##### exit items through the product — 2026-10-02T05:53:44Z
## item 1 — a STRANGER (no cookie), LAN and simulated tunnel
  library  GET  /                                        LAN 302 GATE | tunnel 302 GATE
  library  GET  /                                        LAN 401 GATE | tunnel 401 GATE
  library  GET  /api/v1/books                            LAN 401 GATE | tunnel 401 GATE
  library  GET  /api/v1/healthcheck                      LAN 401 GATE | tunnel 401 GATE
  library  POST /api/v1/setup                            LAN 401 GATE | tunnel 401 GATE
  library  POST /api/v1/auth/login                       LAN 401 GATE | tunnel 401 GATE
  library  GET  /ws/websocket                            LAN 401 GATE | tunnel 401 GATE
  library  GET  /api/v1/opdsx                            LAN 401 GATE | tunnel 401 GATE
  library  GET  /api/v1/opds-evil                        LAN 401 GATE | tunnel 401 GATE
  library  GET  /api/v1/opds/../../api/v1/books          LAN 401 GATE | tunnel 401 GATE
  library  GET  /no-such-page                            LAN 302 GATE | tunnel 302 GATE
  video    GET  /                                        LAN 302 GATE | tunnel 302 GATE
  video    GET  /                                        LAN 401 GATE | tunnel 401 GATE
  video    GET  /history                                 LAN 401 GATE | tunnel 401 GATE
  video    POST /add                                     LAN 401 GATE | tunnel 401 GATE
  video    GET  /socket.io/?EIO=4&transport=polling      LAN 401 GATE | tunnel 401 GATE
  video    GET  /socket.io/?EIO=4&transport=websocket    LAN 401 GATE | tunnel 401 GATE
  video    GET  /download/x.mp4                          LAN 401 GATE | tunnel 401 GATE
item 1: 0 app answers of 36 -> PASS
## item 2 — family members, their OWN logins, through the product's sign-in page
  anna signs in on felhom.enkisfelhom.hu/__family/login: 200; felhom_family set; Max-Age 30 d; Path=/__family; dashboard cookie set: False
  member GET library/ -> 200 APP
  member GET library/api/v1/healthcheck -> 200 APP
  member GET video/ -> 200 APP
  member GET video/socket.io/?EIO=4&transport=polling -> 200 APP
  member GET video/history -> 200 APP
  bela MeTube websocket upgrade -> 101 APP ['Upgrade: websocket']
  bela's MeTube cookie at Grimmory -> 302 GATE
  after the CONTROLLER restarted, anna's Grimmory cookie -> 200 APP (survived)
  anna logs out (200) -> her Grimmory cookie 302 GATE (refused)
## item 3 — a stranger's guesses at the family sign-in lock only the stranger (simulated tunnel)
  stranger 198.51.100.66, 7 wrong for anna: ['401', '401', '401', '401', '401', '429', '429']
  stranger with anna's RIGHT password while locked: 429
  anna herself from 203.0.113.10 (tunnel), at once: 200, session set
  bela from the LAN, at once: 200, session set
  controller log: 2026/10/02 05:54:55 family_gate.go:367: [WARN] [web] family sign-in failed — visitor 198.51.100.66
2026/10/02 05:54:56 family_gate.go:360: [WARN] [web] family sign-in: too many wrong tries — visitor 198.51.100.66, name "anna"
2026/10/02 05:54:58 family_gate.go:360: [WARN] [web] family sign-in: too many wrong tries — visitor 198.51.100.66, name "anna"
2026/10/02 05:54:59 family_gate.go:360: [WARN] [web] family sign-in: too many wrong tries — visitor 198.51.100.66, name "anna"
2026/10/02 05:55:01 family_gate.go:380: [INFO] [web] family sign-in: anna — visitor 203.0.113.10
2026/10/02 05:55:01 family_gate.go:380: [INFO] [web] family sign-in: bela — visitor 192.168.0.180

## item 4 — Grimmory's e-reader exceptions keep Grimmory's OWN login (no family cookie)
  (setup as the household through the gate: OPDS on + an OPDS user, a Kobo token, a KOReader user — values not printed)
  OPDS, the OPDS user's own login                      LAN    -> 200 app '<?xml version="1.0" encoding="UTF-8"?>\n<feed xmlns="http://w'
  OPDS, the OPDS user's own login                      tunnel -> 200 app '<?xml version="1.0" encoding="UTF-8"?>\n<feed xmlns="http://w'
  OPDS, a stranger with a wrong password               tunnel -> 401 app 'HTTP Status 401 - Bad credentials'
  OPDS, a stranger with nothing                        tunnel -> 401 app 'HTTP Status 401 - Full authentication is required to access'
  Kobo initialization, the device token                LAN    -> 200 app '{"Resources":{"user_tasteprofile_genre":"https://storeapi.ko'
  Kobo, a made-up token                                tunnel -> 401 app '{"timestamp":"2026-10-02T05:55:12.892Z","status":401,"error"'
  KOReader sign-in, its own user + md5 key             LAN    -> 200 app '{"username":"korolvaso"}'
  KOReader, a stranger's wrong key                     tunnel -> 401 app '{"timestamp":"2026-10-02T05:55:14.437Z","status":401,"error"'
  Komga API, a stranger with nothing                   tunnel -> 401 app 'HTTP Status 401 - Full authentication is required to access'
  look-alike /api/v1/opdsx (F1)                        tunnel -> 401 GATE '{"error":"sign in with your family login"}'
  look-alike /api/koreaderx                            tunnel -> 401 GATE '{"error":"sign in with your family login"}'
  ../ out of an exception                              tunnel -> 401 GATE '{"error":"sign in with your family login"}'
## R-775 re-measured — a stranger cannot reach Grimmory's web sign-in at all, so its 15-minute lock cannot be aimed from outside
  stranger x6 at /api/v1/auth/login (tunnel): ['401', '401', '401', '401', '401', '401'] -> the household then signs in: 200
## item 5 — the family login and the box dashboard
  family cookies at /launcher -> 302 /login?next=%2Flauncher | at /api/stacks -> 401 | anna's family password at the dashboard login -> 200, session none
## reset and removal end access at the next request (every gated app)
  card: new password for bela -> ok=True; bela's Grimmory cookie -> 302, MeTube cookie -> 302 (302 = sent to sign in)
  card: remove bela -> ok=True members=['anna']; bela's MeTube cookie -> 401; bela signs in again -> 401
## cost — the same request through the gated name, and straight at the container (60 pairs)
  gated (LAN→traefik→forwardAuth→app) median 9.4 ms, p90 10.5 ms; the app straight (guest→container) median 1.0 ms — the honest number is the gate's own: see the controller's forwardAuth timing below
## the controller DOWN — a gated app answers an error, never the app; an exception still reaches the app's own login
  controller stopped: MeTube with a member cookie -> 500 ''; Grimmory API -> 500; Grimmory OPDS exception (wrong password) -> 401 (the app's own refusal)
  controller back: MeTube with bela's earlier cookie (bela was removed) -> 401 GATE
## cost, the gate's own answer: 100 forwardAuth calls from inside the guest straight to the controller with a member cookie — codes {'200'}, median 0.49 ms, p90 0.55 ms, max 0.64 ms (2026-10-02T05:56:36Z)
