Bring README and TODO.md in line with next after the milestone merge (closes #132)
check / check (push) Successful in 40s

Docs only. TODO.md's Next Step no longer says open issues wait on
`next`: no implementation work is open, and the cache design waits on
sneak's review. The README is corrected where the code contradicts it:
where SRP lives and how the login subkey is derived, when email OTP is
used, how the auth token is encoded, the download retry's temporary
files, which CLI commands open a library, what `--exif` records, the ML
data fetch during `quak backup`, the default cache directory, and the
`408`/`429` retries.

Model: opus-5-5
This commit is contained in:
2026-09-29 01:37:26 +00:00
parent 9e6e038545
commit 55738a5107
2 changed files with 73 additions and 50 deletions
+15 -1
View File
@@ -14,13 +14,27 @@ pre-1.0
# Next Step
None: every issue still open is done on `next` and waits for it to reach `main`.
None: no implementation work is open. The cache design,
https://git.eeqj.de/sneak/quak/issues/36, waits on sneak's review.
Tagging and releases are decided by sneak alone, and happen only when he
declares one.
# Completed Steps
- 2026-09-29: Brought the README and this file in line with `next` after the
milestone merge (issue 132). The Next Step says no implementation work is open
and the cache design (issue 36) waits on sneak's review. README corrections:
`script/lint` and `script/test` have no host path, though `yarn test` does;
the SRP handshake uses `fast-srp-hap`, outside `crypto/`; the SRP password is
the first 16 bytes of a 32-byte subkey; email OTP replaces SRP when the
account has email MFA on; the auth token is sent as URL-safe base64 with
padding; each download attempt writes its own temporary file; `login`,
`whoami` and `logout` open no library; `--exif` records XMP and, for a JPEG,
EXIF, and no IPTC; `quak backup` still fetches ML data; the default cache
directory is the per-user one, not an XDG path on macOS; and `408` and `429`
are retried.
- 2026-09-28: Tested the live-photo writer's fsyncs (issue 130). A test checks
that the image's and the video's temp files are fsynced before either is
renamed into place, and the directory after both renames, as the `writeAtomic`