Manifest position 494 · CrUX rank bucket 1000
https://giris.turkiye.gov.tr
Partial after retries
57 of 58 checks judged. End-to-end primary authentication is blocked by unavailable personal credentials; no score is published.
All 58 atomic check outcomes
| Principle / check | Status | Confidence | Evidence or reason |
|---|---|---|---|
respect-user-preferencesrespects-color-scheme | issues | high | The dark-mode screenshot is pixel-identical in palette and file size to the default desktop capture: white page and white form surfaces remain under prefers-color-scheme: dark. F1 medium: The login surface ignores the user’s dark color-scheme preference. |
respect-user-preferencesrespects-reduced-motion | pass | high | Reduced-motion emulation was active; document.getAnimations() returned zero animations across the entry surface, so no non-essential motion or auto-advance remains to suppress. |
respect-user-preferencesrespects-contrast | pass | high | The forced-colors/high-contrast screenshot keeps body text, inputs, buttons, borders, selected navigation and links distinguishable; Lighthouse color contrast also passed. |
implement-natural-interactionsview-transitions | issues | high | DOM/CSS inspection across password, e-signature and bank pages found no view-transition-name or @view-transition rule; the routes are same-origin MPAs with shared chrome. F2 low: Switching authentication methods uses abrupt full-document swaps. |
implement-natural-interactionsscroll-driven-animations | not-applicable | high | No scroll-linked animation, parallax, reveal or carousel behavior exists on the representative login/recovery routes, so there is no scroll animation implementation to assess. |
implement-natural-interactionsphysical-gestures | not-applicable | high | The routes expose conventional forms and links but no gesture-driven interaction, pull/swipe action or snap-scrolling surface. |
provide-guided-navigationscroll-state-aware-chrome | not-applicable | high | The short login page has no persistent scrolled chrome or long-content navigation state requiring scroll-aware adaptation. |
provide-guided-navigationanchored-positioning | not-applicable | high | No tooltip, anchored popover or edge-positioned menu was present; the only overlay is a centered modal assessed under semantic primitives. |
provide-guided-navigationdirects-attention | pass | high | Desktop/mobile screenshots show the selected authentication method prominently; the recovery route provides a seven-step breadcrumb and clearly highlighted current step. |
maximize-content-reduce-noiseno-intrusive-interruptions | pass | high | Initial screenshots on four representative routes show no load-time popup, consent wall, interstitial or content-obscuring banner. |
maximize-content-reduce-noisesemantic-dismissible-primitives | issues | high | The modal probe found .mfp-wrap and .ed-modal DIV elements after activation; the DOM contains zero <dialog> and zero popover elements. F3 low: Informational modals are scripted div overlays triggered by javascript:void links. |
maximize-content-reduce-noisereduced-chrome | pass | high | Screenshots show a compact shared header, authentication selector and form with no advertising or competing application chrome; the primary content dominates the card. |
adapt-to-the-form-factorresponsive-no-horizontal-scroll | pass | high | Layout captures at 780 px and 360 px both report horizontalOverflowPx 0; viewport metadata is present and the mobile screenshot reflows into one column. |
adapt-to-the-form-factorcomponent-level-responsiveness | issues | high | The fetched 51 KB stylesheet and runtime probe contain no @container/container-type, even though shared login, navigation and footer components appear across compact and wide layouts. F4 low: Responsive behavior is tied only to page-level breakpoints. |
adapt-to-the-form-factorinput-modality-aware | issues | high | The focus probe programmatically focused visible controls: authentication links, help links and footer links computed to outline-style none with no focus-specific box shadow; only inputs and primary buttons exposed an outline. F5 high: Keyboard focus is not visibly indicated on most links and navigation controls. |
support-core-task-successclear-purpose-and-primary-action | pass | high | Entry screenshot and DOM clearly explain identity verification, label both credentials, expose Giriş Yap, alternative methods, cancel and password recovery. |
support-core-task-successprimary-flow-completion | blocked | high | End-to-end authentication was attempted as far as the public form, but completion requires a valid Turkish identity credential, password/e-signature/eID, or bank account that was not available and must not be fabricated. |
support-core-task-successclear-system-state-and-recovery | pass | high | DOM and validation probes show required native validity messages, focus moves to the first invalid field, loading text exists, and password recovery is prominently linked; the 406 error document offers Back/Home recovery. |
be-fast-and-stablegood-core-web-vitals | issues | high | Mobile Lighthouse measured LCP 2,594 ms (good threshold <=2,500 ms) and FCP 2,294 ms; the independent desktop trace measured LCP 1,756 ms, so the issue is condition-sensitive rather than catastrophic. F6 medium: Lab LCP narrowly misses the good Core Web Vitals threshold. |
be-fast-and-stablevisual-stability | pass | high | Desktop layout observed CLS 0.00067 and mobile CLS 0 with no visible shift; both are well inside the good threshold. |
be-fast-and-stableefficient-main-thread | pass | high | Trace and layout observers recorded zero long tasks and total blocking time 0 ms; Lighthouse TBT was also 0 ms. |
be-fast-and-stableefficient-resource-delivery | issues | high | HAR recorded a 1,640 ms document request and three parser-inserted classic body scripts without async/defer; total load was 24 requests and 395,431 transferred bytes. F7 medium: The main document is slow and three classic scripts execute in a parser-ordered body chain. |
be-fast-and-stabletrim-unused-and-duplicate-code | issues | high | Lighthouse reports 26 KiB estimated savings in common.1.9.5.js, with 51.8% of its 51,930 bytes unused on the password route. F8 low: The page ships avoidable unused JavaScript. |
be-inclusivenames-roles-labels | pass | high | Lighthouse accessibility scored 100; DOM inspection shows labels for both credential fields, alt text for meaningful logos, button elements for actions and live regions for announcements. |
be-inclusivesufficient-contrast | pass | high | Lighthouse color-contrast audit passed and default/high-contrast screenshots show readable text and control boundaries. |
be-inclusivestructure-and-focus | issues | high | The focus-walk probe shows outline-style none and no focus-specific shadow for authentication links, help links and both footer links, so keyboard users cannot reliably track focus. F20 high: The keyboard focus indicator is absent on most links in the reading and navigation order. |
be-inclusivelegible-text | pass | high | Desktop and mobile screenshots show unclipped, left-aligned Turkish text at readable measure and stable line wrapping; no horizontal overflow was observed. |
be-inclusivezoom-reflow-targets-and-media | pass | high | Lighthouse passes viewport scaling and target-size audits; the 360 px layout reflows without overflow, inputs/buttons are 45 px high, and no timed media requires captions. |
follow-best-practicesno-console-errors | pass | high | Lighthouse errors-in-console audit passed with no logged browser errors. |
follow-best-practicessound-document-and-assets | issues | high | The images primitive and Lighthouse identify the main wordmark plus both footer logos without width/height attributes, although observed CLS remained low. F9 low: Three images omit intrinsic width and height. |
follow-best-practicesbrowser-platform-hygiene | pass | high | Lighthouse found no geolocation/notification prompt on load and no paste prevention; the platform probe likewise found no permission-on-load calls. |
be-discoverabletitle-and-description | issues | high | DOM captures for password, electronic-signature, bank and password-recovery routes all report the same title, despite having different tasks; the shared description is also generic. F10 medium: Distinct authentication and recovery routes all use the generic title “e-Devlet Kapısı”. |
be-discoverablecrawlable-and-mobile-friendly | issues | high | Lighthouse SEO flagged pass_detail_btn, pass_help_btn and gizlilik_btn because each uses href="javascript:void(0)". F11 medium: Three content actions are non-crawlable javascript:void anchors. |
be-discoverablecanonical-and-indexing-signals | issues | high | The runtime probe found no rel=canonical or hreflang. robots.txt permits the entry route, while /sitemap.xml returned a branded 503 document rather than XML during recon. F12 low: Public authentication routes expose no canonical URL and sitemap discovery is unreliable. |
be-discoverablestructured-and-shareable-metadata | issues | high | The DOM probe found zero Open Graph tags and zero JSON-LD blocks across the entry page. F13 low: The identity-service page has no social preview metadata. |
be-private-and-securesecure-transport-and-headers | issues | high | Headers report default-src * with unsafe-inline and unsafe-eval plus data:/blob:. All three Secure/HttpOnly cookies, including JSESSIONID, are SameSite=None. The secrets scanner match was inspected as a jCryption PEM marker and not treated as an exposed key. F14 high: The CSP provides little effective XSS containment and session cookies are cross-site enabled. |
be-private-and-securedata-minimisation-and-third-parties | pass | high | Tracker capture found no known trackers and only one third-party origin, the affiliated e-devlet CDN; cookies were first-party and HAR showed no analytics beacons. |
be-private-and-securein-context-permissions-and-modern-auth | issues | high | The DOM/runtime probe found no WebAuthn or navigator.credentials use. The site offers password, e-signature, bank, mobile-signature and identity-card methods, but not passkeys; no permission prompts fire on load. F16 medium: The primary consumer authentication surface offers no phishing-resistant passkey option. |
be-private-and-securedefensive-browser-policies | issues | high | The response sends Referrer-Policy: unsafe-url, omits Permissions-Policy, and relies on X-Frame-Options without a restrictive CSP frame-ancestors directive. F15 high: Defensive browser policy is weakened by unsafe referrer behavior and missing permission controls. |
be-resilientprogressive-enhancement | pass | high | Discoverability fetch found 100% rendered-content coverage in raw HTML, with title, H1 and description present and no empty JS mount; the crawler screenshot retains the task. |
be-resilientresilient-runtime-behaviour | pass | high | Modal activation produced a visible dialog wrapper with close guidance; desktop/mobile routes rendered without cut-off menus or console errors, and navigation uses ordinary same-origin links. |
be-resilientoffline-and-installable | not-applicable | high | This government identity gateway performs intrinsically online authentication. An offline/installable experience would not permit the core secure task and is not a reasonable requirement. |
be-resilientnetwork-and-http-failure-states | pass | high | A deliberately invalid route returned a branded denial/error page with clear Back, Home, email and phone recovery actions rather than a blank shell or spinner. |
be-internationalisedlang-dir-and-logical-properties | issues | high | html lang="tr" is correct, but stylesheet inspection found 28 physical margin-left/right and padding-left/right declarations and no logical-property strategy; dir is unset. F17 low: The Turkish document declares language correctly but the shared stylesheet is not writing-mode resilient. |
be-internationalisedlocale-aware-data | not-applicable | high | The audited pre-authentication routes render no user-facing dates, currencies, measured values or locale-variable numbers to format. |
be-internationalisedtime-zone-correctness | not-applicable | high | The audited routes contain no event scheduling or time-zone-sensitive data. |
be-trustworthyno-dark-patterns | pass | high | Four route screenshots show no ads, consent nagging, forced continuity, preselected paid option or confirmshaming; cancel and recovery choices are visible. |
be-trustworthyhumane-error-handling | pass | high | Native required-field validation is deferred until reportValidity/submit, focuses the first invalid input and supplies a concrete validation message; empty assertive/polite live regions are available for scripted states. |
be-trustworthytrustworthy-input-assistance | issues | high | The form and both identity/password inputs declare autocomplete="off"; the security copy explicitly tells users to disable browser password saving. The correct tokens would be username and current-password. F18 high: The sign-in form disables autofill and password-manager assistance. |
be-trustworthysafe-commercial-and-account-flows | pass | high | The account gateway discloses five authentication methods, provides cancel and password recovery, and contains no pricing, subscription or continuity commitment. |
be-sustainableoptimised-assets | issues | high | Lighthouse estimates 121 KiB image-delivery savings. The 709×172 security-board logo is displayed around 148×36 and transfers 76 KB; all four images are PNG with no srcset. F19 medium: Oversized legacy PNG logos dominate an otherwise small page. |
be-sustainableno-wasteful-work | pass | high | Trace/layout recorded no long tasks, HAR contains only 24 requests with no tracker traffic, and no autoplay/background media or idle polling was observed. |
be-sustainablethird-party-and-media-budget | pass | high | The 395 KB page has no video/audio/autoplay, no known trackers, and its only cross-origin dependency is the affiliated e-devlet CDN; the remaining image waste is isolated under optimised-assets. |
be-agent-readystructured-agent-capabilities | not-applicable | high | A high-risk identity gateway has no declared agent-facing intent; exposing sign-in capabilities to autonomous agents would require an explicit threat model and is not assumed. |
be-agent-readyon-device-inference | not-applicable | high | The deterministic identity and recovery tasks have no justified inference use case; absence of built-in AI is appropriate. |
be-memory-efficientno-leak-under-repeated-interaction | pass | medium | Heap comparison after one versus twenty modal open/close cycles grew only 3.0% in self size (4,153,123 to 4,278,093 bytes) and 1.0% in nodes (78,812 to 79,579), consistent with bounded warm-up rather than per-cycle unbounded retention. |
be-memory-efficientbounded-footprint | pass | medium | The warmed twenty-cycle snapshot is 4.28 MB self size with 79,579 nodes for a scripted login form, a proportionate footprint; trace showed no long tasks. |
be-memory-efficientno-detached-dom-or-unbounded-listeners | pass | medium | Heap summaries contain no Detached* constructor among top retained constructors, and one-to-twenty-cycle growth is small rather than linear; modal wrapper reuse is therefore supported with medium confidence. |
Provenance
Canonical report: results/atomic/reports/0494-giris_turkiye_gov_tr.json
Report SHA-256: c55e8d7854887a5a3043303efc2f0f9171fb58b586d6734464b61a3f0ada2880
Local retained report: runs/2026-07-17T17-27-24-856Z/atomic-reports/giris_turkiye_gov_tr/2026-07-28T00-45-45-705Z/report.json
Local evidence root: runs/2026-07-17T17-27-24-856Z/atomic-reports/giris_turkiye_gov_tr/2026-07-28T00-45-45-705Z
Catalog SHA-256: sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7
Raw screenshots, HARs, traces, heaps, and other browser artifacts are retained at the local evidence root and intentionally are not committed. Artifact paths in the canonical report are relative to that root.