feat(zcode): integrate PowerContext with ZCode CLI and Windows desktop - #1752
jackie-cqz wants to merge 10 commits into
Conversation
Teingi
left a comment
There was a problem hiding this comment.
Three issues remain in automatic prompt capture and ZCode diagnostics; details inline.
| const MAX_CONTEXT_BYTES = 8_000 | ||
| const MAX_QUERY_CHARACTERS = 8_192 | ||
| const MAX_SOURCE_CHARACTERS = 200_000 | ||
| const SECRET_PATTERN = /(?:\b(?:api[_-]?key|access[_-]?token|token|authorization|password|secret|private[_-]?key)\s*[:=]\s*\S+|\bbearer\s+\S+|\bsk-[A-Za-z0-9_-]{8,}|-----BEGIN [^-]*PRIVATE KEY-----)/iu |
There was a problem hiding this comment.
[P1] Exclude quoted credential keys from automatic Source capture
The key alternative only allows whitespace before : or =, so the closing quote in JSON bypasses this filter. With default capture enabled, {"password":"synthetic-password-for-review"} and {"access_token":"synthetic-token-for-review"} were posted verbatim to /v1/sources/content, while password=synthetic-password-for-review was correctly skipped. Ordinary pasted JSON configuration can therefore persist credentials as Source evidence. Handle quoted credential keys before automatic capture and cover these JSON forms alongside unquoted assignments.
| for await (const chunk of process.stdin) { | ||
| raw += chunk |
There was a problem hiding this comment.
[P2] Decode stdin as a continuous UTF-8 stream
process.stdin yields Buffer chunks, and raw += chunk decodes each independently. A multibyte character crossing a read boundary becomes replacement characters. On Node 24, a single stdin write containing 100,000 Chinese characters produced corrupted capture content; splitting a short valid payload inside 中 also changed its Source ID despite identical session, turn, and input. This corrupts Source evidence and makes retry identity depend on pipe boundaries. Use a streaming UTF-8 decoder or concatenate the bytes before decoding.
| endpoint = _url(_selected_url(host, prefix, native_url)) | ||
| if native_url and native_url != endpoint: | ||
| raise ValueError("Cannot determine a single PowerContext transport: ZCode Hook and MCP URLs differ") # noqa: TRY003 |
There was a problem hiding this comment.
[P2] Match the Hook's saved-URL precedence in doctor
_selected_url() prioritizes environment URLs over powercontext.json, but the installed Hook and MCP both keep the saved URL. With a healthy installation and a stale POWERCONTEXT_ZCODE_SERVER_URL=http://127.0.0.1:1, doctor zcode --json reports all five installation/readiness checks as OK, then adds this false transport mismatch and exits 1. Resolve diagnostics using the Hook's actual precedence so an unused fallback environment variable cannot mark a working installation as broken.
|
@Teingi please review again. thx. |
Which issue or RFC does this PR close?
Closes #1751.
Rationale for this change
ZCode users need a repeatable way to capture project conversations as PowerContext Sources, generate Memory, and recall it in a fresh session. The integration also needs to expose PowerContext MCP operations without requiring users to manage separate Hook and MCP endpoints.
What changes are included in this PR?
UserPromptSubmitHook, PowerContext MCP declaration, and project-context skill for the open-source CLI and official Windows desktop edition.powercontext setup zcodeanddoctor zcode. Setup preserves unrelated ZCode settings, installs a managed plugin copy, and keeps Hook and MCP on one Server URL.Are there any user-facing changes?
ZCode appears as an experimental community integration. Setup writes to the user's ZCode plugin configuration and requires a ZCode restart. No HTTP API or persisted artifact format changes are introduced. Bearer authentication is supported through the ZCode process environment. Cross-machine HTTPS has been validated through an SSH port forward; direct HTTPS ingress and other official desktop versions have not been validated.
How was this change tested?
python -m pytest -q tests/test_cli_zcode.py tests/test_mcp.py tests/e2e/test_zcode_service_chain.py: 19 passed.python -m pytest -q tests/test_integration_manifest.py: 29 passed; generated capability documentation is current.node --test integrations/zcode/plugins/powercontext/tests/plugin.test.mjs integrations/zcode/plugins/powercontext/tests/host.test.mjswithZCODE_CLI_BINset: 12 passed.ty checkpassed for changed Python files. Full-repositoryty checkon Windows still reports existing POSIX-only symbol diagnostics in unrelated modules; Linux CI remains to be run.list_scopesagainst the remote Server, and its ordinary prompt was captured as a Source that was read back from the same remote Scope. Direct TLS on the remote listener could not be validated on the current network path because the handshake failed.AI usage statement
OpenAI GPT-6 assisted with implementation, tests, documentation, and analysis of local validation results. The user performed the official ZCode desktop interactions and supplied the observed tool results.