# Python files to ignore
# Uncomment the following lines if you want to ignore specific Python files
# some_specific_file.py
# temp_*.py

# Python virtual environment
venv/
fresh_venv/
.venv/

# Python cache files
__pycache__/
*.py[cod]
*$py.class

# Tool caches
.mypy_cache/
.pytest_cache/
.ruff_cache/

# Distribution / packaging
dist/
build/
*.egg-info/

# Environment variables
.env
.env.bak-*

# IDE specific files
.vscode/
.idea/
*.swp
*.swo
.cursorrules

# macOS specific files
.DS_Store

# Logs
*.log

# Documentation folder
documents/

# Development tools and files
extract_canvas_api_docs.py
canvas_api_docs/
get_course_grades.py
gradebook.json
# Student data and utility scripts
student_anonymization_mapping.txt
show_student_mappings.py
/_**
.aider*
/test_*.py
!tests/

# Local de-anonymization maps (contains PII)
local_maps/
docs/hybrid_builder_launch.md

# Internal planning/tracking files
CLEANUP.md
CLEANUP_STATE.json
cleanup/

# Archive directory - old structure and development files
archive/
node_modules/

# Smithery build artifacts
.smithery/
smithery-wrapper/node_modules/
smithery-wrapper/.smithery/

# Claude Code per-project working directory (local-only: permissions, in-flight plans, drafts)
# Canonical skills live in top-level skills/ for skills.sh distribution.
.claude/

# Cloudflare Wrangler local cache and state
.wrangler/

# Ephemeral TypeScript execution temp files (from execute_typescript tool)
src/canvas_mcp/code_api/tmp*.ts
src/canvas_mcp/code_api/tmp*.cjs
.mcp.json

# OS cruft
.DS_Store
Thumbs.db

# Editor swap/backup files
*.swp
*.swo
*~

# ---------------------------------------------------------------------------
# internal/ is DENY-BY-DEFAULT. Do not add new exclusion patterns here; add an
# un-ignore below only for a file deliberately meant to be public.
#
# Why inverted (2026-08-20): internal/ previously defaulted to PUBLIC with six
# targeted exclusions, so every new file landed in a public repo despite the
# directory name implying otherwise. internal/session-history.md was tracked
# and world-readable for 22 days carrying a paraphrase of a collaborator's
# private email and the private hosted endpoint URL. A directory whose name
# implies privacy but whose default is publication will keep failing this way.
internal/*
!internal/README.md
!internal/architecture.md
!internal/architecture-review.md
!internal/best-practices.md
!internal/release-checklist.md
!internal/issue-170-followup-draft.md
!internal/research-appservice-mcp-entra.md
# Daily triage briefs stay tracked: the routine reads the newest prior brief to
# compute its cutoff, so untracking them breaks continuity. They must not name
# external collaborators' institutional affiliations or evaluation status.
!internal/issue-triage/
# ---------------------------------------------------------------------------

# docs/ is the Cloudflare Pages publish root — defensive backstop in case a
# local-only file is ever dropped there again.
docs/*.local.*
docs/compliance/

# Claude Desktop Extension build artifact
*.mcpb

# Local agent skills (not part of the public package)
.agents/
internal/hosted-spec-draft/
