Commit Graph
35 Commits
Author SHA1 Message Date
implementer f00c13d57a fix: make .dockerignore exclusions apply at any depth (E00-S02-T08)
CI / Frozen lockfile install (pull_request) Successful in 52s
CI / Secrets not embedded (E00-S02-T08) (pull_request) Successful in 36s
Resolve the security review of #389 (findings 1-4):

- .dockerignore: every env/credential pattern is now **/-prefixed
  (**/.env, **/.env.*, **/node_modules, **/.npmrc, ..., **/secrets,
  **/*.pem, **/*.key, ...) and the redundant 'secrets/' line is dropped.
  Docker's matcher (moby/patternmatcher) anchors slash-less patterns to
  the context root, so the bare forms excluded nothing under apps/server/;
  **/ matches the root AND any nested depth. (finding 1, 3)
- tests/secrets-not-embedded.test.mjs: the dockerignore matcher is now a
  faithful port of moby/patternmatcher (filepath.Clean + anchored full-path
  match + parent-directory propagation), not gitignore basename semantics;
  asserts nested example paths (apps/server/.npmrc, config/server.key,
  apps/server/secrets/...) are excluded; requires no redundant equivalent
  patterns verbatim; adds mutation probes for bare-pattern and
  duplicate-pattern regressions. (finding 2, 3)
- apps/server/Dockerfile + compose.yaml: guarantee restated precisely
  (credential files excluded at the context root AND at any depth).
- .gitea/workflows/ci.yml: new job runs
  'node --test tests/secrets-not-embedded.test.mjs' on every PR; the
  docker-gated layer-scan probe runs where a daemon exists, skips cleanly
  otherwise. (finding 4)
- tests/compose-config.test.mjs: .dockerignore presence list updated to the
  **/-prefixed forms (node_modules, .env).

Tested: secrets suite 16 tests -> 15 pass / 1 docker-gated skip / 0 fail;
full suite 101 pass / 12 fail / 8 skip, failures identical to clean main
(env-dependent pnpm/Node-24 suites); matcher port verified against the
moby/patternmatcher evidence table.
2026-08-29 01:49:07 +00:00
implementer b3ad55efe8 test: lock in no-secrets-in-image criteria (E00-S02-T08)
CI / Frozen lockfile install (pull_request) Successful in 50s
tests/secrets-not-embedded.test.mjs: static assertions that the Dockerfile
embeds no secrets (no secret-bearing ARG/ENV, no secret-path or blanket COPY)
and .dockerignore excludes env/credential files; non-vacuous mutation probes
for every assertion; Docker-gated probe that builds the image with a marker
env file in the context and scans every layer + image config for secret
values.
2026-08-29 01:28:26 +00:00
implementer 0938da8a73 feat: keep secrets out of the app image (E00-S02-T08)
- .dockerignore: exclude env + credential files (.npmrc, .netrc, .aws, .ssh,
  secrets/, *.pem, *.key, *.p12, *.pfx, *.jks, id_rsa, id_ed25519, ...) from
  the build context so a local secret file cannot be embedded in the image
- Dockerfile: document the T08 guarantee (no secret ARG/ENV, fixed non-secret
  COPY paths, runtime credentials via Compose environment)
- compose.yaml: T08 in scope; runtime credentials stay in service environment,
  never in the image
2026-08-29 01:28:26 +00:00
implementer 41428b083e test: lock in read-only rootfs criteria (E00-S02-T06)
CI / Frozen lockfile install (pull_request) Successful in 56s
2026-08-29 00:53:40 +00:00
implementer 7ce3ba53cf feat: make the app root filesystem read-only (E00-S02-T06) 2026-08-29 00:53:40 +00:00
implementer 6e8ba388a6 test: lock in non-root execution criteria (E00-S02-T05)
CI / Frozen lockfile install (pull_request) Successful in 51s
tests/non-root-user.test.mjs locks in both acceptance criteria: a static
assertion that the Dockerfile runtime stage declares a non-root USER (not
root/uid 0, 'USER node' exactly), non-vacuous mutation probes, and a
Docker-gated real-stack probe that starts the stack and asserts 'id -u' and
'id -un' inside the running app container report a non-root user, with the
health endpoint still answering as a regression guard.
2026-08-29 00:41:16 +00:00
implementer a4cf365098 feat: run the app image as a non-root user (E00-S02-T05)
The runtime stage of apps/server/Dockerfile now drops root privileges with
'USER node' — the non-root user (uid/gid 1000) the official Node image ships
with — so the app container does not run with root privileges. The server
binds port 3000 (>= 1024) and only reads the root-owned files copied above,
so no extra user creation or ownership changes are required. compose.yaml
header updated: T05 is in scope; T06 (read-only rootfs) and T07 (multi-arch)
remain out of scope.
2026-08-29 00:41:10 +00:00
implementer b51af02d06 test: lock in DB volume persistence criteria (E00-S02-T04)
CI / Frozen lockfile install (pull_request) Successful in 45s
compose-config: assert the db service mounts the named db-data volume at
the PostgreSQL data directory and the top-level volumes map declares it;
non-vacuous mutation probes (missing mount, missing volume declaration,
wrong mount target all fail); Docker-gated real-stack probe writes a
fixture row and asserts it survives `docker compose restart` (restart)
and `docker compose down` + `up -d` (recreate), cleaned up with
`docker compose down -v`.
2026-08-29 00:32:15 +00:00
implementer 3dd80f91fe feat: persist the database volume across restart/recreate (E00-S02-T04)
Mount the named `db-data` volume at PostgreSQL's data directory
(/var/lib/postgresql/data) on the db service and declare it in the
top-level volumes map, so the database survives `docker compose
restart` and `docker compose down` + `up -d` (recreate). Reset with
`docker compose down -v` per the issue rollback note. Header comments
in compose.yaml and the server Dockerfile updated: T04 is no longer out
of scope; T05/T06 remain.
2026-08-29 00:32:15 +00:00
implementer dfb7b0e952 fix: handle quoted scoped keys in frozen-install probe (E00-S02-T03)
CI / Frozen lockfile install (pull_request) Successful in 50s
2026-08-29 00:23:27 +00:00
implementer f7257f9258 test: lock in app health endpoint criteria (E00-S02-T03) 2026-08-29 00:21:34 +00:00
implementer 9c049ce6b5 feat: app health endpoint succeeds (E00-S02-T03) 2026-08-29 00:21:34 +00:00
implementer 59a102bee3 feat: PostgreSQL health gates app start (E00-S02-T02)
CI / Frozen lockfile install (pull_request) Successful in 47s
2026-08-28 23:59:45 +00:00
implementer 3bbea68e6c fix: align app/db image bases with documented stack (E00-S02-T01)
CI / Frozen lockfile install (pull_request) Successful in 48s
Switch the app image from node:24-alpine to node:24.19.0-bookworm-slim in
both build and runtime stages (Technology-Stack 5.4: glibc Debian base
required because argon2 is a native dependency; musl/Alpine causes
native-module build surprises), and the db image from postgres:16-alpine
to postgres:18-bookworm (Technology-Stack 5.2/5.4/6.2 + golden tuple 7
pin PostgreSQL 18.6; 18-bookworm is the 18.x line on Debian bookworm).

Update tests/compose-config.test.mjs so the committed assertions lock in
the corrected image bases (db image, Dockerfile build/runtime stages,
parser probe).
2026-08-28 23:45:18 +00:00
implementer 3be575818d feat: docker compose up -d starts DB + app (E00-S02-T01)
CI / Frozen lockfile install (pull_request) Successful in 43s
2026-08-28 23:35:05 +00:00
implementer 27851fcaeb test: lock in no core package imports a concrete extension (E00-S01-T14)
CI / Frozen lockfile install (pull_request) Successful in 47s
2026-08-28 23:24:02 +00:00
implementer ca9e0ffaf6 test: lock in clean-clone frozen lockfile install (E00-S01-T13)
CI / Frozen lockfile install (pull_request) Successful in 45s
2026-08-28 23:10:26 +00:00
implementer 5c6ca444d9 test: lock in root build/test/typecheck commands (E00-S01-T12)
CI / Frozen lockfile install (pull_request) Successful in 44s
2026-08-28 22:56:48 +00:00
implementer 729a67b79d test: lock in apps/packages/extensions workspace layout separation (E00-S01-T11)
CI / Frozen lockfile install (pull_request) Successful in 44s
2026-08-28 22:43:01 +00:00
implementer 4b5519465f test: lock in strict base tsconfig for all packages (E00-S01-T10)
CI / Frozen lockfile install (pull_request) Successful in 45s
2026-08-28 21:46:57 +00:00
implementer 628885ae0f test: lock in TypeScript 6.0.3 exact dependency (E00-S01-T09)
CI / Frozen lockfile install (pull_request) Successful in 44s
2026-08-28 21:33:52 +00:00
implementer 6323e486bc docs: document enforced Node 24.x engine restriction (E00-S01-T08)
CI / Frozen lockfile install (pull_request) Successful in 43s
2026-08-28 09:15:09 +00:00
implementer 7c548ac43b test: lock in Node 24.x engine restriction (E00-S01-T08) 2026-08-28 09:15:09 +00:00
implementer d405ee5cfa feat: restrict Node engine to 24.x (E00-S01-T08) 2026-08-28 09:15:09 +00:00
implementer 23a574d6af test: lock in committed pnpm 11.23.0 workspace config (E00-S01-T07)
CI / Frozen lockfile install (pull_request) Successful in 48s
2026-08-28 09:03:50 +00:00
implementer 21485aed44 feat(server): add start script for compiled entrypoint (E00-S01-T06)
CI / Frozen lockfile install (pull_request) Successful in 48s
2026-08-28 08:52:03 +00:00
implementer 72c53494a1 docs: add local non-container developer path guide (E00-S01-T06) 2026-08-28 08:52:03 +00:00
implementer 0d1bd19093 feat: add root build/test/typecheck scripts (E00-S01-T05)
CI / Frozen lockfile install (pull_request) Successful in 50s
Adds root scripts so build, test and typecheck run from the workspace root:
- root package.json gains scripts: build (pnpm -r run build), test
  (node --test on tests/**/*.test.mjs), typecheck (pnpm -r run typecheck)
- every workspace package (apps/server, packages/core,
  extensions/example) gains build (tsc -p tsconfig.json) and typecheck
  (tsc -p tsconfig.json --noEmit) scripts
- typescript 6.0.3 pinned as an exact root devDependency so the commands
  run from a clean checkout; lockfile regenerated with pnpm 11.23.0

Verified from a clean state: pnpm install --frozen-lockfile passes,
pnpm build emits dist for all 3 packages, pnpm typecheck passes for all 3,
pnpm test runs tests/architecture-import.test.mjs 10/10 green, and CI's
pnpm -r list --depth -1 still lists all 4 workspace projects.

Closes #158
2026-08-28 08:39:13 +00:00
implementer 4d0df92290 feat: add dependency-boundary rule and architecture import test (E00-S01-T04)
CI / Frozen lockfile install (pull_request) Successful in 38s
Adds a declarative dependency-boundary rule (dependency-boundaries.json)
classifying workspace packages into apps/packages/extensions groups and
forbidding packages/* (core) from importing extensions/* (concrete
extensions); core depends only on extension contracts, never concrete
extensions.

Adds tests/architecture-import.test.mjs (node:test, zero new dependencies,
lockfile untouched) that loads the rule, walks every workspace package's
source and resolves each import/export/require specifier (bare workspace
names, relative paths, dynamic import(), require(), export-from) to a
group, failing on any forbidden core -> extension edge. Comment-aware
scanning avoids false positives; line numbers in violation reports map to
the original source. Synthetic negative cases prove detection (bare name,
relative path, export-from, dynamic import, require), while the current
compliant graph passes with zero violations.

Verified: 10/10 tests pass; injecting a real core -> extension import makes
the integration test fail with a per-file/line violation report; pnpm 11.23.0
install --frozen-lockfile passes unchanged (CI frozen-install job stays green).

Closes #157
2026-08-28 08:30:34 +00:00
implementer b1fef8d592 feat: configure ESM package boundaries across the workspace (E00-S01-T03)
CI / Frozen lockfile install (pull_request) Successful in 39s
Adds ESM boundary declarations to every workspace package manifest
(apps/server, packages/core, extensions/example): "type": "module",
"main"/"types" entry points and an "exports" map (types + import
conditions) so each package exposes only its public root; adds
"type": "module" to the workspace root package.json so the workspace is
uniformly ESM. Placeholder src/index.ts files stay as empty ESM modules.

Verified: each package compiles under tsconfig.base.json (NodeNext) with
TypeScript 6.0.3 and emits ESM dist/index.js + dist/index.d.ts; Node
imports each package by name through its exports map and rejects deep
subpath imports (ERR_PACKAGE_PATH_NOT_EXPORTED); pnpm 11.23.0
install --frozen-lockfile passes with the lockfile unchanged.

Closes #156
2026-08-28 08:13:00 +00:00
implementer 4e527f9267 feat: add strict tsconfig.base.json shared by all packages (E00-S01-T02)
CI / Frozen lockfile install (pull_request) Successful in 39s
Adds a strict base TypeScript config at the workspace root (ES2023 / NodeNext
/ strict family incl. noUncheckedIndexedAccess, exactOptionalPropertyTypes,
noImplicitOverride, useUnknownInCatchVariables, verbatimModuleSyntax per
Engineering-Standards) and gives every workspace package
(apps/server, packages/core, extensions/example) a tsconfig.json that extends
it. Each package gets a minimal src/index.ts placeholder so it compiles under
the base config (CJS-safe `export {}` until ESM boundaries land in T03).

Verified: every package typechecks and emits (js + d.ts + sourcemap) with the
pinned TypeScript 6.0.3; a strictness probe confirms the strict family fires.

Closes #155
2026-08-28 00:00:51 +00:00
implementer a2fa1dee32 chore: bootstrap pnpm workspace and package manifests
CI / Frozen lockfile install (pull_request) Successful in 48s
E00-S01-T01: create workspace/package manifests
- root package.json pins packageManager pnpm@11.23.0
- pnpm-workspace.yaml separates apps/*, packages/*, extensions/* entries
- skeleton manifests for apps/server, packages/core, extensions/example
- committed frozen lockfile generated by pnpm 11.23.0
- minimal CI: pnpm install --frozen-lockfile + workspace verification
2026-08-27 23:07:58 +00:00
implementer e186faeb44 Add root .gitignore for local env files and node_modules
CI / Run tests (pull_request) Successful in 29s
CI / Secret scan (gitleaks) (pull_request) Successful in 57s
Ignores .env, .env.*, and node_modules/ at any depth so local secrets and dependency directories can never be committed accidentally. Single-file hygiene change; no tracked files affected. Closes #19.
2026-08-26 19:34:37 +00:00
implementer 32c81d8b91 test: add 3xx-redirect failure and no-credential-header/URL checks
CI / Run tests (pull_request) Successful in 16s
CI / Secret scan (gitleaks) (pull_request) Failing after 13s
Extends the newsletter suite with two boundary cases: redirects (301/302/307/
308) must be treated as failures with the user-safe error, and the POST must
carry no credential of any kind — no api-key/auth-token/cookie headers, and no
token/secret in the body or URL.
2026-08-26 11:31:54 +00:00
implementer 86aa3afbbf refactor: newsletter signup posts no credential (SEC-14-R1 option a)
CI / Secret scan (gitleaks) (pull_request) Failing after 12s
CI / Run tests (pull_request) Successful in 15s
Rework PR #15 per security review SEC-14-R1: the client no longer carries
an API token. js/newsletter-config.js ships only the non-secret endpoint,
enforced https-only at config load time via validateEndpoint() (mirroring
the protocol allowlist in js/reading-list.js); js/newsletter.js POSTs
email-only with no Authorization header. Failure paths keep the single
user-safe message that never leaks token, endpoint, status, or raw body;
success still shows the confirmation. CI gains a gitleaks step that fails
on any secret hit; README documents the server-side token, the residual
signup-abuse risk, and the authoritative server-side validation follow-up.
2026-08-26 11:27:11 +00:00