{
  "url": "https://a24.app.gree-pf.net",
  "auditedAt": "2026-07-28T10:02:42.026Z",
  "mode": "report",
  "status": "completed",
  "statusDetail": "Complete atomic audit of the unauthenticated redirect/login surface. Protected post-login game routes were not entered because no credentials were supplied.",
  "page": {
    "appType": "mpa",
    "framework": "Server-rendered HTML with Zepto",
    "notes": "The requested host redirects through five responses to id.gree.net. The representative accessible surface is the GREE authentication gateway."
  },
  "evidenceUsed": [
    "screenshot",
    "DOM",
    "evaluate probes",
    "layout metrics",
    "trace",
    "HAR",
    "discoverability",
    "headers",
    "cookies",
    "trackers",
    "secrets",
    "images",
    "heap summaries",
    "Lighthouse",
    "Modern Web Guidance 0.0.172"
  ],
  "guidanceConsulted": [
    "dark-mode",
    "accessibility",
    "fluid-scaling",
    "forms",
    "performance",
    "security",
    "privacy",
    "optimize-image-priority",
    "break-up-long-tasks",
    "improve-text-layout-and-legibility",
    "declarative-dialog-popover-control",
    "validate-input-after-interaction",
    "webmcp",
    "manage-recurring-intervals",
    "accessible-error-announcement"
  ],
  "artifacts": [
    {
      "type": "screenshot",
      "path": "evidence/desktop.png",
      "caption": "Desktop login surface",
      "condition": "viewport: 1440x900",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile.png",
      "caption": "Responsive mobile login surface",
      "condition": "viewport: 360x800",
      "findingIds": [
        "F02",
        "F08"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/dark.png",
      "caption": "Page under dark preference",
      "condition": "prefers-color-scheme: dark",
      "findingIds": [
        "F01"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/high-contrast.png",
      "caption": "Page under increased contrast preference",
      "condition": "prefers-contrast: more",
      "findingIds": [
        "F02"
      ]
    },
    {
      "type": "layout",
      "path": "evidence/mobile-layout.json",
      "caption": "Mobile layout metrics with zero overflow and CLS",
      "findingIds": []
    },
    {
      "type": "dom",
      "path": "evidence/dom.json",
      "caption": "Rendered final login DOM",
      "findingIds": [
        "F03",
        "F10",
        "F12"
      ]
    },
    {
      "type": "other",
      "path": "evidence/probe.json",
      "caption": "Metadata, semantics, labels, and feature probe",
      "findingIds": [
        "F07",
        "F09",
        "F12",
        "F14",
        "F15"
      ]
    },
    {
      "type": "other",
      "path": "evidence/focus-targets.json",
      "caption": "Keyboard focus and target-size probe",
      "findingIds": [
        "F04",
        "F09"
      ]
    },
    {
      "type": "other",
      "path": "evidence/invalid-submit.json",
      "caption": "Invalid-submit error-state probe",
      "findingIds": [
        "F13"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/invalid-submit.png",
      "caption": "Invalid login submission state",
      "findingIds": [
        "F13"
      ]
    },
    {
      "type": "trace",
      "path": "evidence/load-trace.json",
      "caption": "Raw performance trace",
      "findingIds": []
    },
    {
      "type": "trace-summary",
      "path": "evidence/load-trace-summary.json",
      "caption": "Compact trace summary",
      "findingIds": [
        "F05"
      ]
    },
    {
      "type": "har",
      "path": "evidence/load.har",
      "caption": "Network archive",
      "findingIds": []
    },
    {
      "type": "har-summary",
      "path": "evidence/load-summary.json",
      "caption": "Compact HAR signals",
      "findingIds": [
        "F05"
      ]
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "Lighthouse performance, accessibility, best-practices, and SEO evidence",
      "findingIds": [
        "F05",
        "F06",
        "F07",
        "F08",
        "F09",
        "F10"
      ]
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "Security header inspection",
      "findingIds": [
        "F11"
      ]
    },
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "Cookie inspection",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "Third-party tracker inspection",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "Client secret scan",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "Image audit",
      "findingIds": []
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability.json",
      "caption": "Raw crawler versus rendered discoverability comparison",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-rendered.png",
      "caption": "Rendered discoverability view",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-crawler.png",
      "caption": "Crawler/no-JS view",
      "findingIds": []
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline.heapsnapshot",
      "caption": "Baseline heap summary",
      "findingIds": []
    },
    {
      "type": "heap",
      "path": "evidence/heap-post.heapsnapshot",
      "caption": "Heap after 10 password reveal cycles",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/preferences.json",
      "caption": "Reduced-motion and color-scheme probe",
      "findingIds": [
        "F01"
      ]
    },
    {
      "type": "other",
      "path": "evidence/robots.json",
      "caption": "robots.txt route behavior",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/sitemap.json",
      "caption": "sitemap.xml route behavior",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/guidance-retrieved.txt",
      "caption": "Pinned Modern Web Guidance retrieved for the run",
      "findingIds": []
    }
  ],
  "config": {
    "loaded": false
  },
  "paths": [
    {
      "id": "login",
      "description": "Requested entry URL through its authentication redirect chain; represents the only unauthenticated archetype and core sign-in journey.",
      "url": "https://a24.app.gree-pf.net",
      "conditions": [
        "desktop 1440x900",
        "mobile 360x800",
        "prefers-color-scheme: dark",
        "prefers-contrast: more",
        "prefers-reduced-motion: reduce",
        "keyboard focus"
      ],
      "result": "issues"
    },
    {
      "id": "invalid-login",
      "description": "Submit the login form empty to inspect validation, error messaging, state, and recovery.",
      "url": "https://id.gree.net/",
      "conditions": [
        "invalid form submission"
      ],
      "result": "issues"
    },
    {
      "id": "excluded-protected-routes",
      "description": "Post-authentication game routes were not covered because they require a valid GREE account; the audit does not fabricate credentials.",
      "url": "https://pf.gree.net/24",
      "conditions": [
        "authentication required"
      ],
      "result": "skipped"
    }
  ],
  "findings": [
    {
      "id": "F01",
      "severity": "medium",
      "confidence": "high",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "summary": "No dark color-scheme support",
      "evidence": "The dark-emulated screenshot is pixel-identical to the light capture and the probe reports color-scheme: normal with a light rgb(241,242,243) body.",
      "suggestedFix": "Declare light/dark support at the root and retint surfaces with system-aware color tokens.",
      "effort": "small",
      "artifacts": [
        "evidence/dark.png",
        "evidence/preferences.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F02",
      "severity": "low",
      "confidence": "high",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-contrast",
      "guidanceId": "accessibility",
      "summary": "Contrast preference does not change the presentation",
      "evidence": "The prefers-contrast: more screenshot is visually identical to the default mobile capture, showing no preference-specific adaptation.",
      "suggestedFix": "Use forced-colors-safe system colors and a prefers-contrast treatment for essential controls and links.",
      "effort": "small",
      "artifacts": [
        "evidence/high-contrast.png",
        "evidence/mobile.png"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F03",
      "severity": "low",
      "confidence": "high",
      "principleId": "implement-natural-interactions",
      "principleCheckId": "view-transitions",
      "guidanceId": "performance",
      "summary": "Navigation swaps are abrupt",
      "evidence": "The server-rendered login and registration/password-reset routes use ordinary full-document navigation with no view-transition declaration in the captured DOM.",
      "suggestedFix": "Add a conservative cross-document View Transition for same-origin auth route changes, disabled under reduced motion.",
      "effort": "medium",
      "artifacts": [
        "evidence/dom.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F04",
      "severity": "high",
      "confidence": "high",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "input-modality-aware",
      "guidanceId": "accessibility",
      "summary": "Keyboard focus is not visible on the two primary inputs",
      "evidence": "The focus probe reports outline none and box-shadow none for both email and password inputs; several text links are only 16px tall.",
      "suggestedFix": "Add a high-contrast :focus-visible ring and enlarge compact link hit areas to at least 24 CSS px, preferably 44px for touch.",
      "effort": "small",
      "artifacts": [
        "evidence/focus-targets.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F05",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "good-core-web-vitals",
      "guidanceId": "performance",
      "summary": "Redirect chain makes first paint very slow",
      "evidence": "Lighthouse measured FCP/LCP at 7.6s and the trace measured LCP at 4995ms. Five redirects add about 5.38s before the final login page.",
      "suggestedFix": "Collapse the authentication redirect chain and send unauthenticated users directly to the canonical login endpoint.",
      "effort": "medium",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/load-trace-summary.json",
        "evidence/load-summary.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F06",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "trim-unused-and-duplicate-code",
      "guidanceId": "break-up-long-tasks",
      "summary": "Most of the page stylesheet is unused",
      "evidence": "Lighthouse reports 15,156 bytes, 92.99%, of reg.css unused on this small login page.",
      "suggestedFix": "Split critical login styles from the broad registration bundle and load only styles needed by this route.",
      "effort": "small",
      "artifacts": [
        "evidence/lighthouse.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F07",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-inclusive",
      "principleCheckId": "names-roles-labels",
      "guidanceId": "accessibility",
      "summary": "Core authentication controls lack accessible names and labels",
      "evidence": "Both visible inputs have no associated label. Lighthouse also identifies two icon-only provider buttons and one icon-only help link with no accessible name.",
      "suggestedFix": "Add persistent label elements, accessible names for provider buttons/help link, and an accessible name/state for the password visibility control.",
      "effort": "small",
      "artifacts": [
        "evidence/probe.json",
        "evidence/lighthouse.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F08",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-inclusive",
      "principleCheckId": "sufficient-contrast",
      "guidanceId": "accessibility",
      "summary": "Important links and secondary action text fail WCAG contrast",
      "evidence": "Lighthouse measured ratios from 3.16:1 to 3.64:1 for password reset, help/contact links, and the app-login label, below 4.5:1.",
      "suggestedFix": "Darken the blue and gray text tokens to meet 4.5:1 in every surface state.",
      "effort": "small",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/mobile.png"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F09",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-inclusive",
      "principleCheckId": "structure-and-focus",
      "guidanceId": "accessibility",
      "summary": "The page has no main landmark",
      "evidence": "The DOM probe finds header, footer, and nav but no main; Lighthouse fails landmark-one-main. Input focus styling is also absent.",
      "suggestedFix": "Wrap the authentication content in main and apply consistent :focus-visible styles.",
      "effort": "trivial",
      "artifacts": [
        "evidence/probe.json",
        "evidence/focus-targets.json",
        "evidence/lighthouse.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F10",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-inclusive",
      "principleCheckId": "zoom-reflow-targets-and-media",
      "guidanceId": "fluid-scaling",
      "summary": "Mobile zoom is explicitly disabled",
      "evidence": "The viewport meta contains maximum-scale=1 and user-scalable=0; Lighthouse flags this as preventing low-vision users from magnifying content.",
      "suggestedFix": "Remove maximum-scale and user-scalable restrictions, retaining width=device-width and initial-scale=1.",
      "effort": "trivial",
      "artifacts": [
        "evidence/dom.json",
        "evidence/lighthouse.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F11",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-private-and-secure",
      "principleCheckId": "secure-transport-and-headers",
      "guidanceId": "security",
      "summary": "Browser security headers are absent",
      "evidence": "The headers primitive found no CSP, HSTS, nosniff, clickjacking protection, Referrer-Policy, or Permissions-Policy on the audited entry response.",
      "suggestedFix": "Set HSTS, a nonce/hash-based CSP including frame-ancestors, nosniff, strict referrer policy, and a least-privilege Permissions-Policy across every redirect and final response.",
      "effort": "medium",
      "artifacts": [
        "evidence/headers.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F12",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-private-and-secure",
      "principleCheckId": "in-context-permissions-and-modern-auth",
      "guidanceId": "security",
      "summary": "Password-only authentication lacks a phishing-resistant option",
      "evidence": "The login DOM exposes email/password and federated buttons but no WebAuthn/passkey capability; the page is an authentication surface where passkeys are relevant.",
      "suggestedFix": "Offer passkey sign-in and registration alongside account recovery, with password remaining as a fallback during migration.",
      "effort": "large",
      "artifacts": [
        "evidence/dom.json",
        "evidence/probe.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F13",
      "severity": "medium",
      "confidence": "high",
      "principleId": "be-trustworthy",
      "principleCheckId": "humane-error-handling",
      "guidanceId": "accessible-error-announcement",
      "summary": "Server errors are visible but not programmatically announced",
      "evidence": "Empty submission returns clear Japanese errors, but the probe finds no role=alert messages and fields are not marked aria-invalid.",
      "suggestedFix": "Associate each error with its field, toggle aria-invalid after submission, and announce the error summary through a live region.",
      "effort": "small",
      "artifacts": [
        "evidence/invalid-submit.json",
        "evidence/invalid-submit.png"
      ],
      "pathId": "invalid-login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F14",
      "severity": "high",
      "confidence": "high",
      "principleId": "be-trustworthy",
      "principleCheckId": "trustworthy-input-assistance",
      "guidanceId": "forms",
      "summary": "Login fields omit labels and autocomplete tokens",
      "evidence": "The visible email and password inputs have no labels and autocomplete is empty, preventing reliable password-manager and autofill assistance.",
      "suggestedFix": "Use explicit labels and autocomplete=username and autocomplete=current-password.",
      "effort": "trivial",
      "artifacts": [
        "evidence/probe.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    },
    {
      "id": "F15",
      "severity": "low",
      "confidence": "high",
      "principleId": "be-discoverable",
      "principleCheckId": "title-and-description",
      "guidanceId": "accessibility",
      "summary": "Document metadata is generic",
      "evidence": "The final login document title is only “gree.net” and its description is only “GREE”, which does not identify the login task.",
      "suggestedFix": "Use a task-specific Japanese title and description, such as “GREE ログイン”.",
      "effort": "trivial",
      "artifacts": [
        "evidence/probe.json"
      ],
      "pathId": "login",
      "url": "https://a24.app.gree-pf.net"
    }
  ],
  "taskList": [
    {
      "id": "T1",
      "title": "Make the login form accessible and autofill-friendly",
      "priority": 1,
      "findingIds": [
        "F04",
        "F07",
        "F08",
        "F09",
        "F10",
        "F13",
        "F14"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T2",
      "title": "Collapse the five-hop authentication redirect chain",
      "priority": 2,
      "findingIds": [
        "F05"
      ],
      "guidanceId": "performance",
      "status": "open"
    },
    {
      "id": "T3",
      "title": "Deploy browser-enforced security headers on every hop",
      "priority": 3,
      "findingIds": [
        "F11"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T4",
      "title": "Add a passkey authentication path",
      "priority": 4,
      "findingIds": [
        "F12"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T5",
      "title": "Add adaptive dark and contrast themes",
      "priority": 5,
      "findingIds": [
        "F01",
        "F02"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    },
    {
      "id": "T6",
      "title": "Trim route-specific CSS",
      "priority": 6,
      "findingIds": [
        "F06"
      ],
      "guidanceId": "break-up-long-tasks",
      "status": "open"
    },
    {
      "id": "T7",
      "title": "Use task-specific metadata and restrained route transitions",
      "priority": 7,
      "findingIds": [
        "F03",
        "F15"
      ],
      "guidanceId": "performance",
      "status": "open"
    }
  ],
  "budget": {
    "pathCount": 2,
    "auditPasses": 1
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 58,
    "blocked": 0,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": true
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The dark-emulated screenshot is pixel-identical to the light capture and the probe reports color-scheme: normal with a light rgb(241,242,243) body.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dark.png",
        "evidence/preferences.json"
      ],
      "findingIds": [
        "F01"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "Reduced-motion emulation was active and document.getAnimations() returned an empty list, so no non-essential motion persisted.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "status": "issues",
      "confidence": "high",
      "method": "Lighthouse, DOM probe, focus probe, and screenshots",
      "evidence": "The prefers-contrast: more screenshot is visually identical to the default mobile capture, showing no preference-specific adaptation.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/high-contrast.png",
        "evidence/mobile.png"
      ],
      "findingIds": [
        "F02"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The server-rendered login and registration/password-reset routes use ordinary full-document navigation with no view-transition declaration in the captured DOM.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ],
      "findingIds": [
        "F03"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "DOM/CSS inspection and the static screenshot show no scroll-linked animation or JS scrollytelling behavior.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The form uses native scrolling and controls; no custom pointer gesture or platform-fighting interaction was present.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The single-viewport mobile form has no sticky chrome or scroll-dependent state that obscures orientation.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and DOM/content applicability review",
      "evidence": "The audited login page exposes no tooltip, popover, or menu that requires anchored positioning.",
      "reason": "The audited login page exposes no tooltip, popover, or menu that requires anchored positioning."
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "Screenshots show a direct top-to-bottom hierarchy from email login to alternatives, recovery, and registration.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "Initial desktop and mobile screenshots contain no popup, interstitial, consent wall, or content-obscuring banner.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and DOM/content applicability review",
      "evidence": "No overlay, disclosure, picker, or transient rich control is present on this page.",
      "reason": "No overlay, disclosure, picker, or transient rich control is present on this page."
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The first viewport is dominated by the login form with restrained header/footer chrome.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "At 360x800, layout reports scrollWidth=clientWidth=360 and zero horizontal overflow.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "Desktop and mobile captures show the same form fluidly resizing from a centered max-width panel to the viewport without clipping.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The focus probe reports outline none and box-shadow none for both email and password inputs; several text links are only 16px tall.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/focus-targets.json"
      ],
      "findingIds": [
        "F04"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The first viewport clearly labels email login and presents a prominent login button, with recovery and registration alternatives.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The authentication form submits to the identity endpoint and an invalid attempt returns field-specific feedback without a dead end.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "Empty submission returns clear Japanese errors, but the probe finds no role=alert messages and fields are not marked aria-invalid.",
      "pathIds": [
        "invalid-login"
      ],
      "artifacts": [
        "evidence/invalid-submit.json",
        "evidence/invalid-submit.png"
      ],
      "findingIds": [
        "F13"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "status": "issues",
      "confidence": "high",
      "method": "trace, HAR, and Lighthouse",
      "evidence": "Lighthouse measured FCP/LCP at 7.6s and the trace measured LCP at 4995ms. Five redirects add about 5.38s before the final login page.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/load-trace-summary.json",
        "evidence/load-summary.json"
      ],
      "findingIds": [
        "F05"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "status": "pass",
      "confidence": "medium",
      "method": "trace, HAR, and Lighthouse",
      "evidence": "The layout observer recorded CLS 0 with no shift entries.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/mobile-layout.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "status": "pass",
      "confidence": "medium",
      "method": "trace, HAR, and Lighthouse",
      "evidence": "The trace recorded zero long tasks and 0ms total blocking time.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/load-trace-summary.json"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "status": "issues",
      "confidence": "high",
      "method": "trace, HAR, and Lighthouse",
      "evidence": "Lighthouse measured FCP/LCP at 7.6s and the trace measured LCP at 4995ms. Five redirects add about 5.38s before the final login page.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/load-trace-summary.json",
        "evidence/load-summary.json"
      ],
      "findingIds": [
        "F05"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "status": "issues",
      "confidence": "high",
      "method": "trace, HAR, and Lighthouse",
      "evidence": "Lighthouse reports 15,156 bytes, 92.99%, of reg.css unused on this small login page.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F06"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "status": "issues",
      "confidence": "high",
      "method": "Lighthouse, DOM probe, focus probe, and screenshots",
      "evidence": "Both visible inputs have no associated label. Lighthouse also identifies two icon-only provider buttons and one icon-only help link with no accessible name.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F07"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "status": "issues",
      "confidence": "high",
      "method": "Lighthouse, DOM probe, focus probe, and screenshots",
      "evidence": "Lighthouse measured ratios from 3.16:1 to 3.64:1 for password reset, help/contact links, and the app-login label, below 4.5:1.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/mobile.png"
      ],
      "findingIds": [
        "F08"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "status": "issues",
      "confidence": "high",
      "method": "Lighthouse, DOM probe, focus probe, and screenshots",
      "evidence": "The DOM probe finds header, footer, and nav but no main; Lighthouse fails landmark-one-main. Input focus styling is also absent.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json",
        "evidence/focus-targets.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F09"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "status": "pass",
      "confidence": "medium",
      "method": "Lighthouse, DOM probe, focus probe, and screenshots",
      "evidence": "Desktop and mobile screenshots show unclipped Japanese text, readable line lengths, and stable wrapping.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "status": "issues",
      "confidence": "high",
      "method": "Lighthouse, DOM probe, focus probe, and screenshots",
      "evidence": "The viewport meta contains maximum-scale=1 and user-scalable=0; Lighthouse flags this as preventing low-vision users from magnifying content.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json",
        "evidence/lighthouse.json"
      ],
      "findingIds": [
        "F10"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "Lighthouse best-practices scored 1.0 and did not report console errors or uncaught exceptions.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "DOM inspection confirms HTML doctype, UTF-8 charset, viewport metadata, and no img elements with sizing/aspect-ratio defects.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "Lighthouse best-practices scored 1.0; no notification/geolocation prompt, paste prevention, or visible runtime failure occurred.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The final login document title is only “gree.net” and its description is only “GREE”, which does not identify the login task.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F15"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and DOM/content applicability review",
      "evidence": "The requested application is deliberately gated by authentication, so public crawling of the protected route is not applicable; mobile viewport behavior is judged elsewhere.",
      "reason": "The requested application is deliberately gated by authentication, so public crawling of the protected route is not applicable; mobile viewport behavior is judged elsewhere."
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and DOM/content applicability review",
      "evidence": "The protected application route redirects to authentication and is not intended as an indexable public page.",
      "reason": "The protected application route redirects to authentication and is not intended as an indexable public page."
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and DOM/content applicability review",
      "evidence": "The authentication page is not an article, product, event, or other rich public entity.",
      "reason": "The authentication page is not an article, product, event, or other rich public entity."
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "status": "issues",
      "confidence": "high",
      "method": "headers, cookies, trackers, secrets, and HAR",
      "evidence": "The headers primitive found no CSP, HSTS, nosniff, clickjacking protection, Referrer-Policy, or Permissions-Policy on the audited entry response.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F11"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "status": "pass",
      "confidence": "medium",
      "method": "headers, cookies, trackers, secrets, and HAR",
      "evidence": "Tracker scan found no known trackers, cookies found no stored cookies, and the HAR traffic is limited to GREE identity/application domains.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "status": "issues",
      "confidence": "high",
      "method": "headers, cookies, trackers, secrets, and HAR",
      "evidence": "The login DOM exposes email/password and federated buttons but no WebAuthn/passkey capability; the page is an authentication surface where passkeys are relevant.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "status": "issues",
      "confidence": "high",
      "method": "headers, cookies, trackers, secrets, and HAR",
      "evidence": "The headers primitive found no CSP, HSTS, nosniff, clickjacking protection, Referrer-Policy, or Permissions-Policy on the audited entry response.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/headers.json"
      ],
      "findingIds": [
        "F11"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The final login form is server-rendered HTML and invalid submission is handled by a normal POST response; core credential entry does not depend on SPA rendering.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The responsive form contains no overlays or fragile async widgets; password reveal repeated reliably ten times.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and DOM/content applicability review",
      "evidence": "This authentication gateway intrinsically requires a live identity service; installability and offline login are not meaningful.",
      "reason": "This authentication gateway intrinsically requires a live identity service; installability and offline login are not meaningful."
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "Invalid authentication input returns a complete page with clear recovery links rather than a blank shell or infinite spinner.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The document declares lang=ja and the simple vertical form retains correct reading order and alignment at both viewports.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and DOM/content applicability review",
      "evidence": "No user-visible date, number, currency, duration, or calendar data appears on the audited login surface.",
      "reason": "No user-visible date, number, currency, duration, or calendar data appears on the audited login surface."
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and DOM/content applicability review",
      "evidence": "No user-visible event or time value appears on the audited login surface.",
      "reason": "No user-visible event or time value appears on the audited login surface."
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The screenshots show clear login, recovery, provider, and registration options without forced consent, disguised advertising, or confirmshaming.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "Empty submission returns clear Japanese errors, but the probe finds no role=alert messages and fields are not marked aria-invalid.",
      "pathIds": [
        "invalid-login"
      ],
      "artifacts": [
        "evidence/invalid-submit.json",
        "evidence/invalid-submit.png"
      ],
      "findingIds": [
        "F13"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The visible email and password inputs have no labels and autocomplete is empty, preventing reliable password-manager and autofill assistance.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/probe.json"
      ],
      "findingIds": [
        "F14"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "status": "issues",
      "confidence": "high",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The login DOM exposes email/password and federated buttons but no WebAuthn/passkey capability; the page is an authentication surface where passkeys are relevant.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json",
        "evidence/probe.json"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The images primitive finds no img defects; total transfer is only 85,463 bytes and sprite assets are proportionate to the compact branded form.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "status": "pass",
      "confidence": "medium",
      "method": "DOM/evaluate probes and condition screenshots",
      "evidence": "The trace records no long tasks and the HAR shows only 15 load requests with no tracking or background media.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "status": "pass",
      "confidence": "medium",
      "method": "headers, cookies, trackers, secrets, and HAR",
      "evidence": "No audio/video/autoplay or known trackers are present; total transferred bytes are 85,463 and all named origins belong to the GREE flow.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/dom.json"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and DOM/content applicability review",
      "evidence": "This credential-entry gateway has no declared agent-facing capability and safely exposing authentication actions to generic agents is not an established requirement.",
      "reason": "This credential-entry gateway has no declared agent-facing capability and safely exposing authentication actions to generic agents is not an established requirement."
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "status": "not-applicable",
      "confidence": "high",
      "method": "Recon and DOM/content applicability review",
      "evidence": "The short login form has no summarisation, generation, or inference task where on-device AI would improve the experience.",
      "reason": "The short login form has no summarisation, generation, or inference task where on-device AI would improve the experience."
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "status": "pass",
      "confidence": "medium",
      "method": "heap baseline/post comparison",
      "evidence": "After 10 password reveal/hide cycles, heap self size increased only 21,133 bytes (0.91%) in fresh comparable sessions, with no unbounded-growth signal.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/heap-baseline.heapsnapshot",
        "evidence/heap-post.heapsnapshot"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "status": "pass",
      "confidence": "medium",
      "method": "heap baseline/post comparison",
      "evidence": "The post-interaction heap is about 2.35 MB self size with 52,552 nodes, proportionate to this small server-rendered form.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/heap-baseline.heapsnapshot",
        "evidence/heap-post.heapsnapshot"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "status": "pass",
      "confidence": "medium",
      "method": "heap baseline/post comparison",
      "evidence": "Before/post heap summaries show only a small bounded delta and no Detached* constructor among top retained constructors after repeated toggling.",
      "pathIds": [
        "login"
      ],
      "artifacts": [
        "evidence/heap-baseline.heapsnapshot",
        "evidence/heap-post.heapsnapshot"
      ]
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F01",
        "F02"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F03"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F04"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F13"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F05",
        "F06"
      ]
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F07",
        "F08",
        "F09",
        "F10"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "pass"
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F15"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F11",
        "F12"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F13",
        "F14",
        "F12"
      ]
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "The audited gated login surface has no applicable agent-facing capability or on-device inference use case."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "pass"
    }
  ],
  "agent": "pi",
  "runId": "2026-07-28T10-02-42-026Z"
}
