Tier S (a fix inside a boundary; chaos d8=5, no override). Reported by the
maintainer: "I can't save notes, I get 'refused: no session token'."
The form posted to a bare `/note`. Control 1 requires the token on EVERY
request, so the guard refused all of them.
WHY THE TESTS MISSED IT IS THE PART WORTH RECORDING. I verified the note
channel over real HTTP and got 303 -- but I appended the token to the URL
by hand. I tested the ENDPOINT and not the PATH A PLAYER TAKES, so the one
thing standing between the feature and the user was the one thing not
exercised. Same family as timing the wrong span and counting the wrong
denominator: a correct measurement of the wrong subject.
Fixed with Guard::note_endpoint(), so the form's action carries the token
like every other request. The assertion now pins the token's PRESENCE
rather than the bare path, so reverting the fix turns it red.
Verified the way it should have been done first: read the form's `action`
out of the SERVED page and POST to exactly that, nothing added by hand.
303.
Clippy then flagged document_with_log at 8 arguments. It was right -- the
signature had grown across three passes -- so the two endpoints are now
one `Endpoints` struct rather than an #[allow]. They are one concept: the
guarded surface this page may talk to, one channel that becomes commands
and one that provably cannot.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>