{"slug":"ventura-claw","total":79,"limit":100,"offset":0,"since":null,"commits":[{"hash":"fa4ad4d","date":"2026-07-23 11:41:50 -0700","author":"Steve Abrams","subject":"Pin autonomous Claude CLI invocation to Opus (--model opus)","body":"Bare 'claude' spawn inherited the CLI's drifting default model; pin to Opus\nso this build/gen loop always runs on the intended model.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>"},{"hash":"49d825b","date":"2026-05-31 00:06:17 -0700","author":"SteveStudio2","subject":"fix: add rel=noopener noreferrer to target=_blank link in admin-wizard.html","body":""},{"hash":"f04d321","date":"2026-05-30 21:27:26 -0700","author":"SteveStudio2","subject":"fix(llm): demo classify returned 0/5 — qwen3 reasoning ate token budget + health-gate ignored fallback","body":"Root causes (demo widget = Show HN launch blocker):\n- classifyIntent used num_predict:220 against qwen3:14b (a reasoning model); reasoning\n  tokens consumed the whole budget so response came back EMPTY (done_reason=length).\n  Fix: pass think:false to /api/generate (clean JSON in ~1.2s) + raise budget to 512.\n- _isHealthy() gated only on the PRIMARY endpoint; when Mac1 Ollama returned HTTP 500 it\n  returned null in 0ms and never reached the healthy Mac2 fallback. Fix: healthy if EITHER\n  primary or fallback /api/tags answers.\n- prewarm() logged success without checking r.ok, masking a dead backend (silent 0/5).\n  Fix: check r.ok, warn loudly on unhealthy backend.\n- Defense-in-depth: strip <think> in tryParse + /no_think suffix (for builds that ignore think:false).\n\nNote: OLLAMA_FALLBACK_URL/MODEL added to server/.env (gitignored) — Mac1 stays primary\nper project default, Mac2 (also holds qwen3:14b) is the fallback. Verified PRIMED 5/5.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>"},{"hash":"7a6c4ad","date":"2026-05-29 08:14:19 -0700","author":"Steve","subject":"Update Claude model IDs to claude-opus-4-8 (Opus 4.8 upgrade)","body":"Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>"},{"hash":"01b8b05","date":"2026-05-24 20:51:57 -0700","author":"SteveStudio2","subject":"preload fleet: 5 seed users × 10 connectors from secrets-manager .env","body":"- maskFields: first4 + 8 asterisks + last4 (was first4…last4); pass _* provenance through\n- scripts/preload-fleet.js: full ENV_KEY_TO_CONNECTOR map, 5 canonical logins\n  (admin, info@vcl, steve@vcl, info@dw, steve@dw — all role=admin, bcrypt-hashed)\n- Backs up existing encrypted credentials.json; writes plaintext seed\n  (server boot re-encrypts under CC_SECRET via existing migration block)"},{"hash":"5e81c08","date":"2026-05-19 11:35:50 -0700","author":"Steve","subject":"snapshot — gitify backup 2026-05-19","body":""},{"hash":"90d7b12","date":"2026-05-13 08:58:04 -0700","author":"Steve","subject":"snapshot: 2 file(s) changed, +2 new","body":""},{"hash":"f4a6174","date":"2026-05-07 13:23:36 -0700","author":"SteveStudio2","subject":"marketing: pre-flight section flags Show HN draft is unshippable until demo widget returns to homepage; fix 56→67 connector count","body":""},{"hash":"8cdeaf7","date":"2026-05-07 12:29:33 -0700","author":"Steve","subject":"tighten .gitignore: add missing standing-rule patterns (tmp/ dist/ build/ .next/)","body":""},{"hash":"2c1f81f","date":"2026-05-07 12:26:32 -0700","author":"Steve","subject":"/services: client-side search filter (mirrors /connectors pattern) — substring match across data-svc + name + description + category heading; live 'N / 18 match' count; sections hide when fully filtered; skips demo + how-it-works + compare sections","body":""},{"hash":"1843ec6","date":"2026-05-07 11:54:08 -0700","author":"Steve","subject":"[ops] local ventura-claw process recovered (was missing from pm2 dump); pm2 save'd; sitemap.xml audit clean (0 /admin paths leaked)","body":""},{"hash":"21e25ee","date":"2026-05-07 11:33:57 -0700","author":"Steve","subject":"robots.txt: explicit hint pointing at /feed (RSS) for crawlers that don't honor <link rel=alternate>; multi-line format for readability","body":""},{"hash":"a506956","date":"2026-05-07 11:32:42 -0700","author":"Steve","subject":"BreadcrumbList JSON-LD ('Home › X') on /services + /legal-notice + /how-it-works directly; auto-generated for ALL _shell-rendered pages from canonical URL path; rich-snippet eligible across the site","body":""},{"hash":"334b6e1","date":"2026-05-07 11:22:15 -0700","author":"Steve","subject":"/connectors: client-side search filter — single input filters tiles by name/category/meta on every keystroke; live count ('N / 67 match'); category sections hide when fully filtered","body":""},{"hash":"734a275","date":"2026-05-07 11:01:53 -0700","author":"Steve","subject":"/services + /legal-notice + /how-it-works: <link rel='alternate' type='application/rss+xml'> pointing at /feed; RSS readers + Google/Bing now discover the changelog feed from any page","body":""},{"hash":"1e1f786","date":"2026-05-07 10:59:54 -0700","author":"Steve","subject":"/how-it-works: expand step-2 partner-API tag cloud from 13 → 21 (added Square/Wave/Relay/Bluevine/Next Insurance/Coalition/TaxBandits/Justworks to match SERVICES_CATALOG)","body":""},{"hash":"4da6324","date":"2026-05-07 10:41:08 -0700","author":"Steve","subject":"remaining '56' stragglers swept: login.html (title + 3x og/twitter/JSON-LD + 2x body), /docs (56→67 connector catalog), DEPLOY.md + MARKETING.md internal docs","body":""},{"hash":"8e2cca0","date":"2026-05-07 10:38:17 -0700","author":"Steve","subject":"homepage.html: theme toggle (sun/moon top-right) + light CSS vars + anti-flash inline script; FIX leftover '56 business connectors' in SoftwareApplication JSON-LD → 67 (caught during theme audit)","body":""},{"hash":"a3250a8","date":"2026-05-07 10:30:00 -0700","author":"Steve","subject":"/changelog 2026-05-07: append 4 continued-sweep wins (Last-Modified+/api/public/services SEO, theme toggle on 11 pages, _shell topbar Commerce-Claw fix, disk-audit playbook saved to memory)","body":""},{"hash":"b1dd058","date":"2026-05-07 10:08:54 -0700","author":"Steve","subject":"_shell template: theme toggle (sun/moon, fixed top-right) + light CSS vars; FIX leftover 'Commerce Claw' brand string in topbar → 'VenturaClaw' (caught by /pricing audit); add /services to topbar nav","body":""},{"hash":"7151c1c","date":"2026-05-07 09:41:58 -0700","author":"Steve","subject":"teaser footer: add /connectors + /docs links (alongside /services /how-it-works /legal-notice /privacy /terms /info-email) for discoverability","body":""},{"hash":"b2a4b3b","date":"2026-05-07 09:34:20 -0700","author":"Steve","subject":"/services + /legal-notice + /how-it-works: dark/light theme toggle (sun/moon button) per CLAUDE.md rule — anti-flash inline script + light CSS vars + topbar button + localStorage persistence","body":""},{"hash":"2461005","date":"2026-05-07 09:25:45 -0700","author":"Steve","subject":"/services + /legal-notice + /how-it-works: emit real Last-Modified header (from underlying HTML mtime) + Cache-Control: public, max-age=300, must-revalidate; CDN/proxy cache hint after the post-pivot copy sweep","body":""},{"hash":"b2b64af","date":"2026-05-07 09:14:42 -0700","author":"Steve","subject":"/docs: add curl example for /api/public/services (18-row services-hub catalog) above the demo-classifier example","body":""},{"hash":"23e9887","date":"2026-05-07 09:12:14 -0700","author":"Steve","subject":"+/api/public/services — 18-row JSON catalog (mirrors /api/public/connectors), per-service id/category/name/partners/price_free/price_paid/unit; nginx route added on venturaclaw.com","body":""},{"hash":"a261c64","date":"2026-05-07 09:05:02 -0700","author":"Steve","subject":"/privacy + /terms post-pivot refresh: bump 'Last updated' to 2026-05-07; add 'Lead capture' clause for /services Get-Started forms; clarify 'no markup on partner fees' in /terms","body":""},{"hash":"12f8e98","date":"2026-05-07 08:32:19 -0700","author":"Steve","subject":"/connectors lede: cross-link to /services hub ('Looking for a curated bundle? 18 ready-to-run orchestrations on top of these connectors')","body":""},{"hash":"90488b5","date":"2026-05-07 08:28:20 -0700","author":"Steve","subject":"/changelog: prepend 2026-05-07 'API-orchestration pivot' entry (9 items: hidden door, /how-it-works, /pricing v2, lead funnel, demo widget, brand sweep, session-debrief hardening, dw-collections-viewer wins, SEO); fix '56 indexable' → '67' in earlier entry","body":""},{"hash":"80bb40d","date":"2026-05-07 08:26:06 -0700","author":"Steve","subject":"/docs meta: '56 SaaS connectors' → '67 SaaS connectors and orchestrates 18 small-business services on top'","body":""},{"hash":"1e26894","date":"2026-05-07 07:56:19 -0700","author":"Steve","subject":"homepage.html: '56 connectors' → '67' across title/meta/og/twitter/eyebrow/subhead/aria-label/JS rotator (10 spots)","body":""},{"hash":"ed58e70","date":"2026-05-07 07:54:25 -0700","author":"Steve","subject":"/about: '56 connectors' → '67 + 18 /services orchestrations on top'; key envelope; cross-link /services","body":""},{"hash":"958d1e1","date":"2026-05-06 22:05:49 -0700","author":"Steve","subject":"/services demo widget: tighten CTA copy from 'Run this plan' (long, promised auto-execution we don't have yet) to 'Pre-fill & send' (honest about the human-in-the-loop)","body":""},{"hash":"7489430","date":"2026-05-06 22:03:32 -0700","author":"Steve","subject":"/sitemap.xml: per-URL <lastmod> (resolved from underlying HTML mtime when available, fallback to server start) + <priority> per route; SEO win after post-pivot copy sweep so Google recrawls","body":""},{"hash":"a129aee","date":"2026-05-06 21:34:15 -0700","author":"Steve","subject":"teaser coming-soon: '56 connectors/SaaS tools' → '67' across title/meta/og/hero/connectors-strip (5 spots)","body":""},{"hash":"edaa577","date":"2026-05-06 21:30:33 -0700","author":"Steve","subject":"/services chat: add 7th suggestion pill — '$99 freelance stack' triggering full multi-API walkthrough (domain+email+Stripe+accounting+contracts)","body":""},{"hash":"45ead1c","date":"2026-05-06 21:02:04 -0700","author":"Steve","subject":"/pricing + /connectors + /docs: '56 connectors' → '67 connectors' (real count from /api/public/connectors)","body":""},{"hash":"df490ed","date":"2026-05-06 20:29:42 -0700","author":"Steve","subject":"/services: align top banner + modal disclaimer + flow-foot with API-orchestration framing (matches /legal-notice post-pivot sweep)","body":""},{"hash":"1128b8f","date":"2026-05-06 19:56:03 -0700","author":"Steve","subject":"/legal-notice: clean up the last 4 'Document Preparation' / 'Filing Service' references in section heading + glossary + ack header","body":""},{"hash":"f640869","date":"2026-05-06 19:55:12 -0700","author":"Steve","subject":"/legal-notice: post-pivot sweep — replace all 'document preparation service' / 'filing service' / 'we file' framing with 'API-orchestration service' (matches new positioning); §6400 marked explicitly inapplicable since we don't file gov forms","body":""},{"hash":"8d0f1e1","date":"2026-05-06 19:52:22 -0700","author":"Steve","subject":"/admin/services-leads: dark/light theme toggle (sun/moon button) with anti-flash inline script + localStorage persistence; per CLAUDE.md sun/moon rule","body":""},{"hash":"f80fef5","date":"2026-05-06 19:43:39 -0700","author":"Steve","subject":"/pricing v2: dual-product split (chat orchestrator free + services hub $0–$99 per-service); kills 'eventual flat workspace fee' single-product framing; cross-links /services + /how-it-works","body":""},{"hash":"6b0bf81","date":"2026-05-06 19:38:15 -0700","author":"Steve","subject":"/how-it-works page: 3-step API-orchestration explainer + alternatives comparison + JSON-LD HowTo schema; sitemap entry + nginx proxy + teaser footer link","body":""},{"hash":"5a1709c","date":"2026-05-06 19:24:39 -0700","author":"Steve","subject":"/services hero: tighter measurable hook — '47-second domain + email setup · $39 flat · what a VA charges $300 for'","body":""},{"hash":"a5630c3","date":"2026-05-06 17:12:55 -0700","author":"SteveStudio2","subject":"Add 5 no-auth SMB / civic public-data connectors","body":"Federal:\n  sec         — SEC EDGAR (10-K filings, financial data, ticker lookup)\n  usaspending — federal contracts + grants search by keyword/recipient/year\nLocal-state:\n  nws         — National Weather Service (forecasts + active alerts by lat/lon)\n  lacity      — LA City Open Data (Socrata) — business tax registry, permits,\n                crime, code violations; SoQL query interface\n  cadata      — California Open Data (CKAN) — package search + datastore query\n\nAll zero-auth — pre-connected for everyone. Health probes verified live on\nMac dev + Kamatera prod.\n\n(USPTO was attempted but TSDR + PEDS recently auth-walled their public\nendpoints; dropped from this batch.)"},{"hash":"4cd2509","date":"2026-05-06 17:08:13 -0700","author":"SteveStudio2","subject":"Add 5 no-auth public-data connectors: MET, Cleveland, AIC, Wikipedia, Color API","body":"All 5 are pre-connected — zero credentials required, just HTTPS calls.\nUseful for DW content workflows (art reference, color tooling, encyclopedic\nfact-checks). Live counts on health probe:\n  - MET Museum:                 43,947 PD objects\n  - Cleveland Museum of Art:    68,738 CC0 artworks\n  - Art Institute of Chicago:  131,990 artworks (IIIF imagery)\n  - Wikipedia:                 english REST + search APIs\n  - Color API:                 identify + scheme actions\n\nEach handler follows the archive.js pattern: meta + empty fields + always-\nconfigured + health() probing a free endpoint + 2-3 read-only actions.\n\nRegistered in REAL map with WRITE_ACTIONS: Set([]) (read-only) and\nREAD_ACTIONS enumerated. Catalog entries added to connectors.json (62 total)."},{"hash":"a6a5067","date":"2026-05-06 17:03:19 -0700","author":"SteveStudio2","subject":"ENV_KEY_TO_CONNECTOR: align field names with what the handlers actually read","body":"Previous version used descriptive field keys (api_key, access_token, store).\nThe connector handlers (stripe.js, cloudflare.js, etc) look up creds under\nthe upper-case env var name (STRIPE_SECRET_KEY, CF_API_TOKEN, ...). After\nimport, /admin/connectors UI showed 'filled: true' but every command failed\nwith 'no_token' because the lookup key didn't match the storage key.\n\nFixed by making each entry's 'field' match the handler's lookup key. Notable\nremappings beyond the obvious uppercase-rename:\n- CLOUDFLARE_API_TOKEN  → CF_API_TOKEN  (CF_ prefix in handler)\n- HUBSPOT_ACCESS_TOKEN  → HUBSPOT_TOKEN\n- NOTION_API_KEY        → NOTION_TOKEN\n- CANVA_API_KEY         → CANVA_TOKEN\n- ETSY_API_KEY          → ETSY_KEYSTRING\n- SHOPIFY_ACCESS_TOKEN  → SHOPIFY_ADMIN_TOKEN\n\nAlso added direct-name aliases (HUBSPOT_TOKEN, NOTION_TOKEN, CANVA_TOKEN,\nETSY_KEYSTRING, ETSY_ACCESS_TOKEN) so users can paste either variant.\n\nAfter re-import: stripe + cloudflare + archive flip from rejected → ✓ ok.\nLive prod /api/connectors/health-all confirms 5 connectors authenticate\nwhere 2 did before."},{"hash":"1ad784f","date":"2026-05-06 16:58:34 -0700","author":"SteveStudio2","subject":"Wizard: bulk health strip — see all saved connectors auth status at a glance","body":"- New strip at top of wizard shows one pill per filled connector (✓ ok / ⊘ catalog-only / ✗ rejected)\n- Pulls from existing /api/connectors/health-all (30s cached, no rate hit)\n- Click a pill to insert that connector into the wizard queue at current cursor\n  (handy for fixing a broken one without leaving the page)\n- Re-test button refreshes the strip on demand\n- Connectors absent from /health-all (catalog-only filled) render as ⊘ skipped, not stuck-in-testing\n- Summary line: 'N authenticate · M no test handler · K rejected'"},{"hash":"437cf54","date":"2026-05-06 16:47:20 -0700","author":"SteveStudio2","subject":"Wizard: Test button — saves + validates against connector health, auto-advances on ✓","body":"- New 'Test' button next to 'Save & Next →' chains save → /api/connectors/:id/health\n- Inline result panel shows: ok (green, auto-advances 1.2s), 'no test handler' for\n  catalog-only (yellow, stays put), error reason (red, stays put for fixing)\n- 'Save & Next →' still works as fast-path skip-validation\n- Test-result resets each step"},{"hash":"7334fa7","date":"2026-05-06 16:42:45 -0700","author":"SteveStudio2","subject":"Connector wizard: one-question-at-a-time onboarding at /admin/wizard","body":"Replaces the wall-of-tiles connector page with a guided wizard. Walks Steve\nthrough every unfilled connector one at a time, with paste/skip/save buttons\nand a 'Search Vault' button that auto-fills from secrets-manager .env on\nMac dev (gracefully no-ops on Kamatera prod where the vault isn't present).\n\n- New GET /admin/wizard serves the single-page wizard\n- New GET /api/wizard/vault-search?connector=:id inverts ENV_KEY_TO_CONNECTOR\n  and looks up matching env values from $VC_VAULT_PATH or\n  ~/Projects/secrets-manager/.env. Admin-gated; never proxies arbitrary paths.\n- Cmd/Ctrl-Enter to save+next; progress bar shows N/M filled.\n- Wizard fetches /api/me/connections, filters to .filled==false,\n  uses existing POST /api/me/connections/:id to save each.\n\nMirrored to Kamatera /root/public-projects/ventura-claw with backups."},{"hash":"0c593b6","date":"2026-05-06 16:33:15 -0700","author":"SteveStudio2","subject":"ENV_KEY_TO_CONNECTOR: add ELEVENLABS_API_KEY, PURELYMAIL_API_TOKEN, SHOPIFY_ADMIN_TOKEN","body":"The bulk-import endpoint at /api/me/connections/import maps env-var names to\nconnector credentials via a static table. Three keys that exist in Steve's\nsecrets-manager vault weren't mapped:\n\n- ELEVENLABS_API_KEY  → elevenlabs.ELEVENLABS_API_KEY\n- PURELYMAIL_API_TOKEN → purelymail.PURELYMAIL_API_TOKEN\n- SHOPIFY_ADMIN_TOKEN → shopify.access_token (alias for SHOPIFY_ACCESS_TOKEN)\n\nAfter this patch a fresh import of secrets-manager .env populates 7 of\nSteve's available connectors instead of 5 (stripe, cloudflare, shopify,\ngodaddy, browserbase, elevenlabs, purelymail) — zero unmatched."},{"hash":"03cee41","date":"2026-05-06 16:29:59 -0700","author":"Steve","subject":"/services demo widget: 'Try it now' domain+email orchestration plan; structured 7-step API call sequence + cost + deliverables + lead-modal pre-fill","body":""},{"hash":"ff436d8","date":"2026-05-06 16:26:18 -0700","author":"Steve","subject":"/services chat: welcome message points at API offerings (Stripe/domain/insurance) instead of dropped govt-form services","body":""},{"hash":"473898d","date":"2026-05-06 16:25:49 -0700","author":"Steve","subject":"/services pivot: 30→18 services, dropped all government-portal flows (LLC/DBA/EIN/BOI/sales-tax/trademark/copyright); 5 new categories (Banking/Tax/Insurance/Identity/Documents); replaced LegalZoom comparison with How-It-Works flow; new positioning: API-orchestration not document-prep","body":""},{"hash":"a04d263","date":"2026-05-06 16:17:31 -0700","author":"Steve","subject":"/services: public comparison matrix (VenturaClaw vs LegalZoom/ZenBusiness/Northwest/Bizee) — bundle math + honest 'Northwest is competitive' read","body":""},{"hash":"a075901","date":"2026-05-06 15:53:45 -0700","author":"Steve","subject":"rebrand sweep: users use steve@venturaclaw.com primary + steve@businessclaw.com alias; login accepts either; user-facing 'BusinessClaw' string in connector-acquisition.json fixed","body":""},{"hash":"9c9548d","date":"2026-05-06 14:42:55 -0700","author":"Steve","subject":"/services: JSON-LD ProfessionalService schema + 14 Offers; sitemap + robots wired to venturaclaw.com via nginx; admin /admin/services-leads viewer page","body":""},{"hash":"49f1891","date":"2026-05-06 14:36:00 -0700","author":"Steve","subject":"/services lead capture: modal form + /api/services-lead JSONL + best-effort George email + admin viewer endpoint","body":""},{"hash":"4c50012","date":"2026-05-06 14:30:13 -0700","author":"Steve","subject":"teaser: gold-accent CTA card linking to /services hub + footer links","body":""},{"hash":"39390b0","date":"2026-05-06 13:58:31 -0700","author":"Steve","subject":"/services: per-card 'Not legal advice' badge; /legal-notice: drop §6400-specific framing for general doc-prep model","body":""},{"hash":"28a107c","date":"2026-05-06 13:50:27 -0700","author":"Steve","subject":"/services: cut workers-comp + IRS-payment-plan; ship bold /legal-notice page (UPL/LDA/§6400 disclosures)","body":""},{"hash":"103d327","date":"2026-05-06 13:27:40 -0700","author":"Steve","subject":"services hub: 31 small-biz services + collapsible left chat + smart-router (local-first, Claude opt-in)","body":""},{"hash":"b15fb3e","date":"2026-05-06 13:05:11 -0700","author":"Steve","subject":"competitor matrix: 8 platforms crawled, 10 differentiation vectors","body":""},{"hash":"45dc5f6","date":"2026-05-06 12:53:12 -0700","author":"Steve Abrams","subject":"Snapshot: ElevenLabs + Shopify connectors + coming-soon page","body":"server/connectors/elevenlabs.js — full impl that was missed in the\nearlier commit (file was untracked)\nserver/connectors/shopify.js — DW prod store connector (read shop info,\nproducts, orders; write order.fulfill, order.refund, product.update)\nserver/connectors/index.js — register both with proper write/read action\nsets; Shopify writes are sensitive (gated)\nserver/public/coming-soon.html — placeholder\nserver/server.js — adjacent updates"},{"hash":"5b582d2","date":"2026-05-06 12:52:07 -0700","author":"SteveStudio2","subject":"chat: surface Admin link in topbar for admin users","body":""},{"hash":"37b29cb","date":"2026-05-06 12:12:45 -0700","author":"Steve Abrams","subject":"sync-tokens: strip hardcoded password fallback (was leaked in git)","body":"The literal value '149940c2c5b209fb' was previously the OR-fallback when BC_PASS env was missing — meaning anyone with the repo had Steve's prod password. Now fail-closed: BC_PASS env required at runtime, script exits 1 with clear message if missing. Existing launchd plist already passes the env, so no functional change for the hot path.\n\nNOTE for daylight Steve: rotate the prod password since the old one is in git history.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"},{"hash":"817b756","date":"2026-05-06 12:11:31 -0700","author":"Steve","subject":"no breakins: pull plaintext creds from login banner, add PUT /api/admin/users/:id/password rotation endpoint","body":""},{"hash":"e175bc9","date":"2026-05-06 12:09:10 -0700","author":"Steve Abrams","subject":"Add ElevenLabs as a VenturaClaw connector","body":"- server/connectors/elevenlabs.js — REAL impl, health probe returns\n  subscription tier + char usage\n- server/connectors/index.js — registered in REAL, READ_ACTIONS, WRITE_ACTIONS\n- server/connectors.json — added catalog entry (now 57 connectors)\n- scripts/sync-tokens.js — routes ELEVENLABS_API_KEY into the user vault\n  (verified: 'live' on next sync, health 200 with starter tier 9.3K/90K chars)"},{"hash":"35b8bea","date":"2026-05-06 11:26:21 -0700","author":"Steve Abrams","subject":"test: confirm post-commit celebration sound fires globally","body":"Empty commit to verify the new global git post-commit hook at\n~/.git-hooks/post-commit plays Hero.aiff (the macOS achievement-unlocked\nchime) every time a commit lands. Hooks path is set globally via\ncore.hooksPath so this fires across every repo, with delegation to\nrepo-local hooks preserved."},{"hash":"3911073","date":"2026-05-06 11:20:37 -0700","author":"Steve Abrams","subject":"Drop the .local pseudo-TLD from demo accounts","body":".local is reserved for mDNS / Bonjour, not real email — using it as the\nemail-domain on demo accounts was visually confusing (and inherited from\nthe original businessclaw.local placeholder pattern that I just blindly\nrenamed in the rebrand).\n\nSwitched to venturaclaw.com everywhere, which is real and has a working\nmailbox now:\n- admin@venturaclaw.local       -> admin@venturaclaw.com (+ pw reset to 'admin'\n                                     so the displayed demo creds actually work)\n- steve@venturaclaw.local       -> steve@venturaclaw.com (pw preserved)\n- demo@venturaclaw.local        -> demo@venturaclaw.com (display only)\n- BC_USER default in sync-tokens.js → steve@venturaclaw.com (verified working\n                                       against the canonical hostname)\n\nServer reads users from JSON in memory, so this required a pm2 restart\nafter editing users.json. Login at admin/admin verified 200; steve@ login\nverified to still reject wrong password (401 not 404, so the rename took)."},{"hash":"7c714cb","date":"2026-05-06 11:17:30 -0700","author":"Steve Abrams","subject":"Migrate canonical hostname to venturaclaw.com","body":"Steve registered venturaclaw.com today and asked to put all builds on it.\nSame Express server, new front door:\n\n- Apex A + www CNAME at GoDaddy → 45.61.58.125\n- nginx server block + Let's Encrypt SSL on apex + www\n- MX/SPF/DKIM/DMARC for venturaclaw.com (mirrors agentabrams.com pattern)\n- Domain added to Purelymail; info@venturaclaw.com mailbox provisioned;\n  password in secrets-manager as INFO_VENTURACLAW_COM_PASSWORD.\n- All venturaclaw.agentabrams.com refs across docs + code swapped to\n  venturaclaw.com.\n- venturaclaw.agentabrams.com + businessclaw.agentabrams.com both 301\n  to venturaclaw.com, except /oauth/* + /healthz which still proxy to\n  the app so existing OAuth callback URLs in provider consoles keep\n  working.\n\nCC_SECRET note: rotated during this migration after rsync --delete\nwiped the .env on Kamatera. Old encrypted credentials.json preserved\nas data/credentials.json.pre-rotate-2026-05-06.bak; vault refilled\nfrom secrets-manager via sync-tokens.js (5/14 connectors back, same\nas pre-rotation)."},{"hash":"5f60f03","date":"2026-05-06 10:58:26 -0700","author":"Steve Abrams","subject":"Purge remaining businessclaw / commerce-claw refs across docs + code","body":"Steve flagged that login.html, DEPLOY.md, API.md, MARKETING.md, sync-tokens\ndefaults, package.json names, viewer/server.js, integration tests, and\nrelay/server.js still carried the old brand. Mass-rename:\n\n- businessclaw.agentabrams.com -> venturaclaw.agentabrams.com\n- *.businessclaw.local         -> *.venturaclaw.local (admin/demo accounts)\n- steve@businessclaw.com       -> steve@venturaclaw.local\n- info@businessclaw.com        -> info@venturaclaw.agentabrams.com\n- commerce-claw                -> ventura-claw\n- commerceclaw / businessclaw  -> venturaclaw\n\nAlso renamed the email fields in production users.json on Kamatera\n(admin@businessclaw.local -> admin@venturaclaw.local; steve@businessclaw.com\n-> steve@venturaclaw.local). Hashed passwords preserved in place.\n\nLogin on the canonical hostname now works with steve@venturaclaw.local +\nthe existing password (verified 200 OK)."},{"hash":"181cd5f","date":"2026-05-06 10:21:48 -0700","author":"Steve Abrams","subject":"Rebrand Commerce Claw / BusinessClaw → VenturaClaw","body":"Rename the product and live hostname end-to-end:\n- 96 user-visible refs swapped across public HTML, server.js, marketing\n  pages, login, oauth-setup, JSON-LD/OG tags. Brand-name keeps the\n  italic-gold treatment by splitting Ventura<em>Claw</em>.\n- Subtitle 'Connected Commerce' → 'Connected Operations'.\n- Footer email info@businessclaw.com → info@venturaclaw.agentabrams.com\n  (mailbox provisioned on Purelymail with full MX/SPF/DKIM/DMARC).\n- Bulk-select-and-connect on /connections: per-tile checkboxes plus a\n  Select-all / Connect-selected control bar that walks selected\n  providers through their OAuth popups in a sessionStorage-backed\n  queue, with a Continue button between each so each popup gets a\n  fresh user gesture and avoids browser pop-up blocks.\n- Hardcoded log tag [commerce-claw] → [ventura-claw].\n- launchd job com.steve.businessclaw-sync → com.steve.venturaclaw-sync;\n  sync-tokens.js paths + default BC_URL repointed to venturaclaw.\n\nLive at https://venturaclaw.agentabrams.com (Let's Encrypt SSL,\nnginx → 127.0.0.1:9788). businessclaw.agentabrams.com 301-redirects\nall paths except /oauth/* + /healthz so existing OAuth callback URLs\nregistered in each provider's developer console keep working."},{"hash":"ee0bbe0","date":"2026-05-06 08:16:37 -0700","author":"Steve Abrams","subject":"Launch comms drafts + og-cover.png raster + linter brand polish","body":"- MARKETING.md: Show HN post · 3 seed comments · Twitter · IndieHackers · Search Console + IndexNow steps\n- /static/og-cover.png (1200x630 raster from og-cover.svg via headless Chrome) — needed because some social platforms reject SVG OG\n- Linter polish: contact email shifted info@agentabrams.com → info@businessclaw.com\n- brand.html: sticky section heads, identity card, team grid; admin-connectors: Prime cache button (already shipped earlier, this picks up linter formatting)\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"},{"hash":"c42b617","date":"2026-05-06 07:48:35 -0700","author":"Steve Abrams","subject":"Track homepage.css (was untracked when CSS extraction committed)","body":"Belongs with d9e7a6c — without this file the previous commit ships a broken homepage. fill.html and app/icon.svg left uncommitted (not from this loop).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"},{"hash":"d9e7a6c","date":"2026-05-06 07:48:11 -0700","author":"Steve Abrams","subject":"Externalize homepage inline CSS to /static/homepage.css","body":"Saves ~7KB on every homepage HTML response (37.7KB → 30.8KB).\nRepeat visitors hit the CSS from cache (express.static maxAge:7d).\nPure refactor — zero visual or behavioral change.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"},{"hash":"d6f1881","date":"2026-05-06 05:50:34 -0700","author":"Steve Abrams","subject":"/changelog updated + ● Prime cache UI button on admin","body":"- /changelog top entry now reflects what actually shipped overnight (admin endpoint, sequential prime fix, /feed, /faq, /docs, etc.)\n- /admin/connectors filter bar gets a ● Prime cache button that calls /api/admin/cache/prime, shows primed N/5 + cache size\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"},{"hash":"320d50b","date":"2026-05-06 05:09:13 -0700","author":"Steve Abrams","subject":"Add POST /api/admin/cache/prime endpoint","body":"Re-fires the 5 preset cache primes on demand — useful when Mac1 evicts qwen3:14b\n(concurrent codex 8-way runs etc.) and visitors are eating cold-loads. Admin-gated.\nAudit-logged as admin_cache_prime. Returns {ok, primed, total, cache_size}.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"},{"hash":"21481b0","date":"2026-05-06 04:28:29 -0700","author":"Steve Abrams","subject":"Overnight ticks — public surface polish (post-61cfcb1)","body":"Public pages added:\n- /faq dedicated page (FAQPage JSON-LD for Google rich-result eligibility)\n- /docs page · 5 curl examples for public + auth API surface\n- /changelog page · 4 dated entries · gold-rail timeline\n- /feed RSS · IndieWeb / reader auto-discovery\n- /about /privacy /terms (required SaaS pages)\n- Branded 404 (HTML for browsers, JSON for /api/*)\n\nHomepage improvements:\n- \"How it works\" 3-step strip (Type → Route → Approve, code-on-card)\n- 8-question FAQ section with details/summary expand\n- Live route trail widget · rotating eyebrow taglines (4× cycle)\n- Tile float animation · animated thinking state on demo\n- ?demo=<query> deep-link auto-fires from connector pages\n- noscript fallback (graceful degrade for JS-off visitors)\n- <link rel=\"prefetch\" href=\"/connectors\"> · theme-color · RSS link\n\nPerf + ops:\n- /healthz JSON variant (uptime, mem, demo cache size, LLM endpoints)\n- Sequential preset cache prime on boot (4/5 fills, 20ms cached responses)\n- Allowlist env loader extended for OLLAMA_FALLBACK_URL + CC_KEY_ID\n- robots.txt cleanup (removed dead duplicate handler)\n- Footer cross-links every shell page (/connectors /about /faq /docs /privacy /terms /sitemap.xml)\n- Sitemap grew 3 → 65 URLs · ItemList JSON-LD on /connectors\n- Favicon (gold connector-graph SVG) at .ico/.svg/apple-touch paths\n\nSecurity:\n- esc() XSS sweep on chat.html + brand.html (completes all 5 HTML pages)\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>"},{"hash":"61cfcb1","date":"2026-05-06 02:22:52 -0700","author":"Steve Abrams","subject":"Initial commit · Commerce Claw","body":"Public surface (anon-accessible):\n- / homepage with live-demo widget · 56-connector grid · \"How it works\" 3-step · 8-Q FAQ · live route trail · rotating taglines · branded 404\n- /connectors directory + 56 per-connector pages w/ ItemList JSON-LD\n- /privacy /terms /about /faq (FAQPage JSON-LD) /docs (5 curl examples)\n- /sitemap.xml (64 URLs) · /robots.txt · /healthz JSON variant · favicon (gold connector-graph SVG)\n- POST /api/demo-classify (rate-limited 8/min/IP, no execute, intent-only)\n- GET /api/public/connectors\n\nAuth surface:\n- POST /api/auth/login + bcrypt password hashing + signed session cookies\n- POST /api/me/connections/:id (per-user encrypted token vault)\n- POST /api/me/connections/import (paste-claude-json + paste-env auto-detect)\n- POST /api/chat (regex planner → qwen3:14b LLM escalation → tool-call queue)\n\nAdmin surface:\n- /admin/connectors /admin/users /admin/approvals /admin/audit /admin/oauth-setup\n- POST /api/admin/oauth/:vendor/credentials + /sandbox (Browserbase)\n- GET /admin/audit (event ledger)\n\nSecurity:\n- AES-256-GCM at-rest encryption with versioned key_id envelope (rotation supported)\n- Atomic write + fsync(2) in save() · loud-fail load() (corrupt → exit, never silent default)\n- chmod 0700 data/ + 0600 *.json\n- CSP · HSTS preload · X-Frame DENY · X-Content-Type-Options nosniff\n- Sensitive-action approval queue · audit trail\n- esc() XSS sweep across all 5 user-facing HTML pages\n\nLLM:\n- Local Ollama (Mac1 qwen3:14b via tailnet 100.94.103.98:11434) — zero third-party API\n- Pre-warm on boot · parallel preset-cache prime · 25min keep-alive ping\n- 10min LRU response cache (200 entries) · Mac2 fallback chain (gemma3:12b, dead until OLLAMA_HOST=0.0.0.0)\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>\n"}]}