R-243: offsite_escrow_pending — an operator alarm when off-site is on and the escrow never done (7 days); 09 decisions 177-179; 07 R-899 note
gates / gates (push) Successful in 2m48s

Hub code unreleased; ships with tomorrow's hub release.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-08 08:00:08 +02:00
parent de4a8d20ba
commit b119301c6f
10 changed files with 382 additions and 0 deletions
+4
View File
@@ -703,6 +703,10 @@ var operatorOnlyEvents = map[string]bool{
// the snapshots still hold the data and telling a customer "your backups were deleted"
// would be wrong on the usual reading.
"offsite_snapshots_dropped": true,
// R-243 (2026-10-08): off-site ON, the escrow never done, no off-site copy for 7 days. The household already sees
// the reminder on every page; this is the operator's „they have not acted" line. Listed in the SAME commit.
"offsite_escrow_pending": true,
"offsite_escrow_pending_cleared": true,
// v0.127.0 (decisions 68–69, R-820/R-822). The off-site key registrar, its daily check and the
// clean-up window: custody facts about key lines and fingerprints — the household can take no
// action on any of them. Listed in the SAME commit that mints them.
@@ -0,0 +1,14 @@
package notify
import "testing"
// R-243: the escrow-pending alarm and its clear line are the operator's — the household already sees the reminder
// on every page, and a missing customerMessages entry would mail them raw operator English. Red-proof: delete either
// line from operatorOnlyEvents and this fails naming it.
func TestR243_EscrowPendingIsOperatorOnly(t *testing.T) {
for _, e := range []string{"offsite_escrow_pending", "offsite_escrow_pending_cleared"} {
if !operatorOnlyEvents[e] {
t.Errorf("%s is not operator-only", e)
}
}
}