docs: legalize functional neutrals (CLN-4) + CSP-hash invariant + TOUR follow-up
CLAUDE.md palette now two enforceable lists (6 brand + 8 documented neutrals — anything else is a violation); workflow gains the recompute- CSP-hash-after-JS-edit invariant with the exact command. README points to the neutrals list. TOUR.md follow-up: CLN-3/CLN-4/SEC-7 closed, INF-2 corrected (false positive — .gitignore exists).
This commit is contained in:
@@ -92,3 +92,12 @@ container is redeployed: merge → VPS `git pull && docker compose up -d
|
||||
|
||||
Commits: 4 (fix/clean/docs + this report). BREAKING: 1 (SEC-1, container
|
||||
port — compose covered). Branch left UNMERGED — `gitflow finish` on GO.
|
||||
|
||||
## Follow-up 2026-07-05 — residuals closed (chore/tour-residuals, user GO)
|
||||
|
||||
| ID | Resolution |
|
||||
|----|-----------|
|
||||
| CLN-3 | Card CSS deduplicated via grouped selectors (shared chrome/hover/head/title/tag blocks + per-class specifics), zero HTML change, cascade-order verified (no interfering same-specificity rules between shared and specific blocks), braces 195/195. Honest correction: the audited "~421 redundant lines" was overstated — real net dedup ≈ 60 lines. |
|
||||
| CLN-4 | Norm aligned with reality: the 8 functional neutrals (inks, rule/tag, 2 green intermediates) are now DOCUMENTED as allowed in CLAUDE.md (+ README pointer). "Any color outside the two lists is a violation" keeps the norm enforceable. |
|
||||
| SEC-7 | script-src hardened: `unsafe-inline` replaced by the sha256 hash of the single inline script (index has zero style/script attributes). style-src keeps `unsafe-inline` (CV carries 2 style attributes + single-file convention) — documented. NEW INVARIANT in CLAUDE.md: recompute the hash after any inline-JS edit (stale hash = JS silently blocked in prod). |
|
||||
| INF-2 | CORRECTION: false positive in the 2026-07-05 report-only run — `.gitignore` exists (549B) and covers the expected classes. No action was ever needed. |
|
||||
|
||||
@@ -66,7 +66,7 @@ The PDF must match the latest HTML before pushing or sending.
|
||||
|
||||
## Design system (non-negotiable)
|
||||
|
||||
Palette — exact hex:
|
||||
Palette — exact hex (brand colors):
|
||||
- `#0d1b12` — dark forest (nav, dark sections, footer)
|
||||
- `#1b5e3b` — green primary (links, section titles on light bg)
|
||||
- `#2d7a4f` — green accent (borders, dots, separators)
|
||||
@@ -74,6 +74,13 @@ Palette — exact hex:
|
||||
- `#dff0e7` — green tint (pill bg)
|
||||
- `#f5f3ec` — parchment (page bg)
|
||||
|
||||
Functional neutrals (allowed, intentional — layering + text, NOT brand):
|
||||
- `#183325` (`--dark-mid`), `#0e3320` (`--g900`), `#eef7f1` (`--g050`) —
|
||||
green-scale intermediates for dark layering and light block bg
|
||||
- `#111111` / `#1e1e1e` / `#636363` (`--ink-1/2/3`) — text hierarchy
|
||||
- `#d8d4c8` (`--rule`), `#e6e2d8` (`--tag`) — separators, generic tags
|
||||
Any color outside these two lists is a violation.
|
||||
|
||||
Typography:
|
||||
- `Fraunces` (serif) — display: hero name, section titles, role headings
|
||||
- `JetBrains Mono` (mono) — eyebrows, badges, tech pills, nav, contact rows
|
||||
@@ -124,6 +131,12 @@ None — global rules apply.
|
||||
- Edits to `index.html` or `CV_Bastien_Chanot.html` must preserve the
|
||||
palette + typography + structure unless explicitly asked to change them.
|
||||
- After editing `CV_Bastien_Chanot.html`, regenerate the PDF.
|
||||
- After editing index.html's inline `<script>`, recompute the CSP hash and
|
||||
update `nginx-security-headers.conf` (script-src is hash-pinned — a stale
|
||||
hash silently disables the JS in prod):
|
||||
```bash
|
||||
python3 -c "import hashlib,base64,re;h=base64.b64encode(hashlib.sha256(re.search(r'<script>(.*?)</script>',open('index.html',encoding='utf-8').read(),re.S).group(1).encode()).digest()).decode();print('sha256-'+h)"
|
||||
```
|
||||
- Never add external dependencies beyond Google Fonts.
|
||||
- Never add tracking, analytics, cookie banners or third-party scripts.
|
||||
- Always test in mobile width (375px) and desktop (1440px) before claiming done.
|
||||
|
||||
@@ -73,6 +73,9 @@ Strict palette (non-negotiable):
|
||||
| `#dff0e7` | Green tint — pill background |
|
||||
| `#f5f3ec` | Parchment — page background |
|
||||
|
||||
Plus a documented set of functional neutrals (text inks, rules/tags, two
|
||||
green-scale intermediates) — the exhaustive list lives in `CLAUDE.md`.
|
||||
|
||||
Typography:
|
||||
- `Fraunces` — display (names, titles)
|
||||
- `JetBrains Mono` — technical labels, badges, pills, nav, contact
|
||||
|
||||
Reference in New Issue
Block a user