Manifest position 404 · CrUX rank bucket 1000

https://sso.acesso.gov.br

Coverage complete

Coverage complete for the public, unauthenticated login entry. Authenticated/account routes were excluded because no credentials or test account were supplied.

Attempts
1 / 3
Judged checks
58 / 58
Blocked
0
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighThe dark-preference screenshot remains a white surface, and computed color-scheme is normal.
F-DARK medium: The login page does not follow the system dark theme.
respect-user-preferences
respects-reduced-motion
passhighThe reduced-motion probe matched reduce and found no running animations.
respect-user-preferences
respects-contrast
passhighThe increased-contrast screenshot kept controls and text visible, and the page exposes an explicit high-contrast control.
implement-natural-interactions
view-transitions
issueshighThe rendered DOM contains accordion/modal state changes, while the animation probe found no animations and source inspection found no transition setup.
F-VIEW-TRANSITIONS low: State changes are not enhanced with View Transitions.
implement-natural-interactions
scroll-driven-animations
not-applicablehighThe page has no scroll-linked animation, parallax or scrollytelling surface.
implement-natural-interactions
physical-gestures
not-applicablehighThe authentication entry exposes no swipe, pull, drag or snap gesture interaction.
provide-guided-navigation
scroll-state-aware-chrome
passhighThe narrow screenshot shows a compact header and complete task card without obstructive sticky chrome.
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip or edge-positioned transient surface was present in the audited entry state.
provide-guided-navigation
directs-attention
passhighThe mobile screenshot presents one prominent Continue action followed by clearly separated alternative methods.
maximize-content-reduce-noise
no-intrusive-interruptions
passhighThe load screenshots show no interstitial, consent wall or content-obscuring popup.
maximize-content-reduce-noise
semantic-dismissible-primitives
issueshighRendered source loads modal.js and invokes showModal(...) from a button; no dialog or popover element is present.
F-SEMANTIC-OVERLAY medium: Bank and QR overlays use custom modal scripting rather than native dialog/popover primitives.
maximize-content-reduce-noise
reduced-chrome
passhighThe mobile screenshot devotes almost all space below the compact header to authentication content.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighLayout metrics at 360px report scrollWidth 360, horizontalOverflowPx 0 and a viewport meta tag.
adapt-to-the-form-factor
component-level-responsiveness
not-applicablehighThe audited single-card component is not demonstrated in multiple container contexts, so container-specific adaptation is not applicable.
adapt-to-the-form-factor
input-modality-aware
issueshighThe focus probe measured bank buttons around 27px high with outline none, while the primary mobile controls are 40px high.
F-INPUT-MODALITY high: Several bank controls are too small and lose visible keyboard focus.
support-core-task-success
clear-purpose-and-primary-action
passhighThe first viewport states “Identifique-se” and gives a visually dominant Continue button.
support-core-task-success
primary-flow-completion
passhighThe unauthenticated step exposes CPF, bank, QR and certificate routes with direct controls and no pre-task upsell.
support-core-task-success
clear-system-state-and-recovery
issueshighAfter entering 123 and invoking Continue, aria-invalid remained false and no alert/error text appeared.
F-ERRORS high: Invalid CPF input gives no visible or programmatic recovery feedback.
be-fast-and-stable
good-core-web-vitals
issueshighTrace measured FCP 11.8s and LCP 13.0s; Lighthouse measured FCP 20.0s and LCP 20.5s on a cold mobile run.
F-PERFORMANCE high: The authentication entry is very slow to become visible.
be-fast-and-stable
visual-stability
passhighThe narrow layout observer measured CLS 0 with no recorded shifts.
be-fast-and-stable
efficient-main-thread
passhighTrace total blocking time was 188.86ms with three bounded long tasks; Lighthouse TBT was 2.5ms.
be-fast-and-stable
efficient-resource-delivery
issueshighHAR recorded 72 requests and 1.73 MB transferred, including 1.18 MB of scripts and multiple render-blocking stylesheets.
F-RESOURCES medium: The simple login journey has a heavy, redirect-rich resource load.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighThe HAR identifies a 783,542-byte portal bundle plus challenge, hCaptcha, government-bar, jQuery and other scripts before login.
F-DUPLICATE-CODE medium: Large JavaScript dominates the login load.
be-inclusive
names-roles-labels
issueshighDOM shows label for="cpf" but the input id is accountId; the probe reports no associated label.
F-LABELS high: The visible CPF label is not associated with the CPF input.
be-inclusive
sufficient-contrast
issueshighLighthouse reports 4.37:1 for green #008c32 text and the inverse badge, below the 4.5:1 requirement.
F-CONTRAST medium: The bank-login option fails minimum text contrast.
be-inclusive
structure-and-focus
issueshighThe probe found only h3 headings and several bank buttons with outline none; Lighthouse accessibility was 0.73.
F-STRUCTURE medium: The page starts its heading hierarchy at h3 and some focusable bank controls have no visible outline.
be-inclusive
legible-text
passhighDesktop and mobile screenshots show readable body text and a coherent single-column narrow layout.
be-inclusive
zoom-reflow-targets-and-media
issueshighThe rendered meta viewport contains maximum-scale=1.0 and user-scalable=0.
F-ZOOM high: The viewport explicitly prevents pinch zoom.
follow-best-practices
no-console-errors
issueshighLighthouse records CSP-blocked hCaptcha requests and missing rawline-900 font files.
F-CONSOLE medium: The login load emits console and network errors.
follow-best-practices
sound-document-and-assets
issueshighDOM source shows the main logo and hero image without width/height attributes even though natural dimensions are known.
F-ASSETS low: Rendered images omit intrinsic width and height attributes.
follow-best-practices
browser-platform-hygiene
issueshighLighthouse flags an unload listener and deprecated Protected Audience API use; the HAR also loads jQuery 2.2.4.
F-PLATFORM medium: Deprecated browser behavior and a legacy library remain in the authentication page.
be-discoverable
title-and-description
issueshighThe metadata probe and Lighthouse both report a descriptive title but no meta[name=description].
F-META low: The login page has no meta description.
be-discoverable
crawlable-and-mobile-friendly
not-applicablehighThis is a deliberately gated identity-provider login, so public crawling is not an intended journey.
be-discoverable
canonical-and-indexing-signals
not-applicablehighThis is a transient authorization login URL and should not be indexed.
be-discoverable
structured-and-shareable-metadata
not-applicablehighA transient authentication page is not a rich public entity intended for sharing.
be-private-and-secure
secure-transport-and-headers
issueshighCookie evidence shows two TS cookies without Secure/HttpOnly and SameSite=None; the observed CSP allows unsafe-inline and unsafe-eval.
F-HEADERS high: Cookie and CSP policy are weaker than expected for an identity provider.
be-private-and-secure
data-minimisation-and-third-parties
passhighTracker inventory found no known analytics trackers, and the secret scan found no exposed credentials.
be-private-and-secure
in-context-permissions-and-modern-auth
passhighNo permission prompt appeared on load; the page offers QR, bank and digital-certificate authentication alternatives.
be-private-and-secure
defensive-browser-policies
issueshighHeader probe did not observe nosniff, Referrer-Policy or Permissions-Policy; CSP uses frame-ancestors but also broad unsafe script allowances.
F-DEFENSIVE medium: Several browser defense headers are absent or weak.
be-resilient
progressive-enhancement
issueshighDiscoverability measured 0% content coverage with an empty #root; the crawler view says only “You need to enable JavaScript”.
F-PROGRESSIVE high: The login UI is an empty JavaScript shell for non-JavaScript clients.
be-resilient
resilient-runtime-behaviour
passhighThe mobile screenshot shows the authentication controls contained within the viewport without clipping or broken state.
be-resilient
offline-and-installable
not-applicablehighAuthentication is intrinsically online and no installable app behavior is expected for this entry page.
be-resilient
network-and-http-failure-states
issueshighThe robots.txt request returned HTTP 404 and a page containing only “Erro: 404 Not Found” beneath the site header.
F-FAILURE medium: The representative 404 response offers no recovery path.
be-internationalised
lang-dir-and-logical-properties
passhighThe DOM declares lang="pt-BR" and the Portuguese reading order renders correctly left-to-right.
be-internationalised
locale-aware-data
not-applicablehighThe audited login step displays no dates, numbers, currency, durations or calendar data.
be-internationalised
time-zone-correctness
not-applicablehighThe audited login step contains no time or event data.
be-trustworthy
no-dark-patterns
passhighThe login entry shows neutral alternatives, help, terms and privacy links without confirmshaming or forced commercial continuity.
be-trustworthy
humane-error-handling
issueshighAfter entering 123 and invoking Continue, aria-invalid remained false and no alert/error text appeared.
F-ERRORS high: Invalid CPF input gives no visible or programmatic recovery feedback.
be-trustworthy
trustworthy-input-assistance
issueshighThe CPF input uses autocomplete="new-password" despite being an account identifier.
F-AUTOFILL medium: The CPF sign-in field disables useful identity autofill semantics.
be-trustworthy
safe-commercial-and-account-flows
passhighThe entry page clearly identifies government sign-in, links terms/privacy/help, and presents proportionate authentication alternatives.
be-sustainable
optimised-assets
passhighThe probe found the principal hero image displayed below its natural resolution and compact icon assets at native size.
be-sustainable
no-wasteful-work
passhighThe trace recorded bounded main-thread work after load and no running animations under the reduced-motion probe.
be-sustainable
third-party-and-media-budget
issueshighHAR measured 1.73 MB, 72 requests, 35 images and 827 KB attributed to cross-origin requests before authentication.
F-SUSTAINABILITY medium: Resource cost is disproportionate to the first login step.
be-agent-ready
structured-agent-capabilities
not-applicablehighExposing autonomous agent tools on a sensitive government sign-in surface is not an evident or safe requirement.
be-agent-ready
on-device-inference
not-applicablehighThe deterministic authentication entry has no appropriate summarization or generative inference use case.
be-memory-efficient
no-leak-under-repeated-interaction
not-applicablehighNo safe, representative repeated interaction can be completed before authentication without submitting identity data; a synthetic loop was not fabricated.
be-memory-efficient
bounded-footprint
passhighThe post-load heap summary reports 6.5 MB self size for the feature-rich login, a proportionate single-state footprint.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passhighThe heap summary contains no Detached* constructor population in its reported constructor set; no accumulation is asserted from a single state.

Provenance

Canonical report: results/atomic/reports/0404-sso_acesso_gov_br.json
Report SHA-256: 6fd657f34f689ba00a10a56c447aa8747f463f09796b41bcf3beab47b46a9435
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/sso_acesso_gov_br/2026-07-20T13-26-36-809Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/sso_acesso_gov_br/2026-07-20T13-26-36-809Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.