diff --git a/workplans/KEY-WP-0028-browser-client-field-validation.md b/workplans/KEY-WP-0028-browser-client-field-validation.md index 2876402..46b0672 100644 --- a/workplans/KEY-WP-0028-browser-client-field-validation.md +++ b/workplans/KEY-WP-0028-browser-client-field-validation.md @@ -74,6 +74,16 @@ Two consequences, both corrected within the session: unimplemented was withdrawn with a rationale pointing at the implementation. Nothing was built on it. +A third instance followed the same day, outside this task: a message to +railiance-platform (d361bf28) listed the upstream issuer pin as outstanding when +`docs/evidence/2026-09-09-upstream-issuer-pin.json` showed it done ten hours +earlier — `check_before.issuer_matches: false`, then pinned to +`https://auth.coulomb.social`. Corrected in dd827b9f. The concern itself was +sound; only the claim that it was still owed was wrong, and the two are worth +separating rather than letting the correct half excuse the other. + The lesson worth keeping: in a repository where several sessions work at once, -blocker prose ages faster than the code it describes. Re-read the source before -acting on a workplan's description of it. +prose ages faster than the code and the receipts it describes. `docs/evidence/` +is the authoritative artifact for anything claiming a live proof here. Read it +before writing "outstanding", "unproven" or "not done" — that check is cheaper +than any of the corrections it would have prevented.