diff --git a/docs/ops/HYPERTWIST_PUBLIC_WEBSITE_CONTENT_AND_OPERATOR_MANUAL_PACKET_2026-06-22.md b/docs/ops/HYPERTWIST_PUBLIC_WEBSITE_CONTENT_AND_OPERATOR_MANUAL_PACKET_2026-06-22.md index 6ebe93b..e167466 100644 --- a/docs/ops/HYPERTWIST_PUBLIC_WEBSITE_CONTENT_AND_OPERATOR_MANUAL_PACKET_2026-06-22.md +++ b/docs/ops/HYPERTWIST_PUBLIC_WEBSITE_CONTENT_AND_OPERATOR_MANUAL_PACKET_2026-06-22.md @@ -258,6 +258,44 @@ Latest same-family public-manual follow-up on `2026-06-24`: - embedded simulator browser shell - native Unreal desktop runtime - optional full-browser simulator branch + +Latest auth-shell hardening follow-up later on `2026-06-24`: + +- the same public/protected website lane now also carries the sibling-site + auth-shell posture more faithfully instead of only reusing auth APIs and + route pages +- HyperTwist now has its own first-party auth-shell backdrop ownership for: + - `/login` + - `/register` + - `/auth/*` +- that backdrop is now present through both: + - a runtime route-sync layer inside the React app + - a first-paint HTML fallback in `website/index.html` +- the `SuperTokensWrapper` posture is now route-aware rather than global: + - anonymous brochure routes no longer pay for the full auth shell merely + because auth is configured + - protected app routes, auth routes, and stored-session continuity still do +- this keeps HyperTwist closer to the intended FamiliarOS/ScriptoriumAI + structure while remaining truthful to HyperTwist's desktop-first product + stance +- focused auth/bootstrap validation stayed green under: + - `npm --prefix website test -- --run src/__tests__/App.bootstrap.test.tsx src/__tests__/auth-shell-backdrop.test.ts src/__tests__/public-auth-pages.test.tsx src/__tests__/route-shells.test.tsx` + - `4` test files passed + - `21` tests passed +- the broader owned web-surface umbrella also stayed green again under: + - `scripts/run-hypertwist-web-surface-validation.sh` + - focused website route/auth/release suite: `12` files, `62` tests passed + - website/server suite: `10` files, `36` tests passed + - website plus `Content/Browser` production audits: `found 0 vulnerabilities` + - website/server retained only the already-documented upstream + `supertokens-node -> nodemailer` residual +- current truthful product reading after this follow-up: + - the public website and protected dashboard still stay complementary to the + desktop runtime rather than pretending to replace it + - the shared auth lineage is now not only conceptual but also structural at + the bootstrap/shell layer + - the next public/web packets can focus on higher-order product polish or + deployment truth rather than missing auth-shell parity - the public `/changelog` lane now also carries an explicit release-rollout checklist so release notes remain tied to package proof, protected download posture, and notices or corresponding-source follow-through instead of diff --git a/website/README.md b/website/README.md index 1c3f25c..63a40f2 100644 --- a/website/README.md +++ b/website/README.md @@ -7,6 +7,8 @@ First-party `hypertwist.app` surface for HyperTwist: - browser-facing operator/account dashboard - protected browser-access, account, and notices routes backed by live auth-health and release-manifest authority - shared SuperTokens auth posture reused from the FamiliarOS and ScriptoriumAI website lane +- route-aware SuperTokens wrapping so public brochure routes do not pay for auth chrome unnecessarily while `/app`, `/login`, `/register`, `/auth/*`, and stored-session continuity still do +- FamiliarOS-style first-party auth-shell backdrop for login/register/auth callback posture, including first-paint HTML fallback plus route-synced runtime ownership - desktop download posture and desktop-link handshake endpoints - server-backed release-manifest authority shared by public and protected download surfaces - Paddle-ready pricing/check-out wiring @@ -61,6 +63,10 @@ manual: - the protected app shell now also carries richer operator-facing browser boundary, account, entitlement, and notices guidance instead of treating those routes as thin placeholders beside the main dashboard +- the auth shell now also behaves more like the sibling first-party sites at + the route/bootstrap layer: auth-specific chrome appears on login/register + posture without wrapping every anonymous public route in the same session + shell ## Local development @@ -115,6 +121,35 @@ and supports `--strict-auth-server-audit` when that residual should block. It now also checks that the website-facing Windows packaged-validation summary is fresh against the checked-in authoritative higher-dimensional package report. +Latest auth-shell hardening follow-up on `2026-06-24`: + +- the website now carries a first-party HyperTwist auth-shell backdrop module + and route sync layer derived from the FamiliarOS/ScriptoriumAI auth shell + posture, but adapted to HyperTwist truth: + - `/login` + - `/register` + - `/auth/*` +- `App.tsx` no longer wraps the entire website in `SuperTokensWrapper` just + because auth is configured; it now wraps only: + - `/app*` + - `/login*` + - `/register*` + - `/auth/*` + - or public routes when a stored local platform session already exists +- `website/index.html` now also carries a first-paint auth-backdrop fallback + so auth-shell chrome is present before React route effects settle +- focused website auth/bootstrap validation stayed green under: + - `npm --prefix website test -- --run src/__tests__/App.bootstrap.test.tsx src/__tests__/auth-shell-backdrop.test.ts src/__tests__/public-auth-pages.test.tsx src/__tests__/route-shells.test.tsx` + - `4` test files passed + - `21` tests passed +- the broader owned web-surface umbrella then stayed green again under: + - `scripts/run-hypertwist-web-surface-validation.sh` + - focused website route/auth/release suite: `12` files, `62` tests passed + - website/server suite: `10` files, `36` tests passed + - website and `Content/Browser` production audits: `found 0 vulnerabilities` + - website/server retained only the already-documented upstream + `supertokens-node -> nodemailer` residual + Current dependency-health truth from the `2026-06-23` hardening pass: - `website/` production audit is clean diff --git a/website/index.html b/website/index.html index b569ab7..80bf83a 100644 --- a/website/index.html +++ b/website/index.html @@ -36,6 +36,54 @@
+