Compare commits
4
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6b4b956d51 | ||
|
|
a2a97ebcc7 | ||
|
|
b1625252d5 | ||
|
|
9d40724ab2 |
@@ -4,25 +4,21 @@
|
|||||||
"index": {
|
"index": {
|
||||||
"path": "/",
|
"path": "/",
|
||||||
"cacheControl": "no-cache",
|
"cacheControl": "no-cache",
|
||||||
"contentTypes": ["text/html"],
|
|
||||||
"securityHeaders": true
|
"securityHeaders": true
|
||||||
},
|
},
|
||||||
"runtimeConfig": {
|
"runtimeConfig": {
|
||||||
"path": "/config.json",
|
"path": "/config.json",
|
||||||
"cacheControl": "no-store",
|
"cacheControl": "no-store",
|
||||||
"contentTypes": ["application/json"],
|
|
||||||
"securityHeaders": true
|
"securityHeaders": true
|
||||||
},
|
},
|
||||||
"releaseManifest": {
|
"releaseManifest": {
|
||||||
"path": "/release-manifest.json",
|
"path": "/release-manifest.json",
|
||||||
"cacheControl": "no-store",
|
"cacheControl": "no-store",
|
||||||
"contentTypes": ["application/json"],
|
|
||||||
"securityHeaders": true
|
"securityHeaders": true
|
||||||
},
|
},
|
||||||
"hashedAsset": {
|
"hashedAsset": {
|
||||||
"pathPattern": "/assets/*",
|
"pathPattern": "/assets/*",
|
||||||
"cacheControl": "public, max-age=31536000, immutable",
|
"cacheControl": "public, max-age=31536000, immutable",
|
||||||
"contentTypes": ["text/javascript", "application/javascript"],
|
|
||||||
"securityHeaders": false
|
"securityHeaders": false
|
||||||
},
|
},
|
||||||
"sourceMap": {
|
"sourceMap": {
|
||||||
|
|||||||
@@ -3,7 +3,6 @@
|
|||||||
"responses": {
|
"responses": {
|
||||||
"index": {
|
"index": {
|
||||||
"cache-control": "no-cache",
|
"cache-control": "no-cache",
|
||||||
"content-type": "text/html; charset=utf-8",
|
|
||||||
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
"x-frame-options": "DENY",
|
"x-frame-options": "DENY",
|
||||||
@@ -13,7 +12,6 @@
|
|||||||
},
|
},
|
||||||
"runtimeConfig": {
|
"runtimeConfig": {
|
||||||
"cache-control": "no-store",
|
"cache-control": "no-store",
|
||||||
"content-type": "application/json; charset=utf-8",
|
|
||||||
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
"x-frame-options": "DENY",
|
"x-frame-options": "DENY",
|
||||||
@@ -23,7 +21,6 @@
|
|||||||
},
|
},
|
||||||
"releaseManifest": {
|
"releaseManifest": {
|
||||||
"cache-control": "no-store",
|
"cache-control": "no-store",
|
||||||
"content-type": "application/json; charset=utf-8",
|
|
||||||
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
"x-frame-options": "DENY",
|
"x-frame-options": "DENY",
|
||||||
@@ -32,8 +29,7 @@
|
|||||||
"permissions-policy": "camera=(), microphone=(), geolocation=()"
|
"permissions-policy": "camera=(), microphone=(), geolocation=()"
|
||||||
},
|
},
|
||||||
"hashedAsset": {
|
"hashedAsset": {
|
||||||
"cache-control": "public, max-age=31536000, immutable",
|
"cache-control": "public, max-age=31536000, immutable"
|
||||||
"content-type": "text/javascript; charset=utf-8"
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"bundle": {
|
||||||
|
"initialJsGzipBytes": 204800,
|
||||||
|
"lazyChunkGzipBytes": 122880
|
||||||
|
},
|
||||||
|
"lab": {
|
||||||
|
"lcpMs": 2500,
|
||||||
|
"cls": 0.1,
|
||||||
|
"namedInteractionMs": 200
|
||||||
|
},
|
||||||
|
"field": {
|
||||||
|
"p75LcpMs": 2500,
|
||||||
|
"p75Cls": 0.1,
|
||||||
|
"p75InpMs": 200,
|
||||||
|
"minimumEligibleSamples": null
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"releaseId": "local-release",
|
||||||
|
"environment": "replace-with-production",
|
||||||
|
"source": {
|
||||||
|
"system": "",
|
||||||
|
"exportId": ""
|
||||||
|
},
|
||||||
|
"privacy": {
|
||||||
|
"approved": false,
|
||||||
|
"approvalRef": ""
|
||||||
|
},
|
||||||
|
"window": {
|
||||||
|
"start": "2026-06-01T00:00:00Z",
|
||||||
|
"end": "2026-06-29T00:00:00Z"
|
||||||
|
},
|
||||||
|
"thresholdDecision": {
|
||||||
|
"status": "pending",
|
||||||
|
"minimumEligibleSamples": null,
|
||||||
|
"owner": "",
|
||||||
|
"reviewedAt": "",
|
||||||
|
"evidenceRef": ""
|
||||||
|
},
|
||||||
|
"samples": []
|
||||||
|
}
|
||||||
@@ -0,0 +1,78 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||||
|
"$id": "ART-FE-FIELD-WEB-VITALS@1",
|
||||||
|
"type": "object",
|
||||||
|
"required": [
|
||||||
|
"schemaVersion",
|
||||||
|
"generatedAt",
|
||||||
|
"window",
|
||||||
|
"context",
|
||||||
|
"metrics",
|
||||||
|
"thresholds",
|
||||||
|
"eligibility",
|
||||||
|
"status",
|
||||||
|
"passed"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"schemaVersion": { "const": 1 },
|
||||||
|
"generatedAt": { "type": "string", "format": "date-time" },
|
||||||
|
"window": { "type": "object", "required": ["days", "start", "end"] },
|
||||||
|
"context": {
|
||||||
|
"type": "object",
|
||||||
|
"required": [
|
||||||
|
"source",
|
||||||
|
"sourceSystem",
|
||||||
|
"exportId",
|
||||||
|
"network",
|
||||||
|
"routeAggregation",
|
||||||
|
"releaseId",
|
||||||
|
"privacyApprovalRef",
|
||||||
|
"thresholdDecisionRef",
|
||||||
|
"validationFailures"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"source": { "type": "string" },
|
||||||
|
"sourceSystem": { "type": ["string", "null"] },
|
||||||
|
"exportId": { "type": ["string", "null"] },
|
||||||
|
"network": { "const": "production-real-user" },
|
||||||
|
"routeAggregation": { "const": "route-id-only" },
|
||||||
|
"releaseId": { "type": ["string", "null"] },
|
||||||
|
"privacyApprovalRef": { "type": ["string", "null"] },
|
||||||
|
"thresholdDecisionRef": { "type": ["string", "null"] },
|
||||||
|
"validationFailures": {
|
||||||
|
"type": "array",
|
||||||
|
"items": { "type": "string" }
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
},
|
||||||
|
"thresholds": {
|
||||||
|
"type": "object",
|
||||||
|
"required": [
|
||||||
|
"p75LcpMs",
|
||||||
|
"p75Cls",
|
||||||
|
"p75InpMs",
|
||||||
|
"minimumEligibleSamples"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"metrics": {
|
||||||
|
"type": "object",
|
||||||
|
"required": ["p75LcpMs", "p75Cls", "p75InpMs"]
|
||||||
|
},
|
||||||
|
"eligibility": {
|
||||||
|
"type": "object",
|
||||||
|
"required": [
|
||||||
|
"consentRequired",
|
||||||
|
"totalSamples",
|
||||||
|
"eligibleSamples",
|
||||||
|
"minimumEligibleSamples",
|
||||||
|
"routeSamples"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"status": {
|
||||||
|
"enum": ["PASS", "FAIL_THRESHOLD", "FAIL_UNVERIFIED"]
|
||||||
|
},
|
||||||
|
"passed": { "type": "boolean" }
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
}
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||||
|
"$id": "ART-FE-LAB@1",
|
||||||
|
"type": "object",
|
||||||
|
"required": [
|
||||||
|
"schemaVersion",
|
||||||
|
"generatedAt",
|
||||||
|
"context",
|
||||||
|
"metrics",
|
||||||
|
"thresholds",
|
||||||
|
"fixtures",
|
||||||
|
"passed"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"schemaVersion": { "const": 1 },
|
||||||
|
"generatedAt": { "type": "string", "format": "date-time" },
|
||||||
|
"context": {
|
||||||
|
"type": "object",
|
||||||
|
"required": ["runner", "browser", "viewport", "network", "cpu", "cache", "build"]
|
||||||
|
},
|
||||||
|
"metrics": {
|
||||||
|
"type": "object",
|
||||||
|
"required": ["lcpMs", "cls", "namedInteractionMs"]
|
||||||
|
},
|
||||||
|
"thresholds": { "type": "object" },
|
||||||
|
"fixtures": { "type": "array", "minItems": 2 },
|
||||||
|
"passed": { "type": "boolean" }
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
# Performance evidence contract
|
||||||
|
|
||||||
|
Performance evidence is deliberately split by measurement context:
|
||||||
|
|
||||||
|
- `bundle.json` records production build output and enforces initial JavaScript
|
||||||
|
at 200 KiB gzip and every lazy chunk at 120 KiB gzip.
|
||||||
|
- `lab.json` records Chromium/runner/viewport/network/CPU/cache/build context and
|
||||||
|
enforces LCP 2.5 s, CLS 0.10, and the named route interaction at 200 ms.
|
||||||
|
- `field-web-vitals.json` records consent-filtered, route-ID aggregated,
|
||||||
|
release-specific production samples over 28 days and evaluates p75 LCP, CLS,
|
||||||
|
and INP against 2.5 s, 0.10, and 200 ms.
|
||||||
|
|
||||||
|
The field minimum eligible-sample threshold is intentionally unresolved until
|
||||||
|
a privacy-approved telemetry baseline exists. Therefore the field command
|
||||||
|
fails closed with `FAIL_UNVERIFIED` when run against the example input. Provide
|
||||||
|
`FIELD_WEB_VITALS_INPUT` and `MIN_ELIGIBLE_SAMPLES` only after that decision is
|
||||||
|
recorded. The external input must identify a production release and an exact
|
||||||
|
28-day export window, name the source/export, carry privacy-approval and
|
||||||
|
threshold-decision references, and contain only non-negative route-ID samples.
|
||||||
|
The environment threshold must be a positive integer equal to the approved
|
||||||
|
decision embedded in the input. Invalid metadata fails as `FAIL_UNVERIFIED`;
|
||||||
|
the example can never serve as production evidence.
|
||||||
@@ -20,13 +20,6 @@ The provider-independent cache defaults are:
|
|||||||
- public source maps: disabled
|
- public source maps: disabled
|
||||||
- service worker/offline cache: disabled
|
- service worker/offline cache: disabled
|
||||||
|
|
||||||
HTML, JSON config/manifest, and hashed JavaScript MIME types are also compared
|
|
||||||
to the declared allowlist; a cache-correct response with a mismatched
|
|
||||||
`Content-Type` still fails the hosting gate.
|
|
||||||
|
|
||||||
`corepack pnpm verify:hosting-headers` uses a deterministic fixture locally.
|
`corepack pnpm verify:hosting-headers` uses a deterministic fixture locally.
|
||||||
Set `HOSTING_BASE_URL` to probe deployed responses; production promotion
|
Set `HOSTING_BASE_URL` to probe deployed responses; production promotion
|
||||||
requires the artifact to report `mode: "live"`. The live target must be its
|
requires the artifact to report `mode: "live"`.
|
||||||
canonical, non-loopback HTTPS root URL. Each required surface must return HTTP
|
|
||||||
200 without leaving that origin before its cache, content-type, and security
|
|
||||||
headers can count as deployment evidence.
|
|
||||||
|
|||||||
+4
-1
@@ -33,7 +33,10 @@
|
|||||||
"check:registries": "node scripts/check-registries.mjs",
|
"check:registries": "node scripts/check-registries.mjs",
|
||||||
"verify:compatibility": "node scripts/check-compatibility.mjs",
|
"verify:compatibility": "node scripts/check-compatibility.mjs",
|
||||||
"verify:release": "node scripts/verify-release.mjs",
|
"verify:release": "node scripts/verify-release.mjs",
|
||||||
"verify:hosting-headers": "node scripts/verify-hosting-headers.mjs"
|
"verify:hosting-headers": "node scripts/verify-hosting-headers.mjs",
|
||||||
|
"check:bundle": "node scripts/generate-supply-chain.mjs && node scripts/check-bundle.mjs",
|
||||||
|
"test:performance": "node scripts/test-performance.mjs",
|
||||||
|
"collect:web-vitals-evidence": "node scripts/collect-web-vitals-evidence.mjs"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@tanstack/react-query": "5.101.4",
|
"@tanstack/react-query": "5.101.4",
|
||||||
|
|||||||
@@ -0,0 +1,100 @@
|
|||||||
|
import { readFile, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
import { evaluateBundleBudget } from "../src/application/policies/performance-budgets.js";
|
||||||
|
import { classifyViteJavascript } from "./lib/classify-vite-bundle.mjs";
|
||||||
|
|
||||||
|
const report =
|
||||||
|
/** @type {{
|
||||||
|
* outputs: Array<{ path: string, gzipBytes: number }>,
|
||||||
|
* [key: string]: unknown
|
||||||
|
* }} */ (
|
||||||
|
JSON.parse(await readFile("artifacts/performance/bundle.json", "utf8"))
|
||||||
|
);
|
||||||
|
const viteManifest =
|
||||||
|
/** @type {Record<string, { file: string, isEntry?: boolean, imports?: string[] }>} */ (
|
||||||
|
JSON.parse(await readFile("dist/.vite/manifest.json", "utf8"))
|
||||||
|
);
|
||||||
|
const budgets =
|
||||||
|
/** @type {{ initialJsGzipBytes: number, lazyChunkGzipBytes: number }} */ (
|
||||||
|
JSON.parse(await readFile("config/performance/budgets.json", "utf8")).bundle
|
||||||
|
);
|
||||||
|
|
||||||
|
const outputByPath = new Map(
|
||||||
|
report.outputs.map((output) => [output.path.replace(/^dist\//, ""), output]),
|
||||||
|
);
|
||||||
|
const classification = classifyViteJavascript(viteManifest);
|
||||||
|
const initialJsGzipBytes = classification.initialFiles.reduce(
|
||||||
|
(total, file) => total + (outputByPath.get(file)?.gzipBytes ?? 0),
|
||||||
|
0,
|
||||||
|
);
|
||||||
|
const lazyChunks = classification.lazyFiles.map((file) => ({
|
||||||
|
path: file,
|
||||||
|
gzipBytes: outputByPath.get(file)?.gzipBytes ?? 0,
|
||||||
|
}));
|
||||||
|
const missingOutputs = [
|
||||||
|
...classification.initialFiles,
|
||||||
|
...classification.lazyFiles,
|
||||||
|
].filter((file) => !outputByPath.has(file));
|
||||||
|
const measurements = { initialJsGzipBytes, lazyChunks };
|
||||||
|
const result = evaluateBundleBudget(measurements, budgets);
|
||||||
|
const fixtures = [
|
||||||
|
{
|
||||||
|
name: "initial-js-over-budget",
|
||||||
|
passed:
|
||||||
|
!evaluateBundleBudget(
|
||||||
|
{
|
||||||
|
initialJsGzipBytes: budgets.initialJsGzipBytes + 1,
|
||||||
|
lazyChunks: [],
|
||||||
|
},
|
||||||
|
budgets,
|
||||||
|
).passed,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "lazy-chunk-over-budget",
|
||||||
|
passed:
|
||||||
|
!evaluateBundleBudget(
|
||||||
|
{
|
||||||
|
initialJsGzipBytes: 0,
|
||||||
|
lazyChunks: [
|
||||||
|
{
|
||||||
|
path: "fixture.js",
|
||||||
|
gzipBytes: budgets.lazyChunkGzipBytes + 1,
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
budgets,
|
||||||
|
).passed,
|
||||||
|
},
|
||||||
|
];
|
||||||
|
const passed =
|
||||||
|
result.passed &&
|
||||||
|
fixtures.every((fixture) => fixture.passed) &&
|
||||||
|
classification.missingImports.length === 0 &&
|
||||||
|
missingOutputs.length === 0;
|
||||||
|
const completedReport = {
|
||||||
|
...report,
|
||||||
|
measurements,
|
||||||
|
classification,
|
||||||
|
missingOutputs,
|
||||||
|
thresholds: budgets,
|
||||||
|
results: result,
|
||||||
|
fixtures,
|
||||||
|
passed,
|
||||||
|
};
|
||||||
|
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/performance/bundle.json",
|
||||||
|
`${JSON.stringify(completedReport, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
if (!passed) {
|
||||||
|
process.stderr.write(
|
||||||
|
`Bundle budget or manifest integrity failed: ${[
|
||||||
|
...classification.missingImports,
|
||||||
|
...missingOutputs,
|
||||||
|
].join(", ")}\n`,
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(
|
||||||
|
`Bundle budget: PASS (initial JS ${initialJsGzipBytes} / ${budgets.initialJsGzipBytes} gzip bytes)\n`,
|
||||||
|
);
|
||||||
@@ -0,0 +1,106 @@
|
|||||||
|
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
import {
|
||||||
|
evaluateFieldBudget,
|
||||||
|
percentile75,
|
||||||
|
} from "../src/application/policies/performance-budgets.js";
|
||||||
|
import { validateFieldEvidenceInput } from "./lib/field-vitals-evidence.mjs";
|
||||||
|
|
||||||
|
const inputPath =
|
||||||
|
process.env.FIELD_WEB_VITALS_INPUT ??
|
||||||
|
"config/performance/field-input.example.json";
|
||||||
|
const rawInput = JSON.parse(await readFile(inputPath, "utf8"));
|
||||||
|
const now = new Date();
|
||||||
|
const validation = validateFieldEvidenceInput(
|
||||||
|
rawInput,
|
||||||
|
process.env.MIN_ELIGIBLE_SAMPLES,
|
||||||
|
now,
|
||||||
|
);
|
||||||
|
const input = validation.data;
|
||||||
|
const configured =
|
||||||
|
/** @type {{
|
||||||
|
* p75LcpMs: number,
|
||||||
|
* p75Cls: number,
|
||||||
|
* p75InpMs: number,
|
||||||
|
* minimumEligibleSamples: number | null
|
||||||
|
* }} */ (
|
||||||
|
JSON.parse(await readFile("config/performance/budgets.json", "utf8")).field
|
||||||
|
);
|
||||||
|
const minimumEligibleSamples = validation.minimumEligibleSamples;
|
||||||
|
const fallbackEnd = now;
|
||||||
|
const fallbackStart = new Date(fallbackEnd);
|
||||||
|
fallbackStart.setUTCDate(fallbackStart.getUTCDate() - 28);
|
||||||
|
const start = input ? new Date(input.window.start) : fallbackStart;
|
||||||
|
const end = input ? new Date(input.window.end) : fallbackEnd;
|
||||||
|
const eligible = (input?.samples ?? []).filter((sample) => {
|
||||||
|
const timestamp = new Date(sample.timestamp);
|
||||||
|
return (
|
||||||
|
sample.consent === true &&
|
||||||
|
sample.releaseId === input?.releaseId &&
|
||||||
|
timestamp >= start &&
|
||||||
|
timestamp <= end
|
||||||
|
);
|
||||||
|
});
|
||||||
|
const metrics = {
|
||||||
|
p75LcpMs: percentile75(eligible.map((sample) => sample.lcpMs)),
|
||||||
|
p75Cls: percentile75(eligible.map((sample) => sample.cls)),
|
||||||
|
p75InpMs: percentile75(eligible.map((sample) => sample.inpMs)),
|
||||||
|
};
|
||||||
|
const thresholds = { ...configured, minimumEligibleSamples };
|
||||||
|
const result = evaluateFieldBudget(
|
||||||
|
{ metrics, eligibleSamples: eligible.length },
|
||||||
|
thresholds,
|
||||||
|
);
|
||||||
|
const passed = validation.passed && result.passed;
|
||||||
|
const status = validation.passed ? result.status : "FAIL_UNVERIFIED";
|
||||||
|
const routeSamples = Object.fromEntries(
|
||||||
|
Object.entries(
|
||||||
|
eligible.reduce(
|
||||||
|
(counts, sample) => {
|
||||||
|
counts[sample.routeId] = (counts[sample.routeId] ?? 0) + 1;
|
||||||
|
return counts;
|
||||||
|
},
|
||||||
|
/** @type {Record<string, number>} */ ({}),
|
||||||
|
),
|
||||||
|
).sort(([left], [right]) => left.localeCompare(right)),
|
||||||
|
);
|
||||||
|
const report = {
|
||||||
|
schemaVersion: 1,
|
||||||
|
generatedAt: now.toISOString(),
|
||||||
|
window: { days: 28, start: start.toISOString(), end: end.toISOString() },
|
||||||
|
context: {
|
||||||
|
source: inputPath,
|
||||||
|
sourceSystem: input?.source.system ?? null,
|
||||||
|
exportId: input?.source.exportId ?? null,
|
||||||
|
network: "production-real-user",
|
||||||
|
routeAggregation: "route-id-only",
|
||||||
|
releaseId: input?.releaseId ?? null,
|
||||||
|
privacyApprovalRef: input?.privacy.approvalRef ?? null,
|
||||||
|
thresholdDecisionRef: input?.thresholdDecision.evidenceRef ?? null,
|
||||||
|
validationFailures: validation.failures,
|
||||||
|
},
|
||||||
|
metrics,
|
||||||
|
thresholds,
|
||||||
|
eligibility: {
|
||||||
|
consentRequired: true,
|
||||||
|
totalSamples: input?.samples.length ?? 0,
|
||||||
|
eligibleSamples: eligible.length,
|
||||||
|
minimumEligibleSamples,
|
||||||
|
routeSamples,
|
||||||
|
},
|
||||||
|
status,
|
||||||
|
passed,
|
||||||
|
};
|
||||||
|
|
||||||
|
await mkdir("artifacts/performance", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/performance/field-web-vitals.json",
|
||||||
|
`${JSON.stringify(report, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
if (!passed) {
|
||||||
|
process.stderr.write(
|
||||||
|
`Field Web Vitals: ${status} (approved threshold decision and valid 28-day production evidence are required)\n`,
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write("Field Web Vitals: PASS\n");
|
||||||
@@ -0,0 +1,49 @@
|
|||||||
|
/**
|
||||||
|
* @typedef {{
|
||||||
|
* file: string,
|
||||||
|
* isEntry?: boolean,
|
||||||
|
* imports?: string[]
|
||||||
|
* }} ViteManifestEntry
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Static imports of an entry are part of initial JavaScript. Every remaining
|
||||||
|
* JavaScript output is governed by the lazy-chunk budget.
|
||||||
|
*
|
||||||
|
* @param {Record<string, ViteManifestEntry>} manifest
|
||||||
|
*/
|
||||||
|
export function classifyViteJavascript(manifest) {
|
||||||
|
const initialFiles = new Set();
|
||||||
|
const visitedKeys = new Set();
|
||||||
|
const pendingKeys = Object.entries(manifest)
|
||||||
|
.filter(([, entry]) => entry.isEntry)
|
||||||
|
.map(([key]) => key);
|
||||||
|
const missingImports = [];
|
||||||
|
|
||||||
|
while (pendingKeys.length > 0) {
|
||||||
|
const key = /** @type {string} */ (pendingKeys.pop());
|
||||||
|
if (visitedKeys.has(key)) continue;
|
||||||
|
visitedKeys.add(key);
|
||||||
|
const entry = manifest[key];
|
||||||
|
if (!entry) {
|
||||||
|
missingImports.push(key);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if (entry.file.endsWith(".js")) initialFiles.add(entry.file);
|
||||||
|
pendingKeys.push(...(entry.imports ?? []));
|
||||||
|
}
|
||||||
|
|
||||||
|
const allJavaScript = new Set(
|
||||||
|
Object.values(manifest)
|
||||||
|
.map((entry) => entry.file)
|
||||||
|
.filter((file) => file.endsWith(".js")),
|
||||||
|
);
|
||||||
|
const lazyFiles = [...allJavaScript].filter(
|
||||||
|
(file) => !initialFiles.has(file),
|
||||||
|
);
|
||||||
|
return Object.freeze({
|
||||||
|
initialFiles: Object.freeze([...initialFiles].sort()),
|
||||||
|
lazyFiles: Object.freeze(lazyFiles.sort()),
|
||||||
|
missingImports: Object.freeze(missingImports.sort()),
|
||||||
|
});
|
||||||
|
}
|
||||||
@@ -0,0 +1,122 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
const WINDOW_MILLISECONDS = 28 * 24 * 60 * 60 * 1000;
|
||||||
|
const nonEmptyString = z.string().trim().min(1);
|
||||||
|
const timestamp = nonEmptyString.refine(
|
||||||
|
(value) => Number.isFinite(Date.parse(value)),
|
||||||
|
"must be an RFC 3339 timestamp",
|
||||||
|
);
|
||||||
|
const sampleSchema = z
|
||||||
|
.object({
|
||||||
|
timestamp,
|
||||||
|
consent: z.boolean(),
|
||||||
|
releaseId: nonEmptyString,
|
||||||
|
routeId: nonEmptyString.regex(/^[A-Z][A-Z0-9_]*$/),
|
||||||
|
lcpMs: z.number().finite().nonnegative(),
|
||||||
|
cls: z.number().finite().nonnegative(),
|
||||||
|
inpMs: z.number().finite().nonnegative(),
|
||||||
|
})
|
||||||
|
.strict();
|
||||||
|
|
||||||
|
const fieldEvidenceInputSchema = z
|
||||||
|
.object({
|
||||||
|
schemaVersion: z.literal(1),
|
||||||
|
environment: z.literal("production"),
|
||||||
|
releaseId: nonEmptyString.refine(
|
||||||
|
(value) => value !== "local-release",
|
||||||
|
"must identify an immutable production release",
|
||||||
|
),
|
||||||
|
source: z
|
||||||
|
.object({
|
||||||
|
system: nonEmptyString,
|
||||||
|
exportId: nonEmptyString,
|
||||||
|
})
|
||||||
|
.strict(),
|
||||||
|
privacy: z
|
||||||
|
.object({
|
||||||
|
approved: z.literal(true),
|
||||||
|
approvalRef: nonEmptyString,
|
||||||
|
})
|
||||||
|
.strict(),
|
||||||
|
window: z
|
||||||
|
.object({
|
||||||
|
start: timestamp,
|
||||||
|
end: timestamp,
|
||||||
|
})
|
||||||
|
.strict(),
|
||||||
|
thresholdDecision: z
|
||||||
|
.object({
|
||||||
|
status: z.literal("approved"),
|
||||||
|
minimumEligibleSamples: z.number().int().positive(),
|
||||||
|
owner: nonEmptyString,
|
||||||
|
reviewedAt: timestamp,
|
||||||
|
evidenceRef: nonEmptyString,
|
||||||
|
})
|
||||||
|
.strict(),
|
||||||
|
samples: z.array(sampleSchema),
|
||||||
|
})
|
||||||
|
.strict()
|
||||||
|
.superRefine((input, context) => {
|
||||||
|
const start = Date.parse(input.window.start);
|
||||||
|
const end = Date.parse(input.window.end);
|
||||||
|
if (end - start !== WINDOW_MILLISECONDS) {
|
||||||
|
context.addIssue({
|
||||||
|
code: "custom",
|
||||||
|
path: ["window"],
|
||||||
|
message: "must cover exactly 28 days",
|
||||||
|
});
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {unknown} input
|
||||||
|
* @param {string | undefined} configuredMinimum
|
||||||
|
* @param {Date} [now]
|
||||||
|
*/
|
||||||
|
export function validateFieldEvidenceInput(
|
||||||
|
input,
|
||||||
|
configuredMinimum,
|
||||||
|
now = new Date(),
|
||||||
|
) {
|
||||||
|
const parsed = fieldEvidenceInputSchema.safeParse(input);
|
||||||
|
const failures = parsed.success
|
||||||
|
? []
|
||||||
|
: parsed.error.issues.map(
|
||||||
|
(issue) => `${issue.path.join(".") || "input"}: ${issue.message}`,
|
||||||
|
);
|
||||||
|
const minimumEligibleSamples = Number(configuredMinimum);
|
||||||
|
if (
|
||||||
|
configuredMinimum === undefined ||
|
||||||
|
!Number.isInteger(minimumEligibleSamples) ||
|
||||||
|
minimumEligibleSamples <= 0
|
||||||
|
) {
|
||||||
|
failures.push("MIN_ELIGIBLE_SAMPLES: must be a positive integer");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (parsed.success) {
|
||||||
|
if (
|
||||||
|
parsed.data.thresholdDecision.minimumEligibleSamples !==
|
||||||
|
minimumEligibleSamples
|
||||||
|
) {
|
||||||
|
failures.push(
|
||||||
|
"MIN_ELIGIBLE_SAMPLES: does not match the approved threshold decision",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (Date.parse(parsed.data.window.end) > now.getTime()) {
|
||||||
|
failures.push("window.end: must not be in the future");
|
||||||
|
}
|
||||||
|
if (Date.parse(parsed.data.thresholdDecision.reviewedAt) > now.getTime()) {
|
||||||
|
failures.push("thresholdDecision.reviewedAt: must not be in the future");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return Object.freeze({
|
||||||
|
data: parsed.success ? parsed.data : null,
|
||||||
|
failures: Object.freeze(failures),
|
||||||
|
minimumEligibleSamples:
|
||||||
|
Number.isInteger(minimumEligibleSamples) && minimumEligibleSamples > 0
|
||||||
|
? minimumEligibleSamples
|
||||||
|
: null,
|
||||||
|
passed: parsed.success && failures.length === 0,
|
||||||
|
});
|
||||||
|
}
|
||||||
@@ -1,68 +0,0 @@
|
|||||||
const LOOPBACK_IPV4 = /^127(?:\.\d{1,3}){3}$/;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* A release gate must not promote a local preview server as live hosting
|
|
||||||
* evidence.
|
|
||||||
*
|
|
||||||
* @param {string} value
|
|
||||||
* @returns {
|
|
||||||
* | { passed: true; reason: null; url: URL; observedOrigin: string }
|
|
||||||
* | { passed: false; reason: string; url: URL | null; observedOrigin: string | null }
|
|
||||||
* }
|
|
||||||
*/
|
|
||||||
export function classifyLiveHostingBaseUrl(value) {
|
|
||||||
/** @type {URL} */
|
|
||||||
let url;
|
|
||||||
try {
|
|
||||||
url = new URL(value);
|
|
||||||
} catch {
|
|
||||||
return {
|
|
||||||
passed: false,
|
|
||||||
reason: "HOSTING_BASE_URL must be an absolute URL",
|
|
||||||
url: null,
|
|
||||||
observedOrigin: null,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
const observedOrigin = url.origin;
|
|
||||||
const hostname = url.hostname.toLowerCase().replace(/^\[|\]$/g, "");
|
|
||||||
if (url.protocol !== "https:") {
|
|
||||||
return {
|
|
||||||
passed: false,
|
|
||||||
reason: "live hosting evidence requires HTTPS",
|
|
||||||
url,
|
|
||||||
observedOrigin,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
if (url.username || url.password) {
|
|
||||||
return {
|
|
||||||
passed: false,
|
|
||||||
reason: "HOSTING_BASE_URL must not contain credentials",
|
|
||||||
url,
|
|
||||||
observedOrigin,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
if (
|
|
||||||
hostname === "localhost" ||
|
|
||||||
hostname.endsWith(".localhost") ||
|
|
||||||
hostname === "::1" ||
|
|
||||||
hostname === "0.0.0.0" ||
|
|
||||||
LOOPBACK_IPV4.test(hostname)
|
|
||||||
) {
|
|
||||||
return {
|
|
||||||
passed: false,
|
|
||||||
reason: "local or loopback hosts are not live deployment evidence",
|
|
||||||
url,
|
|
||||||
observedOrigin,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
if (url.pathname !== "/" || url.search || url.hash) {
|
|
||||||
return {
|
|
||||||
passed: false,
|
|
||||||
reason: "HOSTING_BASE_URL must be the canonical root URL",
|
|
||||||
url,
|
|
||||||
observedOrigin,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
return { passed: true, reason: null, url, observedOrigin };
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,148 @@
|
|||||||
|
import { spawn } from "node:child_process";
|
||||||
|
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
||||||
|
import { performance } from "node:perf_hooks";
|
||||||
|
import process from "node:process";
|
||||||
|
|
||||||
|
import { chromium } from "@playwright/test";
|
||||||
|
|
||||||
|
import { evaluateLabBudget } from "../src/application/policies/performance-budgets.js";
|
||||||
|
|
||||||
|
const server = spawn(
|
||||||
|
"corepack",
|
||||||
|
["pnpm", "preview", "--host", "127.0.0.1", "--port", "4173"],
|
||||||
|
{ stdio: "ignore" },
|
||||||
|
);
|
||||||
|
const baseUrl = "http://127.0.0.1:4173";
|
||||||
|
|
||||||
|
async function waitForServer() {
|
||||||
|
for (let attempt = 0; attempt < 50; attempt += 1) {
|
||||||
|
try {
|
||||||
|
const response = await fetch(baseUrl);
|
||||||
|
if (response.ok) return;
|
||||||
|
} catch {
|
||||||
|
// The bounded retry loop handles startup races.
|
||||||
|
}
|
||||||
|
await new Promise((resolve) => setTimeout(resolve, 100));
|
||||||
|
}
|
||||||
|
throw new Error("Preview server did not become ready.");
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
await waitForServer();
|
||||||
|
const release = JSON.parse(
|
||||||
|
await readFile("dist/release-manifest.json", "utf8"),
|
||||||
|
);
|
||||||
|
const thresholds = JSON.parse(
|
||||||
|
await readFile("config/performance/budgets.json", "utf8"),
|
||||||
|
).lab;
|
||||||
|
const browser = await chromium.launch();
|
||||||
|
try {
|
||||||
|
const context = await browser.newContext({
|
||||||
|
viewport: { width: 1280, height: 720 },
|
||||||
|
});
|
||||||
|
const page = await context.newPage();
|
||||||
|
const cdp = await context.newCDPSession(page);
|
||||||
|
await cdp.send("Network.enable");
|
||||||
|
await cdp.send("Network.emulateNetworkConditions", {
|
||||||
|
offline: false,
|
||||||
|
latency: 40,
|
||||||
|
downloadThroughput: 200_000,
|
||||||
|
uploadThroughput: 93_750,
|
||||||
|
connectionType: "cellular4g",
|
||||||
|
});
|
||||||
|
await cdp.send("Emulation.setCPUThrottlingRate", { rate: 4 });
|
||||||
|
await page.addInitScript(() => {
|
||||||
|
const evidence = { lcpMs: 0, cls: 0 };
|
||||||
|
/** @type {any} */ (window).__contractPerformance = evidence;
|
||||||
|
new PerformanceObserver((list) => {
|
||||||
|
for (const entry of list.getEntries()) evidence.lcpMs = entry.startTime;
|
||||||
|
}).observe({ type: "largest-contentful-paint", buffered: true });
|
||||||
|
new PerformanceObserver((list) => {
|
||||||
|
for (const entry of list.getEntries()) {
|
||||||
|
if (!(/** @type {any} */ (entry)).hadRecentInput) {
|
||||||
|
evidence.cls += /** @type {any} */ (entry).value;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}).observe({ type: "layout-shift", buffered: true });
|
||||||
|
});
|
||||||
|
await page.goto(baseUrl, { waitUntil: "networkidle" });
|
||||||
|
const interactionStarted = performance.now();
|
||||||
|
await page.getByRole("link", { name: "샘플 리소스" }).click();
|
||||||
|
await page.getByRole("heading", { name: "세션이 필요합니다." }).waitFor();
|
||||||
|
const namedInteractionMs = performance.now() - interactionStarted;
|
||||||
|
const paint = await page.evaluate(
|
||||||
|
() => /** @type {any} */ (window).__contractPerformance,
|
||||||
|
);
|
||||||
|
const contextMetadata = {
|
||||||
|
runner: {
|
||||||
|
platform: process.platform,
|
||||||
|
architecture: process.arch,
|
||||||
|
nodeVersion: process.version,
|
||||||
|
},
|
||||||
|
browser: { name: "chromium", version: await browser.version() },
|
||||||
|
viewport: { width: 1280, height: 720 },
|
||||||
|
network: {
|
||||||
|
profile: "contract-fast-4g",
|
||||||
|
latencyMs: 40,
|
||||||
|
downloadBytesPerSecond: 200_000,
|
||||||
|
uploadBytesPerSecond: 93_750,
|
||||||
|
},
|
||||||
|
cpu: { throttlingRate: 4 },
|
||||||
|
cache: { state: "cold", isolation: "new-browser-context" },
|
||||||
|
build: { buildId: release.buildId, releaseId: release.releaseId },
|
||||||
|
};
|
||||||
|
const metrics = {
|
||||||
|
lcpMs: Math.round(paint.lcpMs),
|
||||||
|
cls: Number(paint.cls.toFixed(4)),
|
||||||
|
namedInteractionMs: Math.round(namedInteractionMs),
|
||||||
|
};
|
||||||
|
const result = evaluateLabBudget(
|
||||||
|
{ context: contextMetadata, metrics },
|
||||||
|
thresholds,
|
||||||
|
);
|
||||||
|
const fixtures = [
|
||||||
|
{
|
||||||
|
name: "missing-context",
|
||||||
|
passed: !evaluateLabBudget({ metrics }, thresholds).passed,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "lcp-over-threshold",
|
||||||
|
passed: !evaluateLabBudget(
|
||||||
|
{
|
||||||
|
context: contextMetadata,
|
||||||
|
metrics: { ...metrics, lcpMs: thresholds.lcpMs + 1 },
|
||||||
|
},
|
||||||
|
thresholds,
|
||||||
|
).passed,
|
||||||
|
},
|
||||||
|
];
|
||||||
|
const passed = result.passed && fixtures.every((fixture) => fixture.passed);
|
||||||
|
await mkdir("artifacts/performance", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/performance/lab.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
generatedAt: new Date().toISOString(),
|
||||||
|
context: contextMetadata,
|
||||||
|
metrics,
|
||||||
|
thresholds,
|
||||||
|
fixtures,
|
||||||
|
passed,
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
if (!passed) {
|
||||||
|
throw new Error(`Lab performance failed: ${JSON.stringify(metrics)}`);
|
||||||
|
}
|
||||||
|
process.stdout.write(
|
||||||
|
`Lab performance: PASS (LCP ${metrics.lcpMs}ms, CLS ${metrics.cls}, interaction ${metrics.namedInteractionMs}ms)\n`,
|
||||||
|
);
|
||||||
|
} finally {
|
||||||
|
await browser.close();
|
||||||
|
}
|
||||||
|
} finally {
|
||||||
|
server.kill("SIGTERM");
|
||||||
|
}
|
||||||
@@ -1,7 +1,5 @@
|
|||||||
import { mkdir, readFile, readdir, writeFile } from "node:fs/promises";
|
import { mkdir, readFile, readdir, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
import { classifyLiveHostingBaseUrl } from "./lib/hosting-probe.mjs";
|
|
||||||
|
|
||||||
const cachePolicy = JSON.parse(
|
const cachePolicy = JSON.parse(
|
||||||
await readFile("config/hosting/cache-policy.json", "utf8"),
|
await readFile("config/hosting/cache-policy.json", "utf8"),
|
||||||
);
|
);
|
||||||
@@ -9,85 +7,32 @@ const securityPolicy = JSON.parse(
|
|||||||
await readFile("config/hosting/security-headers.json", "utf8"),
|
await readFile("config/hosting/security-headers.json", "utf8"),
|
||||||
);
|
);
|
||||||
const baseUrl = process.env.HOSTING_BASE_URL;
|
const baseUrl = process.env.HOSTING_BASE_URL;
|
||||||
const liveTarget = baseUrl ? classifyLiveHostingBaseUrl(baseUrl) : null;
|
|
||||||
const distFiles = (await readdir("dist", { recursive: true })).map(String);
|
|
||||||
const publicSourceMaps = distFiles.filter((file) => file.endsWith(".map"));
|
|
||||||
const publicServiceWorkers = distFiles.filter((file) =>
|
|
||||||
/(?:^|\/)(?:service-worker|sw)(?:[.-][^/]*)?\.js$/i.test(file),
|
|
||||||
);
|
|
||||||
|
|
||||||
/** @type {Record<string, Record<string, string>>} */
|
/** @type {Record<string, Record<string, string>>} */
|
||||||
let responses = {};
|
let responses;
|
||||||
let mode;
|
let mode;
|
||||||
/** @type {Array<{
|
|
||||||
* surface: string;
|
|
||||||
* header: string;
|
|
||||||
* expected: unknown;
|
|
||||||
* observed: unknown;
|
|
||||||
* reason?: string;
|
|
||||||
* passed: boolean;
|
|
||||||
* }>} */
|
|
||||||
const probeResults = [];
|
|
||||||
|
|
||||||
if (liveTarget?.passed) {
|
if (baseUrl) {
|
||||||
mode = "live";
|
mode = "live";
|
||||||
const assets = await readdir("dist/assets");
|
const assets = await readdir("dist/assets");
|
||||||
const hashedJavaScript = assets.find((file) => file.endsWith(".js"));
|
const hashedAsset = assets.find((file) => !file.endsWith(".map"));
|
||||||
if (!hashedJavaScript) throw new Error("No built hashed JavaScript found.");
|
if (!hashedAsset) throw new Error("No built hashed asset found.");
|
||||||
const paths = {
|
const paths = {
|
||||||
index: "/",
|
index: "/",
|
||||||
runtimeConfig: "/config.json",
|
runtimeConfig: "/config.json",
|
||||||
releaseManifest: "/release-manifest.json",
|
releaseManifest: "/release-manifest.json",
|
||||||
hashedAsset: `/assets/${hashedJavaScript}`,
|
hashedAsset: `/assets/${hashedAsset}`,
|
||||||
};
|
};
|
||||||
responses = {};
|
responses = {};
|
||||||
for (const [surface, pathname] of Object.entries(paths)) {
|
for (const [surface, pathname] of Object.entries(paths)) {
|
||||||
const requestedUrl = new URL(pathname, liveTarget.url);
|
const response = await fetch(new URL(pathname, baseUrl));
|
||||||
try {
|
responses[surface] = Object.fromEntries(
|
||||||
const response = await fetch(requestedUrl, { redirect: "follow" });
|
[...response.headers.entries()].map(([name, value]) => [
|
||||||
const finalUrl = new URL(response.url);
|
name.toLowerCase(),
|
||||||
probeResults.push(
|
value,
|
||||||
{
|
]),
|
||||||
surface,
|
);
|
||||||
header: "http-status",
|
|
||||||
expected: 200,
|
|
||||||
observed: response.status,
|
|
||||||
passed: response.status === 200,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
surface,
|
|
||||||
header: "final-origin",
|
|
||||||
expected: liveTarget.url.origin,
|
|
||||||
observed: finalUrl.origin,
|
|
||||||
passed: finalUrl.origin === liveTarget.url.origin,
|
|
||||||
},
|
|
||||||
);
|
|
||||||
responses[surface] = Object.fromEntries(
|
|
||||||
[...response.headers.entries()].map(([name, value]) => [
|
|
||||||
name.toLowerCase(),
|
|
||||||
value,
|
|
||||||
]),
|
|
||||||
);
|
|
||||||
} catch (error) {
|
|
||||||
probeResults.push({
|
|
||||||
surface,
|
|
||||||
header: "transport",
|
|
||||||
expected: "reachable",
|
|
||||||
observed: error instanceof Error ? error.name : "UnknownError",
|
|
||||||
passed: false,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
} else if (liveTarget) {
|
|
||||||
mode = "invalid-live";
|
|
||||||
probeResults.push({
|
|
||||||
surface: "deployment",
|
|
||||||
header: "base-url",
|
|
||||||
expected: "canonical non-loopback HTTPS root URL",
|
|
||||||
observed: liveTarget.observedOrigin,
|
|
||||||
reason: liveTarget.reason,
|
|
||||||
passed: false,
|
|
||||||
});
|
|
||||||
} else {
|
} else {
|
||||||
mode = "fixture";
|
mode = "fixture";
|
||||||
responses = JSON.parse(
|
responses = JSON.parse(
|
||||||
@@ -95,7 +40,7 @@ if (liveTarget?.passed) {
|
|||||||
).responses;
|
).responses;
|
||||||
}
|
}
|
||||||
|
|
||||||
const results = [...probeResults];
|
const results = [];
|
||||||
for (const [surface, policy] of Object.entries(cachePolicy.surfaces)) {
|
for (const [surface, policy] of Object.entries(cachePolicy.surfaces)) {
|
||||||
if (!("cacheControl" in policy)) continue;
|
if (!("cacheControl" in policy)) continue;
|
||||||
const observed = responses[surface]?.["cache-control"];
|
const observed = responses[surface]?.["cache-control"];
|
||||||
@@ -106,18 +51,6 @@ for (const [surface, policy] of Object.entries(cachePolicy.surfaces)) {
|
|||||||
observed,
|
observed,
|
||||||
passed: observed === policy.cacheControl,
|
passed: observed === policy.cacheControl,
|
||||||
});
|
});
|
||||||
const observedContentType = responses[surface]?.["content-type"];
|
|
||||||
const observedMime = observedContentType
|
|
||||||
?.split(";", 1)[0]
|
|
||||||
.trim()
|
|
||||||
.toLowerCase();
|
|
||||||
results.push({
|
|
||||||
surface,
|
|
||||||
header: "content-type",
|
|
||||||
expected: policy.contentTypes,
|
|
||||||
observed: observedContentType,
|
|
||||||
passed: policy.contentTypes.includes(observedMime),
|
|
||||||
});
|
|
||||||
if (policy.securityHeaders) {
|
if (policy.securityHeaders) {
|
||||||
for (const [header, expected] of Object.entries(securityPolicy.headers)) {
|
for (const [header, expected] of Object.entries(securityPolicy.headers)) {
|
||||||
const observedSecurity = responses[surface]?.[header.toLowerCase()];
|
const observedSecurity = responses[surface]?.[header.toLowerCase()];
|
||||||
@@ -136,19 +69,15 @@ results.push({
|
|||||||
surface: "sourceMap",
|
surface: "sourceMap",
|
||||||
header: "public",
|
header: "public",
|
||||||
expected: false,
|
expected: false,
|
||||||
observed: publicSourceMaps.length > 0,
|
observed: cachePolicy.surfaces.sourceMap.public,
|
||||||
passed:
|
passed: cachePolicy.surfaces.sourceMap.public === false,
|
||||||
cachePolicy.surfaces.sourceMap.public === false &&
|
|
||||||
publicSourceMaps.length === 0,
|
|
||||||
});
|
});
|
||||||
results.push({
|
results.push({
|
||||||
surface: "serviceWorker",
|
surface: "serviceWorker",
|
||||||
header: "enabled",
|
header: "enabled",
|
||||||
expected: false,
|
expected: false,
|
||||||
observed: publicServiceWorkers.length > 0,
|
observed: cachePolicy.surfaces.serviceWorker.enabled,
|
||||||
passed:
|
passed: cachePolicy.surfaces.serviceWorker.enabled === false,
|
||||||
cachePolicy.surfaces.serviceWorker.enabled === false &&
|
|
||||||
publicServiceWorkers.length === 0,
|
|
||||||
});
|
});
|
||||||
|
|
||||||
const passed = results.every((result) => result.passed);
|
const passed = results.every((result) => result.passed);
|
||||||
@@ -160,7 +89,7 @@ await writeFile(
|
|||||||
schemaVersion: 1,
|
schemaVersion: 1,
|
||||||
generatedAt: new Date().toISOString(),
|
generatedAt: new Date().toISOString(),
|
||||||
mode,
|
mode,
|
||||||
baseUrl: liveTarget?.observedOrigin ?? null,
|
baseUrl: baseUrl ?? null,
|
||||||
providerVerificationRequired: mode !== "live",
|
providerVerificationRequired: mode !== "live",
|
||||||
results,
|
results,
|
||||||
passed,
|
passed,
|
||||||
@@ -171,9 +100,7 @@ await writeFile(
|
|||||||
);
|
);
|
||||||
|
|
||||||
if (!passed) {
|
if (!passed) {
|
||||||
process.stderr.write(
|
process.stderr.write("Hosting cache/security header verification failed.\n");
|
||||||
"Hosting cache/content-type/security header verification failed.\n",
|
|
||||||
);
|
|
||||||
process.exit(1);
|
process.exit(1);
|
||||||
}
|
}
|
||||||
process.stdout.write(
|
process.stdout.write(
|
||||||
|
|||||||
@@ -2,10 +2,7 @@ import { createHash } from "node:crypto";
|
|||||||
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
import { verifyCompatibilityTuple } from "../src/application/policies/compatibility.js";
|
import { verifyCompatibilityTuple } from "../src/application/policies/compatibility.js";
|
||||||
import {
|
import { compareReleaseToRuntime } from "../src/contracts/release-tokens.js";
|
||||||
compareReleaseToRuntime,
|
|
||||||
RELEASE_TOKEN_REGISTRY,
|
|
||||||
} from "../src/contracts/release-tokens.js";
|
|
||||||
|
|
||||||
const fixturesDocument =
|
const fixturesDocument =
|
||||||
/** @type {{
|
/** @type {{
|
||||||
@@ -41,14 +38,6 @@ const actualAssetManifestHash = createHash("sha256")
|
|||||||
|
|
||||||
const artifactComparison = compareReleaseToRuntime(release, runtimeConfig);
|
const artifactComparison = compareReleaseToRuntime(release, runtimeConfig);
|
||||||
const artifactMismatches = [...artifactComparison.mismatches];
|
const artifactMismatches = [...artifactComparison.mismatches];
|
||||||
for (const token of Object.keys(RELEASE_TOKEN_REGISTRY)) {
|
|
||||||
if (typeof release[token] !== "string" || release[token].length === 0) {
|
|
||||||
artifactMismatches.push(`releaseToken:${token}`);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if (!Number.isFinite(Date.parse(release.builtAt))) {
|
|
||||||
artifactMismatches.push("releaseToken:builtAtFormat");
|
|
||||||
}
|
|
||||||
if (release.assetManifestHash !== actualAssetManifestHash) {
|
if (release.assetManifestHash !== actualAssetManifestHash) {
|
||||||
artifactMismatches.push("assetManifestContent");
|
artifactMismatches.push("assetManifestContent");
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,96 @@
|
|||||||
|
/**
|
||||||
|
* @param {{
|
||||||
|
* initialJsGzipBytes: number,
|
||||||
|
* lazyChunks: Array<{ path: string, gzipBytes: number }>
|
||||||
|
* }} measurements
|
||||||
|
* @param {{ initialJsGzipBytes: number, lazyChunkGzipBytes: number }} thresholds
|
||||||
|
*/
|
||||||
|
export function evaluateBundleBudget(measurements, thresholds) {
|
||||||
|
const initialPassed =
|
||||||
|
measurements.initialJsGzipBytes <= thresholds.initialJsGzipBytes;
|
||||||
|
const lazyResults = measurements.lazyChunks.map((chunk) => ({
|
||||||
|
...chunk,
|
||||||
|
threshold: thresholds.lazyChunkGzipBytes,
|
||||||
|
passed: chunk.gzipBytes <= thresholds.lazyChunkGzipBytes,
|
||||||
|
}));
|
||||||
|
return Object.freeze({
|
||||||
|
initialPassed,
|
||||||
|
lazyResults: Object.freeze(lazyResults),
|
||||||
|
passed: initialPassed && lazyResults.every((chunk) => chunk.passed),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {{
|
||||||
|
* context?: Record<string, unknown>,
|
||||||
|
* metrics: { lcpMs: number, cls: number, namedInteractionMs: number }
|
||||||
|
* }} report
|
||||||
|
* @param {{ lcpMs: number, cls: number, namedInteractionMs: number }} thresholds
|
||||||
|
*/
|
||||||
|
export function evaluateLabBudget(report, thresholds) {
|
||||||
|
const requiredContext = [
|
||||||
|
"runner",
|
||||||
|
"browser",
|
||||||
|
"viewport",
|
||||||
|
"network",
|
||||||
|
"cpu",
|
||||||
|
"cache",
|
||||||
|
"build",
|
||||||
|
];
|
||||||
|
const missingContext = requiredContext.filter(
|
||||||
|
(field) => report.context?.[field] === undefined,
|
||||||
|
);
|
||||||
|
const results = {
|
||||||
|
lcp: report.metrics.lcpMs <= thresholds.lcpMs,
|
||||||
|
cls: report.metrics.cls <= thresholds.cls,
|
||||||
|
namedInteraction:
|
||||||
|
report.metrics.namedInteractionMs <= thresholds.namedInteractionMs,
|
||||||
|
};
|
||||||
|
return Object.freeze({
|
||||||
|
missingContext: Object.freeze(missingContext),
|
||||||
|
results: Object.freeze(results),
|
||||||
|
passed: missingContext.length === 0 && Object.values(results).every(Boolean),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param {number[]} values */
|
||||||
|
export function percentile75(values) {
|
||||||
|
if (values.length === 0) return null;
|
||||||
|
const sorted = [...values].sort((left, right) => left - right);
|
||||||
|
return sorted[Math.ceil(sorted.length * 0.75) - 1];
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {{
|
||||||
|
* metrics: { p75LcpMs: number | null, p75Cls: number | null, p75InpMs: number | null },
|
||||||
|
* eligibleSamples: number
|
||||||
|
* }} report
|
||||||
|
* @param {{
|
||||||
|
* p75LcpMs: number,
|
||||||
|
* p75Cls: number,
|
||||||
|
* p75InpMs: number,
|
||||||
|
* minimumEligibleSamples: number | null
|
||||||
|
* }} thresholds
|
||||||
|
*/
|
||||||
|
export function evaluateFieldBudget(report, thresholds) {
|
||||||
|
if (
|
||||||
|
thresholds.minimumEligibleSamples === null ||
|
||||||
|
report.eligibleSamples < thresholds.minimumEligibleSamples ||
|
||||||
|
Object.values(report.metrics).some((value) => value === null)
|
||||||
|
) {
|
||||||
|
return Object.freeze({
|
||||||
|
status: /** @type {const} */ ("FAIL_UNVERIFIED"),
|
||||||
|
passed: false,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
const passed =
|
||||||
|
/** @type {number} */ (report.metrics.p75LcpMs) <= thresholds.p75LcpMs &&
|
||||||
|
/** @type {number} */ (report.metrics.p75Cls) <= thresholds.p75Cls &&
|
||||||
|
/** @type {number} */ (report.metrics.p75InpMs) <= thresholds.p75InpMs;
|
||||||
|
return Object.freeze({
|
||||||
|
status: passed
|
||||||
|
? /** @type {const} */ ("PASS")
|
||||||
|
: /** @type {const} */ ("FAIL_THRESHOLD"),
|
||||||
|
passed,
|
||||||
|
});
|
||||||
|
}
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import { classifyViteJavascript } from "../../scripts/lib/classify-vite-bundle.mjs";
|
||||||
|
|
||||||
|
describe("Vite bundle classification", () => {
|
||||||
|
it("counts transitive static imports as initial and keeps dynamic chunks lazy", () => {
|
||||||
|
expect(
|
||||||
|
classifyViteJavascript({
|
||||||
|
"index.html": {
|
||||||
|
file: "assets/entry.js",
|
||||||
|
isEntry: true,
|
||||||
|
imports: ["_shared.js"],
|
||||||
|
},
|
||||||
|
"_shared.js": { file: "assets/shared.js", imports: ["_runtime.js"] },
|
||||||
|
"_runtime.js": { file: "assets/runtime.js" },
|
||||||
|
"src/lazy.js": { file: "assets/lazy.js" },
|
||||||
|
}),
|
||||||
|
).toEqual({
|
||||||
|
initialFiles: [
|
||||||
|
"assets/entry.js",
|
||||||
|
"assets/runtime.js",
|
||||||
|
"assets/shared.js",
|
||||||
|
],
|
||||||
|
lazyFiles: ["assets/lazy.js"],
|
||||||
|
missingImports: [],
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
it("reports a manifest import that cannot be resolved", () => {
|
||||||
|
expect(
|
||||||
|
classifyViteJavascript({
|
||||||
|
"index.html": {
|
||||||
|
file: "assets/entry.js",
|
||||||
|
isEntry: true,
|
||||||
|
imports: ["_missing.js"],
|
||||||
|
},
|
||||||
|
}).missingImports,
|
||||||
|
).toEqual(["_missing.js"]);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,94 @@
|
|||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import { validateFieldEvidenceInput } from "../../scripts/lib/field-vitals-evidence.mjs";
|
||||||
|
|
||||||
|
const input = {
|
||||||
|
schemaVersion: 1,
|
||||||
|
environment: "production",
|
||||||
|
releaseId: "release-2026-06-29",
|
||||||
|
source: {
|
||||||
|
system: "privacy-approved-rum-export",
|
||||||
|
exportId: "export-2026-06-29",
|
||||||
|
},
|
||||||
|
privacy: {
|
||||||
|
approved: true,
|
||||||
|
approvalRef: "PRIVACY-42",
|
||||||
|
},
|
||||||
|
window: {
|
||||||
|
start: "2026-06-01T00:00:00Z",
|
||||||
|
end: "2026-06-29T00:00:00Z",
|
||||||
|
},
|
||||||
|
thresholdDecision: {
|
||||||
|
status: "approved",
|
||||||
|
minimumEligibleSamples: 25,
|
||||||
|
owner: "performance-owner",
|
||||||
|
reviewedAt: "2026-06-30T00:00:00Z",
|
||||||
|
evidenceRef: "PERF-BASELINE-7",
|
||||||
|
},
|
||||||
|
samples: [
|
||||||
|
{
|
||||||
|
timestamp: "2026-06-20T00:00:00Z",
|
||||||
|
consent: true,
|
||||||
|
releaseId: "release-2026-06-29",
|
||||||
|
routeId: "APP_HOME",
|
||||||
|
lcpMs: 1200,
|
||||||
|
cls: 0.01,
|
||||||
|
inpMs: 80,
|
||||||
|
},
|
||||||
|
],
|
||||||
|
};
|
||||||
|
|
||||||
|
describe("field Web Vitals evidence input", () => {
|
||||||
|
it("accepts reviewed, coherent 28-day production metadata", () => {
|
||||||
|
expect(
|
||||||
|
validateFieldEvidenceInput(
|
||||||
|
input,
|
||||||
|
"25",
|
||||||
|
new Date("2026-07-01T00:00:00Z"),
|
||||||
|
),
|
||||||
|
).toMatchObject({
|
||||||
|
failures: [],
|
||||||
|
minimumEligibleSamples: 25,
|
||||||
|
passed: true,
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
it("rejects a threshold that does not match the owner decision", () => {
|
||||||
|
expect(
|
||||||
|
validateFieldEvidenceInput(
|
||||||
|
input,
|
||||||
|
"10",
|
||||||
|
new Date("2026-07-01T00:00:00Z"),
|
||||||
|
),
|
||||||
|
).toMatchObject({
|
||||||
|
failures: [
|
||||||
|
"MIN_ELIGIBLE_SAMPLES: does not match the approved threshold decision",
|
||||||
|
],
|
||||||
|
passed: false,
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
it("rejects local, unapproved, malformed, or impossible measurements", () => {
|
||||||
|
const invalid = {
|
||||||
|
...input,
|
||||||
|
environment: "local",
|
||||||
|
releaseId: "local-release",
|
||||||
|
privacy: { approved: false, approvalRef: "" },
|
||||||
|
window: { ...input.window, end: "2026-06-28T00:00:00Z" },
|
||||||
|
samples: [{ ...input.samples[0], lcpMs: -1 }],
|
||||||
|
};
|
||||||
|
const validation = validateFieldEvidenceInput(
|
||||||
|
invalid,
|
||||||
|
"-1",
|
||||||
|
new Date("2026-07-01T00:00:00Z"),
|
||||||
|
);
|
||||||
|
expect(validation.passed).toBe(false);
|
||||||
|
expect(validation.failures.join("\n")).toContain("environment");
|
||||||
|
expect(validation.failures.join("\n")).toContain("releaseId");
|
||||||
|
expect(validation.failures.join("\n")).toContain("privacy");
|
||||||
|
expect(validation.failures.join("\n")).toContain("lcpMs");
|
||||||
|
expect(validation.failures.join("\n")).toContain(
|
||||||
|
"MIN_ELIGIBLE_SAMPLES: must be a positive integer",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
import { describe, expect, it } from "vitest";
|
|
||||||
|
|
||||||
import { classifyLiveHostingBaseUrl } from "../../scripts/lib/hosting-probe.mjs";
|
|
||||||
|
|
||||||
describe("live hosting evidence target", () => {
|
|
||||||
it("accepts a canonical production HTTPS root", () => {
|
|
||||||
expect(
|
|
||||||
classifyLiveHostingBaseUrl("https://frontend.example.test/"),
|
|
||||||
).toMatchObject({
|
|
||||||
passed: true,
|
|
||||||
observedOrigin: "https://frontend.example.test",
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
it.each([
|
|
||||||
["http://frontend.example.test/", "requires HTTPS"],
|
|
||||||
["https://localhost:4173/", "not live deployment evidence"],
|
|
||||||
["https://127.0.0.1/", "not live deployment evidence"],
|
|
||||||
["https://frontend.example.test/app/", "canonical root URL"],
|
|
||||||
["https://user:secret@frontend.example.test/", "must not contain credentials"],
|
|
||||||
])("rejects %s", (url, reason) => {
|
|
||||||
expect(classifyLiveHostingBaseUrl(url)).toMatchObject({
|
|
||||||
passed: false,
|
|
||||||
reason: expect.stringContaining(reason),
|
|
||||||
});
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -0,0 +1,77 @@
|
|||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import {
|
||||||
|
evaluateBundleBudget,
|
||||||
|
evaluateFieldBudget,
|
||||||
|
evaluateLabBudget,
|
||||||
|
percentile75,
|
||||||
|
} from "../../src/application/policies/performance-budgets.js";
|
||||||
|
|
||||||
|
describe("performance budgets", () => {
|
||||||
|
it("rejects initial and lazy JavaScript above their named limits", () => {
|
||||||
|
const thresholds = {
|
||||||
|
initialJsGzipBytes: 200,
|
||||||
|
lazyChunkGzipBytes: 120,
|
||||||
|
};
|
||||||
|
expect(
|
||||||
|
evaluateBundleBudget(
|
||||||
|
{ initialJsGzipBytes: 201, lazyChunks: [] },
|
||||||
|
thresholds,
|
||||||
|
).passed,
|
||||||
|
).toBe(false);
|
||||||
|
expect(
|
||||||
|
evaluateBundleBudget(
|
||||||
|
{
|
||||||
|
initialJsGzipBytes: 100,
|
||||||
|
lazyChunks: [{ path: "lazy.js", gzipBytes: 121 }],
|
||||||
|
},
|
||||||
|
thresholds,
|
||||||
|
).passed,
|
||||||
|
).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("fails lab evidence when context is absent or a metric is over budget", () => {
|
||||||
|
const thresholds = { lcpMs: 2500, cls: 0.1, namedInteractionMs: 200 };
|
||||||
|
expect(
|
||||||
|
evaluateLabBudget(
|
||||||
|
{ metrics: { lcpMs: 1000, cls: 0, namedInteractionMs: 50 } },
|
||||||
|
thresholds,
|
||||||
|
),
|
||||||
|
).toMatchObject({ passed: false });
|
||||||
|
expect(
|
||||||
|
evaluateLabBudget(
|
||||||
|
{
|
||||||
|
context: {
|
||||||
|
runner: {},
|
||||||
|
browser: {},
|
||||||
|
viewport: {},
|
||||||
|
network: {},
|
||||||
|
cpu: {},
|
||||||
|
cache: {},
|
||||||
|
build: {},
|
||||||
|
},
|
||||||
|
metrics: { lcpMs: 2501, cls: 0, namedInteractionMs: 50 },
|
||||||
|
},
|
||||||
|
thresholds,
|
||||||
|
).passed,
|
||||||
|
).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("uses the nearest-rank p75 and fails closed while sample minimum is deferred", () => {
|
||||||
|
expect(percentile75([4, 1, 3, 2])).toBe(3);
|
||||||
|
expect(
|
||||||
|
evaluateFieldBudget(
|
||||||
|
{
|
||||||
|
metrics: { p75LcpMs: 1000, p75Cls: 0.01, p75InpMs: 50 },
|
||||||
|
eligibleSamples: 100,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
p75LcpMs: 2500,
|
||||||
|
p75Cls: 0.1,
|
||||||
|
p75InpMs: 200,
|
||||||
|
minimumEligibleSamples: null,
|
||||||
|
},
|
||||||
|
),
|
||||||
|
).toEqual({ status: "FAIL_UNVERIFIED", passed: false });
|
||||||
|
});
|
||||||
|
});
|
||||||
Reference in New Issue
Block a user