'Wrong or expired code' — the sentence that stopped the 2026-09-20 walk — read back off guest 9201 through the felhom_lang cookie, with the byte-identical Hungarian beside it. The first pass could not see it because its own Hungarian attempts had tripped the lockout; the window was waited out rather than cleared by a restart, because restarting to make a probe pass measures a box nobody runs. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
3.8 KiB
Live proof — the claim page answers in the reader's language (R-596)
Box: guest 9201 (demo-felhom) on felhom-pve, controller 0.259.0, 2026-09-21.
Method: endpoint-level (no browser on DooPlex). The exact URL the page's own form POSTs to,
reached at the controller container's address with the Host header the router requires, carrying
the felhom_lang cookie the language globe sets — i.e. the real path a household takes, not the
?lang= testing override.
The box is CLAIMED, so
/claimis the RESET-code entry. That is the venue the task named, and it is the same handler, the same page and the same nine messages as a first claim.
A — through the cookie (the household's path)
| cookie | screen | answer |
|---|---|---|
felhom_lang=hu |
page title | Jelszó visszaállítása — Felhom |
felhom_lang=hu |
wrong code | „Hibás vagy lejárt kód" |
felhom_lang=hu |
invalid form | „Érvénytelen űrlap — töltsd újra az oldalt." |
felhom_lang=en |
page title | Reset password — Felhom |
felhom_lang=en |
invalid form | "Invalid form — reload the page." |
felhom_lang=en |
after 5 wrong codes | "Too many attempts — try again in 15 minutes." |
Both Hungarian answers are byte-identical to what the box said at 0.258.0.
B — the lockout proved itself, unasked
The probe sent two wrong codes per language. By the English run the per-source lockout had already tripped from the Hungarian ones, so English received the lockout answer instead of the wrong-code one. That is a stronger result than the one planned:
- The English lockout message is proven live, which was not otherwise going to be walked.
- The lockout is language-blind — the counter is per source, not per language. Attempts made
with
felhom_lang=hulocked out thefelhom_lang=enrequest from the same address. A guesser cannot buy extra attempts by switching the cookie.TestClaimLockoutAnswersInEnglishAndCountsTheSameasserts this on the counter; here the live box demonstrated it by accident.
The ?lang=hu override then returned „Túl sok próbálkozás — próbáld újra 15 perc múlva." — the same
lockout, in Hungarian, from the same tripped counter.
What this did to the box
The claim/reset page's rate limiter was left locked for 15 minutes from the probe (a demo box, Tier 0). It clears itself; nothing was configured, no password was changed, no code was consumed. The dashboard password is unchanged — the probe never submitted a valid code.
C — the drill's own screen, walked after the window reopened
The first pass could not see the wrong-code answer in English, because its own Hungarian attempts had tripped the lockout. The window was waited out rather than cleared by restarting the controller — restarting to make a probe pass would have measured a box nobody runs. One wrong code per language, English first so the Hungarian pass could not pre-lock it:
| cookie | one wrong code | answer |
|---|---|---|
felhom_lang=en |
this-is-not-the-code |
"Wrong or expired code" |
felhom_lang=hu |
this-is-not-the-code |
„Hibás vagy lejárt kód" |
That is the exact screen the 2026-09-20 drill stopped on, and it is now in the reader's language.
It is also the sentence VOLUNTEER-first-hour.en.md §13 quotes, and guide_quote_gate.py now fails
the push if the guide and the bundle ever disagree about it.
The box afterwards
The claim/reset rate limiter was exercised and has since cleared. Nothing was configured, no code was consumed, no password was changed — every attempt used a deliberately wrong code, so none of them could reach the password-setting branch. The dashboard password is the one in the operator's credentials file, unchanged, and was used to sign in for the backups capture after all of this.