CluPilotCloud/tests/Feature
nexxo f8874f32ea
tests / pest (push) Failing after 8m1s Details
tests / assets (push) Successful in 20s Details
tests / release (push) Has been skipped Details
Put customer instances on their own domain, and say which domains are ours
── The zone ────────────────────────────────────────────────────────────────
A fresh install now addresses customer instances under clupilot.cloud rather
than clupilot.com. Not branding: a Nextcloud is third-party software that
strangers sign in to, and on the same registrable domain as the portal it
shares cookie scope, document.domain and CAA with it. The same reason
googleusercontent.com and vercel.app exist.

Existing installations keep whatever the console says — the zone has been a
setting all along. `clupilot:check-zone <zone>` reports what a change would
touch before anything is touched: the DNS records, the monitoring targets,
the certificates and Nextcloud's trusted_domains all carry the old name and
the setting reaches none of them. With no instances in service it says so and
stops. Changing it later is a migration with an outage, and the command says
that too.

── Which addresses are ours ────────────────────────────────────────────────
A new public page at /sicherheit: the domains that belong to us, the rule for
reading an address bar, what we never do, and — the part that matters — what
to do if you have already typed your password into a copy of our sign-in
form. Change it, end every other session, change it wherever else you use it,
tell us. In that order.

Reachable without an account, deliberately: somebody who has just given their
password away is signed in nowhere, and the page they need cannot be behind
the thing they lost.

Linked from the three places a person is when the question comes up: every
mail footer (the mail is the vector), the sign-in form (this is the page a
phishing kit copies, so the real one says which host you are on), and the
site footer.

The domain list is DERIVED from configuration and keyed by what each domain
is for. A list typed into a page would eventually tell a customer that a
phishing domain is one of ours, or that one of ours is not — the same
two-sources-of-truth failure that had the price sheet promising an address on
a domain the company does not own. The operator console is deliberately
absent from it: naming it on a public page tells an attacker where to aim.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-29 16:03:13 +02:00
..
Admin Stop root workers breaking every page, and let the panel be closed 2026-07-29 15:43:54 +02:00
Auth Send an already signed-in operator back to the console, not the portal 2026-07-28 15:55:39 +02:00
Billing Skip the invoice for a full gift, keep it out of revenue, hide its price 2026-07-29 12:41:32 +02:00
Console Check users directly for the reverse operator-identity collision, not just customers 2026-07-28 15:36:29 +02:00
Mail Stop mailing the initial admin password, hold it in the panel until noted 2026-07-28 23:19:20 +02:00
Portal Skip the invoice for a full gift, keep it out of revenue, hide its price 2026-07-29 12:41:32 +02:00
Provisioning Add the SSH identity to the vault, and give deployment config a console page 2026-07-29 00:52:44 +02:00
BillingTest.php feat(portal): billing page — current plan, upgrades, extra storage, add-ons 2026-07-25 13:36:52 +02:00
CartTest.php fix(billing): normalise both sides of the VAT comparison; cast the timestamp 2026-07-26 09:36:07 +02:00
ComponentTest.php feat(portal): Fortify auth + Login/2FA/Dashboard + component kit 2026-07-25 01:20:25 +02:00
ConfirmInModalTest.php Replace native confirm() dialogs with the app's own modal pattern 2026-07-28 19:34:27 +02:00
ConnectionStateTest.php Recover silently from an expired session, and show a connection banner when offline 2026-07-28 21:36:21 +02:00
CustomDomainTest.php Prove a custom domain before serving it, and keep proving it 2026-07-29 14:47:51 +02:00
CustomerTwoFactorTest.php Replace native confirm() dialogs with the app's own modal pattern 2026-07-28 19:34:27 +02:00
DashboardTest.php Stop mailing the initial admin password, hold it in the panel until noted 2026-07-28 23:19:20 +02:00
DeploymentRunsAsTheAppUserTest.php Repair ownership by looking inside, not at the door 2026-07-28 23:53:25 +02:00
DisplayTimezoneTest.php Show times on the operator's clock, keep storing them in UTC 2026-07-27 17:32:21 +02:00
DoubleOptInTest.php Require a confirmed address before an account can use anything 2026-07-28 23:43:20 +02:00
DowngradeTest.php Measure availability, and let a customer move down again 2026-07-27 16:41:15 +02:00
EditInModalTest.php Editing in modals, an update button that is not gated on a stale reading, and a support page that is real 2026-07-27 17:55:49 +02:00
EnsureCustomerActiveTest.php Satisfy Pint on the two new guard-boundary tests 2026-07-28 15:10:58 +02:00
ErrorPagesTest.php Ask the tunnel gateway where it actually listens 2026-07-27 14:43:23 +02:00
ExampleTest.php chore: bootstrap CluPilot control-plane (Laravel 13, Docker stack) 2026-07-25 00:21:30 +02:00
HostStepTest.php Let an update install host packages, without handing out root 2026-07-29 10:27:56 +02:00
IconLayoutTest.php Ask the tunnel gateway where it actually listens 2026-07-27 14:43:23 +02:00
IdentitySeparationTest.php Write down that the console and the portal share no identity 2026-07-28 12:15:13 +02:00
ImpersonationTest.php Refuse a portal login for an address that already belongs to an operator 2026-07-28 14:42:16 +02:00
InstanceMetricsTest.php Measure what the template draws 2026-07-27 16:29:28 +02:00
LandingPriceSheetTest.php Let the owner mark one plan as recommended, from the console 2026-07-29 14:22:22 +02:00
MailTemplatesTest.php Actually issue the invoice when the money arrives 2026-07-29 03:25:56 +02:00
MonitoringStatusSyncTest.php Move the console off /admin, give the status page its own address, and measure monitoring 2026-07-27 06:05:40 +02:00
NewDeviceWarningTest.php Recognise the devices an account signs in from, and warn about a new one 2026-07-28 23:28:34 +02:00
OfficialDomainsTest.php Put customer instances on their own domain, and say which domains are ours 2026-07-29 16:03:13 +02:00
PortalHostTest.php Answer on every name for the website, and send them all to one 2026-07-29 01:29:33 +02:00
PortalTabsTest.php feat(billing): the plan catalogue becomes three tables, and config stops selling 2026-07-26 12:05:56 +02:00
PublicSiteGateTest.php Stop a disabled operator from bypassing the hidden-site gate 2026-07-28 14:42:29 +02:00
ReleaseComparisonTest.php Stop the update agent dying on its own tag arithmetic 2026-07-29 00:00:17 +02:00
ReleaseVersionTest.php Move the console's identity out of the customer table 2026-07-28 10:31:43 +02:00
SeatsTest.php Replace native confirm() dialogs with the app's own modal pattern 2026-07-28 19:34:27 +02:00
SessionListTest.php Show where an account is signed in, and let it sign the other places out 2026-07-28 23:38:17 +02:00
SettingsTest.php fix(portal): enforce customer lifecycle per Codex review 2026-07-25 14:45:03 +02:00
SiteDesignSystemTest.php One wordmark, one typeface, and the address the server actually issues 2026-07-29 14:30:44 +02:00
StatusHistoryTest.php Let an incident be deleted, and start measuring whether the hosts answer 2026-07-29 15:16:48 +02:00
SupportRequestTest.php Editing in modals, an update button that is not gated on a stale reading, and a support page that is real 2026-07-27 17:55:49 +02:00
TrafficTest.php Measure availability, and let a customer move down again 2026-07-27 16:41:15 +02:00
TranslationParityTest.php Ask the tunnel gateway where it actually listens 2026-07-27 14:43:23 +02:00
WelcomeTest.php Give customers two-factor, and stop every button on the settings page reacting at once 2026-07-27 08:48:34 +02:00