v0.245.0 — R-543: the household is asked for the recovery code, the page says "szunetel" until then
gates / gates (push) Successful in 14s

Off-site backup is ON by default and does not RUN until the household creates its
recovery code. The pause is the zero-knowledge escrow design and is untouched here;
what was missing is that nothing ASKED, while the app-backup page promised the very
copy that had never run.

- a reminder bar on every authenticated page while the off-site tier is configured
  and its escrow is not complete, linking /backup/escrow. It is the R-241 bar, second
  instance: same session-cookie dismissal, back next visit, gone for good when
  escrowed. No second banner system. It hangs off executeTemplate, the single render
  choke point, so it cannot reach only the pages someone remembered.
- the tier-1 file sentence renders by tier3State's own vocabulary instead of the
  app's shape: active -> "vedi", escrow_pending -> "vedene ... szunetel" + the route,
  no copy at all -> says so and names both ways out.
- both fixes red-proofed: the bar test fails on BOTH pages with the hook removed; the
  sentence test quotes the exact v0.244.0 promise when the state is ignored.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-16 21:02:51 +02:00
parent 2f8ff2414c
commit ad398b60d9
10 changed files with 436 additions and 9 deletions
@@ -0,0 +1,80 @@
package web
import (
"strings"
"testing"
)
// ── R-543 (second half) — the tier-1 sentence tells the truth about the STATE ───────────────────
//
// v0.244.0 fixed the label (R-537) and introduced a new promise in its place: „a távoli másolat …
// védi", printed from the app's SHAPE alone. On a fresh box the off-site tier is on and PAUSED for
// the recovery code, so that sentence named a protection that had never run once.
//
// The states are tier3State's own vocabulary — the row and the sentence read one source.
const (
protectedNow = "védi" // the active claim
protectedWould = "védené" // the paused, conditional form
pausedClause = "szünetel" // ...and WHY it has not happened
)
func TestR543_Tier1Sentence_ActiveStateKeepsThePromise(t *testing.T) {
note, link, _ := driveFilesNoteFor(true, "active", false)
if !strings.Contains(note, protectedNow) {
t.Errorf("a RUNNING off-site copy must say so plainly; got %q", note)
}
if link != "" {
t.Errorf("a box in the finished state is offered a button it does not need: %q", link)
}
}
// RED-PROOF: return the v0.244.0 sentence for every state and this fails — the paused box is told
// its files are protected by a copy that has never run.
func TestR543_Tier1Sentence_PausedStateDoesNotPromise(t *testing.T) {
note, link, linkText := driveFilesNoteFor(true, "escrow_pending", false)
if strings.Contains(note, protectedNow) {
t.Errorf("R-543: the sentence claims the files ARE protected while the copy is paused for the "+
"recovery code. This is the exact promise a fresh box read for its whole first day: %q", note)
}
if !strings.Contains(note, protectedWould) || !strings.Contains(note, pausedClause) {
t.Errorf("R-543: the paused sentence must say the copy WOULD protect them and that it is "+
"waiting; got %q", note)
}
if link != "/backup/escrow" || linkText == "" {
t.Errorf("R-543: the paused sentence names no route out (link=%q text=%q)", link, linkText)
}
}
// No off-site, no second drive: say there is no copy. Silence here was how the gap survived.
func TestR543_Tier1Sentence_NoCopyAtAllSaysSo(t *testing.T) {
note, link, _ := driveFilesNoteFor(true, "off", false)
if note == "" {
t.Fatal("R-543: an app whose files have NO copy renders no sentence at all")
}
if strings.Contains(note, protectedNow) || strings.Contains(note, protectedWould) {
t.Errorf("R-543: a box with no copy of these files still talks about protection: %q", note)
}
if link == "" {
t.Error("R-543: the no-copy sentence names neither of the two ways out")
}
}
// A second drive IS a real copy of the files — it must not be told it has none.
func TestR543_Tier1Sentence_SecondDriveCounts(t *testing.T) {
note, _, _ := driveFilesNoteFor(true, "off", true)
if !strings.Contains(note, protectedNow) {
t.Errorf("a box whose second drive holds the files is told they are unprotected: %q", note)
}
}
// Negative control: an app whose data really is inside its captured volumes gets no sentence at all,
// in any state — the note exists only for drive-side file legs.
func TestR543_Tier1Sentence_NoFileLegsNoSentence(t *testing.T) {
for _, st := range []string{"active", "escrow_pending", "off", "unconfigured"} {
if note, _, _ := driveFilesNoteFor(false, st, false); note != "" {
t.Errorf("state %q: an app with no drive-side files gets a sentence about them: %q", st, note)
}
}
}