fix(signup): journey follow-ups — heading, announcement, sitemap, sign-in note, journey() seam #125
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web!125
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/120-124-journey-followups"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Closes #120, #121, #122, #123, #124 — all five bitborg-web follow-ups from the sign-up journey epic's final review. Two commits: four small fixes, then one refactor.
#120 + #124 — /welcome said the same thing twice, and omitted what mattered
welcome.titleduplicatedsignup.step.startverbatim in both languages, so the page printed "Start using Bitborg" as step 4 of the list and again as the heading immediately below. It looked like a mistake, and the two strings had to be hand-synced for no reason.Separately, the design specified a line telling the user they may already be signed in, and the implementation dropped it. That line earns its place: the page is reached straight after authenticating on Gitborg Auth, so clicking through may complete with no prompt at all — which, to someone who has just been asked for a credential, reads as "nothing happened".
Both fixed together, because the heading, body and button were all circling one sentence:
welcome.titlewelcome.bodyThe new body restates neither the heading above it nor the button beneath it.
#121 — the step list announced its title twice
The same string was both the region's
aria-labeland its first visible child, so a screen reader read "This takes four steps" as the region name and then again as content. Nowaria-labelledbypointing at that paragraph — the region stays navigable by name, and the accessible name cannot drift from the visible text.#122 — /welcome was missing from the sitemap filter
astro.config.mjsalready excludes/signup,/accountand/auth/*. The two new routes are mid-journey pages: a search visitor landing on "You are ready — sign in to finish setting up" has no account and no idea what preceded it.#123 — journey() conflated page identity with query status
journey()took one string meaning two things.welcomeis a page, not a status, but it was smuggled through the status argument — so/signup?status=welcomerendered "steps 1-3 done, step 4 current" above a complete, empty sign-up form.Unreachable legitimately and harmless, but the conflation would have spread: the next surface needing a step state faces the same choice and the answer keeps being "invent another pseudo-status".
Now
journey({ page, status }). The page decides how far along the user is; the status only says what happened on it.pageis set by the calling page and is not user input;statusstays attacker-controlled from the query string, still falls back safely on unknown values, and is still never used as an index or key lookup.Written test-first. Two new tests name the defect directly — that a query string cannot make the sign-up page claim near-completion, and that the welcome page reads as step four regardless of any status including
success,nomailand nonsense. The supersededstates("welcome")test was removed rather than adapted, since the behaviour it asserted is exactly what this change makes impossible.Both
/welcomepages now passstatus={null}explicitly, documenting that nothing there depends on a query string.Verification
astro check0 errors; eslint + stylelint clean after an import/declaration-order autofixDeployed state this builds on
The epic is live and verified in production: all four pages render the step list,
?status=nomailcorrectly shows zeroaria-current(step 2 is blocked, not current) and carries no inbox instruction, and every page ships four visually-hidden state prefixes.