Files
felhom.eu/documentation/audits/i18n-slice2-2026-09-18/B/live

Live validation — controller v0.253.0 on demo-hp guest 9201 (2026-09-18, release B)

Method: endpoint-level, stated as such. No browser on DooPlex. Session from a real POST /login; X-CSRF-Token from the page meta for API calls; the password passed as a file and deleted from host and guest afterwards.

0. A mistake I made, first — an app was installed on the demo box and removed

My first release-B probe posted /api/stacks/vaultwarden/deploy with empty values, expecting the required-field refusal. The deploy API answers 202 and validates ASYNCHRONOUSLY, and vaultwarden has no required field — so it installed. That is the same mistake the 2026-09-17 session recorded in STATUS.md, repeated. It is not a trap in the product; it is a trap in the probe, and the lesson is narrower than "pick a different app": the deploy endpoint cannot be probed for a refusal at all, because it accepts before it validates.

Removed through the product's own path — stop, then POST /remove with remove_hdd_data and remove_backups — and verified gone: no container, no /opt/felhom/stacks/vaultwarden, zero vaultwarden volumes. The 23 standing containers are all up. The removal answered hdd_note: „Az alkalmazás nem tárolt saját adatot külső meghajtón…", so nothing was on a drive.

The probe was rewritten to use only endpoints whose validator runs BEFORE any mutation (probeB2.sh, probeB3.sh).

1. An error made deep in a package, rendered on the page in each language

POST /sharing/shares with a bad name. The message is produced in internal/settings/smb.go, three layers below the handler, and the redirect is FOLLOWED so what is read is what the page shows.

refusal hu en
name has a slash „a megosztás neve nem tartalmazhat perjelet vagy pontot" "the share name cannot hold a slash or a dot"
name empty „a megosztás neve nem lehet üres" "the share name cannot be empty"
name longer than 15 „a megosztás neve legfeljebb 15 karakter lehet" "the share name can be at most 15 characters"
name starts with _ „a megosztás neve nem kezdődhet aláhúzással — ezek a nevek a rendszernek vannak fenntartva" "the share name cannot start with an underscore — those names are reserved for the system"

Every Hungarian line is the literal that stood in smb.go before the conversion, byte for byte.

2. The compatibility case, still true after B

/sharing?flash=Be%C3%A1ll%C3%ADt%C3%A1s+mentve. — a URL an older controller minted — renders „Beállítás mentve." in both languages. Shown verbatim, never as a key, never dropped.

3. What stays English on purpose, confirmed live

POST /api/stacks/felhom-controller/remove → 403 stack "felhom-controller" is protected and cannot be removed. Internal English, identical in both languages: R-569, not this slice. Recorded here so it is not read as a gap release B left.

An agent-side refusal (/api/disks/format on a device that is not whitelisted) comes back as agentapi: format: HTTP 400: storage: refusing to operate on non-whitelisted block device — the AGENT's sentence, relayed verbatim in both languages. That is the rule working: text this controller did not write is text it does not translate.

4. State left behind

Controller 0.253.0; saved language hu (every English probe used the ?lang=en override, which is not persisted); 23 standing containers up, unchanged; vaultwarden installed by mistake and fully removed; no drive touched, no floor raised, no golden baked.