This commit is contained in:
@@ -0,0 +1,101 @@
|
||||
# P98 — April 2026: «Современная безопасность веба»
|
||||
|
||||
Scope intentionally limited to the P98 overlay, this review note, and three SVG assets. No registry, README, application file, archive JSON, production queue, staging, commit, push, fetch, rebase, reset, stash or checkout belongs to this draft package.
|
||||
|
||||
## Editorial contract
|
||||
|
||||
- Historical cutoff: 2026-04-30.
|
||||
- Three rewrites only: practice map, mechanism traceability/residual risk, field evidence/retest loop.
|
||||
- Each body must be 5,000–15,000 characters; target 9,000–13,000.
|
||||
- M9 voice: short pragmatic Russian technical sentences, named limits, no compliance theatre, no implied production observation.
|
||||
- Opening two paragraphs name a concrete problem and cost.
|
||||
- Every article has an accessible table, a distinct SVG with meaningful alt/caption, ordered sequence, executable public-export example, limits and one next step.
|
||||
- Positive data-model result is only `synthetic-security-review-hand-off`; it never approves, releases, deploys, contacts or changes anything.
|
||||
|
||||
## Pass 1 — problem, density, voice and independence
|
||||
|
||||
### Practice — `editorial-2026-04-practice-modern-web-security`
|
||||
|
||||
- Problem/cost appears in the first paragraph: a control inventory cannot identify an interrupted attack step; investigation cost moves from diagnosis to arguments about configuration.
|
||||
- Independent angle: compose an attack-control-evidence map starting from an attacker verb and one route, then preserve residual ownership question.
|
||||
- Density: each section adds a decision object, table field, executable mapping, failure mode or hand-off boundary. Generic security introduction removed.
|
||||
- M9 voice checked: narrow verbs (`name`, `bind`, `stop`, `hand off`), short claims, no promise of safety.
|
||||
|
||||
### Mechanism — `editorial-2026-04-mechanism-modern-web-security`
|
||||
|
||||
- Problem/cost appears first: a baseline is retrospectively treated as causal proof, producing false confidence and costly incident analysis.
|
||||
- Independent angle: explain traceability as missing relations between threat, interruption, observation and residual risk; it is not a second version of the practice checklist.
|
||||
- Density: matrix separates permitted inferences from prohibited inference jumps; success result is structurally constrained.
|
||||
- M9 voice checked: the article treats evidence as a type of permitted conclusion and uses explicit stops instead of reassurance.
|
||||
|
||||
### Field — `editorial-2026-04-field-modern-web-security`
|
||||
|
||||
- Problem/cost appears first: an ambiguous hand-off grows into an accidental operational permission; later participants cannot recover the original scope.
|
||||
- Independent angle: an authorised-by-schema review loop for bounded evidence/retest, deliberately separated from production authority.
|
||||
- Density: every loop stage carries a named input/output/stop; retest scope is two observations, not a generic retest claim.
|
||||
- M9 voice checked: `authorised` is defined narrowly and denied any organisational or deployment meaning.
|
||||
|
||||
## Pass 2 — sources, historical boundary and executability
|
||||
|
||||
### Source pins independently checked
|
||||
|
||||
1. [W3C CSP Level 3, Working Draft 21 April 2026](https://www.w3.org/TR/2026/WD-CSP3-20260421/) — immutable dated W3C snapshot before the cutoff. Checked text: publication date; CSP is defence-in-depth for content injection, not a replacement for input validation/output encoding; CSP response header is the preferred delivery mechanism. Boundary: Working Draft is not evidence of browser, header or product behaviour.
|
||||
2. [OWASP ASVS v5.0.0, immutable commit `5cf9b032440be53ce345ab3c130fda46ba1ce7a2`](https://github.com/OWASP/ASVS/blob/5cf9b032440be53ce345ab3c130fda46ba1ce7a2/5.0/en/0x12-V3-Web-Frontend-Security.md) — release tag `v5.0.0_release`, commit/release date 2025-05-30. Checked narrow facts: web-frontend requirements include documented expected browser features, CSP response header/directives, safe rendering, cookie and cross-origin requirements. Boundary: a requirement is not a completed assessment or attack-path proof.
|
||||
3. [NISTIR 8397](https://doi.org/10.6028/NIST.IR.8397) — NIST publication 2021-10-06. Checked narrow facts: recommendations include threat modeling, automated testing, static scanning, black-box/code-based tests, fuzzing and web app scanners where applicable. Boundary: NISTIR does not define this synthetic model, a sufficient evidence set or operational authority.
|
||||
|
||||
### Executable surface
|
||||
|
||||
- Public exports: `createFixedSyntheticSecurityReview`, `mapFixedAttackControlEvidence`, `reviewFixedSecurityTraceability`, `createFixedEvidenceRetestCase`, `reviewFixedEvidenceRetestCase`, `runFixedSecurityReviewFixture`.
|
||||
- All records are named, fixed, JSON-cloned, deeply frozen literals in memory.
|
||||
- The practice snippet maps the accepted fixed path; the mechanism snippet proves the unbound-evidence stop; the field snippet returns the bounded synthetic hand-off.
|
||||
- Fixture covers accepted hand-off and closed failures: unnamed attack path, unbound evidence, missing residual risk, unsafe positive result, and missing retest case.
|
||||
- Explicit non-capabilities: no network, filesystem, clock, telemetry, browser, real stand, API, secret, production system, deployment, release or security claim.
|
||||
|
||||
## Pass 3 — release quality
|
||||
|
||||
### Required command record
|
||||
|
||||
Run from `web/` after creation:
|
||||
|
||||
```sh
|
||||
node --check scripts/upgrade-2026-04.mjs
|
||||
node scripts/upgrade-2026-04.mjs --verify-fixture
|
||||
npm run audit:draft -- scripts/upgrade-2026-04.mjs
|
||||
node --input-type=module -e "import { createFixedSyntheticSecurityReview, mapFixedAttackControlEvidence, reviewFixedSecurityTraceability, createFixedEvidenceRetestCase, reviewFixedEvidenceRetestCase } from './scripts/upgrade-2026-04.mjs'; console.log(mapFixedAttackControlEvidence(createFixedSyntheticSecurityReview('mapped-injection-path-v1')).status); console.log(reviewFixedSecurityTraceability(createFixedSyntheticSecurityReview('evidence-without-binding-v1')).status); console.log(reviewFixedEvidenceRetestCase(createFixedEvidenceRetestCase('mapped-injection-path-v1')).status);"
|
||||
xmllint --noout public/assets/editorial/2026/modern-web-security-2026-attack-control-evidence-map.svg public/assets/editorial/2026/modern-web-security-2026-residual-risk-matrix.svg public/assets/editorial/2026/modern-web-security-2026-evidence-review-loop.svg
|
||||
rg -n -i "<(script|foreignObject)\\b|javascript:|data:image|(?:^|[[:space:]])on[a-z]+=" public/assets/editorial/2026/modern-web-security-2026-*.svg || test $? -eq 1
|
||||
git diff --check
|
||||
```
|
||||
|
||||
### Visual and link audit targets
|
||||
|
||||
- Render all three SVG files to 375px PNG with Sharp; inspect each mobile render for legibility, contrast, clipped arrows and legible captions.
|
||||
- Confirm every figure has asset path, meaningful Russian alt, and caption in the article HTML.
|
||||
- Confirm each source URL is HTTPS and pinned by a dated W3C snapshot, a commit hash, or a DOI publication. No mutable "latest" reference.
|
||||
|
||||
### Strict uniqueness target
|
||||
|
||||
Source lists excluded. Run pairwise scan over all body HTML including code. Every pair must have `exactParagraphs160: 0` and `common12WordFragments: 0`.
|
||||
|
||||
### Actual final run — passed
|
||||
|
||||
- `node --check scripts/upgrade-2026-04.mjs` — passed.
|
||||
- `node scripts/upgrade-2026-04.mjs --verify-fixture` — `PASS fixture: 11/11 assertions`.
|
||||
- `npm run audit:draft -- scripts/upgrade-2026-04.mjs` — passed all three: 9,479 / 9,565 / 9,552 body characters.
|
||||
- Literal public-export execution — `fixed-attack-control-evidence-map`, `stop-unbound-evidence`, `synthetic-security-review-hand-off`; all three outputs match the article comments.
|
||||
- `xmllint --noout` — passed for all three SVG assets; SVG safety `rg` found no script, foreignObject, JavaScript URL, data image, or event handler.
|
||||
- Sharp rendered all three SVG files at 375px; visual inspection passed: mobile text is legible, connectors are not clipped, contrast is retained.
|
||||
- Source link audit — W3C dated snapshot and OWASP immutable commit URL returned HTTP 200; DOI resolved successfully. Narrow source claims were rechecked against their pinned documents.
|
||||
- Pairwise strict scan, source lists excluded and code included — all three pairs returned `exactParagraphs160: 0`, `common12WordFragments: 0`.
|
||||
- `git diff --check` — passed. This was the sole Git command used and made no repository change.
|
||||
|
||||
### Disposition
|
||||
|
||||
Draft only. Integration, staging, commit and publication are deliberately out of scope.
|
||||
|
||||
## Независимая приёмка основного редактора — 31.07.2026
|
||||
|
||||
- Сверены source pins: dated CSP3 snapshot действительно содержит дату 21.04.2026 и ограничивает CSP ролью defense-in-depth; pinned ASVS 5.0.0 содержит проверяемые browser-feature, safe-rendering и CSP-header требования; NISTIR 8397 опубликован в октябре 2021 и перечисляет отдельные техники developer verification. Никакой из этих источников не выдан за факт о конкретной системе.
|
||||
- Повторно выполнены `node --check`, fixture `11/11`, `audit:draft` (9 479 / 9 565 / 9 552 знака), три literal public-export вызова, XML и SVG safety scan. Все результаты успешны.
|
||||
- В 375px рендерах три схемы читаемы: текст, связи и стоп-ветви не обрезаны. Попарный scan, исключающий source lists и включающий code, вернул ноль длинных одинаковых абзацев и ноль общих 12-словных фрагментов.
|
||||
- Принято к публикации как overlay P98. Это добавляет только три апрельские ревизии; посторонние незакоммиченные материалы не входят в пакет.
|
||||
Reference in New Issue
Block a user