From 2a2ae7da024bf092d6be3b3fccbb0cde90038574 Mon Sep 17 00:00:00 2001 From: archipelago Date: Tue, 6 Oct 2026 13:17:18 -0400 Subject: [PATCH] Record both-node launcher qualification and real IndeeHub login checks --- docs/post-1.9.0-progress-20261006.md | 37 +++++++++++++++++++++++ tests/lifecycle/indeehub-native-login.cjs | 20 ++++++++---- 2 files changed, 51 insertions(+), 6 deletions(-) diff --git a/docs/post-1.9.0-progress-20261006.md b/docs/post-1.9.0-progress-20261006.md index a01ab3c8..6ce79378 100644 --- a/docs/post-1.9.0-progress-20261006.md +++ b/docs/post-1.9.0-progress-20261006.md @@ -749,3 +749,40 @@ the frame alive too, sharing the same small loading notice. Three additional legacy-overlay tests pass, together with all nine frame tests; both launch paths are included in the served-browser harness. The final build and deployment for this extension are pending; physical companion acceptance is not implied. + +## Both launch paths deployed; actual IndeeHub login verified + +Final UI source `e8683aa5` is deployed on dev and Yaya. Production build and +**1,304 tests across 164 files pass**. Index SHA256: +`629d80d7dea362492d21e174e66e17e6243b6591fa36ba8c2cecf36b4c645eb5`. +Archive SHA256 `a1352d02b444daf8991916afb6faf2b90b7a84160aa471d0ef882b135df49249`. +Backend `2c881f68...`, session keys and app container IDs/start times were preserved; +no management/app restart was needed for this UI rollout. Authenticated RPC passes. + +All **20 served-browser checks pass** across dev/Yaya at 390/1440px: + +- Eight delayed-load checks (standard and custom overlay): hold the app document + beyond the real 12/15-second deadline, retain the exact same iframe, complete + navigation, clear the notice, and keep the automatic companion offer deferred. + The four standard-session cases also retain the frame through readiness flaps. +- Eight concurrent signer checks: both launch paths answer two queued requests + exactly once, preserving the approved completion animation. Signing uses fixtures. +- Four actual IndeeHub native-login checks: genuine NIP-98 authentication, + session201/profile200 and a fresh profile200 after reload. Only guarded local + authentication signatures were allowed; no public events or payments were made. + +The actual-login harness initially tried to click Sign In/Extension after the +app had already opened native consent automatically following identity selection. +Those attempts failed and were retained. The final harness handles either manual +or automatic start, gives consent priority, requires actual successful session and +profile responses, and never force-clicks through an overlay. This is a harness +correction, not a claim that a blocked desktop click was a new product defect. + +Logs: `/tmp/archy-slow-app-{dev,yaya}-{deploy,browser,signer}.log`, +`/tmp/archy-indeehub-fixed-dev-login-3.log`, `/tmp/archy-indeehub-fixed-yaya-login.log`, +`/tmp/archy-slow-app-launch-both-{full-tests,production-build}.log`. +Artifact receipt: `~/.local/state/archipelago/release-qualification/slow-app-ui-e8683aa5/receipt.json`. + +Physical Android WebView background/resume and the separate IndeeHub app-image +update remain open. These results do not imply distributed publishing, payment +recovery or timed rental playback is complete, and no public release was cut. diff --git a/tests/lifecycle/indeehub-native-login.cjs b/tests/lifecycle/indeehub-native-login.cjs index c523a669..9b260ccb 100644 --- a/tests/lifecycle/indeehub-native-login.cjs +++ b/tests/lifecycle/indeehub-native-login.cjs @@ -36,17 +36,25 @@ const fs=require('fs');const {chromium,expect}=require(process.env.PLAYWRIGHT_MO const authenticate=p.getByRole('button',{name:'Authenticate',exact:true});await expect(authenticate).toBeEnabled({timeout:30000});await authenticate.click(); proof.stage='open app sign-in'; const frame=p.frameLocator('iframe[src*="7778"]'); - const signIn=frame.getByRole('button',{name:'Sign In',exact:true});await expect(signIn).toBeVisible({timeout:30000});await signIn.click(); - proof.stage='choose native signer'; + const signIn=frame.getByRole('button',{name:'Sign In',exact:true}); + proof.stage='approve native login'; const extension=frame.getByRole('button',{name:'Extension',exact:true}); - try{await expect(extension).toBeVisible({timeout:10000});await extension.click()}catch(e){console.log(JSON.stringify({...proof,stage:'auth choices',buttons:await frame.getByRole('button').allTextContents()}));throw e} - proof.stage='approve login consent'; - const deadline=Date.now()+45000;let approved=0; + const deadline=Date.now()+45000;let approved=0,extensionChosen=false,signInOpened=false; while(Date.now()s===200||s===201)&&proof.profileResponses.includes(200))break; const approve=p.getByRole('button',{name:'Approve',exact:true}); - if(await approve.isVisible()){if(++approved>6)throw new Error('Unexpected repeated consent');await approve.click();await p.waitForTimeout(800)}else await p.waitForTimeout(250); + if(await approve.isVisible()){ + if(++approved>6)throw new Error('Unexpected repeated consent'); + await approve.click();await p.waitForTimeout(800); + }else if(!signInOpened&&await signIn.isVisible()){ + try{await signIn.click({timeout:1000});signInOpened=true}catch{await p.waitForTimeout(200)} + }else if(!extensionChosen&&await extension.isVisible()){ + // The app can automatically request native login after identity selection. + // Do not click through the parent's consent overlay to choose it again. + try{await extension.click({timeout:1000});extensionChosen=true} + catch{await p.waitForTimeout(200)} + }else await p.waitForTimeout(250); } expect(proof.signedAuthRequests).toBeGreaterThan(0);expect(proof.sessionResponses.some(s=>s===200||s===201)).toBe(true);expect(proof.profileResponses).toContain(200); await expect(signIn).toHaveCount(0,{timeout:10000});