v0.257.0: the app catalog can speak English (R-560, slice 5 Part A)
gates / gates (push) Successful in 25s

The READ PATH for a second language in `.felhom.yml`. An `i18n: {en: …}` sibling
block inside the same file; `Metadata.For(lang)` merges it FIELD BY FIELD over the
Hungarian, so a missing or blank English field shows the Hungarian one and a
half-translated app is a legal, shippable state.

`For("hu")` is the parsed struct with `I18n` cleared and nothing else — measured
against all 53 real catalog files, copied into `internal/stacks/testdata/catalog/`.
Lists replace whole; every other list is matched by its own key, never by position.
`For` never writes through the receiver: the metadata is the stack manager's, shared
by concurrent requests, and an in-place merge would leak one household's language
into another household's page.

Pages reach catalog copy only through `LocalizeStacks`/`LocalizeStackPtr`/`MetaFor`,
and `TestNoDirectMetaCopyReadOnPages` keeps a named, reasoned allow-list of every
direct `.Meta.<copy>` read in `internal/web` so the NEXT page to read one fails the
suite instead of quietly rendering Hungarian to an English household.

Eight red-proofs. Two of them convicted a hollow TEST rather than the code: a struct
copy shares its slices' backing arrays, so the obvious DeepEqual mutation check
passed a deliberately broken merge; and a one-entry fixture cannot tell key matching
from position matching. Both rewritten, both then seen to fail.

MinAgent: 0.131.0 (unchanged). Older controllers are unaffected — `LoadMetadata`
uses non-strict `yaml.Unmarshal`, so a pre-0.257.0 box drops the whole block.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-20 14:31:52 +02:00
parent e81ad613ae
commit 60f0a86bd4
60 changed files with 5318 additions and 6 deletions
+44 -6
View File
@@ -182,7 +182,11 @@ func (s *Server) dashboardHandler(w http.ResponseWriter, r *http.Request) {
data["TitleKey"] = "page.title.dashboard" // i18n: the Hungarian title above is what hu renders
s.addRecoveryBanner(data, r) // R-241: the reminder bar, per visit
data["SettingsWarning"] = s.settings.LoadWarning // non-empty if settings.json was recovered from corruption
data["Stacks"] = deployedStacks
// R-560: the app rows carry catalog copy (each row's `.Meta.Description`), so the list the
// TEMPLATE sees is the localised view. The lists the warning helpers below see are the
// originals — they key on stack NAMES, and handing them a translated copy would only widen
// what a catalog push can reach. For hu this returns the same slice, untouched.
data["Stacks"] = stacks.LocalizeStacks(deployedStacks, s.langFor(r))
data["MissingStorage"] = s.missingStorageMap(deployedStacks)
data["OOMKilled"] = s.stackMgr.OOMKilledStacks() // R-514
nw, ns := s.networkStorageWarnings(deployedStacks) // NAS unreachable (recoverable) / guest-side stub (defect)
@@ -362,7 +366,7 @@ func (s *Server) stacksHandler(w http.ResponseWriter, r *http.Request) {
data := s.baseData("stacks", "Alkalmazások")
data["TitleKey"] = "page.title.stacks" // i18n: the Hungarian title above is what hu renders
allStacks := visibleCatalogStacks(s.stackMgr.GetStacks())
data["Stacks"] = allStacks
data["Stacks"] = stacks.LocalizeStacks(allStacks, s.langFor(r)) // R-560 — see dashboardHandler
data["MissingStorage"] = s.missingStorageMap(allStacks)
nw, ns := s.networkStorageWarnings(allStacks) // NAS unreachable (recoverable) / guest-side stub (defect)
data["NetworkWarnings"] = nw
@@ -415,7 +419,7 @@ func (s *Server) logsHandler(w http.ResponseWriter, r *http.Request, name string
data := s.baseData("logs", stack.Meta.DisplayName+" — Naplók")
data["TitleKey"], data["TitleArgs"] = "page.title.logs", []interface{}{stack.Meta.DisplayName} // i18n: the Hungarian title above is what hu renders
data["Stack"] = stack
data["Stack"] = stacks.LocalizeStackPtr(stack, s.langFor(r)) // R-560
data["Logs"] = logs
s.executeTemplate(w, r, "logs", data)
}
@@ -436,13 +440,23 @@ func (s *Server) deployHandler(w http.ResponseWriter, r *http.Request, name stri
stack, _ := s.stackMgr.GetStack(name)
alreadyDeployed := appCfg != nil && appCfg.Deployed
// R-560 — the ONE place this page's catalog copy is chosen, and it is placed here on purpose:
// every `meta` read below it (the field labels, the descriptions, the optional-config groups)
// is a display read, and this handler only ever renders — the deploy POST is a different
// route. The overlay changes copy fields ONLY; `env_var`, `type`, `generate`, `default`,
// `required` and `locked_after_deploy` are not in MetadataOverlay at all, so the auto-field
// map, the HDD_PATH question and the prefill keys below read exactly what they read before.
lang := s.langFor(r)
localized := meta.For(lang)
meta = &localized
pageTitle, pageTitleKey := meta.DisplayName+" — Telepítés", "page.title.deploy"
if alreadyDeployed {
pageTitle, pageTitleKey = meta.DisplayName+" — Beállítások", "page.title.app_settings"
}
data := s.baseData("deploy", pageTitle)
data["TitleKey"], data["TitleArgs"] = pageTitleKey, []interface{}{meta.DisplayName} // i18n: the Hungarian title above is what hu renders
data["Stack"] = stack
data["Stack"] = stacks.LocalizeStackPtr(stack, lang) // R-560
data["Meta"] = meta
data["AppConfig"] = appCfg
data["AlreadyDeployed"] = alreadyDeployed
@@ -583,7 +597,21 @@ func (s *Server) deployHandler(w http.ResponseWriter, r *http.Request, name stri
// App-to-app integrations
if im := s.integrationMgr.Load(); meta.HasIntegrations() && im != nil {
data["HasIntegrations"] = true
data["Integrations"] = im.ListForProvider(meta.Slug)
// R-560: the integration manager reads the stack's own (Hungarian) Meta to build these
// rows — it has no request and therefore no language. The label and the sentence are
// catalog copy, so they are re-taken from the LOCALISED meta here, matched by target
// the same way the overlay itself matches. Everything else in the row (state, target
// health, last error) is the manager's and is left alone.
rows := im.ListForProvider(meta.Slug)
for i := range rows {
for _, def := range meta.Integrations {
if def.Target == rows[i].Target {
rows[i].Label, rows[i].Description = def.Label, def.Description
break
}
}
}
data["Integrations"] = rows
}
// Geo-restriction per-app data
@@ -707,6 +735,13 @@ func (s *Server) appDetailHandler(w http.ResponseWriter, r *http.Request, slug s
}
}
// R-560 — this page is the one that shows ALL of an app's catalog copy (tagline, use cases,
// first steps, prerequisites, the default-credentials line, the data-folder labels), so the
// localised view is taken ONCE here and `found` is replaced by it. Everything downstream —
// the data-path cards, the initial-credentials note — then reads the household's language
// without a second decision to get wrong.
found = stacks.LocalizeStackPtr(found, s.langFor(r))
data := s.baseData("stacks", found.Meta.DisplayName)
data["Stack"] = found
data["Meta"] = found.Meta
@@ -743,7 +778,10 @@ func (s *Server) appDetailHandler(w http.ResponseWriter, r *http.Request, slug s
data["InitialCreds"] = &stacks.ExtractedCreds{
Available: creds.Available,
Username: creds.Username,
Note: creds.Note,
// R-560: the reader took the note from the manager's Hungarian metadata (it runs
// without a request and has no language). The note is catalog copy, so it is
// re-taken from the localised spec — the same value for hu, byte for byte.
Note: found.Meta.InitialCreds.Note,
// Password deliberately NOT carried — the reveal endpoint is the only path to it.
}
data["InitialCredsHasPassword"] = strings.TrimSpace(creds.Password) != ""
@@ -0,0 +1,108 @@
package web
import (
"fmt"
"go/ast"
"go/parser"
"go/token"
"os"
"sort"
"strings"
"testing"
)
// TestNoDirectMetaCopyReadOnPages — the guard for R-560's whole point.
//
// Catalog copy (`Description`, `AppInfo`, the deploy-field labels, `OptionalConfig`, `Integrations`,
// the `DataPaths` labels, the initial-credentials note) is HUNGARIAN in the value the stack manager
// caches. A page reaches the household's language only by going through `Metadata.For(lang)` —
// `stacks.LocalizeStacks`, `LocalizeStack`, `LocalizeStackPtr` or `MetaFor`. Read `x.Meta.<copy>`
// straight off a manager value and an English household silently gets Hungarian: no error, no log,
// nothing that looks wrong on the page. That is precisely the failure mode this project has shipped
// nine times under a comment that read as settled.
//
// So every direct read of a copy field off a `.Meta` in this package is LISTED BELOW WITH A REASON.
// A new one fails this test, and the author then has two honest choices: route it through For(lang),
// or add it here saying why it may stay Hungarian.
//
// WHAT THIS TEST CANNOT DO: it reads the source, so it cannot tell a localised receiver from an
// unlocalised one — `found.Meta.AppInfo` looks the same either way. It catches the ARRIVAL of a new
// copy read, which is when a human has to think, and that is the whole claim made for it.
//
// RED-PROOF (2026-09-20): adding `_ = stack.Meta.Description` to handlers.go failed this test
// naming handlers.go and Description; removing it went green.
var metaCopyReadAllowlist = map[string]string{
// The app page localises `found` in one place at the top of appDetailHandler and every read
// below it — these included — is of that localised value.
"handlers.go:AppInfo": "appDetailHandler reads it off the LocalizeStackPtr'd `found`",
"handlers.go:InitialCreds": "appDetailHandler: the nil check and the note, both off localised `found`",
// buildDataPathCards is called with the same localised `found`; the labels it renders are the
// English ones when the household is on English.
"datapath_card.go:DataPaths": "buildDataPathCards is handed the localised stack by appDetailHandler",
}
// metaCopyFields are the Metadata fields that carry customer-facing TEXT. Everything else on
// Metadata — Slug, Subdomain, OpenPath, BrandColor, Category, Resources, Lifecycle, CatalogSince,
// HealthCheck, SMTPMapping, Backup — is configuration and reads the same in every language.
// DisplayName is deliberately NOT here: an app's name is not translated (10-localisation.md §11,
// operator ruling 7).
var metaCopyFields = map[string]bool{
"Description": true,
"AppInfo": true,
"DeployFields": true,
"OptionalConfig": true,
"Integrations": true,
"DataPaths": true,
"InitialCreds": true,
}
func TestNoDirectMetaCopyReadOnPages(t *testing.T) {
entries, err := os.ReadDir(".")
if err != nil {
t.Fatal(err)
}
seen := map[string]bool{}
var unlisted []string
for _, e := range entries {
name := e.Name()
if e.IsDir() || !strings.HasSuffix(name, ".go") || strings.HasSuffix(name, "_test.go") {
continue
}
fset := token.NewFileSet()
f, err := parser.ParseFile(fset, name, nil, 0) // comments are not walked — only real reads count
if err != nil {
t.Fatalf("%s: %v", name, err)
}
ast.Inspect(f, func(n ast.Node) bool {
outer, ok := n.(*ast.SelectorExpr)
if !ok || !metaCopyFields[outer.Sel.Name] {
return true
}
inner, ok := outer.X.(*ast.SelectorExpr)
if !ok || inner.Sel.Name != "Meta" {
return true
}
key := name + ":" + outer.Sel.Name
seen[key] = true
if _, allowed := metaCopyReadAllowlist[key]; !allowed {
unlisted = append(unlisted, fmt.Sprintf("%s (%s)", key, fset.Position(outer.Pos())))
}
return true
})
}
sort.Strings(unlisted)
for _, u := range unlisted {
t.Errorf("catalog COPY read straight off .Meta: %s\n"+
" Route it through stacks.LocalizeStack(s)/LocalizeStackPtr/MetaFor(lang), or add it to\n"+
" metaCopyReadAllowlist in this file with the reason it may stay Hungarian.", u)
}
// A stale allow-list entry is a lie about what the code does — it must go when its read goes.
for key := range metaCopyReadAllowlist {
if !seen[key] {
t.Errorf("allow-list entry %q no longer matches any read — delete it", key)
}
}
}