chore(health-check): verify identity concealment against Forgejo 16.0.5 #485

Sammanfogat
supernaut sammanfogade 1 incheckning från chore/concealment-verified-16.0.5 in i main 2026-09-19 21:57:49 +00:00
Ägare

Why

health_check_forgejo_concealment_verified_tag was pinned at 16.0.3-rootless while forgejo_image_tag is now 16.0.5-rootless (#477). The gate fails the assert on every run, and because health-check is tagged always it fails any site.yml invocation, whatever --tags is passed. Nothing can be applied to prod until the surfaces are re-verified.

Verification, 2026-09-19, on the live estate

Forgejo 16.0.5-rootless, Kanidm 1.11.1. All six surfaces, both directions.

Concealed as intended

  • git.bitborg.se/user/settings — no "Full Name" field
  • git.bitborg.se/user/settings/account — no "Set as primary"
  • auth.bitborg.se/ui/profile — no username or display-name inputs

Still present

  • auth.bitborg.se/ui/login signed out — "No account yet? Create one at www.bitborg.se/signup"
  • git.bitborg.se signed out — navbar <a class="item" href="https://www.bitborg.se/signup">Skapa konto</a>

Not over-matched

  • auth.bitborg.se/ui/reset?token=… — the passkey NAME input is visible

What is new this round

The sign-up note was checked against the served markup, not only the render. A concealment rule that stops matching no-ops silently, so a passing screenshot alone does not distinguish "the rule matched" from "the rule matched nothing and the note happens to be there for another reason".

  • /ui/login still emits <form id="login"> containing <input id="username" name="username">, which is exactly what form#login:has(input#username[name="username"])::after targets.
  • /pkg/override.css is served (200, 17 539 b) and linked on the page.
  • ps-2 appears zero times in that markup, so the mobile over-match documented in override.css.j2 (hides any .ps-2 element below 768px) is still inert on 1.11.1.

The two findings recorded at the 16.0.3 verification still hold and are kept in the comment block: the break-glass local admin's password and delete sections are EXTERNAL_USER_DISABLE_FEATURES design rather than a broken selector, and the passkey NAME input is gated by Kanidm's own d-none until the WebAuthn ceremony completes, so the over-match test is #staticPasskeyCreateRow staying at display:flex.

Dry-run

ansible-playbook site.yml --check --diff --limit bitborg-prod:

bitborg-prod : ok=299  changed=11  unreachable=0  failed=0  skipped=118

failed=0, so the gate passes. All 11 changed tasks are accounted for:

bump tasks
Forgejo 16.0.3 → 16.0.5 quadlet unit, image pull, quadlet reload, drill orchestrator, registry-mirror script
Postgres 17.10 → 17.11 quadlet unit, image pull, enable/restart, backup verification script
rclone 1.75.0 → 1.75.1 backup script, drill orchestrator
#484 reconciler env file

The reconciler env file is the eleventh and is new since the previous dry-run: USER_EXEMPT is rendered from reconciler_user_exempt, which derives from forgejo_users, which #484 added an entry to. Its diff is suppressed because the template renders with no_log.

After merge

The Forgejo and Postgres apply is now unblocked. It must be followed by a fresh backup and then a drill, in that order — a drill against an archive predating the upgrade fails doctor [E] migrate.

## Why `health_check_forgejo_concealment_verified_tag` was pinned at `16.0.3-rootless` while `forgejo_image_tag` is now `16.0.5-rootless` (#477). The gate fails the assert on every run, and because `health-check` is tagged `always` it fails **any** `site.yml` invocation, whatever `--tags` is passed. Nothing can be applied to prod until the surfaces are re-verified. ## Verification, 2026-09-19, on the live estate Forgejo 16.0.5-rootless, Kanidm 1.11.1. All six surfaces, both directions. **Concealed as intended** - `git.bitborg.se/user/settings` — no "Full Name" field - `git.bitborg.se/user/settings/account` — no "Set as primary" - `auth.bitborg.se/ui/profile` — no username or display-name inputs **Still present** - `auth.bitborg.se/ui/login` signed out — "No account yet? Create one at www.bitborg.se/signup" - `git.bitborg.se` signed out — navbar `<a class="item" href="https://www.bitborg.se/signup">Skapa konto</a>` **Not over-matched** - `auth.bitborg.se/ui/reset?token=…` — the passkey NAME input is visible ## What is new this round The sign-up note was checked against the **served markup**, not only the render. A concealment rule that stops matching no-ops silently, so a passing screenshot alone does not distinguish "the rule matched" from "the rule matched nothing and the note happens to be there for another reason". - `/ui/login` still emits `<form id="login">` containing `<input id="username" name="username">`, which is exactly what `form#login:has(input#username[name="username"])::after` targets. - `/pkg/override.css` is served (200, 17 539 b) and linked on the page. - `ps-2` appears **zero** times in that markup, so the mobile over-match documented in `override.css.j2` (hides any `.ps-2` element below 768px) is still inert on 1.11.1. The two findings recorded at the 16.0.3 verification still hold and are kept in the comment block: the break-glass **local** admin's password and delete sections are `EXTERNAL_USER_DISABLE_FEATURES` design rather than a broken selector, and the passkey NAME input is gated by Kanidm's own `d-none` until the WebAuthn ceremony completes, so the over-match test is `#staticPasskeyCreateRow` staying at `display:flex`. ## Dry-run `ansible-playbook site.yml --check --diff --limit bitborg-prod`: ``` bitborg-prod : ok=299 changed=11 unreachable=0 failed=0 skipped=118 ``` `failed=0`, so the gate passes. All 11 `changed` tasks are accounted for: | bump | tasks | | --- | --- | | Forgejo 16.0.3 → 16.0.5 | quadlet unit, image pull, quadlet reload, drill orchestrator, registry-mirror script | | Postgres 17.10 → 17.11 | quadlet unit, image pull, enable/restart, backup verification script | | rclone 1.75.0 → 1.75.1 | backup script, drill orchestrator | | #484 | reconciler env file | The reconciler env file is the eleventh and is new since the previous dry-run: `USER_EXEMPT` is rendered from `reconciler_user_exempt`, which derives from `forgejo_users`, which #484 added an entry to. Its diff is suppressed because the template renders with `no_log`. ## After merge The Forgejo and Postgres apply is now unblocked. It must be followed by a **fresh backup and then a drill, in that order** — a drill against an archive predating the upgrade fails `doctor [E] migrate`.
supernaut lade till 1 incheckning 2026-09-19 20:49:51 +00:00
chore(health-check): verify identity concealment against Forgejo 16.0.5
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m43s
eae1677115
All six ADR 0038 surfaces re-checked on 16.0.5-rootless / Kanidm 1.11.1, both
directions: the concealed fields stay concealed, the sign-up note and the
navbar link stay present, and the passkey row is not over-matched.

The sign-up note was checked against the served markup as well as the render.
/ui/login still emits form#login containing input#username[name="username"],
so form#login:has(...)::after still matches rather than silently no-opping.
ps-2 remains absent from that page, so the mobile over-match documented in
override.css.j2 stays inert.

Unblocks the pending Forgejo 16.0.5 and Postgres 17.11 apply.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
supernaut sammanfogade incheckning 84b8d91a19 till main 2026-09-19 21:57:49 +00:00
supernaut tog bort grenen chore/concealment-verified-16.0.5 2026-09-19 21:57:49 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!485
Ingen beskrivning angiven.