docs: controller v0.255.0 — the globe fix on the sign-in-flow pages
gates / gates (push) Successful in 22s

R-579 filed and closed the same day: five shell templates loaded style.css
with no cache-buster, so a browser holding the pre-0.254.0 file rendered the
new globe unstyled; and the globe sat outside the card.

- STATUS.md rewritten for the operator: what was seen, why, the third defect
  found while fixing it (version disclosure on the guest share page, caught by
  TestShareGuest_HeadersTilesNoAdminChrome), and the one decision left —
  raise the fleet floor to 0.255.0, with what happens either way.
- 10-localisation.md §3: the shells' asset tag, and why the two guest pages get
  an opaque tag rather than the version.
- Audit D: the parity diff (91 of 106 fixtures identical, every dashboard page
  among them) and the live endpoint evidence from demo-hp guest 9201.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-09-18 15:12:20 +02:00
parent 3d0eb19a86
commit 4df2cd5174
7 changed files with 154 additions and 37 deletions
@@ -0,0 +1,28 @@
# Live validation — controller v0.255.0 on demo-hp guest 9201 (2026-09-18)
**Method: endpoint-level.** No browser on DooPlex. Three GETs, no session needed, nothing written.
The deploy endpoint was not touched (`.claude/rules/live-probes.md`).
```
stylesheet link : <link rel="stylesheet" href="/static/style.css?v=0.255.0">
globe inside card: card@285 footer@1164 globe@1304 -> INSIDE the card, under the footer
GET style.css?v=0.255.0 : 200, 93 551 bytes
the .shell-lang rule it serves:
.shell-lang { display: flex; justify-content: center; margin-top: 1.5rem; }
old absolute rule gone: 0 occurrences
```
Both halves of the defect are answered on the live box: the page now asks for a **versioned** URL, so
a browser holding the pre-0.254.0 file fetches a new one; and the file it fetches carries the **new**
`.shell-lang` rule, with the old viewport-absolute rule gone. The globe's markup sits inside the card
and below the footer.
**What this does NOT prove:** how it LOOKS. `claude-in-chrome` is not available here, so the byte-level
facts above are the whole of what a machine can check. The screenshot that found the bug is the kind
of evidence that settles it — an operator click-through on `https://felhom.enkisfelhom.hu/login`.
**The guest share page** could not be fetched: there is no live share token on this box, so `/s/<x>`
is a 404. Its change is the cache-buster only, and it is an **opaque tag** rather than the version —
pinned by `TestShareGuest_HeadersTilesNoAdminChrome`, which refused the version when it was tried.
**State:** controller 0.255.0, language `hu`, 23 standing containers up, nothing installed or removed.
@@ -0,0 +1,7 @@
stylesheet link : <link rel="stylesheet" href="/static/style.css?v=0.255.0">
globe inside card: card@285 footer@1164 globe@1304 -> INSIDE the card, under the footer
GET style.css?v=0.255.0 : 200 93551 bytes
the .shell-lang rule it serves:
.shell-lang { display: flex; justify-content: center; margin-top: 1.5rem; }
old absolute rule gone: 0
guest share page link : 404 (404 as expected — no live share token)
@@ -0,0 +1,16 @@
#!/bin/bash
# v0.255.0 proof. Read-only: three GETs, no session needed.
IP=172.17.0.2:8080; H="Host: felhom.enkisfelhom.hu"
curl -s -H "$H" "http://$IP/login" -o /tmp/lg5.html
echo -n " stylesheet link : "; grep -o '<link rel="stylesheet"[^>]*>' /tmp/lg5.html
echo -n " globe inside card: "; python3 - <<'PY'
import io
s=io.open('/tmp/lg5.html',encoding='utf-8').read()
c=s.find('class="login-card"'); g=s.find('class="shell-lang"'); f=s.find('class="login-footer"')
print("card@%d footer@%d globe@%d -> %s"%(c,f,g, "INSIDE the card, under the footer" if c<f<g else "WRONG"))
PY
V=$(grep -o 'style.css?v=[^"]*' /tmp/lg5.html | sed 's/.*v=//')
echo -n " GET style.css?v=$V : "; curl -s -o /tmp/css5 -w "%{http_code} %{size_download} bytes\n" -H "$H" "http://$IP/static/style.css?v=$V"
echo " the .shell-lang rule it serves:"; grep -o '\.shell-lang *{[^}]*}' /tmp/css5 | head -2 | sed 's/^/ /'
echo -n " old absolute rule gone: "; grep -c 'shell-lang { position: absolute' /tmp/css5
echo -n " guest share page link : "; curl -s -H "$H" "http://$IP/s/nosuchtoken" -o /tmp/gs.html -w "%{http_code} " ; grep -o '<link rel="stylesheet"[^>]*>' /tmp/gs.html 2>/dev/null || echo "(404 as expected — no live share token)"
@@ -0,0 +1,68 @@
PARITY DIFF — controller v0.255.0, against the fixtures at 2e9d402 (v0.254.0)
A real (LCS) diff; the per-session CSRF token is blanked on both sides. Two things change and
nothing else: the stylesheet gains its cache-buster, and the globe moves INSIDE the card.
[7 fixtures] recovery_locked_can.html, recovery_locked_cannot.html, recovery_locked_confirm.html, recovery_unlocked_apps.html, recovery_unlocked_empty.html, recovery_unlocked_unavailable.html, recovery_unlocked_untagged.html
- <link rel="stylesheet" href="/static/style.css">
+ <link rel="stylesheet" href="/static/style.css?v=0.247.0">
- <div class="shell-lang"><details class="lang-globe">
- <summary class="lang-globe-btn" aria-label="Nyelv" title="Nyelv"><svg class="ico" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round"
- <ul class="lang-globe-menu">
- <li><form method="POST" action="/settings/language"><input type="hidden" name="_csrf" value="CSRF"><input type="hidden" name="back" value="/i18n-fixture"><button type="sub
- <li><form method="POST" action="/settings/language"><input type="hidden" name="_csrf" value="CSRF"><input type="hidden" name="back" value="/i18n-fixture"><button type="sub
- </ul>
-</details></div>
+ <div class="shell-lang"><details class="lang-globe">
+ <summary class="lang-globe-btn" aria-label="Nyelv" title="Nyelv"><svg class="ico" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round"
+ <ul class="lang-globe-menu">
+ <li><form method="POST" action="/settings/language"><input type="hidden" name="_csrf" value="CSRF"><input type="hidden" name="back" value="/i18n-fixture"><button type="sub
+ <li><form method="POST" action="/settings/language"><input type="hidden" name="_csrf" value="CSRF"><input type="hidden" name="back" value="/i18n-fixture"><button type="sub
+ </ul>
+</details></div>
[4 fixtures] claim_reset_code.html, claim_reset_nocode.html, claim_setup_code.html, claim_setup_nocode.html
- <link rel="stylesheet" href="/static/style.css">
+ <link rel="stylesheet" href="/static/style.css?v=test">
- <div class="shell-lang"><details class="lang-globe">
- <summary class="lang-globe-btn" aria-label="Nyelv" title="Nyelv"><svg class="ico" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round"
- <ul class="lang-globe-menu">
- <li><form method="POST" action="/lang"><input type="hidden" name="back" value="/i18n-fixture"><button type="submit" name="lang" value="hu" lang="hu" class="lang-globe-item
- <li><form method="POST" action="/lang"><input type="hidden" name="back" value="/i18n-fixture"><button type="submit" name="lang" value="en" lang="en" class="lang-globe-item
- </ul>
-</details></div>
+ <div class="shell-lang"><details class="lang-globe">
+ <summary class="lang-globe-btn" aria-label="Nyelv" title="Nyelv"><svg class="ico" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round"
+ <ul class="lang-globe-menu">
+ <li><form method="POST" action="/lang"><input type="hidden" name="back" value="/i18n-fixture"><button type="submit" name="lang" value="hu" lang="hu" class="lang-globe-item
+ <li><form method="POST" action="/lang"><input type="hidden" name="back" value="/i18n-fixture"><button type="submit" name="lang" value="en" lang="en" class="lang-globe-item
+ </ul>
+</details></div>
[3 fixtures] launcher_share_password.html, launcher_shared_apps.html, launcher_shared_empty.html
- <link rel="stylesheet" href="/static/style.css">
+ <link rel="stylesheet" href="/static/style.css?v=7da11d7a">
[1 fixtures] login.html
- <link rel="stylesheet" href="/static/style.css">
+ <link rel="stylesheet" href="/static/style.css?v=0.250.0">
- <div class="shell-lang"><details class="lang-globe">
- <summary class="lang-globe-btn" aria-label="Nyelv" title="Nyelv"><svg class="ico" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round"
- <ul class="lang-globe-menu">
- <li><form method="POST" action="/lang"><input type="hidden" name="back" value="/i18n-fixture"><button type="submit" name="lang" value="hu" lang="hu" class="lang-globe-item
- <li><form method="POST" action="/lang"><input type="hidden" name="back" value="/i18n-fixture"><button type="submit" name="lang" value="en" lang="en" class="lang-globe-item
- </ul>
-</details></div>
+ <div class="shell-lang"><details class="lang-globe">
+ <summary class="lang-globe-btn" aria-label="Nyelv" title="Nyelv"><svg class="ico" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round"
+ <ul class="lang-globe-menu">
+ <li><form method="POST" action="/lang"><input type="hidden" name="back" value="/i18n-fixture"><button type="submit" name="lang" value="hu" lang="hu" class="lang-globe-item
+ <li><form method="POST" action="/lang"><input type="hidden" name="back" value="/i18n-fixture"><button type="submit" name="lang" value="en" lang="en" class="lang-globe-item
+ </ul>
+</details></div>
[91 fixtures] IDENTICAL — EVERY dashboard page among them: zero re-captures outside the shells.
DISTINCT CHANGE SHAPES: 4 — the three shells that gained the moved globe AND the buster, and the
two guest share pages, which gained ONLY the buster (they carry no globe) and take an OPAQUE tag
rather than the version: a stranger holding a capability URL is not told which build is running.