Skip to content

Say "password or recovery shares" in the stale-verify notice (usability S5) - #243

Merged
404SecNotFound merged 6 commits into
mainfrom
claude/serene-carson-0739mv-s5-credentials
Sep 29, 2026
Merged

404SecNotFound merged 6 commits into
mainfrom
claude/serene-carson-0739mv-s5-credentials

Conversation

@404SecNotFound

Copy link
Copy Markdown
Owner

Usability finding S5 from docs/reports/USABILITY-2026-09-29.md (#238).

Merge after #242. Based on main directly and built on top of #235 to #242. Until those land, the diff also shows them. Once they merge, it shows only e020c8d.

The problem

When a password or shares were typed after a verify, the notice read "Changed since: credentials". That is the page's word, not the owner's.

What changes

The notice now reads "password or recovery shares". The value is the VerifyChange string in src/lib/verify-evidence.ts, which the page shows as it is. 14-verify-stale.png is recaptured.

Checks

  • test:backup-workflow (88) and verify-evidence.spec.ts check the new words. The browser test also requires that "credentials" is gone.
  • Restoring the old word fails two unit checks.
  • verify-evidence and verify-confinement specs pass (10 tests). tsc and test:screenshots pass.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr


Generated by Claude Code

404SecNotFound and others added 6 commits September 29, 2026 04:54
Section 06, part g. capture-screenshots.mjs recaptures every README and
walkthrough shot from the production export, and now also:
- takes 07-decrypt-detection.png with Format detail on, since the README
  says it shows the parameters read back from the header;
- adds walkthrough-5-steps.png, placed in WALKTHROUGH.md Part 2 with
  what each step state means;
- adds 13-recovery-tested.png and 14-verify-stale.png for the notes.

docs/reports/USABILITY-2026-09-29.md records one reviewer reading the
captured screens: one defect found and fixed, six copy and layout
findings left open with a recommendation each.

The fixed defect: after testing a backup on the Decrypt tab, the
Recovery tab said the Encrypt form's content had changed. The input
type, text box and chosen file are shared with the Decrypt tab, so its
input was read as the Encrypt form's. Content and input type are now
compared only while the form is on the Encrypt tab.
recovery-test-keeps.spec.ts checks the Recovery tab after a text-mode
and a file-mode test.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Usability finding S2. With Format detail off, the default since
Section 06c, the pane still said it would itemise the container
"header byte by header byte", and its button read "Show the header it
will write", but the itemisation shows no header bytes at that level.

The copy and the button now follow the switch. Off: "its version, its
ways in and its layout" and "Show what it will write". On: the byte
wording, which is true then.

workflow-expert-view.spec.ts reads both. palette-audit.mjs matches
either button label. 01-landing.png is recaptured.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Usability finding S7. "Format detail (header bytes, offsets, KDF
parameters)" wrapped to two lines in the container pane's header.

The label is now "Format detail". What it shows is in an info tooltip
beside it, and in the switch's accessible description so a screen
reader hears it without opening the tooltip. The pane is not inside the
form's TooltipProvider, so it gets its own.

workflow-expert-view.spec.ts checks the label, the accessible name and
the description; removing the description fails it. The shots whose
band includes the pane are recaptured.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Usability finding S3. "Check saved copy" and "Prepare recovery" wrapped
in the three-column grid, so the second row's labels and state words
sat at different heights.

The labels are now "Saved copy" and "Recovery test". Each step is also
two grid rows, label on top and state at the bottom; steps in one row
stretch to the same height, so their state words share a line even
where a label still wraps, as "Recovery test" does at 1180px.

A new test in workflow-steps.spec.ts measures the rows at the
screenshot width. Restoring the old CSS fails it. The tests and
WALKTHROUGH.md use the new labels; 01-landing.png and
walkthrough-5-steps.png are recaptured.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Usability finding S4. The saved-copy step said "then check the copy"
without saying how. Its sentence now names both ways, before and after
a download or print has started: load the saved file on the Decrypt
tab and verify it, or photograph every printed symbol on the Recovery
tab.

test:backup-workflow checks both sentences; the old wording fails.
walkthrough-5-steps.png is recaptured.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
Usability finding S5. When a password or shares were typed after a
verify, the notice said "Changed since: credentials", the page's word
rather than the owner's. It now says "password or recovery shares".

test:backup-workflow and verify-evidence.spec.ts check the new words;
restoring the old one fails the unit checks. 14-verify-stale.png is
recaptured.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GbCLpWTtk1prQYV8z6rYHr
@404SecNotFound
404SecNotFound merged commit ec81068 into main Sep 29, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant