Commit fe83ff502f
Unsigned
Layout: unified · split
Docs/ACCESSIBILITY.md → Docs/ACCESSIBILITY.txt renamed
Docs/ARCHITECTURE.md → Docs/ARCHITECTURE.txt renamed +2 −2
| @@ -76,14 +76,14 @@ The app remains local-first. Purchase and entitlement code is local app infrastr | |||
| 76 | - `DomainReportExporter` | 76 | - `DomainReportExporter` |
| 77 | - `LocalAPIModels` | 77 | - `LocalAPIModels` |
| 78 | 78 | ||
| 79 | `v5.0.0` stabilized this contract: `LocalAPIContract` is the single source of truth for the `v1` wire version and JSON encoder, the response envelope and payloads are documented, and the shape is regression-locked by `LocalAPIContractTests`. See [local-api.md](local-api.md) for the endpoint and compatibility reference, and [data-migration.md](data-migration.md) for how the persisted store is versioned across app updates. | 79 | `v5.0.0` stabilized this contract: `LocalAPIContract` is the single source of truth for the `v1` wire version and JSON encoder, the response envelope and payloads are documented, and the shape is regression-locked by `LocalAPIContractTests`. See [local-api.txt](local-api.txt) for the endpoint and compatibility reference, and [data-migration.txt](data-migration.txt) for how the persisted store is versioned across app updates. |
| 80 | 80 | ||
| 81 | ## Testing | 81 | ## Testing |
| 82 | 82 | ||
| 83 | Two test targets run from the `DomainDig` scheme's test action: | 83 | Two test targets run from the `DomainDig` scheme's test action: |
| 84 | 84 | ||
| 85 | - `DomainDigTests` — unit coverage of the deterministic core: `DomainReportBuilder`, `DomainReportExporter`, `DiffService`, `DomainDataPortabilityService` (merge/replace dedup), the store-migration runner, and the Local API contract. `SnapshotFixture` builds the deep `LookupSnapshot`/`DomainReport` models through the real builder so tests construct inputs without wiring every field. | 85 | - `DomainDigTests` — unit coverage of the deterministic core: `DomainReportBuilder`, `DomainReportExporter`, `DiffService`, `DomainDataPortabilityService` (merge/replace dedup), the store-migration runner, and the Local API contract. `SnapshotFixture` builds the deep `LookupSnapshot`/`DomainReport` models through the real builder so tests construct inputs without wiring every field. |
| 86 | - `DomainDigUITests` — Apple's `performAccessibilityAudit()` over every primary screen at default and largest Dynamic Type, plus metadata and screenshot assertions. See [ACCESSIBILITY.md](ACCESSIBILITY.md). | 86 | - `DomainDigUITests` — Apple's `performAccessibilityAudit()` over every primary screen at default and largest Dynamic Type, plus metadata and screenshot assertions. See [ACCESSIBILITY.txt](ACCESSIBILITY.txt). |
| 87 | 87 | ||
| 88 | A plain `xcodebuild test` (and CI) runs both. The unit net went in first in `v5.0.0` and is what made the god-file decomposition safe to attempt. | 88 | A plain `xcodebuild test` (and CI) runs both. The unit net went in first in `v5.0.0` and is what made the god-file decomposition safe to attempt. |
| 89 | 89 | ||
Docs/data-migration.md → Docs/data-migration.txt renamed +1 −1
| @@ -77,7 +77,7 @@ backup export/import). Its contract: | |||
| 77 | 4. Add a `DataMigrationServiceTests` case that seeds a pre-`N` fixture, runs | 77 | 4. Add a `DataMigrationServiceTests` case that seeds a pre-`N` fixture, runs |
| 78 | `migrateIfNeeded`, and asserts the upgrade plus the version stamp. | 78 | `migrateIfNeeded`, and asserts the upgrade plus the version stamp. |
| 79 | 5. If the change also alters the export shape, bump | 79 | 5. If the change also alters the export shape, bump |
| 80 | `DomainDigBackup.currentSchemaVersion` and update `Docs/local-api.md` / | 80 | `DomainDigBackup.currentSchemaVersion` and update `Docs/local-api.txt` / |
| 81 | backup validation as needed. | 81 | backup validation as needed. |
| 82 | 82 | ||
| 83 | ## Backup import compatibility | 83 | ## Backup import compatibility |
Docs/local-api.md → Docs/local-api.txt renamed
LICENSE +12 −21
| @@ -1,21 +1,12 @@ | |||
| 1 | MIT License | 1 | Copyright (C) 2026 krazy warez |
| 2 | 2 | ||
| 3 | Copyright (c) 2026 Christian Cleberg | 3 | Permission to use, copy, modify, and/or distribute this software for any |
| 4 | 4 | purpose with or without fee is hereby granted. | |
| 5 | Permission is hereby granted, free of charge, to any person obtaining a copy | 5 | |
| 6 | of this software and associated documentation files (the "Software"), to deal | 6 | THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES |
| 7 | in the Software without restriction, including without limitation the rights | 7 | WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF |
| 8 | to use, copy, modify, merge, publish, distribute, sublicense, and/or sell | 8 | MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR |
| 9 | copies of the Software, and to permit persons to whom the Software is | 9 | ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES |
| 10 | furnished to do so, subject to the following conditions: | 10 | WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN |
| 11 | 11 | ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF | |
| 12 | The above copyright notice and this permission notice shall be included in all | 12 | OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. |
| 13 | copies or substantial portions of the Software. | ||
| 14 | |||
| 15 | THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR | ||
| 16 | IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, | ||
| 17 | FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE | ||
| 18 | AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER | ||
| 19 | LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, | ||
| 20 | OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE | ||
| 21 | SOFTWARE. | ||
README.md deleted −108
| @@ -1,108 +0,0 @@ | |||
| 1 | # DomainDig | ||
| 2 | |||
| 3 | [](https://sonarcloud.io/summary/new_code?id=krz_domain-dig) | ||
| 4 | [](https://sonarcloud.io/summary/new_code?id=krz_domain-dig) | ||
| 5 | [](https://sonarcloud.io/summary/new_code?id=krz_domain-dig) | ||
| 6 | [](https://sonarcloud.io/summary/new_code?id=krz_domain-dig) | ||
| 7 | [](LICENSE) | ||
| 8 | |||
| 9 | [](https://apps.apple.com/us/app/domaindig/id6760368004) | ||
| 10 | |||
| 11 | DomainDig is a local-first iOS domain inspection toolkit for DNS, web, ownership, monitoring, reporting, and audit workflows. The app gathers a point-in-time domain snapshot, normalizes it into a canonical `DomainReport`, and keeps user data on device unless the user exports, shares, or syncs it. | ||
| 12 | |||
| 13 | ## Features | ||
| 14 | |||
| 15 | - Domain inspection for DNS records, email security, TLS certificates, HTTP headers, redirects, IP geolocation, reachability, open ports, RDAP, ownership, subdomain discovery, and availability. | ||
| 16 | - Canonical `DomainReport` output used by the app UI and exports. | ||
| 17 | - History snapshots with change summaries, risk scoring, notes, and saved domain context. | ||
| 18 | - Dashboard, watchlist, monitoring, workflows, batch results, integrations, and data portability screens. | ||
| 19 | - Audit Mode with sessions, checklist progress, reviewer notes, findings, evidence snapshots, audit timelines, and markdown/json/pdf export. | ||
| 20 | - Backup and restore for tracked domains, history, audit sessions, workflows, monitoring settings/logs, app settings, and local feature metadata. | ||
| 21 | - Local-first operation with no required backend. | ||
| 22 | - Optional local API surface for automation-compatible report output. | ||
| 23 | |||
| 24 | ## Data And Privacy | ||
| 25 | |||
| 26 | DomainDig stores local app data in on-device persistence. Backup exports can include tracked domains, lookup history, audit sessions, workflow definitions, monitoring configuration, monitoring logs, app settings, and cached feature metadata. Imports are processed on device. | ||
| 27 | |||
| 28 | Network inspection requests are made only to perform the requested domain checks or configured resolver lookups. The app does not require a hosted DomainDig backend. | ||
| 29 | |||
| 30 | ## Development | ||
| 31 | |||
| 32 | ### Requirements | ||
| 33 | |||
| 34 | - Xcode with current iOS SDK support | ||
| 35 | - iOS Simulator or physical iOS device | ||
| 36 | - Swift/Xcode support for filesystem-synchronized groups used by the project | ||
| 37 | |||
| 38 | ### Getting Started | ||
| 39 | |||
| 40 | 1. Clone the repository. | ||
| 41 | ```sh | ||
| 42 | git clone https://github.com/krazywarez/domain-dig.git | ||
| 43 | ``` | ||
| 44 | 2. Open `DomainDig.xcodeproj` in Xcode. | ||
| 45 | 3. Select the `DomainDig` scheme. | ||
| 46 | 4. Build and run on a simulator or device. | ||
| 47 | |||
| 48 | ### Useful Checks | ||
| 49 | |||
| 50 | ```sh | ||
| 51 | xcodebuild -project DomainDig.xcodeproj -scheme DomainDig -destination 'platform=iOS Simulator,name=iPhone 16' build | ||
| 52 | ``` | ||
| 53 | |||
| 54 | The app and local API share the canonical report pipeline through `DomainInspectionService`, `DomainReportBuilder`, and `DomainReportExporter`. The Local API's endpoints, response envelope, and `v1` compatibility policy are documented in [Docs/local-api.md](Docs/local-api.md). How the on-device store evolves across app versions is documented in [Docs/data-migration.md](Docs/data-migration.md). | ||
| 55 | |||
| 56 | ### Tests | ||
| 57 | |||
| 58 | Unit coverage of the deterministic core — `DomainReportBuilder`, `DomainReportExporter`, `DiffService`, `DomainDataPortabilityService` (merge/replace dedup), the migration runner, and the Local API contract — lives in the `DomainDigTests` target: | ||
| 59 | |||
| 60 | ```sh | ||
| 61 | xcodebuild test -project DomainDig.xcodeproj -scheme DomainDig -destination 'platform=iOS Simulator,name=iPhone 16' -only-testing:DomainDigTests | ||
| 62 | ``` | ||
| 63 | |||
| 64 | The `DomainDig` scheme's test action runs both `DomainDigTests` and the `DomainDigUITests` accessibility audit, so a plain `xcodebuild test` (and CI) exercises both. | ||
| 65 | |||
| 66 | ### Accessibility Audit | ||
| 67 | |||
| 68 | `DomainDigUITests` runs `performAccessibilityAudit()` over every primary screen, | ||
| 69 | at default and at the largest accessibility text size. | ||
| 70 | |||
| 71 | ```sh | ||
| 72 | ./Scripts/audit-a11y.sh # oldest supported + newest runtime | ||
| 73 | ./Scripts/audit-a11y.sh floor # oldest supported runtime only (~85s) | ||
| 74 | ``` | ||
| 75 | |||
| 76 | Findings are **reported, not enforced** — they are the burndown list for the | ||
| 77 | accessibility pass. Widen `AccessibilityAuditHarness.enforcedAuditTypes` to turn | ||
| 78 | a category into a build failure as each phase lands. | ||
| 79 | |||
| 80 | Optional pre-push hook, which runs the floor audit when Swift or project files | ||
| 81 | change: | ||
| 82 | |||
| 83 | ```sh | ||
| 84 | git config core.hooksPath .githooks | ||
| 85 | ``` | ||
| 86 | |||
| 87 | See [Docs/ACCESSIBILITY.md](Docs/ACCESSIBILITY.md) for why coverage is split | ||
| 88 | between this script and CI. | ||
| 89 | |||
| 90 | ## Release Planning | ||
| 91 | |||
| 92 | See `RELEASE_ROADMAP.md` for the semver release history from `v4.4.1` through the `v5.0.0` contract-stabilization milestone. | ||
| 93 | |||
| 94 | ## Contributing | ||
| 95 | |||
| 96 | Contributions are welcome. Keep changes scoped, include tests or build verification when behavior changes, and open a pull request with a clear summary of user-facing impact. | ||
| 97 | |||
| 98 | ## Security | ||
| 99 | |||
| 100 | If you discover a security issue, see `SECURITY.md`. | ||
| 101 | |||
| 102 | ## License | ||
| 103 | |||
| 104 | This project is licensed under the MIT License. See `LICENSE`. | ||
| 105 | |||
| 106 | ## Contact | ||
| 107 | |||
| 108 | Questions or feedback: root@krz.sh | ||
README.nfo added +74
| @@ -0,0 +1,74 @@ | |||
| 1 | ┌──────────────────────────────────────────────────────────────┐ | ||
| 2 | │ D O M A I N D I G [ KRZ ] krz.sh │ | ||
| 3 | └──────────────────────────────────────────────────────────────┘ | ||
| 4 | |||
| 5 | WHAT | ||
| 6 | local-first ios domain inspection toolkit. dns, web, ownership, | ||
| 7 | monitoring, reporting, audit. takes a point-in-time snapshot of a | ||
| 8 | domain, normalizes it into a DomainReport, and keeps data on device | ||
| 9 | unless you export, share, or sync it. | ||
| 10 | |||
| 11 | DOES | ||
| 12 | - inspects dns records, email security, tls certs, http headers, | ||
| 13 | redirects, ip geolocation, reachability, open ports, rdap, | ||
| 14 | ownership, subdomains, availability | ||
| 15 | - DomainReport output used by the ui and exports | ||
| 16 | - history snapshots with change summaries, risk scoring, notes | ||
| 17 | - dashboard, watchlist, monitoring, workflows, batch results, | ||
| 18 | integrations, data portability | ||
| 19 | - audit mode: sessions, checklists, reviewer notes, findings, | ||
| 20 | evidence snapshots, timelines, markdown/json/pdf export | ||
| 21 | - backup and restore for tracked domains, history, audit sessions, | ||
| 22 | workflows, monitoring, settings, feature metadata | ||
| 23 | - optional local api for automation-compatible output | ||
| 24 | |||
| 25 | PRIVACY | ||
| 26 | app data lives in on-device storage. network requests go out only | ||
| 27 | to run the checks you asked for or the resolver you configured. no | ||
| 28 | hosted backend required. | ||
| 29 | |||
| 30 | BUILD | ||
| 31 | needs xcode with a current ios sdk and a simulator or device. | ||
| 32 | |||
| 33 | git clone https://github.com/krazywarez/domain-dig.git | ||
| 34 | |||
| 35 | open DomainDig.xcodeproj, pick the DomainDig scheme, build and run. | ||
| 36 | |||
| 37 | build check: | ||
| 38 | |||
| 39 | xcodebuild -project DomainDig.xcodeproj -scheme DomainDig \ | ||
| 40 | -destination 'platform=iOS Simulator,name=iPhone 16' build | ||
| 41 | |||
| 42 | TESTS | ||
| 43 | deterministic core coverage lives in DomainDigTests: | ||
| 44 | |||
| 45 | xcodebuild test -project DomainDig.xcodeproj -scheme DomainDig \ | ||
| 46 | -destination 'platform=iOS Simulator,name=iPhone 16' \ | ||
| 47 | -only-testing:DomainDigTests | ||
| 48 | |||
| 49 | the scheme's test action also runs the DomainDigUITests | ||
| 50 | accessibility audit. | ||
| 51 | |||
| 52 | ./Scripts/audit-a11y.sh # oldest supported + newest | ||
| 53 | ./Scripts/audit-a11y.sh floor # oldest only (~85s) | ||
| 54 | |||
| 55 | findings are reported, not enforced. optional pre-push hook: | ||
| 56 | |||
| 57 | git config core.hooksPath .githooks | ||
| 58 | |||
| 59 | DOCS | ||
| 60 | local api: Docs/local-api.txt | ||
| 61 | data migration: Docs/data-migration.txt | ||
| 62 | accessibility: Docs/ACCESSIBILITY.txt | ||
| 63 | releases: RELEASE_ROADMAP.txt (v4.4.1 -> v5.0.0) | ||
| 64 | security: SECURITY.txt | ||
| 65 | |||
| 66 | LICENSE | ||
| 67 | 0bsd. see LICENSE. | ||
| 68 | |||
| 69 | CONTACT | ||
| 70 | root@krz.sh | ||
| 71 | |||
| 72 | ┌──────────────────────────────────────────────────────────────┐ | ||
| 73 | │ krz.sh │ | ||
| 74 | └──────────────────────────────────────────────────────────────┘ | ||
RELEASE_ROADMAP.md → RELEASE_ROADMAP.txt renamed +2 −2
| @@ -280,14 +280,14 @@ test net. | |||
| 280 | - **Local API `v1` contract stabilized.** `LocalAPIContract` is the single source | 280 | - **Local API `v1` contract stabilized.** `LocalAPIContract` is the single source |
| 281 | of truth for the wire version and JSON encoder; the response envelope and every | 281 | of truth for the wire version and JSON encoder; the response envelope and every |
| 282 | payload are promoted to a first-class, documented contract. | 282 | payload are promoted to a first-class, documented contract. |
| 283 | `Docs/local-api.md` documents each endpoint, the envelope, the encoding | 283 | `Docs/local-api.txt` documents each endpoint, the envelope, the encoding |
| 284 | conventions (notably: absent optionals are omitted, not null), and a | 284 | conventions (notably: absent optionals are omitted, not null), and a |
| 285 | semantic-version compatibility policy. 16 golden structure tests pin the JSON | 285 | semantic-version compatibility policy. 16 golden structure tests pin the JSON |
| 286 | shape so a renamed/removed field fails CI. (#45) | 286 | shape so a renamed/removed field fails CI. (#45) |
| 287 | - **Versioned store-migration policy** for persisted snapshots, backups, audits, | 287 | - **Versioned store-migration policy** for persisted snapshots, backups, audits, |
| 288 | workflows, and settings. `DataMigrationService` became a forward-only, | 288 | workflows, and settings. `DataMigrationService` became a forward-only, |
| 289 | idempotent, never-downgrades runner keyed by an integer store schema version, | 289 | idempotent, never-downgrades runner keyed by an integer store schema version, |
| 290 | replacing the one-shot boolean marker. `Docs/data-migration.md` documents the | 290 | replacing the one-shot boolean marker. `Docs/data-migration.txt` documents the |
| 291 | policy, the two independent version lines (on-device store vs. backup export), | 291 | policy, the two independent version lines (on-device store vs. backup export), |
| 292 | and when to use lenient decoding vs. a migration step; legacy-fixture tests | 292 | and when to use lenient decoding vs. a migration step; legacy-fixture tests |
| 293 | cover it. (#46) | 293 | cover it. (#46) |