- Walked: 2026-05-29 at
bf12b0f7d8c291499e1df1ec75d4bd21acf3f6b1, with the access-denied link repaired later inc9ff6edc40232c1f42ae0bee896e663577cdda41. The retained walker was an ephemeral/tmpscript. - Reconciled and re-run: 2026-07-20 at source and published tip
343b87fe359270d1ad756050f2f67a1ffebd52a4. Store, route, export, erasure, real-PostgreSQL restart, two-process exact-bundle, and five focused Chromium publish cases passed. The surrounding historical shell/editor observations retain their cited evidence dates. - Verdict: partial — current evidence is deep through the local Tara
scene editor and its durable exact-manifest owner receipt. The named
end-to-end journey still stops before editorial approval, audit/immutable
provenance lineage, supersede/withdraw, and customer read-back on
/taraor/lilith. - Current authority:
WALKTHROUGH/journeys/lilith-studio-tara-scene-publish.mdThe journey coverage row rates the authoring layerdeep; the stricter Results ledger remains partial for the unfinished publication legs.
Result at a glance#
| Evidence layer | Historical 2026-05-29 observation | Current-source proof | Authority limit |
|---|---|---|---|
| Route and role gate | /lilith, /lilith-studio, /lilith-studio/tara, and /lilith-studio/scene/new rendered; non-editorial access denied |
All 12 current Lilith/Lilith Studio inventory routes survive; shell specs prove editorial entry and signed-in viewer denial | Anonymous redirect and signed-in denial are proven; the fallback's “Request operator access” still only opens /profile |
| Thin scene creation | /scene/new POSTed to /v1/lilith-studio/scenes |
Live-BFF create, pending lockout, keyboard kind selection, normalized session index, validation, offline error, entry links, and mobile standalone | Creates an authoring row; it is distinct from the full Tara editor and its durable release receipt |
| Tara scene editor | Not exercised because the dated walker could not obtain editor scope | Every asset/control, keyboard + drag placement, graph, lighting/audio/binding, 4,096-attendee model, accessibility gates, manifest, fixture provenance, draft reset, service-worker replay, and mobile width | Fixture-backed authored metadata and deterministic simulation—not live media, 4,096 clients, or immutable provenance |
| Release receipt | The old result described reachability, not approval or consumer publication | Scope-gated exact-manifest POST waits for durable commit; stable replay, owner-only minimized list, manifest digest, PostgreSQL restart recovery, DSAR, erasure fence, retention, and browser success passed | Durable receipt only; no tenant placement, audit event, approval identity, immutable asset resolution, withdraw, or customer release |
| Customer publication | Implied by the historical result title, not walked | No /tara or /lilith consumer imports the publish store |
Absent: the receipt is not an approved scene edition and is not customer-visible |
Evidence map#
The solid path is the current deep boundary. Dashed edges are the still-missing meaning of “publish to Tara.”
Proven observations#
The historical route repair remains valid#
- The walked commit and repair commit both resolve to immutable repository
objects. The current route inventory includes
/lilith, the ten/lilith-studio*entries, and/lilith-studio/tara; none of the four dated surfaces has regressed to a missing route. /lilith-studio/tararemains a read-only server view over Tara today, sittings, and ritual responses. It describes what the BFF currently serves; it is not a preview of a newly authored scene edition./lilith-studio/scene/newremains a member-scoped live-BFF form for a title,sit|ritual|readingkind, optional path, and session index. Its accepted row opens the separate/lilith-studio/scenesworkspace.- The dead
/profile/operator-accessCTA was repaired to/profile. That removes the 404 but does not create an operator-access request or governance workflow; its visible label still promises more than the link performs. - The old “all render/route” and correct access-denied observation therefore
survives as a dated smoke result. Its missing
/tmpwalker prevents selector, environment, and raw-report inspection.
The current editor proof is deep and appropriately bounded#
lilith-scene-editor-deep.spec.tswalks every scene-editor control, all asset handles and placement buttons, browser drag/drop, graph selection, lighting, audio, binding, capacity, sharding, accessibility, readiness, manifest, and provenance selections, then proves edit-after-publish returns the browser to draft.- The authoring state includes four assets and zones, three selectable lighting
presets, three rights-cleared audio beds, three triggers/actions, four
capacity tiers, three sharding profiles, and two options per accessibility
dimension. Control coverage is broad enough to earn
deepat this layer. - The 4,096-attendee result is a pure browser model. The tested stadium + interest-management configuration reports 16 shards; it is not traffic, networking, or runtime-load evidence.
- The accessibility gate exposes row-level text and remediation, blocks publish while any requirement fails, and retains keyboard placement as an equivalent to drag. The exact route is also replayed from the real service worker while offline and checked at a 390px standalone viewport.
- Provenance rows are fixture declarations rendered by
LilithProvenanceInspector. No cited test resolves them to signed immutable asset records.
“Published” currently means a durable owner receipt#
- The editor sends
sceneId, title, capacity tier, shard count, and its exact manifest JSON to/v1/admin/studio/scenes/publish. The route derives the owner from validated auth and returns only after the complete snapshot commits. StudioScenePublishStoreis a strict schema-v1 owner authority over the Postgres-backed snapshot sink. Exact retries have one stable identity; restart recovers the same receipt and manifest digest. GET lists only the exact owner's unexpired receipts and never returns raw manifest JSON.- The exact-owner DSAR contains the original manifest bytes. Signed generated-artifact erasure removes the subject, preserves adjacent owners, and persists a fence that rejects stale recreation. The canonical 365-day window has startup and weekly legal-hold-aware purge execution.
- The route still never calls the admin editorial release-stream service, writes an audit event, resolves declared provenance to immutable assets, identifies an approval decision, or provides withdraw/supersede endpoints.
- The browser publish spec does reach the real route/store, but it intercepts
the island request and reissues it with a server-generated
studio:editorialdevelopment bearer because the in-browser API token is null in E2E. Natural browser-token propagation is not proven by that case. /taraand/lilithstill do not consume the receipt. Re-editing clears the local surfaced identity while the prior durable row remains until retention or signed account erasure.
Boundaries and gaps#
- Deep authoring is not end-to-end publication. The coverage grade is earned through the editor and durable receipt, not through approval or customer availability.
- A release-stream string is not a release stream. It is derived from scene id + a stable content/owner digest and has no approval event log or workflow consumer.
- A durable receipt is not a distributed release authority. The bounded whole-snapshot queue is per process and has no distributed compare-and-swap; concurrent BFF writers can still lose an update.
- Exact bytes are not semantic publication validation. Placements, interactions, accessibility evidence, provenance, and scene graph cross the boundary, but the JSON object is not checked against a complete immutable release schema or asset resolver.
- Fixture provenance is not ledger provenance. The inspector renders authored declarations without signed-asset read-back.
- A modelled audience is not a load test. The 4,096/16-shard result exercises deterministic readiness logic only.
- The browser auth seam is assisted. Server-side bearer injection proves route behavior, not the editor's natural access-token path.
- The access CTA is a live link, not a request.
/profilecannot grant or submit editorial access. - The approval bridge is navigational only. A header link reaches the V1 workflow surface, but no shared scene identity enters its evaluator or the operator queue.
- Customer and audit read-back are absent.
/tara,/lilith, cold PWA, entitlement/tenant policy, crisis framing, audit reconstruction, and supersede/withdraw remain open. - The focused execution is not full-journey proof. The durable publish spec was rerun in Chromium against the exact production BFF bundle; the historical 12-route shell sweep and other editor specs were not all rerun in this slice.
Re-run evidence#
Run the live BFF and production-like web app at one immutable commit, then run the focused specs sequentially with one worker:
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-studio-new-scene.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-studio-shell-smoke.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-scene-editor-smoke.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-scene-editor-deep.spec.ts --project=chromium --workers=1
pnpm --dir apps/oshun/web exec playwright test -c playwright.config.ts e2e/lilith-scene-publish.spec.ts --project=chromium --workers=1
Retain the exact commit, BFF backing tier, browser/storage state, JSON/report artifacts, and the publish-store restart result. A future complete gate must carry one immutable scene identity through manifest persistence, review, approval, durable edition, customer cold-load, and audit reconstruction.
The 2026-07-20 focused rerun used the exact rebased production BFF bundle
(34,982,194 bytes; SHA-256
68c46219f13f2f7dafb25632f82924ef0cb2146d44085569469c22aebcfaeba4).
Store/route/export/erasure tests passed 53/53, the real-PostgreSQL restart and
fence integration passed 1/1, and lilith-scene-publish.spec.ts passed 5/5 in
Chromium with one worker. Two clean BFF processes recovered receipt
scene-publish-e25f2c4e84d1077b3ac2396ebb5cb89d9e4830257e86a5d410f17f75fd49d0ac
and the same manifest digest. The isolated database, Redis namespace, and ports
were removed after proof.
Source trail#
- Current journey contract
- Current coverage registry
- Lilith Studio access gate
- Access-denied fallback
- Thin scene-create form
- Tara read-only mirror
- Tara scene editor
- Scene publish route
- Scene publish store
- External scene contract
Cross-references#
- Lilith Studio shell evidence
- Scene editor evidence
- Tara consumer evidence
- Lilith public surface evidence
- Editorial review journey
- Scene keep-and-share journey
- Current completeness audit
Open questions#
- Should the current action be renamed “Record release receipt” until a reviewed edition exists?
- Which complete publication schema and asset resolver will validate the now- retained manifest's immutable references, tenant/surface target, and policy versions?
- How will one scene identity enter automated checks, human review, audit events, publication, supersede/withdraw, and erasure workflows?
- Which distributed compare-and-swap or row-level authority replaces the per-process whole-snapshot queue across multiple BFF instances?
- When will
/taraconsume only approved editions and prove the result in a clean entitled customer context, including cold/offline behavior? - What first-class workflow should the access-denied CTA open to request,
approve, expire, and audit
studio:editorialaccess?