Manifest position 494 · CrUX rank bucket 1000

https://giris.turkiye.gov.tr

Partial after retries

57 of 58 checks judged. End-to-end primary authentication is blocked by unavailable personal credentials; no score is published.

Attempts
3 / 3
Judged checks
57 / 58
Blocked
1
Not run
0
This report has no published overall score. Blocked and not-run checks are not passes. A coverage-complete report means every check has a judged outcome; it does not mean every check passed.

All 58 atomic check outcomes

Principle / checkStatusConfidenceEvidence or reason
respect-user-preferences
respects-color-scheme
issueshighThe dark-mode screenshot is pixel-identical in palette and file size to the default desktop capture: white page and white form surfaces remain under prefers-color-scheme: dark.
F1 medium: The login surface ignores the user’s dark color-scheme preference.
respect-user-preferences
respects-reduced-motion
passhighReduced-motion emulation was active; document.getAnimations() returned zero animations across the entry surface, so no non-essential motion or auto-advance remains to suppress.
respect-user-preferences
respects-contrast
passhighThe forced-colors/high-contrast screenshot keeps body text, inputs, buttons, borders, selected navigation and links distinguishable; Lighthouse color contrast also passed.
implement-natural-interactions
view-transitions
issueshighDOM/CSS inspection across password, e-signature and bank pages found no view-transition-name or @view-transition rule; the routes are same-origin MPAs with shared chrome.
F2 low: Switching authentication methods uses abrupt full-document swaps.
implement-natural-interactions
scroll-driven-animations
not-applicablehighNo scroll-linked animation, parallax, reveal or carousel behavior exists on the representative login/recovery routes, so there is no scroll animation implementation to assess.
implement-natural-interactions
physical-gestures
not-applicablehighThe routes expose conventional forms and links but no gesture-driven interaction, pull/swipe action or snap-scrolling surface.
provide-guided-navigation
scroll-state-aware-chrome
not-applicablehighThe short login page has no persistent scrolled chrome or long-content navigation state requiring scroll-aware adaptation.
provide-guided-navigation
anchored-positioning
not-applicablehighNo tooltip, anchored popover or edge-positioned menu was present; the only overlay is a centered modal assessed under semantic primitives.
provide-guided-navigation
directs-attention
passhighDesktop/mobile screenshots show the selected authentication method prominently; the recovery route provides a seven-step breadcrumb and clearly highlighted current step.
maximize-content-reduce-noise
no-intrusive-interruptions
passhighInitial screenshots on four representative routes show no load-time popup, consent wall, interstitial or content-obscuring banner.
maximize-content-reduce-noise
semantic-dismissible-primitives
issueshighThe modal probe found .mfp-wrap and .ed-modal DIV elements after activation; the DOM contains zero <dialog> and zero popover elements.
F3 low: Informational modals are scripted div overlays triggered by javascript:void links.
maximize-content-reduce-noise
reduced-chrome
passhighScreenshots show a compact shared header, authentication selector and form with no advertising or competing application chrome; the primary content dominates the card.
adapt-to-the-form-factor
responsive-no-horizontal-scroll
passhighLayout captures at 780 px and 360 px both report horizontalOverflowPx 0; viewport metadata is present and the mobile screenshot reflows into one column.
adapt-to-the-form-factor
component-level-responsiveness
issueshighThe fetched 51 KB stylesheet and runtime probe contain no @container/container-type, even though shared login, navigation and footer components appear across compact and wide layouts.
F4 low: Responsive behavior is tied only to page-level breakpoints.
adapt-to-the-form-factor
input-modality-aware
issueshighThe focus probe programmatically focused visible controls: authentication links, help links and footer links computed to outline-style none with no focus-specific box shadow; only inputs and primary buttons exposed an outline.
F5 high: Keyboard focus is not visibly indicated on most links and navigation controls.
support-core-task-success
clear-purpose-and-primary-action
passhighEntry screenshot and DOM clearly explain identity verification, label both credentials, expose Giriş Yap, alternative methods, cancel and password recovery.
support-core-task-success
primary-flow-completion
blockedhighEnd-to-end authentication was attempted as far as the public form, but completion requires a valid Turkish identity credential, password/e-signature/eID, or bank account that was not available and must not be fabricated.
support-core-task-success
clear-system-state-and-recovery
passhighDOM and validation probes show required native validity messages, focus moves to the first invalid field, loading text exists, and password recovery is prominently linked; the 406 error document offers Back/Home recovery.
be-fast-and-stable
good-core-web-vitals
issueshighMobile Lighthouse measured LCP 2,594 ms (good threshold <=2,500 ms) and FCP 2,294 ms; the independent desktop trace measured LCP 1,756 ms, so the issue is condition-sensitive rather than catastrophic.
F6 medium: Lab LCP narrowly misses the good Core Web Vitals threshold.
be-fast-and-stable
visual-stability
passhighDesktop layout observed CLS 0.00067 and mobile CLS 0 with no visible shift; both are well inside the good threshold.
be-fast-and-stable
efficient-main-thread
passhighTrace and layout observers recorded zero long tasks and total blocking time 0 ms; Lighthouse TBT was also 0 ms.
be-fast-and-stable
efficient-resource-delivery
issueshighHAR recorded a 1,640 ms document request and three parser-inserted classic body scripts without async/defer; total load was 24 requests and 395,431 transferred bytes.
F7 medium: The main document is slow and three classic scripts execute in a parser-ordered body chain.
be-fast-and-stable
trim-unused-and-duplicate-code
issueshighLighthouse reports 26 KiB estimated savings in common.1.9.5.js, with 51.8% of its 51,930 bytes unused on the password route.
F8 low: The page ships avoidable unused JavaScript.
be-inclusive
names-roles-labels
passhighLighthouse accessibility scored 100; DOM inspection shows labels for both credential fields, alt text for meaningful logos, button elements for actions and live regions for announcements.
be-inclusive
sufficient-contrast
passhighLighthouse color-contrast audit passed and default/high-contrast screenshots show readable text and control boundaries.
be-inclusive
structure-and-focus
issueshighThe focus-walk probe shows outline-style none and no focus-specific shadow for authentication links, help links and both footer links, so keyboard users cannot reliably track focus.
F20 high: The keyboard focus indicator is absent on most links in the reading and navigation order.
be-inclusive
legible-text
passhighDesktop and mobile screenshots show unclipped, left-aligned Turkish text at readable measure and stable line wrapping; no horizontal overflow was observed.
be-inclusive
zoom-reflow-targets-and-media
passhighLighthouse passes viewport scaling and target-size audits; the 360 px layout reflows without overflow, inputs/buttons are 45 px high, and no timed media requires captions.
follow-best-practices
no-console-errors
passhighLighthouse errors-in-console audit passed with no logged browser errors.
follow-best-practices
sound-document-and-assets
issueshighThe images primitive and Lighthouse identify the main wordmark plus both footer logos without width/height attributes, although observed CLS remained low.
F9 low: Three images omit intrinsic width and height.
follow-best-practices
browser-platform-hygiene
passhighLighthouse found no geolocation/notification prompt on load and no paste prevention; the platform probe likewise found no permission-on-load calls.
be-discoverable
title-and-description
issueshighDOM captures for password, electronic-signature, bank and password-recovery routes all report the same title, despite having different tasks; the shared description is also generic.
F10 medium: Distinct authentication and recovery routes all use the generic title “e-Devlet Kapısı”.
be-discoverable
crawlable-and-mobile-friendly
issueshighLighthouse SEO flagged pass_detail_btn, pass_help_btn and gizlilik_btn because each uses href="javascript:void(0)".
F11 medium: Three content actions are non-crawlable javascript:void anchors.
be-discoverable
canonical-and-indexing-signals
issueshighThe runtime probe found no rel=canonical or hreflang. robots.txt permits the entry route, while /sitemap.xml returned a branded 503 document rather than XML during recon.
F12 low: Public authentication routes expose no canonical URL and sitemap discovery is unreliable.
be-discoverable
structured-and-shareable-metadata
issueshighThe DOM probe found zero Open Graph tags and zero JSON-LD blocks across the entry page.
F13 low: The identity-service page has no social preview metadata.
be-private-and-secure
secure-transport-and-headers
issueshighHeaders report default-src * with unsafe-inline and unsafe-eval plus data:/blob:. All three Secure/HttpOnly cookies, including JSESSIONID, are SameSite=None. The secrets scanner match was inspected as a jCryption PEM marker and not treated as an exposed key.
F14 high: The CSP provides little effective XSS containment and session cookies are cross-site enabled.
be-private-and-secure
data-minimisation-and-third-parties
passhighTracker capture found no known trackers and only one third-party origin, the affiliated e-devlet CDN; cookies were first-party and HAR showed no analytics beacons.
be-private-and-secure
in-context-permissions-and-modern-auth
issueshighThe DOM/runtime probe found no WebAuthn or navigator.credentials use. The site offers password, e-signature, bank, mobile-signature and identity-card methods, but not passkeys; no permission prompts fire on load.
F16 medium: The primary consumer authentication surface offers no phishing-resistant passkey option.
be-private-and-secure
defensive-browser-policies
issueshighThe response sends Referrer-Policy: unsafe-url, omits Permissions-Policy, and relies on X-Frame-Options without a restrictive CSP frame-ancestors directive.
F15 high: Defensive browser policy is weakened by unsafe referrer behavior and missing permission controls.
be-resilient
progressive-enhancement
passhighDiscoverability fetch found 100% rendered-content coverage in raw HTML, with title, H1 and description present and no empty JS mount; the crawler screenshot retains the task.
be-resilient
resilient-runtime-behaviour
passhighModal activation produced a visible dialog wrapper with close guidance; desktop/mobile routes rendered without cut-off menus or console errors, and navigation uses ordinary same-origin links.
be-resilient
offline-and-installable
not-applicablehighThis government identity gateway performs intrinsically online authentication. An offline/installable experience would not permit the core secure task and is not a reasonable requirement.
be-resilient
network-and-http-failure-states
passhighA deliberately invalid route returned a branded denial/error page with clear Back, Home, email and phone recovery actions rather than a blank shell or spinner.
be-internationalised
lang-dir-and-logical-properties
issueshighhtml lang="tr" is correct, but stylesheet inspection found 28 physical margin-left/right and padding-left/right declarations and no logical-property strategy; dir is unset.
F17 low: The Turkish document declares language correctly but the shared stylesheet is not writing-mode resilient.
be-internationalised
locale-aware-data
not-applicablehighThe audited pre-authentication routes render no user-facing dates, currencies, measured values or locale-variable numbers to format.
be-internationalised
time-zone-correctness
not-applicablehighThe audited routes contain no event scheduling or time-zone-sensitive data.
be-trustworthy
no-dark-patterns
passhighFour route screenshots show no ads, consent nagging, forced continuity, preselected paid option or confirmshaming; cancel and recovery choices are visible.
be-trustworthy
humane-error-handling
passhighNative required-field validation is deferred until reportValidity/submit, focuses the first invalid input and supplies a concrete validation message; empty assertive/polite live regions are available for scripted states.
be-trustworthy
trustworthy-input-assistance
issueshighThe form and both identity/password inputs declare autocomplete="off"; the security copy explicitly tells users to disable browser password saving. The correct tokens would be username and current-password.
F18 high: The sign-in form disables autofill and password-manager assistance.
be-trustworthy
safe-commercial-and-account-flows
passhighThe account gateway discloses five authentication methods, provides cancel and password recovery, and contains no pricing, subscription or continuity commitment.
be-sustainable
optimised-assets
issueshighLighthouse estimates 121 KiB image-delivery savings. The 709×172 security-board logo is displayed around 148×36 and transfers 76 KB; all four images are PNG with no srcset.
F19 medium: Oversized legacy PNG logos dominate an otherwise small page.
be-sustainable
no-wasteful-work
passhighTrace/layout recorded no long tasks, HAR contains only 24 requests with no tracker traffic, and no autoplay/background media or idle polling was observed.
be-sustainable
third-party-and-media-budget
passhighThe 395 KB page has no video/audio/autoplay, no known trackers, and its only cross-origin dependency is the affiliated e-devlet CDN; the remaining image waste is isolated under optimised-assets.
be-agent-ready
structured-agent-capabilities
not-applicablehighA high-risk identity gateway has no declared agent-facing intent; exposing sign-in capabilities to autonomous agents would require an explicit threat model and is not assumed.
be-agent-ready
on-device-inference
not-applicablehighThe deterministic identity and recovery tasks have no justified inference use case; absence of built-in AI is appropriate.
be-memory-efficient
no-leak-under-repeated-interaction
passmediumHeap comparison after one versus twenty modal open/close cycles grew only 3.0% in self size (4,153,123 to 4,278,093 bytes) and 1.0% in nodes (78,812 to 79,579), consistent with bounded warm-up rather than per-cycle unbounded retention.
be-memory-efficient
bounded-footprint
passmediumThe warmed twenty-cycle snapshot is 4.28 MB self size with 79,579 nodes for a scripted login form, a proportionate footprint; trace showed no long tasks.
be-memory-efficient
no-detached-dom-or-unbounded-listeners
passmediumHeap summaries contain no Detached* constructor among top retained constructors, and one-to-twenty-cycle growth is small rather than linear; modal wrapper reuse is therefore supported with medium confidence.

Provenance

Canonical report: results/atomic/reports/0494-giris_turkiye_gov_tr.json
Report SHA-256: c55e8d7854887a5a3043303efc2f0f9171fb58b586d6734464b61a3f0ada2880
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/giris_turkiye_gov_tr/2026-07-28T00-45-45-705Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/giris_turkiye_gov_tr/2026-07-28T00-45-45-705Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7

Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.