Changes touching this path
- the static Clerk key verifies outside the key cache the JWKS copy lives in: clerk.ts byStaticKey makes the category check verifyToken makes and hands a JWK built from CLERK_JWT_KEY to the same verifyJwt with the same options, where verifyToken given the key filed it through loadClerkJwkFromPem marked never to expire, which stopped the JWKS copy expiring, so a key the instance dropped kept verifying over the JWKS until a restart. a refusal Clerk reports as a failed verification goes to the JWKS only when the static key does not verify the signature, so a missing sub or a non-numeric exp, nbf or iat is answered by the static key alone, as the verify doc said and the code did not; the loot-wasm open_sealed_grant, grants.ts keyFor and CONTEXT.md cost claims now add a verify per authored change a grant body carries; the fetch an unknown key id costs is documented; site/test/plan.ts withChangesAtScale inserts inside its try and analyzes again after its deletes; Seam::Gate moved and Converged.moved say what they mean beside the anchor. pinned in 4 new clerk-verify tests: a dropped key stops verifying five minutes after the fetch though the static key verified after it, claim failures answered without the JWKS, HS256 keyed by the public key, the machine category and RS384 refused over both keys, and a key with its line breaks removed read. red under named mutations, each restored, over the 12 clerk-verify tests: the static path back on verifyToken (2 failed and 10 passed), no signature re-check (1 and 11), no category check (1 and 11), the JWK without alg (1 and 11), the PEM read with its armour lines kept (8 and 4); before the fix the new tests went 2 failed and 9 passed of 11. not taken: the span wrapping shared across the pool db.ts files, and running the pg files serially. cargo test green, 4832 passed over 144 test result lines with 15 ignored, the site gate green at 913 passed, and the site live suites 90 passed. owes a site deploy, after which CLERK_JWT_KEY can be set; it also files qpsuxosk, ylrvoopz, the Tickets route server time, and zlulwtlw, the History route live query time, carries a comment on uyzzknlm and resolves zxkpzxvz (qpsuxosk)
96800555 · dbf3dbe6…
Renames are not followed. loot's tree maps a path to an address, so a rename is a delete and an add. This list is the history of the name, not of the bytes.