Release Network Tools 0.2.0
Verify / verify (push) Canceled after 0s

This commit is contained in:
2026-09-02 11:38:57 +02:00
parent 729430295b
commit 429b55d587
30 changed files with 1474 additions and 96 deletions
+4 -3
View File
@@ -3,8 +3,9 @@
Network Tools is a static React/Vite application wrapped in the shared Toolbox shell. `Workbench.tsx` owns only transient view state and delegates to small pure modules:
- `network/url.ts` resolves and decomposes URLs with the platform `URL` parser and returns a password-redacted display value.
- `network/dns.ts` constructs one bounded zone-file record; IPv4 and IPv6 parsing comes from `@add-ideas/toolbox-helpers`.
- `network/http.ts` parses a pasted header block and constructs an explicit CSP from source tokens.
- `network/vlsm.ts` parses bounded `name,hosts` requirements, sorts largest-first and allocates aligned IPv4 blocks atomically inside one parsed base CIDR.
- `network/dns.ts` constructs one bounded zone-file record and inertly parses complete pasted zone text. The zone parser joins bounded parenthesized records, honours local `$ORIGIN`/`$TTL`, validates common RDATA and retains unsupported record types as clearly marked syntax-only data. It rejects rather than follows external/generative directives such as `$INCLUDE`.
- `network/http.ts` parses a pasted header block, analyses a deployed CSP plus baseline response-header protections, and constructs an explicit CSP from source tokens.
- `network/mime.ts` is a project-authored offline reference table.
All version 0.1 operations are short, bounded and synchronous, so the app does not create a worker. There is no server API, service worker, persistence layer or runtime lookup. Relative entry and asset URLs keep the production build relocatable below a nested portal path.
All operations are short, bounded and synchronous, so the app does not create a worker. VLSM is capped at 1,024 requirements; zone text at 2 MiB/50,000 physical lines/20,000 records; headers at 256 KiB/2,048 fields and CSP at 128 KiB. There is no server API, persistence layer or runtime lookup. Relative entry and asset URLs keep the production build relocatable below a nested portal path.
+3 -3
View File
@@ -1,7 +1,7 @@
# Privacy and security
Network Tools has no runtime network operation. Entering a URL does not visit it; constructing a DNS record does not perform a DNS query; and the MIME reference is bundled in the app. There is no account, telemetry, analytics, persistence or imported active content.
Network Tools has no runtime network operation. Entering a URL does not visit it; constructing or parsing DNS data does not perform a DNS query; `$INCLUDE` and other external zone directives are rejected; pasted headers are never requested; and the MIME reference is bundled in the app. There is no account, telemetry, analytics, persistence or imported active content.
Inputs and results stay in React memory until they are replaced or the page is closed. URL passwords are removed from the displayed resolved URL, but query strings, fragments and the original input remain visible and may still contain secrets. Header findings and generated CSP are advisory, not a complete security audit.
Inputs and results stay in React memory until they are replaced or the page is closed. URL passwords are removed from the displayed resolved URL, but query strings, fragments and the original input remain visible and may still contain secrets. VLSM output assumes conventional IPv4 network/broadcast reservations. Zone validation covers common record semantics and labels all other records as syntax-only. Header/CSP findings are defensive review prompts, not proof that an application is secure or correctly deployed.
The URL parser rejects inputs above 16 KiB, the header parser rejects blocks above 256 KiB and obsolete folding/control characters, TXT character strings are limited to 255 UTF-8 bytes, and DNS names/numbers are syntax- and range-checked. These limits reduce accidental resource use; they do not make copied output trustworthy for an unrelated system.
The URL parser rejects inputs above 16 KiB, the header parser rejects blocks above 256 KiB and obsolete folding/control characters, TXT character strings are limited to 255 UTF-8 bytes, and DNS names/numbers are syntax- and range-checked. Zone and VLSM bounds are documented in the architecture. These limits reduce accidental resource use; they do not make copied output trustworthy for an unrelated system.