Skip to content

Lock the Support bundle security and acceptance contract #603

Description

@frankieramirez

Question

What security, backend, frontend, and end-to-end acceptance checks must an implementation pass before Comicarr may restore the Support bundle instruction in its bug-report template?

Cover authentication and CSRF behavior, archive manifest and redaction assertions, supported runtime paths, concurrency and cleanup, binary download behavior, UI states, failure handling, and regression protection.

Settled UI input

Specify the Settings Support bundle interaction places one Support bundle group in Settings → About with an ordered Create → Inspect → Share disclosure sequence and an accessible confirmation dialog. The binary helper validates the fixed response contract before dispatching a short-lived Blob download. The observable state machine covers idle, confirming, creating, complete, partial, canceled, network interruption, concurrent 409, retryable unavailable/generation failure, terminal disclosure validation failure, auth/CSRF, navigation/unmount, focus return, live-region announcements, and object-URL cleanup. Documentation must rename CarePackage and stop claiming the bundle contains config, database, environment, or logs.

Metadata

Metadata

Labels

wayfinder:grillingWayfinder ticket: HITL grilling session

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions