chore(health-check): verify identity concealment against Forgejo 16.0.5 #485
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!485
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "chore/concealment-verified-16.0.5"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Why
health_check_forgejo_concealment_verified_tagwas pinned at16.0.3-rootlesswhileforgejo_image_tagis now16.0.5-rootless(#477). The gate fails the assert on every run, and becausehealth-checkis taggedalwaysit fails anysite.ymlinvocation, whatever--tagsis passed. Nothing can be applied to prod until the surfaces are re-verified.Verification, 2026-09-19, on the live estate
Forgejo 16.0.5-rootless, Kanidm 1.11.1. All six surfaces, both directions.
Concealed as intended
git.bitborg.se/user/settings— no "Full Name" fieldgit.bitborg.se/user/settings/account— no "Set as primary"auth.bitborg.se/ui/profile— no username or display-name inputsStill present
auth.bitborg.se/ui/loginsigned out — "No account yet? Create one at www.bitborg.se/signup"git.bitborg.sesigned out — navbar<a class="item" href="https://www.bitborg.se/signup">Skapa konto</a>Not over-matched
auth.bitborg.se/ui/reset?token=…— the passkey NAME input is visibleWhat is new this round
The sign-up note was checked against the served markup, not only the render. A concealment rule that stops matching no-ops silently, so a passing screenshot alone does not distinguish "the rule matched" from "the rule matched nothing and the note happens to be there for another reason".
/ui/loginstill emits<form id="login">containing<input id="username" name="username">, which is exactly whatform#login:has(input#username[name="username"])::aftertargets./pkg/override.cssis served (200, 17 539 b) and linked on the page.ps-2appears zero times in that markup, so the mobile over-match documented inoverride.css.j2(hides any.ps-2element below 768px) is still inert on 1.11.1.The two findings recorded at the 16.0.3 verification still hold and are kept in the comment block: the break-glass local admin's password and delete sections are
EXTERNAL_USER_DISABLE_FEATURESdesign rather than a broken selector, and the passkey NAME input is gated by Kanidm's ownd-noneuntil the WebAuthn ceremony completes, so the over-match test is#staticPasskeyCreateRowstaying atdisplay:flex.Dry-run
ansible-playbook site.yml --check --diff --limit bitborg-prod:failed=0, so the gate passes. All 11changedtasks are accounted for:The reconciler env file is the eleventh and is new since the previous dry-run:
USER_EXEMPTis rendered fromreconciler_user_exempt, which derives fromforgejo_users, which #484 added an entry to. Its diff is suppressed because the template renders withno_log.After merge
The Forgejo and Postgres apply is now unblocked. It must be followed by a fresh backup and then a drill, in that order — a drill against an archive predating the upgrade fails
doctor [E] migrate.