Release Network Tools 0.2.0
Verify / verify (push) Canceled after 0s

This commit is contained in:
2026-09-02 11:38:57 +02:00
parent 729430295b
commit 429b55d587
30 changed files with 1474 additions and 96 deletions
+6
View File
@@ -1,5 +1,11 @@
# Changelog
## 0.2.0 - 2026-09-02
- Added largest-first IPv4 VLSM planning with bounded, atomic allocation.
- Added inert DNS zone parsing/validation with common record semantics and explicit syntax-only coverage.
- Added multi-field CSP and HTTP security-header analysis.
## 0.1.0 - 2026-09-01
- Added the initial local-first Network Tools workbench.
+3 -3
View File
@@ -1,5 +1,5 @@
==============================================================================
@add-ideas/toolbox-contract@0.2.3
@add-ideas/toolbox-contract@0.3.0
Declared licence: Apache-2.0
==============================================================================
--- LICENSE ---
@@ -198,7 +198,7 @@ Declared licence: Apache-2.0
==============================================================================
@add-ideas/toolbox-helpers@0.1.0
@add-ideas/toolbox-helpers@0.2.0
Declared licence: GPL-3.0-or-later
==============================================================================
--- LICENSE ---
@@ -879,7 +879,7 @@ Public License instead of this License. But first, please read
==============================================================================
@add-ideas/toolbox-shell-react@0.2.3
@add-ideas/toolbox-shell-react@0.3.0
Declared licence: Apache-2.0
==============================================================================
--- LICENSE ---
+6 -3
View File
@@ -4,12 +4,15 @@ Calculate and construct network values locally in the browser.
Network Tools is a standalone local-first application in the [add·ideas Toolbox](https://git.add-ideas.de/lotobo/toolbox-portal). Inputs are processed in the browser and are not uploaded.
## Version 0.1 scope
## Current scope
- IPv4 and IPv6 parsing, canonicalisation, prefix ranges and IPv4 broadcast calculation
- Largest-first IPv4 VLSM planning with conventional network/broadcast reservations, alignment and atomic fit failures
- URL resolution, component/query inspection and password-redacted display without requesting the URL
- Bounded A, AAAA, CNAME, MX, SRV, CAA and TXT zone-record construction
- Bounded response-header inspection and explicit CSP construction
- Inert, bounded zone-file parsing with `$ORIGIN`, `$TTL`, inherited owners, multiline records, common RDATA validation and explicit syntax-only coverage for unknown types; `$INCLUDE` is never followed
- Bounded response-header security analysis covering CSP, HSTS, cookies, CORS, framing, content sniffing, referrer and cross-origin policies
- CSP parsing/diagnostics and explicit conservative CSP construction
- A compact offline extension/MIME reference
The application treats pasted values as untrusted, applies explicit length and numeric limits, and makes no DNS, URL or HTTP request. See [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md) and [docs/PRIVACY-SECURITY.md](docs/PRIVACY-SECURITY.md).
@@ -26,7 +29,7 @@ npm run test:browser
## Release
`npm run release:artifact` creates a deterministic `release/network-tools-0.1.0.zip` and checksum sidecar.
`npm run release:artifact` creates a deterministic `release/network-tools-0.2.0.zip` and checksum sidecar.
## Licence
+2 -2
View File
@@ -1,7 +1,7 @@
# Corresponding source
The corresponding source for Network Tools 0.1.0 is available at:
The corresponding source for Network Tools 0.2.0 is available at:
https://git.add-ideas.de/lotobo/network-tools/src/tag/v0.1.0
https://git.add-ideas.de/lotobo/network-tools/src/tag/v0.2.0
Build with Node.js 22, npm 11, `npm ci`, and `npm run release:artifact`.
+3 -3
View File
@@ -4,9 +4,9 @@ Network Tools 0.1.0 directly depends on these runtime packages:
| Package | Pinned version | Declared licence |
| -------------------------------- | -------------: | ---------------- |
| `@add-ideas/toolbox-contract` | 0.2.3 | Apache-2.0 |
| `@add-ideas/toolbox-helpers` | 0.1.0 | GPL-3.0-or-later |
| `@add-ideas/toolbox-shell-react` | 0.2.3 | Apache-2.0 |
| `@add-ideas/toolbox-contract` | 0.3.0 | Apache-2.0 |
| `@add-ideas/toolbox-helpers` | 0.2.0 | GPL-3.0-or-later |
| `@add-ideas/toolbox-shell-react` | 0.3.0 | Apache-2.0 |
| `react` | 19.2.8 | MIT |
| `react-dom` | 19.2.8 | MIT |
+4 -3
View File
@@ -3,8 +3,9 @@
Network Tools is a static React/Vite application wrapped in the shared Toolbox shell. `Workbench.tsx` owns only transient view state and delegates to small pure modules:
- `network/url.ts` resolves and decomposes URLs with the platform `URL` parser and returns a password-redacted display value.
- `network/dns.ts` constructs one bounded zone-file record; IPv4 and IPv6 parsing comes from `@add-ideas/toolbox-helpers`.
- `network/http.ts` parses a pasted header block and constructs an explicit CSP from source tokens.
- `network/vlsm.ts` parses bounded `name,hosts` requirements, sorts largest-first and allocates aligned IPv4 blocks atomically inside one parsed base CIDR.
- `network/dns.ts` constructs one bounded zone-file record and inertly parses complete pasted zone text. The zone parser joins bounded parenthesized records, honours local `$ORIGIN`/`$TTL`, validates common RDATA and retains unsupported record types as clearly marked syntax-only data. It rejects rather than follows external/generative directives such as `$INCLUDE`.
- `network/http.ts` parses a pasted header block, analyses a deployed CSP plus baseline response-header protections, and constructs an explicit CSP from source tokens.
- `network/mime.ts` is a project-authored offline reference table.
All version 0.1 operations are short, bounded and synchronous, so the app does not create a worker. There is no server API, service worker, persistence layer or runtime lookup. Relative entry and asset URLs keep the production build relocatable below a nested portal path.
All operations are short, bounded and synchronous, so the app does not create a worker. VLSM is capped at 1,024 requirements; zone text at 2 MiB/50,000 physical lines/20,000 records; headers at 256 KiB/2,048 fields and CSP at 128 KiB. There is no server API, persistence layer or runtime lookup. Relative entry and asset URLs keep the production build relocatable below a nested portal path.
+3 -3
View File
@@ -1,7 +1,7 @@
# Privacy and security
Network Tools has no runtime network operation. Entering a URL does not visit it; constructing a DNS record does not perform a DNS query; and the MIME reference is bundled in the app. There is no account, telemetry, analytics, persistence or imported active content.
Network Tools has no runtime network operation. Entering a URL does not visit it; constructing or parsing DNS data does not perform a DNS query; `$INCLUDE` and other external zone directives are rejected; pasted headers are never requested; and the MIME reference is bundled in the app. There is no account, telemetry, analytics, persistence or imported active content.
Inputs and results stay in React memory until they are replaced or the page is closed. URL passwords are removed from the displayed resolved URL, but query strings, fragments and the original input remain visible and may still contain secrets. Header findings and generated CSP are advisory, not a complete security audit.
Inputs and results stay in React memory until they are replaced or the page is closed. URL passwords are removed from the displayed resolved URL, but query strings, fragments and the original input remain visible and may still contain secrets. VLSM output assumes conventional IPv4 network/broadcast reservations. Zone validation covers common record semantics and labels all other records as syntax-only. Header/CSP findings are defensive review prompts, not proof that an application is secure or correctly deployed.
The URL parser rejects inputs above 16 KiB, the header parser rejects blocks above 256 KiB and obsolete folding/control characters, TXT character strings are limited to 255 UTF-8 bytes, and DNS names/numbers are syntax- and range-checked. These limits reduce accidental resource use; they do not make copied output trustworthy for an unrelated system.
The URL parser rejects inputs above 16 KiB, the header parser rejects blocks above 256 KiB and obsolete folding/control characters, TXT character strings are limited to 255 UTF-8 bytes, and DNS names/numbers are syntax- and range-checked. Zone and VLSM bounds are documented in the architecture. These limits reduce accidental resource use; they do not make copied output trustworthy for an unrelated system.
+1 -1
View File
@@ -1,5 +1,5 @@
const CACHE_PREFIX = "network-tools-shell-";
const CACHE_NAME = CACHE_PREFIX + "0.1.0";
const CACHE_NAME = CACHE_PREFIX + "0.2.0";
const CORE = ["./", "./manifest.webmanifest", "./favicon.svg"];
self.addEventListener("install", (event) => {
event.waitUntil(
+12 -1
View File
@@ -3,7 +3,7 @@
"schemaVersion": 1,
"id": "de.add-ideas.network-tools",
"name": "Network Tools",
"version": "0.1.0",
"version": "0.2.0",
"description": "Calculate and construct network values locally in the browser.",
"entry": "./",
"icon": "./favicon.svg",
@@ -21,6 +21,17 @@
"crossOriginIsolated": false,
"topLevelContext": false
},
"io": {
"accepts": [
{ "mediaType": "text/plain", "extensions": [".txt", ".zone"] },
{ "mediaType": "application/json", "extensions": [".json"] }
],
"produces": [
{ "mediaType": "text/plain", "extensions": [".txt", ".zone"] },
{ "mediaType": "application/json", "extensions": [".json"] }
]
},
"capabilities": { "required": [], "optional": [] },
"privacy": {
"processing": "local",
"fileUploads": false,