Verification record: 2026-09-18
This is the previously recorded verification of the 2026-09-18 implementation. It is retained as historical evidence, not a claim about the current checkout. Use the maintainer verification procedure to produce new results.
Verified on 2026-09-18 with Node 24.20.0, Yarn 4.18.0, and Chromium from Playwright 1.63.0.
Completed checks
| Check | Result |
|---|---|
| ESLint style, dedicated JSDoc, source headers, and prose punctuation | Pass |
| Prettier for non-JavaScript formats | Pass |
| Formatter stability | A second formatting pass produces no additional edits |
| EditorConfig | Pass |
| Repository skill validation | Pass |
| Clean source copy | Immutable install and full quality check passed without reference files or pre-existing dependencies |
| Unit tests | 109 passing tests covering components, adapters, lifecycle, composition, coding standards, and isolated helper boundaries |
| Unit coverage | 100% statements, branches, functions, and lines across all maintained JavaScript, enforced per file. V8 HTML/JSON/Cobertura reports retained |
| Showcase production build | Pass |
| Starter production build | Pass |
| Build modes | Readable development output, explicit minification overrides, source maps, and production HTML comment removal verified |
| Development template reload | A changed template invalidates the cached virtual module and produces fresh HTML |
| Production browser acceptance | 18 passing tests, including the component catalogue, native integrations, lazy page loading, and two deployment tests |
| Native integrations | Lazy Leaflet, native video/captions, xterm, and real noVNC decoding exercised with offline fixtures |
| Modal focus ownership | Immediate closure, normal deactivation, native inert restoration, and teardown cancellation verified |
| Production script CSP | Tested with script-src 'self', no unsafe-eval |
Root and /control-panel/ deployments | Deep links, parameters, query/history, assets verified |
| Packed package consumer | Installed tarball in an isolated starter. Build and browser checks passed |
| GitLab pipeline configuration | Schema expansion and eight job-rule selections checked, including delivery exclusion outside protected-main release candidates |
| Local GitLab CI | All seven allowlisted Docker jobs passed through the pinned 4.75.1 runner, including independent package consumption |
| Local runner lifecycle | Private-file permissions, untracked-source refusal, named active jobs, dependency validation, failure statuses, dry-run dispatch, and interrupt status 130 checked |
| Reference integrity | All 24 source/asset hashes match the initial manifest |
Browser checks verify lazy page requests, cached revisits without document reload, stale import rejection, failed-chunk reload recovery, and comment-free production HTML/page chunks. They also cover all demo routes, resource creation/edit/deletion, URL filters/history, theme/layout/sidebar persistence, widget visibility/drag ordering, keyboard tabs/dialog focus, mobile menus, RTL drawer placement, wallboard graphs, form validation/submission, empty/error recovery, permission visibility, and French, German, and Italian localization. The production server returns real 404s for absent assets/API routes instead of the SPA document.
Axe checks the dashboard and all 32 dedicated component pages against WCAG A/AA rules in dark and light modes. Submenu checks cover direct links, independent keyboard disclosure, browser history, active-page state, rail expansion, and RTL mobile navigation. Catalogue browser checks cover disclosures, drawer focus, form controls, isolated table selection/pagination, widget ordering, responsive RTL layout, offline maps, video playback, xterm input, RFB framebuffer decoding, and reconnect/teardown. Optional native libraries are verified absent from ordinary dashboard requests. The same workflow verifies that the pinned sidebar meets both viewport edges at the document top and bottom, then returns to the top before capturing the README preview. This is an automated regression check, not a complete accessibility certification. Tests use reduced motion to avoid inspecting intermediate transition colors. Theme persistence is independently verified after reload.
Local CI follows the documented runner procedure. The successful full run used a temporary alternate Git index to expose reviewed new files without changing the developer’s real index. Job workspaces received source and declared upstream artifacts, without the host’s existing dependencies or build outputs. All job containers and fixture servers exited. Ignored reports and reusable caches remain available. Coverage requires 100% in all four metrics for each included file. Browser acceptance remains a separate gate. Delivery-helper unit tests replace filesystem, network, and subprocess boundaries with mocks and perform no external delivery.
Visual review
The reference’s rendered snapshot and the new application were reviewed in the browser. The derived design retains the compact dark navigation, orange accent, subtle panel gradients/borders, rounded metric cards, SVG trends, status colors, and dense dashboard structure. Generic workspace data and the new Bootstrap component system intentionally replace product-specific text and markup. This is a visual derivation, not a claim of identical pixels across every original screen.
Desktop, light/RTL, and mobile screenshots are generated under test-results/. These test artifacts are excluded from source control. Selected, visually reviewed dark/light dashboard and component-library screenshots are maintained in docs/images/ for the README. The source-only snapshot at .reference/dashboard.html has an explicit “controls inactive” label and is not the working demo.
Practical limits
- Browser automation covers Chromium. Safari/Firefox and real assistive-technology review remain downstream release checks.
- History mode is verified. The router exposes hash mode, but this delivery does not claim tested hash deployment.
- The app needs inline styles for Alpine visibility and data-driven layout/progress. The verified CSP permits inline styles, not inline scripts.
- Real SSH/RFB gateways, authentication, tenant switching, notification delivery, live metrics, and backend authorization are consumer integrations. Demo credentials are never transmitted or persisted.
- Page templates and controllers load on demand. Large-data virtualization and analytical charting remain consumer extensions.
- GitLab publication is configured for the restricted project registry. No package has been published during local verification, and hosted workflow validation requires the GitLab project. Source appearance does not establish whether Claude or another tool authored the reference.
Approximate production baseline: showcase entry JavaScript 86 KB gzip, CSS 44 KB gzip, and entry HTML 5 KB gzip. The dashboard adds approximately 4 KB gzip for its page and shared controller. Starter entry JavaScript is 78 KB gzip, CSS 43 KB gzip, and entry HTML 4 KB gzip. Other page chunks load only when selected. These are build sizes, not network performance measurements. Bootstrap’s full CSS is included deliberately for template coverage.
Author
Laurent Declercq l.declercq@agon-innovation.ch
License
Unless otherwise stated all source code is licensed under LGPL 2.1 and has the following copyright:
© 2026, Agon Partners Innovation AG, All rights reserved.The design material and the “Agon Ātrium” trademark is the property of their authors. Reuse of them without prior consent of their respective authors is strictly prohibited.
Version
Version: 20260921