rdmsm4x changelog — Amagansett API/share Task 5
Implemented the isolated API/share fail-closed seam and verified it without deployment or credentials.
Scope
- Host:
rdmsm4x - Project/worktree:
/Users/richh/dev/_handoff/codex-out/amagansett-api-share-failclosed-20260825 - Branch/commit:
codex/amagansett-api-share-failclosed-20260825/041c50e674960fff02a2b28a383fdab71d1d01d4 - Canonical checkout and Forst sibling worktree were read-only checked and not modified.
Files touched in the project
worker/src/api.tsworker/src/index.tspackages/core/sharing.tspackages/core/types.tstests/unit/worker.test.tsISSUES.md.superpowers/sdd/2026-08-25-technical-completion/task-5-implementation.md
Change and evidence
- Guest reads hash the presented token, require an injected durable lookup adapter, validate hash/expiry/revocation, and render only persisted listing IDs. Unknown, unavailable, mismatched, expired, revoked, malformed, and adapter-error paths are uniform private no-store/noindex 404 responses.
- Owner creation requires exact API host/origin, JSON, bounded 8 KiB body, Access email contract, and explicit save plus lookup adapters. Missing durable adapters and save failures return 503 without a URL.
- Listing/place source observations remain per record; response time is not emitted as freshness. Scheduled and refresh-status state is explicitly disabled and zero-input.
- Commands:
npm test(10 files/75 tests pass),npm run typecheck(pass),npm run check:worker(pass; 25.49 KiB upload, 8.09 KiB gzip, no bindings),git diff --check(pass). - RED/GREEN: initial focused RED had 11 expected failures; focused GREEN passed 18/18.
- Invalid-token local Wrangler probe returned HTTP 404. Wrangler local hostname rewriting selected the generic localhost fallback; direct share-host routing is covered by unit tests.
Backup and undo
- Git commit is the recoverable rollback point; no files outside the project and this changelog were mutated.
- Undo by selecting a prior commit in the isolated worktree; do not overwrite the canonical checkout.
Outstanding owner actions
Keep share creation unavailable until an approved durable adapter/migration and owner revocation path exist. No D1/KV/R2/email/provider binding or deployment was performed.
Review correction
Independent security review identified three Important findings; all
were fixed in separate commit
9e0ba5d49c9a51a93bd20d221c51a5f786aaf058 in the same
isolated worktree. Explicit listing scopes now reject empty, duplicate,
and unknown IDs. Creation reads back by token hash and validates owner,
hash, expiry, revocation, and exact scope before returning a URL.
Request bodies are consumed through a bounded reader that cancels
immediately over 8 KiB, including no-Content-Length chunked streams.
JSON and every share-host fallback now emit
X-Robots-Tag: noindex, nofollow. Final gates: 10 files/80
tests, strict typecheck, Worker dry-run with no bindings, diff check,
clean worktree; canonical and Forst sibling remained unchanged. Notes
entry was refreshed after this correction.