ForgeFX SimulationsPRODUCT & ENGINEERING REFERENCE / 09 SEPTEMBER 2026
FROM SPREADSHEET LOCALIZER TO STANDALONE APP

ForgeLessons
Understanding the App
and Its History

A detailed, source-grounded guide to what the application does, how it protects training content, why the architecture looks this way, and what its repository and live deployment actually prove.

Google Sheets is authoritativeSupabase stores workflowProposals before writesStandalone since 9 September
Snapshot, not a readiness claim. Live guest reading works. Authenticated writes and paid generation were not exercised. Source .3 was ahead of the serving .0 deployment at inspection.

What ForgeLessons Is Now

ForgeLessons is a source-safe localization workspace for training content already held in Google Sheets. It helps an operator find strings, generate or write a proposed target, review the difference, and approve a single-cell write with a recorded read-back. It is not yet a general lesson-authoring system, a field-capture app, or a replacement for the workbook.

The important discovery: the monorepo is historical, not the current home.

ForgeLessons moved to the private forgefx/forgelessons repository on 9 September. The local ForgeApps checkout still contains a dirty app directory, while its remote branches contain the retirement and migration-pointer commits. Treating that directory as current production would blend an old checkout, uncommitted edits, and a completed extraction.

f6f76a711 removed the workspace; e6e510fcf moved the pointer to docs/FORGELESSONS-MIGRATION.md. Standalone 7e3fa74ee established its independent workspace, and 0e790cfe5 reconciled the latest monorepo workflow.

PRODUCT

Review Before Write

English is immutable. AI creates proposals, not direct sheet edits. Applying an exact proposal is another explicit decision.

STORAGE

Two Authorities

Google Sheets holds the cell values. Supabase holds the workflow, permissions, locks, attempts, reservations, and history.

EXECUTION

Browser-Driven

The open page dispatches one awaited cell at a time. A durable job is not an autonomous background worker.

Miguel is identified as project lead; Adam Kane provides support. The standalone README and About page make those roles explicit. The app’s immediate audience is the team maintaining equipment-training text and regional translations, not trainees consuming a learning-management course.

Evidence: README.md, MIGRATION.md, src/pages/AboutPage.tsx, server/localizer.ts.

Source, Deployment, and Live State

These are separate facts, not a single “ready” badge. The investigation pinned source at a456b31c9e3e5fb7428a466a067ac1339902d775 and read committed files with git show after discovering concurrent working-tree changes in the implementation checkout. Those concurrent edits are not included in this source baseline.

Committed Standalone Source

Package version 2026.09.09.3 at a456b31c9. The three commits after the integration baseline change only package.json version text; the inspected diff from 0e790cfe to this tip contains no workflow changes.

Serving Deployment at Inspection

Vercel reported READY for 0e790cfe5, deployment dpl_B4NRvacSC4VahNUcQiEbetaG3fN5. The live header and footer both showed v2026.09.09.0. The later .1, .2, and .3 deployments were BLOCKED. Their exact blocker cause was not established by the deployment-list response.

Hosting Connection

Read-only Vercel API checks confirmed GitHub forgefx/forgelessons, production branch main, repository-root configuration, Node 24.x, and verified domains lessons.forgefx.dev and forgelessons.forgefx.dev. This is live configuration evidence, rather than assuming migration documentation proves the cutover.

Production Browser

/home loaded without personal sign-in. The workbook selector offered John Deere and Halliburton. John Deere exposed 44 tabs; its initial User Notifications tab showed 14 source strings, 0 missing pt-BR targets, 1 reviewed lock, and 0 changed-source flags. These are one tab’s point-in-time counts, not totals for the whole app or evidence of translation accuracy.

Live API Boundary

GET /api/state returned HTTP 200 application/json with readOnly:true, allowWrites:false, and AI unavailable to the guest. GET /api/jobs/step returned HTTP 401 application/json with “Authentication required.” That proves the nested path reaches an authentication boundary; it does not prove an authenticated POST runs a job.

What Was Not Executed

No credentials were entered, no authenticated workflow was exercised, no paid generation was started, and no Google or Supabase records were mutated. No app build or test run was launched for this report. Historical validation claims are labeled as such. The report and screenshot files are the deliverables; app code, branches, and index were left untouched by this researcher.

Observation window: 9 September 2026, approximately 21:37 UTC. This is a historical snapshot of a rapidly changing app. Later releases, including concurrent work elsewhere, may supersede it.

The Real Current Interface

Guest workspace: John Deere / User Notifications, Brazilian Portuguese selected
Guest workspace: John Deere / User Notifications, Brazilian Portuguese selected · Actual production capture, 9 September 2026, 21:37 UTC. Click to enlarge.

The Left Rail Is the Workbook Boundary

A registered-workbook selector is above searchable tab navigation. The UI prioritizes John Deere by a stable known identifier, then sorts other titles and IDs. It remembers an explicit selection in forgelessons.selectedWorkbook, but restores it only if the API still authorizes that workbook. Storage failure degrades gracefully; a saved preference never grants access.

The Main Panel Is a Review Surface

The heading names the selected tab. Metrics, locale selection, search, status filters, and a row table support triage. English and target text remain side by side. The live guest view shows Strings only, while paid and editing controls are disabled. The layout is a localization workbench, not a lesson player.

Same live workspace after selecting Canadian French; a different locale is not a different workbook
Same live workspace after selecting Canadian French; a different locale is not a different workbook · Actual production capture, 9 September 2026, 21:37 UTC. Click to enlarge.
Live About page: workflow narrative and accessible section tabs
Live About page: workflow narrative and accessible section tabs · Actual production capture, 9 September 2026, 21:37 UTC. Click to enlarge.
Live optional login route: sign-in form and separate read-only guest entry
Live optional login route: sign-in form and separate read-only guest entry · Actual production capture, 9 September 2026, 21:37 UTC. Click to enlarge.

The About page has Workflow, Architecture, Tech Stack, Data Schema, Design Choices, Development, and People & Links tabs. Its source supports arrow-key navigation, Home/End keys, tab/tabpanel semantics, and a recognized initial URL hash. These are documentation sections; they are not additional application workflows.

Evidence: fresh production screenshots; src/pages/LessonsPage.tsx, src/pages/AboutPage.tsx, src/components/SiteHeader.tsx.

Feature Inventory and Boundaries

Registered Workbooks and Tabs

Administrative registration verifies Google metadata before creating a workbook record. Existing registration alone does not grant anonymous access: shared reads also need an explicit server-side allowlist. Metadata selection and tab requests are tied to the selected workbook. Tab changes clear stale displayed state; request versioning prevents a late response from replacing a newer tab.

Exact Regional Targets

The supported locales are pt-BR (Brazilian Portuguese), es-419 (Latin American Spanish), and fr-CA (Canadian French). The mapper recognizes existing workbook header aliases such as Portuguese(pt) and Spanish(es). Those are mapped, not renamed. A missing locale column is an explicit unsupported target, not permission to alter the spreadsheet schema.

Search, Filters, and Pagination

Search checks key, English, and selected target text. Filters expose missing translations, changed source, reviewed/locked targets, and protected formula cells. Visible rows are paginated at 25 per page. The source distinguishes target existence from correctness: “translated” means nonempty, not linguistically validated. Source-change and reviewed-stale indicators are separate concepts.

Manual Target Proposal

Edit opens a dialog with locked English and an editable target. Creating a proposal stores the intended text and original cell identity/value/hash; it does not write to Google. The proposal panel shows source, before/after, locale, type, status, and timestamp. A user separately confirms “Approve & write this cell.”

Reviewed Locks

A nonempty target can be marked reviewed. The lock records source hash and target value; stale review is detectable when either changes outside the app. Protected or reviewed targets are excluded from AI candidate selection. Unlock is explicit. A lock expresses human review, not an AI quality score.

AI Modes

Localize missing selects eligible blanks. Spell & grammar selects existing eligible targets. AI check scopes proofreading to one source row. Redo lesson regenerates existing targets and blanks across the whole selected tab; Redo step scopes that operation to exactly one keyed row. Every mode targets one selected locale and produces proposals rather than direct edits.

Context and Glossary

Operators supply manufacturer, machine, reference excerpts/instructions, and source/locale/target glossary entries. Workbook defaults can be replaced by a tab-specific context object. The UI can append a proposal correction to the glossary editor, but it must be reviewed and saved to persist. Existing jobs keep their frozen context rather than inheriting later corrections.

History and Undo

History records write intent and verified or uncertain outcomes. “Preview undo” creates a reverse proposal only for a verified write, subject to current key/column/tab/value checks. Undo is not an immediate rollback button. The reverse proposal requires its own exact apply approval and read-back.

Workflow Pagination

The server returns proposals, jobs, and history in workbook-scoped pages of 200 records, sorted through the store. “Load more workflow records” appends another page. The browser separately filters displayed workflow records to the current tab. This is independent of the 25-row translation-table pagination.

Shell and Support

The current committed router redirects root to /home, serves the localization page and /about, and shows a not-found page elsewhere. It retains shared theme/zoom/tooltips conventions. A standalone source repository, CI configuration, and migration guide now replace dependency on a sibling ForgeApps checkout.

Evidence: src/pages/LessonsPage.tsx, src/App.tsx, server/http.ts, server/domain.ts, server/ai.ts, server/localizer.ts.

Architecture: One App, Two Data Stores

Browser · React

Workbook, tab, locale, row selection
Review dialogs and explicit confirmations
One-cell job dispatcher

↓ HTTPS / JSON
Vercel · TypeScript API

Guest-read gate or authenticated membership
Origin checks → Localizer / AI / Jobs
Lease, intent, reservation, validation

Google Sheets

Authoritative keys, English, target cells
Formatted reads + formula reads
RAW single-cell write and fresh read-back

Supabase / PostgreSQL

App-owned workflow tables
Membership and global lease
Fenced commits and paid-attempt reservations

OpenAI Responses

Server-selected model and rates
Strict JSON translation output
Provider usage and response receipt

The browser does not hold the Google service-account key, OpenAI key, or Supabase service-role key. The API exposes browser-facing Supabase configuration for sign-in but performs business mutations server-side. Service configuration is injected through Doppler; a source extraction is not a migration of those external services.

Presentation and Build

Declared dependencies include React 18.3.1, React Router 6.30.2, TypeScript 5.9.3, Vite 5.4.21, Tailwind 3.4.19, Radix, next-themes, and Supabase JS. These are declared ranges, not a fresh lockfile-resolution audit. Node 24 is the standalone engine. The local workspace retains packages/tooltips and packages/vite-react-singleton; their previous package histories were not imported.

HTTP and Hosting

A shared handleApi function is called from the catch-all entry and explicit nested job entries. Vercel rewrites API requests to the server function before a negative-match SPA fallback. Functions allow 300 seconds. Local Vite development provides the API; static vite preview does not. There is no cron, detached worker, or SQLite runtime in this delivery.

Google Adapter

The server signs an RS256 service-account assertion, exchanges it for an OAuth token, and uses the Sheets API. Each tab is read once as formatted values and again as formulas so displayed strings do not conceal protected formulas. Writes use valueInputOption: RAW and an escaped sheet title plus exact row/column address. Requests have timeouts; the adapter includes per-instance throttling.

Provider Adapter

AI uses the Responses endpoint, strict JSON Schema containing only a translation string, store:false, and a standard/default service tier. Instructions explicitly treat source text, glossary, and context as untrusted data. App-prefixed settings override legacy localizer settings. The actual current model is environment-selected; this report does not infer live authenticated provider configuration from documentation or guest status.

Evidence: package.json, MIGRATION.md, vite.config.ts, vercel.json, server/google.ts, server/config.ts, server/ai.ts.

Persistence and Concurrency in Detail

ForgeLessons does not copy the workbook into a new canonical content database. It stores the supporting workflow by typed record kind and identifier, then reads current Google values when validating a proposal or executing a step. This separation allows the existing sheet workflow to continue, but it also means freshness and external-edit conflicts are fundamental design concerns.

forgelessons_records

Composite primary key (kind,id), JSONB payload, update timestamp, and a workbook/kind lookup index. Record kinds are constrained by SQL.

forgelessons_members

Composite key on Supabase user and workbook. Role is member or admin. A user account alone does not authorize a workbook; registration requires admin membership.

forgelessons_lease

A singleton row stores owner and expiry. Claim grants a 300-second lease. Mutating operations carry the owner token; expired or superseded owners cannot commit.

sheets
Registered workbook title and context defaults / tab contexts.
sources
Per-cell source baseline hashes. Cell identity combines workbook, numeric tab, row, key hash, and locale.
locks
Reviewed source/target snapshot and audit metadata; used to block changes and identify stale reviews.
proposals
Before value, proposed value, immutable source snapshot, row/key/column/tab identity, type, and application status.
history
Durable write intent and verified or uncertain result, linked to the originating proposal.
jobs
Frozen cell queue, context snapshot, estimate, run allowance, per-item status, and last error.
usage
Daily reserved tokens/dollars and actual returned usage. Optional all-days reservation caps accumulate across daily records.
attempts
Reservation written before transport; returned model, provider response ID, usage, rate basis, and outcome when known.
migration
The historical importer marker. It prevents repeating a one-time source import into a nonempty destination.

The four app RPCs are forgelessons_claim, forgelessons_release, forgelessons_commit, and forgelessons_reserve. The migration enables row-level security and revokes direct table/function privileges from anonymous and authenticated browser roles, granting the service role the needed access. The application then implements user/workbook authorization before using that privileged backend.

The store commits explicit record batches under the lease rather than loading and flushing an entire database snapshot. Reservations and write intent become durable before their external side effects. A lease reclaim is not permission to replay an uncertain Google write or paid request. This is a deliberate safety tradeoff: bounded serial execution and manual investigation are preferred to duplicate work or silent data corruption.

Evidence: supabase/migrations/20260908_forgelessons_workflow.sql, server/store.ts, server/auth.ts, server/localizer.ts.

Operator Flows, Step by Step

01 · Read a Shared Workbook

  1. Open /home. The browser obtains sign-in configuration and then requests state.
  2. Without an authorization header, the server considers the explicit shared-read allowlist and returns only registered allowed workbooks.
  3. Choose a workbook; metadata supplies its tabs. Choose a tab and regional locale.
  4. The server reads live formatted values and formulas, maps columns, and returns source/lock flags without creating new source baselines or acquiring a workflow mutation lease.
  5. Search, filter, paginate, or refresh. Guest state omits proposal, job, history, and audit identity payloads; controls do not grant paid/write access.

02 · Make and Apply a Manual Change

  1. An authenticated workbook member selects an editable, non-formula, unlocked target.
  2. The edit dialog preserves source English and sends row/key, source hash, current target value, locale, and proposed text to POST /api/preview.
  3. The server reloads the cell, checks source/target freshness and identity, validates protected tokens and casing, then saves a ready proposal.
  4. The operator reviews the before/after and explicitly approves POST /api/apply with confirm:true.
  5. With writes enabled, the server reloads and rechecks the tab title, key, source hash, target value, target column, reviewed state, and competing uncertain/in-flight writes.
  6. A history record and proposal transition to writing atomically before the Google request.
  7. The target is written as RAW text. Fresh read-back must match value and schema/source identity. Success records verified history and an applied proposal; failure records uncertainty rather than claiming success.

03 · Generate a Batch Safely

  1. Select missing, proofread, or redo scope. Eligibility excludes source formulas, target formulas, reviewed targets, and unmapped columns.
  2. Create a draft queue, freezing source hashes, current targets, keys, locale, and context. The first 20 tab source strings, truncated to 500 characters each, provide neighboring context.
  3. Review the conservative whole-queue estimate. Explicit Start approval is distinct from later Google write approval.
  4. The job becomes running only if the provider is configured, no other batch is running, and no requesting/uncertain item requires investigation.
  5. The browser checks for running work on a four-second interval but prevents overlapping dispatch from that page. Each request awaits at most one cell.
  6. Before transport, the server checks unresolved proposals and live source/target/schema, stores requesting state, decrements run allowance, and reserves usage durably.
  7. The provider returns structured text. Translation validation runs again. The result becomes a reviewable proposal; it does not modify the sheet.
  8. Closing the page stops new dispatch. Pause stops this page’s new dispatch and waits for in-flight work before persisting pause; other open clients must also stop if they are driving the job.

04 · Redo Lesson Versus Redo Step

A “lesson” is the entire selected workbook tab, not the visible search result or current page. A “step” is one source row. Redo includes both existing text and blanks for the selected locale, while respecting reviewed/formula protection. Invalid or conflicting scope is rejected instead of widened. Queues larger than 10,000 cells fail explicitly.

Redo Start approves the frozen queue across durable bounded chunks. Missing/proofread use a per-run allowance and require explicit resume when that allowance is exhausted. The operations guide describes a 20-cell configured chunk/run ceiling and a 1,000,000-token daily ceiling; actual limits are environment-dependent. Redo does not remove daily caps, skip an unresolved row silently, or turn into automatic sheet writes.

05 · Review, Undo, and Context Correction

Mark a nonempty target reviewed only after checking it. A later mismatch makes that review stale. To correct a locked value, explicitly unlock it. To reverse a verified write, preview undo, review the resulting reverse proposal, and separately apply it. To reuse a correction, add it to the glossary editor and save the appropriate workbook or tab context; a running job continues with its original snapshot.

Evidence: src/pages/LessonsPage.tsx, server/http.ts, server/shared-read.ts, server/localizer.ts, server/ai.ts, OPERATIONS.md.

Protection Rules and Their Limits

Schema and Control Rows

The mapper searches the first 20 rows for supported Key/English headers. Duplicate alias matches are rejected as ambiguous. Blank key/source rows and DateVersion/SemanticVersion control keys are excluded. Formula detection comes from the separate FORMULA read, not a guess based only on display text.

Translation Shape

Targets must contain 1–20,000 characters. Formula-like text beginning with =, +, or @ is blocked. Protected number/unit/placeholder/escape/markup token sets must match; markup order must match separately. Casing heuristics preserve all caps, lowercase, title case, and sentence case patterns. These are deterministic guardrails, not a semantic proof of translation quality.

Freshness and Identity

Each proposal is tied to the original value, source hash, key, row, tab title, and column. Changed data blocks apply. Historical undo has its own schema checks. An unresolved proposal can block regeneration for the same cell; uncertain writes block a second proposal from bypassing investigation.

Authorization

Shared GETs are explicitly scoped and read-only. Other operations require a validated Supabase identity and workbook membership; registration needs admin. Mutation routes check JSON content type and the allowed production origin https://lessons.forgefx.dev. The alternate verified domain is not automatically added to that origin allowlist in the inspected source.

Paid Usage

The estimate uses serialized UTF-8 payload byte length plus a buffer as a conservative input-token proxy, and the configured maximum output. Reservations occur before the call and remain across failures. Reported actual usage uses returned token counts and configured rates; it is not provider-invoice reconciliation. Response receipt data strengthens auditability but does not eliminate uncertain transport outcomes.

Prompt Boundary

The AI instructions tell the provider to treat glossary, references, keys, and source strings as untrusted data, preserve product/manufacturer names and technical tokens, and return only JSON. The deterministic validator checks several structural invariants afterward. Human review is still required for technical meaning, natural regional phrasing, and terminology consistency.

No cross-system transaction exists. The Google checks are optimistic. An external editor can race between the app’s final read and write. The database lease coordinates ForgeLessons operations, not Google’s other editors. Exact read-back detects many mismatches after the event; it is not a compare-and-swap guarantee.

Evidence: server/domain.ts, server/auth.ts, server/localizer.ts, server/ai.ts, server/google.ts.

Evolution: From Port to Standalone

The history has two repositories and two sets of hashes. Extraction rewrote the app’s retained commits. The standalone migration file says eight app-scoped commits were retained at extraction and the local shared packages were included as snapshots. Do not cite a rewritten standalone SHA as if it were the same identifier in ForgeApps.

Phase 1 · The Initial Port

The first visible app commit lands the original Sheet Localizer workflow and the new ForgeLessons app in the monorepo on 8 September. The intended change is architectural: keep Sheets authoritative and preserve review protections, but replace the earlier local SQLite workflow storage with Supabase and adopt the standard React shell. Because the first import contains a substantial working app, this Git timeline is not a minute-by-minute account of earlier design or implementation.

Phase 2 · Make the Hosted Paths and Access Model Match the Workflow

Follow-up commits address emitted server imports, local entry, About documentation, API fallback handling, shared reads, optional login, a second workbook, and workbook-scoped requests. The sequence shows why homepage uptime was not enough: an HTML SPA fallback could impersonate a successful API response, and a rendered sign-in screen could still conflict with an agreed shared-view workflow.

Phase 3 · Extract, Then Reconcile

Standalone 7e3fa74ee removes dependency on the larger app workspace, adds local packages and standalone checks, and preserves the app history. c65c43766 explicitly routes API requests to the server function. 0e790cfe5 then integrates the more recent remote monorepo work: redo queues, remembered workbook choice, shared reads, header authentication, scoped provider settings/receipts, and explicit nested job functions. This reconciliation matters because the extraction source had lagged the remote app work.

Phase 4 · Source Versions Advance Beyond the Serving Build

The .1, .2, and .3 standalone releases are version-only commits at the inspected tip. Vercel marked all three blocked while the reconciled .0 deployment remained ready and visibly served .0. This is a deployment-state discrepancy, not evidence that the newer version adds missing features. The inspection did not establish the specific deployment blocker cause.

Monorepo Commit Ledger

2026-09-08T21:56:30-10:00 8dfd3e8c6

feat: land localization apps and accumulated skill updates

First visible app import: React shell, API/domain/store/AI code, SQL migration, scripts and tests land together. This is the first preserved repository evidence, not proof that the idea began that day.

2026-09-08T22:23:19-10:00 2f26ca322

fix(forgelessons): use emitted server import paths

Corrects server imports to emitted .js paths, addressing the distinction between TypeScript source resolution and deployed Node output.

2026-09-08T22:40:23-10:00 617212398

fix(forgelessons): register launcher and add local guest entry

Registers the local launcher and adds loopback guest/operator entry. Local bypass is distinct from production anonymous read access.

2026-09-08T22:47:00-10:00 91cf49fae

fix(forgelessons): standardize About page and record hosted audio

Standardizes the About page and records hosted audio work; it does not establish an end-user narration authoring pipeline.

2026-09-08T22:50:23-10:00 684411e39

docs(forgelessons): add detailed architecture and project reference

Expands architectural/project documentation inside the app.

2026-09-08T22:55:07-10:00 84af174c8

feat(forgelessons): tab About sections and credit Miguel as lead

Organizes About into accessible sections and identifies Miguel as lead.

2026-09-08T22:57:39-10:00 03e632d73

chore(forgelessons): bump to 2026.09.08.1 with scoped budget approval

Updates version to 2026.09.08.1 and records scoped budget approval.

2026-09-09T07:28:19-10:00 cc0380aaf

fix(forgelessons): keep API requests out of SPA fallback

Fixes API traffic falling into the SPA HTML fallback. A 200 shell response had not proved API correctness.

2026-09-09T07:37:22-10:00 f9170ab2d

fix(forgelessons): restore allowlisted anonymous workbook reads

Restores explicitly allowlisted anonymous workbook reads, without anonymous proposals, administration, or paid generation.

2026-09-09T07:43:59-10:00 a266c07b4

feat(forgelessons): add optional login and shared-read logo entry

Makes login optional for shared viewing and adds the logo-based guest entry.

2026-09-09T08:18:36-10:00 4f7cc60ea

fix(forgelessons): enable approved Halliburton workbook and safe discovery

Adds approved Halliburton workbook support and safer discovery behavior.

2026-09-09T08:26:19-10:00 9280159f9

fix(forgelessons): scope tab requests to the selected workbook

Scopes tab requests to the chosen workbook, preventing stale selection/request crossovers.

2026-09-09T08:37:40-10:00 e81b838a0

feat(forgelessons): enable scoped approved operation and nested job routes

Adds scoped approved operations and explicit nested job routes, keeping business logic in the shared authenticated handler.

2026-09-09 · remote-only retirement f6f76a711 e6e510fcf

Retire the Monorepo Workspace

Remove the app package, launcher/build registration, and workspace lockfile entry; move the surviving migration pointer outside apps/. These commits were visible on remote-tracking main/dev but absent from the stale local HEAD used for the initial filesystem inspection.

Standalone Commit Ledger

All commits reachable from the pinned standalone tip are listed below, including rewritten provenance. Timestamps retain their recorded offsets rather than silently normalizing chronology by display date.

2026-09-08T21:56:30-10:00 5c48564f1

feat: land localization apps and accumulated skill updates

2026-09-08T22:23:19-10:00 4274becf9

fix(forgelessons): use emitted server import paths

2026-09-08T22:40:23-10:00 963d48113

fix(forgelessons): register launcher and add local guest entry

2026-09-08T22:47:00-10:00 4c2a133f8

fix(forgelessons): standardize About page and record hosted audio

2026-09-08T22:50:23-10:00 8cfe97e5a

docs(forgelessons): add detailed architecture and project reference

2026-09-08T22:55:07-10:00 46cfd4fb4

feat(forgelessons): tab About sections and credit Miguel as lead

2026-09-08T22:57:39-10:00 1bef7d756

chore(forgelessons): bump to 2026.09.08.1 with scoped budget approval

2026-09-09T07:19:31-10:00 24a67af7c

fix(vercel): close attribution guard holes for forgelang, forgelessons, sheet-localizer

2026-09-09T10:00:12-10:00 7e3fa74ee

feat: make ForgeLessons a standalone ForgeFX repository

2026-09-09T10:00:57-10:00 a0d6417af

chore: release standalone ForgeLessons 2026.09.09.0

2026-09-09T10:05:04-10:00 c65c43766

fix: route API requests to the server function

2026-09-09T10:08:50-10:00 0e790cfe5

feat: preserve latest monorepo lessons workflow

2026-09-09T16:52:43-04:00 d86e973af

chore: bump ForgeLessons to 2026.09.09.1

2026-09-09T17:00:33-04:00 1595245a0

chore: bump ForgeLessons to 2026.09.09.2

2026-09-09T17:23:09-04:00 a456b31c9

chore: bump ForgeLessons to 2026.09.09.3

Evidence: read-only git log, git show, and diff inspection in both repositories; MIGRATION.md. The monorepo ledger is path-scoped to the local HEAD history plus explicitly read remote retirement commits, not a claim to enumerate every wider-repository change.

Limitations, Risks, and What Matters Next

01 · PRODUCT ACCEPTANCE

No-Login Viewing Is Not No-Login Operation

The real guest workspace is usable for reading, but guest editing, administration, and AI are explicitly unavailable. Earlier curated product context describes a preference for no personal login. The current server boundary therefore does not establish acceptance of a fully no-login editing/AI workflow. Any future change must separately define allowed writes, paid usage, and administrative scope rather than making a logo click an authorization mechanism.

02 · RELEASE RELIABILITY

Blocked Releases Need Their Own Diagnosis

The standalone Git link and domains are configured, but three newer deployments were blocked at inspection. Resolve the actual platform restriction and verify the exact serving SHA/version after a successful release. Do not label source “deployed” because it reached main, and do not infer the blocker from author metadata alone.

03 · CONTENT QUALITY

Nonempty Does Not Mean Correct Locale

The fresh pt-BR tab read included Out_Of_Bounds_Failure Name with Échec hors limites and Out_Of_Bounds_Failure Description with Se movió fuera del área operativa designada. Those appear to be French and Spanish text in the selected Portuguese target. The UI marked them translated because they were nonempty. This observation is a review lead, not a complete language audit or a claim that ForgeLessons authored those cells. No corrections were applied.

04 · WORKFLOW SAFETY

Uncertainty Is an Operator Task

Interrupted paid calls and ambiguous writes intentionally stop progress and retain reservations. There is no blanket replay/reset button. Operational recovery needs evidence from provider receipts, live cells, and history before resuming; automatic retry would undermine the safety model.

05 · SCALE

Serial Global Lease and Browser Dispatch

A singleton lease serializes mutations across instances, and one running batch is enforced globally by the source. This limits concurrency across users/workbooks. Several operations scan whole record kinds in paged lists, and tab loads read whole tab ranges twice. The combination favors controlled workloads over high-throughput enterprise orchestration; no performance benchmark was performed.

06 · VALIDATION

Structural Checks Are Not Linguistic Review

Numbers, units, placeholders, markup, and casing checks help prevent damaging changes. They do not prove semantic equivalence or correct regional language. Strict English-derived capitalization can also be a constraint a reviewer needs to understand. A glossary and machine context improve consistency but do not replace qualified technical review.

07 · SCHEMA

Missing Columns Are Not Auto-Created

Redo and localization reject absent target columns with an actionable message. The operations guide specifically keeps unapproved Halliburton schema additions out of scope. Resolving a missing locale column requires separate administrator-approved workbook work, followed by refresh.

08 · ROADMAP

Authoring and Field Capture Remain Separate

Earlier product context describes creating lessons, adding/reordering steps, programmer notes, phone speech-to-text, and onsite photos. These are not implemented features of the pinned router/domain/workflow inspected here. There is no verified direct Word/SharePoint ingestion, Unity synchronization, narration generation, or field-capture pipeline in this app snapshot. Related tools or meeting discussions do not prove an integration exists.

Recommended acceptance order: verify serving release and authenticated boundaries; exercise one bounded real AI proposal in an isolated authorized test tab; independently verify a reviewed apply and a separately approved undo; then assess content-language quality and broader authoring scope. Those are recommendations, not operations performed by this report.

What the Evidence Proves

Freshly Verified

Read-only Git history and source inspection in both repositories; extraction pointer and reconciled standalone history; version-only delta; Vercel Git connection, Node runtime, domain verification, deployment statuses; real anonymous production Home/About/login renders; locale switching; live JSON state and nested-route authentication response; zero uncaught page errors in the captured browser session; no desktop horizontal page overflow on the captured app workspace.

Reported Historical Checks

MIGRATION.md records that local build, lint, 21 UI tests, and 49 server tests passed after reconciliation. This report did not rerun those commands or independently validate the historical count. Existing coverage artifacts in the stale monorepo were not used as proof of current test health.

Test Design Found in Source

The repository separates Vitest UI tests from Node server tests. Named suites cover domain/token rules, auth/origin, request body parsing, routes, shared reads, storage, budget reservations, proposal/apply/undo workflow, redo, workbook preference, and header authentication. Browser and Supabase verification scripts are separate from mocked unit tests. Merely having these files is not a passing test result.

Deliberately Unverified

Authenticated writes and paid calls; actual live provider model/rate settings; all workbook tabs and all target cells; translation quality across the corpus; credential rotation; production database migration internals; load/concurrency performance; complete no-login workflow acceptance; later concurrent implementation work.

The first browser-helper attempt timed out. The researcher used installed Chrome through Playwright for the actual production capture and report QA rather than presenting a simulated interface. The report embeds original captures; it does not reconstruct the app with invented example rows.

Source Map and Reproduction Notes

Source links below are pinned to the reviewed standalone commit, not a moving branch. The repository is private, so readers need GitHub access. Commit links in the chronology distinguish standalone and ForgeApps provenance explicitly.

Evidence Package

The local research package is under /tmp/forgelessons-research/. This report uses history-live-evidence.json, history-commits.json, and the four live-*.png captures. The source generator is history-build.mjs; the browser capture is history-capture.mjs. The exact source snapshot is preserved through pinned citations rather than copying secrets or the private repository into this page.

Scope and Exposure

This standalone preview is authorized technical/business context, not a confidential raw transcript archive. It contains no credential values, access tokens, staff-private context, or raw meeting transcripts. It is link-accessible external hosting, not an authenticated document. Crawler noindex/nofollow metadata is advisory and cannot enforce access control. The report should not be treated as a current health monitor.