REPORT.md — correct observation 4: the memory was right, I did not follow it
gates / gates (push) Successful in 12s
gates / gates (push) Successful in 12s
This commit is contained in:
@@ -353,14 +353,17 @@ Ran 4 tests in 0.106s — OK
|
||||
Found while registering the tenth. Corrected to point at the runner's `GATES` table instead of
|
||||
listing them again — the duplicate list is what drifted.
|
||||
|
||||
4. **NOT-A-FINDING: `demo-hp`'s dashboard password is NOT stale, and my first read of it was wrong.**
|
||||
`POST /login` returned 200-with-login-page and the box logged `Failed login`, which matches the
|
||||
documented "the password drifted" symptom exactly. It had not: the value in
|
||||
`~/.config/credentials` is **single-quoted**, and the extraction recipe recorded in project memory
|
||||
strips only double quotes, so the leading and trailing `'` were being sent as part of the password.
|
||||
With both quote characters stripped, `POST /login` → 302 + `felhom_session`. Nothing on the box was
|
||||
changed to fix this. The memory
|
||||
`credentials-file-values-are-quoted` says values are quoted but its example strips `"` only.
|
||||
4. **NOT-A-FINDING: `demo-hp`'s dashboard password is NOT stale — I made the exact mistake the
|
||||
project already has a memory about.** `POST /login` returned 200-with-login-page and the box logged
|
||||
`Failed login`, which matches the documented "the password drifted" symptom exactly. It had not:
|
||||
values in `~/.config/credentials` are **single-quoted**, my extraction stripped only `"`, and the
|
||||
two `'` characters were being sent as part of the password. With both quote characters stripped,
|
||||
`POST /login` → 302 + `felhom_session`. **Nothing on the box was changed.** The memory
|
||||
`credentials-file-values-are-quoted` states this correctly, gives the right recipe
|
||||
(`tr -d "\"'"`), and records the identical misdiagnosis from 2026-07-20 — where it was written up
|
||||
three times as "the stored password is stale" before being caught. The memory is right; I did not
|
||||
follow it. Its own lesson is the one that applies: **an auth failure is evidence about the bytes
|
||||
you sent, not proof about the stored secret.**
|
||||
|
||||
5. **NOT-A-FINDING: the two `storage/simulate-*` controls are the only deletions that removed a
|
||||
capability someone might want back.** They wrote state, so §2.1's rule deleted them absent a shown
|
||||
|
||||
Reference in New Issue
Block a user