chore: save iqon static deploy snapshot

This commit is contained in:
Sergei Vasilev
2026-05-20 17:21:42 +03:00
parent 497f2450e9
commit c023fe5d8d
121 changed files with 3211 additions and 24373 deletions
+123
View File
@@ -0,0 +1,123 @@
# IQON Phase 1 Hardening Package
Purpose: локальный пакет временного hardening для live WordPress `iqon.com` до полноценного редизайна или статической замены.
## Contents
- [Scope](#scope)
- [Files](#files)
- [Install Draft](#install-draft)
- [Hosting Rule Draft](#hosting-rule-draft)
- [Automated Verification Script](#automated-verification-script)
- [Verification](#verification)
- [Rollback](#rollback)
- [Limits](#limits)
## Scope
Пакет не был установлен на live-сайт. Он подготовлен как reversible snippet для Code Snippets и должен применяться только после отдельного подтверждения на запись во внешний WordPress.
## Files
| File | Role |
|------|------|
| `wp-snippets/iqon-phase1-hardening.php` | PHP snippet for Code Snippets, "Run snippet everywhere" |
| `wp-snippets/hosting-rules.md` | nginx/Apache/file-level drafts for install docs and XML-RPC |
| `scripts/iqon-phase1-verify.sh` | Post-activation verification script |
## Install Draft
1. Открыть WordPress admin через текущий безопасный маршрут доступа.
2. Создать новый snippet с названием `IQON Phase 1 hardening`.
3. Вставить содержимое `wp-snippets/iqon-phase1-hardening.php`.
4. Выбрать режим `Run snippet everywhere`.
5. Сохранить snippet как inactive draft.
6. Сделать свежий backup файлов и базы перед активацией.
7. Активировать snippet.
8. Сразу выполнить проверки из раздела Verification.
## Hosting Rule Draft
PHP snippet не гарантирует блокировку физических файлов, которые веб-сервер отдаёт до WordPress. Для `readme.html` и `license.html` нужен server-level блок или удаление файлов.
nginx draft:
```nginx
location ~* ^/(readme|license)\.html$ {
return 404;
}
```
Если на reg.ru shared hosting нет доступа к nginx-конфигу, проверить доступные механизмы: панель хостинга, `.htaccess`, файловый менеджер или удаление публичных install-doc файлов после backup.
Detailed drafts are in `wp-snippets/hosting-rules.md`.
## Automated Verification Script
After activation:
```bash
scripts/iqon-phase1-verify.sh https://iqon.com
```
Expected signal: final line is `[OK] iqon Phase 1 verification passed for https://iqon.com`.
## Verification
Run after activation:
```bash
curl -I -L https://iqon.com/
```
Expected signal: response includes `X-Content-Type-Options`, `X-Frame-Options`, `Referrer-Policy`, `Permissions-Policy`, and `Content-Security-Policy`.
```bash
curl -sS https://iqon.com/wp-json/wp/v2/users
```
Expected signal: no public list of usernames is returned.
```bash
curl -sS https://iqon.com/ | rg 'http://www\.iqon\.com|http://iqon\.com|http://maps\.google\.com'
```
Expected signal: no output.
```bash
curl -sS https://iqon.com/ | rg 'name="viewport"|iqon-skip-link|og:site_name'
```
Expected signal: viewport exists, skip link exists, site metadata no longer shows `- IQON`.
```bash
curl -I -L https://iqon.com/readme.html
```
Expected signal after hosting rule: `403` or `404`. If it still returns `200`, WordPress snippet is bypassed by static file serving and hosting-level action is still required.
```bash
curl -I --http1.1 https://iqon.com/xmlrpc.php
```
Expected signal: no usable XML-RPC behavior. A stronger check is a safe XML-RPC POST from a test client after confirming no production integrations depend on it.
## Rollback
1. Disable the `IQON Phase 1 hardening` snippet.
2. Clear any page/cache layer if present.
3. Re-run the same curl checks and compare before/after.
4. Remove hosting rule only if it caused a confirmed false positive.
## Limits
- This package does not replace the contact form or legacy CAPTCHA.
- This package does not fix duplicate sitemap URLs.
- This package does not modernize the WordPress theme.
- This package does not verify canonical contact data.
- This package does not confirm the exact WordPress core version.
---
*Created: 20 May 2026*
*Updated: 20 May 2026*