The doc-verifier pass over the new trust/exposure surfaces came back
PASS with five improvements, all applied:
- the store policy notice gains a 'Learn more' into the security doc
(the notice named security.require_signatures but not where it
lives)
- 'blocked' disables the trust gate's install button — an active
button contradicted the 'install would be refused' statement right
above it (guard test added)
- the unknown-exposure tooltip now says what the operator can do
(check where the name resolves)
- dead l10n key verifPillUnverified removed (unverified is the
page-level notice, never a card pill)
- stale header comment in install_verification.dart corrected
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>
The trust-gate dialog replaces its generic 'no per-entry status yet
(alpha)' note with the hub's classified verification statement —
pinned store key / trusted publishers (green), installs without
signature checking (amber), install would be refused (red), bridge
entry (neutral) — via one shared describeInstallVerification mapping.
Against a pre-0.23 hub the field is empty and the old honest wording
stays (pinned by test).
Information architecture: policy-off is a GLOBAL fact, so it appears
as ONE ChainInlineHelp notice above the store grid instead of a
warning pill on every card (card noise); only 'blocked' — a genuine
per-source anomaly — earns a card pill. Doctor's host services show
the hub-classified network reach per endpoint (local only / private
network / publicly reachable with a protect-it hint / reach unknown).
Verified end-to-end against the live dev hub (guide harness): the
wire field arrives, the store page shows exactly one policy notice
and quiet cards; trust-gate variants captured via the dialog
harness. Suite 123 green.
Signed-off-by: flemming-it <stefan.a.flemming@googlemail.com>