Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
52f4896b63 | ||
|
|
3c347d40d8 | ||
|
|
6f88915c7a | ||
|
|
675603c3a2 | ||
|
|
4a3110974b | ||
|
|
caf09ecd56 |
@@ -0,0 +1,158 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"registries": [
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-ROUTE",
|
||||||
|
"path": "src/contracts/routes.js",
|
||||||
|
"exportName": "ROUTE_REGISTRY",
|
||||||
|
"owner": "feature-routing-navigation-guard-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"routeId",
|
||||||
|
"path",
|
||||||
|
"paramsSchema",
|
||||||
|
"searchSchema",
|
||||||
|
"access",
|
||||||
|
"loadingSurface",
|
||||||
|
"errorSurface",
|
||||||
|
"chunkId"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-API",
|
||||||
|
"path": "src/contracts/api-operations.js",
|
||||||
|
"exportName": "API_OPERATIONS",
|
||||||
|
"owner": "feature-api-client-response-envelope-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"method",
|
||||||
|
"path",
|
||||||
|
"operationId",
|
||||||
|
"auth",
|
||||||
|
"timeoutMs",
|
||||||
|
"idempotency",
|
||||||
|
"requestSchema",
|
||||||
|
"responseSchema",
|
||||||
|
"owner"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-ENV",
|
||||||
|
"path": "src/contracts/env.js",
|
||||||
|
"exportName": "ENV_REGISTRY",
|
||||||
|
"owner": "feature-frontend-env-runtime-config-contract",
|
||||||
|
"requiredFields": ["phase", "classification", "required", "defaultValue"]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-STORAGE",
|
||||||
|
"path": "src/contracts/storage-keys.js",
|
||||||
|
"exportName": "STORAGE_REGISTRY",
|
||||||
|
"owner": "feature-frontend-storage-registry-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"logicalName",
|
||||||
|
"physicalKey",
|
||||||
|
"backend",
|
||||||
|
"classification",
|
||||||
|
"schemaVersion",
|
||||||
|
"ttl",
|
||||||
|
"migration",
|
||||||
|
"quotaFallback"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-ERROR",
|
||||||
|
"path": "src/contracts/errors.js",
|
||||||
|
"exportName": "ERROR_REGISTRY",
|
||||||
|
"owner": "feature-frontend-error-classification-boundary-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"kind",
|
||||||
|
"defaultRetryable",
|
||||||
|
"severity",
|
||||||
|
"userMessageKey",
|
||||||
|
"action",
|
||||||
|
"telemetryEvent",
|
||||||
|
"redaction"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-QUERY",
|
||||||
|
"path": "src/contracts/query-keys.js",
|
||||||
|
"exportName": "QUERY_REGISTRY",
|
||||||
|
"owner": "feature-server-state-caching-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"namespace",
|
||||||
|
"serialization",
|
||||||
|
"identity",
|
||||||
|
"invalidation",
|
||||||
|
"version",
|
||||||
|
"persistence"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-TELEMETRY",
|
||||||
|
"path": "src/contracts/telemetry.js",
|
||||||
|
"exportName": "TELEMETRY_REGISTRY",
|
||||||
|
"owner": "feature-frontend-observability-logging-trace-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"eventName",
|
||||||
|
"trigger",
|
||||||
|
"requiredAttributes",
|
||||||
|
"optionalAttributes",
|
||||||
|
"forbiddenAttributes",
|
||||||
|
"sampling",
|
||||||
|
"delivery"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-RELEASE",
|
||||||
|
"path": "src/contracts/release-tokens.js",
|
||||||
|
"exportName": "RELEASE_TOKEN_REGISTRY",
|
||||||
|
"owner": "feature-frontend-release-cache-rollback-contract",
|
||||||
|
"requiredFields": ["token", "source", "compatibilityRole"],
|
||||||
|
"declaredRows": {
|
||||||
|
"appVersion": {
|
||||||
|
"token": "appVersion",
|
||||||
|
"source": "manifest",
|
||||||
|
"compatibilityRole": "human release label"
|
||||||
|
},
|
||||||
|
"buildId": {
|
||||||
|
"token": "buildId",
|
||||||
|
"source": "CI build",
|
||||||
|
"compatibilityRole": "asset and HTML coherence"
|
||||||
|
},
|
||||||
|
"commitSha": {
|
||||||
|
"token": "commitSha",
|
||||||
|
"source": "VCS",
|
||||||
|
"compatibilityRole": "source traceability"
|
||||||
|
},
|
||||||
|
"configSchemaVersion": {
|
||||||
|
"token": "configSchemaVersion",
|
||||||
|
"source": "runtime config schema",
|
||||||
|
"compatibilityRole": "boot compatibility"
|
||||||
|
},
|
||||||
|
"apiContractVersion": {
|
||||||
|
"token": "apiContractVersion",
|
||||||
|
"source": "frontend/backend agreement",
|
||||||
|
"compatibilityRole": "schema compatibility"
|
||||||
|
},
|
||||||
|
"assetManifestHash": {
|
||||||
|
"token": "assetManifestHash",
|
||||||
|
"source": "build output",
|
||||||
|
"compatibilityRole": "chunk integrity"
|
||||||
|
},
|
||||||
|
"releaseId": {
|
||||||
|
"token": "releaseId",
|
||||||
|
"source": "deploy system",
|
||||||
|
"compatibilityRole": "rollback target"
|
||||||
|
},
|
||||||
|
"builtAt": {
|
||||||
|
"token": "builtAt",
|
||||||
|
"source": "CI",
|
||||||
|
"compatibilityRole": "diagnostics only"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"compatibilityImpact": {
|
||||||
|
"allowed": ["none", "additive", "behavior-change", "breaking"],
|
||||||
|
"current": "additive"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"headers": {
|
||||||
|
"Content-Security-Policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
|
"Strict-Transport-Security": "max-age=31536000; includeSubDomains",
|
||||||
|
"X-Frame-Options": "DENY",
|
||||||
|
"Referrer-Policy": "strict-origin-when-cross-origin",
|
||||||
|
"X-Content-Type-Options": "nosniff",
|
||||||
|
"Permissions-Policy": "camera=(), microphone=(), geolocation=()"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
# Browser security boundary
|
||||||
|
|
||||||
|
The browser bundle is public. Secrets, token lifecycle, raw HTML injection,
|
||||||
|
dynamic code execution, untrusted script URLs, and public production source
|
||||||
|
maps are prohibited defaults.
|
||||||
|
|
||||||
|
`config/hosting/security-headers.json` is the declared header set. Hosting
|
||||||
|
verification compares that declaration with live responses. CSP deliberately
|
||||||
|
omits `unsafe-inline` and `unsafe-eval`; production code and built assets must
|
||||||
|
remain compatible with that baseline.
|
||||||
|
|
||||||
|
Route guards are UX hints and client validation does not replace backend
|
||||||
|
authorization or validation.
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
# Build and supply-chain gate
|
||||||
|
|
||||||
|
Merge and release controls:
|
||||||
|
|
||||||
|
- frozen `pnpm-lock.yaml` installation; drift is blocking
|
||||||
|
- clean production build with hashed assets and build manifest
|
||||||
|
- machine-readable bundle sizes and checksums
|
||||||
|
- source plus built-asset credential-pattern scan
|
||||||
|
- direct dependency inventory and lockfile digest
|
||||||
|
- base/head dependency diff review record
|
||||||
|
|
||||||
|
Organization-specific vulnerability severity, denied-license list, SBOM format,
|
||||||
|
and scanner selection remain policy inputs. An approved suppression must record
|
||||||
|
reason, owner, expiry, affected package, and compensating control. Expired
|
||||||
|
suppressions are blocking.
|
||||||
|
|
||||||
|
`artifacts/security/dependency-diff.json` is a local baseline. CI replaces it
|
||||||
|
with the actual base/head direct and transitive lockfile diff before release.
|
||||||
@@ -35,6 +35,7 @@ export default [
|
|||||||
"artifacts/**",
|
"artifacts/**",
|
||||||
"tests/fixtures/typecheck/**",
|
"tests/fixtures/typecheck/**",
|
||||||
"tests/fixtures/architecture/forbidden/**",
|
"tests/fixtures/architecture/forbidden/**",
|
||||||
|
"tests/fixtures/security/forbidden/**",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
eslint.configs.recommended,
|
eslint.configs.recommended,
|
||||||
@@ -98,4 +99,24 @@ export default [
|
|||||||
]),
|
]),
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
files: ["**/*.{js,jsx}"],
|
||||||
|
rules: {
|
||||||
|
"no-eval": "error",
|
||||||
|
"no-new-func": "error",
|
||||||
|
"no-script-url": "error",
|
||||||
|
"no-restricted-syntax": [
|
||||||
|
"error",
|
||||||
|
{
|
||||||
|
selector: "JSXAttribute[name.name='dangerouslySetInnerHTML']",
|
||||||
|
message: "Raw HTML injection is prohibited by FE-OC-019.",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
selector:
|
||||||
|
"CallExpression[callee.object.name='document'][callee.property.name='createElement'][arguments.0.value='script']",
|
||||||
|
message: "Runtime script construction is prohibited by FE-OC-019.",
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
},
|
||||||
];
|
];
|
||||||
|
|||||||
+7
-1
@@ -11,6 +11,7 @@
|
|||||||
"scripts": {
|
"scripts": {
|
||||||
"dev": "vite",
|
"dev": "vite",
|
||||||
"build": "vite build && node scripts/generate-build-manifest.mjs",
|
"build": "vite build && node scripts/generate-build-manifest.mjs",
|
||||||
|
"build:release": "corepack pnpm build && corepack pnpm generate:supply-chain && corepack pnpm scan:security",
|
||||||
"preview": "vite preview",
|
"preview": "vite preview",
|
||||||
"lint": "eslint src scripts tests vite.config.js vitest.config.js playwright.config.js --max-warnings=0",
|
"lint": "eslint src scripts tests vite.config.js vitest.config.js playwright.config.js --max-warnings=0",
|
||||||
"check:architecture": "node scripts/check-architecture.mjs",
|
"check:architecture": "node scripts/check-architecture.mjs",
|
||||||
@@ -24,7 +25,12 @@
|
|||||||
"test:a11y": "playwright test --grep @a11y && node scripts/write-a11y-report.mjs",
|
"test:a11y": "playwright test --grep @a11y && node scripts/write-a11y-report.mjs",
|
||||||
"review:a11y-manual": "node scripts/verify-a11y-manual.mjs",
|
"review:a11y-manual": "node scripts/verify-a11y-manual.mjs",
|
||||||
"test:sample-removal": "node scripts/test-sample-removal.mjs",
|
"test:sample-removal": "node scripts/test-sample-removal.mjs",
|
||||||
"test:all": "pnpm test:runtime-schema && pnpm test:unit && pnpm test:component && pnpm test:integration"
|
"test:all": "corepack pnpm test:runtime-schema && corepack pnpm test:unit && corepack pnpm test:component && corepack pnpm test:integration",
|
||||||
|
"verify:lockfile": "corepack pnpm install --frozen-lockfile",
|
||||||
|
"generate:supply-chain": "node scripts/generate-supply-chain.mjs",
|
||||||
|
"scan:security": "node scripts/security-scan.mjs",
|
||||||
|
"check:browser-security": "node scripts/check-browser-security.mjs",
|
||||||
|
"check:registries": "node scripts/check-registries.mjs"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@tanstack/react-query": "5.101.4",
|
"@tanstack/react-query": "5.101.4",
|
||||||
|
|||||||
@@ -0,0 +1,39 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||||
|
"$id": "build-manifest.schema.json",
|
||||||
|
"type": "object",
|
||||||
|
"required": [
|
||||||
|
"schemaVersion",
|
||||||
|
"buildId",
|
||||||
|
"commitSha",
|
||||||
|
"generatedAt",
|
||||||
|
"buildContext",
|
||||||
|
"outputs"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"schemaVersion": { "const": 1 },
|
||||||
|
"buildId": { "type": "string", "minLength": 1 },
|
||||||
|
"commitSha": { "type": "string", "minLength": 1 },
|
||||||
|
"generatedAt": { "type": "string", "format": "date-time" },
|
||||||
|
"buildContext": {
|
||||||
|
"type": "object",
|
||||||
|
"required": ["nodeVersion", "packageManagerVersion", "runnerImage"],
|
||||||
|
"properties": {
|
||||||
|
"nodeVersion": { "type": "string" },
|
||||||
|
"packageManagerVersion": { "type": "string" },
|
||||||
|
"runnerImage": { "type": "string" }
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
},
|
||||||
|
"outputs": {
|
||||||
|
"type": "object",
|
||||||
|
"required": ["directory", "viteManifest"],
|
||||||
|
"properties": {
|
||||||
|
"directory": { "type": "string" },
|
||||||
|
"viteManifest": { "type": "string" }
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
}
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||||
|
"type": "object",
|
||||||
|
"required": [
|
||||||
|
"schemaVersion",
|
||||||
|
"generatedAt",
|
||||||
|
"compatibilityImpact",
|
||||||
|
"failures",
|
||||||
|
"registries"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"schemaVersion": { "const": 1 },
|
||||||
|
"generatedAt": { "type": "string", "format": "date-time" },
|
||||||
|
"compatibilityImpact": {
|
||||||
|
"enum": ["none", "additive", "behavior-change", "breaking"]
|
||||||
|
},
|
||||||
|
"failures": { "type": "array", "maxItems": 0 },
|
||||||
|
"registries": {
|
||||||
|
"type": "array",
|
||||||
|
"minItems": 8,
|
||||||
|
"maxItems": 8,
|
||||||
|
"items": {
|
||||||
|
"type": "object",
|
||||||
|
"required": ["registryId", "owner", "source", "rowCount", "rows"]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
}
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
import { readdir } from "node:fs/promises";
|
||||||
|
import { spawnSync } from "node:child_process";
|
||||||
|
|
||||||
|
const pnpmCli = /** @type {string} */ (process.env.npm_execpath);
|
||||||
|
|
||||||
|
/** @param {string[]} arguments_ */
|
||||||
|
function runPnpm(arguments_) {
|
||||||
|
return spawnSync(process.execPath, [pnpmCli, ...arguments_], {
|
||||||
|
encoding: "utf8",
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const allowed = runPnpm([
|
||||||
|
"exec",
|
||||||
|
"eslint",
|
||||||
|
"tests/fixtures/security/allowed",
|
||||||
|
"--no-ignore",
|
||||||
|
"--max-warnings=0",
|
||||||
|
]);
|
||||||
|
const forbidden = runPnpm([
|
||||||
|
"exec",
|
||||||
|
"eslint",
|
||||||
|
"tests/fixtures/security/forbidden",
|
||||||
|
"--no-ignore",
|
||||||
|
"--max-warnings=0",
|
||||||
|
]);
|
||||||
|
|
||||||
|
const distFiles = await readdir("dist", { recursive: true });
|
||||||
|
const publicSourceMaps = distFiles.filter((file) => String(file).endsWith(".map"));
|
||||||
|
|
||||||
|
if (allowed.status !== 0 || forbidden.status === 0 || publicSourceMaps.length > 0) {
|
||||||
|
process.stderr.write(allowed.stderr || allowed.stdout);
|
||||||
|
process.stderr.write(forbidden.stderr || forbidden.stdout);
|
||||||
|
if (publicSourceMaps.length > 0) {
|
||||||
|
process.stderr.write(`Public source maps found: ${publicSourceMaps.join(", ")}\n`);
|
||||||
|
}
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
process.stdout.write(
|
||||||
|
"Browser security fixtures: injection rejected, public source maps absent\n",
|
||||||
|
);
|
||||||
@@ -0,0 +1,112 @@
|
|||||||
|
import { access, mkdir, readFile, writeFile } from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
import { pathToFileURL } from "node:url";
|
||||||
|
|
||||||
|
const governance = JSON.parse(
|
||||||
|
await readFile("config/contracts/registry-governance.json", "utf8"),
|
||||||
|
);
|
||||||
|
const failures = [];
|
||||||
|
const owners = new Map();
|
||||||
|
const snapshots = [];
|
||||||
|
|
||||||
|
for (const specification of governance.registries) {
|
||||||
|
if (owners.has(specification.registryId)) {
|
||||||
|
failures.push(`duplicate owner for ${specification.registryId}`);
|
||||||
|
}
|
||||||
|
owners.set(specification.registryId, specification.owner);
|
||||||
|
|
||||||
|
let rows = specification.declaredRows;
|
||||||
|
try {
|
||||||
|
await access(specification.path);
|
||||||
|
const module = await import(
|
||||||
|
`${pathToFileURL(path.resolve(specification.path)).href}?registry-check=${Date.now()}`
|
||||||
|
);
|
||||||
|
rows = module[specification.exportName];
|
||||||
|
} catch {
|
||||||
|
if (!rows) failures.push(`missing registry source ${specification.path}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!rows || typeof rows !== "object" || Array.isArray(rows)) {
|
||||||
|
failures.push(`${specification.registryId} is not an object registry`);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const [rowName, row] of Object.entries(rows)) {
|
||||||
|
if (!row || typeof row !== "object" || Array.isArray(row)) {
|
||||||
|
failures.push(`${specification.registryId}.${rowName} is not an object`);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
for (const field of specification.requiredFields) {
|
||||||
|
if (!(field in row)) {
|
||||||
|
failures.push(`${specification.registryId}.${rowName} missing ${field}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
snapshots.push({
|
||||||
|
registryId: specification.registryId,
|
||||||
|
owner: specification.owner,
|
||||||
|
source: specification.path,
|
||||||
|
rowCount: Object.keys(rows).length,
|
||||||
|
rows,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const sourceFiles = [
|
||||||
|
"src/application",
|
||||||
|
"src/presentation",
|
||||||
|
"src/domain",
|
||||||
|
];
|
||||||
|
const adHocPatterns = [
|
||||||
|
{ name: "direct fetch", expression: /\bfetch\s*\(/ },
|
||||||
|
{ name: "direct localStorage", expression: /\blocalStorage\.(?:get|set|remove)Item/ },
|
||||||
|
{ name: "direct import.meta.env", expression: /\bimport\.meta\.env\./ },
|
||||||
|
{ name: "raw API path", expression: /["']\/api\// },
|
||||||
|
];
|
||||||
|
|
||||||
|
/** @param {string} directory */
|
||||||
|
async function scanDirectory(directory) {
|
||||||
|
const entries = await import("node:fs/promises").then(({ readdir }) =>
|
||||||
|
readdir(directory, { withFileTypes: true }),
|
||||||
|
);
|
||||||
|
for (const entry of entries) {
|
||||||
|
const target = path.join(directory, entry.name);
|
||||||
|
if (entry.isDirectory()) {
|
||||||
|
await scanDirectory(target);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if (!/\.(js|jsx|mjs)$/.test(entry.name)) continue;
|
||||||
|
const content = await readFile(target, "utf8");
|
||||||
|
for (const pattern of adHocPatterns) {
|
||||||
|
if (pattern.expression.test(content)) {
|
||||||
|
failures.push(`ad-hoc ${pattern.name} in ${target}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const sourceDirectory of sourceFiles) {
|
||||||
|
await scanDirectory(sourceDirectory);
|
||||||
|
}
|
||||||
|
|
||||||
|
await mkdir("artifacts/quality", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/quality/registries.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
generatedAt: new Date().toISOString(),
|
||||||
|
compatibilityImpact: governance.compatibilityImpact.current,
|
||||||
|
failures,
|
||||||
|
registries: snapshots,
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
if (failures.length > 0) {
|
||||||
|
process.stderr.write(`Registry governance failed:\n${failures.join("\n")}\n`);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(`Registry governance: ${snapshots.length} registries PASS\n`);
|
||||||
@@ -0,0 +1,102 @@
|
|||||||
|
import { createHash } from "node:crypto";
|
||||||
|
import { gzipSync } from "node:zlib";
|
||||||
|
import {
|
||||||
|
mkdir,
|
||||||
|
readFile,
|
||||||
|
readdir,
|
||||||
|
stat,
|
||||||
|
writeFile,
|
||||||
|
} from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
|
/** @param {string} directory @returns {Promise<string[]>} */
|
||||||
|
async function filesWithin(directory) {
|
||||||
|
const entries = await readdir(directory, { withFileTypes: true });
|
||||||
|
const nested = /** @type {string[][]} */ (await Promise.all(
|
||||||
|
entries.map((entry) => {
|
||||||
|
const target = path.join(directory, entry.name);
|
||||||
|
return entry.isDirectory() ? filesWithin(target) : [target];
|
||||||
|
}),
|
||||||
|
));
|
||||||
|
return nested.flat().sort();
|
||||||
|
}
|
||||||
|
|
||||||
|
const packageJson = JSON.parse(await readFile("package.json", "utf8"));
|
||||||
|
const lockfile = await readFile("pnpm-lock.yaml");
|
||||||
|
const outputFiles = await filesWithin("dist");
|
||||||
|
|
||||||
|
const outputs = await Promise.all(
|
||||||
|
outputFiles.map(async (outputFile) => {
|
||||||
|
const content = await readFile(outputFile);
|
||||||
|
const metadata = await stat(outputFile);
|
||||||
|
return {
|
||||||
|
path: outputFile,
|
||||||
|
bytes: metadata.size,
|
||||||
|
gzipBytes: gzipSync(content).byteLength,
|
||||||
|
sha256: createHash("sha256").update(content).digest("hex"),
|
||||||
|
};
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
|
||||||
|
const dependencies = {
|
||||||
|
...packageJson.dependencies,
|
||||||
|
...packageJson.devDependencies,
|
||||||
|
};
|
||||||
|
const inventory = Object.entries(dependencies)
|
||||||
|
.sort(([left], [right]) => left.localeCompare(right))
|
||||||
|
.map(([name, version]) => ({ name, version, direct: true }));
|
||||||
|
|
||||||
|
await mkdir("artifacts/performance", { recursive: true });
|
||||||
|
await mkdir("artifacts/release", { recursive: true });
|
||||||
|
await mkdir("artifacts/security", { recursive: true });
|
||||||
|
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/performance/bundle.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
generatedAt: new Date().toISOString(),
|
||||||
|
context: {
|
||||||
|
nodeVersion: process.version,
|
||||||
|
packageManager: packageJson.packageManager,
|
||||||
|
runnerImage: process.env.CI_RUNNER_IMAGE ?? `${process.platform}-${process.arch}`,
|
||||||
|
},
|
||||||
|
outputs,
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/release/dependency-inventory.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
lockfileSha256: createHash("sha256").update(lockfile).digest("hex"),
|
||||||
|
dependencies: inventory,
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/release/checksums.txt",
|
||||||
|
`${outputs.map((output) => `${output.sha256} ${output.path}`).join("\n")}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/security/dependency-diff.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
reviewStatus: "local-baseline",
|
||||||
|
directDependencies: inventory.length,
|
||||||
|
highRiskUnreviewed: [],
|
||||||
|
lockfileSha256: createHash("sha256").update(lockfile).digest("hex"),
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
@@ -0,0 +1,82 @@
|
|||||||
|
import { mkdir, readFile, readdir, writeFile } from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
|
const scanRoots = ["src", "dist"];
|
||||||
|
const findings = /** @type {Array<{ruleId: string, file: string}>} */ ([]);
|
||||||
|
const patterns = [
|
||||||
|
{ id: "private-key", expression: /-----BEGIN (?:RSA |EC )?PRIVATE KEY-----/g },
|
||||||
|
{ id: "aws-access-key", expression: /\bAKIA[0-9A-Z]{16}\b/g },
|
||||||
|
{ id: "github-token", expression: /\bgh[pousr]_[A-Za-z0-9_]{30,}\b/g },
|
||||||
|
{
|
||||||
|
id: "assigned-secret",
|
||||||
|
expression:
|
||||||
|
/\b(?:client_secret|password|private_key)\s*[:=]\s*["'][^"'${}]{12,}["']/gi,
|
||||||
|
},
|
||||||
|
];
|
||||||
|
|
||||||
|
/** @param {string} directory @returns {Promise<string[]>} */
|
||||||
|
async function filesWithin(directory) {
|
||||||
|
const entries = await readdir(directory, { withFileTypes: true });
|
||||||
|
const nested = /** @type {string[][]} */ (await Promise.all(
|
||||||
|
entries.map((entry) => {
|
||||||
|
const target = path.join(directory, entry.name);
|
||||||
|
return entry.isDirectory() ? filesWithin(target) : [target];
|
||||||
|
}),
|
||||||
|
));
|
||||||
|
return nested.flat();
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const root of scanRoots) {
|
||||||
|
for (const scanFile of await filesWithin(root)) {
|
||||||
|
if (/\.(png|jpg|jpeg|gif|woff2?|zip)$/i.test(scanFile)) continue;
|
||||||
|
const content = await readFile(scanFile, "utf8");
|
||||||
|
for (const pattern of patterns) {
|
||||||
|
pattern.expression.lastIndex = 0;
|
||||||
|
if (pattern.expression.test(content)) {
|
||||||
|
findings.push({ ruleId: pattern.id, file: scanFile });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const sarif = {
|
||||||
|
version: "2.1.0",
|
||||||
|
$schema:
|
||||||
|
"https://json.schemastore.org/sarif-2.1.0.json",
|
||||||
|
runs: [
|
||||||
|
{
|
||||||
|
tool: {
|
||||||
|
driver: {
|
||||||
|
name: "ca-frontend-secret-scan",
|
||||||
|
rules: patterns.map((pattern) => ({
|
||||||
|
id: pattern.id,
|
||||||
|
shortDescription: { text: "Potential credential material" },
|
||||||
|
})),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
results: findings.map((finding) => ({
|
||||||
|
ruleId: finding.ruleId,
|
||||||
|
message: { text: "Potential secret material must be removed." },
|
||||||
|
locations: [
|
||||||
|
{
|
||||||
|
physicalLocation: {
|
||||||
|
artifactLocation: { uri: finding.file },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
],
|
||||||
|
})),
|
||||||
|
},
|
||||||
|
],
|
||||||
|
};
|
||||||
|
|
||||||
|
await mkdir("artifacts/security", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/security/scan.sarif",
|
||||||
|
`${JSON.stringify(sarif, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
if (findings.length > 0) {
|
||||||
|
process.stderr.write(`Security scan found ${findings.length} blocking result(s).\n`);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write("Source and built-asset secret scan: PASS\n");
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
/**
|
||||||
|
* Untrusted content is rendered as a React text node. HTML interpretation is
|
||||||
|
* intentionally not offered by this template.
|
||||||
|
*
|
||||||
|
* @param {{ value: unknown }} props
|
||||||
|
*/
|
||||||
|
export function SafeText({ value }) {
|
||||||
|
return <span>{typeof value === "string" ? value : String(value ?? "")}</span>;
|
||||||
|
}
|
||||||
@@ -0,0 +1,53 @@
|
|||||||
|
// @vitest-environment jsdom
|
||||||
|
|
||||||
|
import { render, screen } from "@testing-library/react";
|
||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import { SafeText } from "../../src/presentation/security/safe-text.jsx";
|
||||||
|
import { assertSafeConfigNames } from "../../src/contracts/env.js";
|
||||||
|
import { defineStorageKey } from "../../src/contracts/storage-keys.js";
|
||||||
|
import { projectTelemetryEvent } from "../../src/contracts/telemetry.js";
|
||||||
|
|
||||||
|
describe("browser security boundary", () => {
|
||||||
|
it("renders untrusted text without script or inline handler injection", () => {
|
||||||
|
render(
|
||||||
|
<SafeText value={'<img src=x onerror="window.compromised=true"><script>x</script>'} />,
|
||||||
|
);
|
||||||
|
expect(screen.getByText(/<img/)).toBeVisible();
|
||||||
|
expect(document.querySelector("script")).toBeNull();
|
||||||
|
expect(document.querySelector("[onerror]")).toBeNull();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("rejects secret-like client configuration names", () => {
|
||||||
|
expect(() => assertSafeConfigNames({ PRIVATE_KEY: "not-public" })).toThrow();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("rejects browser token storage registration", () => {
|
||||||
|
expect(() =>
|
||||||
|
defineStorageKey({
|
||||||
|
logicalName: "SESSION_TOKEN",
|
||||||
|
scope: "auth",
|
||||||
|
name: "session-token",
|
||||||
|
backend: "sessionStorage",
|
||||||
|
classification: "sensitive-forbidden",
|
||||||
|
schemaVersion: 1,
|
||||||
|
ttl: "session",
|
||||||
|
migration: "discard",
|
||||||
|
quotaFallback: "feature-disable",
|
||||||
|
}),
|
||||||
|
).toThrow();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("drops raw URL/query/token telemetry attributes", () => {
|
||||||
|
const result = projectTelemetryEvent("api.request.failed", {
|
||||||
|
error_kind: "SERVER_FAILURE",
|
||||||
|
http_status_group: "5xx",
|
||||||
|
attempt_count_bucket: "1",
|
||||||
|
route_id: "APP_HOME",
|
||||||
|
raw_url: "https://api.test?token=private",
|
||||||
|
query_string: "token=private",
|
||||||
|
});
|
||||||
|
expect(result.success).toBe(true);
|
||||||
|
expect(JSON.stringify(result)).not.toMatch(/raw_url|query_string|private/);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
export function Fixture({ value }) {
|
||||||
|
return <span>{value}</span>;
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
export function attachScript(source) {
|
||||||
|
const script = document.createElement("script");
|
||||||
|
script.src = source;
|
||||||
|
document.head.append(script);
|
||||||
|
}
|
||||||
+1
@@ -0,0 +1 @@
|
|||||||
|
export const execute = (source) => eval(source);
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
export function RawHtml({ value }) {
|
||||||
|
return <div dangerouslySetInnerHTML={{ __html: value }} />;
|
||||||
|
}
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
import { readFile } from "node:fs/promises";
|
||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
describe("registry governance manifest", () => {
|
||||||
|
it("declares exactly eight single-owner registries and impact labels", async () => {
|
||||||
|
const governance = JSON.parse(
|
||||||
|
await readFile("config/contracts/registry-governance.json", "utf8"),
|
||||||
|
);
|
||||||
|
expect(governance.registries).toHaveLength(8);
|
||||||
|
expect(new Set(governance.registries.map((entry) => entry.registryId)).size).toBe(
|
||||||
|
8,
|
||||||
|
);
|
||||||
|
expect(governance.registries.every((entry) => entry.owner)).toBe(true);
|
||||||
|
expect(governance.compatibilityImpact.allowed).toEqual([
|
||||||
|
"none",
|
||||||
|
"additive",
|
||||||
|
"behavior-change",
|
||||||
|
"breaking",
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
});
|
||||||
Reference in New Issue
Block a user