{
  "url": "https://giris.turkiye.gov.tr",
  "auditedAt": "2026-07-28T00:45:45.705Z",
  "mode": "report",
  "status": "partial",
  "statusDetail": "57 of 58 checks judged. End-to-end primary authentication is blocked by unavailable personal credentials; no score is published.",
  "page": {
    "appType": "mpa",
    "framework": "Server-rendered Java/JSP-style MPA with jQuery and custom edl components",
    "notes": "Public Turkish government identity gateway. Four representative pre-authentication route archetypes were reviewed. Mobile/e-signature/eID variants that share the same template and post-authenticated government services were not covered; a real credential was intentionally not fabricated."
  },
  "evidenceUsed": [
    "screenshot",
    "dom",
    "layout-metrics",
    "evaluate-probe",
    "trace",
    "har",
    "discoverability",
    "headers",
    "cookies",
    "trackers",
    "secrets",
    "images",
    "heap-summary",
    "lighthouse",
    "HTTP fetch",
    "Modern Web Guidance 0.0.172"
  ],
  "guidanceConsulted": [
    "dark-mode",
    "component-specific-light-dark-theme",
    "accessibility",
    "adapt-scrollbar-to-contrast-preferences",
    "same-document-transitions",
    "cross-document-transitions",
    "group-element-transitions",
    "faster-spa-view-transitions",
    "scrollytelling",
    "parallax-scroll-effects",
    "scroll-entry-exit-effects",
    "carousel-slide-effects",
    "physics-based-easing",
    "individual-transform-properties",
    "animate-element-entry-exit",
    "animate-to-from-top-layer",
    "animate-to-intrinsic-sizes",
    "dynamic-sibling-animations",
    "interactive-content-reveal",
    "pull-to-reveal",
    "swipe-to-remove",
    "shrinking-header-on-scroll",
    "scroll-progress-indicator",
    "scroll-position-aware-elements",
    "scroll-snap-realtime-feedback",
    "scroll-snap-state-sync",
    "scroll-target-on-load",
    "soft-edge-content-fade",
    "scrollability-affordance-hints",
    "anchor-positioning-tab-underline",
    "position-aware-tooltips",
    "interest-triggered-tooltips",
    "interest-triggered-action-previews",
    "directional-navigation-transitions",
    "carousel-snap-highlights",
    "navigation-drawer",
    "stack-drill-down",
    "persistent-app-tours",
    "persistent-toast-notifications",
    "light-dismiss-a-dialog",
    "platform-controls-dismiss-dialog",
    "declarative-dialog-popover-control",
    "animated-select-picker",
    "branded-select-styling",
    "brand-consistent-forms",
    "custom-select-picker-layouts",
    "rich-media-picker",
    "complex-shapes",
    "shaped-cutouts",
    "overflow-clipping-control",
    "visually-texture-content",
    "apply-webgl-shaders",
    "interactive-content-in-3d-scenes",
    "highlight-text-ranges",
    "prevent-text-wrapping",
    "customize-scrollbar-color-and-thickness",
    "export-html-media-from-canvas",
    "fluid-scaling",
    "calculate-with-intrinsic-sizes",
    "css-layout",
    "size-aware-styling",
    "content-based-styling",
    "child-state-based-styling",
    "design-token-reactivity",
    "dynamic-sibling-styling",
    "form-fields-automatically-fit-contents",
    "improve-text-layout-and-legibility",
    "forms",
    "accessible-error-announcement",
    "required-field-feedback",
    "validate-input-after-interaction",
    "identify-inp-causes",
    "schedule-tasks-by-priority",
    "optimize-preload-priority",
    "improve-next-page-load-performance",
    "interactions-in-complex-layouts",
    "performance",
    "visually-stable-font-fallbacks",
    "break-up-long-tasks",
    "identify-heavy-scripts",
    "optimize-script-priority",
    "defer-rendering-heavy-content",
    "defer-work-until-scroll-ends",
    "optimize-image-priority",
    "conditional-async-dependencies",
    "expose-canvas-content-to-browser-features",
    "move-dom-element-without-losing-state",
    "precise-text-alignment",
    "visually-stable-mixed-fonts",
    "css",
    "html",
    "reduce-style-repetition",
    "security",
    "privacy",
    "batch-analytics-events",
    "full-session-analytics",
    "calculate-total-foreground-time",
    "passkeys",
    "passkey-registration",
    "passkey-authentication",
    "passkey-reauthentication",
    "passkey-conditional-create",
    "passkey-management",
    "flicker-free-client-side-ab-testing",
    "consistent-cross-document-transitions",
    "stabilize-reactive-state",
    "resilient-context-menus-and-nested-dropdowns",
    "persistent-top-layer-ui",
    "detect-initial-visibility-state",
    "sequence-distributed-events",
    "translator",
    "language-detection",
    "support-global-calendar-systems",
    "capture-location-agnostic-data",
    "format-human-readable-durations",
    "manage-recurring-intervals",
    "calculate-event-differentials",
    "coordinate-global-events",
    "model-partial-time-concepts",
    "search-hidden-content",
    "select-menu-interaction",
    "style-parent-with-has",
    "autofill-address-form",
    "autofill-payment-form",
    "autofill-sign-in-form",
    "autofill-sign-up-form",
    "autofill-highlight-inputs",
    "deliver-optimized-decorative-images",
    "resolution-optimized-pseudo-elements",
    "deprioritize-background-fetches",
    "efficient-background-processing",
    "webmcp",
    "agentic-forms",
    "agentic-javascript-tools",
    "language-model",
    "summarizer"
  ],
  "artifacts": [
    {
      "type": "screenshot",
      "path": "evidence/desktop.png",
      "caption": "Desktop entry route",
      "condition": "viewport: 780x493",
      "findingIds": [
        "F1",
        "F4"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile.png",
      "caption": "Mobile entry route",
      "condition": "viewport: 360x800",
      "findingIds": [
        "F4"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/dark.png",
      "caption": "Entry under dark preference",
      "condition": "prefers-color-scheme: dark",
      "findingIds": [
        "F1"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/high-contrast.png",
      "caption": "Entry under forced colors",
      "condition": "forced-colors: active",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/esign.png",
      "caption": "Electronic-signature route",
      "condition": "desktop",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/bank.png",
      "caption": "Bank selection route",
      "condition": "desktop",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/forgot.png",
      "caption": "Password recovery route",
      "condition": "desktop",
      "findingIds": []
    },
    {
      "type": "dom",
      "path": "evidence/dom-entry.json",
      "caption": "Rendered entry DOM",
      "condition": "default",
      "findingIds": [
        "F2",
        "F3",
        "F10",
        "F11",
        "F16",
        "F18"
      ]
    },
    {
      "type": "dom",
      "path": "evidence/dom-esign.json",
      "caption": "Rendered e-signature DOM",
      "condition": "default",
      "findingIds": [
        "F10"
      ]
    },
    {
      "type": "dom",
      "path": "evidence/dom-bank.json",
      "caption": "Rendered bank route DOM",
      "condition": "default",
      "findingIds": [
        "F10"
      ]
    },
    {
      "type": "dom",
      "path": "evidence/dom-forgot.json",
      "caption": "Rendered recovery DOM",
      "condition": "default",
      "findingIds": [
        "F10"
      ]
    },
    {
      "type": "layout",
      "path": "evidence/layout-desktop.json",
      "caption": "Desktop layout metrics",
      "condition": "780 px",
      "findingIds": [
        "F9"
      ]
    },
    {
      "type": "layout",
      "path": "evidence/layout-mobile.json",
      "caption": "Mobile layout metrics",
      "condition": "360 px",
      "findingIds": []
    },
    {
      "type": "trace",
      "path": "evidence/trace.json",
      "caption": "DevTools performance trace",
      "condition": "cold load",
      "findingIds": []
    },
    {
      "type": "trace-summary",
      "path": "evidence/trace-summary.json",
      "caption": "Trace timing summary",
      "condition": "cold load",
      "findingIds": [
        "F6"
      ]
    },
    {
      "type": "har",
      "path": "evidence/network.har",
      "caption": "Network HAR",
      "condition": "5 second load",
      "findingIds": [
        "F7"
      ]
    },
    {
      "type": "har-summary",
      "path": "evidence/network-summary.json",
      "caption": "Network summary",
      "condition": "5 second load",
      "findingIds": [
        "F7",
        "F19"
      ]
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability.json",
      "caption": "Raw vs rendered discoverability",
      "condition": "JavaScript/no-JavaScript",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-rendered.png",
      "caption": "Rendered crawler comparison",
      "condition": "JavaScript enabled",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-crawler.png",
      "caption": "Crawler comparison",
      "condition": "JavaScript disabled",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "Security headers",
      "condition": "entry",
      "findingIds": [
        "F14",
        "F15"
      ]
    },
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "Cookie audit",
      "condition": "entry",
      "findingIds": [
        "F14"
      ]
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "Tracker audit",
      "condition": "entry",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "Client secret scan",
      "condition": "entry",
      "findingIds": [
        "F14"
      ]
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "Image audit",
      "condition": "entry",
      "findingIds": [
        "F9",
        "F19"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline.heapsnapshot",
      "caption": "Baseline heap summary",
      "condition": "settled page",
      "findingIds": []
    },
    {
      "type": "heap",
      "path": "evidence/heap-one-interaction.json",
      "caption": "Heap after one modal cycle",
      "condition": "one cycle",
      "findingIds": []
    },
    {
      "type": "heap",
      "path": "evidence/heap-twenty-interactions.json",
      "caption": "Heap after twenty modal cycles",
      "condition": "twenty cycles",
      "findingIds": []
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "Full Lighthouse JSON",
      "condition": "mobile default",
      "findingIds": [
        "F8"
      ]
    },
    {
      "type": "other",
      "path": "evidence/lighthouse-summary.json",
      "caption": "Lighthouse scores and metrics",
      "condition": "mobile default",
      "findingIds": [
        "F6"
      ]
    },
    {
      "type": "other",
      "path": "evidence/lighthouse-selected.json",
      "caption": "Selected Lighthouse diagnostic evidence",
      "condition": "mobile default",
      "findingIds": [
        "F8",
        "F9",
        "F19"
      ]
    },
    {
      "type": "other",
      "path": "evidence/lighthouse-binary-failures.json",
      "caption": "Lighthouse binary failures",
      "condition": "mobile default",
      "findingIds": [
        "F11"
      ]
    },
    {
      "type": "other",
      "path": "evidence/probe.json",
      "caption": "DOM/platform/focus probe",
      "condition": "entry",
      "findingIds": [
        "F5",
        "F20",
        "F7",
        "F12",
        "F13",
        "F16",
        "F17",
        "F18"
      ]
    },
    {
      "type": "other",
      "path": "evidence/modal-probe.json",
      "caption": "Activated modal semantics probe",
      "condition": "modal open",
      "findingIds": [
        "F3"
      ]
    },
    {
      "type": "other",
      "path": "evidence/form-validation-probe.json",
      "caption": "Native validation and live-region probe",
      "condition": "blank form",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/http-recon.txt",
      "caption": "Headers, robots and sitemap recon",
      "condition": "HTTP fetch",
      "findingIds": [
        "F12",
        "F15"
      ]
    },
    {
      "type": "other",
      "path": "evidence/404-probe.txt",
      "caption": "Invalid-route failure recovery",
      "condition": "invalid route",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/login-main.css",
      "caption": "Fetched authored stylesheet",
      "condition": "entry",
      "findingIds": [
        "F2",
        "F4",
        "F17"
      ]
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 57,
    "blocked": 1,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": false
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "The dark-mode screenshot is pixel-identical in palette and file size to the default desktop capture: white page and white form surfaces remain under prefers-color-scheme: dark.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/dark.png",
        "evidence/desktop.png"
      ],
      "findingIds": [
        "F1"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Reduced-motion emulation was active; document.getAnimations() returned zero animations across the entry surface, so no non-essential motion or auto-advance remains to suppress.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "The forced-colors/high-contrast screenshot keeps body text, inputs, buttons, borders, selected navigation and links distinguishable; Lighthouse color contrast also passed.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "DOM/CSS inspection across password, e-signature and bank pages found no view-transition-name or @view-transition rule; the routes are same-origin MPAs with shared chrome.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/dom-entry.json",
        "evidence/login-main.css"
      ],
      "findingIds": [
        "F2"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative routes",
      "evidence": "No scroll-linked animation, parallax, reveal or carousel behavior exists on the representative login/recovery routes, so there is no scroll animation implementation to assess.",
      "pathIds": [
        "entry"
      ],
      "status": "not-applicable",
      "reason": "No scroll-linked animation, parallax, reveal or carousel behavior exists on the representative login/recovery routes, so there is no scroll animation implementation to assess."
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative routes",
      "evidence": "The routes expose conventional forms and links but no gesture-driven interaction, pull/swipe action or snap-scrolling surface.",
      "pathIds": [
        "entry"
      ],
      "status": "not-applicable",
      "reason": "The routes expose conventional forms and links but no gesture-driven interaction, pull/swipe action or snap-scrolling surface."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative routes",
      "evidence": "The short login page has no persistent scrolled chrome or long-content navigation state requiring scroll-aware adaptation.",
      "pathIds": [
        "entry"
      ],
      "status": "not-applicable",
      "reason": "The short login page has no persistent scrolled chrome or long-content navigation state requiring scroll-aware adaptation."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative routes",
      "evidence": "No tooltip, anchored popover or edge-positioned menu was present; the only overlay is a centered modal assessed under semantic primitives.",
      "pathIds": [
        "entry"
      ],
      "status": "not-applicable",
      "reason": "No tooltip, anchored popover or edge-positioned menu was present; the only overlay is a centered modal assessed under semantic primitives."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Desktop/mobile screenshots show the selected authentication method prominently; the recovery route provides a seven-step breadcrumb and clearly highlighted current step.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Initial screenshots on four representative routes show no load-time popup, consent wall, interstitial or content-obscuring banner.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "The modal probe found .mfp-wrap and .ed-modal DIV elements after activation; the DOM contains zero <dialog> and zero popover elements.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/modal-probe.json",
        "evidence/dom-entry.json"
      ],
      "findingIds": [
        "F3"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Screenshots show a compact shared header, authentication selector and form with no advertising or competing application chrome; the primary content dominates the card.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Layout captures at 780 px and 360 px both report horizontalOverflowPx 0; viewport metadata is present and the mobile screenshot reflows into one column.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "The fetched 51 KB stylesheet and runtime probe contain no @container/container-type, even though shared login, navigation and footer components appear across compact and wide layouts.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/login-main.css",
        "evidence/mobile.png",
        "evidence/desktop.png"
      ],
      "findingIds": [
        "F4"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "The focus probe programmatically focused visible controls: authentication links, help links and footer links computed to outline-style none with no focus-specific box shadow; only inputs and primary buttons exposed an outline.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F5"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Entry screenshot and DOM clearly explain identity verification, label both credentials, expose Giriş Yap, alternative methods, cancel and password recovery.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "confidence": "high",
      "method": "Attempted the public authentication journey through the credential form",
      "evidence": "End-to-end authentication was attempted as far as the public form, but completion requires a valid Turkish identity credential, password/e-signature/eID, or bank account that was not available and must not be fabricated.",
      "pathIds": [
        "entry"
      ],
      "status": "blocked",
      "reason": "End-to-end authentication was attempted as far as the public form, but completion requires a valid Turkish identity credential, password/e-signature/eID, or bank account that was not available and must not be fabricated."
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "DOM and validation probes show required native validity messages, focus moves to the first invalid field, loading text exists, and password recovery is prominently linked; the 406 error document offers Back/Home recovery.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "Mobile Lighthouse measured LCP 2,594 ms (good threshold <=2,500 ms) and FCP 2,294 ms; the independent desktop trace measured LCP 1,756 ms, so the issue is condition-sensitive rather than catastrophic.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/trace-summary.json"
      ],
      "findingIds": [
        "F6"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Desktop layout observed CLS 0.00067 and mobile CLS 0 with no visible shift; both are well inside the good threshold.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Trace and layout observers recorded zero long tasks and total blocking time 0 ms; Lighthouse TBT was also 0 ms.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "HAR recorded a 1,640 ms document request and three parser-inserted classic body scripts without async/defer; total load was 24 requests and 395,431 transferred bytes.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/probe.json",
        "evidence/network.har"
      ],
      "findingIds": [
        "F7"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "Lighthouse reports 26 KiB estimated savings in common.1.9.5.js, with 51.8% of its 51,930 bytes unused on the password route.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/lighthouse-selected.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F8"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Lighthouse accessibility scored 100; DOM inspection shows labels for both credential fields, alt text for meaningful logos, button elements for actions and live regions for announcements.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Lighthouse color-contrast audit passed and default/high-contrast screenshots show readable text and control boundaries.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "The focus-walk probe shows outline-style none and no focus-specific shadow for authentication links, help links and both footer links, so keyboard users cannot reliably track focus.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F20"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Desktop and mobile screenshots show unclipped, left-aligned Turkish text at readable measure and stable line wrapping; no horizontal overflow was observed.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Lighthouse passes viewport scaling and target-size audits; the 360 px layout reflows without overflow, inputs/buttons are 45 px high, and no timed media requires captions.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Lighthouse errors-in-console audit passed with no logged browser errors.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "The images primitive and Lighthouse identify the main wordmark plus both footer logos without width/height attributes, although observed CLS remained low.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse-selected.json",
        "evidence/layout-desktop.json"
      ],
      "findingIds": [
        "F9"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Lighthouse found no geolocation/notification prompt on load and no paste prevention; the platform probe likewise found no permission-on-load calls.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "DOM captures for password, electronic-signature, bank and password-recovery routes all report the same title, despite having different tasks; the shared description is also generic.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/dom-entry.json",
        "evidence/dom-esign.json",
        "evidence/dom-bank.json",
        "evidence/dom-forgot.json"
      ],
      "findingIds": [
        "F10"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "Lighthouse SEO flagged pass_detail_btn, pass_help_btn and gizlilik_btn because each uses href=\"javascript:void(0)\".",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/lighthouse-binary-failures.json",
        "evidence/dom-entry.json"
      ],
      "findingIds": [
        "F11"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "The runtime probe found no rel=canonical or hreflang. robots.txt permits the entry route, while /sitemap.xml returned a branded 503 document rather than XML during recon.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/probe.json",
        "evidence/http-recon.txt"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "The DOM probe found zero Open Graph tags and zero JSON-LD blocks across the entry page.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F13"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "Headers report default-src * with unsafe-inline and unsafe-eval plus data:/blob:. All three Secure/HttpOnly cookies, including JSESSIONID, are SameSite=None. The secrets scanner match was inspected as a jCryption PEM marker and not treated as an exposed key.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/headers.json",
        "evidence/cookies.json",
        "evidence/secrets.json"
      ],
      "findingIds": [
        "F14"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Tracker capture found no known trackers and only one third-party origin, the affiliated e-devlet CDN; cookies were first-party and HAR showed no analytics beacons.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "The DOM/runtime probe found no WebAuthn or navigator.credentials use. The site offers password, e-signature, bank, mobile-signature and identity-card methods, but not passkeys; no permission prompts fire on load.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/probe.json",
        "evidence/dom-entry.json"
      ],
      "findingIds": [
        "F16"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "The response sends Referrer-Policy: unsafe-url, omits Permissions-Policy, and relies on X-Frame-Options without a restrictive CSP frame-ancestors directive.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/headers.json",
        "evidence/http-recon.txt"
      ],
      "findingIds": [
        "F15"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Discoverability fetch found 100% rendered-content coverage in raw HTML, with title, H1 and description present and no empty JS mount; the crawler screenshot retains the task.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Modal activation produced a visible dialog wrapper with close guidance; desktop/mobile routes rendered without cut-off menus or console errors, and navigation uses ordinary same-origin links.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative routes",
      "evidence": "This government identity gateway performs intrinsically online authentication. An offline/installable experience would not permit the core secure task and is not a reasonable requirement.",
      "pathIds": [
        "entry"
      ],
      "status": "not-applicable",
      "reason": "This government identity gateway performs intrinsically online authentication. An offline/installable experience would not permit the core secure task and is not a reasonable requirement."
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "A deliberately invalid route returned a branded denial/error page with clear Back, Home, email and phone recovery actions rather than a blank shell or spinner.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "html lang=\"tr\" is correct, but stylesheet inspection found 28 physical margin-left/right and padding-left/right declarations and no logical-property strategy; dir is unset.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/probe.json",
        "evidence/login-main.css"
      ],
      "findingIds": [
        "F17"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative routes",
      "evidence": "The audited pre-authentication routes render no user-facing dates, currencies, measured values or locale-variable numbers to format.",
      "pathIds": [
        "entry"
      ],
      "status": "not-applicable",
      "reason": "The audited pre-authentication routes render no user-facing dates, currencies, measured values or locale-variable numbers to format."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative routes",
      "evidence": "The audited routes contain no event scheduling or time-zone-sensitive data.",
      "pathIds": [
        "entry"
      ],
      "status": "not-applicable",
      "reason": "The audited routes contain no event scheduling or time-zone-sensitive data."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Four route screenshots show no ads, consent nagging, forced continuity, preselected paid option or confirmshaming; cancel and recovery choices are visible.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Native required-field validation is deferred until reportValidity/submit, focuses the first invalid input and supplies a concrete validation message; empty assertive/polite live regions are available for scripted states.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "The form and both identity/password inputs declare autocomplete=\"off\"; the security copy explicitly tells users to disable browser password saving. The correct tokens would be username and current-password.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/probe.json",
        "evidence/dom-entry.json"
      ],
      "findingIds": [
        "F18"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "The account gateway discloses five authentication methods, provides cancel and password recovery, and contains no pricing, subscription or continuity commitment.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "confidence": "high",
      "method": "Direct artifact/probe evidence matched to the check",
      "evidence": "Lighthouse estimates 121 KiB image-delivery savings. The 709×172 security-board logo is displayed around 148×36 and transfers 76 KB; all four images are PNG with no srcset.",
      "pathIds": [
        "entry"
      ],
      "status": "issues",
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse-selected.json",
        "evidence/network-summary.json"
      ],
      "findingIds": [
        "F19"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Trace/layout recorded no long tasks, HAR contains only 24 requests with no tracker traffic, and no autoplay/background media or idle polling was observed.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "confidence": "high",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "The 395 KB page has no video/audio/autoplay, no known trackers, and its only cross-origin dependency is the affiliated e-devlet CDN; the remaining image waste is isolated under optimised-assets.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative routes",
      "evidence": "A high-risk identity gateway has no declared agent-facing intent; exposing sign-in capabilities to autonomous agents would require an explicit threat model and is not assumed.",
      "pathIds": [
        "entry"
      ],
      "status": "not-applicable",
      "reason": "A high-risk identity gateway has no declared agent-facing intent; exposing sign-in capabilities to autonomous agents would require an explicit threat model and is not assumed."
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "confidence": "high",
      "method": "Recon and applicability judgement across representative routes",
      "evidence": "The deterministic identity and recovery tasks have no justified inference use case; absence of built-in AI is appropriate.",
      "pathIds": [
        "entry"
      ],
      "status": "not-applicable",
      "reason": "The deterministic identity and recovery tasks have no justified inference use case; absence of built-in AI is appropriate."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "confidence": "medium",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Heap comparison after one versus twenty modal open/close cycles grew only 3.0% in self size (4,153,123 to 4,278,093 bytes) and 1.0% in nodes (78,812 to 79,579), consistent with bounded warm-up rather than per-cycle unbounded retention.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "confidence": "medium",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "The warmed twenty-cycle snapshot is 4.28 MB self size with 79,579 nodes for a scripted login form, a proportionate footprint; trace showed no long tasks.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "confidence": "medium",
      "method": "Direct screenshot, DOM, evaluate, Lighthouse, network, layout or heap evidence as applicable",
      "evidence": "Heap summaries contain no Detached* constructor among top retained constructors, and one-to-twenty-cycle growth is small rather than linear; modal wrapper reuse is therefore supported with medium confidence.",
      "pathIds": [
        "entry"
      ],
      "status": "pass"
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F1"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F2"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F3"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F4",
        "F5"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "incomplete",
      "reason": "One check is externally blocked by unavailable personal authentication credentials."
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F6",
        "F7",
        "F8"
      ]
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F20"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F9"
      ]
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F10",
        "F11",
        "F12",
        "F13"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F14",
        "F16",
        "F15"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F17"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F18"
      ]
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F19"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "All checks were judged not applicable to this high-risk deterministic identity gateway."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "pass"
    }
  ],
  "paths": [
    {
      "id": "entry",
      "description": "Primary password sign-in archetype and common shared chrome; tested desktop, mobile, dark, reduced-motion, forced-colors, keyboard focus, validation, performance, network, security and memory.",
      "url": "https://giris.turkiye.gov.tr/Giris/",
      "conditions": [
        "desktop",
        "viewport: 360x800",
        "prefers-color-scheme: dark",
        "prefers-reduced-motion: reduce",
        "forced-colors: active",
        "keyboard-only",
        "blank validation"
      ],
      "result": "issues"
    },
    {
      "id": "esign",
      "description": "Alternative multi-step credential form, CAPTCHA and instructional-content archetype.",
      "url": "https://giris.turkiye.gov.tr/Giris/Elektronik-Imza",
      "conditions": [
        "desktop"
      ],
      "result": "issues"
    },
    {
      "id": "bank",
      "description": "Authentication-provider listing archetype with image links.",
      "url": "https://giris.turkiye.gov.tr/Giris/Banka-Giris",
      "conditions": [
        "desktop"
      ],
      "result": "issues"
    },
    {
      "id": "recovery",
      "description": "Password-recovery journey entry with progress breadcrumb and recovery choices.",
      "url": "https://giris.turkiye.gov.tr/Giris/SifremiUnuttum",
      "conditions": [
        "desktop"
      ],
      "result": "issues"
    },
    {
      "id": "error",
      "description": "Invalid route used to assess HTTP/network failure recovery.",
      "url": "https://giris.turkiye.gov.tr/Giris/this-route-does-not-exist",
      "conditions": [
        "HTTP fetch"
      ],
      "result": "pass"
    }
  ],
  "findings": [
    {
      "id": "F1",
      "severity": "medium",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "guidanceCategory": "user-experience",
      "summary": "The login surface ignores the user’s dark color-scheme preference.",
      "evidence": "The dark-mode screenshot is pixel-identical in palette and file size to the default desktop capture: white page and white form surfaces remain under prefers-color-scheme: dark.",
      "artifacts": [
        "evidence/dark.png",
        "evidence/desktop.png"
      ],
      "suggestedFix": "Declare color-scheme: light dark and use prefers-color-scheme or light-dark() for page, card, text, control and browser-chrome colors.",
      "effort": "small",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F2",
      "severity": "low",
      "principleId": "implement-natural-interactions",
      "principleCheckId": "view-transitions",
      "guidanceId": "cross-document-transitions",
      "guidanceCategory": "user-experience",
      "summary": "Switching authentication methods uses abrupt full-document swaps.",
      "evidence": "DOM/CSS inspection across password, e-signature and bank pages found no view-transition-name or @view-transition rule; the routes are same-origin MPAs with shared chrome.",
      "artifacts": [
        "evidence/dom-entry.json",
        "evidence/login-main.css"
      ],
      "suggestedFix": "Add @view-transition { navigation: auto } and stable view-transition-name values for shared header/navigation/content, with reduced-motion handling.",
      "effort": "small",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F3",
      "severity": "low",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "semantic-dismissible-primitives",
      "guidanceId": "declarative-dialog-popover-control",
      "guidanceCategory": "user-experience",
      "summary": "Informational modals are scripted div overlays triggered by javascript:void links.",
      "evidence": "The modal probe found .mfp-wrap and .ed-modal DIV elements after activation; the DOM contains zero <dialog> and zero popover elements.",
      "artifacts": [
        "evidence/modal-probe.json",
        "evidence/dom-entry.json"
      ],
      "suggestedFix": "Use a native <dialog> for modal information, a button trigger, showModal(), and native close/cancel behavior.",
      "effort": "medium",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F4",
      "severity": "low",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "component-level-responsiveness",
      "guidanceId": "size-aware-styling",
      "guidanceCategory": "user-experience",
      "summary": "Responsive behavior is tied only to page-level breakpoints.",
      "evidence": "The fetched 51 KB stylesheet and runtime probe contain no @container/container-type, even though shared login, navigation and footer components appear across compact and wide layouts.",
      "artifacts": [
        "evidence/login-main.css",
        "evidence/mobile.png",
        "evidence/desktop.png"
      ],
      "suggestedFix": "Give reusable login/navigation components containment and use size container queries for their compact variants, retaining media-query fallbacks as needed.",
      "effort": "medium",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F5",
      "severity": "high",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "input-modality-aware",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "summary": "Keyboard focus is not visibly indicated on most links and navigation controls.",
      "evidence": "The focus probe programmatically focused visible controls: authentication links, help links and footer links computed to outline-style none with no focus-specific box shadow; only inputs and primary buttons exposed an outline.",
      "artifacts": [
        "evidence/probe.json"
      ],
      "suggestedFix": "Add a consistent, high-contrast :focus-visible ring with adequate offset to every interactive element and test a full keyboard focus walk.",
      "effort": "small",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F20",
      "severity": "high",
      "principleId": "be-inclusive",
      "principleCheckId": "structure-and-focus",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "summary": "The keyboard focus indicator is absent on most links in the reading and navigation order.",
      "evidence": "The focus-walk probe shows outline-style none and no focus-specific shadow for authentication links, help links and both footer links, so keyboard users cannot reliably track focus.",
      "artifacts": [
        "evidence/probe.json"
      ],
      "suggestedFix": "Apply an unobscured :focus-visible indicator to links and controls, then verify sequential focus order across each authentication route.",
      "effort": "small",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F6",
      "severity": "medium",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "good-core-web-vitals",
      "guidanceId": "performance",
      "guidanceCategory": "performance",
      "summary": "Lab LCP narrowly misses the good Core Web Vitals threshold.",
      "evidence": "Mobile Lighthouse measured LCP 2,594 ms (good threshold <=2,500 ms) and FCP 2,294 ms; the independent desktop trace measured LCP 1,756 ms, so the issue is condition-sensitive rather than catastrophic.",
      "artifacts": [
        "evidence/lighthouse-summary.json",
        "evidence/trace-summary.json"
      ],
      "suggestedFix": "Reduce document response delay and prioritize only the actual LCP resource; verify on mobile throttling and with field data.",
      "effort": "medium",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F7",
      "severity": "medium",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "efficient-resource-delivery",
      "guidanceId": "optimize-script-priority",
      "guidanceCategory": "performance",
      "summary": "The main document is slow and three classic scripts execute in a parser-ordered body chain.",
      "evidence": "HAR recorded a 1,640 ms document request and three parser-inserted classic body scripts without async/defer; total load was 24 requests and 395,431 transferred bytes.",
      "artifacts": [
        "evidence/network-summary.json",
        "evidence/probe.json",
        "evidence/network.har"
      ],
      "suggestedFix": "Improve origin response time, load noncritical scripts with defer, and verify the encryption handshake remains correctly sequenced.",
      "effort": "medium",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F8",
      "severity": "low",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "trim-unused-and-duplicate-code",
      "guidanceId": "identify-heavy-scripts",
      "guidanceCategory": "performance",
      "summary": "The page ships avoidable unused JavaScript.",
      "evidence": "Lighthouse reports 26 KiB estimated savings in common.1.9.5.js, with 51.8% of its 51,930 bytes unused on the password route.",
      "artifacts": [
        "evidence/lighthouse-selected.json",
        "evidence/lighthouse.json"
      ],
      "suggestedFix": "Split common.js by feature and conditionally load modal/keyboard behaviors only when their triggers are present.",
      "effort": "medium",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F9",
      "severity": "low",
      "principleId": "follow-best-practices",
      "principleCheckId": "sound-document-and-assets",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "summary": "Three images omit intrinsic width and height.",
      "evidence": "The images primitive and Lighthouse identify the main wordmark plus both footer logos without width/height attributes, although observed CLS remained low.",
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse-selected.json",
        "evidence/layout-desktop.json"
      ],
      "suggestedFix": "Add accurate width and height attributes (or aspect-ratio) to reserve image space before CSS sizing.",
      "effort": "trivial",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F10",
      "severity": "medium",
      "principleId": "be-discoverable",
      "principleCheckId": "title-and-description",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "summary": "Distinct authentication and recovery routes all use the generic title “e-Devlet Kapısı”.",
      "evidence": "DOM captures for password, electronic-signature, bank and password-recovery routes all report the same title, despite having different tasks; the shared description is also generic.",
      "artifacts": [
        "evidence/dom-entry.json",
        "evidence/dom-esign.json",
        "evidence/dom-bank.json",
        "evidence/dom-forgot.json"
      ],
      "suggestedFix": "Generate route-specific titles and descriptions such as “e-Devlet Şifresi ile Giriş | e-Devlet Kapısı”.",
      "effort": "small",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F11",
      "severity": "medium",
      "principleId": "be-discoverable",
      "principleCheckId": "crawlable-and-mobile-friendly",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "summary": "Three content actions are non-crawlable javascript:void anchors.",
      "evidence": "Lighthouse SEO flagged pass_detail_btn, pass_help_btn and gizlilik_btn because each uses href=\"javascript:void(0)\".",
      "artifacts": [
        "evidence/lighthouse-binary-failures.json",
        "evidence/dom-entry.json"
      ],
      "suggestedFix": "Use <button type=\"button\"> for dialog triggers; use real href destinations when the content should remain linkable.",
      "effort": "small",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F12",
      "severity": "low",
      "principleId": "be-discoverable",
      "principleCheckId": "canonical-and-indexing-signals",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "summary": "Public authentication routes expose no canonical URL and sitemap discovery is unreliable.",
      "evidence": "The runtime probe found no rel=canonical or hreflang. robots.txt permits the entry route, while /sitemap.xml returned a branded 503 document rather than XML during recon.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/http-recon.txt"
      ],
      "suggestedFix": "Publish self-referencing canonical URLs for indexable route variants and serve a valid sitemap or intentionally document why this authentication host is excluded.",
      "effort": "small",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F13",
      "severity": "low",
      "principleId": "be-discoverable",
      "principleCheckId": "structured-and-shareable-metadata",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "summary": "The identity-service page has no social preview metadata.",
      "evidence": "The DOM probe found zero Open Graph tags and zero JSON-LD blocks across the entry page.",
      "artifacts": [
        "evidence/probe.json"
      ],
      "suggestedFix": "Add accurate og:title, og:description, og:url and og:image tags; structured data is optional unless an applicable schema accurately represents the service.",
      "effort": "small",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F14",
      "severity": "high",
      "principleId": "be-private-and-secure",
      "principleCheckId": "secure-transport-and-headers",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "summary": "The CSP provides little effective XSS containment and session cookies are cross-site enabled.",
      "evidence": "Headers report default-src * with unsafe-inline and unsafe-eval plus data:/blob:. All three Secure/HttpOnly cookies, including JSESSIONID, are SameSite=None. The secrets scanner match was inspected as a jCryption PEM marker and not treated as an exposed key.",
      "artifacts": [
        "evidence/headers.json",
        "evidence/cookies.json",
        "evidence/secrets.json"
      ],
      "suggestedFix": "Replace the wildcard CSP with explicit source directives and nonces/hashes, remove unsafe-eval/unsafe-inline, and use SameSite=Lax or Strict unless a documented federated flow requires None.",
      "effort": "large",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F15",
      "severity": "high",
      "principleId": "be-private-and-secure",
      "principleCheckId": "defensive-browser-policies",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "summary": "Defensive browser policy is weakened by unsafe referrer behavior and missing permission controls.",
      "evidence": "The response sends Referrer-Policy: unsafe-url, omits Permissions-Policy, and relies on X-Frame-Options without a restrictive CSP frame-ancestors directive.",
      "artifacts": [
        "evidence/headers.json",
        "evidence/http-recon.txt"
      ],
      "suggestedFix": "Use strict-origin-when-cross-origin or no-referrer, add a least-privilege Permissions-Policy, and enforce frame-ancestors in the hardened CSP.",
      "effort": "small",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F16",
      "severity": "medium",
      "principleId": "be-private-and-secure",
      "principleCheckId": "in-context-permissions-and-modern-auth",
      "guidanceId": "passkeys",
      "guidanceCategory": "passkeys",
      "summary": "The primary consumer authentication surface offers no phishing-resistant passkey option.",
      "evidence": "The DOM/runtime probe found no WebAuthn or navigator.credentials use. The site offers password, e-signature, bank, mobile-signature and identity-card methods, but not passkeys; no permission prompts fire on load.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/dom-entry.json"
      ],
      "suggestedFix": "Add passkey registration and authentication as an additional first-class method, with secure account recovery and fallback methods.",
      "effort": "large",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F17",
      "severity": "low",
      "principleId": "be-internationalised",
      "principleCheckId": "lang-dir-and-logical-properties",
      "guidanceId": "translator",
      "guidanceCategory": "built-in-ai",
      "summary": "The Turkish document declares language correctly but the shared stylesheet is not writing-mode resilient.",
      "evidence": "html lang=\"tr\" is correct, but stylesheet inspection found 28 physical margin-left/right and padding-left/right declarations and no logical-property strategy; dir is unset.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/login-main.css"
      ],
      "suggestedFix": "Set direction explicitly where needed and replace layout-critical left/right spacing and positioning with inline/block logical properties.",
      "effort": "medium",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F18",
      "severity": "high",
      "principleId": "be-trustworthy",
      "principleCheckId": "trustworthy-input-assistance",
      "guidanceId": "autofill-sign-in-form",
      "guidanceCategory": "forms",
      "summary": "The sign-in form disables autofill and password-manager assistance.",
      "evidence": "The form and both identity/password inputs declare autocomplete=\"off\"; the security copy explicitly tells users to disable browser password saving. The correct tokens would be username and current-password.",
      "artifacts": [
        "evidence/probe.json",
        "evidence/dom-entry.json"
      ],
      "suggestedFix": "Remove form-level autocomplete=off and use autocomplete=\"username\" and \"current-password\". Do not discourage trusted password managers.",
      "effort": "small",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    },
    {
      "id": "F19",
      "severity": "medium",
      "principleId": "be-sustainable",
      "principleCheckId": "optimised-assets",
      "guidanceId": "deliver-optimized-decorative-images",
      "guidanceCategory": "user-experience",
      "summary": "Oversized legacy PNG logos dominate an otherwise small page.",
      "evidence": "Lighthouse estimates 121 KiB image-delivery savings. The 709×172 security-board logo is displayed around 148×36 and transfers 76 KB; all four images are PNG with no srcset.",
      "artifacts": [
        "evidence/images.json",
        "evidence/lighthouse-selected.json",
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Serve appropriately sized SVG/WebP/AVIF variants, add responsive sources where raster assets remain, and avoid loading below-fold logos at oversized resolutions.",
      "effort": "small",
      "confidence": "high",
      "pathId": "entry",
      "url": "https://giris.turkiye.gov.tr/Giris/"
    }
  ],
  "taskList": [
    {
      "id": "T1",
      "title": "Harden CSP, referrer, permissions and cookie policy",
      "priority": 1,
      "findingIds": [
        "F14",
        "F15"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T2",
      "title": "Restore visible keyboard focus everywhere",
      "priority": 2,
      "findingIds": [
        "F5",
        "F20"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T3",
      "title": "Enable safe sign-in assistance and password managers",
      "priority": 3,
      "findingIds": [
        "F18"
      ],
      "guidanceId": "autofill-sign-in-form",
      "status": "open"
    },
    {
      "id": "T4",
      "title": "Add passkey authentication",
      "priority": 4,
      "findingIds": [
        "F16"
      ],
      "guidanceId": "passkeys",
      "status": "open"
    },
    {
      "id": "T5",
      "title": "Improve mobile LCP and resource scheduling",
      "priority": 5,
      "findingIds": [
        "F6",
        "F7",
        "F8"
      ],
      "guidanceId": "performance",
      "status": "open"
    },
    {
      "id": "T6",
      "title": "Give each route unique, crawlable metadata and controls",
      "priority": 6,
      "findingIds": [
        "F10",
        "F11",
        "F12",
        "F13"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T7",
      "title": "Optimize and intrinsically size images",
      "priority": 7,
      "findingIds": [
        "F9",
        "F19"
      ],
      "guidanceId": "deliver-optimized-decorative-images",
      "status": "open"
    },
    {
      "id": "T8",
      "title": "Respect dark theme and modern responsive components",
      "priority": 8,
      "findingIds": [
        "F1",
        "F4"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    },
    {
      "id": "T9",
      "title": "Replace scripted DIV modals and add route transitions",
      "priority": 9,
      "findingIds": [
        "F2",
        "F3"
      ],
      "guidanceId": "declarative-dialog-popover-control",
      "status": "open"
    },
    {
      "id": "T10",
      "title": "Adopt logical CSS properties",
      "priority": 10,
      "findingIds": [
        "F17"
      ],
      "guidanceId": "translator",
      "status": "open"
    }
  ],
  "budget": {
    "pathCount": 5,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-28T00-45-45-705Z"
}
