# Gift Graph Bug Tracker
> Gift Graph - Known issues, build-night surprises, and their resolution status. Platform findings that belong to Replit rather than Gift Graph are marked and also live as Product notes · FDE feedback in the [[Project - Gift Graph/Build & Iterate/Build Log|Build Log]].
> Last Updated: 2026-10-08
## Format
Each bug follows this structure:
- **ID:** Unique identifier (BUG-XXX)
- **Status:** `Open` | `In Progress` | `Resolved` | `Won't Fix` | `Platform`
- **Severity:** `Critical` | `High` | `Medium` | `Low`
- **Description**, **Root Cause**, **Resolution**
## Open Issues
### BUG-023: A New Domain Signs a Person In to an Empty Account
**Status:** Open
**Severity:** High
**Reported:** 2026-10-08
**Related:** [[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-039|Technical Decisions > TDR-039]], [[Project - Gift Graph/Build & Iterate/Build Log|Build Log]]
**Description:** My first sign-in on giftgraph.aleksandar.app showed an empty dashboard, with no secrets, no connections, and no agents. A sign-in on the old host two minutes later showed my three secrets, Justin, and Claude.
**Root Cause:** In production the server builds the Clerk key from the request's host, `clerk.<host>`, which gives each domain its own issuer in the session. Accounts are keyed on the issuer and the Clerk user together, and the new issuer made a second account for the same person.
**Resolution:** Key accounts on the Clerk user alone and fold the empty account into the real one, rehearsed on a branch of production first. Until it ships, Justin and I sign in at gift-graph.replit.app.
**Platform note:** Replit's Clerk integration derives the key from the host, and the Domains flow says nothing about sign-in. An app that keys users on the issuer splits its people the day it adds a domain.
![[gift-graph-bug-new-domain-empty-account.png|560]]
*Signed in on giftgraph.aleksandar.app · the empty second account*
### BUG-024: Codex Shows a Second Row at Each Sign-In
**Status:** Open
**Severity:** Low
**Reported:** 2026-10-05
**Description:** Codex registers itself as a new OAuth client at every sign-in, and Your agents shows a second Codex row until I disconnect the first.
**Resolution:** Match a new registration to an earlier row by name and callback host, with care for one agent on two machines, and prune clients that never finished a sign-in. In the backlog.
## Platform Findings (Replit)
### BUG-019: Git Pane Pull Stalled Mid-Rebase
**Status:** Platform
**Severity:** Medium
**Reported:** 2026-10-05
**Description:** On a workspace with commits GitHub lacks, Pull rebased by default, stopped on a conflict in `docs/build-log.md`, and left the pane reading "Unsupported state: you are in the middle of a rebase," with no way forward from the pane itself. It happened twice.
**What would help:** A choice of merge or rebase before pulling, Abort and Resolve in the pane when an operation stalls, and a preview of which files will conflict. My workaround is a merge by commit through Agent, with standing rules for Git in `replit.md`.
![[gift-graph-replit-34-git-rebase-stalled.png|480]]
*The Git pane after Pull · no way forward from the pane*
### BUG-016: Publish's Schema Review Cannot Be Skipped
**Status:** Platform (worked around 2026-10-03)
**Severity:** High
**Reported:** 2026-10-03
**Related:** [[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-024|Technical Decisions > TDR-024]]
**Description:** The first publish through the self-migrating loop failed at Replit's schema review, which could not add the level foreign key over production's old rows and offered no way to skip the step. Nothing in production changed.
**What would help:** A way to hand the schema to the app's own migrations. My workaround is a constraint over existing rows in two publishes, or a reset while the data is test data, which is how 006 went out.
### BUG-002: Plan Gate Bent by Ambiguous Text
**Status:** Platform
**Severity:** Medium
**Reported:** 2026-09-30
**Description:** With Revise selected on the plan approval card, text opening "Approved with three additions" was read as approval, and Agent built without showing a revised plan. All three additions landed, nothing was lost.
**What would help:** Restate how the card was read before building whenever the selected option and the text disagree. Plan mode later did exactly this for the deployment fix, which is the contrast worth showing a security team.
### BUG-008: Deck Needs a Project Restructure, Flagged Late
**Status:** Platform
**Severity:** Low
**Reported:** 2026-10-01
**Description:** The slide deck was offered from the publish screen, the outline was scoped and approved, and only then did Agent report that the viewer needs a multi-artifact layout and ask to move the live server.
**What would help:** Flag the structure change when the feature is offered, and offer to build the deck as a separate project that leaves the live app untouched.
## Resolved
### BUG-022: The Demo's Level Switch Did Nothing
**Status:** Resolved (2026-10-07, v0.6.2)
**Severity:** Medium
**Description:** Changing a level on the demo page left the story unchanged.
**Root Cause:** The demo wrote `level` onto a row whose field is `tier`, left behind by the rename.
**Resolution:** The audit found it, and a one-line fix went out in v0.6.2.
### BUG-021: Test Runs Hung for Eight and Sixteen Minutes
**Status:** Resolved (2026-10-07)
**Severity:** Medium
**Root Cause:** `schema.sql` still seeded the two identities against the new users check, the setup threw, and the open pools kept the process alive. Two runs shared one database, and a wait loop polled a file from a killed run.
**Resolution:** The seed is gone, runs go one at a time behind a preflight that checks the database answers and nothing is in flight, and every long run gets a check every two minutes.
### BUG-020: An Email Request Showed Whether an Address Had an Account
**Status:** Resolved (2026-10-07, before release)
**Severity:** Critical
**Related:** [[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-036|Technical Decisions > TDR-036]]
**Description:** The first build of requests by email opened a pending connection row when the address matched, and the requester could see the row and learn who had an account.
**Resolution:** The request lives on the owner's side alone until they answer, a decline claims it with no row made, and the answer is the same either way. Caught in review before any publish.
### BUG-018: Muse Took the Person It Hears for Its Account
**Status:** Resolved (2026-10-07, v0.6.1 inside v0.6.2)
**Severity:** High
**Description:** Justin's Muse read the connect note "You act for justin.calles. You hear Aleksandar A (gg_…) at Hint", told him his token belonged to me, and stopped before saving anything.
**Root Cause:** One line named two people, and the second read as the account.
**Resolution:** The account alone on the first line, with its ID, and the people it hears on a line of their own, labelled as other people.
![[gift-graph-muse-whose-account.webp|360]]
*Muse on Justin's phone, 2026-10-05*
### BUG-017: The Local Database URL Went Empty
**Status:** Resolved (2026-10-04)
**Severity:** Low
**Description:** `neon link` overwrote the local database URL without asking, and the first "test run against Neon" never reached Neon. An unquoted ampersand in the connection strings emptied both variables when the shell loaded them.
**Resolution:** Both strings single-quoted, `neon link` never rerun, and `database.md` says so.
### BUG-015: The Agent Held Three Identities in One Session
**Status:** Resolved (2026-10-03, then 2026-10-07)
**Severity:** Medium
**Description:** Claude Code carried three Gift Graph connections at once and had to guess which one spoke for me.
**Resolution:** The identity line at connect (2026-10-03), the account alone on its first line (2026-10-05), and the seeded identities retired with migration 009 (2026-10-07).
### BUG-014: The Form Picked the Nearest Label
**Status:** Resolved (2026-10-04)
**Severity:** High
**Description:** A bronze statue went out as art prints and tomatoes as premium food, since the vocabulary had nothing closer and the form chose for me.
**Resolution:** Labels became optional, a finder over the list joined the form, vocabulary version 2 went live, and the person's agent picks from the full list ([[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-026|Technical Decisions > TDR-026]]).
### BUG-013: Example Pill Overlapped the Table Header
**Status:** Resolved (2026-10-02, development preview)
**Severity:** Low
**Related:** [[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-020|Technical Decisions > TDR-020]]
**Description:** On the landing page the "Example · Mira would love a notebook" pill sat on the header row, clipping "Sharing level" and "What others can see." The pill was also oversized, and a stray comma trailed "notebook."
**Resolution:** Agent proposed a mock before touching code; I approved the mock. The header row gained about 26px of top padding, the pill shrank to about 26px tall with 13px text, and the comma went. Verified at 1280, 1440, and 390 wide.
### BUG-012: "The Service Could Not Load Your State"
**Status:** Resolved (2026-10-07, not reproduced; the path retired)
**Severity:** Medium
**Reported:** 2026-10-02
**Related:** [[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-017|Technical Decisions > TDR-017]]
**Description:** The owner dashboard in the development preview showed "The service could not load your state" on one sign-in, after the per-account IDs landed.
**Root Cause:** Unknown. The candidates are the migration state in the development database and the session exchange after the account change.
**Resolution:** Not seen again. The token-to-session exchange gave way to Clerk sign-in, and the legacy sign-in left with migration 009 on 2026-10-07.
### BUG-011: Landing Page Reads v0.2 While Production Is Gated
**Status:** Resolved (2026-10-03)
**Severity:** Medium
**Reported:** 2026-10-02
**Related:** [[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-015|Technical Decisions > TDR-015]]
**Description:** gift-graph.replit.app serves the first v0.2 landing page, with the owner dashboard button and the v0.2 copy, while the README says v0.2 does not publish or change production and points to a separate owner-reviewed process. The development preview has since moved further, to the whispers copy, accounts, and the demo.
**Root Cause:** The landing page is its own web artifact and can publish apart from the API migration.
**Resolution:** Production went to v0.4 at schema 006 on 2026-10-03 and has followed every release since. The app migrates itself at start ([[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-024|Technical Decisions > TDR-024]]), and v0.6.2 runs at schema 011.
### BUG-010: README and Repo Description Out of Date
**Status:** Resolved (2026-10-01, cleanup text provided)
**Severity:** Low
**Description:** The README still said "v0.1 in progress" and carried a colon sentence; the repo description read "Imported from zip."
**Resolution:** Description rewritten at creation. README replaced with the live status, how the tiers work, the seven tools, and the connection steps; the status line says "at deploy" until the tests pass in the new layout.
### BUG-009: Tests Not Re-run After the Multi-Artifact Restructure
**Status:** Resolved (2026-10-03)
**Severity:** High
**Reported:** 2026-10-01
**Related:** [[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-010|Technical Decisions > TDR-010]]
**Description:** Task #5 moved the server into `artifacts/`, `lib/`, and `scripts/` to make room for the deck viewer. The 12 integration tests passed before the move. The README now names the command, `pnpm --filter @workspace/api-server test`, against an isolated schema.
**Root Cause:** The restructure ran on a separate copy and was applied after the GitHub push; the live deployment still serves the pre-restructure build.
**Resolution:** Agent's GitHub rebuild ran 97 tests in the new layout on 2026-10-03. The local round on 2026-10-07 ran 85 API tests, 26 web tests, and 21 routing tests.
### BUG-007: Build Log Truncated Mid-Sentence
**Status:** Resolved (2026-10-01)
**Severity:** Low
**Description:** `docs/build-log.md` ended at line 51 inside the Build entry after a paste, and later feedback blocks landed in the wrong entry.
**Resolution:** The complete log was pasted once, with every feedback block in the session it came from. Replit auto-committed it as "Update build log documentation."
### BUG-006: Revoke and Reconnect Semantics Unconfirmed
**Status:** Resolved (2026-10-01, v0.2)
**Severity:** Medium
**Related:** [[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-013|Technical Decisions > TDR-013]]
**Description:** Agent's Unsure note said renewed approval restores access to drops made before a revocation, and the spec did not say whether a reconnect should start fresh.
**Resolution:** Withdrawal is permanent and survives reapproval; revocation blocks future pulls; reapproval cannot bypass the widening checks. Nothing retracts what an agent already received.
### BUG-005: Bearer Tokens Exposed in a Screenshot
**Status:** Resolved (2026-09-30)
**Severity:** Critical
**Description:** A Shell screenshot taken mid-build showed both freshly generated tokens, one highlighted.
**Resolution:** Both values rotated in Tools › Secrets after the build finished; the server reads them at runtime, which changed no code. Rule from here: `clear` the Shell before any screenshot, and generate tokens with `Read-Host` on the client side so they stay out of history.
### BUG-004: Claude Code 401 on the First Tool Call
**Status:** Resolved (2026-10-01)
**Severity:** Low
**Description:** The first demo prompt returned `401 authentication_error, OAuth access token is invalid`, retrying.
**Root Cause:** Claude Code's own sign-in had expired. The error shape is Anthropic's API format; the call never reached Gift Graph, and `claude mcp list` had already shown both servers connected.
**Resolution:** `/login`, then the prompt ran.
### BUG-003: Natural Prompts Miss
**Status:** Resolved (2026-10-03)
**Severity:** Medium
**Reported:** 2026-10-01
**Related:** [[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-005|Technical Decisions > TDR-005]], [[Project - Gift Graph/Build & Iterate/Feature Backlog|Feature Backlog]]
**Description:** A pull for "gift ideas about fonts" returned nothing while a drop with the category text "type and lettering" existed.
**Root Cause:** v0.1 matches literal words in the prompt against disclosed text only, and no word overlapped. The privacy model is working as designed; the cost is that natural prompts miss.
**Resolution:** Hearing returns everything the asker may hear, ranked, with matches first, and the asking agent reasons about fit ([[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-022|Technical Decisions > TDR-022]]). Embeddings wait until they beat the word list on a blind set.
### BUG-001: Publish Failed, "Could not find run command"
**Status:** Resolved (2026-10-01)
**Severity:** High
**Related:** [[Project - Gift Graph/Build & Iterate/Technical Decisions#TDR-007|Technical Decisions > TDR-007]]
**Description:** The first Publish failed although the app ran in the workspace.
**Root Cause:** The preview started the server through the dev workflow; a published deployment reads its own build and run commands from `.replit`, and that section was missing.
**Resolution:** Agent, in Plan mode, added build `npm run build` and run `npm start`, chose Autoscale after confirming the transport is stateless, and the republish went green. Platform note: Agent could set the deployment commands whenever it builds a server, or offer to set them from the error.