mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-27 16:51:12 -07:00
forgectrl reveals the fuse identity only to the token AND the physical button held, so the token alone must answer 403 with the button message. The test now asserts the no-token refusal and the token-without-button refusal and never fetches the identity itself (a 200 would have carried the fuse password into the result log). BRINGUP: the bench campaign on the flashed dev image, 7 of 24 passed so far.