From 30b0e44a450af10fa1e3b78723d0bc023be87d53 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Sun, 5 Jul 2026 20:47:51 +0200 Subject: [PATCH 1/6] chore(clean): remove dead CSS + normalize whitespace (tour CLN) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit index.html: drop unused .reveal.d6 rule (markup uses d1-d5 only). CV_Bastien_Chanot.html: - remove dead `position: running(siteFooter)` — no `element()` consumer, and .footer-bar is `display:none` in @media print (the @page auto-numbered footer replaces it); on screen running() is an invalid position value, ignored. - remove no-op `box-shadow: none` on .page (weasyprint ignores box-shadow; .page sets a shadow nowhere). - remove dead `.skills-grid { font-size: 8.4pt }` (every direct child is a .skill-label/.skill-values div that sets its own size; no bare text). - normalize stray blank lines. Behavior-preserving: PDF regenerated from the edited HTML is byte-identical to the pre-edit baseline (text sha256 + per-page PNG render hash match), so CV_Bastien_Chanot.pdf is unchanged and the PDF=HTML invariant holds. --- CV_Bastien_Chanot.html | 8 +------- index.html | 1 - 2 files changed, 1 insertion(+), 8 deletions(-) diff --git a/CV_Bastien_Chanot.html b/CV_Bastien_Chanot.html index a7dbe22..4c46f65 100644 --- a/CV_Bastien_Chanot.html +++ b/CV_Bastien_Chanot.html @@ -44,14 +44,11 @@ padding: 0; } - - .page { width: 210mm; max-width: 100%; margin: 0 auto; background: var(--page); - overflow: hidden; } @@ -312,8 +309,6 @@ display: grid; grid-template-columns: 115px 1fr; gap: 1px 10px; - font-size: 8.4pt; - } .skill-label { @@ -405,7 +400,6 @@ /* ── FOOTER ── */ .footer-bar { - position: running(siteFooter); background: var(--dark); padding: 5px 20mm; display: flex; @@ -435,7 +429,7 @@ linear-gradient(160deg, #f5f3ec 0%, #edeadf 55%, #f2efe6 100%); padding: 0; } - .page { box-shadow: none; background: transparent; } + .page { background: transparent; } .cv-header { padding: 18px 14mm 14px; } .cv-body { padding: 10px 14mm 12px; background: transparent; } diff --git a/index.html b/index.html index 6e277bb..bdacd6d 100644 --- a/index.html +++ b/index.html @@ -344,7 +344,6 @@ .reveal.d3 { animation-delay: .30s; } .reveal.d4 { animation-delay: .42s; } .reveal.d5 { animation-delay: .55s; } - .reveal.d6 { animation-delay: .68s; } @keyframes rise { to { opacity: 1; transform: translateY(0); } } From 7b3d9bec4c18ca82f16d97966794d2abf932aa7f Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Sun, 5 Jul 2026 21:05:43 +0200 Subject: [PATCH 2/6] =?UTF-8?q?docs(tour):=20report=20chore/tour-2026-07-0?= =?UTF-8?q?5-2=20=E2=80=94=20CONVERGED=20(2=20it.,=201=20clean=20fix=20com?= =?UTF-8?q?mit,=205=20suggestions)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .claude/audits/TOUR.md | 51 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 51 insertions(+) diff --git a/.claude/audits/TOUR.md b/.claude/audits/TOUR.md index 0381333..0755f1b 100644 --- a/.claude/audits/TOUR.md +++ b/.claude/audits/TOUR.md @@ -101,3 +101,54 @@ port — compose covered). Branch left UNMERGED — `gitflow finish` on GO. | CLN-4 | Norm aligned with reality: the 8 functional neutrals (inks, rule/tag, 2 green intermediates) are now DOCUMENTED as allowed in CLAUDE.md (+ README pointer). "Any color outside the two lists is a violation" keeps the norm enforceable. | | SEC-7 | script-src hardened: `unsafe-inline` replaced by the sha256 hash of the single inline script (index has zero style/script attributes). style-src keeps `unsafe-inline` (CV carries 2 style attributes + single-file convention) — documented. NEW INVARIANT in CLAUDE.md: recompute the hash after any inline-JS edit (stale hash = JS silently blocked in prod). | | INF-2 | CORRECTION: false positive in the 2026-07-05 report-only run — `.gitignore` exists (549B) and covers the expected classes. No action was ever needed. | + +## Tour 2026-07-05-2 — AUTO — branch chore/tour-2026-07-05-2 — 2 iterations — CONVERGED + +Re-run of /tour on develop (d7256ff) after the day's earlier tours merged. Goal: +verify no regression + catch anything new. Branch suffixed `-2` to keep this +header distinct from the earlier converged run. gstack OFF → optional It1 cso +posture add-on not run; the security floor (security-auditor + pinned semgrep) +ran BOTH iterations, not degraded. No package.json/Makefile → no automated +tests/lint/build; project checks = domain invariants (CSP-hash, PDF↔HTML). + +| ID | Axis | File | Sev | Finding | Status | +|----|------|------|-----|---------|--------| +| SEC-1 | security | (full tree) | - | Fresh semgrep both iterations → VERDICT PASS, 0 blocking. Sole note: `style-src 'unsafe-inline'` (accepted single-file convention, It1==It2). No regression from the prior SEC fixes; script-src hash still matches inline script | pass | +| CLN-1 | clean | index.html:347 | - | dead `.reveal.d6` rule (markup uses reveal d1–d5 only) | fixed 30b0e44 | +| CLN-2 | clean | CV:408 | - | dead `position: running(siteFooter)` — no `element(siteFooter)` consumer; `.footer-bar` is `display:none` in @media print (@page auto-numbered footer replaces it); on screen running() is an invalid position value, ignored | fixed 30b0e44 | +| CLN-3 | clean | CV:438 | - | no-op `box-shadow: none` on `.page` (`.page` sets a shadow nowhere; weasyprint ignores box-shadow entirely — confirmed by its own warning) | fixed 30b0e44 | +| CLN-4 | clean | CV:315 | - | dead `.skills-grid { font-size: 8.4pt }` — every direct child is a `.skill-label`(9.5pt)/`.skill-values`(10pt) div; no bare text node, no em-dependency → never renders | fixed 30b0e44 | +| CLN-5 | clean | CV:46-48,54,316 | - | stray blank lines (triple blank before `.page`, blanks inside `.page`/`.skills-grid`) | fixed 30b0e44 | +| CLN-6 | a11y | index.html:1003,1007 | - | 2 decorative `.arrow` SVGs miss the `aria-hidden="true"` the sibling download arrow (1011) has. NOT auto-fixed: adding it changes the a11y tree → outside the clean phase's behavior-preserving scope (belongs to an a11y pass; cf. TODO "WCAG AA contrast") | open (suggested) | +| CLN-7 | norm | index.html:931 | - | `.footer` bg `#061008` is off-palette (darker than `--dark #0d1b12`, `--g900 #0e3320`). Design system documents footer = `#0d1b12`. Fix changes rendering (slightly lighter footer) → owner decision, not auto-fixed | open (suggested) | +| CLN-8 | norm | CV:252,135-136,434-435 | - | off-palette colors: `#a8d4bc` tag border (252), gradient stops `#edeadf`/`#f2efe6` (136/435), texture fill `rgba(26,71,48,0.05)` (135/434). All rendering-changing → owner decision, not auto-fixed | open (suggested) | +| CLN-9 | content | index.html vs CV:507-508 | - | profile-state wording drift: landing "Pays de la Loire / remote or 1–2j Paris" vs CV "région nantaise / hybride Nantes / 1–2j Paris" (not contradictory — Nantes ∈ PdL — but CV adds "hybride Nantes"). CLAUDE.md requires cross-file consistency → owner picks canonical wording, not auto-fixed | open (suggested) | +| REC-1 | reconcile | .claude/memory/decisions.md | - | **BDR-004 stale**: text says `nginx:1.27-alpine` / container port 80 / "HSTS omitted at container", but the real Dockerfile+compose (post 2026-07-05 SEC-1 fix) = `nginxinc/nginx-unprivileged:1.28-alpine` / port 8080 / uid 101. That tour never added a superseding decision (index stops at BDR-005). Append-only registry + tour-read-only → SUGGEST a superseding **BDR-006**. README deploy section is already correct | suggested | +| REC-2 | reconcile | .claude/memory/decisions.md | - | BDR-002 "Warnings connus: `box-shadow:none` ignoré par weasyprint" — that declaration was removed this tour (CLN-3), so the documented warning no longer fires. Minor note to add when BDR-002 is next touched | suggested | +| REC-3 | reconcile | TODO.md + registries | - | ZERO false-done. Oracles: 1369d27 exists ✓; `og:image` absent = TODO item genuinely open ✓; CV favicon-block not mirrored = open, matches BDR-005 note ✓; WCAG-contrast + real-mobile-QA open ✓; develop==origin/develop (d7256ff), branch +1 unmerged ✓; BLK-001 resolved, favicon assets present ✓ | consistent | +| DOC-1 | doc | README.md | - | doc-syncer automatic mode → `PATCHED_FILES: (none)`. Deploy section already reflects unprivileged image/port 8080 (prior tour sync); file table matches root inventory; cleanup touched nothing user-facing | no-op | +| INV-1 | invariant | index.html / CV pdf | - | CSP hash `sha256-Al1M34KxI6Ye5Viu6aO//7CYyaLzqtpG9GX95FFlSOY=` recomputed == pinned (inline `