R-304 option C (hub half): recovery_older_package allowlisted and operator-only; design + row updated
gates / gates (push) Successful in 4m13s

Unreleased; ships with tomorrow's hub release.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-08 10:09:20 +02:00
parent 83e6167145
commit 5beedcce1a
7 changed files with 43 additions and 4 deletions
+3
View File
@@ -707,6 +707,9 @@ var operatorOnlyEvents = map[string]bool{
// the reminder on every page; this is the operator's „they have not acted" line. Listed in the SAME commit.
"offsite_escrow_pending": true,
"offsite_escrow_pending_cleared": true,
// R-304 option C (2026-10-08, decision 183): a household's recovery code opens — or may open — an OLDER sealed
// escrow package; reopening old history is operator-only (R-312), so only the operator is told. Same commit.
"recovery_older_package": true,
// v0.127.0 (decisions 68–69, R-820/R-822). The off-site key registrar, its daily check and the
// clean-up window: custody facts about key lines and fingerprints — the household can take no
// action on any of them. Listed in the SAME commit that mints them.
@@ -6,7 +6,8 @@ import "testing"
// on every page, and a missing customerMessages entry would mail them raw operator English. Red-proof: delete either
// line from operatorOnlyEvents and this fails naming it.
func TestR243_EscrowPendingIsOperatorOnly(t *testing.T) {
for _, e := range []string{"offsite_escrow_pending", "offsite_escrow_pending_cleared"} {
// R-304 option C's recovery_older_package is pinned here too (same reason: operator-only, no household text).
for _, e := range []string{"offsite_escrow_pending", "offsite_escrow_pending_cleared", "recovery_older_package"} {
if !operatorOnlyEvents[e] {
t.Errorf("%s is not operator-only", e)
}