Pouya LajevardiandClaude Opus 5 64bce105f8 feat: eyebrow 12px → 13px from one definition; confirm and gate the intake TTL
Two of Pouya's rulings of 2026-08-31, committed as one tree at his instruction
("as-is") because AGENTS.md Change Log entry (ai) covers both and splitting it
would mean rewriting the record rather than moving it. This is a deliberate
departure from one-logical-change-per-commit, recorded here rather than left to
be inferred.

THE EYEBROW. `--text-eyebrow: 0.8125rem` added to tokens.css; `.eyebrow` in
global.css retargeted to it. One edit site, which is what the design system
claimed. 13px is not a rung on the modular ladder — it sits between xs and sm
deliberately, because uppercase mono at 0.18em tracking reads smaller than it
measures. `--text-2xs`'s comment stopped calling itself the eyebrow floor.

The rendered sweep (22 pages × 2 widths, 838 mono elements measured over CDP,
not grepped) found exactly one escape and one deliberate override:

  - h2.footer-heading, 176 instances — an ESCAPED EYEBROW. Five declarations
    byte-identical to `.eyebrow`, differing only in colour. Consolidated to
    `class="eyebrow footer-heading"`; the scoped rule is now colour + margin.
    The colour is load-bearing, not decorative: `.eyebrow`'s own `--text-meta`
    on ink is 3.07:1 and fails.
  - span.eyebrow.brand-tagline, 21 instances — HELD at `--text-2xs`. Measured:
    at 13px the header grows 81 → 83.4px while `--header-h` is pinned at 81 and
    drives `scroll-padding-top`; and with a seventh nav item the CTA lands past
    `.header-inner`'s content edge by 42px at 1216, 18px at 1240, 26px at 1280
    and 1440. Document overflow is 0 in all of those, so no page-level check
    can see it. Insights is that seventh item.

Everything else mono-uppercase is a genuinely different component and was left:
the 0.06em `--tracking-wide` family, the 14px mixed-case designation strip, the
/bio/ print sheet, /contact/'s form labels.

Measured after: contrast unchanged on all 817 instances (11.09 / 8.11 / 5.47 /
5.01:1, all pass at 13px, which is still normal text and needs 4.5:1). Zero
document overflow and identical header geometry at 15 widths. Two eyebrows gain
a line below 414px — /'s hero, already wrapping at 320px before this, and
/insights/'s empty state at 320px only. Accepted, not re-tuned.

docs/02's type spec moved 11–12px → 13px and now enumerates the three 11px
carve-outs instead of implying there are none. The /type-scale/ proof sheet
(d) asked for no longer exists — deleted at build step 2 — so the spec prose is
the proof sheet now.

THE TTL. backend/intake/handler.mjs CONFIRMED to match `AttributeName=ttl`: it
writes `ttl` as a Number, in epoch seconds, at RETENTION_MONTHS = 24. Nothing
needed changing for the enable command.

Removed `|| 0` from the TTL computation. DynamoDB does not expire an item whose
TTL is more than five years past, so `ttl: 0` meant RETAINED FOREVER while
/legal/privacy/ promises deletion — a fallback whose failure mode was the exact
inverse of the claim it was protecting. Unreachable in practice, which is why
it would never have been noticed. A bad value now fails the write.

§7 records TTL as DISABLED at first verification, so the privacy policy's
automatic-deletion promise was unbacked from the moment it was written. §7 is
the only place that status lives; docs/05 and docs/06 carry the constraint and
cite §7, because round 2 of review caught this change set reproducing the SES
DKIM defect — five copies of a status that is about to be re-stamped.

Added, and these are the gate: `TODO(pouya)` on /legal/privacy/'s retention
section, §9 Q60, §12 R19. The page does not publish a period, it asserts a
MECHANISM — deleted by the database rather than by someone remembering — and
nothing in the toolchain can see that. check:claims is frozen with no pattern
for it and deploy does not read docs/06. The copy was NOT softened: it is about
to be true, and weakening a privacy commitment to make it defensible is the
move the rules forbid. What was missing was the gate, not the caveat.

Reviewed by adversarial-reviewer, two rounds (D19 cap), 15 findings, all
accepted, none declined. claims-auditor did not run — D20. Round 1's findings
were almost entirely in prose written that session, and round 2's blocking
finding plus its sharpest should-fix were both defects in round 1's own fixes.

public/pouya-lajevardi-bio.pdf is deliberately NOT in this commit. It was
regenerated and reverted: /bio/'s eyebrow sits inside `.no-print`, so the sheet
has no eyebrow at all, and `cmp -l` showed exactly 10 differing bytes, all in
/CreationDate and /ModDate.

Gates, every one read as an exit status and none through a pipe: check 0,
build 0 (22 pages), check:claims 0, og:proof 0, check:intake 0, lint 0,
minifier tripwire clean, TODO in dist 0. Lighthouse run twice with identical
output: perf 99 on / and 100 on the other 21, a11y 100, best practices 100,
SEO 100 on every indexable page, CLS 0.000, LCP 1.50–2.03s.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Md3GndFqWPzK78xAoebsg5
2026-08-31 13:44:57 -04:00

adr.smlcompany.ca

The dispute resolution practice of Pouya Lajevardi — Toronto.

A static site built with Astro, built for deployment to Amazon S3 behind CloudFront by Gitea Actions — see Deployment; the pipeline is not yet proven.

Quick start

nvm use            # Node 22 LTS — the floor is in package.json engines
npm install
npm run dev        # http://localhost:4321

Scripts

Command Does
npm run dev Development server with hot reload
npm run build Static build to ./dist — 22 pages
npm run preview Serve the built site locally
npm run check astro check — type and template errors
npm run check:claims AGENTS.md §4 Forbidden, enforced on dist/. Runs on every deploy
npm run check:intake The intake form's field table against the Lambda's — two on purpose
npm run og:proof Every og:image resolves; every card headline is its page's <h1>
npm run lint ESLint + Prettier check
npm run format Prettier — rewrite files in place
npm run lighthouse The performance budget, all four categories. Local only
npm run bio:pdf Re-renders the committed one-page PDF from /bio/. Local only
npm run deploy Build and deploy from this machine — see Deployment

Two of those cannot run in CI, and that is stated rather than left to be discovered. lighthouse and bio:pdf drive an installed browser; the Gitea runner has none. They are keyboard gates plus blocking items on docs/06's cutover checklist, and they are deliberately not wired into npm run build or either deploy path — a check described as running where it cannot is the defect AGENTS.md Q22 turned out to be.

og:proof and check:intake exist because two facts here are deliberately duplicated, and a duplicated fact needs a mechanism rather than a comment. Text baked into an OG card cannot be grepped by check:claims, so og:proof comparing each card's headline to its page's <h1> is the only thing keeping card copy inside the claim register. And the Lambda validates against its own field table, because a server that validates against a list the client shipped it is not validating.

(npm run check:claims was missing from this table before 2026-08-31, along with the four added that day. A table of the project's controls that omits a control is the shape those controls exist to catch.)

Before you contribute

Read AGENTS.md first, and maintain it as you work — it is the living record of what this project is, what was decided, and why. Then read CLAUDE.md for the working rules, and the specs in docs/.

The single hardest rule: no factual claim about Pouya, his credentials, his experience, or his practice ships unless it appears in the verified register in AGENTS.md §4. This is a public marketing surface, and the site it replaces contained fabricated credentials.

How work is done here

Pouya decides; Claude Code implements and then adversarially reviews its own work. Run /build <task> for any substantive change — it plans, implements, runs two independent review agents on the diff (the claims audit wherever copy changed), resolves the findings, verifies the build, and records the session in AGENTS.md. /review runs the review pass alone; /wrap closes a session.

Full protocol and prompt guidance: docs/08-execution-protocol.md.

Deployment

Today, deploys run locally: npm run deploy (scripts/deploy-local.sh). It runs the same guard, the same three sync passes with the same cache headers, and the same invalidation as the CI workflow — at this scale the pipeline changes only how a deploy is triggered, not what it does. The script and .gitea/workflows/deploy.yml are one artefact in two places: change one, change both.

.gitea/workflows/deploy.yml is the CI pipeline — Gitea Actions, not GitHub Actions. It has never run, for two reasons that are not oversights:

  • Actions are not enabled and no runner is registered. The Gitea instance is jointly administered, so both need its second administrator (Q23).

(It previously listed a second reason — that the scoped IAM user did not exist. It exists: adr-sml-deploy, created 2026-08-26, Q22 closed 2026-08-28. See AGENTS.md §7 for the inventory and the least-privilege verification.)

Its first step is a guard: the run aborts, naming what is missing, if any required variable or either AWS secret is empty. Only emptiness is tested and no value is echoed.

The GitHub Actions equivalent, which uses OIDC role assumption, is kept as docs/reference/github-actions-oidc.yml.example in case the project ever moves to a forge that supports it. It sits outside .github/workflows/ on purpose: Gitea falls back to that directory when .gitea/workflows is absent, so a workflow file left there with a push trigger would be only conditionally inert. As an .example under docs/ it cannot be picked up at all.

The pipeline is designed around a long-lived AWS credential, and that credential now exists. Gitea is not an AWS OIDC provider, so there is no role to assume: deploys authenticate as a scoped IAM user, adr-sml-deploy, with its access key in the repository's Gitea Actions secrets. The user was created 2026-08-26 and verified least-privilege by execution — AGENTS.md §7, Q22 closed 2026-08-28. Its access key has never been used (LastUsed null), because deploys still run locally. (This paragraph asserted the user "has not been created" until 2026-08-28.) In the meantime the local script refuses to run as user/pouya, the broadly-permissioned personal user — see AGENTS.md §10. Two things are meant to bound the risk, and neither is in place yet:

  • The policy must stay narrow. Four actions: s3:ListBucket on one bucket, s3:PutObject and s3:DeleteObject on that bucket's contents, and cloudfront:CreateInvalidation on one distribution. No Action: "*", no Resource: "*", nothing outside that one bucket and that one distribution. The AWS account is shared with unrelated projects, including a bucket whose name indicates another business's production database backups — that narrowness is what keeps a compromised runner away from it, and it is load-bearing rather than hygiene. See AGENTS.md §10. If a deploy step needs a permission the policy lacks, question the step; do not widen the policy.
  • The key must be rotated quarterly. It now has an owner and a date: first rotation due 2026-11-26 (key created 2026-08-26) — AGENTS.md §12 R17. Create a second access key, update the Gitea secrets, confirm a deploy succeeds, then delete the old one — rotation that leaves the old key active is not rotation, and deleting before verifying leaves no way to authenticate the fix. OIDC would have removed the obligation entirely; it is unavailable, so this is a standing calendar task. (It read "nobody owns that yet" until 2026-08-28; R17 is the owner, and the date is the whole point of the row.)

Full procedure, IAM policy, runner setup, and cutover checklist: docs/06-deployment.md.

S
Description
No description provided
Readme
12 MiB
Languages
Astro 42.7%
JavaScript 28.4%
TypeScript 17.6%
MDX 5.9%
CSS 4%
Other 1.4%