Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
58 changes: 58 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,64 @@ move: the JSON report's `schemaVersion` and the baseline file's. Both are bumped
a field is removed, renamed, or changes meaning — new fields may appear without one, so
consumers must ignore what they do not recognise.

## Unreleased — 0.9.0

### Added

- **`init` sets up the baseline and the CI workflow as well as the config.** After the
config it offers a baseline, when a built site is already there, and points the
config's `audit` block at it. It also offers a GitHub Actions workflow, when the project
is in a git repository. The workflow is written for the project: package manager, build
script, build directory, baseline, `working-directory` in a monorepo, and the action
pinned to this release. An existing workflow is never overwritten. `--no-baseline` and
`--no-ci` turn either offer off.
- **Errors say what to type next.** The exit-2 paths a new user is likely to meet end with
the command that fixes them, on a line of their own:
- a missing config points at `eaa-kit init`;
- a language the country does not have points at `--lang` with one it does;
- an unknown country points at `eaa-kit countries`;
- a missing report, baseline or review record points at the command that writes one;
- a mistyped flag points at that command's `--help`.

Errors carry this as a `next` field, so the message still says only what went wrong.
- **Five more statement templates: Belgium in German, and Czechia, Denmark, Finland and
Sweden.** Each new country has its own language and English; `cs`, `da`, `fi` and `sv`
are new `--lang` values. That makes fifteen countries and thirty-one templates.
`init` now reads `sv`, `da` and `cs` as their countries too.

**Given up, as in 0.8.0:** these citations come from regulators' pages, government
portals and law firms, because the official gazettes could not be reached. They are
marked unverified and cite no article numbers and no fines. Finland has no Swedish
rendering yet.

- **Redirects are found before the crawl, and a redirect to another site is never
followed without agreement.** The entry URL is followed one hop at a time first. When
it leads to another site, as `www.gtainside.de` does to `www.gtainside.com`, the new
`--redirects` option decides what happens:
- `ask`, the default, asks at the terminal, and stops when there is nobody to ask;
- `follow` goes on;
- `stop` never does.

Stopping names the two commands that go on. A redirect within the same site (`www.`,
http to https) is followed without a question. A followed redirect is recorded in every
report: two console lines above the counts, a *Redirected* row in the HTML report,
`completeness.entryRedirect` in the JSON report and an `entryRedirect` property in SARIF.
There is a `redirects` config key and a `redirects` input on the GitHub Action.
- **A sign-in wall stops the run instead of being audited as the site.** It is caught
from evidence the site gives: a 401 or 403, a redirect to an identity provider, a
redirect to a sign-in path, or a redirect to a page with a password field. The run
exits 2 with the credentials flag to use. Credentials are no longer sent past a hop
that leaves the entry's origin. Pages that all land on one address during the crawl are
now called a sign-in page when that page has a password field.

### Changed

- A crawl whose entry URL redirects to another site used to fail every page as
"redirected off" and end with "Could not fetch". It now stops before crawling, says
where the site went, and names the commands to go on. The exit code is 2 either way.
- The baseline and review-record errors no longer put their fix in the message text. It
moved to the error's `next` field, which the CLI prints under the message.

## Unreleased — 0.8.0

### Added
Expand Down
14 changes: 7 additions & 7 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,9 @@ Build-time WCAG 2.2 AA auditor and EU accessibility statement generator for stat
built for the freelancers and small agencies who have to comply with the European
Accessibility Act (in force since 28 June 2025) without an accessibility budget. It started
in the DACH region — the BFSG in Germany, the BaFG in Austria — and the statement now names
the statute and supervisory body of **eleven countries**: Austria, Belgium, Germany,
Switzerland, Spain, France, Ireland, Italy, the Netherlands, Poland and Portugal, each in
its own language as well as English.
the statute and supervisory body of **fifteen countries**: Austria, Belgium, Czechia,
Denmark, Finland, France, Germany, Ireland, Italy, the Netherlands, Poland, Portugal,
Spain, Sweden and Switzerland, each in its own language as well as English.

0.7.0 makes a run cost what it should. A page that has not changed byte for byte is not
audited again, and a run with nothing to re-audit never loads an engine at all: twenty
Expand All @@ -28,8 +28,8 @@ Sites behind a login or a preview protection are auditable too.
npx eaa-kit # nothing to set up: finds your site, audits it, writes a report
npx eaa-kit audit # WCAG 2.2 AA report; finds your build itself
npx eaa-kit diff a.json b.json # what a change made worse, and what it fixed
npx eaa-kit init # write an eaa.config.json
npx eaa-kit statement # accessibility statement, in one of eleven countries
npx eaa-kit init # the config, a baseline and a CI workflow
npx eaa-kit statement # accessibility statement, in one of fifteen countries
npx eaa-kit countries # which ones, in which languages, under which law
npx eaa-kit checklist # the manual review no engine can do for you
```
Expand Down Expand Up @@ -75,7 +75,7 @@ listing the barriers a real audit found.

```bash
eaa-kit statement --output src/content/a11y.md
eaa-kit statement --country PL --lang pl # eaa-kit countries lists all eleven
eaa-kit statement --country PL --lang pl # eaa-kit countries lists all fifteen
```

Each country's statement is a document under its own law rather than a translation of
Expand Down Expand Up @@ -193,7 +193,7 @@ eaa-kit audit --url https://preview.example.com --basic-auth user:password
| --- | --- |
| [Auditing a build](docs/audit.md) | The `audit` command, both engines, exit codes, and what an automated run can and cannot tell you |
| [Defaults from eaa.config](docs/audit.md#defaults-from-eaaconfig) | Writing the flags down once, and what still overrides them |
| [The statement command](docs/statement.md) | The config file, the eleven countries, and filling a statement from audit results |
| [The statement command](docs/statement.md) | The config file, the fifteen countries, and filling a statement from audit results |
| [Baselines](docs/baseline.md) | Adopting the tool on a site that already has violations |
| [Comparing two runs](docs/reports.md#comparing-two-runs) | The `diff` command, and what it refuses to call fixed |
| [Coverage of WCAG](docs/audit.md#how-much-of-wcag-a-run-reaches) | What an automated engine can reach at all, and what it cannot |
Expand Down
97 changes: 95 additions & 2 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,12 +19,105 @@ having to learn the tool first. Three releases get there:
a result made short enough to use while working rather than after.
- **0.9.0 — the first ten minutes.** Everything a new user meets before their first useful
result: `init` that sets up CI and a baseline as well as a config, errors that say what to
type next, and a German rendering for Belgium's third language community. The countries
after this release's four — Sweden, Denmark, Finland, Czechia — go here, with the same rule.
type next, a German rendering for Belgium's third language community, and Sweden,
Denmark, Finland and Czechia.
- **1.0.0 — the promise.** The JSON report, the review record, the baseline and the config
file frozen as documented contracts under semver, with a migration note for anything that
changed on the way. No new surface: 1.0 is 0.9 with the guarantees written down.

## 0.9.0 — the first ten minutes

0.8.0 made the first command do the useful thing. 0.9.0 is about the next few: the ones a
new user runs after the first report, and what they read when one of those goes wrong.

### 1. `init` sets up the project, not only the config

A config file is one of three things a project needs before the tool is doing its job. The
other two are a baseline, so CI fails on new barriers rather than on every existing one,
and the CI job itself. `init` now offers both after writing the config:

- **A baseline**, when there is a built site to record it from. `init` never runs a build
to get one. Recording it says how many barriers it accepts, the config's `audit` block
points at it so a local `eaa-kit audit` reads it too, and the accepted barriers are still
reported on every run, as they always have been.
- **A GitHub Actions workflow** at `.github/workflows/accessibility.yml`, when the project
is in a git repository. It is written for this project: the package manager from the
lockfile, the build script if there is one, the build directory `init` found, the
baseline if one was just recorded, and the action pinned to this exact release.

The refusals: an existing workflow file is never overwritten. Nothing is set up that was
not offered. `--no-ci` and `--no-baseline` answer for a script. With `--yes` the defaults
apply, which means a workflow only inside a git repository and a baseline only when a
build is already there.

### 2. Errors say what to type next

Every exit-2 path a new user is likely to hit ends with the command that fixes it:

- No config: `eaa-kit init`.
- No template in that language: `--lang` with the languages the country has.
- An unknown country: `eaa-kit countries`.
- A missing or outdated report, baseline or review record: the command that writes one.
- A mistyped flag: the command's `--help`.

The rule is the one `start` already follows. An error that the reader cannot act on
without opening the docs is half an error.

### 3. Belgium in German, and four more countries: Sweden, Denmark, Finland, Czechia

| | Statute | Supervision named | Languages |
| --- | --- | --- | --- |
| `BE` | as 0.8.0 | as 0.8.0, in German | `de` added |
| `CZ` | Zákon č. 424/2023 Sb., o požadavcích na přístupnost některých výrobků a služeb | Česká obchodní inspekce (ČOI) | `cs`, `en` |
| `DK` | Lov nr. 801 af 7. juni 2022 om tilgængelighedskrav for produkter og tjenester | Sikkerhedsstyrelsen for e-commerce; supervision is split | `da`, `en` |
| `FI` | Laki digitaalisten palvelujen tarjoamisesta (306/2019), as amended for the Directive | Traficom | `fi`, `en` |
| `SE` | Lag (2023:254) om vissa produkters och tjänsters tillgänglighet | Post- och telestyrelsen (PTS) | `sv`, `en` |

**Written from secondary sources, like 0.8.0's four.** The official gazettes are still not
reachable from where this work is done, and the decision was to go ahead rather than wait.
All five are marked unverified in the registry, in `eaa-kit countries` and in the docs.
Their citations are kept to the statute and the supervisor, with no article numbers and
no fines, for the same reason as 0.8.0's. Nine countries' citations now need checking
against the primary text before the release that carries them is tagged.

Finland's Swedish rendering is not in this release. Swedish is an official language there
and the law exists in Swedish, but a Finnish statement in Swedish is a document of its
own, and it waits for a source text.

### 4. Redirects and sign-in walls, found before the crawl

Two things put a crawl somewhere other than where it was sent. Before this release, one
was found too late and the other only by guessing.

- **A redirect to another site.** `https://www.gtainside.de` answers with a 301 to
`https://www.gtainside.com`. The crawl refused every page as "redirected off" and ended
on an error that did not say what to do. Now the entry is followed one redirect at a
time before the crawl, and a redirect to another site stops the run with where it went
and the two commands that go on: audit the destination, or `--redirects follow`. In a
terminal the default, `ask`, puts the question instead. A redirect within the same site
(`www.`, http to https) is followed without a question. Every redirect the run followed
is written into all four report formats, because a reader who asked for one site and
is reading about another has to find that out before the first finding.
- **A sign-in wall.** A 401 or 403, a redirect to an identity provider, a redirect to a
page that is a sign-in page by name, or a redirect to a page with a password field
stops the run with exit 2 and the credentials flag to use. Before, the run audited the
login form and reported it as the site. The weaker signal found during the crawl, many
pages landing on one address, is now called a sign-in page when that page has a
password field, and "looks like one" otherwise.

The refusals: a redirect to another site is never followed without a flag or a yes. The
destination passes the same `--allow-remote` gate as the entry. Credentials are only sent
while the redirect chain stays on the entry's origin. A redirect the run did not follow
produces no report, because a report about the wrong site is the failure being
prevented.

### Done means

- `lint`, `typecheck`, `test` (with colour forced as well as without), `smoke` and the
packaged-CLI run green across the CI matrix.
- The citation check for 0.8.0's four countries and this release's five, recorded in the
changelog, before either version is tagged.

## 0.8.0 — reach

0.7.0 made a run cost what it should. 0.8.0 spends that on two things: getting the tool to
Expand Down
12 changes: 12 additions & 0 deletions action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,14 @@ inputs:
link following alone finds only what the navigation links to.
required: false
default: ''
redirects:
description: >-
What to do when "url" redirects to another site: ask, follow or stop.
A workflow has nobody to ask, so ask behaves as stop there, and the run
fails with where the site went. Set follow to go on and have the SARIF
log record the redirect. Only used with "url".
required: false
default: ''
max-pages:
description: Stop the crawl after this many pages.
required: false
Expand Down Expand Up @@ -177,6 +185,7 @@ runs:
EAA_URL: ${{ inputs.url }}
EAA_ALLOW_REMOTE: ${{ inputs.allow-remote }}
EAA_SITEMAP: ${{ inputs.sitemap }}
EAA_REDIRECTS: ${{ inputs.redirects }}
EAA_MAX_PAGES: ${{ inputs.max-pages }}
EAA_FAIL_ON: ${{ inputs.fail-on }}
EAA_SARIF: ${{ inputs.sarif-file }}
Expand All @@ -203,6 +212,9 @@ runs:
if [ -n "$EAA_SITEMAP" ]; then
args+=(--sitemap "$EAA_SITEMAP")
fi
if [ -n "$EAA_REDIRECTS" ]; then
args+=(--redirects "$EAA_REDIRECTS")
fi
if [ -n "$EAA_MAX_PAGES" ]; then
args+=(--max-pages "$EAA_MAX_PAGES")
fi
Expand Down
Loading
Loading