Files
felhom.eu/documentation/audits/i18n-closing-2026-09-21/live/claim-page.md
T
admin 11aaeaee8a
gates / gates (push) Successful in 28s
the drill's own screen, walked in English on the live box
'Wrong or expired code' — the sentence that stopped the 2026-09-20 walk — read
back off guest 9201 through the felhom_lang cookie, with the byte-identical
Hungarian beside it. The first pass could not see it because its own Hungarian
attempts had tripped the lockout; the window was waited out rather than cleared
by a restart, because restarting to make a probe pass measures a box nobody runs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-21 08:18:48 +02:00

68 lines
3.8 KiB
Markdown

# Live proof — the claim page answers in the reader's language (R-596)
**Box:** guest 9201 (`demo-felhom`) on `felhom-pve`, controller **0.259.0**, 2026-09-21.
**Method:** endpoint-level (no browser on DooPlex). The exact URL the page's own form POSTs to,
reached at the controller container's address with the `Host` header the router requires, carrying
the **`felhom_lang` cookie the language globe sets** — i.e. the real path a household takes, not the
`?lang=` testing override.
> **The box is CLAIMED, so `/claim` is the RESET-code entry.** That is the venue the task named, and
> it is the same handler, the same page and the same nine messages as a first claim.
## A — through the cookie (the household's path)
| cookie | screen | answer |
|---|---|---|
| `felhom_lang=hu` | page title | `Jelszó visszaállítása — Felhom` |
| `felhom_lang=hu` | wrong code | „Hibás vagy lejárt kód" |
| `felhom_lang=hu` | invalid form | „Érvénytelen űrlap — töltsd újra az oldalt." |
| `felhom_lang=en` | page title | `Reset password — Felhom` |
| `felhom_lang=en` | invalid form | **"Invalid form — reload the page."** |
| `felhom_lang=en` | after 5 wrong codes | **"Too many attempts — try again in 15 minutes."** |
Both Hungarian answers are byte-identical to what the box said at 0.258.0.
## B — the lockout proved itself, unasked
The probe sent two wrong codes per language. By the English run the **per-source lockout had already
tripped from the Hungarian ones**, so English received the lockout answer instead of the wrong-code
one. That is a stronger result than the one planned:
1. The **English lockout message** is proven live, which was not otherwise going to be walked.
2. The **lockout is language-blind** — the counter is per source, not per language. Attempts made
with `felhom_lang=hu` locked out the `felhom_lang=en` request from the same address. A guesser
cannot buy extra attempts by switching the cookie. `TestClaimLockoutAnswersInEnglishAndCountsTheSame`
asserts this on the counter; here the live box demonstrated it by accident.
The `?lang=hu` override then returned „Túl sok próbálkozás — próbáld újra 15 perc múlva." — the same
lockout, in Hungarian, from the same tripped counter.
## What this did to the box
The claim/reset page's rate limiter was left locked for **15 minutes** from the probe (a demo box,
Tier 0). It clears itself; nothing was configured, no password was changed, no code was consumed.
The dashboard password is **unchanged** — the probe never submitted a valid code.
## C — the drill's own screen, walked after the window reopened
The first pass could not see the wrong-code answer in English, because its own Hungarian attempts had
tripped the lockout. The window was **waited out** rather than cleared by restarting the controller —
restarting to make a probe pass would have measured a box nobody runs. One wrong code per language,
**English first** so the Hungarian pass could not pre-lock it:
| cookie | one wrong code | answer |
|---|---|---|
| `felhom_lang=en` | `this-is-not-the-code` | **"Wrong or expired code"** |
| `felhom_lang=hu` | `this-is-not-the-code` | „Hibás vagy lejárt kód" |
**That is the exact screen the 2026-09-20 drill stopped on**, and it is now in the reader's language.
It is also the sentence `VOLUNTEER-first-hour.en.md` §13 quotes, and `guide_quote_gate.py` now fails
the push if the guide and the bundle ever disagree about it.
## The box afterwards
The claim/reset rate limiter was exercised and has since cleared. **Nothing was configured, no code
was consumed, no password was changed** — every attempt used a deliberately wrong code, so none of
them could reach the password-setting branch. The dashboard password is the one in the operator's
credentials file, unchanged, and was used to sign in for the backups capture after all of this.