# Task: Integrate native login and HTTP2-disabled diagnostic package ## Identity - Task ID: 20260819-native-http1-package-c7e4 - Mode: Integration - Branch: codex/20260819-native-http1-package-c7e4-native-http1-package - Worktree: D:\mk-native-http1-package-c7e4 - Base commit: 9ff79e96813ebadade0aecb8f407edf5aee0144a - Owner: codex-root - Status: Completed ## Scope - Integrate the completed native password/mobile-code login change from commit `5a048da8a615792dee9e0c76b6fda814aaa1b854`. - Integrate the temporary Electron HTTP/2 diagnostic bootstrap from commit `411cd9cedfeb14df0c839e6e1cbf1110826ad0e6`. - Produce and verify a Windows x64 diagnostic installer without promoting either change to the default branch. ## Intent And Constraints - Preserve the Main-owned authentication boundary: Renderer login requests continue through Host API routes. - Replace the failing browser desktop-auth flow with the already completed password and mobile verification-code surfaces. - Keep `app.commandLine.appendSwitch('disable-http2')` before the single-instance lock and `app.whenReady()` so every Electron network context inherits the diagnostic switch. - Treat this as an isolated diagnostic package. The default branch and canonical current-state snapshot are not advanced by this task. - Use the project-pinned Python runtime and verified `uv 0.10.0`; do not reuse the earlier native-login package's temporary `uv 0.10.9` substitution. - The user explicitly requested direct execution without sub-agents, so verification was performed in the primary task. ## Outcome - Merged native login as integration commit `3ba90af` and HTTP/2 disablement as integration commit `c1548e6` with no conflicts. - Generated `D:\mk-native-http1-package-c7e4\release\Makelore-2.0.0-win-x64.exe`. - Installer size: `302025649` bytes. - Installer SHA-256: `2A81ECC39A55E3F01ED90A8D1D564E020E82671779E72B50EB76282197D31EC2`. - Authenticode status: `NotSigned`, consistent with the local diagnostic-package environment. - Final `app.asar` contains the password login, mobile login, SMS-code and image-code routes and native login UI, while `/api/auth/browser/start` is absent. - Final `app.asar` contains `disable-http2` before both `requestSingleInstanceLock` and `whenReady` in the packaged Main bootstrap. ## Verification - `pnpm exec vitest run tests/unit/http2-diagnostic-bootstrap.test.ts tests/unit/auth-routes.test.ts tests/unit/auth-store.test.ts tests/unit/login-page.test.tsx tests/unit/works-square-session.test.ts tests/unit/works-square-session-persistence.test.ts tests/unit/works-square-session-persistence-policy.test.ts --reporter=dot` — PASS, 7 files / 98 tests. - `pnpm run typecheck` — PASS. - Scoped ESLint over the changed Main, Renderer, E2E and unit-test files — PASS. - `pnpm test` — PASS, 184 files / 2185 tests. - `pnpm run build:vite` — PASS. - Electron smoke test `can skip setup and open the native login surface` — PASS, 1 test. - `pnpm run package:stage:win-x64` with the verified Learning Player artifact — PASS. - `node scripts/run-electron-builder.mjs --win --publish never` — PASS. - `pnpm run verify:publish-runtime` — PASS, npm `11.6.2`. - `pnpm run verify:artifact:win -- --allow-dirty --installer .\release\Makelore-2.0.0-win-x64.exe` — PASS; Electron `43.4.0`, Node `24.18.1`, OpenCode `1.18.9`, Python runtime present, `uv 0.10.0`, native addons present. - `node scripts/verify-learning-player-artifact.mjs release\win-unpacked\resources\resources\learning-player` — PASS, SHA-256 `748d6d7c74d9d0ba444e0c051a50010f7070e7d6e46442b1e60f1e2be80fd020`. - Direct packaged `app.asar` assertions for the HTTP/2 switch ordering, native auth routes/UI and removal of the legacy browser-start route — PASS. ## Follow-ups - Install this diagnostic package and confirm that password/mobile-code authorization succeeds against the live Works service. - Reproduce the generation-quote request sequence. If the global loading freeze still occurs, the result rules out HTTP/2 as the sole cause and request ownership/cancellation in the quote flow should be instrumented next. ## Promotion Candidates - None from this packaging task. Promotion of native login or temporary HTTP/2 disablement remains an explicit default-branch integration decision after live validation.