Rotated the self-owned Gitea login password end-to-end via the new
lab/rung4-gitea-browser harness: backup-gated (Hard Rule 1) -> pre-change
login(OLD) -> change-form submit -> new stored to gopass -> verified by
browser re-login AND independent API re-auth. GiteaSite promoted to
ProofLiveReal (proof-as-data).
Three real-site fixes surfaced by the live-fire:
- sites.go: Gitea login + "Update Password" buttons carry no type=submit
ATTRIBUTE (only the default DOM property), so CSS [type=submit] misses;
select by class / the account form's sole button instead.
- rod.go: Click now waits for the post-submit navigation to settle before
the success text is read (a remote round-trip, unlike the instant
in-process test) — else Text() resolves against the pre-submit page.
- rod.go: new RodDriver.Insecure (--ignore-certificate-errors) for the
self-signed / Tailscale-fronted host (browser analog of curl -k).
Suite green + -race clean; docs (BROWSER-ROTATION.md §9, BROWSERROT-PLAN.md)
and OVERSEER-STATUS updated.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Mirrors the Hard Rule 5 softening (kept in the local CLAUDE.md): rotation scope
is provable per-credential authorization (self-owned OR recorded client consent),
not operator ownership — enabling managed client rotation. Second factors are
never bypassed/harvested/auto-submitted/simulated; challenges hand off to the
live account holder. Stuffing/takeover primitives stay structurally absent.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Extends the Phase A-tier-1 site-side rotation engine with an optional Node
browser-sidecar and a deterministic self-heal tier, all proven LIVE-VM against
the local lab change-password form. go-rod stays the default; the sidecar is a
swap-in Driver behind the same Session/Driver/Rotator interfaces — no spine
change, backup + verify-new-before-revoke-old + proof gates all apply unchanged.
M-B1 sidecar parity: internal/browserrot/sidecar/ (index.js JSON-RPC over stdio,
patchright real-fingerprint Chromium, playwright-core fallback) + sidecar.go
Driver/Session. A shared test harness runs go-rod and the sidecar through the
identical live rotation proof.
M-B2 stealth: patchright removes navigator.webdriver; humanized input (Bezier
mouse paths + per-key typing jitter, no ML trajectory generation per plan §5).
M-B3 self-heal: Healer interface + heal-retry fill/click/text wrappers; on a
rotted selector, heal.js relocates the field from DOM structure ONLY (never a
value) and the engine rewrites + persists the recipe (recipes.go RecipeBook)
so the next run is Tier-1 again. Deterministic heuristic is the proven Tier-2;
Stagehand LLM strategy is opt-in + UNPROVEN. Leak-check asserts no secret ever
reaches a heal request (redacted IPC transcript).
Secret seam documented honestly: fill carries base64 secret bytes across exactly
one local stdio boundary, typed and wiped, never logged/persisted/sent to a
model. MFA/CAPTCHA still degrade to the human worklist (Hard Rule 5).
14 tests green, -race clean; lab/lab-provision-browserrot.sh proves both drivers.
M-B4 (first REAL self-owned site) deliberately NOT started — needs per-credential
authorization (safe-candidate ladder).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>