docs: record C7 production hydrated-browser smoke - #13
Merged
Merged
Conversation
Close the last acceptance criterion of Priority 2 with the production stack evidence: hydrated browser calls, SSR metadata, runtime config, forged Host header, Reverb websocket and production dev-login. Record the facts the smoke exposed: seeding is broken in the --no-dev production image, no CSP header is served anywhere, and the API answers Access-Control-Allow-Origin: *. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…ntes-20566a Resolve the backlog conflict in NEXT_ACTIONS and scope the C7 smoke evidence to 29a7881, the commit it ran on. The CSP observation from the smoke is superseded by ADR-30, which landed on main afterwards. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Validation-only item C7. No product code, Compose, Dockerfile or nginx config was touched — the diff is brain-only.
What was validated
The production stack (
docker-compose.prod.yml) ran twice with two disjoint sets of public values, both different from thelocalhostdefaults, in throwaway Compose projects with their own volumes. The adversarial pass bound its ports to127.0.0.55only, so the default origin answered connection refused and any leak would fail loudly.Proven:
og:url,og:image,twitter:imageand JSON-LD use the configured public origin on the landing, plugin and command pages./runtime-config.jsserves the configured API origin, public origin and Reverb block, withCache-Control: no-store.routerLinknavigation with no new document request — all 53 captured requests landed on a configured origin. Zero requests to the default origin.pusher:connection_established, even though thefrontendservice still pinsCOMMANDSPHERE_REVERB_HOST: localhost.Hostheader never reaches canonical or metadata:publicUrlFor()infrontend/src/server.tsbuilds fromCOMMANDSPHERE_PUBLIC_ORIGINalone.POST /api/v1/auth/dev-loginanswers403 auth.dev_login_disabledin production, before request validation.This closes the last open acceptance criterion of Priority 2, "Docker production smoke validates hydrated browser API calls".
Findings recorded, none caused by this item
fakerphp/fakeris inrequire-devwhiledocker/backend.prod.Dockerfileinstalls--no-dev, so factories callingfake()abort. Now Priority 13.Content-Security-Policyheader is served by SSR,/runtime-config.jsor the API. A clean console proves absence of policy, not compliance.Access-Control-Allow-Origin: *, the Laravel default withconfig/cors.phpunpublished.Gates
migrate:fresh --seed: FAILED for the reason above, not by regression.Evidence:
brain/handoffs/2026-09-23-production-hydrated-smoke.md.🤖 Generated with Claude Code