diff --git a/IMPLEMENTATION_PLAN.md b/IMPLEMENTATION_PLAN.md index dd3230a..af1f4a2 100644 --- a/IMPLEMENTATION_PLAN.md +++ b/IMPLEMENTATION_PLAN.md @@ -34,7 +34,7 @@ MPRC can open a race or merchandise item for sale only when the platform can: 9. Do not trade payment integrity for UI responsiveness. Confirmation may say “processing”; it must not guess “paid.” 10. Legal/tax/insurance questions are escalated to qualified owners, not decided by an implementation agent. -**WEB-002D pending release boundary:** [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is one active exact-artifact Netlify exception under review and is not published. It projects only the released #291 visible-focus behavior, #490 deterministic phone-menu disclosure/close behavior, and merged #657 route-focus handoff onto live source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. Pinned source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7` must match an exact two-parent merge whose first parent is `95880748e15c03b0ee58da6e1ed11ac6c9526529`. Until the exact preview, signed-out public checks, and immediate repause all pass, #623 deploy `6a7e072f8f346b0008510d29` remains production and the rollback target. #659 does not publish accumulated `main`, deploy Firebase, configure a provider, use an account, change production data, or connect the directory. Directory availability stays literal `false`; reusable hosting remains open under #460/#133/#136. +**WEB-002D completed release boundary:** [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed one exact-artifact Netlify exception on 2026-08-14. Exact release merge `46e23647d8e0bf9fa3a574ea5c5f993be10a419d` published deploy `6a7ece87c5ca4d0007c1a3fc` from source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`. Signed-out desktop route-focus and phone menu/route-focus checks passed. Repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7` passed exact-main CI run `31783808994`; attempt `6a7ed0ddb00a46000818878d` remained unpublished and retained the verified deploy. The manifest is inactive, the temporary source/control/repause refs are absent, and rollback ref `codex/netlify-source-659-rollback` remains pinned to #623 source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. #659 published only the reviewed #291 visible-focus, #490 phone-menu, and #657 route-focus behavior. It deployed no Firebase, Rules, Functions, or indexes; changed no outside-provider configuration, account, sign-in state, production data, payment, or connected directory behavior; and left directory availability literal `false`. Reusable hosting remains open under #460/#133/#136, and #507 still owns every connected-directory gate. ## 3. Dependency map diff --git a/OFFICER_START_HERE.md b/OFFICER_START_HERE.md index a1c6e15..e0a72a9 100644 --- a/OFFICER_START_HERE.md +++ b/OFFICER_START_HERE.md @@ -48,7 +48,7 @@ Use the club's approved password manager for access. Share only a public link or As of **2026-08-13**, a merge runs checks but does not start the GitHub release. The protected release is **NOT AVAILABLE YET** until its short-lived cloud identity and named environment approvers are configured under issue #133. Ordinary Git-triggered Netlify production builds are paused. An overbroad #473 web artifact was published and immediately rolled back; its bounded replacement remains the recorded rollback. #623 then completed one separate, exact-artifact release of the inert member-directory interface. Netlify deploy `6a7e072f8f346b0008510d29` is live from source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. Signed-out route and guard checks passed, no member-directory request was observed, and repause merge `c8678c623afdd9becf77d596b71f36f26f04b746` made the temporary manifest inactive without replacing that deploy. Shop remains the static in-person catalog, while Events and Calendar show a fixed retry-later notice instead of a raw provider error. Event records are still unavailable because no Firebase repair was deployed. This does not change sign-in, expose protected event offers, add officer editing, or make commerce safe. GitHub Pages still reports `runmprc.com` as its custom domain even though Netlify serves that name; source removal is not provider proof. A green test or workflow does **not** by itself prove that GitHub Pages, `runmprc.com`, Firebase, or that domain setting changed. -As of **2026-08-14**, [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is one accessibility-only Netlify release under review and is not published. It pins one frozen 62-file artifact from source `7496fe0881fb52908c4ff2f40f488df09c94c908` and combines only the reviewed visible keyboard focus, phone-menu close/disclosure, and client-side route-focus behavior. Production remains #623 deploy `6a7e072f8f346b0008510d29`, which is also the rollback target. Officers do not run commands, sign in, enter data, change Firebase or a provider, or approve this as a reusable release. A named observer may perform the safe signed-out browser checks only after the platform owner supplies the exact preview, marker, and approval record. Follow [Review, merge, release, and check a change](./docs/officers/PUBLISH_AND_CHECK.md) and stop on any mismatch. +As of **2026-08-14**, [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed one accessibility-only Netlify release. Deploy `6a7ece87c5ca4d0007c1a3fc` is live from frozen source `7496fe0881fb52908c4ff2f40f488df09c94c908`; its exact 62-file marker and signed-out desktop/phone route-focus and menu checks passed. Repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7` made the manifest inactive. Its attempt `6a7ed0ddb00a46000818878d` published nothing and retained the verified deploy. #623 deploy `6a7e072f8f346b0008510d29` is the recorded rollback, not current production. #659 changed no Firebase, provider configuration, account, sign-in state, production data, payment, or connected directory behavior. Officers do not run commands, sign in, enter data, or approve this as a reusable release. Follow the completed record in [Review, merge, release, and check a change](./docs/officers/PUBLISH_AND_CHECK.md). The optional profile-photo and officer People-finder functions are still **NOT AVAILABLE YET**. #621 makes the frontend default an inert preview: My Account shows the future photo and separate finder-choice controls disabled, while the People finder stays behind the administrator guard and shows its name field and Search button disabled. The preview reads no saved photo or setting, accepts or uploads no photo, searches no name, and saves nothing; it shows no people or sample results. #623 published exactly that disabled interface as deploy `6a7e072f8f346b0008510d29`. Officers inspect the protected layouts only in synthetic local artifacts. The completed signed-out production review proved only the exact revision, normal sign-in and administrator guards, and absence of a member-directory network request. Do not sign in to production, choose a real photo, enter a real name, or treat the preview as a directory. #623 changed no Firebase, provider configuration, account, sign-in, or production data. #507 must later prove the privacy, authorization, staging, backend-first deployment, and readback gates before a separate reviewed source change may connect it. Follow the preview and source-review procedure in [Events, shop, members, and money](./docs/officers/EVENTS_SHOP_MEMBERS.md). diff --git a/OPERATIONS_RUNBOOK.md b/OPERATIONS_RUNBOOK.md index d548c59..a5da19f 100644 --- a/OPERATIONS_RUNBOOK.md +++ b/OPERATIONS_RUNBOOK.md @@ -691,7 +691,7 @@ WEB-002A [#473](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/473) compl WEB-002C [#623](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/623) completed its bounded inert member-directory interface release on 2026-08-13. Pinned Deploy Preview `6a7e05febf8fde00084cf9e0` matched release-control head `1fdb31f71fcaf01c33b5e57a4cd28fc473a4a737`, and PR CI run `31728469418` passed. Exact two-parent merge `9d5cc8612b4321172370bd949d307e7e4ac0ec7d`, parents `019353361210021483f23003e09ee6924b78e67c` and `1fdb31f71fcaf01c33b5e57a4cd28fc473a4a737`, tree `41b6d024d369d93f28ea49940b4f4e5710d3ab52`, passed exact-main CI run `31728908486`. Netlify deploy `6a7e072f8f346b0008510d29` became ready and published at `2026-08-13T18:05:35.983Z`. Its marker matched frozen source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, tree `411aa6ec9a9459f5d923030533ffc7c007fe6908`, previous source `39ab8649df411262c8109a3c81a57bc38f1e168b`, rollback deploy `6a6dc9ea588b0c0008036312`, 62 files, and digest `d837272a1e5efc1575809e87f532276b38d1a63f1dd79ec1aef0533f6da8afb1`. Signed-out `/account` and `/admin/member-directory` checks retained the normal guards; route and bundle review found no connected member-directory symbol or request. Protected Account and administrator layouts remain proved only with synthetic local artifacts. Repause head `d401daa409176dce0906c245adf3f20310cb513b` passed PR CI run `31728977578`; exact two-parent repause merge `c8678c623afdd9becf77d596b71f36f26f04b746`, parents `9d5cc8612b4321172370bd949d307e7e4ac0ec7d` and `d401daa409176dce0906c245adf3f20310cb513b`, passed all five exact-main jobs in run `31729248865`. Its Netlify attempt `6a7e081e73fdd60009f7ba57` errored unpublished; provider and marker readback retained deploy `6a7e072f8f346b0008510d29`. The manifest is inactive, the release source ref is absent, and rollback ref `codex/netlify-source-623-rollback` remains. #623 deployed no Firebase, Rules, Functions, or indexes; changed no outside-provider configuration, account, sign-in, or production data; and made no connected directory behavior available. Connected behavior remains **NOT AVAILABLE YET** under [#507](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/507). Do not reuse this exception as a general release button. -WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is an active one-shot Netlify accessibility release under review and is not published. Release ID `WEB-002D-KEYBOARD-FOCUS-2026-08-14` pins remote source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and artifact digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`; the exact six-path diff from previous/current live source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec` has digest `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`. The manifest expects exact first parent `95880748e15c03b0ee58da6e1ed11ac6c9526529`, release branch `codex/issue-659-netlify-release`, source ref `codex/netlify-source-659-keyboard-focus`, and rollback deploy `6a7e072f8f346b0008510d29`; rollback ref `codex/netlify-source-659-rollback` pins the current live source. The frozen source changes only `src/App.jsx`, `src/App.test.jsx`, `src/components/Navbar.jsx`, `src/components/ScrollToTop.jsx`, `src/headerClearance.test.jsx`, and `src/index.css`, combining exact reviewed #291 visible focus, #490 phone-menu disclosure/close behavior, and #657 path-navigation focus. Until the pinned preview, exact two-parent merge, production marker, signed-out desktop/phone focus and menu checks, and immediate repause all pass, #623 deploy `6a7e072f8f346b0008510d29` remains production and the rollback target. Stop for any source, tree, path, count, artifact, parent, marker, focus, menu, network, or repause mismatch. #659 has no authority for Firebase, Rules, Functions, indexes, outside-provider configuration, accounts, sign-in, production data, content, routes, payments, or connected directory behavior; directory availability remains literal `false`. Follow the pending no-terminal procedure in `docs/officers/PUBLISH_AND_CHECK.md`; never use this exception as a general release button. +WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed its one-shot Netlify accessibility release on 2026-08-14. Release ID `WEB-002D-KEYBOARD-FOCUS-2026-08-14` used pinned Deploy Preview `6a7ec998bf8fde00086d2bfe`, matched release-control head `137d8a8721339a6ca1079283cc34c1bd7cc2706c`, and passed PR CI run `31781730576`. Exact two-parent release merge `46e23647d8e0bf9fa3a574ea5c5f993be10a419d`, parents `95880748e15c03b0ee58da6e1ed11ac6c9526529` and `137d8a8721339a6ca1079283cc34c1bd7cc2706c`, tree `3ef47ed0f664e1e9a2c703332ca9071cfda27ad2`, passed exact-main CI run `31783141914`. Netlify deploy `6a7ece87c5ca4d0007c1a3fc` became ready and published at `2026-08-14T08:16:09.268Z`. Its marker and all 62 artifact paths matched source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, previous source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, rollback deploy `6a7e072f8f346b0008510d29`, and digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`; the exact six-path live-source diff digest was `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`. Signed-out desktop `/shop` and phone `/events` checks passed: route changes left main focused at the top without horizontal overflow, and the phone menu exposed truthful open state before destination selection closed it and preserved normal route focus. Repause preview `6a7ecfbc90347c000804901c` matched head `94c949abed3759c15cdaa98afc6896343e8a6edd`, which passed PR CI run `31783487885`; exact repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7`, parents `46e23647d8e0bf9fa3a574ea5c5f993be10a419d` and `94c949abed3759c15cdaa98afc6896343e8a6edd`, tree `c4667394dc9a2286c3a2eda028728314e925c22f`, passed all five exact-main jobs in run `31783808994`. Its attempt `6a7ed0ddb00a46000818878d` errored unpublished; provider and marker readback retained deploy `6a7ece87c5ca4d0007c1a3fc`. The manifest is inactive, the release/control/repause refs are absent, and rollback ref `codex/netlify-source-659-rollback` remains pinned to source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. #659's frozen source differed from its predecessor only at `src/App.jsx`, `src/App.test.jsx`, `src/components/Navbar.jsx`, `src/components/ScrollToTop.jsx`, `src/headerClearance.test.jsx`, and `src/index.css`. It deployed no Firebase, Rules, Functions, or indexes; changed no outside-provider configuration, account, sign-in state, production data, content, route set, payment, or connected directory behavior; and left directory availability literal `false`. Follow the completed no-terminal audit record in `docs/officers/PUBLISH_AND_CHECK.md`; never use this exception as a general release button. Incident record: on 2026-08-01, overbroad source `094af1096ed8721597561cd59bf695d4c4a9d210` was published by merge `40728ff6141e34a279b70cc41d983c22ac5f0daa` as deploy `6a6dc0167fbe68000816b448` after a release-blocker comment. Exact rollback merge `1099ee8e6fdb81141fd9460de175b6d854cbcfdd` published deploy `6a6dc219a8136300081811db`, restoring source `ed1b0833`, tree `878c6628d961f4484cb49208aef53f1e9f2e3b47`, 60 files, and digest `7570955c2a00926e5813aef135f1799172cfd046072ac89fb4e492bed0797092`. Safety merge `dee79511b6e371329aa129139729e112e7a51aad` re-paused the manifest; its Netlify attempt `6a6dc35767a4ef000877e74b` did not publish, and provider readback left the rollback deploy live. The overbroad release ref was deleted and verified absent. This incident changed no Firebase, outside-provider configuration, account, payment, or production data. diff --git a/README.md b/README.md index 074c0b4..c98aba4 100644 --- a/README.md +++ b/README.md @@ -41,7 +41,7 @@ Historical developer/content/LLM guides remain under [`docs/`](./docs/README.md) - `.github/workflows/`: frontend, Functions, Rules CI and deployment automation. - `public/404.html`, `public/index.html`, and `public/spa-navigation.js`: current tested GitHub Pages callback handoff. It preserves safe same-origin path, query, and fragment state. -**Deployment reality checked 2026-08-13:** merges run CI but do not start the manual release workflow. The protected gate accepts one exact current merged commit, rechecks its newest CI run after approval, uses one fixed Firebase target set, fails when protected authority/configuration is missing, verifies Firebase before publishing GitHub Pages, and gives no server credential to website preparation or publication. Ordinary Git-triggered Netlify production builds are paused. The completed bounded #623 release merge `9d5cc8612b4321172370bd949d307e7e4ac0ec7d` published deploy `6a7e072f8f346b0008510d29` from exact source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec` and tree `411aa6ec9a9459f5d923030533ffc7c007fe6908`; its 62-file artifact digest is `d837272a1e5efc1575809e87f532276b38d1a63f1dd79ec1aef0533f6da8afb1`. It adds only an inert profile-photo/searchability and officer People finder interface: the controls are visibly unavailable and make no directory request. No Firebase, provider, account, role, member data, photo, or search backend changed. Repause merge `c8678c623afdd9becf77d596b71f36f26f04b746` passed exact-main CI run `31729248865`; its Netlify attempt `6a7e081e73fdd60009f7ba57` published nothing, and deploy `6a7e072f8f346b0008510d29` remained live. The temporary #623 manifest is inactive again. The prior bounded #473 deploy `6a6dc9ea588b0c0008036312` remains rollback history, not current production. The source stops adding a Pages `CNAME`, but GitHub Pages currently still claims `runmprc.com` and its default URL redirects there; only a controlled #136/WEB-001 publication and provider readback can clear that conflict. Reusable protected publication to the live Netlify-served `runmprc.com` is not configured yet. Treat GitHub Pages, Netlify, `runmprc.com`, Firebase, and outside providers as separate states. +**Deployment reality checked 2026-08-14:** merges run CI but do not start the manual release workflow. The protected gate accepts one exact current merged commit, rechecks its newest CI run after approval, uses one fixed Firebase target set, fails when protected authority/configuration is missing, verifies Firebase before publishing GitHub Pages, and gives no server credential to website preparation or publication. Ordinary Git-triggered Netlify production builds are paused. WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed one bounded accessibility release: exact merge `46e23647d8e0bf9fa3a574ea5c5f993be10a419d` published deploy `6a7ece87c5ca4d0007c1a3fc` from source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and artifact digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`. Signed-out desktop and phone route-focus/menu checks passed. Repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7` passed exact-main CI run `31783808994`; attempt `6a7ed0ddb00a46000818878d` published nothing, deploy `6a7ece87c5ca4d0007c1a3fc` remained live, and the manifest is inactive. #623 deploy `6a7e072f8f346b0008510d29` remains rollback history and its inert directory interface is unchanged beneath the accessibility delta. No Firebase, Rules, Functions, indexes, provider configuration, account, sign-in state, role, member data, payment, or connected directory backend changed. The prior bounded #473 deploy `6a6dc9ea588b0c0008036312` remains older history. The source stops adding a Pages `CNAME`, but GitHub Pages currently still claims `runmprc.com` and its default URL redirects there; only a controlled #136/WEB-001 publication and provider readback can clear that conflict. Reusable protected publication to the live Netlify-served `runmprc.com` is not configured yet. Treat GitHub Pages, Netlify, `runmprc.com`, Firebase, and outside providers as separate states. ## Local setup status diff --git a/SECURITY.md b/SECURITY.md index 03293ce..0e4b96d 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -68,7 +68,7 @@ The findings below describe the repository at the start of the 2026-07-12 assess | RISK-023 | The legacy `functions.config().api.key` endpoint uses a static shared key with no replay control, source restriction, App Check, authenticated operator, or request audit. The API is also scheduled for Firebase decommissioning in March 2027. | Key theft permits bulk role changes and future deployment failure. | Retire it in favor of authenticated admin workflow or narrowly authenticated scheduled import; migrate any remaining config to Secret Manager. | | RISK-024 | OAuth tokens remain plaintext. Repository Rules deny browser access, but protected deployment and live behavior are unproven; least-privilege runtime IAM and an encryption decision remain open. OAUTH-001A1H [#606](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/606) source transactionally rereads the exact access-token, refresh-token, and expiry tuple before persisting a refresh response. A retry rereads the tuple; changed, missing, or malformed state returns one fixed failure without a stale write or downstream bearer call. OAUTH-001B9 [#608](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/608) source records the disconnect secret's Firestore update time before optional revocation, then transactionally rereads it and deletes the local secret/connection pair only when the secret is absent or still has that exact version. A newer version, including byte-identical replacement, is preserved with one fixed unknown result; a transaction conflict rereads without repeating provider work. OAUTH-001B10 [#610](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/610) browser source admits only a fulfilled response value that presents exactly one own enumerable data field, `ok` equal to `true`; it returns a new frozen confirmation and routes other fulfilled results or exceptional inspection through the existing fixed unknown-result view without hiding the connection. Browser JavaScript cannot distinguish a transparent Proxy that faithfully presents that contract, so the received object is never retained. Synthetic tests use no real token, account, or provider call. Provider calls are still not serialized; an exact browser confirmation does not independently prove provider revocation, and provider/local and lost-acknowledgement reconciliation, a trusted connection-only write that does not also version the secret, deployment, and live behavior remain unproven. | Token theft exposes member activity data; an undeployed boundary or an unhandled provider/acknowledgement race can still lose availability or leave local and provider state ambiguous. | Deploy and read back server/IAM-only secret access, decide encryption, serialize or otherwise reconcile refresh and disconnect operations and lost acknowledgements, minimize scopes, audit access, and verify only with approved made-up staged accounts. | | RISK-025 | Admin authentication relies on password Auth plus a long-lived role token; no repository evidence of MFA, recent-auth checks, re-auth for refunds/role grants, or rapid revocation workflow. | A stolen admin session has broad durable impact. | Require MFA for privileged accounts, recent-auth for sensitive actions, capability roles, short sessions/forced refresh, and break-glass procedures. | -| RISK-042 | Profile photos and an officer people finder have no approved privacy notice, retention/backup treatment, scoped capability, or connected production release path. The existing Admin Members page downloads complete account documents and cannot enforce an opt-out promise. #505/#506 source supplies the private processed thumbnail, default-off preference, minimum server-only projection, and bounded audited verified-admin name search, but none is deployed. MEMBERS-DIRECTORY-001D [#621](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/621) makes the frontend default an inert, disabled preview with zero directory reads, uploads, searches, saves, request IDs, or service calls; it does not make the backend available. WEB-002C [#623](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/623) published exactly that frozen inert frontend as Netlify deploy `6a7e072f8f346b0008510d29`; signed-out guard and no-request checks passed, and the temporary release authority is inactive. It did not connect or deploy the backend. | A photo, name, query, preference, prefix digest, or stable entry reference could be exposed, retained, enumerated, correlated, or mistaken for membership evidence if the connected path is enabled prematurely; automated face matching would add unapproved biometric processing. A browser availability constant is not authorization. | Keep the source-controlled availability boundary off and the feature separate from the official roster. Preserve current-source revalidation, direct Rules denials, fixed query/result bounds, no-store responses, pseudonymous rate keys, query-free audit, and synthetic race/opt-out/removal proof. Never store the original, persist raw queries, or add face recognition. Complete #110 policy inputs, AUTH-003 scoped authorization follow-up, #133 protected authority, and #507 staging plus backend-first deployment/readback before a reviewed source flip and connected website publication. | +| RISK-042 | Profile photos and an officer people finder have no approved privacy notice, retention/backup treatment, scoped capability, or connected production release path. The existing Admin Members page downloads complete account documents and cannot enforce an opt-out promise. #505/#506 source supplies the private processed thumbnail, default-off preference, minimum server-only projection, and bounded audited verified-admin name search, but none is deployed. MEMBERS-DIRECTORY-001D [#621](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/621) makes the frontend default an inert, disabled preview with zero directory reads, uploads, searches, saves, request IDs, or service calls; it does not make the backend available. WEB-002C [#623](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/623) published exactly that frozen inert frontend as rollback deploy `6a7e072f8f346b0008510d29`. WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) preserved it byte-for-byte beneath the live accessibility delta in deploy `6a7ece87c5ca4d0007c1a3fc`. Neither release connected or deployed the backend; directory availability remains literal `false`. | A photo, name, query, preference, prefix digest, or stable entry reference could be exposed, retained, enumerated, correlated, or mistaken for membership evidence if the connected path is enabled prematurely; automated face matching would add unapproved biometric processing. A browser availability constant is not authorization. | Keep the source-controlled availability boundary off and the feature separate from the official roster. Preserve current-source revalidation, direct Rules denials, fixed query/result bounds, no-store responses, pseudonymous rate keys, query-free audit, and synthetic race/opt-out/removal proof. Never store the original, persist raw queries, or add face recognition. Complete #110 policy inputs, AUTH-003 scoped authorization follow-up, #133 protected authority, and #507 staging plus backend-first deployment/readback before a reviewed source flip and connected website publication. | | RISK-026 | Firestore Admin SDK bypasses rules and the Functions runtime IAM scope is not documented. #135 removes the long-lived service-account JSON path from release source, but the least-privilege short-lived deploy identity is not configured yet. | Server or CI compromise may expose the entire project; missing provider configuration also blocks release. | Complete the private IAM inventory and #133 OIDC/WIF configuration; keep runtime and deploy identities separate; never restore a JSON key shortcut. | | RISK-027 | Sentry optionally records user email and enables 100% replay on error; analytics/privacy consent, redaction, retention, and field-deny policies are not evidenced. | Forms and account flows contain PII that may be sent to monitoring vendors unexpectedly. | Disable replay on sensitive routes or configure strict masking, avoid email user context, set scrubbing/retention, consent policy, and vendor agreements. | | RISK-028 | No payment reconciliation job, dead-letter/quarantine workflow, or alert proves paid Stripe objects match Firestore. | Missed webhooks and partial failures can persist unnoticed. | Add scheduled reconciliation, alert thresholds, operator repair tooling, and a daily finance report. | @@ -86,7 +86,7 @@ The findings below describe the repository at the start of the 2026-07-12 assess | RISK-034 | Webhook error response includes the Stripe library's signature error detail. | Return generic client errors; keep sanitized structured diagnostics server-side. | | RISK-035 | The deterministic frontend Jest suite and standalone SPA callback suite run as separate blocking hosted CI steps. CI-001B4/#186 merged a non-mutating frontend lint gate as `bec7d5e365eacb418563a172029f241f660d9768`; exact PR and post-merge runs passed. CI-001B4A [#227](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/227) removes one reviewed `arrow-body-style` error, CI-001B4B [#239](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/239) removes one stale `AdminMembers` unknown-rule suppression record, and PAY-004C1 [#359](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/359) retires one `no-alert` warning plus two label-association errors with the unsafe reusable-link controls. Reviewed functional changes in [PR #391](https://github.com/Run-MPRC/Run-MPRC.github.io/pull/391) and [PR #392](https://github.com/Run-MPRC/Run-MPRC.github.io/pull/392) add one and two TypeScript files respectively while retiring two TSX errors each. CI-001B4C [#449](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/449) replaces the four remaining stale `react-hooks/exhaustive-deps` directives with ordinary same-line comments, without changing executable code or the gate. MEMBERS-CONTENT-001B [#492](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/492) removes one finding-free dormant JSX file. MEMBERS-DIRECTORY-001A [#505](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/505) adds four finding-free TypeScript/TSX files, MEMBERS-DIRECTORY-001B [#506](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/506) adds four more, WEB-SUGGESTIONS-001A [#618](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/618) adds one finding-free JSX page, and MEMBERS-DIRECTORY-001D [#621](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/621) adds one finding-free TypeScript availability module. The current baseline scans 120 files and still records 113 configured errors and 6 warnings after the lint process disables the repository's severity-masking `eslint-plugin-only-warn` hook. Branch protection, remaining lint-debt cleanup, and broader domain/integration coverage remain incomplete. | Continue reducing the reviewed finding baseline in focused changes, prove required branch checks, and add domain/integration coverage. Never regenerate the baseline merely to make CI green. | | RISK-036 | #135 adds a manual exact-commit source gate, fixed profile-recovery targets, backend-first order, missing-config failure, and ordinary Git-triggered Netlify production containment. WEB-UX-001A [#457](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/457) used a temporary exact-artifact exception. On 2026-08-01 an overbroad WEB-002A artifact was merged after a late blocker and published; exact rollback merge `1099ee8` restored source `ed1b0833`, and `dee7951` paused the manifest. Bounded replacement [#473](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/473) then published exact source `39ab8649` as deploy `6a6dc9ea588b0c0008036312`; its delta is only Shop and Events/Calendar failure containment, and its public checks passed. Final control `cb6a8f0` made the manifest inactive; Netlify attempt `6a6dcdd47bc81e000859a249` stopped unpublished and left that bounded deploy as #623's rollback. WEB-002C [#623](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/623) then completed one exact-artifact release: merge `9d5cc8612b4321172370bd949d307e7e4ac0ec7d` published frozen inert source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, tree `411aa6ec9a9459f5d923030533ffc7c007fe6908`, 62 files, and digest `d837272a1e5efc1575809e87f532276b38d1a63f1dd79ec1aef0533f6da8afb1` as deploy `6a7e072f8f346b0008510d29`. Signed-out marker, route, guard, and no-connected-symbol/request checks passed. Repause merge `c8678c623afdd9becf77d596b71f36f26f04b746` made the manifest inactive; attempt `6a7e081e73fdd60009f7ba57` stopped unpublished and retained the verified deploy. The release source is absent and the rollback ref remains. Protected environments/OIDC, isolated staging, a reusable live-Netlify path, and provider-owned atomic rollback remain unverified. | Require a final blocker re-read and an executable delta from the live artifact before every release merge. Preserve the exact #473 rollback evidence, keep ordinary publication paused, and keep the reviewed Git rollback projection available. Treat #623 as a completed one-off, not a reusable control. Complete #133 and #136, provision isolated staging, protect the reusable Netlify release path under WEB-001, and rehearse provider rollback before broader production work. | -| WEB-002D pending exact-artifact containment for RISK-036 | [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is an active accessibility-only release under review and is not published. Its frozen source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7` project only reviewed #291 visible-focus, #490 phone-menu, and #657 route-focus behavior over live source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. The exact six-path diff digest is `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`. Production remains #623 deploy `6a7e072f8f346b0008510d29`, which is also the rollback target. Literal-false directory availability, Firebase, providers, accounts, sign-in, production data, and connected directory behavior are unchanged. | Require the pinned preview, exact parent `95880748e15c03b0ee58da6e1ed11ac6c9526529`, exact two-parent merge, signed-out marker/focus/menu checks, separately reviewed rollback, and immediate repause. Stop for any source, tree, scope, count, digest, parent, marker, focus, menu, directory-request, backend, provider, account, data, or repause mismatch. Treat #659 as one temporary exception, not reusable authority. Preserve active #616 OAUTH-001A2L files and its RISK-024 wording byte-for-byte. | +| WEB-002D completed exact-artifact containment for RISK-036 | [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed one accessibility-only release on 2026-08-14. Exact release merge `46e23647d8e0bf9fa3a574ea5c5f993be10a419d` published deploy `6a7ece87c5ca4d0007c1a3fc`; its marker and all 62 artifact paths matched frozen source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`, and exact six-path diff digest `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`. Signed-out desktop and phone route-focus/menu checks passed. Repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7` passed exact-main CI run `31783808994`; attempt `6a7ed0ddb00a46000818878d` stayed unpublished and retained the verified deploy. Literal-false directory availability, Firebase, Rules, Functions, indexes, outside-provider configuration, accounts, sign-in, production data, payments, and connected directory behavior were unchanged. | The manifest is inactive; source/control/repause refs are absent; rollback ref `codex/netlify-source-659-rollback` remains pinned to #623 source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. Treat #659 as a completed one-off, not reusable authority. Keep ordinary publication paused, preserve #507 connected-directory gates, and preserve active #616 OAUTH-001A2L files and its RISK-024 wording byte-for-byte. | | RISK-037 | Account/registration deletion, export, retention, backup, and restore procedures are incomplete. | Approve retention matrix, automate minimization, support access/deletion requests, and test backup restoration. | | RISK-038 | Source-controlled secret scan is ad hoc; no continuous secret scanner, dependency update bot, SBOM, provenance, or branch protection is documented. | Add secret/dependency/code scanning, reviewed lockfile updates, protected environments/branches, and artifact provenance appropriate to project scale. | | RISK-039 | Some authenticated accounts can lack `members/{uid}` after the Firebase cutover; the account screen hid the read failure and exposed an update that could only fail. Manual database/account repair could corrupt roles or private data. | Use an authenticated create-once server bootstrap, keep browser creation denied, fail the UI closed, and prove backend-first deployment with synthetic accounts. | diff --git a/SYSTEM_DESIGN.md b/SYSTEM_DESIGN.md index cca886f..1422394 100644 --- a/SYSTEM_DESIGN.md +++ b/SYSTEM_DESIGN.md @@ -86,7 +86,7 @@ Text alternative: browsers can use the React app, Auth, Firestore, Functions, St | Operational data | Cloud Firestore | `src/services`, `firestore.rules`, `firestore.indexes.json` | Appropriate for current scale; counters and state transitions require transactional design. | | Server API | First-generation Firebase callable/HTTP/trigger functions | `functions/` | Prototype covers most workflows; validation, idempotency, and isolation are incomplete. | | Payments | Stripe Checkout Sessions, Payment Links, refunds, signed webhook | `functions/createCheckoutSession.js`, `createMerchCheckout.js`, `stripeWebhook.js` | Not ready for live payments until P0 issues are complete. | -| Hosting and release | Netlify currently answers `runmprc.com`. GitHub Pages still reports the same custom domain, so its default URL redirects to the Netlify-served name instead of providing an independent copy. #135 source stops ordinary automatic releases, pauses Git-triggered Netlify production builds, and removes the Pages CNAME from future protected artifacts. After an overbroad WEB-002A artifact was rolled back, [#473](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/473) used one bounded replacement exception: exact merge `9ad6837` published source `39ab864`, tree `d76b496`, 60 files, and artifact digest `07b10c7d…` as deploy `6a6dc9ea588b0c0008036312`. Every mismatch failed closed, and the manifest became inactive again. WEB-002C [#623](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/623) completed a second bounded exception: exact merge `9d5cc86` published frozen inert source `c2d87d1`, tree `411aa6e`, 62 files, and digest `d837272a…` as deploy `6a7e072f8f346b0008510d29`. Signed-out guards and no-request proof passed; repause merge `c8678c6` left that deploy live and made the manifest inactive. | `netlify.toml`, `config/netlify-production-release.json`, `scripts/netlify-release-policy.js`, `.github/workflows/deploy.yml`, `public/404.html` | **LIVE FRONTEND CONTAINMENT.** Production is #623 deploy `6a7e072f8f346b0008510d29` from source `c2d87d1`. It adds only the disabled member-directory interface to the #473 surface. Shop remains the static pickup catalog; Events and Calendar disclose no raw provider error. Event records remain unavailable because no Firebase or provider repair was deployed. This does not connect the directory backend or complete the general protected host under #133/#136/WEB-001. | +| Hosting and release | Netlify currently answers `runmprc.com`. GitHub Pages still reports the same custom domain, so its default URL redirects to the Netlify-served name instead of providing an independent copy. #135 source stops ordinary automatic releases, pauses Git-triggered Netlify production builds, and removes the Pages CNAME from future protected artifacts. After an overbroad WEB-002A artifact was rolled back, [#473](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/473) completed one bounded replacement. WEB-002C [#623](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/623) then published the frozen inert directory interface as deploy `6a7e072f8f346b0008510d29`. WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed a third bounded exception: exact merge `46e2364` published frozen source `7496fe0`, tree `ccac4c1`, 62 files, and digest `e4c26e6…` as deploy `6a7ece87c5ca4d0007c1a3fc`. Signed-out route-focus and phone-menu checks passed; repause merge `3138a00` left that deploy live and made the manifest inactive. | `netlify.toml`, `config/netlify-production-release.json`, `scripts/netlify-release-policy.js`, `.github/workflows/deploy.yml`, `public/404.html` | **LIVE FRONTEND CONTAINMENT.** Production is #659 deploy `6a7ece87c5ca4d0007c1a3fc` from source `7496fe0`. It adds only reviewed visible-focus, phone-menu, and client-side route-focus behavior to the inert #623 surface. Shop remains the static pickup catalog; Events and Calendar disclose no raw provider error. Event records remain unavailable because no Firebase or provider repair was deployed. The directory remains literal-false and inert. This does not connect its backend or complete the general protected host under #133/#136/WEB-001. | | Email | Firestore `mail` outbox designed for the Firebase Trigger Email extension | `functions/sendConfirmationEmail.js` | Extension/provider deployment is unverified; outbox creation is not transactionally idempotent and HTML needs escaping. | | Observability | Optional Sentry; Firebase Analytics configuration remains but its runtime is not initialized by #139 source | `src/services/monitoring`, `src/services/analytics` | #134 source bounds Sentry payloads. #139 source removes every application runtime Firebase Analytics import, initialization, and emission while preserving no-op call compatibility. Website publication, provider collection/cookies and historical data, consent, retention, access, deletion, and vendor configuration remain unverified under #110/#111. | | Third-party fitness | Strava OAuth tokens and statistics | `functions/strava.js`, `src/services/strava` | Functional prototype. The #100 source Rules deny browser token access, but Firebase deployment is unproven and transactional refresh, scopes/revocation, IAM/encryption decision, and audit remain OAUTH-001. | @@ -95,7 +95,7 @@ The former workflow automatically published Pages before attempting Firebase and #623 completed the same fail-closed pattern for one inert member-directory interface artifact. Deploy Preview `6a7e05febf8fde00084cf9e0` matched control head `1fdb31f71fcaf01c33b5e57a4cd28fc473a4a737`. Exact merge `9d5cc8612b4321172370bd949d307e7e4ac0ec7d`, with first parent `019353361210021483f23003e09ee6924b78e67c`, published deploy `6a7e072f8f346b0008510d29` from source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, tree `411aa6ec9a9459f5d923030533ffc7c007fe6908`, 62 files, and digest `d837272a1e5efc1575809e87f532276b38d1a63f1dd79ec1aef0533f6da8afb1`. Its marker also records previous source `39ab8649df411262c8109a3c81a57bc38f1e168b` and rollback deploy `6a6dc9ea588b0c0008036312`. Signed-out route, guard, and bundle checks found no connected member-directory request or symbol. Repause merge `c8678c623afdd9becf77d596b71f36f26f04b746` made the manifest inactive; attempt `6a7e081e73fdd60009f7ba57` stopped unpublished and retained the verified deploy and marker. The release source ref is absent and the rollback ref remains. The release changed no Firebase, outside-provider configuration, sign-in state, or production data. Build hooks and a reusable protected Netlify publication path remain unverified. No source test clears the current Pages custom-domain claim, configures #133, or deploys #136; those remain separate provider states. The App Engine synchronization script is another surface that must be documented as active or retired. -WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is one active exact-artifact exception under review, not a completed publication. It freezes only the reviewed #291 visible-focus treatment, #490 deterministic phone-menu disclosure/close behavior, and #657 client-side route-focus handoff over current live source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. Its pinned source is `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and artifact digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`; the exact six-path live-source diff digest is `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`, and the expected production first parent is `95880748e15c03b0ee58da6e1ed11ac6c9526529`. Until its pinned preview, exact two-parent merge, signed-out public focus checks, and immediate repause all pass, #623 deploy `6a7e072f8f346b0008510d29` remains production and the rollback target. #659 changes no route, content, Firebase surface, outside-provider configuration, account, sign-in state, production data, or directory behavior; directory availability remains literal `false`. Stop on any source, tree, file-count, artifact, parent, focus, menu, marker, or repause mismatch. +WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed one exact-artifact exception on 2026-08-14. Pinned preview `6a7ec998bf8fde00086d2bfe` matched control `137d8a8721339a6ca1079283cc34c1bd7cc2706c`. Exact release merge `46e23647d8e0bf9fa3a574ea5c5f993be10a419d` published deploy `6a7ece87c5ca4d0007c1a3fc` from source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and artifact digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`; the exact six-path predecessor diff digest was `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`. Signed-out desktop route-focus and phone menu/route-focus checks passed. Repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7` passed exact-main CI `31783808994`; attempt `6a7ed0ddb00a46000818878d` stayed unpublished and retained the verified deploy. The manifest is inactive; temporary refs are absent; #623 deploy `6a7e072f8f346b0008510d29` is the rollback target. #659 changed no route set, content, Firebase surface, outside-provider configuration, account, sign-in state, production data, payment, or directory behavior; directory availability remains literal `false` and #507 still owns connection. ```mermaid flowchart TD @@ -111,14 +111,14 @@ flowchart TD Verify -- "No" --> Stop Verify -- "Yes" --> Pages["Publish Pages branch without a CNAME"] Merge -. "Ordinary Git production build paused" .-> Netlify["Netlify / runmprc.com\nreusable protected publication not available"] - Completed["#623 exact-parent one-shot completed"] --> WebOnly["Pinned inert web-only artifact live"] + Predecessor["#623 inert artifact retained as rollback"] --> Completed["#659 exact-parent one-shot completed"] + Completed --> WebOnly["Pinned accessibility artifact live"] WebOnly --> Netlify - Netlify --> WebReadback["Exact marker and signed-out guards verified"] - WebReadback --> WebRepause["Temporary authority inactive; verified deploy retained"] - Pending["#659 exact focus artifact under review"] -. "Not published" .-> Netlify + Netlify --> WebReadback["Exact marker and signed-out route/menu checks verified"] + WebReadback --> WebRepause["Temporary authority inactive; #659 deploy retained"] ``` -Text alternative: ordinary merges run CI and do not publish Netlify. #623 completed one exact-parent exception and production now serves its pinned inert artifact. #659 is a separate exact focus-artifact release under review and has not published. Signed-out marker and guard checks passed for #623, then its temporary authority was disabled without replacing the verified deploy. The separate protected workflow still requires approval and verified Firebase before publishing its Pages copy. +Text alternative: ordinary merges run CI and do not publish Netlify. #659 completed one exact-parent accessibility exception, and production now serves deploy `6a7ece87c5ca4d0007c1a3fc` over the inert #623 predecessor. Its exact marker and signed-out route/menu checks passed, then the temporary authority was disabled without replacing the verified deploy. The separate protected workflow still requires approval and verified Firebase before publishing its Pages copy. ### GitHub Pages callback handoff diff --git a/docs/officers/ACCESS_CONTINUITY.md b/docs/officers/ACCESS_CONTINUITY.md index 57a801f..4b2cd3b 100644 --- a/docs/officers/ACCESS_CONTINUITY.md +++ b/docs/officers/ACCESS_CONTINUITY.md @@ -85,14 +85,16 @@ For each system, record only: 11. Confirm missing release authority becomes a red failure before backend installation, cloud authentication, deployment, or website publication. A public website artifact may be prepared without cloud authority. 12. Confirm Firebase verification must finish before the GitHub Pages publication job can start. 13. Confirm ordinary Netlify Git-triggered production builds remain paused. -14. Confirm the live #623 marker names control `9d5cc8612b4321172370bd949d307e7e4ac0ec7d`, source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, tree `411aa6ec9a9459f5d923030533ffc7c007fe6908`, 62 files, digest `d837272a1e5efc1575809e87f532276b38d1a63f1dd79ec1aef0533f6da8afb1`, and deploy `6a7e072f8f346b0008510d29`. -15. Confirm repause merge `c8678c623afdd9becf77d596b71f36f26f04b746` passed CI run `31729248865`. -16. Confirm repause attempt `6a7e081e73fdd60009f7ba57` published nothing and deploy `6a7e072f8f346b0008510d29` stayed live. -17. Record the earlier completed #473 deploy `6a6dc9ea588b0c0008036312` as rollback history. -18. For any future exception, re-read the issue and pull request for a newer blocker. -19. Compare its executable delta with the current live artifact immediately before merge. -20. Confirm reviewers reject release requests older than 24 hours and request the current `main` commit again. -21. **NOT AVAILABLE YET:** complete the synthetic role-boundary drill below after the reviewed database, Function, and website revisions are safely available in protected staging. +14. Confirm the live #659 marker names control `46e23647d8e0bf9fa3a574ea5c5f993be10a419d`, source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`, and deploy `6a7ece87c5ca4d0007c1a3fc`. +15. Confirm release merge `46e23647d8e0bf9fa3a574ea5c5f993be10a419d` passed exact-main CI run `31783141914`. +16. Confirm repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7` passed exact-main CI run `31783808994`. +17. Confirm repause attempt `6a7ed0ddb00a46000818878d` published nothing and deploy `6a7ece87c5ca4d0007c1a3fc` stayed live. +18. Confirm the manifest is inactive, temporary refs are absent, and rollback ref `codex/netlify-source-659-rollback` remains. +19. Record completed #623 deploy `6a7e072f8f346b0008510d29` as the immediate rollback and completed #473 deploy `6a6dc9ea588b0c0008036312` as older history. +20. For any future exception, re-read the issue and pull request for a newer blocker. +21. Compare its executable delta with the current live artifact immediately before merge. +22. Confirm reviewers reject release requests older than 24 hours and request the current `main` commit again. +23. **NOT AVAILABLE YET:** complete the synthetic role-boundary drill below after the reviewed database, Function, and website revisions are safely available in protected staging. ### Synthetic role-boundary drill — NOT AVAILABLE YET diff --git a/docs/officers/EVENTS_SHOP_MEMBERS.md b/docs/officers/EVENTS_SHOP_MEMBERS.md index b15e55d..b2d5246 100644 --- a/docs/officers/EVENTS_SHOP_MEMBERS.md +++ b/docs/officers/EVENTS_SHOP_MEMBERS.md @@ -1229,7 +1229,7 @@ Officer source-review procedure for AUTH-006G [#651] confirmed profile-name Save 111. Confirm active #616 Strava runtime files remain unchanged. 112. Confirm active #616 OAUTH-001A2L/RISK-024 documentation remains unchanged. 113. Confirm the optional-directory availability value remains byte-for-byte `false`. -114. Confirm the last verified production directory deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +114. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 115. Confirm #507 still owns every optional-directory connection and live-proof gate. 116. Record the source change as its own state. 117. Record the named test results as their own state. @@ -1244,11 +1244,11 @@ Officer source-review procedure for AUTH-006G [#651] confirmed profile-name Save 126. Record whether connected profile-photo or officer-finder behavior is live as its own state. 127. Stop before changing Firebase, a provider, an account, production data, directory availability, or the live website. -**Expected result:** one exact current full-name update plus its successful non-null authoritative profile reread renders exactly **Profile name saved.** between the Profile heading and Edit, with status, polite live, atomic, programmatic-focus, bounded-layout, and visible-outline semantics. Only an admitted Save that owned focus records the current generation and attempt ID. Exact current confirmed success alone transfers that intent. The layout effect consumes it before target checks. Absent, body, document-root, or disconnected focus returns to the connected result; retained result focus is left alone; and every other connected focus is preserved. An unfocused Save still shows the truthful result without moving focus. Initial load, validation, update rejection, missing or rejected reread, profile reload, context or generation change, newer attempt, stale work, unmount, and later rerender cannot show or focus stale success. Edit, a new Save, profile load, and context change clear the old result. The handoff creates no extra read, write, request, retry, provider call, log, or stored value. Existing unconfirmed-change recovery remains unchanged. The behavior is source only and **NOT LIVE** until separately published and verified. Directory availability remains `false`, and live #623 remains inert. +**Expected result:** one exact current full-name update plus its successful non-null authoritative profile reread renders exactly **Profile name saved.** between the Profile heading and Edit, with status, polite live, atomic, programmatic-focus, bounded-layout, and visible-outline semantics. Only an admitted Save that owned focus records the current generation and attempt ID. Exact current confirmed success alone transfers that intent. The layout effect consumes it before target checks. Absent, body, document-root, or disconnected focus returns to the connected result; retained result focus is left alone; and every other connected focus is preserved. An unfocused Save still shows the truthful result without moving focus. Initial load, validation, update rejection, missing or rejected reread, profile reload, context or generation change, newer attempt, stale work, unmount, and later rerender cannot show or focus stale success. Edit, a new Save, profile load, and context change clear the old result. The handoff creates no extra read, write, request, retry, provider call, log, or stored value. Existing unconfirmed-change recovery remains unchanged. The behavior is source only and **NOT LIVE** until separately published and verified. Directory availability remains `false`, and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 surface. **Stop conditions:** a real account, profile, name, email, UID, screenshot, or production sign-in; direct production Firebase access; a provider configuration or production-data action; success copy other than **Profile name saved.**; a result shown before a current non-null authoritative reread; a result containing a member, provider, or error detail; missing status, live, atomic, programmatic-focus, bounded-layout, or visible-outline semantics; DOM order other than heading, result, Edit; a focused exact current Save whose confirmed result receives no otherwise-lost focus; an unfocused Save that moves focus; a connected control that loses deliberately selected focus; an intent containing anything beyond generation and attempt ID; transfer before current confirmed success; delayed focus on a later render; stale application, Firestore, identity, UID, generation, attempt, reread, or unmounted work that shows or focuses success; an extra read, write, request, retry, provider call, log, or stored value; changed validation, payload, confirmation-reread, AUTH-006F, unconfirmed-change, failure/retry, AUTH-006I Edit-to-input focus, Cancel-to-Edit focus, directory, or Strava behavior; a Function, Rule, schema, index, package, workflow, provider, account, sign-in, production-data, deployment, publication, membership, dues, role, payment, entitlement, roster, photo-query, facial-recognition, matching, embedding, similarity, or biometric change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, merge, preview, or green CI proves the behavior live. -**Success proof:** record the exact #651 issue, reviewed pull request and commit; trustworthy unchanged-runtime result with one expected failure and 243 skipped tests plus test-only digest `df02329a39ee24b127f801d4a8726f5748bdff0b992b8706a16456bbeb2fd66f`; green 22-of-22 AUTH-006G block; green 265-of-265 Account suite; passing type-check, scoped ESLint, and diff-check; bounded grid, containment, and focus-style evidence; runtime diff digest `c00a6c7e0486dcdfbb0e9d0a4b4c48215f03e3e8c72634fc1f2b17142c08c1d5`; relevant full frontend, repository Node, diagnostic build, unchanged lint-baseline, workflow, and security checks when complete; independent frontend/accessibility, security/privacy/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and live behavior separately. Record the unchanged `false` directory availability and unchanged #623 deploy separately. Source and tests do not prove merge. Merge does not prove publication. Publication does not prove `runmprc.com`, Firebase, provider, account, data, or live behavior. +**Success proof:** record the exact #651 issue, reviewed pull request and commit; trustworthy unchanged-runtime result with one expected failure and 243 skipped tests plus test-only digest `df02329a39ee24b127f801d4a8726f5748bdff0b992b8706a16456bbeb2fd66f`; green 22-of-22 AUTH-006G block; green 265-of-265 Account suite; passing type-check, scoped ESLint, and diff-check; bounded grid, containment, and focus-style evidence; runtime diff digest `c00a6c7e0486dcdfbb0e9d0a4b4c48215f03e3e8c72634fc1f2b17142c08c1d5`; relevant full frontend, repository Node, diagnostic build, unchanged lint-baseline, workflow, and security checks when complete; independent frontend/accessibility, security/privacy/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and live behavior separately. Record the unchanged `false` directory availability, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge. Merge does not prove publication. Publication does not prove `runmprc.com`, Firebase, provider, account, data, or live behavior. **Undo:** use one reviewed frontend-and-documentation revert or safe roll-forward. No Firebase, provider, account, sign-in, or production-data undo is needed because #651 changes source only. An undo must preserve AUTH-006F context fencing, generic unconfirmed-change recovery, the inert directory default, and active #616 work. Do not undo by editing or deleting a profile or account. @@ -1372,7 +1372,7 @@ Officer source-review procedure for AUTH-006H [#653] unconfirmed profile-name Sa 108. Confirm active #616 Strava runtime files remain unchanged. 109. Confirm active #616 OAUTH-001A2L/RISK-024 documentation remains unchanged. 110. Confirm the optional-directory availability value remains byte-for-byte `false`. -111. Confirm the last verified production directory deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +111. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 112. Confirm #507 still owns every optional-directory connection and live-proof gate. 113. Record the source change as its own state. 114. Record the named test results as their own state. @@ -1387,11 +1387,11 @@ Officer source-review procedure for AUTH-006H [#653] unconfirmed profile-name Sa 123. Record whether connected profile-photo or officer-finder behavior is live as its own state. 124. Stop before changing Firebase, a provider, an account, production data, directory availability, or the live website. -**Expected result:** an exact current update rejection, `null` confirmation reread, or rejected confirmation reread keeps the existing fixed unconfirmed alert and enabled **Try profile again** action. Every exact current unconfirmed result records only its generation and attempt ID to own that result. Only an admitted Save that owned focus records a pending focus token. The exact current catch transfers that pending token only when it matches the result. One layout effect consumes it before target checks and requires the matching generation and attempt, unavailable state, no profile, editor, or success confirmation, the exact message, and a connected alert. The alert has assertive, atomic, programmatic-focus, bounded-wrapping, and scoped visible-outline semantics. Its message immediately precedes the retry action. Absent, body, document-root, or disconnected focus returns to the alert; retained alert focus is left alone; and any other connected focus is preserved. An unfocused Save still shows the recovery without moving focus. Initial setup/read failure, validation, reload, context or generation change, newer attempt, stale update/reread work, unmount, and later rerender cannot focus stale recovery. Try clears the old intent before loading. The handoff creates no extra read, write, request, retry, provider call, log, or stored value. It does not claim whether the update persisted. AUTH-006G success remains unchanged. The behavior is source only and **NOT LIVE** until separately published and verified. Directory availability remains `false`, and live #623 remains inert. +**Expected result:** an exact current update rejection, `null` confirmation reread, or rejected confirmation reread keeps the existing fixed unconfirmed alert and enabled **Try profile again** action. Every exact current unconfirmed result records only its generation and attempt ID to own that result. Only an admitted Save that owned focus records a pending focus token. The exact current catch transfers that pending token only when it matches the result. One layout effect consumes it before target checks and requires the matching generation and attempt, unavailable state, no profile, editor, or success confirmation, the exact message, and a connected alert. The alert has assertive, atomic, programmatic-focus, bounded-wrapping, and scoped visible-outline semantics. Its message immediately precedes the retry action. Absent, body, document-root, or disconnected focus returns to the alert; retained alert focus is left alone; and any other connected focus is preserved. An unfocused Save still shows the recovery without moving focus. Initial setup/read failure, validation, reload, context or generation change, newer attempt, stale update/reread work, unmount, and later rerender cannot focus stale recovery. Try clears the old intent before loading. The handoff creates no extra read, write, request, retry, provider call, log, or stored value. It does not claim whether the update persisted. AUTH-006G success remains unchanged. The behavior is source only and **NOT LIVE** until separately published and verified. Directory availability remains `false`, and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 surface. **Stop conditions:** a real account, profile, name, email, UID, screenshot, or production sign-in; direct production Firebase access; a provider configuration or production-data action; unconfirmed copy other than **We could not confirm your profile change. Try the profile again before making another change.**; an alert containing a member, provider, response, or caught detail; missing alert, assertive, atomic, programmatic-focus, bounded-wrapping, or visible-outline semantics; the retry action appearing before the message or not remaining the next Tab stop; focus sent directly to the retry action; a focused exact current Save whose unconfirmed alert receives no otherwise-lost focus; an unfocused Save that moves focus; a connected control that loses deliberately selected focus; a token containing anything beyond generation and attempt ID; transfer outside an exact current catch; a browser claim that the write failed or persisted; delayed focus on a later render; stale application, Firestore, identity, UID, generation, attempt, update, reread, reload, or unmounted work that shows or focuses recovery; an extra read, write, request, retry, provider call, log, or stored value; changed validation, payload, AUTH-006F, AUTH-006G success, Try-profile-again result focus, validation error association, AUTH-006I Edit-to-input focus, Cancel-to-Edit focus, directory, or Strava behavior; a Function, Rule, schema, index, package, workflow, provider, account, sign-in, production-data, deployment, publication, membership, dues, role, payment, entitlement, roster, photo-query, facial-recognition, matching, embedding, similarity, or biometric change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, merge, preview, or green CI proves the behavior live. -**Success proof:** record the exact #653 issue, reviewed pull request and commit; trustworthy unchanged-runtime result with one expected failure and 287 skipped tests plus test-only RED digest `25ca6ccd34dcd0acbef28727d05f05f72079ed6bd55ee0ae3b11b43c04a4f056`; green 23-of-23 AUTH-006H block; green 288-of-288 Account suite; passing type-check, scoped ESLint, and diff-check; bounded wrapping and focus-style evidence; runtime-only digest `6e9d9a8da90d1a0c22144d7e64b27fdb05735893177393ae74bd5e3ff18e6170`; final test-diff digest `895cb6ef708ed0714d53a0cf2dc7b7336104cf111ab2d5f591078051772d81ea`; combined three-path digest `b84d60f1166e924062d65e7a9834d9a94a567098561e9e4ba955d6f3f3b1350b`; relevant full frontend, repository Node, diagnostic build, unchanged lint-baseline, workflow, and security checks when complete; independent frontend/accessibility, security/privacy/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and live behavior separately. Record the unchanged `false` directory availability and unchanged #623 deploy separately. Source and tests do not prove merge. Merge does not prove publication. Publication does not prove `runmprc.com`, Firebase, provider, account, data, or live behavior. +**Success proof:** record the exact #653 issue, reviewed pull request and commit; trustworthy unchanged-runtime result with one expected failure and 287 skipped tests plus test-only RED digest `25ca6ccd34dcd0acbef28727d05f05f72079ed6bd55ee0ae3b11b43c04a4f056`; green 23-of-23 AUTH-006H block; green 288-of-288 Account suite; passing type-check, scoped ESLint, and diff-check; bounded wrapping and focus-style evidence; runtime-only digest `6e9d9a8da90d1a0c22144d7e64b27fdb05735893177393ae74bd5e3ff18e6170`; final test-diff digest `895cb6ef708ed0714d53a0cf2dc7b7336104cf111ab2d5f591078051772d81ea`; combined three-path digest `b84d60f1166e924062d65e7a9834d9a94a567098561e9e4ba955d6f3f3b1350b`; relevant full frontend, repository Node, diagnostic build, unchanged lint-baseline, workflow, and security checks when complete; independent frontend/accessibility, security/privacy/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and live behavior separately. Record the unchanged `false` directory availability, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge. Merge does not prove publication. Publication does not prove `runmprc.com`, Firebase, provider, account, data, or live behavior. **Undo:** use one reviewed frontend-and-documentation revert or safe roll-forward. No Firebase, provider, account, sign-in, or production-data undo is needed because #653 changes source only. An undo must preserve AUTH-006F context fencing, AUTH-006G confirmed-save behavior, the fixed generic unconfirmed recovery, the inert directory default, and active #616 work. Do not undo by editing or deleting a profile or account. @@ -1508,7 +1508,7 @@ Officer source-review procedure for AUTH-006I [#655] profile Edit-to-full-name-i 101. Confirm active #616 Strava runtime blobs remain `2eb48945061ab5ad2a896c6835f308cefd7fe63a` and `d1792d390bd57608fecab84341a6e5916fcf8196`. 102. Confirm active #616 OAUTH-001A2L/RISK-024 documentation remains unchanged. 103. Confirm the optional-directory availability blob remains `295909b0df8dd7c54a0f164f99d4943656aece4b`, whose value is byte-for-byte `false`. -104. Confirm the last verified production directory deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +104. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 105. Confirm #507 still owns every optional-directory connection and live-proof gate. 106. Record the source change as its own state. 107. Record the named test results as their own state. @@ -1523,11 +1523,11 @@ Officer source-review procedure for AUTH-006I [#655] profile Edit-to-full-name-i 116. Record whether connected profile-photo or officer-finder behavior is live as its own state. 117. Stop before changing Firebase, a provider, an account, production data, directory availability, or the live website. -**Expected result:** a connected focused current **Edit** opens the existing editor, clears prior Save feedback, keeps the authoritative current name, and returns otherwise-lost focus once to the connected enabled **Full name** input. Full name remains a native labeled input with its linked description, autocomplete, maximum length, existing global visible-focus rule, and position before Save and Cancel; Save is the next ordinary Tab stop. An unfocused or programmatic Edit opens the editor without moving focus. The layout effect consumes the generation-only intent before checks, preserves any deliberate connected focus, and cannot reuse stale or consumed intent after a target disappears, context changes, profile reloads, Save, Cancel, Try, unmount, or a later render. Editor entry creates no validation, read, write, request, retry, provider call, log, stored value, CSS change, or page node. AUTH-006F/G/H and exact calls remain unchanged. The behavior is source only and **NOT LIVE** until separately published and verified. Directory availability remains `false`, and live #623 remains inert. +**Expected result:** a connected focused current **Edit** opens the existing editor, clears prior Save feedback, keeps the authoritative current name, and returns otherwise-lost focus once to the connected enabled **Full name** input. Full name remains a native labeled input with its linked description, autocomplete, maximum length, existing global visible-focus rule, and position before Save and Cancel; Save is the next ordinary Tab stop. An unfocused or programmatic Edit opens the editor without moving focus. The layout effect consumes the generation-only intent before checks, preserves any deliberate connected focus, and cannot reuse stale or consumed intent after a target disappears, context changes, profile reloads, Save, Cancel, Try, unmount, or a later render. Editor entry creates no validation, read, write, request, retry, provider call, log, stored value, CSS change, or page node. AUTH-006F/G/H and exact calls remain unchanged. The behavior is source only and **NOT LIVE** until separately published and verified. Directory availability remains `false`, and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 surface. **Stop conditions:** a real account, profile, name, email, UID, screenshot, or production sign-in; direct production Firebase access; a provider configuration or production-data action; a non-native Edit or Full name control; changed input value, label, description, autocomplete, maximum length, enabled state, or input/Save/Cancel order; missing existing visible-focus behavior; any Account or global CSS change; an intent containing more than the profile generation; `autoFocus`, timeout, animation frame, text selection, or new React state; an unfocused or programmatic Edit that moves focus; a focused current Edit whose otherwise-lost focus does not reach Full name; focus sent directly to Save or Cancel; a connected deliberate target that loses focus; delayed or repeated focus after a missing, disabled, disconnected, stale, removed, or consumed target; stale application, Firestore, identity, UID, profile generation, load, reload, Try, Save, Cancel, or unmounted work that moves focus; validation, a read, write, request, retry, provider call, log, stored value, or page node caused by entry focus; changed AUTH-006F/G/H, payload, call count, Cancel-to-Edit focus, validation-error behavior, Try settlement, save-pending announcement, directory, or Strava behavior; a Function, Rule, schema, index, service, package, workflow, provider, account, sign-in, production-data, deployment, publication, membership, dues, role, payment, entitlement, roster, photo-query, facial-recognition, matching, embedding, similarity, or biometric change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, merge, preview, or green CI proves the behavior live. -**Success proof:** record the exact #655 issue, reviewed pull request and commit; trustworthy unchanged-runtime result with one expected failure, 288 skipped tests, 289 total tests, focus left on the body, and test-only RED digest `3de742e72b8ef0d847c0a5811da0000631ecd926dcd1e9e5c589932e9b78efb4`; green 17-of-17 AUTH-006I block; green 305-of-305 Account suite; passing type-check, zero-output scoped ESLint, and diff-check; unchanged `Account.css` and `index.css` blobs plus existing global visible-focus evidence; runtime-only digest `a5bddd143b62af06b2357b30f3045117009b3bc827b1753bbb7a34f6c42cd5b4`; final test-diff digest `b5966220783abca0c5cfed832752471f167f0dcf48d636ab2eafd2c07896c3f3`; combined two-path digest `24dcd9003bb12fdc3abccfa19820682473644fa38d8a1b606a8e824277a51dd1`; green full frontend result with 18-of-18 suites and 1,314-of-1,314 tests; green 105-of-105 repository Node result; passing unchanged lint baseline and diagnostic build; workflow and security checks when complete; independent frontend/accessibility, security/privacy/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and live behavior separately. Record the unchanged `false` directory availability and unchanged #623 deploy separately. Source and tests do not prove merge. Merge does not prove publication. Publication does not prove `runmprc.com`, Firebase, provider, account, data, or live behavior. +**Success proof:** record the exact #655 issue, reviewed pull request and commit; trustworthy unchanged-runtime result with one expected failure, 288 skipped tests, 289 total tests, focus left on the body, and test-only RED digest `3de742e72b8ef0d847c0a5811da0000631ecd926dcd1e9e5c589932e9b78efb4`; green 17-of-17 AUTH-006I block; green 305-of-305 Account suite; passing type-check, zero-output scoped ESLint, and diff-check; unchanged `Account.css` and `index.css` blobs plus existing global visible-focus evidence; runtime-only digest `a5bddd143b62af06b2357b30f3045117009b3bc827b1753bbb7a34f6c42cd5b4`; final test-diff digest `b5966220783abca0c5cfed832752471f167f0dcf48d636ab2eafd2c07896c3f3`; combined two-path digest `24dcd9003bb12fdc3abccfa19820682473644fa38d8a1b606a8e824277a51dd1`; green full frontend result with 18-of-18 suites and 1,314-of-1,314 tests; green 105-of-105 repository Node result; passing unchanged lint baseline and diagnostic build; workflow and security checks when complete; independent frontend/accessibility, security/privacy/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and live behavior separately. Record the unchanged `false` directory availability, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge. Merge does not prove publication. Publication does not prove `runmprc.com`, Firebase, provider, account, data, or live behavior. **Undo:** use one reviewed frontend-and-documentation revert or safe roll-forward. No Firebase, provider, account, sign-in, production-data, or CSS undo is needed because #655 changes source focus behavior and documentation only. An undo must preserve AUTH-006F/G/H, the authoritative current name and name-only payload, the inert directory default, and active #616 work. Do not undo by editing or deleting a profile or account. @@ -2849,7 +2849,7 @@ Officer review steps after every prerequisite has proof: ## Optional profile photo and officer people finder — INERT FRONTEND PREVIEW; BACKEND NOT LIVE -**Purpose:** let officers review the future profile-photo, independent finder-choice, and People finder layouts without connecting the private backend. The #621 frontend default is an inert preview: every related control is disabled; it reads no saved photo or setting, accepts or uploads no photo, searches no name, and saves nothing. #623 published only that inert interface as bounded Netlify deploy `6a7e072f8f346b0008510d29`. Signed-out route, guard, and no-directory-request checks passed, and the temporary authority is inactive. After a later approved connection, a signed-in person could choose one private profile thumbnail and, separately, choose whether the People finder may show their display name and thumbnail. A properly authorized officer could search by name and compare voluntary thumbnails visually. The system will not search a photo or recognize a face. +**Purpose:** let officers review the future profile-photo, independent finder-choice, and People finder layouts without connecting the private backend. The #621 frontend default is an inert preview: every related control is disabled; it reads no saved photo or setting, accepts or uploads no photo, searches no name, and saves nothing. #623 published only that inert interface as bounded Netlify deploy `6a7e072f8f346b0008510d29`. Signed-out route, guard, and no-directory-request checks passed, and the temporary authority is inactive. #659 live deploy `6a7ece87c5ca4d0007c1a3fc` preserves the exact inert directory surface beneath its accessibility-only delta. After a later approved connection, a signed-in person could choose one private profile thumbnail and, separately, choose whether the People finder may show their display name and thumbnail. A properly authorized officer could search by name and compare voluntary thumbnails visually. The system will not search a photo or recognize a face. **Approver:** membership lead, privacy owner, and platform/security owner. The privacy owner must approve the final notice and backup/removal wording before connected publication. @@ -2864,7 +2864,8 @@ flowchart TD Officer --> Search["Name field and Search button disabled"] Account --> None["No directory name or photo read, upload, remove, search, or save"] Search --> None - Release["#623 exact inert artifact published"] --> Public["Completed signed-out revision and guard readback only"] + Release["#623 exact inert artifact published"] --> Preserve["#659 accessibility artifact preserves inert surface"] + Preserve --> Public["Completed signed-out revision and guard readback only"] Public -. "does not prove protected layout" .-> Synthetic Hardening["#627 connected-interface hardening — SOURCE ONLY"] --> Preserved["Accessible Account and People finder branches preserved behind false availability"] Review["#629 connected photo review — SOURCE ONLY"] --> Draft["Generated valid image is read locally; centered-square draft says Selected photo — not uploaded yet"] @@ -2914,7 +2915,7 @@ flowchart TD Connected -. "never photo search or proof" .-> Official["Membership, role, payment, or official records"] ``` -Text alternative: the published #623 artifact keeps the Account and administrator-guarded People-finder controls disabled; source-only #627 preserves the accessible connected layouts behind the unchanged false availability value; source-only #629 adds local photo review where Cancel sends nothing, Save alone sends the existing upload command, and the current saved photo remains authoritative with a version-reset unavailable fallback; source-only #631 distinguishes a `null` **No photo** result from an unrenderable supplied **Photo unavailable** result, retries a different later photo version, and lets completed local states clear the query, messages, cards, names, and images with an announcement, input focus, and no new request or service call; that Clear action does not cancel work, erase memory or cache, roll back an audit, or recall a seen result; source-only #633 makes **Remove current saved photo** preserve the same local reading or ready replacement through a confirmed authoritative remove, use the refreshed revision only when the person later chooses Save, focus a remaining Remove action before a ready Save action before the persistent file input, keep the draft after a definitive rejection with successful readback, and after an unknown outcome or failed readback discard its bytes, hide photo and finder mutation controls, and retain only the existing Reload settings recovery with no Save retry; source-only #635 keeps that uncertain-change warning through failed Reload settings attempts until one authoritative profile read succeeds, while generic load failures make no global no-change promise and reload sends no mutation; source-only #637 focuses the recovery action after user-initiated mutation or readback failure, binds a Reload focus intent to the exact current load before focusing a replacement after failure, never steals focus on an initial load failure, and keeps stale application, account, and unmounted completions focus-inert; source-only #639 admits a returned saved photo only when its canonical decoded bytes total 12 through 65,536 with `RIFF` at bytes 0–3 and `WEBP` at bytes 8–11, maps every other returned byte shape to one fixed byte-free failure before the Account image path, preserves the version-scoped **Photo unavailable** fallback and Remove action for structurally admitted bytes the browser cannot display, and leaves outbound uploads unchanged; source-only #641 records only the exact current input-or-Search focus origin after a valid search enters pending, restores that same now-enabled origin after cards, empty, or fixed failure only when native disablement left no meaningful focus, and preserves any other connected focus the user chose during the request; source-only #643 records only the exact current lifetime and removal operation when focused Remove enters pending, and after definitive rejection plus successful authoritative readback restores otherwise-lost focus to surviving Remove, a current ready Save, or the persistent file input without stealing deliberately moved connected focus or attaching the standalone rejection alert to a replacement target; source-only #645 records only the exact current lifetime, operation, and upload-or-remove action when focused Save or Remove enters pending, transfers it only after confirmed success plus current authoritative readback, restores otherwise-lost upload focus to the persistent file input or removal focus by the existing Remove, ready Save, then file-input priority, and preserves any other connected focus deliberately chosen during the mutation or readback; source-only #647 records only the exact current lifetime and visibility operation when the focused officer-finder checkbox enters pending, transfers that intent after confirmed success or definitive rejection only after current authoritative readback, restores otherwise-lost focus to the same connected and enabled checkbox without stealing another deliberately focused control, and consumes without focus when current name eligibility leaves the returned off checkbox disabled; source-only #649 puts the fixed **Profile photo and officer finder settings reloaded** polite atomic status first in recovered ready controls after every valid explicit current Reload success, restores otherwise-lost focus to its connected visibly outlined node only when that exact Reload owned focus and its exact current authoritative read succeeded, preserves any deliberately selected connected focus, shows the result without moving focus for a programmatic or unfocused Reload, and leaves initial/background success and failed Reloads on their existing paths; and only #507 may later connect name search plus voluntary thumbnails after privacy, authorization, staging, and backend-first readback, without photo search, face recognition, or official-record authority. +Text alternative: the published #623 artifact, preserved by live #659 deploy `6a7ece87c5ca4d0007c1a3fc`, keeps the Account and administrator-guarded People-finder controls disabled; source-only #627 preserves the accessible connected layouts behind the unchanged false availability value; source-only #629 adds local photo review where Cancel sends nothing, Save alone sends the existing upload command, and the current saved photo remains authoritative with a version-reset unavailable fallback; source-only #631 distinguishes a `null` **No photo** result from an unrenderable supplied **Photo unavailable** result, retries a different later photo version, and lets completed local states clear the query, messages, cards, names, and images with an announcement, input focus, and no new request or service call; that Clear action does not cancel work, erase memory or cache, roll back an audit, or recall a seen result; source-only #633 makes **Remove current saved photo** preserve the same local reading or ready replacement through a confirmed authoritative remove, use the refreshed revision only when the person later chooses Save, focus a remaining Remove action before a ready Save action before the persistent file input, keep the draft after a definitive rejection with successful readback, and after an unknown outcome or failed readback discard its bytes, hide photo and finder mutation controls, and retain only the existing Reload settings recovery with no Save retry; source-only #635 keeps that uncertain-change warning through failed Reload settings attempts until one authoritative profile read succeeds, while generic load failures make no global no-change promise and reload sends no mutation; source-only #637 focuses the recovery action after user-initiated mutation or readback failure, binds a Reload focus intent to the exact current load before focusing a replacement after failure, never steals focus on an initial load failure, and keeps stale application, account, and unmounted completions focus-inert; source-only #639 admits a returned saved photo only when its canonical decoded bytes total 12 through 65,536 with `RIFF` at bytes 0–3 and `WEBP` at bytes 8–11, maps every other returned byte shape to one fixed byte-free failure before the Account image path, preserves the version-scoped **Photo unavailable** fallback and Remove action for structurally admitted bytes the browser cannot display, and leaves outbound uploads unchanged; source-only #641 records only the exact current input-or-Search focus origin after a valid search enters pending, restores that same now-enabled origin after cards, empty, or fixed failure only when native disablement left no meaningful focus, and preserves any other connected focus the user chose during the request; source-only #643 records only the exact current lifetime and removal operation when focused Remove enters pending, and after definitive rejection plus successful authoritative readback restores otherwise-lost focus to surviving Remove, a current ready Save, or the persistent file input without stealing deliberately moved connected focus or attaching the standalone rejection alert to a replacement target; source-only #645 records only the exact current lifetime, operation, and upload-or-remove action when focused Save or Remove enters pending, transfers it only after confirmed success plus current authoritative readback, restores otherwise-lost upload focus to the persistent file input or removal focus by the existing Remove, ready Save, then file-input priority, and preserves any other connected focus deliberately chosen during the mutation or readback; source-only #647 records only the exact current lifetime and visibility operation when the focused officer-finder checkbox enters pending, transfers that intent after confirmed success or definitive rejection only after current authoritative readback, restores otherwise-lost focus to the same connected and enabled checkbox without stealing another deliberately focused control, and consumes without focus when current name eligibility leaves the returned off checkbox disabled; source-only #649 puts the fixed **Profile photo and officer finder settings reloaded** polite atomic status first in recovered ready controls after every valid explicit current Reload success, restores otherwise-lost focus to its connected visibly outlined node only when that exact Reload owned focus and its exact current authoritative read succeeded, preserves any deliberately selected connected focus, shows the result without moving focus for a programmatic or unfocused Reload, and leaves initial/background success and failed Reloads on their existing paths; and only #507 may later connect name search plus voluntary thumbnails after privacy, authorization, staging, and backend-first readback, without photo search, face recognition, or official-record authority. Officer review steps for the #621 frontend preview: @@ -3016,7 +3017,7 @@ The section purpose, approvers, stop conditions, undo path, and escalation roles 1. Keep the complete profile-photo and People-finder feature marked **NOT AVAILABLE YET**. 2. Ask the platform owner for the exact #627 reviewed pull request, merge commit, and generated-only frontend test record. 3. Confirm the source-controlled availability value remains byte-for-byte `false`. -4. Confirm production deploy `6a7e072f8f346b0008510d29` remains the unchanged inert #623 preview. +4. Confirm production deploy `6a7ece87c5ca4d0007c1a3fc` preserves the unchanged inert #623 preview from rollback deploy `6a7e072f8f346b0008510d29`. 5. Confirm the tests use only made-up names and generated non-face images. 6. Confirm My Account supplies the current full display name to the preserved connected profile controls. 7. Confirm new opt-in uses the same bounded Unicode display-name eligibility as the private projection. @@ -3045,9 +3046,9 @@ The section purpose, approvers, stop conditions, undo path, and escalation roles 30. Confirm #627 changes no Function, Rule, index, service contract, package, workflow, release control, provider setting, account, sign-in state, or production data. 31. Record source change, tests, merge, preview, website publication, exact `runmprc.com` revision, Firebase, provider configuration, account/sign-in change, production data, and connected behavior as separate results. -**#627 expected result:** the reviewed source applies the projection's exact name-eligibility boundary to new opt-in, preserves turn-off after a name becomes ineligible, improves control and placeholder semantics, announces a non-empty search without a count, uses scoped readable colors, contains native controls at 320 pixels, and makes an older file read inert after its Account context changes. The availability value remains `false`. The default branch remains inert, and the live #623 preview remains unchanged. Neither makes a directory request. The backend and connected behavior remain **NOT AVAILABLE YET**. A merge is not website publication. +**#627 expected result:** the reviewed source applies the projection's exact name-eligibility boundary to new opt-in, preserves turn-off after a name becomes ineligible, improves control and placeholder semantics, announces a non-empty search without a count, uses scoped readable colors, contains native controls at 320 pixels, and makes an older file read inert after its Account context changes. The availability value remains `false`. The default branch remains inert, and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the unchanged inert #623 preview. Neither makes a directory request. The backend and connected behavior remain **NOT AVAILABLE YET**. A merge is not website publication. -**#627 success proof:** record the exact issue, reviewed pull request and merge commit, green focused and full frontend checks, type-checking, diagnostic production build, unchanged lint baseline, independent privacy/security, frontend/accessibility, and backup-officer GO reviews, and exact-main CI. Record the unchanged `false` availability value and the unchanged #623 deploy separately. Record website publication, `runmprc.com` revision change, Firebase deployment, Rules or index change, provider configuration, account/sign-in change, production-data action, and connected behavior as **not performed**. Final connection and live proof remain #507 work. +**#627 success proof:** record the exact issue, reviewed pull request and merge commit, green focused and full frontend checks, type-checking, diagnostic production build, unchanged lint baseline, independent privacy/security, frontend/accessibility, and backup-officer GO reviews, and exact-main CI. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Record website publication, `runmprc.com` revision change, Firebase deployment, Rules or index change, provider configuration, account/sign-in change, production-data action, and connected behavior as **not performed**. Final connection and live proof remain #507 work. Officer review steps for MEMBERS-DIRECTORY-001F [#629] explicit photo review — connected source only, **NOT LIVE**: @@ -3060,7 +3061,7 @@ Officer review steps for MEMBERS-DIRECTORY-001F [#629] explicit photo review — 1. Keep the complete profile-photo and People-finder feature marked **NOT AVAILABLE YET**. 2. Ask the platform owner for the exact #629 issue, reviewed pull request, merge commit, and synthetic test record. 3. Confirm the source-controlled availability value remains byte-for-byte `false`. -4. Confirm the last verified production deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +4. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 5. Confirm the synthetic test uses a generated non-face image. 6. Select one supported generated image in the isolated connected-source test. 7. Confirm the browser validates and reads the selection locally. @@ -3133,11 +3134,11 @@ Officer review steps for MEMBERS-DIRECTORY-001F [#629] explicit photo review — 74. Record whether connected behavior became available. 75. Stop. Do not turn availability on, deploy a backend, publish the connected source, or use a real photo. -**Expected result:** selecting a valid generated image produces one centered-square local draft labeled **Selected photo — not uploaded yet** and sends nothing. A polite status announces when that local preview is ready. Cancel discards that draft, sends nothing, announces the result, and returns focus to the persistent file control. Save alone creates a request number, sends the existing revisioned upload request, and then refetches the authoritative processed thumbnail or no-photo fallback; confirmed Save also returns focus to the persistent Add or Replace photo control. Request-number failure or definitive rejection with successful readback retains the retryable draft; unknown or failed readback discards it and hides controls. A visibility save preserves it and refreshes the revision used by its later Save. The application does not use or expose the filename, stale reads and image events are inert, finder visibility is unchanged, and invalid or unreadable selections retain no draft. Unrenderable bytes are discarded and cannot be saved. A failed saved-thumbnail display uses a version-reset **Photo unavailable** fallback while Remove remains available. Availability remains `false`; the live #623 preview and backend remain unchanged. Connected behavior is **NOT AVAILABLE YET**. +**Expected result:** selecting a valid generated image produces one centered-square local draft labeled **Selected photo — not uploaded yet** and sends nothing. A polite status announces when that local preview is ready. Cancel discards that draft, sends nothing, announces the result, and returns focus to the persistent file control. Save alone creates a request number, sends the existing revisioned upload request, and then refetches the authoritative processed thumbnail or no-photo fallback; confirmed Save also returns focus to the persistent Add or Replace photo control. Request-number failure or definitive rejection with successful readback retains the retryable draft; unknown or failed readback discards it and hides controls. A visibility save preserves it and refreshes the revision used by its later Save. The application does not use or expose the filename, stale reads and image events are inert, finder visibility is unchanged, and invalid or unreadable selections retain no draft. Unrenderable bytes are discarded and cannot be saved. A failed saved-thumbnail display uses a version-reset **Photo unavailable** fallback while Remove remains available. Availability remains `false`; live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 preview, and the backend remains unavailable. Connected behavior is **NOT AVAILABLE YET**. **Stop conditions:** a real name or photo; a production sign-in; any photo request before explicit Save; a request number created by selection or Cancel; a filename read, retained, rendered, logged, sent, or exposed; an unknown-outcome or failed-readback draft retained; a retryable draft discarded after request-number failure or definitive rejection with successful readback; a stale draft rendered or sent after reselection, Cancel, unmount, application change, or account change; an invalid, unreadable, or unrenderable byte-bearing draft retained or savable; a saved-photo display failure that removes the Remove action or suppresses a new version; a photo change that alters finder visibility; a Firebase, Rule, index, Function, provider, account, sign-in, or production-data change; an availability flip; a connected website publication; or a claim that source, tests, or merge means the feature is live. -**Success proof:** record the exact #629 issue, reviewed pull request and merge commit; green focused and full frontend checks; type-checking; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, and backup-officer GO reviews; and exact-main CI. Record the unchanged `false` availability value and unchanged #623 deploy separately. Record website publication, `runmprc.com` revision change, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected behavior as **not performed**. Final backend connection and live proof remain #507 work. +**Success proof:** record the exact #629 issue, reviewed pull request and merge commit; green focused and full frontend checks; type-checking; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, and backup-officer GO reviews; and exact-main CI. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Record website publication, `runmprc.com` revision change, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected behavior as **not performed**. Final backend connection and live proof remain #507 work. **Undo:** use one reviewed frontend revert or safe roll-forward. Confirm the default disabled branch still makes zero directory calls. No Firebase or production-data undo is needed because #629 changes source only. @@ -3159,7 +3160,7 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001G [#631] local People-f 6. Ask the platform owner for the written synthetic-behavior report. 7. Confirm the report names the platform owner or testing specialist who ran the test. 8. Confirm the source-controlled availability value remains byte-for-byte `false`. -9. Confirm the last verified production deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +9. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 10. Confirm the evidence uses only made-up names. 11. Confirm the evidence uses only generated non-face thumbnails. 12. Confirm the named test keeps the page behind the existing administrator guard. @@ -3218,11 +3219,11 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001G [#631] local People-f 65. Record whether connected or live People-finder behavior became available as its own state. 66. Stop before changing availability, Firebase, a provider, an account, production data, or the live website. -**Expected result:** the reviewed connected source uses **No photo** only for a `null` photo and uses **Photo unavailable** when a supplied generated thumbnail cannot render. The failed image/data URL leaves the rendered page, and a different later photo version receives a fresh attempt. Clear is offered only after completed validation, empty results, fixed failure, or result cards. It removes the query and prior displayed message, headings, cards, names, and images, uses the persistent polite status region to announce **Search field and displayed result cards cleared.**, focuses the persistent input, creates no request number, and makes no directory-service call. It is not available while idle or pending. Availability remains `false`; the default branch and live #623 preview remain inert. The backend and connected behavior remain **NOT AVAILABLE YET**. +**Expected result:** the reviewed connected source uses **No photo** only for a `null` photo and uses **Photo unavailable** when a supplied generated thumbnail cannot render. The failed image/data URL leaves the rendered page, and a different later photo version receives a fresh attempt. Clear is offered only after completed validation, empty results, fixed failure, or result cards. It removes the query and prior displayed message, headings, cards, names, and images, uses the persistent polite status region to announce **Search field and displayed result cards cleared.**, focuses the persistent input, creates no request number, and makes no directory-service call. It is not available while idle or pending. Availability remains `false`; the default branch remains inert, and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 preview. The backend and connected behavior remain **NOT AVAILABLE YET**. **Stop conditions:** a real name or photo; a face or photo query; production sign-in; direct production Firebase access; Clear offered while idle, pending, or in the disabled preview; a new request number or service call caused by Clear; a failed supplied image that remains in the page or is mislabeled **No photo**; a later photo version that inherits an older failure; a query, prior message, result heading, card, name, image, or image data URL that remains displayed after Clear; missing input focus; an availability flip; a Function, Rule, index, schema, provider, account, sign-in, production-data, or website change; or a claim that local Clear cancels network work, erases browser memory/cache, rolls back the query-free audit, or recalls a result already returned, seen, or captured. -**Success proof:** record the exact #631 issue, reviewed pull request and commit; green separately named MEMBERS-DIRECTORY-001G focused tests; green full frontend tests; type-checking; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value and unchanged #623 deploy separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. +**Success proof:** record the exact #631 issue, reviewed pull request and commit; green separately named MEMBERS-DIRECTORY-001G focused tests; green full frontend tests; type-checking; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. **Undo:** use one reviewed frontend revert or safe roll-forward. Confirm the default disabled branch still makes zero directory calls. No Firebase, provider, account, or production-data undo is needed because #631 changes source only. Undo cannot recall a result already seen or captured and must not alter the query-free audit. @@ -3246,7 +3247,7 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001H [#633] reviewed-repla 8. Confirm the evidence uses only a made-up account. 9. Confirm the evidence uses only generated non-face images. 10. Confirm the source-controlled availability value remains byte-for-byte `false`. -11. Confirm the last verified production deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +11. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 12. Confirm the destructive action is named **Remove current saved photo**. 13. Confirm that label distinguishes the saved thumbnail from the local replacement. 14. Confirm selecting a replacement creates no upload request number. @@ -3303,21 +3304,21 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001H [#633] reviewed-repla 65. Record whether connected behavior became available as its own state. 66. Stop before changing availability, Firebase, a provider, an account, production data, or the live website. -**Expected result:** the reviewed connected source clearly separates **Remove current saved photo** from the local replacement. Confirmed removal and authoritative readback preserve the same current reading or ready draft while updating the saved-photo state and revision. A later explicit Save sends the preserved content type and bytes once against that refreshed revision. Definitive rejection plus successful readback keeps the draft and associates the fixed error with Remove. Unknown outcome or failed readback discards the draft and data URL, hides the photo and finder mutation controls, retains only the existing **Reload settings** recovery, and offers no Save or duplicate-mutation retry. Focus moves to a still-current Remove action first, an eligible Save action second, or the persistent Add/Replace input otherwise. Finder visibility stays unchanged. Stale completions remain inert. Availability remains `false`; the default branch and live #623 preview remain inert. The backend and connected behavior remain **NOT AVAILABLE YET**. +**Expected result:** the reviewed connected source clearly separates **Remove current saved photo** from the local replacement. Confirmed removal and authoritative readback preserve the same current reading or ready draft while updating the saved-photo state and revision. A later explicit Save sends the preserved content type and bytes once against that refreshed revision. Definitive rejection plus successful readback keeps the draft and associates the fixed error with Remove. Unknown outcome or failed readback discards the draft and data URL, hides the photo and finder mutation controls, retains only the existing **Reload settings** recovery, and offers no Save or duplicate-mutation retry. Focus moves to a still-current Remove action first, an eligible Save action second, or the persistent Add/Replace input otherwise. Finder visibility stays unchanged. Stale completions remain inert. Availability remains `false`; the default branch remains inert, and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 preview. The backend and connected behavior remain **NOT AVAILABLE YET**. **Stop conditions:** a real account or photo; production sign-in; a replacement upload before explicit Save; a local draft lost after confirmed removal; a draft retained after an unknown outcome or failed readback; a discarded data URL left in the page; Save using the pre-remove revision; duplicate upload; focus sent to a missing or stale control; an older reader, mutation, or readback restoring bytes, state, focus, or a service call in another context; a photo change that alters finder visibility; a Firebase, Rule, index, Function, service-contract, provider, account, sign-in, production-data, or website change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, or merge means the feature is live. -**Success proof:** record the exact #633 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001H focused tests; green full frontend tests; type-checking; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value and unchanged #623 deploy separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. +**Success proof:** record the exact #633 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001H focused tests; green full frontend tests; type-checking; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. **Undo:** use one reviewed frontend revert or safe roll-forward. Confirm the default disabled branch still makes zero directory calls. No Firebase, provider, account, or production-data undo is needed because #633 changes source only. Undo must not retain or restore a stale local draft. **Escalation:** membership lead plus privacy and platform/security owners. Use the private incident path if a real photo appeared, a replacement was uploaded without explicit Save, draft bytes survived an unknown state, finder visibility changed, or connected behavior became available. -**Expected result:** production deploy `6a7e072f8f346b0008510d29` defaults to a visibly disabled preview that makes zero directory calls, accepts no file or name, and shows no person. Separate synthetic tests prove the protected disabled layouts and preserved connected source. Completed signed-out public readback proves only the exact revision, normal guards, and absence of a member-directory request. The backend and connected behavior remain unavailable. There is no public directory, official roster, public photo URL, Firebase Storage object, photo-as-query path, face recognition, similarity score, embedding, biometric template, export, result total, or pagination. +**Expected result:** production deploy `6a7ece87c5ca4d0007c1a3fc` preserves the #623 visibly disabled preview from rollback deploy `6a7e072f8f346b0008510d29`. It makes zero directory calls, accepts no file or name, and shows no person. Separate synthetic tests prove the protected disabled layouts and preserved connected source. Completed signed-out public readback proves only the exact revision, normal guards, and absence of a member-directory request. The backend and connected behavior remain unavailable. There is no public directory, official roster, public photo URL, Firebase Storage object, photo-as-query path, face recognition, similarity score, embedding, biometric template, export, result total, or pagination. **Stop conditions:** an enabled preview control; a preview that reads saved directory state, accepts a file or finder name, creates a directory request number, calls a directory service, or shows a sample or result card; a real person, name, photo, member record, production sign-in, direct production Firebase access, production data change, or member-directory callable request; a public/permanent photo URL; an upload that silently opts in; a result from a search transaction ordered after completed opt-out; a notice that fails to explain that an earlier-committed response may still arrive; raw image, name, query, result identity, or provider detail in a log, issue, screenshot, message, email, or AI tool; a request for photo search, face recognition, similarity matching, or biometric processing; missing privacy approval for connected publication; an unreviewed availability flip; or a claim that source, tests, merge, frontend publication, or preview means the backend feature is live. -**Success proof:** record the exact #505, #506, and #621 pull requests and merge commits; green focused and full checks; dependency review; independent privacy/security and backup-officer reviews; and explicit statements that Firebase, providers, accounts/sign-in, and production data were unchanged. For #623, record preview deploy `6a7e05febf8fde00084cf9e0`, preview head `1fdb31f71fcaf01c33b5e57a4cd28fc473a4a737`, PR CI `31728469418`, release merge `9d5cc8612b4321172370bd949d307e7e4ac0ec7d`, exact-main CI `31728908486`, production deploy `6a7e072f8f346b0008510d29`, exact public marker, signed-out guards, anonymous no-connected-symbol/request result, repause head `d401daa409176dce0906c245adf3f20310cb513b`, repause PR CI `31728977578`, repause merge `c8678c623afdd9becf77d596b71f36f26f04b746`, repause exact-main CI `31729248865`, unpublished attempt `6a7e081e73fdd60009f7ba57`, and retained-deploy readback. Record that the manifest is inactive, release source is absent, and rollback ref remains. Synthetic artifacts and tests prove only the disabled protected layouts and default zero-directory-call branches. Publication and anonymous readback prove only the exact revision, signed-out guards, and absence of a public member-directory request. Record separately that the privacy notice, Firebase/backend deployment, provider configuration, account/sign-in change, production-data action, connected behavior, and live directory were not performed. Final connected live proof belongs to #507. +**Success proof:** record the exact #505, #506, and #621 pull requests and merge commits; green focused and full checks; dependency review; independent privacy/security and backup-officer reviews; and explicit statements that Firebase, providers, accounts/sign-in, and production data were unchanged. Preserve the full #623 record: preview deploy `6a7e05febf8fde00084cf9e0`, preview head `1fdb31f71fcaf01c33b5e57a4cd28fc473a4a737`, PR CI `31728469418`, release merge `9d5cc8612b4321172370bd949d307e7e4ac0ec7d`, exact-main CI `31728908486`, production deploy `6a7e072f8f346b0008510d29`, exact public marker, signed-out guards, anonymous no-connected-symbol/request result, repause head `d401daa409176dce0906c245adf3f20310cb513b`, repause PR CI `31728977578`, repause merge `c8678c623afdd9becf77d596b71f36f26f04b746`, repause exact-main CI `31729248865`, unpublished attempt `6a7e081e73fdd60009f7ba57`, and retained-deploy readback. Also record that #659 live deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert surface and that its manifest is inactive after unpublished repause attempt `6a7ed0ddb00a46000818878d`. Synthetic artifacts and tests prove only the disabled protected layouts and default zero-directory-call branches. Publication and anonymous readback prove only the exact revision, signed-out guards, and absence of a public member-directory request. Record separately that the privacy notice, Firebase/backend deployment, provider configuration, account/sign-in change, production-data action, connected behavior, and live directory were not performed. Final connected live proof belongs to #507. **Undo:** before or after frontend-preview publication, use one reviewed frontend revert or safe roll-forward and read back the exact disabled state. The #621 preview changes no Firebase record to undo. After a future approved backend release, use the documented backend-first release path and verify opt-out/removal with a made-up account. Never undo by deleting or editing a real account or Firebase record manually. @@ -3341,7 +3342,7 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001I [#635] uncertain-chan 8. Confirm the evidence uses only a made-up account. 9. Confirm the evidence uses only generated non-face image bytes. 10. Confirm the source-controlled availability value remains byte-for-byte `false`. -11. Confirm the last verified production deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +11. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 12. Confirm an ordinary unknown visibility, upload, or removal outcome displays **We could not confirm that change**. 13. Confirm a failed authoritative read after a resolved mutation displays the same warning. 14. Confirm each warning tells the person not to make another change yet. @@ -3386,11 +3387,11 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001I [#635] uncertain-chan 53. Record whether connected behavior became available as its own state. 54. Stop before changing availability, Firebase, a provider, an account, production data, or the live website. -**Expected result:** the reviewed connected source preserves the fixed uncertain-change warning through failed and repeated **Reload settings** reads until one authoritative profile read succeeds. Mutation controls and discarded draft bytes stay absent while the outcome is uncertain. A successful read displays the returned current profile state. Initial profile-load failure and failed confirming read after definitive rejection remain generic unavailable without a global no-change promise. Reload creates no request ID, sends no visibility, upload, or removal mutation, and starts no mutation retry. Application and account lifetime fences keep older reloads inert. Availability remains `false`; the default branch obtains no directory context, creates no request ID, and calls no directory service; and live #623 remains inert. The backend and connected behavior remain **NOT AVAILABLE YET**. +**Expected result:** the reviewed connected source preserves the fixed uncertain-change warning through failed and repeated **Reload settings** reads until one authoritative profile read succeeds. Mutation controls and discarded draft bytes stay absent while the outcome is uncertain. A successful read displays the returned current profile state. Initial profile-load failure and failed confirming read after definitive rejection remain generic unavailable without a global no-change promise. Reload creates no request ID, sends no visibility, upload, or removal mutation, and starts no mutation retry. Application and account lifetime fences keep older reloads inert. Availability remains `false`; the default branch obtains no directory context, creates no request ID, and calls no directory service; and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 surface. The backend and connected behavior remain **NOT AVAILABLE YET**. **Stop conditions:** a real account, name, or photo; production sign-in; direct production Firebase access; a failed Reload that replaces uncertain-change truth with generic unavailable or **No setting was changed**; an initial or definitive-rejection load failure mislabeled as known mutation uncertainty; a discarded draft or data URL restored; a mutation control shown while uncertainty remains; a request number or visibility, upload, or removal mutation caused by Reload; an automatic mutation retry; an older reload changing a new application or account state; a data-flow or page-structure change; a Function, Rule, index, schema, service-contract, provider, account, sign-in, production-data, or website change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, or merge means the feature is live. -**Success proof:** record the exact #635 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001I focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/state, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value and unchanged #623 deploy separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. +**Success proof:** record the exact #635 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001I focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/state, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. **Undo:** use one reviewed frontend revert or safe roll-forward. Confirm the default disabled branch still makes zero directory calls. No Firebase, provider, account, or production-data undo is needed because #635 changes source only. Undo must not introduce a false no-change assurance or restore discarded draft bytes. @@ -3415,7 +3416,7 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001J [#637] profile-recove 9. Confirm the evidence uses only a made-up account. 10. Confirm the evidence uses only generated non-face image bytes. 11. Confirm the source-controlled availability value remains byte-for-byte `false`. -12. Confirm the last verified production deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +12. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 13. Confirm an ordinary unknown visibility outcome focuses **Reload settings**. 14. Confirm an ordinary unknown upload outcome focuses **Reload settings**. 15. Confirm an ordinary unknown removal outcome focuses **Reload settings**. @@ -3473,11 +3474,11 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001J [#637] profile-recove 67. Record whether connected behavior became available as its own state. 68. Stop before changing availability, Firebase, a provider, an account, production data, or the live website. -**Expected result:** the reviewed connected source focuses **Reload settings** after an ordinary unknown visibility, upload, or removal outcome; failed authoritative post-mutation readback; or failed confirming read after definitive rejection. A Reload-created focus intent belongs to the same mounted application-and-account lifetime and is bound to that exact load. Each guarded failed Reload focuses its replacement recovery action. Initial load failure does not steal focus. Successful authoritative reload clears the intent without redirecting focus to an unrelated ready control. Application change, account change, unmount, and stale completion remain focus-inert. The focus handoff creates no request ID, extra service call, mutation, automatic retry, restored draft, or data URL. Existing uncertainty and generic failure truth remain unchanged. Availability remains `false`; the default branch obtains no directory context, creates no request ID, and calls no directory service; and live #623 remains inert. The backend and connected behavior remain **NOT AVAILABLE YET**. +**Expected result:** the reviewed connected source focuses **Reload settings** after an ordinary unknown visibility, upload, or removal outcome; failed authoritative post-mutation readback; or failed confirming read after definitive rejection. A Reload-created focus intent belongs to the same mounted application-and-account lifetime and is bound to that exact load. Each guarded failed Reload focuses its replacement recovery action. Initial load failure does not steal focus. Successful authoritative reload clears the intent without redirecting focus to an unrelated ready control. Application change, account change, unmount, and stale completion remain focus-inert. The focus handoff creates no request ID, extra service call, mutation, automatic retry, restored draft, or data URL. Existing uncertainty and generic failure truth remain unchanged. Availability remains `false`; the default branch obtains no directory context, creates no request ID, and calls no directory service; and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 surface. The backend and connected behavior remain **NOT AVAILABLE YET**. **Stop conditions:** a real account, name, or photo; production sign-in; direct production Firebase access; a user-initiated mutation or readback failure whose rendered **Reload settings** action is not focused; a failed Reload whose replacement **Reload settings** action is not focused; an initial load failure that steals unrelated focus; a successful Reload that redirects focus to an unrelated ready control; an older load, application, account, or unmounted completion that moves focus; a request number or visibility, upload, or removal mutation caused by Reload; an automatic mutation retry; a restored draft or data URL; changed uncertainty or generic failure wording; a data-flow or page-structure change; a Function, Rule, index, schema, service-contract, provider, account, sign-in, production-data, or website change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, or merge means the feature is live. -**Success proof:** record the exact #637 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001J focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value and unchanged #623 deploy separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. +**Success proof:** record the exact #637 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001J focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. **Undo:** use one reviewed frontend revert or safe roll-forward. Confirm the default disabled branch still makes zero directory calls. No Firebase, provider, account, or production-data undo is needed because #637 changes source only. Undo must not strand focus after a user-initiated recovery transition or permit a stale completion to move focus. @@ -3502,7 +3503,7 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001K [#639] saved-photo re 9. Confirm the evidence uses only a made-up account. 10. Confirm the evidence uses only generated non-face image bytes. 11. Confirm the source-controlled availability value remains byte-for-byte `false`. -12. Confirm the last verified production deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +12. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 13. Confirm the named bridge imports the actual Account profile component. 14. Confirm the named bridge imports the actual member-directory service. 15. Confirm the named bridge mocks only Firebase Functions transport. @@ -3573,11 +3574,11 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001K [#639] saved-photo re 80. Record whether connected behavior became available as its own state. 81. Stop before changing availability, Firebase, a provider, an account, production data, or the live website. -**Expected result:** the reviewed connected source admits an inbound returned saved photo only when its existing exact object, WebP MIME, dimensions, and version contract contains canonical decoded bytes from 12 through 65,536 with `RIFF` at bytes 0–3 and `WEBP` at bytes 8–11. Other returned bytes become only **Invalid member directory response.** and the generic unavailable Account state without a saved-thumbnail image, data URL, raw bytes, provider value, caught detail, or log. Structural admission is not full decoding. If the browser cannot display admitted bytes, the image and data URL leave the page, the version-scoped byte-free **Photo unavailable** fallback appears, and **Remove current saved photo** remains enabled without another callable. Outbound JPG, PNG, and WebP admission and exact upload bytes remain unchanged. Availability remains `false`; the default branch obtains no directory-service context, creates no request number, and calls no directory service; and live #623 remains inert. The backend and connected behavior remain **NOT AVAILABLE YET**. +**Expected result:** the reviewed connected source admits an inbound returned saved photo only when its existing exact object, WebP MIME, dimensions, and version contract contains canonical decoded bytes from 12 through 65,536 with `RIFF` at bytes 0–3 and `WEBP` at bytes 8–11. Other returned bytes become only **Invalid member directory response.** and the generic unavailable Account state without a saved-thumbnail image, data URL, raw bytes, provider value, caught detail, or log. Structural admission is not full decoding. If the browser cannot display admitted bytes, the image and data URL leave the page, the version-scoped byte-free **Photo unavailable** fallback appears, and **Remove current saved photo** remains enabled without another callable. Outbound JPG, PNG, and WebP admission and exact upload bytes remain unchanged. Availability remains `false`; the default branch obtains no directory-service context, creates no request number, and calls no directory service; and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 surface. The backend and connected behavior remain **NOT AVAILABLE YET**. **Stop conditions:** a real account, name, or photo; production sign-in; direct production Firebase access; malformed returned bytes that create a saved-thumbnail image or data URL; a rejection that renders or logs raw bytes, a provider value, or caught detail; admitted bytes outside 12 through 65,536; missing `RIFF` or `WEBP` checks; a browser decode failure that leaves the data URL rendered, omits **Photo unavailable**, or removes the Remove action; an extra callable caused by image failure; changed outbound JPG, PNG, or WebP admission or bytes; a photo query; face recognition, matching, embedding, similarity scoring, or biometric processing; a Function, Rule, index, schema, package, workflow, release-control, provider, account, sign-in, production-data, or website change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, or merge means the feature is live. -**Success proof:** record the exact #639 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001K focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend, response-contract, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value and unchanged #623 deploy separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. +**Success proof:** record the exact #639 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001K focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend, response-contract, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. **Undo:** use one reviewed service-and-documentation revert or safe roll-forward. Confirm the default disabled branch still makes zero directory calls. No Firebase, provider, account, or production-data undo is needed because #639 changes source only. Undo must not turn clearly mislabeled returned bytes into a saved-thumbnail image or change outbound upload bytes. @@ -3603,7 +3604,7 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001L [#641] People-finder 10. Confirm the evidence uses only made-up names. 11. Confirm any image evidence uses generated non-face data. 12. Confirm the source-controlled availability value remains byte-for-byte `false`. -13. Confirm the last verified production deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +13. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 14. Confirm a valid query must pass before a focus intent can exist. 15. Confirm request-number creation must succeed before a focus intent can exist. 16. Confirm the current search must enter its pending state before a focus intent can exist. @@ -3679,11 +3680,11 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001L [#641] People-finder 86. Record whether connected or live People-finder behavior became available as its own state. 87. Stop before changing availability, Firebase, a provider, an account, production data, or the live website. -**Expected result:** the reviewed connected source records only an exact-operation name-input or Search-button focus intent after a valid query and request number admit one pending search. Current result cards, empty results, and fixed failure consume that intent after render. The already-focused origin remains focused. Focus evicted to the document body, root, no active element, or a disconnected element returns to the same now-enabled origin. Another connected control deliberately focused during pending keeps focus. Programmatic or outside-focused submit, local validation failure, and request-number failure create no intent. Editing, Clear, application or administrator change, unmount, and obsolete resolution or rejection prevent stale focus movement. Clear keeps its existing local disposal, input focus, and zero-call behavior. Focus creates no request number, extra search, retry, Clear action, result, audit, service call, or data URL. Availability remains `false`; the default branch obtains no directory context, creates no request number, and calls no directory service; and live #623 remains inert. The backend and connected behavior remain **NOT AVAILABLE YET**. +**Expected result:** the reviewed connected source records only an exact-operation name-input or Search-button focus intent after a valid query and request number admit one pending search. Current result cards, empty results, and fixed failure consume that intent after render. The already-focused origin remains focused. Focus evicted to the document body, root, no active element, or a disconnected element returns to the same now-enabled origin. Another connected control deliberately focused during pending keeps focus. Programmatic or outside-focused submit, local validation failure, and request-number failure create no intent. Editing, Clear, application or administrator change, unmount, and obsolete resolution or rejection prevent stale focus movement. Clear keeps its existing local disposal, input focus, and zero-call behavior. Focus creates no request number, extra search, retry, Clear action, result, audit, service call, or data URL. Availability remains `false`; the default branch obtains no directory context, creates no request number, and calls no directory service; and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 surface. The backend and connected behavior remain **NOT AVAILABLE YET**. **Stop conditions:** a real account, name, or photo; production sign-in; direct production Firebase access; a current input- or Search-origin search that leaves focus on the document body after cards, empty, or fixed failure; settlement that moves focus away from another connected control; programmatic submission that steals outside focus; validation or request-number failure that disables controls or starts a search; an application, administrator, unmounted, or obsolete completion that moves focus; a second request number, search, retry, Clear action, result, audit, service call, or data URL caused by focus; changed normalization, response, result, thumbnail, fixed-error, disposal, or guard behavior; a photo query; face recognition, matching, embedding, similarity scoring, biometric processing, total, export, roster authority, or membership proof; a Function, Rule, index, schema, package, workflow, provider, account, sign-in, production-data, or website change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, or merge means the feature is live. -**Success proof:** record the exact #641 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001L focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value and unchanged #623 deploy separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. +**Success proof:** record the exact #641 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001L focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. **Undo:** use one reviewed frontend-and-documentation revert or safe roll-forward. Confirm the default disabled branch still makes zero directory calls. No Firebase, provider, account, or production-data undo is needed because #641 changes source only. Undo must not strand focus after native pending-control eviction or permit a stale completion to move focus. @@ -3707,7 +3708,7 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001M [#643] rejected-remov 8. Confirm the report names the specialist who ran the tests. 9. Confirm every image fixture is generated non-face data. 10. Confirm the source-controlled availability value remains byte-for-byte `false`. -11. Confirm the last verified production deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +11. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 12. Confirm request-number creation must succeed before a rejected-removal focus intent can exist. 13. Confirm the exact current Remove operation must enter `pending` before the intent can exist. 14. Confirm **Remove current saved photo** must own focus when that operation enters `pending`. @@ -3778,11 +3779,11 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001M [#643] rejected-remov 79. Record whether connected or live profile-photo behavior became available as its own state. 80. Stop before changing availability, Firebase, a provider, an account, production data, or the live website. -**Expected result:** the reviewed connected source creates a pending rejected-removal focus intent only after request-number creation and admitted pending removal while **Remove current saved photo** owns focus. That intent contains only the current mounted application-and-account lifetime and exact operation identity. Definitive rejection plus a current successful authoritative readback transfers the matching intent to result ownership, and the ready render consumes it. A current saved photo selects surviving Remove; otherwise an exact current ready draft selects enabled Save; otherwise the persistent Add/Replace input is selected for no, reading, or not-yet-ready draft. Focus returns from the document body, document root, no active element, or a disconnected element, but an already-focused target is left alone and any other connected focus deliberately chosen during pending is preserved. Surviving Remove alone describes the fixed rejection. If Remove disappears, the rejection remains a standalone alert and is not associated with Save or the file input; destination focus does not claim success or deletion proof. Programmatic or outside-focused invocation, request-number failure, failed mutation admission, confirmed success, unknown outcome, failed confirming read, application or account change, unmount, and obsolete completion create no intent or clear or fail its guards. Existing confirmed-removal and #637 Reload focus behavior remains unchanged. Focus creates no request number, callable, retry, mutation, draft, data URL, confirmation, audit, provider action, or data action. Availability remains `false`; the default branch obtains no directory context, creates no request number, and calls no directory service; and live #623 remains inert. The backend and connected behavior remain **NOT AVAILABLE YET**. +**Expected result:** the reviewed connected source creates a pending rejected-removal focus intent only after request-number creation and admitted pending removal while **Remove current saved photo** owns focus. That intent contains only the current mounted application-and-account lifetime and exact operation identity. Definitive rejection plus a current successful authoritative readback transfers the matching intent to result ownership, and the ready render consumes it. A current saved photo selects surviving Remove; otherwise an exact current ready draft selects enabled Save; otherwise the persistent Add/Replace input is selected for no, reading, or not-yet-ready draft. Focus returns from the document body, document root, no active element, or a disconnected element, but an already-focused target is left alone and any other connected focus deliberately chosen during pending is preserved. Surviving Remove alone describes the fixed rejection. If Remove disappears, the rejection remains a standalone alert and is not associated with Save or the file input; destination focus does not claim success or deletion proof. Programmatic or outside-focused invocation, request-number failure, failed mutation admission, confirmed success, unknown outcome, failed confirming read, application or account change, unmount, and obsolete completion create no intent or clear or fail its guards. Existing confirmed-removal and #637 Reload focus behavior remains unchanged. Focus creates no request number, callable, retry, mutation, draft, data URL, confirmation, audit, provider action, or data action. Availability remains `false`; the default branch obtains no directory context, creates no request number, and calls no directory service; and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 surface. The backend and connected behavior remain **NOT AVAILABLE YET**. **Stop conditions:** a real account, name, or photo; production sign-in; direct production Firebase access; a focused current Remove action that disappears after definitive rejection and current successful readback while focus remains on the document body; a ready current replacement that does not select Save; a no, reading, or not-yet-ready draft that does not select the persistent file input; a settlement that steals another connected focus; an outside-focused invocation or request-number failure that creates an intent; a standalone rejection attached to Save or the file input; focus represented as removal success or deletion proof; a failed confirming read or unknown outcome that bypasses Reload recovery; an application, account, unmounted, or obsolete completion that moves focus; a second request number, callable, retry, mutation, draft, data URL, confirmation, audit, provider action, or data action caused by focus; changed draft, confirmed-removal, or #637 recovery behavior; a photo query; face recognition, matching, embedding, similarity scoring, biometric processing, roster authority, or membership proof; a Function, Rule, index, schema, package, workflow, provider, account, sign-in, production-data, or website change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, or merge means the feature is live. -**Success proof:** record the exact #643 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001M focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value and unchanged #623 deploy separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. +**Success proof:** record the exact #643 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001M focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. **Undo:** use one reviewed frontend-and-documentation revert or safe roll-forward. Confirm the default disabled branch still makes zero directory calls. No Firebase, provider, account, or production-data undo is needed because #643 changes source only. Undo must not leave otherwise-lost focus on the document body after the current rejected-removal readback or misassociate the standalone rejection with a replacement action. @@ -3806,7 +3807,7 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001N [#645] confirmed-phot 8. Confirm the report names the specialist who ran the tests. 9. Confirm every image fixture is generated non-face data. 10. Confirm the source-controlled availability value remains byte-for-byte `false`. -11. Confirm the last verified production deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +11. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 12. Confirm request-number creation must succeed before a confirmed-photo focus intent can exist. 13. Confirm the exact upload or removal operation must enter `pending` before the intent can exist. 14. Confirm **Save profile photo** must own focus when an upload operation enters `pending`. @@ -3883,11 +3884,11 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001N [#645] confirmed-phot 85. Record whether connected or live profile-photo behavior became available as its own state. 86. Stop before changing availability, Firebase, a provider, an account, production data, or the live website. -**Expected result:** the reviewed connected source records one pending confirmed-photo focus intent only after request-number creation and admitted pending upload or removal while the exact Save or Remove initiating action owns focus. The intent contains only the current mounted application-and-account lifetime, exact operation identity, and upload-or-remove action. Successful mutation plus a current successful authoritative profile read transfers only the matching intent to one ready render. Confirmed upload selects the persistent file input. Confirmed removal selects surviving Remove first, exact current ready Save second, or the persistent file input otherwise. Focus returns from the document body, document root, no active element, or a disconnected element, but an already-focused destination is left alone and any other connected focus deliberately chosen during mutation or readback is preserved. The result is consumed once. Programmatic or outside-focused invocation, request-number failure, failed mutation admission, definitive rejection, unknown outcome, failed readback, application or account change, unmount, and obsolete completion create no intent or clear or fail its guards. #643 rejected-removal behavior and #637 Reload recovery remain separate. Focus creates no request number, callable, retry, mutation, draft, data URL, confirmation, audit, provider action, or data action. Availability remains `false`; the default branch obtains no directory context, creates no request number, and calls no directory service; and live #623 remains inert. The backend and connected behavior remain **NOT AVAILABLE YET**. +**Expected result:** the reviewed connected source records one pending confirmed-photo focus intent only after request-number creation and admitted pending upload or removal while the exact Save or Remove initiating action owns focus. The intent contains only the current mounted application-and-account lifetime, exact operation identity, and upload-or-remove action. Successful mutation plus a current successful authoritative profile read transfers only the matching intent to one ready render. Confirmed upload selects the persistent file input. Confirmed removal selects surviving Remove first, exact current ready Save second, or the persistent file input otherwise. Focus returns from the document body, document root, no active element, or a disconnected element, but an already-focused destination is left alone and any other connected focus deliberately chosen during mutation or readback is preserved. The result is consumed once. Programmatic or outside-focused invocation, request-number failure, failed mutation admission, definitive rejection, unknown outcome, failed readback, application or account change, unmount, and obsolete completion create no intent or clear or fail its guards. #643 rejected-removal behavior and #637 Reload recovery remain separate. Focus creates no request number, callable, retry, mutation, draft, data URL, confirmation, audit, provider action, or data action. Availability remains `false`; the default branch obtains no directory context, creates no request number, and calls no directory service; and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 surface. The backend and connected behavior remain **NOT AVAILABLE YET**. **Stop conditions:** a real account, name, or photo; production sign-in; direct production Firebase access; a focused current Save or Remove action that is displaced while confirmed work settles but never yields its current destination; settlement that moves focus away from another connected control; an outside-focused or programmatic invocation that creates an intent; an intent that records a profile, revision, request number, photo byte, data URL, provider value, response, or error; a transfer before successful current authoritative readback; changed upload or removal destination order; delayed focus during an unrelated later render; a definitive rejection that uses confirmed-success focus; an unknown outcome or failed readback that bypasses Reload recovery; an application, account, unmounted, or obsolete completion that moves focus; an extra request number, callable, retry, mutation, draft, data URL, confirmation, audit, provider action, or data action caused by focus; changed calls, bytes, revisions, confirmation copy, draft behavior, #643 behavior, or #637 behavior; a photo query; facial recognition, matching, embedding, similarity scoring, biometric processing, roster authority, or membership proof; a People-finder, visibility, service-contract, Function, Rule, index, schema, package, workflow, provider, account, sign-in, production-data, or website change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, merge, or a preview means the feature is live. -**Success proof:** record the exact #645 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001N focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; repository Node tests; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value and unchanged #623 deploy separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove `runmprc.com`, Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. +**Success proof:** record the exact #645 issue, reviewed pull request and commit; trustworthy old-source failure; green separately named MEMBERS-DIRECTORY-001N focused tests; green full frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; repository Node tests; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove `runmprc.com`, Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. **Undo:** use one reviewed frontend-and-documentation revert or safe roll-forward. Confirm the default disabled branch still makes zero directory calls. No Firebase, provider, account, or production-data undo is needed because #645 changes source only. Undo must not restore unconditional confirmed-photo focus or weaken #643 rejected-removal focus and #637 Reload recovery. @@ -3912,7 +3913,7 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001O [#647] visibility foc 9. Confirm every account and name in the evidence is made up. 10. Confirm no real photo appears in the evidence. 11. Confirm the source-controlled availability value remains byte-for-byte `false`. -12. Confirm the last verified production deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +12. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 13. Confirm request-number creation must succeed before a visibility focus intent can exist. 14. Confirm the visibility operation must enter `pending` before the intent can exist. 15. Confirm the exact officer-finder checkbox must own focus when the operation enters `pending`. @@ -3998,11 +3999,11 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001O [#647] visibility foc 95. Record whether connected or live profile-photo or officer-finder behavior became available as its own state. 96. Stop before changing availability, Firebase, a provider, an account, production data, or the live website. -**Expected result:** the reviewed connected source creates one pending visibility focus intent only after request-number creation and admitted pending visibility while the exact officer-finder checkbox owns focus. The intent contains only the current mounted application-and-account lifetime and exact operation identity. Confirmed success plus a current successful authoritative read, or definitive rejection plus a current successful confirming read, transfers only the matching intent to one ready render. That render consumes the result once. Body, document-root, absent, or disconnected focus returns only to the same connected and enabled checkbox. A checkbox that retained focus is left alone. Any other connected focus deliberately chosen during mutation or readback is preserved. A returned off checkbox disabled by current name eligibility consumes the result without focus. Programmatic or outside-focused invocation, request-number failure, failed mutation admission, unknown outcome, failed readback, application or account change, unmount, and obsolete mutation or readback completion create no result or clear or fail its guards. #637 Reload recovery, #643 rejected-removal focus, and #645 confirmed-photo focus remain separate. Focus creates no request number, read, mutation, retry, audit, result, draft, photo byte, data URL, provider action, or data action beyond the already admitted operation. Availability remains `false`; the default branch obtains no directory context, creates no request number, and calls no directory service; and live #623 remains inert. The backend and connected behavior remain **NOT AVAILABLE YET**. +**Expected result:** the reviewed connected source creates one pending visibility focus intent only after request-number creation and admitted pending visibility while the exact officer-finder checkbox owns focus. The intent contains only the current mounted application-and-account lifetime and exact operation identity. Confirmed success plus a current successful authoritative read, or definitive rejection plus a current successful confirming read, transfers only the matching intent to one ready render. That render consumes the result once. Body, document-root, absent, or disconnected focus returns only to the same connected and enabled checkbox. A checkbox that retained focus is left alone. Any other connected focus deliberately chosen during mutation or readback is preserved. A returned off checkbox disabled by current name eligibility consumes the result without focus. Programmatic or outside-focused invocation, request-number failure, failed mutation admission, unknown outcome, failed readback, application or account change, unmount, and obsolete mutation or readback completion create no result or clear or fail its guards. #637 Reload recovery, #643 rejected-removal focus, and #645 confirmed-photo focus remain separate. Focus creates no request number, read, mutation, retry, audit, result, draft, photo byte, data URL, provider action, or data action beyond the already admitted operation. Availability remains `false`; the default branch obtains no directory context, creates no request number, and calls no directory service; and live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 surface. The backend and connected behavior remain **NOT AVAILABLE YET**. **Stop conditions:** a real account, name, or photo; production sign-in; direct production Firebase access; a focused current checkbox that loses focus during confirmed success or definitive rejection plus current successful readback and never regains it while enabled; focus placed on a returned disabled checkbox; settlement that moves focus away from another connected control; an outside-focused or programmatic invocation that creates an intent; an intent that records a query, name, profile, revision, request number, result, error, provider value, photo byte, or data URL; a transfer before successful current authoritative readback; delayed focus during a later unrelated render; an unknown outcome or failed readback that bypasses Reload recovery; an application, account, unmounted, or obsolete completion that moves focus; an extra request number, read, mutation, retry, audit, result, draft, photo byte, data URL, provider action, or data action caused by focus; changed errors, confirmations, revisions, native pending disablement, #637, #643, or #645 behavior; a photo query; facial recognition, matching, embedding, similarity scoring, biometric processing, total, export, roster authority, or membership proof; a People-finder, service-contract, Function, Rule, index, schema, package, workflow, provider, account, sign-in, production-data, or website change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, merge, or a preview means the feature is live. -**Success proof:** record the exact #647 issue, reviewed pull request and commit; trustworthy unchanged-runtime named failure; green 21-test MEMBERS-DIRECTORY-001O block; green full component and frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; repository Node tests; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value and unchanged #623 deploy separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove `runmprc.com`, Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. +**Success proof:** record the exact #647 issue, reviewed pull request and commit; trustworthy unchanged-runtime named failure; green 21-test MEMBERS-DIRECTORY-001O block; green full component and frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; repository Node tests; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove `runmprc.com`, Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. **Undo:** use one reviewed frontend-and-documentation revert or safe roll-forward. Confirm the default disabled branch still makes zero directory calls. No Firebase, provider, account, or production-data undo is needed because #647 changes source only. Undo must not restore lost visibility-checkbox focus after authoritative settlement or weaken #637, #643, or #645 focus containment. @@ -4028,7 +4029,7 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001P [#649] successful Rel 10. Confirm every account and name in the evidence is made up. 11. Confirm no real photo appears in the evidence. 12. Confirm the source-controlled availability value remains byte-for-byte `false`. -13. Confirm the last verified production deployment remains inert #623 deploy `6a7e072f8f346b0008510d29`. +13. Confirm live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 directory surface and literal `false` availability. 14. Confirm the successful result says exactly **Profile photo and officer finder settings reloaded.**. 15. Confirm every valid explicit current Reload with a successful guarded authoritative read shows that result. 16. Confirm the result is the first child of the recovered ready-controls region. @@ -4109,11 +4110,11 @@ Officer source-review procedure for MEMBERS-DIRECTORY-001P [#649] successful Rel 91. Record whether connected or live profile-photo or officer-finder behavior became available as its own state. 92. Stop before changing availability, Firebase, a provider, an account, production data, or the live website. -**Expected result:** every valid explicit current Reload followed by a guarded successful authoritative profile read renders exactly **Profile photo and officer finder settings reloaded.** as the first child of the recovered ready controls, with status, polite live, atomic, programmatic-focus, and visible-outline semantics. The result proves only that the read completed. An exact focused Reload records only the current lifetime and load identity, and only its matching current success may transfer that intent. One ready effect consumes the intent before target checks. Body, document-root, absent, or disconnected focus returns to the connected result; retained result focus is left alone; and any other connected focus deliberately chosen during the read is preserved. A programmatic or unfocused valid Reload shows the result without moving focus. Initial/background success shows no result. Failure shows no success result and retains #637 replacement-Reload focus. Application change, account change, unmount, a new load, obsolete completion, and later rerender cannot reuse the handoff. The result creates no request number, extra read, mutation, retry, audit, draft, photo byte, data URL, provider action, or data action. Availability remains `false`; the default branch obtains no directory-service context, creates no request number, and calls no directory service; live #623 remains inert; and the backend and connected behavior remain **NOT AVAILABLE YET**. +**Expected result:** every valid explicit current Reload followed by a guarded successful authoritative profile read renders exactly **Profile photo and officer finder settings reloaded.** as the first child of the recovered ready controls, with status, polite live, atomic, programmatic-focus, and visible-outline semantics. The result proves only that the read completed. An exact focused Reload records only the current lifetime and load identity, and only its matching current success may transfer that intent. One ready effect consumes the intent before target checks. Body, document-root, absent, or disconnected focus returns to the connected result; retained result focus is left alone; and any other connected focus deliberately chosen during the read is preserved. A programmatic or unfocused valid Reload shows the result without moving focus. Initial/background success shows no result. Failure shows no success result and retains #637 replacement-Reload focus. Application change, account change, unmount, a new load, obsolete completion, and later rerender cannot reuse the handoff. The result creates no request number, extra read, mutation, retry, audit, draft, photo byte, data URL, provider action, or data action. Availability remains `false`; the default branch obtains no directory-service context, creates no request number, and calls no directory service; live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623 surface; and the backend and connected behavior remain **NOT AVAILABLE YET**. **Stop conditions:** a real account, name, or photo; production sign-in; direct production Firebase access; missing or changed successful-Reload copy; a result outside the first recovered ready-controls position; missing status, live, atomic, programmatic-focus, or visible-outline semantics; a result that claims an earlier change succeeded or failed; a result shown for initial/background success or failed Reload; a focused exact current Reload whose successful result receives no otherwise-lost focus; an outside-focused or programmatic invocation that creates an intent; a connected outside or in-profile control that loses deliberately selected focus; an intent that records a UID, query, name, profile, revision, request number, result, error, provider value, photo byte, or data URL; transfer before matching current authoritative success; delayed focus during a later render; an application, account, unmounted, new-load, or obsolete completion that moves focus or renders an old result; an extra request number, read, mutation, retry, audit, draft, photo byte, data URL, provider action, or data action; changed #637, #643, #645, or #647 behavior; a photo query; facial recognition, matching, embedding, similarity scoring, biometric processing, total, export, roster authority, or membership proof; a People-finder, service-contract, Function, Rule, index, schema, package, workflow, permission, ownership, provider, account, sign-in, production-data, or website change; an availability flip; use of a terminal or test harness by the backup officer; or a claim that source, tests, merge, or a preview means the feature is live. -**Success proof:** record the exact #649 issue, reviewed pull request and commit; trustworthy old-source named result with 8 failures and 5 passes; green 15-of-15 MEMBERS-DIRECTORY-001P block; green full component and frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; repository Node tests; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value and unchanged #623 deploy separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove `runmprc.com`, Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. +**Success proof:** record the exact #649 issue, reviewed pull request and commit; trustworthy old-source named result with 8 failures and 5 passes; green 15-of-15 MEMBERS-DIRECTORY-001P block; green full component and frontend tests; type-checking; scoped lint; diagnostic production build; unchanged lint baseline; repository Node tests; workflow checks; diff-check; independent privacy/security, frontend/accessibility, focus/race, and backup-officer reviews; and exact-main CI if merged. Record source, tests, merge, website publication, exact `runmprc.com` revision, Firebase deployment, provider configuration, account/sign-in change, production-data action, and connected/live behavior separately. Record the unchanged `false` availability value, current #659 deploy `6a7ece87c5ca4d0007c1a3fc`, and preserved #623 rollback deploy `6a7e072f8f346b0008510d29` separately. Source and tests do not prove merge; merge does not prove publication; publication does not prove `runmprc.com`, Firebase, provider, account, data, or connected-live behavior. Final connection and live proof remain #507 work. **Undo:** use one reviewed frontend-and-documentation revert or safe roll-forward. Confirm the default disabled branch still makes zero directory calls. No Firebase, provider, account, or production-data undo is needed because #649 changes source only. Undo must not restore the successful-Reload body-focus defect or weaken #637, #643, #645, or #647 focus containment. diff --git a/docs/officers/PUBLISH_AND_CHECK.md b/docs/officers/PUBLISH_AND_CHECK.md index eea3c27..dd08780 100644 --- a/docs/officers/PUBLISH_AND_CHECK.md +++ b/docs/officers/PUBLISH_AND_CHECK.md @@ -10,9 +10,9 @@ **Protected release status:** **NOT AVAILABLE YET.** Issue #135 provides the fail-closed source gate. Issue #133 must still configure protected `staging` and `production` environments, their named reviewers, and a short-lived cloud identity. Public browser build values must be named repository or organization variables because artifact preparation has no protected-environment access; #133/#136 must record and verify them separately. Do not add a long-lived Firebase key as a shortcut. -**Live Netlify publication status:** a reusable protected release is **NOT AVAILABLE YET**. Ordinary Git-triggered production builds are paused by repository configuration. An overbroad #473 artifact was published and then rolled back on 2026-08-01; bounded #473 deploy `6a6dc9ea588b0c0008036312`, source `39ab8649df411262c8109a3c81a57bc38f1e168b`, remains the recorded rollback. #623 completed one separate exact-artifact release. Deploy `6a7e072f8f346b0008510d29`, source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, is production now. Its signed-out marker, guard, route, and no-directory-request checks passed. The manifest is inactive, the release source is absent, and the rollback ref remains. Shop is the static catalog; Events and Calendar show a fixed retry-later notice instead of a raw provider error. Event records remain unavailable because this did not deploy Firebase. GitHub Pages currently still claims the same custom domain; future source omits that claim, but #136/WEB-001 must publish and verify its removal. +**Live Netlify publication status:** a reusable protected release is **NOT AVAILABLE YET**. Ordinary Git-triggered production builds are paused by repository configuration. An overbroad #473 artifact was published and then rolled back on 2026-08-01; bounded #473 deploy `6a6dc9ea588b0c0008036312` is older history. #623 completed the inert-directory predecessor and remains the immediate rollback as deploy `6a7e072f8f346b0008510d29`, source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. #659 completed one separate exact-artifact accessibility release. Deploy `6a7ece87c5ca4d0007c1a3fc`, source `7496fe0881fb52908c4ff2f40f488df09c94c908`, is production now. Its exact marker/artifact and signed-out route-focus/menu checks passed. The manifest is inactive, temporary refs are absent, and the rollback ref remains. Shop is the static catalog; Events and Calendar show a fixed retry-later notice; the directory remains inert. Event records remain unavailable because this did not deploy Firebase. GitHub Pages currently still claims the same custom domain; future source omits that claim, but #136/WEB-001 must publish and verify its removal. -**Pending #659 exception:** WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is one active exact-artifact accessibility release under review and is not published. The frozen source contains only reviewed #291 visible focus, #490 phone-menu disclosure/close behavior, and #657 client-side route focus. Production remains #623 deploy `6a7e072f8f346b0008510d29`, which is also #659's rollback target. This is not an officer-operated or reusable control. The no-terminal procedure below permits only signed-out public checks after exact source, preview, merge, and marker proof. +**Completed #659 exception:** WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed one exact-artifact accessibility release on 2026-08-14. The frozen source contains only reviewed #291 visible focus, #490 phone-menu disclosure/close behavior, and #657 client-side route focus. Production is deploy `6a7ece87c5ca4d0007c1a3fc`; #623 deploy `6a7e072f8f346b0008510d29` is its rollback target. This is not an officer-operated or reusable control. The no-terminal section below is retained as the audit record. ## The release gate @@ -59,7 +59,7 @@ As of **2026-07-13**, with the internal tooling note below checked from source o - `runmprc.com` is served by Netlify, not GitHub Pages. - GitHub Pages currently reports `runmprc.com` as its custom domain and redirects its normal address there. It is not an independently reachable copy today. - Future source stops writing that Pages domain claim. Only provider readback after #136/WEB-001 can prove it cleared. -- Ordinary Git-triggered Netlify production builds are paused. The completed #473 exception used one exact two-parent merge and pinned source/tree/artifact; its release source is retired. #623 completed a second exact-parent one-shot, published only its frozen inert artifact, passed signed-out readback, and was immediately re-paused. Its release source is retired; its rollback ref remains. #659 is a separate exact accessibility artifact under review and is not published; #623 deploy `6a7e072f8f346b0008510d29` remains live and is #659's rollback target. +- Ordinary Git-triggered Netlify production builds are paused. The completed #473 exception used one exact two-parent merge and pinned source/tree/artifact; its release source is retired. #623 completed a second exact-parent one-shot and is #659's rollback predecessor. #659 completed a third exact-parent one-shot, published only its frozen accessibility artifact as deploy `6a7ece87c5ca4d0007c1a3fc`, passed signed-out readback, and was immediately re-paused. Its temporary refs are retired; rollback ref `codex/netlify-source-659-rollback` remains. - Live race signup, merchandise payments, and refunds remain unavailable. - CONFIG-001B1 [#151](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/151) adds source enforcement for a server-only commerce pause. It is not in the fixed profile-recovery release plan, is not deployed, and has no approved officer control. A future reviewed plan must deploy the complete guarded Function set with the deploy ceiling and every runtime/resource flag off, then prove signed webhooks still work. Do not widen the current plan by hand. @@ -165,30 +165,28 @@ If a member or officer sees **Server configuration is unavailable**: 6. Do not expect GitHub Pages, Firebase, Netlify, or `runmprc.com` to change from a merge unless a separate exact temporary release is explicitly armed and reviewed. 7. For any other merge, if Netlify unexpectedly publishes, stop and treat it as a hosting incident. -## Temporary #659 keyboard-navigation and route-focus release — UNDER REVIEW, NOT PUBLISHED +## Temporary #659 keyboard-navigation and route-focus release — COMPLETED 2026-08-14 -**Purpose:** publish one frozen accessibility-only website artifact. Keyboard users receive the reviewed visible-focus treatment, truthful phone-menu disclosure and closing, and a one-time focus move into new main content after client-side path navigation. This does not change public content, routes, sign-in, Firebase, providers, accounts, production data, payments, or connected directory behavior. +**Purpose:** record the completed publication of one frozen accessibility-only website artifact. It contains the reviewed visible-focus treatment, truthful phone-menu disclosure and closing, and a one-time focus move into new main content after client-side path navigation. It changed no public content, route set, sign-in, Firebase, provider configuration, account, production data, payment, or connected directory behavior. **Approver:** Dave Liu as platform owner, plus the accessibility reviewer. This is not an officer-operated or reusable release control. -**Prerequisites:** approved issue [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) with no newer blocker; release ID `WEB-002D-KEYBOARD-FOCUS-2026-08-14`; green exact-head checks; successful pinned Deploy Preview; source commit `7496fe0881fb52908c4ff2f40f488df09c94c908`; source tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`; 62-file digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`; exact six-path live-to-source diff digest `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`; exact first parent `95880748e15c03b0ee58da6e1ed11ac6c9526529`; current production and rollback deploy `6a7e072f8f346b0008510d29`; current live source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`; current live tree `411aa6ec9a9459f5d923030533ffc7c007fe6908`; current live 62-file digest `d837272a1e5efc1575809e87f532276b38d1a63f1dd79ec1aef0533f6da8afb1`; release source `codex/netlify-source-659-keyboard-focus`; rollback source `codex/netlify-source-659-rollback`; an executable six-path diff; reviewed #291, #490, and #657 equivalence evidence; synthetic desktop and phone proof; a prepared manifest-disable change; a named signed-out public observer; and no other `main` merge until verification and repause finish. +**Completed evidence:** approved issue [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659); release ID `WEB-002D-KEYBOARD-FOCUS-2026-08-14`; pinned preview deploy `6a7ec998bf8fde00086d2bfe`; preview/control head `137d8a8721339a6ca1079283cc34c1bd7cc2706c`; green PR CI run `31781730576`; source commit `7496fe0881fb52908c4ff2f40f488df09c94c908`; source tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`; 62-file digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`; previous source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`; rollback deploy `6a7e072f8f346b0008510d29`; exact six-path diff digest `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`; exact release merge `46e23647d8e0bf9fa3a574ea5c5f993be10a419d`, parents `95880748e15c03b0ee58da6e1ed11ac6c9526529` and `137d8a8721339a6ca1079283cc34c1bd7cc2706c`, tree `3ef47ed0f664e1e9a2c703332ca9071cfda27ad2`; green exact-main CI run `31783141914`; ready production deploy `6a7ece87c5ca4d0007c1a3fc`, published `2026-08-14T08:16:09.268Z`; exact marker and all-path artifact match; signed-out desktop `/shop` route-focus and phone `/events` menu/route-focus proof; repause preview `6a7ecfbc90347c000804901c`; repause head `94c949abed3759c15cdaa98afc6896343e8a6edd`; green repause PR CI run `31783487885`; exact repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7`, parents `46e23647d8e0bf9fa3a574ea5c5f993be10a419d` and `94c949abed3759c15cdaa98afc6896343e8a6edd`, tree `c4667394dc9a2286c3a2eda028728314e925c22f`; green repause exact-main CI run `31783808994`; unpublished Netlify attempt `6a7ed0ddb00a46000818878d`; retained production deploy and marker; inactive manifest; absent temporary source/control/repause refs; and retained `codex/netlify-source-659-rollback` ref. **Specialist dependency:** the platform maintainer supplies the exact GitHub, Netlify, marker, artifact, and rollback records. The officer uses reviewed links and a private browser only. The officer does not run a command, sign in, change a provider, inspect private data, or handle a secret. ```mermaid flowchart TD - Source["Frozen six-path source"] --> Preview["Pinned #659 Deploy Preview"] - Preview --> Match{"Source, tree, count, digest, and marker match?"} - Match -- "No" --> Keep["Stop — keep #623 deploy live"] - Match -- "Yes" --> Merge["Exact-parent two-parent merge"] - Merge --> Public["Signed-out desktop and phone checks"] - Public --> Good{"Focus, menu, marker, and network checks pass?"} - Good -- "No" --> Rollback["Restore #623 deploy"] - Good -- "Yes" --> Repause["Disable temporary authority"] - Repause --> Verify["Confirm no replacement; retire temporary refs"] + Source["Frozen six-path source"] --> Preview["Pinned #659 preview matched"] + Preview --> Merge["Exact-parent release merged"] + Merge --> Public["Exact artifact and signed-out route/menu checks passed"] + Public --> Repause["Temporary authority disabled"] + Repause --> Verify["Unpublished attempt; #659 deploy retained"] ``` -In words: the preview must match the exact six-path frozen artifact. Only the exact-parent merge may publish it. Signed-out desktop and phone checks then verify the marker, visible focus, phone-menu behavior, and absence of a directory request. A mismatch leaves or restores the current #623 deploy. A success is immediately re-paused, and the temporary refs are retired. +In words: the preview matched the exact six-path frozen artifact, the exact-parent merge published it, and signed-out desktop and phone checks verified the marker, route focus, phone-menu disclosure/close behavior, and absence of a directory request. Exact served source/CSS and mutation-sensitive tests preserve the bounded visible-focus cue; the live browser record does not separately prove keyboard `:focus-visible`. The release was immediately re-paused, its attempt stayed unpublished, and the temporary refs were retired. + +Completed checklist, retained as the audit record: 1. Open the #659 release pull request. 2. Confirm its destination is `main`. @@ -236,13 +234,13 @@ In words: the preview must match the exact six-path frozen artifact. Only the ex 44. Confirm the release, control, and repause refs are retired. 45. Confirm the rollback ref remains pinned to the prior live source. -**Expected result:** if every gate passes, Netlify serves exactly the frozen accessibility artifact. A direct load keeps body focus and the skip link remains first. A client-side path change moves otherwise-stale focus into main content once with a visible bounded cue. A phone-menu destination closes the menu with truthful disclosure state and leaves normal next-Tab order. The release deploys no Firebase, Rules, Functions, or indexes; configures no provider; uses no account; changes no production data; and does not connect the directory. Until the production and repause proof exists, #659 remains under review and not published, while #623 deploy `6a7e072f8f346b0008510d29` remains live. +**Expected result:** every gate passed, and Netlify serves exactly the frozen accessibility artifact as deploy `6a7ece87c5ca4d0007c1a3fc`. Direct load behavior remains unchanged. A client-side path change moves otherwise-stale focus into main content once. A phone-menu destination closes the menu with truthful disclosure state. The exact served CSS/source and tests preserve the bounded visible cue and next-Tab contract; the signed-out live record proves route focus/menu state but not a separate keyboard `:focus-visible` observation. The release deployed no Firebase, Rules, Functions, or indexes; configured no provider; used no account; changed no production data; and did not connect the directory. #623 deploy `6a7e072f8f346b0008510d29` is the rollback target. **Stop conditions:** stop if `main` advances; a branch, context, source, tree, six-path scope, count, digest, parent, marker, asset, page, focus, cue, menu, network record, rollback, or repause result differs; a seventh source path appears; accumulated `main` behavior appears; the cue is absent or clipped; focus is stolen, trapped, stale, or out of order; the phone menu remains open or reports the wrong state; a protected control is enabled; a public check asks for sign-in or private data; a directory request appears; Firebase or a provider changes; another production attempt starts; or any blocker remains open. -**Success proof:** keep the issue and pull-request links; exact control, source, tree, parent, and six-path diff identities; artifact count and digest; preview deploy and marker; required checks; signed-out desktop and phone page/focus/menu/network results; release merge; production deploy and marker; repause merge and unpublished attempt; retained-deploy readback; retired temporary refs; retained rollback ref; check date; browser; widths; and two redacted public screenshots. Record source, tests, merge, preview, website publication, `runmprc.com` revision, Firebase, outside providers, accounts/sign-in, production data, and live focus behavior as separate states. +**Success proof:** preview deploy `6a7ec998bf8fde00086d2bfe` matched control head `137d8a8721339a6ca1079283cc34c1bd7cc2706c`, and PR CI run `31781730576` passed. Release merge `46e23647d8e0bf9fa3a574ea5c5f993be10a419d` and exact-main CI run `31783141914` passed. Production deploy `6a7ece87c5ca4d0007c1a3fc` published at `2026-08-14T08:16:09.268Z`; its marker matched source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, previous source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, rollback deploy `6a7e072f8f346b0008510d29`, 62 files, and digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`. Every production artifact path matched. Signed-out 1280-by-900 `/shop` and 390-by-844 `/events` route-focus/menu checks passed without horizontal overflow; no directory request occurred. No screenshot was retained, and the live browser record did not separately prove keyboard `:focus-visible`; exact served assets and mutation-sensitive tests supply the cue evidence. Repause head `94c949abed3759c15cdaa98afc6896343e8a6edd` passed PR CI run `31783487885`; merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7` passed all five exact-main jobs in run `31783808994`. Attempt `6a7ed0ddb00a46000818878d` stopped unpublished, and provider plus marker readback retained deploy `6a7ece87c5ca4d0007c1a3fc`. The manifest is inactive; temporary refs are absent; rollback ref remains. Firebase, provider configuration, account/sign-in, production data, payments, and connected directory behavior were unchanged. -**Undo:** before publication, leave deploy `6a7e072f8f346b0008510d29` live. If the wrong result publishes, ask the Netlify team owner to atomically restore that same deploy. If provider restore is unavailable, use only a newly reviewed exact-parent rollback pinned to source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, then repeat its exact preview and marker checks. Disabling the manifest alone does not roll back an already published deploy. +**Undo:** if the verified #659 artifact later proves wrong, ask the Netlify team owner to atomically restore recorded rollback deploy `6a7e072f8f346b0008510d29`. If provider restore is unavailable, use only a newly reviewed exact-parent rollback pinned to source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, then repeat its exact preview and marker checks. The retained rollback ref is evidence, not standing publication authority. Disabling the manifest alone does not roll back an already published deploy. **Escalation:** platform owner first; accessibility reviewer second; security/privacy owner if an unexpected request, private value, account boundary, or provider action appears. Use the private incident path for any private data or secret. Do not copy that value into GitHub, a screenshot, email, or an AI tool. @@ -468,13 +466,13 @@ Do not use this section until #133 records that both GitHub environments are pro 9. Use made-up data only. Do not inspect or change a real member record. 10. Complete the delivery record. -### Check keyboard focus after an approved website publication — #659 EXACT-ARTIFACT CHECK UNDER REVIEW +### Check keyboard focus after an approved website publication — REPEATABLE CHECK; #659 ROUTE/MENU AUDIT COMPLETE **Purpose:** prove that a person using a keyboard can see which public link, button, or navigation control is active. **Approver:** the named release observer, with the platform owner or accessibility reviewer available if the check fails. -**Prerequisites:** the exact approved commit must be live and identified by the host; the public site must be safe to open without signing in; and the observer must use a normal computer with a keyboard. The reusable protected website release is still **NOT AVAILABLE YET** under #133/#136. #659 is one exact-artifact exception under review and is not published. Use this check for #659 only after its public marker matches the approved release; until then, #623 deploy `6a7e072f8f346b0008510d29` remains the verified host record. +**Prerequisites:** the exact approved commit must be live and identified by the host; the public site must be safe to open without signing in; and the observer must use a normal computer with a keyboard. The reusable protected website release is still **NOT AVAILABLE YET** under #133/#136. #659 completed one exact-artifact exception as deploy `6a7ece87c5ca4d0007c1a3fc`, and its marker matches the approved source. The completed route-focus audit did not separately retain a keyboard `:focus-visible` observation or screenshot; repeat the safe steps below if that additional evidence is required. #623 deploy `6a7e072f8f346b0008510d29` is the rollback host record. 1. Open the public website in a private browser window. 2. Confirm the host identifies the exact approved commit. @@ -496,13 +494,13 @@ Do not use this section until #133 records that both GitHub environments are pro **Escalation:** platform owner first, then the accessibility reviewer or backup release officer. Treat an unexpected live publication as a hosting incident. -### Verify focus after a client-side page change — WEB-UX-004 MERGED; #659 LIVE CHECK UNDER REVIEW +### Verify focus after a client-side page change — WEB-UX-004 LIVE IN #659; AUDIT COMPLETE **Purpose:** prove that a keyboard user who opens another page without a full browser reload moves from the old navigation control into the new main content. The source must not move focus on the first page load or take focus that the new page or user already chose. A client-side page change replaces the page content while the website stays open. **Approver:** the pull-request accessibility reviewer approves the source evidence. The named release observer approves a later public check, with the platform owner available if the revision or publication record is unclear. -**Prerequisites:** issue #657; reviewed PR #658 and exact head `a411cb4ebcfb4f1f05b3883721aa55f3d72bc701`; the recorded old-source failure; the named green WEB-UX-004 and full App results; and a reviewed undo. The source check uses GitHub and test summaries only. It needs no terminal, account, sign-in, private page, or real data. #659 now pins the equivalent route-focus behavior with its #291/#490 prerequisites in source `7496fe0881fb52908c4ff2f40f488df09c94c908`, but that one-shot release is under review and is not published. The later public check requires the exact #659 marker, a private browser window, a keyboard, and safe signed-out public pages. Reusable protected publication remains **NOT AVAILABLE YET** under #133/#136. #623 Netlify deploy `6a7e072f8f346b0008510d29`, source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, remains live. Do not call WEB-UX-004 live while that remains the host record. +**Prerequisites:** issue #657; reviewed PR #658 and exact head `a411cb4ebcfb4f1f05b3883721aa55f3d72bc701`; the recorded old-source failure; the named green WEB-UX-004 and full App results; and a reviewed undo. The source check uses GitHub and test summaries only. It needs no terminal, account, sign-in, private page, or real data. #659 published the equivalent route-focus behavior with its #291/#490 prerequisites in source `7496fe0881fb52908c4ff2f40f488df09c94c908` as deploy `6a7ece87c5ca4d0007c1a3fc`. Signed-out desktop and phone route-focus/menu checks passed. Reusable protected publication remains **NOT AVAILABLE YET** under #133/#136. #623 Netlify deploy `6a7e072f8f346b0008510d29`, source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, is the rollback predecessor. **Specialist dependency:** the platform maintainer must supply the exact issue, pull request, commit, test record, and later host readback. The officer can perform every browser step without a terminal. No Firebase or provider specialist action belongs to this check because those surfaces do not change. @@ -524,7 +522,9 @@ Do not use this section until #133 records that both GitHub environments are pro 14. Read the full App result and the hosted required checks for the same exact commit. 15. Record source changed, tests passed, and merge state separately. -**Later signed-out public check — ONLY AFTER THE EXACT #659 MARKER IS LIVE:** +**Completed #659 signed-out evidence:** the exact production marker matched. At 1280 CSS pixels, a client-side change to `/shop` left main content focused at the top with no horizontal overflow. At 390 CSS pixels, the `/events` phone menu reported its open state truthfully, then a destination change closed and hid it and left main content focused at the top with no horizontal overflow. No screenshot was retained. This live record did not separately exercise the initial skip-link Tab, keyboard `:focus-visible`, next-Tab order, or browser Back and Forward. Exact served source and CSS plus mutation-sensitive tests preserve those bounded contracts. + +**Repeatable signed-out public check — use when the additional keyboard evidence is required:** 16. Open the approved public page in a private browser window at 1280 CSS pixels wide. 17. Confirm the host identifies the exact approved commit. @@ -557,11 +557,13 @@ Do not use this section until #133 records that both GitHub environments are pro 44. Save one redacted public screenshot at each width. 45. Record website publication, exact `runmprc.com` revision, Firebase, outside providers, accounts and sign-in, production data, and live behavior as separate states. -**Expected result:** source evidence proves one focus handoff after a real path change, no handoff on first load or same-path cleanup, preservation of newer destination or user focus, and inert stale work. A later approved public check shows main focus at 1280 and 390 CSS pixels, a visible unclipped scoped cue alongside unchanged #291 behavior, normal next-`Tab` order, and the released phone menu closing. This interface change does not deploy Firebase, configure a provider, use an account, sign in, read or change production data, or prove live behavior. +**Actual #659 result:** source evidence proves one focus handoff after a real path change, no handoff on first load or same-path cleanup, preservation of newer destination or user focus, and inert stale work. The completed signed-out check proved main focus after route changes at both widths and truthful phone-menu close behavior. Exact served assets and mutation-sensitive tests preserve the scoped cue and next-Tab contract; the live record did not separately prove keyboard `:focus-visible`, next-Tab, Back/Forward, or screenshots. This interface change did not deploy Firebase, configure a provider, use an account, sign in, or read or change production data. + +**Expected result for a repeated full check:** main focus appears at both widths with a visible unclipped scoped cue, normal next-`Tab` order, correct Back/Forward focus settlement, and the released phone menu closing. Record that later observation separately from the completed #659 evidence above. **Stop conditions:** stop if the issue, commit, review, old-source failure, or green results are missing or mismatched. Stop if the host still identifies #623 or another revision. Stop if anyone asks for sign-in, a private page, a form submission, a real name, member data, payment data, or a provider action. Stop if initial load moves focus, old or hidden navigation keeps focus, destination-chosen focus is replaced, the scoped cue is missing or clipped, focus becomes trapped, the next `Tab` order is wrong, or the layout moves. Stop if a merge, workflow, preview, or screenshot is called proof of publication or live behavior. -**Success proof:** keep the issue, pull request, exact commit, named review, old-source failure, green WEB-UX-004 and full App results, hosted checks, checked public pages, browser, date, widths, and two redacted screenshots. Complete every line below without combining states: +**Success proof:** keep the issue, pull request, exact commit, named review, old-source failure, green WEB-UX-004 and full App results, hosted checks, checked public pages, browser, date, and widths. The completed #659 record has no retained screenshot and no separate live keyboard-cue observation. If the repeatable full check is later performed, add its two redacted screenshots and keyboard results without rewriting the narrower #659 record. Complete every line below without combining states: ```text Source changed: diff --git a/docs/officers/README.md b/docs/officers/README.md index 8c49c2e..c1d0a70 100644 --- a/docs/officers/README.md +++ b/docs/officers/README.md @@ -63,9 +63,9 @@ In words: approve the merge, request one exact release, and approve its protecte Never shorten several of these states to “done.” -Independent officer publishing to the live Netlify host is **NOT AVAILABLE YET**. An overbroad #473 artifact was published and rolled back on 2026-08-01; bounded #473 deploy `6a6dc9ea588b0c0008036312` remains the recorded rollback. #623 completed one separate, exact-artifact release of the inert member-directory interface. Deploy `6a7e072f8f346b0008510d29`, source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, is live. Signed-out guard and no-request checks passed. The temporary manifest is inactive, and its repause attempt did not replace the verified deploy. Shop remains the static pickup catalog, and Events/Calendar show a fixed retry-later notice instead of a raw provider error. Event records remain unavailable. This is not a reusable officer control. Use a platform maintainer until the Netlify connection and rollback path are documented and tested. +Independent officer publishing to the live Netlify host is **NOT AVAILABLE YET**. An overbroad #473 artifact was published and rolled back on 2026-08-01; bounded #473 deploy `6a6dc9ea588b0c0008036312` is older history. #623 completed one exact-artifact release of the inert member-directory interface and remains the immediate rollback at deploy `6a7e072f8f346b0008510d29`. #659 then completed one separate accessibility-only release. Deploy `6a7ece87c5ca4d0007c1a3fc`, source `7496fe0881fb52908c4ff2f40f488df09c94c908`, is live. Signed-out desktop/phone route-focus and menu checks passed. The manifest is inactive, and its repause attempt did not replace the verified deploy. Shop remains the static pickup catalog, Events/Calendar show a fixed retry-later notice, and the directory remains inert. This is not a reusable officer control. Use a platform maintainer until the Netlify connection and rollback path are documented and tested. -WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is one temporary accessibility artifact under review and is not published. It pins source `7496fe0881fb52908c4ff2f40f488df09c94c908` and only the reviewed visible-focus, phone-menu, and client-side route-focus behavior. Production remains #623 deploy `6a7e072f8f346b0008510d29`; that deploy is #659's rollback target. Officers perform no terminal, account, Firebase, provider, or production-data action. A named signed-out observer follows [Review, merge, release, and check a change](./PUBLISH_AND_CHECK.md) only after the platform owner supplies the exact preview and marker. A preview, green check, or merged release control does not prove the website changed. +WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed one temporary accessibility artifact release on 2026-08-14. Deploy `6a7ece87c5ca4d0007c1a3fc` is live and pins source `7496fe0881fb52908c4ff2f40f488df09c94c908` with only the reviewed visible-focus, phone-menu, and client-side route-focus behavior. Signed-out route/menu checks passed. Repause attempt `6a7ed0ddb00a46000818878d` published nothing, retained the deploy, and left the manifest inactive. #623 deploy `6a7e072f8f346b0008510d29` is the rollback target. Officers performed no terminal, account, Firebase, provider-configuration, or production-data action. The completed audit record is in [Review, merge, release, and check a change](./PUBLISH_AND_CHECK.md). A preview, green check, or merged release control alone does not prove the website changed. The protected GitHub release is also **NOT AVAILABLE YET** until #133 configures the environment approvers and short-lived cloud identity. Missing authority stops the release with a red failure before Firebase or website publication. diff --git a/docs/officers/REQUEST_A_CHANGE.md b/docs/officers/REQUEST_A_CHANGE.md index 5093dbf..e1b0600 100644 --- a/docs/officers/REQUEST_A_CHANGE.md +++ b/docs/officers/REQUEST_A_CHANGE.md @@ -34,7 +34,7 @@ Have one of these ready: If you open GitHub yourself, use the [canonical repository on `main`](https://github.com/Run-MPRC/Run-MPRC.github.io/tree/main), then select **Issues**. `main` is now the repository default. Do not use the legacy `dev` branch as the source for a new request. -The GitHub release is manual. A `main` merge runs checks but does not publish the GitHub Pages copy or deploy Firebase. Ordinary Git-triggered Netlify production builds are paused by repository configuration. The completed #623 exception published inert-interface deploy `6a7e072f8f346b0008510d29`, then repause attempt `6a7e081e73fdd60009f7ba57` published nothing and retained that deploy. Its temporary manifest is inactive, so it is not a reusable officer control. The earlier completed #473 deploy `6a6dc9ea588b0c0008036312` is rollback history. Netlify provider settings remain separately unverified. Stop and escalate any unexpected publication. +The GitHub release is manual. A `main` merge runs checks but does not publish the GitHub Pages copy or deploy Firebase. Ordinary Git-triggered Netlify production builds are paused by repository configuration. The completed #659 exception published accessibility deploy `6a7ece87c5ca4d0007c1a3fc`, then repause attempt `6a7ed0ddb00a46000818878d` published nothing and retained that deploy. Its temporary manifest is inactive, so it is not a reusable officer control. Completed #623 inert-interface deploy `6a7e072f8f346b0008510d29` is the immediate rollback, and completed #473 deploy `6a6dc9ea588b0c0008036312` is older history. Netlify provider settings remain separately unverified. Stop and escalate any unexpected publication. ## If you cannot open an AI assistant diff --git a/docs/officers/SYSTEM_MAPS.md b/docs/officers/SYSTEM_MAPS.md index 49dcf25..88b41ec 100644 --- a/docs/officers/SYSTEM_MAPS.md +++ b/docs/officers/SYSTEM_MAPS.md @@ -86,7 +86,7 @@ flowchart TD Rules --> Functions["Deploy and verify named Functions"] Functions --> Pages["Pages branch without Netlify's domain claim"] Main -. "Ordinary Git production build paused" .-> Netlify - Main -. "Completed #623 exact release; manifest inactive" .-> WebGate{"Temporary authority active?"} + Main -. "Completed #659 exact release; manifest inactive" .-> WebGate{"Temporary authority active?"} WebGate -- "No" --> Stop WebGate -- "Yes" --> Netlify Netlify["Netlify — current live host; reusable protected publication unavailable"] --> Live["runmprc.com"] @@ -94,7 +94,7 @@ flowchart TD Dev["dev — legacy branch"] -. "do not use for new release work" .-> PR ``` -In words: merge, release request, and protected approval are separate; a missing or failed Firebase gate publishes nothing; ordinary merges cannot publish Netlify and the completed #623 exception is inactive; its deploy `6a7e072f8f346b0008510d29` remains live while completed #473 deploy `6a6dc9ea588b0c0008036312` is rollback history; the future Pages branch must stop claiming the Netlify domain, and both hosts still need separate proof. +In words: merge, release request, and protected approval are separate; a missing or failed Firebase gate publishes nothing; ordinary merges cannot publish Netlify and the completed #659 exception is inactive; its deploy `6a7ece87c5ca4d0007c1a3fc` remains live while completed #623 deploy `6a7e072f8f346b0008510d29` is the immediate rollback and completed #473 deploy `6a6dc9ea588b0c0008036312` is older history; the future Pages branch must stop claiming the Netlify domain, and both hosts still need separate proof. ## Account and permission ownership diff --git a/docs/officers/UPDATE_PUBLIC_CONTENT.md b/docs/officers/UPDATE_PUBLIC_CONTENT.md index 0d6d50c..ca0ff5d 100644 --- a/docs/officers/UPDATE_PUBLIC_CONTENT.md +++ b/docs/officers/UPDATE_PUBLIC_CONTENT.md @@ -112,13 +112,13 @@ Do not publish photos of minors, private events, name badges, addresses, license 4. Check spelling, title, photo, order, and old-officer removal. 5. Ask AI to confirm no account permissions changed. Website display and GitHub/Firebase access are separate. -## Phone navigation preview check — SOURCE AVAILABLE; #659 LIVE CHECK UNDER REVIEW +## Phone navigation check — #659 LIVE AND VERIFIED 2026-08-14 **Purpose:** confirm that the small-screen menu is predictable before a website release. **Approver:** communications lead or platform owner. -**Before you start:** have the reviewed preview link. Stay signed out and use no private information. WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) freezes the reviewed #490 phone-menu behavior with the related visible-focus and route-focus source for one exact-artifact release, but it is under review and is not published. Production remains #623 deploy `6a7e072f8f346b0008510d29`, which is also #659's rollback target. +**Before you start:** stay signed out and use no private information. WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed one exact-artifact release of the reviewed #490 phone-menu behavior with the related visible-focus and route-focus source. Production deploy `6a7ece87c5ca4d0007c1a3fc` passed the signed-out phone menu and route-focus check. #623 deploy `6a7e072f8f346b0008510d29` is the rollback target. 1. Open the preview at a phone-sized width. 2. Select the MPRC logo while the menu is closed. @@ -141,7 +141,7 @@ Do not publish photos of minors, private events, name badges, addresses, license **Escalation:** platform owner first; accessibility reviewer second. -This check describes #490 source and preview behavior. The #659 signed-out live observer may repeat the phone-menu check only after the public marker identifies the exact approved release. On production, use safe public destinations only; do not choose Sign in, enter data, open a private page, or submit a form. Until the exact #659 publication and repause records pass, this behavior is **NOT LIVE YET** and #623 remains the verified host record. Follow the full no-terminal procedure in [Review, merge, release, and check a change](./PUBLISH_AND_CHECK.md). +The completed #659 signed-out live check used safe public destinations only. At phone width, the menu exposed truthful open disclosure state; choosing `/events` closed it, moved focus to main content at the top, and caused no horizontal overflow. Exact served source, CSS, and mutation-sensitive tests preserve the bounded visible-focus cue; this audit does not claim a saved screenshot or a separate live keyboard `:focus-visible` observation. On production, do not choose Sign in, enter data, open a private page, or submit a form. Repause attempt `6a7ed0ddb00a46000818878d` published nothing and retained deploy `6a7ece87c5ca4d0007c1a3fc`. Follow the full no-terminal record in [Review, merge, release, and check a change](./PUBLISH_AND_CHECK.md). ## Success check diff --git a/tests/release-workflow.test.js b/tests/release-workflow.test.js index efa22a1..e5b2902 100644 --- a/tests/release-workflow.test.js +++ b/tests/release-workflow.test.js @@ -32,15 +32,6 @@ const FINAL_RELEASE_TRUTH_PATHS = [ 'docs/officers/README.md', 'docs/officers/REQUEST_A_CHANGE.md', 'docs/officers/SYSTEM_MAPS.md', -]; -const PENDING_RELEASE_TRUTH_PATHS = [ - 'IMPLEMENTATION_PLAN.md', - 'OFFICER_START_HERE.md', - 'OPERATIONS_RUNBOOK.md', - 'SECURITY.md', - 'SYSTEM_DESIGN.md', - 'docs/officers/PUBLISH_AND_CHECK.md', - 'docs/officers/README.md', 'docs/officers/UPDATE_PUBLIC_CONTENT.md', ]; const { @@ -64,12 +55,6 @@ const finalReleaseTruth = new Map( fs.readFileSync(path.join(ROOT, relativePath), 'utf8'), ]), ); -const pendingReleaseTruth = new Map( - PENDING_RELEASE_TRUTH_PATHS.map((relativePath) => [ - relativePath, - fs.readFileSync(path.join(ROOT, relativePath), 'utf8'), - ]), -); function runNetlifyGate(context) { const env = { ...process.env }; @@ -286,7 +271,7 @@ test('Netlify manifest pins the inactive bounded #659 keyboard-focus release', ( ); }); -test('completed #623 records stay live while #659 is pending', () => { +test('completed #659 records are live while #623 remains rollback history', () => { assert.match( netlifyConfig, /temporary #659 production authority is inactive again/i, @@ -297,19 +282,30 @@ test('completed #623 records stay live while #659 is pending', () => { ); finalReleaseTruth.forEach((contents, relativePath) => { + assert.match(contents, /#659/); + assert.match(contents, /6a7ece87c5ca4d0007c1a3fc/); assert.match(contents, /#623/); assert.match(contents, /6a7e072f8f346b0008510d29/); - assert.match(contents, /#473/); + if (relativePath !== 'docs/officers/UPDATE_PUBLIC_CONTENT.md') { + assert.match(contents, /#473/); + } [ /PENDING #473 RELEASE/i, /Temporary #473 permissions-containment release — PENDING REVIEW AND RELEASE/i, /Issue #473 now prepares a replacement/i, /#473's narrower replacement is \*\*NOT AVAILABLE YET\*\*/i, + /WEB-002D pending/i, + /Temporary #659[^\n]*— (?:UNDER REVIEW|PENDING)/i, + /#659[^\n]{0,180}(?:under review|is not published|not published|not live yet)/i, + /(?:under review|not published)[^\n]{0,180}#659/i, + /#659 LIVE CHECK UNDER REVIEW/i, + /ONLY AFTER THE EXACT #659 MARKER IS LIVE/i, + /production remains #623/i, ].forEach((staleClaim) => { assert.doesNotMatch( contents, staleClaim, - `${relativePath} must not retain stale #473 release status`, + `${relativePath} must not retain stale #659 or #473 release status`, ); }); }); @@ -317,51 +313,55 @@ test('completed #623 records stay live while #659 is pending', () => { const completedTruth = new Map([ [ 'IMPLEMENTATION_PLAN.md', - /#623[^\n]*completed[^\n]*published[^\n]*6a7e072f8f346b0008510d29/i, + /WEB-002D completed release boundary:[^\n]*#659[^\n]*completed[^\n]*6a7ece87c5ca4d0007c1a3fc/i, ], [ 'OFFICER_START_HERE.md', - /#623[^\n]*completed[^\n]*6a7e072f8f346b0008510d29[^\n]*live/i, + /#659[^\n]*completed[^\n]*6a7ece87c5ca4d0007c1a3fc[^\n]*live/i, ], [ 'OPERATIONS_RUNBOOK.md', - /#623[^\n]*completed[^\n]*6a7e072f8f346b0008510d29[^\n]*published/i, + /#659[^\n]*completed[^\n]*6a7ece87c5ca4d0007c1a3fc[^\n]*published/i, ], [ 'README.md', - /completed bounded #623 release[^\n]*published deploy `6a7e072f8f346b0008510d29`/i, + /#659[^\n]*completed one bounded accessibility release[^\n]*published deploy `6a7ece87c5ca4d0007c1a3fc`/i, ], [ 'SECURITY.md', - /#623[^\n]*published[^\n]*inert[^\n]*6a7e072f8f346b0008510d29/i, + /WEB-002D completed exact-artifact containment[^\n]*#659[^\n]*completed[^\n]*published deploy `6a7ece87c5ca4d0007c1a3fc`/i, ], [ 'SYSTEM_DESIGN.md', - /#623[^\n]*completed[^\n]*published[^\n]*inert[^\n]*6a7e072f8f346b0008510d29/i, + /#659[^\n]*completed[^\n]*published deploy `6a7ece87c5ca4d0007c1a3fc`/i, ], [ 'docs/officers/ACCESS_CONTINUITY.md', - /live #623 marker[^\n]*deploy `6a7e072f8f346b0008510d29`/i, + /live #659 marker[^\n]*deploy `6a7ece87c5ca4d0007c1a3fc`/i, ], [ 'docs/officers/EVENTS_SHOP_MEMBERS.md', - /#623 published only that inert interface[^\n]*deploy `6a7e072f8f346b0008510d29`/i, + /live #659 deploy `6a7ece87c5ca4d0007c1a3fc` preserves the inert #623/i, ], [ 'docs/officers/PUBLISH_AND_CHECK.md', - /#623 completed[^\n]*Deploy `6a7e072f8f346b0008510d29`[^\n]*production now/i, + /Temporary #659 keyboard-navigation and route-focus release — COMPLETED 2026-08-14/i, ], [ 'docs/officers/README.md', - /#623 completed[^\n]*inert[^\n]*Deploy `6a7e072f8f346b0008510d29`[^\n]*live/i, + /#659[^\n]*completed[^\n]*Deploy `6a7ece87c5ca4d0007c1a3fc`[^\n]*live/i, ], [ 'docs/officers/REQUEST_A_CHANGE.md', - /completed #623 exception published inert-interface deploy `6a7e072f8f346b0008510d29`/i, + /completed #659 exception published accessibility deploy `6a7ece87c5ca4d0007c1a3fc`/i, ], [ 'docs/officers/SYSTEM_MAPS.md', - /completed #623 exception[^\n]*deploy `6a7e072f8f346b0008510d29` remains live/i, + /completed #659 exception[^\n]*deploy `6a7ece87c5ca4d0007c1a3fc` remains live/i, + ], + [ + 'docs/officers/UPDATE_PUBLIC_CONTENT.md', + /#659 LIVE AND VERIFIED 2026-08-14[\s\S]*production deploy `6a7ece87c5ca4d0007c1a3fc`/i, ], ]); completedTruth.forEach((expectedTruth, relativePath) => { @@ -369,90 +369,52 @@ test('completed #623 records stay live while #659 is pending', () => { assert.match( record, expectedTruth, - `${relativePath} must bind #623's completed state to the live deploy`, + `${relativePath} must bind #659's completed state to the live deploy`, ); - [ - /#623[^\n]{0,80}(?:release|artifact)[^\n]{0,40}(?:is|remains|was) (?:still )?(?:under review|not published)/i, - /#623[^\n]{0,120}has not published or been verified/i, - /#623[^\n]{0,120}remains under review and is not production/i, - /That release is under review and not published/i, - /production (?:still )?serves[^\n]*#473/i, - /Temporary #623[^\n]*— (?:UNDER REVIEW|PENDING)/i, - ].forEach((staleClaim) => { - assert.doesNotMatch( - record, - staleClaim, - `${relativePath} must not retain stale #623 release status`, - ); - }); }); - const expectedPendingTruth = new Map([ - [ - 'IMPLEMENTATION_PLAN.md', - /\*\*WEB-002D pending release boundary:\*\* \[#659\][^\n]*under review and is not published/i, - ], - [ - 'OFFICER_START_HERE.md', - /As of \*\*2026-08-14\*\*, \[#659\][^\n]*under review and is not published/i, - ], - [ - 'OPERATIONS_RUNBOOK.md', - /WEB-002D \[#659\][^\n]*active one-shot Netlify accessibility release under review and is not published/i, - ], - [ - 'SECURITY.md', - /WEB-002D pending exact-artifact containment for RISK-036 \| \[#659\][^\n]*under review and is not published/i, - ], - [ - 'SYSTEM_DESIGN.md', - /WEB-002D \[#659\][^\n]*active exact-artifact exception under review, not a completed publication/i, - ], - [ - 'docs/officers/PUBLISH_AND_CHECK.md', - /^## Temporary #659 keyboard-navigation and route-focus release — UNDER REVIEW, NOT PUBLISHED$/m, - ], - [ - 'docs/officers/README.md', - /WEB-002D \[#659\][^\n]*under review and is not published/i, - ], - [ - 'docs/officers/UPDATE_PUBLIC_CONTENT.md', - /WEB-002D \[#659\][^\n]*under review and is not published/i, - ], - ]); - expectedPendingTruth.forEach((expectedTruth, relativePath) => { - const contents = pendingReleaseTruth.get(relativePath); - assert.match( - contents, - expectedTruth, - `${relativePath} must bind #659 to its exact pending status`, - ); - assert.match(contents, /#659/); - assert.match(contents, /6a7e072f8f346b0008510d29/); - assert.doesNotMatch( - contents, - /#659 (?:has )?completed (?:one|its)|#659 published deploy|#659 is production/i, - `${relativePath} must not claim that #659 is live`, - ); - }); + const canonicalRecords = [ + finalReleaseTruth.get('OPERATIONS_RUNBOOK.md'), + finalReleaseTruth.get('docs/officers/PUBLISH_AND_CHECK.md'), + ]; [ + '6a7ec998bf8fde00086d2bfe', + '137d8a8721339a6ca1079283cc34c1bd7cc2706c', + '31781730576', + '46e23647d8e0bf9fa3a574ea5c5f993be10a419d', + '3ef47ed0f664e1e9a2c703332ca9071cfda27ad2', + '31783141914', + '6a7ece87c5ca4d0007c1a3fc', '7496fe0881fb52908c4ff2f40f488df09c94c908', 'ccac4c189c195db8ab594e0eefe256ea9fa04996', 'e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7', '95880748e15c03b0ee58da6e1ed11ac6c9526529', '462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c', + '6a7ecfbc90347c000804901c', + '94c949abed3759c15cdaa98afc6896343e8a6edd', + '31783487885', + '3138a00c1c48e1d5d1dcda0b44722b09a2194ff7', + 'c4667394dc9a2286c3a2eda028728314e925c22f', + '31783808994', + '6a7ed0ddb00a46000818878d', ].forEach((identifier) => { - [ - pendingReleaseTruth.get('OPERATIONS_RUNBOOK.md'), - pendingReleaseTruth.get('docs/officers/PUBLISH_AND_CHECK.md'), - ].forEach((record) => assert.match(record, new RegExp(identifier))); + canonicalRecords.forEach((record) => { + assert.match(record, new RegExp(identifier)); + }); + }); + canonicalRecords.forEach((record) => { + assert.match(record, /(?:62 files|62-file)/i); + assert.match( + record, + /(?:6a7ed0ddb00a46000818878d[\s\S]{0,240}(?:unpublished|published nothing|publish nothing)|(?:unpublished|published nothing|publish nothing)[\s\S]{0,240}6a7ed0ddb00a46000818878d)/i, + ); + assert.match( + record, + /(?:6a7ece87c5ca4d0007c1a3fc[\s\S]{0,300}(?:retained|remained|left|stayed)|(?:retained|remained|left|stayed)[\s\S]{0,300}6a7ece87c5ca4d0007c1a3fc)/i, + ); }); - const canonicalRecords = [ - finalReleaseTruth.get('OPERATIONS_RUNBOOK.md'), - finalReleaseTruth.get('docs/officers/PUBLISH_AND_CHECK.md'), - ]; + // Preserve the complete historical #623 release and rollback chain. [ '9d5cc8612b4321172370bd949d307e7e4ac0ec7d', '6a7e072f8f346b0008510d29', @@ -469,7 +431,6 @@ test('completed #623 records stay live while #659 is pending', () => { }); }); canonicalRecords.forEach((record) => { - assert.match(record, /(?:62 files|62-file)/i); assert.match( record, /(?:6a7e081e73fdd60009f7ba57[\s\S]{0,240}(?:unpublished|published nothing|publish nothing)|(?:unpublished|published nothing|publish nothing)[\s\S]{0,240}6a7e081e73fdd60009f7ba57)/i,