wishlist: after_setup close/open commands for its own sign-up switch + min_controller 0.301.0 (R-717), proven live on 9202
gates / gates (push) Successful in 7s
gates / gates (push) Successful in 7s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,3 +1,7 @@
|
||||
## 2026-10-06 (evening) — wishlist's own sign-up switch closes after the setup and reopens for the family window (R-717)
|
||||
|
||||
**What runs on a box changed:** wishlist's `.felhom.yml` gains `after_setup` (`command` closes, `open_command` opens — Node's own sqlite module writes `system_config.enableSignup` in group `global`, the value read back before the marker prints) and `min_controller: "0.301.0"` (the controller that knows `open_command`). Pushed AFTER controller v0.301.0 reached demo-hp, demo-felhom and the Tester 1 box. A catalog change does not touch an installed wishlist (the 2026-09-29 Part 0 rule); no box reports wishlist today. Proven live on 9202 with the 0.301.0 test image: after the setup the switch read closed and a stranger straight at the app got 401 „invite only"; in the 15-minute window it read open and a family member signed up (users 1 → 2); at the window's end the close ran again 10 s later and a stranger got 401, users stayed 2 (`felhom.eu/documentation/audits/design-build-2026-10-06/E/live.txt`). Opengist cannot use it: its container has no sqlite tool and no script runtime, and its CLI has no settings command (R-717 stays open for opengist).
|
||||
|
||||
## 2026-10-06 (evening) — wger serves its styles and photos (R-762): a small file server, proven on the bench and on 9202
|
||||
|
||||
**What runs on a box changed:** wger's definition (wger stays `lifecycle: hidden`; no box runs it): `DJANGO_DEBUG=False` (the image's entrypoint then runs `collectstatic` at every start, as upstream's production `prod.env`), a named `wger_static` volume, and a new service `wger-files` (`nginx:1.30.5-alpine`, 32M) that serves `/static/` and `/media/` read-only from the shared volumes. Traefik sends only those two paths to it (a longer rule, so a higher priority); every box gate wraps every router of the stack, so it is gated like wger. No nginx config file: the stock config serves `/usr/share/nginx/html`, where the volumes are mounted. `mem_limit` 384M → 416M. The step is a DEFINITION step, written by `upgrade-test.py --write-ladder --to-definition` from both verdicts; the superseded definition is kept at `steps/9edf34a3d53837df.yml`.
|
||||
|
||||
@@ -1,8 +1,12 @@
|
||||
# REPORT — the operator's ten answers (2026-10-06)
|
||||
# REPORT — design build, catalog side (2026-10-06 evening)
|
||||
|
||||
Full session report: `felhom.eu/REPORT.md`. Baseline `d1a1484`.
|
||||
The session report is `felhom.eu/REPORT.md`. Catalog commits this session:
|
||||
|
||||
Live catalog `1938921`: R-747 (mealie's page: five wrong logins lock the account for 1–2 hours) and R-774 (Karakeep's page:
|
||||
the phone app sends crash reports), hu + en. Tooling: R-734 (the update test ignores listed marker files, immich first) and
|
||||
R-624 (the bench — only the bench — seeds vaultwarden through its admin invite; proven on bench 9401 with a guard check and a
|
||||
secret-hygiene check). Open question for the operator: R-890 (a vaultwarden ladder step still needs a box proof).
|
||||
- `c48a0db` — the bench can test a step that ADDS a service (`upgrade-test.py --move-to`, `--write-ladder --to-definition`);
|
||||
DefinitionEdge tests, red-proved.
|
||||
- `cf1ed43` — wger: `DJANGO_DEBUG=False` + a `wger-files` nginx serving `/static` and `/media` (R-762); a definition step
|
||||
proven on the bench and on 9202, written by the ladder writer; wger stays hidden.
|
||||
- this commit — wishlist's `after_setup` close/open commands and `min_controller: "0.301.0"` (R-717), proven live on 9202;
|
||||
pushed after controller v0.301.0 reached the three boxes.
|
||||
|
||||
Opengist is not covered (no tool in its container to write its setting) — R-717 stays open for it.
|
||||
|
||||
@@ -38,6 +38,19 @@ deploy_fields:
|
||||
# --- The setup gate (controller >= 0.281.0, `09` §3 decisions 46-47) ---
|
||||
# The first visitor would create the admin; a fresh install is closed to everyone but the household until the first setup is done.
|
||||
setup_gate: true
|
||||
# R-717 (`09` §3 decision 47; controller >= 0.301.0 for open_command): Wishlist keeps its sign-up switch ONLY in its own
|
||||
# database (system_config, key enableSignup, group "global"; read on every request by getConfig, measured 2026-10-06 in
|
||||
# v0.67.1 — no row means the built-in default, OPEN). The address block alone closed it until now. `command` closes it
|
||||
# after the household's setup; `open_command` opens it for the household's 15-minute window, and `command` closes it
|
||||
# again when the window ends, after a restart and after an update. Node's own sqlite module (node 24 in the image) — no
|
||||
# extra tool; the value is read back and the marker printed only when it reads what was written.
|
||||
min_controller: "0.301.0"
|
||||
after_setup:
|
||||
service: wishlist
|
||||
command: ["node", "-e", "const {DatabaseSync}=require('node:sqlite');const db=new DatabaseSync('/usr/src/app/data/prod.db');db.exec('PRAGMA busy_timeout=10000');db.prepare(\"insert into system_config(key,value,groupId) values('enableSignup',?,'global') on conflict(key,groupId) do update set value=excluded.value\").run('false');const r=db.prepare(\"select value from system_config where key='enableSignup' and groupId='global'\").get();if(r&&r.value==='false')console.log('FELHOM_SIGNUP_CLOSED');"]
|
||||
success: "FELHOM_SIGNUP_CLOSED"
|
||||
open_command: ["node", "-e", "const {DatabaseSync}=require('node:sqlite');const db=new DatabaseSync('/usr/src/app/data/prod.db');db.exec('PRAGMA busy_timeout=10000');db.prepare(\"insert into system_config(key,value,groupId) values('enableSignup',?,'global') on conflict(key,groupId) do update set value=excluded.value\").run('true');const r=db.prepare(\"select value from system_config where key='enableSignup' and groupId='global'\").get();if(r&&r.value==='true')console.log('FELHOM_SIGNUP_OPEN');"]
|
||||
open_success: "FELHOM_SIGNUP_OPEN"
|
||||
# Decision 47: the app's own sign-up address is closed once the gate opens (measured on 9202 2026-09-29: a stranger's sign-up succeeded after the setup; case-insensitive and slash-tolerant because termix's router ignores case (measured 2026-09-29)).
|
||||
signup_block: "PathRegexp(`(?i)^/+signup/*$`)"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user