Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion IMPLEMENTATION_PLAN.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ MPRC can open a race or merchandise item for sale only when the platform can:
9. Do not trade payment integrity for UI responsiveness. Confirmation may say “processing”; it must not guess “paid.”
10. Legal/tax/insurance questions are escalated to qualified owners, not decided by an implementation agent.

**WEB-002D pending release boundary:** [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is one active exact-artifact Netlify exception under review and is not published. It projects only the released #291 visible-focus behavior, #490 deterministic phone-menu disclosure/close behavior, and merged #657 route-focus handoff onto live source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. Pinned source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7` must match an exact two-parent merge whose first parent is `95880748e15c03b0ee58da6e1ed11ac6c9526529`. Until the exact preview, signed-out public checks, and immediate repause all pass, #623 deploy `6a7e072f8f346b0008510d29` remains production and the rollback target. #659 does not publish accumulated `main`, deploy Firebase, configure a provider, use an account, change production data, or connect the directory. Directory availability stays literal `false`; reusable hosting remains open under #460/#133/#136.
**WEB-002D completed release boundary:** [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed one exact-artifact Netlify exception on 2026-08-14. Exact release merge `46e23647d8e0bf9fa3a574ea5c5f993be10a419d` published deploy `6a7ece87c5ca4d0007c1a3fc` from source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`. Signed-out desktop route-focus and phone menu/route-focus checks passed. Repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7` passed exact-main CI run `31783808994`; attempt `6a7ed0ddb00a46000818878d` remained unpublished and retained the verified deploy. The manifest is inactive, the temporary source/control/repause refs are absent, and rollback ref `codex/netlify-source-659-rollback` remains pinned to #623 source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. #659 published only the reviewed #291 visible-focus, #490 phone-menu, and #657 route-focus behavior. It deployed no Firebase, Rules, Functions, or indexes; changed no outside-provider configuration, account, sign-in state, production data, payment, or connected directory behavior; and left directory availability literal `false`. Reusable hosting remains open under #460/#133/#136, and #507 still owns every connected-directory gate.

## 3. Dependency map

Expand Down
2 changes: 1 addition & 1 deletion OFFICER_START_HERE.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ Use the club's approved password manager for access. Share only a public link or

As of **2026-08-13**, a merge runs checks but does not start the GitHub release. The protected release is **NOT AVAILABLE YET** until its short-lived cloud identity and named environment approvers are configured under issue #133. Ordinary Git-triggered Netlify production builds are paused. An overbroad #473 web artifact was published and immediately rolled back; its bounded replacement remains the recorded rollback. #623 then completed one separate, exact-artifact release of the inert member-directory interface. Netlify deploy `6a7e072f8f346b0008510d29` is live from source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. Signed-out route and guard checks passed, no member-directory request was observed, and repause merge `c8678c623afdd9becf77d596b71f36f26f04b746` made the temporary manifest inactive without replacing that deploy. Shop remains the static in-person catalog, while Events and Calendar show a fixed retry-later notice instead of a raw provider error. Event records are still unavailable because no Firebase repair was deployed. This does not change sign-in, expose protected event offers, add officer editing, or make commerce safe. GitHub Pages still reports `runmprc.com` as its custom domain even though Netlify serves that name; source removal is not provider proof. A green test or workflow does **not** by itself prove that GitHub Pages, `runmprc.com`, Firebase, or that domain setting changed.

As of **2026-08-14**, [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is one accessibility-only Netlify release under review and is not published. It pins one frozen 62-file artifact from source `7496fe0881fb52908c4ff2f40f488df09c94c908` and combines only the reviewed visible keyboard focus, phone-menu close/disclosure, and client-side route-focus behavior. Production remains #623 deploy `6a7e072f8f346b0008510d29`, which is also the rollback target. Officers do not run commands, sign in, enter data, change Firebase or a provider, or approve this as a reusable release. A named observer may perform the safe signed-out browser checks only after the platform owner supplies the exact preview, marker, and approval record. Follow [Review, merge, release, and check a change](./docs/officers/PUBLISH_AND_CHECK.md) and stop on any mismatch.
As of **2026-08-14**, [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed one accessibility-only Netlify release. Deploy `6a7ece87c5ca4d0007c1a3fc` is live from frozen source `7496fe0881fb52908c4ff2f40f488df09c94c908`; its exact 62-file marker and signed-out desktop/phone route-focus and menu checks passed. Repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7` made the manifest inactive. Its attempt `6a7ed0ddb00a46000818878d` published nothing and retained the verified deploy. #623 deploy `6a7e072f8f346b0008510d29` is the recorded rollback, not current production. #659 changed no Firebase, provider configuration, account, sign-in state, production data, payment, or connected directory behavior. Officers do not run commands, sign in, enter data, or approve this as a reusable release. Follow the completed record in [Review, merge, release, and check a change](./docs/officers/PUBLISH_AND_CHECK.md).

The optional profile-photo and officer People-finder functions are still **NOT AVAILABLE YET**. #621 makes the frontend default an inert preview: My Account shows the future photo and separate finder-choice controls disabled, while the People finder stays behind the administrator guard and shows its name field and Search button disabled. The preview reads no saved photo or setting, accepts or uploads no photo, searches no name, and saves nothing; it shows no people or sample results. #623 published exactly that disabled interface as deploy `6a7e072f8f346b0008510d29`. Officers inspect the protected layouts only in synthetic local artifacts. The completed signed-out production review proved only the exact revision, normal sign-in and administrator guards, and absence of a member-directory network request. Do not sign in to production, choose a real photo, enter a real name, or treat the preview as a directory. #623 changed no Firebase, provider configuration, account, sign-in, or production data. #507 must later prove the privacy, authorization, staging, backend-first deployment, and readback gates before a separate reviewed source change may connect it. Follow the preview and source-review procedure in [Events, shop, members, and money](./docs/officers/EVENTS_SHOP_MEMBERS.md).

Expand Down
2 changes: 1 addition & 1 deletion OPERATIONS_RUNBOOK.md
Original file line number Diff line number Diff line change
Expand Up @@ -691,7 +691,7 @@ WEB-002A [#473](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/473) compl

WEB-002C [#623](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/623) completed its bounded inert member-directory interface release on 2026-08-13. Pinned Deploy Preview `6a7e05febf8fde00084cf9e0` matched release-control head `1fdb31f71fcaf01c33b5e57a4cd28fc473a4a737`, and PR CI run `31728469418` passed. Exact two-parent merge `9d5cc8612b4321172370bd949d307e7e4ac0ec7d`, parents `019353361210021483f23003e09ee6924b78e67c` and `1fdb31f71fcaf01c33b5e57a4cd28fc473a4a737`, tree `41b6d024d369d93f28ea49940b4f4e5710d3ab52`, passed exact-main CI run `31728908486`. Netlify deploy `6a7e072f8f346b0008510d29` became ready and published at `2026-08-13T18:05:35.983Z`. Its marker matched frozen source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, tree `411aa6ec9a9459f5d923030533ffc7c007fe6908`, previous source `39ab8649df411262c8109a3c81a57bc38f1e168b`, rollback deploy `6a6dc9ea588b0c0008036312`, 62 files, and digest `d837272a1e5efc1575809e87f532276b38d1a63f1dd79ec1aef0533f6da8afb1`. Signed-out `/account` and `/admin/member-directory` checks retained the normal guards; route and bundle review found no connected member-directory symbol or request. Protected Account and administrator layouts remain proved only with synthetic local artifacts. Repause head `d401daa409176dce0906c245adf3f20310cb513b` passed PR CI run `31728977578`; exact two-parent repause merge `c8678c623afdd9becf77d596b71f36f26f04b746`, parents `9d5cc8612b4321172370bd949d307e7e4ac0ec7d` and `d401daa409176dce0906c245adf3f20310cb513b`, passed all five exact-main jobs in run `31729248865`. Its Netlify attempt `6a7e081e73fdd60009f7ba57` errored unpublished; provider and marker readback retained deploy `6a7e072f8f346b0008510d29`. The manifest is inactive, the release source ref is absent, and rollback ref `codex/netlify-source-623-rollback` remains. #623 deployed no Firebase, Rules, Functions, or indexes; changed no outside-provider configuration, account, sign-in, or production data; and made no connected directory behavior available. Connected behavior remains **NOT AVAILABLE YET** under [#507](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/507). Do not reuse this exception as a general release button.

WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) is an active one-shot Netlify accessibility release under review and is not published. Release ID `WEB-002D-KEYBOARD-FOCUS-2026-08-14` pins remote source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and artifact digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`; the exact six-path diff from previous/current live source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec` has digest `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`. The manifest expects exact first parent `95880748e15c03b0ee58da6e1ed11ac6c9526529`, release branch `codex/issue-659-netlify-release`, source ref `codex/netlify-source-659-keyboard-focus`, and rollback deploy `6a7e072f8f346b0008510d29`; rollback ref `codex/netlify-source-659-rollback` pins the current live source. The frozen source changes only `src/App.jsx`, `src/App.test.jsx`, `src/components/Navbar.jsx`, `src/components/ScrollToTop.jsx`, `src/headerClearance.test.jsx`, and `src/index.css`, combining exact reviewed #291 visible focus, #490 phone-menu disclosure/close behavior, and #657 path-navigation focus. Until the pinned preview, exact two-parent merge, production marker, signed-out desktop/phone focus and menu checks, and immediate repause all pass, #623 deploy `6a7e072f8f346b0008510d29` remains production and the rollback target. Stop for any source, tree, path, count, artifact, parent, marker, focus, menu, network, or repause mismatch. #659 has no authority for Firebase, Rules, Functions, indexes, outside-provider configuration, accounts, sign-in, production data, content, routes, payments, or connected directory behavior; directory availability remains literal `false`. Follow the pending no-terminal procedure in `docs/officers/PUBLISH_AND_CHECK.md`; never use this exception as a general release button.
WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed its one-shot Netlify accessibility release on 2026-08-14. Release ID `WEB-002D-KEYBOARD-FOCUS-2026-08-14` used pinned Deploy Preview `6a7ec998bf8fde00086d2bfe`, matched release-control head `137d8a8721339a6ca1079283cc34c1bd7cc2706c`, and passed PR CI run `31781730576`. Exact two-parent release merge `46e23647d8e0bf9fa3a574ea5c5f993be10a419d`, parents `95880748e15c03b0ee58da6e1ed11ac6c9526529` and `137d8a8721339a6ca1079283cc34c1bd7cc2706c`, tree `3ef47ed0f664e1e9a2c703332ca9071cfda27ad2`, passed exact-main CI run `31783141914`. Netlify deploy `6a7ece87c5ca4d0007c1a3fc` became ready and published at `2026-08-14T08:16:09.268Z`. Its marker and all 62 artifact paths matched source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, previous source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`, rollback deploy `6a7e072f8f346b0008510d29`, and digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`; the exact six-path live-source diff digest was `462eeb01e7a9858678802464f7dd4b76cd2fcb3c13be827efb4f98fa53ca809c`. Signed-out desktop `/shop` and phone `/events` checks passed: route changes left main focused at the top without horizontal overflow, and the phone menu exposed truthful open state before destination selection closed it and preserved normal route focus. Repause preview `6a7ecfbc90347c000804901c` matched head `94c949abed3759c15cdaa98afc6896343e8a6edd`, which passed PR CI run `31783487885`; exact repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7`, parents `46e23647d8e0bf9fa3a574ea5c5f993be10a419d` and `94c949abed3759c15cdaa98afc6896343e8a6edd`, tree `c4667394dc9a2286c3a2eda028728314e925c22f`, passed all five exact-main jobs in run `31783808994`. Its attempt `6a7ed0ddb00a46000818878d` errored unpublished; provider and marker readback retained deploy `6a7ece87c5ca4d0007c1a3fc`. The manifest is inactive, the release/control/repause refs are absent, and rollback ref `codex/netlify-source-659-rollback` remains pinned to source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec`. #659's frozen source differed from its predecessor only at `src/App.jsx`, `src/App.test.jsx`, `src/components/Navbar.jsx`, `src/components/ScrollToTop.jsx`, `src/headerClearance.test.jsx`, and `src/index.css`. It deployed no Firebase, Rules, Functions, or indexes; changed no outside-provider configuration, account, sign-in state, production data, content, route set, payment, or connected directory behavior; and left directory availability literal `false`. Follow the completed no-terminal audit record in `docs/officers/PUBLISH_AND_CHECK.md`; never use this exception as a general release button.

Incident record: on 2026-08-01, overbroad source `094af1096ed8721597561cd59bf695d4c4a9d210` was published by merge `40728ff6141e34a279b70cc41d983c22ac5f0daa` as deploy `6a6dc0167fbe68000816b448` after a release-blocker comment. Exact rollback merge `1099ee8e6fdb81141fd9460de175b6d854cbcfdd` published deploy `6a6dc219a8136300081811db`, restoring source `ed1b0833`, tree `878c6628d961f4484cb49208aef53f1e9f2e3b47`, 60 files, and digest `7570955c2a00926e5813aef135f1799172cfd046072ac89fb4e492bed0797092`. Safety merge `dee79511b6e371329aa129139729e112e7a51aad` re-paused the manifest; its Netlify attempt `6a6dc35767a4ef000877e74b` did not publish, and provider readback left the rollback deploy live. The overbroad release ref was deleted and verified absent. This incident changed no Firebase, outside-provider configuration, account, payment, or production data.

Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ Historical developer/content/LLM guides remain under [`docs/`](./docs/README.md)
- `.github/workflows/`: frontend, Functions, Rules CI and deployment automation.
- `public/404.html`, `public/index.html`, and `public/spa-navigation.js`: current tested GitHub Pages callback handoff. It preserves safe same-origin path, query, and fragment state.

**Deployment reality checked 2026-08-13:** merges run CI but do not start the manual release workflow. The protected gate accepts one exact current merged commit, rechecks its newest CI run after approval, uses one fixed Firebase target set, fails when protected authority/configuration is missing, verifies Firebase before publishing GitHub Pages, and gives no server credential to website preparation or publication. Ordinary Git-triggered Netlify production builds are paused. The completed bounded #623 release merge `9d5cc8612b4321172370bd949d307e7e4ac0ec7d` published deploy `6a7e072f8f346b0008510d29` from exact source `c2d87d1f69f15e128a0bc9b1b9f915b7c8417aec` and tree `411aa6ec9a9459f5d923030533ffc7c007fe6908`; its 62-file artifact digest is `d837272a1e5efc1575809e87f532276b38d1a63f1dd79ec1aef0533f6da8afb1`. It adds only an inert profile-photo/searchability and officer People finder interface: the controls are visibly unavailable and make no directory request. No Firebase, provider, account, role, member data, photo, or search backend changed. Repause merge `c8678c623afdd9becf77d596b71f36f26f04b746` passed exact-main CI run `31729248865`; its Netlify attempt `6a7e081e73fdd60009f7ba57` published nothing, and deploy `6a7e072f8f346b0008510d29` remained live. The temporary #623 manifest is inactive again. The prior bounded #473 deploy `6a6dc9ea588b0c0008036312` remains rollback history, not current production. The source stops adding a Pages `CNAME`, but GitHub Pages currently still claims `runmprc.com` and its default URL redirects there; only a controlled #136/WEB-001 publication and provider readback can clear that conflict. Reusable protected publication to the live Netlify-served `runmprc.com` is not configured yet. Treat GitHub Pages, Netlify, `runmprc.com`, Firebase, and outside providers as separate states.
**Deployment reality checked 2026-08-14:** merges run CI but do not start the manual release workflow. The protected gate accepts one exact current merged commit, rechecks its newest CI run after approval, uses one fixed Firebase target set, fails when protected authority/configuration is missing, verifies Firebase before publishing GitHub Pages, and gives no server credential to website preparation or publication. Ordinary Git-triggered Netlify production builds are paused. WEB-002D [#659](https://github.com/Run-MPRC/Run-MPRC.github.io/issues/659) completed one bounded accessibility release: exact merge `46e23647d8e0bf9fa3a574ea5c5f993be10a419d` published deploy `6a7ece87c5ca4d0007c1a3fc` from source `7496fe0881fb52908c4ff2f40f488df09c94c908`, tree `ccac4c189c195db8ab594e0eefe256ea9fa04996`, 62 files, and artifact digest `e4c26e6f0fbcd086663d86238675f0be228fb649a00628c1c97d1166612f49c7`. Signed-out desktop and phone route-focus/menu checks passed. Repause merge `3138a00c1c48e1d5d1dcda0b44722b09a2194ff7` passed exact-main CI run `31783808994`; attempt `6a7ed0ddb00a46000818878d` published nothing, deploy `6a7ece87c5ca4d0007c1a3fc` remained live, and the manifest is inactive. #623 deploy `6a7e072f8f346b0008510d29` remains rollback history and its inert directory interface is unchanged beneath the accessibility delta. No Firebase, Rules, Functions, indexes, provider configuration, account, sign-in state, role, member data, payment, or connected directory backend changed. The prior bounded #473 deploy `6a6dc9ea588b0c0008036312` remains older history. The source stops adding a Pages `CNAME`, but GitHub Pages currently still claims `runmprc.com` and its default URL redirects there; only a controlled #136/WEB-001 publication and provider readback can clear that conflict. Reusable protected publication to the live Netlify-served `runmprc.com` is not configured yet. Treat GitHub Pages, Netlify, `runmprc.com`, Firebase, and outside providers as separate states.

## Local setup status

Expand Down
Loading