chore(health-check): verify identity concealment against forgejo 16.0.3 #455
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!455
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "concealment-verify-16.0.3"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Closes the loop on the 16.0.3 apply: the post-apply health gate (ADR 0038) failed by design
until the concealment surfaces were re-verified against the deployed images.
All six surfaces checked on the live instance (Forgejo 16.0.3-rootless, Kanidm 1.11.1):
/user/settings— no Full Name field/user/settings/account— no "Set as primary"display:none/ui/profile— no username/display-name inputs/ui/loginsigned out — sign-up note/ui/reset— passkey naming row not over-matched#staticPasskeyCreateRowatdisplay:flexTwo clarifications recorded in the defaults comment:
/user/settings/accountare visible to the localbreak-glass admin (
login_type 0) by design;EXTERNAL_USER_DISABLE_FEATURESremovesthem for external accounts (
login_type 6, verified in the DB for every external user).form#passkeyNamingForm, hidden byKanidm's own
d-nonestep-gating until the WebAuthn ceremony completes — so theover-match check is "our selectors leave the row at
display:flex", not "the input isvisible on page load".