From the fourth E2E run: the agent correctly refused to reproduce a
104 KB SIE file token by token (silent mid-verifikat truncation) and
dead-ended to the web wizard, and its replies were walls of compliance
prose.
1. gnubok_create_sie_upload: signed same-origin upload URL (reuses the
pending-document infra; .se/.sie/.si only, 50 MB HTTP cap).
gnubok_sie_preflight and gnubok_import_sie accept upload_id as the
byte-exact source, plus optional sha256 (hex of the raw bytes)
verified on the upload_id/base64 paths so truncation is DETECTED,
never silent. Inline content above 120k chars is refused with a
pointer to the upload flow. Scope bookkeeping:write (same intent as
import_sie).
2. Skill: brevity rule (max ~8 short lines per reply, one warning per
step, no legal essays), memory-first rule (check what is already
known before asking the opening questions), the upload-first SIE
step, and gnubok_explain_voucher_gap after import for skipped
voucher numbers.
3. CONNECTORS.md starter prompt rewritten memory-first so it stays
copy-paste ready without the user's own data in it. Plugin v1.2.2.
tools/list ceiling 62K to 62.4K documented in the bench.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
The API-key settings panel carried a hand-copied list of scope groups that
had drifted to 24 of the 30 scopes in API_KEY_SCOPES: articles:read/write,
companies:write and the three reconciliation scopes were missing, so a key
minted in the dashboard could not call gnubok_create_company, the article
tools, the seven reconciliation tools or the matching v1 endpoints. The
per-scope "N verktyg" counts in the panel and in the API_KEY_SCOPES
descriptions were hand-maintained and wrong (reports:read said 18, actual
30; bookkeeping:write said 11, actual 22).
- Move the pure scope catalogue (API_KEY_SCOPES, scope lists, SCOPE_GROUPS,
TOOL_SCOPE_MAP) into lib/auth/scope-catalog.ts with no server imports, so
the client-side panel can bundle it. api-keys.ts re-exports everything,
so existing imports are unchanged.
- SCOPE_GROUPS becomes a list of { domain, label, scopes } covering every
scope (reconciliation has three), shared by the panel and the OAuth
consent page. scopeKind() replaces the ad hoc suffix checks.
- TOOL_COUNT_BY_SCOPE is derived from TOOL_SCOPE_MAP at module load; the
hand-written counts are removed from the catalogue descriptions.
- The panel renders groups and cards from the catalogue; i18n keys are
derived from domain and scope id. The "(REST API)" heading suffix is
computed from the counts instead of baked into the labels.
- New unit test asserts every scope belongs to exactly one group and that
counts equal TOOL_SCOPE_MAP occurrences.
- New sv/en strings for the articles, companies:write and reconciliation
scopes.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>