fix: refute (ar)'s intake finding; fix the D20 gloss class; add X-Robots-Tag on *.pdf
Build and deploy / build-and-deploy (push) Failing after 4s
Build and deploy / build-and-deploy (push) Failing after 4s
Pouya's rulings of 2026-09-03, in five parts. 1. THE INTAKE FORM IS NOT BROKEN. (ar) was wrong. docs/09 §7.1 verbatim — POST /api/intake with an Origin header — returns 303 to /contact/could-not-send/ with access-control-allow-origin echoed; the same probe without Origin returns 403. A bare POST 403s BY DESIGN and §7.1 says so three lines below the probe it prescribes: "403 means the Origin header did not arrive". The earlier finding read a status code without reading the document that defines it. Second time in two days. CLAUDE.md's instrument list goes eight to nine. D20 findings 12 and 19 fall with it; §7.2 (that both emails arrive) is still owed. The correction is APPENDED as entry (as); (ar) stands unedited. 2. The privacy retention comment was stale, not a defect — superseded by his decision to publish and confirm after launch, reading from 2026-09-04. Reworded; the TODO(pouya) came off with the gate it enforced. The mechanism finding survives: it was a JSX comment, stripped by Astro, so no build or deploy path could see it. A publication gate that lives only in a stripped comment is not a gate. §9 Q60 corrected. 3. The gloss class is fixed — 15 of the 20 D20 findings, 14 distinct edits across 9 files, under the rule "the gloss may say no more than the extract says; no new claims, no new sources". Swept three unpublished insights drafts too, and corrected the wrong CAA attribution at its source in docs/reference/, which is where a fixed page re-seeds. /bio/ changed, so the committed PDF is regenerated (89,549 B, 1 page asserted). Three findings outstanding: 10 needs a ruling, 11 is ruled and owed via Q60, 13 needs him to have said it. R1 is not one of the twenty. 4. X-Robots-Tag cannot be done with S3 object metadata — --metadata writes user metadata, returned as x-amz-meta-x-robots-tag, which no crawler reads. Built as the CloudFront response-headers policy docs/06 has specified all along: configure.mjs section 4. It needs a --apply run, not a deploy. The policy is cloned from whatever is attached at run time and reconciled on every run, because a response-headers policy replaces rather than merges. 5. Headshot deferred as an open non-defect. The master and the srcset ladder are both fine; Astro passes no quality, so AVIF encodes at sharp's default 50 and is served first. Two review rounds, 29 findings, all resolved, none declined; stopped at two per D19. NINE of round 2's fourteen were defects in round 1's own repairs — including a fix that harmonised both /fees/ rows onto wording that was itself unregistered, publishing an unsourced fee term twice where it had been once. Gates, exit status read for each: check 0 (0 errors, 0 warnings, 0 hints), build 0 (23 pages), check:claims 0, check:intake 0, og:proof 0, lint 0, minifier grep exit 1, router.test.mjs 30/30. Lighthouse NOT run. Nothing deployed and nothing applied to the distribution. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Md3GndFqWPzK78xAoebsg5
This commit is contained in:
co-authored by
Claude Opus 5
parent
b9523817e2
commit
02739adac9
@@ -375,7 +375,7 @@ an operator to delete the three records that authenticate outbound mail —
|
||||
under the heading "Never delete".
|
||||
|
||||
**A measurement is a claim about your instrument until you check the
|
||||
instrument.** This has now cost eight times, and the shape is identical every
|
||||
instrument.** This has now cost nine times, and the shape is identical every
|
||||
time: a number that looks like a finding, from a probe nobody validated.
|
||||
|
||||
- `timeout 60 ls "$DRIVE"` — **the command never ran.** `timeout` is not
|
||||
@@ -417,6 +417,22 @@ time: a number that looks like a finding, from a probe nobody validated.
|
||||
about a colour that is never painted.** Composite against the actual ground
|
||||
before measuring contrast, and take "the ink colour" only from fully opaque
|
||||
pixels.
|
||||
- **`POST /api/intake` returning 403 — read as "the route does not exist", on a
|
||||
LIVE site.** ⚠️ **A bare POST to `/api/intake` returns 403 BY DESIGN.** The
|
||||
handler rejects a request with no `Origin` header, and **`docs/09` §7.1 says so
|
||||
in as many words** — *"403 means the `Origin` header did not arrive"* — three
|
||||
lines below the probe it prescribes. **The only valid route probe is `docs/09`
|
||||
§7.1 verbatim, `Origin` header included; a 403 without that header is not
|
||||
evidence about the route.** Run correctly it returns **303** to
|
||||
`/contact/could-not-send/`, which is the handler answering as designed. This
|
||||
fired **twice on this project in two days** — Pouya's own probe tripped it
|
||||
2026-09-02, and it then reached a Change Log entry, a `docs/06` blocker and a
|
||||
report to him as *"the intake form is live and broken"*. **The status code was
|
||||
read without reading the document that defines what that status code means on
|
||||
that route**, and the document was in the repo the whole time. Generalised:
|
||||
**before interpreting a response, check whether the endpoint documents its own
|
||||
failure modes** — an API that rejects by design looks exactly like an API that
|
||||
is missing.
|
||||
|
||||
So before acting on a number: say what it is a number *of*; confirm the command
|
||||
actually ran and read its exit status; and check it against a second method that
|
||||
|
||||
Reference in New Issue
Block a user