Account loading and recovery — #178
Implementation: PR #185, branch head 23b8bb3cce6e7f1ce7b5d78cc4f8429cd4e64e34.
Local fixture: SW_AUDIT_PORT=4418 node scripts/audit-household-server.mjs dist.
Only synthetic household data was used for failure scenarios. No outgoing emails,
real household edits, delivery changes, or model requests.
Local CUA observations
- 503 responses (including
available:false) retain headings, error messages and Retry for Kids, Adults, portrait and daily delivery. - Keyboard Enter retries the chosen section. The focused control remains in place as Refresh; other section errors remain unchanged.
- Portrait recovery restores the existing Kids/Adults thumbnails. A kid edit containing “Unsaved nickname” survives without replacement; nothing was saved to a real account.
- Network failure recovers with one explicit Kids retry.
- The 30-second synthetic slow request aborts at the client's 15-second deadline and shows a timeout message. Retry recovers the selected section; other sections retain their timeout state.
- A successful empty household shows “Nobody in here yet” and Add a kid. An initial successful load has no visible Refresh controls.
- Expired-session responses retain the section and offer Reload to sign in.
- Error/recovery controls inspected at 390 and 1280 pixels. The final build correctly hides controls after initial success despite the existing button display style.
- Polite live-region markup and keyboard focus were inspected. This is not a full screen-reader audit.
Captures
503-mobile.png and 503-desktop.png show the final error presentation.
recovered-mobile.png shows final-build portrait recovery with the focused Refresh control.
timeout-recovery-mobile.png shows a recovered Kids section alongside independent timeout errors.
Other loading/empty captures record intermediate walkthrough states. Native full-page stitching
was unreliable, so the final error and recovery evidence uses viewport screenshots.
Automated checks: all 34 local preflight gates passed; the focused read suite passed 17 checks. The final build and staged secret scan passed. CI and production release results will be appended once verified.
Release verification
PR #185 merged as 3745b4ed656fd2154cdbd0aaa58f655a4ab4404e. PR CI and main CI
(run 34666061289) passed both jobs. The recovery browser suite passed 432 new assertions
(520 total account browser checks). Automatic website release 34666185982 succeeded.
Cloudflare production deployment 0d75e0cb-b005-410e-83b2-db724faf2947 reports that commit,
commit_dirty:false, and deploy success.
Live signed-in browser inspection found Kids, Adults, portrait and daily delivery all visible and ready, with no error statuses and no unnecessary Retry/Refresh controls. No private household values are recorded here. Public home, Browse, account, planner, signed-out identity and a real PDF download all returned 200; production Turnstile markup, PDF bytes and the new account recovery assets were verified. The initial Python HTTP probe was rejected with 403; the normal curl probe and browser checks passed. No production data was changed.