Give the serve-web daemon a real collaboration runtime so browser and
VSCode-webview editors can drive public-relay sessions through REST,
mirroring the web_auth proxy pattern:
- WebCollabState + a dedicated driver thread (wake channel + 250/100ms
tick) run CollabRuntime against the daemon document; documentRevision
and collabSeq are separate so presence/UI changes never trigger a
whole-document pull
- versioned wire DTOs (CollabStateWire/CollabActionWire, wireVersion 1)
map through explicit validation onto the internal UI types instead of
serde on opaque internals; GET state / POST action / POST presence
routes ride the existing /api/ auth + origin guards
- document pushes during an Active session ingest through a split
PreparedDocument::prepare (off-lock validation) +
install_prepared_document (infallible, in-generation) inside a
begin/finish_local_edit capture; identical pushes produce no txn
- gate_daemon_mutation centralizes session-time refusals (409
collab-readonly/busy/active) across document push, sync-reset,
open-recent, /mcp JSON-RPC, and AI apply paths, matching the desktop
CollabGatePolicy semantics