Skip to content

docs: record C7 production hydrated-browser smoke - #13

Merged
LuanTrindade95 merged 2 commits into
mainfrom
claude/estruturar-agentes-20566a
Sep 23, 2026
Merged

LuanTrindade95 merged 2 commits into
mainfrom
claude/estruturar-agentes-20566a

Conversation

@LuanTrindade95

Copy link
Copy Markdown
Owner

Validation-only item C7. No product code, Compose, Dockerfile or nginx config was touched — the diff is brain-only.

What was validated

The production stack (docker-compose.prod.yml) ran twice with two disjoint sets of public values, both different from the localhost defaults, in throwaway Compose projects with their own volumes. The adversarial pass bound its ports to 127.0.0.55 only, so the default origin answered connection refused and any leak would fail loudly.

Proven:

  • Canonical, og:url, og:image, twitter:image and JSON-LD use the configured public origin on the landing, plugin and command pages.
  • /runtime-config.js serves the configured API origin, public origin and Reverb block, with Cache-Control: no-store.
  • After hydration — proven by a typed search producing DOM results and a routerLink navigation with no new document request — all 53 captured requests landed on a configured origin. Zero requests to the default origin.
  • The browser websocket reaches the configured public Reverb host and gets pusher:connection_established, even though the frontend service still pins COMMANDSPHERE_REVERB_HOST: localhost.
  • A forged Host header never reaches canonical or metadata: publicUrlFor() in frontend/src/server.ts builds from COMMANDSPHERE_PUBLIC_ORIGIN alone.
  • POST /api/v1/auth/dev-login answers 403 auth.dev_login_disabled in production, before request validation.

This closes the last open acceptance criterion of Priority 2, "Docker production smoke validates hydrated browser API calls".

Findings recorded, none caused by this item

  • Seeding is broken in the production image: fakerphp/faker is in require-dev while docker/backend.prod.Dockerfile installs --no-dev, so factories calling fake() abort. Now Priority 13.
  • No Content-Security-Policy header is served by SSR, /runtime-config.js or the API. A clean console proves absence of policy, not compliance.
  • The API answers Access-Control-Allow-Origin: *, the Laravel default with config/cors.php unpublished.

Gates

  • Production Docker runtime gate: VALIDATED in both passes, including migrations and Scout index sync.
  • migrate:fresh --seed: FAILED for the reason above, not by regression.
  • Backend and frontend unit, lint and build gates: PENDING — no code changed.

Evidence: brain/handoffs/2026-09-23-production-hydrated-smoke.md.

🤖 Generated with Claude Code

LuanTrindade95 and others added 2 commits September 23, 2026 08:41
Close the last acceptance criterion of Priority 2 with the production
stack evidence: hydrated browser calls, SSR metadata, runtime config,
forged Host header, Reverb websocket and production dev-login.

Record the facts the smoke exposed: seeding is broken in the --no-dev
production image, no CSP header is served anywhere, and the API answers
Access-Control-Allow-Origin: *.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…ntes-20566a

Resolve the backlog conflict in NEXT_ACTIONS and scope the C7 smoke
evidence to 29a7881, the commit it ran on. The CSP observation from the
smoke is superseded by ADR-30, which landed on main afterwards.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@LuanTrindade95
LuanTrindade95 merged commit c4eee46 into main Sep 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant