Audit findings 6.1-6.4 + the audit's remediation plan itself
(docs/superpowers/plans/2026-07-20-full-audit-remediation-plan.md).
- ruff: 34 → 0 (unused imports/f-strings auto-fixed; E702 semicolon lines
split in test files; one unused local dropped). Suite still 819 green.
- CLAUDE.md + PROJECT_STATE.md no longer claim "no database / settings in
settings.json": the harness selects filesystem OR PostgreSQL session
storage (repository.py, server mode), and settings flow through harness
preferences with the JSON file as fallback only.
- tools/replay: stub /me (SPA boot was parsing the SPA's own HTML as JSON)
and /runtime/prewarm.
- failSession best-effort persistence now logs its failure server-side
instead of vanishing.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Two fixes found while unblocking the L2 setup:
1. conftest: THOTH_SSL_CA is NOT an L2 prerequisite. The DWH endpoint presents a
public cert (*.policlinicosandonato.it, signed by GoDaddy), already in the
certifi bundle, so the REST clients validate TLS with verify=True -- no CA file
needed. The ssl_ca line was commented out in ChironeWp3's nsp.yaml too.
2. test_workspace: the profile-default assertion collided with the operator's real
harness/.env once load_dotenv (D3) started injecting THOTH_PROFILE into the
process env. The test now dels THOTH_PROFILE to assert the actual *default*
(server), regardless of what the operator set in .env.
Suite: 109 passed.