Record reviewed private IndeeHub browser acceptance harness
This commit is contained in:
@@ -0,0 +1,51 @@
|
|||||||
|
# Yaya IndeeHub post-deployment smoke handover
|
||||||
|
|
||||||
|
Status: **prepared and source reviewed; NOT executed or a runtime pass.**
|
||||||
|
|
||||||
|
The reviewed harness, exact-source review receipt and user UAT checklist are
|
||||||
|
archived privately at:
|
||||||
|
|
||||||
|
`/home/archipelago/.local/state/archipelago/release-qualification/indeehub-yaya-smoke-prepared-20261008/`
|
||||||
|
|
||||||
|
- `indeehub-yaya-deployed-smoke.cjs`: actual deployed dashboard/app assets, existing
|
||||||
|
private node session, 390px and 1440px checks; no route replacement.
|
||||||
|
- `indeehub-yaya-smoke-source-review.json`: 17 inspected frontend files match the
|
||||||
|
delivered frontend source receipt at `5d0ea645`; API controllers/DTOs match
|
||||||
|
the API source receipt at `3b09b81d`. Candidate node consent labels checked.
|
||||||
|
- `indeehub-yaya-deployed-smoke-UAT.txt`: run prerequisites and short user checklist.
|
||||||
|
Its original `/tmp` artifact references identify the reviewed source copies;
|
||||||
|
use the archived copies above if temporary files disappear.
|
||||||
|
- `archive-receipt.json` and `SHA256SUMS`: qualification limits and artifact hashes.
|
||||||
|
|
||||||
|
Only `node --check` syntax validation has run. Root reviewed the authentication
|
||||||
|
request guards, signing bounds, selectors and response shapes. No browser,
|
||||||
|
authentication, playback or live-node mutation ran for this harness. The archive
|
||||||
|
contains no cookies or bearer tokens; its private cookie-path reference must not
|
||||||
|
be replaced by an exported credential in documentation.
|
||||||
|
|
||||||
|
## Execution prerequisites and scope
|
||||||
|
|
||||||
|
Wait for reviewed Yaya deployment readiness and an explicit browser resource slot.
|
||||||
|
The harness requires `INDEE_DEPLOYMENT_READY=1` and
|
||||||
|
`ALLOW_REAL_AUTH_SIGNING=1` for the already-authorized authentication-only check,
|
||||||
|
plus the existing private cookie file and browser CDP session. If the session has
|
||||||
|
expired, stop; do not reset credentials or create another identity automatically.
|
||||||
|
Verify `SHA256SUMS` before execution and record runtime results in a new receipt,
|
||||||
|
without changing this prepared-only archive into a claimed pass.
|
||||||
|
|
||||||
|
Browse and Backstage are read-only. Authentication permits bounded existing-identity
|
||||||
|
challenges and exact NIP-98 login events only. Any unknown RPC, forbidden endpoint,
|
||||||
|
non-authentication write or non-login signature makes the run fail. Blocked
|
||||||
|
WebSockets and external media/relay reads remain explicit limitations.
|
||||||
|
|
||||||
|
Playback requires an existing published film with explicit zero project and
|
||||||
|
content prices plus backend confirmation of free pricing and existing storage,
|
||||||
|
then uses its real UI Play button. Selection is limited to the first 30 catalog
|
||||||
|
projects; no eligible reachable title means playback NOT_TESTED. Never substitute
|
||||||
|
personal Cloud media, including `web54321-balanced-2.mp4`, or create a publication.
|
||||||
|
A verified non-filmmaker identity may leave Backstage NOT_TESTED; other failures
|
||||||
|
must not be disguised as an access limitation. Physical-phone UAT remains separate.
|
||||||
|
|
||||||
|
Screenshots from a future run may contain private Backstage display content and
|
||||||
|
must stay in its private output directory. Do not publish this archive or runtime
|
||||||
|
screenshots as public release assets.
|
||||||
Reference in New Issue
Block a user