Adversarial Appearance default returns a saved system scheme for a new User #378

Closed
opened 2026-09-29 00:47:08 +00:00 by kayg · 4 comments
Owner

The one-time adversarial run created a fresh local instance and a new User. Before the probe saved appearance settings, GET /api/v1/appearance returned auto_scheme: {"mode":"system","location":null}. The check at tests/adversarial/attack.py:647-660 expects auto_scheme to be null.

This result came from job/touch-369 after its one merge from dev, during a high-load shared-host run. Please confirm if the system scheme is an intentional default or a persisted setting. Keep the existing test expectation until the owner decides. The touch-369 job made no Appearance API changes.

The one-time adversarial run created a fresh local instance and a new User. Before the probe saved appearance settings, `GET /api/v1/appearance` returned `auto_scheme: {"mode":"system","location":null}`. The check at `tests/adversarial/attack.py:647-660` expects `auto_scheme` to be `null`. This result came from `job/touch-369` after its one merge from `dev`, during a high-load shared-host run. Please confirm if the system scheme is an intentional default or a persisted setting. Keep the existing test expectation until the owner decides. The touch-369 job made no Appearance API changes.
Author
Owner

Starting review of #378 on job/small-bugs-3, based on dev at dfb5964a2fcf13dc8b9a50a319eee09bc386f322. I will inspect the route and adversarial expectation; the issue asks to preserve that expectation pending an owner decision.

Starting review of #378 on `job/small-bugs-3`, based on `dev` at `dfb5964a2fcf13dc8b9a50a319eee09bc386f322`. I will inspect the route and adversarial expectation; the issue asks to preserve that expectation pending an owner decision.
Author
Owner

#378 finding: The issue records that a fresh User receives auto_scheme: {"mode":"system","location":null} before saving appearance settings, while the existing probe expects null. The issue explicitly asks the owner to decide whether the system scheme is an intentional default or a persisted setting. I left the API and test expectation unchanged; this item remains skipped pending that decision.

#378 finding: The issue records that a fresh User receives `auto_scheme: {"mode":"system","location":null}` before saving appearance settings, while the existing probe expects `null`. The issue explicitly asks the owner to decide whether the system scheme is an intentional default or a persisted setting. I left the API and test expectation unchanged; this item remains skipped pending that decision.
Author
Owner

Finished review of #378. HEAD: 4720cac4d2.

Skipped code changes pending the owner decision requested by the issue: a new User currently receives auto_scheme: {"mode":"system","location":null} before saving preferences, while the probe expects null. I did not change API behavior or the existing expectation.

Web gate output (verbatim result lines):

bun run --cwd apps/web check

$ node scripts/check-type-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json
Text sizes and UI shape values use shared role tokens.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/small-bugs-3/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

bun run --cwd apps/web test

FAIL  |component| src/lib/components/analytics/widgets/StatRow.svelte.test.ts > StatRow summary cards > toggles all four cards together and remembers the mode
Error: Test timed out in 5000ms.

Test Files  1 failed | 136 passed (137)
     Tests  1 failed | 888 passed (889)
error: script "test" exited with code 1

The sole Web test failure was the 5-second timeout above in merged Analytics StatRow coverage. I did not change its expectation. No Rust source changed, so no Rust crate gates ran. cargo clean output: Removed 7066 files, 4.0GiB total.

Finished review of #378. HEAD: 4720cac4d20747c4ccf514d94117d03ec5d95067. Skipped code changes pending the owner decision requested by the issue: a new User currently receives auto_scheme: {"mode":"system","location":null} before saving preferences, while the probe expects null. I did not change API behavior or the existing expectation. Web gate output (verbatim result lines): bun run --cwd apps/web check ``` $ node scripts/check-type-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json Text sizes and UI shape values use shared role tokens. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/small-bugs-3/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings ``` bun run --cwd apps/web test ``` FAIL |component| src/lib/components/analytics/widgets/StatRow.svelte.test.ts > StatRow summary cards > toggles all four cards together and remembers the mode Error: Test timed out in 5000ms. Test Files 1 failed | 136 passed (137) Tests 1 failed | 888 passed (889) error: script "test" exited with code 1 ``` The sole Web test failure was the 5-second timeout above in merged Analytics StatRow coverage. I did not change its expectation. No Rust source changed, so no Rust crate gates ran. cargo clean output: Removed 7066 files, 4.0GiB total.
Author
Owner

Owner decision (2026-09-30): System is the correct default colour scheme for a new User. Classify the matrix expectation accordingly; no product change.

Owner decision (2026-09-30): **System** is the correct default colour scheme for a new User. Classify the matrix expectation accordingly; no product change.
kayg closed this issue 2026-09-30 09:31:12 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#378
No description provided.