The owl has finally left the tower.
Commit 26d4407 has been committed and pushed to master with the following spell:
MB724: welcome mbweb behind sixteen protective charms 🏰🛡️
This development checkpoint brings the MB723 and MB724 work into the public Mediabot tree:
3.4dev-20260905_102117MB723 turns the Mediabot web console into a supported development component rather than a collection of experimental corridors hidden behind a tapestry.
The console now provides:
mbweb.service;npm ci;The live operational rehearsal successfully completed:
Apache remained active and unchanged throughout the operation, while every IRC bot remained safely asleep in its own dormitory. 🦉
MB724 adds the cross-cutting security gate for the supported Mediabot 3.5 surface.
Its audit now enforces 37 fail-closed invariants across 16 security axes, covering:
The final MB724 validation completed with:
The Doctor database session was explicitly read-only, metrics remained confined to a bounded loopback endpoint, and no service lifecycle, database, grant, Git or private-file mutation occurred during the MB724 exercise.
The code was ready, but the local commit spellbook briefly mistook two JavaScript configuration references for embedded credentials:
password: env.MBWEB_DB_PASS || ''secret: config.sessionSecretIt also classified the public Apache example and systemd unit incorrectly.
The local, Git-ignored commit.sh helper was therefore repaired so that it can distinguish a map leading to a secret from the secret itself. Literal credentials remain strictly forbidden and are still automatically removed from the staging area.
The helper now also recognises these narrowly bounded public artifacts:
install/apache/*.conf.exampleinstall/systemd/*.serviceThis repair remained local and was not included in the public commit.
Most importantly, the successful full suite was preserved and not rerun merely because the commit helper had stumbled over its own robes.
MBWEB is now committed as part of the supported Mediabot 3.5 development surface.
The final pre-commit full-suite gate, FULL01, has passed. MB719 remains the next open acceptance concern, while MB722 convergence remains blocked until its remaining prerequisites are satisfied.
This is still a development checkpoint: no stable version, release archive or tag has been published.
GitHub currently reports two moderate Dependabot findings on the default branch. They remain a separate dependency-maintenance follow-up; the MBWEB deployment audits reported no high or critical npm vulnerability.
For now, the castle gates are closed, the rollback portkeys have been tested, the owls are undisturbed, and MBWEB is finally where it belongs. 🏰🪄🦉
You must be logged in to reply.