rdmsm4x-changelog-20260827-1720-amagansett-ak-public-read
rdmsm4x-changelog-20260827-1720-amagansett-ak-public-read
Prepared and verified an isolated AK edge repair that restores anonymous home-listing reads after Cloudflare Access removal while keeping owner data and all write/private operations blocked; the repair is committed but not deployed.
Scope
- Host:
rdmsm4x - Project:
amagansett.app - Canonical root inspected only:
/Users/richh/dev/sites/amagansett-app - New linked worktree:
/Users/richh/dev/_handoff/codex-out/amagansett-ak-public-read-20260827 - Branch:
codex/amagansett-ak-public-read-20260827 - Base:
fbd35e73ffafd40dabcf8967d3d1b16126b1a129 - Commit:
9172852bfc4e3cdd8242e130ea1939d19f5fd942 - Live deployment state: unchanged
Changes
- Created the new linked worktree and branch from the completed Guide/API descendant source.
- Superseded the stale
ak-htmx-uiwriter lease only after verifying its preserved worktree was clean atf68a860dac007a034236b04df79fd165bd994b8f. - Added an explicit public-read allowlist in the AK edge for feed, detail, property, nearby, route, search-suggestion, and profile GET requests.
- Added a fixed internal
.invalidpublic-viewer identity and made the edge overwrite any caller-supplied identity on public reads. - Made the public AK edge reject profile/reaction/subscription/inventory/share mutations plus job, digest, subscription, and resolver operations before invoking the protected API binding.
- Added unit and real-component integration coverage proving anonymous inventory renders while an owner's saved reaction remains in the owner's separate partition.
- Added
docs/AK-PUBLIC-READ-REPAIR.mdand updated the Cloudflare telemetry/Access handoff with source, deployment, verification, and rollback details.
Files touched
/Users/richh/dev/_handoff/codex-out/amagansett-ak-public-read-20260827/workers/amagansett-ak-edge/src/index.ts/Users/richh/dev/_handoff/codex-out/amagansett-ak-public-read-20260827/tests/unit/ak-edge.test.ts/Users/richh/dev/_handoff/codex-out/amagansett-ak-public-read-20260827/docs/AK-PUBLIC-READ-REPAIR.md/Users/richh/dev/_handoff/codex-out/amagansett-zaraz-ga4-handoff-20260827/README.md/Users/richh/.agent-coordination/checkins/ak-htmx-ui-codex.json/Users/richh/.agent-coordination/checkins/codex-rdmsm4x-amagansett-ak-public-read-20260827.json/Users/richh/dev/LLM/Claude/changelogs/rdmsm4x-changelog-20260827-1720-amagansett-ak-public-read.md
The canonical checkout and all previously preserved worktrees were left unchanged.
Commands and verification
- Revalidated hostname, roots, worktrees, branches, HEADs, dirty state, check-ins, project index, and fleet coordination policy.
- Ran
npm ciin the new worktree; 150 packages audited with zero vulnerabilities. - Ran the focused AK edge suite before implementation and observed three expected failing regression tests.
- Ran
npm test -- tests/unit/ak-edge.test.ts; 12/12 passed after implementation. - Ran
CI=1 npm run verify; 26 Vitest files / 181 tests passed, strict TypeScript passed, all four product builds passed, Worker dry-runs/contracts passed, and 30 Playwright scenarios passed. - Ran
npx wrangler deploy --dry-run --config deploy/ak.wrangler.jsonc; AK assets and the existingPLATFORM_APIservice binding packaged successfully. - Loaded existing Cloudflare credentials at runtime from
~/.secrets/global.envwithout printing values and ran the read-only Wrangler deployments list. The active pre-repair AK Worker version is4ef2dcbf-b59d-440f-b95a-fcc95561fbc9at 100%. - Re-probed the live anonymous feed; it remains HTTP 403 with
Cloudflare Access identity required, proving no deployment occurred. - Ran
git diff --check, a focused secret-pattern scan, committed the three tracked repair files, and verified the worktree is clean.
Backups and preservation
- The prior AK completion worktree remains preserved at
/Users/richh/dev/_handoff/codex-out/amagansett-ak-completion-20260826, HEAD3930ab2e7744ef3b2457acb433612f72a1357a71. - The prior HTMX worktree remains preserved at
/Users/richh/dev/_handoff/codex-out/amagansett-ak-htmx-ui-20260826, HEADf68a860dac007a034236b04df79fd165bd994b8f. - The completed Guide/API worktree remains preserved at
/Users/richh/dev/_handoff/codex-out/amagansett-guide-venues-20260827, HEADfbd35e73ffafd40dabcf8967d3d1b16126b1a129. - No database, Cloudflare configuration, Access policy, Worker version, Pages deployment, DNS record, or production data changed during this repair phase.
Undo
- Before deployment, no live rollback is needed. Preserve the
worktree; if the source change must be undone, use a new
git revert 9172852bfc4e3cdd8242e130ea1939d19f5fd942commit rather than rewriting history. - After a future deployment, roll the AK Worker back to version
4ef2dcbf-b59d-440f-b95a-fcc95561fbc9. That restores the pre-repair 403 behavior but does not recreate the deleted Access application.
Outstanding owner action
- Confirm whether to deploy only the AK edge from the prepared branch. Do not redeploy the shared API or any other Amagansett surface for this fix.