Repository navigation
fix(settlement): close lane B review follow-ups - #43
Merged
Merged
Conversation
Three findings were carried rather than fixed during B05 and B06. The live-evidence document described the Arc Mainnet profile as OFFLINE_PROTECTED, which is not a state the code has. It now states what packages/arc-adapter/src/profiles.ts actually carries: disabled, verification UNPUBLISHED, and no chain, RPC, explorer, or token value at all. A sponsor reading the document should see the same words as the code. The settlement UI refused secrets by field name only, so a credential arriving under a benign name would have reached a component prop. PEM private keys, JWTs, and bearer tokens are now refused by value shape wherever they appear, including inside arrays, while transaction hashes, addresses, and digests keep rendering. Fields that render verbatim now reject control characters. That covers the identity fields, timestamps, digests, and evidence enums, which all print without sanitizeText by design. The accessibility scan disables axe's color-contrast rule because jsdom cannot compute rendered colours, which left that claim unproven. A static audit now reads the palette tokens and surfaces from the stylesheet and asserts WCAG AA, so a future palette edit that drops below it fails.
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
oneshot | 043160c | Sep 08 2026, 10:43 PM |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes the review findings that were carried rather than fixed during B05 and
B06. Three of them, plus what seven Gate A rounds surfaced while fixing them.
The live-evidence document described a state the code does not have. It said
the Arc Mainnet profile was
OFFLINE_PROTECTED; that string appears nowhere inthe codebase.
packages/arc-adapter/src/profiles.tscarriesenabled: false,verification: 'UNPUBLISHED', and no chain ID, RPC, explorer, or token value atall. The document now says exactly that, so a sponsor reads the same words the
code uses. The neighbouring
FALLBACK_DIRECT_RECOVERYis a real Lane C stateand is untouched.
The settlement UI refused secrets by field name only. A credential arriving
under a benign name would have reached a component prop. PEM private keys, JWTs,
and bearer tokens are now refused by value shape wherever they appear, including
inside arrays, while transaction hashes, addresses, and digests keep rendering.
Fields that render verbatim now reject control characters — identifiers,
timestamps, digests, and evidence enums all print without
sanitizeTextbydesign. A payload missing its required collections fails as a
SanitizationErrorthe route renders deliberately, rather than as aTypeErrorfrom the first
.mapthat touches it.The contrast claim was unproven. The axe scan disables
color-contrastbecause jsdom cannot compute rendered colours.
test/contrast.test.tsnow readsthe palette tokens and every text surface from the stylesheet and asserts WCAG
AA. Every colour clears it, the tightest being
--mutedat 7.88:1, and a futurepalette edit that drops below 4.5 fails the test.
Scope and acceptance criteria
Not a milestone packet. Acceptance is the four findings above, each with tests
asserting the failure direction.
Product and security invariants
Invariant notes:
presentational slice and one documentation line. No settlement path, no
external effect, no state transition.
stays narrow to PEM, JWT, and bearer shapes so ordinary evidence — hashes,
addresses, digests — keeps rendering; widening it further would start
rejecting the data the slice exists to display.
Validation
Independent review evidence
Gate A — exact candidate tree before push
Seven rounds. Round seven is the tree that was pushed.
2dcc2423bc0d221ecreated_at,retrieved_at,digest; audit missed literal surfaces5a05e775statewas covered0e057354develope863a08bTypeErroron missing arrays33c2cdd8TypeError; made it a structured failure48391e4968675764632627716e580988a271c13ddecd4a0d9fe70fd09a23eea95cc5e199930d6d3b043160c925cec0e21e5d7e5ac7b4a3f299abfa1bfree-pi-clideepseek-v4-flashVERDICT: PASSassertNoControlCharacterswould throw a rawTypeErrorif an arrayelement were null. The contract bounds elements to objects, so impact is
nil today.
readTokensin the contrast test lets a later declaration of a tokenoverride an earlier one, matching CSS cascade order for the base rule but
not for media-query overrides.
A recurring theme across these rounds is worth stating plainly: three findings
were prose claiming more than the code did. Each was closed by making the code
true rather than by softening the sentence.
Gate B — exact remote PR head
043160c925cec0e21e5d7e5ac7b4a3f299abfa1bdecd4a0d9fe70fd09a23eea95cc5e199930d6d3bfree-pi-clideepseek-v4-flashVERDICT: PASSassertNoControlCharactersdereferences array elements without a nullcheck; the contract bounds elements to objects, so impact is nil today.
readTokensin the contrast test lets a later token declaration win,which matches the cascade for the base rule but not for media-query
redeclarations. No media query currently recolours an audited token.
Milestone readiness: scope and acceptance criteria PASS, tests and required
checks PASS, security/privacy/secrets PASS, documentation and operations PASS,
ready for human review PASS. Settlement invariants are recorded NOT APPLICABLE:
this is a read-only presentational slice plus one documentation line, with no
settlement path, external effect, or state transition in the diff.
Agent policy / repository-policyand all applicable CI checks pass.Risk and rollback
Residual risks:
another shape is still caught by key name, not by value.
Rollback: revert the commit. The documentation line returns to its previous
wording and the slice returns to key-name-only redaction; nothing depends on the
new exports.
Human merge