Skip to content

Admin password card: records, roadmap and MAP - #212

Merged
itsdestin merged 30 commits into
masterfrom
session/sudo-prompt
Sep 27, 2026
Merged

itsdestin merged 30 commits into
masterfrom
session/sudo-prompt

Conversation

@itsdestin

Copy link
Copy Markdown
Owner

The workspace half of itsdestin/youcoded#580 (admin password card):

  • Questions and review decks (5 rounds + a confirm deck), the signed 25-row contract, the grader's verdicts and the answered acceptance deck, archived under docs/archive/design/2026-09-25-admin-password/.
  • The technical design and its three review rounds, the per-task reviews, the code review and the UX reviews, archived.
  • The roadmap item is closed. Two follow-ups stay filed: API keys and .env values, and GitHub/SSH logins. A busy-button contrast item was also filed.
  • A new MAP row for the feature's code, tests and records.
  • The admin-password capture plan in scripts/ui-review/plans/.

🤖 Generated with Claude Code

itsdestin and others added 30 commits September 25, 2026 23:13
… card

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…r logins filed as follow-ups

Records the answered questions deck.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… the design review deck

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ext, running-as-admin strip)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… inside the field)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…/rejected; design revised

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…n revised

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… order

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…fef407d6)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…cba)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… busy-button contrast item

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… now mechanical

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…acceptance deck spec

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e unreadable

Destin found on his real machine that every real sudo call was refused
(reason: proc-read-failed) because the parent check read /proc/<sudoPid>/exe
via readlink — unreadable (EACCES) for a genuine setuid-root process even
when our real uid matches its real uid, since the kernel clears "dumpable"
on any privilege-elevating exec. Confirmed empirically against /proc/1.
Documents the redesigned check (effective/real uid from status, comm, a
fixed never-PATH-derived location list for a bare argv[0]) and the accepted
residual weakening vs. the original readlink-bound check.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Documents the three follow-on requirements found once the feature ran on
a real machine: (1) one AdminCapability value ('card'/'no-password-only'/
'windows') settled once at app start, before any session may exist, so
the Bash description's sudo sentence is byte-identical for the app's
whole life and never wrong for a session started in the first moments;
(2) never fail silently — a refused/failed password request now surfaces
one plain-language line to both the model and the command's card when the
call can be identified; (3) resume/handoff to a fresh app process carries
no admin state — capability and the description text are both re-read
live, never persisted with a session.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…chine sudo sentence

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…the roadmap item; MAP row

Drops the raw capture folder (runs/) committed by mistake; the decks keep their
own images. Links repointed to docs/archive/.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ng it

navigate() returns before the document exists; on a loaded CI runner the
controls test read a null body (failed youcoded-dev#212's check).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@itsdestin
itsdestin merged commit 0813a38 into master Sep 27, 2026
1 check passed
@itsdestin
itsdestin deleted the session/sudo-prompt branch September 27, 2026 23:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant