Save each discovery conversation's prompts and answers to durable CSV
files (per-conversation + append-only master log) on both save and
completion, so answers survive an extraction error, can be re-fed to the
AI, and can be reviewed/resumed by the user.
- app/services/answer_store.py: canonical prompt list + atomic CSV writes,
master append, and read-back helpers (DB stays system of record; CSV
failures are logged, never fatal).
- discovery router: write CSV on /respond and /complete; new endpoints
GET /answers, GET /answers.csv, POST /reprocess (shared extraction
helper; locked profiles return 409).
- discovery.html: prefill/resume from saved answers after an error and a
"Re-run analysis" button wired to /reprocess.
- scripts/reprocess_csv.py: offline CLI to re-run extraction from a CSV
(print or --write-db).
- QUESTIONS_DIR / QUESTIONS_MASTER_CSV config, .gitignore, README, tests.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Dg6XWUwprmP5QCL18HxssY
Close the remaining Phase 1 DoD gaps and reconcile the browser flow with
the auth layer.
Goals (5 -> 7 prompts):
- Add near-term (6-12mo) and long-term (3-5yr) goal prompts; collect raw
text on the conversation and store AI-articulated goal summaries on the
profile. Extractor articulates the person's own stated goals (mirror,
not compass) and never fabricates. Alembic 003 adds the four columns.
Cookie-based browser sessions (fixes frontend<->auth desync):
- OAuth callback now sets httpOnly session cookies and redirects into the
app instead of returning JSON. get_current_user gains a cookie fallback
(X-API-Key -> Bearer -> cookie). refresh/logout read the refresh cookie
and set/clear cookies. New shared auth.js (authedFetch) sends cookies and
silently refreshes on 401. Static pages drop the bogus user_id and call
the correct /me endpoints.
Profile editing (read/edit/affirm):
- PATCH /discovery/profile/me edits the prose (Ikigai summaries, overlap
narrative, goals); owner-scoped, partial update, 409 when locked. Edit
mode in profile.html with Save/Cancel.
Also: bump default model to claude-sonnet-4-6, align ports to 8011
(OAuth redirect, CORS), add COOKIE_SECURE/POST_LOGIN_REDIRECT config, and
refresh the README to match the shipped behavior.
Tests: 33 passing (added cookie-auth, profile-edit, goal-extraction cases;
factored a shared app_client fixture into conftest.py).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>