Status
Current implementation and local validation report for IARPG-OPS-2 2.0.9-wip. The release remains work in progress.
Purpose
Record proxy-aware transport hardening, controlled local HTTPS reverse-proxy validation, structural accessibility auditing, delivery-budget measurements, defects corrected, and the remaining stable-promotion evidence boundary.
Scope
This report covers the supplied 2.0.8-wip flat deployment and the resulting 2.0.9-wip candidate. It evaluates an ephemeral local TLS terminator and protected origin, an independent direct HTTP origin, forwarded-header trust boundaries, secure-cookie and HSTS behavior, canonical response headers, synthetic crawler-agent reachability, semantic HTML structure, and local delivery budgets. It does not claim an externally reachable host, a publicly trusted production certificate, unrestricted navigated Chromium, native Firefox, native screen-reader speech output, field Core Web Vitals, search-engine account evidence, indexing, ranking, answer inclusion, or generative citation.
Executive Summary
IARPG-OPS-2 2.0.9-wip now treats reverse-proxy scheme information as untrusted unless an operator explicitly enables IARPGTRUSTPROXYHEADERS=1 on a protected origin. A direct-origin request carrying forged Forwarded, X-Forwarded-Proto, and X-Forwarded-SSL fields did not receive HSTS or a Secure session-cookie attribute. The controlled TLS proxy overwrote those same client fields, negotiated certificate-verified TLS 1.3 with TLSAES256GCM_SHA384, emitted one-year HSTS, and produced a Secure, HttpOnly, SameSite=Lax session cookie on the session-backed play route.
The combined edge suite passed 59 of 59 checks: 21 of 21 direct-origin request groups, 22 of 22 HTTPS proxy groups, five explicit edge-boundary checks, 88 of 88 sampled HTML routes with zero structural-accessibility findings, and 10 of 10 local delivery-budget checks. The complete HTTPS sitemap crawl returned 335 of 335 routes with matching canonical metadata and HTTP Link headers. The temporary hosting diagnostic passed 12 of 12 checks, exposed no secrets, and returned a noindex/no-store 404 after it was disabled. Managed Chromium fixtures separately passed 11 of 11 groups while preserving their non-native-navigation truth boundary.
The candidate remains WIP because the local topology does not establish the actual public edge, native browser and assistive-technology behavior, field performance, or live search and crawler outcomes.
Evidence Reviewed
- The complete 2.0.8-wip baseline,
AGENTS.md, active.uaistartup memory, durable memory, manifests, promotion gates, and validation scripts. - Current PHP, JavaScript, CSS, JSON, XML, Markdown, UAI, Apache policy, and public discovery artifacts.
EDGE-PROXY-EVIDENCE-IARPG-OPS-2-2.0.9-wip.jsonand its human-readable companion.STAGING-HOST-EVIDENCE-IARPG-OPS-2-2.0.9-wip.jsonand its human-readable companion.ACCESSIBILITY-STRUCTURE-EVIDENCE-IARPG-OPS-2-2.0.9-wip.jsonand its human-readable companion.DELIVERY-PERFORMANCE-EVIDENCE-IARPG-OPS-2-2.0.9-wip.jsonand its human-readable companion.BROWSER-FIXTURE-VALIDATION-IARPG-OPS-2-2.0.9-wip.jsonand its human-readable companion.
Findings
Proxy-aware transport security
- Forwarded scheme headers are ignored by default. A direct HTTP request carrying forged secure-scheme headers remained an HTTP request, emitted no HSTS, and did not add the Secure attribute to its session cookie.
- Proxy trust is opt-in through
IARPGTRUSTPROXY_HEADERS=1. The controlled proxy replaces rather than appendsForwarded,X-Forwarded-Proto, andX-Forwarded-SSLbefore requests reach the trusted origin. - The local TLS proxy negotiated TLS 1.3 with
TLSAES256GCMSHA384and verified the ephemeral test certificate against the test CA supplied to the validator. - Secure requests emit
Strict-Transport-Security: max-age=31536000. Direct HTTP requests do not emit HSTS. - Session-backed routes use the neutral
iarpg_sessioncookie with HttpOnly, SameSite=Lax, root path, and a transport-appropriate Secure attribute. Ordinary publication pages remain session-free and briefly cacheable. - Shared responses include a canonical HTTP Link header,
Origin-Agent-Cluster: ?1, andX-DNS-Prefetch-Control: offin addition to the existing nonce-bearing content-security policy and isolation headers. - The complete HTTPS sitemap crawl passed 335 of 335 routes and 335 of 335 HTML metadata records.
Operator diagnostic and crawler boundary
hosting-check.phpremains disabled by default and outside navigation and discovery.- During the temporary operator window, the HTTPS diagnostic returned JSON and passed 12 of 12 checks with
safeoutput=true,secretsexposed=false, and no untested result. - After the diagnostic was disabled again, the route returned HTTP 404 with noindex and no-store response policy.
- Synthetic requests using Googlebot, bingbot, OAI-SearchBot, ChatGPT-User, and GPTBot user agents reached 15 of 15 intended public routes, were denied on 10 of 10 protected routes, and appeared in the sanitized aggregate log. This proves request-boundary behavior only; it is not evidence that any named crawler visited the site.
Structural accessibility
- The deterministic structural audit covered every non-templated sitemap route plus six representative standard pages and four representative report pages: 88 of 88 HTML routes.
- The audit inspected 12,502 interactive controls, 389 images, 22 tables, and 1,114 ARIA references with zero findings.
- Rules covered document language, one main landmark, skip navigation, one page-level H1, unique IDs, valid ARIA references, prohibition of positive tabindex, accessible names, image alternatives, named dialogs, table captions and headers, focusable descendants of
aria-hidden, header/main/footer landmarks, and named navigation landmarks. - Missing names on merge and migration textareas were corrected. Report-generated and tool tables now have captions, and standard and mission sidebar navigation landmarks are explicitly named.
- This audit does not establish spoken name, role, state, order, or status output in a native screen reader and does not constitute WCAG certification.
Delivery performance
- All six of six representative HTML routes returned HTTP 200 through the local TLS edge, used gzip, and stayed under the 100 KiB compressed HTML budget. The largest compressed HTML response was 33,455 bytes.
- Initial CSS and JavaScript were gzip-compressed. The measured transfers were 49,034 bytes of CSS and 28,379 bytes of JavaScript.
- The largest initial image was the WebP partner banner at 116,182 bytes, below the 500 KiB budget; PNG remains a fallback rather than the measured preferred source.
- The home route contained no third-party runtime dependency and no blocking script reference.
- The six-route local median was 14.27 ms and the maximum was 47.10 ms in the ephemeral loopback environment. These figures are useful regression measurements, not field latency or Core Web Vitals.
Browser and native assistive-technology boundary
- Managed Chromium fixtures passed 11 of 11 groups for round-trip preservation, theme behavior, responsive containment, 200% and 400% zoom, reduced motion, reduced transparency, forced colors, print, and offline navigation.
- The fixture harness uses server-rendered HTML and local assets because managed policy blocks unrestricted local URL navigation. It is not the unrestricted navigated Chromium gate.
- Native Firefox and native screen-reader speech output remain not tested.
Search and crawler truth boundary
- Canonical HTML remains the primary answer and citation surface. The sitemap, feed, answer catalog, OpenSearch description, robots policy,
llms.txt, JSON companions, and public UAI mirrors are routing aids. - Synthetic user-agent tests, schema markup, canonical headers, and machine-readable answers do not prove indexing, ranking, answer inclusion, crawler acceptance, or external generative citation.
- Google Search Console, Bing Webmaster, IndexNow, production crawler logs, and field performance require host-owned accounts or production traffic and remain outside this local round.
Decisions or Recommendations
- Keep proxy scheme headers ignored by default.
- Enable proxy-header trust only on a protected origin behind a reverse proxy that overwrites all recognized scheme headers and is not directly reachable from the public network.
- Keep the operator diagnostic environment-gated, temporary, sanitized, noindex, and no-store.
- Keep
.menu-stripas the only sticky surface. - Retain WIP status until all native and external promotion gates have current direct evidence.
Risks and Limitations
- The certificate and reverse proxy are ephemeral local test infrastructure. They do not prove the actual hosting account, public certificate chain, CDN, WAF, load balancer, origin firewall, DNS, or public network path.
- Native Firefox, unrestricted navigated Chromium, and native assistive-technology speech output remain unavailable.
- Structural markup checks do not substitute for task-based keyboard, cognitive, visual-contrast, magnification, vestibular-comfort, or speech-output testing by representative users.
- Local loopback transfer sizes and timing do not establish field Core Web Vitals, geographic latency, device rendering cost, or real-user monitoring.
- Synthetic crawler agents do not represent live crawler visits or search-engine acceptance.
Validation Performed
The following current-candidate checks were run:
php -lover every PHP entry point.node --checkover every JavaScript file.- Python syntax compilation for local validation scripts.
scripts/validatebrowserfixtures.pyagainst a real Apache request path: 11 pass, 0 fail.scripts/validateproductionedge.pyagainst an independent direct origin plus certificate-verified local TLS reverse proxy: 59 pass, 0 fail in aggregate.- Embedded staging validation: 21 of 21 direct HTTP groups and 22 of 22 HTTPS proxy groups.
- Temporary hosting diagnostic: 12 pass, 0 fail, 0 not tested, then disabled and rechecked as a noindex/no-store 404.
- Structural accessibility audit: 88 routes, 0 findings.
- Delivery budget audit: 10 pass, 0 fail.
- Complete HTTPS sitemap request and metadata crawl: 335 of 335.
- Synthetic crawler boundary: 15 of 15 public requests, 10 of 10 protected denials, and 5 of 5 user-agent families present in the sanitized log.
Final memory, discovery, checksum, archive, and extracted-candidate revalidation results are recorded in the release validation artifact rather than duplicated here.
Memory References
Related Durable Documents
- [Staging Host and Runtime Validation Report](staging-host-and-runtime-validation-report.md#executive-summary)
- [UI/UX, SEO, AEO, and GEO Improvement Report](ui-ux-seo-aeo-geo-improvement-report.md#executive-summary)
- Split-Memory Architecture
Supersession Status
Current for the IARPG-OPS-2 2.0.9-wip production-edge, accessibility, and delivery hardening round. It augments rather than supersedes the 2.0.8-wip staging and runtime report.