Compare commits
17
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c089e749d0 | ||
|
|
4667cafa43 | ||
|
|
18bea3a852 | ||
|
|
eb37cbe8be | ||
|
|
b82bc73c6c | ||
|
|
89f3c69413 | ||
|
|
5ad6fb032e | ||
|
|
52f4896b63 | ||
|
|
3c347d40d8 | ||
|
|
6f88915c7a | ||
|
|
675603c3a2 | ||
|
|
4a3110974b | ||
|
|
caf09ecd56 | ||
|
|
6db96b6ef5 | ||
|
|
f6300c5d1d | ||
|
|
9a92c11792 | ||
|
|
a023c3b645 |
@@ -9,4 +9,5 @@ artifacts/**/*.json
|
|||||||
artifacts/**/*.xml
|
artifacts/**/*.xml
|
||||||
artifacts/**/*.txt
|
artifacts/**/*.txt
|
||||||
artifacts/**/*.sarif
|
artifacts/**/*.sarif
|
||||||
|
artifacts/tests/e2e/
|
||||||
!artifacts/**/.gitkeep
|
!artifacts/**/.gitkeep
|
||||||
|
|||||||
@@ -0,0 +1,15 @@
|
|||||||
|
# APP_HOME accessibility review
|
||||||
|
|
||||||
|
Status: pending-manual-review
|
||||||
|
|
||||||
|
Reviewer:
|
||||||
|
|
||||||
|
Keyboard: automated tab-order fixture passed; human review pending.
|
||||||
|
|
||||||
|
Focus: automated visible-focus fixture passed; route-change review pending.
|
||||||
|
|
||||||
|
Screen reader: pending.
|
||||||
|
|
||||||
|
Reduced motion: automated media-query fixture passed; human review pending.
|
||||||
|
|
||||||
|
Color signal: pending.
|
||||||
@@ -0,0 +1,63 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"families": {
|
||||||
|
"api": {
|
||||||
|
"additive": {
|
||||||
|
"before": { "required": ["id"], "properties": { "id": {} } },
|
||||||
|
"after": {
|
||||||
|
"required": ["id"],
|
||||||
|
"properties": { "id": {}, "displayName": {} }
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"breaking": {
|
||||||
|
"before": { "required": ["id"], "properties": { "id": {} } },
|
||||||
|
"after": {
|
||||||
|
"required": ["id", "name"],
|
||||||
|
"properties": { "id": {}, "name": {} }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"config": {
|
||||||
|
"additive": {
|
||||||
|
"before": { "required": ["APP_ENV"], "properties": { "APP_ENV": {} } },
|
||||||
|
"after": {
|
||||||
|
"required": ["APP_ENV"],
|
||||||
|
"properties": { "APP_ENV": {}, "OPTIONAL_FLAG": {} }
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"breaking": {
|
||||||
|
"before": { "required": ["APP_ENV"], "properties": { "APP_ENV": {} } },
|
||||||
|
"after": {
|
||||||
|
"required": ["APP_ENV", "NEW_REQUIRED"],
|
||||||
|
"properties": { "APP_ENV": {}, "NEW_REQUIRED": {} }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"storage": {
|
||||||
|
"additive": {
|
||||||
|
"before": { "properties": { "theme": {} } },
|
||||||
|
"after": { "properties": { "theme": {}, "contrast": {} } }
|
||||||
|
},
|
||||||
|
"breaking": {
|
||||||
|
"before": { "properties": { "theme": {} } },
|
||||||
|
"after": { "properties": {} }
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"release": {
|
||||||
|
"additive": {
|
||||||
|
"before": { "required": ["buildId"], "properties": { "buildId": {} } },
|
||||||
|
"after": {
|
||||||
|
"required": ["buildId"],
|
||||||
|
"properties": { "buildId": {}, "builtAt": {} }
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"breaking": {
|
||||||
|
"before": { "required": ["buildId"], "properties": { "buildId": {} } },
|
||||||
|
"after": {
|
||||||
|
"required": ["buildId", "assetManifestHash"],
|
||||||
|
"properties": { "buildId": {}, "assetManifestHash": {} }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,116 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"registries": [
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-ROUTE",
|
||||||
|
"path": "src/contracts/routes.js",
|
||||||
|
"exportName": "ROUTE_REGISTRY",
|
||||||
|
"owner": "feature-routing-navigation-guard-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"routeId",
|
||||||
|
"path",
|
||||||
|
"paramsSchema",
|
||||||
|
"searchSchema",
|
||||||
|
"access",
|
||||||
|
"loadingSurface",
|
||||||
|
"errorSurface",
|
||||||
|
"chunkId"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-API",
|
||||||
|
"path": "src/contracts/api-operations.js",
|
||||||
|
"exportName": "API_OPERATIONS",
|
||||||
|
"owner": "feature-api-client-response-envelope-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"method",
|
||||||
|
"path",
|
||||||
|
"operationId",
|
||||||
|
"auth",
|
||||||
|
"timeoutMs",
|
||||||
|
"idempotency",
|
||||||
|
"requestSchema",
|
||||||
|
"responseSchema",
|
||||||
|
"owner"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-ENV",
|
||||||
|
"path": "src/contracts/env.js",
|
||||||
|
"exportName": "ENV_REGISTRY",
|
||||||
|
"owner": "feature-frontend-env-runtime-config-contract",
|
||||||
|
"requiredFields": ["phase", "classification", "required", "defaultValue"]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-STORAGE",
|
||||||
|
"path": "src/contracts/storage-keys.js",
|
||||||
|
"exportName": "STORAGE_REGISTRY",
|
||||||
|
"owner": "feature-frontend-storage-registry-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"logicalName",
|
||||||
|
"physicalKey",
|
||||||
|
"backend",
|
||||||
|
"classification",
|
||||||
|
"schemaVersion",
|
||||||
|
"ttl",
|
||||||
|
"migration",
|
||||||
|
"quotaFallback"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-ERROR",
|
||||||
|
"path": "src/contracts/errors.js",
|
||||||
|
"exportName": "ERROR_REGISTRY",
|
||||||
|
"owner": "feature-frontend-error-classification-boundary-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"kind",
|
||||||
|
"defaultRetryable",
|
||||||
|
"severity",
|
||||||
|
"userMessageKey",
|
||||||
|
"action",
|
||||||
|
"telemetryEvent",
|
||||||
|
"redaction"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-QUERY",
|
||||||
|
"path": "src/contracts/query-keys.js",
|
||||||
|
"exportName": "QUERY_REGISTRY",
|
||||||
|
"owner": "feature-server-state-caching-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"namespace",
|
||||||
|
"serialization",
|
||||||
|
"identity",
|
||||||
|
"invalidation",
|
||||||
|
"version",
|
||||||
|
"persistence"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-TELEMETRY",
|
||||||
|
"path": "src/contracts/telemetry.js",
|
||||||
|
"exportName": "TELEMETRY_REGISTRY",
|
||||||
|
"owner": "feature-frontend-observability-logging-trace-contract",
|
||||||
|
"requiredFields": [
|
||||||
|
"eventName",
|
||||||
|
"trigger",
|
||||||
|
"requiredAttributes",
|
||||||
|
"optionalAttributes",
|
||||||
|
"forbiddenAttributes",
|
||||||
|
"sampling",
|
||||||
|
"delivery"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"registryId": "FE-REG-RELEASE",
|
||||||
|
"path": "src/contracts/release-tokens.js",
|
||||||
|
"exportName": "RELEASE_TOKEN_REGISTRY",
|
||||||
|
"owner": "feature-frontend-release-cache-rollback-contract",
|
||||||
|
"requiredFields": ["token", "source", "compatibilityRole"]
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"compatibilityImpact": {
|
||||||
|
"allowed": ["none", "additive", "behavior-change", "breaking"],
|
||||||
|
"current": "additive"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"surfaces": {
|
||||||
|
"index": {
|
||||||
|
"path": "/",
|
||||||
|
"cacheControl": "no-cache",
|
||||||
|
"contentTypes": ["text/html"],
|
||||||
|
"securityHeaders": true
|
||||||
|
},
|
||||||
|
"runtimeConfig": {
|
||||||
|
"path": "/config.json",
|
||||||
|
"cacheControl": "no-store",
|
||||||
|
"contentTypes": ["application/json"],
|
||||||
|
"securityHeaders": true
|
||||||
|
},
|
||||||
|
"releaseManifest": {
|
||||||
|
"path": "/release-manifest.json",
|
||||||
|
"cacheControl": "no-store",
|
||||||
|
"contentTypes": ["application/json"],
|
||||||
|
"securityHeaders": true
|
||||||
|
},
|
||||||
|
"hashedAsset": {
|
||||||
|
"pathPattern": "/assets/*",
|
||||||
|
"cacheControl": "public, max-age=31536000, immutable",
|
||||||
|
"contentTypes": ["text/javascript", "application/javascript"],
|
||||||
|
"securityHeaders": false
|
||||||
|
},
|
||||||
|
"sourceMap": {
|
||||||
|
"public": false
|
||||||
|
},
|
||||||
|
"serviceWorker": {
|
||||||
|
"enabled": false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"responses": {
|
||||||
|
"index": {
|
||||||
|
"cache-control": "no-cache",
|
||||||
|
"content-type": "text/html; charset=utf-8",
|
||||||
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
|
"x-frame-options": "DENY",
|
||||||
|
"referrer-policy": "strict-origin-when-cross-origin",
|
||||||
|
"x-content-type-options": "nosniff",
|
||||||
|
"permissions-policy": "camera=(), microphone=(), geolocation=()"
|
||||||
|
},
|
||||||
|
"runtimeConfig": {
|
||||||
|
"cache-control": "no-store",
|
||||||
|
"content-type": "application/json; charset=utf-8",
|
||||||
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
|
"x-frame-options": "DENY",
|
||||||
|
"referrer-policy": "strict-origin-when-cross-origin",
|
||||||
|
"x-content-type-options": "nosniff",
|
||||||
|
"permissions-policy": "camera=(), microphone=(), geolocation=()"
|
||||||
|
},
|
||||||
|
"releaseManifest": {
|
||||||
|
"cache-control": "no-store",
|
||||||
|
"content-type": "application/json; charset=utf-8",
|
||||||
|
"content-security-policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
|
"strict-transport-security": "max-age=31536000; includeSubDomains",
|
||||||
|
"x-frame-options": "DENY",
|
||||||
|
"referrer-policy": "strict-origin-when-cross-origin",
|
||||||
|
"x-content-type-options": "nosniff",
|
||||||
|
"permissions-policy": "camera=(), microphone=(), geolocation=()"
|
||||||
|
},
|
||||||
|
"hashedAsset": {
|
||||||
|
"cache-control": "public, max-age=31536000, immutable",
|
||||||
|
"content-type": "text/javascript; charset=utf-8"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"headers": {
|
||||||
|
"Content-Security-Policy": "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self' https:; font-src 'self'; upgrade-insecure-requests",
|
||||||
|
"Strict-Transport-Security": "max-age=31536000; includeSubDomains",
|
||||||
|
"X-Frame-Options": "DENY",
|
||||||
|
"Referrer-Policy": "strict-origin-when-cross-origin",
|
||||||
|
"X-Content-Type-Options": "nosniff",
|
||||||
|
"Permissions-Policy": "camera=(), microphone=(), geolocation=()"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,77 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"fixtures": [
|
||||||
|
{
|
||||||
|
"name": "coherent-release",
|
||||||
|
"expectedCompatible": true,
|
||||||
|
"frontend": {
|
||||||
|
"buildId": "build-a",
|
||||||
|
"configSchemaVersion": "1.0",
|
||||||
|
"apiContractVersion": "1.0",
|
||||||
|
"assetManifestHash": "assets-a",
|
||||||
|
"releaseId": "release-a"
|
||||||
|
},
|
||||||
|
"runtime": {
|
||||||
|
"buildId": "build-a",
|
||||||
|
"configSchemaVersion": "1.1",
|
||||||
|
"apiContractVersion": "1.2",
|
||||||
|
"assetManifestHash": "assets-a",
|
||||||
|
"releaseId": "release-a"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "mixed-html-and-assets",
|
||||||
|
"expectedCompatible": false,
|
||||||
|
"frontend": {
|
||||||
|
"buildId": "build-a",
|
||||||
|
"configSchemaVersion": "1.0",
|
||||||
|
"apiContractVersion": "1.0",
|
||||||
|
"assetManifestHash": "assets-a",
|
||||||
|
"releaseId": "release-a"
|
||||||
|
},
|
||||||
|
"runtime": {
|
||||||
|
"buildId": "build-b",
|
||||||
|
"configSchemaVersion": "1.0",
|
||||||
|
"apiContractVersion": "1.0",
|
||||||
|
"assetManifestHash": "assets-b",
|
||||||
|
"releaseId": "release-b"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "incompatible-runtime-config",
|
||||||
|
"expectedCompatible": false,
|
||||||
|
"frontend": {
|
||||||
|
"buildId": "build-a",
|
||||||
|
"configSchemaVersion": "1.0",
|
||||||
|
"apiContractVersion": "1.0",
|
||||||
|
"assetManifestHash": "assets-a",
|
||||||
|
"releaseId": "release-a"
|
||||||
|
},
|
||||||
|
"runtime": {
|
||||||
|
"buildId": "build-a",
|
||||||
|
"configSchemaVersion": "2.0",
|
||||||
|
"apiContractVersion": "1.0",
|
||||||
|
"assetManifestHash": "assets-a",
|
||||||
|
"releaseId": "release-a"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "incompatible-api-contract",
|
||||||
|
"expectedCompatible": false,
|
||||||
|
"frontend": {
|
||||||
|
"buildId": "build-a",
|
||||||
|
"configSchemaVersion": "1.0",
|
||||||
|
"apiContractVersion": "1.0",
|
||||||
|
"assetManifestHash": "assets-a",
|
||||||
|
"releaseId": "release-a"
|
||||||
|
},
|
||||||
|
"runtime": {
|
||||||
|
"buildId": "build-a",
|
||||||
|
"configSchemaVersion": "1.0",
|
||||||
|
"apiContractVersion": "2.0",
|
||||||
|
"assetManifestHash": "assets-a",
|
||||||
|
"releaseId": "release-a"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||||
|
"$id": "ART-FE-003@1",
|
||||||
|
"type": "object",
|
||||||
|
"required": ["schemaVersion", "generatedAt", "artifact", "fixtures", "passed"],
|
||||||
|
"properties": {
|
||||||
|
"schemaVersion": { "const": 1 },
|
||||||
|
"generatedAt": { "type": "string", "format": "date-time" },
|
||||||
|
"artifact": {
|
||||||
|
"type": "object",
|
||||||
|
"required": ["checked", "compatible", "mismatches"]
|
||||||
|
},
|
||||||
|
"fixtures": { "type": "array", "minItems": 2 },
|
||||||
|
"passed": { "type": "boolean" }
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
# Manual accessibility review checklist
|
||||||
|
|
||||||
|
Automated axe checks do not establish WCAG conformance. A human reviewer must
|
||||||
|
copy this checklist to `artifacts/tests/a11y-manual/<route-id>.md`, execute it
|
||||||
|
on the release candidate, and sign it.
|
||||||
|
|
||||||
|
- Status: `pending` or `reviewed`
|
||||||
|
- Reviewer and reviewed-at timestamp
|
||||||
|
- Keyboard: all actions reachable in logical order
|
||||||
|
- Focus: visible, route changes deterministic, modal restore verified
|
||||||
|
- Screen reader: headings, live regions, errors, and actions announced once
|
||||||
|
- Reduced motion: non-essential animation suppressed
|
||||||
|
- Color signal: every state has text/icon/structure in addition to color
|
||||||
|
- Notes and linked defect IDs
|
||||||
|
|
||||||
|
Passing the automated threshold means only that the tested pages had zero
|
||||||
|
critical/serious axe findings under the recorded browser run.
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
# Contract compatibility and rollback rules
|
||||||
|
|
||||||
|
The blocking tuple is `(buildId, configSchemaVersion, apiContractVersion,
|
||||||
|
assetManifestHash, releaseId)`. Versions are parsed numerically.
|
||||||
|
|
||||||
|
1. additive changes preserve current required fields
|
||||||
|
2. breaking changes require a major version bump
|
||||||
|
3. persisted cache is discarded unless an explicit tested migration exists
|
||||||
|
4. an incompatible config or API contract blocks product mount
|
||||||
|
5. rollback restores HTML, assets, runtime config, API compatibility, and
|
||||||
|
release manifest as one coherent set
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
# Release, cache, and rollback contract
|
||||||
|
|
||||||
|
Each deployment is an immutable `releases/<releaseId>/` artifact set. The
|
||||||
|
provider adapter must upload assets, release manifest, runtime config, and
|
||||||
|
verify asset reachability before atomically switching the active HTML pointer.
|
||||||
|
The post-switch boot, route, API, telemetry, and reload-loop smoke checks close
|
||||||
|
the deployment.
|
||||||
|
|
||||||
|
Rollback selects a prior release tuple, confirms its assets and runtime/API
|
||||||
|
compatibility, atomically switches the complete set, performs the provider
|
||||||
|
cache action, and repeats the smoke checks. Rebuilding an old commit, replacing
|
||||||
|
HTML alone, or declaring recovery from cache-purge completion is prohibited.
|
||||||
|
Recovery is established by old/new reachability probes.
|
||||||
|
|
||||||
|
The provider-independent cache defaults are:
|
||||||
|
|
||||||
|
- hashed assets: `public, max-age=31536000, immutable`
|
||||||
|
- HTML: `no-cache`
|
||||||
|
- runtime config and release manifest: `no-store`
|
||||||
|
- public source maps: disabled
|
||||||
|
- service worker/offline cache: disabled
|
||||||
|
|
||||||
|
HTML, JSON config/manifest, and hashed JavaScript MIME types are also compared
|
||||||
|
to the declared allowlist; a cache-correct response with a mismatched
|
||||||
|
`Content-Type` still fails the hosting gate.
|
||||||
|
|
||||||
|
`corepack pnpm verify:hosting-headers` uses a deterministic fixture locally.
|
||||||
|
Set `HOSTING_BASE_URL` to probe deployed responses; production promotion
|
||||||
|
requires the artifact to report `mode: "live"`. The live target must be its
|
||||||
|
canonical, non-loopback HTTPS root URL. Each required surface must return HTTP
|
||||||
|
200 without leaving that origin before its cache, content-type, and security
|
||||||
|
headers can count as deployment evidence.
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
# Browser security boundary
|
||||||
|
|
||||||
|
The browser bundle is public. Secrets, token lifecycle, raw HTML injection,
|
||||||
|
dynamic code execution, untrusted script URLs, and public production source
|
||||||
|
maps are prohibited defaults.
|
||||||
|
|
||||||
|
`config/hosting/security-headers.json` is the declared header set. Hosting
|
||||||
|
verification compares that declaration with live responses. CSP deliberately
|
||||||
|
omits `unsafe-inline` and `unsafe-eval`; production code and built assets must
|
||||||
|
remain compatible with that baseline.
|
||||||
|
|
||||||
|
Route guards are UX hints and client validation does not replace backend
|
||||||
|
authorization or validation.
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
# Build and supply-chain gate
|
||||||
|
|
||||||
|
Merge and release controls:
|
||||||
|
|
||||||
|
- frozen `pnpm-lock.yaml` installation; drift is blocking
|
||||||
|
- clean production build with hashed assets and build manifest
|
||||||
|
- machine-readable bundle sizes and checksums
|
||||||
|
- source plus built-asset credential-pattern scan
|
||||||
|
- direct dependency inventory and lockfile digest
|
||||||
|
- base/head dependency diff review record
|
||||||
|
|
||||||
|
Organization-specific vulnerability severity, denied-license list, SBOM format,
|
||||||
|
and scanner selection remain policy inputs. An approved suppression must record
|
||||||
|
reason, owner, expiry, affected package, and compensating control. Expired
|
||||||
|
suppressions are blocking.
|
||||||
|
|
||||||
|
`artifacts/security/dependency-diff.json` is a local baseline. CI replaces it
|
||||||
|
with the actual base/head direct and transitive lockfile diff before release.
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
# Design-token styling contract
|
||||||
|
|
||||||
|
`src/presentation/styles/theme.css` is the styling SSOT. Components consume
|
||||||
|
semantic color, spacing, typography, and radius tokens through static Tailwind
|
||||||
|
classes.
|
||||||
|
|
||||||
|
Arbitrary-value policy:
|
||||||
|
|
||||||
|
- prefer a named semantic token
|
||||||
|
- bracket values are allowed only for one-off platform constraints that cannot
|
||||||
|
be expressed by the current scale
|
||||||
|
- a repeated bracket value must be promoted into `@theme`
|
||||||
|
- user-controlled or runtime-composed class strings are forbidden
|
||||||
|
- class variants must be selected from a closed static map
|
||||||
|
|
||||||
|
The removable sample may demonstrate tokens, but product modules must not
|
||||||
|
import from `src/sample/contract-fixture`.
|
||||||
@@ -35,6 +35,7 @@ export default [
|
|||||||
"artifacts/**",
|
"artifacts/**",
|
||||||
"tests/fixtures/typecheck/**",
|
"tests/fixtures/typecheck/**",
|
||||||
"tests/fixtures/architecture/forbidden/**",
|
"tests/fixtures/architecture/forbidden/**",
|
||||||
|
"tests/fixtures/security/forbidden/**",
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
eslint.configs.recommended,
|
eslint.configs.recommended,
|
||||||
@@ -98,4 +99,24 @@ export default [
|
|||||||
]),
|
]),
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
files: ["**/*.{js,jsx}"],
|
||||||
|
rules: {
|
||||||
|
"no-eval": "error",
|
||||||
|
"no-new-func": "error",
|
||||||
|
"no-script-url": "error",
|
||||||
|
"no-restricted-syntax": [
|
||||||
|
"error",
|
||||||
|
{
|
||||||
|
selector: "JSXAttribute[name.name='dangerouslySetInnerHTML']",
|
||||||
|
message: "Raw HTML injection is prohibited by FE-OC-019.",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
selector:
|
||||||
|
"CallExpression[callee.object.name='document'][callee.property.name='createElement'][arguments.0.value='script']",
|
||||||
|
message: "Runtime script construction is prohibited by FE-OC-019.",
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
},
|
||||||
];
|
];
|
||||||
|
|||||||
+14
-2
@@ -11,6 +11,7 @@
|
|||||||
"scripts": {
|
"scripts": {
|
||||||
"dev": "vite",
|
"dev": "vite",
|
||||||
"build": "vite build && node scripts/generate-build-manifest.mjs",
|
"build": "vite build && node scripts/generate-build-manifest.mjs",
|
||||||
|
"build:release": "corepack pnpm build && corepack pnpm generate:supply-chain && corepack pnpm scan:security",
|
||||||
"preview": "vite preview",
|
"preview": "vite preview",
|
||||||
"lint": "eslint src scripts tests vite.config.js vitest.config.js playwright.config.js --max-warnings=0",
|
"lint": "eslint src scripts tests vite.config.js vitest.config.js playwright.config.js --max-warnings=0",
|
||||||
"check:architecture": "node scripts/check-architecture.mjs",
|
"check:architecture": "node scripts/check-architecture.mjs",
|
||||||
@@ -21,9 +22,18 @@
|
|||||||
"test:component": "vitest run tests/component --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/component.xml",
|
"test:component": "vitest run tests/component --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/component.xml",
|
||||||
"test:integration": "vitest run tests/integration --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/integration.xml",
|
"test:integration": "vitest run tests/integration --reporter=default --reporter=junit --outputFile.junit=artifacts/tests/integration.xml",
|
||||||
"test:e2e": "playwright test",
|
"test:e2e": "playwright test",
|
||||||
"test:a11y": "playwright test --grep @a11y",
|
"test:a11y": "playwright test --grep @a11y && node scripts/write-a11y-report.mjs",
|
||||||
|
"review:a11y-manual": "node scripts/verify-a11y-manual.mjs",
|
||||||
"test:sample-removal": "node scripts/test-sample-removal.mjs",
|
"test:sample-removal": "node scripts/test-sample-removal.mjs",
|
||||||
"test:all": "pnpm test:runtime-schema && pnpm test:unit && pnpm test:component && pnpm test:integration"
|
"test:all": "corepack pnpm test:runtime-schema && corepack pnpm test:unit && corepack pnpm test:component && corepack pnpm test:integration",
|
||||||
|
"verify:lockfile": "corepack pnpm install --frozen-lockfile",
|
||||||
|
"generate:supply-chain": "node scripts/generate-supply-chain.mjs",
|
||||||
|
"scan:security": "node scripts/security-scan.mjs",
|
||||||
|
"check:browser-security": "node scripts/check-browser-security.mjs",
|
||||||
|
"check:registries": "node scripts/check-registries.mjs",
|
||||||
|
"verify:compatibility": "node scripts/check-compatibility.mjs",
|
||||||
|
"verify:release": "node scripts/verify-release.mjs",
|
||||||
|
"verify:hosting-headers": "node scripts/verify-hosting-headers.mjs"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@tanstack/react-query": "5.101.4",
|
"@tanstack/react-query": "5.101.4",
|
||||||
@@ -39,6 +49,7 @@
|
|||||||
"@testing-library/jest-dom": "7.0.0",
|
"@testing-library/jest-dom": "7.0.0",
|
||||||
"@testing-library/react": "16.3.2",
|
"@testing-library/react": "16.3.2",
|
||||||
"@testing-library/user-event": "14.6.1",
|
"@testing-library/user-event": "14.6.1",
|
||||||
|
"@tailwindcss/vite": "4.3.3",
|
||||||
"@types/node": "24.13.3",
|
"@types/node": "24.13.3",
|
||||||
"@types/react": "19.2.8",
|
"@types/react": "19.2.8",
|
||||||
"@types/react-dom": "19.2.3",
|
"@types/react-dom": "19.2.3",
|
||||||
@@ -48,6 +59,7 @@
|
|||||||
"globals": "17.7.0",
|
"globals": "17.7.0",
|
||||||
"jsdom": "29.1.1",
|
"jsdom": "29.1.1",
|
||||||
"msw": "2.15.0",
|
"msw": "2.15.0",
|
||||||
|
"tailwindcss": "4.3.3",
|
||||||
"typescript": "7.0.2",
|
"typescript": "7.0.2",
|
||||||
"vite": "8.1.5",
|
"vite": "8.1.5",
|
||||||
"vitest": "4.1.10"
|
"vitest": "4.1.10"
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ export default defineConfig({
|
|||||||
screenshot: "only-on-failure",
|
screenshot: "only-on-failure",
|
||||||
},
|
},
|
||||||
webServer: {
|
webServer: {
|
||||||
command: "pnpm dev --host 127.0.0.1",
|
command: "corepack pnpm dev --host 127.0.0.1",
|
||||||
url: "http://127.0.0.1:5173",
|
url: "http://127.0.0.1:5173",
|
||||||
reuseExistingServer: !process.env.CI,
|
reuseExistingServer: !process.env.CI,
|
||||||
},
|
},
|
||||||
|
|||||||
Generated
+354
-19
@@ -29,10 +29,13 @@ importers:
|
|||||||
version: 4.12.1(playwright-core@1.62.0)
|
version: 4.12.1(playwright-core@1.62.0)
|
||||||
'@eslint/js':
|
'@eslint/js':
|
||||||
specifier: 10.0.1
|
specifier: 10.0.1
|
||||||
version: 10.0.1(eslint@10.8.0(supports-color@7.2.0))
|
version: 10.0.1(eslint@10.8.0(jiti@2.7.0)(supports-color@7.2.0))
|
||||||
'@playwright/test':
|
'@playwright/test':
|
||||||
specifier: 1.62.0
|
specifier: 1.62.0
|
||||||
version: 1.62.0
|
version: 1.62.0
|
||||||
|
'@tailwindcss/vite':
|
||||||
|
specifier: 4.3.3
|
||||||
|
version: 4.3.3(vite@8.1.5(@types/node@24.13.3)(jiti@2.7.0))
|
||||||
'@testing-library/jest-dom':
|
'@testing-library/jest-dom':
|
||||||
specifier: 7.0.0
|
specifier: 7.0.0
|
||||||
version: 7.0.0(@testing-library/dom@10.4.1)
|
version: 7.0.0(@testing-library/dom@10.4.1)
|
||||||
@@ -53,13 +56,13 @@ importers:
|
|||||||
version: 19.2.3(@types/react@19.2.8)
|
version: 19.2.3(@types/react@19.2.8)
|
||||||
'@vitejs/plugin-react':
|
'@vitejs/plugin-react':
|
||||||
specifier: 6.0.4
|
specifier: 6.0.4
|
||||||
version: 6.0.4(vite@8.1.5(@types/node@24.13.3))
|
version: 6.0.4(vite@8.1.5(@types/node@24.13.3)(jiti@2.7.0))
|
||||||
dependency-cruiser:
|
dependency-cruiser:
|
||||||
specifier: 18.1.0
|
specifier: 18.1.0
|
||||||
version: 18.1.0
|
version: 18.1.0
|
||||||
eslint:
|
eslint:
|
||||||
specifier: 10.8.0
|
specifier: 10.8.0
|
||||||
version: 10.8.0(supports-color@7.2.0)
|
version: 10.8.0(jiti@2.7.0)(supports-color@7.2.0)
|
||||||
globals:
|
globals:
|
||||||
specifier: 17.7.0
|
specifier: 17.7.0
|
||||||
version: 17.7.0
|
version: 17.7.0
|
||||||
@@ -69,15 +72,18 @@ importers:
|
|||||||
msw:
|
msw:
|
||||||
specifier: 2.15.0
|
specifier: 2.15.0
|
||||||
version: 2.15.0(@types/node@24.13.3)(typescript@7.0.2)
|
version: 2.15.0(@types/node@24.13.3)(typescript@7.0.2)
|
||||||
|
tailwindcss:
|
||||||
|
specifier: 4.3.3
|
||||||
|
version: 4.3.3
|
||||||
typescript:
|
typescript:
|
||||||
specifier: 7.0.2
|
specifier: 7.0.2
|
||||||
version: 7.0.2
|
version: 7.0.2
|
||||||
vite:
|
vite:
|
||||||
specifier: 8.1.5
|
specifier: 8.1.5
|
||||||
version: 8.1.5(@types/node@24.13.3)
|
version: 8.1.5(@types/node@24.13.3)(jiti@2.7.0)
|
||||||
vitest:
|
vitest:
|
||||||
specifier: 4.1.10
|
specifier: 4.1.10
|
||||||
version: 4.1.10(@types/node@24.13.3)(jsdom@29.1.1)(msw@2.15.0(@types/node@24.13.3)(typescript@7.0.2))(vite@8.1.5(@types/node@24.13.3))
|
version: 4.1.10(@types/node@24.13.3)(jsdom@29.1.1)(msw@2.15.0(@types/node@24.13.3)(typescript@7.0.2))(vite@8.1.5(@types/node@24.13.3)(jiti@2.7.0))
|
||||||
|
|
||||||
packages:
|
packages:
|
||||||
|
|
||||||
@@ -268,9 +274,22 @@ packages:
|
|||||||
'@types/node':
|
'@types/node':
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
'@jridgewell/gen-mapping@0.3.13':
|
||||||
|
resolution: {integrity: sha512-2kkt/7niJ6MgEPxF0bYdQ6etZaA+fQvDcLKckhy1yIQOzaoKjBBjSj63/aLVjYE3qhRt5dvM+uUyfCg6UKCBbA==}
|
||||||
|
|
||||||
|
'@jridgewell/remapping@2.3.5':
|
||||||
|
resolution: {integrity: sha512-LI9u/+laYG4Ds1TDKSJW2YPrIlcVYOwi2fUC6xB43lueCjgxV4lffOCZCtYFiH6TNOX+tQKXx97T4IKHbhyHEQ==}
|
||||||
|
|
||||||
|
'@jridgewell/resolve-uri@3.1.2':
|
||||||
|
resolution: {integrity: sha512-bRISgCIjP20/tbWSPWMEi54QVPRZExkuD9lJL+UIxUKtwVJA8wW1Trb1jMs1RFXo1CBTNZ/5hpC9QvmKWdopKw==}
|
||||||
|
engines: {node: '>=6.0.0'}
|
||||||
|
|
||||||
'@jridgewell/sourcemap-codec@1.5.5':
|
'@jridgewell/sourcemap-codec@1.5.5':
|
||||||
resolution: {integrity: sha512-cYQ9310grqxueWbl+WuIUIaiUaDcj7WOq5fVhEljNVgRfOUhY9fy2zTvfoqWsnebh8Sl70VScFbICvJnLKB0Og==}
|
resolution: {integrity: sha512-cYQ9310grqxueWbl+WuIUIaiUaDcj7WOq5fVhEljNVgRfOUhY9fy2zTvfoqWsnebh8Sl70VScFbICvJnLKB0Og==}
|
||||||
|
|
||||||
|
'@jridgewell/trace-mapping@0.3.31':
|
||||||
|
resolution: {integrity: sha512-zzNR+SdQSDJzc8joaeP8QQoCQr8NuYx2dIIytl1QeBEZHJ9uW6hebsrYgbz8hJwUQao3TWCMtmfV8Nu1twOLAw==}
|
||||||
|
|
||||||
'@mswjs/interceptors@0.41.9':
|
'@mswjs/interceptors@0.41.9':
|
||||||
resolution: {integrity: sha512-VVPPgHyQ6ShqnrmDWuxjmUIsO9gWyOZFmuOfLd9LfBGQJwZfy0gvv9pbHSJuoFNIYC7ZDX9aoFwowjcdSC4E8w==}
|
resolution: {integrity: sha512-VVPPgHyQ6ShqnrmDWuxjmUIsO9gWyOZFmuOfLd9LfBGQJwZfy0gvv9pbHSJuoFNIYC7ZDX9aoFwowjcdSC4E8w==}
|
||||||
engines: {node: '>=18'}
|
engines: {node: '>=18'}
|
||||||
@@ -402,6 +421,100 @@ packages:
|
|||||||
'@standard-schema/spec@1.1.0':
|
'@standard-schema/spec@1.1.0':
|
||||||
resolution: {integrity: sha512-l2aFy5jALhniG5HgqrD6jXLi/rUWrKvqN/qJx6yoJsgKhblVd+iqqU4RCXavm/jPityDo5TCvKMnpjKnOriy0w==}
|
resolution: {integrity: sha512-l2aFy5jALhniG5HgqrD6jXLi/rUWrKvqN/qJx6yoJsgKhblVd+iqqU4RCXavm/jPityDo5TCvKMnpjKnOriy0w==}
|
||||||
|
|
||||||
|
'@tailwindcss/node@4.3.3':
|
||||||
|
resolution: {integrity: sha512-/T8IKEsf9VTU6tLjgC7+sv2mOPtQxzE2jMw7u4Tt40Tx+QSZxpzh95/H6cMKoja9XuW7iMdLJYBB0o9G1CaAgg==}
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-android-arm64@4.3.3':
|
||||||
|
resolution: {integrity: sha512-Y85A2gmPSkl5Ve5qR86GL4HT509cFqQh1aes9p3sSkyTPwt0Pppf3GkwGe4JPACcRYjgJIEhQgM6dBClnr0NYw==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
cpu: [arm64]
|
||||||
|
os: [android]
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-darwin-arm64@4.3.3':
|
||||||
|
resolution: {integrity: sha512-BiaWatpBcERQFDlOjRDpIVXuFK5PJez5SA4JMg6VYZdBYU+qKfV/vqjcIs+IYmtitf1xYQZTwXvU/8y4lfZUGw==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
cpu: [arm64]
|
||||||
|
os: [darwin]
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-darwin-x64@4.3.3':
|
||||||
|
resolution: {integrity: sha512-fAeUqfV5ndhxRwai8cXGzdLvul9utWOmeTkv69unv4ZXixjn61Z+p9lCWdwOwA3TYboG3BwdVuN/RDjhBRl0mw==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
cpu: [x64]
|
||||||
|
os: [darwin]
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-freebsd-x64@4.3.3':
|
||||||
|
resolution: {integrity: sha512-iyf5bV6+wnAlflVeEy7R25dupxTNECZN5QMI0qNT6eT+EgaGdZcKhGkr5SdoaWiLJ3spLqIY9VCeSGrwmtg4kw==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
cpu: [x64]
|
||||||
|
os: [freebsd]
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-linux-arm-gnueabihf@4.3.3':
|
||||||
|
resolution: {integrity: sha512-aAYUprJAJQWWbRrPvtjdroZ56Md+JM8pMiopS6xGEwDfLhqj+2ver2p4nU4Mb3CRqcMmNBjo8KkUgcxhkzVQGQ==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
cpu: [arm]
|
||||||
|
os: [linux]
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-linux-arm64-gnu@4.3.3':
|
||||||
|
resolution: {integrity: sha512-nDxldcEENOxZRzC2uu9jrutZdAAQtb+8WWDCSnWL1zvBk1+FN+x6MtDViPB5AJMfttVCUhehGWus3XBPgatM/w==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
cpu: [arm64]
|
||||||
|
os: [linux]
|
||||||
|
libc: [glibc]
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-linux-arm64-musl@4.3.3':
|
||||||
|
resolution: {integrity: sha512-Md44bD6veX/PC5iyF8cDVnw4HBIANZepRZZ7a8DQOvkfo5WUBwcp6iAuCUz23u+4SUkhJlD3eL7hNdW8ezd/kA==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
cpu: [arm64]
|
||||||
|
os: [linux]
|
||||||
|
libc: [musl]
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-linux-x64-gnu@4.3.3':
|
||||||
|
resolution: {integrity: sha512-tx7us1muwOKAKWao2v/GaafFeQboE6aj88vC6ziN2NCGcRm8gWUhwjzg+YdVB1e4boAtdtma4L43onunI6NS4w==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
cpu: [x64]
|
||||||
|
os: [linux]
|
||||||
|
libc: [glibc]
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-linux-x64-musl@4.3.3':
|
||||||
|
resolution: {integrity: sha512-SJxX60smvHgasZoBy11dX6YRjXJFovwWBoedhbQPOBzgFWBHGB+TVPWB9BxzR7TTxU8FQZAI2AyiNCMzFm8Img==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
cpu: [x64]
|
||||||
|
os: [linux]
|
||||||
|
libc: [musl]
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-wasm32-wasi@4.3.3':
|
||||||
|
resolution: {integrity: sha512-jx1+rPhY/5Ympkktd656HBWEBLxP7dH06losBLjjf5vgCODXvi9KhtftWcMIwTFIDqBr7cRnQkdLnAG+IOlGvQ==}
|
||||||
|
engines: {node: '>=14.0.0'}
|
||||||
|
cpu: [wasm32]
|
||||||
|
bundledDependencies:
|
||||||
|
- '@napi-rs/wasm-runtime'
|
||||||
|
- '@emnapi/core'
|
||||||
|
- '@emnapi/runtime'
|
||||||
|
- '@tybys/wasm-util'
|
||||||
|
- '@emnapi/wasi-threads'
|
||||||
|
- tslib
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-win32-arm64-msvc@4.3.3':
|
||||||
|
resolution: {integrity: sha512-3rc292Ca2ceK6Ulcc/bAVnTs/3nDtoPhyEKlgPv+yQJQi/JS/AMJlqzxvlDacL1nekbrcf6bTqp/jV4qgnPxNQ==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
cpu: [arm64]
|
||||||
|
os: [win32]
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-win32-x64-msvc@4.3.3':
|
||||||
|
resolution: {integrity: sha512-yJ0pwIVc/nYeGoV02WtsN8KYyLQv7kyI2wDnkezyJlGGjkd4QLwDGAwl47YpPJeuI0M0ObaXGSPjvWDPeTPggw==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
cpu: [x64]
|
||||||
|
os: [win32]
|
||||||
|
|
||||||
|
'@tailwindcss/oxide@4.3.3':
|
||||||
|
resolution: {integrity: sha512-krXjAikiaFSPaK/FkAQT5UTx3VormQaiZ5hBFlJZ9UFQGB/rwg1MZIhHAG9smMQRTdyJxP6Qt5MwMtdyU5FWrA==}
|
||||||
|
engines: {node: '>= 20'}
|
||||||
|
|
||||||
|
'@tailwindcss/vite@4.3.3':
|
||||||
|
resolution: {integrity: sha512-yYU8cogLeSh/ms2jh8Fj7jaba/EWa7Ja6GoUqYZaraEuCI5YS6ms6ObZgjjedm+jm6XZjdNRWBpPP6Z86oOxcw==}
|
||||||
|
peerDependencies:
|
||||||
|
vite: ^5.2.0 || ^6 || ^7 || ^8
|
||||||
|
|
||||||
'@tanstack/query-core@5.101.4':
|
'@tanstack/query-core@5.101.4':
|
||||||
resolution: {integrity: sha512-gNwcvOJcRbLWPOLG/2OBm+zM+Yv+MKsXKEOWC57USuZDEsI71hEErQsiEGx5wX9rzWWkfwM0fVSPoiIFSsxfiw==}
|
resolution: {integrity: sha512-gNwcvOJcRbLWPOLG/2OBm+zM+Yv+MKsXKEOWC57USuZDEsI71hEErQsiEGx5wX9rzWWkfwM0fVSPoiIFSsxfiw==}
|
||||||
|
|
||||||
@@ -1014,6 +1127,10 @@ packages:
|
|||||||
isexe@2.0.0:
|
isexe@2.0.0:
|
||||||
resolution: {integrity: sha512-RHxMLp9lnKHGHRng9QFhRCMbYAcVpn69smSGcq3f36xjgVVWThj4qqLbTLlq7Ssj8B+fIQ1EuCEGI2lKsyQeIw==}
|
resolution: {integrity: sha512-RHxMLp9lnKHGHRng9QFhRCMbYAcVpn69smSGcq3f36xjgVVWThj4qqLbTLlq7Ssj8B+fIQ1EuCEGI2lKsyQeIw==}
|
||||||
|
|
||||||
|
jiti@2.7.0:
|
||||||
|
resolution: {integrity: sha512-AC/7JofJvZGrrneWNaEnJeOLUx+JlGt7tNa0wZiRPT4MY1wmfKjt2+6O2p2uz2+skll8OZZmJMNqeke7kKbNgQ==}
|
||||||
|
hasBin: true
|
||||||
|
|
||||||
js-tokens@4.0.0:
|
js-tokens@4.0.0:
|
||||||
resolution: {integrity: sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ==}
|
resolution: {integrity: sha512-RdJUflcE3cUzKiMqQgsCu06FPu9UdIJO0beYbPhHN4k6apgJtifcoCtT9bcxOpYBtpD2kCM6Sbzg4CausW/PKQ==}
|
||||||
|
|
||||||
@@ -1051,36 +1168,73 @@ packages:
|
|||||||
resolution: {integrity: sha512-+bT2uH4E5LGE7h/n3evcS/sQlJXCpIp6ym8OWJ5eV6+67Dsql/LaaT7qJBAt2rzfoa/5QBGBhxDix1dMt2kQKQ==}
|
resolution: {integrity: sha512-+bT2uH4E5LGE7h/n3evcS/sQlJXCpIp6ym8OWJ5eV6+67Dsql/LaaT7qJBAt2rzfoa/5QBGBhxDix1dMt2kQKQ==}
|
||||||
engines: {node: '>= 0.8.0'}
|
engines: {node: '>= 0.8.0'}
|
||||||
|
|
||||||
|
lightningcss-android-arm64@1.32.0:
|
||||||
|
resolution: {integrity: sha512-YK7/ClTt4kAK0vo6w3X+Pnm0D2cf2vPHbhOXdoNti1Ga0al1P4TBZhwjATvjNwLEBCnKvjJc2jQgHXH0NEwlAg==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
cpu: [arm64]
|
||||||
|
os: [android]
|
||||||
|
|
||||||
lightningcss-android-arm64@1.33.0:
|
lightningcss-android-arm64@1.33.0:
|
||||||
resolution: {integrity: sha512-gEpRTalKdosp4Bb8qWtc2iOgE5SeIHlpS1up9bFq2wAyYhl1UdTObYiHe98zEM9SQvSoqQZ1IQD0JNpg3Ml5pg==}
|
resolution: {integrity: sha512-gEpRTalKdosp4Bb8qWtc2iOgE5SeIHlpS1up9bFq2wAyYhl1UdTObYiHe98zEM9SQvSoqQZ1IQD0JNpg3Ml5pg==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
cpu: [arm64]
|
cpu: [arm64]
|
||||||
os: [android]
|
os: [android]
|
||||||
|
|
||||||
|
lightningcss-darwin-arm64@1.32.0:
|
||||||
|
resolution: {integrity: sha512-RzeG9Ju5bag2Bv1/lwlVJvBE3q6TtXskdZLLCyfg5pt+HLz9BqlICO7LZM7VHNTTn/5PRhHFBSjk5lc4cmscPQ==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
cpu: [arm64]
|
||||||
|
os: [darwin]
|
||||||
|
|
||||||
lightningcss-darwin-arm64@1.33.0:
|
lightningcss-darwin-arm64@1.33.0:
|
||||||
resolution: {integrity: sha512-Sciaz8eenNTKn9b3t7+xr0ipTp9YxKQY4npwQ3mrRuL0BAVHBLyZxofhaKBAVtzmtRZ/zTyo0/to4B1uWG/Djg==}
|
resolution: {integrity: sha512-Sciaz8eenNTKn9b3t7+xr0ipTp9YxKQY4npwQ3mrRuL0BAVHBLyZxofhaKBAVtzmtRZ/zTyo0/to4B1uWG/Djg==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
cpu: [arm64]
|
cpu: [arm64]
|
||||||
os: [darwin]
|
os: [darwin]
|
||||||
|
|
||||||
|
lightningcss-darwin-x64@1.32.0:
|
||||||
|
resolution: {integrity: sha512-U+QsBp2m/s2wqpUYT/6wnlagdZbtZdndSmut/NJqlCcMLTWp5muCrID+K5UJ6jqD2BFshejCYXniPDbNh73V8w==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
cpu: [x64]
|
||||||
|
os: [darwin]
|
||||||
|
|
||||||
lightningcss-darwin-x64@1.33.0:
|
lightningcss-darwin-x64@1.33.0:
|
||||||
resolution: {integrity: sha512-Z5UPAxzrjlWNNyGy6i65cJzzvgJ5D3T6wMvs+gWpY9d7qRhANrxqAp6LhxIgZhWEw18RfJTGcRxjuLIBr+m8XQ==}
|
resolution: {integrity: sha512-Z5UPAxzrjlWNNyGy6i65cJzzvgJ5D3T6wMvs+gWpY9d7qRhANrxqAp6LhxIgZhWEw18RfJTGcRxjuLIBr+m8XQ==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
cpu: [x64]
|
cpu: [x64]
|
||||||
os: [darwin]
|
os: [darwin]
|
||||||
|
|
||||||
|
lightningcss-freebsd-x64@1.32.0:
|
||||||
|
resolution: {integrity: sha512-JCTigedEksZk3tHTTthnMdVfGf61Fky8Ji2E4YjUTEQX14xiy/lTzXnu1vwiZe3bYe0q+SpsSH/CTeDXK6WHig==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
cpu: [x64]
|
||||||
|
os: [freebsd]
|
||||||
|
|
||||||
lightningcss-freebsd-x64@1.33.0:
|
lightningcss-freebsd-x64@1.33.0:
|
||||||
resolution: {integrity: sha512-QQM/Ti/hQajJwCY+RiWuCZ9sdtI/XQk7nDK5vC8kkdwixezOlDgvDx7+RT+QjK6FcFT4MpsuoBnHIo/O3StRRg==}
|
resolution: {integrity: sha512-QQM/Ti/hQajJwCY+RiWuCZ9sdtI/XQk7nDK5vC8kkdwixezOlDgvDx7+RT+QjK6FcFT4MpsuoBnHIo/O3StRRg==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
cpu: [x64]
|
cpu: [x64]
|
||||||
os: [freebsd]
|
os: [freebsd]
|
||||||
|
|
||||||
|
lightningcss-linux-arm-gnueabihf@1.32.0:
|
||||||
|
resolution: {integrity: sha512-x6rnnpRa2GL0zQOkt6rts3YDPzduLpWvwAF6EMhXFVZXD4tPrBkEFqzGowzCsIWsPjqSK+tyNEODUBXeeVHSkw==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
cpu: [arm]
|
||||||
|
os: [linux]
|
||||||
|
|
||||||
lightningcss-linux-arm-gnueabihf@1.33.0:
|
lightningcss-linux-arm-gnueabihf@1.33.0:
|
||||||
resolution: {integrity: sha512-N7FVBe6iS24MlM6R/4RBTxGhQheZGs7tiQ9U32UtF75NzP5Q7xWPRqLBCKxlRQRk3rY1jCIPLzx7WzOhuUIRLQ==}
|
resolution: {integrity: sha512-N7FVBe6iS24MlM6R/4RBTxGhQheZGs7tiQ9U32UtF75NzP5Q7xWPRqLBCKxlRQRk3rY1jCIPLzx7WzOhuUIRLQ==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
cpu: [arm]
|
cpu: [arm]
|
||||||
os: [linux]
|
os: [linux]
|
||||||
|
|
||||||
|
lightningcss-linux-arm64-gnu@1.32.0:
|
||||||
|
resolution: {integrity: sha512-0nnMyoyOLRJXfbMOilaSRcLH3Jw5z9HDNGfT/gwCPgaDjnx0i8w7vBzFLFR1f6CMLKF8gVbebmkUN3fa/kQJpQ==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
cpu: [arm64]
|
||||||
|
os: [linux]
|
||||||
|
libc: [glibc]
|
||||||
|
|
||||||
lightningcss-linux-arm64-gnu@1.33.0:
|
lightningcss-linux-arm64-gnu@1.33.0:
|
||||||
resolution: {integrity: sha512-j2v/itmy4HlNxlc6voKXYgBqNi0Ng2LShg4z7GufpEgs05P+2suBVyi9I6YHq5uoVFx9ETin3eCEhLVyXGQnKg==}
|
resolution: {integrity: sha512-j2v/itmy4HlNxlc6voKXYgBqNi0Ng2LShg4z7GufpEgs05P+2suBVyi9I6YHq5uoVFx9ETin3eCEhLVyXGQnKg==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
@@ -1088,6 +1242,13 @@ packages:
|
|||||||
os: [linux]
|
os: [linux]
|
||||||
libc: [glibc]
|
libc: [glibc]
|
||||||
|
|
||||||
|
lightningcss-linux-arm64-musl@1.32.0:
|
||||||
|
resolution: {integrity: sha512-UpQkoenr4UJEzgVIYpI80lDFvRmPVg6oqboNHfoH4CQIfNA+HOrZ7Mo7KZP02dC6LjghPQJeBsvXhJod/wnIBg==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
cpu: [arm64]
|
||||||
|
os: [linux]
|
||||||
|
libc: [musl]
|
||||||
|
|
||||||
lightningcss-linux-arm64-musl@1.33.0:
|
lightningcss-linux-arm64-musl@1.33.0:
|
||||||
resolution: {integrity: sha512-yiO5ROMuYQgXbC60yjZU5CYSFZGKXL0HFATXt9mHJn1+zW55oCtMI9NfcVhYLMFDL7gV7oBPon/EmMMGg2OvtQ==}
|
resolution: {integrity: sha512-yiO5ROMuYQgXbC60yjZU5CYSFZGKXL0HFATXt9mHJn1+zW55oCtMI9NfcVhYLMFDL7gV7oBPon/EmMMGg2OvtQ==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
@@ -1095,6 +1256,13 @@ packages:
|
|||||||
os: [linux]
|
os: [linux]
|
||||||
libc: [musl]
|
libc: [musl]
|
||||||
|
|
||||||
|
lightningcss-linux-x64-gnu@1.32.0:
|
||||||
|
resolution: {integrity: sha512-V7Qr52IhZmdKPVr+Vtw8o+WLsQJYCTd8loIfpDaMRWGUZfBOYEJeyJIkqGIDMZPwPx24pUMfwSxxI8phr/MbOA==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
cpu: [x64]
|
||||||
|
os: [linux]
|
||||||
|
libc: [glibc]
|
||||||
|
|
||||||
lightningcss-linux-x64-gnu@1.33.0:
|
lightningcss-linux-x64-gnu@1.33.0:
|
||||||
resolution: {integrity: sha512-ar+Ju7LmcN0Jo4FpL4hpFybwNG9/3A/Br5KW2n2jyODg3MEZXaDYADdemoNS+BDNfMgKvylJLj4S5tyRActuAg==}
|
resolution: {integrity: sha512-ar+Ju7LmcN0Jo4FpL4hpFybwNG9/3A/Br5KW2n2jyODg3MEZXaDYADdemoNS+BDNfMgKvylJLj4S5tyRActuAg==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
@@ -1102,6 +1270,13 @@ packages:
|
|||||||
os: [linux]
|
os: [linux]
|
||||||
libc: [glibc]
|
libc: [glibc]
|
||||||
|
|
||||||
|
lightningcss-linux-x64-musl@1.32.0:
|
||||||
|
resolution: {integrity: sha512-bYcLp+Vb0awsiXg/80uCRezCYHNg1/l3mt0gzHnWV9XP1W5sKa5/TCdGWaR/zBM2PeF/HbsQv/j2URNOiVuxWg==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
cpu: [x64]
|
||||||
|
os: [linux]
|
||||||
|
libc: [musl]
|
||||||
|
|
||||||
lightningcss-linux-x64-musl@1.33.0:
|
lightningcss-linux-x64-musl@1.33.0:
|
||||||
resolution: {integrity: sha512-RYiYbkokw0trfKqqzfF55lginwEPrD3OJDfTuJzFs1MK6iFnDenaz1fqLLtX4ITG3OktJQXOeTaw1awrBAlZPw==}
|
resolution: {integrity: sha512-RYiYbkokw0trfKqqzfF55lginwEPrD3OJDfTuJzFs1MK6iFnDenaz1fqLLtX4ITG3OktJQXOeTaw1awrBAlZPw==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
@@ -1109,18 +1284,34 @@ packages:
|
|||||||
os: [linux]
|
os: [linux]
|
||||||
libc: [musl]
|
libc: [musl]
|
||||||
|
|
||||||
|
lightningcss-win32-arm64-msvc@1.32.0:
|
||||||
|
resolution: {integrity: sha512-8SbC8BR40pS6baCM8sbtYDSwEVQd4JlFTOlaD3gWGHfThTcABnNDBda6eTZeqbofalIJhFx0qKzgHJmcPTnGdw==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
cpu: [arm64]
|
||||||
|
os: [win32]
|
||||||
|
|
||||||
lightningcss-win32-arm64-msvc@1.33.0:
|
lightningcss-win32-arm64-msvc@1.33.0:
|
||||||
resolution: {integrity: sha512-1K+MPfLSFVpphzpdbfkhlWk6wBrTObBzS2T6db10PNOZgR9GoVsAWzwNyuhUYYbTp23j+4RrncfujZ4uAzXvwA==}
|
resolution: {integrity: sha512-1K+MPfLSFVpphzpdbfkhlWk6wBrTObBzS2T6db10PNOZgR9GoVsAWzwNyuhUYYbTp23j+4RrncfujZ4uAzXvwA==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
cpu: [arm64]
|
cpu: [arm64]
|
||||||
os: [win32]
|
os: [win32]
|
||||||
|
|
||||||
|
lightningcss-win32-x64-msvc@1.32.0:
|
||||||
|
resolution: {integrity: sha512-Amq9B/SoZYdDi1kFrojnoqPLxYhQ4Wo5XiL8EVJrVsB8ARoC1PWW6VGtT0WKCemjy8aC+louJnjS7U18x3b06Q==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
cpu: [x64]
|
||||||
|
os: [win32]
|
||||||
|
|
||||||
lightningcss-win32-x64-msvc@1.33.0:
|
lightningcss-win32-x64-msvc@1.33.0:
|
||||||
resolution: {integrity: sha512-OlEICDx/Xl0FqSp4bry8zFnCvGpig3Gl4gCquvYwHuqJKEC1+n9NgDniFvqHGmMv1ZkqDJrDqKKSykTDX+ehuA==}
|
resolution: {integrity: sha512-OlEICDx/Xl0FqSp4bry8zFnCvGpig3Gl4gCquvYwHuqJKEC1+n9NgDniFvqHGmMv1ZkqDJrDqKKSykTDX+ehuA==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
cpu: [x64]
|
cpu: [x64]
|
||||||
os: [win32]
|
os: [win32]
|
||||||
|
|
||||||
|
lightningcss@1.32.0:
|
||||||
|
resolution: {integrity: sha512-NXYBzinNrblfraPGyrbPoD19C1h9lfI/1mzgWYvXUTe414Gz/X1FD2XBZSZM7rRTrMA8JL3OtAaGifrIKhQ5yQ==}
|
||||||
|
engines: {node: '>= 12.0.0'}
|
||||||
|
|
||||||
lightningcss@1.33.0:
|
lightningcss@1.33.0:
|
||||||
resolution: {integrity: sha512-WkUDrojuJs0xkgGf2udWxa3yGBRxPtxUkB79i6aCZLRgc7PM8fZe9TosfPDcvEpQZbuFASnHYmRLBLUbmLOIIA==}
|
resolution: {integrity: sha512-WkUDrojuJs0xkgGf2udWxa3yGBRxPtxUkB79i6aCZLRgc7PM8fZe9TosfPDcvEpQZbuFASnHYmRLBLUbmLOIIA==}
|
||||||
engines: {node: '>= 12.0.0'}
|
engines: {node: '>= 12.0.0'}
|
||||||
@@ -1404,6 +1595,9 @@ packages:
|
|||||||
resolution: {integrity: sha512-yEFYrVhod+hdNyx7g5Bnkkb0G6si8HJurOoOEgC8B/O0uXLHlaey/65KRv6cuWBNhBgHKAROVpc7QyYqE5gFng==}
|
resolution: {integrity: sha512-yEFYrVhod+hdNyx7g5Bnkkb0G6si8HJurOoOEgC8B/O0uXLHlaey/65KRv6cuWBNhBgHKAROVpc7QyYqE5gFng==}
|
||||||
engines: {node: '>=20'}
|
engines: {node: '>=20'}
|
||||||
|
|
||||||
|
tailwindcss@4.3.3:
|
||||||
|
resolution: {integrity: sha512-gOhV3P7ufE62QDGg1zVaTgCR+EtPv92k2nIhVcVKcLmxT1sUBsQGhnZj175j+MqRt4zLF7ic+sCYjfhxMxj7YQ==}
|
||||||
|
|
||||||
tapable@2.3.3:
|
tapable@2.3.3:
|
||||||
resolution: {integrity: sha512-uxc/zpqFg6x7C8vOE7lh6Lbda8eEL9zmVm/PLeTPBRhh1xCgdWaQ+J1CUieGpIfm2HdtsUpRv+HshiasBMcc6A==}
|
resolution: {integrity: sha512-uxc/zpqFg6x7C8vOE7lh6Lbda8eEL9zmVm/PLeTPBRhh1xCgdWaQ+J1CUieGpIfm2HdtsUpRv+HshiasBMcc6A==}
|
||||||
engines: {node: '>=6'}
|
engines: {node: '>=6'}
|
||||||
@@ -1707,9 +1901,9 @@ snapshots:
|
|||||||
tslib: 2.8.1
|
tslib: 2.8.1
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
'@eslint-community/eslint-utils@4.10.1(eslint@10.8.0(supports-color@7.2.0))':
|
'@eslint-community/eslint-utils@4.10.1(eslint@10.8.0(jiti@2.7.0)(supports-color@7.2.0))':
|
||||||
dependencies:
|
dependencies:
|
||||||
eslint: 10.8.0(supports-color@7.2.0)
|
eslint: 10.8.0(jiti@2.7.0)(supports-color@7.2.0)
|
||||||
eslint-visitor-keys: 3.4.3
|
eslint-visitor-keys: 3.4.3
|
||||||
|
|
||||||
'@eslint-community/regexpp@4.12.2': {}
|
'@eslint-community/regexpp@4.12.2': {}
|
||||||
@@ -1730,9 +1924,9 @@ snapshots:
|
|||||||
dependencies:
|
dependencies:
|
||||||
'@types/json-schema': 7.0.15
|
'@types/json-schema': 7.0.15
|
||||||
|
|
||||||
'@eslint/js@10.0.1(eslint@10.8.0(supports-color@7.2.0))':
|
'@eslint/js@10.0.1(eslint@10.8.0(jiti@2.7.0)(supports-color@7.2.0))':
|
||||||
optionalDependencies:
|
optionalDependencies:
|
||||||
eslint: 10.8.0(supports-color@7.2.0)
|
eslint: 10.8.0(jiti@2.7.0)(supports-color@7.2.0)
|
||||||
|
|
||||||
'@eslint/object-schema@3.0.5': {}
|
'@eslint/object-schema@3.0.5': {}
|
||||||
|
|
||||||
@@ -1786,8 +1980,25 @@ snapshots:
|
|||||||
optionalDependencies:
|
optionalDependencies:
|
||||||
'@types/node': 24.13.3
|
'@types/node': 24.13.3
|
||||||
|
|
||||||
|
'@jridgewell/gen-mapping@0.3.13':
|
||||||
|
dependencies:
|
||||||
|
'@jridgewell/sourcemap-codec': 1.5.5
|
||||||
|
'@jridgewell/trace-mapping': 0.3.31
|
||||||
|
|
||||||
|
'@jridgewell/remapping@2.3.5':
|
||||||
|
dependencies:
|
||||||
|
'@jridgewell/gen-mapping': 0.3.13
|
||||||
|
'@jridgewell/trace-mapping': 0.3.31
|
||||||
|
|
||||||
|
'@jridgewell/resolve-uri@3.1.2': {}
|
||||||
|
|
||||||
'@jridgewell/sourcemap-codec@1.5.5': {}
|
'@jridgewell/sourcemap-codec@1.5.5': {}
|
||||||
|
|
||||||
|
'@jridgewell/trace-mapping@0.3.31':
|
||||||
|
dependencies:
|
||||||
|
'@jridgewell/resolve-uri': 3.1.2
|
||||||
|
'@jridgewell/sourcemap-codec': 1.5.5
|
||||||
|
|
||||||
'@mswjs/interceptors@0.41.9':
|
'@mswjs/interceptors@0.41.9':
|
||||||
dependencies:
|
dependencies:
|
||||||
'@open-draft/deferred-promise': 2.2.0
|
'@open-draft/deferred-promise': 2.2.0
|
||||||
@@ -1874,6 +2085,74 @@ snapshots:
|
|||||||
|
|
||||||
'@standard-schema/spec@1.1.0': {}
|
'@standard-schema/spec@1.1.0': {}
|
||||||
|
|
||||||
|
'@tailwindcss/node@4.3.3':
|
||||||
|
dependencies:
|
||||||
|
'@jridgewell/remapping': 2.3.5
|
||||||
|
enhanced-resolve: 5.24.2
|
||||||
|
jiti: 2.7.0
|
||||||
|
lightningcss: 1.32.0
|
||||||
|
magic-string: 0.30.21
|
||||||
|
source-map-js: 1.2.1
|
||||||
|
tailwindcss: 4.3.3
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-android-arm64@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-darwin-arm64@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-darwin-x64@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-freebsd-x64@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-linux-arm-gnueabihf@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-linux-arm64-gnu@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-linux-arm64-musl@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-linux-x64-gnu@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-linux-x64-musl@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-wasm32-wasi@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-win32-arm64-msvc@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide-win32-x64-msvc@4.3.3':
|
||||||
|
optional: true
|
||||||
|
|
||||||
|
'@tailwindcss/oxide@4.3.3':
|
||||||
|
optionalDependencies:
|
||||||
|
'@tailwindcss/oxide-android-arm64': 4.3.3
|
||||||
|
'@tailwindcss/oxide-darwin-arm64': 4.3.3
|
||||||
|
'@tailwindcss/oxide-darwin-x64': 4.3.3
|
||||||
|
'@tailwindcss/oxide-freebsd-x64': 4.3.3
|
||||||
|
'@tailwindcss/oxide-linux-arm-gnueabihf': 4.3.3
|
||||||
|
'@tailwindcss/oxide-linux-arm64-gnu': 4.3.3
|
||||||
|
'@tailwindcss/oxide-linux-arm64-musl': 4.3.3
|
||||||
|
'@tailwindcss/oxide-linux-x64-gnu': 4.3.3
|
||||||
|
'@tailwindcss/oxide-linux-x64-musl': 4.3.3
|
||||||
|
'@tailwindcss/oxide-wasm32-wasi': 4.3.3
|
||||||
|
'@tailwindcss/oxide-win32-arm64-msvc': 4.3.3
|
||||||
|
'@tailwindcss/oxide-win32-x64-msvc': 4.3.3
|
||||||
|
|
||||||
|
'@tailwindcss/vite@4.3.3(vite@8.1.5(@types/node@24.13.3)(jiti@2.7.0))':
|
||||||
|
dependencies:
|
||||||
|
'@tailwindcss/node': 4.3.3
|
||||||
|
'@tailwindcss/oxide': 4.3.3
|
||||||
|
tailwindcss: 4.3.3
|
||||||
|
vite: 8.1.5(@types/node@24.13.3)(jiti@2.7.0)
|
||||||
|
|
||||||
'@tanstack/query-core@5.101.4': {}
|
'@tanstack/query-core@5.101.4': {}
|
||||||
|
|
||||||
'@tanstack/react-query@5.101.4(react@19.2.8)':
|
'@tanstack/react-query@5.101.4(react@19.2.8)':
|
||||||
@@ -2014,10 +2293,10 @@ snapshots:
|
|||||||
'@typescript/typescript-win32-x64@7.0.2':
|
'@typescript/typescript-win32-x64@7.0.2':
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
'@vitejs/plugin-react@6.0.4(vite@8.1.5(@types/node@24.13.3))':
|
'@vitejs/plugin-react@6.0.4(vite@8.1.5(@types/node@24.13.3)(jiti@2.7.0))':
|
||||||
dependencies:
|
dependencies:
|
||||||
'@rolldown/pluginutils': 1.0.1
|
'@rolldown/pluginutils': 1.0.1
|
||||||
vite: 8.1.5(@types/node@24.13.3)
|
vite: 8.1.5(@types/node@24.13.3)(jiti@2.7.0)
|
||||||
|
|
||||||
'@vitest/expect@4.1.10':
|
'@vitest/expect@4.1.10':
|
||||||
dependencies:
|
dependencies:
|
||||||
@@ -2028,14 +2307,14 @@ snapshots:
|
|||||||
chai: 6.2.2
|
chai: 6.2.2
|
||||||
tinyrainbow: 3.1.0
|
tinyrainbow: 3.1.0
|
||||||
|
|
||||||
'@vitest/mocker@4.1.10(msw@2.15.0(@types/node@24.13.3)(typescript@7.0.2))(vite@8.1.5(@types/node@24.13.3))':
|
'@vitest/mocker@4.1.10(msw@2.15.0(@types/node@24.13.3)(typescript@7.0.2))(vite@8.1.5(@types/node@24.13.3)(jiti@2.7.0))':
|
||||||
dependencies:
|
dependencies:
|
||||||
'@vitest/spy': 4.1.10
|
'@vitest/spy': 4.1.10
|
||||||
estree-walker: 3.0.3
|
estree-walker: 3.0.3
|
||||||
magic-string: 0.30.21
|
magic-string: 0.30.21
|
||||||
optionalDependencies:
|
optionalDependencies:
|
||||||
msw: 2.15.0(@types/node@24.13.3)(typescript@7.0.2)
|
msw: 2.15.0(@types/node@24.13.3)(typescript@7.0.2)
|
||||||
vite: 8.1.5(@types/node@24.13.3)
|
vite: 8.1.5(@types/node@24.13.3)(jiti@2.7.0)
|
||||||
|
|
||||||
'@vitest/pretty-format@4.1.10':
|
'@vitest/pretty-format@4.1.10':
|
||||||
dependencies:
|
dependencies:
|
||||||
@@ -2228,9 +2507,9 @@ snapshots:
|
|||||||
|
|
||||||
eslint-visitor-keys@5.0.1: {}
|
eslint-visitor-keys@5.0.1: {}
|
||||||
|
|
||||||
eslint@10.8.0(supports-color@7.2.0):
|
eslint@10.8.0(jiti@2.7.0)(supports-color@7.2.0):
|
||||||
dependencies:
|
dependencies:
|
||||||
'@eslint-community/eslint-utils': 4.10.1(eslint@10.8.0(supports-color@7.2.0))
|
'@eslint-community/eslint-utils': 4.10.1(eslint@10.8.0(jiti@2.7.0)(supports-color@7.2.0))
|
||||||
'@eslint-community/regexpp': 4.12.2
|
'@eslint-community/regexpp': 4.12.2
|
||||||
'@eslint/config-array': 0.23.5(supports-color@7.2.0)
|
'@eslint/config-array': 0.23.5(supports-color@7.2.0)
|
||||||
'@eslint/config-helpers': 0.7.0
|
'@eslint/config-helpers': 0.7.0
|
||||||
@@ -2260,6 +2539,8 @@ snapshots:
|
|||||||
minimatch: 10.2.5
|
minimatch: 10.2.5
|
||||||
natural-compare: 1.4.0
|
natural-compare: 1.4.0
|
||||||
optionator: 0.9.4
|
optionator: 0.9.4
|
||||||
|
optionalDependencies:
|
||||||
|
jiti: 2.7.0
|
||||||
transitivePeerDependencies:
|
transitivePeerDependencies:
|
||||||
- supports-color
|
- supports-color
|
||||||
|
|
||||||
@@ -2401,6 +2682,8 @@ snapshots:
|
|||||||
|
|
||||||
isexe@2.0.0: {}
|
isexe@2.0.0: {}
|
||||||
|
|
||||||
|
jiti@2.7.0: {}
|
||||||
|
|
||||||
js-tokens@4.0.0: {}
|
js-tokens@4.0.0: {}
|
||||||
|
|
||||||
jsdom@29.1.1:
|
jsdom@29.1.1:
|
||||||
@@ -2448,39 +2731,88 @@ snapshots:
|
|||||||
prelude-ls: 1.2.1
|
prelude-ls: 1.2.1
|
||||||
type-check: 0.4.0
|
type-check: 0.4.0
|
||||||
|
|
||||||
|
lightningcss-android-arm64@1.32.0:
|
||||||
|
optional: true
|
||||||
|
|
||||||
lightningcss-android-arm64@1.33.0:
|
lightningcss-android-arm64@1.33.0:
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
lightningcss-darwin-arm64@1.32.0:
|
||||||
|
optional: true
|
||||||
|
|
||||||
lightningcss-darwin-arm64@1.33.0:
|
lightningcss-darwin-arm64@1.33.0:
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
lightningcss-darwin-x64@1.32.0:
|
||||||
|
optional: true
|
||||||
|
|
||||||
lightningcss-darwin-x64@1.33.0:
|
lightningcss-darwin-x64@1.33.0:
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
lightningcss-freebsd-x64@1.32.0:
|
||||||
|
optional: true
|
||||||
|
|
||||||
lightningcss-freebsd-x64@1.33.0:
|
lightningcss-freebsd-x64@1.33.0:
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
lightningcss-linux-arm-gnueabihf@1.32.0:
|
||||||
|
optional: true
|
||||||
|
|
||||||
lightningcss-linux-arm-gnueabihf@1.33.0:
|
lightningcss-linux-arm-gnueabihf@1.33.0:
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
lightningcss-linux-arm64-gnu@1.32.0:
|
||||||
|
optional: true
|
||||||
|
|
||||||
lightningcss-linux-arm64-gnu@1.33.0:
|
lightningcss-linux-arm64-gnu@1.33.0:
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
lightningcss-linux-arm64-musl@1.32.0:
|
||||||
|
optional: true
|
||||||
|
|
||||||
lightningcss-linux-arm64-musl@1.33.0:
|
lightningcss-linux-arm64-musl@1.33.0:
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
lightningcss-linux-x64-gnu@1.32.0:
|
||||||
|
optional: true
|
||||||
|
|
||||||
lightningcss-linux-x64-gnu@1.33.0:
|
lightningcss-linux-x64-gnu@1.33.0:
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
lightningcss-linux-x64-musl@1.32.0:
|
||||||
|
optional: true
|
||||||
|
|
||||||
lightningcss-linux-x64-musl@1.33.0:
|
lightningcss-linux-x64-musl@1.33.0:
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
lightningcss-win32-arm64-msvc@1.32.0:
|
||||||
|
optional: true
|
||||||
|
|
||||||
lightningcss-win32-arm64-msvc@1.33.0:
|
lightningcss-win32-arm64-msvc@1.33.0:
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
lightningcss-win32-x64-msvc@1.32.0:
|
||||||
|
optional: true
|
||||||
|
|
||||||
lightningcss-win32-x64-msvc@1.33.0:
|
lightningcss-win32-x64-msvc@1.33.0:
|
||||||
optional: true
|
optional: true
|
||||||
|
|
||||||
|
lightningcss@1.32.0:
|
||||||
|
dependencies:
|
||||||
|
detect-libc: 2.1.2
|
||||||
|
optionalDependencies:
|
||||||
|
lightningcss-android-arm64: 1.32.0
|
||||||
|
lightningcss-darwin-arm64: 1.32.0
|
||||||
|
lightningcss-darwin-x64: 1.32.0
|
||||||
|
lightningcss-freebsd-x64: 1.32.0
|
||||||
|
lightningcss-linux-arm-gnueabihf: 1.32.0
|
||||||
|
lightningcss-linux-arm64-gnu: 1.32.0
|
||||||
|
lightningcss-linux-arm64-musl: 1.32.0
|
||||||
|
lightningcss-linux-x64-gnu: 1.32.0
|
||||||
|
lightningcss-linux-x64-musl: 1.32.0
|
||||||
|
lightningcss-win32-arm64-msvc: 1.32.0
|
||||||
|
lightningcss-win32-x64-msvc: 1.32.0
|
||||||
|
|
||||||
lightningcss@1.33.0:
|
lightningcss@1.33.0:
|
||||||
dependencies:
|
dependencies:
|
||||||
detect-libc: 2.1.2
|
detect-libc: 2.1.2
|
||||||
@@ -2752,6 +3084,8 @@ snapshots:
|
|||||||
|
|
||||||
tagged-tag@1.0.0: {}
|
tagged-tag@1.0.0: {}
|
||||||
|
|
||||||
|
tailwindcss@4.3.3: {}
|
||||||
|
|
||||||
tapable@2.3.3: {}
|
tapable@2.3.3: {}
|
||||||
|
|
||||||
tinybench@2.9.0: {}
|
tinybench@2.9.0: {}
|
||||||
@@ -2836,7 +3170,7 @@ snapshots:
|
|||||||
dependencies:
|
dependencies:
|
||||||
punycode: 2.3.1
|
punycode: 2.3.1
|
||||||
|
|
||||||
vite@8.1.5(@types/node@24.13.3):
|
vite@8.1.5(@types/node@24.13.3)(jiti@2.7.0):
|
||||||
dependencies:
|
dependencies:
|
||||||
lightningcss: 1.33.0
|
lightningcss: 1.33.0
|
||||||
picomatch: 4.0.5
|
picomatch: 4.0.5
|
||||||
@@ -2846,11 +3180,12 @@ snapshots:
|
|||||||
optionalDependencies:
|
optionalDependencies:
|
||||||
'@types/node': 24.13.3
|
'@types/node': 24.13.3
|
||||||
fsevents: 2.3.3
|
fsevents: 2.3.3
|
||||||
|
jiti: 2.7.0
|
||||||
|
|
||||||
vitest@4.1.10(@types/node@24.13.3)(jsdom@29.1.1)(msw@2.15.0(@types/node@24.13.3)(typescript@7.0.2))(vite@8.1.5(@types/node@24.13.3)):
|
vitest@4.1.10(@types/node@24.13.3)(jsdom@29.1.1)(msw@2.15.0(@types/node@24.13.3)(typescript@7.0.2))(vite@8.1.5(@types/node@24.13.3)(jiti@2.7.0)):
|
||||||
dependencies:
|
dependencies:
|
||||||
'@vitest/expect': 4.1.10
|
'@vitest/expect': 4.1.10
|
||||||
'@vitest/mocker': 4.1.10(msw@2.15.0(@types/node@24.13.3)(typescript@7.0.2))(vite@8.1.5(@types/node@24.13.3))
|
'@vitest/mocker': 4.1.10(msw@2.15.0(@types/node@24.13.3)(typescript@7.0.2))(vite@8.1.5(@types/node@24.13.3)(jiti@2.7.0))
|
||||||
'@vitest/pretty-format': 4.1.10
|
'@vitest/pretty-format': 4.1.10
|
||||||
'@vitest/runner': 4.1.10
|
'@vitest/runner': 4.1.10
|
||||||
'@vitest/snapshot': 4.1.10
|
'@vitest/snapshot': 4.1.10
|
||||||
@@ -2867,7 +3202,7 @@ snapshots:
|
|||||||
tinyexec: 1.2.4
|
tinyexec: 1.2.4
|
||||||
tinyglobby: 0.2.17
|
tinyglobby: 0.2.17
|
||||||
tinyrainbow: 3.1.0
|
tinyrainbow: 3.1.0
|
||||||
vite: 8.1.5(@types/node@24.13.3)
|
vite: 8.1.5(@types/node@24.13.3)(jiti@2.7.0)
|
||||||
why-is-node-running: 2.3.0
|
why-is-node-running: 2.3.0
|
||||||
optionalDependencies:
|
optionalDependencies:
|
||||||
'@types/node': 24.13.3
|
'@types/node': 24.13.3
|
||||||
|
|||||||
@@ -0,0 +1,11 @@
|
|||||||
|
{
|
||||||
|
"schemaVersion": 1,
|
||||||
|
"appVersion": "0.1.0",
|
||||||
|
"buildId": "local-build",
|
||||||
|
"commitSha": "local",
|
||||||
|
"configSchemaVersion": "1",
|
||||||
|
"apiContractVersion": "1",
|
||||||
|
"assetManifestHash": "generated-during-build",
|
||||||
|
"releaseId": "local-release",
|
||||||
|
"builtAt": "1970-01-01T00:00:00.000Z"
|
||||||
|
}
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||||
|
"$id": "build-manifest.schema.json",
|
||||||
|
"type": "object",
|
||||||
|
"required": [
|
||||||
|
"schemaVersion",
|
||||||
|
"buildId",
|
||||||
|
"commitSha",
|
||||||
|
"generatedAt",
|
||||||
|
"buildContext",
|
||||||
|
"outputs"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"schemaVersion": { "const": 1 },
|
||||||
|
"buildId": { "type": "string", "minLength": 1 },
|
||||||
|
"commitSha": { "type": "string", "minLength": 1 },
|
||||||
|
"generatedAt": { "type": "string", "format": "date-time" },
|
||||||
|
"buildContext": {
|
||||||
|
"type": "object",
|
||||||
|
"required": ["nodeVersion", "packageManagerVersion", "runnerImage"],
|
||||||
|
"properties": {
|
||||||
|
"nodeVersion": { "type": "string" },
|
||||||
|
"packageManagerVersion": { "type": "string" },
|
||||||
|
"runnerImage": { "type": "string" }
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
},
|
||||||
|
"outputs": {
|
||||||
|
"type": "object",
|
||||||
|
"required": ["directory", "viteManifest"],
|
||||||
|
"properties": {
|
||||||
|
"directory": { "type": "string" },
|
||||||
|
"viteManifest": { "type": "string" }
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
}
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
{
|
||||||
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
||||||
|
"type": "object",
|
||||||
|
"required": [
|
||||||
|
"schemaVersion",
|
||||||
|
"generatedAt",
|
||||||
|
"compatibilityImpact",
|
||||||
|
"failures",
|
||||||
|
"registries"
|
||||||
|
],
|
||||||
|
"properties": {
|
||||||
|
"schemaVersion": { "const": 1 },
|
||||||
|
"generatedAt": { "type": "string", "format": "date-time" },
|
||||||
|
"compatibilityImpact": {
|
||||||
|
"enum": ["none", "additive", "behavior-change", "breaking"]
|
||||||
|
},
|
||||||
|
"failures": { "type": "array", "maxItems": 0 },
|
||||||
|
"registries": {
|
||||||
|
"type": "array",
|
||||||
|
"minItems": 8,
|
||||||
|
"maxItems": 8,
|
||||||
|
"items": {
|
||||||
|
"type": "object",
|
||||||
|
"required": ["registryId", "owner", "source", "rowCount", "rows"]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"additionalProperties": false
|
||||||
|
}
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
import { readdir } from "node:fs/promises";
|
||||||
|
import { spawnSync } from "node:child_process";
|
||||||
|
|
||||||
|
const pnpmCli = /** @type {string} */ (process.env.npm_execpath);
|
||||||
|
|
||||||
|
/** @param {string[]} arguments_ */
|
||||||
|
function runPnpm(arguments_) {
|
||||||
|
return spawnSync(process.execPath, [pnpmCli, ...arguments_], {
|
||||||
|
encoding: "utf8",
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const allowed = runPnpm([
|
||||||
|
"exec",
|
||||||
|
"eslint",
|
||||||
|
"tests/fixtures/security/allowed",
|
||||||
|
"--no-ignore",
|
||||||
|
"--max-warnings=0",
|
||||||
|
]);
|
||||||
|
const forbidden = runPnpm([
|
||||||
|
"exec",
|
||||||
|
"eslint",
|
||||||
|
"tests/fixtures/security/forbidden",
|
||||||
|
"--no-ignore",
|
||||||
|
"--max-warnings=0",
|
||||||
|
]);
|
||||||
|
|
||||||
|
const distFiles = await readdir("dist", { recursive: true });
|
||||||
|
const publicSourceMaps = distFiles.filter((file) => String(file).endsWith(".map"));
|
||||||
|
|
||||||
|
if (allowed.status !== 0 || forbidden.status === 0 || publicSourceMaps.length > 0) {
|
||||||
|
process.stderr.write(allowed.stderr || allowed.stdout);
|
||||||
|
process.stderr.write(forbidden.stderr || forbidden.stdout);
|
||||||
|
if (publicSourceMaps.length > 0) {
|
||||||
|
process.stderr.write(`Public source maps found: ${publicSourceMaps.join(", ")}\n`);
|
||||||
|
}
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
process.stdout.write(
|
||||||
|
"Browser security fixtures: injection rejected, public source maps absent\n",
|
||||||
|
);
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
import { classifyObjectSchemaChange } from "../src/application/policies/compatibility.js";
|
||||||
|
|
||||||
|
const fixtures = JSON.parse(
|
||||||
|
await readFile("config/compatibility/fixtures.json", "utf8"),
|
||||||
|
);
|
||||||
|
const results = [];
|
||||||
|
|
||||||
|
for (const [family, cases] of Object.entries(fixtures.families)) {
|
||||||
|
for (const expected of ["additive", "breaking"]) {
|
||||||
|
const fixture = cases[expected];
|
||||||
|
const actual = classifyObjectSchemaChange(fixture.before, fixture.after);
|
||||||
|
results.push({ family, expected, actual, passed: actual === expected });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
await mkdir("artifacts/release", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/release/compatibility.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
generatedAt: new Date().toISOString(),
|
||||||
|
rules: [
|
||||||
|
"additive changes preserve required fields",
|
||||||
|
"breaking changes require version bump and migration, discard, fallback, or rollback",
|
||||||
|
"config and API major versions must match",
|
||||||
|
"incompatible persisted cache is discarded by default",
|
||||||
|
"rollback uses a coherent compatibility tuple",
|
||||||
|
],
|
||||||
|
results,
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
if (results.some((result) => !result.passed)) {
|
||||||
|
process.stderr.write("Compatibility fixture classification failed.\n");
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write("Compatibility fixtures: PASS\n");
|
||||||
@@ -0,0 +1,112 @@
|
|||||||
|
import { access, mkdir, readFile, writeFile } from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
import { pathToFileURL } from "node:url";
|
||||||
|
|
||||||
|
const governance = JSON.parse(
|
||||||
|
await readFile("config/contracts/registry-governance.json", "utf8"),
|
||||||
|
);
|
||||||
|
const failures = [];
|
||||||
|
const owners = new Map();
|
||||||
|
const snapshots = [];
|
||||||
|
|
||||||
|
for (const specification of governance.registries) {
|
||||||
|
if (owners.has(specification.registryId)) {
|
||||||
|
failures.push(`duplicate owner for ${specification.registryId}`);
|
||||||
|
}
|
||||||
|
owners.set(specification.registryId, specification.owner);
|
||||||
|
|
||||||
|
let rows = specification.declaredRows;
|
||||||
|
try {
|
||||||
|
await access(specification.path);
|
||||||
|
const module = await import(
|
||||||
|
`${pathToFileURL(path.resolve(specification.path)).href}?registry-check=${Date.now()}`
|
||||||
|
);
|
||||||
|
rows = module[specification.exportName];
|
||||||
|
} catch {
|
||||||
|
if (!rows) failures.push(`missing registry source ${specification.path}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!rows || typeof rows !== "object" || Array.isArray(rows)) {
|
||||||
|
failures.push(`${specification.registryId} is not an object registry`);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const [rowName, row] of Object.entries(rows)) {
|
||||||
|
if (!row || typeof row !== "object" || Array.isArray(row)) {
|
||||||
|
failures.push(`${specification.registryId}.${rowName} is not an object`);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
for (const field of specification.requiredFields) {
|
||||||
|
if (!(field in row)) {
|
||||||
|
failures.push(`${specification.registryId}.${rowName} missing ${field}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
snapshots.push({
|
||||||
|
registryId: specification.registryId,
|
||||||
|
owner: specification.owner,
|
||||||
|
source: specification.path,
|
||||||
|
rowCount: Object.keys(rows).length,
|
||||||
|
rows,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const sourceFiles = [
|
||||||
|
"src/application",
|
||||||
|
"src/presentation",
|
||||||
|
"src/domain",
|
||||||
|
];
|
||||||
|
const adHocPatterns = [
|
||||||
|
{ name: "direct fetch", expression: /\bfetch\s*\(/ },
|
||||||
|
{ name: "direct localStorage", expression: /\blocalStorage\.(?:get|set|remove)Item/ },
|
||||||
|
{ name: "direct import.meta.env", expression: /\bimport\.meta\.env\./ },
|
||||||
|
{ name: "raw API path", expression: /["']\/api\// },
|
||||||
|
];
|
||||||
|
|
||||||
|
/** @param {string} directory */
|
||||||
|
async function scanDirectory(directory) {
|
||||||
|
const entries = await import("node:fs/promises").then(({ readdir }) =>
|
||||||
|
readdir(directory, { withFileTypes: true }),
|
||||||
|
);
|
||||||
|
for (const entry of entries) {
|
||||||
|
const target = path.join(directory, entry.name);
|
||||||
|
if (entry.isDirectory()) {
|
||||||
|
await scanDirectory(target);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if (!/\.(js|jsx|mjs)$/.test(entry.name)) continue;
|
||||||
|
const content = await readFile(target, "utf8");
|
||||||
|
for (const pattern of adHocPatterns) {
|
||||||
|
if (pattern.expression.test(content)) {
|
||||||
|
failures.push(`ad-hoc ${pattern.name} in ${target}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const sourceDirectory of sourceFiles) {
|
||||||
|
await scanDirectory(sourceDirectory);
|
||||||
|
}
|
||||||
|
|
||||||
|
await mkdir("artifacts/quality", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/quality/registries.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
generatedAt: new Date().toISOString(),
|
||||||
|
compatibilityImpact: governance.compatibilityImpact.current,
|
||||||
|
failures,
|
||||||
|
registries: snapshots,
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
if (failures.length > 0) {
|
||||||
|
process.stderr.write(`Registry governance failed:\n${failures.join("\n")}\n`);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(`Registry governance: ${snapshots.length} registries PASS\n`);
|
||||||
@@ -1,3 +1,4 @@
|
|||||||
|
import { createHash } from "node:crypto";
|
||||||
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
||||||
import process from "node:process";
|
import process from "node:process";
|
||||||
|
|
||||||
@@ -5,13 +6,23 @@ const packageJson = JSON.parse(await readFile("package.json", "utf8"));
|
|||||||
const packageManagerVersion = packageJson.packageManager.split("@").at(-1);
|
const packageManagerVersion = packageJson.packageManager.split("@").at(-1);
|
||||||
const buildId = process.env.VITE_BUILD_ID ?? "local-build";
|
const buildId = process.env.VITE_BUILD_ID ?? "local-build";
|
||||||
const commitSha = process.env.VITE_COMMIT_SHA ?? "local";
|
const commitSha = process.env.VITE_COMMIT_SHA ?? "local";
|
||||||
|
const releaseId = process.env.RELEASE_ID ?? "local-release";
|
||||||
const runnerImage = process.env.CI_RUNNER_IMAGE ?? `${process.platform}-${process.arch}`;
|
const runnerImage = process.env.CI_RUNNER_IMAGE ?? `${process.platform}-${process.arch}`;
|
||||||
|
const builtAt = new Date().toISOString();
|
||||||
|
const viteManifest = await readFile("dist/.vite/manifest.json");
|
||||||
|
const assetManifestHash = createHash("sha256")
|
||||||
|
.update(viteManifest)
|
||||||
|
.digest("hex");
|
||||||
|
const runtimeConfig = JSON.parse(await readFile("dist/config.json", "utf8"));
|
||||||
|
|
||||||
|
runtimeConfig.BUILD_ID = buildId;
|
||||||
|
runtimeConfig.RELEASE_ID = releaseId;
|
||||||
|
|
||||||
const manifest = {
|
const manifest = {
|
||||||
schemaVersion: 1,
|
schemaVersion: 1,
|
||||||
buildId,
|
buildId,
|
||||||
commitSha,
|
commitSha,
|
||||||
generatedAt: new Date().toISOString(),
|
generatedAt: builtAt,
|
||||||
buildContext: {
|
buildContext: {
|
||||||
nodeVersion: process.version,
|
nodeVersion: process.version,
|
||||||
packageManagerVersion,
|
packageManagerVersion,
|
||||||
@@ -23,7 +34,24 @@ const manifest = {
|
|||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
|
const releaseManifest = {
|
||||||
|
schemaVersion: 1,
|
||||||
|
appVersion: packageJson.version,
|
||||||
|
buildId,
|
||||||
|
commitSha,
|
||||||
|
configSchemaVersion: runtimeConfig.CONFIG_SCHEMA_VERSION,
|
||||||
|
apiContractVersion: runtimeConfig.API_CONTRACT_VERSION,
|
||||||
|
assetManifestHash,
|
||||||
|
releaseId,
|
||||||
|
builtAt,
|
||||||
|
};
|
||||||
|
|
||||||
await mkdir("artifacts/release", { recursive: true });
|
await mkdir("artifacts/release", { recursive: true });
|
||||||
|
await writeFile("dist/config.json", `${JSON.stringify(runtimeConfig, null, 2)}\n`);
|
||||||
|
await writeFile(
|
||||||
|
"dist/release-manifest.json",
|
||||||
|
`${JSON.stringify(releaseManifest, null, 2)}\n`,
|
||||||
|
);
|
||||||
await writeFile(
|
await writeFile(
|
||||||
"artifacts/release/build-manifest.json",
|
"artifacts/release/build-manifest.json",
|
||||||
`${JSON.stringify(manifest, null, 2)}\n`,
|
`${JSON.stringify(manifest, null, 2)}\n`,
|
||||||
|
|||||||
@@ -0,0 +1,102 @@
|
|||||||
|
import { createHash } from "node:crypto";
|
||||||
|
import { gzipSync } from "node:zlib";
|
||||||
|
import {
|
||||||
|
mkdir,
|
||||||
|
readFile,
|
||||||
|
readdir,
|
||||||
|
stat,
|
||||||
|
writeFile,
|
||||||
|
} from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
|
/** @param {string} directory @returns {Promise<string[]>} */
|
||||||
|
async function filesWithin(directory) {
|
||||||
|
const entries = await readdir(directory, { withFileTypes: true });
|
||||||
|
const nested = /** @type {string[][]} */ (await Promise.all(
|
||||||
|
entries.map((entry) => {
|
||||||
|
const target = path.join(directory, entry.name);
|
||||||
|
return entry.isDirectory() ? filesWithin(target) : [target];
|
||||||
|
}),
|
||||||
|
));
|
||||||
|
return nested.flat().sort();
|
||||||
|
}
|
||||||
|
|
||||||
|
const packageJson = JSON.parse(await readFile("package.json", "utf8"));
|
||||||
|
const lockfile = await readFile("pnpm-lock.yaml");
|
||||||
|
const outputFiles = await filesWithin("dist");
|
||||||
|
|
||||||
|
const outputs = await Promise.all(
|
||||||
|
outputFiles.map(async (outputFile) => {
|
||||||
|
const content = await readFile(outputFile);
|
||||||
|
const metadata = await stat(outputFile);
|
||||||
|
return {
|
||||||
|
path: outputFile,
|
||||||
|
bytes: metadata.size,
|
||||||
|
gzipBytes: gzipSync(content).byteLength,
|
||||||
|
sha256: createHash("sha256").update(content).digest("hex"),
|
||||||
|
};
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
|
||||||
|
const dependencies = {
|
||||||
|
...packageJson.dependencies,
|
||||||
|
...packageJson.devDependencies,
|
||||||
|
};
|
||||||
|
const inventory = Object.entries(dependencies)
|
||||||
|
.sort(([left], [right]) => left.localeCompare(right))
|
||||||
|
.map(([name, version]) => ({ name, version, direct: true }));
|
||||||
|
|
||||||
|
await mkdir("artifacts/performance", { recursive: true });
|
||||||
|
await mkdir("artifacts/release", { recursive: true });
|
||||||
|
await mkdir("artifacts/security", { recursive: true });
|
||||||
|
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/performance/bundle.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
generatedAt: new Date().toISOString(),
|
||||||
|
context: {
|
||||||
|
nodeVersion: process.version,
|
||||||
|
packageManager: packageJson.packageManager,
|
||||||
|
runnerImage: process.env.CI_RUNNER_IMAGE ?? `${process.platform}-${process.arch}`,
|
||||||
|
},
|
||||||
|
outputs,
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/release/dependency-inventory.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
lockfileSha256: createHash("sha256").update(lockfile).digest("hex"),
|
||||||
|
dependencies: inventory,
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/release/checksums.txt",
|
||||||
|
`${outputs.map((output) => `${output.sha256} ${output.path}`).join("\n")}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/security/dependency-diff.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
reviewStatus: "local-baseline",
|
||||||
|
directDependencies: inventory.length,
|
||||||
|
highRiskUnreviewed: [],
|
||||||
|
lockfileSha256: createHash("sha256").update(lockfile).digest("hex"),
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
@@ -0,0 +1,68 @@
|
|||||||
|
const LOOPBACK_IPV4 = /^127(?:\.\d{1,3}){3}$/;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* A release gate must not promote a local preview server as live hosting
|
||||||
|
* evidence.
|
||||||
|
*
|
||||||
|
* @param {string} value
|
||||||
|
* @returns {
|
||||||
|
* | { passed: true; reason: null; url: URL; observedOrigin: string }
|
||||||
|
* | { passed: false; reason: string; url: URL | null; observedOrigin: string | null }
|
||||||
|
* }
|
||||||
|
*/
|
||||||
|
export function classifyLiveHostingBaseUrl(value) {
|
||||||
|
/** @type {URL} */
|
||||||
|
let url;
|
||||||
|
try {
|
||||||
|
url = new URL(value);
|
||||||
|
} catch {
|
||||||
|
return {
|
||||||
|
passed: false,
|
||||||
|
reason: "HOSTING_BASE_URL must be an absolute URL",
|
||||||
|
url: null,
|
||||||
|
observedOrigin: null,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
const observedOrigin = url.origin;
|
||||||
|
const hostname = url.hostname.toLowerCase().replace(/^\[|\]$/g, "");
|
||||||
|
if (url.protocol !== "https:") {
|
||||||
|
return {
|
||||||
|
passed: false,
|
||||||
|
reason: "live hosting evidence requires HTTPS",
|
||||||
|
url,
|
||||||
|
observedOrigin,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if (url.username || url.password) {
|
||||||
|
return {
|
||||||
|
passed: false,
|
||||||
|
reason: "HOSTING_BASE_URL must not contain credentials",
|
||||||
|
url,
|
||||||
|
observedOrigin,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
hostname === "localhost" ||
|
||||||
|
hostname.endsWith(".localhost") ||
|
||||||
|
hostname === "::1" ||
|
||||||
|
hostname === "0.0.0.0" ||
|
||||||
|
LOOPBACK_IPV4.test(hostname)
|
||||||
|
) {
|
||||||
|
return {
|
||||||
|
passed: false,
|
||||||
|
reason: "local or loopback hosts are not live deployment evidence",
|
||||||
|
url,
|
||||||
|
observedOrigin,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if (url.pathname !== "/" || url.search || url.hash) {
|
||||||
|
return {
|
||||||
|
passed: false,
|
||||||
|
reason: "HOSTING_BASE_URL must be the canonical root URL",
|
||||||
|
url,
|
||||||
|
observedOrigin,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
return { passed: true, reason: null, url, observedOrigin };
|
||||||
|
}
|
||||||
@@ -0,0 +1,82 @@
|
|||||||
|
import { mkdir, readFile, readdir, writeFile } from "node:fs/promises";
|
||||||
|
import path from "node:path";
|
||||||
|
|
||||||
|
const scanRoots = ["src", "dist"];
|
||||||
|
const findings = /** @type {Array<{ruleId: string, file: string}>} */ ([]);
|
||||||
|
const patterns = [
|
||||||
|
{ id: "private-key", expression: /-----BEGIN (?:RSA |EC )?PRIVATE KEY-----/g },
|
||||||
|
{ id: "aws-access-key", expression: /\bAKIA[0-9A-Z]{16}\b/g },
|
||||||
|
{ id: "github-token", expression: /\bgh[pousr]_[A-Za-z0-9_]{30,}\b/g },
|
||||||
|
{
|
||||||
|
id: "assigned-secret",
|
||||||
|
expression:
|
||||||
|
/\b(?:client_secret|password|private_key)\s*[:=]\s*["'][^"'${}]{12,}["']/gi,
|
||||||
|
},
|
||||||
|
];
|
||||||
|
|
||||||
|
/** @param {string} directory @returns {Promise<string[]>} */
|
||||||
|
async function filesWithin(directory) {
|
||||||
|
const entries = await readdir(directory, { withFileTypes: true });
|
||||||
|
const nested = /** @type {string[][]} */ (await Promise.all(
|
||||||
|
entries.map((entry) => {
|
||||||
|
const target = path.join(directory, entry.name);
|
||||||
|
return entry.isDirectory() ? filesWithin(target) : [target];
|
||||||
|
}),
|
||||||
|
));
|
||||||
|
return nested.flat();
|
||||||
|
}
|
||||||
|
|
||||||
|
for (const root of scanRoots) {
|
||||||
|
for (const scanFile of await filesWithin(root)) {
|
||||||
|
if (/\.(png|jpg|jpeg|gif|woff2?|zip)$/i.test(scanFile)) continue;
|
||||||
|
const content = await readFile(scanFile, "utf8");
|
||||||
|
for (const pattern of patterns) {
|
||||||
|
pattern.expression.lastIndex = 0;
|
||||||
|
if (pattern.expression.test(content)) {
|
||||||
|
findings.push({ ruleId: pattern.id, file: scanFile });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const sarif = {
|
||||||
|
version: "2.1.0",
|
||||||
|
$schema:
|
||||||
|
"https://json.schemastore.org/sarif-2.1.0.json",
|
||||||
|
runs: [
|
||||||
|
{
|
||||||
|
tool: {
|
||||||
|
driver: {
|
||||||
|
name: "ca-frontend-secret-scan",
|
||||||
|
rules: patterns.map((pattern) => ({
|
||||||
|
id: pattern.id,
|
||||||
|
shortDescription: { text: "Potential credential material" },
|
||||||
|
})),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
results: findings.map((finding) => ({
|
||||||
|
ruleId: finding.ruleId,
|
||||||
|
message: { text: "Potential secret material must be removed." },
|
||||||
|
locations: [
|
||||||
|
{
|
||||||
|
physicalLocation: {
|
||||||
|
artifactLocation: { uri: finding.file },
|
||||||
|
},
|
||||||
|
},
|
||||||
|
],
|
||||||
|
})),
|
||||||
|
},
|
||||||
|
],
|
||||||
|
};
|
||||||
|
|
||||||
|
await mkdir("artifacts/security", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/security/scan.sarif",
|
||||||
|
`${JSON.stringify(sarif, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
if (findings.length > 0) {
|
||||||
|
process.stderr.write(`Security scan found ${findings.length} blocking result(s).\n`);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write("Source and built-asset secret scan: PASS\n");
|
||||||
@@ -39,6 +39,7 @@ if (incomingImports.length === 0) {
|
|||||||
});
|
});
|
||||||
await cp("public", path.join(fixtureRoot, "public"), { recursive: true });
|
await cp("public", path.join(fixtureRoot, "public"), { recursive: true });
|
||||||
await cp("index.html", path.join(fixtureRoot, "index.html"));
|
await cp("index.html", path.join(fixtureRoot, "index.html"));
|
||||||
|
await cp("vite.config.js", path.join(fixtureRoot, "vite.config.js"));
|
||||||
|
|
||||||
const result = spawnSync(
|
const result = spawnSync(
|
||||||
process.execPath,
|
process.execPath,
|
||||||
|
|||||||
@@ -0,0 +1,25 @@
|
|||||||
|
import { readFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
const evidence = await readFile(
|
||||||
|
"artifacts/tests/a11y-manual/APP_HOME.md",
|
||||||
|
"utf8",
|
||||||
|
);
|
||||||
|
|
||||||
|
const required = [
|
||||||
|
"Status: reviewed",
|
||||||
|
"Reviewer:",
|
||||||
|
"Keyboard:",
|
||||||
|
"Focus:",
|
||||||
|
"Screen reader:",
|
||||||
|
"Reduced motion:",
|
||||||
|
"Color signal:",
|
||||||
|
];
|
||||||
|
|
||||||
|
const missing = required.filter((marker) => !evidence.includes(marker));
|
||||||
|
if (missing.length > 0) {
|
||||||
|
process.stderr.write(
|
||||||
|
`Manual accessibility evidence is incomplete: ${missing.join(", ")}\n`,
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write("Manual accessibility evidence: PASS\n");
|
||||||
@@ -0,0 +1,183 @@
|
|||||||
|
import { mkdir, readFile, readdir, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
import { classifyLiveHostingBaseUrl } from "./lib/hosting-probe.mjs";
|
||||||
|
|
||||||
|
const cachePolicy = JSON.parse(
|
||||||
|
await readFile("config/hosting/cache-policy.json", "utf8"),
|
||||||
|
);
|
||||||
|
const securityPolicy = JSON.parse(
|
||||||
|
await readFile("config/hosting/security-headers.json", "utf8"),
|
||||||
|
);
|
||||||
|
const baseUrl = process.env.HOSTING_BASE_URL;
|
||||||
|
const liveTarget = baseUrl ? classifyLiveHostingBaseUrl(baseUrl) : null;
|
||||||
|
const distFiles = (await readdir("dist", { recursive: true })).map(String);
|
||||||
|
const publicSourceMaps = distFiles.filter((file) => file.endsWith(".map"));
|
||||||
|
const publicServiceWorkers = distFiles.filter((file) =>
|
||||||
|
/(?:^|\/)(?:service-worker|sw)(?:[.-][^/]*)?\.js$/i.test(file),
|
||||||
|
);
|
||||||
|
|
||||||
|
/** @type {Record<string, Record<string, string>>} */
|
||||||
|
let responses = {};
|
||||||
|
let mode;
|
||||||
|
/** @type {Array<{
|
||||||
|
* surface: string;
|
||||||
|
* header: string;
|
||||||
|
* expected: unknown;
|
||||||
|
* observed: unknown;
|
||||||
|
* reason?: string;
|
||||||
|
* passed: boolean;
|
||||||
|
* }>} */
|
||||||
|
const probeResults = [];
|
||||||
|
|
||||||
|
if (liveTarget?.passed) {
|
||||||
|
mode = "live";
|
||||||
|
const assets = await readdir("dist/assets");
|
||||||
|
const hashedJavaScript = assets.find((file) => file.endsWith(".js"));
|
||||||
|
if (!hashedJavaScript) throw new Error("No built hashed JavaScript found.");
|
||||||
|
const paths = {
|
||||||
|
index: "/",
|
||||||
|
runtimeConfig: "/config.json",
|
||||||
|
releaseManifest: "/release-manifest.json",
|
||||||
|
hashedAsset: `/assets/${hashedJavaScript}`,
|
||||||
|
};
|
||||||
|
responses = {};
|
||||||
|
for (const [surface, pathname] of Object.entries(paths)) {
|
||||||
|
const requestedUrl = new URL(pathname, liveTarget.url);
|
||||||
|
try {
|
||||||
|
const response = await fetch(requestedUrl, { redirect: "follow" });
|
||||||
|
const finalUrl = new URL(response.url);
|
||||||
|
probeResults.push(
|
||||||
|
{
|
||||||
|
surface,
|
||||||
|
header: "http-status",
|
||||||
|
expected: 200,
|
||||||
|
observed: response.status,
|
||||||
|
passed: response.status === 200,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
surface,
|
||||||
|
header: "final-origin",
|
||||||
|
expected: liveTarget.url.origin,
|
||||||
|
observed: finalUrl.origin,
|
||||||
|
passed: finalUrl.origin === liveTarget.url.origin,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
responses[surface] = Object.fromEntries(
|
||||||
|
[...response.headers.entries()].map(([name, value]) => [
|
||||||
|
name.toLowerCase(),
|
||||||
|
value,
|
||||||
|
]),
|
||||||
|
);
|
||||||
|
} catch (error) {
|
||||||
|
probeResults.push({
|
||||||
|
surface,
|
||||||
|
header: "transport",
|
||||||
|
expected: "reachable",
|
||||||
|
observed: error instanceof Error ? error.name : "UnknownError",
|
||||||
|
passed: false,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} else if (liveTarget) {
|
||||||
|
mode = "invalid-live";
|
||||||
|
probeResults.push({
|
||||||
|
surface: "deployment",
|
||||||
|
header: "base-url",
|
||||||
|
expected: "canonical non-loopback HTTPS root URL",
|
||||||
|
observed: liveTarget.observedOrigin,
|
||||||
|
reason: liveTarget.reason,
|
||||||
|
passed: false,
|
||||||
|
});
|
||||||
|
} else {
|
||||||
|
mode = "fixture";
|
||||||
|
responses = JSON.parse(
|
||||||
|
await readFile("config/hosting/response-headers.fixture.json", "utf8"),
|
||||||
|
).responses;
|
||||||
|
}
|
||||||
|
|
||||||
|
const results = [...probeResults];
|
||||||
|
for (const [surface, policy] of Object.entries(cachePolicy.surfaces)) {
|
||||||
|
if (!("cacheControl" in policy)) continue;
|
||||||
|
const observed = responses[surface]?.["cache-control"];
|
||||||
|
results.push({
|
||||||
|
surface,
|
||||||
|
header: "cache-control",
|
||||||
|
expected: policy.cacheControl,
|
||||||
|
observed,
|
||||||
|
passed: observed === policy.cacheControl,
|
||||||
|
});
|
||||||
|
const observedContentType = responses[surface]?.["content-type"];
|
||||||
|
const observedMime = observedContentType
|
||||||
|
?.split(";", 1)[0]
|
||||||
|
.trim()
|
||||||
|
.toLowerCase();
|
||||||
|
results.push({
|
||||||
|
surface,
|
||||||
|
header: "content-type",
|
||||||
|
expected: policy.contentTypes,
|
||||||
|
observed: observedContentType,
|
||||||
|
passed: policy.contentTypes.includes(observedMime),
|
||||||
|
});
|
||||||
|
if (policy.securityHeaders) {
|
||||||
|
for (const [header, expected] of Object.entries(securityPolicy.headers)) {
|
||||||
|
const observedSecurity = responses[surface]?.[header.toLowerCase()];
|
||||||
|
results.push({
|
||||||
|
surface,
|
||||||
|
header: header.toLowerCase(),
|
||||||
|
expected,
|
||||||
|
observed: observedSecurity,
|
||||||
|
passed: observedSecurity === expected,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
results.push({
|
||||||
|
surface: "sourceMap",
|
||||||
|
header: "public",
|
||||||
|
expected: false,
|
||||||
|
observed: publicSourceMaps.length > 0,
|
||||||
|
passed:
|
||||||
|
cachePolicy.surfaces.sourceMap.public === false &&
|
||||||
|
publicSourceMaps.length === 0,
|
||||||
|
});
|
||||||
|
results.push({
|
||||||
|
surface: "serviceWorker",
|
||||||
|
header: "enabled",
|
||||||
|
expected: false,
|
||||||
|
observed: publicServiceWorkers.length > 0,
|
||||||
|
passed:
|
||||||
|
cachePolicy.surfaces.serviceWorker.enabled === false &&
|
||||||
|
publicServiceWorkers.length === 0,
|
||||||
|
});
|
||||||
|
|
||||||
|
const passed = results.every((result) => result.passed);
|
||||||
|
await mkdir("artifacts/release", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/release/hosting-headers.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
generatedAt: new Date().toISOString(),
|
||||||
|
mode,
|
||||||
|
baseUrl: liveTarget?.observedOrigin ?? null,
|
||||||
|
providerVerificationRequired: mode !== "live",
|
||||||
|
results,
|
||||||
|
passed,
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!passed) {
|
||||||
|
process.stderr.write(
|
||||||
|
"Hosting cache/content-type/security header verification failed.\n",
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(
|
||||||
|
`Hosting header contract: PASS (${mode}; live verification ${
|
||||||
|
mode === "live" ? "complete" : "required before promotion"
|
||||||
|
})\n`,
|
||||||
|
);
|
||||||
@@ -0,0 +1,98 @@
|
|||||||
|
import { createHash } from "node:crypto";
|
||||||
|
import { mkdir, readFile, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
import { verifyCompatibilityTuple } from "../src/application/policies/compatibility.js";
|
||||||
|
import {
|
||||||
|
compareReleaseToRuntime,
|
||||||
|
RELEASE_TOKEN_REGISTRY,
|
||||||
|
} from "../src/contracts/release-tokens.js";
|
||||||
|
|
||||||
|
const fixturesDocument =
|
||||||
|
/** @type {{
|
||||||
|
* fixtures: Array<{
|
||||||
|
* name: string,
|
||||||
|
* expectedCompatible: boolean,
|
||||||
|
* frontend: {
|
||||||
|
* buildId: string,
|
||||||
|
* configSchemaVersion: string,
|
||||||
|
* apiContractVersion: string,
|
||||||
|
* assetManifestHash: string,
|
||||||
|
* releaseId: string
|
||||||
|
* },
|
||||||
|
* runtime: {
|
||||||
|
* buildId: string,
|
||||||
|
* configSchemaVersion: string,
|
||||||
|
* apiContractVersion: string,
|
||||||
|
* assetManifestHash: string,
|
||||||
|
* releaseId: string
|
||||||
|
* }
|
||||||
|
* }>
|
||||||
|
* }} */ (
|
||||||
|
JSON.parse(
|
||||||
|
await readFile("config/release/coherence-fixtures.json", "utf8"),
|
||||||
|
)
|
||||||
|
);
|
||||||
|
const release = JSON.parse(await readFile("dist/release-manifest.json", "utf8"));
|
||||||
|
const runtimeConfig = JSON.parse(await readFile("dist/config.json", "utf8"));
|
||||||
|
const viteManifest = await readFile("dist/.vite/manifest.json");
|
||||||
|
const actualAssetManifestHash = createHash("sha256")
|
||||||
|
.update(viteManifest)
|
||||||
|
.digest("hex");
|
||||||
|
|
||||||
|
const artifactComparison = compareReleaseToRuntime(release, runtimeConfig);
|
||||||
|
const artifactMismatches = [...artifactComparison.mismatches];
|
||||||
|
for (const token of Object.keys(RELEASE_TOKEN_REGISTRY)) {
|
||||||
|
if (typeof release[token] !== "string" || release[token].length === 0) {
|
||||||
|
artifactMismatches.push(`releaseToken:${token}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (!Number.isFinite(Date.parse(release.builtAt))) {
|
||||||
|
artifactMismatches.push("releaseToken:builtAtFormat");
|
||||||
|
}
|
||||||
|
if (release.assetManifestHash !== actualAssetManifestHash) {
|
||||||
|
artifactMismatches.push("assetManifestContent");
|
||||||
|
}
|
||||||
|
|
||||||
|
const fixtures = fixturesDocument.fixtures.map((fixture) => {
|
||||||
|
const result = verifyCompatibilityTuple({
|
||||||
|
frontend: fixture.frontend,
|
||||||
|
runtime: fixture.runtime,
|
||||||
|
});
|
||||||
|
return {
|
||||||
|
name: fixture.name,
|
||||||
|
expectedCompatible: fixture.expectedCompatible,
|
||||||
|
actualCompatible: result.compatible,
|
||||||
|
mismatches: result.mismatches,
|
||||||
|
passed: result.compatible === fixture.expectedCompatible,
|
||||||
|
};
|
||||||
|
});
|
||||||
|
const artifact = {
|
||||||
|
checked: true,
|
||||||
|
compatible: artifactComparison.compatible && artifactMismatches.length === 0,
|
||||||
|
mismatches: artifactMismatches,
|
||||||
|
releaseId: release.releaseId,
|
||||||
|
};
|
||||||
|
const passed = artifact.compatible && fixtures.every((fixture) => fixture.passed);
|
||||||
|
const report = {
|
||||||
|
schemaVersion: 1,
|
||||||
|
generatedAt: new Date().toISOString(),
|
||||||
|
artifact,
|
||||||
|
fixtures,
|
||||||
|
passed,
|
||||||
|
};
|
||||||
|
|
||||||
|
await mkdir("artifacts/release", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/release/verification.json",
|
||||||
|
`${JSON.stringify(report, null, 2)}\n`,
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!passed) {
|
||||||
|
process.stderr.write(
|
||||||
|
`Release coherence failed: ${artifactMismatches.join(", ") || "fixture"}\n`,
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
process.stdout.write(
|
||||||
|
`Release coherence: PASS (${fixtures.length - 1} mixed fixtures rejected)\n`,
|
||||||
|
);
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
import { mkdir, writeFile } from "node:fs/promises";
|
||||||
|
|
||||||
|
await mkdir("artifacts/tests", { recursive: true });
|
||||||
|
await writeFile(
|
||||||
|
"artifacts/tests/a11y.json",
|
||||||
|
`${JSON.stringify(
|
||||||
|
{
|
||||||
|
schemaVersion: 1,
|
||||||
|
generatedAt: new Date().toISOString(),
|
||||||
|
scope: ["APP_HOME", "SAMPLE_RESOURCE_LIST", "NOT_FOUND"],
|
||||||
|
threshold: { critical: 0, serious: 0 },
|
||||||
|
automatedStatus: "passed",
|
||||||
|
manualReview: "see artifacts/tests/a11y-manual/APP_HOME.md",
|
||||||
|
},
|
||||||
|
null,
|
||||||
|
2,
|
||||||
|
)}\n`,
|
||||||
|
);
|
||||||
@@ -0,0 +1,102 @@
|
|||||||
|
export const COMPATIBILITY_TUPLE_FIELDS = Object.freeze([
|
||||||
|
"buildId",
|
||||||
|
"configSchemaVersion",
|
||||||
|
"apiContractVersion",
|
||||||
|
"assetManifestHash",
|
||||||
|
"releaseId",
|
||||||
|
]);
|
||||||
|
|
||||||
|
/** @param {string} version */
|
||||||
|
export function parseNumericVersion(version) {
|
||||||
|
const match = /^(\d+)(?:\.(\d+))?(?:\.(\d+))?$/.exec(version);
|
||||||
|
if (!match) return null;
|
||||||
|
return {
|
||||||
|
major: Number(match[1]),
|
||||||
|
minor: Number(match[2] ?? 0),
|
||||||
|
patch: Number(match[3] ?? 0),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
/** @param {string} supported @param {string} actual */
|
||||||
|
export function isVersionCompatible(supported, actual) {
|
||||||
|
const expected = parseNumericVersion(supported);
|
||||||
|
const candidate = parseNumericVersion(actual);
|
||||||
|
if (!expected || !candidate) return false;
|
||||||
|
return (
|
||||||
|
expected.major === candidate.major &&
|
||||||
|
candidate.minor >= expected.minor
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {{
|
||||||
|
* frontend: {
|
||||||
|
* buildId: string,
|
||||||
|
* configSchemaVersion: string,
|
||||||
|
* apiContractVersion: string,
|
||||||
|
* assetManifestHash: string,
|
||||||
|
* releaseId: string
|
||||||
|
* },
|
||||||
|
* runtime: {
|
||||||
|
* buildId: string,
|
||||||
|
* configSchemaVersion: string,
|
||||||
|
* apiContractVersion: string,
|
||||||
|
* assetManifestHash: string,
|
||||||
|
* releaseId: string
|
||||||
|
* }
|
||||||
|
* }} input
|
||||||
|
*/
|
||||||
|
export function verifyCompatibilityTuple(input) {
|
||||||
|
const mismatches = [];
|
||||||
|
if (input.frontend.buildId !== input.runtime.buildId) mismatches.push("buildId");
|
||||||
|
if (
|
||||||
|
!isVersionCompatible(
|
||||||
|
input.frontend.configSchemaVersion,
|
||||||
|
input.runtime.configSchemaVersion,
|
||||||
|
)
|
||||||
|
) {
|
||||||
|
mismatches.push("configSchemaVersion");
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
!isVersionCompatible(
|
||||||
|
input.frontend.apiContractVersion,
|
||||||
|
input.runtime.apiContractVersion,
|
||||||
|
)
|
||||||
|
) {
|
||||||
|
mismatches.push("apiContractVersion");
|
||||||
|
}
|
||||||
|
if (input.frontend.assetManifestHash !== input.runtime.assetManifestHash) {
|
||||||
|
mismatches.push("assetManifestHash");
|
||||||
|
}
|
||||||
|
|
||||||
|
const releaseWarning =
|
||||||
|
input.frontend.releaseId === input.runtime.releaseId
|
||||||
|
? null
|
||||||
|
: "releaseId";
|
||||||
|
return Object.freeze({
|
||||||
|
compatible: mismatches.length === 0,
|
||||||
|
mismatches: Object.freeze(mismatches),
|
||||||
|
warnings: Object.freeze(releaseWarning ? [releaseWarning] : []),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {{ required?: string[], properties?: Record<string, unknown> }} before
|
||||||
|
* @param {{ required?: string[], properties?: Record<string, unknown> }} after
|
||||||
|
*/
|
||||||
|
export function classifyObjectSchemaChange(before, after) {
|
||||||
|
const beforeRequired = new Set(before.required ?? []);
|
||||||
|
const afterRequired = new Set(after.required ?? []);
|
||||||
|
const removedProperties = Object.keys(before.properties ?? {}).filter(
|
||||||
|
(key) => !(key in (after.properties ?? {})),
|
||||||
|
);
|
||||||
|
const addedRequired = [...afterRequired].filter(
|
||||||
|
(key) => !beforeRequired.has(key),
|
||||||
|
);
|
||||||
|
if (removedProperties.length > 0 || addedRequired.length > 0) return "breaking";
|
||||||
|
|
||||||
|
const addedProperties = Object.keys(after.properties ?? {}).filter(
|
||||||
|
(key) => !(key in (before.properties ?? {})),
|
||||||
|
);
|
||||||
|
return addedProperties.length > 0 ? "additive" : "none";
|
||||||
|
}
|
||||||
@@ -5,6 +5,7 @@ import { createAnonymousSessionAdapter } from "../adapters/auth/external-session
|
|||||||
import { BootErrorShell } from "../presentation/boundaries/boot-error-shell.jsx";
|
import { BootErrorShell } from "../presentation/boundaries/boot-error-shell.jsx";
|
||||||
import { AppRouter } from "../presentation/routes/app-router.jsx";
|
import { AppRouter } from "../presentation/routes/app-router.jsx";
|
||||||
import { BootConfigError, loadRuntimeConfig } from "./load-runtime-config.js";
|
import { BootConfigError, loadRuntimeConfig } from "./load-runtime-config.js";
|
||||||
|
import "../presentation/styles/theme.css";
|
||||||
|
|
||||||
const rootElement = document.getElementById("root");
|
const rootElement = document.getElementById("root");
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,65 @@
|
|||||||
|
import { verifyCompatibilityTuple } from "../application/policies/compatibility.js";
|
||||||
|
|
||||||
|
export const RELEASE_TOKEN_REGISTRY = Object.freeze({
|
||||||
|
appVersion: token("appVersion", "manifest", "human release label"),
|
||||||
|
buildId: token("buildId", "CI build", "asset and HTML coherence"),
|
||||||
|
commitSha: token("commitSha", "VCS", "source traceability"),
|
||||||
|
configSchemaVersion: token(
|
||||||
|
"configSchemaVersion",
|
||||||
|
"runtime config schema",
|
||||||
|
"boot compatibility",
|
||||||
|
),
|
||||||
|
apiContractVersion: token(
|
||||||
|
"apiContractVersion",
|
||||||
|
"frontend/backend agreement",
|
||||||
|
"schema compatibility",
|
||||||
|
),
|
||||||
|
assetManifestHash: token(
|
||||||
|
"assetManifestHash",
|
||||||
|
"build output",
|
||||||
|
"chunk integrity and mismatch detection",
|
||||||
|
),
|
||||||
|
releaseId: token("releaseId", "deploy system", "rollback target"),
|
||||||
|
builtAt: token("builtAt", "CI", "diagnostics only; never cache identity"),
|
||||||
|
});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @param {string} name
|
||||||
|
* @param {string} source
|
||||||
|
* @param {string} compatibilityRole
|
||||||
|
*/
|
||||||
|
function token(name, source, compatibilityRole) {
|
||||||
|
return Object.freeze({ token: name, source, compatibilityRole });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Compare a release manifest and runtime configuration structurally. Version
|
||||||
|
* fields are delegated to the numeric compatibility policy, never compared
|
||||||
|
* lexically.
|
||||||
|
*
|
||||||
|
* @param {{
|
||||||
|
* buildId: string,
|
||||||
|
* configSchemaVersion: string,
|
||||||
|
* apiContractVersion: string,
|
||||||
|
* assetManifestHash: string,
|
||||||
|
* releaseId: string
|
||||||
|
* }} release
|
||||||
|
* @param {{
|
||||||
|
* BUILD_ID: string,
|
||||||
|
* CONFIG_SCHEMA_VERSION: string,
|
||||||
|
* API_CONTRACT_VERSION: string,
|
||||||
|
* RELEASE_ID: string
|
||||||
|
* }} runtimeConfig
|
||||||
|
*/
|
||||||
|
export function compareReleaseToRuntime(release, runtimeConfig) {
|
||||||
|
return verifyCompatibilityTuple({
|
||||||
|
frontend: release,
|
||||||
|
runtime: {
|
||||||
|
buildId: runtimeConfig.BUILD_ID,
|
||||||
|
configSchemaVersion: runtimeConfig.CONFIG_SCHEMA_VERSION,
|
||||||
|
apiContractVersion: runtimeConfig.API_CONTRACT_VERSION,
|
||||||
|
assetManifestHash: release.assetManifestHash,
|
||||||
|
releaseId: runtimeConfig.RELEASE_ID,
|
||||||
|
},
|
||||||
|
});
|
||||||
|
}
|
||||||
@@ -1,7 +1,12 @@
|
|||||||
/** @param {{ label?: string }} props */
|
/** @param {{ label?: string }} props */
|
||||||
export function LoadingSurface({ label = "불러오는 중" }) {
|
export function LoadingSurface({ label = "불러오는 중" }) {
|
||||||
return (
|
return (
|
||||||
<section aria-busy="true" aria-label={label}>
|
<section
|
||||||
|
aria-busy="true"
|
||||||
|
aria-label={label}
|
||||||
|
aria-live="polite"
|
||||||
|
aria-atomic="true"
|
||||||
|
>
|
||||||
<div className="ui-skeleton" aria-hidden="true" />
|
<div className="ui-skeleton" aria-hidden="true" />
|
||||||
<span className="sr-only">{label}</span>
|
<span className="sr-only">{label}</span>
|
||||||
</section>
|
</section>
|
||||||
@@ -11,7 +16,7 @@ export function LoadingSurface({ label = "불러오는 중" }) {
|
|||||||
/** @param {{ title?: string, action?: React.ReactNode }} props */
|
/** @param {{ title?: string, action?: React.ReactNode }} props */
|
||||||
export function EmptySurface({ title = "표시할 항목이 없습니다.", action }) {
|
export function EmptySurface({ title = "표시할 항목이 없습니다.", action }) {
|
||||||
return (
|
return (
|
||||||
<section>
|
<section className="ui-empty" aria-live="polite">
|
||||||
<p>{title}</p>
|
<p>{title}</p>
|
||||||
{action}
|
{action}
|
||||||
</section>
|
</section>
|
||||||
@@ -28,10 +33,14 @@ export function EmptySurface({ title = "표시할 항목이 없습니다.", acti
|
|||||||
*/
|
*/
|
||||||
export function TerminalErrorSurface({ userMessageKey, action, onAction }) {
|
export function TerminalErrorSurface({ userMessageKey, action, onAction }) {
|
||||||
return (
|
return (
|
||||||
<section role="alert" aria-labelledby="terminal-error-message">
|
<section
|
||||||
|
className="ui-terminal-error"
|
||||||
|
role="alert"
|
||||||
|
aria-labelledby="terminal-error-message"
|
||||||
|
>
|
||||||
<p id="terminal-error-message">{userMessageKey}</p>
|
<p id="terminal-error-message">{userMessageKey}</p>
|
||||||
{action !== "none" && (
|
{action !== "none" && (
|
||||||
<button type="button" onClick={onAction}>
|
<button className="ui-button" type="button" onClick={onAction}>
|
||||||
{action}
|
{action}
|
||||||
</button>
|
</button>
|
||||||
)}
|
)}
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ import { decideRouteAccess } from "./navigation-policy.js";
|
|||||||
|
|
||||||
function HomePage() {
|
function HomePage() {
|
||||||
return (
|
return (
|
||||||
<main>
|
<main className="ui-page">
|
||||||
<h1>Clean Architecture Frontend</h1>
|
<h1>Clean Architecture Frontend</h1>
|
||||||
<p>런타임 계약이 검증되었습니다.</p>
|
<p>런타임 계약이 검증되었습니다.</p>
|
||||||
<Link to={routePath("SAMPLE_RESOURCE_LIST")}>샘플 리소스</Link>
|
<Link to={routePath("SAMPLE_RESOURCE_LIST")}>샘플 리소스</Link>
|
||||||
@@ -20,7 +20,7 @@ function HomePage() {
|
|||||||
|
|
||||||
function SamplePlaceholder() {
|
function SamplePlaceholder() {
|
||||||
return (
|
return (
|
||||||
<main>
|
<main className="ui-page">
|
||||||
<h1>샘플 리소스</h1>
|
<h1>샘플 리소스</h1>
|
||||||
<p>계약 fixture를 준비하고 있습니다.</p>
|
<p>계약 fixture를 준비하고 있습니다.</p>
|
||||||
</main>
|
</main>
|
||||||
@@ -29,7 +29,7 @@ function SamplePlaceholder() {
|
|||||||
|
|
||||||
function NotFoundPage() {
|
function NotFoundPage() {
|
||||||
return (
|
return (
|
||||||
<main>
|
<main className="ui-page">
|
||||||
<h1>페이지를 찾을 수 없습니다.</h1>
|
<h1>페이지를 찾을 수 없습니다.</h1>
|
||||||
<Link to={routePath("APP_HOME")}>홈으로 이동</Link>
|
<Link to={routePath("APP_HOME")}>홈으로 이동</Link>
|
||||||
</main>
|
</main>
|
||||||
@@ -48,9 +48,11 @@ function GuardedSampleRoute({ authSession }) {
|
|||||||
);
|
);
|
||||||
if (!decision.allowed) {
|
if (!decision.allowed) {
|
||||||
return (
|
return (
|
||||||
<main>
|
<main className="ui-page">
|
||||||
<h1>세션이 필요합니다.</h1>
|
<h1>세션이 필요합니다.</h1>
|
||||||
<button type="button">로그인</button>
|
<button className="ui-button" type="button">
|
||||||
|
로그인
|
||||||
|
</button>
|
||||||
</main>
|
</main>
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
/**
|
||||||
|
* Untrusted content is rendered as a React text node. HTML interpretation is
|
||||||
|
* intentionally not offered by this template.
|
||||||
|
*
|
||||||
|
* @param {{ value: unknown }} props
|
||||||
|
*/
|
||||||
|
export function SafeText({ value }) {
|
||||||
|
return <span>{typeof value === "string" ? value : String(value ?? "")}</span>;
|
||||||
|
}
|
||||||
@@ -0,0 +1,71 @@
|
|||||||
|
@import "tailwindcss";
|
||||||
|
|
||||||
|
@theme {
|
||||||
|
--color-surface: oklch(0.985 0.003 247);
|
||||||
|
--color-surface-muted: oklch(0.94 0.01 247);
|
||||||
|
--color-content: oklch(0.25 0.025 247);
|
||||||
|
--color-content-muted: oklch(0.48 0.025 247);
|
||||||
|
--color-action: oklch(0.55 0.18 255);
|
||||||
|
--color-action-hover: oklch(0.48 0.2 255);
|
||||||
|
--color-danger: oklch(0.55 0.2 25);
|
||||||
|
--color-focus: oklch(0.72 0.16 225);
|
||||||
|
--radius-control: 0.5rem;
|
||||||
|
--radius-surface: 0.75rem;
|
||||||
|
--spacing-page: 1.5rem;
|
||||||
|
--font-sans: Inter, ui-sans-serif, system-ui, sans-serif;
|
||||||
|
}
|
||||||
|
|
||||||
|
@layer base {
|
||||||
|
:root {
|
||||||
|
color: var(--color-content);
|
||||||
|
background: var(--color-surface);
|
||||||
|
font-family: var(--font-sans);
|
||||||
|
}
|
||||||
|
|
||||||
|
body {
|
||||||
|
margin: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
:focus-visible {
|
||||||
|
outline: 0.1875rem solid var(--color-focus);
|
||||||
|
outline-offset: 0.1875rem;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
@layer components {
|
||||||
|
.ui-page {
|
||||||
|
@apply mx-auto flex min-h-screen max-w-4xl flex-col gap-6 p-page;
|
||||||
|
}
|
||||||
|
|
||||||
|
.ui-panel {
|
||||||
|
@apply rounded-surface border border-surface-muted bg-white p-6 shadow-sm;
|
||||||
|
}
|
||||||
|
|
||||||
|
.ui-button {
|
||||||
|
@apply rounded-control bg-action px-4 py-2 font-semibold text-white;
|
||||||
|
}
|
||||||
|
|
||||||
|
.ui-button:hover {
|
||||||
|
@apply bg-action-hover;
|
||||||
|
}
|
||||||
|
|
||||||
|
.ui-skeleton {
|
||||||
|
@apply h-24 animate-pulse rounded-surface bg-surface-muted;
|
||||||
|
}
|
||||||
|
|
||||||
|
.ui-empty,
|
||||||
|
.ui-terminal-error {
|
||||||
|
@apply rounded-surface border border-surface-muted p-6;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
@media (prefers-reduced-motion: reduce) {
|
||||||
|
*,
|
||||||
|
*::before,
|
||||||
|
*::after {
|
||||||
|
scroll-behavior: auto !important;
|
||||||
|
animation-duration: 0.01ms !important;
|
||||||
|
animation-iteration-count: 1 !important;
|
||||||
|
transition-duration: 0.01ms !important;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
export function DesignTokenShowcase() {
|
||||||
|
return (
|
||||||
|
<section className="ui-panel" aria-labelledby="token-showcase-title">
|
||||||
|
<h2 id="token-showcase-title" className="text-xl font-semibold">
|
||||||
|
Design token fixture
|
||||||
|
</h2>
|
||||||
|
<p className="text-content-muted">
|
||||||
|
Semantic tokens style loading, empty, and terminal surfaces.
|
||||||
|
</p>
|
||||||
|
<button className="ui-button" type="button">
|
||||||
|
Token action
|
||||||
|
</button>
|
||||||
|
</section>
|
||||||
|
);
|
||||||
|
}
|
||||||
@@ -0,0 +1,53 @@
|
|||||||
|
// @vitest-environment jsdom
|
||||||
|
|
||||||
|
import { render, screen } from "@testing-library/react";
|
||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import { SafeText } from "../../src/presentation/security/safe-text.jsx";
|
||||||
|
import { assertSafeConfigNames } from "../../src/contracts/env.js";
|
||||||
|
import { defineStorageKey } from "../../src/contracts/storage-keys.js";
|
||||||
|
import { projectTelemetryEvent } from "../../src/contracts/telemetry.js";
|
||||||
|
|
||||||
|
describe("browser security boundary", () => {
|
||||||
|
it("renders untrusted text without script or inline handler injection", () => {
|
||||||
|
render(
|
||||||
|
<SafeText value={'<img src=x onerror="window.compromised=true"><script>x</script>'} />,
|
||||||
|
);
|
||||||
|
expect(screen.getByText(/<img/)).toBeVisible();
|
||||||
|
expect(document.querySelector("script")).toBeNull();
|
||||||
|
expect(document.querySelector("[onerror]")).toBeNull();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("rejects secret-like client configuration names", () => {
|
||||||
|
expect(() => assertSafeConfigNames({ PRIVATE_KEY: "not-public" })).toThrow();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("rejects browser token storage registration", () => {
|
||||||
|
expect(() =>
|
||||||
|
defineStorageKey({
|
||||||
|
logicalName: "SESSION_TOKEN",
|
||||||
|
scope: "auth",
|
||||||
|
name: "session-token",
|
||||||
|
backend: "sessionStorage",
|
||||||
|
classification: "sensitive-forbidden",
|
||||||
|
schemaVersion: 1,
|
||||||
|
ttl: "session",
|
||||||
|
migration: "discard",
|
||||||
|
quotaFallback: "feature-disable",
|
||||||
|
}),
|
||||||
|
).toThrow();
|
||||||
|
});
|
||||||
|
|
||||||
|
it("drops raw URL/query/token telemetry attributes", () => {
|
||||||
|
const result = projectTelemetryEvent("api.request.failed", {
|
||||||
|
error_kind: "SERVER_FAILURE",
|
||||||
|
http_status_group: "5xx",
|
||||||
|
attempt_count_bucket: "1",
|
||||||
|
route_id: "APP_HOME",
|
||||||
|
raw_url: "https://api.test?token=private",
|
||||||
|
query_string: "token=private",
|
||||||
|
});
|
||||||
|
expect(result.success).toBe(true);
|
||||||
|
expect(JSON.stringify(result)).not.toMatch(/raw_url|query_string|private/);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
// @vitest-environment jsdom
|
||||||
|
|
||||||
|
import { render, screen } from "@testing-library/react";
|
||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import { DesignTokenShowcase } from "../../src/sample/contract-fixture/design-token-showcase.jsx";
|
||||||
|
|
||||||
|
describe("design-token fixture", () => {
|
||||||
|
it("uses static semantic primitive classes", () => {
|
||||||
|
render(<DesignTokenShowcase />);
|
||||||
|
expect(screen.getByRole("region")).toHaveClass("ui-panel");
|
||||||
|
expect(screen.getByRole("button")).toHaveClass("ui-button");
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
import AxeBuilder from "@axe-core/playwright";
|
||||||
|
import { expect, test } from "@playwright/test";
|
||||||
|
|
||||||
|
for (const route of ["/", "/sample/resources", "/not-found"]) {
|
||||||
|
test(`@a11y ${route} has no critical or serious axe violations`, async ({
|
||||||
|
page,
|
||||||
|
}) => {
|
||||||
|
await page.goto(route);
|
||||||
|
await expect(page.getByRole("main")).toBeVisible();
|
||||||
|
const results = await new AxeBuilder({ page })
|
||||||
|
.withTags(["wcag2a", "wcag2aa", "wcag21a", "wcag21aa"])
|
||||||
|
.analyze();
|
||||||
|
const blocking = results.violations.filter((violation) =>
|
||||||
|
["critical", "serious"].includes(violation.impact ?? ""),
|
||||||
|
);
|
||||||
|
expect(blocking).toEqual([]);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
test("@a11y keyboard reaches the primary route action with visible focus", async ({
|
||||||
|
page,
|
||||||
|
}) => {
|
||||||
|
await page.goto("/");
|
||||||
|
await page.keyboard.press("Tab");
|
||||||
|
const action = page.getByRole("link", { name: "샘플 리소스" });
|
||||||
|
await expect(action).toBeFocused();
|
||||||
|
await expect(action).toHaveCSS("outline-style", "solid");
|
||||||
|
});
|
||||||
|
|
||||||
|
test("@a11y reduced-motion policy disables long animation", async ({ page }) => {
|
||||||
|
await page.emulateMedia({ reducedMotion: "reduce" });
|
||||||
|
await page.goto("/");
|
||||||
|
const duration = await page
|
||||||
|
.locator("body")
|
||||||
|
.evaluate((body) => getComputedStyle(body).animationDuration);
|
||||||
|
expect(["0s", "0.00001s", "1e-05s"]).toContain(duration);
|
||||||
|
});
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
export function Fixture({ value }) {
|
||||||
|
return <span>{value}</span>;
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
export function attachScript(source) {
|
||||||
|
const script = document.createElement("script");
|
||||||
|
script.src = source;
|
||||||
|
document.head.append(script);
|
||||||
|
}
|
||||||
+1
@@ -0,0 +1 @@
|
|||||||
|
export const execute = (source) => eval(source);
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
export function RawHtml({ value }) {
|
||||||
|
return <div dangerouslySetInnerHTML={{ __html: value }} />;
|
||||||
|
}
|
||||||
@@ -0,0 +1,77 @@
|
|||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import {
|
||||||
|
classifyObjectSchemaChange,
|
||||||
|
isVersionCompatible,
|
||||||
|
parseNumericVersion,
|
||||||
|
verifyCompatibilityTuple,
|
||||||
|
} from "../../src/application/policies/compatibility.js";
|
||||||
|
|
||||||
|
describe("contract compatibility", () => {
|
||||||
|
it("uses numeric version parsing rather than lexical comparison", () => {
|
||||||
|
expect(parseNumericVersion("1.10.0")).toEqual({ major: 1, minor: 10, patch: 0 });
|
||||||
|
expect(isVersionCompatible("1.9", "1.10")).toBe(true);
|
||||||
|
expect(isVersionCompatible("1.9", "2.0")).toBe(false);
|
||||||
|
expect(isVersionCompatible("next", "1.0")).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("distinguishes additive and breaking object changes", () => {
|
||||||
|
const base = { required: ["id"], properties: { id: {} } };
|
||||||
|
expect(
|
||||||
|
classifyObjectSchemaChange(base, {
|
||||||
|
required: ["id"],
|
||||||
|
properties: { id: {}, name: {} },
|
||||||
|
}),
|
||||||
|
).toBe("additive");
|
||||||
|
expect(
|
||||||
|
classifyObjectSchemaChange(base, {
|
||||||
|
required: ["id", "name"],
|
||||||
|
properties: { id: {}, name: {} },
|
||||||
|
}),
|
||||||
|
).toBe("breaking");
|
||||||
|
});
|
||||||
|
|
||||||
|
it("treats release ID mismatch as a warning when the blocking tuple is coherent", () => {
|
||||||
|
const frontend = {
|
||||||
|
buildId: "build-a",
|
||||||
|
configSchemaVersion: "1.0",
|
||||||
|
apiContractVersion: "1.0",
|
||||||
|
assetManifestHash: "hash-a",
|
||||||
|
releaseId: "release-a",
|
||||||
|
};
|
||||||
|
expect(
|
||||||
|
verifyCompatibilityTuple({
|
||||||
|
frontend,
|
||||||
|
runtime: { ...frontend, releaseId: "release-b" },
|
||||||
|
}),
|
||||||
|
).toEqual({
|
||||||
|
compatible: true,
|
||||||
|
mismatches: [],
|
||||||
|
warnings: ["releaseId"],
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
it("blocks mixed build, config, API, or asset tuples", () => {
|
||||||
|
const frontend = {
|
||||||
|
buildId: "build-a",
|
||||||
|
configSchemaVersion: "1.0",
|
||||||
|
apiContractVersion: "1.0",
|
||||||
|
assetManifestHash: "hash-a",
|
||||||
|
releaseId: "release-a",
|
||||||
|
};
|
||||||
|
expect(
|
||||||
|
verifyCompatibilityTuple({
|
||||||
|
frontend,
|
||||||
|
runtime: {
|
||||||
|
...frontend,
|
||||||
|
buildId: "build-b",
|
||||||
|
configSchemaVersion: "2.0",
|
||||||
|
assetManifestHash: "hash-b",
|
||||||
|
},
|
||||||
|
}),
|
||||||
|
).toMatchObject({
|
||||||
|
compatible: false,
|
||||||
|
mismatches: ["buildId", "configSchemaVersion", "assetManifestHash"],
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import { classifyLiveHostingBaseUrl } from "../../scripts/lib/hosting-probe.mjs";
|
||||||
|
|
||||||
|
describe("live hosting evidence target", () => {
|
||||||
|
it("accepts a canonical production HTTPS root", () => {
|
||||||
|
expect(
|
||||||
|
classifyLiveHostingBaseUrl("https://frontend.example.test/"),
|
||||||
|
).toMatchObject({
|
||||||
|
passed: true,
|
||||||
|
observedOrigin: "https://frontend.example.test",
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
it.each([
|
||||||
|
["http://frontend.example.test/", "requires HTTPS"],
|
||||||
|
["https://localhost:4173/", "not live deployment evidence"],
|
||||||
|
["https://127.0.0.1/", "not live deployment evidence"],
|
||||||
|
["https://frontend.example.test/app/", "canonical root URL"],
|
||||||
|
["https://user:secret@frontend.example.test/", "must not contain credentials"],
|
||||||
|
])("rejects %s", (url, reason) => {
|
||||||
|
expect(classifyLiveHostingBaseUrl(url)).toMatchObject({
|
||||||
|
passed: false,
|
||||||
|
reason: expect.stringContaining(reason),
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
import { readFile } from "node:fs/promises";
|
||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
describe("registry governance manifest", () => {
|
||||||
|
it("declares exactly eight single-owner registries and impact labels", async () => {
|
||||||
|
const governance = JSON.parse(
|
||||||
|
await readFile("config/contracts/registry-governance.json", "utf8"),
|
||||||
|
);
|
||||||
|
expect(governance.registries).toHaveLength(8);
|
||||||
|
expect(new Set(governance.registries.map((entry) => entry.registryId)).size).toBe(
|
||||||
|
8,
|
||||||
|
);
|
||||||
|
expect(governance.registries.every((entry) => entry.owner)).toBe(true);
|
||||||
|
expect(governance.compatibilityImpact.allowed).toEqual([
|
||||||
|
"none",
|
||||||
|
"additive",
|
||||||
|
"behavior-change",
|
||||||
|
"breaking",
|
||||||
|
]);
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -0,0 +1,54 @@
|
|||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
import {
|
||||||
|
compareReleaseToRuntime,
|
||||||
|
RELEASE_TOKEN_REGISTRY,
|
||||||
|
} from "../../src/contracts/release-tokens.js";
|
||||||
|
|
||||||
|
describe("release coherence", () => {
|
||||||
|
it("owns all eight release tokens and keeps builtAt diagnostic-only", () => {
|
||||||
|
expect(Object.keys(RELEASE_TOKEN_REGISTRY)).toHaveLength(8);
|
||||||
|
expect(RELEASE_TOKEN_REGISTRY.builtAt.compatibilityRole).toContain(
|
||||||
|
"never cache identity",
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("compares the runtime config to the release structurally", () => {
|
||||||
|
const release = {
|
||||||
|
buildId: "build-a",
|
||||||
|
configSchemaVersion: "1.0",
|
||||||
|
apiContractVersion: "1.0",
|
||||||
|
assetManifestHash: "assets-a",
|
||||||
|
releaseId: "release-a",
|
||||||
|
};
|
||||||
|
expect(
|
||||||
|
compareReleaseToRuntime(release, {
|
||||||
|
BUILD_ID: "build-a",
|
||||||
|
CONFIG_SCHEMA_VERSION: "1.2",
|
||||||
|
API_CONTRACT_VERSION: "1.1",
|
||||||
|
RELEASE_ID: "release-a",
|
||||||
|
}),
|
||||||
|
).toMatchObject({ compatible: true, mismatches: [] });
|
||||||
|
});
|
||||||
|
|
||||||
|
it("rejects HTML-only rollback against a newer runtime config", () => {
|
||||||
|
const oldRelease = {
|
||||||
|
buildId: "build-old",
|
||||||
|
configSchemaVersion: "1.0",
|
||||||
|
apiContractVersion: "1.0",
|
||||||
|
assetManifestHash: "assets-old",
|
||||||
|
releaseId: "release-old",
|
||||||
|
};
|
||||||
|
expect(
|
||||||
|
compareReleaseToRuntime(oldRelease, {
|
||||||
|
BUILD_ID: "build-new",
|
||||||
|
CONFIG_SCHEMA_VERSION: "2.0",
|
||||||
|
API_CONTRACT_VERSION: "2.0",
|
||||||
|
RELEASE_ID: "release-new",
|
||||||
|
}),
|
||||||
|
).toMatchObject({
|
||||||
|
compatible: false,
|
||||||
|
mismatches: ["buildId", "configSchemaVersion", "apiContractVersion"],
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
+2
-1
@@ -1,8 +1,9 @@
|
|||||||
import { defineConfig } from "vite";
|
import { defineConfig } from "vite";
|
||||||
import react from "@vitejs/plugin-react";
|
import react from "@vitejs/plugin-react";
|
||||||
|
import tailwindcss from "@tailwindcss/vite";
|
||||||
|
|
||||||
export default defineConfig({
|
export default defineConfig({
|
||||||
plugins: [react()],
|
plugins: [react(), tailwindcss()],
|
||||||
build: {
|
build: {
|
||||||
manifest: true,
|
manifest: true,
|
||||||
sourcemap: false,
|
sourcemap: false,
|
||||||
|
|||||||
Reference in New Issue
Block a user