# Housekeeping final cutover verification Verified on 2026-08-30 CEST on branch `codex/housekeeping-complete` after production commit `222535e1`. ## Outcome The Housekeeping replacement is complete and the administration UI has been cut over atomically to `/ase`. The former `/admin`, `/mod`, and `/ase-next` UI trees are absent and do not redirect. Internal `/api/admin/*` endpoints remain intentionally available behind their existing permission gates. This report verifies the branch and local production build. It does not claim that the branch is merged, deployed, or healthy in production. ## Delivered cutover - `2b8f73a9` moved the canonical workspace to `src/app/ase`, removed the three legacy UI roots, removed the preview gate, and deleted the superseded UI and dependency surface. - `222535e1` closed the final authorization findings: logo writes require `admin.settings.edit`; generic media deletion cannot traverse into nested asset namespaces; hierarchy bypasses use `isSuperAdmin`; bulk ban/unban require `admin.users.ban`; every bulk target is checked before mutation; configured rank identifiers are no longer capped at 7 and must exist in `permission_ranks`. - The historical migration matrix remains as an auditable 137-row record while the physical legacy-root scanner reports zero retained UI pages. ## Final automated gates | Gate | Result | Evidence | | --- | --- | --- | | Toolchain | Pass | `pnpm toolchain:check`: Node.js `26.8.1` aligned with `.nvmrc`. | | Migration and runtime parity | Pass | `137/137` historical rows valid; legacy UI pages present `0`; runtime discovered/mapped/verified `137/137/137`; removals `2`. | | Housekeeping suite | Pass | `109` test files and `843` tests passed. | | Security regression set | Pass | The focused People production workflow passed `60/60` tests after the review-driven coverage additions. The earlier four-file final-finding set passed `95/95`. | | Full suite | Pass | `262` files passed and `3` skipped; `1,649` tests passed and `5` skipped. Coverage: statements `31.53%`, branches `26.16%`, functions `36.55%`, lines `32.90%`. | | TypeScript | Pass | `pnpm typecheck` exited successfully. | | Dead-code boundary | Pass | `pnpm knip` reported no included file, dependency, dev-dependency, unlisted dependency, or binary findings. | | Changed-file quality | Pass | Biome checked all `9` final-review files with no remaining fixes; `git diff --check` passed. | | Production build | Pass | Next.js `16.3.3` compiled, typechecked, generated `129/129` pages, and exposed `/ase` plus `/ase/[domain]/[[...segments]]` as the only administration UI routes. | The build used an ephemeral local `AUTH_SECRET` because production validation correctly rejects the development environment without one. It was set only in the build process and was not written to `.env`. ## Route and access probes The post-cutover local server returned: | Route | Result | | --- | --- | | `/admin` | `404`, no redirect | | `/admin-next` | `404`, no redirect | | `/ase-next` | `404`, no redirect | | `/mod` | `404`, no redirect | | `/ase` | `307` to `/login` for an anonymous request | | `/api/health` | `200` | The production route manifest independently confirms that `/ase` is the only administration UI root while the retained `/api/admin/*` backend endpoints remain present. ## Visual evidence boundary The authenticated pre-cutover workspace passed all `24/24` domain and viewport combinations at `1440x900`, `1024x768`, `390x844`, and `320x568`; details and screenshot locations are recorded in `2026-08-26-housekeeping-pre-cutover.md`. The final cutover moved that verified workspace to `/ase` without redesigning the rendered workspace. A new authenticated post-cutover browser session was not created because doing so would have required minting or impersonating a privileged session. Final validation therefore combines the existing authenticated visual matrix with the post-cutover source move, route manifest, automated UI tests, and anonymous access probes. No live mutation was submitted. ## Known non-blocking environment debt - `REDIS_URL` is unset locally, so the build warns that multi-instance rate limits, settings cache, and JWT invalidation would fall back to process memory. Production must provide Redis. - Turbopack warns that dynamic translation-file access in `mutation-runtime-external.ts` broadens filesystem tracing. The build still completes, but deployment bundle size should be monitored. - The repository-wide `pnpm lint` remains affected by the existing Windows CRLF baseline. The final changed-file Biome gate and `git diff --check` pass; no unrelated whole-repository formatting churn was introduced. ## Independent review A second read-only review of `222535e1` found no Critical or Important findings and assessed the change as ready to merge. Its two Minor recommendations were both implemented: hierarchy denial now runs against ban, unban, currency, and badge bulk operations, and the production workflow now proves a successful super-admin assignment to an existing configured rank above 7. ## Release state The implementation and local release gates are complete. The branch is suitable for continued review in draft PR #52; merge and deployment remain separate operator decisions.