WEB-600
Cross-app: wire the Live controls site switches (sign-ups, bug form) into the database and the site, refresh the site on switch changes; integration harness running site + admin together
Evidence
From logs/evidence/WEB-600/. Click a thumbnail for the full image.
No evidence files in logs/evidence/WEB-600/.
Tests
$ pnpm db:test$ pnpm db:test$ pnpm web:e2e:integration$ pnpm --filter @zoen/db test && pnpm --filter @zoen/admin typecheck && pnpm ai:test$ pnpm web:e2e:integration$ pnpm web:e2e:integration$ pnpm web:e2e:integration$ pnpm site:e2e$ cd apps/admin && pnpm build >/dev/null 2>&1 && pnpm exec playwright test tests/e2e/live.spec.ts tests/e2e/website.spec.ts tests/e2e/system.spec.ts --workers=1 --reporter=lineNotes
2026-10-04 22:57 UTC · W6 cross-app harness (pnpm web:e2e:integration: both production builds, the admin's webhook pointed at the test site) found and fixed real bugs: (1) the site merged camelCase api.site_settings keys onto snake_case defaults, so the main button, route toggles, sign-ups open and servers-live never reached the site — now mapped key by key; (2) the Live controls site switches (sign-ups, bug form) were stored but enforced nowhere — now refused by insert guards, exposed in public settings, the site shows the bug form as paused, and a flip queues a site refresh (setSwitch now delivers); (3) outbox delivery claimed only the oldest 50 rows once, so a backlog (51 rows from earlier runs) held back fresh changes, and signRevalidation silently cut tags beyond 50 — shared drainOutbox (packages/db) now drains batch by batch with ≤ 50 tags per signed request, used by admin and worker, unit-tested; (4) site maintenance was served as HTTP 200 (rewrite keeps the prerendered status) — the proxy now serves the page as a real 503 + Retry-After; (5) service-role cleanups of site_settings failed silently (check helper not executable) — granted, and test cleanups now throw. Results: integration 5/5, site e2e 39/39, admin live/website/system 29/29, pgTAP 18 files, drain unit test. Observed, not fixed: a benign Next cache-warming race on /status during bursts of tag refreshes (regenerates on the next request). Security note for hosting: the site rate-limits by the first X-Forwarded-For entry, which a client can spoof unless the proxy overwrites it.
