Commit graph

493 commits

Author SHA1 Message Date
pulse-triage[bot]
e994c41c20 chore(frontend): bind browser proof to integrated candidate
The integration merges preserve the exact browser-tested frontend bytes. Rebind the content-bound receipt to the integration tip so the canonical cumulative range passes the parent-identity guard.

Change-source: pulse-maintainer
2026-09-23 10:42:15 +01:00
pulse-triage[bot]
5d831b8765 fix(web): retain PBS host target across transient snapshots (#1723)
The Backups drawer's Identity and History target is the merged PBS host resource. Correlation was recomputed from each snapshot with no memory, so a live refresh that briefly omitted the correlated host row made the drawer fall back to the PBS service target (agent/<service key>), which has no host history. The target flicked between the host series and the service key until the host row returned.

Retain the last resolved correlation per PBS server and reuse it only across such an omission, and only while the remembered host is still fresh relative to the server, so a genuinely removed or replaced host is not advertised indefinitely. A host row that is present but ambiguous still declines, as before.

Adds unit coverage for retention, staleness and pruning, a drawer regression test, and extends the real-browser guard and fixture to omit the host row and assert the identity rows and History chart survive.

Change-source: pulse-maintainer
2026-09-23 10:27:45 +01:00
pulse-triage[bot]
2c3a6b306a fix(web): keep the drawer tab across transient snapshot changes (#1723)
A live resource snapshot can briefly omit a field that gates a drawer tab, for example a merged metrics target during a refresh. The tab guard reset the active tab to Overview whenever the selected tab was missing, so the reported Proxmox -> Backups History tab silently jumped back to Summary on data refresh. Reset only when the drawer starts showing a different resource; each tab body already renders an availability notice while its tab is transiently unavailable. Adds a regression test covering a snapshot that drops and restores the metrics target, a source guard in ResourceDetailDrawer.history.test.tsx, the unified-resources contract update, and a fresh frontend browser-verification receipt from scripts/check-drawer-tab-retention.cjs (the same check times out on the pre-fix source).

Change-source: pulse-maintainer
2026-09-23 00:55:58 +01:00
pulse-triage[bot]
950c875b6f chore(frontend): bind install proof to integration
The exact candidate merges do not alter the browser-tested production utility. Rebind its content-matching receipt to the final combined parent so canonical cumulative governance verifies the retained proof without re-parenting either reviewed candidate.

Change-source: pulse-maintainer
2026-09-22 18:14:12 +01:00
pulse-triage[bot]
a0861d5f66 chore(frontend): bind install paste proof to tested candidate
The test-only assertion update preserves the browser-tested runtime bytes. Bind the retained content-matching receipt to the completed source-proof candidate.

Change-source: pulse-maintainer
2026-09-22 17:32:16 +01:00
pulse-triage[bot]
097e3386e0 fix(agents): keep copied Unix install commands single-line safe
Use explicit shell separators instead of newline-dependent grammar for command fields. Preserve quoted values, private token files, TLS options and preflight ordering; cover paste normalization and execution failures in the owning regression suite. Refs #2123.

Change-source: pulse-maintainer
2026-09-22 17:27:29 +01:00
pulse-triage[bot]
e8383ed63f chore(frontend): bind browser proof to integrated candidate
The integration merge preserves the exact browser-tested frontend bytes. Rebind the content-bound receipt to that merge so the canonical range passes the parent-identity guard.

Change-source: pulse-maintainer
2026-09-22 16:15:05 +01:00
pulse-triage[bot]
da19341fcd fix(web): keep guest filesystem mount paths readable
Render complete wrapping paths above usage using an opt-in shared detail-row layout. Preserve compact rows and unknown-usage semantics. Include the typed regression fixture, registered primitive and Workloads guardrails, substantive owning contracts and the content-bound five-layout browser receipt in the same candidate commit. Recompose the rejected unshared candidate without changing its browser-tested runtime bytes. Addresses #2121.

Change-source: pulse-maintainer
2026-09-22 14:42:22 +01:00
pulse-triage[bot]
dab8daa9a7 fix(web): preserve PBS datastore identity across snapshot reordering
Detach each rendered datastore from the nested PBS snapshot so independent row reconciliation cannot overwrite another datastore's identity. Cover switching and refreshed History in the component regression and real-browser fixture for #1723.

Contract-Neutral: Restore existing PBS datastore row identity during snapshot reconciliation; no API or canonical ownership change.
Change-source: pulse-maintainer
2026-09-22 12:11:59 +01:00
pulse-triage[bot]
9d6025d386 style(frontend): format the PBS host-history regression test
Prettier wraps the added byAgentKey assertion, which failed the Frontend format:check on the candidate integration pull request. Re-point the browser receipt base at this commit's parent; the cumulative guard compares the receipt at the tip against the tip parent, and the two user-visible frontend sources are unchanged.

Change-source: pulse-maintainer
2026-09-22 10:49:25 +01:00
pulse-triage[bot]
76f96f9906 chore(frontend): refresh browser receipt base to the integration merge
The cumulative browser guard matches the receipt at the integration tip against the tip parent. Re-point base_sha from the candidate tip parent e9a426aeeb to the integration merge a3ad75e78b so the content-addressed receipt for the two frontend sources is accepted.

Change-source: pulse-maintainer
2026-09-22 10:28:06 +01:00
pulse-triage[bot]
98cab1a8bd test(frontend): rebind the candidate browser receipt to both surfaces
The cumulative candidate browser guard compares the receipt at the tip against every user-visible frontend source changed since the candidate base. This candidate carries two: the #2119 alert-card footer class and the #1723 PBS host-history correlation. Record both content-addressed sources, the union of the two offline proof matrices, and re-point base_sha at the tip parent so the guard can match the candidate.

Change-source: pulse-maintainer
2026-09-22 09:49:38 +01:00
pulse-triage[bot]
e9a426aeeb fix(web): correlate PBS host history across guest and agent rows (#1723)
A standalone source=pbs host row and the PVE guest carrying the same agent are one machine. Collapse correlation candidates that share an agent identity and prefer the guest metrics target, whose persisted host series the Backups drawer renders; the PBS service target names the service key and has no host history. Distinct agent identities, or rows without a provable identity, still decline to choose so the drawer cannot substitute an unrelated host. Re-compose the reviewed runtime change with its three subsystem contracts, offline browser fixture, check script and a content-addressed browser receipt in one governed commit.

Change-source: pulse-maintainer
2026-09-22 09:43:00 +01:00
pulse-triage[bot]
41fa79d52b fix(alerts): align the Started run with the alert-card footer (#2119)
The Alerts overview alert-card footer is an items-center flex row whose first child, the Started timestamp, carried its own mt-1. Under items-center that margin shifted the Started run 2px below the adjacent delivery-status run, which is the small text misalignment the reporter underlined in #2119. Remove the child margin; the footer row already carries the top margin, so the two runs share a baseline.

Add a presentation regression test and an offline browser proof that measures the text rects of both runs at desktop and narrow widths.

Contract-Neutral: Behavioral footer-alignment fix; no public-contract or subsystem-shape delta.
Change-source: pulse-maintainer
2026-09-21 14:31:27 +01:00
pulse-triage[bot]
1b422dd1a6 Document maintenance API and repair documentation section links
Lands contributor PR #2067 (head 5eeea72a3a, author rcourtman) as a single maintainer commit on main. The PR documents the authenticated /api/resources/{id}/operator-state maintenance window contract and repairs GitHub-compatible documentation heading fragments.

Composed from the reviewed web-product candidate tree 68465bc48d (candidate 20260921T054028Z-web-product), which resolved the conflicts against main and replaced the unavailable github-slugger dependency with a dependency-free GitHub-compatible heading slugger. The tree is unchanged from that reviewed candidate; only the commit shape differs so the fdb2be15be..HEAD provenance range contains no external PR commit.

Validation retained from that candidate: vite build passed, check-bundle-size.mjs passed (vendor within budget), 61 focused vitest tests passed, and the offline Playwright docs-fragment-navigation run passed with a content-addressed browser-verification.json receipt based at fdb2be15be.

Change-source: pulse-maintainer
2026-09-21 07:23:24 +01:00
pulse-triage[bot]
fdb2be15be chore(frontend): refresh browser receipt base to the candidate tip
The cumulative candidate browser guard matches the receipt committed at the tip against the tip parent. Re-point base_sha from the original base to the tip parent so the content-addressed receipt for usePlatformWindowedItems.ts is accepted.

Change-source: pulse-maintainer
2026-09-21 00:06:21 +01:00
pulse-triage[bot]
6f0dc177c8 fix(alerts): keep grouped-list window estimate off the header (#2130)
The virtual window measured only the top spacer's first sibling. On grouped
surfaces that sibling is a short group header, so the estimate collapsed to
the header height and the mounted window advanced roughly one row per header
height of scroll. The Alert Thresholds card list then dropped a host's rows
while scrolling and its Ctrl-F match count oscillated.

Measure the tallest of the first few rendered siblings so a leading header
cannot collapse the estimate, while uniform tables still measure their real
row height. Add a regression test and offline browser proof.

Change-source: pulse-maintainer
2026-09-20 23:50:19 +01:00
pulse-triage[bot]
958eae0744 fix(workloads): widen filesystem panel in guest drawer
The shared DetailSectionTable span algorithm gives the earlier of the last two compact sections the wider column. GuestDrawerOverview declared Tags before Filesystems, so a guest with tags and disks but no network section rendered Tags two tiles wide and the mount-point list one tile wide, which the reporter found hard to read (#2121). Declaring Filesystems first gives the longer list the readable panel and keeps the short tag list narrow.

Recomposes the reviewed #2121 fix and its Playwright browser receipt into a single commit on the current maintenance base (22fd851e72), because the per-commit browser guard requires the receipt in the same commit as the user-visible frontend source. The GuestDrawerOverview.tsx blob is byte-identical to the previously browser-verified content (sha256 bcfebc20), so the receipt is content-addressed to the same source; the added contract assertion and performance-and-scalability ordering note are unchanged.

Refs: https://github.com/rcourtman/Pulse/issues/2121
Change-source: pulse-maintainer
2026-09-19 22:21:58 +01:00
pulse-triage[bot]
b8c968e23c fix(alerts): align overview stat counts
The Alerts overview stats table right-aligned the value cell, but a row carrying the small critical annotation rendered it inline after the count, pushing that count left of the other rows. Give the annotation its own right-aligned cell so the numeric column lines up, and assert the count cell stays numeric in the 24h regression.

Contract-Neutral: Behavioral alignment fix; no public-contract or subsystem-shape delta.
Change-source: pulse-maintainer
2026-09-19 14:51:56 +01:00
pulse-triage[bot]
10d466e1a3 style(alerts): format warning preference repair
Resolve the PR2087 frontend formatting gate without changing severity behavior or rewriting the reviewed source. Re-run the production-component browser matrix and refresh its content hashes; whole-tree formatting and local TypeScript checking pass.

Change-source: pulse-maintainer
2026-09-14 22:46:12 +01:00
pulse-triage[bot]
e8bbda6f71 fix(alerts): preserve warning-level notification preferences
Retain warning severity through email API save/reload and webhook editing instead of coercing it to all. Add adapter round-trip and webhook edit/save regressions for issue #2069 with alerts, API and notifications contracts. Browser verification covers production components at desktop and narrow widths using synthetic settings; backend filtering is unchanged.

Change-source: pulse-maintainer
2026-09-14 22:36:28 +01:00
rcourtman
982465e63c Show a node's guests from the Proxmox overview row
Selecting a node filters its guests and reveals an off-screen guest
heading without moving results that are already visible. Repeating the selection
clears only the node filter. Keep node details on the
chevron and preserve other guest filters when changing or clearing nodes.

Build node filter options from inventory as well as guests so empty nodes
retain their names and selection after reload. Do not present unrelated
inventory failures as the cause of an empty filtered result.

Refs lane L8. Update the owning interaction and identity contracts.
2026-09-12 17:24:46 +01:00
pulse-triage[bot]
bfae4ce0c8 fix(ui): keep disk mounts in the parent scrolling flow
The nested 140px mount list relies on a thin scrollbar to reveal additional disks, which #2051 reports as invisible in Firefox. Remove that nested scroll boundary so all mounts participate in the existing outer scroll flow without changing data or global scrollbar styling.

Validate short and long lists in light/dark Firefox and Chromium fixtures, including keyboard reachability, and retain aggregate/empty-state component coverage. This is synthetic browser proof, not reporter installation acceptance.

Change-source: pulse-maintainer
2026-09-11 11:26:20 +01:00
rcourtman
3c723569e3 Merge main into source-build update safeguards
Reconcile parallel release-version test fixtures while preserving the
current provider settings changes. Refresh browser verification against
the combined source before landing the diagnostic update safeguards.

Refs #1913
2026-09-10 21:31:38 +01:00
pulse-triage[bot]
e8449477ff fix(settings): restore Ollama Basic Auth configuration
The backend supports authenticated Ollama servers but the provider editor omitted its credential fields. Expose write-only password editing with explicit clearing and preserve unchanged credentials. Verify Settings persistence, authenticated connection tests and the Patrol streaming factory using synthetic endpoints.

Change-source: pulse-maintainer
2026-09-10 18:21:29 +01:00
rcourtman
7f15acfbad Keep diagnostic source builds out of release update flows
Diagnostic versions must keep their exact identity without advertising a published server or agent update target. Reuse the canonical source-build classification and discard cached release offers when runtime identity changes.

Show source-build status and manual image replacement guidance. Verify release and preview controls remain available.

Refs #1913
2026-09-10 17:06:27 +01:00
rcourtman
bd37ae186a Preserve live agent state over saved enrollment history
Saved enrollment records can correlate with a live Proxmox host after a
reinstall. The continuity overlay then replaced its current agent payload
with an older offline identity, hiding metrics and marking the node offline.

Use canonical matching to add only absent continuity resources. Preserve
current identity, telemetry and provider links without deleting history or
changing token admission. Cover repeated reads and identity collisions.

Refs #1913
2026-09-10 16:00:36 +01:00
rcourtman
837a5b8843 Fix manual update freshness and unknown release dates
Manual checks previously bypassed only the browser cache, so a newly
published preview could remain hidden behind a fresh-looking server result.
Carry explicit freshness to the provider, retain prior evidence on failure,
and omit unknown dates instead of rendering year one.
2026-09-10 15:33:53 +01:00
pulse-triage[bot]
07ad2a8ea3 fix(alerts): discard pending history reads after clearing
A history request started before a successful clear can return deleted rows afterwards and repopulate the view. Invalidate those reads and settle loading only after the clear succeeds, preserving history on failure and allowing later refreshes.

Change-source: pulse-maintainer
2026-09-10 06:44:37 +01:00
pulse-triage[bot]
605643b017 fix(web): preserve PBS host history targets in Backups
Backups fetched only PBS service rows, leaving standalone host telemetry unavailable, and rejected agents merged into PVE guests. Include PBS agent rows and reuse the deduplicated Overview inventory for unique correlation without changing the PBS drawer identity. Keep guests without agent telemetry and ambiguous identities excluded. Focused drawer and surface regressions cover missing disk data and canonical history targets.

Change-source: pulse-maintainer
2026-09-10 01:03:55 +01:00
pulse-triage[bot]
50270c2499 fix(web): discard obsolete import impact previews
Invalidate in-flight preview generations when the import plan changes or the editor unmounts. Ignore stale success, error and completion updates so another endpoint cannot inherit the prior request's impact.

The deferred-error regression fails before repair. Record the preview lifetime and unchanged setup authority in both owning contracts, with consumer boundary coverage. All 87 focused tests and two source-built Chromium desktop/narrow interaction cases pass; retain exact-content browser evidence.

Change-source: pulse-maintainer
2026-09-10 00:36:48 +01:00
pulse-triage[bot]
6cddb75fb1 fix(web): wrap entitled organization header on compact screens
Activate the offline default context before mobile organization audits. Preserve visible session controls without page overflow, with real-backend Chromium and WebKit proof.

Change-source: pulse-maintainer
2026-09-09 11:42:59 +01:00
pulse-triage[bot]
7de1195416 fix(web): align webhook test custom fields with saved configuration
Manually entered Pushover aliases were normalised on save but not on test, so the test could exercise a different payload. Apply the same normalisation and retain a failing-before parity regression; 56 focused webhook tests pass.

Change-source: pulse-maintainer
2026-09-08 23:29:31 +01:00
pulse-triage[bot]
6edaa56f4f fix(web): avoid prescribing permissions from update access failures
The update evidence reason represents generic permission errors and HTTP 403, not a verified missing Sys.Audit privilege. Report access denial without prescribing a role change, as illustrated by the new #1802 retest. Preserve unavailable and stale evidence semantics. Both focused presentation and drawer suites pass (6 tests).

Change-source: pulse-maintainer
2026-09-08 21:59:40 +01:00
pulse-triage[bot]
6988e486f2 fix(web): identify notification destination server failures
The queue and health API expose server_error, but the delivery UI treated it as unclassified. Preserve that diagnosis and direct operators to service availability and server logs before retrying retained deliveries. Add focused label and health guidance regression coverage.

Change-source: pulse-maintainer
2026-09-08 12:54:21 +01:00
pulse-triage[bot]
f526f72c21 Merge candidate 20260908T021505Z-web-product
Change-source: pulse-maintainer

# Conflicts:
#	docs/release-control/v6/internal/subsystems/alerts.md
#	docs/release-control/v6/internal/subsystems/frontend-primitives.md
#	frontend-modern/browser-verification.json
#	scripts/check-incident-request-ownership.mjs
2026-09-08 03:36:54 +01:00
pulse-triage[bot]
a222424c63 Merge current upstream incident history before publication
Incorporate protected PR #1973 while preserving every reviewed local alert and notification commit in history. Reconcile its failed-read state with per-request ownership and retain exact combined browser evidence.

Change-source: pulse-maintainer
2026-09-08 03:21:41 +01:00
pulse-triage[bot]
7a915017d4 fix(alerts): preserve request ownership in incident error state
PR #1973 introduced resource incident error state independently of the request lifecycle repair. Reconcile its state with this branch's ownership guards so superseded or disposed reads cannot report a false current failure. Reset clears errors and retry preserves cached history while clearing the failure indicator.

Extend lifecycle assertions for error ownership, retry and superseded success after a current failure. Focused incident hook and panel tests pass: 3 files, 17 tests. Full merged UI browser acceptance remains separate.

Change-source: pulse-maintainer
2026-09-08 03:19:57 +01:00
pulse-triage[bot]
e5ef265c77 fix(alerts): retain ownership of incident history requests
Invalidate pending reads on reset and disposal, and gate success, failure and loading writes per resource. Convert the four reproductions to ordinary tests and retain reset/reopen and stale-failure controls. Qualify the real hook and panel with 14 Chromium lifecycle cases; register that exact browser surface proof without broadening path policies. This does not qualify installed delivery or PR1973's absent error accessor.

Change-source: pulse-maintainer
2026-09-08 02:57:57 +01:00
rcourtman
e2b6fe3b16 Preserve canonical incident history and Assistant handoffs
Filter canonical history before selecting occurrences, preserve source evidence
and expose bounded reads and failures. Reconcile duplicate saved shells without
splitting one alert lifecycle, and keep note identity and canonical risk intact.

Carry attributed operator notes into Assistant. Preserve mobile investigations
across layout changes, transfer composer focus on handoff and keep long event
text readable. Record scoped qualification and its unresolved wider limits.

Refs #1782
2026-09-08 02:08:15 +01:00
pulse-triage[bot]
7eec890025 fix(web): clear explicitly withdrawn Proxmox memory
A canonical snapshot can omit memory after the producer marks its Proxmox
facet unavailable. Retaining the previous display metric hides withdrawal
and leaves a stale percentage visible. Clear that explicit transition in
full and fast merges and emit the corresponding store operation, preserving
ordinary partial omission and trusted canonical metrics including zero.

Pin withdrawal and recovery with adapter tests and desktop/narrow Chromium
acceptance. Workload details remain canonical-only; do not invent raw totals
or Usage UI. Record inspected screenshots and matching subsystem contracts.

Change-source: pulse-maintainer
2026-09-07 23:03:54 +01:00
rcourtman
c501376843 Preserve canonical Patrol planning and outcome continuity
Return persisted planning acceptance or refusal inside the investigation turn.
Keep model judgment separate from action authority and preserve accepted action
identity across provider failures. Enforce actor/request idempotency atomically
and retain complete approval and independent verification context.

Preserve unknown disk evidence, stream whitespace and historical resolution
timestamps. Keep conversation scrolling inside its own panel. Record real-model,
disposable-lab and browser qualification with explicit population limits.

Refs #1782
2026-09-07 17:24:25 +01:00
rcourtman
e37353f937 Remove inferred Assistant continuation gates
Let the configured model choose investigation steps within explicit budgets.
Keep canonical planning, permissions and independent verification authoritative,
and preserve streamed conclusions in conversation history.

Expose recorded action outcomes so cached inventory cannot stand in for an
approval or execution receipt. Retain full plan context and make the exact
action review reachable from Assistant, including on narrow screens.

Refs #1782
2026-09-07 14:06:58 +01:00
rcourtman
2a7019b0fa Use typed Proxmox runners and preserve cross-clock action evidence
Proxmox planning and dispatch now require a unique credential-admitted typed
runner with durable receipts. Development authentication preserves explicit
bearer identity so runner activation keeps its tenant and credential scope.

Preserve observer and receiver timestamps from their separate clocks instead
of rejecting or rewriting valid evidence. Keep completed execution separate
from stale or inconclusive verification, and label independent observations
accurately in action reviews.

Verified with targeted race suites, action-review tests and frontend build,
plus a real Assistant start plan and approved VM110 start/stop with independent
Proxmox confirmation. Final action reviews passed Playwright at 1440, 900 and
390 pixels, including retained completed, rejected and expired history.
2026-09-07 12:00:48 +01:00
rcourtman
3a4a3fd62b Preserve native filesystem evidence and Patrol action history
Expose confined, identity-bound filesystem observations through the shared
resource pipeline so investigations can distinguish an exhausted container
mount from unrelated host capacity. Keep unavailable measurements explicit.

Isolate alert-history reads from durable writes and reuse one chronological
fold across polling. Catch up through bounded durable event IDs so simultaneous
readers do not replay every retained snapshot. Retain expired actions when
investigation outcomes move back to needs attention, and keep attached
Assistant context focused.

Record live storage diagnosis, healthy and dependency controls, approved and
rejected Docker outcomes, source-bound browser proof and exact test limits.
Missing-access continuity, VM dispatch completion and remaining Assistant
orchestration defects stay open in the redesign plan.
2026-09-07 09:45:31 +01:00
rcourtman
df0735cc79 Integrate current main with verified Patrol action history
Preserve the incoming delivery-health ordering and demo install-link
changes alongside the qualified Patrol action history. Retain prior
source bindings and record the merged build and browser checks so the
shared proof receipt reflects the integrated tree.
2026-09-06 21:44:13 +01:00
rcourtman
3853124a39 Keep Patrol action history consistent with recorded outcomes
Refresh durable investigation lifecycle from authoritative actions while
preserving completed evidence. Keep resolved history reviewable and label
recorded plan facts separately from action outcomes. Follow all resource
pages during qualification and record live approval, rejection and storage
semantic-review results. Integrate current main and preserve its alert
ordering correction.
2026-09-06 21:23:01 +01:00
rcourtman
f23553f825 Link the demo banner back to the install steps
pulserelay.pro sends curious visitors to the public demo, and the demo
was a dead end: once inside, the only way back to installing Pulse was
the browser's history. The demo-mode banner now ends with "Run Pulse on
your own hardware", opening the site's setup steps in a new tab. It is
install guidance rather than an upsell, so it belongs in demo mode where
commercial surfaces are otherwise hidden.

The read-only notice keeps its own element so the existing text lookup
and dismiss behaviour are unchanged. Verified on a DEMO_MODE=true mock
backend behind Vite at 1280x800 and 390x844: the link renders after the
notice, wraps cleanly on a phone, and carries target _blank with rel
noopener noreferrer.

Contract-Neutral: demo banner copy and link only; no public API, config, or contract surface changes
2026-09-06 20:40:26 +01:00
rcourtman
57ead19484 Preserve Patrol evidence and surface action submission failures
Live funded qualification found hidden tool results and misleading action
submission outcomes. Share the result-bearing transcript across stored chat
and product history, render the retained evidence, and distinguish captured
proposals from broker acceptance. Keep review usable while Patrol is paused.

Record Gemini route pricing and exact qualification limits. Integrate current
main and repeat browser proof for the incoming login flow. Approved/rejected
recovery remains unqualified without the development command agent.
2026-09-06 20:09:54 +01:00
rcourtman
8729bca778 Sign demo-mode visitors in instead of showing them demo/demo
"Try the live demo" on pulserelay.pro landed on a login form with the
demo credentials printed above it. The demo runtime is read-only and its
credentials are public, so making a first-time visitor type them was pure
friction at the moment of curiosity.

When the security status reports demo mode, the login page now submits
demo/demo itself, once per browser tab, showing "Signing you in to the
demo…" in the demo banner while the request is in flight. The marker
lives in sessionStorage under SESSION_STORAGE_KEYS.DEMO_AUTO_LOGIN. The
logout handler sets the same marker to "suppressed" right after it clears
session storage, so a visitor who signs out lands on the form (and stays
there across a reload) rather than being signed straight back in; a new
tab signs in again. SSO callbacks (?oidc / ?saml), first-run setup and a
non-demo runtime never trigger it, and a rejected sign-in falls back to
the normal form with the server's error.

The credential request moves out of the submit handler into
submitCredentials so the form and the automatic path share one code path
and one set of error messages.

Verified on a demo-mode backend (DEMO_MODE=true, mock data, demo/demo)
behind Vite at 1280x800 and 390x844: automatic sign-in from a fresh
context, Logout to the form with the marker suppressed, reload keeps the
form, manual sign-in from the form, second fresh context signs in again,
and a stubbed 401 shows the form with the error. Login and
useAppRuntimeState test files pass (41 tests).

Contract-Neutral: demo-mode login convenience on the existing /api/login flow; no public API, config, or contract surface changes
2026-09-06 17:58:48 +01:00