Root cause of "no formatting for the points": .info-card and .highlight-box are
scoped per page (.page-technologiak / .page-biztonsagimentes) and the new pages
carry .page-teszteles, so NONE of the card chrome applied - the sections were
unstyled text runs. The tester pages now join the technologiak scope, whose h3
is a flex row (these headings carry an icon).
Three more gaps the new pages exposed, all fixed site-wide rather than patched:
- There was no base `a` rule at all, so an inline link in body copy fell back
to the browser default and changed colour once visited. .legal was the only
place this had been fixed. /gyik, /technologiak and /biztonsagimentes each
carry such links and had the same bug.
- `code` was styled only under .legal.
- A <ul> inside an info-card was unstyled: wrong colour, wrong indent.
Justified body copy on the tester pages, as asked. NOTE: no other page
justifies today, so this is deliberately scoped to .page-teszteles and can be
rolled out site-wide or dropped in one edit. hyphens:auto, because Hungarian
sets badly when justified without it.
site.css -> v=10 on all 20 pages.
sitemap.xml: BOM removed. Search Console shows the freshly submitted clean
sitemap as "Sikertelen lekeres" with an empty last-read, and a BOM before the
XML declaration is a known irritant for its parser. The file is otherwise valid
(18 <url>, parses, served 200 as application/xml). No gate covers sitemap.xml
and the BOM rule is for website/*.html only.
Facts corrected - there are NO testers (operator, this evening): "Tester 1" is a
disposable virtual box and "Tester 2" is a friend whose machine is unassembled
and switched off. The page said "Nehany hely mar betoltve", which was untrue; it
now says the test is starting and all 5 places are open. Same correction in
OUTREACH.md (five people needed, not three), CONTEXT.md, and the terms-1.1 mail,
which in practice has one recipient, not two. No scheduled post claimed a
filled place, so none needed editing.
New page pair /teszteles + /en/testing: who the closed test is for, what a
tester needs (machine + internet quoted verbatim from the FAQ, plus a domain),
what they get (terms section 3, nothing new), what we ask for, and how many
places there are. Every "Jelentkezem tesztelonek" button now goes there.
Operator rulings 2026-10-10, recorded in CONTEXT.md:
D1 - the tester's domain is in the TESTER'S OWN name; Felhom pays its fee for
two years and the tester keeps it when the test ends or they leave; DNS
is managed with a token scoped to that one zone only.
D2 - the closed test runs with at most 5 households.
Terms 1.1 adds section 4 (the domain) with the D1 text; old sections 4-11 are
renumbered 5-12 and nothing else changed. Section 11 promises the testers an
e-mail before a change, so one is drafted for the operator to send.
Registered in site_gates.py TWINS/URL and listed in sitemap.xml.
The catalogue side is app-catalog-felhom.eu b7f0f7c. Here: the evidence, the
website, the register and the operator's view.
Website
- Two cards in the Otthon & Eletmod / Home & Lifestyle section of BOTH apps
pages, with assets: grocy-logo.svg is grocy's own icon with its single fill
made white like the other logos, lubelogger-logo.png is the app's own icon
with its dark background dropped and the mark made white (the rule
SparkyFitness's PNG follows), and six screenshots of each app's own UI with a
household's own data, taken headless on the bench from the published template.
- The app count moved 56 -> 58 in 15 places per language set, both languages,
and the open-source tile 49 -> 51. Checked by asking the same patterns for the
new number afterwards. marketing/facebook/COPY.md still says 56 and is NOT
changed: the post it carries is already scheduled.
Evidence
- documentation/audits/new-apps-2026-10-10/ — FIT.md (checklist group 0 for all
three, with the Hungarian-UI column), the bench and box transcripts, the
memory samples, the screenshots and the gate runs.
Register: 137 -> 139 rows, 2 opened, 0 closed.
- R-926 after a remove-keeping-backups and restore, nobody has checked what the
app page shows for an after_install app's generated password. Measured here:
LubeLogger is safe (its login is derived from the environment at every start,
the new password signs in, the data is back); grocy's install password still
signs in from the restored database but the deployed environment no longer
carries ADMIN_PASSWORD at all. Seven apps are in the class.
- R-927 Monica, stopped at checklist 0.2 with the measurements, waiting on the
operator.
Gate scripts: the same console trap in nineteen of them and in repo_gates.py
itself, where it ABORTED THE WHOLE RUNNER at the first gate — printing a
non-ASCII character on this workstation's cp1250 console raised
UnicodeEncodeError before the gate had decided anything, and reuse_refs_check.py
died while printing a NOTE. All now reconfigure their own streams. Red-proof
that the remaining script-test failures are not mine: test_due_checks_gate.py
fails the same 5 of 42 with the change reverted.
I used assets/logo_notext.svg for the header mark. That file is the
LIGHT-BACKGROUND variant: it has SEVEN #00408d fills and ZERO #ffffff, so on
the dark nav the cloud rendered as a hollow outline. The operator caught it.
logo_notext_white.svg is not the answer either -- it is a white OUTLINE
version, also unfilled. Rendered all four candidates side by side on the real
nav background to see it rather than infer it: only logo.svg (and logo.png)
carry the real artwork -- white cloud, #051343 house and servers, #008ddf
swoosh.
FIX: assets/logo-mark.svg, cut from logo.svg -- keep <defs>, path6 and g2;
drop the five wordmark paths and the two empty <text> elements; viewBox
cropped to the mark (70 0 505 295). Vector, correct fills, no text.
All 18 pages point at it; site.css cache-bust v7 -> v8. The CSS comment now
says which file NOT to swap back in, and why.
AND A CORRECTION THAT REMOVES AN OPERATOR TASK (R-916). That row says the
project has no usable vector master because logo.svg "sets felhom.eu as live
text" in 'M+ 2c'/'Vremena Grotesk', and it waits on "the machine with the
fonts". MEASURED today, while cutting the mark out of that very file:
- all five wordmark elements are <path> with real d= geometry
- NO <text> element has any content; the two present are empty leftovers
- the font-family strings the row cites are Inkscape METADATA left on
CONVERTED paths (-inkscape-font-specification). A grep for font-family
finds them and reads as live text -- the likeliest way the original
diagnosis went wrong.
- proof from a renderer that lacks both fonts: Chrome draws logo.svg's
lettering identical to logo.png's, side by side.
NOT re-tested: librsvg specifically -- DooPlex has no rsvg-convert, inkscape
or cairosvg installed today, so the original librsvg/DejaVu observation could
not be reproduced either way. It does not change the structural fact: there
is no font left to substitute. Consequence: the 645x408 PNG is not the only
faithful copy and does not cap picture size.
R-916 state -> READY with "re-check before doing any work: this may need
nothing from the operator at all", rather than closed on my say-so.
HEADER. logo.png carries its OWN "felhom.eu" lettering under the mark, so
putting it next to a typed <span class="logo-text"> said the name twice and
squeezed the mark down to 40px to make room. Now:
- the mark alone, bigger: assets/logo_notext.svg at 54px (44px under 600px).
Vector, so it stays crisp. Its two <text> elements are EMPTY, so R-916's
missing-font problem does not apply to this file -- checked, not assumed.
- the name beside it is the brand's OWN lettering, cropped from logo.png to
the new assets/logo-wordmark.png (632x108, tight bbox).
Why an image and not text: the wordmark's face is "M+ 2c"/"Vremena Grotesk"
(R-916). Nothing here has it, and the site deliberately loads NO external
font -- the privacy notice published this morning states exactly that, so
pulling in Google Fonts to match a logo would have made a published claim
false. Using the artwork is also what the Facebook covers already do. The
white/blue split the operator asked for is in the artwork itself.
Accessibility kept: the mark is alt="" aria-hidden (decorative), the wordmark
carries alt="felhom.eu", so the link still has its accessible name.
FOOTER. The legal links were unstyled, so the browser painted them default
blue and PURPLE once visited. They now follow the site's own convention
(.page-kapcsolat .sidebar-card a): --blue-bright, no underline, underline on
hover. :visited is pinned to the same colour deliberately -- a legal link
that changes colour after one read looks like it stopped working. The same
fix applied to .legal a on the two new legal pages, which had --blue instead
of --blue-bright.
18 of 18 pages carry the new lockup; the English pages keep their /en/ logo
href. site.css cache-bust v6 -> v7 on all 18, per the website rules. Verified
rendered in a browser on both a Hungarian and an English page: both images
load, no .logo-text left anywhere, footer links computed rgb(46,168,245).
site_gates OK (nav/footer per language, BOM, cache-busting, twins).
Two new Hungarian pages, live on push: /adatkezeles (privacy notice) and
/feltetelek (what the free closed test is, and is not). Operator rulings of
2026-10-09: no company exists yet, so the operator is named as a PRIVATE
PERSON with no postal address and no phone; publish before the lawyer has
seen it, because the site was collecting data with no notice at all; the full
ASZF, the impresszum and the review wait for the company (R-802, R-809).
- All 18 pages carry the operator, info@felhom.eu and both links in the
footer. Counted, not assumed: 18 pages found = 18 with both links = 18
structurally valid. English footers say the legal texts are Hungarian.
- The contact form stopped claiming something untrue. The old consent said
"az adatokat harmadik felnek nem adjuk ki" while Resend, Cloudflare and
Google carry the message. Both languages replaced; the link opens in a new
tab so a filled form is not lost.
- site_gates.py NO_TWIN gains the two pages ON PURPOSE, with the reason in a
comment: an unreviewed English legal text would be worse than an honest
pointer from the English footer.
- documentation/legal/{adatkezelesi-tajekoztato,feltetelek}-1.0.md are the
text of record, DERIVED from the published HTML so they cannot drift. The
drafts are kept and marked superseded for the closed test.
FOUR LOAD-BEARING CLAIMS WERE MEASURED, not copied from a vendor or a README:
cookies zero, and no local storage - checked in the browser WITH A
POSITIVE CONTROL (a probe cookie WAS visible to the same
method) after the tracker fired; no Set-Cookie on any response
beacon the exact Umami payload: site id, screen, language, title,
url, referrer - no visitor identifier
Cloudflare DNS only: the public A record 37.191.56.193 is not a
Cloudflare address, so site traffic cannot be proxied
fsn1 Falkenstein, Germany (Hetzner's own location list)
Also measured: felhom-ep0-copy-gc.timer is installed and RAN SUCCESSFULLY
(2026-10-09 08:00, exit 0), so "deleted within 30 days" is true today where
on 2026-10-08 it was written but not switched on.
Three retentions are stated as having NO deadline, deliberately and with the
operator's word: website statistics, web server logs and contact messages
have no automatic deletion, and the pages say so instead of promising a date
nothing enforces. Every other period is enforced by configuration and cited.
No placeholder survived onto either page (0 of "[[", control: the draft still
has 36). The impresszum and the full ASZF are NOT published.
R-813 -> NARROWED. R-915 unblocked: the operator enters the two URLs in the
Meta app's Basic settings; the Live switch stays a separate decision.
R-917 and R-920 -> DEFERRED on the operator's (c): park, publish as posts
once posting starts.