=== R-483 repro on demo-hp — 2026-09-13T19:35:02Z ===
sync: HTTP 200 {"ok":true,"data":{"ok":true,"message":"Sablonok naprakészek — nincs változás"},"message":"Sablonok naprakészek — nincs változás"}
cache has the backend router: 1
--- the operator's own throwaway instance (subdomain travel, 253 media files) is used; its containers get the new routers through the guarded Update (same version) ---
labels before: (none)
--- POST /api/stacks/adventurelog/update at 2026-09-13T19:35:05Z ---
HTTP 202
{"ok":true,"data":{"accepted":true,"completed":false},"message":"Frissítés elindult – az állapot a kártyán követhető"}
  +  0s phase safety-dump
  +  3s phase starting
  +  6s phase verifying
  + 21s phase done
end (2026-09-13T19:35:26Z, +21s): state=running updating=False phase=done err='' hold=''
labels after: Host(`travel.enkisfelhom.hu`) && (PathPrefix(`/media`) || PathPrefix(`/static`) 
healthy: True
signup: 200
login: (302, '/')
location: 201
--- upload through the frontend proxy, WebKit-shaped boundary (what a browser sends) ---
proxy upload -> 500 {"id": null, "image": null}
--- proxy still refuses non-browser multipart; upload through the backend's own API inside the guest (the browser's session cookie, same backend) ---
backend upload -> 403
{"detail":"CSRF Failed: CSRF cookie not set."}
image url: None
--- control: /static and /admin now answer from Django ---
/static/admin/css/base.css -> 200
/admin/login/ -> 403
=== done 2026-09-13T19:35:34Z ===
=== R-483 repro, second half — 2026-09-13T19:36:33Z: an upload placed through the backend's own API (fresh CSRF cookie from the backend), then the photo fetched through the PUBLIC origin ===
login: (302, '/')
have sessionid: True
my place id found: True
backend upload -> 403 | {"detail":"CSRF Failed: CSRF cookie has incorrect length."}
image url: None
=== done 2026-09-13T19:36:37Z ===
=== R-483 repro, third try (the CSRF token is read with cut -f7, quoting-proof) — 2026-09-13T19:37:35Z ===
backend upload -> tokenlen=0 | http=403 | {"detail":"CSRF Failed: CSRF cookie has incorrect length."}
image url: None
=== done 2026-09-13T19:37:39Z ===
=== R-483 repro, fourth try (CSRF cookie from /admin/login/, which always sets one) — 2026-09-13T19:38:02Z ===
backend upload -> tokenlen=0 | http=403 | {"detail":"CSRF Failed: CSRF cookie has incorrect length."}
image url: None
=== done 2026-09-13T19:38:05Z ===
=== R-483 repro, fifth try (curl drops a Secure cookie over http; the token is cut from the raw Set-Cookie header) — 2026-09-13T19:38:30Z ===
backend upload -> tokenlen=0 | http=403 | {"detail":"CSRF Failed: CSRF cookie has incorrect length."}
image url: None
=== done 2026-09-13T19:38:33Z ===
=== R-483 repro, sixth try (token cut from the config endpoint's Set-Cookie header) — 2026-09-13T19:39:01Z ===
backend upload -> tokenlen=32 | http=400 | {"error":"content_type and object_id are required"}
image url: None
=== done 2026-09-13T19:39:05Z ===
=== R-483 repro, seventh try (v0.12.1's image API takes content_type=location + object_id) — 2026-09-13T19:39:21Z ===
backend upload -> http=201 | {"id":"c0b2b8cd-fe22-45db-b2a2-7c859d771941","image":"https://travel.enkisfelhom.hu/media/images/973b9ada-bdab-48f1-85e6-2802a13eb739.webp","is_primary":false,"user":"51f9e8ee-f303-430e-b8ab-aae231e758c4","immich_id":null}
image url: https://travel.enkisfelhom.hu/media/images/973b9ada-bdab-48f1-85e6-2802a13eb739.webp
GET /media/images/973b9ada-bdab-48f1-85e6-2802a13eb739.webp through traefik (public origin) -> 200; bytes identical to the upload: False
the app lists the photo on the place: ['https://travel.enkisfelhom.hu/media/images/973b9ada-bdab-48f1-85e6-2802a13eb739.webp']
=== done 2026-09-13T19:39:25Z ===
--- controls ---
real photo   : (403, 'text/html; charset=utf-8', 'gunicorn')
bogus /media : (403, 'text/html; charset=utf-8', 'gunicorn') (a Django 404, not the frontend's HTML page)
frontend /   : (200, 'text/html', '')
Traceback (most recent call last):
  File "<stdin>", line 4, in <module>
ImportError: cannot import name 'S' from 'app' (/tmp/claude-1000/-mnt-5-hdd-felhom-eu-git/0ff9a77d-5916-4eea-91c4-eaea33e5d9a2/scratchpad/night/app.py)
=== R-483 second cut (port 80) applied to the operator's instance — 2026-09-13T19:46:23Z ===
sync: HTTP 200 {"ok":true,"data":{"ok":true,"updated":["adventurelog"],"message":"Sablonok frissítve — frissítve: adventurelog"},"messa
cache port 80: 1
--- POST /api/stacks/adventurelog/update at 2026-09-13T19:46:25Z ---
HTTP 202
{"ok":true,"data":{"accepted":true,"completed":false},"message":"Frissítés elindult – az állapot a kártyán követhető"}
  +  0s phase safety-dump
  +  3s phase starting
  +  6s phase verifying
  + 21s phase done
end (2026-09-13T19:46:47Z, +21s): state=running updating=False phase=done err='' hold=''
label after: 80
with session: 200 image/webp 154 bytes, magic: b'RIFF' b'WEBP'
anonymous: 403 (the app's privacy rule — control)
=== done 2026-09-13T19:46:54Z ===
