Skip to content

feat(datatug-apps): read-only per-space raw-data viewer (transparency PoC) - #31

Merged
trakhimenok merged 1 commit into
mainfrom
fable/datatug-transparency-viewer
Jul 2, 2026
Merged

trakhimenok merged 1 commit into
mainfrom
fable/datatug-transparency-viewer

Conversation

@trakhimenok

Copy link
Copy Markdown
Contributor

Summary

First slice of the DataTug "explore your own raw data" transparency viewer
(see backstage/docs/roadmaps/datatug-transparency-explorer.md, esp. §1.3
and §6 "S — first high-signal slice"). Adds a read-only, per-space Firestore
viewer inside datatug-apps, rooted at /spaces/{spaceId} instead of
DataTug's own datatug_projects/{id}.

  • New page: "Explore my raw data" (SpaceExplorerPageComponent,
    libs/datatug/main/src/lib/pages/signed-in/space-explorer/), routed at
    /explore/:spaceId (auth-guarded via SNEAT_AUTH_GUARDS, same as /my).
    Lets a signed-in user drill into their own space's raw Firestore subtree —
    breadcrumb navigation, one document's fields rendered as raw JSON, or one
    collection's documents listed — with shortcuts for the known
    ext/{module}/{collection} convention (contactus, listus,
    calendarius, assetus, eventius, …) plus a free-text field for any
    other collection name.
  • New service: SpaceExplorerService
    (libs/datatug/main/src/lib/services/repo/space-explorer.service.ts) —
    modeled on the existing DatatugStoreFirestoreService.watchProjectItem
    pattern (arbitrary-path docData/collectionData streaming under the
    signed-in user's own AngularFire session), but rooted at spaces/{spaceId}
    and using only Firestore's read APIs. Read-only by construction — it
    never imports/calls setDoc/updateDoc/deleteDoc/addDoc, documented
    with an explicit banner comment.
  • Reused, unchanged: the app's existing sneat-eur3-1 AngularFire
    auth wiring (init-firebase.ts, environment.prod.ts) and the existing
    spaces/{space}/{document=**} Firestore security rule
    (sneat-firebase/firebase/firestore.rules) — no backend, rules, or auth
    changes. Scoping ("only see your own space's data") is enforced
    server-side by the rule, same as the rest of the app.
  • Entry point: a "Space ID" input + "Explore" button added to the
    existing /my page. A real "my spaces" list isn't wired up in
    datatug-apps yet, so this PoC accepts a spaceId as a route param —
    noted in-code as a follow-up.

Known limitation (documented in code)

The Firestore client SDK cannot enumerate a document's subcollections
(unlike the Admin SDK's listCollections()) — that introspection is
deliberately not exposed client-side. So the tree browser can't show a
truly complete "here are all the child collections" list; it offers
well-known collection-name shortcuts (space-explorer-known-collections.ts)
plus a free-text field instead. Browsing a name that doesn't exist just
yields an empty list — expected, not an error.

How to run

pnpm install
pnpm exec nx build datatug-app
pnpm exec nx serve datatug-app

Sign in, go to /my, enter a space id you're a member of, click Explore —
or navigate directly to /explore/{spaceId}.

Test plan

  • pnpm exec nx build datatug-app — passes (production build, both
    datatug-main lib and datatug-app)
  • pnpm exec nx lint datatug-main / datatug-app — clean, no
    errors/warnings
  • pnpm exec nx test datatug-main — all 84 existing test files / 108
    tests still pass (no new unit tests added for this PoC — flagged as a
    follow-up)
  • Manual smoke: sign in against sneat-eur3-1, navigate to a real
    space, confirm raw docs render read-only, and confirm a non-member is
    denied by the existing rule — not run in this pass (needs a real
    signed-in session); build + lint + existing test suite is the
    verification for this PoC.

Follow-ups (not in this PR)

  • Wire a real "my spaces" list (replace the manual spaceId input) once a
    space-membership source is reachable from datatug-apps.
  • Slice 2: GitHub/inGitDB-vault transparency viewer reusing
    @ingitdb/client-github (~/projects/ingitdb/ingitdb-ts/packages/client-github)
    — read-only loadCollectionRecords/loadRecord/getContents against one
    real GitHub-vault repo, manual PAT first (see design doc §6 "S/M — GitHub/
    inGitDB slice").
  • Unify into one "Explore my raw data" entry point with a per-space
    Firestore-vs-GitHub badge, once Track B's space→vault pointer exists (see
    design doc §4, §1.7).

🤖 Generated with Claude Code

https://claude.ai/code/session_01FV3pbooAc9UPpNdiaJuKve

… PoC)

Adds an "Explore my raw data" page rooted at /spaces/{spaceId} that lets a
signed-in user browse their own space's Firestore subtree as raw JSON,
read-only. Reuses the app's existing sneat-eur3-1 AngularFire auth and the
DatatugStoreFirestoreService doc/collection-streaming pattern, and relies
entirely on the existing spaces/{space} security rule for scoping — no new
backend, rules, or auth. First slice of the DataTug transparency-explorer
design (backstage/docs/roadmaps/datatug-transparency-explorer.md).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FV3pbooAc9UPpNdiaJuKve
@trakhimenok
trakhimenok merged commit 8ba4351 into main Jul 2, 2026
3 checks passed
@trakhimenok
trakhimenok deleted the fable/datatug-transparency-viewer branch July 2, 2026 06:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant