Benjamin Admin
|
37093ff9e3
|
feat: Browser-Matrix C2 + B11 AI-Retention + Impressum-Specialist-Agent + B1 Mobile Playwright
Task #15 Stage 1.c-e — Browser-Matrix Backend-Integration:
- _phase_c2_browser_matrix.py: ruft consent-tester /scan-matrix wenn
env BROWSER_MATRIX=true, fuellt state["browser_matrix"] +
state["browser_aggregate"] + state["browser_matrix_html"]
- V2-Mail-Block: 🌐 Browser-Matrix Tabelle (Profile · Score ·
Sub-Scores PC/RR/BD · Bewertung) mit Worst-of-Header
- Orchestrator ruft run_phase_c2 nach run_phase_c
KNOWN: Stage 1.b (consent_scanner browser_profile-Param) bleibt
zurueckgestellt (Datei in loc-exception, Hook-Patch verweigert).
Stage 1.a-Shim laeuft im consent-tester — alle Profile aktuell
auf Chromium, echte Engine-Diversitaet kommt mit 1.b.
Task #17 TH-RETENTION-002 als B11 ai_retention_granularity_check:
- Erkennt AI-Provider-Kontext (vertex/openai/anthropic/etc)
- In +-800-char-Window: prueft ≥2 Datenkategorien aus Standard-Liste
(Texteingaben/IP/Geraet/Session/Fehlerprotokoll/Zeitstempel)
- Wenn 1 pauschale Speicherdauer + ≥2 Kategorien aber kein
per-Kategorie-Differential → LOW
- Smoke: Elli-Mock-DSE trifft LOW "AI-Speicherdauer pauschal"
Task #18 Specialist-Agents Phase-1-Prototyp:
- compliance/services/specialist_agents/__init__.py mit Architektur-Doku
- impressum_agent.py: 9 Pflichtangaben § 5 TMG + § 1 DL-InfoV
als Pattern-Registry (Name, Email, Telefon, HR, USt-IdNr,
Vertretungsberechtigt, Aufsichtsbehoerde, Berufsangaben, OS-Link)
- business_scope-aware (OS-Link nur fuer ecommerce, Aufsichtsbehoerde
nur fuer regulated_profession/financial/insurance)
- Phase-1 ist Pattern-Match-only (kein LLM), demonstriert die
Schnittstelle. Phase 2 ersetzt Pattern durch System-Prompt + KB.
- Smoke: minimal-Impressum triggert 4 Findings korrekt
Task #7 B1 Playwright Mobile-Verifikation:
- consent-tester/services/mobile_reachability_scanner.py: echte
WebKit-launch + p.devices['iPhone 15'] preset + de-DE locale +
Europe/Berlin timezone
- Footer-Anchor-Suche via locator("footer >> text=/.../i") fuer
13 Reopen-Phrasen
- Tap-Target-Boundingbox-Messung (Apple HIG / WCAG ≥44x44)
- Click-Behavior: DOM-Modal-Snapshot vor/nach, erkennt CMP-Open
- Output: has_anchor, anchor_text, tap_target_px, click_opens_cmp,
engine_meta, screenshot_b64 (Footer-Crop wenn kein Anchor)
- consent-tester/routes_mobile.py POST /scan-mobile-reachability
- Backend _b1_wiring erweitert: ruft Mobile-Endpoint zuerst,
Fallback auf statischen HTTP-Fetch. Mobile-Daten enrichen
finding.mobile_playwright + Severity-Bump bei
tap-target<44 / click-doesnt-open-CMP.
KNOWN: WebKit-System-Libs sind im Dockerfile ergaenzt (Stage 1.a-
Commit), greifen aber erst nach CI/CD-Rebuild des consent-tester.
Bis dahin faellt B1 sauber auf statischen Fetch zurueck.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
2026-06-06 22:20:25 +02:00 |
|
Benjamin Admin
|
c2c8783fee
|
refactor(agent-check): split routes file (2692→347 LOC) + wire B1/B3/A1 [guardrail-change]
Phase-5 split of agent_compliance_check_routes.py — the 2700-line
monolith was decomposed into 19 modules in compliance/api/agent_check/:
- Phase A-F: resolve / profile+check / banner+TCF / vendors raw+finalize /
HTML blocks top+mid+bot / email / persist
- Helpers: _constants, _helpers, _fetch, _discovery, _single_check
- Schemas + State + thin _orchestrator
A1 ZIP-Anhang nativ in _phase_e_email: evidence_zip_builder.py bundles
slices + manifest.json + audit_metadata.json (SHA256 per slice +
build_sha + source_url). smtp_sender.py erweitert um attachments-Parameter.
B1 COOKIE-CONSENT-UX-001 (Mobile Reachability): consent_reachability_check.py
parses footer anchors, classifies intent (reopen_cmp / info_only /
browser_deflect) + target (same_page_cmp / new_tab / external).
_b1_wiring.py fetches homepage with iPhone-UA + renders Art-7-Abs-3
severity-coloured block.
B3 TH-RETENTION (Cross-Doc Speicherdauer): retention_comparator.py
compares DSI claim ↔ cookie-table duration ↔ actual Max-Age/expires
with 5% tolerance + severity hierarchy (dsi_under_actual HIGH,
table_under_actual HIGH, dsi_vs_table MEDIUM, actual_under_table LOW
Safari-ITP-Hint). _b3_wiring.py + Top-10 mismatches table in mail.
Side-effects:
- Fixed silent UnboundLocalError in original Step 5 (gf_one_pager used
audit_quality_findings before declaration, caught by surrounding
except → block never rendered). New _phase_d3_blocks_bot.py runs
audit-quality FIRST.
- agent_compliance_check_routes.py removed from loc-exceptions.txt
("Phase 5 split target" — done).
Tests: 55/55 grün (B1 22 + B3 27 + saving_scan 6).
E2E: smoke against Elli DSE+Cookie produced HIGH/missing B1 finding,
TH-RETENTION table (17 cookies / 3 ✓ / 3 ✗ / 11 ?), evidence-zip
with 2 slices + manifest + audit_metadata (12089B, SHA256-chained,
source verified), email sent (attachments=1).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
2026-06-06 14:47:25 +02:00 |
|