Spaces:
Sleeping
Sleeping
File size: 7,678 Bytes
2e658e7 | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 | # Hermes Futures Desk — Functional Real-UI Repair Report
Date: 2026-07-22
Package: V5 real-code audit
## Scope
The supplied V4 project was inspected again with a specific requirement: the
production Futures interface must be functional and must not display fabricated,
seeded, random, mock, or presentation-only market/account data. The deterministic
trading engine, Datasource 4 authority, `noTradeGuard`, freshness gates, risk
formulas, server-side Paper revalidation, and Telegram webhook isolation were not
weakened.
## Live-Space verification status
The requested URL was targeted for comparison, but outbound DNS/browser navigation
to `really-amin-simplechatbot.hf.space` was blocked in the available execution
environment. Therefore this report does **not** claim an authenticated live-browser
pass against that deployment. The actual source package was instead audited and
validated locally through its API contracts, complete test suite, JavaScript
parsing, HTML/DOM checks, and production-code scans. A post-deployment authenticated
read-only browser check is still required.
## Newly confirmed and repaired UI issues
### 1. Fabricated symbol catalog entries
**Found:** The server padded a failed/short provider catalog with a large hard-coded
list marked as `source=seed`. Those entries looked like real available markets even
though they had not been returned by a live provider.
**Repair:**
- Removed the entire emergency/seed symbol universe from production code.
- The catalog now contains only symbols returned by real public providers or a
previously persisted real provider cache.
- If neither is available, `/api/futures/symbols` returns an explicit
`state=unavailable`, an empty list, and a reason.
- Manual symbol entry remains possible for real server-side analysis, but it does
not imply Futures verification and cannot authorize execution.
### 2. Presentation-only runtime state
**Found:** The sidebar initially declared the execution environment `Online` before
any server status request had succeeded.
**Repair:**
- The initial state is now `Checking`.
- The badge is updated only from `/api/futures/status`.
- A failed status request changes it to `Unavailable`; no optimistic online state
remains in static HTML.
### 3. Prefilled local user activity
**Found:** New browsers were given a prefilled BTC watchlist and recent-market list,
which looked like existing user activity.
**Repair:**
- Default watchlist is empty.
- Default recent-market history is empty.
- Entries are created only after an actual user selection/action.
### 4. Fabricated account defaults
**Found:** Missing account fields could render as `0` open positions or `paper` mode,
which confused an unavailable response with a genuine zero/real mode.
**Repair:**
- Missing mode and position counts now display `Unavailable`.
- A valid empty positions array still correctly displays `No open Paper positions`.
- Invalid/unavailable position responses are distinguished from a valid empty book.
### 5. Stale chart under a new or unavailable market
**Found:** An old chart could remain visible while a different symbol/interval was
loading or after the new market request failed, making old data appear to belong to
the current market.
**Repair:**
- Candles are cleared whenever symbol, interval, or candle limit changes.
- Structured HTTP 503/unavailable payloads are rendered instead of discarded.
- Generic market errors clear price, funding, open interest, order book, chart, and
verification fields to explicit unavailable/blocked values.
### 6. Duplicate overlapping market requests
**Found:** Automatic refresh, page visibility, symbol changes, and manual refresh
could overlap and issue duplicate market requests.
**Repair:**
- Market loading is single-flight.
- One pending refresh is coalesced and runs after the active request finishes.
- Request sequence checks prevent an older response from overwriting the currently
selected symbol/interval.
- Real refresh cadence is displayed in the UI: status 15 seconds, market 30 seconds,
Telegram 60 seconds.
### 7. Login/session response handling
**Found:** Redirected login HTML or a non-JSON authentication response could be
reported as a generic JSON/API failure.
**Repair:**
- `apiFetch` detects login redirects and expired sessions.
- Non-JSON login pages trigger the real sign-in redirect.
- HTTP status and structured payload are retained on errors so the UI can render
truthful unavailable states.
### 8. Analysis history timestamps
**Found:** The browser could substitute its own current time as if it were the
server-created plan timestamp.
**Repair:**
- Server `created_at` is preserved when present.
- Browser receipt time is stored separately as `received_at`.
- The UI no longer labels a locally invented time as the server plan creation time.
## Existing V4 functional repairs retained
- DS4 fast request plus one bounded cold-start wake retry.
- External Advisory chain: OpenRouter → Google → Hugging Face.
- HTTP 402 skips the failed provider and continues the chain without retrying the
same paid/unavailable provider.
- Sanitized provider-attempt diagnostics in the Advisory page.
- Deprecated Hermes `--insecure` startup option removed.
- Empty `max_concurrent_sessions` normalized.
- Eight hash-routed pages with synchronous navigation, Back/Forward, direct hashes,
keyboard navigation, `hidden`, `inert`, and ARIA state synchronization.
- Paper execution remains server-revalidated and unavailable for unverified markets.
## Real production API bindings verified in source
The production template calls the matching real routes below; it does not generate
market/account responses inside the browser:
- `GET /api/futures/status`
- `GET /api/futures/symbols`
- `GET /api/futures/positions`
- `GET /api/futures/market`
- `POST /api/futures/analyze`
- `POST /api/futures/paper/execute`
- `GET /api/telegram/status`
The corresponding Futures/Telegram routes exist in the backend. Chart diagnostics
are calculated from the returned real candle array; when candles are unavailable,
the diagnostics and chart remain unavailable rather than substituting samples.
## Validation results
- Full local test suite: **108 passed**.
- Python compilation: passed.
- Inline production JavaScript syntax (`node --check`): passed.
- Shell syntax for `scripts/entrypoint.sh`: passed.
- HTML IDs: **119 unique IDs**, no duplicates.
- Static DOM-reference audit: passed.
- All ID-bearing interactive controls have production event handlers.
- Production scan found no seeded catalog, random market generator, mock market
response, dummy position, or synthetic OHLCV path.
- Populated-secret scan: no production secret value found.
- ZIP integrity check: passed after packaging.
- No Paper, Testnet, or Live trade was executed.
- Paper Execute was not called during verification.
Tests use controlled fixtures/mocks only inside the test directory; those are not
production runtime data paths.
## Files changed in the V5 UI truthfulness pass
- `README.md`
- `hermes_overlay/tools/futures_dashboard_api.py`
- `hermes_overlay/tools/templates/hermes_futures_desk_luxury.html`
- `hermes_overlay/tests/test_futures_dashboard_and_state.py`
- `hermes_overlay/tests/test_luxury_template.py`
- `FIX_REPORT.md`
## Required post-deployment acceptance
After deploying this exact package, perform an authenticated read-only pass on the
Space and verify all eight pages, browser Console/Network, real status/symbol/market
responses, 1m/5m/15m/1h chart states, unavailable-state clearing, Back/Forward, and
mobile overflow. Do not click Paper Execute during that verification.
|