yttcom.net
Backend / Tools / DB Viewer
yttcom.net
Domains / DB Viewer
v2.0 · 07.11.26
◇ 10-sys.db
systems/10-master/data/
records.db inbox.db transfers.db knowledge.db jurisdiction.db
10-sys decisions Row #146
Tables
decisions
198
domain
8
events
0
gov_archive
0
gov_archive_fts
0
gov_archive_fts_config
1
gov_archive_fts_data
4
gov_archive_fts_docsize
0
gov_archive_fts_idx
2
items
18
sessions
99
sqlite_sequence
5
transfers_log
0
decisions — Row #146
10-sys.db · systems/10-master/data/
id
146
system
date
08/18/26
subject
Token rotation Phase 2 essentially complete -- 91 files across the whole server-side platform migrated off the hardcoded token
approved_by
USR369 David
se_id
—
tr_id
—
_rowid
146
detail
Full session arc: Phase 1 (auth-lib.php+tokens.json+.htaccess lockdown), then Phase 2 across systems/commands/ (all 40 real files), backend/ (33 files, discovered via RESTORE.php's action=list directory browsing since no grep exists), systems/*/data/api.php (all 11), community/{comms,jurisdiction,kb_api}.php, save.php, session_open.php, transfers/index.php, and root file-reader.php. Final master sweep: 91/91 files clean, 0 errors. Deliberately did NOT migrate file_write_web.php -- its own header explicitly documents 'Admin token only, hardcoded, no cai_auth dependency' as an intentional design choice (it is the recovery tool of last resort; making it depend on auth-lib.php would create a real bootstrapping risk if auth-lib.php itself ever broke). Left as-is, matching its own stated intent, not an oversight. Real bugs found and fixed along the way, unrelated to tokens: (1) verify_lib.php initially broke platform-wide-crashing-adjacent via ML.php 500ing when a naive migration removed a TOKEN constant still referenced elsewhere in the file -- caught immediately, all files re-migrated with a safer redefine-in-place recipe that preserves every downstream reference; (2) backend/records/db/tasks-api.php had a genuine pre-existing SQL bug (unquoted !high/!med/!low literals) causing a 500 on any priority-sorted task list call, fixed and verified; (3) found backend/config/platform.php, a dead file built 07/13/26 explicitly as the intended single token source but never actually required by anything -- fixed it to read from the real shared source too. One process slip: TASKGATE.php's 20-minute backup-gate window lapsed twice mid-session (once for TASKGATE.php itself, once for save.php/session_open.php), meaning those files were deployed before a fresh pre-edit backup existed -- caught each time within the same session, backups retroactively captured, all confirmed working via live tests regardless. One real mistake: a test call against HANDOFF.php used system=10 not realizing that file maps by OLD system code (10=Travel) not decade -- overwrote a deprecated, unread stub file in Travel's gov dir with test content, caught immediately, verified Travel's real handoff-95.md was untouched, restored the stub to a proper deprecated marker. Also took a fresh full-platform snapshot mid-session (platform_snapshot_08_18_26_727pm.zip, 3027 files) as a real restore point before continuing into backend/.
▼ Show timestamps
created_at
2026-08-18 19:58:33
Backend Domains Panel DB Viewer Transfers
Backend Tools DB Viewer DB Admin Server Map File Editor Backend Tools DB Viewer DB Admin Server Map File Editor