Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 3 additions & 5 deletions TODO.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,16 +20,14 @@ Getting **testnet to a two-person shared lab** is also a standing plan, not a pi

----

- **(Tell)** Wire the donor-set waiting period into the product UI. The rules are in [waiting-period.md](specs/tech/subsystems/delegation/waiting-period.md), and the note contracts, same-chain split fold, and one-page-per-schedule notifier rule are in place. Still open: note and project screens that show a pending spend's amount and deadline as money that can still be cancelled (not as raised), donor controls for the delay, strict mode, and flaggers, and a host loop that actually sends the opted-in email or push. Public remarks from people who are not flaggers stay a later UI feature and are not stored on-chain.
- **(Tell)** Send the donor-set waiting-period page. Note and project screens show a pending spend's amount and deadline as money that can still be cancelled, and the note screen has the delay, unsuspicious delay, strict mode, and flaggers. `shouldPageDonor` still only decides once per `(noteId, nonce)`. There is no opt-in store and no email or push sender. Public remarks from people who are not flaggers stay a later UI feature and are not stored on-chain. Rules: [waiting-period.md](specs/tech/subsystems/delegation/waiting-period.md).

- **(Ask)** Expose recurring pledge fine-list and unsuspicious-delay editing in the SDK and UI. The contract supports `setPledgeFineListed` and `setPledgeUnsuspiciousDelay`, but the product controls currently edit individual notes only. Make clear that pledge edits affect future notes and do not update already-minted notes. Rules: [spend-classification.md](specs/tech/subsystems/delegation/spend-classification.md).

- One voice for delegation copy. The donor is authorizing an address to spend a stated amount on projects in Commonality. The delegate promises nothing. A stated intent is public and does not bind the spend. Unspent funds stay revocable by the donor. Commonality does not hold the funds, choose the delegate, or supervise the spending. Remove the steward voice: entrusting money to a scout, program-officer framing, "money under management," and any Commonality ranking whose job is to send people to a delegate. A public history of what an address already funded can stay. "Scout" as the early contributor who may later be reimbursed at cost can stay; do not let that word mean a manager of other people's money. Start with `specs/product/legal/retroactive-funding-redesign.md` (Design 2) and `docs/end-user/lazyGiving/` (`retroactive-funding.md`, `index.md`, `fund-something.md`, `get-your-project-funded.md`). No delegate marketplace.

- Reliable revocation of delegated authority over returned funds. Revocation covers the unspent balance, pending spends, and outstanding receipt claims, so a later refund cannot revive authority the donor removed. Failed-project refunds stay inside the same authorization ("keep trying until I revoke") and remain subject to its current rules and revocation state. Successful-project reimbursement recycling is still an open choice; do not settle it in this item. Write the proposal against `specs/tech/subsystems/delegation/` and [delegation-narrowing.md](specs/product/legal/delegation-narrowing.md) before changing contracts.

- Beneficiary identity on delegated spends. Show and check the actual payout route (a direct recipient fixed at creation, versus beneficiary escrow), not project metadata or the registry's current wallet, and handle wallet rotation when a spend is scheduled or executes. An optional rule may limit the delegate's independent spends to identities the donor has approved, without requiring every donor to preselect recipients or every beneficiary to claim before funds arrive. Distinguish "destination reserved for this identity" from "controller has verified a payout wallet." Neither is an endorsement of the project. A new domain or wallet is not suspicious, and a delegate proving control of their own domain is not evidence of independence. Use [claimable-beneficiaries.md](specs/tech/subsystems/claimable-beneficiaries.md). Do not add new payout-attestation machinery. Write the proposal against `specs/tech/subsystems/delegation/` before changing contracts.

- Exact-payment donor overrides. For an ordinary pending spend, "Approve now" is enough. If that spend breaks a rule she configured, name the exception (for example, a beneficiary outside her approved list) and bind her approval to that payment only. Changing the standing rule is a separate action. The delegate's restrictions stay enforced by the contract. She should not have to revoke and redeposit to make the exception. Write the proposal against `specs/tech/subsystems/delegation/` and [delegation-narrowing.md](specs/product/legal/delegation-narrowing.md) before changing contracts.

----

- **(Tell)** Testnet Commonality SPA does not hydrate. `https://testnet.commonality.works/` and deep links now return the HTML shell (SPA fallback after public-gateway 429 is deployed), but browser loads fail on chunks such as `/assets/address-TZjglcQ5.js` (HTTP 429, public IPFS sunset body). Dedicated Pinata origin times out; Worker then falls through to `ipfs.io` / `w3s.link`. Reproduce, fix the Worker/gateway path so real assets are served from Pinata (or another working origin) instead of caching/returning 429, redeploy `cloudflare-ui-gateway`, and verify `/`, `/founders`, and a hydrated heading in a real browser. Pinata dashboard Host Origins remains Adam’s step in [`inbox.md`](inbox.md). Continuity: [`continuity/2026-09-15-commonality-live-gateway-followup.md`](continuity/2026-09-15-commonality-live-gateway-followup.md).
Expand Down
3 changes: 3 additions & 0 deletions docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -641,6 +641,9 @@ services:
- IPFS_GATEWAY=http://ipfs:8080/ipfs
- IPFS_API=http://ipfs:5001
- HOME=/tmp
# Ponder starts Vite/Chokidar. This host's inotify instance cap is 128,
# and watching /app exhausts it (EMFILE). Match the Render blueprint.
- CHOKIDAR_USEPOLLING=true
healthcheck:
test: |
curl -f -X POST -H "Content-Type: application/json" \
Expand Down
Loading
Loading