{
  "url": "https://secure.therapservices.net",
  "auditedAt": "2026-07-27T13:33:37.181Z",
  "mode": "report",
  "status": "partial",
  "statusDetail": "The public login, reset, help, responsive states, and 404 recovery were audited. Three end-to-end authenticated checks are blocked because no authorized test credentials were supplied.",
  "page": {
    "appType": "mpa",
    "framework": "Server-rendered Bootstrap/jQuery authentication application",
    "notes": "Root redirects through logout to login. Authenticated product routes were not accessible. Public archetypes audited: login, password reset, help modal interaction, and 404 recovery."
  },
  "evidenceUsed": [
    "screenshot",
    "dom",
    "layout-metrics",
    "evaluate-probe",
    "forced-colors",
    "reduced-motion",
    "discoverability",
    "headers",
    "cookies",
    "trackers",
    "secrets",
    "images",
    "har",
    "trace",
    "heap-summary",
    "Lighthouse",
    "curl"
  ],
  "guidanceConsulted": [
    "accessibility",
    "dark-mode",
    "forms",
    "validate-input-after-interaction",
    "autofill-sign-in-form",
    "animate-to-from-top-layer",
    "navigation-drawer",
    "scroll-entry-exit-effects",
    "same-document-transitions",
    "position-aware-tooltips",
    "performance",
    "optimize-preload-priority",
    "optimize-image-priority",
    "optimize-script-priority",
    "defer-rendering-heavy-content",
    "security",
    "privacy",
    "passkeys",
    "passkey-reauthentication",
    "coordinate-global-events",
    "capture-location-agnostic-data",
    "support-global-calendar-systems",
    "stabilize-reactive-state",
    "consistent-cross-document-transitions",
    "agentic-forms",
    "efficient-background-processing",
    "deprioritize-background-fetches",
    "manage-recurring-intervals",
    "html",
    "css"
  ],
  "artifacts": [
    {
      "type": "screenshot",
      "path": "evidence/404-mobile.png",
      "caption": "404 mobile png",
      "findingIds": [
        "F020"
      ],
      "condition": "viewport: 360x800"
    },
    {
      "type": "other",
      "path": "evidence/404-status.txt",
      "caption": "404 status txt",
      "findingIds": [
        "F020"
      ]
    },
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "cookies json",
      "findingIds": [
        "F015"
      ]
    },
    {
      "type": "other",
      "path": "evidence/curl-headers.txt",
      "caption": "curl headers txt"
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-crawler.png",
      "caption": "discoverability crawler png"
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-rendered.png",
      "caption": "discoverability rendered png"
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability.json",
      "caption": "discoverability json"
    },
    {
      "type": "dom",
      "path": "evidence/dom-404.json",
      "caption": "dom 404 json",
      "findingIds": [
        "F007",
        "F020"
      ]
    },
    {
      "type": "dom",
      "path": "evidence/dom-login.json",
      "caption": "dom login json",
      "findingIds": [
        "F002",
        "F003",
        "F005",
        "F007",
        "F010",
        "F016"
      ]
    },
    {
      "type": "dom",
      "path": "evidence/dom-password-reset.json",
      "caption": "dom password reset json",
      "findingIds": [
        "F007"
      ]
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "headers json",
      "findingIds": [
        "F013",
        "F014"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline.heapsnapshot",
      "caption": "heap baseline heapsnapshot",
      "findingIds": [
        "F021"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap-post.heapsnapshot",
      "caption": "heap post heapsnapshot",
      "findingIds": [
        "F021"
      ]
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "images json",
      "findingIds": [
        "F012",
        "F017"
      ]
    },
    {
      "type": "layout",
      "path": "evidence/layout-login-mobile.json",
      "caption": "layout login mobile json",
      "findingIds": [
        "F008"
      ],
      "condition": "viewport: 360x800"
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse-details.json",
      "caption": "lighthouse details json",
      "findingIds": [
        "F006",
        "F011",
        "F012"
      ]
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "lighthouse json",
      "findingIds": [
        "F006",
        "F009",
        "F010",
        "F011"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/login-contrast.png",
      "caption": "login contrast png",
      "condition": "prefers-contrast: more; forced-colors: active"
    },
    {
      "type": "screenshot",
      "path": "evidence/login-dark.png",
      "caption": "login dark png",
      "findingIds": [
        "F001"
      ],
      "condition": "prefers-color-scheme: dark"
    },
    {
      "type": "screenshot",
      "path": "evidence/login-mobile.png",
      "caption": "login mobile png",
      "findingIds": [
        "F004",
        "F008"
      ],
      "condition": "viewport: 360x800"
    },
    {
      "type": "other",
      "path": "evidence/memory-metrics.json",
      "caption": "memory metrics json",
      "findingIds": [
        "F021"
      ]
    },
    {
      "type": "other",
      "path": "evidence/motion-css.json",
      "caption": "motion css json"
    },
    {
      "type": "har-summary",
      "path": "evidence/network-summary.json",
      "caption": "network summary json",
      "findingIds": [
        "F004",
        "F010",
        "F011",
        "F015",
        "F017",
        "F018",
        "F019"
      ]
    },
    {
      "type": "har",
      "path": "evidence/network.har",
      "caption": "network har",
      "findingIds": [
        "F004",
        "F010",
        "F015",
        "F017",
        "F018"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/password-reset-mobile.png",
      "caption": "password reset mobile png",
      "condition": "viewport: 360x800"
    },
    {
      "type": "trace-summary",
      "path": "evidence/performance-trace-summary.json",
      "caption": "performance trace summary json",
      "findingIds": [
        "F009"
      ]
    },
    {
      "type": "trace",
      "path": "evidence/performance-trace.json",
      "caption": "performance trace json",
      "findingIds": [
        "F009"
      ]
    },
    {
      "type": "other",
      "path": "evidence/platform-probe.json",
      "caption": "platform probe json",
      "findingIds": [
        "F001",
        "F002",
        "F005",
        "F006",
        "F007",
        "F008",
        "F010",
        "F016"
      ]
    },
    {
      "type": "other",
      "path": "evidence/raw.html",
      "caption": "raw html"
    },
    {
      "type": "screenshot",
      "path": "evidence/required-validation.png",
      "caption": "required validation png"
    },
    {
      "type": "other",
      "path": "evidence/robots.txt",
      "caption": "robots txt"
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "secrets json"
    },
    {
      "type": "other",
      "path": "evidence/sitemap.xml",
      "caption": "sitemap xml"
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "trackers json",
      "findingIds": [
        "F015",
        "F019"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/trouble-modal.png",
      "caption": "trouble modal png"
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 55,
    "blocked": 3,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": false
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The prefers-color-scheme: dark screenshot is visually identical to the light presentation, and the CSS probe found no prefers-color-scheme or color-scheme implementation.",
      "artifacts": [
        "evidence/login-dark.png",
        "evidence/platform-probe.json"
      ],
      "findingIds": [
        "F001"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Reduced-motion probe found Bootstrap and Font Awesome media rules suppressing transitions/animations and no active animations.",
      "artifacts": [
        "evidence/motion-css.json"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Forced-colors/high-contrast screenshot keeps text, controls, borders, focus, and links visible.",
      "artifacts": [
        "evidence/login-contrast.png"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The rendered CSS/source probe found no view-transition-name, ::view-transition, or document-startViewTransition usage on the login and recovery surfaces.",
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/dom-login.json"
      ],
      "findingIds": [
        "F002"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "No scroll-linked animation exists, and the page uses no scroll event animation handlers, so there is no main-thread scroll-motion anti-pattern.",
      "artifacts": [
        "evidence/platform-probe.json"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The tested public surfaces use native scrolling, form controls, links, and a standard collapsible menu rather than custom pointer-drag gestures.",
      "artifacts": [
        "evidence/login-mobile.png"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The long mobile page scrolls normally with no sticky chrome that needs JS scroll-state synchronization.",
      "artifacts": [
        "evidence/login-mobile.png"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Openable UI is full-width navigation/help UI rather than a tethered tooltip/menu; no overlay drift was observed at mobile or desktop edges.",
      "artifacts": [
        "evidence/login-mobile.png"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Heading, form sequence, full-width Continue action, recovery links, reset notice, and 404 home recovery clearly direct the next action.",
      "artifacts": [
        "evidence/login-mobile.png"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Initial screenshots show no consent wall, popup, or interstitial obscuring the login/reset task.",
      "artifacts": [
        "evidence/login-mobile.png"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "DOM inspection shows #trouble-logging-modal-view is a div with role=dialog, static backdrop wiring, and an iframe, not a <dialog> or popover.",
      "artifacts": [
        "evidence/dom-login.json"
      ],
      "findingIds": [
        "F003"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The mobile screenshot places Release Notes immediately after the form; HAR shows embedded promotional panes account for much of 1.31 MB transferred and 22 third-party requests.",
      "artifacts": [
        "evidence/login-mobile.png",
        "evidence/network-summary.json",
        "evidence/network.har"
      ],
      "findingIds": [
        "F004"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "At 360x800 the layout primitive measured scrollWidth=clientWidth=360, horizontalOverflowPx=0, with viewport meta present.",
      "artifacts": [
        "evidence/layout-login-mobile.json"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "DOM/CSS inspection found Bootstrap viewport grid classes but no @container or container-type declarations for reusable login, reset, navigation, or release-note components.",
      "artifacts": [
        "evidence/dom-login.json",
        "evidence/platform-probe.json"
      ],
      "findingIds": [
        "F005"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Primary fields are 58px high, Continue is 38px, keyboard focus is visible on native controls, and no hover-only primary action was found; smaller ancillary targets are separately reported under inclusive zoom/targets.",
      "artifacts": [
        "evidence/platform-probe.json"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "First viewport clearly labels Login, asks for Login Name and Provider Code, and presents one full-width Continue action.",
      "artifacts": [
        "evidence/login-mobile.png"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "status": "blocked",
      "confidence": "high",
      "method": "Attempted end-to-end authenticated-flow walkthrough from the public login surface",
      "evidence": "The public identifier step was inspected, but no authorized test credentials were supplied, so password/passkey, authenticated completion, cancellation, and sensitive account actions could not be exercised.",
      "reason": "The public identifier step was inspected, but no authorized test credentials were supplied, so password/passkey, authenticated completion, cancellation, and sensitive account actions could not be exercised.",
      "pathIds": [
        "authenticated-flow"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The reset route explains prerequisites and the real HTTP 404 provides a clear home recovery action.",
      "artifacts": [
        "evidence/password-reset-mobile.png"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Lighthouse measured LCP 4.6s, FCP 4.4s, TBT 230ms, and performance score 0.69; an unthrottled trace measured LCP 1.66s, showing network/CPU conditions drive the regression.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/performance-trace-summary.json",
        "evidence/performance-trace.json"
      ],
      "findingIds": [
        "F009"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Mobile layout observation measured CLS 0 with no shifts; Lighthouse also reports CLS 0.",
      "artifacts": [
        "evidence/layout-login-mobile.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Trace recorded one 85.56ms long task and 35.56ms TBT; Lighthouse TBT was 230ms, below the 300ms lab poor threshold.",
      "artifacts": [
        "evidence/performance-trace-summary.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The DOM has 17 classic scripts in <head> without async/defer plus many stylesheets; HAR identifies high-priority parser-blocking styles, absent cache headers, and 1.31MB transferred; Lighthouse estimates 2.18s render-blocking savings.",
      "artifacts": [
        "evidence/dom-login.json",
        "evidence/platform-probe.json",
        "evidence/network-summary.json",
        "evidence/network.har",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F010"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Lighthouse estimates 192KiB unused JS and 49KiB unused CSS; HAR records two near-identical 184KiB gtag resources plus a 146KiB GTM script.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/lighthouse-details.json",
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F011"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Lighthouse found the language-picker button has no accessible name and rightPaneFrame has no title; the platform probe also found leftPaneFrame and rightPaneFrame titles empty.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/lighthouse-details.json",
        "evidence/platform-probe.json"
      ],
      "findingIds": [
        "F006"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Lighthouse color-contrast audit passed, and forced-colors screenshot remained readable.",
      "artifacts": [
        "evidence/lighthouse-details.json"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "DOM inspection found no h1 on login, reset, or 404; the focus probe reports outline none and box-shadow none for #languageSelectPickerBtn.",
      "artifacts": [
        "evidence/dom-login.json",
        "evidence/platform-probe.json",
        "evidence/dom-password-reset.json",
        "evidence/dom-404.json"
      ],
      "findingIds": [
        "F007"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Mobile screenshots show unclipped labels and readable paragraphs with no horizontal overflow; reset fields wrap without content loss.",
      "artifacts": [
        "evidence/login-mobile.png"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The focus/geometry probe measured the language combobox at 24px high and footer/help links at 14px high; the mobile page otherwise reflows without horizontal overflow.",
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/login-mobile.png",
        "evidence/layout-login-mobile.json"
      ],
      "findingIds": [
        "F008"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Lighthouse errors-in-console audit passed with no logged errors.",
      "artifacts": [
        "evidence/lighthouse-details.json"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Lighthouse image-size-responsive reports the 100x40 PNG displayed at 100x40 where 150x60 source pixels are expected for the tested DPR.",
      "artifacts": [
        "evidence/lighthouse-details.json",
        "evidence/images.json"
      ],
      "findingIds": [
        "F012"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Lighthouse found no console/deprecation issue or intrusive permission prompt; the BFCache no-store finding is appropriate for an authentication response.",
      "artifacts": [
        "evidence/lighthouse-details.json"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon-based applicability judgement",
      "evidence": "The authenticated application is deliberately gated; search-result presentation of the login endpoint is not a core outcome.",
      "reason": "The authenticated application is deliberately gated; search-result presentation of the login endpoint is not a core outcome."
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Viewport meta is present and normal links have real href values; Lighthouse crawlable anchors and crawlability audits passed. Public indexing is not a goal for the gated app.",
      "artifacts": [
        "evidence/lighthouse-details.json"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon-based applicability judgement",
      "evidence": "The authenticated application is deliberately gated and does not need canonical/hreflang/sitemap indexing signals on its login endpoint.",
      "reason": "The authenticated application is deliberately gated and does not need canonical/hreflang/sitemap indexing signals on its login endpoint."
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon-based applicability judgement",
      "evidence": "Login, reset, and error pages do not represent a public rich entity or shareable content item.",
      "reason": "Login, reset, and error pages do not represent a public rich entity or shareable content item."
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The headers primitive confirms HTTPS but no Content-Security-Policy, Strict-Transport-Security, or X-Content-Type-Options on the login document.",
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F013"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Tracker evidence finds 7 third-party origins including GTM and DoubleClick; HAR attributes 1.10MB to third parties; cookies include two non-Secure Google Analytics cookies lasting 400 days.",
      "artifacts": [
        "evidence/trackers.json",
        "evidence/network-summary.json",
        "evidence/network.har",
        "evidence/cookies.json"
      ],
      "findingIds": [
        "F015"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "status": "blocked",
      "confidence": "high",
      "method": "Attempted end-to-end authenticated-flow walkthrough from the public login surface",
      "evidence": "The public identifier step was inspected, but no authorized test credentials were supplied, so password/passkey, authenticated completion, cancellation, and sensitive account actions could not be exercised.",
      "reason": "The public identifier step was inspected, but no authorized test credentials were supplied, so password/passkey, authenticated completion, cancellation, and sensitive account actions could not be exercised.",
      "pathIds": [
        "authenticated-flow"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The headers primitive found neither frame-ancestors/X-Frame-Options nor Referrer-Policy or Permissions-Policy on the authentication response.",
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F014"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The login and reset forms are server-rendered HTML with native labels, required controls and form actions; noscript gives an explicit status rather than a blank shell.",
      "artifacts": [
        "evidence/dom-login.json"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "The mobile form, menu and recovery pages fit the viewport; modal cycles kept DOM nodes stable after initial help iframe creation.",
      "artifacts": [
        "evidence/memory-metrics.json"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon-based applicability judgement",
      "evidence": "This is an intrinsically online, security-sensitive authenticated service; installability/offline authentication is not an appropriate requirement.",
      "reason": "This is an intrinsically online, security-sensitive authenticated service; installability/offline authentication is not an appropriate requirement."
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "A genuine unknown route returned HTTP 404 with a concise message and a Go Back to HomePage recovery link.",
      "artifacts": [
        "evidence/404-mobile.png"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "DOM evidence for a real 404 response reports html.lang empty, while login and reset correctly use lang=en.",
      "artifacts": [
        "evidence/dom-404.json",
        "evidence/404-mobile.png",
        "evidence/404-status.txt"
      ],
      "findingIds": [
        "F020"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon-based applicability judgement",
      "evidence": "The public pages show no dates, currency, numbers, durations, or calendars requiring locale formatting.",
      "reason": "The public pages show no dates, currency, numbers, durations, or calendars requiring locale formatting."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon-based applicability judgement",
      "evidence": "The public pages expose no scheduled or stored time concepts.",
      "reason": "The public pages expose no scheduled or stored time concepts."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "No confirmshaming, forced continuity, preselected consent, disguised action, or cancellation obstruction was observed on public login/reset surfaces.",
      "artifacts": [
        "evidence/login-mobile.png"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Required login fields use native required semantics and visible labels; reset instructions explain account prerequisites and recovery ownership without blaming the user.",
      "artifacts": [
        "evidence/dom-login.json"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "DOM and platform probes show loginName and providerCode have empty autocomplete values despite form autocomplete=on.",
      "artifacts": [
        "evidence/dom-login.json",
        "evidence/platform-probe.json"
      ],
      "findingIds": [
        "F016"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "status": "blocked",
      "confidence": "high",
      "method": "Attempted end-to-end authenticated-flow walkthrough from the public login surface",
      "evidence": "The public identifier step was inspected, but no authorized test credentials were supplied, so password/passkey, authenticated completion, cancellation, and sensitive account actions could not be exercised.",
      "reason": "The public identifier step was inspected, but no authorized test credentials were supplied, so password/passkey, authenticated completion, cancellation, and sensitive account actions could not be exercised.",
      "pathIds": [
        "authenticated-flow"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "HAR transfers 544KB of images, led by a 191KB animated GIF and multiple 64-98KB promo images; the logo is a legacy PNG with no responsive source.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/network.har",
        "evidence/images.json"
      ],
      "findingIds": [
        "F017"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "HAR records 22 third-party requests and 1.10MB third-party transfer before user interaction, including duplicate analytics libraries and off-task promo frames.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/network.har"
      ],
      "findingIds": [
        "F018"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Third parties account for 1,102,090 of 1,310,615 transferred bytes (84%), with GTM/gtag and promotional embeds dominating the budget.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/trackers.json"
      ],
      "findingIds": [
        "F019"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon-based applicability judgement",
      "evidence": "Exposing authentication/account actions to agents was judged inappropriate without an explicit safe agent-facing product intent.",
      "reason": "Exposing authentication/account actions to agents was judged inappropriate without an explicit safe agent-facing product intent."
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon-based applicability judgement",
      "evidence": "The public authentication and recovery surfaces have no inference task where a built-in model would improve the experience.",
      "reason": "The public authentication and recovery surfaces have no inference task where a built-in model would improve the experience."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "status": "issues",
      "confidence": "medium",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "In one session usedJSHeapSize rose from 11.38MB before interaction to 11.75MB after 10 cycles and 12.88MB after 20 while DOM nodes stabilized at 159; separate heap summaries rose from 20.55MB to 24.77MB after 10 cycles. This is a suspicion, not proof of an unbounded leak.",
      "artifacts": [
        "evidence/memory-metrics.json",
        "evidence/heap-baseline.heapsnapshot",
        "evidence/heap-post.heapsnapshot"
      ],
      "findingIds": [
        "F021"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Baseline heap summary reports 20.55MB self size for a page with two promotional iframes; the footprint is finite, though network/UI complexity should be reduced.",
      "artifacts": [
        "evidence/heap-baseline.heapsnapshot"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "status": "pass",
      "confidence": "high",
      "method": "DOM/source inspection, visual review, and targeted evidence probe",
      "evidence": "Heap constructor summaries show no Detached* population, and repeated modal cycles stabilized DOM nodes at 159; no direct detached-DOM evidence was found.",
      "artifacts": [
        "evidence/heap-post.heapsnapshot"
      ]
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F001"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F002"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F003",
        "F004"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F005"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "incomplete",
      "reason": "Authorized credentials were not available for the end-to-end authenticated checks."
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F009",
        "F010",
        "F011"
      ]
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F006",
        "F007",
        "F008"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F012"
      ]
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F013",
        "F015",
        "F014"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F020"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F016"
      ]
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F017",
        "F018",
        "F019"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "Recon found no applicable agent-facing surface or inference task."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F021"
      ]
    }
  ],
  "paths": [
    {
      "id": "entry-redirect",
      "description": "Root redirect/logout state leading to login; represents unauthenticated entry.",
      "url": "https://secure.therapservices.net",
      "conditions": [
        "JavaScript on",
        "crawler/no-JavaScript comparison"
      ],
      "result": "issues"
    },
    {
      "id": "login",
      "description": "Primary public login form; represents the authentication entry template.",
      "url": "https://secure.therapservices.net/auth/login",
      "conditions": [
        "desktop",
        "viewport 360x800",
        "prefers-color-scheme dark",
        "prefers-reduced-motion reduce",
        "forced-colors active",
        "keyboard focus"
      ],
      "result": "issues"
    },
    {
      "id": "password-reset",
      "description": "Forgot-password recovery form; represents public account recovery.",
      "url": "https://secure.therapservices.net/auth/password/reset/startPasswordReset",
      "conditions": [
        "viewport 360x800"
      ],
      "result": "issues"
    },
    {
      "id": "help-modal",
      "description": "Trouble Logging In modal repeatedly opened/closed; represents overlay and repeated interaction behavior.",
      "url": "https://secure.therapservices.net/auth/login",
      "conditions": [
        "20 open/close cycles"
      ],
      "result": "issues"
    },
    {
      "id": "error-404",
      "description": "Unknown route; represents HTTP/network recovery and error template.",
      "url": "https://secure.therapservices.net/this-path-does-not-exist-web-uplift",
      "conditions": [
        "viewport 360x800"
      ],
      "result": "issues"
    },
    {
      "id": "authenticated-flow",
      "description": "Password/passkey, authenticated task, and account-management flow; attempted but not covered because credentials were unavailable.",
      "url": "https://secure.therapservices.net",
      "conditions": [
        "authorized authentication required"
      ],
      "result": "skipped"
    }
  ],
  "findings": [
    {
      "id": "F001",
      "severity": "medium",
      "confidence": "high",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "summary": "The login surface remains light when the user requests a dark color scheme.",
      "evidence": "The prefers-color-scheme: dark screenshot is visually identical to the light presentation, and the CSS probe found no prefers-color-scheme or color-scheme implementation.",
      "artifacts": [
        "evidence/login-dark.png",
        "evidence/platform-probe.json"
      ],
      "suggestedFix": "Declare color-scheme and provide dark surface, text, border, focus, and control tokens under prefers-color-scheme.",
      "effort": "medium",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F002",
      "severity": "low",
      "confidence": "high",
      "principleId": "implement-natural-interactions",
      "principleCheckId": "view-transitions",
      "guidanceId": "same-document-transitions",
      "summary": "State and route changes have no View Transition treatment.",
      "evidence": "The rendered CSS/source probe found no view-transition-name, ::view-transition, or document-startViewTransition usage on the login and recovery surfaces.",
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/dom-login.json"
      ],
      "suggestedFix": "Use a restrained same-document transition for multi-step authentication state and cross-document transitions for login/recovery navigation, while preserving reduced-motion behavior.",
      "effort": "medium",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F003",
      "severity": "medium",
      "confidence": "high",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "semantic-dismissible-primitives",
      "guidanceId": "animate-to-from-top-layer",
      "summary": "Login help uses a custom Bootstrap modal rather than the native dialog/top-layer primitive.",
      "evidence": "DOM inspection shows #trouble-logging-modal-view is a div with role=dialog, static backdrop wiring, and an iframe, not a <dialog> or popover.",
      "artifacts": [
        "evidence/dom-login.json"
      ],
      "suggestedFix": "Use <dialog> with showModal(), a labelled close control, Escape support, focus restoration, and reduced-motion-aware entry/exit.",
      "effort": "medium",
      "pathId": "help-modal",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F004",
      "severity": "medium",
      "confidence": "high",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "reduced-chrome",
      "guidanceId": "defer-rendering-heavy-content",
      "summary": "Promotional iframe chrome competes with a security-sensitive login task.",
      "evidence": "The mobile screenshot places Release Notes immediately after the form; HAR shows embedded promotional panes account for much of 1.31 MB transferred and 22 third-party requests.",
      "artifacts": [
        "evidence/login-mobile.png",
        "evidence/network-summary.json",
        "evidence/network.har"
      ],
      "suggestedFix": "Keep the authentication page task-first. Remove promotional panes or defer them until after interaction and outside the primary login layout.",
      "effort": "medium",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F005",
      "severity": "low",
      "confidence": "high",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "component-level-responsiveness",
      "guidanceId": "css",
      "summary": "Responsiveness is viewport-only rather than component-aware.",
      "evidence": "DOM/CSS inspection found Bootstrap viewport grid classes but no @container or container-type declarations for reusable login, reset, navigation, or release-note components.",
      "artifacts": [
        "evidence/dom-login.json",
        "evidence/platform-probe.json"
      ],
      "suggestedFix": "Give reusable panels an inline-size containment context and use container queries for local composition changes, retaining viewport rules only for page-level layout.",
      "effort": "medium",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F006",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-inclusive",
      "principleCheckId": "names-roles-labels",
      "guidanceId": "accessibility",
      "summary": "The custom language picker and promotional frames are not reliably named for assistive technology.",
      "evidence": "Lighthouse found the language-picker button has no accessible name and rightPaneFrame has no title; the platform probe also found leftPaneFrame and rightPaneFrame titles empty.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/lighthouse-details.json",
        "evidence/platform-probe.json"
      ],
      "suggestedFix": "Associate the visible language label with the combobox and title each iframe according to its content, or remove decorative/promo frames from the accessibility tree.",
      "effort": "small",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F007",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-inclusive",
      "principleCheckId": "structure-and-focus",
      "guidanceId": "accessibility",
      "summary": "The heading hierarchy starts at h2 and the custom language picker lacks a visible focus treatment.",
      "evidence": "DOM inspection found no h1 on login, reset, or 404; the focus probe reports outline none and box-shadow none for #languageSelectPickerBtn.",
      "artifacts": [
        "evidence/dom-login.json",
        "evidence/platform-probe.json",
        "evidence/dom-password-reset.json",
        "evidence/dom-404.json"
      ],
      "suggestedFix": "Use one descriptive h1 per page and add an unmistakable :focus-visible outline to the custom combobox without removing native focus indicators.",
      "effort": "small",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F008",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-inclusive",
      "principleCheckId": "zoom-reflow-targets-and-media",
      "guidanceId": "accessibility",
      "summary": "Several interactive targets are materially smaller than the recommended touch size.",
      "evidence": "The focus/geometry probe measured the language combobox at 24px high and footer/help links at 14px high; the mobile page otherwise reflows without horizontal overflow.",
      "artifacts": [
        "evidence/platform-probe.json",
        "evidence/login-mobile.png",
        "evidence/layout-login-mobile.json"
      ],
      "suggestedFix": "Provide at least 24 by 24 CSS pixels for all targets, and preferably 44 by 44 on primary mobile controls, using padding rather than tiny text hit areas.",
      "effort": "small",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F009",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "good-core-web-vitals",
      "guidanceId": "performance",
      "summary": "The login page misses the good LCP range under Lighthouse mobile throttling.",
      "evidence": "Lighthouse measured LCP 4.6s, FCP 4.4s, TBT 230ms, and performance score 0.69; an unthrottled trace measured LCP 1.66s, showing network/CPU conditions drive the regression.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/performance-trace-summary.json",
        "evidence/performance-trace.json"
      ],
      "suggestedFix": "Prioritize the login form, remove nonessential work from the critical path, and verify LCP under throttled mobile conditions.",
      "effort": "medium",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F010",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "efficient-resource-delivery",
      "guidanceId": "optimize-script-priority",
      "summary": "A long chain of parser-blocking CSS and classic head scripts delays the login UI.",
      "evidence": "The DOM has 17 classic scripts in <head> without async/defer plus many stylesheets; HAR identifies high-priority parser-blocking styles, absent cache headers, and 1.31MB transferred; Lighthouse estimates 2.18s render-blocking savings.",
      "artifacts": [
        "evidence/dom-login.json",
        "evidence/platform-probe.json",
        "evidence/network-summary.json",
        "evidence/network.har",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Bundle critical login styles, defer noncritical classic scripts, preserve module semantics, add immutable caching to versioned assets, and lazy-load help/promo dependencies.",
      "effort": "large",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F011",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "trim-unused-and-duplicate-code",
      "guidanceId": "defer-rendering-heavy-content",
      "summary": "The login page ships substantial unused CSS and duplicate analytics JavaScript.",
      "evidence": "Lighthouse estimates 192KiB unused JS and 49KiB unused CSS; HAR records two near-identical 184KiB gtag resources plus a 146KiB GTM script.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/lighthouse-details.json",
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Create a login-specific CSS/JS entry point and use one consent-aware analytics loader rather than loading GTM and duplicate gtag libraries.",
      "effort": "medium",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F012",
      "severity": "low",
      "confidence": "high",
      "principleId": "follow-best-practices",
      "principleCheckId": "sound-document-and-assets",
      "guidanceId": "html",
      "summary": "The logo raster is undersized for the rendered device-pixel requirement.",
      "evidence": "Lighthouse image-size-responsive reports the 100x40 PNG displayed at 100x40 where 150x60 source pixels are expected for the tested DPR.",
      "artifacts": [
        "evidence/lighthouse-details.json",
        "evidence/images.json"
      ],
      "suggestedFix": "Use an SVG logo or supply an appropriately sized responsive raster source while retaining explicit dimensions.",
      "effort": "trivial",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F013",
      "severity": "critical",
      "confidence": "high",
      "principleId": "be-private-and-secure",
      "principleCheckId": "secure-transport-and-headers",
      "guidanceId": "security",
      "summary": "The authentication response lacks core browser security headers.",
      "evidence": "The headers primitive confirms HTTPS but no Content-Security-Policy, Strict-Transport-Security, or X-Content-Type-Options on the login document.",
      "artifacts": [
        "evidence/headers.json"
      ],
      "suggestedFix": "Deploy a nonce/hash-based CSP, HSTS after subdomain readiness, and X-Content-Type-Options: nosniff. Test the policy in report-only mode first.",
      "effort": "medium",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F014",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-private-and-secure",
      "principleCheckId": "defensive-browser-policies",
      "guidanceId": "security",
      "summary": "Clickjacking, referrer, and permissions defenses are not declared.",
      "evidence": "The headers primitive found neither frame-ancestors/X-Frame-Options nor Referrer-Policy or Permissions-Policy on the authentication response.",
      "artifacts": [
        "evidence/headers.json"
      ],
      "suggestedFix": "Add CSP frame-ancestors, a strict-origin-when-cross-origin or stricter Referrer-Policy, and a least-privilege Permissions-Policy.",
      "effort": "small",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F015",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-private-and-secure",
      "principleCheckId": "data-minimisation-and-third-parties",
      "guidanceId": "privacy",
      "summary": "A login page sends extensive analytics traffic and sets long-lived analytics cookies before authentication.",
      "evidence": "Tracker evidence finds 7 third-party origins including GTM and DoubleClick; HAR attributes 1.10MB to third parties; cookies include two non-Secure Google Analytics cookies lasting 400 days.",
      "artifacts": [
        "evidence/trackers.json",
        "evidence/network-summary.json",
        "evidence/network.har",
        "evidence/cookies.json"
      ],
      "suggestedFix": "Remove advertising/analytics from authentication, or gate a single minimized analytics endpoint behind valid consent; mark every retained cookie Secure and select the narrowest SameSite value.",
      "effort": "medium",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F016",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-trustworthy",
      "principleCheckId": "trustworthy-input-assistance",
      "guidanceId": "autofill-sign-in-form",
      "summary": "Authentication identifiers do not expose standard autocomplete semantics.",
      "evidence": "DOM and platform probes show loginName and providerCode have empty autocomplete values despite form autocomplete=on.",
      "artifacts": [
        "evidence/dom-login.json",
        "evidence/platform-probe.json"
      ],
      "suggestedFix": "Apply the most accurate standard autocomplete token, including username where loginName is the account identifier; document a product-specific approach for provider code without inventing invalid tokens.",
      "effort": "small",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F017",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-sustainable",
      "principleCheckId": "optimised-assets",
      "guidanceId": "optimize-image-priority",
      "summary": "Promotional raster and animated GIF assets are disproportionate to the login task.",
      "evidence": "HAR transfers 544KB of images, led by a 191KB animated GIF and multiple 64-98KB promo images; the logo is a legacy PNG with no responsive source.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/network.har",
        "evidence/images.json"
      ],
      "suggestedFix": "Remove promo imagery from authentication, replace required animations with efficient video or modern formats, and serve responsive AVIF/WebP/SVG assets.",
      "effort": "medium",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F018",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-sustainable",
      "principleCheckId": "no-wasteful-work",
      "guidanceId": "deprioritize-background-fetches",
      "summary": "Nonessential promotional and analytics work runs during the critical login load.",
      "evidence": "HAR records 22 third-party requests and 1.10MB third-party transfer before user interaction, including duplicate analytics libraries and off-task promo frames.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/network.har"
      ],
      "suggestedFix": "Do not fetch promo frames or analytics during initial authentication. Load optional support content only on explicit interaction and batch any justified telemetry.",
      "effort": "medium",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F019",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-sustainable",
      "principleCheckId": "third-party-and-media-budget",
      "guidanceId": "efficient-background-processing",
      "summary": "Third-party transfer dominates a simple two-field login page.",
      "evidence": "Third parties account for 1,102,090 of 1,310,615 transferred bytes (84%), with GTM/gtag and promotional embeds dominating the budget.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/trackers.json"
      ],
      "suggestedFix": "Set a strict authentication-page third-party budget, self-host only essential static assets, and eliminate duplicate analytics and promotional media.",
      "effort": "medium",
      "pathId": "login",
      "url": "https://secure.therapservices.net/auth/login"
    },
    {
      "id": "F020",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-internationalised",
      "principleCheckId": "lang-dir-and-logical-properties",
      "guidanceId": "accessibility",
      "summary": "The custom 404 response omits the document language.",
      "evidence": "DOM evidence for a real 404 response reports html.lang empty, while login and reset correctly use lang=en.",
      "artifacts": [
        "evidence/dom-404.json",
        "evidence/404-mobile.png",
        "evidence/404-status.txt"
      ],
      "suggestedFix": "Set lang on every error template and add dir where language selection requires it; audit templates with translated and RTL strings.",
      "effort": "trivial",
      "pathId": "error-404",
      "url": "https://secure.therapservices.net/this-path-does-not-exist-web-uplift"
    },
    {
      "id": "F021",
      "severity": "low",
      "confidence": "medium",
      "principleId": "be-memory-efficient",
      "principleCheckId": "no-leak-under-repeated-interaction",
      "guidanceId": "manage-recurring-intervals",
      "summary": "Repeated help-modal cycles show continued heap growth that warrants leak investigation.",
      "evidence": "In one session usedJSHeapSize rose from 11.38MB before interaction to 11.75MB after 10 cycles and 12.88MB after 20 while DOM nodes stabilized at 159; separate heap summaries rose from 20.55MB to 24.77MB after 10 cycles. This is a suspicion, not proof of an unbounded leak.",
      "artifacts": [
        "evidence/memory-metrics.json",
        "evidence/heap-baseline.heapsnapshot",
        "evidence/heap-post.heapsnapshot"
      ],
      "suggestedFix": "Profile baseline, target, and final heaps with forced GC; verify modal handlers and iframe resources are released, and remove accumulating listeners/timers if retained paths confirm growth.",
      "effort": "medium",
      "pathId": "help-modal",
      "url": "https://secure.therapservices.net/auth/login"
    }
  ],
  "taskList": [
    {
      "id": "T001",
      "title": "Harden authentication response headers and cookie posture",
      "priority": 1,
      "findingIds": [
        "F013",
        "F014",
        "F015"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T002",
      "title": "Remove promotional frames and duplicate analytics from the login critical path",
      "priority": 2,
      "findingIds": [
        "F004",
        "F009",
        "F010",
        "F011",
        "F015",
        "F017",
        "F018",
        "F019"
      ],
      "guidanceId": "performance",
      "status": "open"
    },
    {
      "id": "T003",
      "title": "Fix combobox/frame names, focus, heading structure, and target sizes",
      "priority": 3,
      "findingIds": [
        "F006",
        "F007",
        "F008"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T004",
      "title": "Add dark mode and modern responsive/transition treatment",
      "priority": 4,
      "findingIds": [
        "F001",
        "F002",
        "F005"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    },
    {
      "id": "T005",
      "title": "Use native dialog semantics for login help",
      "priority": 5,
      "findingIds": [
        "F003"
      ],
      "guidanceId": "animate-to-from-top-layer",
      "status": "open"
    },
    {
      "id": "T006",
      "title": "Add sign-in autocomplete semantics and verify modern auth with authorized credentials",
      "priority": 6,
      "findingIds": [
        "F016"
      ],
      "guidanceId": "autofill-sign-in-form",
      "status": "open"
    },
    {
      "id": "T007",
      "title": "Correct error-template language and responsive image delivery",
      "priority": 7,
      "findingIds": [
        "F012",
        "F020"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T008",
      "title": "Investigate help-modal retained heap with a three-snapshot profile",
      "priority": 8,
      "findingIds": [
        "F021"
      ],
      "guidanceId": "manage-recurring-intervals",
      "status": "open"
    }
  ],
  "budget": {
    "pathCount": 6,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-27T13-22-56-133Z"
}
