Skip to content

Manual blocker: reactivation checklist before treating HireProof as active #42

Description

@Iron-Mark

Status

This repository is intentionally inactive for now. Public production surfaces were last verified healthy, but protected/account-backed flows should not be treated as production-ready until this issue is completed.

This issue is public-safe by design. Do not paste secret values, tokens, provider keys, dashboard screenshots with secrets, private customer data, or exploit details here.

Product design archive snapshot

A product design archive has been prepared locally for future product, UI/UX, and portfolio review. It is not a replacement for fresh verification when the repo becomes active again.

Current archive scope:

  • Parent index: docs/product-design/README.md
  • Screen archive index: docs/product-design/screens/README.md
  • Machine-readable manifest: docs/product-design/screens/_manifest.json
  • 195 PNG screenshots, about 20.9 MiB
  • 192 responsive route screenshots across 64 routes
  • Figma overview exports:
    • 00-preview.png
    • 02-design-system.png
    • 03-product-strategy.png

Archive safety checks already completed locally:

  • No raw local capture URL remains in the archive metadata.
  • No .env, key, certificate, database, log, or temp files were found in the archive.
  • Text and PNG raw-string scans found no token-shaped secrets.
  • PNG metadata scan found only basic Figma software metadata in the Figma exports.
  • Screenshot files render from disk with valid dimensions.
  • _manifest.json parses successfully and reports 192/192 responsive captures passed.

Known limitation: full OCR over screenshot pixels was not run because OCR tooling was not available locally. Run OCR before treating the archive as a long-term public reference if screenshots may contain sensitive visible text.

Related detail issue: #43.

Manual blockers before reactivation

  • Confirm the intended product mode: public demo-only, private pilot, or active production.
  • Re-check main and dev branch protections and required checks.
  • Re-run CI on the current default branch.
  • Re-check GitHub code scanning, Dependabot, and secret scanning alerts.
  • Commit or intentionally discard the local product design archive under docs/product-design/.
  • If committing the design archive, optionally run OCR over screenshot pixels first for a stronger public-safety pass.
  • Refresh product/Figma screenshots if product UI changes before the repo becomes active again.
  • Confirm Vercel production is deploying the intended main commit.
  • Run public smoke checks for the homepage, audit page, docs, health endpoint, integrations proof endpoint, and extension download.
  • Decide whether account/session flows are in scope for reactivation.
  • If account/session flows are in scope, configure and verify strong production session/auth secrets in the hosting dashboard. Do not post values here.
  • If hosted BYOK is in scope, configure and verify the hosted credential encryption secret in the hosting dashboard. Do not post values here.
  • If protected headless API or MCP fallback access is in scope, configure and verify a private API key path. Do not post values here.
  • If account-issued API keys already exist or will be used, decide whether to configure a stable API-key hash pepper before issuing more keys. Do not post values here.
  • Run one credential-backed API smoke with a real key from a secure local shell or dashboard secret, and report only pass/fail evidence.
  • Browser-test login, developer portal, provider credential save/revoke, and protected API/MCP flows if those features are being reactivated.
  • Review cost controls for live model/search/OCR providers before enabling public live evidence.
  • Confirm chat/webhook integrations are intentionally enabled or intentionally disabled.
  • Update docs if the activation mode, env requirements, or public claims changed.

Safety rules for this issue

  • Keep all checks at the level of configuration names, statuses, and pass/fail evidence.
  • Use private dashboards or local secure shells for secret values.
  • Do not include instructions for bypassing auth, scanning for vulnerabilities, exploiting routes, or attacking third-party systems.
  • If a security finding appears, describe impact and owner action at a high level, then handle sensitive details privately.

Done when

  • All selected reactivation blockers above are checked or explicitly marked out of scope.
  • Public and credential-backed verification evidence is current.
  • GitHub alerts are clean or explicitly triaged.
  • Production claims match what was actually verified.
  • The product design archive is either committed, refreshed, or intentionally discarded.

Metadata

Metadata

Assignees

No one assigned

    Labels

    codexdocumentationImprovements or additions to documentation

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions