chore(health-check): verify identity concealment against forgejo 16.0.3 #455

Sammanfogat
supernaut sammanfogade 1 incheckning från concealment-verify-16.0.3 in i main 2026-08-31 12:04:45 +00:00
Ägare

Closes the loop on the 16.0.3 apply: the post-apply health gate (ADR 0038) failed by design
until the concealment surfaces were re-verified against the deployed images.

All six surfaces checked on the live instance (Forgejo 16.0.3-rootless, Kanidm 1.11.1):

Surface Result
/user/settings — no Full Name field hidden
/user/settings/account — no "Set as primary" selector matches, computed display:none
/ui/profile — no username/display-name inputs hidden
/ui/login signed out — sign-up note present
signed-out navbar — Create account link present, points at the portal signup
/ui/reset — passkey naming row not over-matched #staticPasskeyCreateRow at display:flex

Two clarifications recorded in the defaults comment:

  • The password/delete sections on /user/settings/account are visible to the local
    break-glass admin (login_type 0) by design; EXTERNAL_USER_DISABLE_FEATURES removes
    them for external accounts (login_type 6, verified in the DB for every external user).
  • On Kanidm 1.11.1 the passkey name input is inside form#passkeyNamingForm, hidden by
    Kanidm's own d-none step-gating until the WebAuthn ceremony completes — so the
    over-match check is "our selectors leave the row at display:flex", not "the input is
    visible on page load".
Closes the loop on the 16.0.3 apply: the post-apply health gate (ADR 0038) failed by design until the concealment surfaces were re-verified against the deployed images. All six surfaces checked on the live instance (Forgejo 16.0.3-rootless, Kanidm 1.11.1): | Surface | Result | |---|---| | `/user/settings` — no Full Name field | hidden | | `/user/settings/account` — no "Set as primary" | selector matches, computed `display:none` | | `/ui/profile` — no username/display-name inputs | hidden | | `/ui/login` signed out — sign-up note | present | | signed-out navbar — Create account link | present, points at the portal signup | | `/ui/reset` — passkey naming row not over-matched | `#staticPasskeyCreateRow` at `display:flex` | Two clarifications recorded in the defaults comment: - The password/delete sections on `/user/settings/account` are visible to the local break-glass admin (`login_type 0`) by design; `EXTERNAL_USER_DISABLE_FEATURES` removes them for external accounts (`login_type 6`, verified in the DB for every external user). - On Kanidm 1.11.1 the passkey name input is inside `form#passkeyNamingForm`, hidden by Kanidm's own `d-none` step-gating until the WebAuthn ceremony completes — so the over-match check is "our selectors leave the row at `display:flex`", not "the input is visible on page load".
supernaut lade till 1 incheckning 2026-08-31 12:01:59 +00:00
chore(health-check): verify identity concealment against forgejo 16.0.3
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m46s
310da4249b
All six ADR 0038 surfaces re-checked on the deployed images (Forgejo
16.0.3-rootless, Kanidm 1.11.1) after the 16.0.2 -> 16.0.3 patch upgrade:

- /user/settings: no Full Name field
- /user/settings/account: "Set as primary" selector matches, computed
  display:none; the password and delete sections visible to the local
  break-glass admin are the EXTERNAL_USER_DISABLE_FEATURES design
  (login_type 0 vs 6), not a selector break
- /ui/profile: no username or display-name inputs
- /ui/login signed out: the sign-up note renders
- signed-out navbar: Create account -> www.bitborg.se/signup
- /ui/reset: the passkey naming row (#staticPasskeyCreateRow) stays
  display:flex; it is hidden only by Kanidm's own d-none step-gating
  until the WebAuthn ceremony completes

Bumps the verified tag so the post-apply health gate goes green.
supernaut sammanfogade incheckning ae5bf124af till main 2026-08-31 12:04:45 +00:00
supernaut tog bort grenen concealment-verify-16.0.3 2026-08-31 12:04:45 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!455
Ingen beskrivning angiven.