Compare commits
5
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3d810ef695 | ||
|
|
6c73b845bd | ||
|
|
638f5f71bd | ||
|
|
8b4f875c1c | ||
|
|
a64708f3de |
+54
-12
@@ -58,7 +58,10 @@
|
|||||||
"gates": {
|
"gates": {
|
||||||
"FE-GATE-001": {
|
"FE-GATE-001": {
|
||||||
"name": "manifest-lockfile",
|
"name": "manifest-lockfile",
|
||||||
"steps": [{ "script": "verify:lockfile", "expect": "pass" }],
|
"steps": [
|
||||||
|
{ "script": "verify:lockfile", "expect": "pass" },
|
||||||
|
{ "script": "check:frozen-lockfile:fixture", "expect": "pass" }
|
||||||
|
],
|
||||||
"logPath": "artifacts/quality/install.txt",
|
"logPath": "artifacts/quality/install.txt",
|
||||||
"evidence": ["artifacts/quality/install.txt"],
|
"evidence": ["artifacts/quality/install.txt"],
|
||||||
"retentionClass": "merge-cycle"
|
"retentionClass": "merge-cycle"
|
||||||
@@ -74,6 +77,7 @@
|
|||||||
"name": "typecheck",
|
"name": "typecheck",
|
||||||
"steps": [
|
"steps": [
|
||||||
{ "script": "check:types", "expect": "pass" },
|
{ "script": "check:types", "expect": "pass" },
|
||||||
|
{ "script": "check:types:recipes", "expect": "pass" },
|
||||||
{ "script": "check:types:fixture", "expect": "fail" },
|
{ "script": "check:types:fixture", "expect": "fail" },
|
||||||
{ "script": "check:types:fixture:ts-port", "expect": "fail" },
|
{ "script": "check:types:fixture:ts-port", "expect": "fail" },
|
||||||
{ "script": "check:types:fixture:ts-result", "expect": "fail" },
|
{ "script": "check:types:fixture:ts-result", "expect": "fail" },
|
||||||
@@ -126,12 +130,14 @@
|
|||||||
"name": "integration",
|
"name": "integration",
|
||||||
"steps": [
|
"steps": [
|
||||||
{ "script": "test:integration", "expect": "pass" },
|
{ "script": "test:integration", "expect": "pass" },
|
||||||
{ "script": "test:reference-feature", "expect": "pass" }
|
{ "script": "test:reference-feature", "expect": "pass" },
|
||||||
|
{ "script": "test:recipes", "expect": "pass" }
|
||||||
],
|
],
|
||||||
"logPath": "artifacts/quality/gates/FE-GATE-007.txt",
|
"logPath": "artifacts/quality/gates/FE-GATE-007.txt",
|
||||||
"evidence": [
|
"evidence": [
|
||||||
"artifacts/tests/integration.xml",
|
"artifacts/tests/integration.xml",
|
||||||
"artifacts/tests/reference-feature.xml"
|
"artifacts/tests/reference-feature.xml",
|
||||||
|
"artifacts/tests/optional-recipes.xml"
|
||||||
],
|
],
|
||||||
"retentionClass": "merge-cycle"
|
"retentionClass": "merge-cycle"
|
||||||
},
|
},
|
||||||
@@ -186,6 +192,8 @@
|
|||||||
{ "script": "check:i18n:fixture", "expect": "fail" },
|
{ "script": "check:i18n:fixture", "expect": "fail" },
|
||||||
{ "script": "check:diagnostics", "expect": "pass" },
|
{ "script": "check:diagnostics", "expect": "pass" },
|
||||||
{ "script": "check:diagnostics:fixture", "expect": "fail" },
|
{ "script": "check:diagnostics:fixture", "expect": "fail" },
|
||||||
|
{ "script": "check:optional-recipes:source", "expect": "pass" },
|
||||||
|
{ "script": "check:optional-recipe-fixtures", "expect": "pass" },
|
||||||
{ "script": "check:registries", "expect": "pass" },
|
{ "script": "check:registries", "expect": "pass" },
|
||||||
{
|
{
|
||||||
"script": "check:registries:compatibility-fixtures",
|
"script": "check:registries:compatibility-fixtures",
|
||||||
@@ -204,6 +212,8 @@
|
|||||||
"artifacts/quality/i18n-fixture.json",
|
"artifacts/quality/i18n-fixture.json",
|
||||||
"artifacts/quality/diagnostics.json",
|
"artifacts/quality/diagnostics.json",
|
||||||
"artifacts/quality/diagnostics-fixture.json",
|
"artifacts/quality/diagnostics-fixture.json",
|
||||||
|
"artifacts/quality/optional-recipes.json",
|
||||||
|
"artifacts/quality/optional-recipe-fixtures.json",
|
||||||
"artifacts/quality/registries.json",
|
"artifacts/quality/registries.json",
|
||||||
"artifacts/quality/registry-compatibility-fixtures.json",
|
"artifacts/quality/registry-compatibility-fixtures.json",
|
||||||
"artifacts/quality/registry-baseline-fixture.json",
|
"artifacts/quality/registry-baseline-fixture.json",
|
||||||
@@ -230,23 +240,45 @@
|
|||||||
"name": "bundle",
|
"name": "bundle",
|
||||||
"steps": [
|
"steps": [
|
||||||
{ "script": "build", "expect": "pass" },
|
{ "script": "build", "expect": "pass" },
|
||||||
{ "script": "check:bundle", "expect": "pass" }
|
{ "script": "check:bundle", "expect": "pass" },
|
||||||
|
{ "script": "check:optional-recipes", "expect": "pass" }
|
||||||
],
|
],
|
||||||
"logPath": "artifacts/quality/gates/FE-GATE-012.txt",
|
"logPath": "artifacts/quality/gates/FE-GATE-012.txt",
|
||||||
"evidence": ["artifacts/performance/bundle.json"],
|
"evidence": [
|
||||||
|
"artifacts/performance/bundle.json",
|
||||||
|
"artifacts/quality/optional-recipes.json"
|
||||||
|
],
|
||||||
"retentionClass": "release-coherence"
|
"retentionClass": "release-coherence"
|
||||||
},
|
},
|
||||||
"FE-GATE-013": {
|
"FE-GATE-013": {
|
||||||
"name": "security",
|
"name": "security",
|
||||||
"steps": [
|
"steps": [
|
||||||
|
{ "script": "verify:reproducible-build", "expect": "pass" },
|
||||||
{ "script": "build:release", "expect": "pass" },
|
{ "script": "build:release", "expect": "pass" },
|
||||||
|
{ "script": "verify:supply-chain", "expect": "pass" },
|
||||||
|
{ "script": "check:supply-chain:fixtures", "expect": "pass" },
|
||||||
|
{
|
||||||
|
"script": "check:supply-chain:provider-fixtures",
|
||||||
|
"expect": "pass"
|
||||||
|
},
|
||||||
|
{ "script": "scan:security:fixture", "expect": "fail" },
|
||||||
{ "script": "check:browser-security", "expect": "pass" }
|
{ "script": "check:browser-security", "expect": "pass" }
|
||||||
],
|
],
|
||||||
"logPath": "artifacts/quality/gates/FE-GATE-013.txt",
|
"logPath": "artifacts/quality/gates/FE-GATE-013.txt",
|
||||||
"evidence": [
|
"evidence": [
|
||||||
"artifacts/security/scan.sarif",
|
"artifacts/security/scan.sarif",
|
||||||
|
"artifacts/security/scan-fixture.sarif",
|
||||||
"artifacts/release/dependency-inventory.json",
|
"artifacts/release/dependency-inventory.json",
|
||||||
"artifacts/security/dependency-diff.json"
|
"artifacts/release/sbom.cdx.json",
|
||||||
|
"artifacts/release/provenance.json",
|
||||||
|
"artifacts/release/reproducible-build.json",
|
||||||
|
"artifacts/security/dependency-diff.json",
|
||||||
|
"artifacts/security/license-report.json",
|
||||||
|
"artifacts/security/vulnerability-report.json",
|
||||||
|
"artifacts/security/supply-chain-verification.json",
|
||||||
|
"artifacts/security/supply-chain-coherence.json",
|
||||||
|
"artifacts/security/supply-chain-fixtures.json",
|
||||||
|
"artifacts/security/supply-chain-provider-fixtures.json"
|
||||||
],
|
],
|
||||||
"retentionClass": "release-coherence"
|
"retentionClass": "release-coherence"
|
||||||
},
|
},
|
||||||
@@ -260,11 +292,15 @@
|
|||||||
"FE-GATE-015": {
|
"FE-GATE-015": {
|
||||||
"name": "release-coherence",
|
"name": "release-coherence",
|
||||||
"steps": [
|
"steps": [
|
||||||
{ "script": "build", "expect": "pass" },
|
{ "script": "build:release", "expect": "pass" },
|
||||||
{ "script": "verify:release", "expect": "pass" }
|
{ "script": "verify:release", "expect": "pass" },
|
||||||
|
{ "script": "verify:supply-chain:promotion", "expect": "pass" }
|
||||||
],
|
],
|
||||||
"logPath": "artifacts/quality/gates/FE-GATE-015.txt",
|
"logPath": "artifacts/quality/gates/FE-GATE-015.txt",
|
||||||
"evidence": ["artifacts/release/verification.json"],
|
"evidence": [
|
||||||
|
"artifacts/release/verification.json",
|
||||||
|
"artifacts/security/promotion-verification.json"
|
||||||
|
],
|
||||||
"retentionClass": "release-coherence"
|
"retentionClass": "release-coherence"
|
||||||
},
|
},
|
||||||
"FE-GATE-016": {
|
"FE-GATE-016": {
|
||||||
@@ -315,10 +351,16 @@
|
|||||||
"retentionClass": "release-coherence"
|
"retentionClass": "release-coherence"
|
||||||
},
|
},
|
||||||
"FE-GATE-020": {
|
"FE-GATE-020": {
|
||||||
"name": "reference-feature-removal",
|
"name": "removability",
|
||||||
"steps": [{ "script": "test:sample-removal", "expect": "pass" }],
|
"steps": [
|
||||||
|
{ "script": "test:sample-removal", "expect": "pass" },
|
||||||
|
{ "script": "test:optional-recipe-removal", "expect": "pass" }
|
||||||
|
],
|
||||||
"logPath": "artifacts/quality/gates/FE-GATE-020.txt",
|
"logPath": "artifacts/quality/gates/FE-GATE-020.txt",
|
||||||
"evidence": ["artifacts/tests/sample-removal.xml"],
|
"evidence": [
|
||||||
|
"artifacts/tests/sample-removal.xml",
|
||||||
|
"artifacts/tests/optional-recipe-removal.xml"
|
||||||
|
],
|
||||||
"retentionClass": "merge-cycle"
|
"retentionClass": "merge-cycle"
|
||||||
},
|
},
|
||||||
"FE-GATE-021": {
|
"FE-GATE-021": {
|
||||||
|
|||||||
@@ -0,0 +1,233 @@
|
|||||||
|
{
|
||||||
|
"$schema": "../../schemas/config/frontend-capability-recipes.schema.json",
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"decisionId": "VD-10",
|
||||||
|
"defaultStatus": "NOT_INSTALLED",
|
||||||
|
"productionRuntimeDependencies": [],
|
||||||
|
"catalogOwner": "frontend-platform",
|
||||||
|
"reviewOn": "project-capability-selection",
|
||||||
|
"vendorPackagePatterns": [
|
||||||
|
"@launchdarkly/*",
|
||||||
|
"@sentry/*",
|
||||||
|
"@opentelemetry/*",
|
||||||
|
"@openapitools/openapi-generator-cli",
|
||||||
|
"@reduxjs/toolkit",
|
||||||
|
"@tanstack/react-virtual",
|
||||||
|
"@uppy/*",
|
||||||
|
"firebase",
|
||||||
|
"idb",
|
||||||
|
"react-window",
|
||||||
|
"redux",
|
||||||
|
"socket.io-client",
|
||||||
|
"tus-js-client",
|
||||||
|
"workbox-window",
|
||||||
|
"xstate",
|
||||||
|
"zustand"
|
||||||
|
],
|
||||||
|
"recipes": [
|
||||||
|
{
|
||||||
|
"id": "realtime",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "The backend exposes ordered push events with a documented resume and authorization protocol.",
|
||||||
|
"forbiddenWhen": ["Polling satisfies the measured freshness requirement.", "Event ordering and reconnect ownership are undefined."],
|
||||||
|
"boundary": "outbound connection plus inbound validated event adapter",
|
||||||
|
"port": "RealtimePort",
|
||||||
|
"fake": "FakeRealtimeAdapter",
|
||||||
|
"failureKinds": ["disconnect", "duplicate", "out-of-order", "auth-expiry"],
|
||||||
|
"lifecycleMethods": ["unsubscribe"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Validate every event envelope.", "Never place credentials in URLs or telemetry.", "Refresh authorization through the session boundary."],
|
||||||
|
"bundleBudgetGzipBytes": 12000,
|
||||||
|
"fallback": "Bounded polling or explicitly stale UI.",
|
||||||
|
"removal": ["Remove composition registration.", "Remove adapter and vendor dependency.", "Run recipe-removal and production-bundle gates."],
|
||||||
|
"serverStatePolicy": "query-cache-owned"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "offline-indexeddb",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "A product requirement needs durable offline data or a durable command queue beyond small public preferences.",
|
||||||
|
"forbiddenWhen": ["The data contains credentials.", "The browser would connect directly to a database or object store.", "A normal HTTP cache is sufficient."],
|
||||||
|
"boundary": "application-owned versioned repository output port",
|
||||||
|
"port": "VersionedOfflineRepository",
|
||||||
|
"fake": "MemoryOfflineRepository",
|
||||||
|
"failureKinds": ["quota", "corruption", "migration-rollback"],
|
||||||
|
"lifecycleMethods": ["close"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Classify persisted fields.", "Encrypting in the same client is not a credential protection boundary.", "Version and test every migration."],
|
||||||
|
"bundleBudgetGzipBytes": 8000,
|
||||||
|
"fallback": "Online-only query path with an explicit offline state.",
|
||||||
|
"removal": ["Stop writes.", "Migrate or purge owned stores.", "Remove repository composition and dependency."],
|
||||||
|
"serverStatePolicy": "reference-or-command-only"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "service-worker-pwa",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "Installability or a measured offline-shell requirement is approved with cache ownership.",
|
||||||
|
"forbiddenWhen": ["Hosting cache and worker cache ownership conflict.", "Update and rollback UX is undefined."],
|
||||||
|
"boundary": "bootstrap update controller and cache policy adapter",
|
||||||
|
"port": "ServiceWorkerUpdatePort",
|
||||||
|
"fake": "FakeServiceWorkerUpdateAdapter",
|
||||||
|
"failureKinds": ["stale-worker", "update-loop", "offline-fallback"],
|
||||||
|
"lifecycleMethods": ["unregister", "rollback"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Never cache authenticated API responses by default.", "Bind cache names to release identity.", "Fail closed on malformed update metadata."],
|
||||||
|
"bundleBudgetGzipBytes": 10000,
|
||||||
|
"fallback": "Normal network application with hosting cache headers.",
|
||||||
|
"removal": ["Deploy an unregister migration.", "Delete owned caches.", "Remove worker registration and manifest."],
|
||||||
|
"serverStatePolicy": "network-cache-policy-only"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "file-transfer",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "The product accepts or delivers files with progress and cancellation requirements.",
|
||||||
|
"forbiddenWhen": ["Allowed size and MIME policy is missing.", "Long-lived credentials would be embedded in URLs."],
|
||||||
|
"boundary": "application file transfer output port behind an authorized backend protocol",
|
||||||
|
"port": "FileTransferPort",
|
||||||
|
"fake": "FakeFileTransferAdapter",
|
||||||
|
"failureKinds": ["size-rejection", "type-rejection", "abort", "expired-url"],
|
||||||
|
"lifecycleMethods": ["cancel-via-AbortSignal"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Treat MIME as untrusted metadata.", "Use short-lived opaque resource identifiers.", "Redact file names when classified as personal data."],
|
||||||
|
"bundleBudgetGzipBytes": 6000,
|
||||||
|
"fallback": "Standard request with bounded size and no background continuation.",
|
||||||
|
"removal": ["Cancel active transfers.", "Remove route actions and composition.", "Remove transfer dependency."],
|
||||||
|
"serverStatePolicy": "query-cache-metadata-only"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "generated-api",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "A versioned backend contract justifies generated transport code.",
|
||||||
|
"forbiddenWhen": ["Generated DTOs would escape into domain or presentation.", "Contract drift cannot block CI."],
|
||||||
|
"boundary": "generated client wrapped by a feature gateway facade and mapper",
|
||||||
|
"port": "GeneratedApiFacade",
|
||||||
|
"fake": "FakeGeneratedApiAdapter",
|
||||||
|
"failureKinds": ["contract-drift", "unsupported-field"],
|
||||||
|
"lifecycleMethods": ["cancel-via-AbortSignal"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Generate from an authenticated source.", "Review generator execution and output.", "Do not log request bodies."],
|
||||||
|
"bundleBudgetGzipBytes": 16000,
|
||||||
|
"fallback": "Existing typed request builder and runtime response schema.",
|
||||||
|
"removal": ["Restore handwritten gateway.", "Remove generated output and generator.", "Verify DTOs do not remain in public types."],
|
||||||
|
"serverStatePolicy": "query-cache-owned"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "feature-flag",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "A staged rollout or kill switch has a named owner, default and stale policy.",
|
||||||
|
"forbiddenWhen": ["A flag is used as authorization.", "Unknown and unavailable behavior is undefined."],
|
||||||
|
"boundary": "application feature policy output port",
|
||||||
|
"port": "FeatureFlagPort",
|
||||||
|
"fake": "FakeFeatureFlagAdapter",
|
||||||
|
"failureKinds": ["provider-unavailable", "unknown-flag", "stale-value"],
|
||||||
|
"lifecycleMethods": ["dispose-provider-if-installed"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Flags are hints, never access control.", "Minimize targeting attributes.", "Apply consent rules to personal attributes."],
|
||||||
|
"bundleBudgetGzipBytes": 10000,
|
||||||
|
"fallback": "Typed local default with an explicit stale decision.",
|
||||||
|
"removal": ["Resolve the rollout permanently.", "Delete flag key and branches.", "Remove provider composition and dependency."],
|
||||||
|
"serverStatePolicy": "policy-cache-only"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "web-worker",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "Profiling shows CPU work blocking the main thread beyond the performance budget.",
|
||||||
|
"forbiddenWhen": ["The task is primarily network I/O.", "Cancellation and stale-result ownership are undefined."],
|
||||||
|
"boundary": "request/result/cancel output port with a validated message adapter",
|
||||||
|
"port": "WorkerTaskPort",
|
||||||
|
"fake": "FakeWorkerTaskAdapter",
|
||||||
|
"failureKinds": ["crash", "stale-result", "transfer-failure"],
|
||||||
|
"lifecycleMethods": ["cancel", "dispose"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Validate worker messages.", "Do not send credentials.", "Bound transferred data and worker count."],
|
||||||
|
"bundleBudgetGzipBytes": 14000,
|
||||||
|
"fallback": "Chunked or deferred main-thread execution within a measured limit.",
|
||||||
|
"removal": ["Stop and dispose workers.", "Restore synchronous facade implementation.", "Remove worker entry and chunk."],
|
||||||
|
"serverStatePolicy": "no-server-state"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "multi-tab",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "A documented workflow must synchronize non-sensitive events across tabs.",
|
||||||
|
"forbiddenWhen": ["The server is the correct conflict authority.", "Event version and source identity are undefined."],
|
||||||
|
"boundary": "versioned browser event output/input adapter",
|
||||||
|
"port": "MultiTabPort",
|
||||||
|
"fake": "FakeMultiTabAdapter",
|
||||||
|
"failureKinds": ["self-echo", "duplicate", "conflict"],
|
||||||
|
"lifecycleMethods": ["unsubscribe", "close"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Broadcast no credentials or personal payload.", "Validate versions.", "Treat events as hints rather than authorization."],
|
||||||
|
"bundleBudgetGzipBytes": 4000,
|
||||||
|
"fallback": "Refresh from the authoritative server on focus.",
|
||||||
|
"removal": ["Close channels.", "Remove event registry entries.", "Restore focus-based refresh."],
|
||||||
|
"serverStatePolicy": "invalidation-only"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "browser-permission",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "A user-initiated flow requires clipboard, notification or media access.",
|
||||||
|
"forbiddenWhen": ["Permission would be requested at boot.", "Denied, dismissed and unsupported UX are not designed."],
|
||||||
|
"boundary": "presentation input action through a browser capability output port",
|
||||||
|
"port": "BrowserPermissionPort",
|
||||||
|
"fake": "FakeBrowserPermissionAdapter",
|
||||||
|
"failureKinds": ["denied", "dismissed", "unsupported"],
|
||||||
|
"lifecycleMethods": ["stop-media-tracks-if-opened"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Require an explicit user gesture.", "Minimize requested scope.", "Do not persist permission as authorization."],
|
||||||
|
"bundleBudgetGzipBytes": 3000,
|
||||||
|
"fallback": "Manual input or copy/download instruction.",
|
||||||
|
"removal": ["Stop acquired resources.", "Remove permission action and adapter.", "Retest denied-path accessibility."],
|
||||||
|
"serverStatePolicy": "no-server-state"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "client-workflow",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "A measured cross-page client-only workflow cannot be represented by URL, local state, context or query cache.",
|
||||||
|
"forbiddenWhen": ["The store would duplicate server response collections.", "A library is selected before state ownership is documented.", "Zustand and Redux Toolkit would both be installed."],
|
||||||
|
"boundary": "workflow-specific local facade; vendor types remain in its adapter",
|
||||||
|
"port": "ClientWorkflowPort",
|
||||||
|
"fake": "FakeClientWorkflowAdapter",
|
||||||
|
"failureKinds": ["reset", "version-mismatch", "server-state-duplication"],
|
||||||
|
"lifecycleMethods": ["unsubscribe", "reset"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Persist only explicitly classified workflow fields.", "Never persist credentials.", "Define logout and version reset."],
|
||||||
|
"bundleBudgetGzipBytes": 9000,
|
||||||
|
"fallback": "URL, component state, context and TanStack Query ownership.",
|
||||||
|
"removal": ["Move remaining state to its natural owner.", "Remove facade and one selected store dependency.", "Verify logout/reset."],
|
||||||
|
"serverStatePolicy": "reference-only"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "large-data-ui",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "Production-like profiling proves a list or grid exceeds interaction and rendering budgets.",
|
||||||
|
"forbiddenWhen": ["Pagination solves the scale requirement.", "Keyboard and screen-reader focus behavior is undefined."],
|
||||||
|
"boundary": "presentation facade around virtualizer or data-grid behavior",
|
||||||
|
"port": "LargeDataUiFacade",
|
||||||
|
"fake": "FakeLargeDataUiAdapter",
|
||||||
|
"failureKinds": ["focus-loss", "stale-row", "scale-limit"],
|
||||||
|
"lifecycleMethods": ["dispose-observers-if-installed"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Render only authorized rows.", "Do not expose hidden row data to telemetry.", "Preserve accessible row identity."],
|
||||||
|
"bundleBudgetGzipBytes": 30000,
|
||||||
|
"fallback": "Accessible pagination and bounded result sets.",
|
||||||
|
"removal": ["Restore paginated primitive.", "Remove facade adapter and dependency.", "Run keyboard and performance evidence."],
|
||||||
|
"serverStatePolicy": "query-cache-owned"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "analytics-error-sink",
|
||||||
|
"status": "RECIPE_AVAILABLE",
|
||||||
|
"trigger": "A production provider, consent policy, retention owner and event registry are approved.",
|
||||||
|
"forbiddenWhen": ["Consent and essential diagnostics are not separated.", "Arbitrary message or attribute keys can bypass redaction."],
|
||||||
|
"boundary": "closed diagnostics/analytics port with provider adapter",
|
||||||
|
"port": "AnalyticsErrorSink",
|
||||||
|
"fake": "RecordingAnalyticsAdapter",
|
||||||
|
"failureKinds": ["consent-denied", "queue-full", "provider-unavailable"],
|
||||||
|
"lifecycleMethods": ["flush", "dispose"],
|
||||||
|
"owner": "project-owner-required",
|
||||||
|
"securityPrivacy": ["Allowlist events and attributes.", "Redact before queueing.", "Apply consent, sampling and retention policy."],
|
||||||
|
"bundleBudgetGzipBytes": 25000,
|
||||||
|
"fallback": "Existing bounded local diagnostics and best-effort telemetry port.",
|
||||||
|
"removal": ["Disable provider delivery.", "Flush or discard by policy.", "Remove adapter, runtime config and dependency."],
|
||||||
|
"serverStatePolicy": "no-server-state"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"snapshotDigest": "ce4fa9b7944f27553067228bd6c9e73e7dc05875c283255b50d7eb3ad2923f6d",
|
||||||
|
"owner": "frontend-platform",
|
||||||
|
"reason": "RP-11-initial-transitive-inventory",
|
||||||
|
"approvedAt": "2026-07-26T08:27:17.874Z"
|
||||||
|
}
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,4 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"changes": []
|
||||||
|
}
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"allowedLicenses": [
|
||||||
|
"(MIT OR CC0-1.0)",
|
||||||
|
"0BSD",
|
||||||
|
"Apache-2.0",
|
||||||
|
"BSD-2-Clause",
|
||||||
|
"BSD-3-Clause",
|
||||||
|
"BlueOak-1.0.0",
|
||||||
|
"CC-BY-4.0",
|
||||||
|
"CC0-1.0",
|
||||||
|
"ISC",
|
||||||
|
"MIT",
|
||||||
|
"MIT-0",
|
||||||
|
"MPL-2.0"
|
||||||
|
],
|
||||||
|
"deniedLicensePatterns": [
|
||||||
|
"(^|\\s)AGPL",
|
||||||
|
"(^|\\s)GPL",
|
||||||
|
"SSPL",
|
||||||
|
"BUSL"
|
||||||
|
],
|
||||||
|
"unknownLicensePolicy": "allow-only-unmaterialized-platform-optional"
|
||||||
|
}
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"trackedRoots": [
|
||||||
|
"src",
|
||||||
|
"recipes",
|
||||||
|
"scripts",
|
||||||
|
"tests",
|
||||||
|
"config",
|
||||||
|
"public",
|
||||||
|
"schemas",
|
||||||
|
".storybook",
|
||||||
|
"package.json",
|
||||||
|
"pnpm-lock.yaml",
|
||||||
|
"vite.config.js",
|
||||||
|
"vitest.config.js",
|
||||||
|
"playwright.config.js"
|
||||||
|
],
|
||||||
|
"generatedRoots": ["dist", "artifacts/release"],
|
||||||
|
"excludedPaths": [
|
||||||
|
"tests/fixtures/security/secret-detection/forbidden"
|
||||||
|
],
|
||||||
|
"allowlist": [
|
||||||
|
{
|
||||||
|
"path": "tests/fixtures/security/secret-detection/allowed/test-credentials.ts",
|
||||||
|
"ruleId": "assigned-secret",
|
||||||
|
"owner": "frontend-platform",
|
||||||
|
"reason": "Synthetic credential verifies the scoped test-only allowlist.",
|
||||||
|
"expiresAt": "2027-07-26T00:00:00.000Z"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"exceptions": []
|
||||||
|
}
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"providerMode": "external-file",
|
||||||
|
"inputEnvironment": "VULNERABILITY_REPORT_PATH",
|
||||||
|
"blockAtSeverity": "high",
|
||||||
|
"allowedSeverities": ["unknown", "low", "moderate", "high", "critical"],
|
||||||
|
"missingProviderStatus": "FAIL_UNVERIFIED"
|
||||||
|
}
|
||||||
@@ -0,0 +1,103 @@
|
|||||||
|
# VD-09: 공급망 inventory, license, vulnerability, SBOM과 provenance
|
||||||
|
|
||||||
|
- 상태: Accepted
|
||||||
|
- 결정일: 2026-07-26
|
||||||
|
- 적용 브랜치: `feature-frontend-supply-chain-verification`
|
||||||
|
- 재검토: 조직 vulnerability scanner, signing/attestation provider와 dependency
|
||||||
|
exception 승인 체계가 선정될 때
|
||||||
|
|
||||||
|
## 배경
|
||||||
|
|
||||||
|
기존 release script는 `package.json`의 직접 dependency 이름과 버전, lockfile
|
||||||
|
전체 digest, `dist` checksum만 기록했다. 전이 dependency, 패키지별 integrity와
|
||||||
|
license, 실제 baseline diff가 없었고 `highRiskUnreviewed: []`는 계산 결과가 아닌
|
||||||
|
고정값이었다. secret scan도 `src`와 `dist`만 검사해 config, scripts, test와
|
||||||
|
generated release metadata를 놓쳤다.
|
||||||
|
|
||||||
|
반면 저장소에는 조직이 선택한 vulnerability source, severity exception 승인자,
|
||||||
|
signing identity와 attestation 저장소가 없다. 외부 provider가 없는 상태를 빈
|
||||||
|
finding과 서명 성공으로 표현하면 local 검증과 release promotion을 혼동한다.
|
||||||
|
|
||||||
|
## 결정
|
||||||
|
|
||||||
|
1. `pnpm-lock.yaml`의 모든 `packages` row와 `pnpm list --depth Infinity`의 실제
|
||||||
|
graph를 결합해 직접/전이, production/development, required/platform-optional,
|
||||||
|
version, SHA-512 SRI, license와 dependency edge를 기록한다.
|
||||||
|
2. inventory row 수는 lockfile package row 수와 같아야 한다. 누락된 전이
|
||||||
|
dependency, malformed integrity와 non-optional `NOASSERTION`은 local gate를
|
||||||
|
실패시킨다.
|
||||||
|
3. license는 설치된 package manifest에서 읽고 closed allow/deny policy로
|
||||||
|
검사한다. 현재 OS에 materialize되지 않은 platform optional만
|
||||||
|
`NOASSERTION`과 그 이유를 명시적으로 허용한다.
|
||||||
|
4. 승인 dependency baseline과 approval digest를 보존하고 현재 lock inventory와
|
||||||
|
actual add/remove/change/upgrade diff를 계산한다. 새 direct production
|
||||||
|
dependency는 owner와 서로 다른 reviewer, reason과 rollback evidence가
|
||||||
|
필요하다.
|
||||||
|
5. inventory를 CycloneDX 1.6 SBOM으로 투영한다. component 수, lockfile digest,
|
||||||
|
SRI, license와 dependency edge가 inventory와 일치해야 한다.
|
||||||
|
6. local in-toto/SLSA 형태 provenance statement는 source set, lockfile, SBOM과
|
||||||
|
`dist` digest를 연결하되 `LOCAL_UNSIGNED`로 표시한다. 외부 attestation은
|
||||||
|
provider, signer와 동일 dist subject digest가 있어야 한다.
|
||||||
|
7. vulnerability adapter는 `VULNERABILITY_REPORT_PATH`가 가리키는
|
||||||
|
machine-readable provider report를 검증한다. report의 lock digest, provider,
|
||||||
|
severity와 exception owner/reviewer/reason/expiry가 유효해야 한다.
|
||||||
|
8. provider report가 없으면 local inventory/license/SBOM/coherence는 `PASS`,
|
||||||
|
promotion은 `FAIL_UNVERIFIED`다. 빈 finding을 만들어 vulnerability PASS로
|
||||||
|
표시하지 않는다.
|
||||||
|
9. secret scan은 source, scripts, tests, tracked config/schema, public, `dist`와
|
||||||
|
generated release metadata를 검사한다. allowlist는 test path에만 허용하며
|
||||||
|
owner, reason과 expiry가 필요하다. 발견한 secret 원문은 artifact에 쓰지 않고
|
||||||
|
rule, path, line과 fingerprint만 남긴다.
|
||||||
|
10. `SOURCE_DATE_EPOCH`를 지원하고 같은 source/lock/config의 production build를
|
||||||
|
두 번 실행해 전체 dist digest 일치를 검증한 뒤 일반 build를 복원한다.
|
||||||
|
|
||||||
|
## 실행 경계와 증적
|
||||||
|
|
||||||
|
```text
|
||||||
|
package.json + frozen pnpm-lock.yaml + installed graph
|
||||||
|
-> deterministic dependency inventory
|
||||||
|
-> license policy + approved actual baseline diff
|
||||||
|
-> CycloneDX SBOM
|
||||||
|
|
||||||
|
source/config/lock + production dist
|
||||||
|
-> local provenance statement
|
||||||
|
-> optional vulnerability/attestation provider inputs
|
||||||
|
-> LOCAL PASS | promotion PASS/FAIL_UNVERIFIED
|
||||||
|
```
|
||||||
|
|
||||||
|
- policy: `config/security/`
|
||||||
|
- generator: `scripts/generate-supply-chain.mjs`
|
||||||
|
- coherence: `scripts/verify-supply-chain-artifacts.mjs`
|
||||||
|
- secret scan: `scripts/security-scan.mjs`
|
||||||
|
- reproducibility: `scripts/verify-reproducible-build.mjs`
|
||||||
|
- inventory: `artifacts/release/dependency-inventory.json`
|
||||||
|
- SBOM/provenance: `artifacts/release/sbom.cdx.json`,
|
||||||
|
`artifacts/release/provenance.json`
|
||||||
|
- local/promotion status:
|
||||||
|
`artifacts/security/supply-chain-verification.json`
|
||||||
|
|
||||||
|
## 검증
|
||||||
|
|
||||||
|
- 현재 lockfile의 561개 package row와 inventory row가 양방향 일치한다.
|
||||||
|
- ordering-only digest, removal, integrity tamper, baseline tamper, high-risk
|
||||||
|
self approval, denied license, critical vulnerability와 만료 exception,
|
||||||
|
provider/digest 오류, SBOM/provenance 불일치 fixture를 검사한다.
|
||||||
|
- synthetic provider/attestation fixture는 promotion `PASS`를 증명한 후 기본
|
||||||
|
`FAIL_UNVERIFIED` 상태를 복원한다.
|
||||||
|
- frozen install은 manifest/lock mismatch fixture를 실제 pnpm으로 거절한다.
|
||||||
|
- source/config/dist 각각의 synthetic secret fixture가 실제 scan을 실패시키고
|
||||||
|
scoped test allowlist만 통과한다.
|
||||||
|
|
||||||
|
## 한계와 재검토 조건
|
||||||
|
|
||||||
|
로컬 manifest license는 법률 검토가 아니며 vulnerability report도 외부 scanner가
|
||||||
|
제공한 데이터의 최신성 자체를 보증하지 않는다. 실제 프로젝트는 provider 버전,
|
||||||
|
database freshness, network outage, exception 승인 조직, signing identity,
|
||||||
|
attestation transparency/retention과 비밀 관리를 결정해야 한다.
|
||||||
|
|
||||||
|
## Rollback
|
||||||
|
|
||||||
|
외부 scanner/attestor adapter는 환경 입력을 제거하면 즉시
|
||||||
|
`FAIL_UNVERIFIED`로 돌아간다. local inventory, lock integrity, license, SBOM,
|
||||||
|
secret, reproducibility와 actual diff gate는 유지한다. scanner 장애를 이유로
|
||||||
|
promotion을 PASS로 변경하지 않는다.
|
||||||
@@ -0,0 +1,99 @@
|
|||||||
|
# VD-10: 선택형 frontend capability recipe
|
||||||
|
|
||||||
|
- 상태: Accepted
|
||||||
|
- 결정일: 2026-07-26
|
||||||
|
- 적용 브랜치: `feature-frontend-optional-adapter-recipes`
|
||||||
|
- 현재 선택 capability: 없음
|
||||||
|
- 재검토: 실제 프로젝트가 realtime, offline, PWA, file, generated API,
|
||||||
|
feature flag, worker, multi-tab, browser permission, client workflow,
|
||||||
|
large-data UI 또는 production analytics/error provider를 요구할 때
|
||||||
|
|
||||||
|
## 배경
|
||||||
|
|
||||||
|
서버의 PostgreSQL, MongoDB, Redis, Kafka, MinIO 같은 기술을 브라우저가 직접
|
||||||
|
소비하지는 않는다. 프론트의 변화 지점은 권한 있는 HTTP/BFF, push event,
|
||||||
|
offline persistence, file protocol, browser runtime, 사용자 동의와 UI 성능
|
||||||
|
경계다. 이 capability를 “언젠가 필요할 수 있다”는 이유로 모두 설치하면 초기
|
||||||
|
bundle, 공급망, runtime config, 보안 표면과 업데이트 비용만 늘어난다.
|
||||||
|
|
||||||
|
반대로 문서에 이름만 적으면 실제 프로젝트에서 port 위치, cancellation,
|
||||||
|
fallback, fake와 제거 기준을 다시 설계해야 한다. 따라서 production runtime에
|
||||||
|
아무것도 설치하지 않되 검증 가능한 vendor-neutral recipe를 저장소 밖이 아닌
|
||||||
|
별도 opt-in 경계에 유지한다.
|
||||||
|
|
||||||
|
## 결정
|
||||||
|
|
||||||
|
1. `config/recipes/frontend-capability-recipes.json`이 12개 recipe의 선택 기준,
|
||||||
|
금지 조건, port/fake, failure matrix, lifecycle cleanup, owner,
|
||||||
|
security/privacy, gzip budget, fallback, server-state 정책과 제거 절차의
|
||||||
|
machine-readable SSOT다.
|
||||||
|
2. 현재 실제 소비 요구와 project owner가 없으므로 12개 상태는 모두
|
||||||
|
`RECIPE_AVAILABLE`이며 `INSTALLED`가 아니다. production runtime dependency와
|
||||||
|
composition registration은 0개다.
|
||||||
|
3. `recipes/frontend-capabilities`의 TypeScript port와 fake/unavailable adapter는
|
||||||
|
실행 가능한 설계 예시다. `src` 또는 production entry가 이 디렉터리를 import할
|
||||||
|
수 없다.
|
||||||
|
4. 프로젝트가 capability를 선택하면 필요한 최소 contract를
|
||||||
|
application-owned output port 또는 presentation facade로 이동하고, concrete
|
||||||
|
vendor adapter는 local adapter 경계에 둔다. recipe 디렉터리를 production에서
|
||||||
|
그대로 import하지 않는다.
|
||||||
|
5. WebSocket/SSE처럼 연결은 outbound이고 수신 event는 inbound인 양방향 기술도
|
||||||
|
한 종류의 “adapter”로 뭉개지 않는다. 연결·credential·reconnect 정책과
|
||||||
|
event validation·input invocation을 분리한다.
|
||||||
|
6. Zustand/Redux Toolkit/state machine은 실제 cross-page client-only workflow가
|
||||||
|
확인된 경우 하나만 선택한다. URL, component state, Context, TanStack Query가
|
||||||
|
이미 소유한 상태를 복제하지 않는다.
|
||||||
|
7. browser credential은 localStorage, URL, recipe store, telemetry 또는
|
||||||
|
BroadcastChannel에 넣지 않는다. 브라우저가 database/object store에 직접
|
||||||
|
접속하는 recipe도 금지한다.
|
||||||
|
8. lifecycle이 있는 capability는 unsubscribe, close, unregister, dispose,
|
||||||
|
cancel 또는 `AbortSignal`을 계약과 contract test에 포함해야 한다.
|
||||||
|
9. 선택하지 않은 recipe sentinel이나 vendor dependency가 production bundle에
|
||||||
|
들어가면 gate를 실패시킨다.
|
||||||
|
10. recipe 전체를 제거한 임시 worktree에서 base typecheck, architecture,
|
||||||
|
unit/component/integration test와 production build가 통과해야 한다.
|
||||||
|
|
||||||
|
## 선택과 설치 절차
|
||||||
|
|
||||||
|
```text
|
||||||
|
measured product/runtime need
|
||||||
|
-> project owner + security/privacy classification
|
||||||
|
-> recipe trigger/forbidden/fallback review
|
||||||
|
-> VD-10 amendment with one selected capability
|
||||||
|
-> application port or presentation facade copied into src
|
||||||
|
-> one concrete adapter under local adapter boundary
|
||||||
|
-> composition-only wiring
|
||||||
|
-> contract/failure/cleanup/integration tests
|
||||||
|
-> bundle + dependency baseline approval
|
||||||
|
-> INSTALLED only after all evidence passes
|
||||||
|
```
|
||||||
|
|
||||||
|
도입 커밋에는 owner, 선택 이유, 대안, gzip 차이, runtime config, browser support,
|
||||||
|
failure UX, observability, rollback과 제거 명령을 기록한다. vendor가 필요한
|
||||||
|
behavior를 fake만으로 확인하고 `INSTALLED`로 바꾸지 않는다.
|
||||||
|
|
||||||
|
## 증적
|
||||||
|
|
||||||
|
- catalog: `config/recipes/frontend-capability-recipes.json`
|
||||||
|
- contracts/fakes: `recipes/frontend-capabilities`
|
||||||
|
- 상세 runbook: `docs/architecture/optional-adapter-recipes.md`
|
||||||
|
- contract test: `tests/recipes/optional-capability-contracts.test.ts`
|
||||||
|
- negative fixture:
|
||||||
|
`tests/fixtures/optional-recipes/forbidden`
|
||||||
|
- validation:
|
||||||
|
`scripts/check-optional-recipes.mjs`
|
||||||
|
- removal:
|
||||||
|
`scripts/test-optional-recipe-removal.mjs`
|
||||||
|
- evidence:
|
||||||
|
`artifacts/quality/optional-recipes.json`,
|
||||||
|
`artifacts/quality/optional-recipe-fixtures.json`,
|
||||||
|
`artifacts/tests/optional-recipes.xml`,
|
||||||
|
`artifacts/tests/optional-recipe-removal.xml`
|
||||||
|
|
||||||
|
## Rollback
|
||||||
|
|
||||||
|
현재 branch는 runtime dependency나 production composition을 바꾸지 않으므로
|
||||||
|
recipe catalog, example과 gate를 함께 revert하면 RP-11 상태로 돌아간다. 실제
|
||||||
|
프로젝트에서 선택한 capability는 그 capability의 port/adapter/composition/
|
||||||
|
dependency commit만 revert한다. 여러 vendor 도입을 하나의 되돌릴 수 없는
|
||||||
|
commit으로 묶지 않는다.
|
||||||
@@ -12,7 +12,7 @@
|
|||||||
- 기본 번들에 포함할 역량과 필요할 때 설치할 확장 역량을 구분한다.
|
- 기본 번들에 포함할 역량과 필요할 때 설치할 확장 역량을 구분한다.
|
||||||
- 특정 벤더를 채택하더라도 제품 코드가 벤더 API에 직접 결합되지 않는지 확인한다.
|
- 특정 벤더를 채택하더라도 제품 코드가 벤더 API에 직접 결합되지 않는지 확인한다.
|
||||||
|
|
||||||
최초 검토 기준은 `develop`의 `cb195f8`이며, RP-01~RP-10 구현 결과를 이 문서에
|
최초 검토 기준은 `develop`의 `cb195f8`이며, RP-01~RP-12 구현 결과를 이 문서에
|
||||||
누적 반영했다. 이후 구현으로 경로나 세부 내용이 달라질 수 있으므로, 각 항목은
|
누적 반영했다. 이후 구현으로 경로나 세부 내용이 달라질 수 있으므로, 각 항목은
|
||||||
문서의 경로뿐 아니라 해당 테스트와 아키텍처 게이트로 계속 검증해야 한다.
|
문서의 경로뿐 아니라 해당 테스트와 아키텍처 게이트로 계속 검증해야 한다.
|
||||||
|
|
||||||
@@ -27,28 +27,21 @@
|
|||||||
- Vitest, Testing Library, MSW, Playwright, axe를 이용한 테스트 계층
|
- Vitest, Testing Library, MSW, Playwright, axe를 이용한 테스트 계층
|
||||||
- CI 게이트 taxonomy와 호환성·보안·성능·릴리스 계약 문서
|
- CI 게이트 taxonomy와 호환성·보안·성능·릴리스 계약 문서
|
||||||
|
|
||||||
그러나 “도메인 기능을 바로 추가할 수 있는 프론트엔드 플랫폼” 기준으로는 아직
|
RP-01~RP-12에서 TypeScript 도구 안전망, application runtime 주입,
|
||||||
중요한 연결부가 빠져 있다. 가장 큰 문제는 공통 기능이 없다는 것보다 이미 있는
|
|
||||||
기능이 실제 기능 화면의 표준 호출 경로로 조립되지 않았다는 점이다.
|
|
||||||
|
|
||||||
특히 다음은 선행 해결이 필요하다.
|
|
||||||
|
|
||||||
RP-01~RP-09에서 TypeScript 도구 안전망, application runtime 주입,
|
|
||||||
query/mutation inbound adapter, HTTP 실행 계약과 executable route/release
|
query/mutation inbound adapter, HTTP 실행 계약과 executable route/release
|
||||||
recovery 계약, 제거 가능한 reference 수직 슬라이스, form/page, design system과
|
recovery 계약, 제거 가능한 reference 수직 슬라이스, form/page, design system과
|
||||||
i18n 실행 경계와 diagnostics/telemetry production wiring은 구현됐다. 현재 선행 해결
|
i18n 실행 경계, diagnostics/telemetry production wiring, registry/test 증거,
|
||||||
대상은 다음과 같다.
|
local 공급망 검증과 제거 가능한 optional adapter recipe가 구현됐다. 저장소 내부
|
||||||
|
P0/P1 acceptance와 P2 recipe 기본값은 `LOCAL_TEMPLATE_READY`다. 다만 실제 제품
|
||||||
|
도메인과 hosting, IdP, vulnerability/signing provider, analytics consent/provider,
|
||||||
|
지원 browser/접근성·field 증거는 프로젝트가 선택하고 검증해야 한다.
|
||||||
|
|
||||||
1. 공급망의 transitive inventory/license/vulnerability/SBOM/provenance 검증
|
따라서 더 정확한 표현은 다음과 같다.
|
||||||
2. optional adapter의 opt-in 경계와 제거 가능한 recipe
|
|
||||||
|
|
||||||
따라서 현재 상태를 “프론트 공통부가 모두 구현됐다”고 표현하면 범위가 과장된다.
|
> application API, 서버 상태, 폼, 라우팅, 페이지, 디자인 시스템, 테스트와
|
||||||
더 정확한 표현은 다음과 같다.
|
> local 공급망 증적의 표준 수직 경로와 opt-in adapter recipe는 갖춰졌다.
|
||||||
|
> 실제 capability 설치와 hosting·IdP·취약점/서명/운영 provider는 프로젝트
|
||||||
> application API, 서버 상태, 폼, 라우팅, 페이지, 디자인 시스템과 테스트 증적의
|
> 통합 범위이며, 없는 외부 증거를 완료로 표시하지 않는다.
|
||||||
> 표준 수직 경로는 갖춰졌다. 현재 남은 저장소 내부 범위는 공급망 검증과
|
|
||||||
> opt-in adapter recipe이며 실제 hosting·IdP·운영 provider는 프로젝트 통합
|
|
||||||
> 범위다.
|
|
||||||
|
|
||||||
## 3. 판정 기준
|
## 3. 판정 기준
|
||||||
|
|
||||||
@@ -72,8 +65,8 @@ i18n 실행 경계와 diagnostics/telemetry production wiring은 구현됐다.
|
|||||||
| 검증 | 준비됨 | runtime/API/route/form Zod parse 결과를 실행 경계에서 사용하고 domain invariant와 분리 | feature별 schema 소유권 유지 |
|
| 검증 | 준비됨 | runtime/API/route/form Zod parse 결과를 실행 경계에서 사용하고 domain invariant와 분리 | feature별 schema 소유권 유지 |
|
||||||
| 인증 연동 | 준비됨/프로젝트 선택 | opaque auth owner와 demo seam 존재 | 인증 방식별 recipe; 기본 token 저장소는 추가하지 않음 |
|
| 인증 연동 | 준비됨/프로젝트 선택 | opaque auth owner와 demo seam 존재 | 인증 방식별 recipe; 기본 token 저장소는 추가하지 않음 |
|
||||||
| 서버 상태 | 준비됨 | reference route의 query/mutation, cancellation, stale, optimistic/conflict/rollback | feature별 query contribution recipe 유지 |
|
| 서버 상태 | 준비됨 | reference route의 query/mutation, cancellation, stale, optimistic/conflict/rollback | feature별 query contribution recipe 유지 |
|
||||||
| 클라이언트 상태 | 부분 준비 | local state, theme context, session external store | 상태 소유권 표와 typed external-store 예제 |
|
| 클라이언트 상태 | 준비됨/프로젝트 선택 | local/URL/query/context 소유권, session external store, typed workflow recipe | 실제 cross-page workflow가 생길 때 하나의 store 선택 |
|
||||||
| 범용 global store | 프로젝트 선택 | 별도 라이브러리 없음 | 필요 조건에 따라 Zustand/Redux Toolkit/state machine 선택 |
|
| 범용 global store | 프로젝트 선택 | runtime library 없음, typed facade/fake와 server-state duplication gate | VD-10 조건에 따라 Zustand/Redux Toolkit/state machine 중 하나 선택 |
|
||||||
| 라우팅 | 준비됨 | Data Router, typed runtime map, codec, metadata consumer, bounded chunk recovery | reference feature route와 release E2E로 사용 범위 확장 |
|
| 라우팅 | 준비됨 | Data Router, typed runtime map, codec, metadata consumer, bounded chunk recovery | reference feature route와 release E2E로 사용 범위 확장 |
|
||||||
| 앱 셸·반응형 | 준비됨 | native modal Drawer, compact/desktop layout, Escape/link dismiss/focus restore, pseudo reflow와 RTL direction | compact browser matrix 유지 |
|
| 앱 셸·반응형 | 준비됨 | native modal Drawer, compact/desktop layout, Escape/link dismiss/focus restore, pseudo reflow와 RTL direction | compact browser matrix 유지 |
|
||||||
| 페이지 템플릿 | 준비됨 | Standard/Collection/Detail/Form/Status와 public design-system entry | feature별 slot 조합 유지 |
|
| 페이지 템플릿 | 준비됨 | Standard/Collection/Detail/Form/Status와 public design-system entry | feature별 slot 조합 유지 |
|
||||||
@@ -89,8 +82,8 @@ i18n 실행 경계와 diagnostics/telemetry production wiring은 구현됐다.
|
|||||||
| UI 회귀 검증 | 준비됨 | dev-only Storybook interaction/axe와 pinned Chromium visual baseline 4종 | cloud review와 다중 OS/device는 프로젝트 선택 |
|
| UI 회귀 검증 | 준비됨 | dev-only Storybook interaction/axe와 pinned Chromium visual baseline 4종 | cloud review와 다중 OS/device는 프로젝트 선택 |
|
||||||
| 샘플 제거 | 준비됨 | feature/catalog/test 제거 후 type/architecture/registry/test/home/build 9단계 검증 | 새 contribution도 같은 제거 gate에 포함 |
|
| 샘플 제거 | 준비됨 | feature/catalog/test 제거 후 type/architecture/registry/test/home/build 9단계 검증 | 새 contribution도 같은 제거 gate에 포함 |
|
||||||
| registry·compatibility 집행 | 준비됨 | 10개 registry type/reference/consumer/orphan, 승인 digest와 actual semantic diff, breaking evidence | public 계약 변경 시 baseline review 유지 |
|
| registry·compatibility 집행 | 준비됨 | 10개 registry type/reference/consumer/orphan, 승인 digest와 actual semantic diff, breaking evidence | public 계약 변경 시 baseline review 유지 |
|
||||||
| 공급망 검사 | 부분 준비 | lockfile·문서·gate는 있으나 실제 transitive 취약점/license/SBOM 깊이가 부족 | pinned scanner와 policy exception/증적 연결 |
|
| 공급망 검사 | 준비됨/프로젝트 선택 | 561개 transitive inventory/integrity/license, actual diff, CycloneDX, local provenance, secret/reproducible build gate | 실제 vulnerability scanner와 signed attestation 없이는 promotion `FAIL_UNVERIFIED` |
|
||||||
| realtime·offline·file 등 | 프로젝트 선택 | 현재 없음 | port/adapter recipe와 선택 기준 제공 |
|
| realtime·offline·file 등 | 준비됨/프로젝트 선택 | 12개 opt-in TypeScript port/fake/unavailable, failure/security/bundle/removal gate | 실제 요구·owner 승인 시 해당 recipe만 설치 |
|
||||||
|
|
||||||
## 5. 우선순위별 발견 사항
|
## 5. 우선순위별 발견 사항
|
||||||
|
|
||||||
@@ -293,6 +286,13 @@ vendor facade, 선택 조건, 실패 정책, 테스트 fixture를 문서로 제
|
|||||||
| large data UI | virtualization, data grid | owned component facade | 데이터 규모가 측정 기준을 넘을 때 |
|
| large data UI | virtualization, data grid | owned component facade | 데이터 규모가 측정 기준을 넘을 때 |
|
||||||
| analytics/error sink | vendor SDK, OpenTelemetry | redaction, consent, sampling adapter | 운영 provider와 정책이 정해졌을 때 |
|
| analytics/error sink | vendor SDK, OpenTelemetry | redaction, consent, sampling adapter | 운영 provider와 정책이 정해졌을 때 |
|
||||||
|
|
||||||
|
12개 항목의 현재 상태는 모두 `RECIPE_AVAILABLE / NOT_INSTALLED`다.
|
||||||
|
`config/recipes/frontend-capability-recipes.json`이 선택/금지 조건, failure,
|
||||||
|
cleanup, security/privacy, bundle budget, fallback과 제거 절차의 SSOT이며,
|
||||||
|
`recipes/frontend-capabilities`에 production-excluded TypeScript port와
|
||||||
|
fake/unavailable adapter가 있다. 도입 절차는
|
||||||
|
`docs/architecture/optional-adapter-recipes.md`를 따른다.
|
||||||
|
|
||||||
서버의 Redis, MongoDB, PostgreSQL, MinIO를 브라우저가 직접 연결하는 구조는 기본
|
서버의 Redis, MongoDB, PostgreSQL, MinIO를 브라우저가 직접 연결하는 구조는 기본
|
||||||
frontend adapter catalog에 넣지 않는다. 브라우저는 권한 있는 backend API/BFF를
|
frontend adapter catalog에 넣지 않는다. 브라우저는 권한 있는 backend API/BFF를
|
||||||
통해 이 자원에 접근해야 한다. 프론트에서 대응되는 변화 지점은 데이터베이스
|
통해 이 자원에 접근해야 한다. 프론트에서 대응되는 변화 지점은 데이터베이스
|
||||||
|
|||||||
@@ -892,6 +892,31 @@ owner와 만료 시한이 있는 quarantine만 허용한다.
|
|||||||
RP-11은 P1 최종 저장소 기준선이다. scanner outage를 무검증 승인으로 우회하지
|
RP-11은 P1 최종 저장소 기준선이다. scanner outage를 무검증 승인으로 우회하지
|
||||||
않고 promotion을 보류한다.
|
않고 promotion을 보류한다.
|
||||||
|
|
||||||
|
**구현 증거 (2026-07-26)**
|
||||||
|
|
||||||
|
- VD-09에서 frozen pnpm graph와 lockfile을 local SSOT로, package manifest
|
||||||
|
license policy와 CycloneDX 1.6을 local evidence로 채택했다. 외부 vulnerability
|
||||||
|
report와 signed attestation이 없으면 promotion은 `FAIL_UNVERIFIED`다.
|
||||||
|
- 현재 직접 35개, 전체 전이 561개 dependency의 name/version, direct/scope/
|
||||||
|
optional, SHA-512 integrity, license와 dependency edge를 deterministic
|
||||||
|
inventory로 생성한다. lockfile row와 inventory가 양방향 일치하지 않으면
|
||||||
|
실패한다.
|
||||||
|
- 승인 baseline digest와 actual add/remove/change/upgrade diff를 계산하고 새
|
||||||
|
direct production dependency에는 owner와 다른 reviewer, reason과 rollback을
|
||||||
|
요구한다.
|
||||||
|
- CycloneDX SBOM component/edge와 local in-toto/SLSA 형태 provenance의
|
||||||
|
source/lock/SBOM/dist digest를 coherence gate로 다시 계산한다.
|
||||||
|
- license allow/deny, vulnerability severity와 독립·만료 exception 정책,
|
||||||
|
provider lock digest와 attestation subject를 machine-readable하게 검증한다.
|
||||||
|
provider fixture는 promotion PASS를 증명한 뒤 unconfigured
|
||||||
|
`FAIL_UNVERIFIED`를 복원한다.
|
||||||
|
- secret scan을 source/scripts/tests/config/schema/public/dist/generated release
|
||||||
|
metadata로 확장하고 원문 대신 rule/path/line/fingerprint만 SARIF에 남긴다.
|
||||||
|
test-only allowlist도 owner/reason/expiry를 강제한다.
|
||||||
|
- `SOURCE_DATE_EPOCH` 기반 동일 build 2회 digest, 실제 frozen install mismatch,
|
||||||
|
transitive omission/integrity/baseline/self-review/license/vulnerability/
|
||||||
|
provider/SBOM/provenance/secret negative fixture를 blocking gate에 연결했다.
|
||||||
|
|
||||||
## 9. P1 exit gate
|
## 9. P1 exit gate
|
||||||
|
|
||||||
- 현실적인 form의 validation/dirty/pending/422/conflict가 작동한다.
|
- 현실적인 form의 validation/dirty/pending/422/conflict가 작동한다.
|
||||||
@@ -978,6 +1003,31 @@ RP-12는 recipe별 merge commit이다. optional adapter 문제 시 해당 recipe
|
|||||||
revert하고 RP-11을 유지한다. 여러 vendor를 되돌릴 수 없는 한 commit에 묶지
|
revert하고 RP-11을 유지한다. 여러 vendor를 되돌릴 수 없는 한 commit에 묶지
|
||||||
않는다.
|
않는다.
|
||||||
|
|
||||||
|
**구현 증거 (2026-07-26)**
|
||||||
|
|
||||||
|
- VD-10에서 실제 project 요구가 선택되지 않았음을 기록하고 12개 capability를
|
||||||
|
모두 `RECIPE_AVAILABLE`, production runtime dependency 0개로 유지했다.
|
||||||
|
- machine-readable catalog에 recipe별 trigger/forbidden 조건, boundary,
|
||||||
|
port/fake, failure matrix, lifecycle cleanup, project owner 요구,
|
||||||
|
security/privacy, gzip budget, fallback, server-state 정책과 제거 순서를
|
||||||
|
등록했다.
|
||||||
|
- production-excluded `recipes/frontend-capabilities`에 12개 vendor-neutral
|
||||||
|
TypeScript port와 deterministic fake, fail-closed unavailable adapter를
|
||||||
|
제공한다. 프로젝트는 선택한 최소 계약만 application/presentation 경계로
|
||||||
|
복사하고 concrete adapter를 composition에서 연결한다.
|
||||||
|
- realtime ordering/unsubscribe, offline migration/close, worker cancel,
|
||||||
|
multi-tab dedupe, permission result, workflow reset, large-data stale
|
||||||
|
generation, analytics consent/redaction/queue와 나머지 facade contract를
|
||||||
|
runnable test로 검증한다.
|
||||||
|
- cleanup 누락, 승인되지 않은 dependency, vendor direct import, credential
|
||||||
|
storage/URL/telemetry 경로, server-state store 복제와 production recipe import
|
||||||
|
negative fixture를 blocking gate에 연결했다.
|
||||||
|
- recipe와 recipe test를 통째로 제거한 임시 사본에서 base typecheck,
|
||||||
|
architecture, 전체 test와 production build를 실행하며, opt-in하지 않은
|
||||||
|
sentinel이 built `dist`에 없는지 검사한다.
|
||||||
|
- 상세 도입/배치/검증/제거 절차는
|
||||||
|
`docs/architecture/optional-adapter-recipes.md`에 기록했다.
|
||||||
|
|
||||||
## 11. Vendor decision gate
|
## 11. Vendor decision gate
|
||||||
|
|
||||||
| ID | 시점 | 결정 | 기본값 또는 미결정 시 처리 | 차단 범위 |
|
| ID | 시점 | 결정 | 기본값 또는 미결정 시 처리 | 차단 범위 |
|
||||||
|
|||||||
@@ -885,27 +885,32 @@ capability의 기본 정책, port 또는 안전한 no-op 구현과 composition
|
|||||||
|
|
||||||
| Adapter | 도입 조건 | 기본 상태 |
|
| Adapter | 도입 조건 | 기본 상태 |
|
||||||
| --- | --- | --- |
|
| --- | --- | --- |
|
||||||
| WebSocket/SSE | 실시간 server event 필요 | 미설치 recipe |
|
| WebSocket/SSE | 실시간 server event 필요 | opt-in recipe 제공, 미설치 |
|
||||||
| IndexedDB | 큰 offline data 또는 durable queue 필요 | 미설치 recipe |
|
| IndexedDB | 큰 offline data 또는 durable queue 필요 | opt-in recipe 제공, 미설치 |
|
||||||
| Service Worker/PWA | offline shell과 installability 필요 | 미설치 recipe |
|
| Service Worker/PWA | offline shell과 installability 필요 | opt-in recipe 제공, 미설치 |
|
||||||
| Offline mutation queue | 재연결 후 명령 재처리 필요 | 미설치 recipe |
|
| Offline mutation queue | 재연결 후 명령 재처리 필요 | 미설치 recipe |
|
||||||
| Feature flag | remote rollout/kill switch 필요 | 미설치 recipe |
|
| Feature flag | remote rollout/kill switch 필요 | opt-in recipe 제공, 미설치 |
|
||||||
| Translation catalog vendor | 원격 catalog·복수 namespace 운영 필요 | 기본 locale facade 뒤에 미설치 |
|
| Translation catalog vendor | 원격 catalog·복수 namespace 운영 필요 | 기본 locale facade 뒤에 미설치 |
|
||||||
| Analytics | 사용자 동의 기반 product analytics 필요 | 미설치 recipe |
|
| Analytics | 사용자 동의 기반 product analytics 필요 | opt-in recipe 제공, 미설치 |
|
||||||
| Error-reporting SDK | 운영 예외 집계 필요 | 미설치 recipe |
|
| Error-reporting SDK | 운영 예외 집계 필요 | opt-in recipe 제공, 미설치 |
|
||||||
| OpenTelemetry | 조직 trace 연계 필요 | 미설치 recipe |
|
| OpenTelemetry | 조직 trace 연계 필요 | opt-in recipe 제공, 미설치 |
|
||||||
| Web Worker | CPU 작업이 main thread를 막음 | 미설치 recipe |
|
| Web Worker | CPU 작업이 main thread를 막음 | opt-in recipe 제공, 미설치 |
|
||||||
| Notification | 사용자 권한 기반 browser notification 필요 | 미설치 recipe |
|
| Notification | 사용자 권한 기반 browser notification 필요 | opt-in recipe 제공, 미설치 |
|
||||||
| Clipboard/File/Media | 해당 browser capability 필요 | 미설치 recipe |
|
| Clipboard/File/Media | 해당 browser capability 필요 | opt-in recipe 제공, 미설치 |
|
||||||
| Image CDN adapter | responsive image transform 필요 | 미설치 recipe |
|
| Image CDN adapter | responsive image transform 필요 | 미설치 recipe |
|
||||||
| Virtualization | 대량 list rendering이 측정상 병목 | 미설치 recipe |
|
| Virtualization | 대량 list rendering이 측정상 병목 | opt-in recipe 제공, 미설치 |
|
||||||
| OpenAPI generator | backend 계약에서 client 생성 필요 | 미설치 recipe |
|
| OpenAPI generator | backend 계약에서 client 생성 필요 | opt-in recipe 제공, 미설치 |
|
||||||
| Zustand/Redux/Jotai | 복잡한 cross-page client state 확인 | 미설치 recipe |
|
| Zustand/Redux/Jotai | 복잡한 cross-page client state 확인 | opt-in recipe 제공, 미설치 |
|
||||||
| XState 등 state machine | 장기 workflow 상태 전이가 복잡함 | 미설치 recipe |
|
| XState 등 state machine | 장기 workflow 상태 전이가 복잡함 | opt-in recipe 제공, 미설치 |
|
||||||
| Cloud visual-review service | 외부 승인·호스팅 workflow 필요 | 로컬 Storybook/visual gate 뒤에 미설치 |
|
| Cloud visual-review service | 외부 승인·호스팅 workflow 필요 | 로컬 Storybook/visual gate 뒤에 미설치 |
|
||||||
|
|
||||||
선택 adapter는 “나중에 쓸 수 있으므로” 기본 bundle에 넣지 않는다. 도입
|
선택 adapter는 “나중에 쓸 수 있으므로” 기본 bundle에 넣지 않는다. 도입
|
||||||
조건, 보안 영향, bundle 비용과 제거 방법이 확인된 경우에만 추가한다.
|
조건, 보안 영향, bundle 비용과 제거 방법이 확인된 경우에만 추가한다.
|
||||||
|
현재 구현된 공통 catalog, TypeScript contract/fake와 blocking gate는
|
||||||
|
`docs/architecture/optional-adapter-recipes.md`와
|
||||||
|
`config/recipes/frontend-capability-recipes.json`을 따른다. 이 recipe source를
|
||||||
|
production에서 직접 import하는 것은 금지하며 선택한 contract만 application
|
||||||
|
소유 경계로 이동한다.
|
||||||
|
|
||||||
## 19. 새 outbound adapter 추가 recipe
|
## 19. 새 outbound adapter 추가 recipe
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,156 @@
|
|||||||
|
# Optional frontend adapter recipes
|
||||||
|
|
||||||
|
이 문서는 도메인과 무관한 선택형 frontend capability를 실제 프로젝트에
|
||||||
|
도입하는 실행 가이드다. 기본 스켈레톤에는 vendor runtime을 설치하지 않는다.
|
||||||
|
`RECIPE_AVAILABLE`은 계약·fake·failure policy가 준비됐다는 뜻이며 실제 provider,
|
||||||
|
runtime behavior 또는 production readiness를 뜻하지 않는다.
|
||||||
|
|
||||||
|
## 1. 현재 상태와 파일 지도
|
||||||
|
|
||||||
|
| 항목 | 경로 | production 포함 |
|
||||||
|
| --- | --- | --- |
|
||||||
|
| 선택/금지/예산 SSOT | `config/recipes/frontend-capability-recipes.json` | 정책만 |
|
||||||
|
| catalog JSON schema | `schemas/config/frontend-capability-recipes.schema.json` | 아니오 |
|
||||||
|
| TypeScript port | `recipes/frontend-capabilities/contracts.ts` | 아니오 |
|
||||||
|
| fake/unavailable | `recipes/frontend-capabilities/fake-adapters.ts` | 아니오 |
|
||||||
|
| contract test | `tests/recipes/optional-capability-contracts.test.ts` | 아니오 |
|
||||||
|
| 정적/번들 gate | `scripts/check-optional-recipes.mjs` | build 도구 |
|
||||||
|
| negative fixture | `scripts/check-optional-recipe-fixtures.mjs` | 아니오 |
|
||||||
|
| 완전 제거 gate | `scripts/test-optional-recipe-removal.mjs` | 아니오 |
|
||||||
|
|
||||||
|
현재 `productionRuntimeDependencies`는 빈 배열이며 12개 recipe 모두 선택되지
|
||||||
|
않았다. TypeScript example은 product source가 import할 library가 아니라 선택
|
||||||
|
시 복사하고 좁힐 출발점이다.
|
||||||
|
|
||||||
|
## 2. 어느 경계에 두는가
|
||||||
|
|
||||||
|
| capability 성격 | port 소유자 | adapter 방향 | concrete 위치 예 |
|
||||||
|
| --- | --- | --- | --- |
|
||||||
|
| application이 외부 결과를 요청 | application | outbound | `src/adapters/<capability>` |
|
||||||
|
| URL/browser event가 의도를 전달 | application input | inbound | `src/presentation/adapters` |
|
||||||
|
| React rendering behavior만 교체 | presentation | local facade | `src/presentation/<capability>` |
|
||||||
|
| feature 전용 protocol | feature application | in/out 분리 | `src/features/<name>/adapters` |
|
||||||
|
|
||||||
|
WebSocket 연결 생성, reconnect와 credential attachment는 outbound다. 수신 JSON
|
||||||
|
검증과 application input 호출은 inbound다. Service Worker update event,
|
||||||
|
BroadcastChannel event도 같은 원칙을 적용한다. generated DTO와 vendor SDK
|
||||||
|
type은 facade 밖으로 노출하지 않는다.
|
||||||
|
|
||||||
|
## 3. 12개 recipe 선택표
|
||||||
|
|
||||||
|
| recipe | 설치하는 경우 | 설치하면 안 되는 경우 | 핵심 fallback |
|
||||||
|
| --- | --- | --- | --- |
|
||||||
|
| realtime | ordered push/resume protocol이 확정됨 | polling이 충분하거나 ordering owner 없음 | bounded polling/stale UI |
|
||||||
|
| offline/IndexedDB | durable offline data/queue가 제품 요구 | credential 저장, DB 직접 연결, HTTP cache로 충분 | online-only + offline state |
|
||||||
|
| Service Worker/PWA | install/offline shell과 cache owner 승인 | update/rollback UX 없음 | hosting cache 기반 network app |
|
||||||
|
| file transfer | progress/cancel/size/type 정책 필요 | long-lived credential URL | bounded normal request |
|
||||||
|
| generated API | versioned source와 drift CI가 있음 | DTO가 domain/UI로 노출됨 | typed request builder + schema |
|
||||||
|
| feature flag | rollout/kill switch owner와 default 있음 | authorization에 사용 | typed local default |
|
||||||
|
| Web Worker | profiler가 main-thread 병목을 증명 | 단순 network I/O | chunked/deferred execution |
|
||||||
|
| multi-tab | 비민감 event 동기화가 필요 | server가 conflict authority | focus 시 authoritative refresh |
|
||||||
|
| browser permission | user gesture 기반 기능 필요 | boot 요청, denied UX 없음 | manual input/instruction |
|
||||||
|
| client workflow | cross-page client-only state가 실재 | query/server state 복제 | URL/local/context/query |
|
||||||
|
| large data UI | 실측 scale이 budget 초과 | pagination으로 충분, a11y 미정 | accessible pagination |
|
||||||
|
| analytics/error sink | provider·consent·retention 승인 | arbitrary payload/redaction 우회 | bounded local diagnostics |
|
||||||
|
|
||||||
|
정확한 failure matrix, security/privacy, gzip budget과 제거 순서는 JSON catalog가
|
||||||
|
SSOT다. 문서와 catalog가 다르면 gate가 검사하는 catalog를 우선 고치고 이 표도
|
||||||
|
같이 갱신한다.
|
||||||
|
|
||||||
|
## 4. 공통 구현 순서
|
||||||
|
|
||||||
|
1. 문제를 vendor 이름이 아닌 capability와 측정값으로 기록한다.
|
||||||
|
2. catalog의 trigger와 forbidden 조건을 모두 검토한다.
|
||||||
|
3. project owner, security/privacy reviewer, gzip budget과 재검토 날짜를 VD-10
|
||||||
|
amendment에 기록한다.
|
||||||
|
4. existing URL/local/context/query/application port로 해결되지 않는지 확인한다.
|
||||||
|
5. 필요한 contract만 `recipes`에서 해당 application/presentation 경계로 복사해
|
||||||
|
실제 payload와 failure union으로 좁힌다.
|
||||||
|
6. concrete SDK는 `src/adapters/...` 또는 local presentation facade adapter에서만
|
||||||
|
import한다.
|
||||||
|
7. composition root가 concrete adapter를 주입한다. page/use case가 constructor를
|
||||||
|
직접 호출하지 않는다.
|
||||||
|
8. fake, unavailable, timeout/cancel, cleanup, malformed input, redaction과
|
||||||
|
integration test를 작성한다.
|
||||||
|
9. runtime config schema, dependency inventory/approval, SBOM, bundle budget,
|
||||||
|
browser support와 runbook을 갱신한다.
|
||||||
|
10. 실제 provider integration과 negative behavior가 통과한 뒤에만 catalog 상태를
|
||||||
|
별도 project catalog에서 `INSTALLED`로 바꾼다.
|
||||||
|
|
||||||
|
## 5. capability별 필수 검증
|
||||||
|
|
||||||
|
### Realtime
|
||||||
|
|
||||||
|
- runtime schema로 envelope/version/event ID/sequence/timestamp를 검증한다.
|
||||||
|
- reconnect는 exponential backoff 상한, visibility/offline 상태, auth refresh와
|
||||||
|
resume token expiry를 정의한다.
|
||||||
|
- duplicate/out-of-order는 domain use case에 전달하기 전에 정책화한다.
|
||||||
|
- route unmount/logout에서 unsubscribe하고 heartbeat timer를 종료한다.
|
||||||
|
|
||||||
|
### Offline/Service Worker
|
||||||
|
|
||||||
|
- store/cache 이름과 schema는 release와 독립적인 migration version을 가진다.
|
||||||
|
- quota, corrupt row, partial migration, downgrade/rollback을 fixture로 만든다.
|
||||||
|
- authenticated response와 credential은 기본 cache 대상이 아니다.
|
||||||
|
- stale worker loop를 막고 unregister 후 owned cache 삭제가 가능한지 검증한다.
|
||||||
|
|
||||||
|
### File/generated API
|
||||||
|
|
||||||
|
- upload는 client MIME을 신뢰하지 않고 size/type/server rejection을 모두 다룬다.
|
||||||
|
- progress는 unknown total을 허용하며 navigation/unmount에서 AbortSignal로
|
||||||
|
취소한다.
|
||||||
|
- generated code는 facade 뒤 DTO이며 runtime response schema와 contract drift
|
||||||
|
gate를 유지한다.
|
||||||
|
|
||||||
|
### Flag/worker/multi-tab/browser
|
||||||
|
|
||||||
|
- flag unknown/unavailable/stale에서 명시적 typed fallback을 사용하고 access
|
||||||
|
control로 사용하지 않는다.
|
||||||
|
- worker는 task ID/generation/cancel을 사용해 stale result를 폐기하고 crash를
|
||||||
|
normalized failure로 바꾼다.
|
||||||
|
- multi-tab은 source/event/version으로 self-echo와 duplicate를 막고 payload를
|
||||||
|
비민감 invalidation hint로 제한한다.
|
||||||
|
- browser permission은 user gesture에서만 요청하고 denied/dismissed/unsupported를
|
||||||
|
서로 다른 UX 결과로 처리한다.
|
||||||
|
|
||||||
|
### Client workflow/large data/analytics
|
||||||
|
|
||||||
|
- workflow store는 server entity/collection을 복제하지 않고 query key나 ID 참조만
|
||||||
|
보관한다. logout/reset/version mismatch 정책을 테스트한다.
|
||||||
|
- virtualization은 profiler와 production-like row count로 정당화하며 keyboard,
|
||||||
|
focus restoration, screen reader와 stale row identity를 검증한다.
|
||||||
|
- analytics는 essential diagnostics와 consent-required event를 분리하고 closed
|
||||||
|
event/attribute registry, pre-queue redaction, sampling, bounded queue와
|
||||||
|
retention을 적용한다.
|
||||||
|
|
||||||
|
## 6. 검증 명령
|
||||||
|
|
||||||
|
```bash
|
||||||
|
corepack pnpm check:types:recipes
|
||||||
|
corepack pnpm test:recipes
|
||||||
|
corepack pnpm build
|
||||||
|
corepack pnpm check:optional-recipes
|
||||||
|
corepack pnpm check:optional-recipe-fixtures
|
||||||
|
corepack pnpm test:optional-recipe-removal
|
||||||
|
```
|
||||||
|
|
||||||
|
negative gate는 cleanup 누락, unselected dependency, local adapter 밖 vendor
|
||||||
|
import, credential localStorage/URL/telemetry 경로, workflow store의 server-state
|
||||||
|
복제와 production source의 recipe import를 거절한다. removal gate는 recipe와
|
||||||
|
recipe test를 삭제한 임시 사본에서 base typecheck, architecture, test와 build를
|
||||||
|
실행한다.
|
||||||
|
|
||||||
|
## 7. 제거 체크리스트
|
||||||
|
|
||||||
|
1. 신규 호출과 background 작업을 중지한다.
|
||||||
|
2. subscription, worker, channel, media track, observer를 cleanup한다.
|
||||||
|
3. persisted store/cache/event queue의 migrate 또는 purge 정책을 실행한다.
|
||||||
|
4. composition registration과 runtime config를 제거한다.
|
||||||
|
5. concrete adapter, facade/port와 vendor dependency를 제거한다.
|
||||||
|
6. dependency baseline, SBOM과 bundle baseline을 갱신한다.
|
||||||
|
7. typecheck/test/build, production bundle absence와 도메인 기능 fallback을
|
||||||
|
검증한다.
|
||||||
|
|
||||||
|
provider 장애 시 fake로 바꾸어 production을 PASS 처리하지 않는다. 문서화된
|
||||||
|
unavailable fallback만 사용하고 provider가 필수인 promotion은
|
||||||
|
`FAIL_UNVERIFIED` 또는 blocked 상태로 유지한다.
|
||||||
@@ -179,6 +179,11 @@ export type AppFailure =
|
|||||||
|
|
||||||
vendor를 선택하더라도 feature 외부에는 hook/facade만 export한다. 제품 코드가
|
vendor를 선택하더라도 feature 외부에는 hook/facade만 export한다. 제품 코드가
|
||||||
store instance의 `getState`와 `setState`를 임의 호출하지 않게 한다.
|
store instance의 `getState`와 `setState`를 임의 호출하지 않게 한다.
|
||||||
|
현재 `recipes/frontend-capabilities`의 `ClientWorkflowPort`와
|
||||||
|
`FakeClientWorkflowAdapter`가 vendor-neutral opt-in 예제를 제공한다. 기본
|
||||||
|
production에는 Zustand/Redux Toolkit/state-machine dependency가 없고,
|
||||||
|
`check:optional-recipe-fixtures`가 server response collection을 client workflow
|
||||||
|
store에 복제하는 패턴을 거절한다.
|
||||||
|
|
||||||
### 3.3 persistence
|
### 3.3 persistence
|
||||||
|
|
||||||
|
|||||||
@@ -1,18 +1,47 @@
|
|||||||
# Build and supply-chain gate
|
# Build and supply-chain gate
|
||||||
|
|
||||||
Merge and release controls:
|
## Local blocking controls
|
||||||
|
|
||||||
- frozen `pnpm-lock.yaml` installation; drift is blocking
|
- `pnpm install --frozen-lockfile` and a real manifest/lock mismatch fixture
|
||||||
- clean production build with hashed assets and build manifest
|
- all direct and transitive lockfile rows with package SHA-512 integrity
|
||||||
- machine-readable bundle sizes and checksums
|
- production/development, direct/transitive and platform-optional classification
|
||||||
- source plus built-asset credential-pattern scan
|
- package-manifest license allow/deny policy
|
||||||
- direct dependency inventory and lockfile digest
|
- approved inventory baseline digest and actual add/remove/change/upgrade diff
|
||||||
- base/head dependency diff review record
|
- independent review for new direct production dependencies
|
||||||
|
- CycloneDX 1.6 SBOM and inventory component/edge coherence
|
||||||
|
- source/lock/SBOM/dist-linked local provenance statement
|
||||||
|
- source, opt-in recipes, scripts, tests, tracked config/schema, public, built asset and generated
|
||||||
|
release metadata secret scan
|
||||||
|
- two-build `SOURCE_DATE_EPOCH` reproducibility check
|
||||||
|
|
||||||
Organization-specific vulnerability severity, denied-license list, SBOM format,
|
The canonical commands are:
|
||||||
and scanner selection remain policy inputs. An approved suppression must record
|
|
||||||
reason, owner, expiry, affected package, and compensating control. Expired
|
|
||||||
suppressions are blocking.
|
|
||||||
|
|
||||||
`artifacts/security/dependency-diff.json` is a local baseline. CI replaces it
|
```bash
|
||||||
with the actual base/head direct and transitive lockfile diff before release.
|
corepack pnpm verify:lockfile
|
||||||
|
corepack pnpm verify:reproducible-build
|
||||||
|
corepack pnpm build:release
|
||||||
|
corepack pnpm verify:supply-chain
|
||||||
|
corepack pnpm check:supply-chain:fixtures
|
||||||
|
```
|
||||||
|
|
||||||
|
`config/security/dependency-baseline.json` is the approved local baseline.
|
||||||
|
Changing it requires `DEPENDENCY_BASELINE_OWNER` and
|
||||||
|
`DEPENDENCY_BASELINE_REASON`; editing the digest or hardcoding an empty diff is
|
||||||
|
rejected.
|
||||||
|
|
||||||
|
## External promotion controls
|
||||||
|
|
||||||
|
The vulnerability adapter reads the file named by
|
||||||
|
`VULNERABILITY_REPORT_PATH`. It requires a provider, the exact lockfile digest,
|
||||||
|
severity findings and valid independent, unexpired exception evidence.
|
||||||
|
`PROVENANCE_ATTESTATION_PATH` must name a provider, signer and the exact built
|
||||||
|
dist subject digest.
|
||||||
|
|
||||||
|
If either provider input is absent, local verification remains meaningful but
|
||||||
|
`artifacts/security/supply-chain-verification.json` records
|
||||||
|
`promotionStatus: FAIL_UNVERIFIED`. `verify:supply-chain:promotion` then exits
|
||||||
|
non-zero. Scanner or signing outages are not converted to an empty PASS.
|
||||||
|
|
||||||
|
Approved vulnerability exceptions require vulnerability/package identity,
|
||||||
|
owner, a different reviewer, reason and expiry. Expired or self-approved
|
||||||
|
exceptions are blocking.
|
||||||
|
|||||||
@@ -1299,6 +1299,16 @@ TypeScript test, Storybook, coverage, visual과 built-dist 명령은
|
|||||||
- flaky test를 owner/만료일 없이 skip
|
- flaky test를 owner/만료일 없이 skip
|
||||||
- CI gate에 `continue-on-error`
|
- CI gate에 `continue-on-error`
|
||||||
|
|
||||||
|
### 선택형 adapter recipe gate
|
||||||
|
|
||||||
|
선택형 capability example은 `tests/recipes`에서 contract/fake/unavailable을
|
||||||
|
실행하지만 production entry에는 포함하지 않는다. `check:optional-recipes`는
|
||||||
|
12개 catalog 완전성, unselected dependency, production source import와 built
|
||||||
|
bundle sentinel 부재를 검사한다. negative fixture는 lifecycle cleanup 누락,
|
||||||
|
vendor direct import, credential storage/URL/telemetry 경로와 workflow store의
|
||||||
|
server-state 복제를 거절한다. `test:optional-recipe-removal`은 recipe 전체를
|
||||||
|
제거한 사본에서 base typecheck/test/build를 다시 실행한다.
|
||||||
|
|
||||||
## 20. 단계별 도입 순서
|
## 20. 단계별 도입 순서
|
||||||
|
|
||||||
1. `tsconfig.test.json`과 test typecheck gate를 추가한다.
|
1. `tsconfig.test.json`과 test typecheck gate를 추가한다.
|
||||||
|
|||||||
@@ -79,6 +79,7 @@ export default [
|
|||||||
"tests/fixtures/diagnostics/forbidden/**",
|
"tests/fixtures/diagnostics/forbidden/**",
|
||||||
"tests/fixtures/i18n/forbidden/**",
|
"tests/fixtures/i18n/forbidden/**",
|
||||||
"tests/fixtures/security/forbidden/**",
|
"tests/fixtures/security/forbidden/**",
|
||||||
|
"tests/fixtures/optional-recipes/**",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
eslint.configs.recommended,
|
eslint.configs.recommended,
|
||||||
|
|||||||
+16
-2
@@ -13,7 +13,7 @@
|
|||||||
"build": "vite build && node scripts/generate-build-manifest.mjs",
|
"build": "vite build && node scripts/generate-build-manifest.mjs",
|
||||||
"build:release": "corepack pnpm build && corepack pnpm generate:supply-chain && corepack pnpm scan:security",
|
"build:release": "corepack pnpm build && corepack pnpm generate:supply-chain && corepack pnpm scan:security",
|
||||||
"preview": "vite preview",
|
"preview": "vite preview",
|
||||||
"lint": "eslint src scripts tests .storybook vite.config.js vitest.config.js playwright*.config.js --max-warnings=0",
|
"lint": "eslint src scripts tests recipes .storybook vite.config.js vitest.config.js playwright*.config.js --max-warnings=0",
|
||||||
"check:architecture": "node scripts/check-architecture.mjs",
|
"check:architecture": "node scripts/check-architecture.mjs",
|
||||||
"check:design-system": "node scripts/check-design-system.mjs",
|
"check:design-system": "node scripts/check-design-system.mjs",
|
||||||
"check:design-system:fixture": "node scripts/check-design-system.mjs --fixture",
|
"check:design-system:fixture": "node scripts/check-design-system.mjs --fixture",
|
||||||
@@ -25,6 +25,7 @@
|
|||||||
"check:types:app": "tsc --project tsconfig.app.json",
|
"check:types:app": "tsc --project tsconfig.app.json",
|
||||||
"check:types:node": "tsc --project tsconfig.node.json",
|
"check:types:node": "tsc --project tsconfig.node.json",
|
||||||
"check:types:test": "tsc --project tsconfig.test.json",
|
"check:types:test": "tsc --project tsconfig.test.json",
|
||||||
|
"check:types:recipes": "tsc --project tsconfig.recipes.json",
|
||||||
"check:types:fixture": "tsc --ignoreConfig --allowJs --checkJs --noEmit --target ES2022 --module NodeNext --moduleResolution NodeNext tests/fixtures/typecheck/invalid-port-call.js",
|
"check:types:fixture": "tsc --ignoreConfig --allowJs --checkJs --noEmit --target ES2022 --module NodeNext --moduleResolution NodeNext tests/fixtures/typecheck/invalid-port-call.js",
|
||||||
"check:types:fixture:ts-port": "tsc --ignoreConfig --strict --noEmit --target ES2022 --module ESNext --moduleResolution Bundler tests/fixtures/typecheck/invalid-port-implementation.ts",
|
"check:types:fixture:ts-port": "tsc --ignoreConfig --strict --noEmit --target ES2022 --module ESNext --moduleResolution Bundler tests/fixtures/typecheck/invalid-port-implementation.ts",
|
||||||
"check:types:fixture:ts-result": "tsc --ignoreConfig --strict --noEmit --target ES2022 --module ESNext --moduleResolution Bundler tests/fixtures/typecheck/invalid-result-narrowing.ts",
|
"check:types:fixture:ts-result": "tsc --ignoreConfig --strict --noEmit --target ES2022 --module ESNext --moduleResolution Bundler tests/fixtures/typecheck/invalid-result-narrowing.ts",
|
||||||
@@ -41,6 +42,7 @@
|
|||||||
"test:unit": "vitest run tests/unit --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/unit.xml",
|
"test:unit": "vitest run tests/unit --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/unit.xml",
|
||||||
"test:component": "vitest run tests/component --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/component.xml",
|
"test:component": "vitest run tests/component --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/component.xml",
|
||||||
"test:integration": "vitest run tests/integration --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/integration.xml",
|
"test:integration": "vitest run tests/integration --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/integration.xml",
|
||||||
|
"test:recipes": "vitest run tests/recipes --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/optional-recipes.xml --passWithNoTests",
|
||||||
"test:e2e": "playwright test",
|
"test:e2e": "playwright test",
|
||||||
"test:e2e:dev": "playwright test --config playwright.dev.config.js",
|
"test:e2e:dev": "playwright test --config playwright.dev.config.js",
|
||||||
"storybook": "storybook dev -p 6006",
|
"storybook": "storybook dev -p 6006",
|
||||||
@@ -53,14 +55,26 @@
|
|||||||
"test:a11y": "playwright test --grep @a11y && node scripts/write-a11y-report.mjs",
|
"test:a11y": "playwright test --grep @a11y && node scripts/write-a11y-report.mjs",
|
||||||
"review:a11y-manual": "node scripts/verify-a11y-manual.mjs",
|
"review:a11y-manual": "node scripts/verify-a11y-manual.mjs",
|
||||||
"test:sample-removal": "node scripts/test-sample-removal.mjs",
|
"test:sample-removal": "node scripts/test-sample-removal.mjs",
|
||||||
|
"test:optional-recipe-removal": "node scripts/test-optional-recipe-removal.mjs",
|
||||||
"test:reference-feature": "vitest run tests/features/reference-feature --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/reference-feature.xml --passWithNoTests",
|
"test:reference-feature": "vitest run tests/features/reference-feature --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/reference-feature.xml --passWithNoTests",
|
||||||
"test:coverage": "vitest run tests/runtime-schema tests/unit tests/component tests/integration tests/features/reference-feature --coverage --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/coverage.xml && node scripts/check-risk-coverage.mjs",
|
"test:coverage": "vitest run tests/runtime-schema tests/unit tests/component tests/integration tests/features/reference-feature --coverage --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/coverage.xml && node scripts/check-risk-coverage.mjs",
|
||||||
"check:coverage:fixture": "node scripts/check-risk-coverage.mjs --summary tests/fixtures/coverage/below-threshold.json --artifact artifacts/quality/risk-coverage-fixture.json",
|
"check:coverage:fixture": "node scripts/check-risk-coverage.mjs --summary tests/fixtures/coverage/below-threshold.json --artifact artifacts/quality/risk-coverage-fixture.json",
|
||||||
"test:all": "corepack pnpm test:runtime-schema && corepack pnpm test:unit && corepack pnpm test:component && corepack pnpm test:integration && corepack pnpm test:reference-feature",
|
"test:all": "corepack pnpm test:runtime-schema && corepack pnpm test:unit && corepack pnpm test:component && corepack pnpm test:integration && corepack pnpm test:reference-feature && corepack pnpm test:recipes",
|
||||||
"verify:lockfile": "corepack pnpm install --frozen-lockfile",
|
"verify:lockfile": "corepack pnpm install --frozen-lockfile",
|
||||||
|
"check:frozen-lockfile:fixture": "node scripts/check-frozen-lockfile-fixture.mjs",
|
||||||
"generate:supply-chain": "node scripts/generate-supply-chain.mjs",
|
"generate:supply-chain": "node scripts/generate-supply-chain.mjs",
|
||||||
|
"verify:supply-chain": "node scripts/verify-supply-chain-artifacts.mjs",
|
||||||
|
"update:dependency-baseline": "node scripts/update-dependency-baseline.mjs",
|
||||||
|
"check:supply-chain:fixtures": "node scripts/check-supply-chain-fixtures.mjs",
|
||||||
|
"check:supply-chain:provider-fixtures": "node scripts/check-supply-chain-provider-fixtures.mjs",
|
||||||
|
"verify:supply-chain:promotion": "node scripts/verify-supply-chain-promotion.mjs",
|
||||||
|
"verify:reproducible-build": "node scripts/verify-reproducible-build.mjs",
|
||||||
"scan:security": "node scripts/security-scan.mjs",
|
"scan:security": "node scripts/security-scan.mjs",
|
||||||
|
"scan:security:fixture": "node scripts/security-scan.mjs --policy tests/fixtures/security/secret-detection/forbidden-policy.json --artifact artifacts/security/scan-fixture.sarif",
|
||||||
"check:browser-security": "node scripts/check-browser-security.mjs",
|
"check:browser-security": "node scripts/check-browser-security.mjs",
|
||||||
|
"check:optional-recipes": "node scripts/check-optional-recipes.mjs --require-dist",
|
||||||
|
"check:optional-recipes:source": "node scripts/check-optional-recipes.mjs",
|
||||||
|
"check:optional-recipe-fixtures": "node scripts/check-optional-recipe-fixtures.mjs",
|
||||||
"check:registries": "node scripts/check-registries.mjs",
|
"check:registries": "node scripts/check-registries.mjs",
|
||||||
"check:registries:structure": "node scripts/check-registries.mjs --no-baseline",
|
"check:registries:structure": "node scripts/check-registries.mjs --no-baseline",
|
||||||
"check:registries:compatibility-fixtures": "node scripts/check-registry-compatibility-fixtures.mjs",
|
"check:registries:compatibility-fixtures": "node scripts/check-registry-compatibility-fixtures.mjs",
|
||||||
|
|||||||
@@ -0,0 +1,207 @@
|
|||||||
|
/**
|
||||||
|
* Opt-in capability contracts.
|
||||||
|
*
|
||||||
|
* This directory is a copyable recipe source, not a production entry. A project
|
||||||
|
* moves only the selected contract into its application-owned boundary and puts
|
||||||
|
* a concrete implementation behind that port.
|
||||||
|
*/
|
||||||
|
export const OPTIONAL_RECIPE_RUNTIME_SENTINEL =
|
||||||
|
"frontend-optional-recipe-must-not-reach-production";
|
||||||
|
|
||||||
|
export type CapabilityFailureCode =
|
||||||
|
| "ABORTED"
|
||||||
|
| "AUTH_EXPIRED"
|
||||||
|
| "CONFLICT"
|
||||||
|
| "CONSENT_DENIED"
|
||||||
|
| "CONTRACT_DRIFT"
|
||||||
|
| "CORRUPT_DATA"
|
||||||
|
| "DISCONNECTED"
|
||||||
|
| "EXPIRED_RESOURCE"
|
||||||
|
| "INVALID_INPUT"
|
||||||
|
| "LIMIT_EXCEEDED"
|
||||||
|
| "MIGRATION_FAILED"
|
||||||
|
| "NOT_FOUND"
|
||||||
|
| "PROVIDER_UNAVAILABLE"
|
||||||
|
| "QUOTA_EXCEEDED"
|
||||||
|
| "STALE_RESULT"
|
||||||
|
| "UNSUPPORTED";
|
||||||
|
|
||||||
|
export type CapabilityFailure = Readonly<{
|
||||||
|
code: CapabilityFailureCode;
|
||||||
|
retryable: boolean;
|
||||||
|
safeMessage: string;
|
||||||
|
}>;
|
||||||
|
|
||||||
|
export type CapabilityResult<T> =
|
||||||
|
| Readonly<{ ok: true; value: T }>
|
||||||
|
| Readonly<{ ok: false; failure: CapabilityFailure }>;
|
||||||
|
|
||||||
|
export type Cleanup = () => void;
|
||||||
|
|
||||||
|
export type RealtimeEvent<T> = Readonly<{
|
||||||
|
id: string;
|
||||||
|
sequence: number;
|
||||||
|
occurredAt: string;
|
||||||
|
payload: T;
|
||||||
|
}>;
|
||||||
|
|
||||||
|
export interface RealtimeSubscription {
|
||||||
|
readonly resumeToken: string | null;
|
||||||
|
unsubscribe(): void;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface RealtimePort<T> {
|
||||||
|
subscribe(input: {
|
||||||
|
channel: string;
|
||||||
|
resumeToken?: string;
|
||||||
|
signal?: AbortSignal;
|
||||||
|
onEvent(event: CapabilityResult<RealtimeEvent<T>>): void;
|
||||||
|
}): Promise<CapabilityResult<RealtimeSubscription>>;
|
||||||
|
heartbeat(signal?: AbortSignal): Promise<CapabilityResult<void>>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface VersionedOfflineRepository<T extends { id: string }> {
|
||||||
|
open(input: {
|
||||||
|
schemaVersion: number;
|
||||||
|
signal?: AbortSignal;
|
||||||
|
}): Promise<CapabilityResult<void>>;
|
||||||
|
get(id: string, signal?: AbortSignal): Promise<CapabilityResult<T | null>>;
|
||||||
|
put(value: T, signal?: AbortSignal): Promise<CapabilityResult<void>>;
|
||||||
|
migrate(input: {
|
||||||
|
from: number;
|
||||||
|
to: number;
|
||||||
|
signal?: AbortSignal;
|
||||||
|
}): Promise<CapabilityResult<void>>;
|
||||||
|
close(): void;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface ServiceWorkerUpdatePort {
|
||||||
|
inspect(signal?: AbortSignal): Promise<
|
||||||
|
CapabilityResult<Readonly<{ updateAvailable: boolean; version: string | null }>>
|
||||||
|
>;
|
||||||
|
activate(version: string, signal?: AbortSignal): Promise<CapabilityResult<void>>;
|
||||||
|
rollback(signal?: AbortSignal): Promise<CapabilityResult<void>>;
|
||||||
|
unregister(): Promise<CapabilityResult<void>>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export type TransferProgress = Readonly<{
|
||||||
|
transferredBytes: number;
|
||||||
|
totalBytes: number | null;
|
||||||
|
}>;
|
||||||
|
|
||||||
|
export interface FileTransferPort {
|
||||||
|
upload(input: {
|
||||||
|
file: Readonly<{ name: string; size: number; type: string }>;
|
||||||
|
signal: AbortSignal;
|
||||||
|
onProgress(progress: TransferProgress): void;
|
||||||
|
}): Promise<CapabilityResult<Readonly<{ resourceId: string }>>>;
|
||||||
|
download(input: {
|
||||||
|
resourceId: string;
|
||||||
|
signal: AbortSignal;
|
||||||
|
onProgress(progress: TransferProgress): void;
|
||||||
|
}): Promise<CapabilityResult<Uint8Array>>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface GeneratedApiFacade {
|
||||||
|
execute<TOutput>(input: {
|
||||||
|
operationId: string;
|
||||||
|
contractVersion: string;
|
||||||
|
body?: unknown;
|
||||||
|
signal?: AbortSignal;
|
||||||
|
}): Promise<CapabilityResult<TOutput>>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface FeatureFlagPort<TFlags extends Record<string, boolean | string | number>> {
|
||||||
|
evaluate<TKey extends keyof TFlags>(input: {
|
||||||
|
key: TKey;
|
||||||
|
fallback: TFlags[TKey];
|
||||||
|
maxAgeMs: number;
|
||||||
|
}): Promise<CapabilityResult<TFlags[TKey]>>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface WorkerTaskPort<TInput, TOutput> {
|
||||||
|
run(input: {
|
||||||
|
taskId: string;
|
||||||
|
generation: number;
|
||||||
|
payload: TInput;
|
||||||
|
signal: AbortSignal;
|
||||||
|
}): Promise<CapabilityResult<TOutput>>;
|
||||||
|
cancel(taskId: string): void;
|
||||||
|
dispose(): void;
|
||||||
|
}
|
||||||
|
|
||||||
|
export type MultiTabEvent<T> = Readonly<{
|
||||||
|
eventId: string;
|
||||||
|
sourceId: string;
|
||||||
|
version: number;
|
||||||
|
payload: T;
|
||||||
|
}>;
|
||||||
|
|
||||||
|
export interface MultiTabPort<T> {
|
||||||
|
publish(event: MultiTabEvent<T>): CapabilityResult<void>;
|
||||||
|
subscribe(input: {
|
||||||
|
sourceId: string;
|
||||||
|
onEvent(event: CapabilityResult<MultiTabEvent<T>>): void;
|
||||||
|
}): Cleanup;
|
||||||
|
close(): void;
|
||||||
|
}
|
||||||
|
|
||||||
|
export type BrowserCapability =
|
||||||
|
| "clipboard-read"
|
||||||
|
| "clipboard-write"
|
||||||
|
| "media"
|
||||||
|
| "notification";
|
||||||
|
|
||||||
|
export type PermissionDecision = "granted" | "denied" | "dismissed";
|
||||||
|
|
||||||
|
export interface BrowserPermissionPort {
|
||||||
|
request(input: {
|
||||||
|
capability: BrowserCapability;
|
||||||
|
signal?: AbortSignal;
|
||||||
|
}): Promise<CapabilityResult<PermissionDecision>>;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface ClientWorkflowPort<TState, TEvent> {
|
||||||
|
snapshot(): Readonly<TState>;
|
||||||
|
dispatch(event: TEvent): CapabilityResult<Readonly<TState>>;
|
||||||
|
reset(): void;
|
||||||
|
subscribe(listener: (state: Readonly<TState>) => void): Cleanup;
|
||||||
|
}
|
||||||
|
|
||||||
|
export interface LargeDataUiFacade<TRow extends { id: string }> {
|
||||||
|
window(input: {
|
||||||
|
offset: number;
|
||||||
|
limit: number;
|
||||||
|
generation: number;
|
||||||
|
}): CapabilityResult<ReadonlyArray<TRow>>;
|
||||||
|
focus(rowId: string): CapabilityResult<void>;
|
||||||
|
replace(rows: ReadonlyArray<TRow>, generation: number): void;
|
||||||
|
}
|
||||||
|
|
||||||
|
export type SafeAnalyticsValue = boolean | number | string | null;
|
||||||
|
|
||||||
|
export interface AnalyticsErrorSink {
|
||||||
|
record(input: {
|
||||||
|
kind: "analytics" | "error";
|
||||||
|
eventId: string;
|
||||||
|
consent: "granted" | "denied" | "not-required";
|
||||||
|
attributes: Readonly<Record<string, SafeAnalyticsValue>>;
|
||||||
|
}): CapabilityResult<void>;
|
||||||
|
flush(signal?: AbortSignal): Promise<CapabilityResult<void>>;
|
||||||
|
dispose(): void;
|
||||||
|
}
|
||||||
|
|
||||||
|
export type OptionalCapabilityPorts = Readonly<{
|
||||||
|
realtime: RealtimePort<unknown>;
|
||||||
|
offline: VersionedOfflineRepository<{ id: string }>;
|
||||||
|
serviceWorker: ServiceWorkerUpdatePort;
|
||||||
|
fileTransfer: FileTransferPort;
|
||||||
|
generatedApi: GeneratedApiFacade;
|
||||||
|
featureFlag: FeatureFlagPort<Record<string, boolean | string | number>>;
|
||||||
|
worker: WorkerTaskPort<unknown, unknown>;
|
||||||
|
multiTab: MultiTabPort<unknown>;
|
||||||
|
browserPermission: BrowserPermissionPort;
|
||||||
|
clientWorkflow: ClientWorkflowPort<unknown, unknown>;
|
||||||
|
largeDataUi: LargeDataUiFacade<{ id: string }>;
|
||||||
|
analytics: AnalyticsErrorSink;
|
||||||
|
}>;
|
||||||
@@ -0,0 +1,542 @@
|
|||||||
|
import type {
|
||||||
|
AnalyticsErrorSink,
|
||||||
|
BrowserCapability,
|
||||||
|
BrowserPermissionPort,
|
||||||
|
CapabilityFailure,
|
||||||
|
CapabilityResult,
|
||||||
|
ClientWorkflowPort,
|
||||||
|
FeatureFlagPort,
|
||||||
|
FileTransferPort,
|
||||||
|
GeneratedApiFacade,
|
||||||
|
LargeDataUiFacade,
|
||||||
|
MultiTabEvent,
|
||||||
|
MultiTabPort,
|
||||||
|
OptionalCapabilityPorts,
|
||||||
|
PermissionDecision,
|
||||||
|
RealtimeEvent,
|
||||||
|
RealtimePort,
|
||||||
|
RealtimeSubscription,
|
||||||
|
SafeAnalyticsValue,
|
||||||
|
ServiceWorkerUpdatePort,
|
||||||
|
VersionedOfflineRepository,
|
||||||
|
WorkerTaskPort,
|
||||||
|
} from "./contracts.js";
|
||||||
|
|
||||||
|
export function success<T>(value: T): CapabilityResult<T> {
|
||||||
|
return Object.freeze({ ok: true, value });
|
||||||
|
}
|
||||||
|
|
||||||
|
export function failure(
|
||||||
|
code: CapabilityFailure["code"],
|
||||||
|
retryable = false,
|
||||||
|
safeMessage = "Optional capability is unavailable.",
|
||||||
|
): CapabilityResult<never> {
|
||||||
|
return Object.freeze({
|
||||||
|
ok: false,
|
||||||
|
failure: Object.freeze({ code, retryable, safeMessage }),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
function aborted(signal?: AbortSignal): CapabilityResult<never> | null {
|
||||||
|
return signal?.aborted
|
||||||
|
? failure("ABORTED", false, "The operation was cancelled.")
|
||||||
|
: null;
|
||||||
|
}
|
||||||
|
|
||||||
|
export class FakeRealtimeAdapter<T> implements RealtimePort<T> {
|
||||||
|
readonly #subscriptions = new Map<
|
||||||
|
string,
|
||||||
|
{
|
||||||
|
lastSequence: number;
|
||||||
|
onEvent(event: CapabilityResult<RealtimeEvent<T>>): void;
|
||||||
|
}
|
||||||
|
>();
|
||||||
|
|
||||||
|
async subscribe(input: {
|
||||||
|
channel: string;
|
||||||
|
resumeToken?: string;
|
||||||
|
signal?: AbortSignal;
|
||||||
|
onEvent(event: CapabilityResult<RealtimeEvent<T>>): void;
|
||||||
|
}): Promise<CapabilityResult<RealtimeSubscription>> {
|
||||||
|
const cancelled = aborted(input.signal);
|
||||||
|
if (cancelled) return cancelled;
|
||||||
|
const key = `${input.channel}:${this.#subscriptions.size + 1}`;
|
||||||
|
this.#subscriptions.set(key, { lastSequence: -1, onEvent: input.onEvent });
|
||||||
|
const unsubscribe = () => this.#subscriptions.delete(key);
|
||||||
|
input.signal?.addEventListener("abort", unsubscribe, { once: true });
|
||||||
|
return success(
|
||||||
|
Object.freeze({
|
||||||
|
resumeToken: input.resumeToken ?? null,
|
||||||
|
unsubscribe,
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
async heartbeat(signal?: AbortSignal): Promise<CapabilityResult<void>> {
|
||||||
|
return aborted(signal) ?? success(undefined);
|
||||||
|
}
|
||||||
|
|
||||||
|
emit(channel: string, event: RealtimeEvent<T>): void {
|
||||||
|
for (const [key, subscription] of this.#subscriptions) {
|
||||||
|
if (!key.startsWith(`${channel}:`)) continue;
|
||||||
|
if (event.sequence <= subscription.lastSequence) {
|
||||||
|
subscription.onEvent(
|
||||||
|
failure(
|
||||||
|
"STALE_RESULT",
|
||||||
|
false,
|
||||||
|
"A duplicate or out-of-order event was ignored.",
|
||||||
|
),
|
||||||
|
);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
subscription.lastSequence = event.sequence;
|
||||||
|
subscription.onEvent(success(event));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
get activeSubscriptionCount(): number {
|
||||||
|
return this.#subscriptions.size;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class MemoryOfflineRepository<T extends { id: string }>
|
||||||
|
implements VersionedOfflineRepository<T>
|
||||||
|
{
|
||||||
|
readonly #records = new Map<string, T>();
|
||||||
|
#openVersion: number | null = null;
|
||||||
|
|
||||||
|
async open(input: {
|
||||||
|
schemaVersion: number;
|
||||||
|
signal?: AbortSignal;
|
||||||
|
}): Promise<CapabilityResult<void>> {
|
||||||
|
const cancelled = aborted(input.signal);
|
||||||
|
if (cancelled) return cancelled;
|
||||||
|
if (!Number.isInteger(input.schemaVersion) || input.schemaVersion < 1) {
|
||||||
|
return failure("CORRUPT_DATA", false, "Invalid offline schema version.");
|
||||||
|
}
|
||||||
|
this.#openVersion = input.schemaVersion;
|
||||||
|
return success(undefined);
|
||||||
|
}
|
||||||
|
|
||||||
|
async get(id: string, signal?: AbortSignal): Promise<CapabilityResult<T | null>> {
|
||||||
|
const cancelled = aborted(signal);
|
||||||
|
if (cancelled) return cancelled;
|
||||||
|
if (this.#openVersion === null) {
|
||||||
|
return failure("PROVIDER_UNAVAILABLE", false, "Repository is closed.");
|
||||||
|
}
|
||||||
|
return success(this.#records.get(id) ?? null);
|
||||||
|
}
|
||||||
|
|
||||||
|
async put(value: T, signal?: AbortSignal): Promise<CapabilityResult<void>> {
|
||||||
|
const cancelled = aborted(signal);
|
||||||
|
if (cancelled) return cancelled;
|
||||||
|
if (this.#openVersion === null) {
|
||||||
|
return failure("PROVIDER_UNAVAILABLE", false, "Repository is closed.");
|
||||||
|
}
|
||||||
|
this.#records.set(value.id, structuredClone(value));
|
||||||
|
return success(undefined);
|
||||||
|
}
|
||||||
|
|
||||||
|
async migrate(input: {
|
||||||
|
from: number;
|
||||||
|
to: number;
|
||||||
|
signal?: AbortSignal;
|
||||||
|
}): Promise<CapabilityResult<void>> {
|
||||||
|
const cancelled = aborted(input.signal);
|
||||||
|
if (cancelled) return cancelled;
|
||||||
|
if (this.#openVersion !== input.from || input.to <= input.from) {
|
||||||
|
return failure("MIGRATION_FAILED", false, "Offline migration was rejected.");
|
||||||
|
}
|
||||||
|
this.#openVersion = input.to;
|
||||||
|
return success(undefined);
|
||||||
|
}
|
||||||
|
|
||||||
|
close(): void {
|
||||||
|
this.#openVersion = null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class FakeServiceWorkerUpdateAdapter implements ServiceWorkerUpdatePort {
|
||||||
|
#activeVersion: string | null;
|
||||||
|
#candidateVersion: string | null;
|
||||||
|
|
||||||
|
constructor(activeVersion: string | null, candidateVersion: string | null) {
|
||||||
|
this.#activeVersion = activeVersion;
|
||||||
|
this.#candidateVersion = candidateVersion;
|
||||||
|
}
|
||||||
|
|
||||||
|
async inspect(signal?: AbortSignal) {
|
||||||
|
return (
|
||||||
|
aborted(signal) ??
|
||||||
|
success({
|
||||||
|
updateAvailable: this.#candidateVersion !== null,
|
||||||
|
version: this.#candidateVersion,
|
||||||
|
})
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
async activate(version: string, signal?: AbortSignal) {
|
||||||
|
const cancelled = aborted(signal);
|
||||||
|
if (cancelled) return cancelled;
|
||||||
|
if (version !== this.#candidateVersion) {
|
||||||
|
return failure("STALE_RESULT", false, "Worker update is no longer current.");
|
||||||
|
}
|
||||||
|
this.#activeVersion = version;
|
||||||
|
this.#candidateVersion = null;
|
||||||
|
return success(undefined);
|
||||||
|
}
|
||||||
|
|
||||||
|
async rollback(signal?: AbortSignal) {
|
||||||
|
const cancelled = aborted(signal);
|
||||||
|
if (cancelled) return cancelled;
|
||||||
|
if (!this.#activeVersion) {
|
||||||
|
return failure("NOT_FOUND", false, "No active worker can be rolled back.");
|
||||||
|
}
|
||||||
|
this.#activeVersion = null;
|
||||||
|
return success(undefined);
|
||||||
|
}
|
||||||
|
|
||||||
|
async unregister() {
|
||||||
|
this.#activeVersion = null;
|
||||||
|
this.#candidateVersion = null;
|
||||||
|
return success(undefined);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class FakeFileTransferAdapter implements FileTransferPort {
|
||||||
|
constructor(
|
||||||
|
private readonly maxBytes = 5_000_000,
|
||||||
|
private readonly acceptedTypes: ReadonlySet<string> = new Set([
|
||||||
|
"application/pdf",
|
||||||
|
"image/png",
|
||||||
|
]),
|
||||||
|
) {}
|
||||||
|
|
||||||
|
async upload(input: Parameters<FileTransferPort["upload"]>[0]) {
|
||||||
|
const cancelled = aborted(input.signal);
|
||||||
|
if (cancelled) return cancelled;
|
||||||
|
if (
|
||||||
|
input.file.size > this.maxBytes ||
|
||||||
|
!this.acceptedTypes.has(input.file.type)
|
||||||
|
) {
|
||||||
|
return failure("LIMIT_EXCEEDED", false, "File size or type is not allowed.");
|
||||||
|
}
|
||||||
|
input.onProgress({
|
||||||
|
transferredBytes: input.file.size,
|
||||||
|
totalBytes: input.file.size,
|
||||||
|
});
|
||||||
|
return success({ resourceId: `fake:${input.file.name}` });
|
||||||
|
}
|
||||||
|
|
||||||
|
async download(input: Parameters<FileTransferPort["download"]>[0]) {
|
||||||
|
const cancelled = aborted(input.signal);
|
||||||
|
if (cancelled) return cancelled;
|
||||||
|
if (input.resourceId.startsWith("expired:")) {
|
||||||
|
return failure("EXPIRED_RESOURCE", true, "The download link expired.");
|
||||||
|
}
|
||||||
|
const bytes = new TextEncoder().encode(input.resourceId);
|
||||||
|
input.onProgress({
|
||||||
|
transferredBytes: bytes.byteLength,
|
||||||
|
totalBytes: bytes.byteLength,
|
||||||
|
});
|
||||||
|
return success(bytes);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class FakeGeneratedApiAdapter implements GeneratedApiFacade {
|
||||||
|
constructor(
|
||||||
|
private readonly contractVersion: string,
|
||||||
|
private readonly handlers: Readonly<
|
||||||
|
Record<string, (body: unknown) => unknown | Promise<unknown>>
|
||||||
|
>,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
async execute<TOutput>(
|
||||||
|
input: Parameters<GeneratedApiFacade["execute"]>[0],
|
||||||
|
): Promise<CapabilityResult<TOutput>> {
|
||||||
|
const cancelled = aborted(input.signal);
|
||||||
|
if (cancelled) return cancelled;
|
||||||
|
if (input.contractVersion !== this.contractVersion) {
|
||||||
|
return failure("CONTRACT_DRIFT", false, "API contract version is unsupported.");
|
||||||
|
}
|
||||||
|
const handler = this.handlers[input.operationId];
|
||||||
|
if (!handler) {
|
||||||
|
return failure("UNSUPPORTED", false, "API operation is unsupported.");
|
||||||
|
}
|
||||||
|
return success((await handler(input.body)) as TOutput);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class FakeFeatureFlagAdapter<
|
||||||
|
TFlags extends Record<string, boolean | string | number>,
|
||||||
|
> implements FeatureFlagPort<TFlags>
|
||||||
|
{
|
||||||
|
constructor(
|
||||||
|
private readonly values: Readonly<Partial<TFlags>>,
|
||||||
|
private readonly available = true,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
async evaluate<TKey extends keyof TFlags>(input: {
|
||||||
|
key: TKey;
|
||||||
|
fallback: TFlags[TKey];
|
||||||
|
maxAgeMs: number;
|
||||||
|
}): Promise<CapabilityResult<TFlags[TKey]>> {
|
||||||
|
if (!this.available) {
|
||||||
|
return failure("PROVIDER_UNAVAILABLE", true, "Flag provider is unavailable.");
|
||||||
|
}
|
||||||
|
const value = this.values[input.key];
|
||||||
|
return success((value ?? input.fallback) as TFlags[TKey]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class FakeWorkerTaskAdapter<TInput, TOutput>
|
||||||
|
implements WorkerTaskPort<TInput, TOutput>
|
||||||
|
{
|
||||||
|
readonly #cancelled = new Set<string>();
|
||||||
|
|
||||||
|
constructor(
|
||||||
|
private readonly handler: (input: TInput) => TOutput | Promise<TOutput>,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
async run(input: {
|
||||||
|
taskId: string;
|
||||||
|
generation: number;
|
||||||
|
payload: TInput;
|
||||||
|
signal: AbortSignal;
|
||||||
|
}): Promise<CapabilityResult<TOutput>> {
|
||||||
|
if (input.signal.aborted || this.#cancelled.has(input.taskId)) {
|
||||||
|
return failure("ABORTED", false, "Worker task was cancelled.");
|
||||||
|
}
|
||||||
|
const output = await this.handler(input.payload);
|
||||||
|
if (input.signal.aborted || this.#cancelled.has(input.taskId)) {
|
||||||
|
return failure("STALE_RESULT", false, "Stale worker result was discarded.");
|
||||||
|
}
|
||||||
|
return success(output);
|
||||||
|
}
|
||||||
|
|
||||||
|
cancel(taskId: string): void {
|
||||||
|
this.#cancelled.add(taskId);
|
||||||
|
}
|
||||||
|
|
||||||
|
dispose(): void {
|
||||||
|
this.#cancelled.clear();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class FakeMultiTabAdapter<T> implements MultiTabPort<T> {
|
||||||
|
readonly #seen = new Set<string>();
|
||||||
|
readonly #listeners = new Set<{
|
||||||
|
sourceId: string;
|
||||||
|
onEvent(event: CapabilityResult<MultiTabEvent<T>>): void;
|
||||||
|
}>();
|
||||||
|
|
||||||
|
publish(event: MultiTabEvent<T>): CapabilityResult<void> {
|
||||||
|
if (this.#seen.has(event.eventId)) {
|
||||||
|
return failure("CONFLICT", false, "Duplicate multi-tab event was ignored.");
|
||||||
|
}
|
||||||
|
this.#seen.add(event.eventId);
|
||||||
|
for (const listener of this.#listeners) {
|
||||||
|
if (listener.sourceId !== event.sourceId) {
|
||||||
|
listener.onEvent(success(event));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return success(undefined);
|
||||||
|
}
|
||||||
|
|
||||||
|
subscribe(input: {
|
||||||
|
sourceId: string;
|
||||||
|
onEvent(event: CapabilityResult<MultiTabEvent<T>>): void;
|
||||||
|
}) {
|
||||||
|
this.#listeners.add(input);
|
||||||
|
return () => this.#listeners.delete(input);
|
||||||
|
}
|
||||||
|
|
||||||
|
close(): void {
|
||||||
|
this.#listeners.clear();
|
||||||
|
this.#seen.clear();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class FakeBrowserPermissionAdapter implements BrowserPermissionPort {
|
||||||
|
constructor(
|
||||||
|
private readonly decisions: Readonly<
|
||||||
|
Partial<Record<BrowserCapability, PermissionDecision>>
|
||||||
|
>,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
async request(input: {
|
||||||
|
capability: BrowserCapability;
|
||||||
|
signal?: AbortSignal;
|
||||||
|
}): Promise<CapabilityResult<PermissionDecision>> {
|
||||||
|
const cancelled = aborted(input.signal);
|
||||||
|
if (cancelled) return cancelled;
|
||||||
|
const decision = this.decisions[input.capability];
|
||||||
|
return decision
|
||||||
|
? success(decision)
|
||||||
|
: failure("UNSUPPORTED", false, "Browser capability is unsupported.");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class FakeClientWorkflowAdapter<TState, TEvent>
|
||||||
|
implements ClientWorkflowPort<TState, TEvent>
|
||||||
|
{
|
||||||
|
readonly #initial: TState;
|
||||||
|
readonly #listeners = new Set<(state: Readonly<TState>) => void>();
|
||||||
|
#state: TState;
|
||||||
|
|
||||||
|
constructor(
|
||||||
|
initial: TState,
|
||||||
|
private readonly transition: (state: TState, event: TEvent) => TState,
|
||||||
|
) {
|
||||||
|
this.#initial = structuredClone(initial);
|
||||||
|
this.#state = structuredClone(initial);
|
||||||
|
}
|
||||||
|
|
||||||
|
snapshot(): Readonly<TState> {
|
||||||
|
return structuredClone(this.#state);
|
||||||
|
}
|
||||||
|
|
||||||
|
dispatch(event: TEvent): CapabilityResult<Readonly<TState>> {
|
||||||
|
this.#state = this.transition(this.#state, event);
|
||||||
|
const snapshot = this.snapshot();
|
||||||
|
this.#listeners.forEach((listener) => listener(snapshot));
|
||||||
|
return success(snapshot);
|
||||||
|
}
|
||||||
|
|
||||||
|
reset(): void {
|
||||||
|
this.#state = structuredClone(this.#initial);
|
||||||
|
const snapshot = this.snapshot();
|
||||||
|
this.#listeners.forEach((listener) => listener(snapshot));
|
||||||
|
}
|
||||||
|
|
||||||
|
subscribe(listener: (state: Readonly<TState>) => void) {
|
||||||
|
this.#listeners.add(listener);
|
||||||
|
return () => this.#listeners.delete(listener);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export class FakeLargeDataUiAdapter<TRow extends { id: string }>
|
||||||
|
implements LargeDataUiFacade<TRow>
|
||||||
|
{
|
||||||
|
#rows: ReadonlyArray<TRow> = [];
|
||||||
|
#generation = 0;
|
||||||
|
|
||||||
|
window(input: { offset: number; limit: number; generation: number }) {
|
||||||
|
if (input.generation !== this.#generation) {
|
||||||
|
return failure("STALE_RESULT", false, "Stale row window was discarded.");
|
||||||
|
}
|
||||||
|
if (input.offset < 0 || input.limit < 1) {
|
||||||
|
return failure("INVALID_INPUT", false, "Invalid row window.");
|
||||||
|
}
|
||||||
|
return success(this.#rows.slice(input.offset, input.offset + input.limit));
|
||||||
|
}
|
||||||
|
|
||||||
|
focus(rowId: string) {
|
||||||
|
return this.#rows.some((row) => row.id === rowId)
|
||||||
|
? success(undefined)
|
||||||
|
: failure("NOT_FOUND", false, "Row is no longer available.");
|
||||||
|
}
|
||||||
|
|
||||||
|
replace(rows: ReadonlyArray<TRow>, generation: number): void {
|
||||||
|
this.#rows = rows;
|
||||||
|
this.#generation = generation;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const sensitiveAttribute = /credential|authorization|cookie|password|secret|token/i;
|
||||||
|
|
||||||
|
export class RecordingAnalyticsAdapter implements AnalyticsErrorSink {
|
||||||
|
readonly records: Array<
|
||||||
|
Readonly<{
|
||||||
|
kind: "analytics" | "error";
|
||||||
|
eventId: string;
|
||||||
|
attributes: Readonly<Record<string, SafeAnalyticsValue>>;
|
||||||
|
}>
|
||||||
|
> = [];
|
||||||
|
|
||||||
|
constructor(private readonly capacity = 100) {}
|
||||||
|
|
||||||
|
record(input: Parameters<AnalyticsErrorSink["record"]>[0]) {
|
||||||
|
if (input.kind === "analytics" && input.consent !== "granted") {
|
||||||
|
return failure("CONSENT_DENIED", false, "Analytics consent was not granted.");
|
||||||
|
}
|
||||||
|
if (this.records.length >= this.capacity) {
|
||||||
|
return failure("LIMIT_EXCEEDED", true, "Analytics queue is full.");
|
||||||
|
}
|
||||||
|
const attributes = Object.fromEntries(
|
||||||
|
Object.entries(input.attributes).filter(([key]) => !sensitiveAttribute.test(key)),
|
||||||
|
);
|
||||||
|
this.records.push(
|
||||||
|
Object.freeze({ kind: input.kind, eventId: input.eventId, attributes }),
|
||||||
|
);
|
||||||
|
return success(undefined);
|
||||||
|
}
|
||||||
|
|
||||||
|
async flush(signal?: AbortSignal) {
|
||||||
|
return aborted(signal) ?? success(undefined);
|
||||||
|
}
|
||||||
|
|
||||||
|
dispose(): void {
|
||||||
|
this.records.length = 0;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const unavailableAsync = async () =>
|
||||||
|
failure("PROVIDER_UNAVAILABLE", true, "Capability was not installed.");
|
||||||
|
const unavailableSync = () =>
|
||||||
|
failure("PROVIDER_UNAVAILABLE", true, "Capability was not installed.");
|
||||||
|
|
||||||
|
export function createUnavailableAdapters(): OptionalCapabilityPorts {
|
||||||
|
return Object.freeze({
|
||||||
|
realtime: {
|
||||||
|
subscribe: unavailableAsync,
|
||||||
|
heartbeat: unavailableAsync,
|
||||||
|
},
|
||||||
|
offline: {
|
||||||
|
open: unavailableAsync,
|
||||||
|
get: unavailableAsync,
|
||||||
|
put: unavailableAsync,
|
||||||
|
migrate: unavailableAsync,
|
||||||
|
close() {},
|
||||||
|
},
|
||||||
|
serviceWorker: {
|
||||||
|
inspect: unavailableAsync,
|
||||||
|
activate: unavailableAsync,
|
||||||
|
rollback: unavailableAsync,
|
||||||
|
unregister: unavailableAsync,
|
||||||
|
},
|
||||||
|
fileTransfer: {
|
||||||
|
upload: unavailableAsync,
|
||||||
|
download: unavailableAsync,
|
||||||
|
},
|
||||||
|
generatedApi: { execute: unavailableAsync },
|
||||||
|
featureFlag: { evaluate: unavailableAsync },
|
||||||
|
worker: {
|
||||||
|
run: unavailableAsync,
|
||||||
|
cancel() {},
|
||||||
|
dispose() {},
|
||||||
|
},
|
||||||
|
multiTab: {
|
||||||
|
publish: unavailableSync,
|
||||||
|
subscribe: () => () => {},
|
||||||
|
close() {},
|
||||||
|
},
|
||||||
|
browserPermission: { request: unavailableAsync },
|
||||||
|
clientWorkflow: {
|
||||||
|
snapshot: () => Object.freeze({ unavailable: true }),
|
||||||
|
dispatch: unavailableSync,
|
||||||
|
reset() {},
|
||||||
|
subscribe: () => () => {},
|
||||||
|
},
|
||||||
|
largeDataUi: {
|
||||||
|
window: unavailableSync,
|
||||||
|
focus: unavailableSync,
|
||||||
|
replace() {},
|
||||||
|
},
|
||||||
|
analytics: {
|
||||||
|
record: unavailableSync,
|
||||||
|
flush: unavailableAsync,
|
||||||
|
dispose() {},
|
||||||
|
},
|
||||||
|
});
|
||||||
|
}
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
export * from "./contracts.js";
|
||||||
|
export * from "./fake-adapters.js";
|
||||||
@@ -0,0 +1,60 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||||
|
"$id": "https://clean-architecture-frontend.local/schemas/dependency-inventory.schema.json",
|
||||||
|
"type": "object",
|
||||||
|
"additionalProperties": false,
|
||||||
|
"required": [
|
||||||
|
"schemaVersion",
|
||||||
|
"packageManager",
|
||||||
|
"lockfileSha256",
|
||||||
|
"dependencyCount",
|
||||||
|
"directDependencyCount",
|
||||||
|
"dependencies"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"schemaVersion": { "const": 2 },
|
||||||
|
"packageManager": { "type": "string", "minLength": 1 },
|
||||||
|
"lockfileSha256": {
|
||||||
|
"type": "string",
|
||||||
|
"pattern": "^[a-f0-9]{64}$"
|
||||||
|
},
|
||||||
|
"dependencyCount": { "type": "integer", "minimum": 1 },
|
||||||
|
"directDependencyCount": { "type": "integer", "minimum": 1 },
|
||||||
|
"dependencies": {
|
||||||
|
"type": "array",
|
||||||
|
"minItems": 1,
|
||||||
|
"items": {
|
||||||
|
"type": "object",
|
||||||
|
"additionalProperties": false,
|
||||||
|
"required": [
|
||||||
|
"name",
|
||||||
|
"version",
|
||||||
|
"direct",
|
||||||
|
"scope",
|
||||||
|
"optional",
|
||||||
|
"license",
|
||||||
|
"integrity",
|
||||||
|
"dependencies"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"name": { "type": "string", "minLength": 1 },
|
||||||
|
"version": { "type": "string", "minLength": 1 },
|
||||||
|
"direct": { "type": "boolean" },
|
||||||
|
"scope": {
|
||||||
|
"enum": ["production", "development"]
|
||||||
|
},
|
||||||
|
"optional": { "type": "boolean" },
|
||||||
|
"license": { "type": "string", "minLength": 1 },
|
||||||
|
"integrity": {
|
||||||
|
"type": "string",
|
||||||
|
"pattern": "^sha512-"
|
||||||
|
},
|
||||||
|
"dependencies": {
|
||||||
|
"type": "array",
|
||||||
|
"items": { "type": "string", "minLength": 1 }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,55 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||||
|
"$id": "https://clean-architecture-frontend.local/schemas/supply-chain-verification.schema.json",
|
||||||
|
"type": "object",
|
||||||
|
"additionalProperties": false,
|
||||||
|
"required": [
|
||||||
|
"schemaVersion",
|
||||||
|
"localStatus",
|
||||||
|
"promotionStatus",
|
||||||
|
"lockfileSha256",
|
||||||
|
"sourceSetSha256",
|
||||||
|
"distSha256",
|
||||||
|
"sbomSha256",
|
||||||
|
"dependencyDiff",
|
||||||
|
"highRiskReview",
|
||||||
|
"vulnerabilityStatus",
|
||||||
|
"provenanceAttestationStatus",
|
||||||
|
"failures"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"schemaVersion": { "const": 1 },
|
||||||
|
"localStatus": { "enum": ["PASS", "FAIL"] },
|
||||||
|
"promotionStatus": {
|
||||||
|
"enum": ["PASS", "FAIL_UNVERIFIED"]
|
||||||
|
},
|
||||||
|
"lockfileSha256": {
|
||||||
|
"type": "string",
|
||||||
|
"pattern": "^[a-f0-9]{64}$"
|
||||||
|
},
|
||||||
|
"sourceSetSha256": {
|
||||||
|
"type": "string",
|
||||||
|
"pattern": "^[a-f0-9]{64}$"
|
||||||
|
},
|
||||||
|
"distSha256": {
|
||||||
|
"type": "string",
|
||||||
|
"pattern": "^[a-f0-9]{64}$"
|
||||||
|
},
|
||||||
|
"sbomSha256": {
|
||||||
|
"type": "string",
|
||||||
|
"pattern": "^[a-f0-9]{64}$"
|
||||||
|
},
|
||||||
|
"dependencyDiff": { "type": "object" },
|
||||||
|
"highRiskReview": { "type": "array" },
|
||||||
|
"vulnerabilityStatus": {
|
||||||
|
"enum": ["PASS", "FAIL", "FAIL_UNVERIFIED"]
|
||||||
|
},
|
||||||
|
"provenanceAttestationStatus": {
|
||||||
|
"enum": ["PASS", "FAIL_UNVERIFIED"]
|
||||||
|
},
|
||||||
|
"failures": {
|
||||||
|
"type": "array",
|
||||||
|
"items": { "type": "string" }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,87 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||||
|
"$id": "frontend-capability-recipes.schema.json",
|
||||||
|
"title": "Frontend optional capability recipe catalog",
|
||||||
|
"type": "object",
|
||||||
|
"additionalProperties": false,
|
||||||
|
"required": [
|
||||||
|
"$schema",
|
||||||
|
"schemaVersion",
|
||||||
|
"decisionId",
|
||||||
|
"defaultStatus",
|
||||||
|
"productionRuntimeDependencies",
|
||||||
|
"catalogOwner",
|
||||||
|
"reviewOn",
|
||||||
|
"vendorPackagePatterns",
|
||||||
|
"recipes"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"$schema": { "type": "string", "minLength": 1 },
|
||||||
|
"schemaVersion": { "const": 1 },
|
||||||
|
"decisionId": { "const": "VD-10" },
|
||||||
|
"defaultStatus": { "const": "NOT_INSTALLED" },
|
||||||
|
"productionRuntimeDependencies": {
|
||||||
|
"type": "array",
|
||||||
|
"maxItems": 0
|
||||||
|
},
|
||||||
|
"catalogOwner": { "type": "string", "minLength": 1 },
|
||||||
|
"reviewOn": { "type": "string", "minLength": 1 },
|
||||||
|
"vendorPackagePatterns": {
|
||||||
|
"type": "array",
|
||||||
|
"minItems": 1,
|
||||||
|
"uniqueItems": true,
|
||||||
|
"items": { "type": "string", "minLength": 1 }
|
||||||
|
},
|
||||||
|
"recipes": {
|
||||||
|
"type": "array",
|
||||||
|
"minItems": 12,
|
||||||
|
"maxItems": 12,
|
||||||
|
"items": { "$ref": "#/$defs/recipe" }
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"$defs": {
|
||||||
|
"recipe": {
|
||||||
|
"type": "object",
|
||||||
|
"additionalProperties": false,
|
||||||
|
"required": [
|
||||||
|
"id",
|
||||||
|
"status",
|
||||||
|
"trigger",
|
||||||
|
"forbiddenWhen",
|
||||||
|
"boundary",
|
||||||
|
"port",
|
||||||
|
"fake",
|
||||||
|
"failureKinds",
|
||||||
|
"lifecycleMethods",
|
||||||
|
"owner",
|
||||||
|
"securityPrivacy",
|
||||||
|
"bundleBudgetGzipBytes",
|
||||||
|
"fallback",
|
||||||
|
"removal",
|
||||||
|
"serverStatePolicy"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"id": { "type": "string", "minLength": 1 },
|
||||||
|
"status": { "const": "RECIPE_AVAILABLE" },
|
||||||
|
"trigger": { "type": "string", "minLength": 1 },
|
||||||
|
"forbiddenWhen": { "$ref": "#/$defs/nonEmptyStrings" },
|
||||||
|
"boundary": { "type": "string", "minLength": 1 },
|
||||||
|
"port": { "type": "string", "minLength": 1 },
|
||||||
|
"fake": { "type": "string", "minLength": 1 },
|
||||||
|
"failureKinds": { "$ref": "#/$defs/nonEmptyStrings" },
|
||||||
|
"lifecycleMethods": { "$ref": "#/$defs/nonEmptyStrings" },
|
||||||
|
"owner": { "type": "string", "minLength": 1 },
|
||||||
|
"securityPrivacy": { "$ref": "#/$defs/nonEmptyStrings" },
|
||||||
|
"bundleBudgetGzipBytes": { "type": "integer", "minimum": 1 },
|
||||||
|
"fallback": { "type": "string", "minLength": 1 },
|
||||||
|
"removal": { "$ref": "#/$defs/nonEmptyStrings" },
|
||||||
|
"serverStatePolicy": { "type": "string", "minLength": 1 }
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"nonEmptyStrings": {
|
||||||
|
"type": "array",
|
||||||
|
"minItems": 1,
|
||||||
|
"items": { "type": "string", "minLength": 1 }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
import { spawnSync } from "node:child_process";
|
||||||
|
import { cp, mkdtemp, readFile, rm, writeFile } from "node:fs/promises";
|
||||||
|
import { tmpdir } from "node:os";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
|
const fixtureRoot = await mkdtemp(
|
||||||
|
path.join(tmpdir(), "ca-frontend-frozen-lockfile-"),
|
||||||
|
);
|
||||||
|
try {
|
||||||
|
await cp("pnpm-lock.yaml", path.join(fixtureRoot, "pnpm-lock.yaml"));
|
||||||
|
const manifest = JSON.parse(await readFile("package.json", "utf8"));
|
||||||
|
manifest.dependencies.react = "0.0.0-invalid-fixture";
|
||||||
|
await writeFile(
|
||||||
|
path.join(fixtureRoot, "package.json"),
|
||||||
|
`${JSON.stringify(manifest, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
const result = spawnSync(
|
||||||
|
"corepack",
|
||||||
|
[
|
||||||
|
"pnpm",
|
||||||
|
"install",
|
||||||
|
"--frozen-lockfile",
|
||||||
|
"--lockfile-only",
|
||||||
|
"--ignore-scripts",
|
||||||
|
],
|
||||||
|
{
|
||||||
|
cwd: fixtureRoot,
|
||||||
|
encoding: "utf8",
|
||||||
|
},
|
||||||
|
);
|
||||||
|
if (result.status === 0) {
|
||||||
|
process.stderr.write("Tampered manifest unexpectedly passed frozen install.\n");
|
||||||
|
process.exitCode = 1;
|
||||||
|
} else {
|
||||||
|
process.stdout.write("Frozen lockfile mismatch fixture: rejected PASS\n");
|
||||||
|
}
|
||||||
|
} finally {
|
||||||
|
await rm(fixtureRoot, { recursive: true, force: true });
|
||||||
|
}
|
||||||
@@ -0,0 +1,93 @@
|
|||||||
|
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
import {
|
||||||
|
scanOptionalRecipeSources,
|
||||||
|
validateRecipeCatalog,
|
||||||
|
} from "./lib/optional-recipes.mjs";
|
||||||
|
|
||||||
|
const catalog = JSON.parse(
|
||||||
|
await readFile("config/recipes/frontend-capability-recipes.json", "utf8"),
|
||||||
|
);
|
||||||
|
const packageDocument = JSON.parse(await readFile("package.json", "utf8"));
|
||||||
|
|
||||||
|
const cleanupCatalog = structuredClone(catalog);
|
||||||
|
cleanupCatalog.recipes.find(
|
||||||
|
/** @param {{id: string}} recipe */ (recipe) => recipe.id === "realtime",
|
||||||
|
).lifecycleMethods = [];
|
||||||
|
|
||||||
|
const dependencyCatalog = structuredClone(catalog);
|
||||||
|
dependencyCatalog.productionRuntimeDependencies = ["zustand"];
|
||||||
|
|
||||||
|
const workflowCatalog = structuredClone(catalog);
|
||||||
|
workflowCatalog.recipes.find(
|
||||||
|
/** @param {{id: string}} recipe */ (recipe) => recipe.id === "client-workflow",
|
||||||
|
).serverStatePolicy = "copied-server-state";
|
||||||
|
|
||||||
|
const sourceViolations = await scanOptionalRecipeSources(
|
||||||
|
"tests/fixtures/optional-recipes/forbidden",
|
||||||
|
{ scanProductionBoundary: false },
|
||||||
|
);
|
||||||
|
const productionViolations = await scanOptionalRecipeSources(
|
||||||
|
"tests/fixtures/optional-recipes/forbidden/production-import",
|
||||||
|
{ scanProductionBoundary: true },
|
||||||
|
);
|
||||||
|
sourceViolations.push(...productionViolations);
|
||||||
|
const ruleIds = new Set(sourceViolations.map(({ ruleId }) => ruleId));
|
||||||
|
const results = [
|
||||||
|
{
|
||||||
|
id: "cleanup-omission",
|
||||||
|
passed: validateRecipeCatalog(cleanupCatalog, packageDocument).some(
|
||||||
|
(violation) => violation === "realtime:CLEANUP_CONTRACT_MISSING",
|
||||||
|
),
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: "unselected-runtime-dependency",
|
||||||
|
passed: validateRecipeCatalog(dependencyCatalog, packageDocument).includes(
|
||||||
|
"UNSELECTED_RUNTIME_DEPENDENCY",
|
||||||
|
),
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: "server-state-policy",
|
||||||
|
passed: validateRecipeCatalog(workflowCatalog, packageDocument).includes(
|
||||||
|
"client-workflow:SERVER_STATE_DUPLICATION_POLICY",
|
||||||
|
),
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: "vendor-direct-import",
|
||||||
|
passed: ruleIds.has("VENDOR_IMPORT_OUTSIDE_ADAPTER"),
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: "credential-leak",
|
||||||
|
passed: ruleIds.has("CREDENTIAL_LEAK_PATH"),
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: "server-state-source-duplication",
|
||||||
|
passed: ruleIds.has("CLIENT_STORE_DUPLICATES_SERVER_STATE"),
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: "production-imports-recipe",
|
||||||
|
passed: ruleIds.has("PRODUCTION_IMPORTS_RECIPE"),
|
||||||
|
},
|
||||||
|
];
|
||||||
|
const report = {
|
||||||
|
schemaVersion: 1,
|
||||||
|
results,
|
||||||
|
passed: results.every(({ passed }) => passed),
|
||||||
|
};
|
||||||
|
await mkdir("artifacts/quality", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/quality/optional-recipe-fixtures.json",
|
||||||
|
`${JSON.stringify(report, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
if (!report.passed) {
|
||||||
|
process.stderr.write(
|
||||||
|
`Optional recipe negative fixtures failed: ${results
|
||||||
|
.filter(({ passed }) => !passed)
|
||||||
|
.map(({ id }) => id)
|
||||||
|
.join(", ")}\n`,
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(
|
||||||
|
`Optional recipe negative fixtures: PASS (${results.length} forbidden cases rejected)\n`,
|
||||||
|
);
|
||||||
@@ -0,0 +1,74 @@
|
|||||||
|
import { mkdir, readFile, stat, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
import {
|
||||||
|
scanOptionalRecipeSources,
|
||||||
|
scanProductionBundle,
|
||||||
|
validateRecipeCatalog,
|
||||||
|
} from "./lib/optional-recipes.mjs";
|
||||||
|
|
||||||
|
/** @param {string} name @param {string} fallback */
|
||||||
|
const argument = (name, fallback) => {
|
||||||
|
const index = process.argv.indexOf(name);
|
||||||
|
return index === -1 ? fallback : process.argv[index + 1];
|
||||||
|
};
|
||||||
|
|
||||||
|
const catalogPath = argument(
|
||||||
|
"--catalog",
|
||||||
|
"config/recipes/frontend-capability-recipes.json",
|
||||||
|
);
|
||||||
|
const sourceRoot = argument("--source-root", "src");
|
||||||
|
const distRoot = argument("--dist-root", "dist");
|
||||||
|
const artifactPath = argument(
|
||||||
|
"--artifact",
|
||||||
|
"artifacts/quality/optional-recipes.json",
|
||||||
|
);
|
||||||
|
const requireDist = process.argv.includes("--require-dist");
|
||||||
|
|
||||||
|
const catalog = JSON.parse(await readFile(catalogPath, "utf8"));
|
||||||
|
const packageDocument = JSON.parse(await readFile("package.json", "utf8"));
|
||||||
|
const catalogViolations = validateRecipeCatalog(catalog, packageDocument);
|
||||||
|
const sourceViolations = await scanOptionalRecipeSources(sourceRoot);
|
||||||
|
const bundlePresent = await stat(`${distRoot}/.vite/manifest.json`)
|
||||||
|
.then(() => true)
|
||||||
|
.catch(() => false);
|
||||||
|
const bundleViolations = await scanProductionBundle(distRoot);
|
||||||
|
const violations = [
|
||||||
|
...catalogViolations.map((ruleId) => ({ ruleId, path: catalogPath })),
|
||||||
|
...sourceViolations,
|
||||||
|
...bundleViolations.map((path) => ({
|
||||||
|
ruleId: "UNSELECTED_RECIPE_IN_PRODUCTION_BUNDLE",
|
||||||
|
path,
|
||||||
|
})),
|
||||||
|
...(requireDist && !bundlePresent
|
||||||
|
? [{ ruleId: "PRODUCTION_BUNDLE_MISSING", path: distRoot }]
|
||||||
|
: []),
|
||||||
|
];
|
||||||
|
const report = {
|
||||||
|
schemaVersion: 1,
|
||||||
|
decisionId: "VD-10",
|
||||||
|
selectedCapabilities: [],
|
||||||
|
recipeCount: Array.isArray(catalog.recipes) ? catalog.recipes.length : 0,
|
||||||
|
productionRuntimeDependencies:
|
||||||
|
catalog.productionRuntimeDependencies ?? null,
|
||||||
|
bundleStatus: bundlePresent
|
||||||
|
? bundleViolations.length === 0
|
||||||
|
? "PASS"
|
||||||
|
: "FAIL"
|
||||||
|
: "NOT_BUILT",
|
||||||
|
violations,
|
||||||
|
passed: violations.length === 0,
|
||||||
|
};
|
||||||
|
await mkdir("artifacts/quality", { recursive: true });
|
||||||
|
await writeFile(artifactPath, `${JSON.stringify(report, null, 2)}\n`);
|
||||||
|
|
||||||
|
if (violations.length > 0) {
|
||||||
|
process.stderr.write(
|
||||||
|
`Optional recipe contract failed:\n${violations
|
||||||
|
.map((violation) => `${violation.ruleId}: ${violation.path}`)
|
||||||
|
.join("\n")}\n`,
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(
|
||||||
|
`Optional recipes: PASS (${report.recipeCount} recipe-only capabilities, bundle=${report.bundleStatus})\n`,
|
||||||
|
);
|
||||||
@@ -0,0 +1,148 @@
|
|||||||
|
import { mkdir, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
import {
|
||||||
|
diffDependencyInventories,
|
||||||
|
isValidSha512Integrity,
|
||||||
|
supplyChainDigest,
|
||||||
|
validateDependencyReview,
|
||||||
|
validateLicensePolicy,
|
||||||
|
validateVulnerabilityReport,
|
||||||
|
verifySupplyChainCoherence,
|
||||||
|
} from "./lib/supply-chain.mjs";
|
||||||
|
|
||||||
|
const integrity = `sha512-${Buffer.alloc(64, 1).toString("base64")}`;
|
||||||
|
const baseDependency = {
|
||||||
|
name: "base",
|
||||||
|
version: "1.0.0",
|
||||||
|
direct: false,
|
||||||
|
scope: "production",
|
||||||
|
optional: false,
|
||||||
|
license: "MIT",
|
||||||
|
integrity,
|
||||||
|
dependencies: [],
|
||||||
|
};
|
||||||
|
const directDependency = {
|
||||||
|
...baseDependency,
|
||||||
|
name: "new-direct",
|
||||||
|
direct: true,
|
||||||
|
};
|
||||||
|
const before = { dependencies: [baseDependency] };
|
||||||
|
const after = { dependencies: [baseDependency, directDependency] };
|
||||||
|
const diff = diffDependencyInventories(before, after);
|
||||||
|
const selfReview = validateDependencyReview(diff, after, {
|
||||||
|
changes: [
|
||||||
|
{
|
||||||
|
changeId: "add:new-direct@1.0.0",
|
||||||
|
owner: "same-person",
|
||||||
|
reviewer: "same-person",
|
||||||
|
reason: "fixture",
|
||||||
|
rollback: "remove",
|
||||||
|
},
|
||||||
|
],
|
||||||
|
});
|
||||||
|
const deniedLicense = validateLicensePolicy(
|
||||||
|
{
|
||||||
|
dependencies: [{ ...baseDependency, license: "AGPL-3.0" }],
|
||||||
|
},
|
||||||
|
{
|
||||||
|
allowedLicenses: ["MIT"],
|
||||||
|
deniedLicensePatterns: ["AGPL"],
|
||||||
|
},
|
||||||
|
);
|
||||||
|
const vulnerable = validateVulnerabilityReport(
|
||||||
|
{
|
||||||
|
provider: "fixture",
|
||||||
|
scannedLockfileSha256: "lock",
|
||||||
|
findings: [
|
||||||
|
{
|
||||||
|
id: "CVE-FIXTURE",
|
||||||
|
packageName: "base",
|
||||||
|
version: "1.0.0",
|
||||||
|
severity: "critical",
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
{ blockAtSeverity: "high" },
|
||||||
|
{
|
||||||
|
exceptions: [
|
||||||
|
{
|
||||||
|
vulnerabilityId: "CVE-FIXTURE",
|
||||||
|
packageName: "base",
|
||||||
|
owner: "owner",
|
||||||
|
reviewer: "reviewer",
|
||||||
|
reason: "expired fixture",
|
||||||
|
expiresAt: "2000-01-01T00:00:00.000Z",
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
"lock",
|
||||||
|
new Date("2026-07-26T00:00:00.000Z"),
|
||||||
|
);
|
||||||
|
const mismatchedCoherence = verifySupplyChainCoherence(
|
||||||
|
{
|
||||||
|
components: [],
|
||||||
|
metadata: {
|
||||||
|
properties: [{ name: "ca:lockfileSha256", value: "wrong" }],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{ dependencies: [baseDependency], lockfileSha256: "lock" },
|
||||||
|
{
|
||||||
|
subject: [{ digest: { sha256: "wrong" } }],
|
||||||
|
predicate: { materials: { lockfileSha256: "wrong" } },
|
||||||
|
},
|
||||||
|
"dist",
|
||||||
|
);
|
||||||
|
const orderingStable =
|
||||||
|
supplyChainDigest({ dependencies: [baseDependency, directDependency] }) ===
|
||||||
|
supplyChainDigest({ dependencies: [directDependency, baseDependency] });
|
||||||
|
const approvedDigest = supplyChainDigest(before);
|
||||||
|
const tamperedBaselineRejected =
|
||||||
|
approvedDigest !==
|
||||||
|
supplyChainDigest({
|
||||||
|
dependencies: [{ ...baseDependency, version: "9.9.9-tampered" }],
|
||||||
|
});
|
||||||
|
const providerFailure = validateVulnerabilityReport(
|
||||||
|
{
|
||||||
|
provider: "",
|
||||||
|
scannedLockfileSha256: "wrong",
|
||||||
|
findings: [],
|
||||||
|
},
|
||||||
|
{ blockAtSeverity: "high" },
|
||||||
|
{ exceptions: [] },
|
||||||
|
"lock",
|
||||||
|
);
|
||||||
|
const results = [
|
||||||
|
{
|
||||||
|
id: "transitive-removal-is-real-diff",
|
||||||
|
passed:
|
||||||
|
diffDependencyInventories(after, before).removed[0] ===
|
||||||
|
"new-direct@1.0.0",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: "tampered-integrity-rejected",
|
||||||
|
passed: !isValidSha512Integrity("sha512-dGFtcGVyZWQ="),
|
||||||
|
},
|
||||||
|
{ id: "high-risk-self-approval-rejected", passed: !selfReview.passed },
|
||||||
|
{ id: "denied-license-rejected", passed: !deniedLicense.passed },
|
||||||
|
{
|
||||||
|
id: "critical-vulnerability-expired-exception-rejected",
|
||||||
|
passed: !vulnerable.passed,
|
||||||
|
},
|
||||||
|
{ id: "sbom-provenance-mismatch-rejected", passed: !mismatchedCoherence.passed },
|
||||||
|
{ id: "dependency-ordering-deterministic", passed: orderingStable },
|
||||||
|
{ id: "baseline-digest-tamper-rejected", passed: tamperedBaselineRejected },
|
||||||
|
{
|
||||||
|
id: "vulnerability-provider-evidence-invalid",
|
||||||
|
passed: !providerFailure.passed,
|
||||||
|
},
|
||||||
|
];
|
||||||
|
await mkdir("artifacts/security", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/security/supply-chain-fixtures.json",
|
||||||
|
`${JSON.stringify({ schemaVersion: 1, results }, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
if (results.some((result) => !result.passed)) {
|
||||||
|
process.stderr.write("Supply-chain negative fixture failed.\n");
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(`Supply-chain fixtures: ${results.length} PASS\n`);
|
||||||
@@ -0,0 +1,105 @@
|
|||||||
|
import { spawnSync } from "node:child_process";
|
||||||
|
import { mkdir, readFile, rm, writeFile } from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
|
const fixtureDirectory = path.resolve(".tmp/supply-chain-provider-fixture");
|
||||||
|
await rm(fixtureDirectory, { recursive: true, force: true });
|
||||||
|
await mkdir(fixtureDirectory, { recursive: true });
|
||||||
|
const inventory = JSON.parse(
|
||||||
|
await readFile("artifacts/release/dependency-inventory.json", "utf8"),
|
||||||
|
);
|
||||||
|
const verification = JSON.parse(
|
||||||
|
await readFile(
|
||||||
|
"artifacts/security/supply-chain-verification.json",
|
||||||
|
"utf8",
|
||||||
|
),
|
||||||
|
);
|
||||||
|
const vulnerabilityPath = path.join(
|
||||||
|
fixtureDirectory,
|
||||||
|
"vulnerability-report.json",
|
||||||
|
);
|
||||||
|
const attestationPath = path.join(fixtureDirectory, "attestation.json");
|
||||||
|
await writeFile(
|
||||||
|
vulnerabilityPath,
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
provider: "fixture-scanner",
|
||||||
|
scannedLockfileSha256: inventory.lockfileSha256,
|
||||||
|
generatedAt: "2026-07-26T00:00:00.000Z",
|
||||||
|
findings: [],
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
await writeFile(
|
||||||
|
attestationPath,
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
provider: "fixture-attestor",
|
||||||
|
signer: "fixture-workload-identity",
|
||||||
|
subject: {
|
||||||
|
name: "dist",
|
||||||
|
digest: { sha256: verification.distSha256 },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
const providerRun = spawnSync(
|
||||||
|
"node",
|
||||||
|
["scripts/generate-supply-chain.mjs"],
|
||||||
|
{
|
||||||
|
env: {
|
||||||
|
...process.env,
|
||||||
|
VULNERABILITY_REPORT_PATH: vulnerabilityPath,
|
||||||
|
PROVENANCE_ATTESTATION_PATH: attestationPath,
|
||||||
|
},
|
||||||
|
encoding: "utf8",
|
||||||
|
},
|
||||||
|
);
|
||||||
|
let promotionStatus = "MISSING";
|
||||||
|
if (providerRun.status === 0) {
|
||||||
|
promotionStatus = JSON.parse(
|
||||||
|
await readFile(
|
||||||
|
"artifacts/security/supply-chain-verification.json",
|
||||||
|
"utf8",
|
||||||
|
),
|
||||||
|
).promotionStatus;
|
||||||
|
}
|
||||||
|
const restore = spawnSync(
|
||||||
|
"node",
|
||||||
|
["scripts/generate-supply-chain.mjs"],
|
||||||
|
{ encoding: "utf8" },
|
||||||
|
);
|
||||||
|
await rm(fixtureDirectory, { recursive: true, force: true });
|
||||||
|
const passed =
|
||||||
|
providerRun.status === 0 &&
|
||||||
|
promotionStatus === "PASS" &&
|
||||||
|
restore.status === 0;
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/security/supply-chain-provider-fixtures.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
providerAccepted: providerRun.status === 0,
|
||||||
|
promotionStatus,
|
||||||
|
unverifiedDefaultRestored: restore.status === 0,
|
||||||
|
status: passed ? "PASS" : "FAIL",
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
if (!passed) {
|
||||||
|
process.stderr.write(
|
||||||
|
`Supply-chain provider fixture failed: ${providerRun.stderr || restore.stderr}\n`,
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(
|
||||||
|
"Supply-chain provider fixture: verified PASS and unconfigured default restored\n",
|
||||||
|
);
|
||||||
@@ -15,7 +15,13 @@ const buildId = process.env.VITE_BUILD_ID ?? "local-build";
|
|||||||
const commitSha = process.env.VITE_COMMIT_SHA ?? "local";
|
const commitSha = process.env.VITE_COMMIT_SHA ?? "local";
|
||||||
const releaseId = process.env.RELEASE_ID ?? "local-release";
|
const releaseId = process.env.RELEASE_ID ?? "local-release";
|
||||||
const runnerImage = process.env.CI_RUNNER_IMAGE ?? `${process.platform}-${process.arch}`;
|
const runnerImage = process.env.CI_RUNNER_IMAGE ?? `${process.platform}-${process.arch}`;
|
||||||
const builtAt = new Date().toISOString();
|
const buildTime = process.env.SOURCE_DATE_EPOCH
|
||||||
|
? new Date(Number(process.env.SOURCE_DATE_EPOCH) * 1_000)
|
||||||
|
: new Date();
|
||||||
|
if (!Number.isFinite(buildTime.getTime())) {
|
||||||
|
throw new Error("SOURCE_DATE_EPOCH must be epoch seconds");
|
||||||
|
}
|
||||||
|
const builtAt = buildTime.toISOString();
|
||||||
const viteManifest = await readFile("dist/.vite/manifest.json", "utf8");
|
const viteManifest = await readFile("dist/.vite/manifest.json", "utf8");
|
||||||
const viteManifestObject =
|
const viteManifestObject =
|
||||||
/** @type {Record<string, {file: string, name?: string, isDynamicEntry?: boolean}>} */ (
|
/** @type {Record<string, {file: string, name?: string, isDynamicEntry?: boolean}>} */ (
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
|
import { spawnSync } from "node:child_process";
|
||||||
import { createHash } from "node:crypto";
|
import { createHash } from "node:crypto";
|
||||||
import { gzipSync } from "node:zlib";
|
import { gzipSync } from "node:zlib";
|
||||||
import {
|
import {
|
||||||
@@ -9,47 +10,404 @@ import {
|
|||||||
} from "node:fs/promises";
|
} from "node:fs/promises";
|
||||||
import path from "node:path";
|
import path from "node:path";
|
||||||
|
|
||||||
|
import {
|
||||||
|
diffDependencyInventories,
|
||||||
|
flattenPnpmDependencyTree,
|
||||||
|
isValidSha512Integrity,
|
||||||
|
parsePnpmLockfilePackages,
|
||||||
|
supplyChainDigest,
|
||||||
|
validateDependencyReview,
|
||||||
|
validateLicensePolicy,
|
||||||
|
validateVulnerabilityReport,
|
||||||
|
verifySupplyChainCoherence,
|
||||||
|
} from "./lib/supply-chain.mjs";
|
||||||
|
|
||||||
/** @param {string} directory @returns {Promise<string[]>} */
|
/** @param {string} directory @returns {Promise<string[]>} */
|
||||||
async function filesWithin(directory) {
|
async function filesWithin(directory) {
|
||||||
const entries = await readdir(directory, { withFileTypes: true });
|
try {
|
||||||
const nested = /** @type {string[][]} */ (await Promise.all(
|
const entries = await readdir(directory, { withFileTypes: true });
|
||||||
entries.map((entry) => {
|
const nested = /** @type {string[][]} */ (await Promise.all(
|
||||||
const target = path.join(directory, entry.name);
|
entries.map((entry) => {
|
||||||
return entry.isDirectory() ? filesWithin(target) : [target];
|
const target = path.join(directory, entry.name);
|
||||||
}),
|
return entry.isDirectory() ? filesWithin(target) : [target];
|
||||||
));
|
}),
|
||||||
return nested.flat().sort();
|
));
|
||||||
|
return nested.flat().sort();
|
||||||
|
} catch {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param {string} file */
|
||||||
|
async function sha256File(file) {
|
||||||
|
return createHash("sha256").update(await readFile(file)).digest("hex");
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param {string[]} files */
|
||||||
|
async function digestFileSet(files) {
|
||||||
|
const rows = await Promise.all(
|
||||||
|
files.sort().map(async (file) => ({
|
||||||
|
path: file.replaceAll("\\", "/"),
|
||||||
|
sha256: await sha256File(file),
|
||||||
|
})),
|
||||||
|
);
|
||||||
|
return supplyChainDigest(rows);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param {string} file @returns {Promise<Record<string, unknown> | null>} */
|
||||||
|
async function optionalJson(file) {
|
||||||
|
try {
|
||||||
|
return JSON.parse(await readFile(file, "utf8"));
|
||||||
|
} catch {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function buildDependencyInventory() {
|
||||||
|
const packageJson = JSON.parse(await readFile("package.json", "utf8"));
|
||||||
|
const lockfileText = await readFile("pnpm-lock.yaml", "utf8");
|
||||||
|
const lockfileSha256 = createHash("sha256")
|
||||||
|
.update(lockfileText)
|
||||||
|
.digest("hex");
|
||||||
|
const listed = spawnSync(
|
||||||
|
"corepack",
|
||||||
|
["pnpm", "list", "--json", "--depth", "Infinity"],
|
||||||
|
{
|
||||||
|
encoding: "utf8",
|
||||||
|
maxBuffer: 32 * 1024 * 1024,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
if (listed.status !== 0) {
|
||||||
|
throw new Error(`pnpm dependency graph failed: ${listed.stderr}`);
|
||||||
|
}
|
||||||
|
const roots = JSON.parse(listed.stdout);
|
||||||
|
const root = roots[0];
|
||||||
|
const flattened = await flattenPnpmDependencyTree(
|
||||||
|
root,
|
||||||
|
packageJson.dependencies ?? {},
|
||||||
|
packageJson.devDependencies ?? {},
|
||||||
|
);
|
||||||
|
const lockRows = parsePnpmLockfilePackages(lockfileText);
|
||||||
|
const lockByIdentity = new Map(
|
||||||
|
lockRows.map((row) => [`${row.name}@${row.version}`, row]),
|
||||||
|
);
|
||||||
|
const failures = [];
|
||||||
|
const dependencies = flattened.map((dependency) => {
|
||||||
|
const identity = `${dependency.name}@${dependency.version}`;
|
||||||
|
const lockRow = lockByIdentity.get(identity);
|
||||||
|
if (!lockRow) failures.push(`dependency missing from lockfile: ${identity}`);
|
||||||
|
if (lockRow && !isValidSha512Integrity(lockRow.integrity)) {
|
||||||
|
failures.push(`dependency has invalid sha512 integrity: ${identity}`);
|
||||||
|
}
|
||||||
|
return {
|
||||||
|
...dependency,
|
||||||
|
integrity: lockRow?.integrity ?? "missing",
|
||||||
|
};
|
||||||
|
});
|
||||||
|
const inventoryIds = new Set(
|
||||||
|
dependencies.map((dependency) => `${dependency.name}@${dependency.version}`),
|
||||||
|
);
|
||||||
|
for (const lockRow of lockRows) {
|
||||||
|
const identity = `${lockRow.name}@${lockRow.version}`;
|
||||||
|
if (!inventoryIds.has(identity)) {
|
||||||
|
failures.push(`transitive lockfile dependency omitted: ${identity}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (failures.length > 0) {
|
||||||
|
throw new Error(failures.join("\n"));
|
||||||
|
}
|
||||||
|
return {
|
||||||
|
schemaVersion: 2,
|
||||||
|
packageManager: packageJson.packageManager,
|
||||||
|
lockfileSha256,
|
||||||
|
dependencyCount: dependencies.length,
|
||||||
|
directDependencyCount: dependencies.filter((entry) => entry.direct).length,
|
||||||
|
dependencies,
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
const packageJson = JSON.parse(await readFile("package.json", "utf8"));
|
const packageJson = JSON.parse(await readFile("package.json", "utf8"));
|
||||||
const lockfile = await readFile("pnpm-lock.yaml");
|
|
||||||
const outputFiles = await filesWithin("dist");
|
const outputFiles = await filesWithin("dist");
|
||||||
|
if (outputFiles.length === 0) {
|
||||||
|
throw new Error("dist is missing; run the production build first");
|
||||||
|
}
|
||||||
const outputs = await Promise.all(
|
const outputs = await Promise.all(
|
||||||
outputFiles.map(async (outputFile) => {
|
outputFiles.map(async (outputFile) => {
|
||||||
const content = await readFile(outputFile);
|
const content = await readFile(outputFile);
|
||||||
const metadata = await stat(outputFile);
|
const metadata = await stat(outputFile);
|
||||||
return {
|
return {
|
||||||
path: outputFile,
|
path: outputFile.replaceAll("\\", "/"),
|
||||||
bytes: metadata.size,
|
bytes: metadata.size,
|
||||||
gzipBytes: gzipSync(content).byteLength,
|
gzipBytes: gzipSync(content).byteLength,
|
||||||
sha256: createHash("sha256").update(content).digest("hex"),
|
sha256: createHash("sha256").update(content).digest("hex"),
|
||||||
};
|
};
|
||||||
}),
|
}),
|
||||||
);
|
);
|
||||||
|
const distDigest = supplyChainDigest(
|
||||||
|
outputs.map(({ path: outputPath, bytes, sha256 }) => ({
|
||||||
|
path: outputPath,
|
||||||
|
bytes,
|
||||||
|
sha256,
|
||||||
|
})),
|
||||||
|
);
|
||||||
|
const inventory = await buildDependencyInventory();
|
||||||
|
const licensePolicy = JSON.parse(
|
||||||
|
await readFile("config/security/dependency-policy.json", "utf8"),
|
||||||
|
);
|
||||||
|
const licenseResult = validateLicensePolicy(inventory, licensePolicy);
|
||||||
|
|
||||||
const dependencies = {
|
const baseline = await optionalJson(
|
||||||
...packageJson.dependencies,
|
"config/security/dependency-baseline.json",
|
||||||
...packageJson.devDependencies,
|
);
|
||||||
|
const baselineApproval = await optionalJson(
|
||||||
|
"config/security/dependency-baseline.approval.json",
|
||||||
|
);
|
||||||
|
const dependencyEvidence = JSON.parse(
|
||||||
|
await readFile(
|
||||||
|
"config/security/dependency-change-evidence.json",
|
||||||
|
"utf8",
|
||||||
|
),
|
||||||
|
);
|
||||||
|
const skipsBaseline = process.argv.includes("--no-baseline");
|
||||||
|
const baselineFailures = [];
|
||||||
|
let dependencyDiff =
|
||||||
|
/** @type {ReturnType<typeof diffDependencyInventories>} */ ({
|
||||||
|
added: [],
|
||||||
|
removed: [],
|
||||||
|
changed: [],
|
||||||
|
upgrades: [],
|
||||||
|
});
|
||||||
|
let reviewResult =
|
||||||
|
/** @type {ReturnType<typeof validateDependencyReview>} */ ({
|
||||||
|
passed: skipsBaseline,
|
||||||
|
highRisk: [],
|
||||||
|
failures: skipsBaseline ? [] : ["dependency baseline unavailable"],
|
||||||
|
});
|
||||||
|
if (baseline && baselineApproval) {
|
||||||
|
const actualBaselineDigest = supplyChainDigest(baseline);
|
||||||
|
if (
|
||||||
|
baselineApproval.schemaVersion !== 1 ||
|
||||||
|
baselineApproval.snapshotDigest !== actualBaselineDigest ||
|
||||||
|
typeof baselineApproval.owner !== "string" ||
|
||||||
|
!baselineApproval.owner
|
||||||
|
) {
|
||||||
|
baselineFailures.push("dependency baseline approval digest mismatch");
|
||||||
|
}
|
||||||
|
dependencyDiff = diffDependencyInventories(baseline, inventory);
|
||||||
|
reviewResult = validateDependencyReview(
|
||||||
|
dependencyDiff,
|
||||||
|
inventory,
|
||||||
|
dependencyEvidence,
|
||||||
|
);
|
||||||
|
} else if (!skipsBaseline) {
|
||||||
|
baselineFailures.push("dependency baseline and approval are required");
|
||||||
|
}
|
||||||
|
|
||||||
|
const vulnerabilityPolicy = JSON.parse(
|
||||||
|
await readFile("config/security/vulnerability-policy.json", "utf8"),
|
||||||
|
);
|
||||||
|
const vulnerabilityExceptions = JSON.parse(
|
||||||
|
await readFile("config/security/vulnerability-exceptions.json", "utf8"),
|
||||||
|
);
|
||||||
|
const vulnerabilityInput = process.env.VULNERABILITY_REPORT_PATH
|
||||||
|
? await optionalJson(process.env.VULNERABILITY_REPORT_PATH)
|
||||||
|
: null;
|
||||||
|
const vulnerabilityResult = vulnerabilityInput
|
||||||
|
? validateVulnerabilityReport(
|
||||||
|
vulnerabilityInput,
|
||||||
|
vulnerabilityPolicy,
|
||||||
|
vulnerabilityExceptions,
|
||||||
|
inventory.lockfileSha256,
|
||||||
|
)
|
||||||
|
: {
|
||||||
|
passed: false,
|
||||||
|
failures: ["external vulnerability provider report is missing"],
|
||||||
|
blocking: [],
|
||||||
|
};
|
||||||
|
const vulnerabilityReport = {
|
||||||
|
schemaVersion: 1,
|
||||||
|
provider: vulnerabilityInput?.provider ?? "UNCONFIGURED",
|
||||||
|
scannedLockfileSha256:
|
||||||
|
vulnerabilityInput?.scannedLockfileSha256 ?? inventory.lockfileSha256,
|
||||||
|
status: vulnerabilityInput
|
||||||
|
? vulnerabilityResult.passed
|
||||||
|
? "PASS"
|
||||||
|
: "FAIL"
|
||||||
|
: "FAIL_UNVERIFIED",
|
||||||
|
findings: vulnerabilityInput?.findings ?? [],
|
||||||
|
exceptionsApplied:
|
||||||
|
vulnerabilityInput && vulnerabilityResult.passed
|
||||||
|
? vulnerabilityExceptions.exceptions
|
||||||
|
: [],
|
||||||
|
failures: vulnerabilityResult.failures,
|
||||||
|
blocking: vulnerabilityResult.blocking,
|
||||||
|
};
|
||||||
|
|
||||||
|
const sourceFiles = (
|
||||||
|
await Promise.all(
|
||||||
|
[
|
||||||
|
"src",
|
||||||
|
"scripts",
|
||||||
|
"config",
|
||||||
|
"public",
|
||||||
|
"schemas",
|
||||||
|
"package.json",
|
||||||
|
"pnpm-lock.yaml",
|
||||||
|
"vite.config.js",
|
||||||
|
].map(async (target) => {
|
||||||
|
try {
|
||||||
|
const metadata = await stat(target);
|
||||||
|
return metadata.isDirectory() ? filesWithin(target) : [target];
|
||||||
|
} catch {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
}),
|
||||||
|
)
|
||||||
|
).flat();
|
||||||
|
const sourceSetSha256 = await digestFileSet(sourceFiles);
|
||||||
|
|
||||||
|
const components = inventory.dependencies.map((dependency) => ({
|
||||||
|
type: "library",
|
||||||
|
"bom-ref": `pkg:npm/${encodeURIComponent(dependency.name)}@${dependency.version}`,
|
||||||
|
name: dependency.name,
|
||||||
|
version: dependency.version,
|
||||||
|
scope: dependency.optional ? "optional" : "required",
|
||||||
|
hashes: [
|
||||||
|
{
|
||||||
|
alg: "SHA-512",
|
||||||
|
content: dependency.integrity.slice("sha512-".length),
|
||||||
|
},
|
||||||
|
],
|
||||||
|
licenses:
|
||||||
|
dependency.license === "NOASSERTION"
|
||||||
|
? [{ expression: "NOASSERTION" }]
|
||||||
|
: [{ expression: dependency.license }],
|
||||||
|
properties: [
|
||||||
|
{ name: "ca:direct", value: String(dependency.direct) },
|
||||||
|
{ name: "ca:scope", value: dependency.scope },
|
||||||
|
],
|
||||||
|
}));
|
||||||
|
const serialSeed = supplyChainDigest({
|
||||||
|
lockfileSha256: inventory.lockfileSha256,
|
||||||
|
components: components.map((component) => component["bom-ref"]),
|
||||||
|
});
|
||||||
|
const sbom = {
|
||||||
|
bomFormat: "CycloneDX",
|
||||||
|
specVersion: "1.6",
|
||||||
|
serialNumber: `urn:uuid:${serialSeed.slice(0, 8)}-${serialSeed.slice(8, 12)}-${serialSeed.slice(12, 16)}-${serialSeed.slice(16, 20)}-${serialSeed.slice(20, 32)}`,
|
||||||
|
version: 1,
|
||||||
|
metadata: {
|
||||||
|
component: {
|
||||||
|
type: "application",
|
||||||
|
name: packageJson.name,
|
||||||
|
version: packageJson.version,
|
||||||
|
},
|
||||||
|
properties: [
|
||||||
|
{
|
||||||
|
name: "ca:lockfileSha256",
|
||||||
|
value: inventory.lockfileSha256,
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
components,
|
||||||
|
dependencies: inventory.dependencies.map((dependency) => ({
|
||||||
|
ref: `pkg:npm/${encodeURIComponent(dependency.name)}@${dependency.version}`,
|
||||||
|
dependsOn: dependency.dependencies.map((identity) => {
|
||||||
|
const separator = identity.lastIndexOf("@");
|
||||||
|
return `pkg:npm/${encodeURIComponent(identity.slice(0, separator))}@${identity.slice(separator + 1)}`;
|
||||||
|
}),
|
||||||
|
})),
|
||||||
|
};
|
||||||
|
|
||||||
|
const provenance = {
|
||||||
|
_type: "https://in-toto.io/Statement/v1",
|
||||||
|
subject: [{ name: "dist", digest: { sha256: distDigest } }],
|
||||||
|
predicateType: "https://slsa.dev/provenance/v1",
|
||||||
|
predicate: {
|
||||||
|
buildDefinition: {
|
||||||
|
buildType: "https://vite.dev/build/v1",
|
||||||
|
externalParameters: {
|
||||||
|
nodeVersion: process.version,
|
||||||
|
packageManager: packageJson.packageManager,
|
||||||
|
},
|
||||||
|
internalParameters: {
|
||||||
|
sourceSetSha256,
|
||||||
|
},
|
||||||
|
resolvedDependencies: [
|
||||||
|
{
|
||||||
|
uri: "pnpm-lock.yaml",
|
||||||
|
digest: { sha256: inventory.lockfileSha256 },
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
runDetails: {
|
||||||
|
builder: { id: "local:clean-architecture-frontend-template" },
|
||||||
|
metadata: { invocationId: "LOCAL_UNSIGNED" },
|
||||||
|
},
|
||||||
|
materials: {
|
||||||
|
lockfileSha256: inventory.lockfileSha256,
|
||||||
|
sourceSetSha256,
|
||||||
|
sbomSha256: supplyChainDigest(sbom),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
};
|
||||||
|
const coherence = verifySupplyChainCoherence(
|
||||||
|
sbom,
|
||||||
|
inventory,
|
||||||
|
provenance,
|
||||||
|
distDigest,
|
||||||
|
);
|
||||||
|
|
||||||
|
const attestationInput = process.env.PROVENANCE_ATTESTATION_PATH
|
||||||
|
? await optionalJson(process.env.PROVENANCE_ATTESTATION_PATH)
|
||||||
|
: null;
|
||||||
|
const attestationSubject =
|
||||||
|
/** @type {Record<string, unknown>} */ (
|
||||||
|
/** @type {Record<string, unknown>} */ (
|
||||||
|
attestationInput?.subject ?? {}
|
||||||
|
).digest ?? {}
|
||||||
|
);
|
||||||
|
const attestationPassed =
|
||||||
|
attestationSubject.sha256 === distDigest &&
|
||||||
|
typeof attestationInput?.provider === "string" &&
|
||||||
|
Boolean(attestationInput.provider) &&
|
||||||
|
typeof attestationInput?.signer === "string" &&
|
||||||
|
Boolean(attestationInput.signer);
|
||||||
|
const localFailures = [
|
||||||
|
...licenseResult.failures,
|
||||||
|
...baselineFailures,
|
||||||
|
...reviewResult.failures,
|
||||||
|
...coherence.failures,
|
||||||
|
];
|
||||||
|
if (vulnerabilityInput && !vulnerabilityResult.passed) {
|
||||||
|
localFailures.push(
|
||||||
|
...vulnerabilityResult.failures,
|
||||||
|
...vulnerabilityResult.blocking,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
const localPassed = localFailures.length === 0;
|
||||||
|
const promotionPassed =
|
||||||
|
localPassed && vulnerabilityResult.passed && attestationPassed;
|
||||||
|
const verification = {
|
||||||
|
schemaVersion: 1,
|
||||||
|
localStatus: localPassed ? "PASS" : "FAIL",
|
||||||
|
promotionStatus: promotionPassed ? "PASS" : "FAIL_UNVERIFIED",
|
||||||
|
lockfileSha256: inventory.lockfileSha256,
|
||||||
|
sourceSetSha256,
|
||||||
|
distSha256: distDigest,
|
||||||
|
sbomSha256: supplyChainDigest(sbom),
|
||||||
|
dependencyDiff,
|
||||||
|
highRiskReview: reviewResult.highRisk,
|
||||||
|
vulnerabilityStatus: vulnerabilityReport.status,
|
||||||
|
provenanceAttestationStatus: attestationPassed
|
||||||
|
? "PASS"
|
||||||
|
: "FAIL_UNVERIFIED",
|
||||||
|
failures: localFailures,
|
||||||
};
|
};
|
||||||
const inventory = Object.entries(dependencies)
|
|
||||||
.sort(([left], [right]) => left.localeCompare(right))
|
|
||||||
.map(([name, version]) => ({ name, version, direct: true }));
|
|
||||||
|
|
||||||
await mkdir("artifacts/performance", { recursive: true });
|
await mkdir("artifacts/performance", { recursive: true });
|
||||||
await mkdir("artifacts/release", { recursive: true });
|
await mkdir("artifacts/release", { recursive: true });
|
||||||
await mkdir("artifacts/security", { recursive: true });
|
await mkdir("artifacts/security", { recursive: true });
|
||||||
|
|
||||||
await writeFile(
|
await writeFile(
|
||||||
"artifacts/performance/bundle.json",
|
"artifacts/performance/bundle.json",
|
||||||
`${JSON.stringify(
|
`${JSON.stringify(
|
||||||
@@ -59,7 +417,8 @@ await writeFile(
|
|||||||
context: {
|
context: {
|
||||||
nodeVersion: process.version,
|
nodeVersion: process.version,
|
||||||
packageManager: packageJson.packageManager,
|
packageManager: packageJson.packageManager,
|
||||||
runnerImage: process.env.CI_RUNNER_IMAGE ?? `${process.platform}-${process.arch}`,
|
runnerImage:
|
||||||
|
process.env.CI_RUNNER_IMAGE ?? `${process.platform}-${process.arch}`,
|
||||||
},
|
},
|
||||||
outputs,
|
outputs,
|
||||||
},
|
},
|
||||||
@@ -67,36 +426,66 @@ await writeFile(
|
|||||||
2,
|
2,
|
||||||
)}\n`,
|
)}\n`,
|
||||||
);
|
);
|
||||||
|
|
||||||
await writeFile(
|
await writeFile(
|
||||||
"artifacts/release/dependency-inventory.json",
|
"artifacts/release/dependency-inventory.json",
|
||||||
`${JSON.stringify(
|
`${JSON.stringify(inventory, null, 2)}\n`,
|
||||||
{
|
);
|
||||||
schemaVersion: 1,
|
await writeFile(
|
||||||
lockfileSha256: createHash("sha256").update(lockfile).digest("hex"),
|
"artifacts/release/sbom.cdx.json",
|
||||||
dependencies: inventory,
|
`${JSON.stringify(sbom, null, 2)}\n`,
|
||||||
},
|
);
|
||||||
null,
|
await writeFile(
|
||||||
2,
|
"artifacts/release/provenance.json",
|
||||||
)}\n`,
|
`${JSON.stringify(provenance, null, 2)}\n`,
|
||||||
);
|
);
|
||||||
|
|
||||||
await writeFile(
|
await writeFile(
|
||||||
"artifacts/release/checksums.txt",
|
"artifacts/release/checksums.txt",
|
||||||
`${outputs.map((output) => `${output.sha256} ${output.path}`).join("\n")}\n`,
|
`${outputs.map((output) => `${output.sha256} ${output.path}`).join("\n")}\n`,
|
||||||
);
|
);
|
||||||
|
|
||||||
await writeFile(
|
await writeFile(
|
||||||
"artifacts/security/dependency-diff.json",
|
"artifacts/security/dependency-diff.json",
|
||||||
`${JSON.stringify(
|
`${JSON.stringify(
|
||||||
{
|
{
|
||||||
schemaVersion: 1,
|
schemaVersion: 2,
|
||||||
reviewStatus: "local-baseline",
|
baselineDigest: baseline ? supplyChainDigest(baseline) : null,
|
||||||
directDependencies: inventory.length,
|
currentDigest: supplyChainDigest(inventory),
|
||||||
highRiskUnreviewed: [],
|
...dependencyDiff,
|
||||||
lockfileSha256: createHash("sha256").update(lockfile).digest("hex"),
|
highRisk: reviewResult.highRisk,
|
||||||
|
reviewFailures: reviewResult.failures,
|
||||||
},
|
},
|
||||||
null,
|
null,
|
||||||
2,
|
2,
|
||||||
)}\n`,
|
)}\n`,
|
||||||
);
|
);
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/security/license-report.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
status: licenseResult.passed ? "PASS" : "FAIL",
|
||||||
|
dependencyCount: inventory.dependencyCount,
|
||||||
|
results: licenseResult.results,
|
||||||
|
failures: licenseResult.failures,
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/security/vulnerability-report.json",
|
||||||
|
`${JSON.stringify(vulnerabilityReport, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/security/supply-chain-verification.json",
|
||||||
|
`${JSON.stringify(verification, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!localPassed) {
|
||||||
|
process.stderr.write(
|
||||||
|
`Local supply-chain verification failed:\n- ${localFailures.join("\n- ")}\n`,
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(
|
||||||
|
`Supply chain: LOCAL PASS (${inventory.dependencyCount} dependencies); promotion=${verification.promotionStatus}\n`,
|
||||||
|
);
|
||||||
|
|||||||
@@ -0,0 +1,265 @@
|
|||||||
|
import { readFile, readdir } from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
|
export const REQUIRED_RECIPE_IDS = Object.freeze([
|
||||||
|
"analytics-error-sink",
|
||||||
|
"browser-permission",
|
||||||
|
"client-workflow",
|
||||||
|
"feature-flag",
|
||||||
|
"file-transfer",
|
||||||
|
"generated-api",
|
||||||
|
"large-data-ui",
|
||||||
|
"multi-tab",
|
||||||
|
"offline-indexeddb",
|
||||||
|
"realtime",
|
||||||
|
"service-worker-pwa",
|
||||||
|
"web-worker",
|
||||||
|
]);
|
||||||
|
|
||||||
|
const lifecycleRecipes = new Set([
|
||||||
|
"analytics-error-sink",
|
||||||
|
"browser-permission",
|
||||||
|
"client-workflow",
|
||||||
|
"file-transfer",
|
||||||
|
"generated-api",
|
||||||
|
"multi-tab",
|
||||||
|
"offline-indexeddb",
|
||||||
|
"realtime",
|
||||||
|
"service-worker-pwa",
|
||||||
|
"web-worker",
|
||||||
|
]);
|
||||||
|
|
||||||
|
/** @param {unknown} value */
|
||||||
|
function nonEmptyStrings(value) {
|
||||||
|
return (
|
||||||
|
Array.isArray(value) &&
|
||||||
|
value.length > 0 &&
|
||||||
|
value.every((entry) => typeof entry === "string" && entry.trim().length > 0)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {unknown} input
|
||||||
|
* @param {Readonly<Record<string, unknown>>} packageDocument
|
||||||
|
* @returns {string[]}
|
||||||
|
*/
|
||||||
|
export function validateRecipeCatalog(input, packageDocument) {
|
||||||
|
const document =
|
||||||
|
/** @type {Record<string, any>} */ (
|
||||||
|
input && typeof input === "object" ? input : {}
|
||||||
|
);
|
||||||
|
/** @type {string[]} */
|
||||||
|
const violations = [];
|
||||||
|
if (document.schemaVersion !== 1) violations.push("CATALOG_SCHEMA_VERSION");
|
||||||
|
if (document.decisionId !== "VD-10") violations.push("CATALOG_DECISION");
|
||||||
|
if (document.defaultStatus !== "NOT_INSTALLED") {
|
||||||
|
violations.push("CATALOG_DEFAULT_MUST_BE_NOT_INSTALLED");
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
!Array.isArray(document.productionRuntimeDependencies) ||
|
||||||
|
document.productionRuntimeDependencies.length > 0
|
||||||
|
) {
|
||||||
|
violations.push("UNSELECTED_RUNTIME_DEPENDENCY");
|
||||||
|
}
|
||||||
|
if (!nonEmptyStrings(document.vendorPackagePatterns)) {
|
||||||
|
violations.push("VENDOR_PATTERN_CATALOG");
|
||||||
|
}
|
||||||
|
if (!Array.isArray(document.recipes)) {
|
||||||
|
return [...violations, "RECIPE_CATALOG_MISSING"];
|
||||||
|
}
|
||||||
|
|
||||||
|
const actualIds = document.recipes
|
||||||
|
.map(/** @param {Record<string, unknown>} recipe */ (recipe) => recipe.id)
|
||||||
|
.sort();
|
||||||
|
if (JSON.stringify(actualIds) !== JSON.stringify(REQUIRED_RECIPE_IDS)) {
|
||||||
|
violations.push("RECIPE_ID_SET");
|
||||||
|
}
|
||||||
|
if (new Set(actualIds).size !== actualIds.length) {
|
||||||
|
violations.push("RECIPE_ID_DUPLICATE");
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const recipe of document.recipes) {
|
||||||
|
const id = typeof recipe.id === "string" ? recipe.id : "unknown";
|
||||||
|
if (recipe.status !== "RECIPE_AVAILABLE") {
|
||||||
|
violations.push(`${id}:STATUS_MUST_NOT_CLAIM_INSTALLED`);
|
||||||
|
}
|
||||||
|
for (const field of [
|
||||||
|
"trigger",
|
||||||
|
"boundary",
|
||||||
|
"port",
|
||||||
|
"fake",
|
||||||
|
"owner",
|
||||||
|
"fallback",
|
||||||
|
"serverStatePolicy",
|
||||||
|
]) {
|
||||||
|
if (typeof recipe[field] !== "string" || recipe[field].trim().length === 0) {
|
||||||
|
violations.push(`${id}:MISSING_${field.toUpperCase()}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for (const field of [
|
||||||
|
"forbiddenWhen",
|
||||||
|
"failureKinds",
|
||||||
|
"securityPrivacy",
|
||||||
|
"removal",
|
||||||
|
]) {
|
||||||
|
if (!nonEmptyStrings(recipe[field])) {
|
||||||
|
violations.push(`${id}:MISSING_${field.toUpperCase()}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
!Number.isInteger(recipe.bundleBudgetGzipBytes) ||
|
||||||
|
recipe.bundleBudgetGzipBytes < 1
|
||||||
|
) {
|
||||||
|
violations.push(`${id}:INVALID_BUNDLE_BUDGET`);
|
||||||
|
}
|
||||||
|
if (recipe.owner === "frontend-platform") {
|
||||||
|
violations.push(`${id}:PROJECT_OWNER_NOT_ASSIGNED`);
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
lifecycleRecipes.has(id) &&
|
||||||
|
!nonEmptyStrings(recipe.lifecycleMethods)
|
||||||
|
) {
|
||||||
|
violations.push(`${id}:CLEANUP_CONTRACT_MISSING`);
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
id === "client-workflow" &&
|
||||||
|
recipe.serverStatePolicy !== "reference-only"
|
||||||
|
) {
|
||||||
|
violations.push(`${id}:SERVER_STATE_DUPLICATION_POLICY`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const dependencies = {
|
||||||
|
.../** @type {Record<string, string>} */ (packageDocument.dependencies ?? {}),
|
||||||
|
.../** @type {Record<string, string>} */ (
|
||||||
|
packageDocument.devDependencies ?? {}
|
||||||
|
),
|
||||||
|
};
|
||||||
|
for (const pattern of document.vendorPackagePatterns ?? []) {
|
||||||
|
const wildcard = String(pattern).endsWith("*");
|
||||||
|
const prefix = String(pattern).replace(/\/?\*$/, "");
|
||||||
|
if (
|
||||||
|
Object.keys(dependencies).some(
|
||||||
|
(dependency) =>
|
||||||
|
dependency === prefix ||
|
||||||
|
dependency.startsWith(`${prefix}/`) ||
|
||||||
|
(wildcard && dependency.startsWith(prefix)),
|
||||||
|
)
|
||||||
|
) {
|
||||||
|
violations.push(`UNSELECTED_VENDOR_INSTALLED:${prefix}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return violations;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param {string} directory @returns {Promise<string[]>} */
|
||||||
|
export async function sourceFiles(directory) {
|
||||||
|
let entries;
|
||||||
|
try {
|
||||||
|
entries = await readdir(directory, { withFileTypes: true });
|
||||||
|
} catch (error) {
|
||||||
|
if (
|
||||||
|
error &&
|
||||||
|
typeof error === "object" &&
|
||||||
|
"code" in error &&
|
||||||
|
error.code === "ENOENT"
|
||||||
|
) {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
throw error;
|
||||||
|
}
|
||||||
|
const groups = await Promise.all(
|
||||||
|
entries.map((entry) => {
|
||||||
|
const target = path.join(directory, entry.name);
|
||||||
|
return entry.isDirectory()
|
||||||
|
? sourceFiles(target)
|
||||||
|
: /\.(?:js|jsx|mjs|ts|tsx|mts)$/.test(entry.name)
|
||||||
|
? [target]
|
||||||
|
: [];
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
return groups.flat();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {string} root
|
||||||
|
* @param {{scanProductionBoundary?: boolean}} [options]
|
||||||
|
*/
|
||||||
|
export async function scanOptionalRecipeSources(
|
||||||
|
root,
|
||||||
|
{ scanProductionBoundary = true } = {},
|
||||||
|
) {
|
||||||
|
/** @type {Array<{ruleId: string; path: string}>} */
|
||||||
|
const violations = [];
|
||||||
|
for (const file of await sourceFiles(root)) {
|
||||||
|
const relative = path.relative(process.cwd(), file).replaceAll("\\", "/");
|
||||||
|
const relativeToRoot = path.relative(root, file).replaceAll("\\", "/");
|
||||||
|
const content = await readFile(file, "utf8");
|
||||||
|
const imports = [
|
||||||
|
...content.matchAll(
|
||||||
|
/(?:from\s*|import\s*\(\s*)["']([^"']+)["']/g,
|
||||||
|
),
|
||||||
|
].map((match) => match[1]);
|
||||||
|
|
||||||
|
if (
|
||||||
|
scanProductionBoundary &&
|
||||||
|
(relativeToRoot.startsWith("src/") ||
|
||||||
|
(path.basename(path.resolve(root)) === "src" &&
|
||||||
|
!relativeToRoot.startsWith(".."))) &&
|
||||||
|
imports.some((specifier) =>
|
||||||
|
/(?:^|\/)recipes\/frontend-capabilities(?:\/|$)/.test(specifier),
|
||||||
|
)
|
||||||
|
) {
|
||||||
|
violations.push({ ruleId: "PRODUCTION_IMPORTS_RECIPE", path: relative });
|
||||||
|
}
|
||||||
|
|
||||||
|
const localVendorAdapter =
|
||||||
|
relative.includes("recipes/") && relative.includes("/adapters/");
|
||||||
|
if (
|
||||||
|
!localVendorAdapter &&
|
||||||
|
imports.some((specifier) =>
|
||||||
|
/^(?:@launchdarkly\/|@sentry\/|@opentelemetry\/|@openapitools\/openapi-generator-cli$|@reduxjs\/toolkit$|@tanstack\/react-virtual$|@uppy\/|firebase(?:\/|$)|idb$|react-window$|redux(?:\/|$)|socket\.io-client$|tus-js-client$|workbox-window$|xstate$|zustand$)/.test(
|
||||||
|
specifier,
|
||||||
|
),
|
||||||
|
)
|
||||||
|
) {
|
||||||
|
violations.push({ ruleId: "VENDOR_IMPORT_OUTSIDE_ADAPTER", path: relative });
|
||||||
|
}
|
||||||
|
|
||||||
|
if (
|
||||||
|
/localStorage\s*\.\s*(?:setItem|getItem)\s*\([^)]*(?:credential|password|secret|token)/is.test(
|
||||||
|
content,
|
||||||
|
) ||
|
||||||
|
/searchParams\s*\.\s*set\s*\(\s*["'](?:credential|password|secret|token)/is.test(
|
||||||
|
content,
|
||||||
|
) ||
|
||||||
|
/(?:record|track|emit)\s*\(\s*\{[\s\S]{0,400}(?:credential|password|secret|token)\s*:/i.test(
|
||||||
|
content,
|
||||||
|
)
|
||||||
|
) {
|
||||||
|
violations.push({ ruleId: "CREDENTIAL_LEAK_PATH", path: relative });
|
||||||
|
}
|
||||||
|
|
||||||
|
if (
|
||||||
|
/(?:createStore|configureStore|create\s*\()\s*\([\s\S]{0,600}(?:apiResponse|queryData|serverState)\s*:/i.test(
|
||||||
|
content,
|
||||||
|
)
|
||||||
|
) {
|
||||||
|
violations.push({ ruleId: "CLIENT_STORE_DUPLICATES_SERVER_STATE", path: relative });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return violations;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param {string} distRoot */
|
||||||
|
export async function scanProductionBundle(distRoot) {
|
||||||
|
/** @type {string[]} */
|
||||||
|
const violations = [];
|
||||||
|
for (const file of await sourceFiles(distRoot)) {
|
||||||
|
const content = await readFile(file, "utf8");
|
||||||
|
if (content.includes("frontend-optional-recipe-must-not-reach-production")) {
|
||||||
|
violations.push(path.relative(process.cwd(), file));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return violations;
|
||||||
|
}
|
||||||
@@ -0,0 +1,547 @@
|
|||||||
|
import { createHash } from "node:crypto";
|
||||||
|
import { readFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
/** @param {unknown} value @returns {unknown} */
|
||||||
|
export function canonicalizeSupplyChainValue(value) {
|
||||||
|
if (Array.isArray(value)) {
|
||||||
|
return value
|
||||||
|
.map(canonicalizeSupplyChainValue)
|
||||||
|
.sort((left, right) =>
|
||||||
|
JSON.stringify(left).localeCompare(JSON.stringify(right)),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if (value && typeof value === "object") {
|
||||||
|
return Object.fromEntries(
|
||||||
|
Object.entries(value)
|
||||||
|
.sort(([left], [right]) => left.localeCompare(right))
|
||||||
|
.map(([key, item]) => [key, canonicalizeSupplyChainValue(item)]),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return value;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param {unknown} value */
|
||||||
|
export function supplyChainDigest(value) {
|
||||||
|
return createHash("sha256")
|
||||||
|
.update(JSON.stringify(canonicalizeSupplyChainValue(value)))
|
||||||
|
.digest("hex");
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param {string} lockfile */
|
||||||
|
export function parsePnpmLockfilePackages(lockfile) {
|
||||||
|
const entries =
|
||||||
|
/** @type {Array<{name: string, version: string, integrity: string}>} */ (
|
||||||
|
[]
|
||||||
|
);
|
||||||
|
let inPackages = false;
|
||||||
|
/** @type {{name: string, version: string, integrity: string} | null} */
|
||||||
|
let current = null;
|
||||||
|
|
||||||
|
for (const line of lockfile.split(/\r?\n/)) {
|
||||||
|
if (line === "packages:") {
|
||||||
|
inPackages = true;
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if (line === "snapshots:") {
|
||||||
|
if (current) entries.push(current);
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
if (!inPackages) continue;
|
||||||
|
const packageMatch = line.match(/^ {2}(\S.*):$/);
|
||||||
|
if (packageMatch) {
|
||||||
|
if (current) entries.push(current);
|
||||||
|
const key = packageMatch[1].replace(/^['"]|['"]$/g, "");
|
||||||
|
const separator = key.lastIndexOf("@");
|
||||||
|
current = {
|
||||||
|
name: key.slice(0, separator),
|
||||||
|
version: key.slice(separator + 1),
|
||||||
|
integrity: "",
|
||||||
|
};
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
const integrityMatch = line.match(/\bintegrity:\s*([^,}\s]+)/);
|
||||||
|
if (current && integrityMatch) {
|
||||||
|
current.integrity = integrityMatch[1];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return entries.sort((left, right) =>
|
||||||
|
`${left.name}@${left.version}`.localeCompare(
|
||||||
|
`${right.name}@${right.version}`,
|
||||||
|
),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param {string} integrity */
|
||||||
|
export function isValidSha512Integrity(integrity) {
|
||||||
|
if (!integrity.startsWith("sha512-")) return false;
|
||||||
|
try {
|
||||||
|
return Buffer.from(integrity.slice("sha512-".length), "base64").length === 64;
|
||||||
|
} catch {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {unknown} raw
|
||||||
|
* @returns {string}
|
||||||
|
*/
|
||||||
|
export function normalizeLicense(raw) {
|
||||||
|
if (typeof raw === "string" && raw.trim()) return raw.trim();
|
||||||
|
if (
|
||||||
|
raw &&
|
||||||
|
typeof raw === "object" &&
|
||||||
|
"type" in raw &&
|
||||||
|
typeof raw.type === "string"
|
||||||
|
) {
|
||||||
|
return raw.type;
|
||||||
|
}
|
||||||
|
if (Array.isArray(raw)) {
|
||||||
|
const licenses = raw.map(normalizeLicense).filter(
|
||||||
|
(license) => license !== "NOASSERTION",
|
||||||
|
);
|
||||||
|
return licenses.length > 0 ? licenses.join(" OR ") : "NOASSERTION";
|
||||||
|
}
|
||||||
|
return "NOASSERTION";
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {Record<string, unknown>} root
|
||||||
|
* @param {Readonly<Record<string, string>>} directProduction
|
||||||
|
* @param {Readonly<Record<string, string>>} directDevelopment
|
||||||
|
*/
|
||||||
|
export async function flattenPnpmDependencyTree(
|
||||||
|
root,
|
||||||
|
directProduction,
|
||||||
|
directDevelopment,
|
||||||
|
) {
|
||||||
|
const records =
|
||||||
|
/** @type {Map<string, {
|
||||||
|
* name: string,
|
||||||
|
* version: string,
|
||||||
|
* direct: boolean,
|
||||||
|
* scope: "production" | "development",
|
||||||
|
* optional: boolean,
|
||||||
|
* packagePath: string,
|
||||||
|
* dependencies: Set<string>
|
||||||
|
* }>} */ (new Map());
|
||||||
|
const directIds = new Set();
|
||||||
|
for (const [name, rawDependency] of Object.entries(
|
||||||
|
/** @type {Record<string, unknown>} */ (root.dependencies ?? {}),
|
||||||
|
)) {
|
||||||
|
if (
|
||||||
|
Object.hasOwn(directProduction, name) &&
|
||||||
|
rawDependency &&
|
||||||
|
typeof rawDependency === "object" &&
|
||||||
|
!Array.isArray(rawDependency)
|
||||||
|
) {
|
||||||
|
directIds.add(
|
||||||
|
`${name}@${String(
|
||||||
|
/** @type {Record<string, unknown>} */ (rawDependency).version ?? "",
|
||||||
|
)}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for (const [name, rawDependency] of Object.entries(
|
||||||
|
/** @type {Record<string, unknown>} */ (root.devDependencies ?? {}),
|
||||||
|
)) {
|
||||||
|
if (
|
||||||
|
Object.hasOwn(directDevelopment, name) &&
|
||||||
|
rawDependency &&
|
||||||
|
typeof rawDependency === "object" &&
|
||||||
|
!Array.isArray(rawDependency)
|
||||||
|
) {
|
||||||
|
directIds.add(
|
||||||
|
`${name}@${String(
|
||||||
|
/** @type {Record<string, unknown>} */ (rawDependency).version ?? "",
|
||||||
|
)}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {Record<string, unknown>} node
|
||||||
|
* @param {"production" | "development"} scope
|
||||||
|
* @param {boolean} optionalPath
|
||||||
|
*/
|
||||||
|
function visit(node, scope, optionalPath) {
|
||||||
|
for (const [groupName, group] of Object.entries({
|
||||||
|
dependencies: node.dependencies,
|
||||||
|
devDependencies: node.devDependencies,
|
||||||
|
optionalDependencies: node.optionalDependencies,
|
||||||
|
})) {
|
||||||
|
if (!group || typeof group !== "object" || Array.isArray(group)) continue;
|
||||||
|
for (const [name, rawDependency] of Object.entries(group)) {
|
||||||
|
if (
|
||||||
|
!rawDependency ||
|
||||||
|
typeof rawDependency !== "object" ||
|
||||||
|
Array.isArray(rawDependency)
|
||||||
|
) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
const dependency =
|
||||||
|
/** @type {Record<string, unknown>} */ (rawDependency);
|
||||||
|
const version = String(dependency.version ?? "");
|
||||||
|
const packagePath = String(dependency.path ?? "");
|
||||||
|
const identity = `${name}@${version}`;
|
||||||
|
const childScope =
|
||||||
|
scope === "production" && groupName !== "devDependencies"
|
||||||
|
? "production"
|
||||||
|
: "development";
|
||||||
|
const childOptional =
|
||||||
|
optionalPath || groupName === "optionalDependencies";
|
||||||
|
const previous = records.get(identity);
|
||||||
|
const dependencies = previous?.dependencies ?? new Set();
|
||||||
|
for (const childGroup of [
|
||||||
|
dependency.dependencies,
|
||||||
|
dependency.optionalDependencies,
|
||||||
|
]) {
|
||||||
|
if (
|
||||||
|
!childGroup ||
|
||||||
|
typeof childGroup !== "object" ||
|
||||||
|
Array.isArray(childGroup)
|
||||||
|
) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
for (const [childName, rawChild] of Object.entries(childGroup)) {
|
||||||
|
if (
|
||||||
|
rawChild &&
|
||||||
|
typeof rawChild === "object" &&
|
||||||
|
!Array.isArray(rawChild)
|
||||||
|
) {
|
||||||
|
dependencies.add(
|
||||||
|
`${childName}@${String(rawChild.version ?? "")}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
records.set(identity, {
|
||||||
|
name,
|
||||||
|
version,
|
||||||
|
direct: directIds.has(identity),
|
||||||
|
scope:
|
||||||
|
previous?.scope === "production" || childScope === "production"
|
||||||
|
? "production"
|
||||||
|
: "development",
|
||||||
|
optional: previous ? previous.optional && childOptional : childOptional,
|
||||||
|
packagePath: previous?.packagePath || packagePath,
|
||||||
|
dependencies,
|
||||||
|
});
|
||||||
|
visit(dependency, childScope, childOptional);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const productionRoot = {
|
||||||
|
dependencies: Object.fromEntries(
|
||||||
|
Object.entries(
|
||||||
|
/** @type {Record<string, unknown>} */ (root.dependencies ?? {}),
|
||||||
|
).filter(([name]) => Object.hasOwn(directProduction, name)),
|
||||||
|
),
|
||||||
|
};
|
||||||
|
const developmentRoot = {
|
||||||
|
devDependencies: Object.fromEntries(
|
||||||
|
Object.entries(
|
||||||
|
/** @type {Record<string, unknown>} */ (root.devDependencies ?? {}),
|
||||||
|
).filter(([name]) => Object.hasOwn(directDevelopment, name)),
|
||||||
|
),
|
||||||
|
};
|
||||||
|
visit(productionRoot, "production", false);
|
||||||
|
visit(developmentRoot, "development", false);
|
||||||
|
|
||||||
|
const result = [];
|
||||||
|
for (const record of records.values()) {
|
||||||
|
let license = "NOASSERTION";
|
||||||
|
let optional = record.optional;
|
||||||
|
if (record.packagePath) {
|
||||||
|
try {
|
||||||
|
const manifest = JSON.parse(
|
||||||
|
await readFile(`${record.packagePath}/package.json`, "utf8"),
|
||||||
|
);
|
||||||
|
license = normalizeLicense(manifest.license ?? manifest.licenses);
|
||||||
|
} catch {
|
||||||
|
// Platform-specific optional packages may not be materialized locally.
|
||||||
|
optional = true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
result.push({
|
||||||
|
name: record.name,
|
||||||
|
version: record.version,
|
||||||
|
direct: record.direct,
|
||||||
|
scope: record.scope,
|
||||||
|
optional,
|
||||||
|
license,
|
||||||
|
dependencies: [...record.dependencies].sort(),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
return result.sort((left, right) =>
|
||||||
|
`${left.name}@${left.version}`.localeCompare(
|
||||||
|
`${right.name}@${right.version}`,
|
||||||
|
),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {Readonly<Record<string, unknown>>} before
|
||||||
|
* @param {Readonly<Record<string, unknown>>} after
|
||||||
|
*/
|
||||||
|
export function diffDependencyInventories(before, after) {
|
||||||
|
const beforeRows =
|
||||||
|
/** @type {Array<Record<string, unknown>>} */ (before.dependencies ?? []);
|
||||||
|
const afterRows =
|
||||||
|
/** @type {Array<Record<string, unknown>>} */ (after.dependencies ?? []);
|
||||||
|
const beforeMap = new Map(
|
||||||
|
beforeRows.map((row) => [`${row.name}@${row.version}`, row]),
|
||||||
|
);
|
||||||
|
const afterMap = new Map(
|
||||||
|
afterRows.map((row) => [`${row.name}@${row.version}`, row]),
|
||||||
|
);
|
||||||
|
const added = [...afterMap.keys()].filter((key) => !beforeMap.has(key));
|
||||||
|
const removed = [...beforeMap.keys()].filter((key) => !afterMap.has(key));
|
||||||
|
const changed = [];
|
||||||
|
for (const key of [...beforeMap.keys()].filter((item) => afterMap.has(item))) {
|
||||||
|
if (
|
||||||
|
supplyChainDigest(beforeMap.get(key)) !==
|
||||||
|
supplyChainDigest(afterMap.get(key))
|
||||||
|
) {
|
||||||
|
changed.push(key);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
const upgrades = [];
|
||||||
|
for (const removedKey of removed) {
|
||||||
|
const previous = beforeMap.get(removedKey);
|
||||||
|
const replacement = added.find(
|
||||||
|
(addedKey) => afterMap.get(addedKey)?.name === previous?.name,
|
||||||
|
);
|
||||||
|
if (replacement) {
|
||||||
|
upgrades.push({
|
||||||
|
name: previous?.name,
|
||||||
|
from: previous?.version,
|
||||||
|
to: afterMap.get(replacement)?.version,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return Object.freeze({
|
||||||
|
added: Object.freeze(added.sort()),
|
||||||
|
removed: Object.freeze(removed.sort()),
|
||||||
|
changed: Object.freeze(changed.sort()),
|
||||||
|
upgrades: Object.freeze(
|
||||||
|
upgrades.sort((left, right) =>
|
||||||
|
String(left.name).localeCompare(String(right.name)),
|
||||||
|
),
|
||||||
|
),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {Readonly<Record<string, unknown>>} inventory
|
||||||
|
* @param {Readonly<Record<string, unknown>>} policy
|
||||||
|
*/
|
||||||
|
export function validateLicensePolicy(inventory, policy) {
|
||||||
|
const allowed = new Set(
|
||||||
|
/** @type {string[]} */ (policy.allowedLicenses ?? []),
|
||||||
|
);
|
||||||
|
const denied = /** @type {string[]} */ (policy.deniedLicensePatterns ?? []);
|
||||||
|
const failures = [];
|
||||||
|
const results = [];
|
||||||
|
for (const dependency of /** @type {Array<Record<string, unknown>>} */ (
|
||||||
|
inventory.dependencies ?? []
|
||||||
|
)) {
|
||||||
|
const license = String(dependency.license ?? "NOASSERTION");
|
||||||
|
const explicitlyDenied = denied.some((pattern) =>
|
||||||
|
new RegExp(pattern, "i").test(license),
|
||||||
|
);
|
||||||
|
const unknownAccepted =
|
||||||
|
license === "NOASSERTION" && dependency.optional === true;
|
||||||
|
const passed =
|
||||||
|
!explicitlyDenied && (allowed.has(license) || unknownAccepted);
|
||||||
|
results.push({
|
||||||
|
package: `${dependency.name}@${dependency.version}`,
|
||||||
|
license,
|
||||||
|
passed,
|
||||||
|
reason: unknownAccepted ? "platform-optional-not-materialized" : null,
|
||||||
|
});
|
||||||
|
if (!passed) {
|
||||||
|
failures.push(
|
||||||
|
`${dependency.name}@${dependency.version} has disallowed license ${license}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return Object.freeze({
|
||||||
|
passed: failures.length === 0,
|
||||||
|
failures: Object.freeze(failures),
|
||||||
|
results: Object.freeze(results),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {ReturnType<typeof diffDependencyInventories>} diff
|
||||||
|
* @param {Readonly<Record<string, unknown>>} inventory
|
||||||
|
* @param {Readonly<Record<string, unknown>>} evidenceFile
|
||||||
|
*/
|
||||||
|
export function validateDependencyReview(diff, inventory, evidenceFile) {
|
||||||
|
const rows =
|
||||||
|
/** @type {Array<Record<string, unknown>>} */ (inventory.dependencies ?? []);
|
||||||
|
const byIdentity = new Map(
|
||||||
|
rows.map((row) => [`${row.name}@${row.version}`, row]),
|
||||||
|
);
|
||||||
|
const evidence = new Map(
|
||||||
|
/** @type {Array<Record<string, unknown>>} */ (
|
||||||
|
evidenceFile.changes ?? []
|
||||||
|
).map((entry) => [entry.changeId, entry]),
|
||||||
|
);
|
||||||
|
const highRisk = diff.added.filter((identity) => {
|
||||||
|
const row = byIdentity.get(identity);
|
||||||
|
return row?.direct === true && row.scope === "production";
|
||||||
|
});
|
||||||
|
const failures = [];
|
||||||
|
for (const identity of highRisk) {
|
||||||
|
const changeId = `add:${identity}`;
|
||||||
|
const entry = evidence.get(changeId);
|
||||||
|
if (!entry) {
|
||||||
|
failures.push(`high-risk dependency missing review: ${changeId}`);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
for (const field of ["owner", "reviewer", "reason", "rollback"]) {
|
||||||
|
if (typeof entry[field] !== "string" || !entry[field].trim()) {
|
||||||
|
failures.push(`${changeId} missing ${field}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (entry.owner === entry.reviewer) {
|
||||||
|
failures.push(`${changeId} may not be self-approved`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return Object.freeze({
|
||||||
|
passed: failures.length === 0,
|
||||||
|
highRisk: Object.freeze(highRisk),
|
||||||
|
failures: Object.freeze(failures),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const severityRank = new Map([
|
||||||
|
["unknown", 0],
|
||||||
|
["low", 1],
|
||||||
|
["moderate", 2],
|
||||||
|
["high", 3],
|
||||||
|
["critical", 4],
|
||||||
|
]);
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {Readonly<Record<string, unknown>>} report
|
||||||
|
* @param {Readonly<Record<string, unknown>>} policy
|
||||||
|
* @param {Readonly<Record<string, unknown>>} exceptionFile
|
||||||
|
* @param {string} lockfileSha256
|
||||||
|
* @param {Date} [now]
|
||||||
|
*/
|
||||||
|
export function validateVulnerabilityReport(
|
||||||
|
report,
|
||||||
|
policy,
|
||||||
|
exceptionFile,
|
||||||
|
lockfileSha256,
|
||||||
|
now = new Date(),
|
||||||
|
) {
|
||||||
|
const failures = [];
|
||||||
|
if (report.scannedLockfileSha256 !== lockfileSha256) {
|
||||||
|
failures.push("vulnerability report lockfile digest mismatch");
|
||||||
|
}
|
||||||
|
if (typeof report.provider !== "string" || !report.provider.trim()) {
|
||||||
|
failures.push("vulnerability report provider missing");
|
||||||
|
}
|
||||||
|
const threshold = severityRank.get(String(policy.blockAtSeverity)) ?? 3;
|
||||||
|
const exceptions =
|
||||||
|
/** @type {Array<Record<string, unknown>>} */ (
|
||||||
|
exceptionFile.exceptions ?? []
|
||||||
|
);
|
||||||
|
const blocking = [];
|
||||||
|
for (const finding of /** @type {Array<Record<string, unknown>>} */ (
|
||||||
|
report.findings ?? []
|
||||||
|
)) {
|
||||||
|
const severity = String(finding.severity ?? "unknown").toLowerCase();
|
||||||
|
if ((severityRank.get(severity) ?? 0) < threshold) continue;
|
||||||
|
const exception = exceptions.find(
|
||||||
|
(entry) =>
|
||||||
|
entry.vulnerabilityId === finding.id &&
|
||||||
|
entry.packageName === finding.packageName,
|
||||||
|
);
|
||||||
|
const expiry =
|
||||||
|
typeof exception?.expiresAt === "string"
|
||||||
|
? Date.parse(exception.expiresAt)
|
||||||
|
: Number.NaN;
|
||||||
|
const validException =
|
||||||
|
exception &&
|
||||||
|
typeof exception.owner === "string" &&
|
||||||
|
exception.owner.trim() &&
|
||||||
|
typeof exception.reviewer === "string" &&
|
||||||
|
exception.reviewer.trim() &&
|
||||||
|
exception.owner !== exception.reviewer &&
|
||||||
|
typeof exception.reason === "string" &&
|
||||||
|
exception.reason.trim() &&
|
||||||
|
Number.isFinite(expiry) &&
|
||||||
|
expiry > now.getTime();
|
||||||
|
if (!validException) {
|
||||||
|
blocking.push(
|
||||||
|
`${finding.id}:${finding.packageName}@${finding.version}:${severity}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return Object.freeze({
|
||||||
|
passed: failures.length === 0 && blocking.length === 0,
|
||||||
|
failures: Object.freeze(failures),
|
||||||
|
blocking: Object.freeze(blocking),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {Readonly<Record<string, unknown>>} sbom
|
||||||
|
* @param {Readonly<Record<string, unknown>>} inventory
|
||||||
|
* @param {Readonly<Record<string, unknown>>} provenance
|
||||||
|
* @param {string} distDigest
|
||||||
|
*/
|
||||||
|
export function verifySupplyChainCoherence(
|
||||||
|
sbom,
|
||||||
|
inventory,
|
||||||
|
provenance,
|
||||||
|
distDigest,
|
||||||
|
) {
|
||||||
|
const failures = [];
|
||||||
|
const componentCount = Array.isArray(sbom.components)
|
||||||
|
? sbom.components.length
|
||||||
|
: -1;
|
||||||
|
const dependencyCount = Array.isArray(inventory.dependencies)
|
||||||
|
? inventory.dependencies.length
|
||||||
|
: -2;
|
||||||
|
if (componentCount !== dependencyCount) {
|
||||||
|
failures.push("SBOM component count does not match inventory");
|
||||||
|
}
|
||||||
|
const metadata =
|
||||||
|
/** @type {Record<string, unknown>} */ (sbom.metadata ?? {});
|
||||||
|
const properties =
|
||||||
|
/** @type {Array<{name?: string, value?: string}>} */ (
|
||||||
|
metadata.properties ?? []
|
||||||
|
);
|
||||||
|
if (properties.find(
|
||||||
|
/** @param {{name?: string, value?: string}} property */
|
||||||
|
(property) =>
|
||||||
|
property.name === "ca:lockfileSha256" &&
|
||||||
|
property.value === inventory.lockfileSha256,
|
||||||
|
) === undefined) {
|
||||||
|
failures.push("SBOM lockfile digest does not match inventory");
|
||||||
|
}
|
||||||
|
const subject =
|
||||||
|
/** @type {Array<Record<string, unknown>>} */ (provenance.subject ?? [])[0];
|
||||||
|
const subjectDigest =
|
||||||
|
/** @type {Record<string, unknown>} */ (subject?.digest ?? {});
|
||||||
|
if (subjectDigest.sha256 !== distDigest) {
|
||||||
|
failures.push("provenance subject does not match built dist digest");
|
||||||
|
}
|
||||||
|
const predicate =
|
||||||
|
/** @type {Record<string, unknown>} */ (provenance.predicate ?? {});
|
||||||
|
const materials =
|
||||||
|
/** @type {Record<string, unknown>} */ (predicate.materials ?? {});
|
||||||
|
if (materials.lockfileSha256 !== inventory.lockfileSha256) {
|
||||||
|
failures.push("provenance lockfile material does not match inventory");
|
||||||
|
}
|
||||||
|
return Object.freeze({
|
||||||
|
passed: failures.length === 0,
|
||||||
|
failures: Object.freeze(failures),
|
||||||
|
});
|
||||||
|
}
|
||||||
+149
-44
@@ -1,10 +1,37 @@
|
|||||||
import { mkdir, readFile, readdir, writeFile } from "node:fs/promises";
|
import { createHash } from "node:crypto";
|
||||||
|
import { mkdir, readFile, readdir, stat, writeFile } from "node:fs/promises";
|
||||||
import path from "node:path";
|
import path from "node:path";
|
||||||
|
|
||||||
const scanRoots = ["src", "dist"];
|
/** @param {string} name @param {string} fallback */
|
||||||
const findings = /** @type {Array<{ruleId: string, file: string}>} */ ([]);
|
function argumentValue(name, fallback) {
|
||||||
|
const index = process.argv.indexOf(name);
|
||||||
|
return index >= 0 && process.argv[index + 1]
|
||||||
|
? process.argv[index + 1]
|
||||||
|
: fallback;
|
||||||
|
}
|
||||||
|
|
||||||
|
const policyPath = argumentValue(
|
||||||
|
"--policy",
|
||||||
|
"config/security/secret-scan-policy.json",
|
||||||
|
);
|
||||||
|
const artifactPath = argumentValue(
|
||||||
|
"--artifact",
|
||||||
|
"artifacts/security/scan.sarif",
|
||||||
|
);
|
||||||
|
const policy = JSON.parse(await readFile(policyPath, "utf8"));
|
||||||
|
const findings =
|
||||||
|
/** @type {Array<{
|
||||||
|
* ruleId: string,
|
||||||
|
* file: string,
|
||||||
|
* line: number,
|
||||||
|
* fingerprint: string
|
||||||
|
* }>} */ ([]);
|
||||||
|
const policyFailures = [];
|
||||||
const patterns = [
|
const patterns = [
|
||||||
{ id: "private-key", expression: /-----BEGIN (?:RSA |EC )?PRIVATE KEY-----/g },
|
{
|
||||||
|
id: "private-key",
|
||||||
|
expression: /-----BEGIN (?:RSA |EC )?PRIVATE KEY-----/g,
|
||||||
|
},
|
||||||
{ id: "aws-access-key", expression: /\bAKIA[0-9A-Z]{16}\b/g },
|
{ id: "aws-access-key", expression: /\bAKIA[0-9A-Z]{16}\b/g },
|
||||||
{ id: "github-token", expression: /\bgh[pousr]_[A-Za-z0-9_]{30,}\b/g },
|
{ id: "github-token", expression: /\bgh[pousr]_[A-Za-z0-9_]{30,}\b/g },
|
||||||
{
|
{
|
||||||
@@ -14,35 +41,101 @@ const patterns = [
|
|||||||
},
|
},
|
||||||
];
|
];
|
||||||
|
|
||||||
/** @param {string} directory @returns {Promise<string[]>} */
|
/** @param {string} target @returns {Promise<string[]>} */
|
||||||
async function filesWithin(directory) {
|
async function filesWithin(target) {
|
||||||
const entries = await readdir(directory, { withFileTypes: true });
|
try {
|
||||||
const nested = /** @type {string[][]} */ (await Promise.all(
|
const metadata = await stat(target);
|
||||||
entries.map((entry) => {
|
if (metadata.isFile()) return [target];
|
||||||
const target = path.join(directory, entry.name);
|
const entries = await readdir(target, { withFileTypes: true });
|
||||||
return entry.isDirectory() ? filesWithin(target) : [target];
|
const nested = /** @type {string[][]} */ (await Promise.all(
|
||||||
}),
|
entries.map((entry) => {
|
||||||
));
|
const child = path.join(target, entry.name);
|
||||||
return nested.flat();
|
return entry.isDirectory() ? filesWithin(child) : [child];
|
||||||
|
}),
|
||||||
|
));
|
||||||
|
return nested.flat();
|
||||||
|
} catch {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
for (const root of scanRoots) {
|
const excluded = new Set(
|
||||||
for (const scanFile of await filesWithin(root)) {
|
/** @type {string[]} */ (policy.excludedPaths ?? []).map((entry) =>
|
||||||
if (/\.(png|jpg|jpeg|gif|woff2?|zip)$/i.test(scanFile)) continue;
|
entry.replaceAll("\\", "/"),
|
||||||
const content = await readFile(scanFile, "utf8");
|
),
|
||||||
for (const pattern of patterns) {
|
);
|
||||||
pattern.expression.lastIndex = 0;
|
const allowlist =
|
||||||
if (pattern.expression.test(content)) {
|
/** @type {Array<{
|
||||||
findings.push({ ruleId: pattern.id, file: scanFile });
|
* path: string,
|
||||||
}
|
* ruleId: string,
|
||||||
|
* owner: string,
|
||||||
|
* reason: string,
|
||||||
|
* expiresAt: string
|
||||||
|
* }>} */ (policy.allowlist ?? []);
|
||||||
|
for (const entry of allowlist) {
|
||||||
|
const expiry = Date.parse(entry.expiresAt);
|
||||||
|
if (
|
||||||
|
!entry.path.startsWith("tests/") ||
|
||||||
|
!entry.owner?.trim() ||
|
||||||
|
!entry.reason?.trim() ||
|
||||||
|
!Number.isFinite(expiry) ||
|
||||||
|
expiry <= Date.now()
|
||||||
|
) {
|
||||||
|
policyFailures.push(
|
||||||
|
`invalid or expired secret allowlist entry: ${entry.path}:${entry.ruleId}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const roots = [
|
||||||
|
...(/** @type {string[]} */ (policy.trackedRoots ?? [])),
|
||||||
|
...(/** @type {string[]} */ (policy.generatedRoots ?? [])),
|
||||||
|
];
|
||||||
|
const scanFiles = (
|
||||||
|
await Promise.all(roots.map((root) => filesWithin(root)))
|
||||||
|
).flat();
|
||||||
|
for (const scanFile of [...new Set(scanFiles)].sort()) {
|
||||||
|
const normalized = scanFile.replaceAll("\\", "/");
|
||||||
|
if (
|
||||||
|
[...excluded].some(
|
||||||
|
(entry) => normalized === entry || normalized.startsWith(`${entry}/`),
|
||||||
|
) ||
|
||||||
|
/\.(?:png|jpe?g|gif|webp|woff2?|zip|gz|sarif)$/i.test(normalized)
|
||||||
|
) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
let content;
|
||||||
|
try {
|
||||||
|
content = await readFile(scanFile, "utf8");
|
||||||
|
} catch {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
for (const pattern of patterns) {
|
||||||
|
pattern.expression.lastIndex = 0;
|
||||||
|
for (const match of content.matchAll(pattern.expression)) {
|
||||||
|
const isAllowed = allowlist.some(
|
||||||
|
(entry) =>
|
||||||
|
entry.path === normalized &&
|
||||||
|
entry.ruleId === pattern.id &&
|
||||||
|
Date.parse(entry.expiresAt) > Date.now(),
|
||||||
|
);
|
||||||
|
if (isAllowed) continue;
|
||||||
|
const prefix = content.slice(0, match.index);
|
||||||
|
findings.push({
|
||||||
|
ruleId: pattern.id,
|
||||||
|
file: normalized,
|
||||||
|
line: prefix.split(/\r?\n/).length,
|
||||||
|
fingerprint: createHash("sha256")
|
||||||
|
.update(`${pattern.id}:${normalized}:${String(match.index)}`)
|
||||||
|
.digest("hex"),
|
||||||
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
const sarif = {
|
const sarif = {
|
||||||
version: "2.1.0",
|
version: "2.1.0",
|
||||||
$schema:
|
$schema: "https://json.schemastore.org/sarif-2.1.0.json",
|
||||||
"https://json.schemastore.org/sarif-2.1.0.json",
|
|
||||||
runs: [
|
runs: [
|
||||||
{
|
{
|
||||||
tool: {
|
tool: {
|
||||||
@@ -54,29 +147,41 @@ const sarif = {
|
|||||||
})),
|
})),
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
results: findings.map((finding) => ({
|
results: [
|
||||||
ruleId: finding.ruleId,
|
...findings.map((finding) => ({
|
||||||
message: { text: "Potential secret material must be removed." },
|
ruleId: finding.ruleId,
|
||||||
locations: [
|
message: {
|
||||||
{
|
text: "Potential secret material must be removed.",
|
||||||
physicalLocation: {
|
|
||||||
artifactLocation: { uri: finding.file },
|
|
||||||
},
|
|
||||||
},
|
},
|
||||||
],
|
partialFingerprints: {
|
||||||
})),
|
primaryLocationLineHash: finding.fingerprint,
|
||||||
|
},
|
||||||
|
locations: [
|
||||||
|
{
|
||||||
|
physicalLocation: {
|
||||||
|
artifactLocation: { uri: finding.file },
|
||||||
|
region: { startLine: finding.line },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
],
|
||||||
|
})),
|
||||||
|
...policyFailures.map((failure) => ({
|
||||||
|
ruleId: "invalid-allowlist",
|
||||||
|
message: { text: failure },
|
||||||
|
})),
|
||||||
|
],
|
||||||
},
|
},
|
||||||
],
|
],
|
||||||
};
|
};
|
||||||
|
|
||||||
await mkdir("artifacts/security", { recursive: true });
|
await mkdir(path.dirname(artifactPath), { recursive: true });
|
||||||
await writeFile(
|
await writeFile(artifactPath, `${JSON.stringify(sarif, null, 2)}\n`);
|
||||||
"artifacts/security/scan.sarif",
|
if (findings.length > 0 || policyFailures.length > 0) {
|
||||||
`${JSON.stringify(sarif, null, 2)}\n`,
|
process.stderr.write(
|
||||||
);
|
`Security scan found ${findings.length + policyFailures.length} blocking result(s).\n`,
|
||||||
|
);
|
||||||
if (findings.length > 0) {
|
|
||||||
process.stderr.write(`Security scan found ${findings.length} blocking result(s).\n`);
|
|
||||||
process.exit(1);
|
process.exit(1);
|
||||||
}
|
}
|
||||||
process.stdout.write("Source and built-asset secret scan: PASS\n");
|
process.stdout.write(
|
||||||
|
`Tracked source, config, built asset and artifact secret scan: PASS (${scanFiles.length} files)\n`,
|
||||||
|
);
|
||||||
|
|||||||
@@ -0,0 +1,113 @@
|
|||||||
|
import { spawnSync } from "node:child_process";
|
||||||
|
import {
|
||||||
|
cp,
|
||||||
|
mkdir,
|
||||||
|
readFile,
|
||||||
|
readdir,
|
||||||
|
rm,
|
||||||
|
symlink,
|
||||||
|
writeFile,
|
||||||
|
} from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
|
const fixtureRoot = path.resolve(".tmp/optional-recipe-removal");
|
||||||
|
const pnpmCli = /** @type {string} */ (process.env.npm_execpath);
|
||||||
|
const copyTargets = [
|
||||||
|
"src",
|
||||||
|
"tests",
|
||||||
|
"recipes",
|
||||||
|
"scripts",
|
||||||
|
"config",
|
||||||
|
"public",
|
||||||
|
"index.html",
|
||||||
|
"package.json",
|
||||||
|
"tsconfig.base.json",
|
||||||
|
"tsconfig.json",
|
||||||
|
"tsconfig.app.json",
|
||||||
|
"tsconfig.node.json",
|
||||||
|
"tsconfig.test.json",
|
||||||
|
"tsconfig.recipes.json",
|
||||||
|
"vite.config.js",
|
||||||
|
"vitest.config.js",
|
||||||
|
"playwright.config.js",
|
||||||
|
"eslint.config.js",
|
||||||
|
".dependency-cruiser.cjs",
|
||||||
|
];
|
||||||
|
|
||||||
|
/** @param {string} script */
|
||||||
|
function runPnpm(script) {
|
||||||
|
return (
|
||||||
|
spawnSync(process.execPath, [pnpmCli, script], {
|
||||||
|
cwd: fixtureRoot,
|
||||||
|
stdio: "inherit",
|
||||||
|
}).status === 0
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param {string} directory @returns {Promise<string[]>} */
|
||||||
|
async function filesBelow(directory) {
|
||||||
|
const entries = await readdir(directory, { withFileTypes: true });
|
||||||
|
const groups = await Promise.all(
|
||||||
|
entries.map((entry) => {
|
||||||
|
const target = path.join(directory, entry.name);
|
||||||
|
return entry.isDirectory() ? filesBelow(target) : [target];
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
return groups.flat();
|
||||||
|
}
|
||||||
|
|
||||||
|
await rm(fixtureRoot, { recursive: true, force: true });
|
||||||
|
await mkdir(fixtureRoot, { recursive: true });
|
||||||
|
for (const target of copyTargets) {
|
||||||
|
await cp(target, path.join(fixtureRoot, target), { recursive: true });
|
||||||
|
}
|
||||||
|
await symlink(path.resolve("node_modules"), path.join(fixtureRoot, "node_modules"), "dir");
|
||||||
|
await rm(path.join(fixtureRoot, "recipes"), { recursive: true, force: true });
|
||||||
|
await rm(path.join(fixtureRoot, "tests/recipes"), {
|
||||||
|
recursive: true,
|
||||||
|
force: true,
|
||||||
|
});
|
||||||
|
|
||||||
|
const checks = [
|
||||||
|
["typecheck", runPnpm("check:types")],
|
||||||
|
["architecture", runPnpm("check:architecture")],
|
||||||
|
["test", runPnpm("test:all")],
|
||||||
|
["build", runPnpm("build")],
|
||||||
|
];
|
||||||
|
/** @type {string[]} */
|
||||||
|
const residue = [];
|
||||||
|
for (const file of await filesBelow(path.join(fixtureRoot, "dist"))) {
|
||||||
|
if (!/\.(?:js|css|html|json)$/.test(file)) continue;
|
||||||
|
const content = await readFile(file, "utf8");
|
||||||
|
if (content.includes("frontend-optional-recipe-must-not-reach-production")) {
|
||||||
|
residue.push(path.relative(fixtureRoot, file));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
checks.push(["bundle-residue", residue.length === 0]);
|
||||||
|
const passed = checks.every(([, result]) => result);
|
||||||
|
await mkdir("artifacts/tests", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/tests/optional-recipe-removal.xml",
|
||||||
|
`<?xml version="1.0" encoding="UTF-8"?>\n` +
|
||||||
|
`<testsuite name="optional-recipe-removal" tests="${checks.length}" failures="${passed ? 0 : 1}">` +
|
||||||
|
checks
|
||||||
|
.map(
|
||||||
|
([name, result]) =>
|
||||||
|
`<testcase name="${name}">${result ? "" : `<failure>${residue.join(", ")}</failure>`}</testcase>`,
|
||||||
|
)
|
||||||
|
.join("") +
|
||||||
|
`</testsuite>\n`,
|
||||||
|
);
|
||||||
|
await rm(fixtureRoot, { recursive: true, force: true });
|
||||||
|
if (!passed) {
|
||||||
|
process.stderr.write(
|
||||||
|
`Optional recipe removal failed: ${checks
|
||||||
|
.filter(([, result]) => !result)
|
||||||
|
.map(([name]) => name)
|
||||||
|
.join(", ")}\n`,
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(
|
||||||
|
`Optional recipe removal: PASS (${checks.length} base checks)\n`,
|
||||||
|
);
|
||||||
@@ -18,11 +18,13 @@ const featureOwnedPaths = [
|
|||||||
featureSource,
|
featureSource,
|
||||||
featureTests,
|
featureTests,
|
||||||
"tests/e2e/reference-form.spec.js",
|
"tests/e2e/reference-form.spec.js",
|
||||||
|
"tests/e2e/reference-route.spec.js",
|
||||||
"tests/mocks",
|
"tests/mocks",
|
||||||
];
|
];
|
||||||
const copyTargets = [
|
const copyTargets = [
|
||||||
"src",
|
"src",
|
||||||
"tests",
|
"tests",
|
||||||
|
"recipes",
|
||||||
"scripts",
|
"scripts",
|
||||||
"config",
|
"config",
|
||||||
"public",
|
"public",
|
||||||
@@ -33,6 +35,7 @@ const copyTargets = [
|
|||||||
"tsconfig.app.json",
|
"tsconfig.app.json",
|
||||||
"tsconfig.node.json",
|
"tsconfig.node.json",
|
||||||
"tsconfig.test.json",
|
"tsconfig.test.json",
|
||||||
|
"tsconfig.recipes.json",
|
||||||
"vite.config.js",
|
"vite.config.js",
|
||||||
"vitest.config.js",
|
"vitest.config.js",
|
||||||
"playwright.config.js",
|
"playwright.config.js",
|
||||||
|
|||||||
@@ -0,0 +1,47 @@
|
|||||||
|
import { spawnSync } from "node:child_process";
|
||||||
|
import { readFile, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
import { supplyChainDigest } from "./lib/supply-chain.mjs";
|
||||||
|
|
||||||
|
const owner = process.env.DEPENDENCY_BASELINE_OWNER;
|
||||||
|
const reason = process.env.DEPENDENCY_BASELINE_REASON;
|
||||||
|
if (!owner?.trim() || !reason?.trim()) {
|
||||||
|
process.stderr.write(
|
||||||
|
"DEPENDENCY_BASELINE_OWNER and DEPENDENCY_BASELINE_REASON are required.\n",
|
||||||
|
);
|
||||||
|
process.exit(2);
|
||||||
|
}
|
||||||
|
|
||||||
|
const commands = /** @type {Array<[string, string[]]>} */ ([
|
||||||
|
["corepack", ["pnpm", "build"]],
|
||||||
|
["node", ["scripts/generate-supply-chain.mjs", "--no-baseline"]],
|
||||||
|
]);
|
||||||
|
for (const [command, args] of commands) {
|
||||||
|
const result = spawnSync(command, args, { stdio: "inherit" });
|
||||||
|
if (result.status !== 0) process.exit(result.status ?? 1);
|
||||||
|
}
|
||||||
|
|
||||||
|
const inventory = JSON.parse(
|
||||||
|
await readFile("artifacts/release/dependency-inventory.json", "utf8"),
|
||||||
|
);
|
||||||
|
await writeFile(
|
||||||
|
"config/security/dependency-baseline.json",
|
||||||
|
`${JSON.stringify(inventory, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
await writeFile(
|
||||||
|
"config/security/dependency-baseline.approval.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
snapshotDigest: supplyChainDigest(inventory),
|
||||||
|
owner,
|
||||||
|
reason,
|
||||||
|
approvedAt: new Date().toISOString(),
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
process.stdout.write(
|
||||||
|
`Dependency baseline approved: ${inventory.dependencyCount} packages\n`,
|
||||||
|
);
|
||||||
@@ -0,0 +1,76 @@
|
|||||||
|
import { spawnSync } from "node:child_process";
|
||||||
|
import { mkdir, readFile, readdir, writeFile } from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
|
import { supplyChainDigest } from "./lib/supply-chain.mjs";
|
||||||
|
|
||||||
|
/** @param {string} directory @returns {Promise<string[]>} */
|
||||||
|
async function filesWithin(directory) {
|
||||||
|
const entries = await readdir(directory, { withFileTypes: true });
|
||||||
|
const nested = /** @type {string[][]} */ (await Promise.all(
|
||||||
|
entries.map((entry) => {
|
||||||
|
const target = path.join(directory, entry.name);
|
||||||
|
return entry.isDirectory() ? filesWithin(target) : [target];
|
||||||
|
}),
|
||||||
|
));
|
||||||
|
return nested.flat().sort();
|
||||||
|
}
|
||||||
|
|
||||||
|
async function distDigest() {
|
||||||
|
const rows = await Promise.all(
|
||||||
|
(await filesWithin("dist")).map(async (file) => ({
|
||||||
|
path: path.relative("dist", file).replaceAll("\\", "/"),
|
||||||
|
bytes: (await readFile(file)).byteLength,
|
||||||
|
content: supplyChainDigest(await readFile(file)),
|
||||||
|
})),
|
||||||
|
);
|
||||||
|
return supplyChainDigest(rows);
|
||||||
|
}
|
||||||
|
|
||||||
|
function build(environment = process.env) {
|
||||||
|
return spawnSync("corepack", ["pnpm", "build"], {
|
||||||
|
env: environment,
|
||||||
|
encoding: "utf8",
|
||||||
|
maxBuffer: 16 * 1024 * 1024,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const deterministicEnvironment = {
|
||||||
|
...process.env,
|
||||||
|
SOURCE_DATE_EPOCH: "946684800",
|
||||||
|
};
|
||||||
|
const firstBuild = build(deterministicEnvironment);
|
||||||
|
const firstDigest = firstBuild.status === 0 ? await distDigest() : "BUILD_FAILED";
|
||||||
|
const secondBuild = build(deterministicEnvironment);
|
||||||
|
const secondDigest =
|
||||||
|
secondBuild.status === 0 ? await distDigest() : "BUILD_FAILED";
|
||||||
|
const restoreBuild = build();
|
||||||
|
const passed =
|
||||||
|
firstBuild.status === 0 &&
|
||||||
|
secondBuild.status === 0 &&
|
||||||
|
restoreBuild.status === 0 &&
|
||||||
|
firstDigest === secondDigest;
|
||||||
|
|
||||||
|
await mkdir("artifacts/release", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/release/reproducible-build.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
sourceDateEpoch: deterministicEnvironment.SOURCE_DATE_EPOCH,
|
||||||
|
firstDigest,
|
||||||
|
secondDigest,
|
||||||
|
restored: restoreBuild.status === 0,
|
||||||
|
status: passed ? "PASS" : "FAIL",
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
if (!passed) {
|
||||||
|
process.stderr.write(
|
||||||
|
`Reproducible build failed: first=${firstDigest} second=${secondDigest}\n`,
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(`Reproducible build: PASS (${firstDigest})\n`);
|
||||||
@@ -0,0 +1,121 @@
|
|||||||
|
import { createHash } from "node:crypto";
|
||||||
|
import { mkdir, readFile, readdir, stat, writeFile } from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
|
import {
|
||||||
|
isValidSha512Integrity,
|
||||||
|
parsePnpmLockfilePackages,
|
||||||
|
supplyChainDigest,
|
||||||
|
verifySupplyChainCoherence,
|
||||||
|
} from "./lib/supply-chain.mjs";
|
||||||
|
|
||||||
|
/** @param {string} directory @returns {Promise<string[]>} */
|
||||||
|
async function filesWithin(directory) {
|
||||||
|
const entries = await readdir(directory, { withFileTypes: true });
|
||||||
|
const nested = /** @type {string[][]} */ (await Promise.all(
|
||||||
|
entries.map((entry) => {
|
||||||
|
const target = path.join(directory, entry.name);
|
||||||
|
return entry.isDirectory() ? filesWithin(target) : [target];
|
||||||
|
}),
|
||||||
|
));
|
||||||
|
return nested.flat().sort();
|
||||||
|
}
|
||||||
|
|
||||||
|
const inventory = JSON.parse(
|
||||||
|
await readFile("artifacts/release/dependency-inventory.json", "utf8"),
|
||||||
|
);
|
||||||
|
const sbom = JSON.parse(
|
||||||
|
await readFile("artifacts/release/sbom.cdx.json", "utf8"),
|
||||||
|
);
|
||||||
|
const provenance = JSON.parse(
|
||||||
|
await readFile("artifacts/release/provenance.json", "utf8"),
|
||||||
|
);
|
||||||
|
const verification = JSON.parse(
|
||||||
|
await readFile(
|
||||||
|
"artifacts/security/supply-chain-verification.json",
|
||||||
|
"utf8",
|
||||||
|
),
|
||||||
|
);
|
||||||
|
const lockfileText = await readFile("pnpm-lock.yaml", "utf8");
|
||||||
|
const lockfileSha256 = createHash("sha256")
|
||||||
|
.update(lockfileText)
|
||||||
|
.digest("hex");
|
||||||
|
const outputs = await Promise.all(
|
||||||
|
(await filesWithin("dist")).map(async (file) => {
|
||||||
|
const content = await readFile(file);
|
||||||
|
return {
|
||||||
|
path: file.replaceAll("\\", "/"),
|
||||||
|
bytes: (await stat(file)).size,
|
||||||
|
sha256: createHash("sha256").update(content).digest("hex"),
|
||||||
|
};
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
const distDigest = supplyChainDigest(outputs);
|
||||||
|
const coherence = verifySupplyChainCoherence(
|
||||||
|
sbom,
|
||||||
|
inventory,
|
||||||
|
provenance,
|
||||||
|
distDigest,
|
||||||
|
);
|
||||||
|
const failures = [...coherence.failures];
|
||||||
|
if (
|
||||||
|
inventory.lockfileSha256 !== lockfileSha256 ||
|
||||||
|
verification.lockfileSha256 !== lockfileSha256
|
||||||
|
) {
|
||||||
|
failures.push("inventory/verification lockfile digest mismatch");
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
verification.distSha256 !== distDigest ||
|
||||||
|
verification.sbomSha256 !== supplyChainDigest(sbom)
|
||||||
|
) {
|
||||||
|
failures.push("verification digest set is incoherent");
|
||||||
|
}
|
||||||
|
const lockRows = parsePnpmLockfilePackages(lockfileText);
|
||||||
|
const inventoryRows =
|
||||||
|
/** @type {Array<Record<string, unknown>>} */ (
|
||||||
|
inventory.dependencies ?? []
|
||||||
|
);
|
||||||
|
const inventoryByIdentity = new Map(
|
||||||
|
inventoryRows.map((entry) => [
|
||||||
|
`${entry.name}@${entry.version}`,
|
||||||
|
entry,
|
||||||
|
]),
|
||||||
|
);
|
||||||
|
if (lockRows.length !== inventoryRows.length) {
|
||||||
|
failures.push("transitive dependency count differs from lockfile");
|
||||||
|
}
|
||||||
|
for (const lockRow of lockRows) {
|
||||||
|
const identity = `${lockRow.name}@${lockRow.version}`;
|
||||||
|
const dependency = inventoryByIdentity.get(identity);
|
||||||
|
if (
|
||||||
|
!dependency ||
|
||||||
|
dependency.integrity !== lockRow.integrity ||
|
||||||
|
!isValidSha512Integrity(lockRow.integrity)
|
||||||
|
) {
|
||||||
|
failures.push(`lockfile inventory integrity mismatch: ${identity}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const report = {
|
||||||
|
schemaVersion: 1,
|
||||||
|
status: failures.length === 0 ? "PASS" : "FAIL",
|
||||||
|
dependencyCount: inventoryRows.length,
|
||||||
|
lockfileSha256,
|
||||||
|
distSha256: distDigest,
|
||||||
|
sbomSha256: supplyChainDigest(sbom),
|
||||||
|
failures,
|
||||||
|
};
|
||||||
|
await mkdir("artifacts/security", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/security/supply-chain-coherence.json",
|
||||||
|
`${JSON.stringify(report, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
if (failures.length > 0) {
|
||||||
|
process.stderr.write(
|
||||||
|
`Supply-chain artifact coherence failed:\n- ${failures.join("\n- ")}\n`,
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(
|
||||||
|
`Supply-chain artifact coherence: PASS (${inventoryRows.length} dependencies)\n`,
|
||||||
|
);
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
const verification = JSON.parse(
|
||||||
|
await readFile(
|
||||||
|
"artifacts/security/supply-chain-verification.json",
|
||||||
|
"utf8",
|
||||||
|
),
|
||||||
|
);
|
||||||
|
const passed = verification.promotionStatus === "PASS";
|
||||||
|
const report = {
|
||||||
|
schemaVersion: 1,
|
||||||
|
status: passed ? "PASS" : "FAIL_UNVERIFIED",
|
||||||
|
vulnerabilityStatus: verification.vulnerabilityStatus,
|
||||||
|
provenanceAttestationStatus:
|
||||||
|
verification.provenanceAttestationStatus,
|
||||||
|
lockfileSha256: verification.lockfileSha256,
|
||||||
|
distSha256: verification.distSha256,
|
||||||
|
};
|
||||||
|
await mkdir("artifacts/security", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/security/promotion-verification.json",
|
||||||
|
`${JSON.stringify(report, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
if (!passed) {
|
||||||
|
process.stderr.write(
|
||||||
|
"Supply-chain promotion is FAIL_UNVERIFIED: external vulnerability and signed provenance evidence are required.\n",
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write("Supply-chain promotion evidence: PASS\n");
|
||||||
@@ -1,6 +1,4 @@
|
|||||||
import { expect, test } from "../support/browser/strict-browser-test.js";
|
import { expect, test } from "../support/browser/strict-browser-test.js";
|
||||||
import { successEnvelope } from "../mocks/contracts/envelopes.js";
|
|
||||||
import { ROUTE_REGISTRY } from "../../src/features/installed-feature-contracts.js";
|
|
||||||
|
|
||||||
test("boots the public app shell", async ({ page }) => {
|
test("boots the public app shell", async ({ page }) => {
|
||||||
await page.goto("/");
|
await page.goto("/");
|
||||||
@@ -26,39 +24,6 @@ test("navigates to a registry-backed example without a page reload", async ({
|
|||||||
).toBeFocused();
|
).toBeFocused();
|
||||||
});
|
});
|
||||||
|
|
||||||
test("opens the protected integration route through the local demo seam", async ({
|
|
||||||
page,
|
|
||||||
}) => {
|
|
||||||
const protectedRoute = Object.values(ROUTE_REGISTRY).find(
|
|
||||||
(definition) => definition.access === "integration-defined",
|
|
||||||
);
|
|
||||||
if (!protectedRoute) throw new Error("An integration route is required");
|
|
||||||
await page.route(
|
|
||||||
"http://localhost:8080/api/reference-resources?*",
|
|
||||||
(route) =>
|
|
||||||
route.fulfill({
|
|
||||||
json: successEnvelope([
|
|
||||||
{
|
|
||||||
id: "browser-reference",
|
|
||||||
name: "Browser reference",
|
|
||||||
createdAt: "2026-07-26T00:00:00.000Z",
|
|
||||||
},
|
|
||||||
]),
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
await page.goto(protectedRoute.path);
|
|
||||||
await expect(
|
|
||||||
page.getByRole("heading", { name: "세션이 필요합니다." }),
|
|
||||||
).toBeVisible();
|
|
||||||
|
|
||||||
await page.getByRole("button", { name: "로그인 시작" }).click();
|
|
||||||
|
|
||||||
await expect(
|
|
||||||
page.getByRole("heading", { name: protectedRoute.title }),
|
|
||||||
).toBeVisible();
|
|
||||||
await expect(page.getByText("인증됨")).toBeVisible();
|
|
||||||
});
|
|
||||||
|
|
||||||
test("provides an escape-dismissible mobile navigation", async ({ page }) => {
|
test("provides an escape-dismissible mobile navigation", async ({ page }) => {
|
||||||
await page.setViewportSize({ width: 390, height: 844 });
|
await page.setViewportSize({ width: 390, height: 844 });
|
||||||
await page.goto("/");
|
await page.goto("/");
|
||||||
|
|||||||
@@ -0,0 +1,36 @@
|
|||||||
|
import { expect, test } from "../support/browser/strict-browser-test.js";
|
||||||
|
import { successEnvelope } from "../mocks/contracts/envelopes.js";
|
||||||
|
import { ROUTE_REGISTRY } from "../../src/features/installed-feature-contracts.js";
|
||||||
|
|
||||||
|
test("opens the protected integration route through the local demo seam", async ({
|
||||||
|
page,
|
||||||
|
}) => {
|
||||||
|
const protectedRoute = Object.values(ROUTE_REGISTRY).find(
|
||||||
|
(definition) => definition.access === "integration-defined",
|
||||||
|
);
|
||||||
|
if (!protectedRoute) throw new Error("An integration route is required");
|
||||||
|
await page.route(
|
||||||
|
"http://localhost:8080/api/reference-resources?*",
|
||||||
|
(route) =>
|
||||||
|
route.fulfill({
|
||||||
|
json: successEnvelope([
|
||||||
|
{
|
||||||
|
id: "browser-reference",
|
||||||
|
name: "Browser reference",
|
||||||
|
createdAt: "2026-07-26T00:00:00.000Z",
|
||||||
|
},
|
||||||
|
]),
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
await page.goto(protectedRoute.path);
|
||||||
|
await expect(
|
||||||
|
page.getByRole("heading", { name: "세션이 필요합니다." }),
|
||||||
|
).toBeVisible();
|
||||||
|
|
||||||
|
await page.getByRole("button", { name: "로그인 시작" }).click();
|
||||||
|
|
||||||
|
await expect(
|
||||||
|
page.getByRole("heading", { name: protectedRoute.title }),
|
||||||
|
).toBeVisible();
|
||||||
|
await expect(page.getByText("인증됨")).toBeVisible();
|
||||||
|
});
|
||||||
+3
@@ -0,0 +1,3 @@
|
|||||||
|
export function persistCredential(token: string) {
|
||||||
|
localStorage.setItem("authToken", token);
|
||||||
|
}
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
import { OPTIONAL_RECIPE_RUNTIME_SENTINEL } from "../../../../../../recipes/frontend-capabilities/index.js";
|
||||||
|
|
||||||
|
export const recipeInProduction = OPTIONAL_RECIPE_RUNTIME_SENTINEL;
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
export const store = createStore({
|
||||||
|
serverState: [{ id: "copied-from-query-cache" }],
|
||||||
|
});
|
||||||
+3
@@ -0,0 +1,3 @@
|
|||||||
|
import { initialize } from "@launchdarkly/client-sdk";
|
||||||
|
|
||||||
|
export const leakedVendor = initialize;
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
export const client_secret = "fixture-only-secret-value";
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"trackedRoots": [
|
||||||
|
"tests/fixtures/security/secret-detection/forbidden"
|
||||||
|
],
|
||||||
|
"generatedRoots": [],
|
||||||
|
"excludedPaths": [],
|
||||||
|
"allowlist": []
|
||||||
|
}
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
{
|
||||||
|
"client_secret": "synthetic-forbidden-secret"
|
||||||
|
}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
globalThis.password = "synthetic-built-secret";
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
export const leaked = "AKIAABCDEFGHIJKLMNOP";
|
||||||
@@ -0,0 +1,280 @@
|
|||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import {
|
||||||
|
FakeBrowserPermissionAdapter,
|
||||||
|
FakeClientWorkflowAdapter,
|
||||||
|
FakeFeatureFlagAdapter,
|
||||||
|
FakeFileTransferAdapter,
|
||||||
|
FakeGeneratedApiAdapter,
|
||||||
|
FakeLargeDataUiAdapter,
|
||||||
|
FakeMultiTabAdapter,
|
||||||
|
FakeRealtimeAdapter,
|
||||||
|
FakeServiceWorkerUpdateAdapter,
|
||||||
|
FakeWorkerTaskAdapter,
|
||||||
|
MemoryOfflineRepository,
|
||||||
|
RecordingAnalyticsAdapter,
|
||||||
|
createUnavailableAdapters,
|
||||||
|
} from "../../recipes/frontend-capabilities/index.js";
|
||||||
|
|
||||||
|
describe("optional capability recipes", () => {
|
||||||
|
it("requires realtime cleanup and rejects duplicate or out-of-order events", async () => {
|
||||||
|
const adapter = new FakeRealtimeAdapter<{ value: string }>();
|
||||||
|
const received: string[] = [];
|
||||||
|
const subscription = await adapter.subscribe({
|
||||||
|
channel: "orders",
|
||||||
|
onEvent(result) {
|
||||||
|
received.push(result.ok ? result.value.payload.value : result.failure.code);
|
||||||
|
},
|
||||||
|
});
|
||||||
|
expect(subscription.ok).toBe(true);
|
||||||
|
adapter.emit("orders", {
|
||||||
|
id: "event-2",
|
||||||
|
sequence: 2,
|
||||||
|
occurredAt: "2026-07-26T00:00:00.000Z",
|
||||||
|
payload: { value: "new" },
|
||||||
|
});
|
||||||
|
adapter.emit("orders", {
|
||||||
|
id: "event-1",
|
||||||
|
sequence: 1,
|
||||||
|
occurredAt: "2026-07-26T00:00:00.000Z",
|
||||||
|
payload: { value: "old" },
|
||||||
|
});
|
||||||
|
expect(received).toEqual(["new", "STALE_RESULT"]);
|
||||||
|
if (subscription.ok) subscription.value.unsubscribe();
|
||||||
|
expect(adapter.activeSubscriptionCount).toBe(0);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("models offline schema migration and closed-repository fallback", async () => {
|
||||||
|
const repository = new MemoryOfflineRepository<{ id: string; name: string }>();
|
||||||
|
expect(await repository.open({ schemaVersion: 1 })).toEqual({
|
||||||
|
ok: true,
|
||||||
|
value: undefined,
|
||||||
|
});
|
||||||
|
await repository.put({ id: "one", name: "offline" });
|
||||||
|
expect(await repository.migrate({ from: 1, to: 2 })).toEqual({
|
||||||
|
ok: true,
|
||||||
|
value: undefined,
|
||||||
|
});
|
||||||
|
expect(await repository.get("one")).toEqual({
|
||||||
|
ok: true,
|
||||||
|
value: { id: "one", name: "offline" },
|
||||||
|
});
|
||||||
|
repository.close();
|
||||||
|
expect((await repository.get("one")).ok).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("covers service-worker stale update and explicit unregister", async () => {
|
||||||
|
const adapter = new FakeServiceWorkerUpdateAdapter("v1", "v2");
|
||||||
|
expect((await adapter.inspect()).ok).toBe(true);
|
||||||
|
expect((await adapter.activate("stale")).ok).toBe(false);
|
||||||
|
expect(await adapter.activate("v2")).toEqual({ ok: true, value: undefined });
|
||||||
|
expect(await adapter.unregister()).toEqual({ ok: true, value: undefined });
|
||||||
|
});
|
||||||
|
|
||||||
|
it("covers file validation, progress and AbortSignal cancellation", async () => {
|
||||||
|
const adapter = new FakeFileTransferAdapter(10, new Set(["text/plain"]));
|
||||||
|
const progress: number[] = [];
|
||||||
|
const controller = new AbortController();
|
||||||
|
const uploaded = await adapter.upload({
|
||||||
|
file: { name: "safe.txt", size: 4, type: "text/plain" },
|
||||||
|
signal: controller.signal,
|
||||||
|
onProgress(value) {
|
||||||
|
progress.push(value.transferredBytes);
|
||||||
|
},
|
||||||
|
});
|
||||||
|
expect(uploaded.ok).toBe(true);
|
||||||
|
expect(progress).toEqual([4]);
|
||||||
|
controller.abort();
|
||||||
|
const cancelled = await adapter.download({
|
||||||
|
resourceId: "one",
|
||||||
|
signal: controller.signal,
|
||||||
|
onProgress() {},
|
||||||
|
});
|
||||||
|
expect(cancelled).toMatchObject({
|
||||||
|
ok: false,
|
||||||
|
failure: { code: "ABORTED" },
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
it("keeps generated API and feature flag vendors behind typed facades", async () => {
|
||||||
|
const api = new FakeGeneratedApiAdapter("2026-07", {
|
||||||
|
list: () => [{ id: "one" }],
|
||||||
|
});
|
||||||
|
expect(
|
||||||
|
await api.execute<Array<{ id: string }>>({
|
||||||
|
operationId: "list",
|
||||||
|
contractVersion: "2026-07",
|
||||||
|
}),
|
||||||
|
).toEqual({ ok: true, value: [{ id: "one" }] });
|
||||||
|
expect(
|
||||||
|
(
|
||||||
|
await api.execute({
|
||||||
|
operationId: "list",
|
||||||
|
contractVersion: "old",
|
||||||
|
})
|
||||||
|
).ok,
|
||||||
|
).toBe(false);
|
||||||
|
|
||||||
|
const flags = new FakeFeatureFlagAdapter<{ checkout: boolean }>({
|
||||||
|
checkout: true,
|
||||||
|
});
|
||||||
|
expect(
|
||||||
|
await flags.evaluate({
|
||||||
|
key: "checkout",
|
||||||
|
fallback: false,
|
||||||
|
maxAgeMs: 1_000,
|
||||||
|
}),
|
||||||
|
).toEqual({ ok: true, value: true });
|
||||||
|
});
|
||||||
|
|
||||||
|
it("discards cancelled worker results and de-duplicates multi-tab events", async () => {
|
||||||
|
const worker = new FakeWorkerTaskAdapter<number, number>((value) => value * 2);
|
||||||
|
const controller = new AbortController();
|
||||||
|
worker.cancel("cancelled");
|
||||||
|
expect(
|
||||||
|
(
|
||||||
|
await worker.run({
|
||||||
|
taskId: "cancelled",
|
||||||
|
generation: 1,
|
||||||
|
payload: 2,
|
||||||
|
signal: controller.signal,
|
||||||
|
})
|
||||||
|
).ok,
|
||||||
|
).toBe(false);
|
||||||
|
|
||||||
|
const tabs = new FakeMultiTabAdapter<{ refreshed: boolean }>();
|
||||||
|
const observed: string[] = [];
|
||||||
|
const cleanup = tabs.subscribe({
|
||||||
|
sourceId: "tab-b",
|
||||||
|
onEvent(result) {
|
||||||
|
if (result.ok) observed.push(result.value.eventId);
|
||||||
|
},
|
||||||
|
});
|
||||||
|
expect(
|
||||||
|
tabs.publish({
|
||||||
|
eventId: "one",
|
||||||
|
sourceId: "tab-a",
|
||||||
|
version: 1,
|
||||||
|
payload: { refreshed: true },
|
||||||
|
}).ok,
|
||||||
|
).toBe(true);
|
||||||
|
expect(
|
||||||
|
tabs.publish({
|
||||||
|
eventId: "one",
|
||||||
|
sourceId: "tab-a",
|
||||||
|
version: 1,
|
||||||
|
payload: { refreshed: true },
|
||||||
|
}).ok,
|
||||||
|
).toBe(false);
|
||||||
|
expect(observed).toEqual(["one"]);
|
||||||
|
cleanup();
|
||||||
|
tabs.close();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("separates browser permission, local workflow and large-data behavior", async () => {
|
||||||
|
const permissions = new FakeBrowserPermissionAdapter({
|
||||||
|
notification: "denied",
|
||||||
|
});
|
||||||
|
expect(
|
||||||
|
await permissions.request({ capability: "notification" }),
|
||||||
|
).toEqual({ ok: true, value: "denied" });
|
||||||
|
expect(
|
||||||
|
(
|
||||||
|
await permissions.request({
|
||||||
|
capability: "clipboard-read",
|
||||||
|
})
|
||||||
|
).ok,
|
||||||
|
).toBe(false);
|
||||||
|
|
||||||
|
const workflow = new FakeClientWorkflowAdapter(
|
||||||
|
{ step: 0 },
|
||||||
|
(state, event: "next") => ({
|
||||||
|
step: event === "next" ? state.step + 1 : state.step,
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
workflow.dispatch("next");
|
||||||
|
expect(workflow.snapshot()).toEqual({ step: 1 });
|
||||||
|
workflow.reset();
|
||||||
|
expect(workflow.snapshot()).toEqual({ step: 0 });
|
||||||
|
|
||||||
|
const data = new FakeLargeDataUiAdapter<{ id: string; name: string }>();
|
||||||
|
data.replace([{ id: "one", name: "row" }], 2);
|
||||||
|
expect(data.window({ offset: 0, limit: 1, generation: 1 }).ok).toBe(false);
|
||||||
|
expect(data.window({ offset: 0, limit: 1, generation: 2 })).toEqual({
|
||||||
|
ok: true,
|
||||||
|
value: [{ id: "one", name: "row" }],
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
it("enforces analytics consent, redaction and bounded queues", () => {
|
||||||
|
const adapter = new RecordingAnalyticsAdapter(1);
|
||||||
|
expect(
|
||||||
|
adapter.record({
|
||||||
|
kind: "analytics",
|
||||||
|
eventId: "page-viewed",
|
||||||
|
consent: "denied",
|
||||||
|
attributes: {},
|
||||||
|
}).ok,
|
||||||
|
).toBe(false);
|
||||||
|
expect(
|
||||||
|
adapter.record({
|
||||||
|
kind: "error",
|
||||||
|
eventId: "render-failed",
|
||||||
|
consent: "not-required",
|
||||||
|
attributes: { routeId: "HOME", authToken: "must-not-survive" },
|
||||||
|
}).ok,
|
||||||
|
).toBe(true);
|
||||||
|
expect(adapter.records[0]?.attributes).toEqual({ routeId: "HOME" });
|
||||||
|
expect(
|
||||||
|
adapter.record({
|
||||||
|
kind: "error",
|
||||||
|
eventId: "second",
|
||||||
|
consent: "not-required",
|
||||||
|
attributes: {},
|
||||||
|
}).ok,
|
||||||
|
).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("provides fail-closed unavailable adapters for every capability", async () => {
|
||||||
|
const adapters = createUnavailableAdapters();
|
||||||
|
const controller = new AbortController();
|
||||||
|
const results = await Promise.all([
|
||||||
|
adapters.realtime.heartbeat(),
|
||||||
|
adapters.offline.open({ schemaVersion: 1 }),
|
||||||
|
adapters.serviceWorker.unregister(),
|
||||||
|
adapters.fileTransfer.download({
|
||||||
|
resourceId: "one",
|
||||||
|
signal: controller.signal,
|
||||||
|
onProgress() {},
|
||||||
|
}),
|
||||||
|
adapters.generatedApi.execute({
|
||||||
|
operationId: "one",
|
||||||
|
contractVersion: "one",
|
||||||
|
}),
|
||||||
|
adapters.featureFlag.evaluate({
|
||||||
|
key: "one",
|
||||||
|
fallback: false,
|
||||||
|
maxAgeMs: 0,
|
||||||
|
}),
|
||||||
|
adapters.worker.run({
|
||||||
|
taskId: "one",
|
||||||
|
generation: 1,
|
||||||
|
payload: null,
|
||||||
|
signal: controller.signal,
|
||||||
|
}),
|
||||||
|
adapters.browserPermission.request({ capability: "notification" }),
|
||||||
|
adapters.analytics.flush(),
|
||||||
|
]);
|
||||||
|
expect(results.every((result) => !result.ok)).toBe(true);
|
||||||
|
expect(adapters.multiTab.publish({
|
||||||
|
eventId: "one",
|
||||||
|
sourceId: "one",
|
||||||
|
version: 1,
|
||||||
|
payload: null,
|
||||||
|
}).ok).toBe(false);
|
||||||
|
expect(adapters.clientWorkflow.dispatch(null).ok).toBe(false);
|
||||||
|
expect(
|
||||||
|
adapters.largeDataUi.window({ offset: 0, limit: 1, generation: 1 }).ok,
|
||||||
|
).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,89 @@
|
|||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import {
|
||||||
|
diffDependencyInventories,
|
||||||
|
isValidSha512Integrity,
|
||||||
|
parsePnpmLockfilePackages,
|
||||||
|
supplyChainDigest,
|
||||||
|
validateDependencyReview,
|
||||||
|
validateLicensePolicy,
|
||||||
|
} from "../../scripts/lib/supply-chain.mjs";
|
||||||
|
|
||||||
|
const integrity = `sha512-${Buffer.alloc(64, 7).toString("base64")}`;
|
||||||
|
const dependency = {
|
||||||
|
name: "fixture",
|
||||||
|
version: "1.0.0",
|
||||||
|
direct: true,
|
||||||
|
scope: "production",
|
||||||
|
optional: false,
|
||||||
|
license: "MIT",
|
||||||
|
integrity,
|
||||||
|
dependencies: [],
|
||||||
|
};
|
||||||
|
|
||||||
|
describe("supply-chain policy", () => {
|
||||||
|
it("parses every top-level lockfile package and validates SRI", () => {
|
||||||
|
const parsed = parsePnpmLockfilePackages(`
|
||||||
|
packages:
|
||||||
|
|
||||||
|
'@scope/one@1.0.0':
|
||||||
|
resolution: {integrity: ${integrity}}
|
||||||
|
|
||||||
|
two@2.0.0:
|
||||||
|
resolution: {integrity: ${integrity}}
|
||||||
|
|
||||||
|
snapshots:
|
||||||
|
`);
|
||||||
|
expect(parsed).toEqual([
|
||||||
|
{ name: "@scope/one", version: "1.0.0", integrity },
|
||||||
|
{ name: "two", version: "2.0.0", integrity },
|
||||||
|
]);
|
||||||
|
expect(parsed.every((entry) => isValidSha512Integrity(entry.integrity))).toBe(
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("keeps inventory digests stable when dependency ordering changes", () => {
|
||||||
|
const other = { ...dependency, name: "other" };
|
||||||
|
expect(supplyChainDigest([dependency, other])).toBe(
|
||||||
|
supplyChainDigest([other, dependency]),
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("calculates actual additions and requires independent high-risk review", () => {
|
||||||
|
const before = { dependencies: [] };
|
||||||
|
const after = { dependencies: [dependency] };
|
||||||
|
const diff = diffDependencyInventories(before, after);
|
||||||
|
expect(diff.added).toEqual(["fixture@1.0.0"]);
|
||||||
|
expect(
|
||||||
|
validateDependencyReview(diff, after, {
|
||||||
|
changes: [
|
||||||
|
{
|
||||||
|
changeId: "add:fixture@1.0.0",
|
||||||
|
owner: "one",
|
||||||
|
reviewer: "one",
|
||||||
|
reason: "fixture",
|
||||||
|
rollback: "remove",
|
||||||
|
},
|
||||||
|
],
|
||||||
|
}).passed,
|
||||||
|
).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("allows explicit policy licenses and rejects denied licenses", () => {
|
||||||
|
expect(
|
||||||
|
validateLicensePolicy(
|
||||||
|
{ dependencies: [dependency] },
|
||||||
|
{ allowedLicenses: ["MIT"], deniedLicensePatterns: ["AGPL"] },
|
||||||
|
).passed,
|
||||||
|
).toBe(true);
|
||||||
|
expect(
|
||||||
|
validateLicensePolicy(
|
||||||
|
{
|
||||||
|
dependencies: [{ ...dependency, license: "AGPL-3.0" }],
|
||||||
|
},
|
||||||
|
{ allowedLicenses: ["MIT"], deniedLicensePatterns: ["AGPL"] },
|
||||||
|
).passed,
|
||||||
|
).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
+2
-1
@@ -3,6 +3,7 @@
|
|||||||
"references": [
|
"references": [
|
||||||
{ "path": "./tsconfig.app.json" },
|
{ "path": "./tsconfig.app.json" },
|
||||||
{ "path": "./tsconfig.node.json" },
|
{ "path": "./tsconfig.node.json" },
|
||||||
{ "path": "./tsconfig.test.json" }
|
{ "path": "./tsconfig.test.json" },
|
||||||
|
{ "path": "./tsconfig.recipes.json" }
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{
|
||||||
|
"extends": "./tsconfig.base.json",
|
||||||
|
"compilerOptions": {
|
||||||
|
"lib": ["ES2022", "DOM", "DOM.Iterable"],
|
||||||
|
"types": ["node"]
|
||||||
|
},
|
||||||
|
"include": ["recipes/**/*.ts"],
|
||||||
|
"exclude": ["dist", "node_modules"]
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user