Files
huncode 542b2c393d
Build and deploy / deploy (push) Successful in 7s
record April 2026 release verification
2026-07-31 19:31:41 +03:00

119 lines
13 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# P98 — April 2026: «Современная безопасность веба»
Scope intentionally limited to the P98 overlay, this review note, and three SVG assets. No registry, README, application file, archive JSON, production queue, staging, commit, push, fetch, rebase, reset, stash or checkout belongs to this draft package.
## Editorial contract
- Historical cutoff: 2026-04-30.
- Three rewrites only: practice map, mechanism traceability/residual risk, field evidence/retest loop.
- Each body must be 5,000–15,000 characters; target 9,000–13,000.
- M9 voice: short pragmatic Russian technical sentences, named limits, no compliance theatre, no implied production observation.
- Opening two paragraphs name a concrete problem and cost.
- Every article has an accessible table, a distinct SVG with meaningful alt/caption, ordered sequence, executable public-export example, limits and one next step.
- Positive data-model result is only `synthetic-security-review-hand-off`; it never approves, releases, deploys, contacts or changes anything.
## Pass 1 — problem, density, voice and independence
### Practice — `editorial-2026-04-practice-modern-web-security`
- Problem/cost appears in the first paragraph: a control inventory cannot identify an interrupted attack step; investigation cost moves from diagnosis to arguments about configuration.
- Independent angle: compose an attack-control-evidence map starting from an attacker verb and one route, then preserve residual ownership question.
- Density: each section adds a decision object, table field, executable mapping, failure mode or hand-off boundary. Generic security introduction removed.
- M9 voice checked: narrow verbs (`name`, `bind`, `stop`, `hand off`), short claims, no promise of safety.
### Mechanism — `editorial-2026-04-mechanism-modern-web-security`
- Problem/cost appears first: a baseline is retrospectively treated as causal proof, producing false confidence and costly incident analysis.
- Independent angle: explain traceability as missing relations between threat, interruption, observation and residual risk; it is not a second version of the practice checklist.
- Density: matrix separates permitted inferences from prohibited inference jumps; success result is structurally constrained.
- M9 voice checked: the article treats evidence as a type of permitted conclusion and uses explicit stops instead of reassurance.
### Field — `editorial-2026-04-field-modern-web-security`
- Problem/cost appears first: an ambiguous hand-off grows into an accidental operational permission; later participants cannot recover the original scope.
- Independent angle: an authorised-by-schema review loop for bounded evidence/retest, deliberately separated from production authority.
- Density: every loop stage carries a named input/output/stop; retest scope is two observations, not a generic retest claim.
- M9 voice checked: `authorised` is defined narrowly and denied any organisational or deployment meaning.
## Pass 2 — sources, historical boundary and executability
### Source pins independently checked
1. [W3C CSP Level 3, Working Draft 21 April 2026](https://www.w3.org/TR/2026/WD-CSP3-20260421/) — immutable dated W3C snapshot before the cutoff. Checked text: publication date; CSP is defence-in-depth for content injection, not a replacement for input validation/output encoding; CSP response header is the preferred delivery mechanism. Boundary: Working Draft is not evidence of browser, header or product behaviour.
2. [OWASP ASVS v5.0.0, immutable commit `5cf9b032440be53ce345ab3c130fda46ba1ce7a2`](https://github.com/OWASP/ASVS/blob/5cf9b032440be53ce345ab3c130fda46ba1ce7a2/5.0/en/0x12-V3-Web-Frontend-Security.md) — release tag `v5.0.0_release`, commit/release date 2025-05-30. Checked narrow facts: web-frontend requirements include documented expected browser features, CSP response header/directives, safe rendering, cookie and cross-origin requirements. Boundary: a requirement is not a completed assessment or attack-path proof.
3. [NISTIR 8397](https://doi.org/10.6028/NIST.IR.8397) — NIST publication 2021-10-06. Checked narrow facts: recommendations include threat modeling, automated testing, static scanning, black-box/code-based tests, fuzzing and web app scanners where applicable. Boundary: NISTIR does not define this synthetic model, a sufficient evidence set or operational authority.
### Executable surface
- Public exports: `createFixedSyntheticSecurityReview`, `mapFixedAttackControlEvidence`, `reviewFixedSecurityTraceability`, `createFixedEvidenceRetestCase`, `reviewFixedEvidenceRetestCase`, `runFixedSecurityReviewFixture`.
- All records are named, fixed, JSON-cloned, deeply frozen literals in memory.
- The practice snippet maps the accepted fixed path; the mechanism snippet proves the unbound-evidence stop; the field snippet returns the bounded synthetic hand-off.
- Fixture covers accepted hand-off and closed failures: unnamed attack path, unbound evidence, missing residual risk, unsafe positive result, and missing retest case.
- Explicit non-capabilities: no network, filesystem, clock, telemetry, browser, real stand, API, secret, production system, deployment, release or security claim.
## Pass 3 — release quality
### Required command record
Run from `web/` after creation:
```sh
node --check scripts/upgrade-2026-04.mjs
node scripts/upgrade-2026-04.mjs --verify-fixture
npm run audit:draft -- scripts/upgrade-2026-04.mjs
node --input-type=module -e "import { createFixedSyntheticSecurityReview, mapFixedAttackControlEvidence, reviewFixedSecurityTraceability, createFixedEvidenceRetestCase, reviewFixedEvidenceRetestCase } from './scripts/upgrade-2026-04.mjs'; console.log(mapFixedAttackControlEvidence(createFixedSyntheticSecurityReview('mapped-injection-path-v1')).status); console.log(reviewFixedSecurityTraceability(createFixedSyntheticSecurityReview('evidence-without-binding-v1')).status); console.log(reviewFixedEvidenceRetestCase(createFixedEvidenceRetestCase('mapped-injection-path-v1')).status);"
xmllint --noout public/assets/editorial/2026/modern-web-security-2026-attack-control-evidence-map.svg public/assets/editorial/2026/modern-web-security-2026-residual-risk-matrix.svg public/assets/editorial/2026/modern-web-security-2026-evidence-review-loop.svg
rg -n -i "<(script|foreignObject)\\b|javascript:|data:image|(?:^|[[:space:]])on[a-z]+=" public/assets/editorial/2026/modern-web-security-2026-*.svg || test $? -eq 1
git diff --check
```
### Visual and link audit targets
- Render all three SVG files to 375px PNG with Sharp; inspect each mobile render for legibility, contrast, clipped arrows and legible captions.
- Confirm every figure has asset path, meaningful Russian alt, and caption in the article HTML.
- Confirm each source URL is HTTPS and pinned by a dated W3C snapshot, a commit hash, or a DOI publication. No mutable "latest" reference.
### Strict uniqueness target
Source lists excluded. Run pairwise scan over all body HTML including code. Every pair must have `exactParagraphs160: 0` and `common12WordFragments: 0`.
### Actual final run — passed
- `node --check scripts/upgrade-2026-04.mjs` — passed.
- `node scripts/upgrade-2026-04.mjs --verify-fixture` — `PASS fixture: 11/11 assertions`.
- `npm run audit:draft -- scripts/upgrade-2026-04.mjs` — passed all three: 9,479 / 9,565 / 9,552 body characters.
- Literal public-export execution — `fixed-attack-control-evidence-map`, `stop-unbound-evidence`, `synthetic-security-review-hand-off`; all three outputs match the article comments.
- `xmllint --noout` — passed for all three SVG assets; SVG safety `rg` found no script, foreignObject, JavaScript URL, data image, or event handler.
- Sharp rendered all three SVG files at 375px; visual inspection passed: mobile text is legible, connectors are not clipped, contrast is retained.
- Source link audit — W3C dated snapshot and OWASP immutable commit URL returned HTTP 200; DOI resolved successfully. Narrow source claims were rechecked against their pinned documents.
- Pairwise strict scan, source lists excluded and code included — all three pairs returned `exactParagraphs160: 0`, `common12WordFragments: 0`.
- `git diff --check` — passed. This was the sole Git command used and made no repository change.
### Disposition
Draft only. Integration, staging, commit and publication are deliberately out of scope.
## Независимая приёмка основным редактором — 31 июля 2026
Пакет принят поверх отчёта автора. Проверялись и тексты, и исполняемый surface, и реальные исторические первоисточники.
### Проход 1 — проблема, плотность и редакторская самостоятельность
- Все три текста открываются конкретной потерей: инвентарь не показывает прерванный шаг атаки; baseline выдаётся за причинное доказательство; hand-off разрастается в ложный допуск.
- Независимые углы сохранены: практика строит карту path/control/evidence, механизм запрещает скачки вывода через traceability, field-публикация ограничивает передачу и retest scope.
- `audit:draft` повторно подтвердил объём: 9 479 / 9 565 / 9 552 знака. В каждом тексте есть таблица, отдельная схема, исполняемый пример, последовательность, ограничения и следующий шаг.
### Проход 2 — факты, источники и исполняемость
- Датированный [W3C CSP3 snapshot от 21.04.2026](https://www.w3.org/TR/2026/WD-CSP3-20260421/) повторно прочитан напрямую: он называет CSP defense-in-depth, не заменяющей input validation/output encoding, и называет `Content-Security-Policy` HTTP response header предпочтительным механизмом доставки policy. Это поддерживает только узкие формулировки статей, не поведение какого-либо приложения.
- [OWASP ASVS commit `5cf9b032440be53ce345ab3c130fda46ba1ce7a2`](https://github.com/OWASP/ASVS/tree/5cf9b032440be53ce345ab3c130fda46ba1ce7a2) повторно сверён: commit датирован 30.05.2025, а `git ls-remote --tags` связывает его с тегом `v5.0.0_release`. В pinned frontend chapter действительно есть browser features, CSP, safe rendering, cookies и cross-origin requirements; это requirements, не evidence конкретной защиты.
- Официальная [страница NISTIR 8397](https://csrc.nist.gov/pubs/ir/8397/final) подтверждает выпуск 6 октября 2021 года и разные рекомендации: threat modeling, automated testing, static scanning, black-box/code-based tests, fuzzing и web app scanners where applicable. Она не определяет synthetic model.
- Повторный literal execution public exports вернул только ожидаемые статусы: `fixed-attack-control-evidence-map`, `stop-unbound-evidence`, `synthetic-security-review-hand-off`, `stop-unknown-fixed-evidence-case`. У положительного результата остались два named observations и `productionEffect: not-attempted`.
### Проход 3 — выпускная проверка
- `node --check`, fixture `11/11`, `npm run audit:draft`, XML и SVG safety scan прошли повторно.
- Все три SVG отрендерены Sharp в 375px и просмотрены. Во время приёмки матрица residual risk была переработана: прежние длинные подписи на этой ширине обрезались; итоговая версия использует короткие, различимые подписи и сохраняет тот же смысл. Карта и loop также читаемы без мелкого текста или обрезанных connectors.
- Строгий pairwise scan без source lists, но включая code: во всех трёх парах `exactParagraphs160: 0`, `common12WordFragments: 0`.
- Итог: три записи готовы к интеграции как ограниченные synthetic security-reasoning статьи. Они не являются assessment, approval, release или утверждением о production security posture.