From 4df2cd51740b790bba7643d6f01d414380fcc697 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Fri, 18 Sep 2026 15:12:20 +0200 Subject: [PATCH] =?UTF-8?q?docs:=20controller=20v0.255.0=20=E2=80=94=20the?= =?UTF-8?q?=20globe=20fix=20on=20the=20sign-in-flow=20pages?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit R-579 filed and closed the same day: five shell templates loaded style.css with no cache-buster, so a browser holding the pre-0.254.0 file rendered the new globe unstyled; and the globe sat outside the card. - STATUS.md rewritten for the operator: what was seen, why, the third defect found while fixing it (version disclosure on the guest share page, caught by TestShareGuest_HeadersTilesNoAdminChrome), and the one decision left — raise the fleet floor to 0.255.0, with what happens either way. - 10-localisation.md §3: the shells' asset tag, and why the two guest pages get an opaque tag rather than the version. - Audit D: the parity diff (91 of 106 fixtures identical, every dashboard page among them) and the live endpoint evidence from demo-hp guest 9201. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- STATUS.md | 61 +++++++---------- documentation/architecture/10-localisation.md | 10 +++ .../i18n-slice2-2026-09-18/D/live/README.md | 28 ++++++++ .../D/live/after-0.255.0.txt | 7 ++ .../i18n-slice2-2026-09-18/D/live/probeE.sh | 16 +++++ .../i18n-slice2-2026-09-18/D/parity-diff.txt | 68 +++++++++++++++++++ documentation/backlog/OPEN-ITEMS.md | 1 + 7 files changed, 154 insertions(+), 37 deletions(-) create mode 100644 documentation/audits/i18n-slice2-2026-09-18/D/live/README.md create mode 100644 documentation/audits/i18n-slice2-2026-09-18/D/live/after-0.255.0.txt create mode 100644 documentation/audits/i18n-slice2-2026-09-18/D/live/probeE.sh create mode 100644 documentation/audits/i18n-slice2-2026-09-18/D/parity-diff.txt diff --git a/STATUS.md b/STATUS.md index 2f1eaf96..d7d662e8 100644 --- a/STATUS.md +++ b/STATUS.md @@ -1,49 +1,36 @@ # STATUS — what works, what's broken, what's next -**Updated 2026-09-18 (night) — the language work is finished, and the switch is now a globe.** +**Updated 2026-09-18 (late) — the globe you photographed is fixed.** -> **Ready for a volunteer: yes.** A Hungarian household sees what it saw yesterday, apart from one -> deliberate change: the two small "Magyar / English" links at the bottom of the menu are now a globe. +> **Ready for a volunteer: yes.** -**Decisions I took.** One you were asked for, taken on its own stated default: **if someone switches -the claim page to English and then claims the box, the box becomes English.** They chose it, and the -first screen they see should be in it. You can reverse it; nothing else depends on it. +**What you saw, and why.** The globe on the sign-in page came out as a bare triangle and two plain +words, floating outside the card. Two separate faults: -**What I did today.** Three releases, and the language job is done. +1. **Your browser was still using the old stylesheet.** Those pages asked for the style file without a + version number on the end, so a browser that had already downloaded it kept the old copy — and the + old copy knows nothing about a globe. The main dashboard has always asked with a version number; + these pages never did. **Five pages had it, not three.** +2. **Even styled, it sat outside the card**, pinned to the corner of the window, so it read as part of + the browser rather than part of the page. It is now inside the card, centred under the footer, and + the little menu opens upward. -1. The sentences the program writes into the pages. -2. The error messages — about 180 of them, written deep inside the program. -3. Today's last piece: **the notes the box saves overnight**, and **the globe**. +**A third thing I found while fixing it.** My first fix would have printed the exact software version +onto the page a guest opens from a share link — someone you sent a link to, who should not be told +which build you are running. **An existing test caught it.** Those two pages now get a scrambled tag +instead: it does the same job and says nothing. -**The globe.** Two text links at the bottom of the menu asked you to recognise two words as links, -and they wrapped. Now there is one globe — the symbol everyone already reads as "language". Click it -and a small list opens: Magyar, English, with the current one ticked. **The sign-in page and the claim -page have it too**, which matters: someone who cannot read Hungarian could not previously find their -way out of Hungarian before signing in. Their choice is kept in their own browser only — it never -changes what the household has chosen, and a signed-in household never picks up a stranger's choice. +**Checked on the demo HP box:** the page now asks for the versioned file, the file it gets back +carries the new rule, and the old rule is gone. **What I cannot check is how it looks** — there is no +browser on this machine. That part is your click. -**One thing to expect, and it is the choice you were offered.** The notes saved overnight are written -in the box's language at the moment they are written. If you switch language, last night's note stays -in the old language until the next night rewrites it. +**Rows.** One opened and closed the same day. -**What broke, and what I did about it.** **I introduced a freeze.** The code that writes the overnight -note asked the box "what language are you?" at a moment when that question could not be answered — -and it would have hung there **forever, holding a lock the rest of the box needs**. On a real machine -an overnight cloud backup would have stopped and taken everything else with it. The test run caught it -by taking 25 minutes instead of 8. It is fixed, and there is now a check that names the exact line in -a second instead of hanging. I also found and fixed a second one before it shipped: the recovery -screen's globe would have looked like it worked and done nothing. - -**Rows.** One closed (the whole language job), two opened. The register went from **269** to **271**. - -**The floor is raised, as you asked.** The fleet minimum went from 0.253.0 to **0.254.0**. The N100 -demo box took it by itself in about forty seconds and is healthy, with its other four apps still -running; its sign-in page now shows the globe and none of the old text links. The HP demo box already -had it. **The two boxes that are switched off did not get it** — Peti's has been off for 65 days on a -much older version, Tester 1 for a day — and they will take it on their own when they come back, -which is how a floor always works. Neither has been tried on this version. - -**Needs you.** Nothing. If you do nothing: the two sleeping boxes update themselves when they wake. +**Needs you — one decision.** **Raise the floor to 0.255.0?** +- **If you do:** every box serves the fixed pages on its next check-in, and nobody sees the broken globe. +- **If you do nothing:** boxes on 0.254.0 keep showing it to anyone whose browser cached the old style + file. Nothing is at risk; it just looks wrong. +- I would raise it — the thing it fixes is the thing you noticed. --- diff --git a/documentation/architecture/10-localisation.md b/documentation/architecture/10-localisation.md index 970d8aed..4b18806f 100644 --- a/documentation/architecture/10-localisation.md +++ b/documentation/architecture/10-localisation.md @@ -436,6 +436,16 @@ cannot inherit a language a previous visitor picked in the same browser. The rec measured live before it was right: an anonymous form there sets a cookie that `langFor` then ignores, and the button appears to do nothing. +**[FACT] Where the globe SITS, and a stale-stylesheet trap that only a screenshot could show +(v0.255.0, R-579).** On the pages outside the dashboard chrome the globe is **inside the card, centred +under the footer**, with the menu opening upward — the shared `.lang-globe-menu` rule, so the two +surfaces cannot drift apart. It was first placed at the corner of the VIEWPORT, which read as a stray +browser control rather than part of the page. And five of those shells requested `style.css` with **no +`?v=`**, so a browser holding a copy from before the globe existed kept serving CSS with no +`.lang-globe` rules and it rendered as a bare, unstyled `
`. **Every test passed, because they +all read the markup and the fault was in which CSS file the browser fetched.** `Version` is now set in +`executeTemplateLang`, once, for every shell. + **[DESIGN] `POST /lang` is CSRF-exempt, for a reason narrow enough to check.** The only achievable effect of a forged request is to change the language of the page the victim's own browser shows them. It writes one display-only cookie, reads nothing, touches no setting, and `safeBackPath` refuses a diff --git a/documentation/audits/i18n-slice2-2026-09-18/D/live/README.md b/documentation/audits/i18n-slice2-2026-09-18/D/live/README.md new file mode 100644 index 00000000..852c9e7d --- /dev/null +++ b/documentation/audits/i18n-slice2-2026-09-18/D/live/README.md @@ -0,0 +1,28 @@ +# Live validation — controller v0.255.0 on demo-hp guest 9201 (2026-09-18) + +**Method: endpoint-level.** No browser on DooPlex. Three GETs, no session needed, nothing written. +The deploy endpoint was not touched (`.claude/rules/live-probes.md`). + +``` +stylesheet link : +globe inside card: card@285 footer@1164 globe@1304 -> INSIDE the card, under the footer +GET style.css?v=0.255.0 : 200, 93 551 bytes +the .shell-lang rule it serves: + .shell-lang { display: flex; justify-content: center; margin-top: 1.5rem; } +old absolute rule gone: 0 occurrences +``` + +Both halves of the defect are answered on the live box: the page now asks for a **versioned** URL, so +a browser holding the pre-0.254.0 file fetches a new one; and the file it fetches carries the **new** +`.shell-lang` rule, with the old viewport-absolute rule gone. The globe's markup sits inside the card +and below the footer. + +**What this does NOT prove:** how it LOOKS. `claude-in-chrome` is not available here, so the byte-level +facts above are the whole of what a machine can check. The screenshot that found the bug is the kind +of evidence that settles it — an operator click-through on `https://felhom.enkisfelhom.hu/login`. + +**The guest share page** could not be fetched: there is no live share token on this box, so `/s/` +is a 404. Its change is the cache-buster only, and it is an **opaque tag** rather than the version — +pinned by `TestShareGuest_HeadersTilesNoAdminChrome`, which refused the version when it was tried. + +**State:** controller 0.255.0, language `hu`, 23 standing containers up, nothing installed or removed. diff --git a/documentation/audits/i18n-slice2-2026-09-18/D/live/after-0.255.0.txt b/documentation/audits/i18n-slice2-2026-09-18/D/live/after-0.255.0.txt new file mode 100644 index 00000000..11b73d1d --- /dev/null +++ b/documentation/audits/i18n-slice2-2026-09-18/D/live/after-0.255.0.txt @@ -0,0 +1,7 @@ + stylesheet link : + globe inside card: card@285 footer@1164 globe@1304 -> INSIDE the card, under the footer + GET style.css?v=0.255.0 : 200 93551 bytes + the .shell-lang rule it serves: + .shell-lang { display: flex; justify-content: center; margin-top: 1.5rem; } + old absolute rule gone: 0 + guest share page link : 404 (404 as expected — no live share token) diff --git a/documentation/audits/i18n-slice2-2026-09-18/D/live/probeE.sh b/documentation/audits/i18n-slice2-2026-09-18/D/live/probeE.sh new file mode 100644 index 00000000..75735810 --- /dev/null +++ b/documentation/audits/i18n-slice2-2026-09-18/D/live/probeE.sh @@ -0,0 +1,16 @@ +#!/bin/bash +# v0.255.0 proof. Read-only: three GETs, no session needed. +IP=172.17.0.2:8080; H="Host: felhom.enkisfelhom.hu" +curl -s -H "$H" "http://$IP/login" -o /tmp/lg5.html +echo -n " stylesheet link : "; grep -o ']*>' /tmp/lg5.html +echo -n " globe inside card: "; python3 - <<'PY' +import io +s=io.open('/tmp/lg5.html',encoding='utf-8').read() +c=s.find('class="login-card"'); g=s.find('class="shell-lang"'); f=s.find('class="login-footer"') +print("card@%d footer@%d globe@%d -> %s"%(c,f,g, "INSIDE the card, under the footer" if c]*>' /tmp/gs.html 2>/dev/null || echo "(404 as expected — no live share token)" diff --git a/documentation/audits/i18n-slice2-2026-09-18/D/parity-diff.txt b/documentation/audits/i18n-slice2-2026-09-18/D/parity-diff.txt new file mode 100644 index 00000000..282b8e61 --- /dev/null +++ b/documentation/audits/i18n-slice2-2026-09-18/D/parity-diff.txt @@ -0,0 +1,68 @@ +PARITY DIFF — controller v0.255.0, against the fixtures at 2e9d402 (v0.254.0) + +A real (LCS) diff; the per-session CSRF token is blanked on both sides. Two things change and +nothing else: the stylesheet gains its cache-buster, and the globe moves INSIDE the card. + +[7 fixtures] recovery_locked_can.html, recovery_locked_cannot.html, recovery_locked_confirm.html, recovery_unlocked_apps.html, recovery_unlocked_empty.html, recovery_unlocked_unavailable.html, recovery_unlocked_untagged.html + - + + + -
+ - + -