Skip to content

Harden consent integration and release pipeline - #1

Draft
amWeb-DevTeam wants to merge 8 commits into
mainfrom
codex/security-hardening-rc2
Draft

amWeb-DevTeam wants to merge 8 commits into
mainfrom
codex/security-hardening-rc2

Conversation

@amWeb-DevTeam

Copy link
Copy Markdown
Owner

What changed

  • context-safe reCAPTCHA and JavaScript value encoding
  • nonce-based strict CSP support and removal of inline event handlers
  • fixed MODX-derived runtime paths instead of editable component path settings
  • MODX 3.x, PHP 7.4+, and JSON installation validation
  • browser gates proving no third-party request before consent or after rejection
  • pinned GitHub Actions and Playwright dependencies
  • deterministic MODX transport normalization, checksums, provenance, and clean package lifecycle testing
  • persistent GSD context for future development

Why

The public release candidate needs secure defaults and verifiable controls around consent enforcement, CSP integration, supported runtimes, and release provenance.

Validation

  • npm audit: 0 vulnerabilities
  • Playwright: 3/3 passed
  • PHP syntax: passed in MODX DDEV runtime
  • MODX transport build: passed twice
  • normalized builds: byte-identical
  • artifact SHA-256: fea322a43937f6945efd908a881463fac199a2aca2eede188ca849c2d1f321a9

The GitHub release workflow additionally installs and uninstalls the normalized package on a clean MODX 3.2.3 environment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants