9167cf53af
gates / gates (push) Successful in 23s
The hub has written every customer e-mail in Hungarian whatever the box was set to. The box has published its language since controller v0.247.0; nothing read it. Now it does. Nothing an operator reads changes. The Hungarian mails are byte-identical, and that is a diff rather than a reading: 56 goldens per language captured from v0.117.0 BEFORE any string moved, and all 56 Hungarian ones pass unchanged after every sentence was routed through the new bundle. - internal/i18n: flat bundle, 79 keys, hu authoritative + hu fallback, ceiling 0. - customerMessages/severityLabels are DERIVED from the bundle, so a sentence is written in one place and all 40+ tests that read those maps still work. - Language order: last reported -> created-with -> hu. reports.language defaults to EMPTY, never hu: "never told us" is not "chose Hungarian". - message_customer on POST /api/v1/event, additive and optional forever, for the sentences the box composes and the hub cannot translate. - The bind page is per-language, and its `expired` state stays Hungarian: it is the state an unknown token lands in, so rendering a real English customer's token in English would make the LANGUAGE answer what the TEXT refuses to. Two defects found inside the release: - R-581: the newest report was picked by received_at, which has SECOND granularity, so same-second reports tied and the winner was arbitrary. Ordered by the autoincrement id now. GetCustomers() still has the shape - row open. - R-582: the English copy-guard stems, ported word for word from Hungarian, convicted 141 honest sentences. The English claim is a phrase with a modal. R-555 closed: the language allowlist entry is out of wire_contract_gate.py. hub_copy_gate.py follows the sentences into the bundle - without that it would have scanned four files that no longer hold any customer text and reported success. Three new decoys incl. an innocent control. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
69 lines
3.1 KiB
Go
69 lines
3.1 KiB
Go
package web
|
|
|
|
// R-497 — the „Tulajdonosi jelmondat" is delivered by NOTHING in the product: it is minted at customer
|
|
// creation, shown only on the operator's customer page, and never e-mailed (the operator has not ruled
|
|
// that e-mail may carry it). Measured 2026-09-14 in the first-hour drill: the self-bind mail told the
|
|
// customer they had received it „a beállításkor" — true only if the operator remembered to hand it over,
|
|
// and nothing told the operator to.
|
|
//
|
|
// These pin the CONSEQUENCE, not a string for its own sake: the operator is told at the moment the
|
|
// phrase exists, the page repeats it where the phrase is shown, and the customer's mail names the person
|
|
// they got it from. The last test pins what must NOT change — the mail still carries no phrase.
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
|
|
"gitea.dooplex.hu/admin/felhom-hub/internal/notify"
|
|
)
|
|
|
|
// handoverMarker is the operator-facing instruction. One sentence, rendered in two places.
|
|
const handoverMarker = "Hand this phrase to the customer now"
|
|
|
|
func TestCustomerPage_CreatedFlashTellsTheOperatorToHandOverThePhrase(t *testing.T) {
|
|
s, st := newTestServer(t)
|
|
seedCustomer(t, st, "acme", "")
|
|
|
|
created := renderCustomerPageWithQuery(t, s, "acme", "?flash=created")
|
|
if !strings.Contains(created, handoverMarker) {
|
|
t.Errorf("the customer-created flash does not tell the operator to hand over the phrase:\n%s", created)
|
|
}
|
|
if !strings.Contains(created, "never e-mailed") {
|
|
t.Error("the created flash must say the phrase is never e-mailed — otherwise the operator waits for a mail")
|
|
}
|
|
|
|
// Nominal page (no flash): the instruction stays beside the phrase, where the operator reveals it.
|
|
plain := renderCustomerPage(t, s, "acme")
|
|
if !strings.Contains(plain, handoverMarker) {
|
|
t.Error("the Credentials block does not repeat the hand-over sentence beside the phrase")
|
|
}
|
|
}
|
|
|
|
func TestSelfBindEmail_SaysWhoHandedOverThePhrase(t *testing.T) {
|
|
_, body := notify.FormatSelfBindEmail("hu", "acme", "https://hub.example/bind/tok")
|
|
|
|
if strings.Contains(body, "beállításkor kaptál") {
|
|
t.Error("the mail still says the customer received the phrase „a beállításkor” — nothing delivers it then")
|
|
}
|
|
if !strings.Contains(body, "üzemeltetőjétől") {
|
|
t.Errorf("the mail must name who hands over the phrase (the Felhom operator):\n%s", body)
|
|
}
|
|
// Unchanged contract: one name, and what the thing is.
|
|
if !strings.Contains(body, "tulajdonosi jelmondatodat") || !strings.Contains(body, "5 szóból álló kifejezést") {
|
|
t.Error("the mail lost the secret's name or its description")
|
|
}
|
|
}
|
|
|
|
// The phrase itself must never ride the mail. A customer with a seeded phrase gets a mail that does not
|
|
// contain it — the builder takes no phrase argument today; this pins that no future edit adds one via
|
|
// the link text or a helper.
|
|
func TestSelfBindEmail_NeverCarriesThePhrase(t *testing.T) {
|
|
const phrase = "alma korte szilva barack meggy"
|
|
_, body := notify.FormatSelfBindEmail("hu", "acme", "https://hub.example/bind/tok")
|
|
for _, w := range strings.Fields(phrase) {
|
|
if strings.Contains(body, w) {
|
|
t.Errorf("the self-bind mail contains a passphrase word %q", w)
|
|
}
|
|
}
|
|
}
|