Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260825-2144-amagansett-api-share-task5

rdmsm4x changelog — Amagansett API/share Task 5

Implemented the isolated API/share fail-closed seam and verified it without deployment or credentials.

Scope

Files touched in the project

Change and evidence

Backup and undo

Outstanding owner actions

Keep share creation unavailable until an approved durable adapter/migration and owner revocation path exist. No D1/KV/R2/email/provider binding or deployment was performed.

Review correction

Independent security review identified three Important findings; all were fixed in separate commit 9e0ba5d49c9a51a93bd20d221c51a5f786aaf058 in the same isolated worktree. Explicit listing scopes now reject empty, duplicate, and unknown IDs. Creation reads back by token hash and validates owner, hash, expiry, revocation, and exact scope before returning a URL. Request bodies are consumed through a bounded reader that cancels immediately over 8 KiB, including no-Content-Length chunked streams. JSON and every share-host fallback now emit X-Robots-Tag: noindex, nofollow. Final gates: 10 files/80 tests, strict typecheck, Worker dry-run with no bindings, diff check, clean worktree; canonical and Forst sibling remained unchanged. Notes entry was refreshed after this correction.