browserrot: Phase A-tier-1 site-side rotation engine (go-rod)
Deterministic, headless browser-driven password rotation: discover change page via RFC 8615 / links, inject old+new over CDP (no model in the loop), submit, and re-login to verify the new password before commit. Implements rotate.Rotator so the mandatory backup gate, verify-before-revoke ordering, and proof gate apply unchanged; RevokeOld is a no-op (the site invalidates the old pw). Proof-as-data per Site: the engine is LIVE-VM (real headless Chromium vs a real local change-password form, via lab-provision-browserrot.sh / TestIntegration_realBrowserRotation); real-site selector tables stay UNPROVEN and nothing auto-registers into production rotate yet. 14 packages, -race clean. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -56,6 +56,7 @@ multipass exec incredigo-sbx -- bash -lc '
|
||||
| `lab-provision-keepass.sh` | KeePassXC (`keepassxc-cli`) |
|
||||
| `lab-provision-bitwarden.sh` + `vw-register.py` | Vaultwarden + `bw` CLI |
|
||||
| `lab-provision-browsercsv.sh` + `csv-commit-probe.py` | Chrome/Firefox CSV (staging only) |
|
||||
| `lab-provision-browserrot.sh` | Phase A-tier-1 site-side rotation engine (`internal/browserrot`) — real headless Chromium against a throwaway local change-password form (fake cred) |
|
||||
| `tui-probe.py` | drives the `guide` Bubble Tea TUI under a pty |
|
||||
|
||||
## Custody / smoke
|
||||
|
||||
Reference in New Issue
Block a user