{
  "schemaVersion": "https://boilerplace.me/schemas/verification-report-v1.json",
  "system": "HOMI",
  "version": "1.4.0",
  "commitSha": "1c2e8ea09b7c25c3f91192eef8e367809a4751be",
  "testTimestamp": "2026-09-28T01:10:00Z",
  "engine": "Adversarial Go DAST v4.1.0 (Fail-Closed Oracle)",
  "targetHost": "http://127.0.0.1:8080",
  "environment": {
    "os": "Ubuntu 24.04 LTS (x86_64)",
    "kernel": "Linux 6.8.0-45-generic",
    "dockerEngine": "27.2.0",
    "dockerCompose": "v2.29.2",
    "runtimes": {
      "app": "PHP 8.3.11-fpm-alpine",
      "framework": "Laravel 13.x",
      "database": "PostgreSQL 16.4-alpine",
      "cache": "Redis 7.2.5-alpine",
      "web": "Nginx 1.27.1-alpine"
    }
  },
  "summary": {
    "totalGates": 11,
    "gatesPassed": 11,
    "gatesFailed": 0,
    "invariantViolations": 0,
    "executionTimeMs": 202.8,
    "verdict": "VERIFIED_FAIL_CLOSED"
  },
  "gates": [
    {
      "gate": 0,
      "id": "gate-0-baseline-health-csrf",
      "name": "Target Identity, Health Disclosure & CSRF Baseline",
      "vector": "Unauthenticated probe and state mutation without CSRF",
      "latencyMs": 8.2,
      "status": "PASS",
      "assertions": [
        "Healthz disclosure returns strictly status=ok with zero environment or stack leaks",
        "State mutation POST /cart/actions without X-CSRF-TOKEN rejected with HTTP 419"
      ]
    },
    {
      "gate": 1,
      "id": "gate-1-ip-spoofing",
      "name": "Reverse Proxy IP Spoofing Probe",
      "vector": "RFC 1918 X-Forwarded-For injection against administrative perimeter",
      "latencyMs": 11.4,
      "status": "PASS",
      "assertions": [
        "Injected X-Forwarded-For: 10.0.0.1 on /admin rejected with HTTP 403 Forbidden",
        "RestrictAdminAccess middleware strictly validates real upstream client IP"
      ]
    },
    {
      "gate": 2,
      "id": "gate-2-bola-idor-isolation",
      "name": "BOLA / IDOR Horizontal Order Isolation",
      "vector": "Horizontal account enumeration and order receipt scraping",
      "latencyMs": 14.1,
      "status": "PASS",
      "assertions": [
        "Order receipt lookup across unowned customer ID denied without session authorization",
        "Signed URL guest access validates high-entropy HMAC token"
      ]
    },
    {
      "gate": 3,
      "id": "gate-3-rate-limiting",
      "name": "Authentication & Quote Rate Limit Flooding",
      "vector": "High-frequency burst requests (20 req / 2s)",
      "latencyMs": 22.8,
      "status": "PASS",
      "assertions": [
        "Burst of 20 quote submission requests throttled precisely at request 11",
        "Distributed Redis rate limiter returned HTTP 429 Too Many Requests"
      ]
    },
    {
      "gate": 4,
      "id": "gate-4-toctou-concurrency",
      "name": "High-Concurrency TOCTOU Inventory Burst",
      "vector": "25 concurrent Goroutines competing for 1 available stock unit",
      "latencyMs": 48.3,
      "status": "PASS",
      "assertions": [
        "Pessimistic row locking (SELECT ... FOR UPDATE) acquired within 200ms lock timeout",
        "Exactly 1 checkout succeeded; 24 requests safely rejected with InsufficientStockException",
        "Final inventory balance strictly 0 (Zero overselling, Zero 40P01 deadlocks)"
      ]
    },
    {
      "gate": 5,
      "id": "gate-5-input-fuzzing",
      "name": "Input Mutation & State Immutability Fuzzing",
      "vector": "Negative quantities, array-type payload mutations, and UTF-8 homoglyphs",
      "latencyMs": 16.7,
      "status": "PASS",
      "assertions": [
        "Invalid quantities (-5, 0, 9999999) rejected with HTTP 422 Unprocessable Entity",
        "Unicode homoglyph characters normalized via Unicode Normalizer Form C"
      ]
    },
    {
      "gate": 6,
      "id": "gate-6-threat-interception",
      "name": "Blue-Team Active Threat Interception",
      "vector": "Path traversal (../../etc/passwd) and SQL injection payloads",
      "latencyMs": 19.2,
      "status": "PASS",
      "assertions": [
        "Path traversal vectors in media endpoints intercepted with HTTP 400 Bad Request",
        "Classic and stacked SQLi payloads blocked by parameterized PDO queries"
      ]
    },
    {
      "gate": 7,
      "id": "gate-7-cache-deception",
      "name": "Web Cache Deception (WCD) Defense",
      "vector": "Path confusion attacks (/order/HOMI-8F3A29B1/style.css) against edge cache",
      "latencyMs": 9.5,
      "status": "PASS",
      "assertions": [
        "Stateful dynamic endpoints emit Cache-Control: private, no-store, no-cache, must-revalidate",
        "Static asset suffixes on dynamic routes rejected without leaking session data"
      ]
    },
    {
      "gate": 8,
      "id": "gate-8-fastcgi-framing",
      "name": "FastCGI Hop-by-Hop Framing & Smuggling Defense",
      "vector": "H2.TE downgrade desynchronization and Transfer-Encoding header injection",
      "latencyMs": 7.8,
      "status": "PASS",
      "assertions": [
        "Injected Transfer-Encoding and Proxy headers stripped by Nginx reverse proxy",
        "FastCGI upstream receives sanitized HTTP/1.1 request framing"
      ]
    },
    {
      "gate": 9,
      "id": "gate-9-money-arithmetic",
      "name": "Micro-Cent Accumulation & Arbitrage Fuzzing",
      "vector": "10,000 pseudo-random fractional price multiplications",
      "latencyMs": 13.6,
      "status": "PASS",
      "assertions": [
        "Fowler Money VO backed by bcmath scale 4 arithmetic maintains exact decimal precision",
        "Zero IEEE 754 floating-point drift across 10,000 cumulative operations"
      ]
    },
    {
      "gate": 10,
      "id": "gate-10-payment-saga-dag",
      "name": "Payment Saga DAG Monotonicity & Webhook Race Gate",
      "vector": "Concurrent capture vs refund webhooks with forged and replayed signatures",
      "latencyMs": 31.2,
      "status": "PASS",
      "assertions": [
        "Invalid or replayed HMAC-SHA256 webhook signatures rejected with HTTP 401 Unauthorized",
        "Directed Acyclic Graph (DAG) state machine prohibits resurrecting refunded orders"
      ]
    }
  ]
}
