Skip to content

Hold what the page says about a backup to that backup (Section 06a) - #231

Merged
404SecNotFound merged 1 commit into
mainfrom
claude/serene-carson-0739mv
Sep 28, 2026
Merged

404SecNotFound merged 1 commit into
mainfrom
claude/serene-carson-0739mv

Conversation

@404SecNotFound

Copy link
Copy Markdown
Owner

Section 06, part a (roadmap). Holds what the page says about a backup to that backup.

What changes

  • Workflow model. src/lib/backup-workflow.ts is a pure model of the creation workflow (editing, a job working, created) and of exports started from the backup. It accepts a result or an end only from the job it is waiting on, so a job the user has moved on from cannot put the page back into a success state.
  • Old receipt comes down. Starting a new encrypt takes down the previous receipt and its rehearsal. They stayed up through the run, a Stop and a failure, with buttons that did nothing.
  • Changes are named. After a seal, the receipt and the Recovery tab name what has changed since the backup was made. That covers content, access rule, key derivation, cipher, size hiding and input type.
  • Download and print are recorded as started, with the time. The Recovery tab says the page cannot see whether they were kept.
  • Stale exports are refused. Both paper-vault prints and the download re-check the operation after their awaits. The shares dialog's print would otherwise print shares after a wipe.
  • Rehearsal no longer sticks on "Opening..." after a Stop or an input switch.
  • Access rule shown up front. The exact AND/OR rule is shown above the Encrypt button, in the receipt's words.

Tests

  • npm run test:backup-workflow (new, wired into CI) passes 24 checks. Negative control. Removing the job comparison from the reducer fails 5 of them.
  • tests/browser/workflow-evidence.spec.ts (new) has 4 Chromium tests. Negative control. Four separate faults (job-start receipt clear removed, "changed since" disabled, download record removed, rule line hidden) each failed its own test.

Gates run locally on ed140c9

  • npm run typecheck and all 38 Node test:* scripts pass.
  • Python gates (test:conformance, test:keym2, test:conformance2, test:recovery) pass with reference/conformance-requirements.txt installed.
  • npm run build passes.
  • Chromium with --workers=2 had 323 passed and 5 skipped. The one failure was the known async-guard.spec.ts flake ("switching tabs mid-derivation...") on a worker-boundary timing assertion. That spec then passed 5 of 5 with --repeat-each=5.
  • Firefox and WebKit were not run locally. CI covers them.

Left for later parts of Section 06

  • the visible step order
  • the expert view for format and KDF detail
  • the verify result outliving its input
  • testing from the Recovery tab wiping the receipt
  • the auto-lock clearing evidence while the shares dialog stays open
  • production screenshots and usability notes

🤖 Generated with Claude Code

https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr


Generated by Claude Code

Section 06, part a. src/lib/backup-workflow.ts is a pure model of the
creation workflow (editing, a job working, created) and of exports
started from the backup. It accepts a result or an end only from the job
it is waiting on, so a job the user has moved on from cannot put the
page back into a success state.

Wired into the page:
- Starting a new encrypt takes down the previous receipt and its
  rehearsal. They stayed up through the run, a Stop and a failure, with
  buttons that did nothing.
- After a seal, the receipt and the Recovery tab name what has changed
  since the backup was made: content, access rule, key derivation,
  cipher, size hiding or input type.
- Download and print are recorded as started, with the time, and the
  Recovery tab says the page cannot see whether they were kept.
- Both paper-vault prints and the download re-check the operation after
  their awaits; the shares dialog's print would otherwise print shares
  after a wipe.
- A rehearsal interrupted by Stop or an input switch no longer stays on
  "Opening...".
- The exact AND/OR rule is shown above the Encrypt button, in the
  receipt's words.

Adds test:backup-workflow and tests/browser/workflow-evidence.spec.ts.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant