chore(health-check): record concealment verified against Kanidm 1.11.1 #436

Sammanfogat
supernaut sammanfogade 1 incheckning från chore/concealment-verified-kanidm-1-11-1 in i main 2026-08-17 19:08:22 +00:00
Ägare

Closes out the ADR 0038 gate that the 1.11.1 upgrade deliberately overrode.

Verified by hand on 2026-08-17. All six surfaces, in both directions the gate cares about:

Direction Surface Result
Hidden as intended /user/settings no Full Name field
Hidden as intended /user/settings/account no "Set as primary", no password section, no delete
Hidden as intended Kanidm /ui/profile no username or display-name inputs
Still present /ui/login signed out "No account yet?" note there
Still present portal navbar signed out "Create account" there
Not over-matched /ui/reset?token=... passkey NAME input VISIBLE

That last one is the direction that broke passkey enrolment outright on 2026-08-04, when an unscoped .row:has(input[name="name"]) hid the add-passkey row.

What was verified is recorded next to the tag, not left implicit. The tag alone says a human looked; it does not say what they looked at.

On process

The upgrade was applied with this gate overridden at runtime (-e health_check_concealment=false), never by committing a disabled gate or pre-bumping this value. So nothing in the repository asserted a verification that had not happened. This commit is that assertion, made after the fact it asserts.

Verification

A full --check with the gate ON and no override:

TASK [health-check : Health gate — identity concealment ...]
ok: [bitborg-prod] => "Concealment selectors verified against the deployed Forgejo + Kanidm tags."

PLAY RECAP  bitborg-prod : ok=291  changed=2  failed=0

The remaining changed=2 is the pending Alloy bump (#433), unrelated.

Closes out the ADR 0038 gate that the 1.11.1 upgrade deliberately overrode. Verified by hand on 2026-08-17. All six surfaces, in both directions the gate cares about: | Direction | Surface | Result | | --- | --- | --- | | Hidden as intended | `/user/settings` | no Full Name field | | Hidden as intended | `/user/settings/account` | no "Set as primary", no password section, no delete | | Hidden as intended | Kanidm `/ui/profile` | no username or display-name inputs | | Still present | `/ui/login` signed out | "No account yet?" note there | | Still present | portal navbar signed out | "Create account" there | | **Not over-matched** | `/ui/reset?token=...` | passkey NAME input **VISIBLE** | That last one is the direction that broke passkey enrolment outright on 2026-08-04, when an unscoped `.row:has(input[name="name"])` hid the add-passkey row. **What was verified is recorded next to the tag**, not left implicit. The tag alone says a human looked; it does not say what they looked at. ## On process The upgrade was applied with this gate overridden **at runtime** (`-e health_check_concealment=false`), never by committing a disabled gate or pre-bumping this value. So nothing in the repository asserted a verification that had not happened. This commit is that assertion, made after the fact it asserts. ## Verification A full `--check` with the gate **ON** and no override: ``` TASK [health-check : Health gate — identity concealment ...] ok: [bitborg-prod] => "Concealment selectors verified against the deployed Forgejo + Kanidm tags." PLAY RECAP bitborg-prod : ok=291 changed=2 failed=0 ``` The remaining `changed=2` is the pending Alloy bump (#433), unrelated.
supernaut lade till 1 incheckning 2026-08-17 18:53:59 +00:00
chore(health-check): record concealment verified against Kanidm 1.11.1
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m53s
0630a08e9a
Verified by hand on 2026-08-17, after the 1.10.4 to 1.11.1 upgrade. All six
surfaces checked, in both directions the gate cares about.

Hidden as intended: Forgejo /user/settings has no Full Name field;
/user/settings/account has no "Set as primary", no password section and no
delete; Kanidm /ui/profile has no username or display-name inputs.

Still present: the "No account yet?" note on /ui/login signed out, and "Create
account" in the signed-out portal navbar. These fail the opposite way, by
vanishing and leaving a visitor no route to an account.

Not over-matched: the passkey NAME input on /ui/reset?token=... is VISIBLE.
That is the direction that broke passkey enrolment outright on 2026-08-04, when
an unscoped `.row:has(input[name="name"])` hid the add-passkey row.

What was verified is recorded next to the tag rather than left implicit, because
the tag on its own only says a human looked, not what they looked at.

The upgrade was applied with this gate overridden at runtime
(-e health_check_concealment=false), never by committing a disabled gate or by
pre-bumping this value, so nothing in the repository claimed a verification that
had not happened. This commit is that claim, made after the fact it asserts.

Verified: a full --check with the gate ON and no override now reports
"Concealment selectors verified against the deployed Forgejo + Kanidm tags",
failed=0.
supernaut sammanfogade incheckning e675d44e2c till main 2026-08-17 19:08:22 +00:00
supernaut tog bort grenen chore/concealment-verified-kanidm-1-11-1 2026-08-17 19:08:22 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!436
Ingen beskrivning angiven.