From 04abeb20c06c8c5a891cfcb908a8b78e62dae2e7 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Mon, 31 Aug 2026 10:39:36 +0200 Subject: [PATCH] =?UTF-8?q?REPORT.md=20=E2=80=94=20correct=20observation?= =?UTF-8?q?=204:=20the=20memory=20was=20right,=20I=20did=20not=20follow=20?= =?UTF-8?q?it?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- REPORT.md | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) diff --git a/REPORT.md b/REPORT.md index ed23eaa..04a72ea 100644 --- a/REPORT.md +++ b/REPORT.md @@ -353,14 +353,17 @@ Ran 4 tests in 0.106s — OK Found while registering the tenth. Corrected to point at the runner's `GATES` table instead of listing them again — the duplicate list is what drifted. -4. **NOT-A-FINDING: `demo-hp`'s dashboard password is NOT stale, and my first read of it was wrong.** - `POST /login` returned 200-with-login-page and the box logged `Failed login`, which matches the - documented "the password drifted" symptom exactly. It had not: the value in - `~/.config/credentials` is **single-quoted**, and the extraction recipe recorded in project memory - strips only double quotes, so the leading and trailing `'` were being sent as part of the password. - With both quote characters stripped, `POST /login` → 302 + `felhom_session`. Nothing on the box was - changed to fix this. The memory - `credentials-file-values-are-quoted` says values are quoted but its example strips `"` only. +4. **NOT-A-FINDING: `demo-hp`'s dashboard password is NOT stale — I made the exact mistake the + project already has a memory about.** `POST /login` returned 200-with-login-page and the box logged + `Failed login`, which matches the documented "the password drifted" symptom exactly. It had not: + values in `~/.config/credentials` are **single-quoted**, my extraction stripped only `"`, and the + two `'` characters were being sent as part of the password. With both quote characters stripped, + `POST /login` → 302 + `felhom_session`. **Nothing on the box was changed.** The memory + `credentials-file-values-are-quoted` states this correctly, gives the right recipe + (`tr -d "\"'"`), and records the identical misdiagnosis from 2026-07-20 — where it was written up + three times as "the stored password is stale" before being caught. The memory is right; I did not + follow it. Its own lesson is the one that applies: **an auth failure is evidence about the bytes + you sent, not proof about the stored secret.** 5. **NOT-A-FINDING: the two `storage/simulate-*` controls are the only deletions that removed a capability someone might want back.** They wrote state, so §2.1's rule deleted them absent a shown