feat: production run — Q61 ramp, /404/, CloudFront router, cutover runbook
Build and deploy / build-and-deploy (push) Failing after 4s
Build and deploy / build-and-deploy (push) Failing after 4s
Five items of Pouya's production run, 2026-09-01.
Q61 — scroll-padding-top becomes a max() ramp on `10lh - 83px`, with the
plain calc() first as the fallback for engines without `lh`. Hidden focus
stops under minimumFontSize=32: 290 of 1,455 -> 0, control build still
290. Default settings byte-identical (0 differences over 352 page-widths x
17 fields). The 12 residual cells at minimumFontSize=16/20 are pre-existing
and unchanged-or-better; reported, not widened, per instruction.
Intake backend + CloudFront — docs/09-cutover-runbook.md is the
copy-paste sequence for admin execution: every command followed by its
verification and expected output, rollback per part, and Part 10 is Q60's
TTL test. infra/cloudfront/router.js is the trailing-slash function
(30-case suite; 8 fail against the pre-review version, incl. a
protocol-relative open redirect). infra/cloudfront/configure.mjs is
dry-run-by-default and idempotent. scripts/intake-env.mjs emits the six
Lambda env vars from src/data/site.ts.
Four launch blockers found by reading the running system:
- handler.mjs wrote pk/sk; the live table's key is submissionId with no
sort key, so every submission would have failed validation silently
- the Lambda invoke permission is scoped to the old route path
- 22 of 23 pages 403 without the router function
- there was no 404 page; src/pages/404.astro adds it
Claims audit (D20 cutover pass) — five gloss over-reaches corrected on
/practice/energy/, /practice/insurance/ (x2), /practice/technology/ and
/med-arb/. Three findings left open for Pouya: Q62, the /med-arb/ gloss,
and Q60.
Q62 — one frozen-tripwire pattern added under the freeze's own breach
exception, with a probe and four negative fixtures. check:claims exits 1
until the false /legal/privacy/ sentence is corrected, so both deploy
paths are blocked by a mechanism rather than by memory.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Md3GndFqWPzK78xAoebsg5
This commit is contained in:
co-authored by
Claude Opus 5
parent
ca1c2524e1
commit
bd282aa47d
@@ -245,6 +245,23 @@ const COLLECTED = INTAKE_FIELDS.map((field) => field.label);
|
||||
not the section that answers the same question is the sweep failure
|
||||
`CLAUDE.md` describes. Found by `adversarial-reviewer` round 2. */
|
||||
}
|
||||
{
|
||||
/* TODO(pouya): the sentence below is FALSE as at 2026-09-01 and this
|
||||
page must not go public until you rule — §9 Q62. The AWS account has
|
||||
an `admins` IAM group carrying `AdministratorAccess` with TWO
|
||||
members, you and one other person, and
|
||||
`simulate-principal-policy` returns **allowed** for
|
||||
`dynamodb:GetItem`/`Query`/`Scan` on this table for both.
|
||||
Evidence and commands:
|
||||
`docs/reference/intake-table-access-verification.md`.
|
||||
THE QUESTION: do you remove that access — which may be the same
|
||||
co-administrator Q23's Gitea instance depends on, so it is not free
|
||||
— or does this paragraph state the true number? Nothing here may be
|
||||
softened into "authorised administrators": on this page a reader is
|
||||
entitled to the specific, and a true vacancy is worse than a false
|
||||
specific only in that it cannot be caught.
|
||||
Raised by `claims-auditor`, D20 cutover audit, finding 8. */
|
||||
}
|
||||
<p>
|
||||
I can. The table is reachable by the function that writes to it and by
|
||||
one administrative account, which is mine — nobody else has access to
|
||||
|
||||
Reference in New Issue
Block a user