Skip to content

Commit 4d04b6b

Browse files
docs(plugin-auth): re-anchor the dead tracker citations to the commits that decided them (#20634)
Part of #20596 Clause-②: no ## What changed This is the third stage of the `domain:services` lane of the dead-citation sweep. It covers `packages/plugins/plugin-auth/src/**` and nothing else. By census, it is the largest package in the lane that no open PR or in-flight claim holds (the claim, `5888562941`, gives the order). Later stages cover the other packages, so this PR says `Part of` and the card stays open. Every comment or docblock site in scope that cited a tracker number answering 404 has been rewritten in ruling C+D's form C (comment 5749154545 on #19123), by the method of stages 1 and 2 (PR #20609 as `422db788a`, PR #20626 as `b80ab579d`). That is **95 sites on 95 lines in 31 files, covering 16 numbers**: - the 52 census sites (all of this package's census sites); - 38 sites in test comments, which the census defers; - 5 sites in the hyphen-joined spelling `#13398-class`, which the gate's extractor does not match at all (see Acceptance notes). Each rewritten line now cites the commit in `origin/main` history that decided what the line describes, and it says in its own words what that commit decided. No ADR or ruling-record file records the decision behind any of the 16 numbers, so every anchor is a commit: **15 distinct shas** (`#11477` and `#12029` share one, because `#12029` was the pull request that settled `#11477`). No number was dropped. Only comments changed. Every touched source file keeps its line count (107 lines out, 107 in, over 31 files), so no line citation into these files moves. 12 of those 107 lines hold no dead citation; they are reflow or a lost referent, listed under Wordings below. No code token moves (see the guard below). **No citation number is added.** Every tracker number on an added line was already on the line it replaces. Over the whole diff, added minus removed is 0 or negative for every number (the gate's own `extractCitations` over the diff: 103 citations removed, 13 added, all 13 kept resolving numbers), and no number is new to the diff. No PR number stands on an added line. Twenty-one dead sites are left on purpose, all of them test titles (see the list below). One more file: a `patch` changeset for `@objectstack/plugin-auth`, because the rewritten docblocks ship (see Changeset below). ## Census: `plugin-auth`, before and after **Instrument (A1).** The gate's own `node scripts/check-issue-citations.mjs --census --json`, read-only and unchanged. The count below is its `allocated-but-absent` findings under `packages/plugins/plugin-auth/`. Each run counts as a reading only because its board frontier equals the newest issue number, read by a separate request just before and just after the run. | reading | tree | board | whole-repo `allocated-but-absent` | plugin-auth sites | lines | files | numbers | |---|---|---|---|---|---|---|---| | before | base `b80ab579d`, run 2026-09-29T10:43:31Z to 10:47:03Z | enumerated, 185 pages, frontier #20629 (newest #20628 before, #20629 after), 18,456 numbers | 1,955 | **52** | 52 | 13 | 12 | | after | head `5ae64e8b8`, run 11:12:05Z to 11:15:37Z | enumerated, 185 pages, frontier #20630 (newest #20630 before and after), 18,457 numbers | 1,903 | **0** | 0 | 0 | 0 | The before count matches the 52 that census `5884031174` read at `f11b5f20`. The whole-repo drop is 52, exactly this diff's census sites. The `resolves` tally is 32,832 in both runs, and `resolves-as-pull-request` (1,984) and `cross-repo-unjudged` (995) did not move either. No run was truncated or discarded: all three enumerations in this stage (two census runs and the supplementary board below) read 185 pages at the newest frontier. **Supplementary instrument, the whole scope.** The census does not read test files or strings, and this stage's scope includes test comments. So a second reading runs the gate's own exported `extractCitations` (whole-file and comment-prose projections) and `classifyCitation` over every `.ts` file under `plugin-auth/src` (178 files). It uses one board, enumerated by the gate's own `enumerateBoard` at 10:50:47Z (185 pages, frontier #20629, equal to the newest). | reading | citations | dead | src comment | test comment | src string | test string | |---|---|---|---|---|---|---| | before, `b80ab579d` | 2,150 | **111** | 52 | 38 | 0 | 21 | | after, `9fd0ebf10` | 2,060 | **21** | 0 | 0 | 0 | 21 | Its src-comment column equals the census's 52, which is the control on the second instrument. The 1,966 resolving, 46 pull-request and 27 cross-repo citations are the same in both readings. Neither instrument sees the 5 `#13398-class` sites; a plain grep for the 16 numbers over `plugin-auth/src` at the head finds only the 21 test titles (and the digits `11477` inside test fixture e-mail addresses and a password, which are code tokens, not citations). ## Per-number table Sites and files count all dead sites the gate sees in scope at the base (comments and strings, tests included). `rewritten / left` counts the sites rewritten and the sites left. Each anchor was read in its message and diff, not only its subject. | number | sites / files | rewritten / left | anchor: what it decided | |---|---|---|---| | `#8676` | 22/6 | 18/4 | `d6e80b28b`: `sys_account.password` and `previous_password_hashes` are flagged `internal: true`, and every reader is recovered through the engine's privileged accessor (the adapter readback table gains `password`; plugin-auth's own raw-engine reads get `recoverInternalFieldsForSystemRead`). Its subject names `#8676` | | `#8734` | 4/2 | 3/1 | `f8eb73601`: the last-admin guard's standing-key lists are bound to what `resolveAuthzContext` actually reads (`STANDING_KEYS_BY_TABLE` / `STANDING_KEY_EXCLUSIONS` and the correspondence gate). Its subject names `#8734` | | `#10165` | 1/1 | 1/0 | `801296050`: lifecycle `ttl` gains an `onlyWhen` row filter (maintainer ruling option A on `#10165`, quoted in its message). The same anchor the spec stages gave this number | | `#10366` | 3/2 | 2/1 | `bbe643c08`: the localhost trusted-origin substitution is gated to non-production. Its diff writes both rewritten lines and its changeset names `#10366` | | `#11343` | 19/8 | 18/1 | `c0714eb5d`: walled platform-admin elevation requires a VERIFIED owner-email match (a fail-closed allow-list over `email_verified`), the bootstrap replays on the verifying `sys_user` update, and the dev-admin seed stamps its account verified. Its message names `#11343` as the card it completes | | `#11477` | 6/3 | 3/3 | `6dd3e6968`: `/admin/remove-user` gets the raw-mount shading `/admin/ban-user` has, so authorization runs before the break-glass guard (ruled option A on `#11477`, as its message records) | | `#11626` | 1/1 | 1/0 | `a6eca9223`: `check:engine-double-contract` admits a single-verb engine double on the contract it DECLARES, a second admission route beside sibling inference. Its diff names that route `#11626` | | `#11640` | 11/6 | 7/4 | `bf8d129b5`: a walled deployment whose declared owner has no verification path gets a loud, named warning at boot, and boot proceeds (maintainer ruling 2026-08-25, option A). Its subject names `#11640` | | `#11741` | 4/2 | 2/2 | `b706af987`: `SendEmailInput` gains an optional `organizationId`, threaded from the producers that hold one (the invitation among them). The same anchor stages 1 and 2 and the spec stages gave this number | | `#11757` | 4/4 | 4/0 | `4d25d22d4`: the rc.1-era `sys_scim_provider` platform object is retired. Every `#11757` site in the tree before it says the object "retires under #11757" | | `#12029` | 2/2 | 2/0 | `6dd3e6968`: `#12029` was the pull request itself; this is its squash commit, the gate-then-delegate mount on `/admin/remove-user` | | `#13398` | 6/2 | 3/3 | `e238c79f0`: the published-sink ruling, that raising a log level must never widen a published sink. No record of the ruling exists in the repo; this commit's pin is the earliest text in history that records it (see Wordings) | | `#14762` | 21/4 | 19/2 | `35e94c96b`: auth OTP SMS and auth mail read the recipient's own `sys_user.locale`, one rung above the request and the deployment default, in the order ruled for `#14788`. Its diff carries `#14762` 24 times | | `#14902` | 3/2 | 3/0 | `61821e54c`: a plain unique index over duplicate rows is loud and non-fatal (the boot continues), and `os migrate plan` stops calling it `safe`. Its message names `#14902` as the card it ends | | `#14998` | 2/1 | 2/0 | `f1e91595f`: the batch-6 admin endpoint graphs load at module top, not inside each clocked case, which removed the cold-import timeout flake | | `#15092` | 2/1 | 2/0 | `9e9f03abe`: `settleSelfRegistrationGrant`'s trailing filter no longer silently DROPS a malformed permission-set row; it refuses. The only commit in history that names `#15092` | Plus 5 `#13398-class` sites the gate does not extract, anchored like the other `#13398` sites: `boot-sign-in-reachability.ts:109`, `:512`, `boot-sign-in-reachability.test.ts:595`, `tenancy-service.ts:249`, `:257-258`. Every cited sha matches exactly one commit (`git rev-parse --disambiguate`, count 1 for each), and every one is an ancestor of the base (`merge-base --is-ancestor`, exit 0 for all 15; the history is complete, `--is-shallow-repository` false, 15,083 commits). A line-origin pickaxe (`git log -S` on each dead line's exact text) found each line entering either in its anchor commit or in a later commit that cites that commit's decision: for example `4d5b4f832` (the operator-provisioned stamp) and `4f65837a7` (the L3 re-anchor) cite `c0714eb5d`'s verified-owner rule, `f074616e6` (invitation locale) cites `35e94c96b`'s stored rung, `8064e6da1` (the has-permission mount) cites `6dd3e6968`'s seam, and `9bd4344e4` carries the `account-identity-preflight` text that cites `61821e54c`. ## Wordings to check - **`#13398` → `e238c79f0`, and not stage 2's `953a81f4a`.** Stage 2 anchored its one `#13398` site at `953a81f4a` (2026-09-02) as the earliest application of the published-sink ruling. In this package, `e238c79f0` (2026-08-31) already records it: its pin in `durability-swallow-repair.test.ts` says raising the level "means widening a published sink — refused as actively harmful by the maintainer's" ruling. It is earlier, and it is in this package, so it is the anchor here. Its own commit message still calls the level "#13398's question", which is why the lines say "the published-sink ruling (commit e238c79)" rather than claiming that commit made the ruling. - **Reflow, 11 lines with no dead site** (every file keeps its line count): - `auth-manager.ts:7554-7557`: 「routes that LEVEL question to the published-sink ruling (commit e238c79) and tells this batch to fix the SILENCE only」, the rest of the paragraph reflowed unchanged (3 lines). - `durability-swallow-repair.test.ts:36-40` (4 lines) and `:527-529` (2 lines): the same substitution, and 「which routes that question there」 became 「which keeps that question」, because "there" pointed at the number. - `tenancy-service.ts:257-258`: 「exactly what the sink ruling (commit e238c79) forbids」 (1 line). - `find-envelope-limb-removal.test.ts:47-48`: 「also carried the silent-DROP shape, and commit 9e9f03a fixed it in the OPPOSITE direction」 (1 line). - **A lost referent, 1 line.** `auth-plugin.ts:2738-2739`: 「(the #12029 worked reading — a shadow is accounted for …)」 became 「(as it read commit 6dd3e69's remove-user mount — a shadow is accounted for …)」. `check:auth-mount-ledger` has counted a shadowing mount since `26dea1495`; the "worked reading" was that PR's application of it to `/admin/remove-user`, which `6dd3e6968` mounts. - `sys-session-ttl-sweep.test.ts:230`: 「the naive policy commit 8012960 existed to make avoidable」, where `801296050` is the `ttl.onlyWhen` filter the ablation removes. - `durability-swallow-repair.test.ts:62`: the flake report became a pointer to the commit that removed the flake (`f1e91595f`), with `#15603` kept beside it. - `auth-manager.ts:5629`: 「the pre-#14762 deployment-default behaviour」 became 「the deployment default, as before commit 35e94c9」. ## The 21 sites left - **Test titles (21 sites).** `describe` / `it` titles, which are string tokens: `admin-remove-user-gate-ordering.test.ts:207`, `:263`, `:298` (`#11477`), `auth-email-locale.test.ts:528` and `auth-manager.test.ts:2545` (`#14762`), `auth-manager.test.ts:1562` (`#10366`), `:2866`, `:2880` (`#11741`), `:4105` and `internal-field-readback.test.ts:219`, `:230`, `:286` (`#8676`), `auth-plugin-walled-owner-verification-path.test.ts:87`, `:193`, `:317`, `:384` (`#11640`), `durability-swallow-repair.test.ts:159`, `:567`, `:670` (`#13398`), `last-admin-standing-keys.test.ts:61` (`#8734`) and `walled-owner-operator-stamp.test.ts:355` (`#11343`). Tokens, left as they were, as stages 1 and 2 left theirs. - There is no non-test string, no generated file and no quoted ruling carrying a dead number in this package. ## Mechanical guard: no code token moves The guard compares the TypeScript parser's leaf nodes, with comments as trivia and JSDoc nodes excluded, base `b80ab579d` against head. Template literals are therefore read in context. It ran over all 31 touched `.ts` files. - Real run: 158,646 base tokens, **0 files with a token change** (exit 0). - Comment control in `auth-manager.ts` (`As above — the flagged column` to `Likewise — the flagged column`): 0 files changed, as expected (exit 0). - Positive control, a code token changed in `auth-manager.ts` (a fourth element added to the `fields` projection of the password-reuse read): DIFFER (exit 1). - Positive control, one digit changed inside a kept test title (`admin-remove-user-gate-ordering.test.ts:207`): DIFFER (exit 1). Every mutation went through `scripts/ablation-replace.mjs`, and each landed (anchor 1 to 0, blob changed). Each restore was proven byte-identical to the HEAD blob (`c0bdef025a39`, `ec83f09f556e`), with `git diff HEAD` empty and a clean tree afterwards. ## Changeset This change ships bytes, so a `patch` changeset for `@objectstack/plugin-auth` (`.changeset/20596-plugin-auth-provenance-anchors.md`) is included. It says only that the provenance comments were re-anchored. Measured on the built package (A3): `files[]` is `dist`, `README.md` and `CHANGELOG.md`. After the build, the rewritten comments reach `dist`: `35e94c96b` appears 8 times in each of `dist/index.d.ts`, `index.d.mts`, `index.js` and `index.mjs`; `f8eb73601` twice in each declaration file; `bf8d129b5` and `e238c79f0` once in each of the four; `d6e80b28b` and `4d25d22d4` twice in each runtime file; `c0714eb5d` and `61821e54c` once in each declaration file; `b706af987` once in each runtime file. Positive control: the unchanged line 「read best-effort off the identity row.」 beside a shipped rewrite is found once in `index.d.ts` and once in `index.js`. A never-written negative phrase appears nowhere. No dead number of the 16 is left anywhere in `dist`. ## Gates (head `5ae64e8b8`) - **Citation judging, as CI runs it:** `pnpm check:issue-citations` (self-test) exits 0. `node scripts/check-issue-citations.mjs` exits 0: the diff-scoped run judged 5 citations across 14 files, and all 5 resolve. - **Doc authoring:** `pnpm check:doc-authoring` exits 0, with the sibling-package prose ids at their baseline and no growth. - **Derived gates:** `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` at `5ae64e8b8` derived 65 commands: all 57 derived at dispatch, plus `check:duration-unit-keys`, `check:engine-double-contract`, `check:logger-receiver-detach`, `check:objectql-double-limit`, `check:query-options-erasure`, `check:type-check-coverage`, `check:type-check-debt` and `check:where-matcher`. It was re-derived after a fresh `git fetch` (`origin/main` `a918fe7fd`, 2 commits ahead, neither touching `plugin-auth`): the same 65. Each ran with its exit code captured before any pipe, and all 65 exit 0. `--ran`, fed each command with its exit code, reports 65 run, 0 NOT MEASURED (a derived zero), 0 unrun, and exits 0. A full `turbo run build` of `./packages/*` and `./packages/*/*` ran first under the shared verify lock (71 of 71 tasks, exit 0), so no gate hit an unbuilt workspace. - **Tests and typecheck, under the verify lock:** - `pnpm --filter @objectstack/plugin-auth test`: 115 files and 2,464 tests pass. That is every test file in the package, the 17 touched ones included. - `pnpm --filter @objectstack/plugin-auth typecheck` exits 0 (`tsc` main, `tsconfig.examples.json`, and `check:test-typecheck` held at its ledger). The main program reads 63 non-test files; the `tsconfig.test.json` program reads all 178 files under `src/`, the 115 test files included, and all 31 touched files are in it (`--listFiles`). - **Lint, as a proven narrowing:** `eslint --no-inline-config --format json` over the 31 touched `.ts` files gives 31 files, 0 errors and 0 warnings. All 31 are in eslint's own population (`isPathIgnored` is false for each). `eslint.config.mjs` never enables type-aware linting (no `parserOptions.project`, as its own line 328 states), so a comment edit here cannot move the verdict on any untouched file. The repo-wide `pnpm lint` is CI's run. - **Control bytes:** `pnpm check:nul-bytes` exits 0, and a raw scan of the 32 changed files for control bytes finds none. ## Acceptance notes - **The gate's extractor does not see a hyphen-joined number.** `CITATION_RE` ends in a lookahead that refuses a following hyphen, so `#13398-class` is not a citation to either the diff gate or the census, dead or alive. This stage rewrote the 5 such sites in `plugin-auth` because they are the same dead number in the same comment prose. At the head, 10 dead `#N-word` sites remain in `packages/**/src` (a raw line scan of `.ts` files against the cached board): `service-automation` 5 (all `#13398-class`), `rest` 2, `plugin-security` 1, `runtime` 1, `spec` 1. The census cannot count them, so a later stage reaching those packages has to look for them by hand. No instrument change here. - **The census instrument did not truncate in this stage.** Three enumerations read 185 pages each at the newest frontier. - **Anchors the next stages can reuse.** These numbers stand elsewhere on the census at the head: `#11343` in `plugin-security` (6) and `types` (2), anchor `c0714eb5d`; `#14902` in `driver-sql` (7) and `cli` (1), anchor `61821e54c`; `#13398` in `service-automation` (4, plus the 5 hyphen-joined sites), anchor `e238c79f0`; `#8734` in `core` (2), anchor `f8eb73601`; `#10165` in `objectql` (2) and `platform-objects` (1), anchor `801296050`; `#11757` in `platform-objects` (2), anchor `4d25d22d4`; `#11741` in `plugin-email` (2), anchor `b706af987`; `#8676` in `platform-objects` (1), anchor `d6e80b28b`. - **Base.** The branch is 2 commits behind `origin/main` (`a918fe7fd`, read at 11:20Z). Neither touches `plugin-auth`, this changeset or any of these 16 numbers, so there was no merge. --- _Generated by [Claude Code](https://claude.ai/code/session_01XY5uCwTjZj7884yYtyur4H)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
1 parent f29c83d commit 4d04b6b

32 files changed

Lines changed: 117 additions & 107 deletions
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
---
2+
'@objectstack/plugin-auth': patch
3+
---
4+
5+
Provenance comments in `plugin-auth` were re-anchored
6+
7+
Comment and docblock lines under `src/` that cited tracker numbers which no
8+
longer resolve on GitHub now cite the commit in this repository's history that
9+
decided the matter, and say in their own words what was decided. Comments
10+
only: no type, schema, export, log or refusal text, or runtime behaviour changes.

‎packages/plugins/plugin-auth/src/account-identity-preflight.test.ts‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@
1818
* declaration without the constraint. That population is real and reachable:
1919
* `syncDeclaredIndexes` logs a plain UNIQUE whose CREATE fails on existing
2020
* duplicates onto the durability channel and lets the boot continue
21-
* (#14902 / #15479), deliberately, so one dirty table cannot take a deployment
21+
* (commit 61821e54c / #15479), deliberately, so one dirty table cannot take a deployment
2222
* down. `SYS_ACCOUNT_NO_UNIQUE` below is that deployment, spelled as a fixture
2323
* — the same shape with the unique index absent.
2424
*
@@ -51,7 +51,7 @@ const SYSTEM = { context: { isSystem: true } } as never;
5151

5252
/**
5353
* `sys_account` as a deployment whose declared `(provider_id, account_id)`
54-
* UNIQUE was never physically created — the #14902 / #15479 population. Only
54+
* UNIQUE was never physically created — the commit 61821e54c / #15479 population. Only
5555
* the columns the probe reads are spelled.
5656
*/
5757
const SYS_ACCOUNT_NO_UNIQUE = {

‎packages/plugins/plugin-auth/src/account-identity-preflight.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ import { keysetWalk } from '@objectstack/types';
3131
*
3232
* ⚠️ "Declared" is not "present". `syncDeclaredIndexes` logs a plain UNIQUE
3333
* whose CREATE fails on existing duplicates onto the durability channel and
34-
* lets the boot continue (#14902 / #15479) — deliberately, so one dirty table
34+
* lets the boot continue (commit 61821e54c / #15479) — deliberately, so one dirty table
3535
* cannot take a deployment down. A database that ever held duplicates therefore
3636
* carries the declaration and not the constraint, and can still hold the class
3737
* today.

‎packages/plugins/plugin-auth/src/admin-has-permission-endpoint.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@
2626
* who is a platform admin under ADR-0068 (`isPlatformAdminUser`, the same
2727
* predicate every shaded `/admin/*` mount trusts) sending a body the vendor's
2828
* own handler would EVALUATE. Every other caller and every other body shape
29-
* is DELEGATED through `AuthManager.handleRequest` — the #12029 gate-then-
29+
* is DELEGATED through `AuthManager.handleRequest` — commit 6dd3e6968's gate-then-
3030
* delegate seam — so the vendor's native bytes stand: an anonymous caller
3131
* still gets the enveloped 401, a plain member still gets its own
3232
* `200 {"error":null,"success":false}` negative (pinned by the non-admin

‎packages/plugins/plugin-auth/src/admin-remove-user-gate-ordering.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
// Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license.
22
//
3-
// #11477 — ORDERING PIN: on `/admin/remove-user` the break-glass guard must run
3+
// commit 6dd3e6968 — ORDERING PIN: on `/admin/remove-user` the break-glass guard must run
44
// AFTER authorization, and the whole `/admin/*` family must agree on that order.
55
//
66
// ── The defect this pins, and why a pin is half the fix ─────────────────────

‎packages/plugins/plugin-auth/src/auth-email-locale.test.ts‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
* caller's own `Accept-Language` first (only when it names a locale in
99
* `AUTH_EMAIL_TEMPLATE_LOCALES`), and the deployment default second. The
1010
* 2026-08-13 ruling had made the deployment default the whole answer and
11-
* rejected `Accept-Language` outright. #14762 then added the rung ABOVE both,
11+
* rejected `Accept-Language` outright. Commit 35e94c96b then added the rung ABOVE both,
1212
* per the #14788 option-D ruling of 2026-09-03: the recipient's own
1313
* `sys_user.locale` (#13881) when the account holds one.
1414
*
@@ -479,7 +479,7 @@ describe('#14319 — authEmailLocaleFromRequest', () => {
479479
});
480480
});
481481

482-
// ── #14762 — the stored rung ───────────────────────────────────────────────
482+
// ── commit 35e94c96b — the stored rung ─────────────────────────────────────
483483

484484
/**
485485
* #14788 was ruled option D on 2026-09-03 (maintainer verbatim 「同意」):

‎packages/plugins/plugin-auth/src/auth-manager.test.ts‎

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1553,7 +1553,7 @@ describe('AuthManager', () => {
15531553
});
15541554
});
15551555

1556-
// #10366 — the localhost-wildcard trio is a DEVELOPMENT convenience and is
1556+
// commit bbe643c08 — the localhost-wildcard trio is a DEVELOPMENT convenience and is
15571557
// gated on `NODE_ENV !== 'production'`. Before the gate the condition tested
15581558
// only emptiness, so a production deployment whose trusted-origin list
15591559
// resolved empty silently CSRF-trusted every `localhost` / `*.localhost`
@@ -2530,7 +2530,7 @@ describe('AuthManager', () => {
25302530
expect(sms.sent[0].body).toContain('verification code');
25312531
});
25322532

2533-
// ── #14762 — the recipient's own `sys_user.locale` as the top rung ──────
2533+
// ── commit 35e94c96b — the recipient's own `sys_user.locale` as the top rung
25342534
//
25352535
// #14788 was ruled option D on 2026-09-03: `sys_user.locale` when set →
25362536
// the request's `Accept-Language` → the deployment default. There is no
@@ -2651,7 +2651,7 @@ describe('AuthManager', () => {
26512651

26522652
// ── #14641 — the SMS INVITE path gets the same rung ──────────────────
26532653
//
2654-
// Its OWN describe, sibling to #14762 above rather than nested inside it:
2654+
// Its OWN describe, sibling to commit 35e94c96b's above, not nested inside it:
26552655
// the reporter path is what the next reader greps, and these pins answer
26562656
// for #14641, not for the card that gave the OTP send its rung.
26572657
describe("#14641 — the invitation SMS reads the invitee's own locale", () => {
@@ -2858,7 +2858,7 @@ describe('AuthManager', () => {
28582858
expect(data.acceptUrl).toBe('http://localhost:3000/_console/accept-invitation/tok456');
28592859
});
28602860

2861-
// #11741 — the invitation producer HOLDS an organization (the invitation
2861+
// commit b706af987 — the invitation producer HOLDS an organization (the invitation
28622862
// row's own organizationId), so it threads that exact value into
28632863
// SendTemplateInput for the sys_email.organization_id stamp. Auth mail
28642864
// that genuinely has no organization (password reset / verification /
@@ -4086,15 +4086,15 @@ describe('AuthManager', () => {
40864086
expect(written).toEqual(['hash:current', 'hash:old1']); // prepend + trim to 2
40874087
});
40884088

4089-
// ---- #8676: the same control, against an engine that actually STRIPS ----
4089+
// ---- commit d6e80b28b: the same control, against an engine that actually STRIPS ----
40904090
//
40914091
// ⚠️ Every test above uses `makeEngine`, which hands back the stored object
40924092
// untouched. That is a faithful model of a strip-less engine — and it is
4093-
// precisely why those tests carry NO information about #8676: once
4093+
// precisely why those tests carry NO information about commit d6e80b28b: once
40944094
// `sys_account.password` and `previous_password_hashes` are `internal:
40954095
// true`, the REAL engine omits both from this read, with no `isSystem`
40964096
// carve-out and in spite of the explicit projection (#7728's design;
4097-
// measured against a real ObjectQL engine + stub driver on #8676, which
4097+
// measured against a real ObjectQL engine + stub driver for commit d6e80b28b, which
40984098
// returned `{"id":"a1"}` for the exact query at `assertPasswordNotReused`).
40994099
// `compareList` then empties, the loop never runs, `PASSWORD_REUSE` is
41004100
// never thrown, and the method's own `catch { return undefined }` means
@@ -4188,7 +4188,7 @@ describe('AuthManager', () => {
41884188
});
41894189

41904190
it('⛔ the recovery is LOAD-BEARING: drop the accessor and the control provably dies', async () => {
4191-
// The falsification arm. This is the pre-#8676 shape — a stripping
4191+
// The falsification arm. This is the shape before commit d6e80b28b — a stripping
41924192
// engine with no privileged accessor — and it is what every assertion
41934193
// in this block would look like if the recovery were removed. Pinned so
41944194
// the four tests above can never pass vacuously: if the strip stopped

0 commit comments

Comments
 (0)