From 96b6ff9972ccc4790f973de6b02fe9f3b8f18f6f Mon Sep 17 00:00:00 2001 From: archipelago Date: Fri, 9 Oct 2026 11:09:45 -0400 Subject: [PATCH] Record native autosign regression correction and live UAT limits --- docs/post-1.8.22-regressions-20261001.md | 32 ++++++++++++++++++++++++ 1 file changed, 32 insertions(+) diff --git a/docs/post-1.8.22-regressions-20261001.md b/docs/post-1.8.22-regressions-20261001.md index ce77349d..2da4043e 100644 --- a/docs/post-1.8.22-regressions-20261001.md +++ b/docs/post-1.8.22-regressions-20261001.md @@ -42,6 +42,38 @@ acceptance; this is a new paid-file incident. ## Current tasks +- 2026-10-09 UI checkpoint: IndeeHub commit `40b3798` is served on Yaya + (index SHA256 `d921a88448f89674809dbe623ec045849012b1fb0330e3abf1d2d6836e9b3c96`). + Publishing now appears only in its own editor tab; Assets remains mounted + across tab switches. Copy distinguishes computer upload from Cloud-backed + catalog publication; saved-registration recovery is under a details control. + Production build and 26 focused frontend tests pass. Browser checks verify + native signer availability, no automatic login, removal of local account + controls and clearing of legacy app-local accounts. Real selected-identity + sign-in and video upload/publication remain unverified. This is a running + container frontend patch, not a durable pinned-image/catalog deployment. + Backend correction `424070d2` has ngit proposal + `9d6de783f5022b3b859e0b1f3e881e389da4482dd5dd15ff29a40b4e25dafcb8`; + isolated regression and optimized build are still running, not passed or + deployed. Preserve this distinction when resuming the backend work. + +- 2026-10-09 follow-up: operator reports missing autosign and the same generic + registration error. `40b3798` disabled provider auto-authentication without + replacing it with app authentication on native selection; this was a regression. + IndeeHub `7b18912` adds a single shared automatic/manual login path driven by + the trusted provider's `onIdentitySelected`. It rejects mismatching signer keys + and changed selections, checks the backend profile, and never falls back to a + cached app identity. Twenty-one focused tests and the production build pass. + Yaya serves index SHA256 + `1c7fee64430b0d993288408dbe493d0f4f55a49fe2422a3507c7204c12343632`; + the native provider bytes are unchanged. A disposable served-app browser test + verifies selection triggers exactly one kind-27235 signature request without + clicking login; it intentionally stops before signing with a stub. This is not + real-identity login acceptance. The first browser run raced deployment and + failed against the previous build; the post-deployment rerun passes. + Authenticated read-only registration RPC still reproduces the generic failure, + with server cause `IndeeHub is not installed`; backend build/test remain pending. + - [ ] **2026-10-09 IndeeHub UAT remains failed:** operator still reports wrong Nostr identity, upload failure and confusing always-visible publishing UI. Preserve native identities; remove only app-local generated/imported accounts.