docs: legalize functional neutrals (CLN-4) + CSP-hash invariant + TOUR follow-up

CLAUDE.md palette now two enforceable lists (6 brand + 8 documented
neutrals — anything else is a violation); workflow gains the recompute-
CSP-hash-after-JS-edit invariant with the exact command. README points to
the neutrals list. TOUR.md follow-up: CLN-3/CLN-4/SEC-7 closed, INF-2
corrected (false positive — .gitignore exists).
This commit is contained in:
Bastien Chanot
2026-07-05 19:59:45 +02:00
parent c0632aefa8
commit ef7e2312c6
3 changed files with 26 additions and 1 deletions
+14 -1
View File
@@ -66,7 +66,7 @@ The PDF must match the latest HTML before pushing or sending.
## Design system (non-negotiable)
Palette — exact hex:
Palette — exact hex (brand colors):
- `#0d1b12` — dark forest (nav, dark sections, footer)
- `#1b5e3b` — green primary (links, section titles on light bg)
- `#2d7a4f` — green accent (borders, dots, separators)
@@ -74,6 +74,13 @@ Palette — exact hex:
- `#dff0e7` — green tint (pill bg)
- `#f5f3ec` — parchment (page bg)
Functional neutrals (allowed, intentional — layering + text, NOT brand):
- `#183325` (`--dark-mid`), `#0e3320` (`--g900`), `#eef7f1` (`--g050`) —
green-scale intermediates for dark layering and light block bg
- `#111111` / `#1e1e1e` / `#636363` (`--ink-1/2/3`) — text hierarchy
- `#d8d4c8` (`--rule`), `#e6e2d8` (`--tag`) — separators, generic tags
Any color outside these two lists is a violation.
Typography:
- `Fraunces` (serif) — display: hero name, section titles, role headings
- `JetBrains Mono` (mono) — eyebrows, badges, tech pills, nav, contact rows
@@ -124,6 +131,12 @@ None — global rules apply.
- Edits to `index.html` or `CV_Bastien_Chanot.html` must preserve the
palette + typography + structure unless explicitly asked to change them.
- After editing `CV_Bastien_Chanot.html`, regenerate the PDF.
- After editing index.html's inline `<script>`, recompute the CSP hash and
update `nginx-security-headers.conf` (script-src is hash-pinned — a stale
hash silently disables the JS in prod):
```bash
python3 -c "import hashlib,base64,re;h=base64.b64encode(hashlib.sha256(re.search(r'<script>(.*?)</script>',open('index.html',encoding='utf-8').read(),re.S).group(1).encode()).digest()).decode();print('sha256-'+h)"
```
- Never add external dependencies beyond Google Fonts.
- Never add tracking, analytics, cookie banners or third-party scripts.
- Always test in mobile width (375px) and desktop (1440px) before claiming done.