimmo/Database:cursor/privacy-quiet-signal-adopt-bc81, then verify that the pull request head contains the published commit before reporting success. Always fix P0 and P1 findings. For P2 and lower findings, fix only clear, scoped, low-risk issues; otherwise disposition them with a concise reason. For a fixed thread, reply with as the first line and as the second line. For a no-code disposition, use followed by . These result markers authorize the workflow to close that exact thread only after it verifies a fixed commit is the pull request head; a local-only commit is not a fix. If publication or verification fails, do not use either result marker, do not claim success, and leave the thread open with the blocker. If human input or new authorization is required, do the same. Finish only after every actionable thread is fixed or dispositioned and closed, or explicitly left open for a human decision. Do not update the branch from main, address unrelated reviews, broaden scope, or create more than one scoped fix commit. Do not use external APIs, paid services, credentials, dependency changes, or broad refactors unless explicitly authorized. Add targeted tests where behavior changes and run the narrowest relevant validation.

@chatgpt-codex-connector

Copy link
Copy Markdown

Summary

  • Updated the privacy-page chrome to measure its rendered height and only remain sticky when at least one 44px tap target of page content remains accessible. The measurement is refreshed when the Important notice or viewport size changes. src/components/privacy-quiet-signal-page.tsxL193-L217
  • Made sticky positioning conditional, preventing enlarged text from turning the header and Important panel into a viewport-sized overlay over the privacy accordion. src/components/privacy-quiet-signal-page.tsxL253-L259
  • Added a focused Chromium regression test using a 320×568 viewport and 200% root text size; it scrolls to, activates, and verifies the “Your responsibilities” accordion. tests/ui-smoke.spec.tsL2203-L2214
  • Created the single scoped local commit 1dcb39db9b8069158cfbd2cb4e10527d54960584 (fix(privacy): release oversized sticky chrome).
  • Publication is blocked: the authenticated GitHub connector and required make_pr tool are unavailable in this environment, while HTTPS Git authentication is not configured. The remote PR branch therefore remains at 33bef1cb9be2891f2bee3ffa5e5e7d8a42336135. I have not posted resolution markers or claimed the review thread is fixed, because the repair is local-only.

Testing

  • npm run workflow:design-sweep -- --write-evidence
  • npm run ensure — verified the Database application at the coordinator-selected http://localhost:3131.
  • npm run format
  • npm run test:e2e -- tests/ui-smoke.spec.ts --project=chromium --grep "privacy sections remain operable"
  • node --input-type=module <<'EOF' … EOF — live Chromium verification reported {"expanded":"true","scrollY":4018,"position":"static"} at 320×568 with 200% text.
  • npm run test -- --run tests/privacy-ui.test.ts
  • git diff --check
  • git commit -m "fix(privacy): release oversized sticky chrome"
  • ⚠️ git push origin HEAD:refs/heads/cursor/privacy-quiet-signal-adopt-bc81 — blocked because the environment has no authenticated GitHub credentials (could not read Username for 'https://github.com').
  • ⚠️ git ls-remote origin refs/heads/cursor/privacy-quiet-signal-adopt-bc81 — confirmed the remote PR head is still the original 33bef1cb9be2891f2bee3ffa5e5e7d8a42336135, not the local fix commit.

View task →

cursoragent and others added 2 commits August 12, 2026 06:35
Rebuild /privacy to match Quiet-scroll DNA: brand mark header with
signal badge and Draft on the right, full-bleed Important row with
spine/shield/uppercase label, denser accordion, 80rem measure, desktop
Signal Index, and compact processing-map pills on phone — still no
phone number chips.
@BigSimmo
BigSimmo enabled auto-merge August 12, 2026 06:36
cursoragent and others added 4 commits August 12, 2026 06:49
Replace the dual-mount pill strip (which clipped External on phone) with
one stacked/3-col instrument card, drop the duplicate aria region, and
stop the Quiet badge and page title from truncating on 320px.
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Align the production Quiet Signal page with design-system tokens (text
roles, tracking scale, elevation, tap sizes), drop sticky chrome when it
exceeds the viewport so accordion hits remain reachable at large text,
and update the standalone shell contract for the owned safe-area pad.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
@BigSimmo

Copy link
Copy Markdown
Owner Author

Babysit update (68175781)

Synced origin/main (post-#1832) and cleared required blockers:

Blocker Fix
Static / design-system (text-soft, legacy tap h-11, tracking literals, shadow-tight, colour-only LiveDot, raw padding) Quiet Signal page now uses design tokens / elevation / min-h-tap
Unit / search-page-shell-standalone.contract Contract updated for Quiet Signal’s owned safe-area pad
Codex P1: sticky chrome covers accordion at 200% text Drop sticky when chrome height ≥ viewport
Sentry: useLayoutEffect under renderToStaticMarkup Switched to useEffect

Review threads replied + resolved. Local proof: check:design-system-contract pass; privacy + shell contract tests 7/7. Leaving merge/auto-merge to you.

Replace in-flow stacked rows with the Quiet Signal instrument strip —
tone-washed three-column cells, MapPin marks, fused under Important —
so regions stay visible without Live Signal circle jump chips. Phone
gets Expand all and denser accordion rhythm.
@cursor cursor Bot changed the title feat(privacy): Quiet Signal layout for /privacy feat(privacy): Quiet Signal production page with elevated processing map Aug 12, 2026
@BigSimmo
BigSimmo merged commit bc00419 into main Aug 12, 2026
28 of 29 checks passed
@BigSimmo
BigSimmo deleted the cursor/privacy-quiet-signal-adopt-bc81 branch August 12, 2026 08:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants