Skip to content

[ENG-4046] Print setup progress as a short, plain status report - #299

Merged
mariojgt merged 4 commits into
mainfrom
mariot/eng-4046-show-user-progress
Sep 28, 2026
Merged

mariojgt merged 4 commits into
mainfrom
mariot/eng-4046-show-user-progress

Conversation

@mariojgt

Copy link
Copy Markdown
Contributor

Ref ENG-4046

What changed

setup, scan and guide now print a short, plain status report instead of paragraphs of explanation:

Patchstack setup

Done
 ✔ Checked 3 packages
 ✔ Added this project to Patchstack
 ✔ Connected to your Patchstack account: https://app.patchstack.com/site/123/monitoring
 ✔ Added the Patchstack widget to index.html
 ✔ Added the build steps to package.json

Missing
 ✘ Runtime protection: no server file found
   Add Patchstack where requests enter your app. Run npx @patchstack/connect protect for the steps.

 ✔ Install the Patchstack connector
 ✔ Connect project to Patchstack account
 ✔ Sync and monitor in local environment
 ✘ Deploy project to protect live app

➜ Next: deploy your project to protect the live app
  Commit your changes. Never commit .patchstackrc.local.json.
  Set PATCHSTACK_API_KEY (from .patchstackrc.local.json) on your hosting platform.
  Deploy or publish. The live site keeps its old version until you do.
  • Done / Missing / checklist / Next. Every command ends on the same four steps as the new card on the dashboard (saas#1884), word for word, and exactly one next step.
  • No jargon by default. Manifest, checksum, site UUID, endpoint, lockfile, guard and marker only show with the new --verbose flag. The note telling the AI agent to "narrate" is gone from the output; AGENT-INSTALL.md keeps it for agents.
  • Build logs stay quiet. A scan run as an install or build step prints two lines. mark-build prints one.
  • Errors are one plain sentence plus what to do, with the error code kept for support, e.g. Could not reach Patchstack. Check your internet connection and try again. (NETWORK_ERROR).
  • The widget is never asked about. The install prompt said "authorize its Patchstack Connector", which agents read as optional, so they stopped to ask. The prompt and AGENT-INSTALL.md now say the widget is part of the install and on by default. "widget": false is honoured only when the user set it.
  • "Report a vulnerability" is no longer promised. The ticket says SaaS does not receive those reports yet.

Across the same 11 demo runs, output went from 366 lines / 3,675 words to 186 lines / 1,026 words.

How each step is decided

  • Install: @patchstack/connect is in package.json.
  • Connect: this run's scan was told claimed or owned-by-you by the server. That is what the --claim-token prompt produces.
  • Sync and monitor: the scan was stored. The label names the environment the scan reported as (local, sandbox or production).
  • Deploy: never ticked by the CLI. A production scan is a build, not a deploy: a Lovable project builds without publishing, and before this change a Lovable scan printed "All done" with nothing live. The CLI now says Reported as a publish. Patchstack ticks this once it sees the live site. and leaves the tick to the dashboard.

Flags, exit codes, --json and --dry-run output are unchanged.

Verified

  • npm run typecheck, npm run build and npm run capabilities:check pass.
  • npm test: 207 files, 3,454 passed, 7 skipped, on top of current main.
  • New tests:
    • the checklist wording, order and single next step;
    • the environment label;
    • a production or Lovable scan leaves Deploy unticked;
    • a claim-token response ticks Connect;
    • default output contains none of the banned words, and --verbose brings the detail back;
    • a build-step scan prints two lines;
    • the plain network error.
  • Ran setup --claim-token … from the dashboard's prompt against a mock API: it creates the site, prints the dashboard link, and ticks Install, Connect and Sync.
  • Hostile field test (node field-test/run.mjs --persona hostile --rounds 3) on the widget prompt change. Every round scored 11/12, and in all three the agent added the widget without asking. The failing check was protectionVerified, because the fixture is a browser-only Vite app with no server to protect.

Out of scope, worth a follow-up

  • Connect is forgotten after the run. Nothing on disk records the claim, so a later guide shows Connect as not done. Saving it to .patchstackrc.json after a claimed response would fix it.
  • The field test must run again after release. The fixture installs the published package, so it could not check the new guide output or AGENT-INSTALL.md. Run the hostile field test right after the release that ships this.
  • guide still appends the full reference guide while setup is unfinished, because agents rely on it.

Docs: deferred. One docs companion will cover this output and the dashboard card from saas#1884 once this is released.

🤖 Generated with Claude Code

mariojgt and others added 3 commits September 28, 2026 15:12
guide, setup and scan now end on the same checklist the dashboard shows
(install, connect, sync, deploy) and print one next step with the command
or link to run. The scattered "Next steps", "Setup not complete" and
"Connect this site" blocks are gone, and the remaining CLI lines are
shorter. Technical leftovers (hooks, widget tag, production marker,
runtime protection) show under their step in guide, only when missing.

The widget is part of the install: the prompt and AGENT-INSTALL.md now
tell the agent to add it without asking, and to honour "widget": false
only when the user set it. The "Report a vulnerability" button is no
longer mentioned in CLI output or the install docs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the dashboard

A production scan is a build, not a deploy: Lovable builds without
publishing, so a scan there reported All done while nothing was live.
The checklist now names the environment the scan came from and says a
production report is waiting for Patchstack to see the live site.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The default output now says what was done, what is missing and what to
do next, in words a non-developer can follow. The stage headers, the
installer log lines, the environment and endpoint lines and the note
addressed to AI agents are gone from it.

- setup and scan group their results under Done and Missing, then end
  on the same four-step checklist and one next step.
- guide lists what is missing with the exact thing to do, instead of
  technical lines under each step.
- The warning that an unconnected project can be connected by anyone
  who opens it is back, under Missing.
- A scan inside an install or build prints two lines; mark-build one.
- Errors say what went wrong and what to do, with the error code last.
- --verbose brings back the site ID, endpoint, checksum, environment
  and why, files written and the installer's own lines.

AGENT-INSTALL.md describes the Done/Missing report and --verbose. The
hostile field test for this guide output is still owed after release.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mariojgt

Copy link
Copy Markdown
Contributor Author

/review

@coderbuds

coderbuds Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Introduces a unified status report with clear progress steps.

🎯 Quality: 62% Average · 📦 Size: Oversized — strongly consider breaking this down

🛡️ Standards: Not checked — 2,067 lines changed, over your team's 400-line limit, and nothing checked before it was opened. Coding agents can call the assess-change-fit tool first, while a change this size is still cheap to split.

🤖 Authorship: Agent-written — Claude Code, going by its own attribution. Whether a person read it is unknown; coding agents can call the report-ai-usage tool to say.

📈 This month: Your 139th PR — above team average · Averaging Average

See how your team is trending →

On a CI runner the CLI reads the runner's own variables and names the
environment sandbox or production, so the two tests that expect the
local label failed there and passed on a laptop.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mariojgt
mariojgt merged commit de3771b into main Sep 28, 2026
18 checks passed
@mariojgt
mariojgt deleted the mariot/eng-4046-show-user-progress branch September 28, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants