IDENTITY-CONTRACT: three statements a reader would take as fact, corrected
G-1 records the standing lesson for this document: an interface document should contain no statement a reader will take as fact when it is not yet one. Three remained in it. Section 2 chain diagram read DECIDES against CT 101, which decides nothing and sets no header. Section 5 routing table listed /m/stl as members. Section 5 stated flatly that export is gated today. Section 8 said the opposite of all three, further down, where an outside implementer would reach it second. None of the three is now removed or softened. The scheme stays and each says which it is - where the line falls once enforced, not where it falls now. README: deploy/ added to the layout, absent since 12 SEP. The reading order no longer contradicts PROCESS section 8 and HANDOFF section 0, and points at DIVERGENCES.md. The AGPL section 13 obligation is marked not met, stated in the document that states the obligation. ACCEPTANCE section 7 records that its correction finally landed in HANDOFF section 7, and why parking a correction in a second document is a bad pattern: it sat here for three weeks while the wrong numbers stayed where people read first. Applied by anchored patcher. Suite 643 passed, oracle intact. Documentation only.
This commit is contained in:
@@ -61,10 +61,16 @@ browser
|
||||
-> wg-pk public TLS for dev.mechcomp.kane-il.us
|
||||
-> WireGuard tunnel
|
||||
-> DNAT on srv-b scoped to the hub as source
|
||||
-> CT 101 nginx local staging-CA TLS; DECIDES; sets the headers
|
||||
-> CT 101 nginx local staging-CA TLS; the deciding hop -- see below
|
||||
-> CT 100 :8770 the application
|
||||
```
|
||||
|
||||
**Nothing decides anything today.** CT 101 terminates TLS and proxies. It sets no
|
||||
`X-Mechcomp-Auth-*` header, because §3 is not implemented — see §8. The label
|
||||
marks where the decision belongs once it exists, not a duty CT 101 currently
|
||||
performs. An earlier version of this diagram read `DECIDES`, which an outside
|
||||
implementer would reasonably have taken as a description of what runs.
|
||||
|
||||
Three things about this that are easy to get wrong:
|
||||
|
||||
**CT 101 does not know the public name.** Its `server_name` is
|
||||
@@ -186,6 +192,15 @@ Everything requiring membership lives under `/m/`. Everything else is public.
|
||||
/m/... anything gated later members
|
||||
```
|
||||
|
||||
**This table is the scheme, not the current state.** `/m/` is not gated today and
|
||||
`/m/stl` ships open (§8). The right-hand column says where the line falls once
|
||||
the `location /m/` block exists, not where it falls now. `web/app.py` states the
|
||||
same thing in its own docstring.
|
||||
|
||||
Stated explicitly because `CONSUMER_INTERFACE_GATES.md` G-1 records the standing
|
||||
lesson for this document: an interface document should contain no statement a
|
||||
reader will take as fact when it is not yet one.
|
||||
|
||||
The proxy gets **one** `location /m/` block, written once and not edited again.
|
||||
Gating a new endpoint afterwards is choosing a URL in Python — no proxy change,
|
||||
no shared-infrastructure change, no escalation. Ungating one is the same move in
|
||||
@@ -194,7 +209,8 @@ reverse.
|
||||
That cheapness is the point. It means the placement of the line is a reversible
|
||||
decision rather than a structural one.
|
||||
|
||||
**Where the line is today: export is gated; looking is not.** The catalogue and
|
||||
**Where the line falls once it is enforced: export is gated; looking is not.**
|
||||
The catalogue and
|
||||
the composer are open to anyone. What requires membership is producing an
|
||||
artifact that carries a design record, because the record names an author and an
|
||||
author only means something once somebody established who they are. The site is
|
||||
|
||||
Reference in New Issue
Block a user