From ef7e2312c69674a9bded06474359d5eedceadb41 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Sun, 5 Jul 2026 19:59:45 +0200 Subject: [PATCH] docs: legalize functional neutrals (CLN-4) + CSP-hash invariant + TOUR follow-up MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CLAUDE.md palette now two enforceable lists (6 brand + 8 documented neutrals — anything else is a violation); workflow gains the recompute- CSP-hash-after-JS-edit invariant with the exact command. README points to the neutrals list. TOUR.md follow-up: CLN-3/CLN-4/SEC-7 closed, INF-2 corrected (false positive — .gitignore exists). --- .claude/audits/TOUR.md | 9 +++++++++ CLAUDE.md | 15 ++++++++++++++- README.md | 3 +++ 3 files changed, 26 insertions(+), 1 deletion(-) diff --git a/.claude/audits/TOUR.md b/.claude/audits/TOUR.md index f039810..0381333 100644 --- a/.claude/audits/TOUR.md +++ b/.claude/audits/TOUR.md @@ -92,3 +92,12 @@ container is redeployed: merge → VPS `git pull && docker compose up -d Commits: 4 (fix/clean/docs + this report). BREAKING: 1 (SEC-1, container port — compose covered). Branch left UNMERGED — `gitflow finish` on GO. + +## Follow-up 2026-07-05 — residuals closed (chore/tour-residuals, user GO) + +| ID | Resolution | +|----|-----------| +| CLN-3 | Card CSS deduplicated via grouped selectors (shared chrome/hover/head/title/tag blocks + per-class specifics), zero HTML change, cascade-order verified (no interfering same-specificity rules between shared and specific blocks), braces 195/195. Honest correction: the audited "~421 redundant lines" was overstated — real net dedup ≈ 60 lines. | +| CLN-4 | Norm aligned with reality: the 8 functional neutrals (inks, rule/tag, 2 green intermediates) are now DOCUMENTED as allowed in CLAUDE.md (+ README pointer). "Any color outside the two lists is a violation" keeps the norm enforceable. | +| SEC-7 | script-src hardened: `unsafe-inline` replaced by the sha256 hash of the single inline script (index has zero style/script attributes). style-src keeps `unsafe-inline` (CV carries 2 style attributes + single-file convention) — documented. NEW INVARIANT in CLAUDE.md: recompute the hash after any inline-JS edit (stale hash = JS silently blocked in prod). | +| INF-2 | CORRECTION: false positive in the 2026-07-05 report-only run — `.gitignore` exists (549B) and covers the expected classes. No action was ever needed. | diff --git a/CLAUDE.md b/CLAUDE.md index cae6427..75d6790 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -66,7 +66,7 @@ The PDF must match the latest HTML before pushing or sending. ## Design system (non-negotiable) -Palette — exact hex: +Palette — exact hex (brand colors): - `#0d1b12` — dark forest (nav, dark sections, footer) - `#1b5e3b` — green primary (links, section titles on light bg) - `#2d7a4f` — green accent (borders, dots, separators) @@ -74,6 +74,13 @@ Palette — exact hex: - `#dff0e7` — green tint (pill bg) - `#f5f3ec` — parchment (page bg) +Functional neutrals (allowed, intentional — layering + text, NOT brand): +- `#183325` (`--dark-mid`), `#0e3320` (`--g900`), `#eef7f1` (`--g050`) — + green-scale intermediates for dark layering and light block bg +- `#111111` / `#1e1e1e` / `#636363` (`--ink-1/2/3`) — text hierarchy +- `#d8d4c8` (`--rule`), `#e6e2d8` (`--tag`) — separators, generic tags +Any color outside these two lists is a violation. + Typography: - `Fraunces` (serif) — display: hero name, section titles, role headings - `JetBrains Mono` (mono) — eyebrows, badges, tech pills, nav, contact rows @@ -124,6 +131,12 @@ None — global rules apply. - Edits to `index.html` or `CV_Bastien_Chanot.html` must preserve the palette + typography + structure unless explicitly asked to change them. - After editing `CV_Bastien_Chanot.html`, regenerate the PDF. +- After editing index.html's inline `',open('index.html',encoding='utf-8').read(),re.S).group(1).encode()).digest()).decode();print('sha256-'+h)" + ``` - Never add external dependencies beyond Google Fonts. - Never add tracking, analytics, cookie banners or third-party scripts. - Always test in mobile width (375px) and desktop (1440px) before claiming done. diff --git a/README.md b/README.md index a23462c..4d79c21 100644 --- a/README.md +++ b/README.md @@ -73,6 +73,9 @@ Strict palette (non-negotiable): | `#dff0e7` | Green tint — pill background | | `#f5f3ec` | Parchment — page background | +Plus a documented set of functional neutrals (text inks, rules/tags, two +green-scale intermediates) — the exhaustive list lives in `CLAUDE.md`. + Typography: - `Fraunces` — display (names, titles) - `JetBrains Mono` — technical labels, badges, pills, nav, contact