Security and privacy
True removal of unselected elements
A package holds nothing for elements outside its spec: no code, assets, migrations or data tables, and hiding by a flag does not count. A packaging command proves the absence of files, menu entries, permissions and database tables for a profile, and the core tests check the database side.
Built in the repository (checked files or tested library code; not a product you can run yet)
What to plan for
- A removed element's data is a separate choice
- Proven per profile, not for every possible spec
- Installer behaviour not tested
What the catalog lists
Planned items that match this topic (keyword match; read each as a pointer):
- True removal: a build holds nothing for elements outside its spec SEC-0042
- Hiding by flag does not count as removal SEC-0043
- Absence test per profile: files SEC-0044
- Absence test per profile: commands and menus refuse SEC-0045
- Absence test per profile: database schema lacks removed tables SEC-0046
Honesty note
Everything listed is a plan or a design principle. No app is released and nothing is audited or certified.