Files
felhom.eu/documentation/audits/i18n-closing-2026-09-21/live/claim-page.md
T
admin 11aaeaee8a
gates / gates (push) Successful in 28s
the drill's own screen, walked in English on the live box
'Wrong or expired code' — the sentence that stopped the 2026-09-20 walk — read
back off guest 9201 through the felhom_lang cookie, with the byte-identical
Hungarian beside it. The first pass could not see it because its own Hungarian
attempts had tripped the lockout; the window was waited out rather than cleared
by a restart, because restarting to make a probe pass measures a box nobody runs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-21 08:18:48 +02:00

3.8 KiB

Live proof — the claim page answers in the reader's language (R-596)

Box: guest 9201 (demo-felhom) on felhom-pve, controller 0.259.0, 2026-09-21. Method: endpoint-level (no browser on DooPlex). The exact URL the page's own form POSTs to, reached at the controller container's address with the Host header the router requires, carrying the felhom_lang cookie the language globe sets — i.e. the real path a household takes, not the ?lang= testing override.

The box is CLAIMED, so /claim is the RESET-code entry. That is the venue the task named, and it is the same handler, the same page and the same nine messages as a first claim.

cookie screen answer
felhom_lang=hu page title Jelszó visszaállítása — Felhom
felhom_lang=hu wrong code „Hibás vagy lejárt kód"
felhom_lang=hu invalid form „Érvénytelen űrlap — töltsd újra az oldalt."
felhom_lang=en page title Reset password — Felhom
felhom_lang=en invalid form "Invalid form — reload the page."
felhom_lang=en after 5 wrong codes "Too many attempts — try again in 15 minutes."

Both Hungarian answers are byte-identical to what the box said at 0.258.0.

B — the lockout proved itself, unasked

The probe sent two wrong codes per language. By the English run the per-source lockout had already tripped from the Hungarian ones, so English received the lockout answer instead of the wrong-code one. That is a stronger result than the one planned:

  1. The English lockout message is proven live, which was not otherwise going to be walked.
  2. The lockout is language-blind — the counter is per source, not per language. Attempts made with felhom_lang=hu locked out the felhom_lang=en request from the same address. A guesser cannot buy extra attempts by switching the cookie. TestClaimLockoutAnswersInEnglishAndCountsTheSame asserts this on the counter; here the live box demonstrated it by accident.

The ?lang=hu override then returned „Túl sok próbálkozás — próbáld újra 15 perc múlva." — the same lockout, in Hungarian, from the same tripped counter.

What this did to the box

The claim/reset page's rate limiter was left locked for 15 minutes from the probe (a demo box, Tier 0). It clears itself; nothing was configured, no password was changed, no code was consumed. The dashboard password is unchanged — the probe never submitted a valid code.

C — the drill's own screen, walked after the window reopened

The first pass could not see the wrong-code answer in English, because its own Hungarian attempts had tripped the lockout. The window was waited out rather than cleared by restarting the controller — restarting to make a probe pass would have measured a box nobody runs. One wrong code per language, English first so the Hungarian pass could not pre-lock it:

cookie one wrong code answer
felhom_lang=en this-is-not-the-code "Wrong or expired code"
felhom_lang=hu this-is-not-the-code „Hibás vagy lejárt kód"

That is the exact screen the 2026-09-20 drill stopped on, and it is now in the reader's language. It is also the sentence VOLUNTEER-first-hour.en.md §13 quotes, and guide_quote_gate.py now fails the push if the guide and the bundle ever disagree about it.

The box afterwards

The claim/reset rate limiter was exercised and has since cleared. Nothing was configured, no code was consumed, no password was changed — every attempt used a deliberately wrong code, so none of them could reach the password-setting branch. The dashboard password is the one in the operator's credentials file, unchanged, and was used to sign in for the backups capture after all of this.