REPORT.md — correct observation 4: the memory was right, I did not follow it
gates / gates (push) Successful in 12s

This commit is contained in:
2026-08-31 10:39:36 +02:00
parent 0989bb83c3
commit 04abeb20c0
+11 -8
View File
@@ -353,14 +353,17 @@ Ran 4 tests in 0.106s — OK
Found while registering the tenth. Corrected to point at the runner's `GATES` table instead of
listing them again — the duplicate list is what drifted.
4. **NOT-A-FINDING: `demo-hp`'s dashboard password is NOT stale, and my first read of it was wrong.**
`POST /login` returned 200-with-login-page and the box logged `Failed login`, which matches the
documented "the password drifted" symptom exactly. It had not: the value in
`~/.config/credentials` is **single-quoted**, and the extraction recipe recorded in project memory
strips only double quotes, so the leading and trailing `'` were being sent as part of the password.
With both quote characters stripped, `POST /login` → 302 + `felhom_session`. Nothing on the box was
changed to fix this. The memory
`credentials-file-values-are-quoted` says values are quoted but its example strips `"` only.
4. **NOT-A-FINDING: `demo-hp`'s dashboard password is NOT stale — I made the exact mistake the
project already has a memory about.** `POST /login` returned 200-with-login-page and the box logged
`Failed login`, which matches the documented "the password drifted" symptom exactly. It had not:
values in `~/.config/credentials` are **single-quoted**, my extraction stripped only `"`, and the
two `'` characters were being sent as part of the password. With both quote characters stripped,
`POST /login` → 302 + `felhom_session`. **Nothing on the box was changed.** The memory
`credentials-file-values-are-quoted` states this correctly, gives the right recipe
(`tr -d "\"'"`), and records the identical misdiagnosis from 2026-07-20 — where it was written up
three times as "the stored password is stale" before being caught. The memory is right; I did not
follow it. Its own lesson is the one that applies: **an auth failure is evidence about the bytes
you sent, not proof about the stored secret.**
5. **NOT-A-FINDING: the two `storage/simulate-*` controls are the only deletions that removed a
capability someone might want back.** They wrote state, so §2.1's rule deleted them absent a shown