# Dispatch for worker_m1_m2_1

## Mission
Implement Milestones M1 (Core Server & Storage Decoupling) and M2 (Frontend UI & Workflow Fixes) for the HAD Digital MVP skeleton per ORIGINAL_REQUEST.md and PROJECT.md.

## Exclusive Write Ownership
You own exclusively:
- `c:\AI Projects\Kais Project\MVP/*`
Do NOT modify files in `04_Build/` or `05_Test/`.

## Mandatory Reading
- `c:\AI Projects\Kais Project\ORIGINAL_REQUEST.md` (mandatory).
- `c:\AI Projects\Kais Project\.agents\orchestrator_1\PROJECT.md`
- `c:\AI Projects\Kais Project\.agents\explorer_survey_2\handoff.md`
- `c:\AI Projects\Kais Project\.agents\explorer_survey_2\proposed_patches.patch` (exact blueprint of fixes).

## Scope of Work
1. **Milestone M1: Core Server & Database Engine**:
   - `MVP/config_manager.py`:
     - Implement `get_bundle_dir()` (sys._MEIPASS when frozen, else project parent) and `get_data_dir()` (persistent writable location outside sys._MEIPASS).
     - Point static assets, `ctcae_rules.json`, and `guidance.json` to `BUNDLE_DIR`.
     - Point `had.db` to `DATA_DIR` to prevent PyInstaller ephemeral data loss.
   - `MVP/app.py`:
     - Serve static files from `get_bundle_dir() / "static"`.
     - In `/api/login`: Return `{"ok": True, "message": "Login successful", "user": {k: user[k] for k in ("id", "username", "role", "display_name", "patient_id")}}`.
     - In `/api/whoami`: Return HTTP 200 with `{"authenticated": False}` when not logged in, or `{"authenticated": True, "user": ...}` when logged in.
     - In `POST /api/reports`: Support both flat payload (`symptom_id`, `severity_score`, etc.) and multi-symptom dictionary payload (`{"patient_id": 1, "symptoms": {...}, "notes": "..."}`). Fall back to `user.get("patient_id")` if `patient_id` omitted for patient role.
     - Switch server to `http.server.ThreadingHTTPServer` for concurrent request handling.
   - `MVP/database.py`: Ensure persistent SQLite initialization with WAL mode, foreign keys, and 5000ms busy timeout.
2. **Milestone M2: Responsive Local Frontend**:
   - `MVP/static/app.js`:
     - In login handler: Accept `(data && (data.ok || data.user))` so successful logins transition to dashboard.
     - Update demo credentials box to match seeded users:
       - Oncologist: `dr.martin / demo123`
       - HAD Nurse: `inf.moret / demo123`
       - Patient: `patient.durand / demo123`
     - Verify patient toxicity questionnaire form correctly submits report payload and displays confirmation/guidance.
     - Verify clinician care timeline displays submitted reports with CTCAE grades and alert tags.
   - `MVP/static/index.html` & `app.css`: Ensure responsive layout on desktop and mobile viewports.

## Mandatory Integrity Warning
DO NOT CHEAT. All implementations must be genuine. DO NOT hardcode test results, create dummy/facade implementations, or circumvent the intended task. A teamwork_preview_auditor will independently verify your work. Integrity violations WILL be detected and your work WILL be rejected.

## Verification
Run tests to verify:
1. Start server with python, test `/api/whoami`, login as `patient.durand`, submit toxicity report, verify SQLite row, login as `dr.martin`, check timeline.
2. Document commands and verification output in `c:\AI Projects\Kais Project\.agents\worker_m1_m2_1\handoff.md`.

## 2026-09-05T10:39:30Z
You are worker_m1_m2_1.
Your working directory is: c:\AI Projects\Kais Project\.agents\worker_m1_m2_1
Your dispatch instructions are at: c:\AI Projects\Kais Project\.agents\worker_m1_m2_1\DISPATCH.md
Read c:\AI Projects\Kais Project\ORIGINAL_REQUEST.md first.
MANDATORY: Read ORIGINAL_REQUEST.md, .agents/orchestrator_1/PROJECT.md, and .agents/explorer_survey_2/proposed_patches.patch.
MANDATORY INTEGRITY WARNING:
DO NOT CHEAT. All implementations must be genuine. DO NOT hardcode test results, create dummy/facade implementations, or circumvent the intended task. A teamwork_preview_auditor will independently verify your work. Integrity violations WILL be detected and your work WILL be rejected.

Implement Milestones M1 and M2 in MVP/:
1. Decouple bundle and persistent data paths in config_manager.py to prevent _MEIPASS data loss.
2. Update app.py static serving, login response ok: True, /api/whoami status, report submission handling, ThreadingHTTPServer.
3. Update static/app.js login handler (accept data.ok or data.user), demo credentials display, and form/timeline responsiveness.
Verify with Python commands and tests.
Write your completion handoff report to: c:\AI Projects\Kais Project\.agents\worker_m1_m2_1\handoff.md
Send a completion message back when done.

## 2026-09-05T10:46:48Z
**Context**: Bug fix in MVP/app.py during M1/M2 implementation
**Content**: `test_writer_track_1` reported a SQL error in `MVP/app.py` line 232:
`SELECT protocol_name, current_cycle, total_cycles FROM treatment_plans WHERE patient_id = ? AND status = 'active' LIMIT 1`
The table `treatment_plans` defined in `MVP/database.py` has column `cycle_count` (not `total_cycles`).
**Action**: Please fix this query in `MVP/app.py` to use `cycle_count` (or `cycle_count AS total_cycles` if returning dict) so that calls to `/api/patients` execute cleanly without SQLite column errors.
