docs: record web credential rotation

This commit is contained in:
Wyndham ARR
2026-07-31 15:41:36 +08:00
parent bf7939dd1a
commit a891c0ae7a
6 changed files with 42 additions and 14 deletions

View File

@@ -9,7 +9,7 @@ No timed or externally delegated commitment is currently active.
- The Booking extraction/review program is source-complete, migrated and transaction-tested against live PostgreSQL with
an outer rollback. One operator-authorized real upload/edit/delete/activate flow remains open product acceptance work;
this record is not authorization to change the current Booking source.
- Rotate the Web password to a value distinct from the public username, update only the existing Keychain item and
perform one controlled restart/login/logout check.
- The 2026-07-31 Keychain-only credential rotation and controlled restart/login/logout check are complete, but the new
password still matches the username. Rotate it again to a distinct high-entropy value when the operator chooses one.
- Package Node/artifact-tool and a shared output volume into the eventual production worker runtime.
- Run one controlled no-PII XML vertical slice on the eventual ARR2.0 server deployment.