Add coaching preferences (auto-derived from the profile, user-overridable) and
a periodic check-in engine that quotes the person's own words and asks whether
their direction still feels valid — mirror, not compass.
- Preferences are deterministic: a documented triad mapping (gut → direct/
higher-friction, heart → warm/drift-sensitive, head → reflective/question-led)
produces defaults for the six fields (coaching_frequency, coaching_style,
misalignment_threshold, friction_tolerance, prefer_questions_over_directives,
time_of_day_preference). PUT overrides; regenerate re-derives.
- CheckinCoach (app/services/coaching.py): Anthropic-backed; writes a check-in
that quotes the person's goals back and asks if the direction still holds.
- Endpoints (app/routers/coaching.py): GET/PUT/regenerate preferences;
GET/POST checkins; respond (records still_valid); admin POST /run is the
weekly batch (due = cadence elapsed + locked profile), intended for a cron.
- Models + migration 005: coaching_preferences (per user) and coaching_checkin.
- Frontend: coaching.html (preferences form + check-in feed); linked from
profile.html.
Tests: 68 passing (added deterministic-preference unit tests and coaching
endpoint/batch tests; run in-container). README updated for Phase 3.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Close the remaining Phase 1 DoD gaps and reconcile the browser flow with
the auth layer.
Goals (5 -> 7 prompts):
- Add near-term (6-12mo) and long-term (3-5yr) goal prompts; collect raw
text on the conversation and store AI-articulated goal summaries on the
profile. Extractor articulates the person's own stated goals (mirror,
not compass) and never fabricates. Alembic 003 adds the four columns.
Cookie-based browser sessions (fixes frontend<->auth desync):
- OAuth callback now sets httpOnly session cookies and redirects into the
app instead of returning JSON. get_current_user gains a cookie fallback
(X-API-Key -> Bearer -> cookie). refresh/logout read the refresh cookie
and set/clear cookies. New shared auth.js (authedFetch) sends cookies and
silently refreshes on 401. Static pages drop the bogus user_id and call
the correct /me endpoints.
Profile editing (read/edit/affirm):
- PATCH /discovery/profile/me edits the prose (Ikigai summaries, overlap
narrative, goals); owner-scoped, partial update, 409 when locked. Edit
mode in profile.html with Save/Cancel.
Also: bump default model to claude-sonnet-4-6, align ports to 8011
(OAuth redirect, CORS), add COOKIE_SECURE/POST_LOGIN_REDIRECT config, and
refresh the README to match the shipped behavior.
Tests: 33 passing (added cookie-auth, profile-edit, goal-extraction cases;
factored a shared app_client fixture into conftest.py).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>