Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,12 +6,15 @@ All notable changes are documented here. RealDone follows semantic versioning wh

### Added

- Pre-capture visual privacy for automatic scans and contract/role verification: known-sensitive inputs, `secretEnv` and auth-state contexts now suppress screenshot/video binaries while safe controls retain them, with additive value-free report metadata.
- Fresh Phase K qualification at fingerprint `4625a9cc…` across TodoMVC, Actual Budget, Conduit SQLite/PostgreSQL 17/Supabase Data API and Pocket Ledger, including PostgreSQL CRUD cleanup, 6/6 visible Pocket Ledger actions, Level 7 roles and a new Codex MCP RD901 regression/repair cycle.
- Fail-closed per-trace retention for automatic scans and contract/MCP verification: bounded ZIP inspection now checks generated sensitive fields, contract `secretEnv`, opaque Playwright auth-state cookies/tokens and generic credential patterns before report linkage, with additive value-free suppression metadata for deleted unsafe or unscannable traces.
- Fresh fingerprint-bound Phase J qualification across TodoMVC, Actual Budget, Conduit SQLite/PostgreSQL 17/Supabase Data API and Pocket Ledger, including PostgreSQL CRUD cleanup, Level 7 roles and a new Codex MCP RD901 regression/repair cycle.
- Coverage-balanced quick-scan scheduling that represents more routes, action kinds, intents, and keyboard/submit activation paths within the same finite action budget, while placing known policy/environment denials after runnable actions.
- Additive action-selection telemetry in JSON and HTML reports, including eligible/selected/omitted counts, route coverage, semantic coverage, denial counts, the deterministic strategy version, and an explicit partial-scan explanation.
- Fresh fingerprint-bound qualification across TodoMVC, Actual Budget, Conduit/SQLite, Conduit/PostgreSQL 17 + Supabase Data API, and Codex-generated Pocket Ledger, including PostgreSQL create/update/delete cleanup, Level 7 roles, and a real Codex MCP baseline → RD901 regression → repair cycle.
- Hosted main run `30195945498` passed and signed all 15 normative gates across Linux, Windows and macOS for the Phase I fingerprint and installed-package path.
- Hosted main run `30200299159` passed and signed all 15 normative gates across Linux, Windows and macOS for the Phase J fingerprint; both aggregate artifacts verified against merge `6d736d5`.

### Fixed

Expand Down
2 changes: 1 addition & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ RealDone drives a real browser. The default policy limits mutations to local/tes

Recorded password-like inputs are replaced by environment-variable references and rrweb runs with all input masking enabled. Playwright auth-state files contain sensitive cookies and may grant account access; keep them under the ignored `.realdone/` directory, never commit them, and rotate staging credentials after suspected exposure.

Playwright traces and browser videos can contain visible application content, URLs, and interaction state that generic secret redaction cannot remove. They are opt-in, remain in the ignored local report tree, and must be reviewed before sharing or attaching to a public issue.
Playwright traces and browser videos can contain visible application content, URLs, and interaction state that generic secret redaction cannot remove. Retained traces pass bounded secret inspection, while known-sensitive and auth-state contexts disable standalone/trace screenshots and video before capture. Remaining visual artifacts are opt-in, stay in the ignored local report tree, and must be reviewed before sharing or attaching to a public issue.

PostgreSQL credentials and CA material must be provided through the environment names referenced by the adapter config. Prefer a dedicated least-privilege read-only role. Source verification also opens a read-only transaction. Database cleanup is a separate opt-in path requiring CLI confirmation, config permission, exact allowlisted key fields, and a maximum-row rollback guard; use it only against disposable local or staging data.

Expand Down
2 changes: 1 addition & 1 deletion docs/ADVANCED.md
Original file line number Diff line number Diff line change
Expand Up @@ -75,7 +75,7 @@ Capture full debugging artifacts explicitly when needed:
realdone verify flow.json --deep --trace --video
```

Trace ZIPs and browser videos are linked from local HTML/JSON evidence. They can contain application content, so keep them under the ignored `.realdone/` tree and review them before sharing.
Trace ZIPs and browser videos are linked from local HTML/JSON evidence. Retained traces pass bounded secret inspection; screenshot/video capture is suppressed for known-sensitive and authenticated contexts because binary inspection cannot prove rendered content safe. Other visual artifacts can still contain application content, so keep them under the ignored `.realdone/` tree and review them before sharing.

Attach read-only, value-free source snapshots to every executed mutation when source-of-truth change evidence is needed:

Expand Down
2 changes: 1 addition & 1 deletion docs/CI.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ Provide database/provider credentials and optional CA material as masked workflo

The action accepts one `browser` per job (`chromium`, `firefox`, or `webkit`). Use a job matrix when every engine must gate a pull request. `database-configs`, `provider-configs`, `role-states`, and `plugins` are newline-separated; secret values remain in environment variables or Playwright auth-state files rather than action inputs. Set `install-browser: "false"` only when the selected Playwright browser is already installed.

`deep`, `trace`, and `video` are separate boolean inputs. Deep verification increases browser-context count; traces and videos can be large and may contain private application content, so enable them selectively.
`deep`, `trace`, and `video` are separate boolean inputs. Deep verification increases browser-context count; traces and videos can be large and may contain private application content, so enable them selectively. Known-sensitive and auth-state contexts suppress screenshot/video capture before binary creation and expose value-free metadata instead.

## Playwright export

Expand Down
4 changes: 4 additions & 0 deletions docs/COMPATIBILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@ Unreleased main fingerprint `f3f65840…` preserved the same matrix and package

The subsequent Phase I status merge `42006c4` independently repeated the full matrix and signed 15/15 in hosted main run [`30196808460`](https://github.com/datzle123/RealDone/actions/runs/30196808460).

Phase J fingerprint `0b39d542…` repeated the matrix in hosted main run [`30200299159`](https://github.com/datzle123/RealDone/actions/runs/30200299159). GitHub signed both aggregate artifacts for merge `6d736d5`, and `gh attestation verify` accepted their Linux/macOS/Windows provenance.

| Surface | Release gate |
| --- | --- |
| Node.js | 20 and 22 |
Expand All @@ -30,3 +32,5 @@ Codex and Claude Code integrations are command presets, not embedded SDKs. RealD
Coverage-balanced action selection adds an optional `completeness.selection` object to `scan.json`. Existing `schemaVersion: "1.0"` fields and meanings are unchanged, old reports remain readable, and validators use passthrough/additive compatibility. Consumers may ignore the new telemetry or use it to distinguish discovered, selected, omitted, and route-represented action coverage.

Secret-safe trace retention adds optional `evidence.traceSuppression` on scan findings and optional `artifacts.traceSuppressions` on contract verification. Existing trace paths are unchanged when a ZIP passes inspection; rejected traces are absent by design. Consumers that ignore the new metadata continue to read schema `1.0`, while Windows, macOS and Linux use the same bounded `fflate` ZIP inspection path.

Private visual retention adds optional `evidence.visualSuppressions` on scan findings and optional `artifacts.visualSuppressions` on contract verification. Each entry contains only `artifact` (`screenshot` or `video`) and a bounded `reason` (`sensitive-input` or `authenticated-context`). Existing screenshot/video paths remain unchanged for safe contexts, old reports remain readable, and consumers may ignore the additive fields under schema `1.0`.
2 changes: 2 additions & 0 deletions docs/CONTRACTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -130,6 +130,8 @@ Password-like fields never store their value. The contract contains `secretEnv`,
REALDONE_PASSWORD="..." realdone verify .realdone/flows/login.json
```

When a contract uses `secretEnv` or an auth-state file, RealDone does not start browser video capture for that context. The verification report records only a value-free visual suppression reason; unauthenticated contracts without sensitive inputs still retain video when `--video` is enabled.

## Verify

```bash
Expand Down
2 changes: 1 addition & 1 deletion docs/PERFORMANCE.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ Quick scan remains intentionally light: one Chromium worker, no provider/databas

`--deep` opens one additional browser context per executed mutation to confirm persistence scope. Keep it opt-in for important flows or scheduled audits rather than paying that cost in every quick scan.

`--trace` records Playwright snapshots/screenshots and `--video` records the browser viewport. Both add I/O, storage, and post-processing work; use them for diagnosis or release evidence rather than routine scans. Every newly closed trace receives one bounded ZIP secret inspection before it can be linked; unsafe, invalid, oversized, or over-expanded traces are deleted fail-closed. `--trace-on-failure` then deletes safe passing traces, retaining portable ZIP evidence only for findings or failed contract verification.
`--trace` records Playwright snapshots/screenshots and `--video` records the browser viewport. Both add I/O, storage, and post-processing work; use them for diagnosis or release evidence rather than routine scans. Every newly closed trace receives one bounded ZIP secret inspection before it can be linked; unsafe, invalid, oversized, or over-expanded traces are deleted fail-closed. Screenshot/video recording is not started for known-sensitive or authenticated contexts because binary inspection cannot prove rendered content safe. `--trace-on-failure` then deletes safe passing traces, retaining portable ZIP evidence only for findings or failed contract verification.

`scan --full` raises the default safe budgets to 100 pages, 500 actions, and 30 minutes, enables deep persistence and trace-on-failure, but never enables destructive or external effects. Explicit budget flags or policy values still win, and exhausted budgets set `truncated`.

Expand Down
7 changes: 6 additions & 1 deletion docs/PRODUCT_SPECIFICATION.md
Original file line number Diff line number Diff line change
Expand Up @@ -660,6 +660,8 @@ Baseline

Mỗi Playwright trace chỉ được liên kết vào evidence sau khi ZIP vừa tạo đã qua kiểm tra secret có giới hạn. Phép kiểm tra phải gồm cả sensitive field được điền, `secretEnv`, opaque cookie/token trong Playwright `storageState` đã được cấp, và các pattern credential tổng quát. Nếu phát hiện secret, ZIP không đọc được, hoặc vượt giới hạn kiểm tra, RealDone phải xóa trace theo hướng fail-closed, không công bố đường dẫn đã bị loại, và chỉ ghi metadata lý do không chứa giá trị hay fingerprint của secret. Quy tắc này áp dụng giống nhau cho scan tự động, contract verification, browser matrix, CI và MCP.

PNG screenshot và WebM video là binary artifact nên text secret scanner không thể chứng minh nội dung render bên trong là an toàn. Khi automatic action có field nhạy cảm đã biết, hoặc browser context dùng `storageState`/auth state, RealDone không được tạo standalone screenshot, trace-embedded screenshot hay video cho context đó. Contract context có `secretEnv` hoặc auth state cũng phải chặn trace screenshot và video trước khi recording bắt đầu. Report chỉ được ghi additive suppression metadata gồm loại artifact và lý do hữu hạn, không chứa giá trị, fingerprint, selector hay đường dẫn artifact đã bị chặn. Automatic scan và contract không nhạy cảm phải giữ screenshot/video control để tránh biến privacy gate thành việc vô hiệu hóa toàn bộ visual evidence.

---

# 13. State Snapshot Engine
Expand Down Expand Up @@ -1112,6 +1114,7 @@ Report phải phân biệt:
* regression;
* expected change.
* trace đã bị loại bởi kiểm tra secret, tách biệt với việc không bật trace hoặc xóa passing trace theo `--trace-on-failure`.
* screenshot/video đã bị chặn bởi visual-privacy policy, tách biệt với việc người dùng không bật video hoặc action không cần screenshot.

---

Expand Down Expand Up @@ -1218,6 +1221,8 @@ Cleanup ledger phải ghi mọi resource được tạo.

Trace là artifact nhạy cảm: redaction trong JSON/DOM không đủ để chứng minh ZIP Playwright an toàn. Mọi trace được giữ lại phải qua kiểm tra bounded ngay sau khi đóng trace; trace không kiểm tra được hoặc có secret phải bị xóa trước khi report được ghi.

Screenshot/video cũng là artifact nhạy cảm nhưng không có text-inspection gate đáng tin cậy. RealDone phải fail closed trước capture đối với known-sensitive input, `secretEnv` và authenticated context; không được tạo binary rồi chỉ dựa vào aggregate scanner vốn bỏ qua định dạng binary.

---

# 26. Benchmark System
Expand Down Expand Up @@ -1359,7 +1364,7 @@ Một release chỉ được phát hành khi:
11. Environment health gate pass.
12. Cross-platform smoke pass.
13. Report schema backward-compatible.
14. Không có secret trong artifact; trace bị phát hiện không an toàn hoặc không kiểm tra được phải bị xóa và không được liên kết trong report.
14. Không có secret trong artifact; trace bị phát hiện không an toàn hoặc không kiểm tra được phải bị xóa và không được liên kết trong report; screenshot/video của known-sensitive hoặc authenticated context phải bị chặn trước capture và chỉ để lại value-free suppression metadata.
15. Case study bên ngoài không regression nghiêm trọng.

Không được release chỉ vì:
Expand Down
Loading