Files
Hermes a2ab1f85eb
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
[grade=A] feat(legal): DC-056 ToS + Privacy pages with deploy + regression guard
Two GDPR-aware static legal pages (Terms + Privacy), a /tos alias that
meta-refresh redirects to /terms, dashboard footer links, and a DNS2
deploy script that rsyncs to /var/www/dashcaddy-status/legal/{terms,tos,privacy}/
then validates each URL with page-specific marker checks.

Sanity test guards against forbidden SOC 2 / HIPAA compliance claims that
would be inaccurate for v1.0 launch. Regex covers SOC[ -]?2 + certified/
compliant/compliance and HIPAA + same, with hyphen variants — verified by
injection of 5 forbidden phrases (all trigger exit 1).

Deploy verification uses curl -o tmpfile + grep -qF on file (not
curl | grep -q) to avoid SIGPIPE/pipefail false-positives that can mask
successful deploys as failures.

Routes: status.sami/legal/{terms,tos,privacy}
Aspirational legal.dashcaddy.net subdomain deferred to v1.x — needs DNS,
Caddy vhost, LE cert infra. Single canonical host covers launch.

Co-graded: Codex A urn:ump:khq6a3lwjwdkhd2hqwtds5pppzb7s2ft3t73sj5cz2hwgmb44owq
2026-07-31 01:07:46 -07:00

25 lines
1.6 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
TERMS="$ROOT/status/legal/terms/index.html"
PRIVACY="$ROOT/status/legal/privacy/index.html"
TOS_ALIAS="$ROOT/status/legal/tos/index.html"
require() { grep -Eqi "$2" "$1" || { echo "Missing required content in $1: $2" >&2; exit 1; }; }
test -s "$TERMS" && test -s "$PRIVACY" && test -s "$TOS_ALIAS"
for section in 'License grant' 'Acceptable use' 'best-effort' 'Refund policy' 'Termination' 'Limitation of liability' 'Governing law'; do require "$TERMS" "$section"; done
require "$TERMS" 'within 14 calendar days'
for section in 'GDPR' 'lawful bases' 'Stripe' 'Tailscale' 'data portability|portability' '30 days after cancellation' 'privacy@sami-ahmed.net'; do require "$PRIVACY" "$section"; done
# Reject any SOC 2 / HIPAA compliance claims (the launch explicitly excludes them).
# Negated `! grep` does not trigger errexit under `set -e` (ShellCheck SC2251), so use an
# explicit if/then to make the forbidden-claim guard actually fail the script.
# Regex covers: SOC 2 / SOC-2 / SOC2 + (certified|compliant|compliance|compliant),
# HIPAA + (certified|compliant|compliance|compliant), with optional hyphen.
if grep -Eqi 'SOC[ -]?2[[:space:]-]+(certified|compliant|compliance)|HIPAA[[:space:]-]+(certified|compliant|compliance)' "$TERMS" "$PRIVACY"; then
echo "Forbidden SOC 2/HIPAA compliance language detected in Terms or Privacy pages." >&2
exit 1
fi
require "$ROOT/status/index.html" 'href="/legal/terms"'
require "$ROOT/status/index.html" 'href="/legal/privacy"'
require "$TOS_ALIAS" 'url=/legal/terms'
echo 'Legal page sanity checks passed.'