V1 Web PWA · Walk result

Journey result: Lilith Studio Tara scene publish

A dated evidence record for V1 Web PWA: observed behavior, current source reconciliation, automation evidence, and explicit proof limits.

verdict: partial· 2026-05-29
8sections8 minread1table

On this page
  • Walked: 2026-05-29 at bf12b0f7d8c291499e1df1ec75d4bd21acf3f6b1, with the access-denied link repaired later in c9ff6edc40232c1f42ae0bee896e663577cdda41. The retained walker was an ephemeral /tmp script.
  • Reconciled and re-run: 2026-07-20 at source and published tip 343b87fe359270d1ad756050f2f67a1ffebd52a4. Store, route, export, erasure, real-PostgreSQL restart, two-process exact-bundle, and five focused Chromium publish cases passed. The surrounding historical shell/editor observations retain their cited evidence dates.
  • Verdict: partial — current evidence is deep through the local Tara scene editor and its durable exact-manifest owner receipt. The named end-to-end journey still stops before editorial approval, audit/immutable provenance lineage, supersede/withdraw, and customer read-back on /tara or /lilith.
  • Current authority: WALKTHROUGH/journeys/lilith-studio-tara-scene-publish.md The journey coverage row rates the authoring layer deep; the stricter Results ledger remains partial for the unfinished publication legs.

Result at a glance#

Evidence layer Historical 2026-05-29 observation Current-source proof Authority limit
Route and role gate /lilith, /lilith-studio, /lilith-studio/tara, and /lilith-studio/scene/new rendered; non-editorial access denied All 12 current Lilith/Lilith Studio inventory routes survive; shell specs prove editorial entry and signed-in viewer denial Anonymous redirect and signed-in denial are proven; the fallback's “Request operator access” still only opens /profile
Thin scene creation /scene/new POSTed to /v1/lilith-studio/scenes Live-BFF create, pending lockout, keyboard kind selection, normalized session index, validation, offline error, entry links, and mobile standalone Creates an authoring row; it is distinct from the full Tara editor and its durable release receipt
Tara scene editor Not exercised because the dated walker could not obtain editor scope Every asset/control, keyboard + drag placement, graph, lighting/audio/binding, 4,096-attendee model, accessibility gates, manifest, fixture provenance, draft reset, service-worker replay, and mobile width Fixture-backed authored metadata and deterministic simulation—not live media, 4,096 clients, or immutable provenance
Release receipt The old result described reachability, not approval or consumer publication Scope-gated exact-manifest POST waits for durable commit; stable replay, owner-only minimized list, manifest digest, PostgreSQL restart recovery, DSAR, erasure fence, retention, and browser success passed Durable receipt only; no tenant placement, audit event, approval identity, immutable asset resolution, withdraw, or customer release
Customer publication Implied by the historical result title, not walked No /tara or /lilith consumer imports the publish store Absent: the receipt is not an approved scene edition and is not customer-visible

Evidence map#

The solid path is the current deep boundary. Dashed edges are the still-missing meaning of “publish to Tara.”

flowchart LR A[Editorial session] --> B[Lilith Studio shell] B --> C[Tara scene editor] C --> D[Readiness gates] D --> E[Exact-manifest publish POST] E --> F[Durable owner receipt] C --> G[Fixture manifest and provenance] G --> F F -. not linked .-> H[Editorial review identity] H -. not approved .-> I[Durable release edition] I -. not consumed .-> J[Tara and Lilith surfaces]

Proven observations#

The historical route repair remains valid#

  • The walked commit and repair commit both resolve to immutable repository objects. The current route inventory includes /lilith, the ten /lilith-studio* entries, and /lilith-studio/tara; none of the four dated surfaces has regressed to a missing route.
  • /lilith-studio/tara remains a read-only server view over Tara today, sittings, and ritual responses. It describes what the BFF currently serves; it is not a preview of a newly authored scene edition.
  • /lilith-studio/scene/new remains a member-scoped live-BFF form for a title, sit|ritual|reading kind, optional path, and session index. Its accepted row opens the separate /lilith-studio/scenes workspace.
  • The dead /profile/operator-access CTA was repaired to /profile. That removes the 404 but does not create an operator-access request or governance workflow; its visible label still promises more than the link performs.
  • The old “all render/route” and correct access-denied observation therefore survives as a dated smoke result. Its missing /tmp walker prevents selector, environment, and raw-report inspection.

The current editor proof is deep and appropriately bounded#

  • lilith-scene-editor-deep.spec.ts walks every scene-editor control, all asset handles and placement buttons, browser drag/drop, graph selection, lighting, audio, binding, capacity, sharding, accessibility, readiness, manifest, and provenance selections, then proves edit-after-publish returns the browser to draft.
  • The authoring state includes four assets and zones, three selectable lighting presets, three rights-cleared audio beds, three triggers/actions, four capacity tiers, three sharding profiles, and two options per accessibility dimension. Control coverage is broad enough to earn deep at this layer.
  • The 4,096-attendee result is a pure browser model. The tested stadium + interest-management configuration reports 16 shards; it is not traffic, networking, or runtime-load evidence.
  • The accessibility gate exposes row-level text and remediation, blocks publish while any requirement fails, and retains keyboard placement as an equivalent to drag. The exact route is also replayed from the real service worker while offline and checked at a 390px standalone viewport.
  • Provenance rows are fixture declarations rendered by LilithProvenanceInspector. No cited test resolves them to signed immutable asset records.

“Published” currently means a durable owner receipt#

  • The editor sends sceneId, title, capacity tier, shard count, and its exact manifest JSON to /v1/admin/studio/scenes/publish. The route derives the owner from validated auth and returns only after the complete snapshot commits.
  • StudioScenePublishStore is a strict schema-v1 owner authority over the Postgres-backed snapshot sink. Exact retries have one stable identity; restart recovers the same receipt and manifest digest. GET lists only the exact owner's unexpired receipts and never returns raw manifest JSON.
  • The exact-owner DSAR contains the original manifest bytes. Signed generated-artifact erasure removes the subject, preserves adjacent owners, and persists a fence that rejects stale recreation. The canonical 365-day window has startup and weekly legal-hold-aware purge execution.
  • The route still never calls the admin editorial release-stream service, writes an audit event, resolves declared provenance to immutable assets, identifies an approval decision, or provides withdraw/supersede endpoints.
  • The browser publish spec does reach the real route/store, but it intercepts the island request and reissues it with a server-generated studio:editorial development bearer because the in-browser API token is null in E2E. Natural browser-token propagation is not proven by that case.
  • /tara and /lilith still do not consume the receipt. Re-editing clears the local surfaced identity while the prior durable row remains until retention or signed account erasure.

Boundaries and gaps#

  • Deep authoring is not end-to-end publication. The coverage grade is earned through the editor and durable receipt, not through approval or customer availability.
  • A release-stream string is not a release stream. It is derived from scene id + a stable content/owner digest and has no approval event log or workflow consumer.
  • A durable receipt is not a distributed release authority. The bounded whole-snapshot queue is per process and has no distributed compare-and-swap; concurrent BFF writers can still lose an update.
  • Exact bytes are not semantic publication validation. Placements, interactions, accessibility evidence, provenance, and scene graph cross the boundary, but the JSON object is not checked against a complete immutable release schema or asset resolver.
  • Fixture provenance is not ledger provenance. The inspector renders authored declarations without signed-asset read-back.
  • A modelled audience is not a load test. The 4,096/16-shard result exercises deterministic readiness logic only.
  • The browser auth seam is assisted. Server-side bearer injection proves route behavior, not the editor's natural access-token path.
  • The access CTA is a live link, not a request. /profile cannot grant or submit editorial access.
  • The approval bridge is navigational only. A header link reaches the V1 workflow surface, but no shared scene identity enters its evaluator or the operator queue.
  • Customer and audit read-back are absent. /tara, /lilith, cold PWA, entitlement/tenant policy, crisis framing, audit reconstruction, and supersede/withdraw remain open.
  • The focused execution is not full-journey proof. The durable publish spec was rerun in Chromium against the exact production BFF bundle; the historical 12-route shell sweep and other editor specs were not all rerun in this slice.

Re-run evidence#

Run the live BFF and production-like web app at one immutable commit, then run the focused specs sequentially with one worker:

bash
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-studio-new-scene.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-studio-shell-smoke.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-scene-editor-smoke.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-scene-editor-deep.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-scene-publish.spec.ts --project=chromium --workers=1

Retain the exact commit, BFF backing tier, browser/storage state, JSON/report artifacts, and the publish-store restart result. A future complete gate must carry one immutable scene identity through manifest persistence, review, approval, durable edition, customer cold-load, and audit reconstruction.

The 2026-07-20 focused rerun used the exact rebased production BFF bundle (34,982,194 bytes; SHA-256 68c46219f13f2f7dafb25632f82924ef0cb2146d44085569469c22aebcfaeba4). Store/route/export/erasure tests passed 53/53, the real-PostgreSQL restart and fence integration passed 1/1, and lilith-scene-publish.spec.ts passed 5/5 in Chromium with one worker. Two clean BFF processes recovered receipt scene-publish-e25f2c4e84d1077b3ac2396ebb5cb89d9e4830257e86a5d410f17f75fd49d0ac and the same manifest digest. The isolated database, Redis namespace, and ports were removed after proof.

Source trail#

Cross-references#

Open questions#

  • Should the current action be renamed “Record release receipt” until a reviewed edition exists?
  • Which complete publication schema and asset resolver will validate the now- retained manifest's immutable references, tenant/surface target, and policy versions?
  • How will one scene identity enter automated checks, human review, audit events, publication, supersede/withdraw, and erasure workflows?
  • Which distributed compare-and-swap or row-level authority replaces the per-process whole-snapshot queue across multiple BFF instances?
  • When will /tara consume only approved editions and prove the result in a clean entitled customer context, including cold/offline behavior?
  • What first-class workflow should the access-denied CTA open to request, approve, expire, and audit studio:editorial access?