Skip to content

v3.2.0: Authenticated scan inputs

Latest

Choose a tag to compare

@snapsynapse snapsynapse released this 04 Oct 03:30
· 2 commits to main since this release
Immutable release. Only release title and notes can be modified.
v3.2.0
0ae5735

v3.2.0: Authenticated scan inputs

This release adds bounded authenticated scans to the existing Puppeteer engine.
Supply Playwright-format cookies and local storage together with per-target
expected URLs and visible readiness selectors. The scanner, JSON adapter and
reusable Action accept the same paired inputs. Each target receives a fresh
context, and authentication failures remain operational failures even when
accessibility gating is disabled.

Supplied state values are redacted from page-derived axe evidence while rule
IDs, severities and tags retain their meaning. Authentication files are
protected against output aliases, and the Action guards upload paths.

The validation lockfile updates fast-uri to fix GHSA-hrr3-gc8f-f4qj.
The scanner verifies its local executable dependencies before loading them.
Guide 0.3.17 replaces third-party installer dispatch with release-specific
source acquisition. Acquiring source does not register an agent-client skill;
the Skills CLI remains documented separately.

Compatibility and limits

  • Node.js 22.12.0 or later; managed Puppeteer 25.10.0 and axe-core 4.12.1 are unchanged.
  • Existing unauthenticated behavior, baseline semantics and experimental CLI contract are preserved.
  • Authentication supports cookies and local storage only. Queries/fragments, IndexedDB, partitioned cookies, authenticated discovery and bounded journeys are outside this slice.
  • Intercepted cross-origin page requests are blocked. This is not a sandbox for hostile applications, workers or popups.
  • Reports can contain private page content. Use synthetic accounts and handle artifacts accordingly.
  • Guide actions remain public-only. Authenticated scans require separate explicit authorization.

Validation

See ops/v3.2.0-release-preparation.md for candidate tests, exact verifier
identities, artifact readback and outstanding publication gates. Local
conformance is not hosted verification or accessibility certification.