Files
EpicNext-Cms/docs/superpowers/evidence/2026-08-30-housekeeping-final.md
T
Simo 43470ebf82
CI / check (pull_request) Failing after 10s
CI / deploy (pull_request) Skipped
CI / release (pull_request) Skipped
feat(housekeeping): unify complete rebuild in gated preview
2026-08-31 20:37:51 +02:00

5.2 KiB

Housekeeping final cutover verification

Verified on 2026-08-30 CEST on branch codex/housekeeping-complete after production commit 222535e1.

Outcome

The Housekeeping replacement is complete and the administration UI has been cut over atomically to /ase. The former /admin, /mod, and /ase-next UI trees are absent and do not redirect. Internal /api/admin/* endpoints remain intentionally available behind their existing permission gates.

This report verifies the branch and local production build. It does not claim that the branch is merged, deployed, or healthy in production.

Delivered cutover

  • 2b8f73a9 moved the canonical workspace to src/app/ase, removed the three legacy UI roots, removed the preview gate, and deleted the superseded UI and dependency surface.
  • 222535e1 closed the final authorization findings: logo writes require admin.settings.edit; generic media deletion cannot traverse into nested asset namespaces; hierarchy bypasses use isSuperAdmin; bulk ban/unban require admin.users.ban; every bulk target is checked before mutation; configured rank identifiers are no longer capped at 7 and must exist in permission_ranks.
  • The historical migration matrix remains as an auditable 137-row record while the physical legacy-root scanner reports zero retained UI pages.

Final automated gates

Gate Result Evidence
Toolchain Pass pnpm toolchain:check: Node.js 26.8.1 aligned with .nvmrc.
Migration and runtime parity Pass 137/137 historical rows valid; legacy UI pages present 0; runtime discovered/mapped/verified 137/137/137; removals 2.
Housekeeping suite Pass 109 test files and 843 tests passed.
Security regression set Pass The focused People production workflow passed 60/60 tests after the review-driven coverage additions. The earlier four-file final-finding set passed 95/95.
Full suite Pass 262 files passed and 3 skipped; 1,649 tests passed and 5 skipped. Coverage: statements 31.53%, branches 26.16%, functions 36.55%, lines 32.90%.
TypeScript Pass pnpm typecheck exited successfully.
Dead-code boundary Pass pnpm knip reported no included file, dependency, dev-dependency, unlisted dependency, or binary findings.
Changed-file quality Pass Biome checked all 9 final-review files with no remaining fixes; git diff --check passed.
Production build Pass Next.js 16.3.3 compiled, typechecked, generated 129/129 pages, and exposed /ase plus /ase/[domain]/[[...segments]] as the only administration UI routes.

The build used an ephemeral local AUTH_SECRET because production validation correctly rejects the development environment without one. It was set only in the build process and was not written to .env.

Route and access probes

The post-cutover local server returned:

Route Result
/admin 404, no redirect
/admin-next 404, no redirect
/ase-next 404, no redirect
/mod 404, no redirect
/ase 307 to /login for an anonymous request
/api/health 200

The production route manifest independently confirms that /ase is the only administration UI root while the retained /api/admin/* backend endpoints remain present.

Visual evidence boundary

The authenticated pre-cutover workspace passed all 24/24 domain and viewport combinations at 1440x900, 1024x768, 390x844, and 320x568; details and screenshot locations are recorded in 2026-08-26-housekeeping-pre-cutover.md.

The final cutover moved that verified workspace to /ase without redesigning the rendered workspace. A new authenticated post-cutover browser session was not created because doing so would have required minting or impersonating a privileged session. Final validation therefore combines the existing authenticated visual matrix with the post-cutover source move, route manifest, automated UI tests, and anonymous access probes. No live mutation was submitted.

Known non-blocking environment debt

  • REDIS_URL is unset locally, so the build warns that multi-instance rate limits, settings cache, and JWT invalidation would fall back to process memory. Production must provide Redis.
  • Turbopack warns that dynamic translation-file access in mutation-runtime-external.ts broadens filesystem tracing. The build still completes, but deployment bundle size should be monitored.
  • The repository-wide pnpm lint remains affected by the existing Windows CRLF baseline. The final changed-file Biome gate and git diff --check pass; no unrelated whole-repository formatting churn was introduced.

Independent review

A second read-only review of 222535e1 found no Critical or Important findings and assessed the change as ready to merge. Its two Minor recommendations were both implemented: hierarchy denial now runs against ban, unban, currency, and badge bulk operations, and the production workflow now proves a successful super-admin assignment to an existing configured rank above 7.

Release state

The implementation and local release gates are complete. The branch is suitable for continued review in draft PR #52; merge and deployment remain separate operator decisions.