Manifest position 404 · CrUX rank bucket 1000
https://sso.acesso.gov.br
Coverage complete
Coverage complete for the public, unauthenticated login entry. Authenticated/account routes were excluded because no credentials or test account were supplied.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | The dark-preference screenshot remains a white surface, and computed color-scheme is normal. F-DARK medium: The login page does not follow the system dark theme. |
respect-user-preferencesrespects-reduced-motion | pass | high | The reduced-motion probe matched reduce and found no running animations. |
respect-user-preferencesrespects-contrast | pass | high | The increased-contrast screenshot kept controls and text visible, and the page exposes an explicit high-contrast control. |
implement-natural-interactionsview-transitions | issues | high | The rendered DOM contains accordion/modal state changes, while the animation probe found no animations and source inspection found no transition setup. F-VIEW-TRANSITIONS low: State changes are not enhanced with View Transitions. |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | The page has no scroll-linked animation, parallax or scrollytelling surface. |
implement-natural-interactionsphysical-gestures | not-applicable | high | The authentication entry exposes no swipe, pull, drag or snap gesture interaction. |
provide-guided-navigationscroll-state-aware-chrome | pass | high | The narrow screenshot shows a compact header and complete task card without obstructive sticky chrome. |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip or edge-positioned transient surface was present in the audited entry state. |
provide-guided-navigationdirects-attention | pass | high | The mobile screenshot presents one prominent Continue action followed by clearly separated alternative methods. |
maximize-content-reduce-noiseno-intrusive-interruptions | pass | high | The load screenshots show no interstitial, consent wall or content-obscuring popup. |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | Rendered source loads modal.js and invokes showModal(...) from a button; no dialog or popover element is present. F-SEMANTIC-OVERLAY medium: Bank and QR overlays use custom modal scripting rather than native dialog/popover primitives. |
maximize-content-reduce-noisereduced-chrome | pass | high | The mobile screenshot devotes almost all space below the compact header to authentication content. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | high | Layout metrics at 360px report scrollWidth 360, horizontalOverflowPx 0 and a viewport meta tag. |
adapt-to-the-form-factorcomponent-level-responsiveness | not-applicable | high | The audited single-card component is not demonstrated in multiple container contexts, so container-specific adaptation is not applicable. |
adapt-to-the-form-factorinput-modality-aware | issues | high | The focus probe measured bank buttons around 27px high with outline none, while the primary mobile controls are 40px high. F-INPUT-MODALITY high: Several bank controls are too small and lose visible keyboard focus. |
support-core-task-successclear-purpose-and-primary-action | pass | high | The first viewport states “Identifique-se” and gives a visually dominant Continue button. |
support-core-task-successprimary-flow-completion | pass | high | The unauthenticated step exposes CPF, bank, QR and certificate routes with direct controls and no pre-task upsell. |
support-core-task-successclear-system-state-and-recovery | issues | high | After entering 123 and invoking Continue, aria-invalid remained false and no alert/error text appeared. F-ERRORS high: Invalid CPF input gives no visible or programmatic recovery feedback. |
be-fast-and-stablegood-core-web-vitals | issues | high | Trace measured FCP 11.8s and LCP 13.0s; Lighthouse measured FCP 20.0s and LCP 20.5s on a cold mobile run. F-PERFORMANCE high: The authentication entry is very slow to become visible. |
be-fast-and-stablevisual-stability | pass | high | The narrow layout observer measured CLS 0 with no recorded shifts. |
be-fast-and-stableefficient-main-thread | pass | high | Trace total blocking time was 188.86ms with three bounded long tasks; Lighthouse TBT was 2.5ms. |
be-fast-and-stableefficient-resource-delivery | issues | high | HAR recorded 72 requests and 1.73 MB transferred, including 1.18 MB of scripts and multiple render-blocking stylesheets. F-RESOURCES medium: The simple login journey has a heavy, redirect-rich resource load. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | The HAR identifies a 783,542-byte portal bundle plus challenge, hCaptcha, government-bar, jQuery and other scripts before login. F-DUPLICATE-CODE medium: Large JavaScript dominates the login load. |
be-inclusivenames-roles-labels | issues | high | DOM shows label for="cpf" but the input id is accountId; the probe reports no associated label. F-LABELS high: The visible CPF label is not associated with the CPF input. |
be-inclusivesufficient-contrast | issues | high | Lighthouse reports 4.37:1 for green #008c32 text and the inverse badge, below the 4.5:1 requirement. F-CONTRAST medium: The bank-login option fails minimum text contrast. |
be-inclusivestructure-and-focus | issues | high | The probe found only h3 headings and several bank buttons with outline none; Lighthouse accessibility was 0.73. F-STRUCTURE medium: The page starts its heading hierarchy at h3 and some focusable bank controls have no visible outline. |
be-inclusivelegible-text | pass | high | Desktop and mobile screenshots show readable body text and a coherent single-column narrow layout. |
be-inclusivezoom-reflow-targets-and-media | issues | high | The rendered meta viewport contains maximum-scale=1.0 and user-scalable=0. F-ZOOM high: The viewport explicitly prevents pinch zoom. |
follow-best-practicesno-console-errors | issues | high | Lighthouse records CSP-blocked hCaptcha requests and missing rawline-900 font files. F-CONSOLE medium: The login load emits console and network errors. |
follow-best-practicessound-document-and-assets | issues | high | DOM source shows the main logo and hero image without width/height attributes even though natural dimensions are known. F-ASSETS low: Rendered images omit intrinsic width and height attributes. |
follow-best-practicesbrowser-platform-hygiene | issues | high | Lighthouse flags an unload listener and deprecated Protected Audience API use; the HAR also loads jQuery 2.2.4. F-PLATFORM medium: Deprecated browser behavior and a legacy library remain in the authentication page. |
be-discoverabletitle-and-description | issues | high | The metadata probe and Lighthouse both report a descriptive title but no meta[name=description]. F-META low: The login page has no meta description. |
be-discoverablecrawlable-and-mobile-friendly | not-applicable | high | This is a deliberately gated identity-provider login, so public crawling is not an intended journey. |
be-discoverablecanonical-and-indexing-signals | not-applicable | high | This is a transient authorization login URL and should not be indexed. |
be-discoverablestructured-and-shareable-metadata | not-applicable | high | A transient authentication page is not a rich public entity intended for sharing. |
be-private-and-securesecure-transport-and-headers | issues | high | Cookie evidence shows two TS cookies without Secure/HttpOnly and SameSite=None; the observed CSP allows unsafe-inline and unsafe-eval. F-HEADERS high: Cookie and CSP policy are weaker than expected for an identity provider. |
be-private-and-securedata-minimisation-and-third-parties | pass | high | Tracker inventory found no known analytics trackers, and the secret scan found no exposed credentials. |
be-private-and-securein-context-permissions-and-modern-auth | pass | high | No permission prompt appeared on load; the page offers QR, bank and digital-certificate authentication alternatives. |
be-private-and-securedefensive-browser-policies | issues | high | Header probe did not observe nosniff, Referrer-Policy or Permissions-Policy; CSP uses frame-ancestors but also broad unsafe script allowances. F-DEFENSIVE medium: Several browser defense headers are absent or weak. |
be-resilientprogressive-enhancement | issues | high | Discoverability measured 0% content coverage with an empty #root; the crawler view says only “You need to enable JavaScript”. F-PROGRESSIVE high: The login UI is an empty JavaScript shell for non-JavaScript clients. |
be-resilientresilient-runtime-behaviour | pass | high | The mobile screenshot shows the authentication controls contained within the viewport without clipping or broken state. |
be-resilientoffline-and-installable | not-applicable | high | Authentication is intrinsically online and no installable app behavior is expected for this entry page. |
be-resilientnetwork-and-http-failure-states | issues | high | The robots.txt request returned HTTP 404 and a page containing only “Erro: 404 Not Found” beneath the site header. F-FAILURE medium: The representative 404 response offers no recovery path. |
be-internationalisedlang-dir-and-logical-properties | pass | high | The DOM declares lang="pt-BR" and the Portuguese reading order renders correctly left-to-right. |
be-internationalisedlocale-aware-data | not-applicable | high | The audited login step displays no dates, numbers, currency, durations or calendar data. |
be-internationalisedtime-zone-correctness | not-applicable | high | The audited login step contains no time or event data. |
be-trustworthyno-dark-patterns | pass | high | The login entry shows neutral alternatives, help, terms and privacy links without confirmshaming or forced commercial continuity. |
be-trustworthyhumane-error-handling | issues | high | After entering 123 and invoking Continue, aria-invalid remained false and no alert/error text appeared. F-ERRORS high: Invalid CPF input gives no visible or programmatic recovery feedback. |
be-trustworthytrustworthy-input-assistance | issues | high | The CPF input uses autocomplete="new-password" despite being an account identifier. F-AUTOFILL medium: The CPF sign-in field disables useful identity autofill semantics. |
be-trustworthysafe-commercial-and-account-flows | pass | high | The entry page clearly identifies government sign-in, links terms/privacy/help, and presents proportionate authentication alternatives. |
be-sustainableoptimised-assets | pass | high | The probe found the principal hero image displayed below its natural resolution and compact icon assets at native size. |
be-sustainableno-wasteful-work | pass | high | The trace recorded bounded main-thread work after load and no running animations under the reduced-motion probe. |
be-sustainablethird-party-and-media-budget | issues | high | HAR measured 1.73 MB, 72 requests, 35 images and 827 KB attributed to cross-origin requests before authentication. F-SUSTAINABILITY medium: Resource cost is disproportionate to the first login step. |
be-agent-readystructured-agent-capabilities | not-applicable | high | Exposing autonomous agent tools on a sensitive government sign-in surface is not an evident or safe requirement. |
be-agent-readyon-device-inference | not-applicable | high | The deterministic authentication entry has no appropriate summarization or generative inference use case. |
be-memory-efficientno-leak-under-repeated-interaction | not-applicable | high | No safe, representative repeated interaction can be completed before authentication without submitting identity data; a synthetic loop was not fabricated. |
be-memory-efficientbounded-footprint | pass | high | The post-load heap summary reports 6.5 MB self size for the feature-rich login, a proportionate single-state footprint. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | high | The heap summary contains no Detached* constructor population in its reported constructor set; no accumulation is asserted from a single state. |
Provenance
Canonical report: results/atomic/reports/0404-sso_acesso_gov_br.json
Report SHA-256: 6fd657f34f689ba00a10a56c447aa8747f463f09796b41bcf3beab47b46a9435
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/sso_acesso_gov_br/2026-07-20T13-26-36-809Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/sso_acesso_gov_br/2026-07-20T13-26-36-809Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.