Backend serializes `Events []Event` as JSON `null` when the slice is nil (Go's zero value for slices). Spec §8.4 shows it as an array — stale spec, verified actual behavior with `curl http://localhost:22784/api/m/<uuid>` returning `"events": null` on a freshly-created token with no triggers. Zod schema was `events: z.array(eventResponseSchema)` — failed to parse the null, threw PARSE_ERROR, manage page rendered "CANNOT REACH ARCHIVE" instead of the empty dossier. Fixed: `.nullish().transform(v => v ?? [])` — accepts null/undefined and normalizes to []. Manage page's `events.length === 0` empty-state check ("No events recorded yet") now reachable; consumers always see an array. Caught by memory rule feedback_verify_data_shapes.md: trust reality > spec. I trusted §8.4's example object during Phase 14 schema design instead of hitting the live endpoint. Same kind of drift as the four Phase-14 spec-vs-code divergences cleared at the time — this one slipped through because TokenManagePage was never end-to-end exercised pre-UI. |
||
|---|---|---|
| .. | ||
| base64-tool | ||
| c2-beacon | ||
| caesar-cipher | ||
| canary-token-generator | ||
| dns-lookup | ||
| firewall-rule-engine | ||
| hash-cracker | ||
| keylogger | ||
| linux-cis-hardening-auditor | ||
| linux-ebpf-security-tracer | ||
| metadata-scrubber-tool | ||
| network-traffic-analyzer | ||
| simple-port-scanner | ||
| simple-vulnerability-scanner | ||
| systemd-persistence-scanner | ||