4040 Commits

Author SHA1 Message Date
rcourtman cba3b3e857 Resume v6.2.0 release execution 2026-08-09 16:54:18 +01:00
rcourtman 1213b6d918 Stabilize remaining API performance proofs 2026-08-09 16:52:19 +01:00
rcourtman 53d9d00d8d Claim v6.2.0 release execution 2026-08-09 16:14:40 +01:00
rcourtman fe14b195d0 Stabilize API performance release proofs 2026-08-09 16:12:19 +01:00
rcourtman be18f99d24 fix(rbac): make SSO user access manageable 2026-08-09 13:36:07 +01:00
rcourtman 70f7ca9f6f fix(pbs): skip superuser-only node lookup for tokens 2026-08-09 12:25:07 +01:00
rcourtman 2a95ae35c3 Record v6.2.0 rehearsal stop condition 2026-08-09 12:11:07 +01:00
rcourtman e2a2e7d4d2 Record v6.2.0 Windows signing exception 2026-08-09 11:05:20 +01:00
rcourtman e9904157e7 Prepare v6.2.0 stable release 2026-08-09 10:43:19 +01:00
rcourtman b9811cdf53 fix(settings): prevent credential autofill in provider controls 2026-08-09 10:31:03 +01:00
rcourtman c33ed56f1f fix(alerts): preserve backup posture for offline guests (#1693) 2026-08-09 10:08:40 +01:00
rcourtman 16179dd0a5 Improve 6.2 usability across core workflows 2026-08-09 01:16:15 +01:00
rcourtman 63a0adf9ac Repair rejected agent credentials safely 2026-08-09 00:51:38 +01:00
rcourtman 4e1d2f6d5d fix(telemetry): scale adoption reporting 2026-08-09 00:35:40 +01:00
Richard Courtman 1b804cf206 fix(release): wait for convergence metadata 2026-08-08 22:18:39 +01:00
Richard Courtman e245aa11e2 fix(release): add activation-only recovery 2026-08-08 22:10:49 +01:00
Richard Courtman 894e0eb213 chore(release): prepare v6.2.0-rc.11 2026-08-08 20:26:15 +01:00
rcourtman fe5dfd11ec docs(monitoring): define HTTP probe fallback contract 2026-08-08 20:03:19 +01:00
rcourtman 52fbcfd341 fix(release): allow draft asset smoke access 2026-08-08 18:57:11 +01:00
rcourtman 76e07be290 chore(security): complete Cloudflare token replacement 2026-08-08 17:50:04 +01:00
rcourtman 71aa9b3ffc chore(security): reopen Cloudflare replacement rotation 2026-08-08 17:37:43 +01:00
rcourtman 81ccca17a5 Prepare v6.2.0-rc.10 release 2026-08-08 17:34:07 +01:00
rcourtman afe0f900e5 chore(security): record credential containment closure 2026-08-08 17:26:21 +01:00
rcourtman 5ff0855882 revert(commercial): restore self-hosted opt-in posture 2026-08-08 16:48:19 +01:00
rcourtman e391d631d1 fix(api): validate hosted magic-link URL before token mint 2026-08-08 12:07:40 +01:00
rcourtman 9c23e10858 fix(api): validate hosted diagnostics URL before token mint 2026-08-08 11:34:49 +01:00
rcourtman f7ca17bbc1 chore(governance): release hosted installer-origin claim 2026-08-08 10:56:31 +01:00
rcourtman 2030d71fd9 fix(api): fail closed for hosted installer origins 2026-08-08 10:56:19 +01:00
rcourtman 679f00b25c chore(governance): release installer-origin claim 2026-08-08 10:36:13 +01:00
rcourtman 9ac11eeb54 fix(api): harden PVE and PBS installer origins
Route config-owned install commands and setup-script artifacts through the canonical trusted request-origin resolver. Preserve configured URL precedence and add endpoint-level adversarial coverage for token-bearing commands.
2026-08-08 10:35:52 +01:00
rcourtman 76f433c2f8 chore(governance): release request-origin security claim 2026-08-08 09:50:26 +01:00
rcourtman 860f639f3b fix(api): validate request-derived command origins 2026-08-08 09:42:21 +01:00
rcourtman 8ff64e0dee Fix PBS node identity retry classification 2026-08-08 09:39:02 +01:00
rcourtman d45e597dbb fix(governance): block prerelease on credential containment 2026-08-08 05:55:12 +01:00
rcourtman 6fb9634423 chore(governance): release settings responsive claim 2026-08-08 05:27:11 +01:00
rcourtman 70162c0295 fix(settings): prevent responsive panel clipping 2026-08-08 05:27:08 +01:00
rcourtman e434466269 fix(security): verify SSH hosts during proxy cleanup 2026-08-08 05:18:55 +01:00
rcourtman 790a7d8ce1 chore(governance): release worktree helper claim 2026-08-08 04:08:44 +01:00
rcourtman ebff6f9946 fix(governance): restore advertised worktree helpers 2026-08-08 04:08:35 +01:00
rcourtman 60c1c51eb9 fix(workloads): serve viewer-safe inventory health 2026-08-08 03:36:55 +01:00
rcourtman d1f687c0ea fix(governance): enforce frontend dependency audits 2026-08-08 03:26:36 +01:00
rcourtman 633d3117f7 fix(governance): fail closed on unsupported commercial evidence 2026-08-08 03:11:12 +01:00
rcourtman d130d00867 fix(release): make customer promotion convergent 2026-08-08 02:36:28 +01:00
rcourtman 541c9be7fd fix(websocket): keep oversized recovery baseline-free 2026-08-08 01:35:49 +01:00
rcourtman 98ecfb3f10 fix(updates): gate update-status polling by route authority 2026-08-08 01:21:44 +01:00
rcourtman 7a0f410508 fix(settings): gate all admin-only panels 2026-08-08 01:19:44 +01:00
rcourtman 6d8a509376 fix(settings): serve runtime display settings to viewers 2026-08-08 01:10:40 +01:00
rcourtman fbee92614a fix(release): restore verifiable MSP evaluation delivery 2026-08-08 01:04:07 +01:00
rcourtman b0759d20d7 fix(release): activate before mutable customer promotion 2026-08-08 00:58:18 +01:00
rcourtman 27b4d98bc0 fix(workloads): stop offering viewers an infrastructure page they cannot open
The "No workload inventory available" empty state told every session to
"Review source credentials, permissions, and collection status in Settings
→ Infrastructure" and rendered a button to /settings/infrastructure. Since
755a88878 gated that nav item on the infrastructureRead capability, a
non-admin viewer cannot open the page — and once inventory source health is
served at monitoring:read, a viewer with a broken source lands on this exact
state and is pointed at a door that is locked for them.

Gate the call to action on the destination's own capability. Reusing
infrastructureRead rather than a second predicate is what keeps the link and
the nav gate from drifting apart. Without it the copy now names the action a
viewer can actually take: contact an administrator.

The signal did not exist outside Settings — infrastructureRead only reached
useSettingsAccess's local fetch, which runs when Settings mounts and so is no
help to a page deciding whether to link there. Publish it from the
/api/security/status resolve that useAppRuntimeState already performs on
mount, alongside the sessionCapabilities sync that hangs off the same call.
No new request is added. Unresolved sessions keep the link, matching how
settingsNavVisibility treats an unresolved capability set, so an admin never
flickers through the restricted copy.

The banner itself, the admin path, and the monitoring:read inventory-sources
call are all unchanged. The surface's inline fallback now defers to the
shared presentation helper instead of duplicating the copy, so the gate
cannot be bypassed by whichever path renders.

Verified on a scratch instance against real proxy-auth sessions: the viewer
(detailLevel authenticated, infrastructureRead false) gets the reworded copy
and no link at 1280x800 and 375x812, while the admin (privileged) is
byte-identical to before. Because the empty state is only reachable by a
viewer once inventory health is served at monitoring:read, the live exercise
ran with that branch's route present.
2026-08-07 22:57:16 +01:00