Two of task 19's re-pointed assertions were checking the built page for
tokens only the legacy page has, and both were hidden behind the
full-guide snapshot failure because verify.mjs stops at the first throw.
- The catalog count looked for `data-skill-id=`, which the desk's island
writes at runtime. Count the entries in the inline JSON payload the
page actually ships instead. Still 24.
- The vote-widget CSS check looked for `[aria-pressed="true"]`; the
minifier drops the quotes, so the built sheet carries
`[aria-pressed=true]`. Match either form.
Also re-baselines the full-guide rendered-text snapshot. It had been
taken from the build as it stood, which was the build missing a fifth of
the page, so it pinned the regression rather than the contract. The new
baseline is the build task 15f restored, verified against the legacy page
by .agents/scripts/rendered-text-diff.mjs: en 432/432 and pt 431/431,
missing 0, extra 0, order clean.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Reinstate all 42 legacy facts as output or authoritative-source contracts, retain output snapshots, and set the 84-assertion floor. Extend the audit count without changing site content or components.
Verify rendered routes, translations, CSS dependencies, variables, and built CSS values. Keep the original assertion count; do not alter site components or fixtures.
The skills-review desk is static, so "which draft would you ship?" needs a
stateful counterpart. vote-service is a small Go API on its own pod backed by
a JSON file on a ReadWriteOnce PVC, with one active vote per skill per source
IP as the anti-abuse rule and CORS (ALLOWED_ORIGIN) as the caller boundary.
Deployment notes that differ from the obvious path, all confirmed against the
live cluster: the image is side-loaded with `ctr image import` plus
`imagePullPolicy: Never` because kubelet has no credentials for the Nexus ref;
the pod is pinned to `kubernets` because the hostpath PV takes a nodeAffinity
for whichever node first binds it; and public exposure is Caddy on the VPS,
not the cloudflared tunnel.
The ingress controller runs with `use-forwarded-headers` off, so nginx
overwrites X-Forwarded-For with its own peer — every visitor would collapse
into one voter and each skill would cap at one vote overall. Caddy stamps the
true remote address into X-Client-IP, which nginx forwards untouched, and
clientIP() reads that first. Scoped to this app rather than flipping the
global flag, which would change client-IP handling for every other ingress.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- Add 'Source on Gitea' link next to every 'Open the X lab' link,
pointing to https://git.marcospaulo.dev.br/netcracker/ai-for-dummies/...
- Same download links added to both SilverBullet guides (Preview +
Source on Gitea) under Path A and Path B.
- Tighten standalone verify rule: only block external <script src> and
<link rel=stylesheet href>. Plain <a href=https://...> hyperlinks are
not runtime dependencies.
- Unslop pass across all deck text, SilverBullet EN/PT, hands-on/rules
header/label/README: kill triplets, dramatic single-word sentences,
'matrix below / looks good / cuts the opposite failure' rhetoric.
Header subtitle now reads 'Toggle rules. Same task, different
coverage.' (was 'different leash').
verify: all six checks pass.