| Next revision | Previous revision |
| provenance:security:authentication [2026/09/11 07:14] – New page: working log for Security:Authentication — the inclusion rule, the 184-candidate hand audit, five probes plus a full-text recall pass, folds and residue, 95 quote checks, external sources and rejections, four review passes, and the scripts with t karel.kubicek.claude | provenance:security:authentication [2026/09/11 07:18] (current) – Count this section's own table in the render check. Authored by Claude karel.kubicek.claude |
|---|
| | **The ''poster'' paper {[tchokodeu2024_poster]}** | IN, flagged in its verdict reason as a poster whose figures are preliminary | OUT for being two pages. It is the only paper here whose frame is organisations rather than a ranking list, which is worth showing | | | **The ''poster'' paper {[tchokodeu2024_poster]}** | IN, flagged in its verdict reason as a poster whose figures are preliminary | OUT for being two pages. It is the only paper here whose frame is organisations rather than a ranking list, which is worth showing | |
| | **Publishing "nobody uses an LLM"** | Published, with the year-by-year corpus counts and the thin-slice caveat in the same paragraph | Withhold it. The claim rests on an enum over a provisional slice, and "nobody" is the kind of word a probe should not be allowed to produce — which is why it is stated as an enum count over the population, not as a probe result | | | **Publishing "nobody uses an LLM"** | Published, with the year-by-year corpus counts and the thin-slice caveat in the same paragraph | Withhold it. The claim rests on an enum over a provisional slice, and "nobody" is the kind of word a probe should not be allowed to produce — which is why it is stated as an enum count over the population, not as a probe result | |
| | |
| | ===== After Publishing: What the Rendered Page Showed ===== |
| | |
| | Source-level checks pass on a page that renders wrong, so both pages were verified against the rendered DOM after saving, not against their wikitext. |
| | |
| | ^ Check ^ Result ^ |
| | | **The bibliography was stale, silently.** The content page first rendered **24 reference entries for 51 distinct citekeys**, numbered up to [51] with gaps — every inline marker resolved, so nothing looked broken. bibtex4dw had served a cached parse of ''literature:bibliography'' that predated the 27 new entries | Fixed by requesting ''?purge=true'' on the bibliography and then on each citing page. The content page now renders **51 of 51** with no gaps, and ''security'' renders its four new keys | |
| | | Content page structure | 11 h2, 21 h3, 12 tables, 131 table rows, both boxes as ''div''s, **0 red links**, no leftover literal markup | |
| | | Provenance page structure | 16 h2, 22 h3, 15 tables (this one included), 13 ''pre'' blocks — 12 file blocks and one code block — 23 reference entries, **0 red links** after fixing one namespace-relative ''%%[[artifacts]]%%'' | |
| | | The escaped citekey | ''%%{[key]}%%'' renders as literal text rather than resolving, which is the point of the escape | |
| | | Site-wide red-link gate | ''node scripts/sitemap.mjs'' — 174 pages, 4 promised-but-missing, all 4 declared on [[:roadmap]], **0 undeclared**, exit 0 | |
| |
| ===== Review Passes ===== | ===== Review Passes ===== |
| | 2 | The CTAP row named 2.3 (Proposed Standard, 2026-02-26) and missed that **CTAP 2.3.1 has been in Working Draft since 2026-05-29**, published to the specs directory in August | **Accepted and fixed.** The row now carries both | | | 2 | The CTAP row named 2.3 (Proposed Standard, 2026-02-26) and missed that **CTAP 2.3.1 has been in Working Draft since 2026-05-29**, published to the specs directory in August | **Accepted and fixed.** The row now carries both | |
| | 3 | The Microsoft Entra citation was dated 2026-08-26, which is an ''updated_at'' metadata value whose matching commit edits a shared include; the page itself displays "Last updated on 2026-06-23" | **Accepted and fixed.** The footnote now gives the displayed date and explains the discrepancy — which Pass 2 read the other way round, so the footnote records both readings | | | 3 | The Microsoft Entra citation was dated 2026-08-26, which is an ''updated_at'' metadata value whose matching commit edits a shared include; the page itself displays "Last updated on 2026-06-23" | **Accepted and fixed.** The footnote now gives the displayed date and explains the discrepancy — which Pass 2 read the other way round, so the footnote records both readings | |
| | 4 | Six URLs inside the //reproduced script output// are dead (a 401 anonymous-review link, three 404s, a 502, a 403) | **Accepted as informational, not fixed.** They are artifact links the **papers themselves** declared, reproduced verbatim inside a ''%%<file>%%'' block. Rewriting them would falsify the audit trail; the rot is the finding, and [[artifacts]] is the page about it | | | 4 | Six URLs inside the //reproduced script output// are dead (a 401 anonymous-review link, three 404s, a 502, a 403) | **Accepted as informational, not fixed.** They are artifact links the **papers themselves** declared, reproduced verbatim inside a ''%%<file>%%'' block. Rewriting them would falsify the audit trail; the rot is the finding, and [[:artifacts]] is the page about it | |
| | — | Tally | 31 of 34 external claims verified correct, including every GitHub date via the commits API rather than ''pushed_at'', the FIDO MDS 429 reproduced on three retries, and the Web Almanac's zero WebAuthn mentions | | | — | Tally | 31 of 34 external claims verified correct, including every GitHub date via the commits API rather than ''pushed_at'', the FIDO MDS 429 reproduced on three retries, and the Web Almanac's zero WebAuthn mentions | |
| |
| * The roadmap row this page closed: [[:roadmap]], with its own log at [[provenance:roadmap]] | * The roadmap row this page closed: [[:roadmap]], with its own log at [[provenance:roadmap]] |
| * The neighbour that owns login-as-an-instrument: [[Programming:Registration]] and [[provenance:programming:registration]] | * The neighbour that owns login-as-an-instrument: [[Programming:Registration]] and [[provenance:programming:registration]] |
| | |
| | ====== References ====== |
| | |
| | The same shared bibliography as the content page; this log adds no entries of its own. |
| | |
| | <bibtex bibliography></bibtex> |
| |