Record native autosign regression correction and live UAT limits

This commit is contained in:
archipelago
2026-10-09 11:09:45 -04:00
parent 424070d215
commit 96b6ff9972
+32
View File
@@ -42,6 +42,38 @@ acceptance; this is a new paid-file incident.
## Current tasks
- 2026-10-09 UI checkpoint: IndeeHub commit `40b3798` is served on Yaya
(index SHA256 `d921a88448f89674809dbe623ec045849012b1fb0330e3abf1d2d6836e9b3c96`).
Publishing now appears only in its own editor tab; Assets remains mounted
across tab switches. Copy distinguishes computer upload from Cloud-backed
catalog publication; saved-registration recovery is under a details control.
Production build and 26 focused frontend tests pass. Browser checks verify
native signer availability, no automatic login, removal of local account
controls and clearing of legacy app-local accounts. Real selected-identity
sign-in and video upload/publication remain unverified. This is a running
container frontend patch, not a durable pinned-image/catalog deployment.
Backend correction `424070d2` has ngit proposal
`9d6de783f5022b3b859e0b1f3e881e389da4482dd5dd15ff29a40b4e25dafcb8`;
isolated regression and optimized build are still running, not passed or
deployed. Preserve this distinction when resuming the backend work.
- 2026-10-09 follow-up: operator reports missing autosign and the same generic
registration error. `40b3798` disabled provider auto-authentication without
replacing it with app authentication on native selection; this was a regression.
IndeeHub `7b18912` adds a single shared automatic/manual login path driven by
the trusted provider's `onIdentitySelected`. It rejects mismatching signer keys
and changed selections, checks the backend profile, and never falls back to a
cached app identity. Twenty-one focused tests and the production build pass.
Yaya serves index SHA256
`1c7fee64430b0d993288408dbe493d0f4f55a49fe2422a3507c7204c12343632`;
the native provider bytes are unchanged. A disposable served-app browser test
verifies selection triggers exactly one kind-27235 signature request without
clicking login; it intentionally stops before signing with a stub. This is not
real-identity login acceptance. The first browser run raced deployment and
failed against the previous build; the post-deployment rerun passes.
Authenticated read-only registration RPC still reproduces the generic failure,
with server cause `IndeeHub is not installed`; backend build/test remain pending.
- [ ] **2026-10-09 IndeeHub UAT remains failed:** operator still reports wrong
Nostr identity, upload failure and confusing always-visible publishing UI.
Preserve native identities; remove only app-local generated/imported accounts.