feat(legal): terms and privacy pages, login consent recorded per version, re-consent gate (draft text, placeholders)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01N4f2nya58RoRu4yEmJgRGE
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
788a84a4c0
commit
8f58eccecf
@@ -128,6 +128,16 @@ docker stats --no-stream
|
||||
|
||||
UFW permits only the confirmed SSH port, HTTP, and HTTPS. PostgreSQL, Web, API, and the Docker API remain private.
|
||||
|
||||
## Legal entity and documents gate (2026-09-30)
|
||||
|
||||
Before a production release, run the legal-consent test with the production flag on:
|
||||
|
||||
```bash
|
||||
cd frontend && JYOTISHA_REQUIRE_LEGAL_ENTITY=1 npx tsx --test tests/legal-consent-20260930.test.tsx
|
||||
```
|
||||
|
||||
It fails while `frontend/src/lib/legal-entity.ts` still holds placeholder operator details or the terms / privacy text is still marked draft. The workflows are not changed for this (they are product-owner territory); the step is manual until the product owner wires it in.
|
||||
|
||||
## Manual production deployment with Gitea Actions
|
||||
|
||||
GitHub production deployment is retired. Production changes are released only by manually dispatching `.gitea/workflows/deploy-production.yml`. The workflow requires an exact SHA shared by `main` and `staging`, an exact-SHA staging push gate and image manifest, the manual release gate, and matching public staging health. It deploys immutable registry digests and never builds application images on the production host.
|
||||
|
||||
Reference in New Issue
Block a user