28 KiB
28 KiB
API Security Testing Tool - Implementation Checklist
Project Start Date: 2025-11-08 Status: In Progress
✅ PROJECT SETUP
Initial Structure
- Create
/backenddirectory - Create
/frontenddirectory - Create
/confdirectory for Docker/Nginx configs - Create root
.gitignorefile
🐍 BACKEND - FOUNDATION
Python Project Setup
- Create
backend/pyproject.tomlwith project metadata - Create
backend/requirements.txtwith all dependencies - Create
backend/.python-version(specify Python 3.11) - Create
backend/.style.yapffor code formatting - Create
backend/.env.examplewith all required environment variables - Create
backend/__init__.py(empty, marks as package)
Core Configuration
- Create
backend/config.pywith Settings class (Pydantic BaseSettings) - Add all magic number constants to config.py (PASSWORD_MIN_LENGTH, MAX_REQUESTS_DEFAULT, etc.)
- Add database URL configuration
- Add JWT settings (SECRET_KEY, ALGORITHM, ACCESS_TOKEN_EXPIRE_MINUTES)
- Add CORS origins configuration
- Add scanner default settings
- Implement cached settings function with @lru_cache
Core Modules - backend/core/
- Create
backend/core/__init__.py - Create
backend/core/enums.pywith ScanStatus enum - Add Severity enum to enums.py
- Add TestType enum to enums.py
- Create
backend/core/database.pywith SQLAlchemy engine setup - Add SessionLocal factory to database.py
- Add Base declarative_base to database.py
- Add get_db() dependency function to database.py
- Create
backend/core/security.pywith bcrypt password hashing - Add JWT token creation function to security.py
- Add JWT token decode/verify function to security.py
- Create
backend/core/dependencies.pywith HTTPBearer security - Add get_current_user() dependency to dependencies.py
🗄️ BACKEND - DATA LAYER
Models - backend/models/
- Create
backend/models/__init__.py - Create
backend/models/User.py(thin, just table definition) - Create
backend/models/ScanResult.py(scan history table) - Create
backend/models/ApiTarget.py(optional: store target APIs)
Schemas (Pydantic V2) - backend/schemas/
- Create
backend/schemas/__init__.py - Create
backend/schemas/shared_schemas.pywith generic response models - Create
backend/schemas/user_schemas.pywith UserCreate schema - Add UserLogin schema to user_schemas.py
- Add UserResponse schema with ConfigDict(from_attributes=True) to user_schemas.py
- Add TokenResponse schema to user_schemas.py
- Create
backend/schemas/scan_schemas.pywith ScanRequest schema - Add ScanResult schema to scan_schemas.py (individual test result)
- Add ScanResponse schema to scan_schemas.py (complete scan response)
- Replace ALL magic numbers in Field() with config constants
TypedDicts - backend/types/
- Create
backend/types/__init__.py - Create
backend/types/scan_types.pywith ScannerResult TypedDict - Add ScannerConfig TypedDict to scan_types.py
- Create
backend/types/service_types.pywith service layer TypedDicts - Create
backend/types/repository_types.pywith UserDict TypedDict
Repositories - backend/repositories/
- Create
backend/repositories/__init__.py - Create
backend/repositories/shared_repository.pywith base repository functions - Create
backend/repositories/user_repository.pyas static class - Add get_by_email() method to UserRepository
- Add get_by_id() method to UserRepository
- Add create() method to UserRepository
- Add get_all_active() method to UserRepository
- Create
backend/repositories/scan_repository.pyas static class - Add save_scan() method to ScanRepository
- Add get_by_user() method to ScanRepository
- Add get_by_id() method to ScanRepository
🧠 BACKEND - BUSINESS LOGIC
Services - backend/services/
- Create
backend/services/__init__.py - Create
backend/services/auth_service.pywith AuthService class - Add register_user() method to AuthService
- Add login_user() method to AuthService (returns TokenResponse)
- Add password validation logic to AuthService
- Add user existence check to AuthService
- Create
backend/services/user_service.pywith UserService class - Add get_user_profile() method to UserService
- Add update_user() method to UserService
- Create
backend/services/scan_service.pywith ScanService class - Add run_scan() async method to ScanService
- Add get_scan_history() method to ScanService
- Add get_scan_by_id() method to ScanService
- Implement concurrent scanner execution with asyncio.gather() in ScanService
🔍 BACKEND - SECURITY SCANNERS
Base Scanner - backend/scanners/
- Create
backend/scanners/__init__.py - Create
backend/scanners/base_scanner.pywith BaseScanner ABC - Add abstract scan() method to BaseScanner
- Add _create_result() helper method to BaseScanner
Rate Limit Scanner
- Create
backend/scanners/rate_limit_scanner.pyinheriting BaseScanner - Implement concurrent request sending with httpx AsyncClient
- Add response analysis logic (count 429 status codes)
- Add vulnerability detection logic (no rate limiting = vulnerable)
- Add evidence collection (requests_sent, successful_requests, rate_limited)
- Add recommendations for vulnerable cases
- Add _send_request() helper method
Auth Scanner
- Create
backend/scanners/auth_scanner.pyinheriting BaseScanner - Implement expired token test
- Implement missing token test
- Implement malformed token test
- Implement token location tests (header/query/body)
- Add vulnerability detection logic
- Add evidence collection
- Add recommendations
SQLi Scanner
- Create
backend/scanners/sqli_scanner.pyinheriting BaseScanner - Define common SQLi payloads list
- Implement payload injection in URL params
- Implement payload injection in request body
- Implement error-based detection (look for SQL errors in responses)
- Implement time-based detection (measure response times)
- Add vulnerability detection logic
- Add evidence collection (vulnerable params, payloads that worked)
- Add recommendations
IDOR/BOLA Scanner
- Create
backend/scanners/idor_scanner.pyinheriting BaseScanner - Implement ID parameter detection in URLs
- Implement ID increment/decrement testing
- Implement unauthorized access detection (200 status = vulnerable)
- Add vulnerability detection logic
- Add evidence collection (accessible IDs, endpoints)
- Add recommendations
🛣️ BACKEND - API ROUTES
Routes - backend/routes/
- Create
backend/routes/__init__.py - Create
backend/routes/auth.pywith APIRouter - Add POST /api/auth/register endpoint (returns UserResponse)
- Add POST /api/auth/login endpoint (returns TokenResponse)
- Add exception handling for ValueError in auth routes
- Create
backend/routes/users.pywith APIRouter - Add GET /api/users/profile endpoint (protected)
- Add PUT /api/users/update endpoint (protected)
- Create
backend/routes/scans.pywith APIRouter - Add POST /api/scans/run endpoint (async, protected)
- Add GET /api/scans/history endpoint (protected)
- Add GET /api/scans/{scan_id} endpoint (protected)
Main Application
- Create
backend/main.pywith FastAPI app initialization - Add CORS middleware with configured origins
- Include auth router with prefix /api/auth
- Include users router with prefix /api/users
- Include scans router with prefix /api/scans
- Add root health check endpoint GET /
- Add database table creation (Base.metadata.create_all)
- Configure docs URL as /api/docs
- Configure redoc URL as /api/redoc
- Add uvicorn run configuration if name == "main"
⚛️ FRONTEND - FOUNDATION
Vite + React + TypeScript Setup
- Initialize Vite project with React + TypeScript template in /frontend
- Create
frontend/tsconfig.jsonwith strict mode enabled - Create
frontend/vite.config.tswith path aliases (@/) - Create
frontend/.eslintrc.cjswith TypeScript rules - Create
frontend/.prettierrcwith formatting rules - Create
frontend/.env.examplewith VITE_API_URL
Package Installation
- Install React and React-DOM
- Install react-router-dom for routing
- Install @tanstack/react-query for server state
- Install zustand for UI state management
- Install axios for HTTP requests
- Install zod for validation
- Install react-hook-form for forms
- Install @hookform/resolvers for Zod integration
- Install @radix-ui/react-tabs for accessible tabs
- Install @radix-ui/react-dialog for modals
- Install recharts for data visualization
- Install react-icons for icons
Frontend Structure
- Create
frontend/src/config/directory - Create
frontend/src/types/directory - Create
frontend/src/hooks/directory - Create
frontend/src/lib/directory - Create
frontend/src/store/directory - Create
frontend/src/services/directory - Create
frontend/src/components/directory - Create
frontend/src/pages/directory - Create
frontend/src/styles/directory
⚙️ FRONTEND - CONFIGURATION
Config Files - frontend/src/config/
- Create
frontend/src/config/constants.tswith APP_CONFIG object - Add ROUTES constants to constants.ts (LOGIN, REGISTER, DASHBOARD, etc.)
- Add UI_TEXT constants to constants.ts (buttons, headers, labels, placeholders, errors, success)
- Add SCAN_CONFIG constants to constants.ts (max requests, available tests)
- Add SEVERITY_CONFIG to constants.ts (colors, labels, icons)
- Create
frontend/src/config/api.tswith API_CONFIG object - Add BASE_URL to api.ts (from env var)
- Add TIMEOUT to api.ts
- Add all ENDPOINTS to api.ts (AUTH, SCANS, USERS)
- Create
frontend/src/config/theme.csswith CSS variables - Add color variables (primary, status colors, backgrounds, text, borders)
- Add spacing variables to theme.css
- Add border-radius variables to theme.css
- Add shadow variables to theme.css
- Add transition variables to theme.css
- Add typography variables to theme.css
- Add z-index layer variables to theme.css
📝 FRONTEND - TYPES
Type Definitions - frontend/src/types/
- Create
frontend/src/types/api.types.ts - Add LoginRequest interface to api.types.ts
- Add RegisterRequest interface to api.types.ts
- Add AuthResponse interface to api.types.ts
- Add UserResponse interface to api.types.ts
- Add TestType type union to api.types.ts
- Add ScanStatus type union to api.types.ts
- Add Severity type union to api.types.ts
- Add ScanRequest interface to api.types.ts
- Add ScanResult interface to api.types.ts
- Add ScanResponse interface to api.types.ts
- Create
frontend/src/types/scan.types.tsfor scanner-specific types - Create
frontend/src/types/auth.types.tsfor auth-specific types
🔌 FRONTEND - API INTEGRATION
API Client - frontend/src/lib/
- Create
frontend/src/lib/api.tswith axios instance creation - Configure axios baseURL from API_CONFIG
- Configure axios timeout
- Add request interceptor to attach JWT token from localStorage
- Add response interceptor to handle 401 errors (logout + redirect)
- Create
frontend/src/lib/queryClient.tswith TanStack Query setup - Configure default query options (refetchOnWindowFocus, retry, staleTime)
- Create
frontend/src/lib/utils.tsfor helper functions
Services - frontend/src/services/
- Create
frontend/src/services/authService.ts - Add login() function to authService (store token in localStorage)
- Add register() function to authService
- Add logout() function to authService (remove token + redirect)
- Add getToken() function to authService
- Add isAuthenticated() function to authService
- Create
frontend/src/services/scanService.ts - Add runScan() function to scanService
- Add getScanHistory() function to scanService
- Add getScanById() function to scanService
🪝 FRONTEND - CUSTOM HOOKS
Hooks - frontend/src/hooks/
- Create
frontend/src/hooks/useAuth.ts - Add useLogin() hook with useMutation (invalidates queries on success)
- Add useRegister() hook with useMutation
- Add useLogout() hook
- Add useAuth() hook (returns isAuthenticated + logout)
- Create
frontend/src/hooks/useScan.ts - Add useRunScan() hook with useMutation (invalidates scan history)
- Add useScanHistory() hook with useQuery
- Add useScan(scanId) hook with useQuery (enabled when scanId exists)
- Create
frontend/src/hooks/useLocalStorage.tsfor generic localStorage hook
🏪 FRONTEND - STATE MANAGEMENT
Zustand Store - frontend/src/store/
- Create
frontend/src/store/uiStore.tswith Zustand store - Add theme state (dark/light) to uiStore
- Add setTheme() action to uiStore
- Add toggleTheme() action to uiStore
- Add sidebarOpen state to uiStore
- Add toggleSidebar() action to uiStore
- Add isLoading state to uiStore
- Add setLoading() action to uiStore
- Implement persist middleware for theme and sidebarOpen
🎨 FRONTEND - COMMON COMPONENTS
Common Components - frontend/src/components/common/
- Create
frontend/src/components/common/Button.tsx - Add Button component with variant prop (primary, secondary, danger, success, ghost)
- Add size prop to Button (sm, md, lg)
- Add isLoading prop to Button (shows spinner)
- Create
frontend/src/styles/components/Button.csswith all variants - Create
frontend/src/components/common/Input.tsx - Add Input component with label, error, and all HTML input props
- Create
frontend/src/styles/components/Input.css - Create
frontend/src/components/common/Card.tsx - Create
frontend/src/styles/components/Card.css - Create
frontend/src/components/common/Badge.tsxfor status/severity badges - Create
frontend/src/styles/components/Badge.csswith severity colors - Create
frontend/src/components/common/LoadingSpinner.tsx - Create
frontend/src/styles/components/LoadingSpinner.css
🏗️ FRONTEND - LAYOUT COMPONENTS
Layout - frontend/src/components/layout/
- Create
frontend/src/components/layout/Header.tsx - Add logo/app name to Header
- Add user email display to Header
- Add logout button to Header
- Add theme toggle to Header
- Create
frontend/src/styles/components/Header.css - Create
frontend/src/components/layout/Sidebar.tsx - Add navigation links to Sidebar (Dashboard, Scan, History)
- Add active route highlighting to Sidebar
- Create
frontend/src/styles/components/Sidebar.css - Create
frontend/src/components/layout/Layout.tsxwith Outlet - Combine Header + Sidebar + main content area in Layout
- Create
frontend/src/styles/components/Layout.css
🔐 FRONTEND - AUTH COMPONENTS
Auth Components - frontend/src/components/auth/
- Create
frontend/src/components/auth/LoginForm.tsx - Add React Hook Form setup with Zod validation to LoginForm
- Add email field to LoginForm (validated with EmailStr)
- Add password field to LoginForm (min 8 chars)
- Add submit button with loading state to LoginForm
- Add error message display to LoginForm
- Add "Register" link to LoginForm
- Create
frontend/src/styles/components/LoginForm.css - Create
frontend/src/components/auth/RegisterForm.tsx - Add React Hook Form setup with Zod validation to RegisterForm
- Add email and password fields to RegisterForm
- Add password confirmation field to RegisterForm
- Add submit button with loading state to RegisterForm
- Add error message display to RegisterForm
- Add "Login" link to RegisterForm
- Create
frontend/src/styles/components/RegisterForm.css
🔬 FRONTEND - SCAN COMPONENTS
Scan Components - frontend/src/components/scan/
- Create
frontend/src/components/scan/ScanConfigForm.tsx - Add React Hook Form setup with Zod validation to ScanConfigForm
- Add target_url field to ScanConfigForm (validated as URL)
- Add auth_token field to ScanConfigForm (optional)
- Add tests_to_run checkboxes to ScanConfigForm (from SCAN_CONFIG)
- Add max_requests number input to ScanConfigForm (min/max from config)
- Add submit button with loading state to ScanConfigForm
- Add form error handling to ScanConfigForm
- Create
frontend/src/styles/components/ScanConfigForm.css - Create
frontend/src/components/scan/ScanResults.tsx - Add results summary header to ScanResults (total tests, vulnerabilities found)
- Add results grid to ScanResults (maps over results array)
- Add export button to ScanResults
- Create
frontend/src/styles/components/ScanResults.css - Create
frontend/src/components/scan/ResultCard.tsx - Add test name header to ResultCard
- Add status badge to ResultCard (uses SEVERITY_CONFIG for colors/icons)
- Add details section to ResultCard
- Add evidence section to ResultCard (formatted JSON)
- Add recommendations list to ResultCard
- Add conditional styling for vulnerable vs safe in ResultCard
- Create
frontend/src/styles/components/ResultCard.css - Create
frontend/src/components/scan/ScanHistory.tsx - Add table/list view to ScanHistory
- Add date, target URL, vulnerabilities count to each history item
- Add "View Details" button to each history item
- Create
frontend/src/styles/components/ScanHistory.css
📄 FRONTEND - PAGES
Pages - frontend/src/pages/
- Create
frontend/src/pages/LoginPage.tsx - Add LoginForm component to LoginPage
- Add page title and description to LoginPage
- Create
frontend/src/styles/pages/LoginPage.css - Create
frontend/src/pages/RegisterPage.tsx - Add RegisterForm component to RegisterPage
- Add page title and description to RegisterPage
- Create
frontend/src/styles/pages/RegisterPage.css - Create
frontend/src/pages/DashboardPage.tsx - Add welcome message to DashboardPage
- Add quick stats (total scans, recent vulnerabilities) to DashboardPage
- Add recent scan results to DashboardPage
- Create
frontend/src/styles/pages/DashboardPage.css - Create
frontend/src/pages/ScanPage.tsx - Add ScanConfigForm to ScanPage
- Add ScanResults display to ScanPage (conditional on scan completion)
- Create
frontend/src/styles/pages/ScanPage.css - Create
frontend/src/pages/HistoryPage.tsx - Add ScanHistory component to HistoryPage
- Add pagination to HistoryPage
- Create
frontend/src/styles/pages/HistoryPage.css
🎯 FRONTEND - APP SETUP
Main App Files
- Create
frontend/src/App.tsxwith React Router setup - Add Routes for /login, /register to App.tsx
- Add ProtectedRoute wrapper component to App.tsx
- Add Routes for /, /scan, /history (all protected) to App.tsx
- Add Layout wrapper for protected routes in App.tsx
- Create
frontend/src/main.tsxentry point - Add QueryClientProvider to main.tsx
- Add BrowserRouter to main.tsx
- Import theme.css in main.tsx
- Import index.css in main.tsx
- Create
frontend/src/styles/index.csswith global styles - Add CSS reset/normalize to index.css
- Add global font families to index.css
- Add global box-sizing to index.css
- Update
frontend/index.htmlwith app title and meta tags
🐳 DOCKER CONFIGURATION
Docker Files - /conf/
- Create
conf/Dockerfile.backend - Add Python 3.11-slim base image to Dockerfile.backend
- Add WORKDIR /app to Dockerfile.backend
- Add requirements.txt COPY and pip install to Dockerfile.backend
- Add application code COPY to Dockerfile.backend
- Add EXPOSE 8000 to Dockerfile.backend
- Add CMD with uvicorn to Dockerfile.backend
- Create
conf/Dockerfile.frontend - Add Node 20-alpine base image to Dockerfile.frontend
- Add WORKDIR /app to Dockerfile.frontend
- Add package.json COPY and npm ci to Dockerfile.frontend
- Add application code COPY to Dockerfile.frontend
- Add EXPOSE 5173 to Dockerfile.frontend
- Add CMD with npm run dev to Dockerfile.frontend
- Create
conf/nginx.conf - Add events block with worker_connections to nginx.conf
- Add upstream backend block to nginx.conf
- Add upstream frontend block to nginx.conf
- Add server block listening on port 80 to nginx.conf
- Add location / proxy to frontend in nginx.conf
- Add location /api proxy to backend in nginx.conf
- Add WebSocket upgrade headers to nginx.conf
Docker Compose
- Create
docker-compose.ymlat project root - Add PostgreSQL 16-alpine service to docker-compose.yml
- Configure postgres environment variables (user, password, db)
- Add postgres port mapping 5432:5432
- Add postgres volume for data persistence
- Add postgres healthcheck
- Add backend service to docker-compose.yml
- Configure backend build context and Dockerfile path
- Add backend environment variables (DATABASE_URL, SECRET_KEY, DEBUG)
- Add backend port mapping 8000:8000
- Add backend depends_on db with health condition
- Add backend volume for hot reload
- Add backend command with --reload flag
- Add frontend service to docker-compose.yml
- Configure frontend build context and Dockerfile path
- Add frontend environment variable VITE_API_URL
- Add frontend port mapping 5173:5173
- Add frontend volumes (code + node_modules)
- Add frontend command with --host flag
- Add nginx service to docker-compose.yml (production profile)
- Configure nginx port 80:80
- Add nginx volume for config file
- Add nginx depends_on backend and frontend
- Define postgres_data volume at bottom of docker-compose.yml
Environment Configuration
- Create
.envfile at project root (copy from .env.example) - Set SECRET_KEY in .env (generate random key)
- Set DEBUG=true for development in .env
- Set DATABASE_URL in .env
- Create
frontend/.envfile - Set VITE_API_URL=http://localhost:8000 in frontend/.env
🧪 TESTING
Backend Testing
- Create
backend/tests/__init__.py - Create
backend/tests/conftest.pywith pytest fixtures - Add test database fixture to conftest.py
- Add test client fixture to conftest.py
- Create
backend/tests/test_auth_service.py - Add test for user registration in test_auth_service.py
- Add test for user login in test_auth_service.py
- Add test for duplicate email in test_auth_service.py
- Create
backend/tests/test_scan_service.py - Add test for successful scan in test_scan_service.py
- Add test for concurrent scanner execution in test_scan_service.py
- Create
backend/tests/test_scanners/directory - Add test for rate limit scanner
- Add test for auth scanner
- Add test for SQLi scanner
- Add test for IDOR scanner
- Create
backend/tests/test_routes/directory - Add test for auth endpoints
- Add test for scan endpoints
Frontend Testing
- Install vitest, @testing-library/react, @testing-library/user-event
- Create
frontend/vitest.config.ts - Create
frontend/src/tests/setup.tswith testing setup - Create
frontend/src/components/__tests__/directory - Add Button component tests
- Add Input component tests
- Add LoginForm tests
- Add ScanConfigForm tests
- Create
frontend/src/hooks/__tests__/directory - Add useAuth hook tests
- Add useScan hook tests
📚 DOCUMENTATION
README Files
- Create comprehensive root
README.md - Add project overview to README
- Add features list to README
- Add tech stack to README
- Add quick start guide to README
- Add Docker setup instructions to README
- Add local development setup to README
- Add API documentation link to README
- Add contribution guidelines to README
- Add license to README
- Create
backend/README.mdwith backend-specific docs - Create
frontend/README.mdwith frontend-specific docs
Code Documentation
- Add docstrings to all backend functions/classes
- Add JSDoc comments to all frontend functions/components
- Add inline comments for complex logic in backend
- Add inline comments for complex logic in frontend
API Documentation
- Verify FastAPI auto-generated docs at /api/docs work
- Verify ReDoc at /api/redoc works
- Create Postman/Insomnia collection for API testing (optional)
🚀 DEPLOYMENT PREPARATION
Production Configuration
- Create production
.env.examplewith secure defaults - Add HTTPS configuration to nginx.conf (commented out)
- Add Gunicorn configuration for backend
- Add production build script to frontend package.json
- Create production docker-compose.prod.yml
- Add health check endpoints to backend
- Add frontend build optimization in vite.config.ts
Security Hardening
- Add rate limiting to FastAPI backend
- Add CORS whitelist for production
- Add CSP headers to nginx
- Add security headers to nginx (X-Frame-Options, etc.)
- Add input sanitization to frontend
- Verify JWT expiration works correctly
- Verify password hashing uses bcrypt
✅ FINAL CHECKS
Code Quality
- Run pylint/ruff on backend code
- Run ESLint on frontend code
- Run Prettier on frontend code
- Format backend code with yapf/black
- Check all type hints in backend
- Check all TypeScript types in frontend
- Verify no
anytypes in frontend - Verify no magic numbers/strings in backend
- Verify no magic numbers/strings in frontend
Functionality Testing
- Test user registration flow end-to-end
- Test user login flow end-to-end
- Test JWT token expiration and refresh
- Test rate limit scanner against test API
- Test auth scanner against test API
- Test SQLi scanner against test API
- Test IDOR scanner against test API
- Test scan history retrieval
- Test scan results display
- Test export functionality (if implemented)
- Test responsive design on mobile
- Test responsive design on tablet
- Test responsive design on desktop
Performance
- Check backend API response times
- Check frontend initial load time
- Verify lazy loading works for routes
- Verify TanStack Query caching works
- Check database query performance
- Add indexes to database tables if needed
Git & GitHub
- Initialize git repository
- Create
.gitignore(node_modules, .env, pycache, etc.) - Make initial commit
- Create GitHub repository
- Push to GitHub
- Add repository description
- Add repository topics/tags
- Create LICENSE file
- Add screenshots to README
- Add demo GIF/video to README
📊 PROJECT METRICS
Total Tasks: 390+ Estimated Time: 8-12 hours Completed: 0%
🎯 PRIORITY ORDER (What to Build First)
- Backend Foundation (config, core, models, schemas)
- Backend Repositories & Services (data + business logic)
- Backend Routes (API endpoints)
- One Scanner (rate limit - simplest)
- Frontend Foundation (config, types, services)
- Frontend Auth (login/register pages)
- Frontend Scan Page (form + results)
- Remaining Scanners (auth, SQLi, IDOR)
- Docker Setup (get everything running together)
- Testing & Polish (tests, docs, final touches)
Last Updated: 2025-11-08 Current Phase: Setup