Files
felhom.eu/documentation/audits/website-refresh-2026-10-08/shots
admin 67b3fd23d1
gates / gates (push) Failing after 13m1s
website refresh: true numbers (56 apps), claims checked against the capability map, ten missing apps, an English twin of every public page (public, choice B), 404 page; site gates 13-18 + 11 decoys; R-902 opened
Part A: claim table documentation/audits/website-refresh-2026-10-08/claims.md; "100% open source" corrected
from the licence read; unbacked claims cut (firewall, RAID, snapshots, new-machine restore, self-managed
mode, household VPN, "never lost"). Part B: dawarich, docmost, grimmory, homebox, karakeep, mealie, metube,
radicale, recipe-importer, sparkyfitness cards; plant-it and wger cut (not offered). Part C: /en/ twins,
nav language switch, hreflang both ways, sitemap with xhtml:link, og-image-en.png. Part D: site_gates.py
twins/lang/same-apps/no-Hungarian/FAQ-JSON-LD/tail. Operator ruling 9 + choice B in 10-localisation.md §11,
§10.7. Register: R-902 (contact mailer source in no repo); R-813, R-784, R-559 annotated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012qRErfCoiTkvDK9N5XHbzb
2026-10-08 08:29:17 +02:00
..

Website refresh 2026-10-08: logos and screenshots for five catalog apps

Five apps get logos and screenshots here: Docmost, Homebox, Mealie, Recipe Importer and SparkyFitness. The work used the same method as felhom.eu 8e31b450 and 344081f0, and ran on 2026-10-08 between 05:55 and 06:28 UTC.

Method

  • Where the work ran. Scratch guest 9202 on demo-hp, reached only by ssh hp + pct exec 9202 -- bash -s. Scripts went in on stdin, so nothing was written on the demo-hp host. Guest 9201 and the other machines were not touched.
  • Install and removal. Each app was installed through the product (POST /api/stacks/<app>/deploy from tools/wr.py deploy, which uses the catalog's box_walk.deploy) and removed through the product (stop, then POST /api/stacks/<app>/remove with remove_hdd_data and remove_backups set to true). The work handled one app at a time: install, seed, screenshot, copy the raw PNGs off the box, remove, verify. <app>/run.log holds each removal and its VERIFY block. baseline-9202.txt and teardown-9202.txt hold the box state before and after.
  • Screenshots. Headless Chrome ran inside 9202: ghcr.io/puppeteer/puppeteer:latest, digest sha256:60ad89b1…. This image was already on the box and was left in place. Chrome ran on network traefik-public with --host-resolver-rules=MAP * 172.18.0.5 (traefik) and --ignore-certificate-errors, so it reached each app under its real name <sub>.enkisfelhom.hu. The dashboard session cookie let Chrome through the setup gate, the same way a household passes it.
  • Shot sizes. Desktop shots are 1280x800. Phone shots are 390x844 at 2x. tools/towebp.py converted the PNGs to WebP (Pillow, quality 80, method 6).
  • Demo content. All content is invented: "Demo Család" / demo@example.com, made-up items, recipes and pages. No third-party site was contacted for content.
  • Secrets. No secret is in this directory. The dashboard session and the demo password went into the guest only as a 0600 secrets.json, and shred -u removed it as soon as Chrome exited. Chrome output passed through a filter that redacted long values.

Per app

Docmost (docmost/docmost:0.96.0)

  • Logo. docmost-logo.png is /app/apps/client/dist/icons/app-icon-512x512.png from the image, copied byte for byte. The project ships no SVG logo: the image holds only vite.svg, the Vite placeholder, and the GitHub tree of tag v0.96.0 has no other SVG. Licence: AGPL-3.0 (GitHub LICENSE).
  • Setup. Docmost's own first-run setup (POST /api/auth/setup) created the workspace "Demo Család". Five invented Hungarian pages were added through its own Markdown import (/api/pages/import).
  • Interface language. Docmost 0.96 ships no Hungarian locale, so the interface is in English.
  • Shots.
    1. Home: "Spaces you belong to" and the recently updated pages.
    2. The page "Házirend": headings, a list and a table, with the page tree on the left.
    3. Phone: the same page.

Homebox (ghcr.io/sysadminsmedia/homebox:0.26.2)

  • Logo. homebox-logo.svg is /favicon.svg, served by the app's own binary (embedded static/public/favicon.svg), copied byte for byte. Licence: AGPL-3.0 (GitHub).
  • Seed. Done through Homebox's own API (/api/v1/entities, /api/v1/tags). The seed added four locations, three tags and eight items with prices in HUF. Homebox's empty English default locations and tags were deleted.
  • Interface language. Hungarian, set with Homebox's own language preference.
  • Shots.
    1. Home: totals, recently added items and locations.
    2. The item "Fűnyíró".
    3. Phone: home.

Mealie (ghcr.io/mealie-recipes/mealie:v3.28.0)

  • Logo. mealie-logo.svg comes from /opt/mealie/lib/python3.14/site-packages/mealie/frontend/icons/safari-pinned-tab.svg in the image. Mealie's colour icons are PNG only, so the SVG was edited in two ways:

    • The single fill colour was changed from #000000 to #E58325. That orange was sampled from the image's own frontend/icon.png.
    • The DOCTYPE and the fixed width/height were removed. The viewBox was kept.

    Licence: AGPL-3.0-only (wheel METADATA in the image; GitHub agrees).

  • Seed. The first account (changeme@example.com) signed in with the password this install generated, through /api/auth/token. It added six invented Hungarian recipes and a six-day dinner plan through Mealie's own API, and set the display name to "Demo Család".

  • Interface language. Hungarian (the cookie that Mealie's own language switch writes). The first-login wizard was skipped with Mealie's own "I'm already set up" button.

  • Shots.

    1. The recipe "Rakott krumpli".
    2. The meal planner for the week.
    3. Phone: the recipe.

Recipe Importer (gitea.dooplex.hu/admin/recipe-importer:v0.9.11, the operator's own project)

  • Logo. recipe-importer-logo.svg is /app/app/assets/logo_favicon_2.svg from the image, copied byte for byte. This is the file the app serves as its favicon. The image also holds /app/app/assets/logo.svg, which is the same mark plus the word "felhom.eu".

  • Note: this logo is the Felhom cloud mark, not a separate app logo. The project has no logo of its own.

  • Licence. No LICENSE file: gitea.dooplex.hu/admin/recipe-importer/raw/branch/main/LICENSE returns 404, and the repo API lists no licence.

  • Setup. No recipe site was contacted. The app's own settings form was saved with an invented Mealie address (https://recipes.example.hu) and a placeholder key, because the import page opens only after that save. No Mealie existed behind the address.

  • Shots.

    1. Single import, with an invented example.com address typed in.
    2. Bulk import, with four invented addresses.
    3. Settings after the save.

    The phone layout overflows sideways (the app's own CSS), so no phone shot was used: raw/unused-phone-import.png.

SparkyFitness (codewithcj/sparkyfitness:v0.17.3 + _server:v0.17.3)

  • Logo. sparkyfitness-logo.png is /usr/share/nginx/html/images/icons/icon-512x512.png from the frontend image, copied byte for byte. It is 384x512 and 129 KB, larger than the other PNG logos (the largest is 31 KB). The project ships no SVG logo: its GitHub tree has only feature icons.
  • Licence: NOT open source. LICENSE at tag v0.17.3 is a custom licence: "use, copy, modify, and distribute the Software for non-commercial purposes only". This affects a paid service that offers the app, and the operator should read it. It was not judged here.
  • Seed. An invented account was made through its own sign-up (/api/auth/sign-up/email), which is open while the setup gate is up. Six invented foods and today's diary went in through /api/foods and /api/food-entries. Fourteen days of invented weight and waist check-ins went in through /api/measurements/check-in. Five glasses of water went in with the diary's own "+" button.
  • Interface language. Set to Hungarian in the account preferences. The app's own translation is partial, so some labels stay in English.
  • Dismissed screens.
    • The "new version available (v1.8.0)" notice was dismissed by setting the app's own dismissedReleaseVersion key. The notice points to the GitHub release; where the app fetches it from was not checked. Its first appearance is in raw/unused-first-load-version-notice.png.
    • The onboarding wizard was closed with its own "Skip".
  • Shots.
    1. The diary: energy goal, nutrition summary and water.
    2. Reports > Measurements: the 14-day weight and waist trend.
    3. Phone: the diary.

Tools

  • tools/wr.py: install, shoot, fetch, remove and verify.
  • tools/sw.py: the box_walk shim that runs scripts through pct exec stdin.
  • tools/<app>.js: one Chrome script per app.
  • tools/mealie-probe.js: a read-only probe.
  • tools/towebp.py: the PNG to WebP converter.
  • tools/env.sh: the two path variables.