diff --git a/CONTEXT.md b/CONTEXT.md index 2d11e4b..c1427f1 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -7,7 +7,11 @@ > > Ask Claude Code: "Please update CONTEXT.md with what we did today" -Last updated: 2026-10-02 (v0.287.0 — the family gate, decisions 63/64, R-780) +Last updated: 2026-10-02 afternoon (v0.288.0 — the remove dialog names the household's files, decision 67, R-800) + +> **2026-10-02 (afternoon) — v0.288.0 (floored, golden 0.288.0 vouched):** `userdata_kept` in hdd-data and both remove +> results; the dialog says the household's files stay and names them (decision 67). Rule for later work: a remove NEVER +> deletes a `${USERDATA_PATH}` folder — only the app's `${HDD_PATH}` binds, volumes and backups. > **2026-10-02 — v0.287.0 (floored, golden 0.287.0 vouched): the family gate.** `internal/family` (members, sessions asked > on every request), `stacks/family_gate.go` (door before the first start; anchored exceptions; record at install and at a diff --git a/REPORT.md b/REPORT.md index f2dd796..d72a1fa 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,31 +1,13 @@ -# REPORT — v0.287.0: the family gate (decisions 63/64, R-780) — 2026-10-02 +# REPORT — v0.288.0: the remove dialog and result name the household's files (decision 67, R-800) — 2026-10-02 -Full session report: `felhom.eu/REPORT-family-gate-2026-10-02.md`. Evidence: `felhom.eu/documentation/audits/family-gate-2026-10-02/` -(A = the controller live on 9202, B = the catalog apps on 9202, B4 = a demo box, E = the floor). Architecture read: -`01-topology-and-trust.md` §5 (now with the family gate paragraph), `09` §3 decisions 46, 47, 63, 64. +Full session report: `felhom.eu/REPORT-persistence-sweep-2026-10-02.md`. Architecture: `07-backup-architecture.md` §6.5 +(decision 67 recorded there), `09` §3 decision 67. -## What shipped (v0.287.0, commits 977665d + c8d5ee2) - -- **`internal/family`** — the household's family members: own name + password each (4×4 letters, shown once, bcrypt in - `family.json` 0600), sessions of 30 days, asked on EVERY request (`Valid`), so reset / remove / logout end access at - the next request. A wrong name costs the same bcrypt time as a right one. -- **`internal/stacks/family_gate.go`** — a template's `family_gate: true` gets a traefik forwardAuth door per router, - written BEFORE the first start (an app is never published open); `family_gate_except:` literal prefixes become - routers without the door, anchored `^/prefix(/|$)` (finding F1); the record is written at install and at a removed - app's restore; the tick rewrites/removes the files. `min_controller:` refuses a template that needs a newer box. -- **`internal/web/family_gate.go`** — `/__felhom_gate/family` (forwardAuth), `/__family/start|login|logout` on the - dashboard host; the family cookie (`Path=/__family`) is NEVER accepted by RequireAuth; the sign-in locks per visitor - (5/min, via `rateKey`, R-753) and per name (10/10 min). The Család card (Settings → Security): add / new password / - remove, password once, `no-store`. hu + en, informal „te", no „kérjük"; parity green. - -## Proof - -- Tests: `internal/family/family_test.go`, `internal/stacks/family_gate_test.go`, `internal/web/family_gate_test.go`. - **Red-proofs RP-F1..F7** (each mutant made its named test fail, then reverted): `A/RP-F-family-gate-mutants.txt`. - Full suite rc 0; `controller_gates.py` OK. -- **Live on 9202 through the product** (`A/items.txt`): a stranger 0 app answers of 36 (LAN + simulated tunnel); members - in with their own logins, the websocket 101; reset/remove/logout end access at once; a stranger's 7 guesses locked - only the stranger; each Grimmory exception kept Grimmory's own login and the look-alikes stayed gated; the controller - down → 500, never the app; the gate's own cost 0.49 ms median. Survived an Update and a remove + restore (`B/box/`). -- **Floor 0.287.0** (min_agent 0.131.0): both demo boxes on 0.287.0 in ~25 s (`E/floor.txt`). **Golden 0.287.0** baked, - round-tripped, vouched (`felhom.eu/documentation/tests/golden-0.287.0-2026-10-02/`). +- `userdata_kept` (the folders the app binds through `${USERDATA_PATH}` that exist; always a list) in + `GET /api/stacks/{name}/hdd-data` and in the results of `POST …/remove` and `DELETE /api/stacks/{name}`. Both dialogs and + both results show „A fájljaid ezekben a mappákban megmaradnak — a fájlböngészőben látod őket:" / "Your files in these + folders stay — you see them in the file browser:". The "no data on a drive" note is no longer given when userdata exists. +- Nothing new is deleted or kept: a remove never deleted userdata (pinned since R-442). +- Tests `TestRemoveStack_R800_*`; red-proof RP-R800-1/2 (`felhom.eu/documentation/audits/persistence-sweep-2026-10-02/B/`); + parity fixtures regenerated (additions only). Live on 9202 (`B/r800-9202.txt`). +- Floor 0.288.0 → both demo boxes in 20 s; golden 0.288.0 baked + vouched.